Yes, you can use the local Claude Code CLI with an API key instead of a Pro or Max subscription. Set ANTHROPIC_API_KEY, launch claude, approve the key when prompted, and run /status to verify the active credential. Anthropic documents this API-key authentication path.
An approved key bills its Claude Console organization instead of your subscription allowance. Commands and prices were checked on September 23, 2026.
Set up your Claude Code API key
Have an authorized key and an installed CLI? Follow these steps. Otherwise, see Get a key or install Claude Code.
Run claude --version; the Sonnet 5.5 examples need v2.1.284 or later, and claude update upgrades a native install.
- 1Set the key and launch from the same terminal
If you're switching an existing setup, inspect
/statusfirst. These shell examples clear common gateway and cloud selections in the current terminal. Remove unintended settings-file entries too: settings-fileenvvalues overwrite shell exports.Remove a gateway's
ANTHROPIC_MODELfrom settings when using the savedmodelfield; the environment variable takes precedence.Watch outThis changes which account paysAn approved
ANTHROPIC_API_KEYoverrides a saved subscription login. Inclaude -p, the key is selected without approval unless a higher-priority provider or credential wins. See authentication precedence.Replace placeholders locally. Literal secrets can remain in shell history. Settings-file keys are plaintext and reach subprocesses; never commit them to shared project settings. Use a credential helper for secret-manager-backed persistence.
Shellunset ANTHROPIC_AUTH_TOKEN ANTHROPIC_BASE_URL ANTHROPIC_MODEL unset CLAUDE_CODE_USE_BEDROCK CLAUDE_CODE_USE_VERTEX CLAUDE_CODE_USE_FOUNDRY export ANTHROPIC_API_KEY="YOUR_ANTHROPIC_API_KEY" claude --model claude-sonnet-5-5PowerShellRemove-Item Env:ANTHROPIC_AUTH_TOKEN -ErrorAction SilentlyContinue Remove-Item Env:ANTHROPIC_BASE_URL -ErrorAction SilentlyContinue Remove-Item Env:ANTHROPIC_MODEL -ErrorAction SilentlyContinue Remove-Item Env:CLAUDE_CODE_USE_BEDROCK -ErrorAction SilentlyContinue Remove-Item Env:CLAUDE_CODE_USE_VERTEX -ErrorAction SilentlyContinue Remove-Item Env:CLAUDE_CODE_USE_FOUNDRY -ErrorAction SilentlyContinue $env:ANTHROPIC_API_KEY = "YOUR_ANTHROPIC_API_KEY" claude --model claude-sonnet-5-5Create or edit
~/.claude/settings.json, or%USERPROFILE%\.claude\settings.jsonon Windows. Merge this into existing settings without replacing permissions or hooks:JSON{ "env": { "ANTHROPIC_API_KEY": "YOUR_ANTHROPIC_API_KEY" }, "model": "claude-sonnet-5-5" }Remove unintended tokens, endpoints, cloud flags and
ANTHROPIC_MODELentries from settings and the launch environment. Pin the first verification launch:Shellclaude --model claude-sonnet-5-5Later launches can use the saved
modelfield.Sources: the API-key variable, settings format,
--modelflag, and Sonnet 5.5 API ID. - 2Approve, verify and send one small test
Approve the custom key if prompted. If you previously declined it, enable Use custom API key in
/config. The toggle appears whileANTHROPIC_API_KEYis set.Run
/status. Check that the active API-key source namesANTHROPIC_API_KEY. When login and key both exist, the status screen marks the unused credential.Send:
textReply with OK. Do not use tools.Confirm usage in the associated organization's Console Usage page. For an employer-owned account, ask the administrator to confirm it. The test also consumes system-prompt and context tokens.
Get a key or install Claude Code
Follow Anthropic's API-key creation instructions and Console billing instructions, or our step-by-step guide to getting a Claude API key and adding credits. Use the installation instructions below if you also need the CLI.
Create a funded, authorized Console key
Create a key in Claude Console API keys, or use your employer's authorized key without its billing-owner login.
Anthropic recommends a personal key for your development. Name it, select its linked account and a single workspace, set an expiration, and copy it: the full secret appears only once.
Most Console organizations use prepaid credits, purchased by an Admin or Billing user in Console Billing. Some use negotiated invoicing. These API billing arrangements are separate from a chat subscription.
Install or update Claude Code
Anthropic's recommended native installer requires no Node.js. These commands execute its installer; teams should use their approved channel.
curl -fsSL https://claude.ai/install.sh | bash
# Open a new terminal, then:
claude --versionirm https://claude.ai/install.ps1 | iex
# Open a new terminal, then:
claude --versionUse the update command matching your installation:
| Installation | Update command |
|---|---|
| Native | claude update |
| Homebrew stable cask | brew upgrade claude-code |
| Homebrew latest cask | brew upgrade claude-code@latest |
| WinGet | winget upgrade Anthropic.ClaudeCode |
| npm | npm install -g @anthropic-ai/claude-code@latest |
Exit, relaunch and run claude --version. Native installs also update in the background. Homebrew and WinGet offer optional background updates; package-manager installations normally need manual updates.
Stable lags latest, and package-manager releases may not yet be available. Check the resulting version before selecting Sonnet 5.5.
Choose which account pays
The credential authorizes model calls, the endpoint determines where they go, and the billing system records usage. An endpoint alone does not select a billing account.
| Route | What you configure | Billing system | Claude subscription needed? |
|---|---|---|---|
| Claude.ai login | Sign in to your eligible account | Plan allowance plus optional paid usage credits | Yes for individual Pro/Max access |
| Direct Anthropic key | ANTHROPIC_API_KEY | Associated Console organization | No |
| Console browser login | claude auth login --console | Console organization | No |
| Requesty | Base URL plus Requesty token | Requesty account | No |
| Bedrock, Google Cloud or Foundry | Provider flag plus cloud credentials | Cloud account | No |
Sources: Claude Code authentication, subscription usage credits, and our Requesty integration. The free claude.ai plan does not include Claude Code.

Console API billing without managing a key yourself
Remove conflicting credential overrides, then use the documented Console login command:
claude auth login --console
claudeThe recommended Sign in with your Console account option stores an OAuth-backed Anthropic profile without creating a key. The alternative creates a legacy key. Keyless Console sign-in requires v2.1.242 or later and may be unavailable under some policies.
A Profile row in /status can therefore mean Console API billing. OAuth alone does not identify who pays.
Cloud sessions always use subscription credentials. Desktop has separate third-party inference settings. Remote Control and voice are unavailable during API-key, auth-token or helper authentication.
Which credential wins when you are already subscribed?
Anthropic documents this credential order for ordinary local sessions:
| Priority | Credential source | What to check |
|---|---|---|
| 1 | Cloud-provider selection | CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, CLAUDE_CODE_USE_FOUNDRY |
| 2 | Bearer token | ANTHROPIC_AUTH_TOKEN |
| 3 | Direct API key | ANTHROPIC_API_KEY, with interactive approval |
| 4 | Helper output | apiKeyHelper |
| 5 | OAuth token environment variable | CLAUDE_CODE_OAUTH_TOKEN |
| 6 | Named profile, federation variables or active federation profile | ANTHROPIC_PROFILE or federation configuration |
| 7 | Saved subscription login | Login selected through /login |
Logging in to Pro does not remove an exported key. After approval, the key wins. Declining it interactively does not protect a later claude -p process from selecting it.
Profile and managed-gateway exceptions
An unnamed active user_oauth profile ranks below a working saved subscription login. An active oidc_federation profile ranks above /login, even without ANTHROPIC_PROFILE. See the full profile precedence reference.
An authenticated self-hosted Claude apps gateway session outranks the table's sources. This is distinct from Requesty's bearer-token setup. Managed gateway-sign-in policy can constrain the route.
Authentication precedence is not settings precedence
Claude Code resolves configuration before selecting a credential. Settings priority is managed, command line, project local, shared project, then user. Settings-file env entries overwrite matching shell variables. See settings precedence and environment resolution.
Clearing an export can leave a settings-file override in place. Inspect /status and its setting sources in the affected session. Anthropic's environment-variable reference covers the broader configuration surface.
Switch back to your subscription safely
Stop unattended jobs and exit the session. Remove persistent overrides before clearing the terminal: settings-file removal takes effect on the next launch.
Check:
- User, project-local and shared project settings.
- Shell profiles, Windows user variables, IDE launch settings and CI secrets.
apiKeyHelper, cloud flags, endpoint and gateway-specific model overrides.- Advanced OAuth, named-profile or federation configuration if used.
Clear common direct-key and gateway overrides:
unset ANTHROPIC_API_KEY ANTHROPIC_AUTH_TOKEN ANTHROPIC_BASE_URL
unset CLAUDE_CODE_USE_BEDROCK CLAUDE_CODE_USE_VERTEX CLAUDE_CODE_USE_FOUNDRY
unset ANTHROPIC_MODELRemove-Item Env:ANTHROPIC_API_KEY -ErrorAction SilentlyContinue
Remove-Item Env:ANTHROPIC_AUTH_TOKEN -ErrorAction SilentlyContinue
Remove-Item Env:ANTHROPIC_BASE_URL -ErrorAction SilentlyContinue
Remove-Item Env:CLAUDE_CODE_USE_BEDROCK -ErrorAction SilentlyContinue
Remove-Item Env:CLAUDE_CODE_USE_VERTEX -ErrorAction SilentlyContinue
Remove-Item Env:CLAUDE_CODE_USE_FOUNDRY -ErrorAction SilentlyContinue
Remove-Item Env:ANTHROPIC_MODEL -ErrorAction SilentlyContinueLaunch claude and check /status. If the subscription login is missing, run claude auth login, or /login in-session, and select your claude.ai subscription. Use these current authentication commands rather than claude login or claude logout.
Remove a persistent Windows user environment override
Clearing Env: leaves saved user variables intact. Remove each persisted value you no longer want, for example:
[Environment]::SetEnvironmentVariable("ANTHROPIC_API_KEY", $null, "User")Repeat for saved token, endpoint, model or cloud flags. Open a new terminal and fully restart an IDE that inherited the old environment. See the environment-variable documentation.
Remove the winning override; deleting your entire .claude directory is unnecessary.
API billing or a subscription: what will it cost?
Metering suits occasional use. A subscription suits sustained interactive use if its allowance covers your work. Compare your measured API bill with the plan fee and the limits you hit.
Current published prices
Anthropic's API rates, checked September 23, 2026, in USD per million tokens at standard global rates:
| Model | Uncached input | 5-minute cache write | 1-hour cache write | Cache read | Output |
|---|---|---|---|---|---|
| Sonnet 5.5 | $2.00 | $2.50 | $4.00 | $0.20 | $10.00 |
| Opus 5.5 | $4.00 | $5.00 | $8.00 | $0.20 | $20.00 |
| Haiku 4.5 | $1.00 | $1.25 | $2.00 | $0.10 | $5.00 |
Opus 5.5 requires Claude Code v2.1.280 or later.
US monthly web prices are $20 for Pro, $100 for Max 5x and $200 for Max 20x. Plans have session and weekly limits; regional and mobile prices can differ. Optional usage credits add charges.
A cache-aware worked example
Assume one unit of coding work uses these aggregate billable tokens across all requests:
| Separate billing category | Assumed tokens | Sonnet 5.5 calculation | Cost |
|---|---|---|---|
| Uncached input | 100,000 | 0.1 × $2 | $0.20 |
| 5-minute cache writes | 100,000 | 0.1 × $2.50 | $0.25 |
| Cache reads | 1,000,000 | 1 × $0.20 | $0.20 |
| Output, including billable thinking | 50,000 | 0.05 × $10 | $0.50 |
| Total per assumed unit | $1.15 |
Don't count cache writes or reads again as uncached input. We exclude fast mode, one-hour cache writes, server-tool fees, tax, regional premiums and contracted discounts.

The same token shape costs $2.10 on Opus 5.5: (0.1 × $4) + (0.1 × $5) + (1 × $0.20) + (0.05 × $20). Compare completed work as well as tokens when choosing a model.
On Sonnet 5.5, four units cost 4 × $1.15 = $4.60; 20 cost $23; 100 cost $115.
Illustrative API spend versus a plan fee
4, 20 and 100 units at $1.15 each

At this token mix, $20 ÷ $1.15 ≈ 17.4 units reaches Pro's monthly purchase price. Check whether your plan's limits cover your workload; subscriptions also include other Claude surfaces.
Continue a subscription with usage credits
Pro and Max subscribers can enable subscription usage credits, add funds and set a monthly spend limit in claude.ai's Usage settings. At the plan limit, enabled credits with funds available let you choose to continue at standard API rates, charged separately.
Keep subscription authentication. /usage-credits opens the settings page and is unavailable with API-key authentication. These credits cover Claude conversations and Claude Code terminal usage. They do not fund a Console key or turn it into subscription-first fallback.
Measure the bill and set a boundary
For API users, /usage shows session usage; /cost is an alias. Dollar totals are local estimates, including with administrator-configured rates. Use Console Usage for direct billing and Requesty's ledger for our routes. To log session events, use Anthropic's session hooks.
API access has rate and monthly spend limits. A non-default Console workspace supports a lower spend limit than the organization. Review auto-reload before using a prepaid balance as your boundary.
For an unattended job, --max-budget-usd sets a per-run budget including subagent spend. This example uses $2:
claude -p "Summarize this repository's architecture. Do not modify files." \
--model claude-sonnet-5-5 \
--max-budget-usd 2The flag is print-mode only. Use account or workspace controls for an interactive monthly boundary.
Use Requesty for per-developer keys and spend caps
One Requesty key per developer gives you access to 600+ models in Claude Code, a monthly cap per key, and cost per developer. Set it up with ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN, as documented in our Claude Code integration.
Use https://router.requesty.ai, without /v1 or /anthropic. These Sonnet 5.5 examples need v2.1.284 or later. Remove conflicting settings-file overrides, then choose a method:
unset ANTHROPIC_API_KEY
unset CLAUDE_CODE_USE_BEDROCK CLAUDE_CODE_USE_VERTEX CLAUDE_CODE_USE_FOUNDRY
export ANTHROPIC_BASE_URL="https://router.requesty.ai"
export ANTHROPIC_AUTH_TOKEN="YOUR_REQUESTY_API_KEY"
export ANTHROPIC_MODEL="anthropic/claude-sonnet-5-5"
claudeRemove-Item Env:ANTHROPIC_API_KEY -ErrorAction SilentlyContinue
Remove-Item Env:CLAUDE_CODE_USE_BEDROCK -ErrorAction SilentlyContinue
Remove-Item Env:CLAUDE_CODE_USE_VERTEX -ErrorAction SilentlyContinue
Remove-Item Env:CLAUDE_CODE_USE_FOUNDRY -ErrorAction SilentlyContinue
$env:ANTHROPIC_BASE_URL = "https://router.requesty.ai"
$env:ANTHROPIC_AUTH_TOKEN = "YOUR_REQUESTY_API_KEY"
$env:ANTHROPIC_MODEL = "anthropic/claude-sonnet-5-5"
claudeMerge into user settings:
{
"env": {
"ANTHROPIC_BASE_URL": "https://router.requesty.ai",
"ANTHROPIC_AUTH_TOKEN": "YOUR_REQUESTY_API_KEY",
"ANTHROPIC_MODEL": "anthropic/claude-sonnet-5-5"
}
}Remove the previous direct-key entry and unintended provider flags, then launch claude. The token is stored in plaintext.
We checked anthropic/claude-sonnet-5-5 in our live catalog on September 30. Any allowed catalog ID works through ANTHROPIC_MODEL; non-Claude models vary in tool and Claude-specific feature support.
Verify the documented /status fields: Anthropic base URL should show https://router.requesty.ai, and active Auth token should name ANTHROPIC_AUTH_TOKEN. Send the small test and confirm it in Requesty's analytics dashboard through the cost-tracking guide. Request-level visibility shows the calls behind the session; the gateway carries model requests, with background traffic taking other paths.
For a team rollout:
- Create a named key per developer or workstation using our key and spend-limit instructions.
- Set a monthly cap with per-key spend controls.
- Review costs by key or owning member in cost-tracking views.
Pay-as-you-go pricing is provider token costs plus 5%, with no per-seat fee or minimum spend. The $23 token bill above becomes $23 × 1.05 = $24.15, before other applicable charges.
Follow our Claude Code integration docs, then create your Requesty account.
Advanced authentication for teams
Use personal developer keys and service-account keys for shared automation, following Anthropic's key-type guidance. Separate coding from production workloads with Console workspaces.
