Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Device-code sign-in page redesigned and gains a way to deny a request

The gateway's /device sign-in page is restyled for accessibility, can now deny a sign-in request, and refuses codes already used or expired

Group of 2 You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
AuthArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

What

Device-code sign-in is the flow where a device shows you a code and you type it into a web page to approve the sign-in. The gateway's /device page for enterprise identity providers changed in several ways:

  • Redesigned page: the status badge ("Connect device" / "Confirm device") and the error card were replaced by a plain heading, a refusal paragraph marked role=alert, and an input labelled with aria-labelledby. These make the page easier to use with screen readers. The page now reads "Enter the code from your device."
  • Deny endpoint: alongside POST /device there is now POST /device/deny, which marks a pending code as denied and shows you a result page.
  • Safer completion: finishing a sign-in now writes the result only if the code is still pending (setIfUnchanged), so a code that was already used or denied cannot be overwritten. Before, the result was written unconditionally.
  • Clear message for stale codes: a code that is no longer pending shows "This device code has already been used or has expired."

Why

You can now reject a sign-in request you did not start rather than just ignoring it. A code that has already been used or denied can no longer be completed a second time.

See this entry in the whole of v2.1.290 →

Feedback