Rules

Proxy Only Your AI Tools: A Complete Clash Verge Rule List for Claude, ChatGPT, Gemini and Copilot

Both extremes are uncomfortable. Full-tunnel proxying slows down local sites, adds latency to games, and cuts off corporate hosts. No proxy at all and Claude Code, Cursor and Copilot simply do not connect. The middle path is an allowlist: send AI service domains and processes into a proxy group, leave everything else DIRECT.

What follows is the list and a paste-ready config, not another syntax tutorial. For syntax basics see rule routing; for where the rules go and how Merge is saved, see Merge custom rules.

The four-category model

Before the host lists, internalize the shape of every AI session, because it explains every entry below. A full session with any one service touches four categories of host, and a different symptom appears when each is missing:

Category What breaks if missing Example host
Web assets Blank or half-rendered UI oaistatic.com, claudeusercontent.com
API endpoints Tool cannot talk at all api.anthropic.com, generativelanguage.googleapis.com
Sign-in / auth Loads but will not log in platform.claude.com, auth.openai.com
Telemetry / updates Slow start, no error statsig.com, sentry.io

Allowlisting only the primary domain catches the first two and misses the last two—which is why "it opens but feels broken" is the most common report after a half-finished list.

Decide whether this is worth doing

Allowlisting and full-tunnel Tun solve different halves of the same problem. The Tun mode for AI tools article handles "the tool ignores my system proxy" — one switch, traffic captured at the virtual adapter, every CLI and editor covered at once. This article handles what happens after capture: which flows should go out and which should stay local.

Three situations justify the effort. Limited node bandwidth, where you do not want cloud-storage downloads and OS updates eating the tunnel. Latency-sensitive gaming on regional servers, where a proxy hop turns 30ms into 80ms. A corporate intranet alongside a VPN, where proxied DNS stops resolving internal hosts. Outside those three, enable Tun and move on.

The opposite requirement — proxy is already on, and you want games and downloads pulled back out — lives in DIRECT rules for games and downloads. The two sets coexist in one Merge file: the allowlist pushes AI traffic out, the denylist pulls heavy traffic back, and the subscription rules cover the rest.

The domain list, grouped by purpose

The usual failure is allowlisting only the primary domain. A full session with any AI service touches four categories: web assets, API endpoints, sign-in and auth, and telemetry or updates. Missing the first two produces obvious errors. Missing auth produces "loads but will not log in". Missing telemetry produces no error at all — just a slow start.

Anthropic / Claude

Host Purpose Symptom if blocked
api.anthropic.com Claude API requests, WebFetch domain safety check, feature flags Claude Code cannot talk at all
claude.ai Web app and account authentication Web app will not open
claude.com Sign-in entry page, redirects to claude.ai Blank page after clicking log in
platform.claude.com Console auth; OAuth token exchange, refresh and revocation also land here, including for claude.ai accounts Stuck at sign-in, or logged out after a while
statsig.anthropic.com Feature flags and telemetry First command can hang for minutes before responding
mcp-proxy.anthropic.com MCP connector traffic for claude.ai accounts Connectors unavailable
downloads.claude.ai Native installer, auto-updater, plugin downloads Updates fail (not needed for npm installs)
assets-proxy.anthropic.com, claudeusercontent.com Desktop and web app assets, Artifacts Blank UI instead of an error
sentry.io Error reporting Optional, safe to leave out

platform.claude.com is the one people skip. The name suggests it only matters for API console users, but claude.ai subscription accounts refresh their OAuth tokens through the same host. Three suffix rules — anthropic.com, claude.ai, claude.com — cover nearly the whole table.

OpenAI / ChatGPT

Host Purpose
chatgpt.com, chat.openai.com Web app (the older host still sits in the redirect chain)
openai.com, including api.openai.com and platform.openai.com API endpoints and developer platform
auth.openai.com, auth0.openai.com, setup.auth.openai.com Sign-in and auth
cdn.workos.com, setup.workos.com, forwarder.workos.com, workos.imgix.net Enterprise SSO flow
challenges.cloudflare.com, tcr9i.chat.openai.com Human verification
oaistatic.com Front-end static assets
oaiusercontent.com Uploaded files and generated content
statsig.com, statsigapi.net, featuregates.org, featureassets.org Feature flags
ios / android / desktop.chat.openai.com Native clients
o33249.ingest.sentry.io, rum.browser-intake-datadoghq.com Error and performance reporting, optional

challenges.cloudflare.com deserves attention. It is not an OpenAI host at all, and a large share of "stuck on the human verification spinner" reports come down to that check exiting from a different IP than the session. Match it with an exact DOMAIN rule rather than a suffix, so you do not drag all of cloudflare.com into the tunnel. If chat works but uploads fail, oaiusercontent.com is missing.

