Supported harnesses
A harness is a program that sends model traffic through Gate on your behalf: a coding-agent CLI, a desktop or chat app, or an SDK. This page lists every one Gate has taken a position on, and what that position promises.
The three levels
- Certified — Gate’s test suite drives it against a real install, and a bug against it is a defect Gate fixes.
- Works — traffic reaches Gate and Gate can name it, but there is no command line for us to drive, so the Certified bar cannot be applied. Each row says what we verified and what we did not.
- Unsupported — traffic may still reach Gate and may still be named. No guide, no test, no promise.
Where an entry does not fully qualify for its level, the exception under its table says so. How it connects tells you what setup costs you: Gate Connect either writes the app’s own settings or routes its traffic through Gate for you, and where it says you point it at Gate yourself, the setup guide has the base URL to paste.
What Certified is tested against
Certified harnesses are driven through their real command line against a mock gateway on a clean machine, on the three platforms Gate ships to (macOS, Windows and Linux) and in both billing modes — paying through Gate, and bringing your own provider keys. That test suite runs outside this repository: this page records the result it reports, it does not measure it.
That is narrower than it sounds. It is not a first run against production, and not a run on a machine already carrying your own setup: your shell, your installed version, your existing credentials and your provider’s live behaviour are all outside what it covers.
Certified
| Harness | How it connects | Setup guide | Verified |
|---|---|---|---|
| Claude Code | Gate Connect sets it up for you | Claude Code | 2026-09-09 |
| OpenAI Codex CLI | Gate Connect sets it up for you | OpenAI Codex CLI | 2026-09-09 |
| OpenClaw | Gate Connect routes its traffic through Gate | OpenClaw | 2026-09-09 |
| OpenCode | Gate Connect sets it up for you | OpenCode | 2026-09-09 |
Exceptions — where an entry does not fully meet its level, in the manifest’s words:
- OpenClaw — OpenClaw lists a web_search tool of its own, but every call of that name we have seen came from Anthropic’s SDK, never from a request OpenClaw sent. Certified everywhere else, so the one unconfirmed tool name is published rather than hidden.
- OpenCode — We have not yet written the end-to-end walkthrough that follows OpenCode’s setup guide on a clean machine, so that one check is recorded as pending rather than claimed as done.
Works
No such run exists for the harnesses below, so read the row before you point a workload at it.
| Harness | How it connects | What we verified | What we have not |
|---|---|---|---|
| Anthropic SDK | You point it at Gate yourself | Pointing the SDK’s base URL at Gate’s /v1 endpoint reaches the gateway on Anthropic’s own /v1/messages wire. Gate records the traffic as Anthropic SDK in your dashboard. | No setup guide of its own: the wiring is the one the Claude Code guide documents. No automated run on every release: a library is not an install we can drive. |
| ChatGPT Desktop | Gate Connect routes its traffic through Gate | With the chatgpt-apps domain turned on in Gate Connect, the ChatGPT app’s chat traffic goes through Gate.Gate recognises the traffic as ChatGPT Desktop in your dashboard. | Codex Desktop’s model calls ride the same host but come from an embedded agent that ignores your machine’s proxy setting; they are not captured. No automated run on every release: there is no command line for us to drive. |
| ChatGPT for Web | Gate Connect routes its traffic through Gate | Gate recognises the traffic as ChatGPT for Web in your dashboard. Gate Connect offers a chatgpt domain you can turn on. | No automated run on every release: there is no command line for us to drive. Gate Connect describes that domain as the route for a ChatGPT subscription used through Codex rather than for the browser, so pairing it with the web app is our claim, not the app’s. |
| Claude for Desktop | Gate Connect routes its traffic through Gate | With the anthropic domain turned on in Gate Connect, the app’s traffic to Anthropic goes through Gate — confirmed against a real Cowork generation.Gate recognises the traffic as Claude for Desktop in your dashboard. | There is no command line for us to drive, so there is no release-by-release run against a real install. Anthropic’s telemetry host, a-api.anthropic.com, is passed through untouched and never inspected. |
| Claude for Web | Gate Connect routes its traffic through Gate | With the claude-web domain turned on in Gate Connect, claude.ai traffic goes through Gate.Gate recognises the traffic as Claude for Web in your dashboard. | No key brokering: claude.ai carries no API key at all, so Gate treats it as inspection and audit rather than routing. No automated run on every release: there is no command line for us to drive. |
