{"version":"2.1.285","anchor":"new-org-policy-failure-message-for-claude-ssh","canonical_anchor":"new-org-policy-failure-message-for-claude-ssh","heading":"claude ssh gets a stale_tunnel_credential failure case","tier":"notice","area":"Elsewhere","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/new-org-policy-failure-message-for-claude-ssh","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### claude ssh gets a stale_tunnel_credential failure case\n\nclaude ssh now reports when the machine's credentials changed while your organization's policy was loading, and handles it like a timeout\n\n**What**\n\n`claude ssh` runs Claude Code on another machine over a secure connection (a tunnel). Before a session starts, Claude Code loads your organization's policy. That loading has a new failure case for when the machine running `claude ssh` changes its credentials partway through:\n\n- `stale_tunnel_credential` is a new reason the policy load can fail. It comes with its own message: \"the machine running claude ssh changed credentials while your organization's policy was loading\".\n\n- This outcome is now grouped with timeout and parse_failed as a \"live\" outcome, rather than being treated separately.\n\n- A new function marks a session's verdict as disowned (`sessionVerdictDisowned`) and announces that the verdict changed, the first time this happens.\n\n**Why**\n\nIf a credential change interrupts policy loading in an ssh session, you now get a message that says what happened instead of a less specific failure.\n\n- Area: Elsewhere\n- Names: `claude ssh`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}