Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.223 Home All releases olderv2.1.222 v2.1.224newer

api.anthropic.com and api-staging.anthropic.com are accepted as trusted OAuth origins

You'll notice
Useful2 Signal0
Auth not in their notes

Login now trusts a fixed set of Anthropic API origins unless you point it at a custom OAuth URL.

CLAUDE_CODE_CUSTOM_OAUTH_URL
What

OAuth origin validation now trusts a fixed set of Anthropic API origins rather than only the origin derived from the configured base API URL.

Details
  • If CLAUDE_CODE_CUSTOM_OAUTH_URL is set, only the configured origin is trusted and the fixed set is not consulted.
  • Rejections still report a reason: not_https, userinfo_or_port or untrusted_origin.
Evidence

https://api-staging.anthropic.com

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.223 →