Authentication and security
The extension does not handle login, authentication or credentials: the CLI does. It only
launches and drives claude.exe; sign-in and token storage stay entirely on the CLI side, exactly
as they would from a plain shell.
Signing in to Claude
Section titled “Signing in to Claude”Log in the normal way, from a terminal: run claude (or use Open Claude in Terminal / a CLI
pane) and follow the CLI’s own /login flow. The extension never sees or stores your credentials.
Using a provider
Section titled “Using a provider”A provider (GLM/z.ai, a gateway, any Anthropic-compatible host) authenticates through the usual
environment variables (ANTHROPIC_BASE_URL, ANTHROPIC_AUTH_TOKEN, …), set at the OS level or per
pane via profiles. See Another provider.
What is stored
Section titled “What is stored”Either way the extension holds no secrets of its own: it inherits whatever the CLI and the process environment provide.
See Settings and data for every file the extension writes and where.
No telemetry
Section titled “No telemetry”The extension sends no telemetry. Statistics are aggregated locally from the session files the CLI already writes on your machine: nothing is uploaded.
It makes one network request of its own: when a chat opens it asks the npm registry which version of Claude Code is the latest, to offer the update. It sends nothing but its own name and version. Everything else on the network is the CLI’s.