Connect Claude Code, Cursor and any SDK to the gateway

Claude Code does not know Atlasberg exists. It just thinks the Anthropic API lives at another address. The same trick works for Cursor, Codex, Gemini CLI and every official SDK.

How it works

Your tool (Keeps speaking its native protocol.) -> Base URL (Points at the matching drop-in route on the gateway.) -> Virtual key (Goes where the provider key used to go. Or a personal token, with SSO.). Two settings per tool. Nothing else changes: same commands, same models, same streaming.

You need a virtual key (it starts with sk-atlas-) or, if your company enabled single sign-on for the terminal, a personal token from the atlasberg login command. Ask your administrator which one applies; Tutorial 3 covers the SSO path.

Claude Code

On the first run Claude Code asks whether to use the key from the variable instead of signing in at Anthropic. Confirm once. The ANTHROPIC_AUTH_TOKEN alternative also works, because the gateway accepts Authorization: Bearer sk-atlas-....

Model: If the company wants to fix the model, use the global routing rule from Tutorial 1. The ANTHROPIC_MODEL variable in the env block also works, but the rule on the gateway applies to every client at once and does not depend on anyone honoring the variable.

  • System: macOS | Path: /Library/Application Support/ClaudeCode/managed-settings.json
  • System: Linux and WSL | Path: /etc/claude-code/managed-settings.json
  • System: Windows | Path: C:\ProgramData\ClaudeCode\managed-settings.json
  • env injects the variables into every Claude Code session, without depending on the person's shell.
  • CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC turns off telemetry, update checks and other calls the firewall would block and that would produce error noise.
  • apiKeyHelper is a script that prints the credential. Claude Code runs it and refreshes the value by TTL. This is where the key becomes invisible.

The minimum: two variables

Claude Code builds ANTHROPIC_BASE_URL + /v1/messages, which lands on /anthropic/v1/messages. That route already answers messages with streaming, count_tokens and models, which is all it uses. The key travels in the x-api-key header and the gateway recognizes it as virtual by the prefix. The model claude-sonnet-5 without a prefix is resolved by the catalog.

So the developer configures nothing

Claude Code reads a managed settings file that the organization controls and the user cannot override. The MDM or the onboarding script writes this file:

The credential script

Option A reads the virtual key that provisioning left on the machine. Option B, for companies with SSO on the terminal, asks the atlasberg CLI for the personal token. Both print one line and exit.

What the developer sees

Opens the terminal, runs claude, it works. If they try a personal key or point at Anthropic directly, the firewall cuts it. If they exceed the budget, soft cut degrades to the cheapest allowed model instead of denying.

# base URL points at the gateway's Anthropic drop-in route
export ANTHROPIC_BASE_URL=https://llm.company.com/anthropic
# the virtual key takes the place of the Anthropic key
export ANTHROPIC_API_KEY=sk-atlas-...
$ claude
Detected a custom API key in your environment (ANTHROPIC_API_KEY).
Do you want to use this API key? › Yes

✓ Connected. Model: claude-sonnet-5
{
  "env": {
    "ANTHROPIC_BASE_URL": "https://llm.company.com/anthropic",
    "CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC": "1"
  },
  "apiKeyHelper": "/usr/local/bin/atlasberg-credential"
}
#!/bin/sh
# Linux: file written by onboarding, owner = user, mode 0400
if [ -r "$HOME/.config/atlasberg/virtual-key" ]; then
  cat "$HOME/.config/atlasberg/virtual-key"
  exit 0
fi
# macOS: Keychain item written by the MDM
security find-generic-password -s atlasberg-virtual-key -w 2>/dev/null
{
  "env": { "ANTHROPIC_BASE_URL": "https://llm.company.com/anthropic" },
  "apiKeyHelper": "atlasberg key-helper"
}

Cursor

Under Settings > Models, paste the virtual key in the OpenAI API key field and check Override OpenAI Base URL with:

The /cursor route exists because Cursor sends a hybrid Responses API payload to the chat completions endpoint. The gateway converts in both directions. Add the models the team may use to the custom models list, with the same name as in the catalog.

