{"version":"2.1.286","anchor":"oauth-provider-docs-tls-and-client-guarantees-text-updated","canonical_anchor":"oauth-provider-docs-tls-and-client-guarantees-text-updated","heading":"Built-in OAuth provider documentation says endpoint paths come from discovery","tier":"notice","area":"Gateways","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/oauth-provider-docs-tls-and-client-guarantees-text-updated","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Built-in OAuth provider documentation says endpoint paths come from discovery\n\nThe OAuth provider documentation built into Claude Code now says endpoint paths come from the discovery document and explains re-login after a certificate change\n\n**What**\n\nClaude Code includes documentation for people running their own sign-in (OAuth) server. OAuth is the standard way a program signs you in through a separate login service. That text changed:\n\n- A new \"Client guarantees\" section says the OAuth endpoint paths come from your discovery document, the file where a sign-in server lists its addresses. The text used to say the client always uses `\/oauth\/token`.\n\n- After a certificate rotation, the documentation now says the user must run `\/login` and accept the new certificate.\n\n**Why**\n\nIf you operate a custom OAuth host, the documentation now says Claude Code uses the paths your discovery document gives instead of a fixed path, and that users need to sign in again after you change certificates.\n\n- Area: Gateways\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}