DurinDoor
Providers

Claude Code

Connect a Claude subscription account and check client compatibility, models, and quota.

Claude Code (claude, alias cc) uses a Claude.ai subscription through Anthropic's OAuth login, the same one the claude CLI uses. It is different from the anthropic provider, which takes a paid API key. To point the Claude Code CLI at DurinDoor as a client, see Claude Code integration.

The provider page shows a risk notice: this is a subscription session that was not licensed for router use, and Anthropic can restrict the account. Use an account you can afford to lose.

Connect

Open Providers, then Claude Code, then Connect.

Sign in at claude.ai and approve access. DurinDoor asks for org:create_api_key user:profile user:inference with a PKCE challenge.

Anthropic sends the authorization result to its code page (https://platform.claude.com/oauth/code/callback), not the dashboard. Copy the code shown there and paste it into the Claude Connect dialog, on local or hosted dashboards. DurinDoor binds pasted codes to the current login attempt; if you paste a full callback URL with a state, that state must match.

After the exchange DurinDoor reads your profile for the email and plan. Importing ~/.claude/.credentials.json is not supported; sign in through the dashboard.

Access tokens refresh four hours before expiry, both on request and in the background refresh pass. A refresh that fails with invalid_grant needs a new login.

Claude Code CLI version

DurinDoor does not check which Claude Code CLI you have installed. It does present itself to Anthropic as a specific Claude Code release. This build presents version 2.1.282 by default. It must stay at or above 2.1.280, the first release Anthropic accepts for Claude Opus 5.5. Requests to Anthropic carry:

  • User-Agent: claude-cli/2.1.282 (external, sdk-cli)
  • the beta flags, SDK and runtime headers from the captured Claude Code fingerprint
  • a billing header with cc_version=2.1.282

When Anthropic starts gating a model on a newer release before DurinDoor ships one, set CLAUDE_CODE_CLIENT_VERSION and restart:

export CLAUDE_CODE_CLIENT_VERSION="2.1.300"

The value is read once at startup and replaces the version in both the user agent and the billing header. Anything that is not a short header-safe token ([A-Za-z0-9][A-Za-z0-9._-]{0,31}) is ignored and the pin is used. See Environment variables.

There is one catch. When a real Claude Code client sends a request through DurinDoor, DurinDoor keeps that client's identity headers (user agent, SDK and runtime versions, session id) in memory and uses them for later cc/ requests in place of the pinned values. Beta flags from both sets are merged. That cache lasts until the process restarts and always holds the most recent client.

So an old claude CLI pointed at DurinDoor makes every cc/ request look like that old version, and Anthropic rejects Claude Opus 5.5 from releases older than 2.1.280. Keep the Claude Code CLI you route through DurinDoor at 2.1.280 or newer:

claude --version
npm install -g @anthropic-ai/claude-code@latest

If you updated the CLI and still see old-version behaviour, restart DurinDoor to clear the cached headers.

Betas passed through from the client

DurinDoor builds the outbound anthropic-beta header itself. Three flags from the incoming request are always added to it when the client sends them, because the body fields they unlock return 400 without them:

BetaNeeded for
thinking-binding-controls-2026-08-01thinking.block_binding on Fable 5.1 and Opus 5.5
thinking-display-updates-2026-08-18thinking.display on Fable 5.1 and Opus 5.5
dangerous-tool-use-2026-09-03the safeguards field Claude Code 2.1.278 and later sends

The same allowlist applies to Claude models on Anthropic-compatible nodes.

Request compatibility

The connection uses the Claude subscription Messages endpoint. DurinDoor adds Claude Code compatibility metadata and can rename tools upstream, then maps tool names back for the client. This is distinct from the API-key Anthropic provider.

Use a current Claude Code client when a model requires newer request headers. The gateway preserves required beta flags from compatible clients, but model entitlement still depends on the account.

Models

Send cc/<model>, for example cc/claude-sonnet-5. cc/claude-opus-5-5 (Claude Opus 5.5) is the default Opus model the Claude Code integration card writes. GET /v1/models shows the current set.

Quota

The Quota Tracker reads Anthropic's OAuth usage endpoint and shows:

  • session (5h), the rolling five-hour window
  • weekly (7d), the seven-day window
  • per-model weekly rows when Anthropic reports them

In the per-account view, if another Claude account on the current Quota Tracker page reports a model-specific weekly window (for example weekly fable (7d)), accounts that omit it show a muted row with — remaining and not reported for the reset. This row cannot be hidden: Anthropic did not report the window for that account, so it is not evidence of either available or exhausted quota. Placeholders are display-only and excluded from merged quota totals and routing.

The account refresh icon's Refresh (bypass cache) action requests GET /api/usage/<connectionId>?refresh=1. It bypasses the fresh quota cache, but still honors Anthropic's 429 cooldown. During that cooldown the tracker keeps the cached rows and their stale warning instead of polling Anthropic again. The existing ?force=1 API flag remains supported.

Preflight skips an account whose window is exhausted. Auto-ping can restart the five-hour window on a schedule; see Quota tracking.

After login, send a short request with a cc/ ID from your catalog and confirm Usage. If authentication fails, reconnect. If a model requires a newer CLI, update the client and restart DurinDoor. Test tool calls separately from basic text replies.

On this page

Edit on GitHub