{"version":"2.1.286","anchor":"oauth-gateway-docs-endpoint-fallback-and-reverse-proxy-guid","canonical_anchor":"oauth-gateway-docs-endpoint-fallback-and-reverse-proxy-guid","heading":"Gateway sign-in endpoints fall back to defaults instead of having to share one origin","tier":"notice","area":"Gateways","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/oauth-gateway-docs-endpoint-fallback-and-reverse-proxy-guid","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Gateway sign-in endpoints fall back to defaults instead of having to share one origin\n\nGateway sign-in endpoints are used only if they are absolute same-origin URLs, otherwise defaults apply; reverse proxies on another hostname are covered\n\n**Unclear.** Whether the client code behaves exactly as this text describes is not confirmed.\n\n**What**\n\nA gateway is a server some organisations put between Claude Code and the service, and it handles sign-in. The documentation built into Claude Code for people who build gateways has changed.\n\n- `device_authorization_endpoint`, `token_endpoint` and `revocation_endpoint` are each used only if they are an absolute URL on the same origin as `{base}`, the gateway's base address. Before, the text said all of them had to be on that origin.\n\n- Otherwise the client falls back to `{base}\/oauth\/device_authorization` or `{base}\/oauth\/token`, and skips revocation, the step that cancels a sign-in token.\n\n- A gateway reached through a reverse proxy on another hostname works if the proxy serves every path.\n\n**Why**\n\nThe text reflects a change in client behaviour: a gateway that advertises an unusable endpoint no longer breaks sign-in, because Claude Code uses the standard path instead. If you run a gateway, sign-out may skip revocation when your revocation endpoint is on a different origin.\n\n- Area: Gateways\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}