Client or integration
Claude Code
Area
CLI
Summary
When ocx claude is launched from a project directory containing an .env.local file with ANTHROPIC_API_KEY, the bundled Bun runtime automatically loads that variable before OpenCodex assembles the Claude Code child environment.
With claudeCode.authMode set to subscription, OpenCodex preserves the dotenv-loaded value as though it were an explicitly exported user credential. Claude Code then disables the user's claude.ai connectors and attempts the Anthropic API billing path instead of using the existing Claude.ai OAuth subscription.
The result is misleading for subscription users: the Claude.ai login is healthy, but Claude Code reports an API credit-balance error.
Expected behavior: subscription mode should preserve the existing Claude.ai OAuth login and should not be overridden by a working-directory dotenv file unless the user explicitly opts into API-key authentication.
Reproduction
-
Install @bitkyc08/opencodex@2.7.42.
-
Log in to Claude Code with /login; verify that claude auth status reports a Claude.ai subscription.
-
In the project working directory, create an .env.local file containing an API-key-shaped value (the real value is intentionally omitted):
ANTHROPIC_API_KEY=<redacted-api-key>
-
Configure OpenCodex for Claude subscription mode, with no OpenCodex admission API key:
{
"claudeCode": {
"enabled": true,
"authMode": "subscription",
"systemEnv": false
}
}
-
Make sure the parent shell does not already export the variable, then launch Claude Code from that directory:
env -u ANTHROPIC_API_KEY -u ANTHROPIC_AUTH_TOKEN \\
ocx claude -p "Reply with exactly: OK" --output-format text
The failure is reproducible when the bundled Bun runtime auto-loads the working-directory .env.local file.
Version
- OpenCodex:
@bitkyc08/opencodex 2.7.42
- Bundled Bun:
1.3.14
- Claude Code:
2.1.220
Operating system
Ubuntu 24.04.4 LTS (x86_64)
Provider and model
Anthropic / Claude.ai subscription OAuth; model-independent (observed with a Sonnet model).
Logs or error output
⚠ claude.ai connectors are disabled because ANTHROPIC_API_KEY or another auth source is set and takes precedence over your claude.ai login · Unset …
Credit balance too low · Add funds: https://platform.claude.com/settings/billing
Redacted configuration
{
"claudeCode": {
"enabled": true,
"authMode": "subscription",
"systemEnv": false
},
"providers": {
"anthropic": {
"adapter": "anthropic",
"authMode": "oauth"
}
}
}
No OpenCodex admission API keys were configured. No account identifiers, tokens, or secret values are included here.
Suggested implementation direction
- Launch the bundled Bun CLI with automatic dotenv loading disabled for the
ocx claude path (for example, --no-env-file), or otherwise distinguish dotenv-loaded values from intentionally exported authentication variables.
- Add a regression test covering
ocx claude from a working directory containing .env.local, with claudeCode.authMode=subscription and no admission key.
- Preserve the existing behavior for an explicitly exported API key when the user intentionally selects API-key/proxy authentication.
Workaround
Setting the variable to an empty value for the child process prevents Bun from replacing it from .env.local:
ANTHROPIC_API_KEY= ANTHROPIC_AUTH_TOKEN= ocx claude
Screenshots and supporting files
None. The failure is fully reproducible from the steps above.
Checks
Client or integration
Claude Code
Area
CLI
Summary
When
ocx claudeis launched from a project directory containing an.env.localfile withANTHROPIC_API_KEY, the bundled Bun runtime automatically loads that variable before OpenCodex assembles the Claude Code child environment.With
claudeCode.authModeset tosubscription, OpenCodex preserves the dotenv-loaded value as though it were an explicitly exported user credential. Claude Code then disables the user's claude.ai connectors and attempts the Anthropic API billing path instead of using the existing Claude.ai OAuth subscription.The result is misleading for subscription users: the Claude.ai login is healthy, but Claude Code reports an API credit-balance error.
Expected behavior: subscription mode should preserve the existing Claude.ai OAuth login and should not be overridden by a working-directory dotenv file unless the user explicitly opts into API-key authentication.
Reproduction
Install
@bitkyc08/opencodex@2.7.42.Log in to Claude Code with
/login; verify thatclaude auth statusreports a Claude.ai subscription.In the project working directory, create an
.env.localfile containing an API-key-shaped value (the real value is intentionally omitted):Configure OpenCodex for Claude subscription mode, with no OpenCodex admission API key:
{ "claudeCode": { "enabled": true, "authMode": "subscription", "systemEnv": false } }Make sure the parent shell does not already export the variable, then launch Claude Code from that directory:
The failure is reproducible when the bundled Bun runtime auto-loads the working-directory
.env.localfile.Version
@bitkyc08/opencodex 2.7.421.3.142.1.220Operating system
Ubuntu 24.04.4 LTS (x86_64)
Provider and model
Anthropic / Claude.ai subscription OAuth; model-independent (observed with a Sonnet model).
Logs or error output
Redacted configuration
{ "claudeCode": { "enabled": true, "authMode": "subscription", "systemEnv": false }, "providers": { "anthropic": { "adapter": "anthropic", "authMode": "oauth" } } }No OpenCodex admission API keys were configured. No account identifiers, tokens, or secret values are included here.
Suggested implementation direction
ocx claudepath (for example,--no-env-file), or otherwise distinguish dotenv-loaded values from intentionally exported authentication variables.ocx claudefrom a working directory containing.env.local, withclaudeCode.authMode=subscriptionand no admission key.Workaround
Setting the variable to an empty value for the child process prevents Bun from replacing it from
.env.local:Screenshots and supporting files
None. The failure is fully reproducible from the steps above.
Checks