What probably matters to youSection of the release
Unclear These settings are read by the desktop app's settings readers, and it is not clear whether the Claude Code command line also honours them.
What
Sign-in through a company identity provider using OpenID Connect (OIDC, a standard way to log in through an organisation's single sign-on system) is no longer tied to the gateway setup. A new credential kind, external-idp, comes with two new settings:
inferenceIdpOidc configures the identity provider sign-in.
inferenceIdpAuthFlow chooses between browser sign-in and broker sign-in.
This also covers Bedrock proxies. The older gateway settings, inferenceGatewayOidc and inferenceGatewayOidcAuthFlow, are still read, but they are now marked as deprecated, with no date set for their removal.
A warning is now shown when a token of type access_token is configured without an API resource scope. Several Foundry, Bedrock and other settings are also now marked as applying only to the desktop app.
Why
Administrators who already use single sign-on can reuse the same sign-in setup with Bedrock proxies and other providers instead of only with the gateway. Existing configurations that use the gateway settings keep working for now, but they are worth moving to the new names.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThese settings are read by the desktop app's settings readers, and it is not clear whether the Claude Code command line also honours them.