Skip to content

[Bug] ocx claude lets Bun dotenv ANTHROPIC_API_KEY override Claude.ai subscription auth #701

Description

@jhste102lab

Client or integration

Claude Code

Area

CLI

Summary

When ocx claude is launched from a project directory containing an .env.local file with ANTHROPIC_API_KEY, the bundled Bun runtime automatically loads that variable before OpenCodex assembles the Claude Code child environment.

With claudeCode.authMode set to subscription, OpenCodex preserves the dotenv-loaded value as though it were an explicitly exported user credential. Claude Code then disables the user's claude.ai connectors and attempts the Anthropic API billing path instead of using the existing Claude.ai OAuth subscription.

The result is misleading for subscription users: the Claude.ai login is healthy, but Claude Code reports an API credit-balance error.

Expected behavior: subscription mode should preserve the existing Claude.ai OAuth login and should not be overridden by a working-directory dotenv file unless the user explicitly opts into API-key authentication.

Reproduction

  1. Install @bitkyc08/opencodex@2.7.42.

  2. Log in to Claude Code with /login; verify that claude auth status reports a Claude.ai subscription.

  3. In the project working directory, create an .env.local file containing an API-key-shaped value (the real value is intentionally omitted):

    ANTHROPIC_API_KEY=<redacted-api-key>
  4. Configure OpenCodex for Claude subscription mode, with no OpenCodex admission API key:

    {
      "claudeCode": {
        "enabled": true,
        "authMode": "subscription",
        "systemEnv": false
      }
    }
  5. Make sure the parent shell does not already export the variable, then launch Claude Code from that directory:

    env -u ANTHROPIC_API_KEY -u ANTHROPIC_AUTH_TOKEN \\
      ocx claude -p "Reply with exactly: OK" --output-format text

The failure is reproducible when the bundled Bun runtime auto-loads the working-directory .env.local file.

Version

  • OpenCodex: @bitkyc08/opencodex 2.7.42
  • Bundled Bun: 1.3.14
  • Claude Code: 2.1.220

Operating system

Ubuntu 24.04.4 LTS (x86_64)

Provider and model

Anthropic / Claude.ai subscription OAuth; model-independent (observed with a Sonnet model).

Logs or error output

⚠ claude.ai connectors are disabled because ANTHROPIC_API_KEY or another auth source is set and takes precedence over your claude.ai login · Unset …
Credit balance too low · Add funds: https://platform.claude.com/settings/billing

Redacted configuration

{
  "claudeCode": {
    "enabled": true,
    "authMode": "subscription",
    "systemEnv": false
  },
  "providers": {
    "anthropic": {
      "adapter": "anthropic",
      "authMode": "oauth"
    }
  }
}

No OpenCodex admission API keys were configured. No account identifiers, tokens, or secret values are included here.

Suggested implementation direction

  • Launch the bundled Bun CLI with automatic dotenv loading disabled for the ocx claude path (for example, --no-env-file), or otherwise distinguish dotenv-loaded values from intentionally exported authentication variables.
  • Add a regression test covering ocx claude from a working directory containing .env.local, with claudeCode.authMode=subscription and no admission key.
  • Preserve the existing behavior for an explicitly exported API key when the user intentionally selects API-key/proxy authentication.

Workaround

Setting the variable to an empty value for the child process prevents Bun from replacing it from .env.local:

ANTHROPIC_API_KEY= ANTHROPIC_AUTH_TOKEN= ocx claude

Screenshots and supporting files

None. The failure is fully reproducible from the steps above.

Checks

  • I searched existing issues and documentation.
  • I removed secrets, tokens, account details, request credentials, and personal data.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions