Home › Claude Code › Errors › 401 / 403 auth
OverviewInstallCLI referencePricing & limitsAgent SDKSkills & pluginsGitHubWeb, desktop & IDEModelsErrorsOpen source?TutorialFor studentsQA automationvs Cursorvs Codex & OpenCodeSubagentsHooksMCPEcosystemVS CodeOpenRouterRate limits中文指南
Last updated: September 30, 2026

Claude Code 401 and 403: invalid authentication credentials, invalid API key, "Not logged in", host_not_allowed

401 means the credential Claude Code sent was not accepted; 403 means it was accepted but the request was not allowed. Almost every 401 report on the tracker comes down to *which* credential was sent, because Claude Code can hold three at once: an OAuth login, an ANTHROPIC_API_KEY in the environment, and an apiKeyHelper in settings. Start by finding out which one is active.

TLDR

  • /status shows the active auth method and endpoint. An API key in the environment always beats /login.
  • invalid x-api-key / Invalid API key · Fix external API key — the key does not belong to the endpoint in ANTHROPIC_BASE_URL.
  • 401 Invalid authentication credentials after /login — the OAuth token was revoked or refreshed badly; log out, clear the stored credential, log in again.
  • 403 — a proxy, sandbox egress rule or organization membership blocked the request; the credential is fine.

The messages

API Error: 401 {"type":"error","error":{"type":"authentication_error","message":"Invalid authentication credentials"}}
API Error: 401 invalid x-api-key
Invalid API key · Fix external API key
Not logged in · Please run /login
Login expired · Please run /login
API Error: 403 x-deny-reason: host_not_allowed
Error: Poll: Access denied (403): Account is no longer a member of the organization associated with this token.

Step 1: which credential is being sent?

claude
/status                       # auth method, endpoint, model
echo $ANTHROPIC_API_KEY | cut -c1-12
echo $ANTHROPIC_BASE_URL
grep -n apiKeyHelper ~/.claude/settings.json

Precedence is simple once you know it: an ANTHROPIC_API_KEY in the environment (or the value returned by apiKeyHelper) is used instead of the OAuth login. A stale key exported in .bashrc months ago, or a key from another gateway, is the classic cause of a 401 that survives every /login. Unset it, or set the right one.

401 with an API key: key and endpoint do not match

invalid x-api-key and Invalid API key · Fix external API key mean the endpoint did not recognise the key. A key belongs to exactly one endpoint: an Anthropic console key works only against api.anthropic.com; a gateway key works only against that gateway's ANTHROPIC_BASE_URL. Sending a console key to https://aiprimetech.io or a gateway key to Anthropic both return 401. Also check for a trailing newline or quote pasted into the variable, and that the key has not been revoked or rotated on the dashboard.

curl -s https://aiprimetech.io/v1/models -H "x-api-key: $ANTHROPIC_API_KEY" -H "anthropic-version: 2023-06-01" | head -c 300
# a JSON list = key accepted; authentication_error = wrong key for this host

401 after /login: the OAuth token

API Error: 401 Invalid authentication credentials right after a successful browser login is the most-reported shape (#69706, open, Windows, active Pro subscription; #44265, token reported expired immediately after login).

A commenter on the first thread found the stored refreshToken was an empty string in ~/.claude/.credentials.json, which makes every request 401 until the file is replaced by a fresh login. #54443 documents the server rejecting sessions before the locally stored expiry and the refresh call returning 400, so Please run /login comes back every few hours; running several Claude Code instances on one account makes it worse, because they race to refresh the same token. #44585: /login prints *Login successful* and reverts to *Not logged in* at once.

  • /logout, then delete the stored credential (~/.claude/.credentials.json on Linux and Windows; the *Claude Code-credentials* item in Keychain on macOS), then /login in a browser without the Claude in Chrome extension.
  • Close other Claude Code windows, the desktop app and IDE extensions before logging in; they refresh the same token. The OAuth error page covers *Failed to refresh OAuth token: another Claude Code process is refreshing it*.
  • claude update: #54235 traced a 401 to a specific version and a beta-flag environment variable; auth regressions get fixed quickly.
  • Headless or SSH machine: claude setup-token on a machine where the browser login works, then use the token there.
  • Working now beats debugging: with ANTHROPIC_API_KEY set, Claude Code never touches OAuth.

