Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-code

Claude apps gateway deployment and operations changedclaude-apps-gateway-deploy

Nearest release: v2.1.289, published 8 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 4 Oct 2026 05:10 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 4 Oct 2026 05:37 UTC.

Upstream edited
Recorded here
Lines+8added
Lines−1removed
From line 377 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits23to this page, all time

The whole hunk

from line 377, old and new numbered
/
lines
from line 377
377377 
378378The gateway answers `431` when a request's headers total more than 256 KiB, or more than [`limits.max_request_header_bytes`](/docs/en/claude-apps-gateway-config#http-tuning) if you set it. It writes no log line or audit event for these requests. Gateway versions before v2.1.284 answer `431` above 16 KiB.
379379 
380What to change depends on your gateway's version and configuration:
380Start with the first of these that applies to your gateway:
381381 
382382* **Gateway older than v2.1.284**: upgrade the gateway
383383* **`limits.max_request_header_bytes` set**: raise the value or remove the key
384384* **Neither applies, or `431` continues afterward**: have your IdP emit fewer groups. [Identity provider setup](#identity-provider-setup) covers how Okta, Microsoft Entra ID, and Google Workspace supply groups
385 
386When you trim the groups claim, keep the groups you named in these settings, which decide a developer's access, policy, and spend caps:
387 
388* **[`oidc.allowed_groups`](/docs/en/claude-apps-gateway-config#oidc)**: decides who can sign in
389* **[`admin.admin_groups`](/docs/en/claude-apps-gateway-config#admin)**: decides who can call the admin API with their gateway session
390* **`match.groups` in [`managed.policies`](/docs/en/claude-apps-gateway-config#managed)**: decides which policy applies to a developer
391* **`rbac_group` [spend caps](/docs/en/claude-apps-gateway-spend-limits)**: decide which group caps apply to a developer
385392 
386393## Related
387394 
Feedback