Google Gemini

Host Purpose
gemini.google.com Web app
generativelanguage.googleapis.com Gemini API, the main Gemini CLI endpoint
cloudcode-pa.googleapis.com Code Assist auth path used by Gemini CLI
accounts.google.com, oauth2.googleapis.com Google account sign-in and OAuth
apis.google.com, www.googleapis.com General Google API calls
jnn-pa.googleapis.com, waa-pa.clients6.google.com Gemini app integrity checks
storage.googleapis.com Model and asset delivery
gstatic.com, googleusercontent.com Static assets and images

Gemini leans on the login path harder than the others — if the Google account will not sign in, nothing else matters, so accounts.google.com and oauth2.googleapis.com are mandatory. Region errors after the rules are correct are a node problem, not a rule problem; see Gemini region troubleshooting.

GitHub Copilot and Cursor

Host Purpose
github.com/login/, github.com/copilot/ Authentication and Copilot on the web
api.github.com (/user, /copilot_internal/) User and subscription data
api.individual / api.business / api.enterprise.githubcopilot.com Plan-specific suggestion endpoints, in effect since February 2026
copilot-proxy.githubusercontent.com API service for Copilot suggestions
copilot-telemetry.githubusercontent.com Client telemetry
default.exp-tas.com Client experimentation
github.githubassets.com, avatars.githubusercontent.com Authentication page assets
api2 / api3 / api5 / repo42.cursor.sh Cursor main API, Tab completions, agent requests, codebase indexing
authenticate.cursor.sh, authenticator.cursor.sh Cursor login webview and token issuer
marketplace.cursorapi.com, cursor-cdn.com, downloads.cursor.com Extension marketplace and client updates

default.exp-tas.com is the classic Copilot omission. It only carries experimentation flags, which sounds skippable, yet when it is unreachable Copilot Chat goes unresponsive and the diagnostics panel reports HTTP 400 against that host. Cursor documents wildcards on purpose — cursor.sh, cursorapi.com and cursor-cdn.com — because its subdomains grow with new features and an itemized list falls behind. More Copilot symptoms in Copilot login and completion fixes.

Missing-host quick reference

When a tool misbehaves, match the symptom to the missing category instead of guessing:

Symptom Most likely missing host
App opens, sign-in spins forever platform.claude.com / auth.openai.com / accounts.google.com
UI renders but images/artifacts blank claudeusercontent.com / oaistatic.com / googleusercontent.com
Chat works, file upload fails oaiusercontent.com
First command hangs minutes, then runs statsig.* / featuregates.org telemetry
Stuck on human-verification spinner challenges.cloudflare.com (route with exact DOMAIN)
Copilot Chat unresponsive, HTTP 400 in logs default.exp-tas.com

Three ways to write the same rule

  • DOMAIN-SUFFIX / DOMAIN — precise and readable. A suffix covers subdomains, so anthropic.com alone picks up api, statsig and mcp-proxy. The cost is maintenance when hosts change.
  • RULE-SET via rule-provider — someone else maintains the list and you inherit updates. The cost is an extra network dependency, undefined behaviour when the provider fails to fetch, and rules you cannot read while debugging.
  • PROCESS-NAME / PROCESS-PATH — "everything this binary sends goes to the proxy". Least maintenance for CLIs, with prerequisites covered below.

The combination that holds up: domain rules on top for exact matches, process rules underneath as a safety net for endpoints you have not catalogued yet.

Three traps with process names

Names differ per platform. Windows carries the extension (claude.exe, codex.exe, Cursor.exe); macOS and Linux do not. A config shared across machines needs both spellings.

An npm-installed CLI may not run under its own name. Claude Code now ships a native installer that drops a standalone claude binary in the user directory, but older npm installs and wrapper paths issue requests as node. Gemini CLI is an npm package and behaves the same way. Writing PROCESS-NAME,node works and simultaneously proxies every other Node program on the machine, including your local dev server — PROCESS-PATH pointing at the specific binary is the safer form.

Process matching also needs the core to see process ownership. Tun mode or an installed service/helper is the dependable path; system proxy alone does not always populate it. Check find-process-mode too: strict is the default, always forces lookups, and off disables matching entirely. Router configs frequently ship with off, and copying one silently kills every process rule.

