Skip to content

Strip CLAUDE_CODE_OAUTH_TOKEN from gateway lane environments #32

Description

@thisguymartin

Problem

Gateway lanes (deepseek, minimax, and openrouter from #31) run the stock claude binary against a third-party endpoint. Before injecting the gateway's settings, childEnvironment in runner/run.ts removes every inherited ANTHROPIC_* variable plus the names in GATEWAY_INHERITED_CONFLICTS (runner/flex-providers.ts). Neither list contains CLAUDE_CODE_OAUTH_TOKEN.

If a parent shell exports CLAUDE_CODE_OAUTH_TOKEN (for example from claude setup-token), a gateway child inherits it. We have not verified which credential Claude Code sends when both ANTHROPIC_AUTH_TOKEN and CLAUDE_CODE_OAUTH_TOKEN are set. If the OAuth token wins or is sent alongside, a claude.ai subscription credential reaches a third-party endpoint. The runner's OAuth guard only checks .credentials.json in the lane's config dir, so it cannot catch a token that arrives through the environment.

Fix

  • Add CLAUDE_CODE_OAUTH_TOKEN to GATEWAY_INHERITED_CONFLICTS.
  • Extend the lists every alternative Claude provider selector test in flex-providers.test.ts and the env-dump test in run.test.ts to assert it never reaches a gateway child.
  • Check whether any other Claude Code credential variable can be inherited the same way, and strip those too.

Done when

  • No gateway child receives CLAUDE_CODE_OAUTH_TOKEN.
  • bash scripts/check.sh passes.
  • Live gate row D in Claude Code and Codex, run with CLAUDE_CODE_OAUTH_TOKEN exported in the parent shell, with evidence in the PR.

Found while planning OpenRouter support (#7, plan in docs/plans/2026-10-05-openrouter-gateway.md). It affects the existing DeepSeek and MiniMax lanes, so it is a separate change with its own gate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions