Configure proxy, certificates, DNS, and browser behavior for Qoder CLI CN
Qoder CLI CN needs network access for authentication, model inference, web search/fetching, and more. In corporate intranets, proxied environments, or restricted networks, you may need to configure a proxy, certificates, or custom DNS behavior for it. This page covers the relevant environment variables and configuration.Most network settings are controlled by standard environment variables, so you can carry over the network configuration habits you already have in your terminal.
The proxy is read at startup; restart Qoder CLI CN after changes.
Both cases (e.g. HTTPS_PROXY and https_proxy) are recognized; some tools require the lowercase form.
When qoderclicn is launched through the Agent SDK or a desktop integration, an explicit SDK proxy option takes precedence. If it is omitted and advanced.useProxyFromEnvironment is enabled (the default), qoderclicn uses the inherited proxy environment variables for its own outbound requests. Disable that setting to force a direct connection.
In networks using self-signed certificates or corporate root certificates, specify additional trusted certificates via the standard Node.js environment variables:
Variable
Description
NODE_EXTRA_CA_CERTS
Path to an additional CA certificate file (PEM format).
If certificate verification fails (such as unable to verify the first certificate), you usually need to point the variables above at the correct root certificate.
For environments with special DNS resolution order requirements, set the resolution order with the advanced.dnsResolutionOrder setting (such as preferring IPv4 or following the system order). This setting requires a restart after changes.
Flows such as sign-in authentication try to open a browser to complete the callback by default. The CLI automatically detects environments without a graphical interface and skips launching the browser, printing a link you can copy manually instead — an environment is treated as headless if any of the following holds:
CI is set;
BROWSER=www-browser;
DEBIAN_FRONTEND=noninteractive;
inside an SSH session (SSH_CONNECTION);
on Linux, none of DISPLAY, WAYLAND_DISPLAY, or MIR_SOCKET is set.
So no extra configuration is needed in SSH remote sessions, containers, or CI environments. For authentication details, see Sign-in and Authentication.
Connection timeouts or unreachable: confirm the proxy variables are set correctly and NO_PROXY doesn't miss required internal domains.
Certificate errors: configure NODE_EXTRA_CA_CERTS to point at the corporate root certificate.
Browser won't open during sign-in: in headless environments the CLI automatically skips launching the browser and prints the login link — copy it into a browser manually; you can also switch to Personal Access Token authentication.