Skip to content
AI Dev Toolkit.
Esc
  • AI Token CounterCount tokens for GPT, Claude, Gemini, DeepSeek, Qwen and more.Tool
  • LLM API Cost CalculatorEstimate per-request, daily and monthly API costs.Tool
  • AI Model ComparisonCompare prices, context windows and features across models.Tool
  • AI Model Pricing PagesSpecs, real costs and cheaper alternatives for popular models.Tool
  • Context Window CheckerSee whether your text fits each model's context window.Tool
  • Subscription vs API CalculatorFind out whether a chat plan or the API is cheaper for you.Tool
  • GPU / VRAM CalculatorCheck how much VRAM a local model needs and which GPUs fit.Tool
  • Claude Code Error DatabaseExact Claude Code error messages with tested fixes.Tool

Claude Code · Certificates and network

curl: (60) SSL certificate problem: unable to get local issuer certificate

The Claude Code installer’s download failed certificate checks, usually because of a TLS-inspecting proxy.

Message

The exact error

Claude Code
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.

Meaning

What it means

This one comes from curl, not Claude Code: the install command downloads the installer over HTTPS, and curl couldn’t verify the server’s certificate. It’s the same root cause as the in-app certificate errors (a proxy re-signing traffic with a root curl doesn’t trust) but it happens before Claude Code is even installed, so the fix is for curl.

Causes

Common causes

  • A corporate proxy inspecting HTTPS with a root curl doesn’t trust
  • An outdated certificate bundle on the machine

Fix

How to fix it

  1. Give curl your company’s root certificate

    Export the proxy root as a PEM file (see the steps on the UNABLE_TO_GET_ISSUER_CERT_LOCALLY page), then:

    macOS / Linux
    curl --cacert /path/to/corp-ca.pem -fsSL https://claude.ai/install.sh | bash
  2. On Windows, use an installer that reads the Windows store

    The PowerShell installer downloads through .NET, which uses the Windows certificate store, so a company root that IT installed is trusted automatically. WinGet avoids curl entirely.

    PowerShell
    irm https://claude.ai/install.ps1 | iex
    Or WinGet
    winget install Anthropic.ClaudeCode
  3. Then set up Claude Code itself

    After installing, Claude Code makes its own HTTPS connections. If you had to give curl a certificate, give Claude Code the same one with NODE_EXTRA_CA_CERTS before your first run.

  4. Update the certificate bundle

    Debian / Ubuntu
    sudo apt-get update && sudo apt-get install ca-certificates

Don’t do this

  • Don’t add -k or --insecure to the install command. You would be running a script downloaded without checking it came from Anthropic.

Related

Search all Claude Code errors