What
.github/workflows/claude-code-review.yml fails on every pull request. Checked the last eight
runs: every PR-branch run is failure, every develop run is skipped (by design, it only runs on
PRs). Confirmed on #399, #402, #403, #405 and #406.
Every check on those PRs was green. The review job was the only red one, and it has been red long
enough that it is now routinely merged past, which is the actual cost: a permanently failing check
trains everyone to stop reading CI.
It is not the reviews, and not the code
The failing step is Run Claude Review, and the result object says:
"type": "result",
"subtype": "success",
"is_error": true,
"duration_ms": 164,
"num_turns": 1,
"total_cost_usd": 0,
"permission_denials_count": 0
164 milliseconds, one turn, zero cost, zero permission denials. It exits before doing any work
and without making a billable model call, which rules out the diff, the prompt, a tool failure, a
timeout and a rate limit.
Almost certainly the credential
The workflow authenticates with claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
(claude-code-review.yml:50). That secret was last updated 2026-01-06, over eight months ago.
An expired or revoked OAuth token produces exactly this shape: immediate failure, no turns, no cost.
I cannot verify the token's contents or rotate it, so this is stated as the strong hypothesis it is
rather than a confirmed root cause. It is cheap to test by rotating.
Fix
Someone with repository admin generates a fresh token and updates the secret:
claude setup-token
gh secret set CLAUDE_CODE_OAUTH_TOKEN --repo sccn/eegprep
Then re-run the workflow on any open PR and confirm it posts a review.
Worth deciding at the same time
If this job is not going to be kept working, it should be removed rather than left failing. A check
that is always red is worse than no check: it costs a CI slot on every push and it teaches people
that a red X on this repository means nothing.
Related
What
.github/workflows/claude-code-review.ymlfails on every pull request. Checked the last eightruns: every PR-branch run is
failure, everydeveloprun isskipped(by design, it only runs onPRs). Confirmed on #399, #402, #403, #405 and #406.
Every check on those PRs was green. The review job was the only red one, and it has been red long
enough that it is now routinely merged past, which is the actual cost: a permanently failing check
trains everyone to stop reading CI.
It is not the reviews, and not the code
The failing step is
Run Claude Review, and the result object says:164 milliseconds, one turn, zero cost, zero permission denials. It exits before doing any work
and without making a billable model call, which rules out the diff, the prompt, a tool failure, a
timeout and a rate limit.
Almost certainly the credential
The workflow authenticates with
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}(
claude-code-review.yml:50). That secret was last updated 2026-01-06, over eight months ago.An expired or revoked OAuth token produces exactly this shape: immediate failure, no turns, no cost.
I cannot verify the token's contents or rotate it, so this is stated as the strong hypothesis it is
rather than a confirmed root cause. It is cheap to test by rotating.
Fix
Someone with repository admin generates a fresh token and updates the secret:
Then re-run the workflow on any open PR and confirm it posts a review.
Worth deciding at the same time
If this job is not going to be kept working, it should be removed rather than left failing. A check
that is always red is worse than no check: it costs a CI slot on every push and it teaches people
that a red X on this repository means nothing.
Related