{"version":"2.1.284","anchor":"gateway-oidc-supports-private-key-jwt-certificate-client-aut","canonical_anchor":"gateway-oidc-supports-private-key-jwt-certificate-client-aut","heading":"Claude gateway can sign in to its identity provider with a certificate","tier":"use","area":"Gateway","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/gateway-oidc-supports-private-key-jwt-certificate-client-aut","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Claude gateway can sign in to its identity provider with a certificate\n\nThe gateway's OIDC config accepts `private_key_jwt` with a certificate in `oidc.client_assertion`, so `oidc.client_secret` is now optional\n\n**What**\n\nThe Claude gateway signs in to an identity provider (the service that manages your organisation's logins) using OIDC, a standard sign-in protocol. It can now prove who it is with a certificate instead of a shared secret. Set `token_endpoint_auth_method: private_key_jwt` and add an `oidc.client_assertion` block with `private_key_pem` and `certificate_pem`. `oidc.client_secret` is now optional, and it must be removed when you use this method.\n\nThe gateway signs a short-lived assertion, valid for 300 seconds, for the initial sign-in and for each token refresh. On refresh it is sent together with anything `scope_on_refresh` adds. At startup the gateway logs the certificate's thumbprint and expiry date. The configuration is rejected when:\n\n- the private key is encrypted\n\n- the key is not RSA, or is under 2048 bits\n\n- a certificate chain is given instead of a single certificate\n\n- the certificate does not match the key\n\n- the identity provider's discovery document lists no token endpoint\n\n**Why**\n\nThe gateway can now work with identity providers, such as Microsoft Entra, that hand out certificates rather than client secrets.\n\n- Area: Gateway\n- Names: `token_endpoint_auth_method`, `oidc.client_assertion`, `private_key_pem`, `certificate_pem`, `oidc.client_secret`\n- Tier: Use it now\n- Useful: 4\/5\n- Signal: 2\/5"}