Administrators distribute configuration through managed settings. Some forced-login policies block environment credentials and helpers; ask the administrator to approve a blocked route.
Retrieve the key with apiKeyHelper
A helper retrieves credentials without a static settings-file key. This example requires authenticated Vault access to an api_key field at secret/claude-code. Adapt the path to your deployment using Anthropic's credential-helper pattern.
Save as ~/bin/get-claude-key.sh:
#!/bin/sh
exec vault kv get -field=api_key secret/claude-codeMake it executable:
chmod +x ~/bin/get-claude-key.shMerge into user settings:
{
"apiKeyHelper": "~/bin/get-claude-key.sh",
"model": "claude-sonnet-5-5"
}Save as C:\scripts\get-claude-key.ps1:
vault kv get -field=api_key secret/claude-codeMerge into user settings:
{
"apiKeyHelper": "powershell -NoProfile -File C:\\scripts\\get-claude-key.ps1",
"model": "claude-sonnet-5-5"
}Remove higher-priority ANTHROPIC_API_KEY and ANTHROPIC_AUTH_TOKEN values. For direct Anthropic use, also remove unintended gateway models, custom endpoints and cloud selections.
Print only the credential to stdout. Don't run the helper in a shared or recorded terminal. Claude Code sends its output in both API-key and bearer headers. The default cache lifetime is five minutes; CLAUDE_CODE_API_KEY_HELPER_TTL_MS changes it in milliseconds.
Use Bedrock, Vertex AI or Foundry instead
These routes use cloud credentials and billing. Remove conflicting provider flags, direct keys, gateway tokens and helpers, then verify the provider with /status.
Amazon Bedrock
Configure an AWS profile, model access and IAM permissions. The Bedrock guide documents:
aws sso login --profile=YOUR_PROFILE
export AWS_PROFILE=YOUR_PROFILE
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_REGION=us-east-1
export ANTHROPIC_MODEL='us.anthropic.claude-sonnet-4-6'
claudeUse an approved inference-profile ID for your region; the example uses the documented US profile. Bedrock API-key authentication uses AWS_BEARER_TOKEN_BEDROCK.
Select 3rd-party platform, then Amazon Bedrock, or run /setup-bedrock for the wizard. To leave, remove CLAUDE_CODE_USE_BEDROCK at its persistent source; /logout is unavailable here.
Google Cloud
Google Cloud's Agent Platform, formerly Vertex AI, retains VERTEX variables in its Claude Code integration. Enable billing, model access, IAM permissions and quota:
gcloud config set project YOUR_PROJECT_ID
gcloud services enable aiplatform.googleapis.com
gcloud auth application-default login
export CLAUDE_CODE_USE_VERTEX=1
export CLOUD_ML_REGION=global
export ANTHROPIC_VERTEX_PROJECT_ID=YOUR_PROJECT_ID
export ANTHROPIC_MODEL='claude-sonnet-5'
claudeCheck model and location access in your project, then inspect /status for API provider, GCP project, Default region and Model.
Select 3rd-party platform, then Google Vertex AI, or run /setup-vertex for the wizard. Remove the provider flag to leave; /logout is unavailable here.
Microsoft Foundry
Provision a resource and Claude deployment in Microsoft Foundry, then follow the Foundry guide:
export CLAUDE_CODE_USE_FOUNDRY=1
export ANTHROPIC_FOUNDRY_RESOURCE="YOUR_RESOURCE_NAME"
export ANTHROPIC_FOUNDRY_API_KEY="YOUR_FOUNDRY_API_KEY"
export ANTHROPIC_MODEL="YOUR_DEPLOYMENT_NAME"
claudeUse your deployment name as the model. Clear unintended ANTHROPIC_FOUNDRY_AUTH_TOKEN and ANTHROPIC_FOUNDRY_BASE_URL overrides: the token outranks the key. Foundry also supports a full endpoint or the default Azure credential chain and has no interactive setup wizard.
Fix common Claude Code API-key errors
Start with the active credential. For installation or settings-validation errors, run claude doctor without starting a session. Use /status to check who pays.
Anthropic documents API-key and credit errors and gateway troubleshooting.
| Symptom | Check first | Fix |
|---|---|---|
| Login prompt despite a key | Same terminal, exported variable, prior approval | Set before launch; check /config; restart |
| API charges while subscribed | /status, profiles, settings, IDE or CI inheritance | Remove the winning credential at its source |
Invalid API key or 401 | Active key, expiration, endpoint, invisible characters | Correct or rotate the identified credential; don't print it |
Credit balance is too low | Console organization, balance and limits | Fund the correct organization or switch billing deliberately |
| Gateway 404 | Root base URL | For Requesty, use https://router.requesty.ai |
| Unsupported or missing model | CLI version, direct ID versus provider/model, access | Update through your channel; use an allowed ID |
| Shell fixed, IDE still wrong | Parent environment and extension settings | Fully restart the IDE; verify its session |
| Helper fails | Executable path, Vault login, stdout | Reauthenticate the secret manager; return only the key |
| Administrator-policy error | Managed login requirements | Ask the administrator; don't bypass policy |
| 429 after switching to API | API rate limits or spend limits | Check Console limits and reduce concurrent work |
For VS Code gateways, configure claudeCode.environmentVariables for the extension's credential check; a terminal export alone is insufficient.
Check for a shell key without revealing it
if [ -n "${ANTHROPIC_API_KEY:-}" ]; then
printf '%s\n' 'ANTHROPIC_API_KEY is set'
else
printf '%s\n' 'ANTHROPIC_API_KEY is not set'
fiif ($env:ANTHROPIC_API_KEY) {
"ANTHROPIC_API_KEY is set"
} else {
"ANTHROPIC_API_KEY is not set"
}This checks the shell; /status includes the running session's resolved configuration. A project .env file alone doesn't prove inheritance. Shell plugins, direnv and IDE terminals can inject its values.
Before your first long session
Claude Code API-billing checklist
0 of 7 done
Measure a representative week of completed tasks, API spend and subscription limits. For developer keys and caps, follow our Claude Code integration docs.
Sources
Commands, configuration and prices checked September 23, 2026.
Frequently asked questions
- Can I use Claude Code with an API key instead of a subscription?
- Yes. The local Claude Code CLI supports an Anthropic Console API key without a Pro or Max subscription. Model usage is billed to the Console organization associated with the key, subject to API rate and spend limits.
- How do I set a Claude Code API key?
- Set ANTHROPIC_API_KEY before launching claude, approve the custom key when prompted, then run /status to check the active credential. You can set the variable in your shell or under env in your user settings.json file.
- Does a Claude subscription include API credits?
- Ordinary Claude Console API usage is separate from your Claude subscription. Optional subscription usage credits let you continue through your claude.ai account, but they do not fund a Console API key.
- Which credential wins if I have a subscription and an API key?
- In an ordinary local interactive session, ANTHROPIC_API_KEY overrides a saved subscription login after you approve the key. In print mode, the key is used without that approval prompt. Cloud-provider selection and ANTHROPIC_AUTH_TOKEN rank above the API key.
- How do I check whether Claude Code is billing my API key?
- Run /status to identify the active credential source, then check the associated Console organization's Usage page after a small test. The dollar figure in /usage is computed locally and remains an estimate, even with administrator-configured rates.
- Why does Claude Code say my credit balance is too low when I have Max?
- You may be using a Console API key rather than your subscription login. Check /status and the selected Console organization's balance and limits before buying credits or switching credentials.
- How do I switch Claude Code back to my subscription?
- Remove API keys, gateway tokens, helpers and provider-selection overrides from the shell and persistent settings that launch Claude Code. Relaunch, sign in with your claude.ai subscription if needed, and confirm the selected credential with /status.
- SEP '26
How to Get a Claude API Key (and Manage Credits and Billing)
Get a Claude API key in the Console, test it with curl or an SDK, buy credits, set monthly spending limits, and fix common billing errors safely.
- SEP '26
Claude Code Hooks: 10 Examples for Logging, Safety and Costs
Set up Claude Code hooks with 10 copy-paste examples for logs, guardrails, formatting and notifications, plus session cost tracking that uses the right data.
- JUL '26
$1.8k before anyone noticed: how to cap runaway agent spend
Retry storms, agent loops, and stolen keys are the three ways teams lose four figures of LLM budget in a day. A practical setup for hard caps, per key limits, alerts, and loop detection.