> For the complete documentation index, see [llms.txt](https://sealights-docs.tricentis.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sealights-docs.tricentis.com/setup-and-configuration/guides/configure-a-proxy.md).

# Configure a proxy

Route the ABAP Agent's traffic through your corporate proxy — the connection to SeaLights and the connections to your test repositories.

Use this guide when the Windows host that runs the ABAP Agent reaches the internet or your test tools only through a proxy server. The agent has **two independent proxy settings**, because it talks to two kinds of systems:

* **SeaLights** — the `[proxy]` section of `config.toml` (or environment variables). Used by `slabapcli`, the watcher, and the **SeaLights ABAP Server** Windows service.
* **Test repositories** — the `[adapters]` section of `config.toml`. Used by the test repository connectors that call a web API.

Configuring one does not configure the other. Most proxy setups need both.

## Before you start

* The agent is installed and `config.toml` exists (see [Setup and installation](broken://pages/jvmOWRjO10SvuLg7G51U)).
* You know the proxy address (for example `http://proxy.example.com:8080`) and, if the proxy requires it, a user name and password.
* You can open a terminal as an Administrator in the agent's `bin` directory.

## Overview

| Connection                                                                        | Setting used                                                                                                     | Restart needed                                                                                                                                                                                      |
| --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `slabapcli` calls to SeaLights (for example `sealights set` and `sealights test`) | `[proxy]` or `SL_PROXY*` environment variables                                                                   | No. Applies the next time you run a command.                                                                                                                                                        |
| Watcher jobs (build modifications, footprints, and similar)                       | `[proxy]` or `SL_PROXY*` environment variables                                                                   | No server restart. Build Modifications use the new settings on their next run. Footprints runs continuously, so run `slabapcli footprints stop`, then `slabapcli footprints run` for each pipeline. |
| **SeaLights ABAP Server** service (SeaLights API calls and uploads)               | `[proxy]` or `SL_PROXY*` environment variables                                                                   | **Yes.** Run `slabapcli server stop`, then `slabapcli server start`.                                                                                                                                |
| Test repositories                                                                 | `[adapters]`, used by `tosca`, `toscacloud`, `ado`, `qtest`, and `ssm`. See [Part 2](#part-2-test-repositories). | No. Applies to the next connection test or search.                                                                                                                                                  |
| SAP RFC connections                                                               | None. RFC does not use an HTTP proxy. See [SAP RFC connections](#sap-rfc-connections).                           | Not applicable                                                                                                                                                                                      |

## Part 1: Connect to SeaLights through a proxy

The agent does **not** read the Windows system proxy settings for its SeaLights connection. It uses a proxy only if you configure one with the steps below.

{% stepper %}
{% step %}

### Save the proxy

Run `proxy set` with your proxy address. Add `--auth` if the proxy requires a user name and password. The CLI then prompts for them.

{% tabs %}
{% tab title="Command Prompt" %}
{% code title="Command" overflow="wrap" %}

```batch
slabapcli.exe proxy set --server "http://proxy.example.com:8080" --auth
```

{% endcode %}
{% endtab %}

{% tab title="PowerShell" %}
{% code title="Command" overflow="wrap" %}

```powershell
.\slabapcli.exe proxy set --server 'http://proxy.example.com:8080' --auth
```

{% endcode %}
{% endtab %}
{% endtabs %}

{% code title="Expected output (PowerShell)" overflow="wrap" lineNumbers="true" %}

```log
.\slabapcli.exe proxy set --server 'http://proxy.example.com:8080' --auth
[2026-04-21 09:20:11.514+01:00] [info] Detected Windows version: Windows 11
[2026-04-21 09:20:11.516+01:00] [info] Config pathname: C:\ProgramData\Tricentis\SeaLights\ABAP Agent\config\config.toml
Enter username: user1
Enter password: ********
Confirm password: ********
Password accepted (sha1 3b1f0c7a).
```

{% endcode %}

* `--server` (`-s`) is required. It must be an `http://` or `https://` address that includes a host name. Include the port.
* `--auth` (`-a`) prompts for the user name and password. The password is not displayed, and the `sha1` value is a short fingerprint you can use to confirm you typed the password you intended.
* The user name and password are stored encrypted when secret protection is on (see [Configuration settings](broken://pages/DZM4uWEu5r51kMDWCmDB)).
* Proxy credentials are used only when **both** a user name and a password are set. The CLI and the watcher support basic proxy authentication only.
* `proxy set` replaces the whole `[proxy]` section. If you run it again without `--auth`, the proxy is saved without credentials and any credentials stored earlier are discarded.

