Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure a proxy with Guzzle’s proxy request option: provide one proxy URI for both protocols, or an array with separate http, https, and optional no entries. Keep TLS verification enabled, protect proxy credentials, and check the Guzzle and libcurl versions before using HTTPS proxies or proxy-authorization headers.

Configure a proxy for a request

Guzzle accepts proxy configuration in the options array passed to request(). The following example routes HTTP and HTTPS requests through the same HTTP proxy and bypasses it for localhost and a subdomain family:

<?php

require 'vendor/autoload.php';

use GuzzleHttpClient;

$client = new Client();
$response = $client->request('GET', 'https://example.com', [
    'proxy' => [
        'http'  => 'http://proxy.example:8080',
        'https' => 'http://proxy.example:8080',
        'no'    => ['localhost', '.internal.example'],
    ],
]);

echo $response->getStatusCode(), "n";
echo $response->getBody();

The http and https keys describe the destination protocol. Their values are proxy URIs; an HTTPS destination can commonly be reached through an HTTP proxy, so the https entry above still begins with http://. Use an https:// proxy URI only when your proxy endpoint itself supports TLS and your Guzzle and libcurl versions support it.

For a single proxy endpoint used for all protocols, the proxy option can instead be a URI string, such as 'proxy' => 'http://proxy.example:8080'. The array form is preferable when you need different proxy endpoints by protocol or a bypass list. See Guzzle’s proxy request option for the documented forms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
GL.iNet GL-MT300N-V2 (Mango) Portable Mini Travel Wireless Pocket VPN WiFi Router - 2X Ethernet Ports | USB 2.0 | OpenWrt | OpenVPN/Wireguard for Public & Hotel Wi-Fi | Easy to Set up via Admin Panel
  • 【WIRELESS MOBILE MINI TRAVEL ROUTER】 Convert a public network (wired or wireless) to a private Wi-Fi for secure surfing. Tethering. Powered by any laptop USB, power banks or 5V/2A DC adapters (sold separately). 39g (1.41 Oz) only, portable and pocket friendly. 2.4GHz ONLY
  • 【OPEN SOURCE & PROGRAMMABLE】 OpenWrt pre-installed, USB disk extendable.
  • 【LARGER STORAGE & EXTENDABILITY】 128MB RAM, 16MB Flash ROM, dual Ethernet ports, UART and GPIOs available for hardware DIY.
  • 【OPENVPN CLIENT】 OpenVPN client pre-installed, compatible with 30+ VPN service providers.
  • 【PACKAGE CONTENTS】 GL-MT300N-V2 (Mango) mini router (2-year Warranty), USB cable, Ethernet cable, User Manual. Please update to the latest firmware.

Set a client-wide default or override one call

Client-wide default

Put the option in the client constructor when most requests should use the same proxy:

$client = new GuzzleHttpClient([
    'proxy' => [
        'http'  => 'http://proxy.example:8080',
        'https' => 'http://proxy.example:8080',
        'no'    => ['localhost', '.internal.example'],
    ],
]);

$response = $client->request('GET', 'https://example.com');

One-request override

Put proxy in the request options when only one operation needs a proxy, or when it differs from the client default. Guzzle clients are immutable after creation: to change shared defaults, create another client with the desired configuration rather than trying to mutate the existing client. Request options and their behavior are described in the Guzzle request options documentation.

