ScreenshotNeo

BlogComparisons

HTTP vs. HTTPS Proxies: Differences and Use Cases

Learn how HTTP proxies tunnel HTTPS, when HTTPS means TLS to the proxy, and how interception changes trust, security and operations.

By the ScreenshotNeo team30 September 20266 min read

HTTP vs. HTTPS Proxies: Differences and Use Cases

Short answer: “HTTP proxy” and “HTTPS proxy” are not two opposite standardized categories. An HTTP proxy can carry HTTPS traffic: the client sends CONNECT host:443, receives a tunnel, and then negotiates TLS with the origin through that tunnel. “HTTPS proxy” may instead mean that the client-to-proxy hop uses TLS, or simply an HTTP proxy used to reach HTTPS sites. Always identify the connection leg and whether TLS is intercepted.

In a normal tunnel, the proxy relays encrypted bytes and cannot read the HTTPS request or response body. In TLS interception, the proxy terminates the client TLS session, inspects it, and opens a second TLS session to the origin. That makes the proxy an active trust boundary.

HTTP proxy vs. HTTPS proxy at a glance

Question HTTP proxy carrying HTTPS Proxy endpoint reached over HTTPS TLS-intercepting proxy
Client-to-proxy connection HTTP, commonly CONNECT TLS-protected Usually TLS-protected and terminated by proxy
Client-to-origin TLS End-to-end through tunnel End-to-end if proxy only tunnels Two TLS sessions
Can proxy read application data? No, after TLS negotiation No, if it tunnels Yes, by design
Typical role Forward gateway Forward gateway with encrypted proxy hop Inspection and policy

See MDN CONNECT and RFC 9110 for the protocol definition.

How HTTPS through an HTTP proxy works

  1. The client connects to the proxy and authenticates if required.
  2. For an HTTPS URL, it sends CONNECT example.com:443 HTTP/1.1.
  3. The proxy checks policy and returns success or rejection.
  4. After success, the client starts a TLS handshake with example.com through the tunnel.
  5. HTTP requests, cookies and response bodies are encrypted inside that TLS session.

The proxy can still see metadata such as the requested destination, timing and byte counts. CONNECT can be restricted to port 443 or an allow-list. An unrestricted relay can be abused to reach reserved ports or relay SMTP spam; RFC 9110 and MDN recommend restricting destinations and ports.

CONNECT establishes a tunnel before the client negotiates TLS with the origin.
CONNECT establishes a tunnel before the client negotiates TLS with the origin.

What “HTTPS proxy” can mean

TLS to the proxy, tunnel to the origin

The client negotiates TLS with the proxy endpoint, then asks it to connect to the origin. The origin TLS session remains end-to-end. This protects credentials sent to the proxy from local observers but does not hide metadata from the proxy operator.

Tunneling and TLS interception create different trust boundaries.
Tunneling and TLS interception create different trust boundaries.

An HTTP proxy used for HTTPS websites

Libraries and provider dashboards often label a proxy “HTTPS” because it supports HTTPS destinations. The proxy URL may still be HTTP and the traffic is protected by CONNECT. Check the URL scheme and provider documentation.

TLS interception

An intercepting proxy presents a certificate to the client, decrypts the request, applies policy and creates a separate TLS connection to the origin. Devices must trust its issuing CA. Without that trust, clients report certificate errors. This is different from tunneling; see The Security Impact of HTTPS Interception.

Forward and reverse proxies

A forward proxy serves a client or group of clients. The client chooses the destination and sends traffic through the gateway. A reverse proxy sits in front of servers and can provide load balancing, authentication, decryption and caching. The HTTP-versus-HTTPS wording usually concerns forward-proxy connections; reverse-proxy TLS termination is a separate deployment decision. See MDN’s proxy guide.

Use cases

  • Corporate egress: route employee or build traffic through a policy gateway.
  • Restricted networks: use CONNECT when direct outbound connections are prohibited.
  • Selective routing: PAC files choose direct access or a proxy per URL.
  • Other TCP protocols: CONNECT can carry SSH or FTP where policy permits.
  • Reverse-proxy protection: terminate TLS, authenticate, cache or balance traffic before an origin.
  • IP tunneling: RFC 9484 defines HTTP-based IP proxying for remote-access VPNs, site-to-site VPNs and general packet tunneling. It is distinct from a normal TCP CONNECT tunnel.

