Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.218 Home All releases olderv2.1.217 v2.1.219newer
Claude Code v2.1.218

MCP XAA (Cross-Account Authentication) via JWT-Bearer

New infrastructure for MCP servers that require enterprise cross-account OAuth authentication. The flow:

  1. Performs Protected Resource Metadata (PRM) discovery against the MCP server URL
  2. Exchanges an identity provider ID token for an intermediate JWT Authorization Grant (ID-JAG)
  3. Exchanges the ID-JAG for an access token at the authorization server via the urn:ietf:params:oauth:grant-type:jwt-bearer grant type

ID tokens are cached in user config keyed by normalized IdP URL. This is infrastructure for enterprise MCP authentication scenarios; end users will see this flow when their MCP server requires cross-account auth.

Evidence

New XAA implementation (search for "XAA: PRM discovery failed")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.218 →