October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
browser automation

How to Use a Proxy in Puppeteer: Full Guide for 2026

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Chromium’s --proxy-server launch argument to route Puppeteer traffic through an HTTP proxy, then call page.authenticate() before navigation when that proxy requires HTTP credentials. For isolated jobs, use a browser context’s documented proxy options when your installed Puppeteer release supports them. SOCKS5 authentication is a special case: Chrome’s SOCKS implementation does not accept credentials through page.authenticate().

What a Puppeteer proxy changes

A proxy sits between the Chromium process and destination servers. With an HTTP proxy, ordinary HTTP requests are forwarded by the proxy. For an HTTPS URL, Chromium normally uses the HTTP CONNECT method to establish a tunnel; TLS then remains between the browser and destination, although the proxy sees the target hostname while creating the tunnel.

The proxy affects browser page traffic only when Chromium receives the proxy setting. It does not automatically mean that every Node.js request, Puppeteer download, or operating-system service uses that proxy. Keep those scopes separate when diagnosing a leak or a failed connection.

Requirements and safe configuration

  • Node.js and a Puppeteer package installed in the project.
  • A proxy endpoint in the form http://host:port (or another protocol supported by your Chromium build).
  • Credentials supplied through environment variables or a secret manager, not committed source code.
  • A test URL that reports the apparent client IP, so you can verify routing without assuming it worked.

Proxy use must comply with the target website’s terms, applicable law, and the proxy provider’s rules. A proxy can change network identity; it does not grant permission to bypass access controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Browser-wide HTTP proxy: the standard setup

Pass the proxy to puppeteer.launch(). The setting applies to pages created by that browser instance.

const puppeteer = require('puppeteer');

const proxyServer = process.env.PROXY_SERVER; // e.g. http://proxy-host:proxy-port
const username = process.env.PROXY_USERNAME;
const password = process.env.PROXY_PASSWORD;

(async () => {
  const browser = await puppeteer.launch({
    args: [`--proxy-server=${proxyServer}`],
  });

  try {
    const page = await browser.newPage();

    // Only call this when the proxy uses HTTP authentication.
    if (username && password) {
      await page.authenticate({ username, password });
    }

    await page.goto('https://example.com', { waitUntil: 'networkidle2' });
    console.log('title:', await page.title());
  } finally {
    await browser.close();
  }
})();

Set PROXY_SERVER before starting the script. Call page.authenticate() before goto(), because it answers the proxy’s HTTP authentication challenge. Puppeteer’s API describes this as providing credentials for HTTP authentication and notes that request interception is enabled behind the scenes, which can affect performance.

Verify the apparent IP

Replace the example URL with an IP-echo endpoint you trust:

await page.goto('https://your-ip-echo.example/', { waitUntil: 'domcontentloaded' });
console.log(await page.evaluate(() => document.body.innerText));

This pattern demonstrates verification; it is not a claim that a particular endpoint, proxy, or provider was tested here. If the reported address is your direct address, stop and fix routing rather than silently continuing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Proxy authentication: HTTP versus SOCKS

HTTP proxy credentials

For a proxy that responds with an HTTP authentication challenge, use:

await page.authenticate({
  username: process.env.PROXY_USERNAME,
  password: process.env.PROXY_PASSWORD,
});

Do not include credentials in the --proxy-server argument unless the proxy and Chromium version explicitly support that format. Command-line arguments can appear in process listings and logs.

SOCKS and SOCKS5 limitations

Chrome’s SOCKS proxy implementation does not support SOCKS5 authentication, and page.authenticate() cannot provide SOCKS credentials. This is a Chromium browser-stack limitation, not a promise about every third-party proxy wrapper. If your endpoint requires authenticated SOCKS5, ask the provider for an HTTP endpoint or place a locally controlled forwarder in front of the upstream proxy, subject to the provider’s terms.

Choosing the scope: browser, context, or page

Approach Scope Authentication and state Trade-offs
--proxy-server at launch Every page in one browser HTTP credentials are supplied per page with page.authenticate(); cookies and storage are shared unless isolated separately Simple and widely used; changing identity normally means starting another browser
Browser context proxyServer All requests in that context Context-level routing and a bypass list are documented in Puppeteer’s Next API; release availability must be checked Useful for separate jobs in one browser, but the Next API is version-sensitive
Request interception or a local forwarder Can approximate per-page or per-job routing Depends on the forwarder or interception layer; an upstream authenticated proxy may be hidden behind the local endpoint More moving parts, extra handling, and potentially another network hop

Do not treat a context option as a setter for an already-created page. Create the context with the option, then create pages inside it. Check the API documentation matching your installed release before relying on Next-only fields.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Context-level example (release-dependent)

const context = await browser.createBrowserContext({
  proxyServer: 'http://proxy-host:proxy-port',
  proxyBypassList: ['<-loopback>', 'localhost'],
});
const page = await context.newPage();
await page.goto('https://example.com');

The option names and availability can change between releases. If your installed version rejects them, use a separate browser launch or upgrade only after checking compatibility with the rest of your application.

Separate proxies for jobs and rotation

“Rotation” can mean two different operations:

  • Provider-managed rotation: one endpoint assigns different upstream addresses according to the provider’s policy.
  • Application-selected rotation: your code chooses a different endpoint for each browser or context.

If each job needs a distinct proxy identity and clean cookies, start a browser per job or create an isolated context when context-level routing is available in your release. Reusing a page can retain cookies, local storage, cache, and login state. Reusing a context intentionally shares those items and may be useful for a session that should persist.

Changing proxies does not guarantee that a target will permit access, avoid CAPTCHAs, or stop rate limiting. Rotation policy should be chosen with the site’s rules, session requirements, geography, protocol support, and provider terms in mind.

Environment variables: what they do and do not do

Puppeteer configuration documentation lists HTTP_PROXY, HTTPS_PROXY, and NO_PROXY as environment settings. Their effect depends on the process and operation reading them. They should not be confused with Chromium’s page-routing argument.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In particular, puppeteer-core ignores Puppeteer configuration and environment variables intended for Puppeteer’s own configuration. For deterministic browser traffic, pass --proxy-server explicitly and verify the resulting IP. Use environment variables for secrets and deployment configuration, not as proof that a page is proxied.

Local forwarding with an authenticated upstream

A local forwarding proxy can accept a simple unauthenticated connection from Chromium and connect onward using upstream credentials. The Puppeteer guide discusses proxy-chain for this pattern. It adds a local process and an extra hop, so monitor its lifecycle and close it when the browser exits.

This approach can help when Chromium’s direct authentication behavior does not match the upstream provider, but it does not remove protocol limitations or provider restrictions. A request-interception plugin is another possible design, yet interception adds per-request handling overhead and package compatibility must be checked against the Puppeteer version; do not adopt an unmaintained example package as a default.

Performance, reliability, and security

Performance

  • page.authenticate() turns on request interception behind the scenes, which Puppeteer warns may affect performance.
  • A local forwarder adds a process boundary and network hop.
  • Interception-based routing handles requests in application code and can increase CPU and latency.
  • No general speed penalty or success rate can be stated without measuring your browser version, proxy, destination, and workload.

Reliability

Use explicit navigation timeouts, log the selected endpoint (without logging secrets), and record whether the proxy check succeeded before processing valuable pages. Keep browser and context lifecycles bounded so failed proxies do not leave orphaned processes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security

Protect proxy credentials as production secrets. Avoid embedding them in URLs, screenshots, error messages, or command histories. With HTTPS through an HTTP proxy, the proxy can observe the destination hostname and connection metadata during CONNECT; it cannot normally read the tunneled page contents unless TLS is deliberately intercepted and trusted.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting checklist

The page uses the direct IP

  • Confirm the launch argument is exactly --proxy-server=http://host:port and was passed to the browser that created the page.
  • Check for a typo in the host or port and verify the endpoint independently with a proxy-aware command-line request.
  • Ensure no code launches a second browser without the argument.
  • Run the IP-echo check before the real job and fail closed if it reports the direct address.

407 Proxy Authentication Required

  • Confirm the proxy expects HTTP authentication rather than SOCKS credentials.
  • Call page.authenticate() before navigation and use the exact username and password supplied by the provider.
  • Test the credentials outside Puppeteer, then rotate the secret if it may have been exposed.

SOCKS5 authentication fails

Do not keep retrying page.authenticate(); it cannot supply SOCKS credentials in Chrome’s implementation. Request an HTTP endpoint or use a vetted local forwarder that supports the provider’s protocol.

HTTPS pages fail while HTTP pages work

  • Check that the proxy supports HTTPS tunneling with CONNECT.
  • Verify firewall rules and DNS behavior for the proxy host.
  • Test the same destination through the endpoint independently, then inspect Chromium’s error output without disabling TLS verification.

Only some hosts bypass the proxy

Review proxyBypassList if you use a browser context option, and inspect NO_PROXY in the environment. Remove broad bypass rules when every request must use the proxy, while retaining necessary loopback exceptions for local services.

Navigation hangs or times out

  • Check proxy health and destination reachability separately.
  • Set a finite navigation timeout and capture the browser error.
  • Try a new browser or context to eliminate stale cookies, cache, or a dead connection.
  • Do not silently retry through a direct connection when proxy routing is a requirement.

Or skip the browser setup

If your goal is a clean rendered image or PDF rather than browser automation, ScreenshotNeo provides a single screenshot request. It removes cookie banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, with the response identifying the page verdict and billing status. Its MCP server lets Claude, Cursor, and other MCP clients call take_screenshot, get_page_info, and capture_pdf.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the API documentation at https://screenshotneo.com/docs/ for options such as full-page lazy-image loading, CSS-selector element capture, device presets, custom headers and cookies, waits, blocking rules, signed links, asynchronous jobs, bulk capture, and PDF settings.

Best Value
The SQL Programming Language: .
  • Used Book in Good Condition
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to try it.

FAQ

Can one Puppeteer page use a different proxy after it is created?

The standard documented setup is browser-wide at launch. Context-level proxy options apply when the context is created and are release-dependent; for reliable per-job changes, create a new context or browser.

Should I use an HTTP or SOCKS proxy?

Choose based on the endpoint’s protocol, authentication support, destination requirements, and your installed Chromium behavior. HTTP authentication works with page.authenticate(); Chrome SOCKS5 authentication does not.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does proxying hide browser fingerprints?

No. A proxy changes network routing and usually the apparent IP, but it does not by itself change browser fingerprinting signals, cookies, TLS characteristics, or automation detection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.