403: allowed to authenticate, not allowed to do that

  • `x-deny-reason: host_not_allowed` — a proxy in front of the request refuses the destination. Seen from the web/desktop sandbox egress allowlist (#93562, open: hosts outside a built-in list get 403 on CONNECT even with *All domains* selected) and from corporate proxies. Add the host to the allowlist, or run the CLI outside the sandbox.
  • Sandbox git proxy 403 on git push to an existing branch (#57356) — the sandbox's git proxy policy, not GitHub. Push from a normal terminal.
  • `Account is no longer a member of the organization associated with this token` — the token was issued for an organization you left or that changed; claude remote-control used to crash every session on it (#53563). Log out and back in to mint a token for the current organization.
  • 403 from a gateway — the key is valid but the account is disabled, out of balance for that model, or the model is not in your plan; the response body says which. Check the dashboard before changing anything client-side.
  • `/feedback` returning 403 (#55348) — a service-side outage of that one endpoint; it does not affect the model.

The API-key route

unset ANTHROPIC_API_KEY ANTHROPIC_BASE_URL   # back to the subscription login
# or: bypass OAuth entirely
export ANTHROPIC_BASE_URL=https://aiprimetech.io
export ANTHROPIC_API_KEY=your_gateway_key
claude

A gateway key is a plain API key: no OAuth, no token refresh, no organization membership, and the 401 family reduces to *does the key match the host*. If you are locked in a /login loop and need to ship today, that is the fastest exit; your first crypto top-up is doubled (+100%).

Tired of fighting this one?

Run Claude Code through the AI Prime Tech gateway instead: the same Claude models on the gateway's own upstream accounts, two environment variables to switch, and new accounts get $5 in free API credit with code FIXIT — no card.

export ANTHROPIC_BASE_URL=https://aiprimetech.io
export ANTHROPIC_API_KEY=your_key

Create an account with code FIXIT

Frequently asked questions

How do I fix 'API Error: 401 Invalid authentication credentials' in Claude Code?

Check /status for the active credential. Unset a stale ANTHROPIC_API_KEY, or /logout, delete ~/.claude/.credentials.json (Keychain on macOS) and /login again with other Claude Code instances closed. As a bypass, an API key skips OAuth entirely.

Why does Claude Code say invalid API key?

The key does not belong to the endpoint in ANTHROPIC_BASE_URL. A console key needs api.anthropic.com; a gateway key needs that gateway's URL. Also check for pasted whitespace and for a revoked key.

Why does Claude Code keep asking me to run /login?

The OAuth token is being rejected before its local expiry or the refresh fails, often because several Claude Code processes share one token. Close the others, log out, clear the stored credential, log in again, and update the CLI.

What does 403 x-deny-reason: host_not_allowed mean?

A proxy (the sandbox egress allowlist or a corporate proxy) refused the destination host. Your credentials are fine; allow the host or run outside the sandbox.

Run Claude Code on the gateway

Same models, two environment variables, credits at 7.69× face value — or a flat-rate unlimited plan. New accounts: $5 in free API credit with code FIXIT.

Get an API key See unlimited plans

AI Prime Tech is an independent API gateway and is not affiliated with, endorsed by, or sponsored by Anthropic. “Claude” and “Claude Code” are trademarks of Anthropic. Claude Code features described here follow Anthropic’s public documentation at the time of writing and change frequently; prices and model lists on this page are read from this gateway’s live settings.

More Claude Code guides

Claude Code errors and how to fix themClaude Code "API Error: 500": what it means and what actually fixes itClaude "Overloaded" error (API Error 529): what it means and what to doClaude Code API Error 400: prompt is too long, tool use concurrency, and the restClaude Code OAuth errors: timeout of 15000ms exceeded, and status code 500"Claude Code process exited with code 1": how to find the real error and fix itClaude "Prompt is too long", "input is too long for requested model" and "Context limit reached": what fills the window and how to get it backClaude usage limit reached: session, weekly and Opus limits, "specified API usage limits", "credit balance is too low" — and what to doClaude Code connection errors: ECONNRESET, connection lost mid-response, "Waiting for API response", "Unable to connect to API", SSL certificate errorsClaude Code hangs, gets stuck or stops responding: how to find out where it is stuck and get outClaude.ai not working: "Something went wrong", capacity constraints, "5-hour limit reached", "error logging you in" and the rest