The same server can also work as an ordinary proxy — for browsers, utility programs, bots and everything unrelated to AI. That is handy when you need one way out to the internet with clear accounting: you can see who connected and how much traffic passed. In the interface this capability is organized as proxy services, and there can be several of them — one per channel. A service is configured on the channel itself, in the “HTTP proxies” section.
What exactly is offered
A proxy service is set up on every channel separately. On its port, both familiar ways of connecting are understood: HTTP proxy and SOCKS5. The program picks the way by its own settings — no need to open two ports. Works for browsers, download managers, any program that can work through a proxy.
The main difference from an ordinary proxy: connections reach the internet only through the channel whose port you connected to. If the channel is your proxy in another country, the browser exits from there too. A direct channel — the traffic goes from the server’s own address. So different contractors can be given different addresses: each their own port and their own channel.
Enabling it
By default nobody listens: a fresh install exposes no proxy at all until you set a port. There is no switch in the “Settings” window any more — the port and sign-in are set on the channel itself, in the “HTTP proxies” section. The channel editor has an “Inbound listener” section with a “Listen port” field and a “Require authentication” switch.
An empty port or zero means “not exposed” — this channel does not work as a proxy. Changes apply within about 15 seconds, without a restart: a changed port or sign-in conditions carry over to new connections, while the already open ones keep working until they end. The same can be done by editing the http-providers.yml file in the configuration folder — it is picked up in about 300 ms.
If the port is taken by another program, the listener does not start and tries again at the next check. The app itself keeps working — nothing crashes.
The port and publishing it
The listen port is unique across channels: the product will not give two channels the same port. Allowed values run from 0 to 65535, where 0 means “not exposed”.
Like the app’s main address, this port does not follow the subfolder, and in Docker it is published with its own line in the startup file. Until the line is added, the port is unreachable from outside. Practical advice: expose only the ports you really need.
Signing in with an access key
The key here is the same one as for the models. By default only an access-key holder can connect: for the HTTP proxy it is ordinary authorization where the login is anything and the password is your key; for SOCKS5 the same key is checked.
If the key has allowed channels, it will not pass through a foreign port: the key is admitted only to the channels it is allowed. Details are in the Access Keys section.
The check can be switched off — then the port is open to anyone who can reach it. The product warns about this right in the channel editor. That mode is acceptable only on an internal network; putting it on the internet is a bad idea.
License
The proxy service works only with a valid license — just like calls to the models. While there is no license or it has expired, every connection is refused: HTTP gets a 402 reply, SOCKS5 a disconnect, and a row with the reason appears in the “Proxy traffic” log. The interface, the chat and the service pages stay available. Details are on the Licensing page.
Limits
- Up to 256 concurrent connections per port. Extra connections are closed at once, without a reply — that is protection from overload.
- 30 seconds to establish a connection. If the connection is not up within that time, it is closed.
- After establishment, time is unlimited — the connection lives as long as there is something to exchange.
Channels
A connection reaches the internet only through the channel whose port you connected to: there is no backup channel and no direct fallback. The channel does not work — the connection does not establish. That is deliberate: the port means “through this channel and nothing else”.
The channels themselves are created in the neighboring “HTTP proxies” section. What they are and which kinds exist — in the Providers section.
The log
Every connection lands in its own log — it opens in the log section on the “Proxy traffic” tab: the time, the key, the channel, the protocol, the destination address, how many bytes went out and came in, the duration and the error if there was one. There too — today’s statistics and the list of channels that carried the most traffic. Filtering works by key, channel, protocol and errors.
Money
Ordinary traffic is counted in volume, but never counted in money, and it does not touch the spending limits. Even if gigabytes pass through the proxy service, the AI key will not be blocked — these are different things and they should not be mixed.
Next: what can be configured in the interface at all — in the Settings section.