Skip to content

anthropic

Testing CIMD across Anthropic's clients against a self-hosted server

Claude News

Anthropic only documents Client ID Metadata Document (CIMD) support for Claude Code. For Desktop, Web, and Cowork, the docs just note that they share infrastructure, with no client_id and no registration mechanism spelled out. A researcher going by Leduccc ran each product through his own authorization server and captured the responses straight off the traffic.

All four clients picked CIMD over Dynamic Client Registration. Code hits claude.ai/oauth/claude-code-client-metadata, while Web, Desktop, and Cowork use claude.ai/oauth/mcp-oauth-client-metadata.

Because Cowork runs on Anthropic's servers, Leduccc pushed the flow all the way to a tool call. The tools/call request carried the same bearer token issued in the original CIMD exchange. The testing ran on May 15, 2026, against Claude Code CLI 2.1.142 and Claude.app v1.7196.0.

Related stories

  1. Anthropic will bill again for requests its safeguards block
  2. Claude helped make claude.ai 3x faster in two weeks
  3. Opus 5.5 costs less and answers old agent code with 400s
  4. Opus 5.5 finds new bugs for CodeRabbit and misses old ones
  5. Anthropic's 225 bug finds, one attack in the wild
  6. Claude's API sandbox got a new name and a cost readout

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.