Skip to content
AI Dev Toolkit.
Esc
  • AI Token CounterCount tokens for GPT, Claude, Gemini, DeepSeek, Qwen and more.Tool
  • LLM API Cost CalculatorEstimate per-request, daily and monthly API costs.Tool
  • AI Model ComparisonCompare prices, context windows and features across models.Tool
  • AI Model Pricing PagesSpecs, real costs and cheaper alternatives for popular models.Tool
  • Context Window CheckerSee whether your text fits each model's context window.Tool
  • Subscription vs API CalculatorFind out whether a chat plan or the API is cheaper for you.Tool
  • GPU / VRAM CalculatorCheck how much VRAM a local model needs and which GPUs fit.Tool
  • Claude Code Error DatabaseExact Claude Code error messages with tested fixes.Tool

Claude Code · Certificates and network

Self-signed certificate detected (SELF_SIGNED_CERT_IN_CHAIN)

The certificate chain ends in a self-signed root Claude Code doesn’t trust: the signature of a proxy or a private certificate authority.

Message

The exact error

Claude Code
Unable to connect to API: Self-signed certificate detected (SELF_SIGNED_CERT_IN_CHAIN). The certificate comes from an authority Claude Code doesn't trust, usually a TLS-inspecting corporate proxy or a gateway signed by a private CA: set NODE_EXTRA_CA_CERTS to that CA bundle, or add it to the system certificate store · see https://code.claude.com/docs/en/network-config

Also appears as:

During /login or the startup check
SSL certificate error (SELF_SIGNED_CERT_IN_CHAIN). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
Before v2.1.273
Unable to connect to API: Self-signed certificate detected. Check your proxy or corporate SSL certificates
Related code with the same message
DEPTH_ZERO_SELF_SIGNED_CERT (the server’s own certificate is self-signed)

Meaning

What it means

Every certificate chain ends in a root that signs itself. Public roots are trusted because they ship with operating systems and Claude Code. When the root at the end of the chain isn’t one of those, Claude Code reports a self-signed certificate. In practice it means something between you and Anthropic presented its own certificate, typically a company proxy that inspects HTTPS, or a gateway using an internal certificate authority.

Causes

Common causes

  • TLS inspection by a corporate proxy, antivirus web shield or firewall
  • An internal LLM gateway (set with ANTHROPIC_BASE_URL) using a certificate from a private CA
  • Antivirus “HTTPS scanning” on a personal computer, which installs its own root

Fix

How to fix it

  1. Find out which certificate authority is intercepting

    Open https://api.anthropic.com in your browser and click the padlock, then view the certificate chain. If the top of the chain is your company’s or a security product’s root (names like Zscaler, Netskope, Palo Alto, Fortinet or your company name) rather than a public authority, a TLS-inspecting proxy is in the path. That root is the certificate Claude Code needs to trust. Your IT team can also give you the file directly.

  2. On a personal computer, check your antivirus

    Products with HTTPS or web scanning add their own root certificate. Either export that root as below, or turn off HTTPS scanning for *.anthropic.com in the antivirus settings.

  3. Export that root certificate as a PEM file

    NODE_EXTRA_CA_CERTS needs PEM text, the kind that starts with -----BEGIN CERTIFICATE-----. A binary .cer (DER) file doesn’t work, and Node gives no warning about it.

    Windows (PowerShell): export from the certificate store and convert to PEM
    $cert = Get-ChildItem Cert:\LocalMachine\Root | Where-Object Subject -like "*Your Proxy CA*" | Select-Object -First 1
    New-Item -ItemType Directory -Force C:\certs | Out-Null
    Export-Certificate -Cert $cert -FilePath C:\certs\corp-ca.cer -Type CERT
    certutil -encode C:\certs\corp-ca.cer C:\certs\corp-ca.pem
    macOS: export from the System keychain as PEM
    security find-certificate -a -c "Your Proxy CA" -p /Library/Keychains/System.keychain > ~/corp-ca.pem
    Linux: the system bundle already includes CAs your admin installed
    # Debian/Ubuntu
    ls /etc/ssl/certs/ca-certificates.crt
    # RHEL/Fedora
    ls /etc/pki/tls/certs/ca-bundle.crt
  4. Point Claude Code at the file, then restart it

    Claude Code reads these variables once at startup, so restart it after setting them. Putting the variable in the env block of ~/.claude/settings.json makes it apply to every session, including background agents that don’t inherit your shell.

    macOS / Linux
    export NODE_EXTRA_CA_CERTS=~/corp-ca.pem
    claude
    Windows PowerShell
    $env:NODE_EXTRA_CA_CERTS = 'C:\certs\corp-ca.pem'
    claude
    Or permanently, in ~/.claude/settings.json
    {
      "env": {
        "NODE_EXTRA_CA_CERTS": "/path/to/corp-ca.pem"
      }
    }
  5. Confirm the certificate loaded

    Start a session with claude --debug and look in the debug log (in ~/.claude/debug/) for CA certs: Appended extra certificates from NODE_EXTRA_CA_CERTS. A Failed to read line means the path is wrong. In plain Node, a missing file shows Warning: Ignoring extra certs from …, load failed on the first secure connection.

Don’t do this

  • Don’t set NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.

Related

Search all Claude Code errors