{"version":"2.1.284","anchor":"detailed-error-when-managed-login-policy-conflicts-with-an-a","canonical_anchor":"detailed-error-when-managed-login-policy-conflicts-with-an-a","heading":"Clearer error when a managed login policy clashes with your API key or token","tier":"notice","area":"Elsewhere","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/detailed-error-when-managed-login-policy-conflicts-with-an-a","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Clearer error when a managed login policy clashes with your API key or token\n\nWhen managed settings require a specific sign-in but another credential is set, the error names that credential, where it came from, and how to fix it\n\n**What**\n\nAn organisation can use managed settings (settings an administrator installs on the machine) to require a particular way of signing in, using `forceLoginMethod`, `forceLoginOrgUUID` or a cloud gateway requirement. If your session is set up with a different credential, Claude Code now shows a detailed message. It names the credential and where it came from:\n\n- `ANTHROPIC_API_KEY`\n\n- `ANTHROPIC_AUTH_TOKEN`\n\n- an `apiKeyHelper` command\n\n- a saved Console key\n\n- a credential supplied by the app hosting Claude Code\n\n- `--bare`, which turns first-party sign-in off, so there is no sign-in at all\n\nThe message says which settings file's `env` block set the credential and suggests specific fixes, such as removing the key from that block or asking your administrator. It also includes a note for administrators: on a third-party desktop session, `forceLoginOrgUUID` and `forceLoginMethod` apply to first-party sign-in and should be removed from that machine's managed settings.\n\n**Why**\n\nIf your credentials and your organisation's sign-in policy disagree, you now see which file to change instead of a plain refusal.\n\n- Area: Elsewhere\n- Names: `forceLoginMethod`, `forceLoginOrgUUID`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}