Network proxy configuration
Configure shared network routing and distinguish proxy failures from service errors.
In this topic
Mellow's Global Proxy setting configures supported application requests through a single proxy endpoint. It is useful on networks that require a gateway for downloads or external services. It is not a system-wide VPN and does not establish an access policy for every process on the Mac.
Enter an endpoint, not a web address
Search settings for Global Proxy. Supply a scheme, host, and explicit port:
http://proxy.example.net:8080
https://proxy.example.net:8443
socks5://proxy.example.net:1080
These are examples, not active proxy services. Replace the host and port with values supplied by your network administrator.
The parser accepts HTTP, HTTPS, SOCKS, and the socks5 spelling. The port must be between 1 and 65535. A path other than /, query string, fragment, embedded username, or embedded password is rejected. Local-only reserved hosts are rejected by the endpoint validator. A PAC file URL is not an accepted replacement for a proxy endpoint.
Do not paste credentials into the URL. The setting intentionally does not treat URL user information as a credential store.
Know which traffic is covered
The shared networking configuration produces Foundation proxy settings for participating URLSession clients. Coverage depends on the consumer using that configuration. Mellow's networking tests cover several provider, download, plugin-host, MCP, and media consumers, but that is not a guarantee about arbitrary third-party subprocesses.
A command launched by a tool, a browser's own network stack, and sandbox egress can have separate configuration. If your requirement is that all traffic must follow a particular network policy, validate each execution surface rather than relying on the word “Global.”
The sandbox's allowlist and network controls remain an independent boundary. A proxy choice should not be interpreted as granting a sandbox agent permission to contact every destination reachable by the proxy.
Check a change end to end
- Confirm the endpoint is reachable from the Mac and the port is correct.
- Save the proxy setting and start a fresh operation in the feature being tested.
- Verify a small request before retrying a large model download.
- Inspect the operation's destination, error, and timing in diagnostic output.
- Compare the same feature with the previous configuration when isolating a failure.
Avoid treating an unrelated successful request as proof of coverage. A provider call and a Git subprocess can use different network clients.
Diagnose rejection and connection failures
| Result | Likely boundary |
|---|---|
| Setting rejected immediately | Endpoint syntax, credentials, reserved host, or port validation |
| Connection timeout | Proxy reachability, firewall, or listener |
| Proxy responds but destination fails | Destination policy, TLS, authentication, or destination network |
| One feature works and another fails | Different consumer or process network configuration |
| Setting changed but old request continues | Existing connection or session still in use |
When sharing a report, include the scheme and a redacted endpoint, the feature tested, and the returned error. Do not include passwords or token-bearing destination URLs. The implementation source is Packages/MellowNetworking/Sources/GlobalProxyConfiguration.swift; app and CLI consumers should use the shared validated configuration rather than introducing their own URL parser.