Skip to content

[BUG] OAuth "Invalid code" error directs users to check length; actual cause is a missing "#" delimiter #91157

Description

@coy247

What's Wrong?

The manual OAuth paste flow rejects input with:

OAuth error: Invalid code. Please make sure the full code was copied

The message directs the user to verify the code's length. The actual failure
condition is a missing # delimiter, which no length check can detect. A user whose
pasted value is long and complete-looking has no way to self-diagnose, producing an
unresolvable retry loop.

From the shipping binary, the parser is:

let [code, state] = input.trim().split("#");
if (!code || !state) { error("Invalid code. Please make sure the full code was copied") }

Input must contain # with non-empty content on both sides (<code>#<state>).

The delimiter is easy to lose for two reasons, both invisible to the user:

  1. # is a word boundary — double-click selection stops before #state.
  2. # is the URL fragment delimiter — any URL normalization drops everything after it.

What Should Happen?

The error should name the actual condition and how to fix it. Suggested:

"Code must be in the form `code#state`. Copy the entire value, including the `#`
 and everything after it. Tip: `#` is a word boundary — double-clicking selects
 only the first half."

And distinguish the two failure modes: missing delimiter vs. one side empty.

Error Messages / Logs

OAuth error: Invalid code. Please make sure the full code was copied

Press Enter to retry.

Two clipboard states captured during live failures on this machine:
attempt 1 : 346 chars, contains '#': NO -> rejected
attempt 2 : 1084 chars, contains '#': NO -> rejected
Both were long and untruncated. Both failed on the delimiter alone.

Steps to Reproduce

  1. Run claude in a terminal and start the login flow.
  2. When the authorize page displays the code, double-click the code to select it
    (this is the natural gesture and selects only up to the #).
  3. Copy, and paste at the Paste code here if prompted > prompt.
  4. Observe: "Invalid code. Please make sure the full code was copied"
  5. Verify the clipboard was NOT truncated:
    pbpaste | wc -c # long
    pbpaste | grep -c '#' # 0 <- the actual cause
  6. Following the message's advice (checking the code is "full") confirms it looks
    complete and returns you to step 4.

Additional Information

Ruled out during diagnosis: browser-specific behavior (reproduces in multiple browsers
including a fresh in-app browser), network interception (the authorize URL is built from
client constants and printed before any network request is made), and credential expiry
(credentials were valid throughout).


Environment

Claude Code 2.1.212 (Claude Code)
Platform Claude API (Max subscription)
OS macOS 27.0 (build 26A5425a, developer beta)
Hardware Apple M2 Pro, arm64
Terminal / Shell Ghostty 1.3.1 / zsh (also reproduced in Terminal.app)
Model Opus
Regression No — not tested against a prior version

Preflight: searched existing issues; single bug report; on latest version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:authbugSomething isn't workinghas reproHas detailed reproduction stepsplatform:macosIssue specifically occurs on macOS

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions