How to Configure croc to Use SOCKS5 or HTTP Proxy for File Transfers
croc supports tunneling encrypted file transfers through both SOCKS5 and HTTP CONNECT proxies using the --socks5 and --connect CLI flags, which create custom dialers in src/comm/comm.go to route traffic before establishing the encrypted session.
croc is an open-source, cross-platform tool for secure peer-to-peer file transfers. Configuring croc to use SOCKS5 or HTTP proxy servers allows you to route traffic through intermediate hops for privacy, censorship circumvention, or corporate network compliance, with proxy application happening transparently before the cryptographic handshake.
How Proxy Support Works in croc
The schollz/croc repository implements proxy support across three layers of the architecture:
-
CLI Flag Definition – In
src/cli/cli.go, lines 84‑85 and 154‑155 define the--socks5and--connectstring flags. These are registered for both sending and receiving modes to ensure the proxy configuration is available regardless of which peer initiates the transfer. -
Dialer Construction – The
src/comm/comm.gomodule (lines 45‑78) handles protocol-specific dialer creation:- SOCKS5: Uses
golang.org/x/net/proxyto parse the proxy URL and instantiate aproxy.Dialer. - HTTP: Uses the third-party
github.com/magisterquis/connectproxypackage to build a CONNECT-style tunnel dialer. - Errors during proxy parsing or connection establishment are wrapped and propagated to the user immediately.
- SOCKS5: Uses
-
Transport Integration – The constructed dialer is injected into
src/tcp/tcp.go, ensuring all subsequent network operations—including relay negotiation, PAKE authentication, and AES-encrypted data transfer—flow through the proxy tunnel.
Configuring SOCKS5 Proxies
To route traffic through a SOCKS5 proxy (such as Tor), pass the address with the --socks5 flag:
croc --socks5 "127.0.0.1:9050" send myphoto.jpg
You can also use the SOCKS5_PROXY environment variable to avoid repeating the flag:
export SOCKS5_PROXY="127.0.0.1:9050"
croc send secret.txt
Under the hood, croc passes the address to proxy.SOCKS5 from golang.org/x/net/proxy, creating a dialer that wraps the raw TCP connection before any cryptographic material is exchanged.
Configuring HTTP CONNECT Proxies
For environments requiring HTTP CONNECT tunnels, use the --connect flag:
croc --connect "http://proxy.example.com:3128" send archive.tar.gz
Alternatively, set the HTTP_PROXY environment variable:
export HTTP_PROXY="http://proxy.example.com:3128"
croc send report.pdf
In src/comm/comm.go, this invokes the connectproxy library to establish the CONNECT tunnel, after which croc upgrades the socket to its encrypted transport protocol.
Combining Proxies with Other croc Features
Proxy flags integrate seamlessly with additional options. For example, generate a QR code while tunneling through SOCKS5:
croc --socks5 "127.0.0.1:9050" --qr send project.zip
The proxy dialer is established first; then the QR code generation, relay communication, and encrypted transfer proceed entirely over the tunneled connection.
Summary
- croc supports both SOCKS5 and HTTP CONNECT proxies for transparent tunneling of encrypted file transfers.
- Use
--socks5for SOCKS5 proxies and--connectfor HTTP proxies, as defined insrc/cli/cli.go. - Environment variables
SOCKS5_PROXYandHTTP_PROXYprovide scriptable alternatives to CLI flags. - The proxy dialer is constructed in
src/comm/comm.gousinggolang.org/x/net/proxy(SOCKS5) orconnectproxy(HTTP), then applied insrc/tcp/tcp.gobefore the encryption layer initializes.
Frequently Asked Questions
Does croc support SOCKS4 or SOCKS4a proxies?
No. The implementation in src/comm/comm.go specifically utilizes golang.org/x/net/proxy for SOCKS5 only. Attempting to use a SOCKS4 address will result in a connection or parsing error.
Can I use environment variables instead of CLI flags for proxy configuration?
Yes. Set SOCKS5_PROXY or HTTP_PROXY in your shell environment. croc checks these variables when the corresponding CLI flags are omitted, allowing persistent proxy configuration without modifying command lines.
Does routing through a proxy affect croc's end-to-end encryption?
No. The proxy tunnel is established at the TCP layer in src/tcp/tcp.go before the PAKE-authenticated key exchange and AES encryption begins. All payload data remains end-to-end encrypted between the sender and receiver, unreadable by the proxy server.
How do I troubleshoot proxy connection failures in croc?
croc returns detailed error messages from src/comm/comm.go if the proxy URL is malformed or the proxy refuses the connection. Verify the address format (include http:// for HTTP proxies), ensure the target port is accessible, and confirm that any required authentication credentials are properly embedded in the URL according to your proxy server's specification.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →