Claude apps gateway deployment and operations changedclaude-apps-gateway-deploy
Nearest release: v2.1.289, published 8 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 4 Oct 2026 05:10 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 4 Oct 2026 05:37 UTC.
Upstream edited
Recorded here
Lines+8added
Lines−1removed
From line
377
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits23to this page, all time
The whole hunk
from line 377, old and new numbered
/
from line 377
377377
378378The gateway answers `431` when a request's headers total more than 256 KiB, or more than [`limits.max_request_header_bytes`](/docs/en/claude-apps-gateway-config#http-tuning) if you set it. It writes no log line or audit event for these requests. Gateway versions before v2.1.284 answer `431` above 16 KiB.
379379
380What to change depends on your gateway's version and configuration:
380Start with the first of these that applies to your gateway:
381381
382382* **Gateway older than v2.1.284**: upgrade the gateway
383383* **`limits.max_request_header_bytes` set**: raise the value or remove the key
384384* **Neither applies, or `431` continues afterward**: have your IdP emit fewer groups. [Identity provider setup](#identity-provider-setup) covers how Okta, Microsoft Entra ID, and Google Workspace supply groups
385
386When you trim the groups claim, keep the groups you named in these settings, which decide a developer's access, policy, and spend caps:
387
388* **[`oidc.allowed_groups`](/docs/en/claude-apps-gateway-config#oidc)**: decides who can sign in
389* **[`admin.admin_groups`](/docs/en/claude-apps-gateway-config#admin)**: decides who can call the admin API with their gateway session
390* **`match.groups` in [`managed.policies`](/docs/en/claude-apps-gateway-config#managed)**: decides which policy applies to a developer
391* **`rbac_group` [spend caps](/docs/en/claude-apps-gateway-spend-limits)**: decide which group caps apply to a developer
385392
386393## Related
387394
No line in this hunk matches that.