Skip to content

Error reference

What each Claude Code error message means and how to fix it, from API, auth and network failures to CLI, plugin, tool, background session and config warnings.

This is the lookup page for error text. Search it for the words in your message (Ctrl+F or Cmd+F works well, since most entries quote the stable part of the message), read the one-line cause, and apply the fix. Messages are grouped by where they come from. Many have changed wording between releases; where an old version behaves differently in a way that matters, the entry says so.

Two habits save time before you dig in. First, /status shows which credential, settings sources and model a session is really using, and it resolves a surprising share of auth and limit errors. Second, Claude Code has usually already retried before showing you anything, so a message on screen means retrying has run out, not that it never started.

Note: Claude Code's own messages sometimes contain a long dash. To keep this page searchable in plain text, quotes below include only the part of each message on one side of that dash.

How automatic retries work

Claude Code retries transient failures up to 10 times with exponential backoff. What gets retried depends on how far the response had got.

Retried:

  • Server errors, overloads and timeouts before any of the response has streamed.
  • A server error or overload after Claude finished thinking but before any text or tool call (up to two retries).
  • Dropped connections before Claude completed any part of its response, including its thinking. If the drop comes after thinking but before any text or tool call, Claude Code retries twice quickly, then ends the turn with Connection lost before a response was produced. A connection broken by your computer sleeping counts as a dropped connection (Connection lost while your computer was asleep, or Your computer went to sleep before a response was produced).
  • A stalled stream (headers arrived, no content, or thinking done with nothing after it): one extra retry outside the normal budget, then The response stalled before a response was produced.
  • A streaming request that never gets response headers within the first-byte deadline: one re-send, then No response from API.
  • A response the output content filter stops before thinking finishes or any text starts: one re-send.
  • Temporary 429 throttles, including ones without your plan's quota headers. Not a gateway's spend-limit 429.
  • A request whose input plus max_tokens exceeds the context limit: retried with a smaller max_tokens, or compacted when no reduction fits.
  • Expired Google Cloud credentials, or AWS credentials that fail to load: cached credentials dropped and two retries.
  • A 401 or 403 while an apiKeyHelper script supplies the key: the script reruns and the request retries with fresh output.

Not retried:

  • TLS certificate validation failures (a TLS-inspecting proxy, missing NODE_EXTRA_CA_CERTS, expired certificate). These show on the first attempt. Transient TLS conditions like handshake timeouts still retry.
  • A failure after Claude completed a block of text or a tool call. Re-running could execute tools twice, so Claude Code keeps what was finished and continues from it; see The response above may be incomplete.
  • A failure after the response finished. The turn simply ends normally.
  • A Bedrock stream with the wrong content-type, a non-streaming retry that returns something that isn't an API message, and requests your organisation's policy check denied.

What the spinner shows

During retries you see Retrying in Ns · attempt x/y after a label. The label names the real reason straight away when you can act on it (network down, TLS handshake, rate limit), otherwise API error until the third attempt. For a 529 it also tells you where to check status: status.claude.com for the Anthropic API, or the provider or gateway host otherwise.

If no data arrives for 20 seconds, Waiting for API response · will retry in … · check your network appears before any retry. The request hasn't failed yet; the countdown runs to the point where Claude Code aborts the stalled connection. During an advisor consultation the threshold is 90 seconds, because long reviews legitimately send nothing for a while. If the banner keeps returning, treat it as a network problem.

Tuning retries

VariableDefaultEffect
CLAUDE_CODE_MAX_RETRIES10Attempts before giving up. Capped at 15 unless the watchdog is on. Lower it in scripts to fail faster
CLAUDE_CODE_RETRY_WATCHDOGunsetSet to 1 in unattended runs to retry 429 and 529 capacity errors indefinitely, and raise the default retry count for other transient errors to 300 (roughly three hours) with no cap. A 429 reporting a spend limit or exhausted usage credits still fails at once
API_TIMEOUT_MS600000Per-request timeout in ms. Also caps how long the retry waits for headers. A positive value under 11 seconds turns the first-byte deadline off
CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIESunsetLimit on re-sends of a timed-out non-streaming request. Each attempt times out after 300 seconds locally, or API_TIMEOUT_MS if set. Needs v2.1.285+
CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MSunsetFirst-byte deadline for streaming requests, clamped between 10 seconds and 30 minutes. Needs v2.1.242+

Server errors

These come from the inference provider behind your endpoint, not from your prompt or account (with a couple of exceptions noted).

MessageCauseWhat to do
API Error: 500 Internal server error (or any 5xx)An unexpected failure inside the API. A proxy's HTML error page shows as the status plus the page title, such as API Error: 502 Bad GatewayCheck status.claude.com or the provider status page the message names. Wait a minute and type try again. If it persists with no incident posted, run /feedback
API Error: Repeated 529 Overloaded errorsThe API is at capacity for everyone. Not your quotaWait and retry. Capacity is per model, so /model to another model keeps you going. You may be prompted with Opus is experiencing high load, please use /model to switch to Sonnet (or the Fable equivalent)
Request timed outNo reply before the deadline (10 minutes by default), often under load or for a very long answerRetry. Raise API_TIMEOUT_MS for slow networks or proxies
API Error: No response from API (waited ...)No response headers arrived within the first-byte deadline, twiceSend again. If a proxy holds responses until they complete, raise API_TIMEOUT_MS (and on Bedrock also CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS). If only the first attempt keeps timing out, raise CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS
Agent terminated early due to an API error: <detail>A subagent's request failed terminally, for example on a usage limitLook up the detail after the colon on this page, fix that, then ask Claude to retry or resume the subagent

The response above may be incomplete

A stream broke after Claude had already completed some text or a tool call. Claude Code keeps the finished work, runs any finished tool calls, and appends one of these:

VariantWhat broke
Server error mid-responseAn overload or 5xx partway through
Connection lost mid-responseThe connection dropped, or a proxy closed the body early
Your computer went to sleep mid-responseSleep broke the connection
The response stopped arrivingThe connection stayed open but went silent, so the idle watchdog aborted it
Part of the response never arrivedA stream event was dropped between the API and Claude Code
The response stream was malformedA damaged or out-of-order event arrived

In an interactive session, read what's on screen (an interrupted final block is discarded) and reply continue. In -p text output you get the last completed text block plus the notice; JSON formats put it in the result field. Non-interactive runs and subagents first prompt Claude to continue up to three times when the cut-off reply was text only, and show the notice only once those are used up.

If the stream breaks before Claude has started any text or tool call, you won't see this notice. Claude Code re-issues the request (ending with Part of the response never arrived and no response was produced or The response stream was malformed and no response was produced if that keeps happening), or falls back to a non-streaming request. With that fallback switched off via CLAUDE_CODE_DISABLE_NONSTREAMING_FALLBACK, you get API Error: Content block not found, Content block already closed or Stream event unreadable.

Auto mode errors

When the auto mode classifier can't produce a decision, the action isn't auto-approved. Reads, searches and edits inside your working directory skip the classifier and keep working.

