PuppyIP Resource Center
Proxy Format Guides 12 min Published 2026-06-18 Updated 2026-10-06

Convert proxy fields to SOCKS5 URLs: a local format-conversion guide

To put a host, port, username and password into the address format your client accepts, use the browser-local converter without logging in. Confirm the node's actual protocol before choosing an output format. Successful conversion only proves the text was processed.

Proxy formats SOCKS5 Remote DNS HTTP CONNECT Local conversion Bulk CSV

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • PuppyIP's converter needs no login and processes input locally in your browser. You remain responsible for copied or downloaded plaintext.
  • The host:port:username:password format can become a SOCKS5 URL, but selecting that format does not add SOCKS5 support or verify credentials and connectivity.
  • UTF-8 TXT/CSV files are supported: at most 1 MiB per file, 100 records per batch and 8192 characters per record. Errors and duplicates count; excess records suspend the entire batch.
  • Check whether your client wants a full URI or separate host, port, user and pass fields.
  • socks5:// usually resolves domains locally; socks5h:// explicitly requests proxy-side resolution, where the client supports it.
  • HTTP CONNECT creates a tunnel to a destination. It neither automatically decrypts TLS nor proves UDP support.

Where to find the no-login local converter

Open https://puppyip.com/tools/proxy-converter. It organizes existing proxy details in the current browser, supports pasted text and local TXT/CSV import, and does not upload or save conversion inputs. Enable JavaScript, enter one record per line, choose the output format and click Convert format.

The page offers six text outputs: IP:port:username:password, username:password@IP:port, HTTP URL, SOCKS5 URL, IP:port and address only. HTTPS URLs are accepted as input but are not an output option. The converter does not accept socks5h:// input. The later socks5h explanation concerns clients explicitly supporting that syntax, not this converter.

Confirm the delivered node's actual protocols and ports before choosing a representation your client accepts. Rewriting HTTP details as a SOCKS5 URL changes text, not the node protocol. It verifies no password, exit or destination access. Check connectivity in your actual client afterward.

Step 1: understand the four fields

Delivery details usually include a host, port, username and password. The host is the connection address, the port is its entry point, and the username and password authenticate the connection.

Some clients want a complete address pasted once; others want four separate fields. They describe the same connection details but belong in different input locations.

Example: separated fields to a SOCKS5 URL

All examples here are fictional. The reserved addresses 192.0.2.10 and 2001:db8::10 and dummy credentials are not working proxies. For 192.0.2.10:1080:demo_user:demo_password, selecting SOCKS5 URL produces socks5://demo_user:[email protected]:1080. The input order is host, port, username, password; do not put the username in the host field.

A fictional IPv6 example with password symbols is [2001:db8::10]:1080:demo_user:p@ss#1, represented as socks5://demo_user:p%40ss%231@[2001:db8::10]:1080. Brackets separate the IPv6 host from its port; percent-encoding separates credentials from URI delimiters. This illustrates formats, not connectivity or SOCKS5 support at these addresses.

Use raw credentials in separated fields and CSV columns, and encode them once in a full URI. The converter parses URL encoding before producing the chosen output. Do not pre-encode a raw password and then enter it as separated-field input. For colons in usernames or whitespace at credential edges, use a correctly encoded URI or CSV with explicit column boundaries. Plain text trims the whole line, potentially losing trailing password spaces without an error; no error does not prove lossless credentials.

Step 2: choose the URI syntax the client supports

For a client explicitly requiring a URL, use socks5://user:pass@host:port. If it supports proxy-side destination DNS and you need that behavior, use socks5h://user:pass@host:port. The h is a client convention, not a separate proxy protocol.

For separate fields, do not paste the complete address into Host. Enter only the host there, only the port in Port, and raw credentials in their respective fields.

Full URIs, separate fields and environment variables

If a client requests a URI, use its supported scheme://username:password@host:port. If it requests separate fields, enter only the IP or domain in Host, a number in Port and each raw credential separately. Do not confuse the destination website with the proxy entry point.

Environment variables work only when the client reads them. In curl, https_proxy selects a proxy for HTTPS destinations, but its value may still be http://proxy.example:3128. http_proxy must be lowercase, whereas HTTPS_PROXY may be uppercase. Destinations matching NO_PROXY bypass the proxy. Also inspect the client's own proxy settings.

Special characters and IPv6 need clear boundaries

Encode credential characters such as @, # and % once as required by the client. The fictional password p@ss#1 becomes p%40ss%231 in a URI; separated password fields normally take raw p@ss#1 unless the client explicitly says otherwise. Do not encode the entire address or encode an already encoded value again.

IPv6 contains colons and needs brackets in a URI host, for example http://[2001:db8::10]:3128. All example domains, addresses and credentials are documentation values, not real connections. Both client and proxy must support the address type.

TXT/CSV import: limits, headers and row errors

Choose Import file and select UTF-8 TXT or CSV: at most 1 MiB, 100 records per batch and 8192 characters per record. Each nonempty TXT line is one record. Errors and duplicates count. More than 100 records suspends the entire batch; deduplicating 101 records does not make that batch acceptable. Split it first.