Careful: In several configurations Cursor makes the call from its own servers, not from the user's machine. In that case llm.company.com must be reachable from the internet, and the virtual key becomes the only protection. Confirm the behavior in the documentation of the version in use before exposing the gateway.

https://llm.company.com/cursor/v1

Codex CLI, Continue, Cline, Aider and any OpenAI SDK

To ask for a model from another provider through the OpenAI route, use the prefix: anthropic/claude-sonnet-5.

export OPENAI_BASE_URL=https://llm.company.com/openai/v1
export OPENAI_API_KEY=sk-atlas-...

Anthropic SDK

from anthropic import Anthropic
client = Anthropic(
    base_url="https://llm.company.com/anthropic",
    api_key="sk-atlas-...",
)
import Anthropic from "@anthropic-ai/sdk";
const client = new Anthropic({
  baseURL: "https://llm.company.com/anthropic",
  apiKey: "sk-atlas-...",
});

Gemini CLI and Google SDK

export GOOGLE_GEMINI_BASE_URL=https://llm.company.com/genai
export GEMINI_API_KEY=sk-atlas-...

Unified API

Internal applications can use the OpenAI format at the root and pick the provider by the model prefix. One client, every provider:

curl -s https://llm.company.com/v1/chat/completions \
  -H "Authorization: Bearer sk-atlas-..." \
  -H "Content-Type: application/json" \
  -d '{"model":"anthropic/claude-sonnet-5","messages":[{"role":"user","content":"Hello"}]}'

Quick reference

  • Client: Claude Code | Base URL: ANTHROPIC_BASE_URL=https://llm.company.com/anthropic | Credential: ANTHROPIC_API_KEY or apiKeyHelper
  • Client: Anthropic SDK | Base URL: base_url=https://llm.company.com/anthropic | Credential: api_key
  • Client: Cursor | Base URL: https://llm.company.com/cursor/v1 | Credential: OpenAI API Key field
  • Client: Codex, OpenAI SDK, Continue, Cline, Aider | Base URL: OPENAI_BASE_URL=https://llm.company.com/openai/v1 | Credential: OPENAI_API_KEY
  • Client: Gemini CLI, Google SDK | Base URL: GOOGLE_GEMINI_BASE_URL=https://llm.company.com/genai | Credential: GEMINI_API_KEY
  • Client: Internal applications | Base URL: https://llm.company.com/v1 | Credential: Authorization: Bearer
  • Symptom: 401 virtual_key_required | Cause: The tool sent no key, or sent it in a header the gateway does not read | Fix: Check the variable; the key must carry the sk-atlas- prefix
  • Symptom: 401 virtual_key_not_found | Cause: Revoked, expired or mistyped key | Fix: Ask the administrator to reissue it
  • Symptom: 403 model not allowed | Cause: The key does not have that model in its allowed list | Fix: Ask for the model to be added to the key or the team
  • Symptom: Certificate error | Cause: Corporate CA not seen by Node | Fix: NODE_EXTRA_CA_CERTS pointing at the CA's PEM bundle
  • Symptom: Claude Code slow to start | Cause: Telemetry hitting the firewall | Fix: CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1

If something fails

Do it all with an AI agent

If you would rather delegate, paste the prompt below into Claude Code or another AI agent with terminal access. It is written to ask for everything it needs before touching anything, show a plan, wait for your confirmation and only then execute. It never asks for the value of a provider key and never writes a secret into a repository file.

Next: sign in from the terminal with SSO

Replace the virtual key with a personal token issued after the corporate login. No key on the laptop.

Back: every AI request through the gateway

How the infrastructure team publishes the gateway, blocks direct egress and creates teams and keys.

You are going to configure my workstation so that my AI tools go through the company's Atlasberg gateway, following https://atlasberg.com/docs/tutoriais/conectar-claude-code. Do not invent anything: ask for what is missing.

Before touching any file, ask me, one question at a time:
1. The gateway URL (example: https://llm.company.com).
2. How I authenticate: (a) I have a virtual key that starts with sk-atlas-, or (b) the company uses single sign-on from the terminal with the atlasberg CLI. If (b), stop here and send me to https://atlasberg.com/docs/tutoriais/login-por-dispositivo, which has the right prompt.
3. If it is a key: where it is. In a file, in the Keychain, or I will paste it now. If I paste it, write it to ~/.config/atlasberg/virtual-key with permission 0400, do not echo the key back and do not put it in any other file.
4. Which tools I use: Claude Code, Cursor, Codex CLI, Continue, Cline, Aider, Gemini CLI, Anthropic SDK, OpenAI SDK, Google SDK.
5. My system (macOS, Linux, WSL or Windows) and my shell (bash, zsh, fish, PowerShell).
6. Whether this is my own work machine (configure my shell profile) or whether I am preparing a company-managed configuration for every workstation (Claude Code's managed-settings.json, which needs administrator privilege).
7. Whether the gateway uses a corporate CA certificate and, if so, the path of the CA PEM.

Then show what you are going to write and where, and ask for confirmation. Only then do it:
a) Claude Code: export ANTHROPIC_BASE_URL=<gateway>/anthropic. For the key, create the script /usr/local/bin/atlasberg-credential (or ~/.local/bin/atlasberg-credential without sudo) that prints the key by reading ~/.config/atlasberg/virtual-key or the Keychain, and point apiKeyHelper at it. For the managed configuration, write the file at the system path (macOS: /Library/Application Support/ClaudeCode/managed-settings.json; Linux and WSL: /etc/claude-code/managed-settings.json; Windows: C:\ProgramData\ClaudeCode\managed-settings.json) with an env block holding ANTHROPIC_BASE_URL and CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1, plus the apiKeyHelper. On a personal machine, put the variables in my shell profile and the apiKeyHelper in ~/.claude/settings.json.
b) Cursor: tell me exactly what to paste under Settings > Models: the key in the OpenAI API Key field and <gateway>/cursor/v1 in Override OpenAI Base URL. This is manual, do not try to automate it.
c) Codex, Continue, Cline, Aider and the OpenAI SDK: OPENAI_BASE_URL=<gateway>/openai/v1 and OPENAI_API_KEY=<key>.
d) Gemini CLI and Google SDK: GOOGLE_GEMINI_BASE_URL=<gateway>/genai and GEMINI_API_KEY=<key>.
e) Anthropic SDK: show the code snippet with base_url=<gateway>/anthropic.
f) If the CA is corporate: NODE_EXTRA_CA_CERTS pointing at the PEM, in the same place as the other variables.
g) Test, showing only a summary: GET <gateway>/health; POST <gateway>/anthropic/v1/messages with the key in the x-api-key header, anthropic-version 2023-06-01, model claude-sonnet-5 and max_tokens 32; GET <gateway>/api/governance/virtual-keys/quota with x-atlasberg-vk. On 401 virtual_key_required, 401 virtual_key_not_found, a 403 for the model, a 400 for the provider or a certificate error, explain what it means per the tutorial's table and what I need to ask the administrator for.
h) Open a new shell session and confirm the variables are loaded. Tell me that on the first run Claude Code will ask whether to use the key from the variable, and that the answer is yes.

Rules: never print the full key; when quoting it, use sk-atlas-... Do not configure a direct provider key. Do not disable certificate verification.

About Atlasberg Platform

Atlasberg Platform is the control layer between a company and every AI model: each request is authenticated with a virtual key, filtered by policy and DLP, routed to the right provider and written to a hash-chained audit trail. It exposes an OpenAI-compatible API, so applications only swap the base URL.

The same artifact runs in Atlasberg Cloud, in your VPC, on-premises or fully air-gapped, and is priced by capacity and modules, never per seat.

This page is part of the official documentation. To talk to the engineering team, write to [email protected] or use https://atlasberg.com/contato. Answers come within one business day.

Agents: this page is also available as Markdown at /docs/tutoriais/conectar-claude-code.md, or by requesting this URL with the header Accept: text/markdown. Index of everything: /llms.txt.