Your Claude or ChatGPT plan on a server: what's allowed
Signing in to Claude Code or Codex with your own plan on a server is allowed. What the labs' terms bar, what risks your account, and where CLIProxyAPI stands.
Yes, when it is the labs’ own tool, signed in by you, for your own work. Anthropic’s terms for Claude Code say that its rules do not prevent an end user from signing in to the unmodified Claude Code with their own Claude subscription, including where a platform hosts Claude Code. OpenAI’s Codex documentation describes signing in on a remote machine. Neither lab’s terms for its own tool make the location of the machine a condition. What puts an account at risk is what happens to the sign-in: a Claude subscription token stored by a tool other than Claude Code, a proxy that serves your plan as an API to other tools, or a login shared with someone else. Anthropic reserves the right to enforce its rules “without prior notice.”
What Anthropic’s terms say
The rules for using a Claude plan with Claude Code are on Anthropic’s legal and compliance page. As read on 5 October 2026, it says four things a person with a server needs to know.
- A hosted machine is covered. The rules do not prevent “an end user from signing in to the unmodified Claude Code binary with their own Claude subscription, including where a platform hosts Claude Code.”
- The sign-in is for Anthropic’s own apps. Subscription sign-in is “designed to support ordinary use of Claude Code and other native Anthropic applications.” The same page bars third-party developers from routing requests through Pro or Max credentials for their users, and says developers “may not collect, store, or intermediate Claude.ai credentials or session tokens.”
- The limits are for one person. “Advertised usage limits for Pro and Max plans assume ordinary, individual usage of Claude Code and the Agent SDK.”
- Enforcement may come without warning. Anthropic “reserves the right to take measures to enforce these restrictions and may do so without prior notice.”
Anthropic’s Consumer Terms, which govern Pro and Max, add that you may not share your login or credentials or make your account available to anyone else. They let Anthropic suspend or end access without notice if it believes the terms were materially breached, and a subscription ended for a material breach is not refunded.
Anthropic documents scripts on a subscription: its authentication docs offer a one-year token for “CI pipelines, scripts, or other environments where interactive browser login isn’t available.” What the token is and what it can’t do is in the setup-token guide.
What OpenAI’s terms say
OpenAI’s Codex authentication docs name two ways in: “Sign in with ChatGPT for subscription access” and an API key for usage-based access. For a remote or headless machine they recommend device code sign-in, still labelled beta: codex login --device-auth, after a switch in your ChatGPT security settings that the device-code guide walks through. The login lands in ~/.codex/auth.json, which OpenAI says to treat “like a password.”
On automation the two labs differ. OpenAI’s page on account sign-in in CI opens with “The right way to authenticate automation is with an API key,” and offers running a pipeline as your ChatGPT account only as an advanced workflow “for enterprise and other trusted private automation.” Codex you drive yourself on a server is the ordinary case; a job that runs Codex unattended on your plan is the exception.
OpenAI’s Terms of Use say: “You may not share your account credentials or make your account available to anyone else and are responsible for all activities that occur under your account.” Among the things you may not do: “circumvent any rate limits or restrictions.”
Sign in with ChatGPT, OpenAI’s programme for other apps to use your plan, has terms of its own, and they do bear on location. OpenAI’s Sign in with ChatGPT Terms say: “Any persistent storage of Authentication Tokens must be local and under the user’s control, not in a remote or managed environment.” How that bears on OpenClaw on a server is in the OpenClaw and ChatGPT subscription guide.
What puts an account at risk
None of the clauses on the labs’ own tools is about where the machine is. Of the public reports of banned accounts we found in early October 2026, none rested on a server’s address alone: each also involved a key shared with a team, many accounts, a third-party client, or a VPN. The risks are about the sign-in:
- Your Claude token in another tool. A subscription token pasted into a tool other than Claude Code has that tool store your subscription token, which Anthropic’s terms bar third-party developers from doing. OpenClaw is the common case, covered in the OpenClaw and Claude subscription guide.
- A proxy that serves your plan as an API. CLIProxyAPI, an open-source project, is the best known: it runs the Claude and Codex sign-ins itself, keeps the tokens, and answers API calls from any other tool on your subscription, with load balancing across several accounts. Its own settings describe disguising its requests as the official clients. It is not the unmodified Claude Code signing in. Set beside it: Anthropic’s page says Claude.ai credentials and session tokens may not be stored or intermediated, and that the plans’ limits “assume ordinary, individual usage”; OpenAI’s terms bar circumventing its rate limits.
- A login used by more than you. A server a team shares, signed in to one person’s plan, is an account made available to others under both labs’ terms.
Many sessions at once on your own plan is a use Anthropic builds for: agent teams and Projects start several sessions themselves. They all draw on the one plan’s limits, which is how heavy use is metered. Running an orchestrator over many sessions covers that setup.
Signing in on a server
Claude Code signs in on a server the way it does on a laptop: run claude, open the link in any browser, and when the browser shows a code instead of returning, paste it at the terminal’s prompt, which Anthropic says is “common in WSL2, SSH sessions, and containers.” On Linux the login is kept in ~/.claude/.credentials.json, readable only by you. Remote Control needs this full login; a setup-token can only make model requests. A session that outlives its login “stops making progress once the credential expires,” so a machine that runs sessions unattended needs its login renewed before then.
Codex signs in with codex login --device-auth, as above.
On a machine someone else hosts, the same holds as long as the sign-in is yours and the host never handles it. A host that installs Claude Code for you is bound by the same Anthropic page: it must leave the binary unmodified and every sign-in method in place, and each user must authenticate with their own credentials. On Everpod’s developer pod, Claude Code, Codex or both come installed, and you sign in to each with your own subscription or API key. No model usage is included, and your sign-ins never pass through us.