OAuth token expired / refresh failed
The stored OAuth token lapsed and the refresh did not recover it.
344 issues · 91 open · 253 resolved (74%) · first seen May 7, 2025
First response · account
What to do now
Most likely: Authentication, usage state or session size blocked the request.
- Check the exact account, organization and usage window currently selected.
- Try a new short session before deleting credentials or local history.
- If the state is inconsistent across machines, preserve diagnostics and re-authenticate once.
These are conservative triage steps, not an official Anthropic fix. Use the issue and workaround evidence below before making a destructive configuration change.
Is this getting better or worse?
This class of problem is holding steady. 119 new reports in the last 90 days vs 116 in the 90 before — +3%. The open backlog peaked at 91 in 2026-08 and sits at 91 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
191 of these reports name the Claude Code build they were running, spanning 103 releases. Heaviest reporters:
- Claude Code v2.1.220
- Claude Code v2.1.229
- Claude Code v2.1.39
- Claude Code v2.1.119
- Claude Code v2.1.203
- Claude Code v2.1.177
- Claude Code v2.1.218
- Claude Code v2.1.198
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 7 days across 253 closures. Of the 253 closures with a recorded reason, 17% were closed as completed and 210 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
116 of these issues post a workaround someone says worked. The highest-engagement ones:
- [FEATURE] Enable Claude Code to access chat history in Claude App
- …opt-in, no sync needed in the other direction. The current workaround (manually summarizing and pasting context) defeats the entire purpose of persistent memory and cross-session continuity that Anthropic is actively bu…
Found in the thread of #15542 · still open - Missing Token Refresh Mechanism for MCP Server Integrations
- …ll, it's an option. I notice Linear's MCP server chose that workaround too: their access tokens expire in 7 days by default. But I don't think it's the right solution, and neither do the MCP protocol authors, [who say](…
Found in the thread of #5706 · resolved - Frequent re-authentication required with multiple concurrent Claude Code sessions (OAuth refresh token race condition)
- …rocesses share a single token manager that handles refresh. Workaround Currently, the only workaround is to close stale Claude Code sessions to reduce the number of concurrent processes competing for token refresh. This…
Found in the description of #24317 · resolved - [BUG] OAuth token expiration disrupts autonomous workflows – refresh token handling needed
- …t working, giving the same error message again Update: Temp workaround is to go to the folder and start Claude CLI with , then continue the session from there.
Found in the thread of #12447 · still open - [BUG] OAuth error: timeout of 15000ms exceeded can not login it keeps timout even though I tried token too
- I found a workaround for this issue. I used the binary from a previous version (2.1.50), which can be found in ~/.local/share/claude/versions. I logged in using that version, and once the authentication was successful, I…
Found in the thread of #33214 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–100
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 344 matches; the statistics above cover all 344.
- [FEATURE] Enable Claude Code to access chat history in Claude App
- Missing Token Refresh Mechanism for MCP Server Integrations
- Frequent re-authentication required with multiple concurrent Claude Code sessions (OAuth refresh token race condition)
- [BUG] OAuth token expiration disrupts autonomous workflows – refresh token handling needed
- [BUG] OAuth error: timeout of 15000ms exceeded can not login it keeps timout even though I tried token too
- [BUG] MCP OAuth tokens without expires_in and refresh_token silently expires
- [BUG] Claude Code MCP client ignores scopes_supported from OAuth protected resource metadata, preventing refresh token issuance
- [BUG] MCP OAuth: Claude doesn't auto-refresh access tokens, daily "Connection expired" despite valid refresh token
- [BUG] OAuth Authentication Succeeds but MCP Reconnection Fails - Requires Restart
- [Bug] OAuth token expiration causing repeated 401 authentication errors during active sessions
- [BUG] OAuth credentials shared across CLAUDE_CONFIG_DIR profiles causing data isolation failure (compliance risk)
- MCP OAuth token refresh not persisting for Notion MCP server
- Linear MCP OAuth fails with "Invalid client" — metadata-URL clientId + ephemeral loopback port
- [BUG] Can't authenticate on individual account - OAuth error
- [BUG] OAuth Authorize button returns 500 Internal Server Error — cannot login to Claude Code in VSCode
- [Bug] OAuth callback timeout causes "Failed to fetch user roles" error
- OAuth token expired immediately after fresh login - cannot use Claude Code (blocking)
- [BUG] OAuth refresh returns 400 after early 401 before local expiresAt; concurrent sessions forced to /login
- MCP OAuth tokens not auto-refreshing despite valid refresh tokens
- MCP OAuth tokens expire frequently, requiring manual /mcp reconnect
- Feature request: lossless context cleanup before auto-compaction
- login oauth keeps failing! cant login!
- Claude Code login fails with service unavailability and rate limit errors
- [BUG] macOS Keychain: security -i 4096-byte line buffer causes credential corruption with MCP OAuth plugins
- [BUG] Omits OAuth resource parameter required by MCP 2025-06-18
- OAuth refresh token not used when credentials are copied to remote/headless machines
- Allow configurable session/auth token TTL to prevent daily re-login
- Bug: /login Does Not Recover Active Session After OAuth Token Expiration
- [BUG] claude --teleport shows non-helpful error message if OAuth token has expired
- when I start again with working after a night of rest I...
- [BUG] Login authenticates but has_finished_claudeai_onboarding=false walls existing paid Max account behind new-account onboarding (web/desktop/setup-token) — 10th public report of this signature, first with the mechanism captured on the wire
- [BUG] Claude Code v2.1.92 - OAuth token always expired after login
- [Bug] Anthropic API Error: 500 Internal Server Error
- I have been asked to log in 6 times since the release of sonnet 4.5
- [BUG] authentication_error and login failed
- [BUG] OAuth access token expires after ~8 hours and refresh token is not used — requires full re-login every day (Windows 11)
- [BUG] MCP OAuth 403 insufficient_scope step-up authorization does not trigger re-authorization flow
- [BUG] Claude code not conecting in CLI or extension
- OAuth token not persisted/refreshed for --print mode, breaks automation
- [BUG] Session Token Expiry Kills Active Agents Without Warning
- [Bug] API Error: Rate limit reached on Max Plan subscription
- [Bug] OAuth token expiration requiring frequent re-authentication
- [BUG] MCP 403 insufficient_scope step-up authorization is dropped and misreported as "token expired"
- [BUG] /usage hangs indefinitely after OAuth token expires (idle session)
- [Bug] OAuth refresh token not auto-refreshing on WSL — requires manual re-login daily
- OAuth expiration causes retry storm consuming 100% session usage (3.75M wasted tokens)
- API Error: 401 {"type":"error","error":{"type":"authenticati.../su
- [BUG] CCR scheduled triggers fail to load MCP connector tools in unattended runs
- [BUG] Claude code for VS Code OAuth token expiry not handled gracefully
- [Bug] Anthropic API Error: Duplicate Tool Names in Subagent Configuration
- [BUG] Still not fixed the auth bug? How long?