Runnable examples

cURL

curl --proxy http://proxy.example:8080 \
  --proxy-user 'USERNAME:PASSWORD' \
  --verbose https://example.com/

cURL sends CONNECT automatically for an HTTPS URL. For a proxy endpoint reached over TLS:

curl --proxy https://proxy.example:8443 https://example.com/

For TLS interception, install the approved proxy CA in the cURL trust store. Avoid --insecure except for controlled diagnostics.

Python

import requests

proxies = {
    'http': 'http://USERNAME:PASSWORD@proxy.example:8080',
    'https': 'http://USERNAME:PASSWORD@proxy.example:8080',
}
response = requests.get('https://example.com/', proxies=proxies, timeout=(10, 30))
response.raise_for_status()
print(response.status_code, response.url)

The https dictionary entry means “use this proxy for HTTPS destinations”; its value can still be an HTTP proxy that receives CONNECT. Configure verify with an approved CA bundle for interception.

Node.js

import { fetch, ProxyAgent } from 'undici';

const dispatcher = new ProxyAgent('http://USERNAME:PASSWORD@proxy.example:8080');
const response = await fetch('https://example.com/', { dispatcher });
if (!response.ok) throw new Error(`${response.status} ${response.statusText}`);
console.log(await response.text());

Install with npm install undici. Node’s built-in fetch does not automatically use a system proxy; pass a ProxyAgent explicitly.

Security checklist

  • Decide whether the proxy may decrypt content and document who operates it.
  • Allow-list CONNECT destinations and ports; never expose an open relay.
  • Validate the origin certificate and the proxy’s upstream certificate separately.
  • Protect credentials and keep them out of source code, shell history and logs.
  • Define retention and access rules for proxy logs.
  • Do not claim that a proxy guarantees anonymity or fixes an insecure origin.

Performance, reliability and cost

A proxy adds a network hop. DNS behavior, TCP and TLS handshakes, distance and queueing can increase latency. Reuse connections, enable keep-alive, set explicit connect and read timeouts, and choose a region close to the client or origin. Stream large responses instead of buffering them.

Retry idempotent GET requests only when failures are transient. Use exponential backoff with jitter and a capped attempt count. Do not blindly retry POST requests or authentication failures. Monitor CONNECT rejections, TLS errors, timeouts and proxy saturation separately from origin failures.

Proxy costs depend on provider bandwidth, request volume, locations and interception features. The protocol does not define price or performance guarantees.

Troubleshooting

Symptom Cause Fix
407 Proxy Authentication Required Missing or invalid credentials Supply proxy credentials and URL-escape special characters.
403 or CONNECT denied Destination or port is outside policy Request an allow-list change; do not bypass policy.
Certificate verify failed Interception CA is untrusted or origin certificate is invalid Install the approved CA and separately validate the origin certificate.
Direct works, proxy times out Proxy egress, DNS, firewall or route problem Compare verbose direct and proxy traces and inspect proxy logs.
HTTP works, HTTPS fails CONNECT disabled or restricted Enable CONNECT for the destination or use a compatible proxy.
Node fetch ignores proxy No automatic system-proxy behavior Pass an undici ProxyAgent dispatcher.
Unexpected privacy exposure Proxy intercepts TLS or logs metadata Check the certificate chain, operator policy and logging configuration.

Or skip the browser setup

If you need a clean image or PDF of a web page rather than proxy administration, ScreenshotNeo makes one API request. It accepts cookie and consent banners before capture and removes 60+ known consent platforms, newsletter popups and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and X-Page-Verdict and X-Billed identify the result. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.

See the ScreenshotNeo API documentation for proxy headers and cookies, user agents, time zones, geolocation, waits, blocking rules, full-page and element captures, PDF settings, custom JavaScript and CSS, caching, signed links, async webhooks and bulk capture.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Free accounts include 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots, with every feature on every plan. Create a free ScreenshotNeo account.

FAQ

Can an HTTP proxy handle HTTPS websites?

Yes, when it supports CONNECT and permits the destination. It carries the encrypted TLS session without reading the application payload.

Can an HTTPS proxy see my traffic?

Only if it performs TLS interception or TLS terminates there. A normal CONNECT tunnel does not expose the HTTPS payload.

Is CONNECT the same as a VPN?

No. CONNECT normally creates a TCP tunnel for one destination. RFC 9484 defines a separate mechanism for proxying IP packets.

Does a proxy make me anonymous?

No. The operator can see connection metadata and may log it; DNS, endpoint security and the destination can also identify activity.