Authenticate to the proxy safely

Guzzle documents proxy credentials embedded in the URI’s user information. For example:

'proxy' => 'http://username:[email protected]:8080'

Do not commit a credential-bearing URI to source control or print it in logs. Load credentials from a protected environment variable or secret manager, and redact proxy URIs from exception messages and diagnostics. If the proxy expects an authentication mechanism other than URI user information, confirm that the transport handler you use supports it before deploying.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
UGREEN NAS DXP2800 2-Bay for Advanced Home Users, Remote Workers & Creators
  • 【Advanced Home Data & Media Hub】For advanced home users who need phone backup, file storage, and centralized data management. Centralize family photos, 4K videos, movies, computer backups, and personal files in one place while running multiple apps for home entertainment and everyday data management. Suitable for households with growing digital libraries and multiple NAS use cases.
  • 【Built for Creators, Media Servers & Advanced Apps】Powered by the Intel N100 Quad-Core CPU, 8GB DDR5 RAM, 2.5GbE networking, and dual M.2 NVMe slots, DXP2800 handles large files and heavier workloads with ease. Run Docker, virtual machines, and media server applications compatible with Plex—ideal for content creators, tech enthusiasts, and advanced home users managing 4K videos, RAW photos, personal media libraries, and multiple NAS apps.
  • 【Up to 80TB for Growing Digital Libraries】 Supports up to 80TB of storage using two HDD bays and two M.2 NVMe SSD slots for family photos, movies, RAW photos, 4K videos, work files, and device backups. AI photo management supports recognition of people, objects, scenes, and locations, album organization, and duplicate photo detection. HDDs and SSDs are not included.
  • 【AI-powered Home Surveillance】Turn DXP2800 into a centralized home surveillance hub by connecting compatible network cameras and storing recordings locally on your NAS. AI-powered features include Face Recognition, People Detection, and Pet Detection, helping advanced home users review important events more efficiently while managing home surveillance and personal data in one place.
  • 【One data Center Across Your Devices】Keep files from desktops, laptops, phones, tablets, and other devices together instead of scattered across cloud accounts and external drives. Access, back up, organize, and share data across Windows, macOS, Android, iOS, web browsers, and compatible smart TVs—ideal for creators and advanced home users working across multiple devices.

Do not treat a destination request’s ordinary authorization settings as proxy authentication. The proxy and the destination are different peers, and credentials intended for one should not be exposed to the other. In particular, review Guzzle’s version and redirect behavior before setting a first-class Proxy-Authorization header; see the security section below.

Use environment variables and bypass selected hosts

Guzzle documents HTTP_PROXY for HTTP requests, HTTPS_PROXY for HTTPS requests, and NO_PROXY for destinations that should bypass the proxy. A Unix-like shell example is:

export HTTP_PROXY='http://proxy.example:8080'
export HTTPS_PROXY='http://proxy.example:8080'
export NO_PROXY='localhost,127.0.0.1,.internal.example'

Environment settings are useful when deployment configuration, rather than application code, should choose the proxy. Guzzle documents an important caveat: it reads HTTP_PROXY only under the CLI SAPI, because untrusted CGI input can create HTTPoxy-style behavior. See Guzzle’s environment-variable guidance.

When you explicitly pass a proxy option as an array, include the no list there if those requests need exclusions. Do not assume that NO_PROXY will automatically fill an explicit option’s missing bypass list. For example, a local development call might use:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Synology DS223 Home & Office Backup Hub - Centralize Files, Protect Data & Monitor Property (2-Bay Diskless NAS)
  • One Place for All Your Data - Consolidate scattered files from multiple computers, phones and external drives into one accessible hub with 100% ownership
  • Professional File Collaboration - Share projects with clients, sync documents across teams and maintain version control without Dropbox fees
  • Automated Backup Protection - Set-and-forget backups for Macs, PCs and mobile devices to multiple destinations including cloud and external drives
  • DIY Surveillance System - Transform IP cameras into a professional monitoring solution with motion alerts, recording schedules and remote viewing
  • 2-Year Warranty - Reliable hardware backed by Synology's expert customer support team and ongoing software updates
$response = $client->request('GET', 'http://localhost:8080/health', [
    'proxy' => [
        'http'  => 'http://proxy.example:8080',
        'https' => 'http://proxy.example:8080',
        'no'    => ['localhost', '127.0.0.1', '.internal.example'],
    ],
]);

Test each bypass entry against the hostnames your application actually requests. A bypass mismatch can route internal traffic through the proxy or cause a request that should use the proxy to connect directly.

Choose a proxy URL scheme without weakening TLS

There are two separate TLS questions: whether the connection to the proxy is encrypted, and whether the destination server certificate is validated. An https:// proxy URI requests TLS to the proxy itself; an HTTPS destination still needs certificate validation. Guzzle’s verify option defaults to true. Leave it enabled, or set it to a trusted CA bundle path if the runtime needs an explicit bundle:

$client->request('GET', 'https://example.com', [
    'proxy' => 'http://proxy.example:8080',
    'verify' => '/etc/ssl/certs/ca-certificates.crt',
]);

Use the CA bundle path appropriate for the host system; the example path is not universal. Do not use 'verify' => false as a routine workaround. Guzzle explicitly labels disabling certificate verification insecure in its TLS verification documentation.

For an https:// proxy, Guzzle 7.12.1 or later is required to avoid the documented silent downgrade behavior, and libcurl must support HTTPS proxies. The security advisory notes that libcurl versions older than 7.50.2 may treat an HTTPS proxy as plaintext without warning. Check both the installed PHP package version and the actual libcurl used by the PHP cURL extension; the system’s command-line curl version may not describe PHP’s runtime transport.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Master Vpn - Free Unlimited VPN Proxy Server
  • Unlimited bandwidth, unlimited data.
  • Super-fast VPN and one tap connect.
  • Free worldwide multiple servers.
  • Works with all type of data carries. (Wi-Fi, 4G, LTE, 3G).
  • No registration, sign up needed.

Check Guzzle security advisories before production

Proxy-Authorization header exposure

Upgrade to Guzzle 7.14.2 or later before using first-class Proxy-Authorization headers. A 2026 advisory says earlier versions can put that header in the origin header list when a request goes direct, bypasses the proxy, uses SOCKS, or changes route after a redirect. The advisory describes a scenario in which a request through a proxy reaches an attacker-controlled HTTP URL and follows a redirect to an HTTPS or no-proxy destination directly, potentially exposing proxy credentials. Read the Guzzle security advisories and apply the advisory’s workaround if you cannot upgrade: remove first-class Proxy-Authorization fields and, where appropriate, use proxy URL user information or CURLOPT_PROXYUSERPWD with a cURL handler.

Noncanonical host routing

Also review the noncanonical-host advisory before deploying. It identifies patched versions 7.15.2 and 8.0.1 for a host-routing divergence that can affect proxy selection and host checks. Confirm the advisory’s affected-version details against the version line you run; do not infer that a version from another Guzzle major line is automatically patched.

HTTPS proxy downgrade

For HTTPS proxy endpoints, use Guzzle 7.12.1 or later and a libcurl version that supports HTTPS proxies; the advisory identifies libcurl older than 7.50.2 as potentially downgrading the proxy connection to plaintext silently. The advisory records a CVSS 3.1 base score of 5.3 for this issue and for the Proxy-Authorization issue; these are severity scores, not measures of how often an application will encounter the vulnerabilities.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Transport support, performance, and operational trade-offs

