Claude Code · Certificates and network
SSL certificate is not yet valid (CERT_NOT_YET_VALID)
The certificate’s start date is in the future as far as your computer knows, which almost always means your system clock is wrong.
Message
The exact error
Unable to connect to API: SSL certificate is not yet validAlso appears as:
- During /login (OAuth error)
- OAuth error: SSL certificate error (CERT_NOT_YET_VALID). If you are behind a corporate proxy or TLS-intercepting firewall, set NODE_EXTRA_CA_CERTS to your CA bundle path, or ask IT to allowlist *.anthropic.com. Run `claude doctor` for details.
Meaning
What it means
Certificates are valid between two dates. This error means the current time on your computer is before the certificate’s start date. Anthropic’s certificates aren’t issued in the future, so the usual culprit is a clock that’s behind: a laptop with a dead battery, a virtual machine restored from a snapshot, or a dual-boot system with mismatched time settings. Less often, a proxy issues a fresh certificate and your clock is a few minutes behind it.
Causes
Common causes
- Your computer’s date or time is behind (check the year too)
- A virtual machine, container or WSL instance whose clock drifted after sleep or snapshot restore
- A TLS-inspecting proxy minting certificates that start a moment after your slightly slow clock
Fix
How to fix it
Set the clock automatically
On Windows you can also use Settings › Time & language › Date & time › Sync now. On WSL, restarting it with
wsl --shutdownfrom Windows usually brings its clock back in line.Windows (PowerShell as administrator) w32tm /resyncLinux and WSL timedatectl set-ntp true datemacOS System Settings › General › Date & Time › turn on “Set time and date automatically”Check the date the error mentions
Open
https://api.anthropic.comin a browser on the same machine. If the browser shows the same certificate date error, the clock is the problem; if it loads normally, look at a proxy between Claude Code and the internet.If the clock is right, talk to whoever runs the proxy
A proxy that issues certificates starting exactly now can trip clocks that are slightly behind. Your IT team can backdate the certificates it issues by a few minutes, or exclude
*.anthropic.comfrom inspection.
Don’t do this
- Don’t set
NODE_TLS_REJECT_UNAUTHORIZED=0. It switches off certificate checking entirely, so any machine on the network could read or change your traffic, including your API key.
Related