Does Chrome Have a Proxy Setting for Each Profile?
There is no proxy field inside Chrome on Windows, macOS or Linux — the Settings button hands you to the operating system’s proxy dialog, which applies to every app on the machine. To get a chrome per profile proxy, you set it outside that panel: a launch flag paired with its own user-data directory, a proxy extension scoped to one profile, a PAC script, or a managed policy. Each option has a different scope, and each fails in a different way.

📌 TL;DR Executive Summary
- Core Takeaway: Chrome resolves proxy settings from four ranked sources — managed policy, extension, command-line flag, system settings. A per-profile proxy only works if nothing higher in that chain overrides it.
- Key Risk/Challenge: Launching with
--proxy-serveralone does nothing if another Chrome process is already running, and the flag cannot accept a username or password. - Recommended Solution: One profile folder, one shortcut carrying
--user-data-dirand--proxy-server, verified with an IP check and a WebRTC check — or a browser that handles this per profile natively.
How Chrome Decides Which Proxy to Use
Chromium reads proxy configuration from four ranked sources. From highest priority to lowest: a managed policy pushed by an administrator, an extension using the chrome.proxy API, a command-line flag, and the system settings. The highest source that exists wins, and the others are ignored without an error message.
That ranking explains the most common complaint — “I set the flag and Chrome still uses my normal connection.” Usually a policy or an active proxy extension sits above the flag. It also explains why Chrome behaves this way at all: the Chromium network settings design document states that proxy, SSL/TLS and certificate handling are read from the operating system so administrators can control every application at once. Per-instance proxy control arrived later, as command-line options.
Once you add a chrome per profile proxy of your own, that ranking is what decides whether it takes effect. A leftover policy or a forgotten extension still wins, and Chrome reports no error when it does.
Proxying itself happens at the URL level: Chrome maps a URL to an ordered list of proxy servers before the request leaves the browser. That is why a bypass rule can send one host direct while every other request goes through the proxy.
| Source | Scope | Priority | What it looks like in practice |
|---|---|---|---|
| Managed policy | Whole install or machine | Highest | Admin-set proxy or WebRTC policy; your flag is ignored silently |
| Extension (chrome.proxy API) | One profile | Second | Per-profile by design, credentials supported |
| Command-line flag | One browser process | Third | Needs --user-data-dir; no credentials; void if Chrome is already running |
| System settings | Every app on the OS | Lowest | What Chrome’s Settings button opens; HTTP only on Windows |
Step-by-Step: One Proxy Per Chrome Profile With –user-data-dir
This is the only native method that gives each account a separate session and a separate proxy without installing anything into the browser. It relies on two switches working together: one points Chrome at its own profile folder, the other points it at a proxy.
- Close every Chrome window and confirm no process is left. The
--proxy-serverflag applies to a single instance and is ignored when an existing Chrome process is running. Check Task Manager on Windows or Activity Monitor on macOS for stray processes first. - Write your endpoints in URL form. Use
http://host:port,https://host:portorsocks5://host:port. Keep logins separate — the flag does not accept credentials. - Create one profile folder per account. For example
C:\chrome-profiles\store-usandC:\chrome-profiles\store-de. Each folder holds its own cookies, history, logins and local storage. - Launch Chrome with both switches. On Windows:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --user-data-dir="C:\chrome-profiles\store-us" --proxy-server="http://gate.example.com:8000". On macOS:/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --user-data-dir=/Users/me/chrome-profiles/store-us --proxy-server=socks5://gate.example.com:1080. Add--proxy-bypass-listonly next to a proxy flag — it is inert on its own, and it matches trailing domains, so"*google.com"also catchesigoogle.com. - Duplicate the shortcut instead of retyping the command. Copy the desktop shortcut, rename it to the account, and append the same two switches with the new folder and endpoint in the Target field.
- Repeat with a second folder and a second proxy. Two windows, two folders, two exit IPs, one machine.
You can also map schemes explicitly — --proxy-server="http=gate.example.com:80;ftp=gate2.example.com:21" — or force a clean direct connection for one instance with the special value direct://.
If you would rather build the folders through the UI first and attach proxies afterwards, the walkthrough for how to create multiple Chrome profiles covers the naming and shortcut side.
When you script the launch, keep the same pairing. Each account gets its own user data directory and its own proxy argument:
const puppeteer = require('puppeteer');
// One entry per account: its own profile folder and its own proxy.
const accounts = [
{ userDataDir: '/Users/me/chrome-profiles/store-us', proxy: 'http://gate.example.com:8000' },
{ userDataDir: '/Users/me/chrome-profiles/store-de', proxy: 'socks5://gate.example.com:1080' },
];
(async () => {
for (const account of accounts) {
const browser = await puppeteer.launch({
headless: false,
userDataDir: account.userDataDir,
args: [`--proxy-server=${account.proxy}`],
});
const page = await browser.newPage();
await page.goto('https://api.ipify.org?format=json'); // any IP echo page
console.log(account.userDataDir, await page.evaluate(() => document.body.innerText));
await browser.close();
}
})();
What to check afterwards: open an IP echo page in each window. The two windows must return different addresses, and each address should match the city and country you bought for that proxy. If both windows show the same IP, the second launch reused the first browser process — close everything and relaunch with distinct folders.
Step-by-Step: One Proxy Per Profile With a Proxy Extension
Extensions are the built-in answer to per-profile proxying because the chrome.proxy API only applies to the profile the extension is installed in. Install it in one profile and the other profiles never see it.
- Open the target profile and go to
chrome://extensions. - Pick a maintained extension. The original Proxy SwitchyOmega stopped running after Google retired Manifest V2 in mid-2025. ZeroOmega is the Manifest V3 fork still receiving updates in 2026; FoxyProxy and Simple Proxy Switcher use the same API with different rule-building interfaces.
- Install it while that profile window is in focus so it lands in the right profile and nowhere else.
- Create a proxy profile with scheme, host, port, username and password, then apply it. Unlike the command-line flag, extensions store credentials — no repeated login prompt.
- Repeat per profile, assigning a different endpoint each time. Add auto-switch rules if specific domains should bypass the proxy.
Because chrome.proxy is scoped to the profile it is installed in, a chrome per profile proxy configured this way survives restarts without a launch shortcut and keeps its credentials. That is the main advantage over the command-line flag.
From Chrome 148, extension APIs are also available under the browser namespace as a cross-browser alternative to chrome, which matters if you maintain your own routing extension.
What to check afterwards: open chrome://extensions in two profiles and confirm each lists only its own proxy extension, then open the popup in each to see the active endpoint. If a profile shows no extension but still routes through a proxy, something at system or policy level is doing the work.
PAC Files, Bypass Lists and Managed Policy
Chromium offers three ways to resolve proxies: manual rules, a PAC script, and auto-detect through the WPAD protocol over DHCP or DNS. A PAC file is a JavaScript function, FindProxyForURL(url, host), that returns a directive per request — "PROXY gate.example.com:8000", "SOCKS5 gate.example.com:1080" or "DIRECT". Point Chrome at it with --proxy-pac-url=file:///path/to/proxy.pac or through the operating system’s automatic-configuration field.
How Send.win Helps With Chrome Per Profile Proxy
Send.win is an antidetect browser built for exactly this kind of work — every profile is a clean, isolated identity:
- Isolated profiles – unique fingerprint, separate cookies and storage per profile
- Stealth engine – canvas, WebGL, fonts, and audio spoofed at the engine level
- Desktop app + cloud sessions – native app for Windows, macOS, and Linux, or run profiles in the cloud with no install
- Built-in residential proxies – with automatic timezone, locale, and WebRTC matching
- Team features – share logged-in profiles with teammates without sharing passwords
Try the instant cloud browser demo — no install, no signup — or download the desktop app. The 30-day free trial needs no credit card, and paid plans start at $6.99/month billed annually (see pricing).
