Claude Code · Certificates and network
SSL certificate has expired (CERT_HAS_EXPIRED)
A certificate in the chain is past its end date, usually because your clock is ahead or a proxy is serving an expired certificate.
Message
The exact error
Unable to connect to API: SSL certificate has expiredAlso appears as:
- During /login
- SSL certificate error (CERT_HAS_EXPIRED). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
Meaning
What it means
Claude Code rejected the connection because a certificate in the chain ended before the time your computer reports. Anthropic renews its certificates well before they expire, so the cause is nearly always local: a clock set in the future, an old corporate root that expired, or a proxy that kept serving a certificate past its date.
Causes
Common causes
- Your computer’s date is ahead (often the year)
- Your company’s proxy root or intermediate certificate has expired, or you pointed
NODE_EXTRA_CA_CERTSat an old copy - An outdated certificate store on an old operating system
Fix
How to fix it
Check your system clock first
Make sure the date, time and time zone are right and set automatically. The commands on the CERT_NOT_YET_VALID page apply here too.
Check which certificate expired
Open
https://api.anthropic.comin a browser on the same machine and inspect the certificate chain. If a company or security-product certificate in the chain is expired, ask IT to renew it, then export the new root and update yourNODE_EXTRA_CA_CERTSfile.Update your system’s certificates
Debian / Ubuntu sudo apt-get update && sudo apt-get install ca-certificatesmacOS and Windows Install pending operating system updates; root certificates update with the OS.
Don’t do this
- Don’t set
NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.
Related