OAuth token expired / refresh failed — page 3
The stored OAuth token lapsed and the refresh did not recover it.
344 issues · 91 open · 253 resolved (74%) · first seen May 7, 2025
First response · account
What to do now
Most likely: Authentication, usage state or session size blocked the request.
- Check the exact account, organization and usage window currently selected.
- Try a new short session before deleting credentials or local history.
- If the state is inconsistent across machines, preserve diagnostics and re-authenticate once.
These are conservative triage steps, not an official Anthropic fix. Use the issue and workaround evidence below before making a destructive configuration change.
Is this getting better or worse?
This class of problem is holding steady. 119 new reports in the last 90 days vs 115 in the 90 before — +3%. The open backlog peaked at 91 in 2026-08 and sits at 91 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
191 of these reports name the Claude Code build they were running, spanning 103 releases. Heaviest reporters:
- Claude Code v2.1.220
- Claude Code v2.1.229
- Claude Code v2.1.39
- Claude Code v2.1.119
- Claude Code v2.1.203
- Claude Code v2.1.177
- Claude Code v2.1.218
- Claude Code v2.1.198
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 7 days across 253 closures. Of the 253 closures with a recorded reason, 17% were closed as completed and 210 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
116 of these issues post a workaround someone says worked. The highest-engagement ones:
- [FEATURE] Enable Claude Code to access chat history in Claude App
- …opt-in, no sync needed in the other direction. The current workaround (manually summarizing and pasting context) defeats the entire purpose of persistent memory and cross-session continuity that Anthropic is actively bu…
Found in the thread of #15542 · still open - Missing Token Refresh Mechanism for MCP Server Integrations
- …ll, it's an option. I notice Linear's MCP server chose that workaround too: their access tokens expire in 7 days by default. But I don't think it's the right solution, and neither do the MCP protocol authors, [who say](…
Found in the thread of #5706 · resolved - Frequent re-authentication required with multiple concurrent Claude Code sessions (OAuth refresh token race condition)
- …rocesses share a single token manager that handles refresh. Workaround Currently, the only workaround is to close stale Claude Code sessions to reduce the number of concurrent processes competing for token refresh. This…
Found in the description of #24317 · resolved - [BUG] OAuth token expiration disrupts autonomous workflows – refresh token handling needed
- …t working, giving the same error message again Update: Temp workaround is to go to the folder and start Claude CLI with , then continue the session from there.
Found in the thread of #12447 · still open - [BUG] OAuth error: timeout of 15000ms exceeded can not login it keeps timout even though I tried token too
- I found a workaround for this issue. I used the binary from a previous version (2.1.50), which can be found in ~/.local/share/claude/versions. I logged in using that version, and once the authentication was successful, I…
Found in the thread of #33214 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 201–300
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 344 matches; the statistics above cover all 344.
- [Bug] Unexpected session logout causing task state loss
- [BUG] API Error: 401 — authentication_error: OAuth token
- OAuth MCP servers fail in remote-control mode due to disabled redirect handling
- awsAuthRefresh Credential Reload Issues - Inconsistent Behavior and Multi-Session Failures
- streamable-http MCP transport ignored, falls back to SSE
- [BUG] OAuth token expires 5-10 times within a single session, requiring constant /login
- OAuth refresh token never used — forces re-login every 8 hours
- OAuth token refresh race condition with multiple concurrent CLI processes
- MCP OAuth tokens not persisting across sessions (HTTP transport)
- unusually fast 30 minute token burn in Claude pro
- [BUG] MCP Atlassian OAuth tokens stored but not retrieved for SSE connection (400 error)
- [BUG] MCP OAuth: "Token expired without refresh token" despite refresh token being stored in Keychain
- [BUG] Claude Code VSCode extension stops responding on Cursor — double activation and process duplication (works on v2.1.1)
- Sessions should pick up refreshed AWS credentials without restart
- Bug: GOOGLE_REFRESH_TOKEN not passed to MCP server process
- [Bug] MCP OAuth refresh tokens stored but never used - causing widespread auth failures
- [BUG]
- Supabase plugin requires re-authentication on every new session (regression)
- [BUG] OAuth token expiration causing repeated 401 errors despite re-authentication
- [Bug] File search functionality broken after upgrade to 2.1.9
- OAuth token expires mid-session in Claude Desktop with no recovery path
- MCP OAuth tokens expire in idle conversations with no way to re-authenticate
- Retain user input after OAuth token expiration and re-login
- [BUG]
- [FEATURE]
- [Bug] Claude Opus hallucinating fabricated system-reminder blocks with fake tool results
- [FEATURE] Decision History Tracking with DECISIONS.md
- [Bug] /context command returns textual error instead of loading context
- [Bug] Anthropic API Error: OAuth token expiration not handled, requires manual /login restart
- [Bug] Context low warning triggers despite available token budget
- Teleport doesn't work. I started a Claude Code session on...
- [Bug] Unauthorized git push to main branch without user confirmation
- [BUG] Claude Code Browser - Persistent disconnection for Max subscribers requiring daily re-authentication
- [DOCS] Document default OAuth token `expires_in` behavior when omitted
- Agent creation in recommended mode doesn't work
- [Bug] Repeated Compaction Fails with "Conversation Too Long" Error
- Claude asks "Do you trust the files in this folder?" every launch
- [Bug] Anthropic API Error: Invalid Compact Message Content
- Missing Tool Result Block for Tool Use ID toolu_01TtqtoE6BkdCjrQPZtqCDbJ
- Anthropic API Authentication Token Expired
- Its my 3rd time getting this message for no reason " ...
- [BUG][Max Plan] OAuth Login Blocked - 'OAuth token has expired' Error on Every Login Attempt
- `claude remote-control` server exits on 401 after exactly 24h — does not refresh its OAuth access token, killing every attached session
- [BUG] HTTP MCP: OAuth succeeds, then initialize hangs until CONNECT_TIMEOUT (raising MCP_TIMEOUT doesn't help)
- Setup-token auth silently downgrades Fable 5 to Sonnet 5 (subscriptionType missing from token profile) — forces fleets back onto fragile stored /login auth
- MCP OAuth storage wiped mid-session (no update involved); CLI silently registers a new dynamic client, breaking auth for all remote MCP servers
- Read tool displays secret file contents in plaintext with no redaction, even when user only asked for a path
- Desktop app /mcp gallery lacks reauthenticate state and per-session server visibility (vs terminal)
- Local CLI auth expires every ~12h during long-running Remote Control sessions (personal Max) — forced /login; docs claim credentials auto-refresh
- MCP OAuth DCR fails for Calendly: client_name "Claude Code (<server>)" rejected as invalid_client_metadata (recurrence of #59445)
- Claude Max subscribers required to re-authenticate daily — OAuth refresh token TTL too short
- [BUG] Don't surface never-connected first-party connectors (Gmail/Calendar/Drive) as startup action items in Claude Code
- Single failed proactive token refresh hard-wipes auth and traps every session in an uncompletable /login
- [BUG] Windows: /login authorization-code prompt accepts no input (type or paste) while the main REPL composer works — interactive login impossible
- [BUG] MCP OAuth refresh token being used 4 days after it was already refreshed
- Hosted Notion MCP (DCR): client re-registers per session → repeated full re-auth (orphaned refresh tokens)
- [Bug] Single-use OAuth refresh token consumed by test copy invalidates production token
- claude.ai Shopify MCP: token-expired loop after multi-shop switch, unrecoverable from client side
- [BUG] Cowork Gmail/Outlook MCP connectors lose auth state, require disconnect-reconnect cycles repeatedly
- [BUG] OAuth token refresh never attempted for custom connectors via mcp-proxy.anthropic.com
- OAuth token expiration is too short for Max subscribers
- Gmail MCP: Draft link fails to open with no error feedback
- [DOCS] Troubleshooting missing macOS keychain guidance for Console login "Not logged in" errors
- [BUG] OAuth token expired → /login times out, no recovery path
- [BUG] OAuth token refresh returns persistent 429 for headless automation account (1 call/4h, started ~March 20)
- RFC: Prevent parallel auth kickout via token refresh serialization
- [BUG] Slack MCP server rejects connection: "App is not enabled for Slack MCP server access" (Anthropic app A08SF47R6P4 needs MCP toggle)
- Feedback from a loyal Max subscriber: OAuth token revocation drove me to switch to Gemini
- MCP /mcp menu does not show servers needing re-authentication after token revocation
- Retain user input after OAuth token expiration and re-login