PAC is the right tool when only part of your traffic should be proxied — marketplaces, ad managers and social platforms through the proxy, everything else direct. Two limits matter. A PAC file cannot carry a password. And specifying an HTTPS proxy is generally not possible through system proxy settings, so that case needs a PAC script or a Chrome-level setting such as a flag, extension or policy.
Two more switches belong in the same toolbox. --no-proxy-server overrides every other proxy setting and forces a direct connection, useful for a clean “control” instance. --proxy-auto-detect turns on WPAD discovery. Remember that --proxy-bypass-list has no effect unless --proxy-server is also present.
Verify the Proxy Took Effect: Four Checks You Can Run in a Minute
Do not trust the settings page. Verify the chrome per profile proxy from inside the profile, because that is where leaks show up.
- IP check. Load an IP echo page in the profile. The address, country and provider should match the endpoint you configured. Compare at least two profiles side by side.
- DNS check. Run a DNS leak test. With an HTTP or HTTPS proxy, Chrome defers name resolution to the proxy, so the resolvers you see should belong to the proxy network rather than your ISP.
- WebRTC check. Run a WebRTC leak test in the same tab. If it exposes your home IP, add the limiter extension or set the policy before you log into anything you care about.
- Authentication check. Visit a few pages and watch for a proxy login prompt. Repeated prompts mean credentials are not being stored — something the launch flag can never do.
For a wider checklist that covers cookie hygiene and profile naming alongside the network checks, the step-by-step guide to using browser profiles with proxies walks through the same verification loop in more detail.
HTTP, HTTPS or SOCKS5: Choosing Per Profile
The transport you pick changes how DNS is handled, which authentication Chrome can negotiate, and how many connections you get. That last number matters when one profile runs several heavy tabs.
| Proxy type | DNS resolution | Authentication | Notes for per-profile use |
|---|---|---|---|
| HTTP | Deferred to the proxy | Basic, Digest, Negotiate, NTLM | Proxies http, https, ws and wss; HTTP/1.1 proxies are capped at 32 simultaneous connections across all domains |
| HTTPS | Deferred to the proxy | As HTTP, plus client certificates | HTTP/2 to the proxy allows more concurrent connections; usually cannot be set through system settings |
| SOCKS5 | Resolved proxy-side | No SOCKSv4 authentication support | Best when you need non-HTTP traffic handled too |
| SOCKS4 | Resolved client-side | None | IPv4 addresses only; SOCKSv4a extensions are not supported |
In practice, residential HTTP or SOCKS5 endpoints handle most account work. If a SOCKS5 endpoint connects but every page times out, the cause is usually DNS rather than the proxy itself — the troubleshooting steps for when a SOCKS5 proxy not working in Chrome covers the common causes.
Pitfalls That Break a Chrome Per Profile Proxy
- Chrome is already running. The single biggest cause of “the flag does nothing.” Close every window and confirm no process remains before launching with the switches.
- Credentials inside the flag. Supplying
user:pass@hostinline returnsnet::ERR_NO_SUPPORTED_PROXIES. Use an extension, a PAC script or an endpoint that whitelists your IP instead. - Two accounts sharing one user-data directory. Same cookies, same session, same proxy — the isolation you thought you had does not exist. When you set up several stores at once, the recipe for one profile per account is the safer pattern.
- A policy you did not set. On a managed machine, a pushed proxy or WebRTC policy sits above everything you configure locally.
- Leaks around the proxy. DNS and WebRTC can still expose the real network path even when the IP check passes.
- Mistaking proxy isolation for browser isolation. One machine produces one class of fingerprint — canvas, WebGL, audio, fonts, hardware. Two Chrome profiles on the same laptop can look like the same device to a determined platform even with two different exit IPs.
- Assuming this works on mobile. Chrome for Android has no proxy setting of its own; only the Wi-Fi network’s HTTP proxy applies, and it has no login fields.
One clarification worth keeping straight: “Chrome has no proxy settings” is accurate for Windows, macOS and Linux, but ChromeOS sets a proxy per network, so the statement does not hold there.