MessageCauseWhat to do
<model> is temporarily unavailable, so auto mode cannot determine the safety of <tool> (sometimes with (rate-limited), (overloaded), (server error), (timed out) or (connection failed))The classifier model failedRetry after a few seconds; Claude usually does this itself. Repeated timeouts or connection failures point to your network. On Bedrock, if it never clears, your account can't invoke the named model: check IAM, or for Mantle IDs contact your AWS account team
Auto mode could not evaluate this action and is blocking it for safetyThe classifier's reply couldn't be parsedRetry. Run claude --debug if it repeats
Same, plus a safety check separate from auto mode blocked this request because of earlier conversation contentAn API safety filter tripped on earlier conversation contentNot a verdict on the action, and retrying won't help. Switch permission mode so you can approve manually, or start a fresh conversation. These don't count towards auto mode's pause thresholds
Auto mode classifier transcript exceeded context windowThe conversation is too big for the classifierApprove or deny the fallback prompt, and /compact. In -p with no permission prompt tool, the action is skipped
The server-side auto mode classifier gave no verdictUnder server-side review, the server gave no verdictRetry. After 10 in a row you get Auto mode is unavailable and the turn stops: send another message, check whether a gateway is truncating or rewriting streams, set CLAUDE_CODE_AUTO_MODE_SERVER=0 to use local classifier requests, or switch out of auto mode

Usage limits

Most of these mean a quota on your account or plan is used up. Three are different: the temporary server throttle, the 1M-context entitlement check, and the unanswered usage-credits prompt.

MessageCauseWhat to do
You've hit your session limit / weekly limit / Opus limit / Sonnet limitYour subscription's rolling allowance ran out. Session and weekly limits cover all models; Opus and Sonnet limits cover one familyWait for the reset time shown. For a family limit, /model to another family (expect no cache hits on the switch). /usage shows limits; /usage-credits buys more on Pro and Max or requests it from your admin on Team and Enterprise. Interactive claude.ai sessions can wait and continue automatically after the reset
Usage credits required for 1M contextYou selected a [1m] model and your plan only offers 1M context through usage credits/model to the variant without [1m], or turn usage credits on and restart. If it appeared because context grew past 200K, Claude Code compacts automatically. CLAUDE_CODE_DISABLE_1M_CONTEXT=1 hides 1M variants
the prompt to confirm went unanswered (Fable usage credits)A consent prompt for billing Fable to usage credits closed with nobody answering, typical in Remote Control, background or teammate sessionsAnswer it where the session runs (attach from agent view for background sessions), /model to a model that doesn't use credits, or lengthen dialogExpiry
Server is temporarily limiting requests (not your usage limit)A short server-side throttleWait and retry
Request rejected (429)Your API key's, Bedrock project's or Google Cloud project's rate limitCheck /status for a stray ANTHROPIC_API_KEY, raise your tier in the provider console, and reduce concurrency (CLAUDE_CODE_MAX_TOOL_USE_CONCURRENCY, fewer parallel subagents, a smaller model)
You've hit your monthly spend limit (or individual, org's monthly, team's shared budget, channel's monthly, individual usage limit)Usage credits hit a spend cap. The text after the dot says who can raise itPro and Max: raise it in claude.ai usage settings or /usage-credits. Team and Enterprise: an admin raises it, and /usage-credits asks them. If a reset time is shown you can wait instead
spend limit reached (daily; resets ...)A Claude apps gateway operator's cap. Not retriedWait for the reset or ask the operator. spend limit unavailable means the gateway couldn't read its records and usually clears itself
Credit balance is too lowYour Console org is out of prepaid credits, or a Console key is being used when you meant your subscriptionOn a subscription, check /status for an API key row and unset ANTHROPIC_API_KEY. Otherwise add credits in Console billing and consider auto-reload
Could not update your spend limitThe server rejected a change you made from the limit promptIf a reason is shown, pick a value that satisfies it. The generic form (Press Enter to retry) may be transient. Otherwise change it in claude.ai billing

Authentication errors

Run /status first: it shows which credential is active, and that decides which fix applies.

Claude login and API keys

MessageCauseWhat to do
Not logged in · Please run /login (Desktop: Authentication required)No usable credential/login. Signing in from another window using the same config directory also fixes an open interactive session. For CI, use an apiKeyHelper
Could not resolve authentication methodA background or cloud worker started with no credentialMake sure the credential is set in the environment that launches the worker. Upgrade if older than v2.1.176
Invalid API key · Fix external API keyThe key was rejected, or blocked locally because it contains a character a header can't carryCheck for typos and revocation. Look for stale keys loaded by direnv or .env files (env | grep ANTHROPIC). Or unset the key and /login
Your apiKeyHelper script is failingThe helper exited non-zero, timed out, printed nothing, or printed something other than a keyRun the helper yourself. It must print only the key (printable ASCII, up to 16,384 characters) and exit 0. /status shows the failure. /login doesn't help while the helper is configured
Invalid auth token, Invalid ANTHROPIC_CUSTOM_HEADERS, Invalid request header from the environmentA value contains a line break, NUL or character above U+00FF (curly quotes and zero-width spaces are common culprits from pasting)Retype the value around the reported position. Keep ANTHROPIC_CUSTOM_HEADERS to one Name: Value per line
Your ANTHROPIC_API_KEY belongs to a disabled organization, or This organization has been disabledA stale environment key overrides your subscriptionUnset the key and remove it from your profile. If the hint says Update or unset, you have no saved login, so also /login
Your organization has disabled API key authenticationYour Console admin turned off API keysRemove ANTHROPIC_API_KEY or the apiKeyHelper setting, then /login with claude.ai
Your organization has disabled Claude subscription access for Claude CodeA server-side org setting (code oauth_org_not_allowed in SDK and -p)Ask an admin to enable it, or use a Console API key
Routines are disabled by your organization's policyAn Owner turned routines offAsk an Owner to enable Routines in the Claude Code admin settings, or use scheduled tasks
OAuth token revoked / OAuth token has expiredThe API rejected your saved login, or an expired CLAUDE_CODE_OAUTH_TOKEN/login. For a long-lived token, generate a new one with claude setup-token
API Error: 401 Invalid authentication credentialsThe account or organisation behind a valid-looking credential was disabled or the credential revokedIf /status shows an active API key, rotate or unset it. Otherwise /login once. If it returns, the account or org is inactive; ask your admin. Through a gateway, the text is the gateway's
Login expired · Please run /loginRenewal failed and Claude Code cleared the saved login, so nothing is sent/login. /status shows a Login row reading Expired in this state
Could not refresh your login because another Claude Code process is refreshing itAnother process held the shared refresh lockRetry in a minute, close other Claude Code windows, or /login
Couldn't save your loginThe credential store refused the write (often a locked macOS Keychain)Unlock the Keychain and /login again
Failed to start OAuth callback serverClaude Code couldn't listen on 127.0.0.1Use claude setup-token elsewhere and set CLAUDE_CODE_OAUTH_TOKEN, or an API key. In a sandbox, allow local listeners
Claude login not acceptedA cloud session start got a 401/login and try again
Artifacts need a claude.ai loginNo claude.ai credential usable for artifacts/login and choose Claude account with subscription. Remove any credential the message says takes precedence
Not signed in to the Cloud gateway, or Administrator policy requires a Cloud gateway sign-inManaged settings set forceLoginMethod to "gateway" or forceLoginGatewayUrl/login on the Cloud gateway screen. For the startup form, remove the credential the message names
Your account is on holdThe account is suspended (code account_on_hold)Use the link to view details or appeal. Another account or API key still works meanwhile
Anthropic profile login expiredThe credential profile (from ANTHROPIC_PROFILE or discovered) has expired with no refreshSign in to the profile again (via /login and the Console option for profiles written by the keyless sign-in or ant auth login), or stop using the profile
OAuth token does not meet scope requirement: user:profileYour token predates a newer scope/login; no need to log out first
claude.ai rejected the session tokenA claude.ai connector request was rejected because of your Claude Code login/login, then reconnect the connector in /mcp

