What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
If your AI agent stopped working after you added an LLM gateway or corporate proxy, first identify whether the failure is in the API request, agent turn, session, or runtime. Then trace the credential and request through the process that launches the agent, the gateway, and the model provider. A gateway can introduce a second authentication boundary, a different endpoint or model route, and new network or TLS requirements.
Before changing settings, record the client and gateway versions, endpoint type, deployment surface, exact status and error, timestamp, model/provider, and a redacted request ID. Remove secrets and sensitive prompts, but preserve enough detail to match the request to gateway and provider logs.
Why did my AI agent stop working after I added a gateway?
The gateway changes the path between the agent and its model provider. It may authenticate the agent with one credential, then use a separate provider credential for the upstream request. It may also change the API endpoint, routing rules, model naming, network path, or TLS trust requirements.
Start by locating where the failure occurs rather than treating every error as a bad API key. OpenAI’s error and recovery guidance distinguishes request errors from failures after a turn starts and from session or environment errors.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- Request creation/API error: inspect the HTTP status and response
errorobject, including itscode,message, andparamwhen present. - Turn failure after acceptance: inspect the turn status and its error code and message.
- Session or runtime failure: inspect session and environment error details, including startup and connectivity problems.
- Tool or MCP initialization failure: identify the named tool/server that failed and check its configuration and credentials.
These categories narrow the investigation; they do not prove that the gateway itself is at fault. The status meanings in a gateway-mediated setup can also depend on which component generated the response.
Why am I getting a 401 after adding an LLM gateway?
A 401 usually makes credential flow the first thing to verify, but there may be two credentials: one the agent presents to the gateway and another the gateway uses with the provider. Anthropic explains that gateways can keep provider keys server-side while developers use gateway credentials in its LLM gateway documentation.
- Identify what the agent is meant to send. Confirm whether this route expects a gateway token, a provider key, or another credential. Do not assume the gateway token is the provider’s key.
- Check how the client reads it. Confirm the exact environment variable, configured header, or credential helper used by this client.
- Check the actual launching process. Verify that the credential is available to the shell, desktop app, service, worker, or container that runs the agent. A variable set in a terminal may not be inherited by a desktop app or service.
- Verify gateway-side access. Check whether the gateway accepts the credential for the relevant route, project, tenant, or organization.
- Verify upstream access. Check that the gateway has a valid provider credential and permission for the chosen model.
OpenAI’s Codex gateway connection guidance describes environment-variable, custom-header, and command-helper patterns. Deliver secrets through the organization’s secure mechanism; do not put them in committed TOML, source files, screenshots, terminal transcripts, or logs.
Rank #2
For Claude Code, an active gateway credential replaces the developer’s Claude subscription login for those requests, and billing is charged to the owner of the forwarded gateway credential. Setting ANTHROPIC_BASE_URL to a gateway does not by itself supply a gateway credential or guarantee that the subscription credential will be replaced. See Anthropic’s gateway documentation for the behavior and configuration details.
The API key works in my terminal but the agent still says unauthorized
Compare the process contexts, not just the secret value. The agent might be launched by a desktop app, service manager, container, or worker with a different environment from your interactive shell. Confirm that the expected credential name is present in that process, that any helper is executable and accessible there, and that the app or service was restarted after a configuration change. Never expose the credential value to prove it is present; use redacted diagnostics or check only the variable name and whether it is set.
Check header placement and endpoint type
Authentication headers are not interchangeable, and the right header depends on the endpoint family. For example, Cloudflare documents cf-aig-authorization for provider-native AI Gateway endpoints at gateway.ai.cloudflare.com, while its REST API uses the standard Authorization header. Its documentation distinguishes Cloudflare gateway authorization from upstream provider credentials. Check the actual endpoint and current authenticated gateway instructions rather than copying a recipe for another endpoint.
Rank #3
Check the expected scheme and spelling exactly. Authorization: Bearer …, x-api-key, and vendor-specific headers have different meanings. Look for duplicate, stale, or overridden authentication settings if the client has credential-precedence rules. If you inspect the outgoing request at the gateway edge, record header names and redact all credential values.
Why does the gateway return model not found?
Successful authentication does not guarantee correct routing. Check the base URL and path, API format, provider route, model identifier, and key selection. Cloudflare’s AI Gateway troubleshooting guide distinguishes provider-specific paths from its unified compatibility endpoint, which uses provider-prefixed model names.
- Confirm the client calls the intended host and endpoint path; remove secrets before sharing a URL.
- Check that the route targets the intended provider and API family.
- Compare the model spelling and any required provider prefix with the gateway’s route configuration.
- Verify the model is available to both the gateway account and the upstream provider.
- If the gateway has multiple bring-your-own-key (BYOK) credentials, confirm it selects the intended default key or alias.
