Skip to content
AI Dev Toolkit.
Esc
  • AI Token CounterCount tokens for GPT, Claude, Gemini, DeepSeek, Qwen and more.Tool
  • LLM API Cost CalculatorEstimate per-request, daily and monthly API costs.Tool
  • AI Model ComparisonCompare prices, context windows and features across models.Tool
  • AI Model Pricing PagesSpecs, real costs and cheaper alternatives for popular models.Tool
  • Context Window CheckerSee whether your text fits each model's context window.Tool
  • Subscription vs API CalculatorFind out whether a chat plan or the API is cheaper for you.Tool
  • GPU / VRAM CalculatorCheck how much VRAM a local model needs and which GPUs fit.Tool
  • Claude Code Error DatabaseExact Claude Code error messages with tested fixes.Tool

Claude Code · Certificates and network

SSL certificate hostname mismatch (ERR_TLS_CERT_ALTNAME_INVALID)

The certificate Claude Code received is for a different hostname than the one it asked for, so something is answering in Anthropic’s place.

Message

The exact error

Claude Code
Unable to connect to API: SSL certificate hostname mismatch

Also appears as:

During /login (OAuth error)
OAuth error: SSL certificate error (ERR_TLS_CERT_ALTNAME_INVALID). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
Related code with the same message
HOSTNAME_MISMATCH

Meaning

What it means

A certificate lists the hostnames it’s valid for. This error means the server that answered presented a certificate that doesn’t cover the name Claude Code connected to, such as api.anthropic.com or platform.claude.com. Trusting a different CA won’t fix it: the problem is that the wrong server, or a misconfigured proxy, is responding.

Causes

Common causes

  • Hotel, airport or café Wi-Fi with a sign-in page that intercepts HTTPS until you log in
  • A proxy or firewall that blocks the host and serves its own block page certificate
  • An entry in your hosts file or a DNS override pointing Anthropic’s hostnames elsewhere
  • ANTHROPIC_BASE_URL set to a gateway whose certificate doesn’t include the hostname you used

Fix

How to fix it

  1. Sign in to the network

    On public Wi-Fi, open any website in your browser and complete the sign-in page, then retry.

  2. Check where the hostname points

    Remove any hosts-file line for an Anthropic or Claude hostname that you didn’t add on purpose.

    macOS / Linux
    grep -i anthropic /etc/hosts
    nslookup api.anthropic.com
    Windows PowerShell
    Select-String -Path C:\Windows\System32\drivers\etc\hosts -Pattern anthropic
    nslookup api.anthropic.com
  3. Check for a gateway URL

    Run echo $ANTHROPIC_BASE_URL (or echo $env:ANTHROPIC_BASE_URL in PowerShell) and look for it in the env block of your settings files. If it points at a gateway, its certificate must include that gateway’s hostname; ask its operator to fix it.

  4. Ask IT to let Anthropic’s hosts through

    If a corporate proxy is answering, the error message’s own advice applies: ask IT to allowlist *.anthropic.com (and the other hosts Claude Code needs) rather than block or rewrite them.

Don’t do this

  • Don’t set NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.
  • Adding the proxy’s CA with NODE_EXTRA_CA_CERTS won’t help here: the certificate is for the wrong name, not from an unknown issuer.

Related

Search all Claude Code errors