How to give an AI browser agent a proxy
Set the proxy on the agent’s browser, not in the prompt: proxy=ProxySettings(server=...) in browser-use, --proxy-server for Playwright MCP, localBrowserLaunchOptions.proxy in Stagehand. Run the agent on a machine whose IP you’ve authorized, and budget about 10 threads for every browser tab the agent keeps open.
An AI browser agent is a language model that controls a real browser: it reads the page (as a screenshot, an accessibility snapshot or both), decides what to click or type, and repeats until the task is done. Open-source frameworks such as browser-use, Playwright MCP and Stagehand let you run that browser on your own computer or server and plug in any model you like.
People add a proxy for the same reasons they would with a scraper: to spread an agent’s traffic over more IPs than their own, to see a site from a USA or EU address, and to keep a busy agent from getting their office or home IP rate-limited. The catch is that an agent is a heavy user. It loads full pages, often several times per task, over many parallel connections.
Most proxy problems with agents come from three places: the proxy is “requested” in the task prompt instead of configured on the browser, the agent runs on a vendor’s cloud where your IP authorization can’t follow it, or too many tabs share a small thread plan. This guide shows the exact setting in each framework, where an agent can and can’t use Storm proxies, and how to size the plan.
Which Storm plan fits
Agents drive a full browser, and one tab uses around 10 threads, so the 10-thread rotating package is only good for a first test. For one or two agents running side by side, 40 threads is the practical start; 80 or 150 threads fit a small fleet. If your agent logs in to accounts, or runs inside a hosted service that only accepts a username and password, a private dedicated proxy fits better than rotating IPs.
Rotating proxies (from $14/mo): 700,000+ IPs behind fixed gateway IP:PORTs. New IP on every request, or every 3 or 15 minutes. USA, EU, USA+EU or Worldwide. Unlimited bandwidth on every plan.
Get 40 threads for $39/mo See all rotating proxies plansBefore you start
- Log in to the member area and copy your gateway
IP:PORTs. They never change; the rotation happens on our side. - Add the public IP of the computer or server that will run your tool under Authorized IPs, click Save, and allow up to 15 minutes before testing. Rotating and residential proxies use IP authentication, so there is no username or password.
- Dedicated proxies work with either IP authentication or a username and password. Use user:pass if your IP changes or the tool runs on several machines.
- Count your threads: the tool’s total open connections must stay within your plan (for example 40 threads on the 40-thread plan).
- Put an agent’s browser behind a proxy, step by step
- Copy-paste config for each framework
- Hosted agents: where an IP-authorized proxy can’t follow
- Thread math for agents
- Which gateway suits which agent task
- Why unlimited bandwidth matters more for agents than for scrapers
- Keep the model’s API calls off the proxy
- Common errors and fixes
- FAQ
Put an agent’s browser behind a proxy, step by step
- Decide where the browser will run
The proxy must be reachable from the machine that launches the browser. That’s your laptop, a desktop, or a VPS you control. If the browser runs on someone else’s cloud (a hosted agent product or a cloud browser service), read “Hosted agents” below before buying anything.
- Authorize that machine’s IP
Find the public IP of the machine that starts the browser, not the one you type into. If you SSH into a VPS and run browser-use there, the VPS IP is the one to save under Authorized IPs in the member area. Allow up to 15 minutes after saving.
- Pick the gateway for the job
For research tasks that only read public pages, the Main rotating gateway is fine. For anything with a login, a cart or a multi-page form, use the 15-minute or 3-minute gateway, or a dedicated proxy, so the IP stays put while the agent works through the steps.
- Add the proxy to the browser config
Use the framework’s own proxy option (examples below). Writing “use a US proxy” in the task does nothing: the model can’t change how Chromium connects. The setting has to live in the code or the MCP server arguments.
- Check the exit IP from inside the agent’s browser
Ask the agent to open https://httpbin.org/ip and report the IP. A
requestscall from the same script proves nothing; it bypasses the browser. - Limit parallel agents to your threads
Count roughly 10 threads per open tab. Cap the number of agents (and tell them not to open extra tabs) so the total stays inside your plan, then run the real tasks.