Gateways vary in API-format and feature compatibility. If a tool or newer client feature breaks only after the gateway is inserted, check whether that gateway forwards the relevant API features and headers and whether its current compatibility guidance covers the client version. Anthropic notes that third-party gateways are not endorsed, maintained, or audited by Anthropic and that the organization operating one is responsible for keeping it compatible; see Anthropic’s gateway guidance.
Rank #4
How do I fix certificate or TLS errors behind a corporate proxy?
Test from the same runtime that launches the agent. A developer workstation’s successful DNS lookup or connection does not establish that a container, desktop app, or service can reach the same host. Check DNS resolution, egress rules, proxy allowlists, and reachability to the gateway and required provider endpoints.
For a certificate error, determine whether the corporate proxy performs TLS inspection and whether the runtime trusts the organization’s root certificate. Anthropic says Claude Code trusts bundled Mozilla and operating-system CA stores by default. Reading the OS store requires a runtime that supports tls.getCACertificates; for npm installations, the documentation specifies Node 22.15 or later. Its corporate network configuration guide identifies NODE_EXTRA_CA_CERTS as an option on older Node versions.
That Anthropic guide also documents basic proxy authentication through proxy URL configuration and describes disabling gzip request bodies when a TLS-inspection proxy mishandles compressed bodies. Those are Claude Code-specific settings; use the equivalent documentation for other agents. Avoid hardcoding proxy passwords in scripts; use environment variables or secure credential storage.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
Use logs and controlled tests to isolate the failing hop
Match the client timestamp and redacted request ID to gateway access/error logs and, where available, provider diagnostics. Establish whether the request reached the gateway, whether gateway authentication passed, which route and upstream key were selected, and what status the provider returned. Cloudflare recommends reviewing AI Gateway logs, checking provider credentials and provider status, and reviewing rate-limit settings when investigating timeout or request failures in its troubleshooting guide.
If you can, compare one redacted request through the gateway with a known-good provider-native request from the same runtime and network. Change one variable at a time—such as header placement, route, or model—so a changed error gives you useful evidence. Do not paste or print a secret; compare credential presence, scope, alias, header name, and permissions instead.
Match the symptom to the first checks
| Symptom | First checks | Evidence to inspect |
|---|---|---|
| 401 or unauthenticated | Credential availability in the launching process; expected header and scheme; gateway versus provider credential; scope and expiry | Client error body, gateway authentication log, and redacted final header names |
| 403 or forbidden | Account, project, model, route, or organization permission; gateway policy | Error code/message and gateway policy log |
| 404 or model not found | Base URL/path, provider route, model spelling and availability, required model prefix | Request URL with secrets removed, model field, and gateway routing log |
| TLS or certificate error | Runtime CA store, installed root CA, NODE_EXTRA_CA_CERTS, proxy inspection |
Runtime version, certificate chain, and proxy configuration |
| Timeout or connection failure | DNS, egress/allowlist, proxy reachability, provider status, rate limits | Client timeout, gateway logs, and provider status |
| Works in shell but not desktop app or service | Environment inheritance, credential-helper path and permissions, app/service restart | Launch context and effective environment-variable names, never secret values |
| New tool or feature fails after gateway insertion | Gateway API compatibility and forwarding of required headers/features | Current gateway compatibility guidance and request logs |
OpenAI’s error guidance identifies 401 unauthorized and 403 forbidden as authentication or access problems, 404/model-not-found as an unavailable resource or model, and 424 MCP startup failure as a server-configuration or credential problem. Connection errors and timeouts point toward connection or service failures. These are diagnostic categories, not proof of which component caused the problem.
Retry only after checking what the agent already did
Fix invalid credentials, missing permissions, incorrect endpoints, and billing limits before retrying. For a rate limit, overload, timeout, or temporary service failure, first check whether the agent created a session or turn, whether work was saved, and whether any tools or external actions completed. A failed turn may have side effects, so blindly rerunning an operation can duplicate work.
Recommended Free Tools
When a failure appears transient, honor the service’s retry timing and cap the number of attempts. OpenAI’s recovery guidance recommends checking saved work and completed actions before repeating an operation and limiting retries.
If the gateway itself is the problem
If logs show that the gateway rejects an otherwise valid request, cannot route the required API format, or fails to expose necessary diagnostics, evaluate alternatives against the way your organization operates agents. Anthropic describes gateway functions such as credential handling, usage tracking, cost controls, audit logging, and provider switching, while emphasizing the operator’s responsibility for compatibility in its gateway guidance.
Quick Recap
- Supported API formats and compatibility with current client features
- Credential delivery and header mapping for each deployment surface
- Provider/model routing, including aliases and BYOK key selection
- Log correlation, redaction, rate limits, and budget controls
- Deployment and maintenance work, including how quickly compatibility changes are documented
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