The command writes this section to `config.toml`:

```toml
[proxy]
server   = 'http://proxy.example.com:8080'
username = '<encrypted>'
password = '<encrypted>'
```

{% endstep %}

{% step %}

### Check the saved proxy

{% tabs %}
{% tab title="Command Prompt" %}
{% code title="Command" overflow="wrap" %}

```batch
slabapcli.exe proxy list
```

{% endcode %}
{% endtab %}

{% tab title="PowerShell" %}
{% code title="Command" overflow="wrap" %}

```powershell
.\slabapcli.exe proxy list
```

{% endcode %}
{% endtab %}
{% endtabs %}

{% code title="Expected output (PowerShell)" overflow="wrap" lineNumbers="true" %}

```log
Proxy configuration:
  Server: http://proxy.example.com:8080
  Authentication: enabled
    Username: user1
    Password: ****** (Encrypted)
```

{% endcode %}

If no proxy is saved, the output ends with `No proxy configured.` If the proxy has no credentials, it shows `Authentication: disabled`. When secret protection is not enabled, the stored password is shown in clear text.

{% hint style="info" %}
`proxy list` shows only the `[proxy]` section. If you also set `SL_PROXY*` environment variables, those take precedence (see [Optional: use environment variables](#optional-use-environment-variables)).
{% endhint %}
{% endstep %}

{% step %}

### Test the connection to SeaLights

{% tabs %}
{% tab title="Command Prompt" %}
{% code title="Command" overflow="wrap" %}

```batch
slabapcli.exe sealights test
```

{% endcode %}
{% endtab %}

{% tab title="PowerShell" %}
{% code title="Command" overflow="wrap" %}

```powershell
.\slabapcli.exe sealights test
```

{% endcode %}
{% endtab %}
{% endtabs %}

{% code title="Expected output (PowerShell)" overflow="wrap" lineNumbers="true" %}

```log
.\slabapcli.exe sealights test
[2026-04-21 09:21:54.009+01:00] [info] Detected Windows version: Windows 11
[2026-04-21 09:21:54.011+01:00] [info] Config pathname: C:\ProgramData\Tricentis\SeaLights\ABAP Agent\config\config.toml
[2026-04-21 09:21:54.013+01:00] [info] Test SeaLights: customer.sealights.co
Agent token is valid.
Sealights connectivity check succeeded.
```

{% endcode %}

This test runs in the CLI itself, so it already uses the new proxy. It does not prove that the **server** uses it: the server only reads the proxy when it starts.
{% endstep %}

{% step %}

### Restart the server

The **SeaLights ABAP Server** service reads the proxy settings only when it starts. There is no `server restart` command, so stop and start the service:

{% tabs %}
{% tab title="Command Prompt" %}
{% code title="Command" overflow="wrap" %}

```batch
slabapcli.exe server stop
slabapcli.exe server start
```

{% endcode %}
{% endtab %}

{% tab title="PowerShell" %}
{% code title="Command" overflow="wrap" %}

```powershell
.\slabapcli.exe server stop
.\slabapcli.exe server start
```

{% endcode %}
{% endtab %}
{% endtabs %}

Until you restart, the server keeps using the previous proxy settings. See [Live reload and restart-required fields](broken://pages/DZM4uWEu5r51kMDWCmDB#live-reload-and-restart-required-fields) and [Start the ABAP Agent Server](broken://pages/jjXJbDJ9CnFBYzl2NDMP).

