DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.
Requests no longer send cookie and bearer credentials together
You'll notice
Useful3Signal2
Internals
Requests now send only one form of credential, never a cookie and a bearer token together.
What's wrong with this entry?
Anonymous. No account, no email.
What
Outgoing request headers are now cleaned so only one credential goes out: a cookie removes the Authorization header, and an Authorization header removes both the cookie and X-Organization-Uuid.
Details
The bearer header is now built by a shared constructor rather than each site writing Bearer itself.
Evidence
X-Organization-Uuid
Strings lifted out of the shipped bundle, so the claim above can be checked against them.