Claude Code · Certificates and network
SSL certificate verification failed (UNABLE_TO_GET_ISSUER_CERT_LOCALLY)
Claude Code can’t trace the API’s certificate to an authority it trusts, almost always because a corporate proxy re-signs HTTPS traffic.
Message
The exact error
Unable to connect to API: SSL certificate verification failed (UNABLE_TO_GET_ISSUER_CERT_LOCALLY). The certificate comes from an authority Claude Code doesn't trust, usually a TLS-inspecting corporate proxy or a gateway signed by a private CA: set NODE_EXTRA_CA_CERTS to that CA bundle, or add it to the system certificate store · see https://code.claude.com/docs/en/network-configAlso appears as:
- During /login or the startup check
- SSL certificate error (UNABLE_TO_GET_ISSUER_CERT_LOCALLY). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
- Before v2.1.273
- Unable to connect to API: SSL certificate verification failed. Check your proxy or corporate SSL certificates
- Related codes with the same message
- UNABLE_TO_VERIFY_LEAF_SIGNATURE, UNABLE_TO_GET_ISSUER_CERT
Meaning
What it means
When Claude Code connects to api.anthropic.com, it checks that the certificate it receives was issued by an authority it trusts. This error means the chain leads to an issuer it has never seen. On a work network that is usually a TLS-inspecting proxy or firewall: it decrypts HTTPS, then re-signs it with your company’s own root certificate, which Claude Code doesn’t know about. The connection is refused before any data is sent.
Causes
Common causes
- A corporate proxy or security product (Zscaler, Netskope, Palo Alto, Fortinet and similar) inspecting HTTPS traffic
- An LLM gateway or internal relay signed by a private certificate authority
- The company root is installed on your computer, but Claude Code is reading only its bundled certificates (an older Node for npm installs, or
CLAUDE_CODE_CERT_STORE=bundled)
Fix
How to fix it
Find out which certificate authority is intercepting
Open
https://api.anthropic.comin your browser and click the padlock, then view the certificate chain. If the top of the chain is your company’s or a security product’s root (names like Zscaler, Netskope, Palo Alto, Fortinet or your company name) rather than a public authority, a TLS-inspecting proxy is in the path. That root is the certificate Claude Code needs to trust. Your IT team can also give you the file directly.If your company root is already installed, check Claude Code can read the system store
By default Claude Code trusts its bundled certificates and your operating system’s store, so a proxy root installed by IT normally just works. That needs the native installer, or Node 22.15 or later for npm installs; older Node versions only see the bundled set and
NODE_EXTRA_CA_CERTS. Also check thatCLAUDE_CODE_CERT_STOREisn’t set tobundled, which turns the system store off.Export that root certificate as a PEM file
NODE_EXTRA_CA_CERTSneeds PEM text, the kind that starts with-----BEGIN CERTIFICATE-----. A binary.cer(DER) file doesn’t work, and Node gives no warning about it.Windows (PowerShell): export from the certificate store and convert to PEM $cert = Get-ChildItem Cert:\LocalMachine\Root | Where-Object Subject -like "*Your Proxy CA*" | Select-Object -First 1 New-Item -ItemType Directory -Force C:\certs | Out-Null Export-Certificate -Cert $cert -FilePath C:\certs\corp-ca.cer -Type CERT certutil -encode C:\certs\corp-ca.cer C:\certs\corp-ca.pemmacOS: export from the System keychain as PEM security find-certificate -a -c "Your Proxy CA" -p /Library/Keychains/System.keychain > ~/corp-ca.pemLinux: the system bundle already includes CAs your admin installed # Debian/Ubuntu ls /etc/ssl/certs/ca-certificates.crt # RHEL/Fedora ls /etc/pki/tls/certs/ca-bundle.crtPoint Claude Code at the file, then restart it
Claude Code reads these variables once at startup, so restart it after setting them. Putting the variable in the
envblock of~/.claude/settings.jsonmakes it apply to every session, including background agents that don’t inherit your shell.macOS / Linux export NODE_EXTRA_CA_CERTS=~/corp-ca.pem claudeWindows PowerShell $env:NODE_EXTRA_CA_CERTS = 'C:\certs\corp-ca.pem' claudeOr permanently, in ~/.claude/settings.json { "env": { "NODE_EXTRA_CA_CERTS": "/path/to/corp-ca.pem" } }Confirm the certificate loaded
Start a session with
claude --debugand look in the debug log (in~/.claude/debug/) forCA certs: Appended extra certificates from NODE_EXTRA_CA_CERTS. AFailed to readline means the path is wrong. In plain Node, a missing file showsWarning: Ignoring extra certs from …, load failedon the first secure connection.
Don’t do this
- Don’t set
NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.
Related
Related errors
- Self-signed certificate detected (SELF_SIGNED_CERT_IN_CHAIN)Certificates and network
- curl: (60) SSL certificate problem: unable to get local issuer certificateCertificates and network
- SSL certificate has expired (CERT_HAS_EXPIRED)Certificates and network
- Unable to connect to APICertificates and network