{% hint style="warning" %}
If `[proxy].server` is not an absolute `http://` or `https://` address, the server does not start. Correct the value and start it again.
{% endhint %}
{% endstep %}
{% endstepper %}

### Optional: use environment variables

Instead of (or on top of) the `[proxy]` section, you can set environment variables. They take precedence over `[proxy]`.

| Variable            | Meaning                                                   |
| ------------------- | --------------------------------------------------------- |
| `SL_PROXY_SERVER`   | Proxy address. Checked first.                             |
| `SL_PROXY`          | Proxy address. Used only if `SL_PROXY_SERVER` is not set. |
| `SL_PROXY_USERNAME` | Proxy user name. Overrides `[proxy].username`.            |
| `SL_PROXY_PASSWORD` | Proxy password. Overrides `[proxy].password`.             |

* Always include `http://` or `https://` and the port in the address.
* The server reads the variables when it starts, and `slabapcli` and the watcher read them when they start. Set them as **system** (machine-level) variables so the Windows service and scheduled jobs see them, then restart the service and open a new terminal.

{% tabs %}
{% tab title="Command Prompt" %}
{% code title="Command" overflow="wrap" %}

```batch
setx /M SL_PROXY_SERVER "http://proxy.example.com:8080"
```

{% endcode %}
{% endtab %}

{% tab title="PowerShell" %}
{% code title="Command" overflow="wrap" %}

```powershell
[Environment]::SetEnvironmentVariable('SL_PROXY_SERVER', 'http://proxy.example.com:8080', 'Machine')
```

{% endcode %}
{% endtab %}
{% endtabs %}

{% hint style="warning" %}
Environment variables are stored in plain text. Prefer `slabapcli proxy set --auth` for credentials, which stores them encrypted when secret protection is on.
{% endhint %}

### Optional: allow a TLS-inspecting proxy

Some proxies decrypt and re-encrypt HTTPS traffic with their own certificate. If the agent then reports `SSL server verification failed`, the preferred fix is to install the proxy's root certificate in the Windows certificate store. As a workaround in a controlled environment, you can turn off certificate verification:

```toml
[http]
disableSslCheck = true
```

{% hint style="danger" %}
`disableSslCheck = true` turns off TLS certificate verification for **all** HTTPS calls made by `slabapcli`, the watcher, and the server, including the calls that carry your SeaLights token. Anyone who can intercept the connection can then impersonate SeaLights. Use it only on a trusted network, and remove it once the certificate is installed.
{% endhint %}

`[http].disableSslCheck` needs a server restart, like the proxy. It does not affect test repository connections (see Part 2 for those). For the full error and resolution, see [E-008](broken://pages/DTAUuyOmlKawT2B8UTYM#e-008-ssl-certificate-verification-failed).

### Change or remove the proxy

* **Change it:** run `slabapcli proxy set` again with the new address (and `--auth` if needed), then restart the server.
* **Remove it:** there is no `proxy` command that deletes the setting. Delete the whole `[proxy]` section from `config.toml`, remove any `SL_PROXY*` environment variables, and restart the server. Check the result with `slabapcli proxy list`, which then prints `No proxy configured.`

## Part 2: Test repositories

Test repository connectors do **not** use `[proxy]`. They read the `[adapters]` section of `config.toml`, which applies to **all** your test repositories.

| Test repository              | Uses the `[adapters]` proxy?                        | What it uses instead                                       |
| ---------------------------- | --------------------------------------------------- | ---------------------------------------------------------- |
| `tosca` (Tosca REST API)     | Yes                                                 |                                                            |
| `toscacloud` (Tosca Cloud)   | Yes, for the REST calls and for the sign-in request |                                                            |
| `ado` (Azure DevOps)         | Yes                                                 |                                                            |
| `qtest` (Tricentis qTest)    | Yes                                                 |                                                            |
| `ssm` (SAP Solution Manager) | Yes                                                 |                                                            |
| `excel`, `xray`              | Not needed                                          | These read a workbook file and make no web calls.          |
| `certify`                    | Not needed                                          | It connects directly to a database and makes no web calls. |
| `alm` (OpenText ALM)         | No                                                  | The agent has no proxy setting for ALM.                    |
| `octane` (OpenText Octane)   | No                                                  | The agent has no proxy setting for Octane.                 |
| `calm` (SAP Cloud ALM)       | No                                                  | The agent has no proxy setting for SAP Cloud ALM.          |

For the connectors in the last three rows, the agent does not apply a proxy of its own. Their traffic uses the default network behavior of the Windows host.

