{"version":"2.1.286","anchor":"credential-recheck-when-the-stored-oauth-token-is-unusable","canonical_anchor":"credential-recheck-when-the-stored-oauth-token-is-unusable","heading":"Claude Code rechecks an unusable sign-in token, plus other sign-in changes","tier":"notice","area":"Auth","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/credential-recheck-when-the-stored-oauth-token-is-unusable","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Claude Code rechecks an unusable sign-in token, plus other sign-in changes\n\nWhen the stored sign-in token is unusable, Claude Code rechecks the stored credentials, rate-limited, alongside other sign-in changes\n\n**Unclear.** An extra condition controls when the recheck runs, and it is not clear what it checks or how often the recheck helps in practice.\n\n**What**\n\nClaude Code keeps a copy of your sign-in token (the saved credential that proves you are logged in) and checks whether the stored credentials have changed. That check has a new fallback.\n\n- If the credentials look unchanged but the cached token is unusable, Claude Code rechecks it and reads the keychain again. The keychain is your system's secure password store.\n\n- The recheck is rate-limited using a timestamp, `lastUnusableTokenRecheckAt`.\n\n- Before, only a change in the credentials' version or file modification time triggered a reload.\n\n- A variable mix-up in the version comparison was fixed.\n\n- Without the keychain, the modification time of `.credentials.json` is read differently.\n\n- A new experiment name, `auth_refresh_lock`, was added to the list of known gates, and `auto_mode_classifier_wording` was removed.\n\n- One sign-in request now sends a user-agent header, which identifies the program making the request.\n\n**Why**\n\nIf your token was refreshed elsewhere or stopped working, a running session has another chance to pick up working credentials without a restart.\n\n- Area: Auth\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5"}