Remote Control sign-in messages

When Remote Control loses its credentials it stops, your local session keeps running, and a line beginning Remote Control disconnected names the reason: Claude.ai login expired, Claude.ai login was rejected, OAuth token unavailable, OAuth token refresh failed, JWT refresh failed: no OAuth token, or Signed out of Claude. Run /login, then /remote-control. Messages ending run /login to restore Remote Control reconnect by themselves after you sign in.

Two related stops:

  • signed-in claude.ai account or organization changed on this machine: you switched accounts elsewhere. Run /remote-control to start a session as the new account, or /login back first.
  • Remote Control stopped with the app running this session is now signed in to a different Claude account or is signed out of Claude: the hosting desktop app or IDE changed. Sign in there and turn Remote Control back on, or start a new session under the new account.

Remote Control is only available when using Claude via api.anthropic.com means the session goes through Bedrock, Vertex, a custom ANTHROPIC_BASE_URL, ANTHROPIC_UNIX_SOCKET or a cloud gateway. Unset the variable it names (check the env block of your settings too).

MCP server sign-in

MessageCauseWhat to do
MCP server "<name>" needs you to sign in againThe server's sign-in expired or was revoked/mcp, select the server, sign in
rejected the credential from its headersHelperThe helper's output was refused (after one rerun)Fix the helper, then reconnect in /mcp
rejected the Authorization header in its configA static header is wrongUpdate it, then reconnect
needs additional permissions (scope: "<scope>")The server returned 403 insufficient_scopeRe-authenticate from /mcp. If you pinned oauth.scopes, add the scope first
This server's URL is missing or not a valid URLThe url doesn't parseFix it, or set the variable its ${VAR} refers to
Issuer mismatch in authorization response (RFC 9207)The redirect's iss doesn't match the server's metadata, which is what a mix-up attack looks likeRetry, then report to the server operator. MCP_SDK_GENERATION=v1 skips the check but removes the protection
Refusing to send credentials to non-https token endpointThe token endpoint isn't HTTPS or loopbackServe it over HTTPS. MCP_SDK_GENERATION=v1 allows plain HTTP for every server until you exit

Cloud providers and gateways

MessageCauseWhat to do
AWS credentials expired or invalid401 from Claude Platform on AWS or the Mantle endpointRun the refresh command named (such as aws sso login --profile ...), or /login then 3rd-party platform then Claude Platform on AWS · refresh credentials when awsAuthRefresh is set. Check with aws sts get-caller-identity
AWS authentication failed403 from AWS, or 401 from Bedrock. Could be an expired token or a missing IAM permissionRefresh credentials, then check IAM and that the model is enabled for your account and region
Google Cloud credentials expired or invalid401 from Agent Platformgcloud auth application-default login (or your gcpAuthRefresh command), or fix GOOGLE_APPLICATION_CREDENTIALS. Through a gateway with CLAUDE_CODE_SKIP_VERTEX_AUTH, refresh the gateway token
Google Cloud authentication failed403: missing IAM role or model not enabledCheck roles and model access in Google Cloud's Agent Platform
Microsoft Foundry authentication failed401 or 403 from FoundryRotate ANTHROPIC_FOUNDRY_API_KEY, mint a new ANTHROPIC_FOUNDRY_AUTH_TOKEN, or az login. Then check RBAC on the resource
Could not load AWS credentials / Could not load Google Cloud credentialsThe local credential chain produced nothing (code cloud_credential_error)Run your provider sign-in and retry
AWS default-chain credential resolve timed outThe chain hung for 60 seconds, often a credential_process waiting for input or an IMDS that never answersTest aws sts get-caller-identity. Sign in first. Raise CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS if an MFA flow genuinely needs longer
Timed out after 60s waiting for AWS, A request to AWS timed outA call during the Bedrock setup wizard stalledSame checks as above; fix network or proxy first
Cloud gateway session expired, Cloud gateway <url> no longer accepts this sessionThe gateway session can't be renewed/login
Sign-in timed out while waiting for you to continueYou left the gateway account confirmation open too long/login again and confirm promptly
Gateway refused the request403 from the gateway or its upstreamSigning in won't help; ask the gateway administrator

