Skip to main content
If you have a Claude Pro or Max plan, you can use that with Pullfrog instead of paying for Anthropic API tokens on top. Pullfrog runs Claude models through your subscription using the OAuth token Claude Code mints with claude setup-token.
Claude subscription auth is for Anthropic models specifically. For other providers, see BYOK or Pullfrog Router.

Setup

Run one command from inside your repo:
The CLI:
  1. Prompts you to run claude setup-token — it opens your browser, signs in with your Claude Pro/Max subscription, and prints a long-lived OAuth token (starting with sk-ant-oat…).
  2. Asks you to paste that token back.
  3. Stores a subscription connection in Pullfrog’s encrypted credential store.
That’s it. The next workflow run on this repo will use your Claude subscription instead of needing an Anthropic API key.
On org-owned repos, the CLI prompts you to pick a storage scope: account (shared across every repo your org owns) or repo (just this repo). User-owned repos always store at account scope.
Run the command again to add another subscription or replace a specific connection. Claude connections are identified by the last six characters of their setup token.

When to use this

  • You’re already paying for Claude Pro/Max and don’t want to also pay per Anthropic API token.
  • You want the simplest setup — one command, no API key management, no GitHub Actions secrets.
  • You’re OK with Anthropic’s usage policies applying to your usage.

How it works

Once stored, Pullfrog injects the token at the start of each workflow run and Claude Code uses it for all Anthropic model calls (claude-opus, claude-sonnet, claude-haiku, etc. — anything under the anthropic/ provider). If a subscription is exhausted or revoked, Pullfrog tries the next connection for the same model, including a supplied ANTHROPIC_API_KEY. Fallback order and multiple accounts. Unlike a ChatGPT Codex credential, the Claude OAuth token is static — claude setup-token mints a long-lived token (about a year) with no refresh chain, so nothing rotates mid-run and there’s no write-back. You shouldn’t need to re-run npx pullfrog auth claude until the token expires or you revoke it. The token lives on the workflow runner’s disk only for the duration of the job, in a location the agent itself cannot read. It’s never written to your repository, your GitHub Actions secrets, or anywhere else outside the encrypted Pullfrog store.

Troubleshooting

claude not found. Install the Claude Code CLI first — see Anthropic’s docs. Then re-run claude setup-token and npx pullfrog auth claude. Subscription exhausted or token revoked. If runs stop using your subscription, the token may have hit a usage limit or been revoked. Pullfrog logs a preflight line (401/429) and falls back to ANTHROPIC_API_KEY when one is configured. Re-run claude setup-token and npx pullfrog auth claude to refresh the credential.

See also

  • BYOK — bring your own provider keys for other models.
  • Codex subscription — the same flow for OpenAI models.
  • Grok subscription — the same flow for xAI models.
  • Models — all supported Anthropic models and other providers.
  • Pullfrog Router — the no-keys alternative; billed at raw provider cost.