| Hermes | Gate Connect routes its traffic through Gate | Pointing Hermes at Gate as a custom endpoint provider works in both billing modes: paying through Gate, and bringing your own provider keys. Gate Connect can set Hermes up for you, and our test suite drives a real Hermes install on macOS and Linux. | Windows: our test suite does not cover Hermes there. Attribution on a real install: Gate Connect names Hermes by writing a header into its config, and nothing in our suite has yet driven a real Hermes and seen that header arrive. Until it has, treat naming as designed rather than demonstrated. Attribution off the OpenAI wire: the header Hermes sends is documented as applying to OpenAI-compatible endpoints only, so a native-Anthropic or Bedrock setup routes through Gate exactly as before but is recorded without a name. Compression: Hermes’s tool names come from its own documentation; we have never seen them on traffic we could attribute to Hermes. |
| OpenAI SDK | You point it at Gate yourself | The OpenAI SDK setup guide and the dashboard’s connect tab carry the wiring for both billing modes. Gate records the traffic as OpenAI SDK in your dashboard. | No automated run on every release: a library is not an install we can drive. Traffic from apps Gate cannot recognise by name is recorded under this name. Hermes used to be the standing example and no longer is: Gate Connect now writes a header into its config that names it. |
| OpenAI apps | Gate Connect routes its traffic through Gate | With the openai domain turned on in Gate Connect, calls to OpenAI’s inference paths on api.openai.com /v1/ go through Gate. | Which app sent the request: the domain covers any client that honours your machine’s proxy setting, so traffic is recorded under the SDK it speaks rather than under an app. Codex is explicitly not covered: Gate Connect sets it up directly instead, and its embedded agent ignores your machine’s proxy setting. No automated run on every release: there is no command line for us to drive. |
| OpenCode Zen / Go | Gate Connect routes its traffic through Gate | With the opencode domain turned on in Gate Connect, OpenCode’s own Zen and Go endpoints on opencode.ai /zen/v1/* and /zen/go/v1/* go through Gate.Gate records the traffic under OpenCode in your dashboard. | Zen and Go are not told apart: they share one host, one upstream and one entry in your dashboard. No automated run of their own on every release, beyond the one that drives OpenCode itself. |
| OpenRouter apps | Gate Connect routes its traffic through Gate | With the openrouter domain turned on in Gate Connect, calls to openrouter.ai/api/v1/* go through Gate. | Which app sent the request: the domain covers any OpenRouter client that honours your machine’s proxy setting. No automated run on every release: there is no command line for us to drive. |
Exceptions — where an entry does not fully meet its level, in the manifest’s words:
- Hermes — Hermes’s tool names for compression come from its own documentation: we confirmed them on traffic from Anthropic’s SDK, never on a request we could attribute to Hermes.
- Hermes — Our test suite does not cover Hermes on Windows, so the Certified bar — every platform Gate ships to — is not met.
Unsupported
Traffic from these may still reach Gate through the machine-wide proxy setting, and Gate may still name it in your dashboard. Gate publishes no guide, runs no test and makes no promise about any of them.
- Aider — Detected in traffic only: nothing routes it, no guide, no test.
- Antigravity — Detected in traffic only: nothing routes it, no guide, no test.
- Cline — Detected in traffic only: nothing routes it, no guide, no test.
- Codex Desktop — Nothing can route it: its model calls come from an embedded agent that ignores your machine’s proxy setting. Route Codex through its command line instead, which Gate Connect sets up for you.
- Cody — Detected in traffic only: nothing routes it, no guide, no test.
- Continue — Detected in traffic only: nothing routes it, no guide, no test.
- Cursor — The work to route Cursor was never completed and certificate pinning may rule it out entirely. Gate still recognises Cursor traffic that reaches it by some other route.
- Gemini — Gemini support was added early on and then removed again, with no return scheduled. Gate can neither route Gemini traffic nor recognise it.
- Goose — Detected in traffic only: nothing routes it, no guide, no test.
- OpenHands — Detected in traffic only: nothing routes it, no guide, no test.
- Plandex — Detected in traffic only: nothing routes it, no guide, no test.
- Roo Code — Detected in traffic only: nothing routes it, no guide, no test.