{"version":"2.1.281","anchor":"oauth-token-save-now-records-the-host","canonical_anchor":"oauth-token-save-now-records-the-host","heading":"OAuth token save now records the host","tier":"internal","area":"Auth","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/oauth-token-save-now-records-the-host","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### OAuth token save now records the host\n\nSaving claude.ai sign-in tokens now also records which host they belong to\n\n**Unclear.** The finding does not say how the recorded host is used afterwards.\n\n**What**\n\nWhen you sign in with a claude.ai account, Claude Code stores sign-in tokens (the saved credentials that keep you logged in) under the name `claudeAiOauth`. Before saving them, it now builds a value tied to the current host, the server address Claude Code is talking to.\n\n**Why**\n\nIn practice, saved sign-in details are now linked to a specific host rather than stored with no record of where they came from.\n\n- Area: Auth\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 2\/5"}