Skip to main content

third-option

Signs Claude Code in to a Third Option gateway from anywhere, and keeps the session fresh.

Claude Code's own gateway login accepts only a gateway on a private network: every address the host resolves to must be RFC 1918, CGNAT or loopback, and no setting widens that. A gateway with a public address — a hosted one, or a company's reached without the VPN — has no interactive way in. This is that way in.

Install

cargo install third-option
npm install -g third-option
uv tool install third-option        # or: pipx install third-option

Prebuilt for Linux x64 and arm64 (glibc) and Apple Silicon; cargo install builds anywhere Rust does.

Use

third-option enroll https://gateway.example.com

That opens the gateway's sign-in page, waits for you to confirm the code it printed, then writes Claude Code's settings.json ($CLAUDE_CONFIG_DIR, else ~/.claude) so that:

  • env.ANTHROPIC_BASE_URL is the gateway and model discovery is on, so the model picker shows what the gateway serves;
  • apiKeyHelper is third-option token, which prints the session token and renews it through the gateway's refresh grant before it runs out;
  • whatever the gateway pushes from /managed/settings — model, permissions, the telemetry exporter — is merged in, the operator's keys winning and lists such as permissions.deny unioned;
  • when telemetry is pushed, otelHeadersHelper is third-option otel-headers, so exports to the gateway carry the session and land.

Nothing else in the file is touched. Run enroll again to pick up a changed policy. third-option status shows the session, when it ends, and what Claude Code points at; third-option models lists what this identity may use.

Verb Does
enroll [url] sign in if needed, then point Claude Code at the gateway
login <url> sign in only — for a scripted client that sets ANTHROPIC_BASE_URL itself
token print a fresh session token (apiKeyHelper)
otel-headers print {"Authorization": "Bearer …"} (otelHeadersHelper)
status, models, logout [--all]

--gateway <url> picks a gateway; otherwise $ANTHROPIC_BASE_URL — which Claude Code sets from the env block when it runs a helper — then the last login. --no-browser prints the link instead of opening it.

Where the session is kept

The session is a credential, so it lives in the OS secure store: the Keychain on macOS, the Secret Service (GNOME Keyring, KWallet) on Linux, the Credential Manager on Windows — service third-option, account the gateway's origin, so it is the entry you see in Keychain Access or Seahorse. macOS asks once per new build of the binary whether it may read its own entry; "Always Allow" is the answer. credentials.json under $THIRD_OPTION_HOME, else ~/.config/third-option, only records which gateways have a session and which was used last.

Where no secure store is reachable — a server with no session bus, a CI runner — login keeps the session in that file instead, readable only by you, and says so. THIRD_OPTION_STORAGE=file chooses the file outright; THIRD_OPTION_STORAGE=keyring refuses the fallback. status shows where each session is.

Two modes, one gateway

Public — this CLI Private network — Claude Code's own login
Reaches the gateway over any TLS route private addresses only
Enrollment third-option enroll /login, pinned by a machine policy file
Credential apiKeyHelper the pinned gateway session
Managed settings merged into your settings.json by enroll pushed live, not editable
Telemetry signed by otelHeadersHelper signed by the session

They are exclusive on one machine: the policy file that turns on Claude Code's own gateway login (/etc/claude-code/managed-settings.json; /Library/Application Support/ClaudeCode/ on macOS) makes it refuse every helper credential. enroll and status say so when they see one. The private-network mode is the stronger one, so a fleet on its own network should use it; this CLI is for everyone else.

Scripted use

export ANTHROPIC_BASE_URL=https://gateway.example.com
export ANTHROPIC_AUTH_TOKEN="$(third-option token)"

token renews the session when it has under fifteen minutes left, so a long-running script can call it again rather than cache the value.

License

MIT OR Apache-2.0.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl (3.1 MB view details)

Uploaded Python 3manylinux: glibc 2.28+ x86-64

third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl (2.9 MB view details)

Uploaded Python 3manylinux: glibc 2.28+ ARM64

third_option-0.2.0-py3-none-macosx_11_0_arm64.whl (1.8 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

File details

Details for the file third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 de3f31f35efe601fc927f0ff8b680d40da922eff8fe314672465d1f012c3beec
MD5 8d3e89ddaf174d3bfe316ef312930e57
BLAKE2b-256 f0ffacfba6677d4ddf3620d1da178028df7ea7664bdd49d9571a7eb60c3b34e1

See more details on using hashes here.

Provenance

The following attestation bundles were made for third_option-0.2.0-py3-none-manylinux_2_28_x86_64.whl:

Publisher: release-third-option.yml on 3rd-option/monorepo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 7d8b54f83f58c0e1ffaa409e35552adef7445c1fee64ebcd3c885bcc53e502bb
MD5 deae0798bd4947a4db736e89d5ff7b58
BLAKE2b-256 9b8760b0750fb7c005ebd345dcbbc1b30fec70b5bd6e114a06861b36082e97cb

See more details on using hashes here.

Provenance

The following attestation bundles were made for third_option-0.2.0-py3-none-manylinux_2_28_aarch64.whl:

Publisher: release-third-option.yml on 3rd-option/monorepo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file third_option-0.2.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for third_option-0.2.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 03985d06b520e1bfce08863de88f11b498309f5933daec1ab9e5ddc5dae91b20
MD5 495711b2e74955a11f9cafb29649f491
BLAKE2b-256 a468581ee43680afaa94d9416fd471b04f9f5531718a9d8347b0f363107e67e4

See more details on using hashes here.

Provenance

The following attestation bundles were made for third_option-0.2.0-py3-none-macosx_11_0_arm64.whl:

Publisher: release-third-option.yml on 3rd-option/monorepo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

3 files

This release

0.2.0 This release

3 files

0.1.0

3 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page