Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Short answer: configure the proxy endpoint with Selenium’s Proxy object, but do not put username:password in a Chrome proxy URL. Chrome ignores credentials embedded in manual proxy settings. Authentication is a separate browser-level challenge that must be satisfied by a compatible mechanism—such as integrated Negotiate/NTLM credentials, a tested extension approach, or a proxy service that supplies an already-authorized route.
This distinction prevents the most common failure: a browser that starts normally but returns 407 Proxy Authentication Required. The examples below use Python Selenium 4 and headless Chrome, then show how to verify routing and diagnose authentication independently from page automation.
What Selenium can configure—and what it cannot
Selenium exposes proxy configuration through its Python Proxy API and browser options (see the Options API). That tells Chrome which host, port and protocol to use. It does not provide a proxy service, validate your account, or inject arbitrary credentials into Chrome’s authentication flow.
Chromium’s proxy documentation is explicit: “Chrome does not implement this, and will not use any credentials embedded in the proxy settings.” Therefore, this is not a reliable solution:
#1 Best Overall
http://user:[email protected]:8080
Keep the endpoint and credentials conceptually separate. A browser-level proxy challenge can occur before a page is available, so submitting a username and password to an HTML login form is not the same operation.
Choose a proxy scheme that Chrome can authenticate
| Endpoint | Connection to proxy | Chrome authentication notes | Use when |
|---|---|---|---|
| HTTP proxy | Plain HTTP to the proxy; HTTPS destinations can still be tunneled with CONNECT | Chromium documents Basic, Digest, Negotiate and NTLM for HTTP proxy authentication. Basic sends credentials without encryption at the authentication layer. | Your provider supports one of Chrome’s documented schemes and you have a secure deployment path for credentials. |
| HTTPS proxy | TLS-protected connection to the proxy, as documented by Chromium | Confirm that the provider and Chrome agree on the authentication scheme and certificate trust. | You need encryption between the browser host and proxy. |
| SOCKSv5 | SOCKS protocol; DNS behavior depends on the configuration and provider | Chrome’s implementation does not support SOCKSv5 authentication methods. A username/password SOCKSv5 endpoint is therefore a poor fit for Chrome. | Only when the endpoint needs no authentication and supports the traffic your test requires. |
Ask the provider for the exact protocol, hostname, port and authentication scheme. “SOCKS5 with a username and password” is not interchangeable with an HTTP proxy that uses Basic or NTLM.
Prerequisites and a safe test plan
- Python 3 and a current Selenium 4 installation (
pip install -U selenium). - A Chrome/Chromium installation and a matching driver, or Selenium Manager configured to obtain one.
- A proxy endpoint authorized for your account, including its scheme and port.
- Credentials supplied through environment variables or a secret manager—not source files, shell history, logs or screenshots.
- A controlled endpoint that reports the request’s public egress address. Use one approved by your organization; do not infer proxy use merely because Chrome launched.
First test the endpoint with the provider’s approved method. Then test browser routing without page business logic. Finally test the target site. This ordering separates a bad proxy or credential from a Selenium selector bug.
Recommended Free Tools
Configure the proxy endpoint in headless Chrome
The following program configures an HTTP proxy endpoint. It intentionally contains no username or password, because Chrome will not consume credentials embedded in the manual setting.
Rank #2
import os
from selenium import webdriver
from selenium.webdriver.chrome.options import Options
from selenium.webdriver.common.proxy import Proxy, ProxyType
proxy_host = os.environ["PROXY_HOST"]
proxy_port = int(os.environ["PROXY_PORT"])
proxy = Proxy()
proxy.proxy_type = ProxyType.MANUAL
proxy.http_proxy = f"{proxy_host}:{proxy_port}"
proxy.ssl_proxy = f"{proxy_host}:{proxy_port}"
options = Options()
options.add_argument("--headless=new")
options.add_argument("--no-sandbox") # needed in some containers; assess your threat model
options.add_argument("--disable-dev-shm-usage")
options.proxy = proxy
try:
with webdriver.Chrome(options=options) as driver:
driver.set_page_load_timeout(60)
driver.get("https://example.com/")
print(driver.current_url)
print(driver.title)
finally:
pass
Set the values before running:
export PROXY_HOST=proxy.example.net
export PROXY_PORT=8080
python capture.py
Use ssl_proxy for HTTPS destinations. Add a separate ftp_proxy only if your task genuinely uses FTP. Review bypass rules: an accidental bypass can send the verification URL directly to the internet.
How to satisfy the authentication challenge
Integrated Negotiate or NTLM
Chrome can use cached machine credentials for Negotiate or NTLM under its documented restrictions. This is an enterprise authentication flow, not a general-purpose way to pass arbitrary per-proxy credentials. The test account must already be authorized on the machine or domain, and Chrome policy, realm and allowlisting must permit the exchange. A random proxy username and password cannot simply be converted into this flow.
Confirm the provider’s challenge and identity requirements before changing Chrome policies. Never enable broad credential delegation just to make a test pass.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Extension-based handling
Chrome provides the chrome.proxy extension API, which requires the proxy permission. An extension can set proxy rules and, in some deployments, react to an authentication challenge. The official API documentation does not establish one universal recipe that works across every Chrome release, headless mode and proxy scheme, so treat extension loading as a version-pinned implementation that must be tested.
If you evaluate this route, verify all of the following with the exact Chrome and Selenium versions used in production:
- The selected headless mode actually loads the extension.
- The manifest permissions match the API calls and are accepted by that Chrome version.
- The proxy’s challenge is the type your listener handles (Basic, Digest, Negotiate or NTLM).
- Credentials are injected from a secret store at runtime and never written to the extension bundle or logs.
- Browser logs show the extension loaded and no policy or certificate errors.
Do not claim success from a browser that merely starts. Verify the public egress address and inspect the first network failure.
Why page-level Selenium code is the wrong layer
A driver.find_element(...).send_keys(...) login script can fill a website’s form after navigation. A proxy challenge may happen before that document loads and is represented by an HTTP 407 response. Handle the challenge at the browser or network layer, then let Selenium automate the page.
Free tools Windows power users keep installed
One-click scans. No signup required.
Verification procedure
- Record the intended endpoint: protocol, host, port, authentication scheme and account or allowlist.
- Run the provider-approved connectivity test outside Selenium.
- Launch the minimal Selenium program with only proxy settings and a short timeout.
- Visit a controlled “what is my IP” or egress-reporting endpoint and compare its address with the direct connection.
- Only after routing is confirmed, add cookies, headers, waits and application selectors.
- Repeat the test from the same container, user account and region used in production; proxy allowlists often depend on source IP.
Troubleshooting authenticated headless sessions
407 Proxy Authentication Required
The proxy was reached, but authentication failed or was not attempted. Recheck the username, password, account status, source-IP allowlist and scheme. Confirm that you did not rely on user:password@host in the proxy URL. If the provider offers only SOCKSv5 authentication, choose an HTTP/HTTPS endpoint instead.
The browser opens, but the target is reached directly
Inspect HTTP and HTTPS proxy fields, bypass rules and environment-specific Chrome policies. Verify with an egress-reporting endpoint; startup success proves nothing about routing.
A page hangs or times out
Check proxy reachability outside Selenium, DNS behavior, TLS interception and the provider’s concurrency limits. Reduce the page-load timeout only after establishing a realistic baseline, and capture browser logs to distinguish a blocked resource from a dead proxy.
An extension works headed but not headless
Pin Chrome and Selenium, test the exact --headless=new mode in the deployment image, and confirm extension-loading support. The extension API documentation does not guarantee identical behavior across all headless versions; a headed test is not proof for production.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchCredentials appear in logs or artifacts
Rotate the exposed secret, scrub command history and CI output, and inspect screenshots, crash dumps and browser logs. Pass secrets through an environment or secret manager and redact proxy URLs before logging.
Best Value
BiDi is useful, but it is not a proxy-login shortcut
WebDriver BiDi is the W3C bidirectional protocol for browser automation, created by Selenium and browser vendors. It enables event-oriented browser communication, but Selenium’s documentation does not present enabling BiDi as a general solution for entering proxy credentials. Turn it on only when you need a documented BiDi capability; solve proxy authentication with a mechanism appropriate to the proxy scheme.
Performance, reliability and security considerations
- Each proxy hop adds connection and authentication latency. Use explicit page-load and script timeouts and collect timings so a slow proxy is not mistaken for a Selenium defect.
- Reuse a driver when the proxy identity can remain constant; create isolated sessions when credentials, IP identity or cookies must not mix.
- Do not disable certificate verification to “fix” an HTTPS proxy error. Install the provider’s documented CA only when your security team approves TLS interception.
- Prefer stronger authentication or a secure transport over Basic where the provider supports it, because Basic transmits credentials in an easily recoverable form at the authentication layer.
- Do not place proxy secrets in screenshots, exception messages, process arguments or committed CI configuration.
Or skip the browser setup
If your actual goal is a clean image or PDF rather than interactive browser automation, ScreenshotNeo makes one authenticated API call for a URL. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.
Using the API requires a ScreenshotNeo access key, not a target-site proxy credential. See the ScreenshotNeo API documentation for all options.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`${res.status} ${await res.text()}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));
The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account.
Frequently Asked Questions
Can I use http://user:password@host:port with Chrome Selenium?
No. Chromium says it will not use credentials embedded in manual proxy settings. Configure the endpoint separately and use an authentication mechanism supported by the proxy and Chrome.
Does WebDriver BiDi enter proxy credentials?
No general recipe is documented. BiDi provides bidirectional browser events and functionality; it is not a universal proxy-authentication interface.
Is an authenticated SOCKSv5 proxy compatible with Chrome?
Chrome’s documented implementation supports no SOCKSv5 authentication methods, so use a compatible HTTP or HTTPS proxy when credentials are required.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

