# How to Configure croc to Use SOCKS5 or HTTP Proxy for File Transfers

> Learn how to configure croc to use SOCKS5 or HTTP proxy for secure file transfers. Utilize the --socks5 and --connect flags for seamless proxy integration.

- Repository: [Zack/croc](https://github.com/schollz/croc)
- Tags: how-to-guide
- Published: 2026-07-26

---

**croc supports tunneling encrypted file transfers through both SOCKS5 and HTTP CONNECT proxies using the `--socks5` and `--connect` CLI flags, which create custom dialers in [`src/comm/comm.go`](https://github.com/schollz/croc/blob/main/src/comm/comm.go) to route traffic before establishing the encrypted session.**

croc is an open-source, cross-platform tool for secure peer-to-peer file transfers. Configuring croc to use SOCKS5 or HTTP proxy servers allows you to route traffic through intermediate hops for privacy, censorship circumvention, or corporate network compliance, with proxy application happening transparently before the cryptographic handshake.

## How Proxy Support Works in croc

The schollz/croc repository implements proxy support across three layers of the architecture:

1. **CLI Flag Definition** – In [`src/cli/cli.go`](https://github.com/schollz/croc/blob/main/src/cli/cli.go), lines 84‑85 and 154‑155 define the `--socks5` and `--connect` string flags. These are registered for both sending and receiving modes to ensure the proxy configuration is available regardless of which peer initiates the transfer.

2. **Dialer Construction** – The [`src/comm/comm.go`](https://github.com/schollz/croc/blob/main/src/comm/comm.go) module (lines 45‑78) handles protocol-specific dialer creation:
   - **SOCKS5**: Uses `golang.org/x/net/proxy` to parse the proxy URL and instantiate a `proxy.Dialer`.
   - **HTTP**: Uses the third-party `github.com/magisterquis/connectproxy` package to build a CONNECT-style tunnel dialer.
   - Errors during proxy parsing or connection establishment are wrapped and propagated to the user immediately.

3. **Transport Integration** – The constructed dialer is injected into [`src/tcp/tcp.go`](https://github.com/schollz/croc/blob/main/src/tcp/tcp.go), ensuring all subsequent network operations—including relay negotiation, PAKE authentication, and AES-encrypted data transfer—flow through the proxy tunnel.

## Configuring SOCKS5 Proxies

To route traffic through a SOCKS5 proxy (such as Tor), pass the address with the `--socks5` flag:

```bash
croc --socks5 "127.0.0.1:9050" send myphoto.jpg

```

You can also use the **`SOCKS5_PROXY`** environment variable to avoid repeating the flag:

```bash
export SOCKS5_PROXY="127.0.0.1:9050"
croc send secret.txt

```

Under the hood, croc passes the address to `proxy.SOCKS5` from `golang.org/x/net/proxy`, creating a dialer that wraps the raw TCP connection before any cryptographic material is exchanged.

## Configuring HTTP CONNECT Proxies

For environments requiring HTTP CONNECT tunnels, use the `--connect` flag:

```bash
croc --connect "http://proxy.example.com:3128" send archive.tar.gz

```

Alternatively, set the **`HTTP_PROXY`** environment variable:

```bash
export HTTP_PROXY="http://proxy.example.com:3128"
croc send report.pdf

```

In [`src/comm/comm.go`](https://github.com/schollz/croc/blob/main/src/comm/comm.go), this invokes the `connectproxy` library to establish the CONNECT tunnel, after which croc upgrades the socket to its encrypted transport protocol.

## Combining Proxies with Other croc Features

Proxy flags integrate seamlessly with additional options. For example, generate a QR code while tunneling through SOCKS5:

```bash
croc --socks5 "127.0.0.1:9050" --qr send project.zip

```

The proxy dialer is established first; then the QR code generation, relay communication, and encrypted transfer proceed entirely over the tunneled connection.

## Summary

- **croc** supports both SOCKS5 and HTTP CONNECT proxies for transparent tunneling of encrypted file transfers.
- Use `--socks5` for SOCKS5 proxies and `--connect` for HTTP proxies, as defined in [`src/cli/cli.go`](https://github.com/schollz/croc/blob/main/src/cli/cli.go).
- Environment variables `SOCKS5_PROXY` and `HTTP_PROXY` provide scriptable alternatives to CLI flags.
- The proxy dialer is constructed in [`src/comm/comm.go`](https://github.com/schollz/croc/blob/main/src/comm/comm.go) using `golang.org/x/net/proxy` (SOCKS5) or `connectproxy` (HTTP), then applied in [`src/tcp/tcp.go`](https://github.com/schollz/croc/blob/main/src/tcp/tcp.go) before the encryption layer initializes.

## Frequently Asked Questions

### Does croc support SOCKS4 or SOCKS4a proxies?

No. The implementation in [`src/comm/comm.go`](https://github.com/schollz/croc/blob/main/src/comm/comm.go) specifically utilizes `golang.org/x/net/proxy` for SOCKS5 only. Attempting to use a SOCKS4 address will result in a connection or parsing error.

### Can I use environment variables instead of CLI flags for proxy configuration?

Yes. Set `SOCKS5_PROXY` or `HTTP_PROXY` in your shell environment. croc checks these variables when the corresponding CLI flags are omitted, allowing persistent proxy configuration without modifying command lines.

### Does routing through a proxy affect croc's end-to-end encryption?

No. The proxy tunnel is established at the TCP layer in [`src/tcp/tcp.go`](https://github.com/schollz/croc/blob/main/src/tcp/tcp.go) before the PAKE-authenticated key exchange and AES encryption begins. All payload data remains end-to-end encrypted between the sender and receiver, unreadable by the proxy server.

### How do I troubleshoot proxy connection failures in croc?

croc returns detailed error messages from [`src/comm/comm.go`](https://github.com/schollz/croc/blob/main/src/comm/comm.go) if the proxy URL is malformed or the proxy refuses the connection. Verify the address format (include `http://` for HTTP proxies), ensure the target port is accessible, and confirm that any required authentication credentials are properly embedded in the URL according to your proxy server's specification.