Network and connection errors

MessageCauseWhat to do
Unable to connect to API, Connection refused (ECONNREFUSED), Can't reach the API server (ENOTFOUND), No internet route (EHOSTUNREACH), Couldn't connect through your proxy (ERR_PROXY_TUNNEL), Connection dropped (ECONNRESET)The TCP connection failedTest with curl -I https://api.anthropic.com (curl.exe on Windows). Set HTTPS_PROXY behind a proxy. If curl works but Claude Code doesn't, look for a leftover ANTHROPIC_BASE_URL pointing at a dead proxy, a bad /etc/resolv.conf (common in WSL), stale VPN utun interfaces on macOS, or Docker Desktop intercepting traffic
Unable to connect to Anthropic servicesFirst-run check couldn't reach api.anthropic.com or platform.claude.com within 10 secondsCheck the proxy variable it names. Claude Code may also not be available in your country. Skipped when managed settings force gateway login
Socket is closedUsually a Windows corporate proxy dropping a tunnel mid-responseUpdate to v2.1.214+, which retries it. If it continues, check the proxy
API returned an empty or malformed response (HTTP 200)A non-streaming retry got a 200 that isn't an API message: an HTML page, empty body, or captive portalRead the Response: clause to see who answered. Complete Wi-Fi sign-in pages. Fix the gateway hop. CLAUDE_CODE_DISABLE_NONSTREAMING_FALLBACK=1 turns this fallback off
Streaming response ended before any complete data was receivedA proxy swallowed or transformed the stream; Claude Code retried without streamingMake the proxy pass streaming bodies and headers through untouched
Bedrock streaming response has content-type "..."Something between you and Bedrock rewrote the binary event streamPass application/vnd.amazon.eventstream through unmodified. CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_GUARD=1 hides the error but falls back to slower non-streaming requests
SSL certificate verification failed (UNABLE_TO_GET_ISSUER_CERT_LOCALLY), Self-signed certificate detected, SSL certificate errorA TLS-inspecting proxy or private CA. Not retriedPoint NODE_EXTRA_CA_CERTS at your CA bundle. Never set NODE_TLS_REJECT_UNAUTHORIZED=0. See Network configuration
403 with x-deny-reason: host_not_allowedA cloud session or routine hit its network allowlistEdit the environment: change Network access from Trusted to Custom and add the domain (optionally keeping the default list), or choose Full. Org-shared environments need an Owner
artifact content fetch failed (proxy refused the connection: HTTP 407/403/...)Your proxy refused the CONNECT to *.frame.claudeusercontent.com407: add credentials to the proxy URL. 403: ask for the host to be allowed. Or add .frame.claudeusercontent.com (no broader) to NO_PROXY
The cloud environments service returned an empty response / unexpected formatUsually a service-side blipRetry; check status.claude.com if it persists
Couldn't reconnect to your Remote Control sessionResuming couldn't confirm the remote session/remote-control to retry, or start fresh with claude --remote-control
N sessions ended while this machine was offlineThe server cleaned up the Remote Control environmentRecover work from any kept worktrees, then run claude remote-control again
Couldn't share the transcript.The 8 MiB upload couldn't be reduced enough, failed, or the local archive couldn't be writtenUse /feedback instead
Couldn't send feedbackThe /feedback upload failed (or not signed in)/login if asked, retry, or file on GitHub

Request errors

Context and size

MessageCauseWhat to do
Prompt is too long (interactive: Context limit reached · /compact or /clear to continue)The conversation plus attachments exceeds the context window. Bedrock says Input is too long for requested model; a Claude apps gateway says capability_rejected: prompt_too_long/compact, or /clear. Run /context to see what's using space, /mcp disable <name> for unused servers, and move bulky CLAUDE.md content into path-scoped rules. Turn auto-compact back on if you disabled it (the message tells you when)
Prompt is too long · automatic compaction failed: <error>Compaction itself failedFix the named error first
Prompt is too long · this conversation is a single exchangeNothing earlier to summarise; the request is mostly system prompt, tools or attachments, or your one prompt/clear and start smaller, or reduce tools and attachments
Context exceeds the ...-token limit by ... tokens (in /context)You're past the window/compact or /clear. The past the ...-token compaction window form just means compaction is due
Request too large (max 32MB)The raw body exceeded 32MB, usually images and attachments/compact drops accumulated attachments. If it says compacting cannot make it fit, press Esc twice to go back past the big turn, or /clear. Reference files by path rather than pasting
Image was too largeOver the API's size or dimension limits (8000px longest edge, or 3000px with more than 20 images in context)Claude Code swaps in a placeholder and carries on. Resize or crop before pasting
Unable to resize imageCouldn't decode or shrink it (CMYK JPEG, animated WebP, damaged file, unreadable dimensions, over 2000x2000)Re-save as PNG, JPEG, GIF or WebP, or resize it yourself
PDF too large (max 100 pages, 20MB), PDF is password protected, The PDF file was not validThe PDF can't be attachedRead a page range instead, extract text with pdftotext, or remove the password
pdftoppm is not installedPage-range reads need popplerbrew install poppler or apt-get install poppler-utils

Malformed requests

MessageCauseWhat to do
Extra inputs are not permitted ... context_managementA gateway stripped the anthropic-beta headerForward that header, or set CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS=1
tools.N.custom.input_schema: JSON schema is invalid, Property keys should match patternAn MCP tool's schema fails validation (N is its position, not a name)Update to v2.1.216+, which excludes such tools. Otherwise disable servers until it stops; property names must be 1 to 64 characters of letters, digits, _, ., -
tool_use.name: String should have at most 200 charactersAn overlong tool name in historyclaude update and resume; newer versions trim it
due to tool use concurrency issues, orphaned tool_result, duplicate tool_use ID, unexpected tool_use_id, thinking blocks ... cannot be modifiedHistory is out of sequenceOn Opus 4.7 or 4.8, update first (pre-v2.1.156 bug). Then /rewind or Esc twice to a checkpoint before the bad turn
Invalid data in redacted_thinking blockAn earlier thinking block was refusedHandled automatically from v2.1.282. On older versions, update and resume, or /clear
[Unsupported tool content removed]A proxy-produced tool block was stripped when loading a sessionNothing to do. If every resumed turn fails with server_tool_use.name: Input should be, update
role 'system' must precede an 'assistant' messageA proxy inserted its own system messageTest without the proxy and report it to its operator
Invalid encrypted_content in search_result block and related encrypted_index, Failed to decrypt web search result content, encrypted_stdoutHistory contains hosted web-search or code-execution content the API can't decrypt, usually from a gatewayWeb-search forms recover automatically from v2.1.282. Otherwise /rewind or /clear, and tell the gateway operator

Models, thinking and effort

MessageCauseWhat to do
There's an issue with the selected modelUnknown model name or no access/model interactively, --model or ANTHROPIC_MODEL in -p, model in SDK options. Prefer aliases like sonnet. Hunt down stale IDs set elsewhere (see Model configuration)
Model "..." is not a recognized model id. Did you mean ...A switch passed something that can't be a model ID (often a display name)Pick from /model. Update if the alias is newer than your version
Model '...' not foundThe endpoint couldn't confirm the nameUse /model or an alias; check your provider's catalogue. SDK users can call supportedModels()
Couldn't confirm model "..." with the APIThe 5-second verification got no answerTry again; check connectivity
API error: ... · model not changedVerification failed for another reason, such as 429Act on the server's explanation and retry
Claude Opus is not available with the Claude Pro planYour plan doesn't include itChoose another model. After upgrading, /logout and /login to refresh the plan
Claude Code ... does not support this model; version ... or newer is required, or older than the minimum version required by your organization's policyYour binary is too old (claude_code_version_too_old)Update whichever binary made the request: claude update, the desktop app, the VS Code extension, or the SDK package. On the stable channel you may need the latest channel
Model ... is restricted by your organization's settings, Model ... is not available. Your organization restricts model selection.Disabled by an admin, or excluded by availableModels / deniedModels/model to an allowed one; remove the restricted ID from flags, env or frontmatter; ask an admin
Can't switch to the default modelManaged deniedModels or an exact availableModels blocks what Default resolves to, or managed settings couldn't be readPick an allowed model by name, or ask your admin
Model switch ... blocked by a PreModelSwitch hookA hook denied it, timed out, wanted confirmation the session can't show, or managed plugin hooks couldn't be checkedAddress the reason given; fix or extend a hanging hook's timeout; switch interactively; run claude --debug for load failures
couldn't save it as your defaultWriting ~/.claude/settings.json failed (read-only, or invalid JSON)The session switched anyway. Fix the file and switch again
is less capable than the current main model / Advisor will not activate / cannot adviseYour advisor ranks below the main modelChoose a stronger advisor or a smaller main model
thinking.type.enabled is not supported for this modelYour version predates the model's minimum (Opus 4.7: v2.1.111, Opus 4.8: v2.1.154, Sonnet 5: v2.1.197, Opus 5: v2.1.219, Opus 5.5: v2.1.280, Sonnet 5.5: v2.1.284)claude update (move to the latest channel if needed) or upgrade the SDK package, or pick an older model
Effort '<level>' isn't available with thinking turned offEffort above high with thinking disabled/effort high, or turn thinking back on (unset MAX_THINKING_TOKENS=0, remove "alwaysThinkingEnabled": false)
max_tokens must be greater than thinking.budget_tokensThinking budget leaves no room for the answerRaise CLAUDE_CODE_MAX_OUTPUT_TOKENS