Paste-ready YAML

Get the entry point right or none of this fires: v1.6.x accepted prepend-rules and prepend-proxy-groups inside Merge, but since v1.7.x Merge became Extended Configuration, which the official docs limit to key-value override — list values are replaced wholesale, and prepend/append now live in the profile's right-click Edit Rules / Edit Proxy Groups editors. So the config below is split into the two places you actually paste it.

First, in Edit Proxy Groups, prepend area, define a manual group:

  - name: AI
    type: select
    proxies:
      - PROXY            # replace with a group or node that exists in your subscription
      - DIRECT

Second, in Edit Rules, prepend area — the listed order is the match order:

  # --- 1. Loopback and intranet always come first ---
  - IP-CIDR,127.0.0.0/8,DIRECT,no-resolve
  - IP-CIDR,10.0.0.0/8,DIRECT,no-resolve
  - IP-CIDR,172.16.0.0/12,DIRECT,no-resolve
  - IP-CIDR,192.168.0.0/16,DIRECT,no-resolve
  - DOMAIN-SUFFIX,corp.example.com,DIRECT    # your intranet suffix

  # --- 2. Anthropic / Claude: three suffixes cover API, auth, updates ---
  - DOMAIN-SUFFIX,anthropic.com,AI
  - DOMAIN-SUFFIX,claude.ai,AI
  - DOMAIN-SUFFIX,claude.com,AI
  - DOMAIN-SUFFIX,claudeusercontent.com,AI

  # --- 3. OpenAI / ChatGPT ---
  - DOMAIN-SUFFIX,openai.com,AI
  - DOMAIN-SUFFIX,chatgpt.com,AI
  - DOMAIN-SUFFIX,oaistatic.com,AI
  - DOMAIN-SUFFIX,oaiusercontent.com,AI
  - DOMAIN-SUFFIX,workos.com,AI              # enterprise SSO
  - DOMAIN-SUFFIX,statsig.com,AI             # feature flags
  - DOMAIN-SUFFIX,statsigapi.net,AI
  - DOMAIN-SUFFIX,featuregates.org,AI
  - DOMAIN-SUFFIX,featureassets.org,AI
  - DOMAIN,challenges.cloudflare.com,AI      # human check, exact match only

  # --- 4. Google Gemini: the login path must go with it ---
  - DOMAIN-SUFFIX,gemini.google.com,AI
  - DOMAIN-SUFFIX,aistudio.google.com,AI
  - DOMAIN-SUFFIX,generativelanguage.googleapis.com,AI
  - DOMAIN-SUFFIX,cloudcode-pa.googleapis.com,AI
  - DOMAIN-SUFFIX,accounts.google.com,AI
  - DOMAIN-SUFFIX,oauth2.googleapis.com,AI
  - DOMAIN-SUFFIX,apis.google.com,AI

  # --- 5. GitHub Copilot ---
  - DOMAIN-SUFFIX,githubcopilot.com,AI
  - DOMAIN-SUFFIX,exp-tas.com,AI
  - DOMAIN,copilot-proxy.githubusercontent.com,AI
  - DOMAIN,copilot-telemetry.githubusercontent.com,AI
  - DOMAIN,api.github.com,AI
  - DOMAIN-SUFFIX,github.com,AI

  # --- 6. Cursor: wildcards are the documented approach ---
  - DOMAIN-SUFFIX,cursor.sh,AI
  - DOMAIN-SUFFIX,cursor.com,AI
  - DOMAIN-SUFFIX,cursorapi.com,AI
  - DOMAIN-SUFFIX,cursor-cdn.com,AI

  # --- 7. Process catch-all for endpoints not yet listed ---
  - PROCESS-NAME,claude,AI
  - PROCESS-NAME,claude.exe,AI
  - PROCESS-NAME,codex,AI
  - PROCESS-NAME,codex.exe,AI
  - PROCESS-NAME,Cursor,AI
  - PROCESS-NAME,Cursor.exe,AI

Three things you must edit. The proxies list under the AI group has to reference a group or node that actually exists in your subscription, since a wrong name can stop the profile loading. Replace corp.example.com with your intranet suffix, or delete the line. Verify the process names against how you installed each tool — an npm-installed Gemini CLI needs node or a PROCESS-PATH entry.

Notice there is no MATCH and no GEOIP,CN,DIRECT here, deliberately. A catch-all inside the prepend area discards the entire provider rule set behind it, leaving you with a hand-written and incomplete routing table. Let the subscription own the final rule.