- [FEATURE] Markdown syntax highlighting in prompt input field
- [BUG] VS Code Extension: Expired OAuth token reused across windows without refresh - breaks multi-project workflow
- [BUG] Session timeout
- [BUG] - API Error: 401 {"type":"error","error":{"type":"authentication_error","message":"OAuth token has expired. Please obtain a new token or refresh your existing token."},"request_id":"req_011CSSdA5fqJCVm1m4XMjNks"}
- [BUG] API Error: 401 OAuth Token issue
- [BUG] Claude account logout/switch discards all MCP OAuth grants (mcpOAuth is stored inside the account credential)
- MCP OAuth: valid stored token for mcp.facebook.com/ads reported as "OAuth session expired and could not be refreshed" (issuer mismatch, no refresh token)
- [FEATURE] Supported way to share/copy credentials between CLAUDE_CONFIG_DIR profiles (macOS Keychain makes file-level workarounds impossible)
- [Bug] Daemon proactive refresh hangs ~9h on Windows, falls back to non-existent keychain
- remote-control: session children exit on expired session_token with no refresh, then daemon permanently refuses to re-spawn them
- MCP OAuth: per-process refresh lock lets concurrent sessions race token refresh; rotation-strict servers revoke the token family, forcing manual re-auth
- [BUG] macOS DarkWake: transient DNS failure during OAuth refresh loses login
- [BUG] Platform incidents (Aug 4/5) force-logged-out multiple different Claude accounts simultaneously — refresh tokens invalidated, manual re-login required on every account
- [BUG] Mobile attach to ONE specific local session returns 401 'OAuth access token expired' after account token rotation; bridge binding is server-authoritative and survives every local remedy
- Background auth daemon fails to recover from a rejected proactive refresh, requires manual re-login every ~8h (Max plan)
- MCP OAuth: client performs full re-authorization at session start while valid refresh tokens exist
- [BUG] Windows: recurring forced logouts since ~Jul 22 — .credentials.json overwritten with test-fixture content ("fixture-claude-secret-value-x")
- Claude GitHub App stuck as "Authorized OAuth App" — never completes installation, all repo writes fail with 403
- Repeated mid-session logouts on macOS with concurrent instances sharing one Keychain OAuth chain
- HTTP MCP OAuth: refresh token stored but never exercised, server drops to bootstrap tools when the access token expires (~12h)
- macOS Keychain: concurrent sessions race on OAuth refresh; setup-token workaround strips claude.ai connectors, leaving no viable headless pattern
- [BUG] Claude Desktop 3P: managedMcpServers OAuth never refreshes on-demand — a failed silent refresh 403s every call until manual reconnect
- Desktop app: add a way to restart/reload a session's MCP connections without losing history (mid-session re-auth support)
- [DOCS] [Authentication] No documentation for the v2.1.203 proactive login-expiry warning that prevents background-session interruption
- MCP OAuth: parallel sessions sharing the credential store break refresh-token rotation (family revoked, all sessions forced to interactive re-auth)
- [BUG] MCP OAuth re-auth UI not shown for page reload/background Streamable HTTP auth failure
- Security: undeclared HTTP MCP transport persisted with credentials in global .credentials.json, presented as a project MCP, survives config removal
- VS Code: session resume from claude.ai/code fails with lock contention and expired OAuth token
- Remote Control: OAuth access token revoked mid-session (401), hub loses all remote sessions — twice in two weeks
- [BUG] Windows/VS Code: OAuth refresh token rejected (HTTP 400) after every sleep/wake since 2.1.247, forces /login daily (refresh raced at extension startup or lost mid-flight)