Skip to content

Other LLM gateways

Using an LLM gateway your organisation already runs with Claude Code, what it buys you, the rollout sequence and how it affects subscriptions.

This section is for organisations that already run an LLM gateway or API gateway and want Claude Code to go through it, rather than adopting Claude apps gateway. If you are still deciding between the two, read the gateway overview first.

Which page you want depends on your role:

You areGo to
A developer whose company already has a gatewayConnect Claude Code to an LLM gateway
An admin rolling a gateway out to staffRoll out an LLM gateway
The person configuring the gateway product itselfGateway compatibility guide

Any gateway that exposes one of the supported API formats will work. Anthropic does not endorse, maintain or audit third-party gateways, and routing Claude Code to non-Claude models through a gateway is not supported. Install and run the gateway following the vendor's own documentation, then do the Claude Code side using the steps below.

Why put a gateway in the path

A gateway centralises five things:

  1. Credentials. The provider key lives only on the server. Developers carry a gateway credential instead.
  2. Usage attribution. You can see spend by person or team whichever provider served the request.
  3. Cost controls. Budgets and rate limits are enforced in one place.
  4. Audit logging. Every model request can be logged for compliance.
  5. Provider switching. You change the upstream in the gateway's configuration, not on every laptop.

The first four work whether the upstream is Anthropic's API or a cloud provider. The fifth only holds if the gateway exposes a single Anthropic-format endpoint regardless of what sits behind it. If instead it exposes Bedrock's or Vertex's native format, the client configuration is tied to that provider, and Claude Code changes what it sends and which defaults it applies accordingly.

The price is that the gateway becomes infrastructure you own. Claude Code adds capabilities every release, and a gateway that strips the new headers or fields quietly breaks the features that depend on them. Somebody needs to own upgrades. The compatibility guide lists what must be forwarded.

The rollout in four steps

Whatever product you use, the Claude Code side looks the same:

  1. Deploy the gateway and give it your provider credential so it can authenticate upstream calls.
  2. Issue each developer their own gateway credential. Usage is then attributed per person and offboarding revokes a single credential.
  3. Distribute the configuration with a managed settings file plus your secrets tooling, so each machine gets the base URL and a credential with no manual steps. Without settings distribution, developers set the variables themselves using the connect page.
  4. Have each developer confirm it worked by checking for the configuration inside Claude Code, so mistakes surface before anyone depends on it.

Roll out an LLM gateway goes through each step with the files to ship. The gateway is one part of a wider organisational setup; policy, visibility and data handling are covered in Set up Claude Code for your organisation.

Locking machines to the gateway

To make the gateway the only place a managed machine can send model traffic, put both of these in the same managed settings file:

{
  "allowedProviders": ["customEndpoint"],
  "env": {
    "ANTHROPIC_BASE_URL": "https://llm.internal.example.co.uk"
  }
}

Claude Code will then refuse to start a session aimed anywhere else, whether that is Anthropic directly or a developer's private proxy, and accepts ANTHROPIC_BASE_URL only with the value from that file. If the gateway is reached through a provider-specific variable such as ANTHROPIC_BEDROCK_BASE_URL, the allowedProviders entry names which variable to pin instead. This needs Claude Code v2.1.285 or later. See allowedProviders in the settings reference.

Subscriptions and gateways

While a gateway credential variable or an apiKeyHelper is active, every request carries that credential in place of the developer's claude.ai login. The subscription's usage limits do not apply, and Claude Code keeps the saved login on disk without sending it. The traffic is billed per token to whoever owns the credential the gateway forwards with: your Anthropic Console organisation, or your Bedrock, Google Cloud or Microsoft Foundry account if the gateway routes there.

Setting ANTHROPIC_BASE_URL on its own is different. Requests go through the gateway, but the saved claude.ai login stays the active credential, so subscription limits and billing apply as normal. For that to work, a gateway that passes the traffic to Anthropic must forward the OAuth capability in the anthropic-beta header; the request headers section of the compatibility guide has the details.