The messages
API Error: 401 {"type":"error","error":{"type":"authentication_error","message":"Invalid authentication credentials"}}
API Error: 401 invalid x-api-key
Invalid API key · Fix external API key
Not logged in · Please run /login
Login expired · Please run /login
API Error: 403 x-deny-reason: host_not_allowed
Error: Poll: Access denied (403): Account is no longer a member of the organization associated with this token.
Step 1: which credential is being sent?
claude
/status # auth method, endpoint, model
echo $ANTHROPIC_API_KEY | cut -c1-12
echo $ANTHROPIC_BASE_URL
grep -n apiKeyHelper ~/.claude/settings.json
Precedence is simple once you know it: an ANTHROPIC_API_KEY in the environment (or the value returned by apiKeyHelper) is used instead of the OAuth login. A stale key exported in .bashrc months ago, or a key from another gateway, is the classic cause of a 401 that survives every /login. Unset it, or set the right one.
401 with an API key: key and endpoint do not match
invalid x-api-key and Invalid API key · Fix external API key mean the endpoint did not recognise the key. A key belongs to exactly one endpoint: an Anthropic console key works only against api.anthropic.com; a gateway key works only against that gateway's ANTHROPIC_BASE_URL. Sending a console key to https://aiprimetech.io or a gateway key to Anthropic both return 401. Also check for a trailing newline or quote pasted into the variable, and that the key has not been revoked or rotated on the dashboard.
curl -s https://aiprimetech.io/v1/models -H "x-api-key: $ANTHROPIC_API_KEY" -H "anthropic-version: 2023-06-01" | head -c 300
# a JSON list = key accepted; authentication_error = wrong key for this host
401 after /login: the OAuth token
API Error: 401 Invalid authentication credentials right after a successful browser login is the most-reported shape (#69706, open, Windows, active Pro subscription; #44265, token reported expired immediately after login).
A commenter on the first thread found the stored refreshToken was an empty string in ~/.claude/.credentials.json, which makes every request 401 until the file is replaced by a fresh login. #54443 documents the server rejecting sessions before the locally stored expiry and the refresh call returning 400, so Please run /login comes back every few hours; running several Claude Code instances on one account makes it worse, because they race to refresh the same token. #44585: /login prints *Login successful* and reverts to *Not logged in* at once.
/logout, then delete the stored credential (~/.claude/.credentials.jsonon Linux and Windows; the *Claude Code-credentials* item in Keychain on macOS), then/loginin a browser without the Claude in Chrome extension.- Close other Claude Code windows, the desktop app and IDE extensions before logging in; they refresh the same token. The OAuth error page covers *Failed to refresh OAuth token: another Claude Code process is refreshing it*.
claude update: #54235 traced a 401 to a specific version and a beta-flag environment variable; auth regressions get fixed quickly.- Headless or SSH machine:
claude setup-tokenon a machine where the browser login works, then use the token there. - Working now beats debugging: with
ANTHROPIC_API_KEYset, Claude Code never touches OAuth.
403: allowed to authenticate, not allowed to do that
- `x-deny-reason: host_not_allowed` — a proxy in front of the request refuses the destination. Seen from the web/desktop sandbox egress allowlist (#93562, open: hosts outside a built-in list get 403 on CONNECT even with *All domains* selected) and from corporate proxies. Add the host to the allowlist, or run the CLI outside the sandbox.
- Sandbox git proxy 403 on
git pushto an existing branch (#57356) — the sandbox's git proxy policy, not GitHub. Push from a normal terminal. - `Account is no longer a member of the organization associated with this token` — the token was issued for an organization you left or that changed;
claude remote-controlused to crash every session on it (#53563). Log out and back in to mint a token for the current organization. - 403 from a gateway — the key is valid but the account is disabled, out of balance for that model, or the model is not in your plan; the response body says which. Check the dashboard before changing anything client-side.
- `/feedback` returning 403 (#55348) — a service-side outage of that one endpoint; it does not affect the model.
The API-key route
unset ANTHROPIC_API_KEY ANTHROPIC_BASE_URL # back to the subscription login
# or: bypass OAuth entirely
export ANTHROPIC_BASE_URL=https://aiprimetech.io
export ANTHROPIC_API_KEY=your_gateway_key
claude
A gateway key is a plain API key: no OAuth, no token refresh, no organization membership, and the 401 family reduces to *does the key match the host*. If you are locked in a /login loop and need to ship today, that is the fastest exit; your first crypto top-up is doubled (+100%).
Tired of fighting this one?
Run Claude Code through the AI Prime Tech gateway instead: the same Claude models on the gateway's own upstream accounts, two environment variables to switch, and new accounts get $5 in free API credit with code FIXIT — no card.
export ANTHROPIC_BASE_URL=https://aiprimetech.io
export ANTHROPIC_API_KEY=your_keyFrequently asked questions
How do I fix 'API Error: 401 Invalid authentication credentials' in Claude Code?
Check /status for the active credential. Unset a stale ANTHROPIC_API_KEY, or /logout, delete ~/.claude/.credentials.json (Keychain on macOS) and /login again with other Claude Code instances closed. As a bypass, an API key skips OAuth entirely.
Why does Claude Code say invalid API key?
The key does not belong to the endpoint in ANTHROPIC_BASE_URL. A console key needs api.anthropic.com; a gateway key needs that gateway's URL. Also check for pasted whitespace and for a revoked key.
Why does Claude Code keep asking me to run /login?
The OAuth token is being rejected before its local expiry or the refresh fails, often because several Claude Code processes share one token. Close the others, log out, clear the stored credential, log in again, and update the CLI.
What does 403 x-deny-reason: host_not_allowed mean?
A proxy (the sandbox egress allowlist or a corporate proxy) refused the destination host. Your credentials are fine; allow the host or run outside the sandbox.
Run Claude Code on the gateway
Same models, two environment variables, credits at 7.69× face value — or a flat-rate unlimited plan. New accounts: $5 in free API credit with code FIXIT.
Get an API key See unlimited plansAI Prime Tech is an independent API gateway and is not affiliated with, endorsed by, or sponsored by Anthropic. “Claude” and “Claude Code” are trademarks of Anthropic. Claude Code features described here follow Anthropic’s public documentation at the time of writing and change frequently; prices and model lists on this page are read from this gateway’s live settings.