Guzzle can use different handlers, including cURL and PHP’s stream handler. Proxy-scheme support and handler-specific authentication options are not interchangeable. Verify the handler selected in your application and whether the required PHP cURL extension and libcurl features are installed. This matters especially for HTTPS and SOCKS proxy endpoints and options such as CURLOPT_PROXYUSERPWD.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Synology DS124 Personal Backup & File Hub - Protect Photos, Secure Home Surveillance (1-Bay Diskless NAS)
  • Complete Phone & Computer Backup - Automatically protect photos, documents and videos from iPhone android, Mac and Windows to one secure location
  • Your Private File Cloud - Access files from anywhere and share large projects with family or clients without relying on expensive cloud subscriptions
  • Smart Home Security Hub - Monitor your home 24/7 with AI-powered surveillance that detects people, vehicles and sends instant alerts
  • 100% Data Ownership - Keep full control of your personal data with multi-platform access and no monthly subscription fees
  • 2-Year Warranty - Reliable hardware backed by Synology's expert customer support team and ongoing software updates
  • Latency: A proxy adds a network hop and may add connection setup time. Measure the request path used in production rather than assuming the proxy is neutral.
  • Connection reuse: Reuse a configured Guzzle client for requests that share its defaults; create a separate client when proxy defaults need to differ.
  • Timeouts and failures: Set request timeouts appropriate to the application and distinguish proxy connection failures from destination timeouts in logs, without logging secrets.
  • Geography and egress: A proxy changes the network path and can change the apparent egress location, but the actual location and policy depend on the endpoint provider. Verify the endpoint’s behavior and terms rather than assuming a particular region.
  • Cost: Proxy provider charges, traffic allowances, and geographic options depend on the provider and are not determined by Guzzle.

Troubleshoot common proxy failures

Symptom Likely cause What to check or change
Connection refused or timeout before an HTTP response Wrong proxy hostname or port, unavailable endpoint, firewall restriction, or unsupported proxy protocol Confirm the effective URI and scheme without printing credentials; test network access to the proxy host and port, then verify handler support.
HTTP works but HTTPS fails Separate http and https entries differ, proxy CONNECT behavior is unavailable, or TLS trust is misconfigured Test an HTTP and HTTPS destination separately. Confirm the HTTPS destination’s proxy entry and keep verify enabled with a trusted CA bundle.
HTTPS proxy appears to connect without encryption Guzzle or libcurl is too old for the selected scheme Use Guzzle 7.12.1 or later and verify the libcurl linked to PHP supports HTTPS proxies; do not rely on a quiet connection as proof of TLS.
Local or internal host unexpectedly uses the proxy The host is missing from the explicit no list or does not match the configured bypass Add the required hostname to no when passing explicit proxy options, then test localhost and each internal domain individually.
Proxy credentials are rejected Incorrect user information, unsupported authentication mechanism, or credentials encoded incorrectly in a URI Verify credentials with the proxy operator and check transport-handler support. Keep secrets out of source and logs.
Certificate verification fails The runtime lacks a trusted CA bundle or the destination/proxy certificate chain is invalid Install or point to a trusted CA bundle with verify; do not disable validation.
Credentials appear on a redirected or direct request First-class Proxy-Authorization header behavior on an affected Guzzle version Upgrade to Guzzle 7.14.2 or later, review redirect and bypass paths, and follow the advisory workaround where upgrading is not immediately possible.
Proxy choice differs for unusual hostnames Host normalization or routing divergence covered by the noncanonical-host advisory Review the advisory and use a patched version, listed as 7.15.2 or 8.0.1 for the affected lines.

Or skip the browser setup

If your task is capturing a web page rather than routing an application’s own HTTP request through a proxy, ScreenshotNeo is a website screenshot API and MCP server. A single GET request returns a PNG, JPEG, WebP, or PDF, and its capture flow handles consent banners and overlays instead of requiring you to build browser automation around them.

cURL example, with the API details in the ScreenshotNeo documentation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

Cookie banners, newsletter popups, and chat widgets are removed before capture; each cleanup step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. An MCP server exposes screenshot tools to Claude, Cursor, and other MCP clients. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.

Sign up for ScreenshotNeo’s free plan and get 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does Guzzle proxy configuration support a bypass list?

Yes. In an explicit array-form proxy option, use the no entry for hosts that should connect directly.

Can I use an HTTPS destination through an HTTP proxy?

Yes. The proxy URI describes the proxy endpoint; an HTTP proxy can be used for an HTTPS destination when it supports the required tunneling behavior.

Does configuring a proxy make destination TLS verification unnecessary?

No. Keep Guzzle’s verify option enabled so the destination certificate is validated.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.