Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
Internal ChangesKind: in v2.1.284,
Internal ChangesSection of the release
What
When Claude Code registers itself with a server that uses OAuth, a common sign-in standard, it tells the server how it will prove its identity. If that method is configured as private_key_jwt, Claude Code now sends "none" instead of passing the value through. Other values work as before, using client_secret_basic or client_secret_post depending on what the server supports.
Why
Servers that advertise private_key_jwt should now get a registration they accept, instead of one that Claude Code cannot then complete.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether this applies to MCP server sign-in specifically is not confirmed.
Anthropic's release notes agreeAdded certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers…