{"version":"2.1.290","anchor":"oidc-client-assertion-certificate-expiry-warnings","canonical_anchor":"oidc-client-assertion-certificate-expiry-warnings","heading":"Earlier, repeated warnings before a sign-in certificate expires","tier":"notice","area":"Auth","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/oidc-client-assertion-certificate-expiry-warnings","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Earlier, repeated warnings before a sign-in certificate expires\n\nClaude Code now checks the private_key_jwt sign-in certificate each time it is used and warns, with rotation steps, as expiry nears\n\n**Unclear.** The exact length of the warning window before expiry is not known.\n\n**What**\n\nSome organisations sign Claude Code in through their identity provider, the service that manages company logins, using a certificate with the `private_key_jwt` method. Claude Code now checks that certificate every time it uses it, not just once at startup. It logs a warning when the certificate is close to expiring or is not valid yet. The warning is limited so it does not repeat constantly, and it includes steps to rotate the certificate, starting with \"To rotate: add a new certificate at the IdP and keep this one\".\n\nA certificate with no subject no longer makes the log line crash.\n\n**Why**\n\nAdministrators get advance notice before sign-ins stop working, with instructions to replace the certificate in time.\n\n- Area: Auth\n- Names: `private_key_jwt`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5\n- Scope: org\n- Heads-up: no"}