Local proxy¶
All platforms. Both proxies listen on 127.0.0.1 only — never on the local network.
| Setting | Default · notes |
|---|---|
| SOCKS5 proxy | off — port 1080 |
| HTTP proxy | off — port 8080 |
| Username / password | empty — one credential pair shared by both proxies. Both fields must be set for authentication to apply; leave empty for no authentication. |
Ports are configurable and persist when the proxy is toggled off. Defaults sit outside the 10808–10810 range on purpose, because subscription configs commonly use those ports for internal chain hops — a collision would silently drop the inbound. On Apple platforms these proxies exist only while the tunnel is connected.