What's Wrong?
The manual OAuth paste flow rejects input with:
OAuth error: Invalid code. Please make sure the full code was copied
The message directs the user to verify the code's length. The actual failure
condition is a missing # delimiter, which no length check can detect. A user whose
pasted value is long and complete-looking has no way to self-diagnose, producing an
unresolvable retry loop.
From the shipping binary, the parser is:
let [code, state] = input.trim().split("#");
if (!code || !state) { error("Invalid code. Please make sure the full code was copied") }
Input must contain # with non-empty content on both sides (<code>#<state>).
The delimiter is easy to lose for two reasons, both invisible to the user:
# is a word boundary — double-click selection stops before #state.
# is the URL fragment delimiter — any URL normalization drops everything after it.
What Should Happen?
The error should name the actual condition and how to fix it. Suggested:
"Code must be in the form `code#state`. Copy the entire value, including the `#`
and everything after it. Tip: `#` is a word boundary — double-clicking selects
only the first half."
And distinguish the two failure modes: missing delimiter vs. one side empty.
Error Messages / Logs
OAuth error: Invalid code. Please make sure the full code was copied
Press Enter to retry.
Two clipboard states captured during live failures on this machine:
attempt 1 : 346 chars, contains '#': NO -> rejected
attempt 2 : 1084 chars, contains '#': NO -> rejected
Both were long and untruncated. Both failed on the delimiter alone.
Steps to Reproduce
- Run
claude in a terminal and start the login flow.
- When the authorize page displays the code, double-click the code to select it
(this is the natural gesture and selects only up to the #).
- Copy, and paste at the
Paste code here if prompted > prompt.
- Observe: "Invalid code. Please make sure the full code was copied"
- Verify the clipboard was NOT truncated:
pbpaste | wc -c # long
pbpaste | grep -c '#' # 0 <- the actual cause
- Following the message's advice (checking the code is "full") confirms it looks
complete and returns you to step 4.
Additional Information
Ruled out during diagnosis: browser-specific behavior (reproduces in multiple browsers
including a fresh in-app browser), network interception (the authorize URL is built from
client constants and printed before any network request is made), and credential expiry
(credentials were valid throughout).
Environment
|
|
| Claude Code |
2.1.212 (Claude Code) |
| Platform |
Claude API (Max subscription) |
| OS |
macOS 27.0 (build 26A5425a, developer beta) |
| Hardware |
Apple M2 Pro, arm64 |
| Terminal / Shell |
Ghostty 1.3.1 / zsh (also reproduced in Terminal.app) |
| Model |
Opus |
| Regression |
No — not tested against a prior version |
Preflight: searched existing issues; single bug report; on latest version.
What's Wrong?
The manual OAuth paste flow rejects input with:
The message directs the user to verify the code's length. The actual failure
condition is a missing
#delimiter, which no length check can detect. A user whosepasted value is long and complete-looking has no way to self-diagnose, producing an
unresolvable retry loop.
From the shipping binary, the parser is:
Input must contain
#with non-empty content on both sides (<code>#<state>).The delimiter is easy to lose for two reasons, both invisible to the user:
#is a word boundary — double-click selection stops before#state.#is the URL fragment delimiter — any URL normalization drops everything after it.What Should Happen?
The error should name the actual condition and how to fix it. Suggested:
And distinguish the two failure modes: missing delimiter vs. one side empty.
Error Messages / Logs
Two clipboard states captured during live failures on this machine:
attempt 1 : 346 chars, contains '#': NO -> rejected
attempt 2 : 1084 chars, contains '#': NO -> rejected
Both were long and untruncated. Both failed on the delimiter alone.
Steps to Reproduce
claudein a terminal and start the login flow.(this is the natural gesture and selects only up to the
#).Paste code here if prompted >prompt.pbpaste | wc -c # long
pbpaste | grep -c '#' # 0 <- the actual cause
complete and returns you to step 4.
Additional Information
Ruled out during diagnosis: browser-specific behavior (reproduces in multiple browsers
including a fresh in-app browser), network interception (the authorize URL is built from
client constants and printed before any network request is made), and credential expiry
(credentials were valid throughout).
Environment
Preflight: searched existing issues; single bug report; on latest version.