Aider is a terminal pair-programmer that edits your repo by calling a model API—OpenAI, Anthropic, or a local gateway. On a restricted network it has to reach that API through Clash Verge, and because it runs inside a shell, it inherits none of the browser's proxy settings automatically. Timeouts are almost always one of two layers: the shell is not proxied, or the model provider dislikes the exit region. A browser that loads chatgpt.com proves nothing about Aider.
Pick the approach before touching config. Tun captures the whole machine and covers every shell; environment variables are per-shell but work on locked-down corporate machines. Overview: Tun & AI; siblings for other CLIs: Claude Code, Codex.
The one check before anything else
Confirm the egress path itself works before blaming Aider. Open Clash Verge, select a working node, and load a foreign site in the browser (latency test). If the browser cannot get out, no terminal tool will either—fix egress first, then come back here.
Prove Tun
Enable Tun, open a new terminal, run Aider, and watch the Connections view for the model API host. No hits at all means the capture layer is not engaging—check Tun start failed and firewall blocking. Hits that time out point at the node, not the config.
Env var fallback
If Tun is unavailable, export the proxy in the shell that launches Aider. Use the mixed port shown in the UI, not a number copied from an article (port conflicts):
export HTTPS_PROXY=http://127.0.0.1:7897
export HTTP_PROXY=http://127.0.0.1:7897
export NO_PROXY=127.0.0.1,localhost
The NO_PROXY line matters when Aider talks to a local model or a local gateway—without it, calls to your own machine get shoved at the proxy and look dead. Do not hardcode a port into your shell rc file; a port that changes on the next restart turns into a mystery failure weeks later.
Keys vs proxy
Read the Connections view to decide what is actually broken. No outbound hits at all → fix the proxy layer first (Tun off, or vars missing from this shell). Hits returning 401 or quota errors → credentials or plan, not the network. Region rejections → swap the exit node, covered in provider choice and latency testing.
Minimal repro
- Send one short chat message with the Connections view open.
- Timeout with no hits → node / Tun / vars.
- Region reject → swap node; do not reinstall Aider, the config is fine.
Two mistakes that waste an hour
- Exporting in one shell, running in another. Environment variables do not cross shell boundaries. The terminal where you typed
exportmust be the one that launches Aider. - An npm-installed Aider resolving as node. If you installed via npm, the requests may leave as the
nodeprocess. Process-name rules then catch every Node program on the machine; prefer Tun or a PROCESS-PATH rule pointing at the specific binary.
Back up the working config once it is stable: backup and migrate. Client builds: download center.