Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.228 Home All releases olderv2.1.227 v2.1.229newer
Claude Code v2.1.228

Gateway OAuth endpoints return 404 when sign-in is not configured

You'll notice
Useful2 Signal2
Gateway

Gateway sign-in endpoints return a flat 404 when no identity provider is configured.

What

On the self-hosted gateway, POST /oauth/device_authorization and POST /oauth/token now answer with a plain 404 not found when the OIDC identity-provider config is absent, before any rate-limiting or form parsing. Previously the handlers ran regardless.

Details
  • This matches the discovery document, which already omitted both endpoints unless OIDC config was present.
  • The guard reads a config precondition; the exact config key it checks is not fully pinned down in the build.
Evidence

/oauth/device_authorization

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.228 →