When Per-Profile Proxies Are Not Enough
Everything above gives you separate cookies and separate exit IPs. It does not give you separate machines. The fingerprint Chrome presents — canvas, WebGL, audio, installed fonts, hardware concurrency — is generated by the laptop, so profiles on the same device remain linkable in principle. You also have to source and rotate proxies yourself, store credentials, and hand over passwords when a teammate needs one profile.
Send.win approaches the same problem from the other end. Each profile in the Sendwin Browser desktop app carries its own fingerprint, with canvas, WebGL, audio, fonts and hardware spoofed at the engine level and kept coherent, so profiles do not share an identity. Residential proxies are included on every plan, and timezone, locale, WebRTC and geolocation follow the proxy’s exit IP automatically — the leak you patched with an extension is closed by default instead. Profiles can also run on Send.win’s cloud nodes from any device, unlimited on Pro and Team after the free 10-minute daily preview, and you can share a profile with a paid teammate so it opens already signed in. For a straight comparison of where each approach fits, see Send.win vs Chrome profiles.
🏆 Send.win Verdict
Chrome can do a per-profile proxy — a separate user-data folder per account, a proxy extension, or a PAC file. What it cannot do is make two profiles on the same laptop read as two different computers, and that is where multi-account work gets flagged. Send.win keeps the profile-per-account model you already built, but moves the fingerprint and the proxy into the browser engine, so the isolation covers WebRTC, geolocation and hardware signals rather than cookies alone.
Try Send.win free today — 30 days, $0 today, desktop app for Windows, macOS and Linux, plus a cloud preview you can open without installing anything.
Frequently Asked Questions
Does Chrome have its own proxy settings?
Not on Windows, macOS or Linux. The Settings button opens your operating system’s proxy dialog, which affects every application on the machine. ChromeOS is the exception, where a proxy is configured per network. Everything Chrome-specific happens through a flag, an extension, a PAC file or a managed policy.
Can two Chrome profiles use two different proxies?
Yes, but not through the profile switcher. Setting a chrome per profile proxy means leaving the switcher behind: either a launch flag paired with a separate --user-data-dir per account, or a proxy extension installed only in the profile that needs it. The system proxy panel cannot do this because it applies to the whole operating system.
How do I set a proxy for just one Chrome window?
Launch a second Chrome instance with its own user-data directory and its own --proxy-server value. Close all existing Chrome windows first, otherwise the flag is ignored and the new window joins the running process with the old settings.
Why does –proxy-server ignore my username and password?
The flag does not accept credentials. Passing them inline as user:pass@host:port fails with net::ERR_NO_SUPPORTED_PROXIES. Use a proxy extension that stores credentials, a PAC script, or an endpoint that authenticates you by IP.
How do I stop the Chrome proxy login popup?
Store the credentials somewhere Chrome can read them: an extension using the chrome.proxy API, or the macOS Proxies pane, which has username and password fields per proxy row. Windows manual proxy setup takes an HTTP proxy only and has no username field, so Chrome prompts when the proxy challenges it.
Should I choose HTTP or SOCKS5 for each profile?
HTTP proxies defer name resolution to the proxy and support Basic, Digest, Negotiate and NTLM authentication, which suits most account work. SOCKS5 resolves names proxy-side and handles more than HTTP traffic. SOCKS4 resolves client-side, needs IPv4 and lacks the SOCKSv4a extensions Chrome expects.
How do I stop WebRTC leaking my real IP behind a proxy?
Install the WebRTC Network Limiter extension, or set the WebRtcIPHandling policy. Chrome ships no WebRTC settings page, so there is nothing in the UI to switch off. Run a leak test after every change and confirm it shows the proxy address, not your home connection.
Does a per-profile proxy keep platforms from linking my accounts?
It removes the shared-IP signal, which is a real improvement, but it is not complete. Profiles on one machine still share canvas, WebGL, audio, font and hardware characteristics, and a platform that fingerprints device-level signals can still connect them across separate exit IPs. Treat the proxy as one layer, not the whole defence.