Copy-paste config for each framework
Replace GATEWAY_IP:PORT with a gateway from your member area. Rotating and residential gateways need no username or password once the machine’s IP is authorized. Use the user:pass forms only with private dedicated proxies (PROXY_IP:PORT).
import asyncio
from browser_use import Agent, Browser, ChatOpenAI
from browser_use.browser import ProxySettings
browser = Browser(
headless=True,
proxy=ProxySettings(
server="http://GATEWAY_IP:PORT", # http:// even for https sites
bypass="localhost,127.0.0.1",
),
)
async def main():
agent = Agent(
task="Open https://httpbin.org/ip and report the IP address shown.",
llm=ChatOpenAI(model="gpt-4.1-mini"),
browser=browser,
)
await agent.run()
asyncio.run(main())from browser_use import Browser
from browser_use.browser import ProxySettings
browser = Browser(
proxy=ProxySettings(
server="http://PROXY_IP:PORT",
username="USERNAME",
password="PASSWORD",
),
){
"mcpServers": {
"playwright": {
"command": "npx",
"args": [
"@playwright/mcp@latest",
"--proxy-server=http://GATEWAY_IP:PORT",
"--proxy-bypass=localhost,127.0.0.1",
"--isolated"
]
}
}
}// mcp-config.json, start the server with:
// npx @playwright/mcp@latest --config mcp-config.json
{
"browser": {
"browserName": "chromium",
"launchOptions": {
"headless": true,
"proxy": {
"server": "http://PROXY_IP:PORT",
"username": "USERNAME",
"password": "PASSWORD"
}
}
}
}import { Stagehand } from "@browserbasehq/stagehand";
const stagehand = new Stagehand({
env: "LOCAL", // the browser runs on this machine
localBrowserLaunchOptions: {
proxy: {
server: "http://GATEWAY_IP:PORT",
// username / password only for dedicated proxies
},
},
});
await stagehand.init();
const page = stagehand.context.pages()[0];
await page.goto("https://httpbin.org/ip");Hosted agents: where an IP-authorized proxy can’t follow
Be clear about where the browser actually lives. ChatGPT’s agent mode, Browser Use Cloud, Browserbase sessions and similar services run the browser on the vendor’s servers. Their outgoing IPs belong to the vendor, they’re shared with other customers, and they can change from one session to the next. You can’t put those IPs in your Authorized IPs list and expect them to stay valid, and Storm rotating and residential proxies have no username and password to hand over instead.
That leaves three honest options:
- Run the agent yourself. browser-use, Playwright MCP and Stagehand in
LOCALmode all launch the browser on your machine. Your MCP client or chat app can still be anywhere; what matters is the machine that starts Chromium. - Use a VPS with a fixed IP. Put the agent on a small Linux server, authorize its IP once, and run it headless. This is also the fix when your home IP changes (or authorize a free No-IP hostname).
- Use private dedicated proxies with user:pass when a hosted tool has a custom-proxy field that takes host, port, username and password. Each one is a static USA IP only you use, with up to 100 threads.
If a hosted product has no custom-proxy field, no proxy provider can change its IP.
Thread math for agents
A browser doesn’t fetch a page over one connection. It opens several in parallel for HTML, scripts, styles, fonts, images and tracking calls, so one tab uses around 10 threads on our gateways. An agent that opens a second tab to compare prices doubles that for as long as both are open.
- 10 threads: one agent, one tab, for testing the setup only.
- 40 threads: about 3 agents at once with some headroom, or 4 if each keeps strictly to one tab.
- 80 threads: about 7 parallel agents.
- 150 threads: about 14 parallel agents; 200 threads, about 19.
Leave one tab’s worth spare. Going over the limit shows up as random connection failures mid-task, which the model then tries to “solve” by clicking around.
Search engines are the exception. Keep Google and other search engines to the Main gateway and at most a quarter of your threads: on a 40-thread plan that’s 10 threads, which is a single agent tab. Better: give the agent its start URLs directly.
Which gateway suits which agent task
- Reading public pages (research, price checks, summarising articles): the Main rotating gateway. Each new connection may leave from a different IP, which is fine when nothing depends on a session.
- Logged-in or multi-step work (forms, checkouts, dashboards): the 15-minute gateway, or a dedicated proxy if the task can take longer than that. A site that sees one session jump between IPs mid-checkout often signs it out.
- Sign-ups and social sites: the 3-minute gateway is meant for account registration, social sites and browsing (USA only). It isn’t for search-engine scraping.
