PacketStream integration

Using PacketStream residential proxies on macOS

Set PacketStream as the macOS system proxy so Safari and other Mac apps use a residential exit, then check the exit IP.

Use the macOS proxy settings when you want Safari and other Mac apps to use a residential exit without configuring each app. macOS can save your PacketStream username and password with the proxy.

If you only need one browser, the Chrome or Firefox guide is simpler and keeps your credentials encrypted on the way to PacketStream.

Before you start

Copy these values from the Proxy Access page in your dashboard:

FieldValue
Serverproxy.packetstream.io
Port31112
UsernameYour Proxy Username
PasswordYour Proxy Password (auth key), with optional suffixes

Leave Protocol on that page set to HTTP Proxy so it shows port 31112. Choosing a Location or Sticky IP adds the matching suffix to the Proxy Password for you.

Every app that follows the system proxy sends its traffic through PacketStream, including background sync and updates. All of it is billed at $1 per GB, so turn the proxy off when you finish.

Configure

These steps follow Apple’s documentation for macOS 27 and macOS Tahoe 26.

  1. Choose Apple menu > System Settings, then click Network in the sidebar.
  2. Select the network service you use, such as Wi-Fi, then click Details.
  3. Click Proxies.
  4. Turn on Web proxy (HTTP). Enter proxy.packetstream.io as the server and 31112 as the port. Turn on Proxy server requires password, then enter your username and password.
  5. Turn on Secure web proxy (HTTPS) and enter the same server, port, username, and password. Use port 31112 here too, not 31111.
  6. Leave SOCKS proxy off. Keep Exclude simple hostnames on.
  7. Click OK.

The settings apply only to the network service you edited. If you switch from Wi-Fi to Ethernet, repeat the steps for that service.

To stop using PacketStream, go back to Proxies, turn off both proxies, and click OK.

Verify your exit

Open ipinfo.io in Safari and check the IP and country.

If it shows your usual IP or an iCloud Private Relay address, the proxy isn’t being used. Check that you’re on the network service you configured and that your proxy settings were saved.

Country targeting and sticky sessions

Keep the username unchanged and add suffixes to the password. On macOS, change the password in both the HTTP and HTTPS entries.

GoalPassword
New exit per connectionAUTH_KEY
United States exitAUTH_KEY_country-US
Keep one exitAUTH_KEY_session-browser42
BothAUTH_KEY_country-US_session-browser42
  • Without a session, each new connection can get a different exit, and one page load opens several connections. Use a session for logins and other multi-step browsing.
  • Use only letters and digits in the session label. Everything from the first other character is dropped, so my-phone becomes my.
  • A session ends after 60 minutes without a new connection. It also fails if the Packeter providing the exit disconnects; choose a new label to continue.
  • To get a valid code, choose the country in the Location list on the Proxy Access page; the generated password then carries the right suffix. An unrecognized code is ignored and you can get an exit in any country, so check the country at ipinfo.io after you change it.
  • If no exit is available in a recognized country, requests fail instead of using another country.

See rotation and sticky sessions and country targeting for details.

Which apps use it

  • Safari and apps built on Apple’s networking frameworks should use the saved username and password.
  • Chrome and Edge ignore saved proxy credentials and show their own prompt. Enter the same username and password there.
  • Firefox follows the system proxy by default and is likely to prompt as well.
  • Command-line tools such as curl don’t read these settings. Use the cURL guide instead.

Why port 31112

PacketStream recommends its HTTPS endpoint on port 31111, which encrypts the connection to the gateway. macOS proxy settings can only describe a plain HTTP proxy: Secure web proxy (HTTPS) means the proxy used for https:// sites, not an encrypted proxy. Port 31111 expects an encrypted connection from the first byte, so a system setting pointed at it fails.

With port 31112:

  • https:// sites stay encrypted end to end.
  • Your username, auth key, and the hostnames you visit reach the gateway unencrypted, and so do plain http:// pages.
  • Use the setup only on networks you trust. If your auth key may have been exposed, select Reset Proxy Password on the Proxy Access page.

For browsing only, the Chrome and Firefox guides use port 31111 and keep that connection encrypted.

Limitations

  • The system proxy carries web traffic over TCP only. Traffic over UDP, such as browser video calls (WebRTC), may still connect directly. Don’t rely on this setup for anonymity.
  • Leave SOCKS off. PacketStream’s SOCKS5 endpoint requires a username and password, and Chrome and Edge don’t send them to a system SOCKS proxy, so those browsers fail.

Troubleshooting

  • The password prompt keeps coming back. Check the username and password for typos or extra spaces. If you changed a suffix, update both the HTTP and HTTPS entries.
  • Pages don’t load. Confirm both entries use port 31112. Port 31111 doesn’t work in system settings.
  • The exit doesn’t change after a refresh. Browsers reuse open connections, so a refresh can keep the same exit.

See proxy troubleshooting for authentication, targeting, and rotation checks.

Ready to use PacketStream on macOS? Create an account to get the proxy username and auth key used in the example above.
Create account