Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.293 ·

Hosted managed MCP config now refuses client secrets except Google ones

Hosted managed config now rejects an MCP server's OAuth client secret unless it is a Google client, and points others to oauth.clientSecretHelper

You'll notice Improvements
JSON All of v2.1.293
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
MCPArea: what it touches
ImprovementsKind: in v2.1.293,
ImprovementsSection of the release

Unclear It is not clear how much of this checking applies to the command-line tool rather than to Desktop and the hosted control plane.

What

This concerns hybrid, or hosted, managed configuration, where an organisation's settings are stored and served centrally. Within it, managedMcpServers is the setting that hands MCP servers (outside services that give Claude extra tools) to every user. That setting now has stricter checks:

  • A stored OAuth client secret (a password-like value an app uses to sign in to a service) is refused unless the server is a Google OAuth client.
  • For Google, the sign-in server must be exactly https://accounts.google.com, and the secret must have Google's usual shape, starting with GOCSPX-.
  • For any other identity provider, Claude Code says to supply the secret through oauth.clientSecretHelper instead.
  • Gateway identity-provider OIDC keys (sign-in details for a company login system) are moved to a credential type called external-idp.
  • A configuration that turns on no surface at all, meaning no tab the app could open, now produces a warning asking you to enable at least one.

Before this, there was no client-secret check. The surface check looked only at whether the cowork and chat tabs were enabled.

Why

Hosted managed config can now hold fewer secrets directly. Administrators using a provider other than Google need to move the secret to a helper. The new warning catches a configuration that would leave the app with nothing to show.

Read from
Names in the bundlemanagedMcpServers
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear how much of this checking applies to the command-line tool rather than to Desktop and the hosted control plane.

See this entry in the whole of v2.1.293 →

Feedback