{% stepper %}
{% step %}

### Edit the `[adapters]` section

Open `config.toml` (by default `C:\ProgramData\Tricentis\SeaLights\ABAP Agent\config\config.toml`) as an Administrator. The default file already contains an `[adapters]` section with blank proxy values. Fill them in:

```toml
[adapters]
proxyAddress  = 'http://proxy.example.com:8080'  # leave blank for no explicit proxy
proxyUsername = '<proxy-user>'                    # optional
proxyPassword = '<proxy-password>'                # optional
proxyDomain   = 'CUSTOMER'                        # optional, domain for domain-joined proxies
```

| Key                              | Description                                                                                                                            |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| `proxyAddress`                   | Proxy address. If you leave it blank, the agent configures no proxy for the connector and the Windows host's default behavior applies. |
| `proxyUsername`, `proxyPassword` | Proxy credentials. Optional.                                                                                                           |
| `proxyDomain`                    | Domain for domain-joined proxies (NTLM). Optional. When set, it is sent with the user name and password.                               |

* `proxyAddress` is required when `proxyUsername`, `proxyPassword`, or `proxyDomain` is set. Otherwise the connector fails with `[adapters].proxyAddress is required when proxyUsername, proxyPassword, or proxyDomain is set.`
* For `toscacloud`, the sign-in request goes directly to the identity provider when `proxyAddress` is blank. Set `proxyAddress` whenever sign-in must also pass through the proxy.
* The `[adapters]` section also holds other settings, such as `restClientTimeoutSeconds`. See [Configuration settings](broken://pages/DZM4uWEu5r51kMDWCmDB).
  {% endstep %}

{% step %}

### Handle the credentials

`proxyUsername`, `proxyPassword`, and `proxyDomain` are secret fields, like the credentials of a test repository.

* **Secret protection off** (`key` and `iv` in `[settings]` are empty): type the values in plain text, as in the example above.
* **Secret protection on:** the agent reads these three fields as encrypted values. A plain text value makes the connection test fail. `proxyAddress` is never encrypted, so a proxy that needs no credentials works the same way in both modes.

{% hint style="warning" %}
No `slabapcli` command sets the `[adapters]` proxy credentials. If secret protection is on and your proxy requires credentials for test repositories, contact SeaLights support before you edit the file.
{% endhint %}
{% endstep %}

{% step %}

### No restart needed

The agent reads `[adapters]` each time it connects to a test repository, so the new values apply to the next connection test or search. You do not restart the server for `[adapters]` changes. A search that is already running finishes with the previous values.
{% endstep %}

{% step %}

### Test the test repository connection

Use the pipeline and test repository names from your `config.toml`.

{% tabs %}
{% tab title="Command Prompt" %}
{% code title="Command" overflow="wrap" %}

```batch
slabapcli.exe testrepo test --pipeline "<pipeline>" --testrepo "<name>"
```

{% endcode %}
{% endtab %}

{% tab title="PowerShell" %}
{% code title="Command" overflow="wrap" %}

```powershell
.\slabapcli.exe testrepo test --pipeline '<pipeline>' --testrepo '<name>'
```

{% endcode %}
{% endtab %}
{% endtabs %}

{% code title="Expected output (PowerShell)" overflow="wrap" lineNumbers="true" %}

```log
.\slabapcli.exe testrepo test --pipeline 'ALM_Demo-S21' --testrepo 'ALM_Demo-qtest'
[2026-03-08 10:47:12.454+02:00] [info] Detected Windows version: Windows 11
[2026-03-08 10:47:12.456+02:00] [info] Config pathname: C:\ProgramData\Tricentis\SeaLights\ABAP Agent\config\config.toml
Connection test passed for 'ALM_Demo-qtest' (pipeline: 'ALM_Demo-S21').
```

{% endcode %}

The server must be running for this command. See [Configure test repositories](broken://pages/RZTKL0g90WmKm4Prs0gG#slabapcli-testrepo-test) for all options and error messages.
{% endstep %}
{% endstepper %}

### Optional: allow a TLS-inspecting proxy for a test repository

`[http].disableSslCheck` does not apply to test repositories. Two connectors have their own switch, in their own `config.toml` section:

```toml
[adapters.toscacloud]
ignoreCertificateErrors = true   # Tosca Cloud REST and sign-in calls

[adapters.ssm]
ignoreCertificateErrors = true   # SAP Solution Manager REST calls
```

The default is `false` for both.