- Residential ports: one residential IP for 5 minutes, changing at fixed times (minute 1, 6, 11 and so on). Open connections can drop at that moment, so short tasks fit better than a 20-minute workflow.
- One fixed identity per agent: give each agent its own dedicated proxy. Rotating pools are the wrong tool when an account should always see the same IP.
Why unlimited bandwidth matters more for agents than for scrapers
A scraper fetches the HTML and moves on. An agent needs the page fully rendered so it can take a screenshot or an accessibility snapshot after almost every action. That means every script, image, font and ad loads through the proxy, and the agent often revisits the same page several times while it plans, checks its work or recovers from a misclick.
On a plan billed per gigabyte, that traffic is hard to predict: one agent stuck in a loop on an image-heavy site can burn through a month’s allowance overnight. Storm plans are priced per thread, port or proxy with unlimited bandwidth, so the cost stays the same whether the agent loads 50 pages or 50,000.
The screenshots themselves go from your machine to the model’s API, not through the proxy, as long as you set the proxy on the browser only.
Keep the model’s API calls off the proxy
Set the proxy in the browser config, not as a global HTTP_PROXY/HTTPS_PROXY environment variable. Many Python and Node SDKs honour those variables, so a global setting would also send your OpenAI, Anthropic or Gemini API calls through the gateway. That adds latency and uses threads you need for pages, for traffic that gains nothing from a proxy. The PLAYWRIGHT_MCP_PROXY_SERVER variable is safe because only the Playwright MCP server reads it.
If you connect Playwright MCP to a browser that’s already open (its extension mode or --cdp-endpoint), the proxy flags don’t change that browser. Set the proxy where that browser was launched, for example with the steps in our Chrome proxy guide. For scripted, non-agent automation the same gateways work in plain Playwright and Puppeteer.
Common errors and fixes
net::ERR_PROXY_CONNECTION_FAILED on the first pageThe machine that launches the browser isn’t authorized, or was added less than 15 minutes ago. On a VPS, authorize the VPS IP, not your laptop’s. Also check the port is copied exactly from the member area.net::ERR_TUNNEL_CONNECTION_FAILED on HTTPS sitesThe proxy server was written as https://GATEWAY_IP:PORT, or the gateway reset the connection because your IP isn’t on the list. Use http:// in the proxy URL; HTTPS pages still load encrypted.ProxySettings, --proxy-server or localBrowserLaunchOptions, and restart the MCP server after changing its arguments.407 Proxy Authentication RequiredOn rotating or residential plans an unauthorized IP shows as a reset or tunnel error, not a 407, so a 407 there comes from another proxy in the chain. On dedicated proxies, check the username and password, and don’t put credentials inside --proxy-server; use the config file’s launchOptions.proxy fields.FAQ
Can I use Storm proxies with ChatGPT agent or other hosted agents?
Not with rotating or residential plans. Hosted agents browse from the vendor’s servers, and those IPs can’t be authorized in your member area. If the hosted tool lets you enter a custom proxy with username and password, a private dedicated proxy works there. Otherwise, run an open-source agent such as browser-use on your own machine or VPS.
How many threads does one AI agent need?
Plan on about 10 threads per open browser tab. One agent with one tab fits the 10-thread package for testing, but for real work start with 40 threads, which runs about three agents side by side.
Do I need to change the proxy in the prompt?
No, and it won’t work. The language model can’t reconfigure the browser’s network. The proxy is set once in the framework’s config, and the agent uses it for every page.
Does browser-use support proxies with a username and password?
Yes. ProxySettings takes server, bypass, username and password. With Storm, use the username and password only for dedicated proxies; rotating and residential gateways work by IP authorization.
Will screenshots and page loads cost extra on Storm?
No. Every plan has unlimited bandwidth and is priced per thread, port or proxy. Heavy pages and repeated loads don’t change the bill; only the number of parallel connections is limited.
Still have questions? Contact us here. A real person answers.
Related guides
Tool facts checked against the official documentation (October 2026): browser-use docs: browser parameters · browser-use docs: remote browser and proxy · Playwright MCP README · Stagehand docs: browser configuration. Storm Proxies facts: our plans page and refund policy.
Unlimited bandwidth. One flat monthly price.
Access is live the moment you pay, and the smallest package of each proxy type has a 24-hour money-back guarantee on your first order.