Explainer29 September 20268 min read

HTTP vs SOCKS5 proxy: how they differ, and which to use

HTTP vs SOCKS5 proxy: how each protocol works, socks5 vs socks5h DNS, which tools support which, tested snippets, and when to pick each one.

HTTP vs SOCKS5 proxy comes down to the language your tool speaks to the proxy. An HTTP proxy understands web requests and reaches https sites through a CONNECT tunnel. A SOCKS5 proxy relays any TCP connection without reading it. For web scraping both reach the same sites at similar speed, so tool support usually decides.

Below: what each protocol does on the wire, why socks5h:// exists, which tools handle which, and how both work on ProxyPanda. Every snippet ran against two local test proxies that ask for a login, one HTTP and one SOCKS5 server we wrote to RFC 1928 and RFC 1929, using curl 8.5, Python requests 2.34 with PySocks 1.7.1, Node.js 22 with socks-proxy-agent 10.1, Google Chrome 154 and headless Chromium 153.

What is an HTTP proxy?

An HTTP proxy speaks HTTP to your tool, and it behaves differently for the two kinds of site:

  • For an http:// site, your tool sends the whole request to the proxy, which fetches the page. The proxy can read the request and add or change headers.
  • For an https:// site, your tool sends one CONNECT line naming the host and port. The proxy opens a connection there, answers 200, and from then on only passes bytes along. Your tool speaks TLS to the site through that CONNECT tunnel, so the proxy sees the hostname and the byte count, never the page.

The login travels in a header on that first request:

CONNECT api.ipify.org:443 HTTP/1.1
Host: api.ipify.org:443
Proxy-Authorization: Basic VVNFUk5BTUU6UEFTU1dPUkQ=

HTTP/1.1 200 Connection Established

The long string is USERNAME:PASSWORD in base64, an encoding with no secrecy. curl and requests both send it with the first CONNECT, so our test proxy logged one exchange per connection.

What is a SOCKS5 proxy?

A SOCKS5 proxy does not know what HTTP is. It opens a TCP connection wherever you ask and relays bytes both ways, so it also carries non-web traffic, such as an SSH session, from any program with a SOCKS setting. First comes a short handshake:

  1. Greeting. The client says "version 5" and lists the login methods it can do. 0x00 means no login, 0x02 means username and password.
  2. Method choice. A proxy that wants a login picks 0x02. If the client did not offer it, the proxy answers 0xFF, "no acceptable method", and closes.
  3. Login. Under RFC 1929 the client sends the username and password as plain bytes, and the proxy answers success or failure.
  4. Connect request. The client names the target by one of three address types: an IPv4 address, an IPv6 address or a domain name, plus the port.
  5. Reply. The proxy connects and says so. For an https site, TLS then runs through it end to end, as through a CONNECT tunnel.

Our test server logged each step. This is requests with socks5h://:

greeting methods=[0, 2]
auth user=USERNAME ok
request cmd=1 atyp=domain target=api.ipify.org:443

The standard also defines a UDP relay. We have not verified it on our gateways, so treat SOCKS5 on ProxyPanda as TCP only, and ask in Discord before you build anything on UDP.

socks5 vs socks5h: where the DNS lookup happens

The address type in step 4 is the part people trip over. With socks5h://, your tool sends the hostname and the proxy resolves it. With socks5://, your own machine looks the name up first and sends only the resulting IP. Swapping one letter changed our server's log to:

request cmd=1 atyp=ipv4 target=104.26.12.205:443

Prefer the remote lookup, socks5h, for two reasons. With socks5://, your resolver, and whoever runs it, sees every hostname you visit. And large sites return different addresses by region, so a local lookup gives you the server near you, not the one near the proxy's exit.

An HTTP proxy always resolves remotely, because the hostname travels in the request. Tools spell the SOCKS choice differently:

  • curl: socks5h:// or --socks5-hostname resolve on the proxy; socks5:// or --socks5 resolve locally.
  • requests and socks-proxy-agent: the same rule, confirmed in our log.
  • Chrome: always sent the hostname in our test, even though the flag is spelled socks5://.
  • Firefox: tick "Proxy DNS when using SOCKS v5" in the connection settings.

Which tools support HTTP and SOCKS5

Tool HTTP proxy with login SOCKS5 proxy with login
curl built in built in: socks5h:// or --socks5-hostname
Python requests built in needs pip install "requests[socks]"
Node.js undici ProxyAgent or https-proxy-agent needs socks-proxy-agent
Chrome and Chromium yes, with a login prompt or page.authenticate no: only without a login
Firefox yes, with a login prompt the settings dialog has no login fields
Antidetect browsers yes GoLogin, Multilogin and MoreLogin list SOCKS5 in their proxy forms

curl

Either form works. The second keeps the password out of the URL, which helps when it contains symbols:

curl -s -x socks5h://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org
curl -s --socks5-hostname HOST:PORT -U "USERNAME:PASSWORD" https://api.ipify.org

A wrong password gives curl: (97) User was rejected by the SOCKS5 server (1 1). and a missing one gives curl: (97) No authentication method was acceptable. Proxy error codes lists the rest, and the curl guide covers the HTTP side.

Python requests

requests needs PySocks for SOCKS. Without it, a socks5h:// proxy fails with InvalidSchema: Missing dependencies for SOCKS support. Install the extra:

pip install "requests[socks]"

Then the proxy URL is the only change from the HTTP version in the Python requests guide:

import requests

PROXY = "socks5h://USERNAME:PASSWORD@HOST:PORT"
proxies = {"http": PROXY, "https": PROXY}

r = requests.get("https://api.ipify.org", proxies=proxies, timeout=30)
print(r.status_code, r.text)

A wrong password raises a ConnectionError ending in SOCKS5 authentication failed.

