Configure clients
Start with http://localhost:8317 on the host. For another device, use your LAN or tailnet address and follow Network and TLS. The client key is the 1Password field claude-api-key; it is different from the management password and from provider tokens.
Claude Code
Install Claude Code, connect a Claude account, and run:
bash
make claude URL=http://localhost:8317Pass CLI flags through ARGS:
bash
make claude URL=http://localhost:8317 ARGS='--model claude-haiku-4-5-20251001'The helper sets ANTHROPIC_BASE_URL, reads ANTHROPIC_AUTH_TOKEN through hara-key, and supplies the portless CA for Node-based clients. For the LAN address, omit URL after configuring portless.
make claude alias prints an optional claude-hara alias for your shell profile. For a direct setup in a terminal:
bash
export ANTHROPIC_BASE_URL='http://localhost:8317'
export ANTHROPIC_AUTH_TOKEN="$(./scripts/hara-key claude-api-key)"
claudeRun this from a normal terminal. A nested Claude desktop session can use its own authentication instead and receive a proxy 401.
Codex
The public codex/proxy.config.toml is a template. Install it through the helper so its key command uses your actual checkout path:
bash
make codex profile
make codexThe helper writes ~/.codex/proxy.config.toml (or the directory selected by CODEX_HOME) with owner-only permissions. It replaces the __HARA_KEY_COMMAND__ placeholder without copying your global configuration into this repository. This profile format requires a Codex release that supports profile files, command-based provider auth, and supports_websockets.
The profile uses http://localhost:8317/v1, the Responses API, and WebSockets. It reads the same client key from hara-key. Plain codex continues to use your normal configuration.
Prove the transport after connecting an appropriate account:
bash
make codex smokeA successful answer alone is insufficient: Codex can fall back to HTTP. The smoke helper fails if it sees Falling back from WebSockets to HTTPS transport.
For a different host, edit your installed private profile's base_url. A URL= Make override does not rewrite the Codex profile. Moving or deleting this checkout also requires reinstalling the profile so its auth command remains valid.
OpenAI-compatible clients
Configure these values in your client:
| Setting | Value on the host |
|---|---|
| Base URL | http://localhost:8317/v1 |
| API key | Your claude-api-key field |
| Model | A model returned by /v1/models |
List available models without printing the key:
bash
client_key="$(./scripts/hara-key claude-api-key)"
curl --fail-with-body http://localhost:8317/v1/models \
-H "Authorization: Bearer $client_key"
unset client_keyFor a chat client, substitute an available model in this example:
bash
client_key="$(./scripts/hara-key claude-api-key)"
curl --fail-with-body http://localhost:8317/v1/chat/completions \
-H "Authorization: Bearer $client_key" \
-H 'Content-Type: application/json' \
-d '{"model":"YOUR_AVAILABLE_MODEL","messages":[{"role":"user","content":"Reply with pong"}]}'
unset client_keyThis sends a real request and uses provider capacity. Keep shell tracing (set -x) off while using credentials. Desktop clients may need the key pasted into their own private settings; never copy those settings into the repo.