Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

Gateway sign-in endpoints fall back to defaults instead of having to share one origin

Gateway sign-in endpoints are used only if they are absolute same-origin URLs, otherwise defaults apply; reverse proxies on another hostname are covered

Group of 2 You'll notice Improvements
JSON All of v2.1.286
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
GatewaysArea: what it touches
ImprovementsKind: in v2.1.286,
ImprovementsSection of the release

What

A gateway is a server some organisations put between Claude Code and the service, and it handles sign-in. The documentation built into Claude Code for people who build gateways has changed.

  • device_authorization_endpoint, token_endpoint and revocation_endpoint are each used only if they are an absolute URL on the same origin as {base}, the gateway's base address. Before, the text said all of them had to be on that origin.
  • Otherwise the client falls back to {base}/oauth/device_authorization or {base}/oauth/token, and skips revocation, the step that cancels a sign-in token.
  • A gateway reached through a reverse proxy on another hostname works if the proxy serves every path.

Why

The text reflects a change in client behaviour: a gateway that advertises an unusable endpoint no longer breaks sign-in, because Claude Code uses the standard path instead. If you run a gateway, sign-out may skip revocation when your revocation endpoint is on a different origin.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether the client code behaves exactly as this text describes is not confirmed.

See this entry in the whole of v2.1.286 →

Feedback