Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Claude gateway can sign in to its identity provider with a certificate

The gateway's OIDC config accepts private_key_jwt with a certificate in oidc.client_assertion, so oidc.client_secret is now optional

Use it now Notable New Features
JSON All of v2.1.284
Use it nowTier: how much it should matter to you
4Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
GatewayArea: what it touches
New FeaturesKind: in v2.1.284,
What probably matters to youSection of the release
What

The Claude gateway signs in to an identity provider (the service that manages your organisation's logins) using OIDC, a standard sign-in protocol. It can now prove who it is with a certificate instead of a shared secret. Set token_endpoint_auth_method: private_key_jwt and add an oidc.client_assertion block with private_key_pem and certificate_pem. oidc.client_secret is now optional, and it must be removed when you use this method.

The gateway signs a short-lived assertion, valid for 300 seconds, for the initial sign-in and for each token refresh. On refresh it is sent together with anything scope_on_refresh adds. At startup the gateway logs the certificate's thumbprint and expiry date. The configuration is rejected when:

  • the private key is encrypted
  • the key is not RSA, or is under 2048 bits
  • a certificate chain is given instead of a single certificate
  • the certificate does not match the key
  • the identity provider's discovery document lists no token endpoint
Why

The gateway can now work with identity providers, such as Microsoft Entra, that hand out certificates rather than client secrets.

Read from
Names in the bundletoken_endpoint_auth_methodoidc.client_assertionprivate_key_pemcertificate_pemoidc.client_secret
What the documentation says
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeAdded certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers…

See this entry in the whole of v2.1.284 →

Feedback