Skip to content

[BUG] headroom wrap claude + CLAUDE_CODE_USE_FOUNDRY not working #1076

Description

@noamgot

Description

I tried to use headroom within my organization's setup (claude code + litellm gateway), according to recent changes (see #726 ; these changes aren't documented btw...). I opened claude code with headroom wrap claude and prompted "how are you?". I got this response:

● API Error: Failed to get token from azureADTokenProvider: ChainedTokenCredential authentication failed.
  CredentialUnavailableError: EnvironmentCredential is unavailable. No underlying credential could be used. To troubleshoot, visit
  https://aka.ms/azsdk/js/identity/environmentcredential/troubleshoot.
  CredentialUnavailableError: ManagedIdentityCredential: Authentication failed. Message Attempted to use the IMDS endpoint, but it is not available.
  CredentialUnavailableError: Azure CLI could not be found. Please visit https://aka.ms/azure-cli for installation instructions and then, once installed,
  authenticate to your Azure account using 'az login'.
  CredentialUnavailableError: Error: Unable to execute PowerShell. Ensure that it is installed in your system. To troubleshoot, visit
  https://aka.ms/azsdk/js/identity/powershellcredential/troubleshoot.
  CredentialUnavailableError: Azure Developer CLI couldn't be found. To mitigate this issue, see the troubleshooting guidelines at
  https://aka.ms/azsdk/js/identity/azdevclicredential/troubleshoot.

To Reproduce

Steps to reproduce the behavior:

  1. Install headroom with uv tool install "headroom-ai[all]"
  2. set the following env-vars (in my case - in ~/.zshrc)
export ANTHROPIC_AUTH_TOKEN=...
export ANTHROPIC_API_KEY=${ANTHROPIC_AUTH_TOKEN}  # I added this later - still get the same error...
export ANTHROPIC_BASE_URL=https://my.org.litellm.gateway.com
export CLAUDE_CODE_USE_FOUNDRY=1
export ANTHROPIC_FOUNDRY_BASE_URL=https://my.org.litellm.gateway.com
  1. run headroom wrap claude
  2. prompt claude code anything (e.g. "how are you")
  3. See error

Expected Behavior

I expect the same experience as running vanilla claude

Actual Behavior

see above

Code Sample

irrelevant

Error Output

● API Error: Failed to get token from azureADTokenProvider: ChainedTokenCredential authentication failed.
  CredentialUnavailableError: EnvironmentCredential is unavailable. No underlying credential could be used. To troubleshoot, visit
  https://aka.ms/azsdk/js/identity/environmentcredential/troubleshoot.
  CredentialUnavailableError: ManagedIdentityCredential: Authentication failed. Message Attempted to use the IMDS endpoint, but it is not available.
  CredentialUnavailableError: Azure CLI could not be found. Please visit https://aka.ms/azure-cli for installation instructions and then, once installed,
  authenticate to your Azure account using 'az login'.
  CredentialUnavailableError: Error: Unable to execute PowerShell. Ensure that it is installed in your system. To troubleshoot, visit
  https://aka.ms/azsdk/js/identity/powershellcredential/troubleshoot.
  CredentialUnavailableError: Azure Developer CLI couldn't be found. To mitigate this issue, see the troubleshooting guidelines at
  https://aka.ms/azsdk/js/identity/azdevclicredential/troubleshoot.

Environment

  • Headroom version: headroom, version 0.26.0
  • Python version: 3.13.12
  • OS: Ubuntu 22.04
  • LLM Provider: Anthropic via LiteLLM

Additional Context

  1. I also tried running headroom proxy, here are the logs, maybe it'll help
Starting proxy server...

  URL:          http://127.0.0.1:8787
  Mode:         token
  Optimization: ENABLED
  Caching:      ENABLED
  Rate Limit:   ENABLED
  Memory:       DISABLED
  License:      OSS (no license key)
  Code-Aware:   DISABLED (--code-aware or HEADROOM_CODE_AWARE_ENABLED=1 to enable)
  Context Tool: rtk
  Extensions:   (none discovered)
  Telemetry:    DISABLED

Performance Tuning:  (all defaults — set HEADROOM_COMPRESSION_STABLE_AFTER_TURN / HEADROOM_STALE_READ_COMPRESS_AFTER_TURNS to tune)

Routing:
  /v1/messages                    → https://my.org.litellm.gateway.com
  /v1/chat/completions            → https://api.openai.com
  /v1/responses                   → https://api.openai.com  (HTTP + WebSocket)
  /v1internal:streamGenerateContent → https://cloudcode-pa.googleapis.com
  /v1/projects/.../publishers/... → https://us-central1-aiplatform.googleapis.com

Usage:
  Claude Code:   ANTHROPIC_BASE_URL=http://127.0.0.1:8787 claude
  Codex / OpenAI: OPENAI_BASE_URL=http://127.0.0.1:8787/v1 your-app

Endpoints:
  GET  /livez      Process liveness
  GET  /readyz     Traffic readiness
  GET  /health     Aggregate health
  GET  /stats      Detailed statistics
  GET  /stats-history Durable compression history + display session
  GET  /metrics    Prometheus metrics
  1. Using headroom wrap claude I see this line:
  Launching Claude Code (API routed through Headroom)...
  Foundry mode: ANTHROPIC_FOUNDRY_BASE_URL=http://127.0.0.1:8787 → upstream https://my.org.litellm.gateway.com

so it looks like the routing should work...

  1. Using either headroom wrap claude or headroom proxy followed by ANTHROPIC_BASE_URL=http://127.0.0.1:8787 claude, I noticed CC writes "Microsoft Foundry":
Image

To me it looks related to the Azure error we saw above (I know our litellm uses Amazon Bedrock's models, so it makes no sense to me that CC tries to access Azure...)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    HighCritical regressions and blockersbugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions