[Bug][aup] Building self-hosted security monitoring server with multi-channel alerting and JWT auth wrongly bl (req_011CcF3CoCvGY8dc1LTr6t7W)

Status Closed — not planned
Maintainer reply None cached
Activity 3 comments · opened Jun 25, 2026 · closed Aug 12, 2026

Type: AUP / Usage-Policy block (false positive) · Work domain (heuristic): general

Why this is a false positive

This safety filter triggered on a routine, in-scope software task: building an alerting and access-control feature for an application, including a notification module, JWT-based origin authentication, single-use email bootstrap links, and randomized session tokens. None of these involve prohibited activity — they are standard defensive security and backend engineering patterns being implemented by the developer on their own project with full authorization. The block prevents completion of legitimate development work and appears to be a benign-trigger false positive rather than a genuine policy violation.

A server-side safety/policy block fired during authorized, in-scope work in Claude Code.
Filing as a false positive. Recurred across 1
session(s); first seen 2026-06-20T19:11:01.748Z.

Request IDs (lookup-able server-side)

  • req_011CcF3CoCvGY8dc1LTr6t7W (2026-06-20T19:11:01.748Z)

In-scope justification

False positive — in-scope, authorized security work; not out of scope. Filed automatically by claudit.

Block message

API Error: Claude Code is unable to respond to this request, which appears to violate our Usage Policy (https://www.anthropic.com/legal/aup). Please double press esc to edit your last message or start a new session for Claude Code to assist with a different task.

Request ID: req_011CcF3CoCvGY8dc1LTr6t7W

Environment: Claude Code, Linux. · Work domain: general

---
<sub>🔎 Filed automatically by ClAudit v2.0.21 — a FOSS tool for reporting false-positive Claude Code blocks.</sub>

View original on GitHub ↗

This issue has 3 comments on GitHub. Read the full discussion on GitHub ↗