Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Reading a new release v2.1.280 First look · 1/6 0 findings $0.00 so far
One change · claude-docs

Connect a service that isn't in the list changed

claude-tag/admins/connections/custom

Nearest release: v2.1.268, published 2 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Recorded here
Lines+16added
Lines−8removed
From line 39 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits8to this page, all time

The whole hunk

from line 39, old and new numbered
/
lines
from line 39
3939| **Bearer** | An API key or token sent as `Authorization: Bearer <token>`. Most SaaS REST APIs. |
4040| **Basic** | HTTP Basic authentication (`Authorization: Basic <base64(user:password)>`) |
4141| **Body parameter** | A token the API expects in the request body or query string instead of a header |
42| **AWS SigV4** | AWS services and APIs that require Signature Version 4 signing |
42| **AWS SigV4** | AWS service APIs on `amazonaws.com` endpoints that require Signature Version 4 signing |
4343| **GCP access token (with Service Account Key)** | Google Cloud APIs; the proxy exchanges the SA key for an access token |
4444| **GCP IAP (with Service Account Key)** | Google Cloud services behind Identity-Aware Proxy |
4545| **OAuth 2.0 JWT bearer** | APIs that accept a JWT signed with your private key in exchange for an access token (DocuSign, for example) |
from line 52
5252 
5353### AWS SigV4
5454 
55Use the **AWS SigV4** credential type for AWS service APIs (S3, Lambda, Amazon Bedrock, an API Gateway endpoint with IAM authorization). Agent Proxy reads the AWS service and signing region from the hostname and signs each outbound request with the credential at the boundary, so neither the model nor the sandbox holds the keys. The host must be an `amazonaws.com` endpoint; the proxy can't sign requests to an API Gateway custom domain or to a non-AWS API that uses Signature Version 4.
55Use the **AWS SigV4** credential type for AWS service APIs such as S3, Lambda, and DynamoDB. Agent Proxy reads the AWS service and signing region from the hostname and signs each outbound request with the credential at the boundary, so neither the model nor the sandbox holds the keys.
5656 
57| Field | Value |
58| :---------------- | :---------------------------------------------------------------------------------------------------------------------- |
59| Access key ID | The IAM user or role access key, for example `AKIAIOSFODNN7EXAMPLE` |
60| Secret access key | The matching secret access key |
61| Session token | Optional. Only needed for temporary credentials from AWS STS. |
62| Allowed websites | The AWS service endpoint host, for example `s3.us-east-1.amazonaws.com` or `abc123.execute-api.us-east-1.amazonaws.com` |
57Agent Proxy signs requests to hostnames in these forms:
58 
59* `service.region.amazonaws.com`
60* S3 virtual-hosted-style endpoints, for example `my-bucket.s3.us-east-1.amazonaws.com`
61* The regionless hosts of global AWS services such as IAM, STS, and CloudFront
62 
63Apart from S3 virtual-hosted-style endpoints, Agent Proxy can't read the service from a hostname that has extra parts before the service name, so requests to those hosts fail before reaching AWS. Examples include the host of an API Gateway invoke URL, such as `abc123.execute-api.us-east-1.amazonaws.com`, and the host of an Amazon Managed Workflows for Apache Airflow (MWAA) environment. The proxy also can't sign requests to an API Gateway custom domain or to a non-AWS API that uses Signature Version 4.
64 
65| Field | Value |
66| :---------------- | :---------------------------------------------------------------------------------------------------------- |
67| Access key ID | The IAM user or role access key, for example `AKIAIOSFODNN7EXAMPLE` |
68| Secret access key | The matching secret access key |
69| Session token | Optional. Only needed for temporary credentials from AWS STS. |
70| Allowed websites | The AWS service endpoint host, for example `s3.us-east-1.amazonaws.com` or `lambda.us-east-1.amazonaws.com` |
6371 
6472Use long-lived credentials from a dedicated IAM user where you can. Temporary STS credentials work but expire on their own schedule, and the connection stops working when they do; you re-enter all three values to rotate.
6573