Skip to main content

Module settings

Module settings 

Source
Expand description

What a session here would authenticate as, read from files rather than guessed from three environment variables.

pitboard decided whether a switch would mean anything by reading ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN and CLAUDE_CODE_OAUTH_TOKEN out of its own process environment. Two holes followed. Claude Code resolves authentication from a layered settings system, and any layer can set an env block, an apiKeyHelper, or one of the third-party provider switches; under any of those a session ignores the login pitboard moves, and pitboard reported a clean switch. And the app has no shell environment at all: launched from Finder it saw none of the three, so the one surface that could not warn was the one most likely to be used on a machine that needed the warning.

Files are the one thing an app launched from Finder and a shell agree about. Measured in 2.1.278: managed settings live in /Library/Application Support/ClaudeCode on macOS and /etc/claude-code elsewhere, as managed-settings.json and a managed-settings.d drop-in directory beside it; a person’s own are <config dir>/settings.json.

Project settings are deliberately not read. .claude/settings.json is a fact about one directory, not about the machine, and an answer true in the directory pitboard happened to be run from is worse than no answer at all.

Structs§

Override
One reason a session would not use the login pitboard moves.

Functions§

custom_oauth
Whether a custom OAuth endpoint is configured. Set, it renames both the keychain item and the config file Claude Code uses, so pitboard would be reading and writing the wrong ones: a refusal rather than a warning.
overrides
Every reason a session started here would authenticate as something other than the login pitboard moves. Empty means a switch changes what a session sees, which is the answer pitboard needs before it moves anything.