What
A gateway is a server some organisations put between Claude Code and the service, and it handles sign-in. The documentation built into Claude Code for people who build gateways has changed.
device_authorization_endpoint,token_endpointandrevocation_endpointare each used only if they are an absolute URL on the same origin as{base}, the gateway's base address. Before, the text said all of them had to be on that origin.- Otherwise the client falls back to
{base}/oauth/device_authorizationor{base}/oauth/token, and skips revocation, the step that cancels a sign-in token. - A gateway reached through a reverse proxy on another hostname works if the proxy serves every path.
Why
The text reflects a change in client behaviour: a gateway that advertises an unusable endpoint no longer breaks sign-in, because Claude Code uses the standard path instead. If you run a gateway, sign-out may skip revocation when your revocation endpoint is on a different origin.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Whether the client code behaves exactly as this text describes is not confirmed.