Safety and policy refusals

MessageCauseWhat to do
API Error: <model> can't help with this. Start a new session to continue.A Usage Policy check on the whole conversation. Resuming carries the same contentEsc twice or /rewind to before the triggering turn and rephrase, or /clear. In -p, start a new session without --continue; another model may help
<model>'s safeguards flagged this message (or this session)Content was flagged as a cybersecurity topic. On Bedrock, Vertex and Foundry you get the Usage Policy message insteadApply to the Cyber Verification Program if your work needs it; /feedback for false positives; /rewind to keep working
Details: `[reasoning_extraction]` Something asked Claude to reproduce its internal reasoning verbatim, perhaps in CLAUDE.md, a skill, agent prompt, output style or MCP descriptionRemove that instruction. claude --safe-mode shows whether a customisation is the trigger. Asking for an explanation or summary is fine
API Error: Output blocked by content filtering policyThe output filter stopped the replyRephrase or /rewind

Installation errors

MessageCauseWhat to do
Installation was killed before it could finish (exit code 137)Usually the Linux OOM killer; install needs about 512MB freeFree memory, add swap, or use a larger instance. See Troubleshoot installation
The connection dropped while downloading the update (attempt 3/3: ...)Three download attempts failed (drops, stalls or checksum failures)Run claude update again, set HTTPS_PROXY if needed, ask IT to allow full downloads from downloads.claude.ai, and run claude doctor
Download timed out: exceeded the total deadlineThe download took over 10 minutes. Not retriedRetry from a faster network

Command-line errors

Flags and input

MessageCauseWhat to do
--bg and --print conflictA print run can never become an attachable background sessionUse claude --bg "<task>" or claude -p "<task>", not both
Cannot use both --append-subagent-system-prompt and --append-subagent-system-prompt-fileTwo forms of the same flagKeep one. (Before v2.1.283 the main system prompt pairs conflicted too)
Error: Invalid --agents configuration:Bad JSON, a schema problem, or a name starting with -. Checks run in order, up to 20 lines shownFix each listed problem. --agents takes a JSON object, or a file path only with --print (-p) and --agents file not found are the file-path variants
Error: --json-schema is not a valid JSON Schema: ... (also is not valid JSON, must be a JSON object)The schema didn't compileFix the keyword the diagnostic names. format is accepted as an annotation. See Headless
Error: Settings file exceeds the 2MiB limit / Cannot use settings file (Not a regular file ...)Bad --settings targetPoint at a normal JSON file under 2 MiB
Error: Input must be provided either through stdin or as a prompt argument when using --printstdout isn't a terminal (PowerShell ISE, IDE output panes), so claude ran non-interactively, or -p had no promptUse a real terminal, or pass a prompt: claude -p "..."
Claude Code can't read the keyboard here: stdin is not a terminalInteractive mode with piped input on Windows, or no /dev/tty elsewhereRun directly in a terminal, or add -p (works with --continue and --resume)
Error: Input contained only whitespace / Blank promptA prompt with no visible textCheck the variable or file your script builds the prompt from
Error: stream-json input carried over 256M characters with no newlineNon-JSON data piped into --input-format stream-json, or one giant messageEach message must be one newline-terminated JSON line; drop the flag for plain text
Unknown command: /<name>Typo, unavailable command (platform, plan, auth), or an uninstalled plugin or MCP prompt. Only interactive terminals reject unknown names; elsewhere the text goes to ClaudeUse the suggestion, or type / to browse; check the commands reference for requirements

Directories, trust and environment

MessageCauseWhat to do
The current directory no longer exists / Can't read the current directory (EACCES)Started from a deleted or unreadable directorycd somewhere real, or cd "$PWD" if it was recreated. For macOS EPERM in Desktop, Documents, Downloads or iCloud, restart the terminal and grant it access under Privacy & Security > Files and Folders
Temp directory ... Refusing to use it, or ENOSPC ... mkdir '/tmp/claude-<uid>'Can't create the private temp dir, or something suspicious is already there (symlink, wrong owner, bad mode)Free space, remove the named entry itself (not its target), chmod 0700, or set CLAUDE_CODE_TMPDIR
couldn't be resolved to a real location, so its skills, commands, and agents weren't loaded/add-dir on a subdirectory whose real path can't be confirmedCheck it's a real directory inside the working directory. File access is unaffected
Error: Workspace not trusted (Remote Control)claude rc couldn't ask about trust, for example with redirected I/O or a tiny terminalRun claude rc or claude there once and accept trust. Home directory trust is never saved, so use a project directory
`<flag>` before `remote-control` is not carried overA global flag like --settings or --permission-mode placed before the verbMove Remote Control's own options after the verb (claude remote-control --permission-mode <mode>)
Cloud sessions cannot be created from a --restricted sessionThey wouldn't enforce restricted modeWork locally, or start an unrestricted session
Cloud sessions are disabled by your organization's policyallow_remote_sessions is off (also blocks /teleport, /remote-env, /web-setup)Ask an Owner. Couldn't verify your organization's policy means check your network and restart
`claude import` is not yet available in this buildThe feature flag is off: fresh install, third-party provider or gateway, or telemetry-related variables disable flag fetchingStart a session once and retry, or set things up manually
Could not read Claude Code config~/.claude.json doesn't parseRun claude with no arguments to reset it, or fix the JSON

