You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
AuthArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release
Unclear The exact length of the warning window before expiry is not known.
What
Some organisations sign Claude Code in through their identity provider, the service that manages company logins, using a certificate with the private_key_jwt method. Claude Code now checks that certificate every time it uses it, not just once at startup. It logs a warning when the certificate is close to expiring or is not valid yet. The warning is limited so it does not repeat constantly, and it includes steps to rotate the certificate, starting with "To rotate: add a new certificate at the IdP and keep this one".
A certificate with no subject no longer makes the log line crash.
Why
Administrators get advance notice before sign-ins stop working, with instructions to replace the certificate in time.
Read from
Names in the bundleprivate_key_jwt
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe exact length of the warning window before expiry is not known.