← All incidents

minorotherverifiedfirsthand

The credentials were simply gone, but the AI agent blamed the CLI flags

An agent built into a home-made business system failed with `claude-cli exited with code 1`. The AI coding agent went after the CLI flags and concluded that an earlier workaround had stopped working.

Observed
Severity score
3/10
Blast radius
uptime
Tags
#claude-code#authentication#misdiagnosis#cli-flags

Cause

In reality, neither the login credentials file nor the Keychain entry existed; the login had vanished entirely. Without credentials, every flag combination fails with the same message, so no difference between flags could ever have shown up.

Consequence

Diagnosis time went into comparing flags, and a wrong conclusion — 'the workaround broke' — was reached. The practical damage was limited to the business system's agent being down until recovery.

Fix

Running /login from claude and signing back in with the subscription account restored it. When you see 'Not logged in', check that credentials exist at all before touching flags.

What happened

A home-built business system includes a secretary agent that works by calling the claude CLI. One day it failed with claude-cli exited with code 1. Running it by hand gave Not logged in · Please run /login.

That message was familiar. With an earlier CLI version, claude -p --bare had failed with the same words because it skipped reading the auth store. Back then, --setting-sources "" had been verified on the machine as a working substitute, and it was recorded as the workaround.

The chaos on the ground

The AI coding agent followed that memory. It suspected the flags first and tried the variants one by one: with --bare, with --setting-sources "", and plain claude -p with nothing extra.

Every one of them came back identical: Not logged in · Please run /login.

The agent’s conclusion was “the workaround has stopped working.” It used to pass with --setting-sources ""; now it didn’t; therefore the workaround broke. It sounds logical, but the comparison had no foundation. Everything failed the same way not because the difference between flags had disappeared, but because the thing that would have produced a difference wasn’t there.

Root cause

Neither the credentials file (~/.claude/.credentials.json) nor the Keychain entry existed. The login was gone, full stop. It wasn’t a balance problem and it wasn’t a flag problem.

With no credentials at all, every flag combination fails with the same message, so of course comparing flags showed nothing. Because the error text matched a known past issue, the diagnosis started from “same cause as last time” and skipped the most basic check.

The fix

  • Started claude in a terminal, ran /login, chose the subscription account, and approved it in the browser. That restored everything.
  • When “Not logged in” appears, don’t start with the flags. Look at the credentials file and the Keychain and confirm credentials exist at all.
  • When every variant produces the same result, suspect a missing shared precondition, not “everything broke at once.” Comparisons only mean something when the ground under them is the same.

This diagnostic order was added to the top of the note that records the old workaround, so the next agent that sees the same message doesn’t take the same shortcut.

Sources

  • Firsthand account from the site operator. There is no public write-up to link to.