When a vendor or a library says "HTTPS proxy", it usually means one of two different things.

Meaning one: a proxy for HTTPS sites

This is the common one. Your client connects to an ordinary HTTP proxy and asks it, with CONNECT, for a tunnel to an https:// site. TLS runs end to end between your client and the website, so the page is encrypted all the way. The proxy URL still starts with http://:

export HTTPS_PROXY=http://USERNAME:PASSWORD@HOST:PORT

The variable is named for the sites it applies to, not for the connection to the proxy. That naming is the root of most of the confusion.

Meaning two: a proxy you reach over TLS

Here the hop from your client to the proxy is itself encrypted, and the proxy URL starts with https://. It protects what crosses that hop in the clear: the Proxy-Authorization header with your credentials, and the hostnames in CONNECT lines. curl supports it, as do some other clients; many libraries do not, or need extra setup.

What to use on ProxyHive

For HTTPS sites through ProxyHive, use the HTTP port with an http:// proxy URL. Your traffic to the site is still encrypted end to end. If you worry about credentials crossing a network you do not trust, an IP allowlist keeps them off the wire altogether; the proxy authentication guide compares the two.

Common confusion

Neither meaning lets the proxy read your HTTPS pages. Only a proxy that you have told your client to trust as a certificate authority can do that, which is a man-in-the-middle setup and never something a proxy vendor should ask of you.