CSV may use a single proxy header containing one complete representation per row, or host, port, username, password and protocol columns. host and port are required; the others are optional, but authenticated records need both username and password. Column order may vary with correct headers. Unknown or duplicate columns fail. protocol may be blank or the source node's http, https or socks5; do not guess a protocol to bypass errors.

Fields containing commas or double quotes must follow CSV quoting rules; do not split a password at a comma. Credential spaces and symbols are preserved. CSV host columns provide a distinct boundary and accept bare IPv6, while full URIs or host-with-port text still need brackets. Ordinary parse errors identify the row; valid records in the same batch can continue. Check input, valid, duplicate, error and converted counts before copying. Reconvert after editing input or changing formats.

TXT exports valid results in the selected format; CSV exports fixed separated fields. If a CSV field could be interpreted as a spreadsheet formula, the tool blocks the whole CSV export and identifies its record and field. Use TXT or copy instead; do not alter real passwords to export. CSV protocol comes from the input record. The output dropdown is not evidence that the node's protocol changed.

Step 3: determine where DNS is resolved

RFC 1928 lets clients submit IPv4, domains or IPv6, with ATYP identifying the destination address type. Carrying a domain in the protocol does not mean every client defaults to proxy-side DNS.

In an authorized test environment, request the same domain with socks5:// and socks5h:// and record client versions and resolution errors. curl uses local and proxy-side resolution respectively. Proxy resolution for one request does not change every application on the computer. The linked pre-purchase acceptance guide has command examples; keep real credentials only in protected local configuration.

Step 4: understand HTTP CONNECT and SOCKS limits

RFC 9110 specifies that after a successful CONNECT 2xx response, the proxy enters blind bidirectional forwarding. It creates a TCP tunnel without automatically decrypting TLS inside it. The client must still validate the destination certificate.

SOCKS defines TCP CONNECT and UDP ASSOCIATE, but the client, proxy service and application must all support the required operation. Saving a URI does not prove UDP works, and protocol support is not the same as availability in your current plan.

Step 5: separate proxy authentication from destination responses

user and pass authenticate to the proxy. For HTTP proxy 407 responses, check authentication and credentials. Destination 401 or 403 responses occur at another layer and are not fixed by repeatedly editing the URI. See the layered connection troubleshooting guide in the sources.

A TLS certificate error is not necessarily a proxy password error. Confirm CONNECT or SOCKS handshaking first, then check the destination domain, system clock, certificate chain and client trust store.

Step 6: check and redact copied details

Check for extra spaces, line breaks, unintended punctuation or a missing password. For symbols in credentials, prefer the generated copy result rather than manually rewriting it.

Screenshots, tickets and team documents should retain the protocol, redacted host, port and error layer. Map delivery fields to the client's accepted inputs. PuppyIP users can use the page's Visit PuppyIP and Open tutorials links to confirm product and configuration instructions.

The local page retains neither input nor output after refresh, departure or clearing. Parsing and file reading upload nothing to the server. Its actual connect-src 'none' policy restricts script network connections. That boundary applies to this converter and does not mean other testing tools run locally.

You remain responsible for credentials copied to a clipboard, saved in TXT/CSV or shared as QR codes. Process only authorized connections; do not expose complete addresses or files. Share redacted fields and error layers with support. Enter the output in the actual client as it requires, then check the exit and necessary network paths.

Sources

Frequently Asked Questions

Where is a no-login browser-local converter?

Use https://puppyip.com/tools/proxy-converter for separated fields, HTTP/SOCKS5 URLs and TXT/CSV. It uploads and saves no conversion inputs. Selecting SOCKS5 changes the representation, not the node protocol, and proves no successful connection.

What if TXT/CSV input exceeds limits or has errors?

Check UTF-8 encoding, a maximum 1 MiB file, 100 records and 8192 characters per record. Errors and duplicates count; excessive records suspend the whole batch. Fix ordinary row errors and check valid output. Spreadsheet-formula risk blocks the entire CSV export; use TXT or copy without changing real passwords.

Can I send the complete address to a colleague?

Avoid casual forwarding. It may contain credentials. Share only with people who need authorized access and keep it out of public screenshots.

How do socks5 and socks5h differ?

socks5:// usually resolves domains locally; socks5h:// explicitly asks a supporting client to send domains to the proxy for resolution. Verify the behavior with actual client requests.

Does HTTP CONNECT decrypt HTTPS?

No. Once the tunnel is established, the proxy forwards bytes while TLS remains between the client and destination, unless a separate, explicit managed inspection mechanism exists.

Does a socks5 URI guarantee UDP?

No. UDP ASSOCIATE exists in the protocol, but client, proxy and application must implement and enable it. Confirm and test each before buying.

Why does the copied address still fail?

First check whether the full URI or separated fields are in the correct inputs. Then separate DNS, TCP, proxy authentication, tunnel and TLS failures. Repeated exit changes are not diagnosis.

Why is traffic direct despite HTTPS_PROXY?

Check whether the program reads that variable, overrides it with in-program settings, or matches NO_PROXY. The variable names its destination protocol; it does not automatically configure every application. Verify the actual client's exit.