{% hint style="danger" %}
When `ignoreCertificateErrors` is `true`, the connector accepts **any** TLS certificate, so anyone who can intercept the connection can impersonate the test tool and read the credentials you send. Use it only on a trusted network. The preferred fix is to install the proxy's root certificate in the Windows certificate store.
{% endhint %}

## SAP RFC connections

Connections to your SAP systems use SAP RFC, not HTTP, so neither `[proxy]` nor `[adapters]` applies to them. If your network requires a SAProuter between the agent and SAP, add a `router` value, in SAProuter string format, to the RFC Destination's `[[rfc]]` entry in `config.toml` (for example `router = '/H/sap_router_host/S/3299/H/target_host/S/3200'`). `rfc set` has no option for it, but keeps an existing value. See [Create, test, and list RFC Destinations](broken://pages/zPfkH57Cxw3SCdFvArqI) and the `[[rfc]]` section of [Configuration settings](broken://pages/DZM4uWEu5r51kMDWCmDB).

## Troubleshooting

| Symptom                                                                                                                               | What to check                                                                                                                                                                                                                                                                                           |
| ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `sealights test` fails with a connection error or timeout                                                                             | Run `slabapcli proxy list` and check the address, scheme (`http` or `https`), and port. Check whether `SL_PROXY_SERVER` or `SL_PROXY` is set on the host: environment variables override `[proxy]`. If the proxy needs credentials, run `proxy set` again with `--auth`.                                |
| `sealights test` succeeds, but server uploads fail                                                                                    | The server reads `[proxy]` and `SL_PROXY*` only at startup. Run `slabapcli server stop`, then `slabapcli server start`.                                                                                                                                                                                 |
| `SSL server verification failed`                                                                                                      | A TLS-inspecting proxy is replacing the certificate. Install its root certificate in the Windows certificate store, or see [Optional: allow a TLS-inspecting proxy](#optional-allow-a-tls-inspecting-proxy) and [E-008](broken://pages/DTAUuyOmlKawT2B8UTYM#e-008-ssl-certificate-verification-failed). |
| The server does not start after you edit `[proxy]`                                                                                    | `[proxy].server` must be an absolute `http://` or `https://` address with a host name. Fix or remove the section, then start the server.                                                                                                                                                                |
| `testrepo test` fails, but `sealights test` succeeds                                                                                  | The two use different settings. Check `[adapters]` `proxyAddress`, and confirm that your test repository type is one that uses it (see the table in Part 2). Read the adapter log of the failed task. See [Troubleshooting the ABAP Agent](broken://pages/DTAUuyOmlKawT2B8UTYM).                        |
| `[adapters].proxyAddress is required when proxyUsername, proxyPassword, or proxyDomain is set.`                                       | You set proxy credentials or a domain but left `proxyAddress` blank. Set the address, or remove the credentials.                                                                                                                                                                                        |
| The test repository connection test fails after you added `[adapters]` proxy credentials on an installation with secret protection on | The agent expects encrypted values in these fields. See step 2 of [Part 2](#part-2-test-repositories), *Handle the credentials*.                                                                                                                                                                        |

## Related reading

* [Setup and installation](broken://pages/jvmOWRjO10SvuLg7G51U)
* [Set up the agent](broken://pages/54pGpo5ULmlonbluKqHL) — `sealights set`, `proxy set`, and `proxy list`
* [Configuration settings](broken://pages/DZM4uWEu5r51kMDWCmDB) — `[proxy]`, `[http]`, `[adapters]`, and live reload
* [Start the ABAP Agent Server](broken://pages/jjXJbDJ9CnFBYzl2NDMP)
* [Configure test repositories](broken://pages/RZTKL0g90WmKm4Prs0gG)
* [Test Tool Integrations](broken://pages/X3jEQR7gju1fIaT7v4vC)
* [Troubleshooting the ABAP Agent](broken://pages/DTAUuyOmlKawT2B8UTYM)
