Auth failures now name where the bad credential came from, like your custom headers.
What's wrong with this entry?
When a request is rejected and the credentials came from headers rather than a plain API key, the error now names the actual source: ANTHROPIC_CUSTOM_HEADERS, an external auth token, or an external API key, with the server's own message appended after a middot.
- Previously these fell through to the generic x-api-key wording, which pointed at a setting the user was not using.
- Credentials from a managed key or from a claude.ai login are classified as an authentication failure instead.
Invalid ANTHROPIC_CUSTOM_HEADERS
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.223
api.anthropic.com and api-staging.anthropic.com are accepted as trusted OAuth origins
Both mention custom auth