{"version":"2.1.293","anchor":"managed-config-hybrid-validation-google-oauth-client-secret","canonical_anchor":"managed-config-hybrid-validation-google-oauth-client-secret","heading":"Hosted managed MCP config now refuses client secrets except Google ones","tier":"notice","area":"MCP","scope":"org","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/managed-config-hybrid-validation-google-oauth-client-secret","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Hosted managed MCP config now refuses client secrets except Google ones\n\nHosted managed config now rejects an MCP server's OAuth client secret unless it is a Google client, and points others to oauth.clientSecretHelper\n\n**Unclear.** It is not clear how much of this checking applies to the command-line tool rather than to Desktop and the hosted control plane.\n\n**What**\n\nThis concerns hybrid, or hosted, managed configuration, where an organisation's settings are stored and served centrally. Within it, `managedMcpServers` is the setting that hands MCP servers (outside services that give Claude extra tools) to every user. That setting now has stricter checks:\n\n- A stored OAuth client secret (a password-like value an app uses to sign in to a service) is refused unless the server is a Google OAuth client.\n\n- For Google, the sign-in server must be exactly `https:\/\/accounts.google.com`, and the secret must have Google's usual shape, starting with `GOCSPX-`.\n\n- For any other identity provider, Claude Code says to supply the secret through `oauth.clientSecretHelper` instead.\n\n- Gateway identity-provider OIDC keys (sign-in details for a company login system) are moved to a credential type called `external-idp`.\n\n- A configuration that turns on no surface at all, meaning no tab the app could open, now produces a warning asking you to enable at least one.\n\nBefore this, there was no client-secret check. The surface check looked only at whether the cowork and chat tabs were enabled.\n\n**Why**\n\nHosted managed config can now hold fewer secrets directly. Administrators using a provider other than Google need to move the secret to a helper. The new warning catches a configuration that would leave the app with nothing to show.\n\n- Area: MCP\n- Names: `managedMcpServers`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: org\n- Heads-up: yes"}