Rye supervision workbench
Troubleshooting
Diagnose missing traffic, CA trust failures, authentication issues, and policy behavior in Rye.
Diagnostic order
Start with the runtime path. Every local failure usually lands in one of four places: the agent process was not launched through Rye, the proxy is not active, CA trust is missing, or policy rejected the request.
Primary local health check
rye doctorrye doctor should be the first command for local issues. It checks auth, daemon state, proxy routing, CA trust, and connectivity before you chase tool-specific behavior.
Failure signatures
No traffic appears
The usual cause is process timing. If Claude Code, Codex, Cursor, or another agent started before Rye, it may keep using its original environment.
rye status
rye history --last 15mTLS or certificate errors
TLS failures mean the model client does not trust Rye's local inspection certificate for the intercepted provider host.
rye up --install-ca --intercept-patterns openai.com,anthropic.com,claude.com,chatgpt.com,cursor.com,windsurf.comRequests are blocked
A block is a successful policy decision, not a proxy failure. Read the decision record before changing local configuration.
rye history --last 15mDevice is rejected
Device rejection means Rye can see the local runtime, but the workspace does not trust this workstation for supervised traffic.
rye auth loginPolicy evidence
Recovery loop
- Run
rye doctor. - Confirm the agent was launched after Rye.
- Check
rye history --last 15m. - Inspect the policy decision if the request was blocked.
- Restart the supervised agent after any proxy, CA, or environment change.