Using a remote rule set instead

rule-providers is a map rather than a list, so it can go straight into the Extended Configuration; the line that references it still belongs in the Edit Rules prepend area.

rule-providers:
  ai-services:
    type: http
    behavior: classical
    format: yaml
    url: "https://your-chosen-ruleset.yaml"
    path: ./ruleset/ai-services.yaml
    interval: 86400

Then add one line in the Edit Rules prepend area:

  - RULE-SET,ai-services,AI

Copy the URL from the rule repository yourself instead of from any article — these paths move, and a dead URL looks exactly like "my rule was ignored". behavior has to match the set: classical accepts full rule syntax, domain accepts hostnames only, and a mismatch fails to parse. Keep a handful of hand-written DOMAIN-SUFFIX lines alongside the provider so a failed fetch does not take you offline.

Rule order, the number one reason nothing happens

Clash evaluates top-down and stops at the first match. That single behaviour explains most "my rule does not work" reports: something broader above it got there first.

  1. Loopback and intranet DIRECT at the very top.
  2. AI domain rules next, which must land before the provider GEOIP and MATCH lines — the Edit Rules prepend area gives you this for free.
  3. Process rules after the domain rules, since process lookups cost more than domain matching.
  4. Everything else stays with the subscription: local direct routing, ad blocking, and the final catch-all.

The classic mistake is appending AI rules to the end of the config, or using the append area. That position sits after GEOIP and MATCH, where the catch-all has already claimed the traffic. When DIRECT rules share the same prepend area, put the more specific line higher — between PROCESS-NAME and DOMAIN-SUFFIX, position is the only tiebreaker.

Proving a rule actually matched

  1. Save the edit and reload the config. Saving alone changes nothing.
  2. Open Connections and clear the existing list.
  3. Trigger one real request: send a message in Claude Code, or ask Cursor for a completion. A ping or a browser homepage may take a different path.
  4. Find that connection and read the rule column. DOMAIN-SUFFIX,anthropic.com with the AI group means your rule won. GEOIP or MATCH means the catch-all beat you — go back to ordering.
  5. For more detail, set the log level to info; each connection logs the matched rule and the policy used. When the log and the Connections page disagree, trust the log.

No entry at all means the traffic never reached Clash, which is a system proxy or Tun problem rather than a rules problem — see system proxy not working. An entry that reached the AI group and still failed points at the node; switch regions and follow the layered checks in Claude Code proxy setup. Reading logs: log troubleshooting.

Per-tool verification

After reloading, confirm each tool actually exits through the AI group. One real action per tool, then read the rule column:

Tool Action Expected host in Connections
Claude Code Send a chat message api.anthropic.com → AI group
ChatGPT web Open the app and send one message chatgpt.com, oaiusercontent.com → AI group
Gemini CLI Run one prompt generativelanguage.googleapis.com → AI group
Copilot Trigger one completion api.githubcopilot.com or copilot-proxy.githubusercontent.com → AI group
Cursor Ask for a Tab completion api2.cursor.sh → AI group

If a row shows GEOIP or MATCH instead of the AI group, the prepend did not land ahead of the subscription rules—revisit rule order. If the request never appears, the tool is not honoring the system proxy; that is a system proxy issue, not a rules issue.

The list expires, so learn to capture your own

Expect a few months of shelf life. GitHub changed the Copilot coding agent network configuration in February 2026, splitting the endpoint by subscription plan across api.business, api.enterprise and api.individual.githubcopilot.com, which broke allowlists pinned to api.githubcopilot.com.

Capturing is simple: clear the Connections list, perform exactly one action — one sign-in, one message, one completion — and read off the new hostnames. One action at a time is the whole trick; with three tools open you cannot tell which connection belongs to what. Add a suspicious host to the AI group, confirm the flow works, then move entries back to DIRECT one at a time to find which ones were genuinely required. That bisection leaves you with rules you understand, which matters more than the line count.

Telemetry hosts (statsig, sentry, telemetry endpoints) fail quietly rather than loudly — the symptom is a slow start or an occasional stall, no error. When something "works but feels slow", suspect that category before swapping nodes.

When to stop

Three acceptance checks: AI tools sign in and respond; local sites, downloaders and games show DIRECT in Connections; intranet hosts resolve and load. Once all three pass, stop adding rules. Every extra preventive line makes the next diagnosis harder.

Copy the Merge text somewhere safe before editing so a bad session costs one paste to undo. Once the rules settle, back up the config — this list is harder to rebuild from memory than a subscription URL. Older client builds may not support every rule type; builds are in the download center.

Rules need a core that understands them

PROCESS-NAME and rule-provider syntax rely on a recent Mihomo core. Grab the current Clash Verge Rev build from the download center before pasting this YAML.