Built-in OAuth provider documentation says endpoint paths come from discovery
The OAuth provider documentation built into Claude Code now says endpoint paths come from the discovery document and explains re-login after a certificate change
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
GatewaysArea: what it touches
ImprovementsKind: in v2.1.286,
ImprovementsSection of the release
What
Claude Code includes documentation for people running their own sign-in (OAuth) server. OAuth is the standard way a program signs you in through a separate login service. That text changed:
A new "Client guarantees" section says the OAuth endpoint paths come from your discovery document, the file where a sign-in server lists its addresses. The text used to say the client always uses /oauth/token.
After a certificate rotation, the documentation now says the user must run /login and accept the new certificate.
Why
If you operate a custom OAuth host, the documentation now says Claude Code uses the paths your discovery document gives instead of a fixed path, and that users need to sign in again after you change certificates.
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeFixed macOS sessions still showing "Not logged in" or "Login expired" after /login succeeds in another Claude Code window when a leftover…