Claude apps gateway configuration changedclaude-apps-gateway-config
Nearest release: v2.1.292, published 7 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 7 Oct 2026 00:29 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 7 Oct 2026 00:37 UTC.
Upstream edited
Recorded here
Lines+3added
Lines−3removed
From line
140
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits47to this page, all time
The whole hunk
from line 140, old and new numbered
/
from line 140
140140The gateway reads the key and certificate once at boot, so a changed file takes effect only after a restart. Rotate in this order so that no token request presents a certificate the IdP doesn't have:
141141
1421421. Upload the new certificate to the IdP alongside the old one.
1432. Replace the key and certificate files that `gateway.yaml` loads, then restart the gateway.
1443. Remove the old certificate from the IdP.
1432. Replace the key and certificate files that `gateway.yaml` loads, then restart the gateway. If you run several replicas, a [rolling restart](/docs/en/claude-apps-gateway-deploy#upgrades) works, because the IdP has both certificates until you remove the old one.
1443. After every replica has restarted, remove the old certificate from the IdP.
145145
146146#### IdP requests through a forward proxy
147147
from line 201
201201
202202| Field | Required | Description |
203203| - | - | - |
204| `postgres_url` | Yes | `postgres://` or `postgresql://` URL. Required: the device-grant rendezvous, where the browser callback writes and the polling CLI reads, needs cross-replica state. The gateway runs its own schema migrations at boot and on upgrade, so the role needs rights to create and alter tables on the target schema. See [Upgrades](/docs/en/claude-apps-gateway-deploy#upgrades) and [Postgres](/docs/en/claude-apps-gateway-deploy#postgres). |
204| `postgres_url` | Yes | `postgres://` or `postgresql://` URL with one host, not a comma-separated list. The gateway runs its own schema migrations at boot and on upgrade, so the role needs rights to create and alter tables on the target schema. See [Upgrades](/docs/en/claude-apps-gateway-deploy#upgrades) and [Postgres](/docs/en/claude-apps-gateway-deploy#postgres). |
205205| `username` | No | Overrides the user in `postgres_url` |
206206| `password` | No | Database credential. Set it here rather than in `postgres_url` so the credential stays out of the URL. Accepts any characters and takes precedence over URL credentials. |
207207| `max_connections` | No | Postgres connection-pool size per replica. Default `5`, which is conservative and friendly to shared databases. With [spend limits](#admin) enabled, the hot path does a few operations per inference request, so raise it for a dedicated database under load, and keep replicas × this below the database's `max_connections`. |
No line in this hunk matches that.