MCP commands

MessageCauseWhat to do
Could not import <server>: Invalid name ...Claude Desktop allows names claude mcp doesn'tRename to letters, digits, hyphens and underscores, or add it directly with claude mcp add
Cannot add MCP server to scope: managedManaged scope comes only from managedMcpServersUse local, user or project
Cannot add MCP server: your organization's managed settings allow only MCP servers that plugins providestrictPluginOnlyCustomization locks mcpInstall a plugin that provides it, or ask an admin
is Anthropic-hosted and doesn't support local OAuthHosts such as gmail.mcp.claude.com sign in only through claude.aiclaude mcp remove <name>, then connect it on claude.ai
Can't read .mcp.json: it isn't a regular file or is larger than 2097152 bytesSomething odd at .mcp.jsonReplace it with a normal JSON file or delete it
MCP server "<name>" was not saved to / was not removed fromThe change wasn't in ~/.claude.json when read back (read-only file or sandbox)Make it writable or run outside the sandbox, then repeat
MCP server "<name>" may not have been saved / removedCouldn't read the file back to confirmCheck with claude mcp get <name> and repeat if needed
Server rejected the Authorization header minted by the configured headersHelper401 or 403 with a helper-supplied header; no OAuth fallbackRun the helper the way Claude Code would and fix its output, then Reconnect
Error: MCP tool ... (passed via --permission-prompt-tool) not foundThe server never connected within MCP_TIMEOUT (30 seconds), or the name is wrongCheck claude mcp list, the mcp__<server>__<tool> name, or raise MCP_TIMEOUT
OAuth callback port <port> is already in useA fixed port (MCP_OAUTH_CALLBACK_PORT or --callback-port) is takenFind the process with lsof -ti:<port> -sTCP:LISTEN (Windows: netstat -ano | findstr :<port>), or register another port
No available ports for OAuth redirectNothing can listen on 127.0.0.1Allow local listeners in security software or the sandbox

Skills, review and GitHub

MessageCauseWhat to do
Shell command failed for pattern "..." from /security-revieworigin/HEAD doesn't exist (single-branch clone, empty remote, no remote)git remote set-head origin <default-branch> (fetch the branch first if needed), or git fetch origin && git remote set-head origin --auto. The same message applies to any skill whose injected command fails
Shell command permission check failed for pattern "..."A skill's injected command wasn't permittedPre-approve it with allowed-tools; see Skills
Skill <name> requires bash (`shell: bash` in frontmatter) but Git Bash was not foundBash-only skill on a machine without Git BashInstall Git for Windows or set shell: powershell
Diff is too large for ultrareview / PR #<N> is too largeOver the file or line limits; no free run usedPass a closer base (/code-review ultra develop) or split the change. See Ultrareview
Could not find merge-base with <branch>No shared commit with the basePass the right base, or git fetch --unshallow origin
Your checkout has no branches (detached HEAD only)Nothing to bundlegit checkout -b <name>
Ultrareview clones <owner>/<repo> ... and none is connected, GitHub isn't connected to your Claude accountNo GitHub account linked/web-setup, or connect at claude.ai/connect-github, then wait a minute
Your connected GitHub account can't see <owner>/<repo>App not installed or wrong account/web-setup with a gh login that can see it, or install the Claude GitHub app
The GitHub App preflight failed transientlyBundle upload failed and the GitHub check hit a transient errorRetry shortly
Not uploading this working tree: core.ignoreCase ... (also core.attributesFile, attr.tree)The upload can't honour that git setting, so encrypted-by-filter files might leakApply the fix in the message's last sentence
IP allowlist, requires single sign-on, or Conditional Access policy blocking ClaudeA GitHub organisation policyAllow Anthropic's IPs, reconnect GitHub and Authorize the org, or ask the Entra admin
Single sign-on authorization needed (/install-github-app)Your gh token isn't SSO-authorisedgh auth refresh -h github.com -s repo,workflow, or configure SSO on your PAT

Sessions and UI

MessageCauseWhat to do
Failed to resume the conversation.The transcript couldn't be readRetry with claude --resume <session-id>; update if older than v2.1.285; otherwise start fresh
No conversation found with session ID: <id>Typo, transcript deleted after the retention period (30 days by default), other machine, or duplicate copiesUse claude --resume and Ctrl+A to search every project. -p and SDK sessions aren't in the picker. See Sessions
Windows reported an error (EBADF)Security or encryption software intercepted the transcript readExclude %USERPROFILE%\.claude\projects (or your CLAUDE_CONFIG_DIR) from scanning
Cannot switch renderers while work is running in the background / in this session/tui restarts the process and would lose background work or session-only restrictionsWait or stop tasks via /tasks, or switch from a session without those restrictions
Couldn't open Claude Desktopopen or rundll32 failedOpen the app yourself and retry /desktop
Couldn't read/back up/update your Zed keymap, isn't a readable list of keybindings/terminal-setup left keymap.json alonePaste the block from the message yourself, or fix the file's syntax
Skill usage reports are not available on this connection./skill-doctor over Remote ControlRun it on the host machine
Custom output styles can't be selected over Remote Control or from a relayed messageOnly built-in styles are allowed therePick a built-in, or set outputStyle locally. See Output styles
Output styles are saved to local settings (.claude/settings.local.json), which this session doesn't loadSetting sources exclude localAdd local, or set outputStyle in a file the session loads
/recap only runs when you ask for it yourself in this sessionThe request came via Slack, Teams, a project thread, a routine or another programRun /recap yourself in the session

Plugin errors

MessageCauseWhat to do
`plugin eval` is currently in early access / currently unavailableVersion older than v2.1.269, or switched off server-sideclaude update; for the second, try later
Marketplace "<name>" is registered from an untrusted sourceA reserved name not sourced from github.com/anthropicsclaude plugin marketplace remove <name> and re-add from the official source
"<name>" is another spelling of "<reserved>"Looks like a reserved nameRename, or remove the ignored entry
Claude Code refuses the marketplace name / Marketplace name impersonates an official Anthropic/Claude marketplaceImpersonating nameRemove it (this uninstalls its plugins) or wait for a rename
Marketplace "<name>" is already added from a different sourceName clashInstall from the existing one by name, or remove it first
references ${user_config.*} in a shell-form command (also monitors and headersHelper)Config values could be executed by a shellUse exec form with args, or read $CLAUDE_PLUGIN_OPTION_<KEY>; read values inside scripts
Plugin archive integrity check failedDownloaded archive doesn't match its sha256 pinPublishers: recompute with shasum -a 256. Users: /plugin marketplace update <name> and retry
path escapes plugin directoryA component path or symlink leads outside the plugin, or uses backslashes on macOS/LinuxMove the file inside, use ./ and forward slashes, copy instead of symlinking
path could not be checked (ELOOP/EIO/ESTALE/EACCES)The OS errored on a plugin pathFix the loop, remount the share or restore permissions, then /reload-plugins
marketplace entry path does not stay inside the marketplace directory, Plugin source path refusedAbsolute, climbing, network, backslash or escaping-symlink entry, or a relative entry in a URL-only marketplaceUse a plain relative source such as ./plugins/my-plugin, or add the marketplace from git
Failed to load marketplace configuration / Marketplace configuration file is corrupted~/.claude/plugins/known_marketplaces.json is unreadable or wrong shapeRepair it, or replace with {} and re-add marketplaces
Plugin "<name>@synced" is required by your organizationAn org-required synced pluginAsk a claude.ai admin
"<plugin>" was not uninstalled: it is still switched on in <file>A settings file still enables itRemove it from enabledPlugins in that file, then uninstall again

More plugin issues live in Plugin troubleshooting.