- [BUG] Claude code version npm-global (1.0.128), vs code plugin, constantly disconnected and request for re-login
- [BUG] claudeAiOauth wiped from Keychain (tokens blanked, expiresAt:0) when concurrent Desktop sessions race the single-use refresh token — refresh failure clobbers the winner's rotated credential
- Feature request: suppress the startup "N MCP servers need authentication" warning (lazy / on-demand OAuth re-auth)
- [BUG] MCP HTTP OAuth: refresh token never used; multi-session sharing broken
- OAuth token not persisted — Max subscribers forced to /login every session for months
- Background subagents cannot access OAuth-authenticated MCP servers
- [BUG] OAuth token expired — `claude login` fails with 401, no browser flow initiated, no recovery path after 34+ hours
- [BUG] /install-github-app generates workflow with OAuth tokens that expire without auto-refresh
- [BUG] M365 connector fails with AADSTS50076 when tenant requires MFA via Conditional Access
- [BUG] API Error: 401
- [BUG] OAuth token refresh fails due to Keychain permission errors (possibly after updates)
- [BUG] OAuth access token not auto-refreshed on startup — forces re-login after every PC restart
- [BUG] Authentication issue with Visual Studio Code Plugin
- Auto-refresh MCP OAuth tokens on expiry
- macOS Keychain: security -i 4096-byte line buffer causes credential corruption with MCP OAuth plugins
- [BUG] Claude Code doesn't inherit refreshed AWS credentials from SAML-to in GitHub Codespaces, causing 403 "security token expired" errors every 30 minutes
- [BUG] Errore di autenticazione persistente con Claude Code - Token OAuth scaduto
- [BUG] `CLAUDE_CODE_OAUTH_TOKEN` is shadowed by a stale `~/.claude/.credentials.json` (precedence reversed in 2.1.x) → `/login`
- [BUG] OAuth token expires excessively — multiple times per day
- [Bug] OAuth refresh token race condition in multi-instance scenarios
- [Bug] Exit-time refresh tokens not persisted, causing invalid grant errors on restart
- [BUG] Claude Code npm package immediately enters interactive mode with OAuth expired error - authentication commands don't trigger OAuth flow
- Gmail MCP (custom-added server) returns "The caller does not have permission" on every call, even immediately after a fresh interactive OAuth grant
- [BUG] /mcp shows unconnected integrations (Gmail, Google Calendar, Google Drive) as connected
- Sub-agent API 401 (auth expired) is reported to parent agent as "Request interrupted by user for tool use"
- VS Code extension forces daily re-login due to refresh token rejection (400) when multiple windows are open
- VS Code extension always returns 401 "OAuth token has expired" on macOS 12 (Monterey) - cannot authenticate at all
- [BUG] claude remote-control dies with 401 when mobile client connects (token valid but poll fails)
- API Error: 401 {"type":"error","error":{"type":"authenticati...
- OAuth refresh token rejected server-side after ~24h - forced /login every day (Max sub, single machine)
- [BUG] "Please run /login · API Error: 401 ... token expired" has no recovery path when using Claude Platform for AWS (awsAuthRefresh configured)
- [BUG] Slack MCP (HTTP OAuth): tokens cleared on every 401 instead of using refresh token — forces full re-auth ~each session
- [BUG] "Gmail MCP label_thread returns 403 - gmail.modify scope blocked by Google"
- OAuth auto-refresh fails in non-interactive (subprocess) mode → 401 after token expiry
- [BUG] Rate limits too aggressive for Pro plan (90€/month)
- OAuth access token not auto-refreshed — daily re-login required for subscription users
- [BUG] OAuth tokens expire silently, breaking unattended automation (LaunchAgent/cron)
- [FEATURE] Share MCP OAuth tokens globally for user-scoped servers instead of per-project
- [BUG] Custom MCP connector loses OAuth authentication after ~1-2 hours (refresh token not used)
- [DOCS] MCP OAuth docs omit re-authentication behavior after refresh token expiry
- [BUG] Slack MCP plugin: 1-hour token expiry with no refresh token forces frequent re-authentication
- macOS Keychain credential corruption: security -i 4096-byte line buffer causes OAuth token refresh failures
- `allowed-tools:` silently ignored in agent frontmatter — subagent inherits all parent tools, leading to credential hunting
- OAuth token refresh race condition with multiple concurrent sessions on same machine
- [Bug] v2.1.37 regression: OAuth authentication fails in sdk-cli/headless mode on macOS (cron-spawned processes)
- [BUG] `/mcp reconnect` doesn't refresh expired OAuth access tokens for HTTP MCP servers
- [Bug] Context window exhaustion causes multi-agent freeze
- [BUG] CLI is unrecoverable when returning to an expired session — /login and all inputs fail with 403
- OAuth MCP connectors: random mid-session "disconnected" requiring /mcp Reauthenticate (persistent across versions)