Provider Protocol Smoke Test¶
Observed dynamically — Claude Code 2.1.177, artifact
eb073035…e40ed9. The real signed executable completed one text-only turn
against a loopback Anthropic-compatible endpoint in --bare --print mode.
Probe source · sanitized report · offline validator
Boundary sequence¶
sequenceDiagram
accTitle: Provider Protocol Smoke Test - Boundary sequence
accDescr: Diagram showing boundary sequence in the Provider Protocol Smoke Test section.
participant C as Claude Code 2.1.177
participant L as Loopback provider
participant O as stream-json stdout
participant F as Temporary home
C->>L: HEAD /
L-->>C: 200 reachability response
C->>L: POST /v1/messages
L-->>C: Synthetic text SSE stream
C->>O: system/init + system/status
C->>O: stream_event sequence
C->>O: assistant + result/success
C->>F: .claude.json + backup
Transport observations¶
The CLI first issued an unauthenticated HEAD / using the Bun/1.3.14 user
agent. It then sent one authenticated POST /v1/messages using
claude-cli/2.1.177 (external, sdk-cli). The credential itself was discarded;
the report retains only that x-api-key was present and authorization was
absent.
This ordering is scoped to this invocation. A separate
bare-and-safe runtime probe supplied a custom
system prompt and went directly to POST /v1/messages, establishing that the
reachability preflight is not universal without isolating which startup input
controls it.
The Messages request exposed these top-level fields:
context_management, max_tokens, messages, metadata, model, stream,
system, thinking, and tools.
The request advertised protocol families for Claude Code, interleaved thinking,
context management, and prompt-caching scope through anthropic-beta. The exact
header names and safe protocol values remain searchable in the report.
Content boundary
The three system blocks and two user-content blocks are represented by type, byte length, and SHA-256 only. The atlas does not publish their text.
Output stream¶
With partial messages enabled, the observed order was:
system/initsystem/statusmessage_startcontent_block_startcontent_block_delta- aggregate
assistant content_block_stopmessage_deltamessage_stopresult/success
The init record named the model, tools, agents, skills, plugins, MCP servers,
permission mode, output style, and CLI version as public SDK fields. This probe
disabled tools, so both the init tool list and API tools array were empty.
Filesystem observation¶
--no-session-persistence prevented a conversation transcript, but did not
make the invocation write-free. Under the new temporary home the process still
created:
.claude/.claude.json.claude/backups/.claude.json.backup.$EPOCH_MS
This narrows the meaning of the flag: it suppresses session persistence, not all application-state writes. The committed report stores only normalized relative paths, sizes, and hashes.
What this does not establish¶
- It does not show the authenticated OAuth path or third-party providers.
- It does not exercise retries, errors, tool calls, hooks, MCP, or compaction.
- A loopback endpoint cannot prove all production network destinations.
--bareintentionally omits several normal-mode customization paths.
Those are separate probes so each conclusion retains a small, reviewable test surface.