Tool errors

Claude sees these as tool results and corrects most of them on its own. You only need to act when one keeps recurring.

MessageCauseWhat to do
Error: No such tool available: <name>Wrong name (case matters, so read vs Read), an MCP server still connecting or disconnected, or a name trimmed at 200 charactersUsually nothing. If MCP tools keep failing, check /mcp
Agent '<name>' would be spawned with zero toolsEvery tools entry was unrecognised, unavailable to subagents, or matched nothing in this sessionFix the entries, or delete the tools field to give the agent the default set. See Subagents
File is covered by a Read deny rule in your permission settingsEdit or Write on a path you denied for ReadNarrow the rule, or add a matching Edit deny to block NotebookEdit too
cannot contain null bytes (\0)A path argument had a NULNothing; Claude retries
subagent_type is required: the general-purpose agent is not availableBuilt-ins disabled with CLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS=1, or an Agent(...) allowlist excludes itUsually nothing; otherwise allow general-purpose
this write left the memory index at MEMORY.md ... over its ... read limitAuto memory's index passed 200 lines or 25KB, so the tail won't loadLet Claude compact it into one line per entry with detail in topic files. See Memory
pkill: refusing to runOn Linux, the pattern would kill Claude Code itselfNarrow the pattern, or use pkill -P $$
Failed to write to <name>'s inbox (and plan, permission and shutdown variants)An agent team mailbox write failed (disk, permissions or lock)Resend; check space and that ~/.claude/teams is writable
Its agent definition was not restored: the folder ... is not trustedA teammate's agent file came from an untrusted folderRun claude there once and accept trust
Message too large for cross-session deliveryOver 1,048,576 serialised charactersSummarise, split, or send a file path. See Cross-session messaging
Too many messages to this session just nowA burst hit the recipient's rate limitBatch remaining content into one message
Cross-session message was dropped at the recipient session's inboxQueue full, too fast, duplicate, or a relay loop was cutAssume it wasn't seen; send fewer, larger messages; type into a session yourself to break a loop
Refusing to send: reply target is a symlink / cannot vet reply targetThe recipient's socket path can't be trustedUsually nothing; investigate what created the link
Refusing to read/write/search <path>: its symlink resolution changed after permission was checked (and related could not be determined, is a symbolic link, Refusing to write through symlink, into symlinked directory, permission check expired, ripgrep was found only by name on PATH)A path's real location couldn't be confirmed between the permission check and the operationUsually nothing. Find whatever keeps rewriting a link; install ripgrep so rg resolves to an absolute path; update if Windows sandboxes (pre-v2.1.265) or macOS screenshots (pre-v2.1.273) trigger it
task output swap refused, Command killed: its output file was replaced or could no longer be verifiedSomething replaced or linked files in Claude Code's temp directoryUpdate to v2.1.260+, then restart with CLAUDE_CODE_TMPDIR set to a fresh directory, or remove the stray link or directory itself
Your disk quota is full ... (EDQUOT), ... is full (ENOSPC), Command output was lost: the temp filesystem ... is full / is out of inodesThe temp filesystem or your quota is exhausted, so output was lostDelete files (many small ones for inodes), or set CLAUDE_CODE_TMPDIR elsewhere, then rerun
the source file is not valid UTF-8 text / has the replacement character U+FFFDAn artifact source isn't clean UTF-8Usually Claude fixes it. Write an intended U+FFFD as &#xFFFD;
Not published: that file is on a network shareUNC or /net pathCopy locally, or on Windows map a drive and pass it with --add-dir at launch
Reading a local file from outside this session's connected folders ... needs the approval cardCowork session that can't ask youCopy the file into a connected folder as a regular file
WebFetch cannot fetch localhost or other hostnames without a dotBy designClaude uses curl via Bash instead
The safety check for domain ... is rate-limited, Unable to verify if domain ... is safe to fetchWebFetch's domain check against api.anthropic.com failedContinue without the page, allowlist api.anthropic.com, or set skipWebFetchPreflight: true

Background session errors

These come from background sessions and from worktree isolation checks.

MessageCauseWhat to do
Can't open MCP settings while no terminal is attached to this background session (and /install-github-app)Dialogs need an attached terminal. The session shows under Needs inputAttach from agent view and rerun, or use /mcp enable, disable or reconnect <server>
blocked because the path is spelled in a form that cannot be safely resolvedWorktree guard can't verify the path (symlinks with .., device or network forms, unreadable parents)Usually nothing; Claude retries with the direct path. Edit symlink targets by their real path
blocked because the path is network-shapedUNC or /net path with a local checkoutUse the local path
is isolated in the worktree <path>, but this command ... Refusing to run itThe command targets the main checkout, or uses constructs like ${!name} that can't be verifiedSplit into plain commands run from the worktree; act on the main checkout yourself
This session has no saved transcriptBackgrounded session stopped before its first reply finishedThe original conversation is intact; claude respawn <id> starts this one fresh
Can't open (running in another terminal), This conversation is already open in another running Claude sessionAnother process holds the transcriptUse that process, or exit it and retry
This session's saved conversation is no longer on diskTranscript cleaned up while the service was offclaude rm <id> or claude respawn <id>
kept <id>, unpushed commits on "<branch>"Deleting would lose commits that exist on no remotePush or merge them, or use the printed --discard-unpushed command
terminal host process diedThe host process under the background service diedPress Enter on the row, or claude attach <id> again. Shell-command rows aren't rerun automatically
Session isn't respondingNo output for about ten secondsPress Enter again, or claude stop <id> then claude attach <id>
Session <id> was stopped while the respawn was in flightSomeone stopped it mid-restartReopen or claude respawn <id> if that wasn't you
This session was running agent '<name>', which is no longer availableThe custom agent file is gone or its folder untrusted; default tools applyRe-create the agent, or resume with --agent <name>
CLAUDE_CODE_PROCESS_WRAPPER: launcher ...The launcher value isn't usable, or it didn't execPoint it at an executable that ends with exec "$@", then claude daemon stop --any
EUNKNOWN: unknown error, uv_spawn (Windows)A restriction policy blocked a program, or an npm reinstall was mid-flightUpdate to v2.1.212+, wait for npm, or ask your admin about AppLocker or Group Policy
EACCES: permission denied, posix_spawn, Claude Code is being updated by npm on this machinenpm was replacing the binaryRetry when the update finishes; otherwise check permissions or reinstall
exited before it became reachableThe background service crashed at startFix the quoted line. On Windows with nothing on stderr every time, delete ~/.claude/daemon.lock
working directory no longer exists or is not accessibleDirectory removed during startRecreate it or dispatch from elsewhere
Workspace not trusted. (dispatch)No trust and no way to askRun claude there and accept trust; home-directory and could not be resolved on disk variants explain themselves

