Skip to content
Build with Mellow

Network proxy configuration

Configure shared network routing and distinguish proxy failures from service errors.

In this topic

Mellow's Global Proxy setting configures supported application requests through a single proxy endpoint. It is useful on networks that require a gateway for downloads or external services. It is not a system-wide VPN and does not establish an access policy for every process on the Mac.

Enter an endpoint, not a web address

Search settings for Global Proxy. Supply a scheme, host, and explicit port:

http://proxy.example.net:8080
https://proxy.example.net:8443
socks5://proxy.example.net:1080

These are examples, not active proxy services. Replace the host and port with values supplied by your network administrator.

The parser accepts HTTP, HTTPS, SOCKS, and the socks5 spelling. The port must be between 1 and 65535. A path other than /, query string, fragment, embedded username, or embedded password is rejected. Local-only reserved hosts are rejected by the endpoint validator. A PAC file URL is not an accepted replacement for a proxy endpoint.

Do not paste credentials into the URL. The setting intentionally does not treat URL user information as a credential store.

Know which traffic is covered

The shared networking configuration produces Foundation proxy settings for participating URLSession clients. Coverage depends on the consumer using that configuration. Mellow's networking tests cover several provider, download, plugin-host, MCP, and media consumers, but that is not a guarantee about arbitrary third-party subprocesses.

A command launched by a tool, a browser's own network stack, and sandbox egress can have separate configuration. If your requirement is that all traffic must follow a particular network policy, validate each execution surface rather than relying on the word “Global.”

The sandbox's allowlist and network controls remain an independent boundary. A proxy choice should not be interpreted as granting a sandbox agent permission to contact every destination reachable by the proxy.

Check a change end to end

  1. Confirm the endpoint is reachable from the Mac and the port is correct.
  2. Save the proxy setting and start a fresh operation in the feature being tested.
  3. Verify a small request before retrying a large model download.
  4. Inspect the operation's destination, error, and timing in diagnostic output.
  5. Compare the same feature with the previous configuration when isolating a failure.

Avoid treating an unrelated successful request as proof of coverage. A provider call and a Git subprocess can use different network clients.

Diagnose rejection and connection failures

ResultLikely boundary
Setting rejected immediatelyEndpoint syntax, credentials, reserved host, or port validation
Connection timeoutProxy reachability, firewall, or listener
Proxy responds but destination failsDestination policy, TLS, authentication, or destination network
One feature works and another failsDifferent consumer or process network configuration
Setting changed but old request continuesExisting connection or session still in use

When sharing a report, include the scheme and a redacted endpoint, the feature tested, and the returned error. Do not include passwords or token-bearing destination URLs. The implementation source is Packages/MellowNetworking/Sources/GlobalProxyConfiguration.swift; app and CLI consumers should use the shared validated configuration rather than introducing their own URL parser.