aria2 proxy settings: --all-proxy, and why torrent peers never use it
aria2 proxy settings: --all-proxy sends HTTP, HTTPS and FTP downloads through an HTTP proxy, but aria2 has no SOCKS5 and its torrent peers always go direct.
aria2 proxy settings come down to one flag: --all-proxy, which sends aria2's HTTP, HTTPS and FTP downloads through an HTTP proxy. aria2 has no SOCKS5 support at all, and for BitTorrent the proxy reaches only HTTP trackers and web seeds. Connections to peers, DHT and UDP trackers always leave from your own address. For mirror downloads it works well; for hiding a torrent client's address, aria2 is the wrong tool.
That makes this page shorter than our other client guides, and more useful to anyone building a script: it tells you which half of aria2 a proxy can help with.
Do you need a proxy for this?
If you are fetching a Linux image or a dataset with aria2, probably not. aria2 is excellent at pulling one file from several mirrors at once, and none of that needs a proxy. Through a metered proxy, every byte of the file counts as traffic.
A proxy is the right call when your script or server has to send its downloads from a particular address, for example a build machine that must leave through a fixed exit. Whatever you fetch, keep to files you are allowed to share and download: distribution images, open-source releases, research data, game and software patches. Unauthorised sharing is not allowed on ProxyPanda, and the acceptable use policy puts staying within the law on you. Lawful peer-to-peer traffic is fine on our residential proxies and on dedicated IPs with no traffic cap, though aria2's own peer connections never reach a proxy anyway, as below.
What aria2 can send through a proxy
From aria2's manual and its issue tracker:
- HTTP proxies only. The proxy options take a host with an optional
http://in front, an optional login before it and an optional port after it, as inhttp://USERNAME:PASSWORD@HOST:PORT. The manual never mentions SOCKS. The issue asking for SOCKS support, number 153, has been open since 2013. - Mirror downloads, fully. HTTP, HTTPS and FTP transfers go through the proxy.
- HTTP trackers, yes. The maintainer: "aria2 can connect to tcp tracker via HTTP proxy. There is no proxy support for UDP traffic."
- Peers, never. aria2's source opens peer connections straight to the peer's address.
- DHT and UDP trackers, never. The manual notes that
--enable-dht"also enables UDP tracker support", and both are UDP.
What our test showed
On 8 October 2026 we ran aria2 1.37.0, the Alpine Linux package, in a container. We set --all-proxy to a local HTTP proxy (tinyproxy) that logs every request, turned DHT off, and gave aria2 Debian 13.7.0's netinst torrent.
The proxy logged two kinds of request: the announce to Debian's HTTP tracker, and HTTPS requests to cdimage.debian.org, the torrent's web seed. We sampled aria2's open connections every three seconds. The three samples taken while it was downloading showed three connections to the proxy each time, and 30, 43 and 44 going straight to peers. The peers saw our address, exactly as the manual and source suggest.
Note the web seed. A torrent that lists one sends part of its data over HTTPS, and that part does cross the proxy, so it shows on the meter even though the peers do not.
The limits on our side as well
- No SOCKS5 in aria2 means no SOCKS5 from us here. Use our HTTP proxy. If your project needs SOCKS5, it needs a different tool; see the end of this page.
- An HTTP proxy carries no UDP, which is why aria2's UDP traffic could not be proxied even in principle.
- Nothing is encrypted by the proxy. HTTPS downloads stay encrypted end to end inside the tunnel. Plain HTTP and FTP downloads, and the proxy login, are readable on the way to the proxy.
Commands
A mirror download through the proxy, with the login kept out of the URL so special characters in a password do not break it:
aria2c --all-proxy="http://HOST:PORT" \
--all-proxy-user="USERNAME" --all-proxy-passwd="PASSWORD" \
https://cdimage.debian.org/debian-cd/current/amd64/bt-cd/SHA256SUMS
We ran this against our local test proxy without a login; the two login flags are as aria2's manual documents them. There are also --http-proxy, --https-proxy and --ftp-proxy if you want a proxy for one protocol only, and --proxy-method accepts get or tunnel. If your server's address is on our IP allowlist, drop the login flags.
If you run a torrent with the proxy set, turn DHT off so nothing UDP goes out on its own:
aria2c --all-proxy="http://HOST:PORT" --enable-dht=false --seed-time=0 file.torrent
That keeps the tracker announce on the proxy and stops DHT and UDP trackers. It does not move the peers. --seed-time=0 makes aria2 exit when the download completes instead of staying on to seed.
Use aria2 to check our meter
Because aria2 sends a mirror download wholly through the proxy, it is the easiest way to test the meter itself:
- Note the traffic figure for your service in the dashboard. How to see how much traffic is left shows where.
- Download one file of known size through
--all-proxy, such as a distribution image whose size is printed on the mirror's directory page. - Wait a few minutes, since figures update regularly rather than live, and look again.
The figure should rise by about the file's size, plus a little for headers and the TLS handshake. If the gap is bigger than a percent or two, we want to hear about it; the rules, and what we do when we are wrong, are under metering. How to check your proxy provider's meter goes into the method.
For a torrent, expect the opposite: the meter moves only for the tracker announce and any web-seed data, because the peers never touch the proxy.
If you need SOCKS5 or proxied peers
aria2 cannot do either. For a script that needs peers behind a SOCKS5 proxy, a client with a daemon and an API does it properly: qBittorrent in its -nox form, or Deluge. For plain HTTPS downloads over SOCKS5, curl handles socks5h:// directly, as HTTP vs SOCKS5 shows.
Quick answers
Does aria2 support SOCKS5? No. Only HTTP proxies, and the request for SOCKS has been open since 2013.
Does --all-proxy hide my IP from torrent peers? No. Peer connections always go direct.
Do DHT and UDP trackers use the proxy? No. Turn them off with --enable-dht=false when a proxy is set.
Is aria2 still maintained? Lightly. The latest release is 1.37.0, from November 2023.
Next step
Use aria2 for what a proxy can do well, a mirror download from a fixed exit, and read the meter after the first file. If you are choosing a tool for a lawful torrent job instead, which torrent clients work with SOCKS5 compares them, and Discord is there for anything this page leaves open.