Wrapper and IDE errors

MessageCauseWhat to do
Error: Claude Code process exited with code NThe underlying claude exited non-zero; the real error is in its outputIn VS Code, click View output logs. In SDK apps, catch the error (see Agent SDK troubleshooting). Run claude in a terminal in the same project to reproduce. A Windows 4294967295 exit at a turn boundary is handled quietly
Could not locate the Claude CLI on PATH (VS Code, PowerShell)The installed CLI isn't on the PATH VS Code capturedAdd it as a user or system variable, not just in your PowerShell profile, then restart VS Code
The connection to Claude Code ended before this message completedThe process ended before acknowledgingSend it again

Rewind and session saving

MessageCauseWhat to do
Restored the code, but skipped N files/rewind won't write through links, changed directories or unreadable backupsTurn on /debug to see the paths; undo those files by hand if needed. See Checkpointing
No files were restoredBackups missing (retention sweep after about 30 days, or a failed copy into a fork) or files unwritableAsk Claude to reverse the edits or use git. Raise cleanupPeriodDays for the future
Transcript writes are failing (... ENOSPC)Saving the transcript is failingFix the named condition; the warning clears on the next successful write
Transcript saving is off with CLAUDE_CODE_SKIP_PROMPT_HISTORY is setDeliberate opt-out, or inherited by accidentUnset it and restart if unintended
Transcript saving is off with inherited CLAUDE_CODE_CHILD_SESSION markerTreated as a nested sessionRestart with CLAUDE_CODE_FORCE_SESSION_PERSISTENCE=1, and remove the marker from whatever launches you

Configuration warnings

Most of these print to stderr at startup. In background sessions and JSON output modes they go to the debug log instead (~/.claude/debug/<session-id>.txt, captured with --debug).

MessageCauseWhat to do
Claude Code exited after an unrecoverable interface errorThe terminal UI crashed; if during fullscreen start-up, the next launch uses the classic rendererRestart and claude --resume. See Fullscreen
Agent descriptions are over the 15.0k-token limitYour custom subagents' names and descriptions are too long in totalTrim descriptions or delete unused agents
Not loaded: rename ... a name reserved for the skills synced from your claude.ai accountSomething uses anthropic-skills as its nameRename it and restart
Ignoring N permissions.allow entries from ... this workspace has not been trustedProject allow rules need workspace trustAccept the trust dialog, or set hasTrustDialogAccepted in ~/.claude.json for -p use
is a network path, which cannot be added as a working directoryUNC, /net automount or a link to a network locationMap a drive and pass it at launch, or mount locally
Remote managed settings failed to load (<cause>)Server-managed settings fetch or validation failed; runs on cached policy or noneCheck connectivity or sign-in, or ask the admin to fix invalid settings
Managed settings were not approved; exiting without applying them.You declined the approval dialogRestart and approve
Claude Code can't start: your organization's managed settings block the default model / allows only the models listed in "availableModels"No allowed model can be the defaultAdmins: widen availableModels or narrow deniedModels
Your organization's managed settings allow Claude Code to use: ...Your provider isn't in allowedProvidersFollow the To continue: steps
MCP server <name> is blocked by enterprise managed policydeniedMcpServers, allowedMcpServers, strictPluginOnlyCustomization or disableClaudeAiConnectorsCheck your own settings first, then ask the admin
Managed settings document could not be parsed as a JSON object / drop-in directory could not be readA deployed managed source is broken; Claude Code fails closedAdmins fix or remove it. See Managed settings
Unable to read managed policy settings.A managed source exists but couldn't be readAdmins fix the Detail: cause
otelHeadersHelper failed; telemetry is not being exportedThe helper failed or printed bad outputMake it exit 0 within 30 seconds and print a JSON object of string headers
headersHelper not runNo saved trust for this folder in -p or SDK modeAccept trust interactively or set hasTrustDialogAccepted
Invalid permission rule "..." was skipped: Malformed Tool(content) ruleThe rule doesn't end at its closing parenthesisRewrite it, for example Bash(ls *). Parentheses inside content are literal
... is not matched by file permission checksWrite, NotebookEdit, MultiEdit or Glob path rules are never consultedUse Edit(path) or Read(path) instead
... has a wildcard before the rest of the commandA rule like Bash(git * main) also approves inserted options such as -cPut * only after the subcommand, one rule per subcommand. See Permissions
Denying Bash also turns off the PowerShell tool, so Claude has neitherWindows with Git Bash and a blanket Bash denySet CLAUDE_CODE_USE_POWERSHELL_TOOL=1, or use scoped Bash rules
"crossSessionInbound" must be one of "accept", "hold", "refuse"Typo in the setting; messages are held meanwhile (refused if in managed settings)Fix the value
ANTHROPIC_FOUNDRY_RESOURCE must be a Foundry resource nameA URL or hostname was givenUse the bare name, or set ANTHROPIC_FOUNDRY_BASE_URL instead (not both)
CLAUDE_CODE_DISABLE_1M_CONTEXT is set, but the 200K limit isn't enforcedOther configuration defeats the capSet CLAUDE_CODE_AUTO_COMPACT_WINDOW=200000 or autoCompactWindow, or update
[claude-code:unrecognized_model] {...}Your version doesn't recognise the model ID (written once per model to stderr in -p, debug log otherwise)Add a modelOverrides entry mapping a real Claude model ID to your alias, update, or fix the typo
Stale sandbox mask files left by a killed session (in claude doctor)Zero-byte placeholders left after a killed sandboxed session on Linux or WSL2With no other session running in the project, rm each listed file

A modelOverrides entry for a gateway alias looks like this, with a real model ID as the key and your gateway's name as the value:

{
  "modelOverrides": {
    "claude-sonnet-4-6": "team-sonnet-prod"
  }
}

Responses seem worse than usual

No error, just weaker answers? It's almost always session state rather than a model swap. Claude Code doesn't silently change model versions; the only switches are a configured --fallback-model after an availability error (one turn, with a transcript notice), a Bedrock or Vertex default becoming unavailable, and automatic fallback when a safeguard category has a fallback model (also announced). Check:

  • Model: /model. A leftover choice or ANTHROPIC_MODEL may have you on something smaller.
  • Effort: /effort. Raise it for hard debugging or design. Defaults differ by model.
  • Context: /context. Near full, /compact at a sensible point or /clear.
  • Stale instructions: oversized CLAUDE.md files and unused MCP tools crowd the window and steer answers. /doctor flags them.

When a reply goes wrong, rewinding beats arguing. Press Esc twice or use /rewind, then re-prompt with more detail; correcting in-thread leaves the bad attempt in context. If something still seems off, /feedback with what you expected sends Anthropic the transcript. If Claude warns about prompt injection in text Claude Code added itself, update and retry, and report it if it persists.

Reporting an error

  • /feedback sends your transcript and a description to Anthropic and can open a prefilled GitHub issue. On Bedrock, Vertex, Foundry and other third-party setups, or with no Anthropic credentials, it saves a local archive for your account team instead.
  • claude doctor gives a read-only installation report; /doctor checks and fixes inside a session.
  • Check status.claude.com for incidents and search the GitHub issues.