Skip to content
AI Dev Toolkit.
Esc
  • AI Token CounterCount tokens for GPT, Claude, Gemini, DeepSeek, Qwen and more.Tool
  • LLM API Cost CalculatorEstimate per-request, daily and monthly API costs.Tool
  • AI Model ComparisonCompare prices, context windows and features across models.Tool
  • AI Model Pricing PagesSpecs, real costs and cheaper alternatives for popular models.Tool
  • Context Window CheckerSee whether your text fits each model's context window.Tool
  • Subscription vs API CalculatorFind out whether a chat plan or the API is cheaper for you.Tool
  • GPU / VRAM CalculatorCheck how much VRAM a local model needs and which GPUs fit.Tool
  • Claude Code Error DatabaseExact Claude Code error messages with tested fixes.Tool

Claude Code · Certificates and network

SSL certificate verification failed (UNABLE_TO_GET_ISSUER_CERT_LOCALLY)

Claude Code can’t trace the API’s certificate to an authority it trusts, almost always because a corporate proxy re-signs HTTPS traffic.

Message

The exact error

Claude Code
Unable to connect to API: SSL certificate verification failed (UNABLE_TO_GET_ISSUER_CERT_LOCALLY). The certificate comes from an authority Claude Code doesn't trust, usually a TLS-inspecting corporate proxy or a gateway signed by a private CA: set NODE_EXTRA_CA_CERTS to that CA bundle, or add it to the system certificate store · see https://code.claude.com/docs/en/network-config

Also appears as:

During /login or the startup check
SSL certificate error (UNABLE_TO_GET_ISSUER_CERT_LOCALLY). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
Before v2.1.273
Unable to connect to API: SSL certificate verification failed. Check your proxy or corporate SSL certificates
Related codes with the same message
UNABLE_TO_VERIFY_LEAF_SIGNATURE, UNABLE_TO_GET_ISSUER_CERT

Meaning

What it means

When Claude Code connects to api.anthropic.com, it checks that the certificate it receives was issued by an authority it trusts. This error means the chain leads to an issuer it has never seen. On a work network that is usually a TLS-inspecting proxy or firewall: it decrypts HTTPS, then re-signs it with your company’s own root certificate, which Claude Code doesn’t know about. The connection is refused before any data is sent.

Causes

Common causes

  • A corporate proxy or security product (Zscaler, Netskope, Palo Alto, Fortinet and similar) inspecting HTTPS traffic
  • An LLM gateway or internal relay signed by a private certificate authority
  • The company root is installed on your computer, but Claude Code is reading only its bundled certificates (an older Node for npm installs, or CLAUDE_CODE_CERT_STORE=bundled)

Fix

How to fix it

  1. Find out which certificate authority is intercepting

    Open https://api.anthropic.com in your browser and click the padlock, then view the certificate chain. If the top of the chain is your company’s or a security product’s root (names like Zscaler, Netskope, Palo Alto, Fortinet or your company name) rather than a public authority, a TLS-inspecting proxy is in the path. That root is the certificate Claude Code needs to trust. Your IT team can also give you the file directly.

  2. If your company root is already installed, check Claude Code can read the system store

    By default Claude Code trusts its bundled certificates and your operating system’s store, so a proxy root installed by IT normally just works. That needs the native installer, or Node 22.15 or later for npm installs; older Node versions only see the bundled set and NODE_EXTRA_CA_CERTS. Also check that CLAUDE_CODE_CERT_STORE isn’t set to bundled, which turns the system store off.

  3. Export that root certificate as a PEM file

    NODE_EXTRA_CA_CERTS needs PEM text, the kind that starts with -----BEGIN CERTIFICATE-----. A binary .cer (DER) file doesn’t work, and Node gives no warning about it.

    Windows (PowerShell): export from the certificate store and convert to PEM
    $cert = Get-ChildItem Cert:\LocalMachine\Root | Where-Object Subject -like "*Your Proxy CA*" | Select-Object -First 1
    New-Item -ItemType Directory -Force C:\certs | Out-Null
    Export-Certificate -Cert $cert -FilePath C:\certs\corp-ca.cer -Type CERT
    certutil -encode C:\certs\corp-ca.cer C:\certs\corp-ca.pem
    macOS: export from the System keychain as PEM
    security find-certificate -a -c "Your Proxy CA" -p /Library/Keychains/System.keychain > ~/corp-ca.pem
    Linux: the system bundle already includes CAs your admin installed
    # Debian/Ubuntu
    ls /etc/ssl/certs/ca-certificates.crt
    # RHEL/Fedora
    ls /etc/pki/tls/certs/ca-bundle.crt
  4. Point Claude Code at the file, then restart it

    Claude Code reads these variables once at startup, so restart it after setting them. Putting the variable in the env block of ~/.claude/settings.json makes it apply to every session, including background agents that don’t inherit your shell.

    macOS / Linux
    export NODE_EXTRA_CA_CERTS=~/corp-ca.pem
    claude
    Windows PowerShell
    $env:NODE_EXTRA_CA_CERTS = 'C:\certs\corp-ca.pem'
    claude
    Or permanently, in ~/.claude/settings.json
    {
      "env": {
        "NODE_EXTRA_CA_CERTS": "/path/to/corp-ca.pem"
      }
    }
  5. Confirm the certificate loaded

    Start a session with claude --debug and look in the debug log (in ~/.claude/debug/) for CA certs: Appended extra certificates from NODE_EXTRA_CA_CERTS. A Failed to read line means the path is wrong. In plain Node, a missing file shows Warning: Ignoring extra certs from …, load failed on the first secure connection.

Don’t do this

  • Don’t set NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.

Related

Search all Claude Code errors