What probably matters to youSection of the release
What
The Claude gateway signs in to an identity provider (the service that manages your organisation's logins) using OIDC, a standard sign-in protocol. It can now prove who it is with a certificate instead of a shared secret. Set token_endpoint_auth_method: private_key_jwt and add an oidc.client_assertion block with private_key_pem and certificate_pem. oidc.client_secret is now optional, and it must be removed when you use this method.
The gateway signs a short-lived assertion, valid for 300 seconds, for the initial sign-in and for each token refresh. On refresh it is sent together with anything scope_on_refresh adds. At startup the gateway logs the certificate's thumbprint and expiry date. The configuration is rejected when:
the private key is encrypted
the key is not RSA, or is under 2048 bits
a certificate chain is given instead of a single certificate
the certificate does not match the key
the identity provider's discovery document lists no token endpoint
Why
The gateway can now work with identity providers, such as Microsoft Entra, that hand out certificates rather than client secrets.
Read from
Names in the bundletoken_endpoint_auth_methodoidc.client_assertionprivate_key_pemcertificate_pemoidc.client_secret
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeAdded certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers…