{"name":"client_assertion","slug":"client-assertion","family":"setting","title":"Settings keys","noun":"settings key","description":"The gateway's OIDC config accepts `private_key_jwt` with a certificate in `oidc.client_assertion`, so `oidc.client_secret` is now optional","description_source":"entry","described_by":{"version":"2.1.284","anchor":"gateway-oidc-supports-private-key-jwt-certificate-client-aut"},"presence":{"first_seen":"2.1.287","removed_in":null,"in_current_build":true,"newest_mined":"2.1.295","builds":9,"mined_builds":138,"first_cited":{"version":"2.1.284","released_at":"2026-09-28 17:11:59","spans":1}},"aliases":[],"entries":[{"version":"2.1.284","anchor":"gateway-oidc-supports-private-key-jwt-certificate-client-aut","heading":"Claude gateway can sign in to its identity provider with a certificate","line":"The gateway's OIDC config accepts `private_key_jwt` with a certificate in `oidc.client_assertion`, so `oidc.client_secret` is now optional","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"}],"entries_total":1,"docs":[{"source":"api","path":"manage-claude\/wif-providers\/azure","title":"Create the app registration that represents the Claude API audience.","documented":false},{"source":"api","path":"manage-claude\/wif-providers\/okta","title":"okta","documented":false},{"source":"claude-code","path":"claude-apps-gateway-config","title":"Claude apps gateway configuration","documented":false}],"docs_total":3,"gates":[],"related":[{"name":"client_id","slug":"client-id","description":"MCP OAuth token refresh retries smarter and keeps your saved redirect URI across reconnects."},{"name":"client_secret","slug":"client-secret","description":"The gateway's OIDC config accepts `private_key_jwt` with a certificate in `oidc.client_assertion`, so `oidc.client_secret` is now optional"},{"name":"clientRequestId","slug":"clientrequestid","description":"API success telemetry now records time-to-first-content, a client request id, and the user message's UUID"},{"name":"clientSecretHelper","slug":"clientsecrethelper","description":"Hosted managed config now rejects an MCP server's OAuth client secret unless it is a Google client, and points others to oauth.clientSecretHelper"},{"name":"clientSlackTagConnected","slug":"clientslacktagconnected","description":"Slack-connected ('Claude Tag') sessions now skip writing remote feature flags to disk"}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/client-assertion","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}