You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
MCPArea: what it touches
ImprovementsKind: in v2.1.293,
ImprovementsSection of the release
Unclear It is not clear how much of this checking applies to the command-line tool rather than to Desktop and the hosted control plane.
What
This concerns hybrid, or hosted, managed configuration, where an organisation's settings are stored and served centrally. Within it, managedMcpServers is the setting that hands MCP servers (outside services that give Claude extra tools) to every user. That setting now has stricter checks:
A stored OAuth client secret (a password-like value an app uses to sign in to a service) is refused unless the server is a Google OAuth client.
For Google, the sign-in server must be exactly https://accounts.google.com, and the secret must have Google's usual shape, starting with GOCSPX-.
For any other identity provider, Claude Code says to supply the secret through oauth.clientSecretHelper instead.
Gateway identity-provider OIDC keys (sign-in details for a company login system) are moved to a credential type called external-idp.
A configuration that turns on no surface at all, meaning no tab the app could open, now produces a warning asking you to enable at least one.
Before this, there was no client-secret check. The surface check looked only at whether the cowork and chat tabs were enabled.
Why
Hosted managed config can now hold fewer secrets directly. Administrators using a provider other than Google need to move the secret to a helper. The new warning catches a configuration that would leave the app with nothing to show.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear how much of this checking applies to the command-line tool rather than to Desktop and the hosted control plane.