Corporate proxy or firewall
Everything Cardinal does from your computer goes to one place: your Cardinal address, the one in your install line. Nothing goes to any other server for Cardinal.
What needs to reach your Cardinal address
- The install line downloads
join.shorjoin.ps1, thencardinal-runner.mjs. - The installer fetches your settings block from
/api/setup/settings. - The runner asks for jobs at
/api/runner/polland sends answers to/api/runner/jobs/followed by the job number and/result. A poll can stay open for about 20 seconds while it waits for a job. - Claude Code sends telemetry to
/api/otel/v1/logsand/api/otel/v1/metrics. - Claude Code's session-end hook posts to
/api/hooks/session.
The connection must be secure: the installer refuses a Cardinal address that isn't, except on your own computer for testing.
Claude itself
Your claude still needs its own connection to Anthropic, as it does without Cardinal. Cardinal doesn't change that.
When a proxy gets in the way
- The installer says "couldn't download the runner": the download was blocked. Ask IT to allow your Cardinal address.
- A message that Cardinal answered with an error for the settings and to check your connection: the runner's Node.js couldn't reach Cardinal through the proxy. Node.js needs your proxy settings in its environment, and a company certificate needs
NODE_EXTRA_CA_CERTSpointing at the certificate file. Ask IT for both. - The runner's log shows repeated connection errors: it retries on its own, waiting longer each time, up to 5 minutes between tries.
Inspection and timeouts
Some proxies cut long requests. The runner's poll waits up to about 20 seconds, then a new one starts, so short cuts only slow jobs down.