third-option
Signs Claude Code in to a Third Option gateway from anywhere, and keeps the session fresh.
Claude Code's own gateway login accepts only a gateway on a private network: every address the host resolves to must be RFC 1918, CGNAT or loopback, and no setting widens that. A gateway with a public address — a hosted one, or a company's reached without the VPN — has no interactive way in. This is that way in.
Install
cargo install third-option
npm install -g third-option
uv tool install third-option # or: pipx install third-option
Prebuilt for Linux x64 and arm64 (glibc) and Apple Silicon; cargo install
builds anywhere Rust does.
Use
third-option enroll https://gateway.example.com
That opens the gateway's sign-in page, waits for you to confirm the code it
printed, then writes Claude Code's settings.json ($CLAUDE_CONFIG_DIR,
else ~/.claude) so that:
env.ANTHROPIC_BASE_URLis the gateway and model discovery is on, so the model picker shows what the gateway serves;apiKeyHelperisthird-option token, which prints the session token and renews it through the gateway's refresh grant before it runs out;- whatever the gateway pushes from
/managed/settings— model, permissions, the telemetry exporter — is merged in, the operator's keys winning and lists such aspermissions.denyunioned; - when telemetry is pushed,
otelHeadersHelperisthird-option otel-headers, so exports to the gateway carry the session and land.
Nothing else in the file is touched. Run enroll again to pick up a changed
policy. third-option status shows the session, when it ends, and what Claude
Code points at; third-option models lists what this identity may use.
| Verb | Does |
|---|---|
enroll [url] |
sign in if needed, then point Claude Code at the gateway |
login <url> |
sign in only — for a scripted client that sets ANTHROPIC_BASE_URL itself |
token |
print a fresh session token (apiKeyHelper) |
otel-headers |
print {"Authorization": "Bearer …"} (otelHeadersHelper) |
status, models, logout [--all] |
--gateway <url> picks a gateway; otherwise $ANTHROPIC_BASE_URL — which
Claude Code sets from the env block when it runs a helper — then the last
login. --no-browser prints the link instead of opening it.
Where the session is kept
The session is a credential, so it lives in the OS secure store: the Keychain
on macOS, the Secret Service (GNOME Keyring, KWallet) on Linux, the Credential
Manager on Windows — service third-option, account the gateway's origin, so
it is the entry you see in Keychain Access or Seahorse. macOS asks once per
new build of the binary whether it may read its own entry; "Always Allow" is
the answer. credentials.json under $THIRD_OPTION_HOME, else
~/.config/third-option, only records which gateways have a session and which
was used last.
Where no secure store is reachable — a server with no session bus, a CI
runner — login keeps the session in that file instead, readable only by
you, and says so. THIRD_OPTION_STORAGE=file chooses the file outright;
THIRD_OPTION_STORAGE=keyring refuses the fallback. status shows where each
session is.
Two modes, one gateway
| Public — this CLI | Private network — Claude Code's own login | |
|---|---|---|
| Reaches the gateway over | any TLS route | private addresses only |
| Enrollment | third-option enroll |
/login, pinned by a machine policy file |
| Credential | apiKeyHelper |
the pinned gateway session |
| Managed settings | merged into your settings.json by enroll |
pushed live, not editable |
| Telemetry | signed by otelHeadersHelper |
signed by the session |
They are exclusive on one machine: the policy file that turns on Claude
Code's own gateway login (/etc/claude-code/managed-settings.json;
/Library/Application Support/ClaudeCode/ on macOS) makes it refuse every
helper credential. enroll and status say so when they see one. The
private-network mode is the stronger one, so a fleet on its own network
should use it; this CLI is for everyone else.
Scripted use
export ANTHROPIC_BASE_URL=https://gateway.example.com
export ANTHROPIC_AUTH_TOKEN="$(third-option token)"
token renews the session when it has under fifteen minutes left, so a
long-running script can call it again rather than cache the value.
License
MIT OR Apache-2.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl.
File metadata
- Download URL: third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl
- Upload date:
- Size: 3.1 MB
- Tags: Python 3, manylinux: glibc 2.28+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
de3f31f35efe601fc927f0ff8b680d40da922eff8fe314672465d1f012c3beec
|
|
| MD5 |
8d3e89ddaf174d3bfe316ef312930e57
|
|
| BLAKE2b-256 |
f0ffacfba6677d4ddf3620d1da178028df7ea7664bdd49d9571a7eb60c3b34e1
|
Provenance
The following attestation bundles were made for third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl:
Publisher:
release-third-option.yml on 3rd-option/monorepo
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl -
Subject digest:
de3f31f35efe601fc927f0ff8b680d40da922eff8fe314672465d1f012c3beec - Sigstore transparency entry: 2653185863
- Sigstore integration time:
-
Permalink:
3rd-option/monorepo@0ea0e48617c6381dfcbb9ab1d23927294229aba8 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/3rd-option
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-third-option.yml@0ea0e48617c6381dfcbb9ab1d23927294229aba8 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl.
File metadata
- Download URL: third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl
- Upload date:
- Size: 2.9 MB
- Tags: Python 3, manylinux: glibc 2.28+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7d8b54f83f58c0e1ffaa409e35552adef7445c1fee64ebcd3c885bcc53e502bb
|
|
| MD5 |
deae0798bd4947a4db736e89d5ff7b58
|
|
| BLAKE2b-256 |
9b8760b0750fb7c005ebd345dcbbc1b30fec70b5bd6e114a06861b36082e97cb
|
Provenance
The following attestation bundles were made for third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl:
Publisher:
release-third-option.yml on 3rd-option/monorepo
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl -
Subject digest:
7d8b54f83f58c0e1ffaa409e35552adef7445c1fee64ebcd3c885bcc53e502bb - Sigstore transparency entry: 2653186539
- Sigstore integration time:
-
Permalink:
3rd-option/monorepo@0ea0e48617c6381dfcbb9ab1d23927294229aba8 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/3rd-option
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-third-option.yml@0ea0e48617c6381dfcbb9ab1d23927294229aba8 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file third_option-0.2.0-py3-none-macosx_11_0_arm64.whl.
File metadata
- Download URL: third_option-0.2.0-py3-none-macosx_11_0_arm64.whl
- Upload date:
- Size: 1.8 MB
- Tags: Python 3, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
03985d06b520e1bfce08863de88f11b498309f5933daec1ab9e5ddc5dae91b20
|
|
| MD5 |
495711b2e74955a11f9cafb29649f491
|
|
| BLAKE2b-256 |
a468581ee43680afaa94d9416fd471b04f9f5531718a9d8347b0f363107e67e4
|
Provenance
The following attestation bundles were made for third_option-0.2.0-py3-none-macosx_11_0_arm64.whl:
Publisher:
release-third-option.yml on 3rd-option/monorepo
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
third_option-0.2.0-py3-none-macosx_11_0_arm64.whl -
Subject digest:
03985d06b520e1bfce08863de88f11b498309f5933daec1ab9e5ddc5dae91b20 - Sigstore transparency entry: 2653186142
- Sigstore integration time:
-
Permalink:
3rd-option/monorepo@0ea0e48617c6381dfcbb9ab1d23927294229aba8 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/3rd-option
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-third-option.yml@0ea0e48617c6381dfcbb9ab1d23927294229aba8 -
Trigger Event:
workflow_dispatch
-
Statement type: