Claude Code · Certificates and network
Self-signed certificate detected (SELF_SIGNED_CERT_IN_CHAIN)
The certificate chain ends in a self-signed root Claude Code doesn’t trust: the signature of a proxy or a private certificate authority.
Message
The exact error
Unable to connect to API: Self-signed certificate detected (SELF_SIGNED_CERT_IN_CHAIN). The certificate comes from an authority Claude Code doesn't trust, usually a TLS-inspecting corporate proxy or a gateway signed by a private CA: set NODE_EXTRA_CA_CERTS to that CA bundle, or add it to the system certificate store · see https://code.claude.com/docs/en/network-configAlso appears as:
- During /login or the startup check
- SSL certificate error (SELF_SIGNED_CERT_IN_CHAIN). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
- Before v2.1.273
- Unable to connect to API: Self-signed certificate detected. Check your proxy or corporate SSL certificates
- Related code with the same message
- DEPTH_ZERO_SELF_SIGNED_CERT (the server’s own certificate is self-signed)
Meaning
What it means
Every certificate chain ends in a root that signs itself. Public roots are trusted because they ship with operating systems and Claude Code. When the root at the end of the chain isn’t one of those, Claude Code reports a self-signed certificate. In practice it means something between you and Anthropic presented its own certificate, typically a company proxy that inspects HTTPS, or a gateway using an internal certificate authority.
Causes
Common causes
- TLS inspection by a corporate proxy, antivirus web shield or firewall
- An internal LLM gateway (set with
ANTHROPIC_BASE_URL) using a certificate from a private CA - Antivirus “HTTPS scanning” on a personal computer, which installs its own root
Fix
How to fix it
Find out which certificate authority is intercepting
Open
https://api.anthropic.comin your browser and click the padlock, then view the certificate chain. If the top of the chain is your company’s or a security product’s root (names like Zscaler, Netskope, Palo Alto, Fortinet or your company name) rather than a public authority, a TLS-inspecting proxy is in the path. That root is the certificate Claude Code needs to trust. Your IT team can also give you the file directly.On a personal computer, check your antivirus
Products with HTTPS or web scanning add their own root certificate. Either export that root as below, or turn off HTTPS scanning for
*.anthropic.comin the antivirus settings.Export that root certificate as a PEM file
NODE_EXTRA_CA_CERTSneeds PEM text, the kind that starts with-----BEGIN CERTIFICATE-----. A binary.cer(DER) file doesn’t work, and Node gives no warning about it.Windows (PowerShell): export from the certificate store and convert to PEM $cert = Get-ChildItem Cert:\LocalMachine\Root | Where-Object Subject -like "*Your Proxy CA*" | Select-Object -First 1 New-Item -ItemType Directory -Force C:\certs | Out-Null Export-Certificate -Cert $cert -FilePath C:\certs\corp-ca.cer -Type CERT certutil -encode C:\certs\corp-ca.cer C:\certs\corp-ca.pemmacOS: export from the System keychain as PEM security find-certificate -a -c "Your Proxy CA" -p /Library/Keychains/System.keychain > ~/corp-ca.pemLinux: the system bundle already includes CAs your admin installed # Debian/Ubuntu ls /etc/ssl/certs/ca-certificates.crt # RHEL/Fedora ls /etc/pki/tls/certs/ca-bundle.crtPoint Claude Code at the file, then restart it
Claude Code reads these variables once at startup, so restart it after setting them. Putting the variable in the
envblock of~/.claude/settings.jsonmakes it apply to every session, including background agents that don’t inherit your shell.macOS / Linux export NODE_EXTRA_CA_CERTS=~/corp-ca.pem claudeWindows PowerShell $env:NODE_EXTRA_CA_CERTS = 'C:\certs\corp-ca.pem' claudeOr permanently, in ~/.claude/settings.json { "env": { "NODE_EXTRA_CA_CERTS": "/path/to/corp-ca.pem" } }Confirm the certificate loaded
Start a session with
claude --debugand look in the debug log (in~/.claude/debug/) forCA certs: Appended extra certificates from NODE_EXTRA_CA_CERTS. AFailed to readline means the path is wrong. In plain Node, a missing file showsWarning: Ignoring extra certs from …, load failedon the first secure connection.
Don’t do this
- Don’t set
NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.
Related