Node.js

undici's ProxyAgent, the usual way to proxy fetch, accepts only http: and https: proxy URLs. undici 8 adds a Socks5ProxyAgent, but it prints an experimental warning and refuses the socks5h: scheme. The steady route is socks-proxy-agent (npm i socks-proxy-agent):

import https from 'node:https';
import { SocksProxyAgent } from 'socks-proxy-agent';

const agent = new SocksProxyAgent('socks5h://USERNAME:PASSWORD@HOST:PORT');

https.get('https://api.ipify.org', { agent }, (res) => {
  let body = '';
  res.on('data', (chunk) => (body += chunk));
  res.on('end', () => console.log(res.statusCode, body));
});

With axios, pass the same agent as { httpAgent: agent, httpsAgent: agent, proxy: false }. The Node.js guide has the HTTP version.

Browsers: Chrome cannot log in to a SOCKS5 proxy

We pointed Chrome 154 at our login-protected SOCKS5 server with --proxy-server=socks5://HOST:PORT. Its greeting offered only method 0x00, no login, so the server refused it and the page failed with ERR_SOCKS_CONNECTION_FAILED. Putting USERNAME:PASSWORD@ into the flag failed earlier, with ERR_NO_SUPPORTED_PROXIES. Headless Chromium 153 behaved the same, and Playwright refused to launch Chromium at all with a SOCKS5 username set: Browser does not support socks5 proxy authentication. The same Chrome loaded the page through a SOCKS5 server with no login.

Firefox's connection dialog has SOCKS Host, Port and SOCKS v5, but no username or password field. So in a browser, use HTTP with a login, or SOCKS5 with your address on the IP allowlist so no login is needed. The browser guide covers the HTTP route; Chrome proxy errors decodes the error pages.

Is SOCKS5 faster than HTTP?

Not in a way the protocol alone would explain. Once a connection is set up, both only pass bytes along; the difference is in the setup. An HTTP proxy with a login needs one exchange, the CONNECT and its 200. SOCKS5 with a login needs three: greeting, login and connect request. That is two extra round trips to the proxy per new connection, and nothing after it.

With made-up numbers: if a round trip to the proxy takes 40 ms, SOCKS5 adds 80 ms to opening a connection. Reuse one connection for 100 requests and that is 80 ms in total; open a fresh one per request and it is 8 seconds across the 100. Reuse connections with keep-alive whichever protocol you choose. Where the exit sits and how fast the site answers matter far more.

SOCKS5 vs HTTPS proxy

"HTTPS proxy" means two different things:

  • https:// in a proxy URL means an encrypted connection to the proxy itself. The login and the CONNECT line are hidden on the hop between you and the proxy.
  • "HTTPS" in a tool's protocol menu often means an HTTP proxy that opens CONNECT tunnels. Proxifier uses the word this way, as the Proxifier guide notes.

Neither plain HTTP nor SOCKS5 encrypts the hop to the proxy: the HTTP login is base64 and the SOCKS5 login is plain bytes. Pages on https sites stay encrypted end to end in every case. On a network you do not trust, the IP allowlist keeps the password off the wire; proxy vs VPN covers what else a proxy does and does not hide.

When to use HTTP and when to use SOCKS5

  • Scraping over https with curl, requests or Node: HTTP. Nothing extra to install, and failures come back as status codes such as 407 and 502, easier to read than a closed socket.
  • A program that is not a web client, or one that only offers a SOCKS setting: SOCKS5.
  • Chrome or Firefox: HTTP with a login, or SOCKS5 with the IP allowlist.
  • An antidetect browser: either; pick the one its form and your service page agree on.

How HTTP and SOCKS5 work on ProxyPanda

On residential, the gateway answers HTTP and SOCKS5 on every port it publishes. Keep the same HOST, PORT, USERNAME and PASSWORD from the service page and change only the scheme, http:// or socks5h://. With Sticky IP the session option travels in the password, so copy it exactly as shown whichever scheme you use.

On ISP and datacenter, each proxy has a protocol you switch in the dashboard: HTTP, HTTPS or SOCKS5, as that proxy offers. A proxy may show a separate SOCKS5 port, and the service page shows the port for the chosen protocol, so copy it again after you switch.

The IP allowlist works with both protocols. It is also the way to use SOCKS5 in Chrome.

Quick answers

What is the difference between an HTTP and a SOCKS5 proxy? An HTTP proxy speaks HTTP and tunnels https with CONNECT. A SOCKS5 proxy relays any TCP connection after a short handshake and never reads the traffic.

What does socks5h mean? The same SOCKS5 protocol, with the hostname sent to the proxy to resolve. Use it for scraping.

Is SOCKS5 more secure than HTTP? No. Neither encrypts the hop to the proxy. https sites stay encrypted end to end through both.

Why does Chrome show ERR_SOCKS_CONNECTION_FAILED? Either the SOCKS5 proxy wants a login, which Chrome cannot send, or the port speaks only HTTP. Allowlist your IP, or switch the entry to http://.

Next step

On a residential service, run the curl line above once with http:// and once with socks5h:// against the same port. Both should print an exit address that is not yours; keep whichever suits your tools. A small top-up is enough for the test, and if one of the two refuses to connect, ask in Discord with the error and the password masked.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord