Expand description
What a session here would authenticate as, read from files rather than guessed from three environment variables.
pitboard decided whether a switch would mean anything by reading ANTHROPIC_API_KEY,
ANTHROPIC_AUTH_TOKEN and CLAUDE_CODE_OAUTH_TOKEN out of its own process
environment. Two holes followed. Claude Code resolves authentication from a layered
settings system, and any layer can set an env block, an apiKeyHelper, or one of the
third-party provider switches; under any of those a session ignores the login pitboard
moves, and pitboard reported a clean switch. And the app has no shell environment at
all: launched from Finder it saw none of the three, so the one surface that could not
warn was the one most likely to be used on a machine that needed the warning.
Files are the one thing an app launched from Finder and a shell agree about. Measured in
2.1.278: managed settings live in /Library/Application Support/ClaudeCode on macOS and
/etc/claude-code elsewhere, as managed-settings.json and a managed-settings.d
drop-in directory beside it; a person’s own are <config dir>/settings.json.
Project settings are deliberately not read. .claude/settings.json is a fact about one
directory, not about the machine, and an answer true in the directory pitboard happened
to be run from is worse than no answer at all.
Structs§
- Override
- One reason a session would not use the login pitboard moves.
Functions§
- custom_
oauth - Whether a custom OAuth endpoint is configured. Set, it renames both the keychain item and the config file Claude Code uses, so pitboard would be reading and writing the wrong ones: a refusal rather than a warning.
- overrides
- Every reason a session started here would authenticate as something other than the login pitboard moves. Empty means a switch changes what a session sees, which is the answer pitboard needs before it moves anything.