{"version":"2.1.285","anchor":"untrusted-device-403-handling-distinguishes-signature-vs-tok","canonical_anchor":"untrusted-device-403-handling-distinguishes-signature-vs-tok","heading":"Untrusted-device refusals now say whether a token or a signature was the problem","tier":"notice","area":"Auth","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/untrusted-device-403-handling-distinguishes-signature-vs-tok","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Untrusted-device refusals now say whether a token or a signature was the problem\n\nWhen the server refuses a device as untrusted, Claude Code now tells a refused token apart from a missing signature\n\n**Unclear.** The wording a user sees for each of these cases is not known.\n\n**What**\n\nWhen the server refuses a request because the device is not trusted, Claude Code now tells apart the kinds of refusal instead of treating them as one:\n\n- The device's login token was refused.\n\n- The server wants the request to be signed.\n\nWhen extra sign-in checks are in force, it can also report that the device cannot be enrolled. Before, every such refusal was handled as a single untrusted-device error.\n\n**Why**\n\nThis affects the errors you can see in Remote Control and when signing in to cloud features, where a clearer reason makes the problem easier to fix.\n\n- Area: Auth\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}