Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.277 Latest v2.1.284 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260928T220706Z

157 pages moved out of 255 read.

Pages moved 157 significant first
Pages read 255 in this capture
Captured 22:07 UTC
Corpus hash 9aad7bf66b91 corpus-hash

What this read moved

101-125 of 157, page 5 of 7

This capture is too large to show at once. Changes 101-125 of 157 are below, significant first; the rest are on the following screens.

government/desktop/import Changed · +4 / -4 lines

from line 57
5757 
5858## Troubleshooting
5959 
60| What you see | Likely cause | What to do |
61| -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
62| Your export exceeds the import size limit | You have more data than the import can bring over | Remove conversations or files you no longer need in the web app, in line with your organization's records policy, then run the import again |
63| The account does not match your organization | You signed in to the web app with a different account or organization | In the browser, sign in to the web app with your work account, then click **Sign in** in the dialog again |
60| What you see | Likely cause | What to do |
61| - | - | - |
62| Your export exceeds the import size limit | You have more data than the import can bring over | Remove conversations or files you no longer need in the web app, in line with your organization's records policy, then run the import again |
63| The account does not match your organization | You signed in to the web app with a different account or organization | In the browser, sign in to the web app with your work account, then click **Sign in** in the dialog again |
6464| The **Import & export** page says import isn't enabled for this deployment | Your app is out of date, or Anthropic has not yet enabled the import for your organization | Update Claude Desktop to the latest version. If the page still says import isn't enabled, contact your administrator, who can ask Anthropic to enable it |
6565 
6666For anything else, try the import again; if it keeps failing, contact your administrator.

government/org-admin/compliance-api Changed · +12 / -12 lines

from line 35
3535 
3636### Query parameters
3737 
38| Parameter | Description |
39| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
38| Parameter | Description |
39| - | - |
4040| `since` or `created_at.gte` | The earliest event time to return, as an RFC 3339 timestamp or epoch seconds. A lower bound is required on every request that does not carry a cursor. |
41| `until` or `created_at.lte` | The latest event time to return, in the same format. Optional. |
42| `after_id` | An opaque cursor that continues from where a previous page left off. Pass the `last_id` value from the previous response. |
43| `before_id` | An opaque cursor that pages in the other direction. Pass the `first_id` value from the previous response. Cannot be combined with `after_id`. |
44| `actor_ids[]` | Return only events performed by the listed actors. Repeat the parameter to pass more than one. |
45| `activity_types[]` | Return only events of the listed types. Repeat the parameter to pass more than one. |
46| `limit` | Maximum events per page, from 1 to 5000. Defaults to 100. |
41| `until` or `created_at.lte` | The latest event time to return, in the same format. Optional. |
42| `after_id` | An opaque cursor that continues from where a previous page left off. Pass the `last_id` value from the previous response. |
43| `before_id` | An opaque cursor that pages in the other direction. Pass the `first_id` value from the previous response. Cannot be combined with `after_id`. |
44| `actor_ids[]` | Return only events performed by the listed actors. Repeat the parameter to pass more than one. |
45| `activity_types[]` | Return only events of the listed types. Repeat the parameter to pass more than one. |
46| `limit` | Maximum events per page, from 1 to 5000. Defaults to 100. |
4747 
4848The exclusive bounds `created_at.gt` and `created_at.lt` are also accepted if your collector needs them.
4949 
from line 89
8989 
9090On every `user.*` activity, two top-level fields identify the user the event is about, so your SIEM can map events back to people in your directory without a separate lookup.
9191 
92| Field | Description |
93| ------------ | -------------------------------------------------------------------------------- |
94| `user_id` | The Claude for Government user ID, in the same `usr_` format as `actor.user_id`. |
95| `user_email` | The user's email address at the time of the event. |
92| Field | Description |
93| - | - |
94| `user_id` | The Claude for Government user ID, in the same `usr_` format as `actor.user_id`. |
95| `user_email` | The user's email address at the time of the event. |
9696 
9797The user an event is about is not always the actor. When an owner changes someone's role, the `actor` block names the owner and these fields name the user whose role changed.
9898 

government/org-admin/overview Changed · +13 / -13 lines

from line 39
3939 
4040**People**
4141 
42| Page | What it's for |
43| ---------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
44| [Users](/docs/government/org-admin/users) | Find users, change their role or seat tier, check their usage, and reset their rate limits. |
45| [Seats](/docs/government/org-admin/seats) | See how many seats of each tier your organization has and how many are currently in use. |
46| [Tiers](/docs/government/org-admin/seat-tiers) | Review the Anthropic-managed seat tiers and create your own tiers with custom model access and spend limits. |
42| Page | What it's for |
43| - | - |
44| [Users](/docs/government/org-admin/users) | Find users, change their role or seat tier, check their usage, and reset their rate limits. |
45| [Seats](/docs/government/org-admin/seats) | See how many seats of each tier your organization has and how many are currently in use. |
46| [Tiers](/docs/government/org-admin/seat-tiers) | Review the Anthropic-managed seat tiers and create your own tiers with custom model access and spend limits. |
4747| [Group mappings](/docs/government/org-admin/provisioning) | Map directory groups to seat tiers and roles so that users added through your directory land in the right place automatically. |
4848 
4949**Usage**
5050 
51| Page | What it's for |
52| ------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------- |
53| [Analytics](/docs/government/org-admin/analytics) | Review requests, tokens, spend, top users, and credit balance over time across your organization. |
54| [Compliance API](/docs/government/org-admin/compliance-api) | Create and manage read-only API keys that stream your organization's audit events to a SIEM or log management system. |
55| [Billing](/docs/government/org-admin/billing) | See the billing account that funds your organization, its balance and any spend caps, and adjust your seat allocation. |
51| Page | What it's for |
52| - | - |
53| [Analytics](/docs/government/org-admin/analytics) | Review requests, tokens, spend, top users, and credit balance over time across your organization. |
54| [Compliance API](/docs/government/org-admin/compliance-api) | Create and manage read-only API keys that stream your organization's audit events to a SIEM or log management system. |
55| [Billing](/docs/government/org-admin/billing) | See the billing account that funds your organization, its balance and any spend caps, and adjust your seat allocation. |
5656 
5757**Settings**
5858 
59| Page | What it's for |
60| --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
59| Page | What it's for |
60| - | - |
6161| [Config](/docs/government/org-admin/configuration) | Adjust product settings such as telemetry, the Claude Desktop banner, and product availability for everyone in your organization. |
62| [Readiness](/docs/government/org-admin/readiness) | See what is blocking users from using Claude and where each item is resolved. |
62| [Readiness](/docs/government/org-admin/readiness) | See what is blocking users from using Claude and where each item is resolved. |
6363 
6464<Warning>
6565 The **Billing** tab only appears when the billing account is active and your own organization is active on it. If you don't see it, contact your tenant administrators about credits or spend caps.

government/org-admin/users Changed · +6 / -6 lines

from line 16
1616 
1717Each user appears as a card with their name, email address, and the following fields:
1818 
19| Field | Description |
20| -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
21| **Role** | The user's role in this organization. You can change it directly from the dropdown. |
22| **Seat tier** | Which seat tier the user currently occupies. You can change it directly from the dropdown. |
23| **Usage** | Two bars showing how much of the user's 5-hour and 7-day spend limits are currently used, with the exact percentage alongside each. Hover over the bars to see when each limit resets. Users who have no seat tier show a dash instead of the bars. |
24| **Last login** | The date and time the user last signed in. |
19| Field | Description |
20| - | - |
21| **Role** | The user's role in this organization. You can change it directly from the dropdown. |
22| **Seat tier** | Which seat tier the user currently occupies. You can change it directly from the dropdown. |
23| **Usage** | Two bars showing how much of the user's 5-hour and 7-day spend limits are currently used, with the exact percentage alongside each. Hover over the bars to see when each limit resets. Users who have no seat tier show a dash instead of the bars. |
24| **Last login** | The date and time the user last signed in. |
2525 
2626The **…** menu on each card has the **Reset usage limits** action, which clears the user's current rate-limit windows. The menu appears only when your organization has at least one [self-managed seat tier](/docs/government/org-admin/seat-tiers).
2727 

government/overview Changed · +11 / -11 lines

from line 6
66 
77> **Find your section:**
88>
9> | If you are… | Start with |
10> | --------------------------- | ------------------------------------------------------------- |
11> | A tenant administrator | [Tenant administration](/docs/government/tenant-admin/overview) |
12> | An organization owner | [Organization administration](/docs/government/org-admin/overview) |
13> | Any user | [Your account](/docs/government/account/overview) |
14> | Anyone using Claude Desktop | [Use Claude Desktop](/docs/government/desktop/plugins) |
9> | If you are… | Start with |
10> | - | - |
11> | A tenant administrator | [Tenant administration](/docs/government/tenant-admin/overview) |
12> | An organization owner | [Organization administration](/docs/government/org-admin/overview) |
13> | Any user | [Your account](/docs/government/account/overview) |
14> | Anyone using Claude Desktop | [Use Claude Desktop](/docs/government/desktop/plugins) |
1515 
1616This guide covers the portals used to manage Claude for Government: how access, seats, and usage are organized, and who is responsible for each part.
1717 
from line 60
6060 
6161The portal has three views. Which ones you can reach depends on your role, and you switch between them using the link in the page footer.
6262 
63| View | Who has it | What it's for |
64| -------------------------------------------------------- | --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
65| [**Tenant**](/docs/government/tenant-admin/overview) | Tenant administrators | Creating organizations, configuring identity and access (single sign-on, provisioning, and routing rules), distributing seats, setting spend caps, and managing who else is a tenant administrator. |
66| [**Organization admin**](/docs/government/org-admin/overview) | Organization owners and tenant administrators | Managing users and seats, setting usage tiers, viewing analytics, and configuring organization-level settings. |
67| [**Account**](/docs/government/account/overview) | Everyone | Viewing your own profile, checking your usage limits, and managing where you're signed in. |
63| View | Who has it | What it's for |
64| - | - | - |
65| [**Tenant**](/docs/government/tenant-admin/overview) | Tenant administrators | Creating organizations, configuring identity and access (single sign-on, provisioning, and routing rules), distributing seats, setting spend caps, and managing who else is a tenant administrator. |
66| [**Organization admin**](/docs/government/org-admin/overview) | Organization owners and tenant administrators | Managing users and seats, setting usage tiers, viewing analytics, and configuring organization-level settings. |
67| [**Account**](/docs/government/account/overview) | Everyone | Viewing your own profile, checking your usage limits, and managing where you're signed in. |
6868 
6969When you sign in, you land on the most relevant view for you. Organization owners land on the organization admin view, and everyone else lands on their account view. This includes tenant administrators who are not also an organization owner; they start on their account view and can use the **Switch to admin view** link in the page footer, and from there switch to the tenant view.
7070 

office-agents/data-storage Changed · +37 / -37 lines

from line 41
4141The table below gives the result for each change users and administrators
4242actually make.
4343 
44| Change | Result |
45| ------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
46| Uninstall and reinstall the same add-in | Data intact |
47| Move to a different store listing, or to one published with a new ID | Data intact. A new listing means a new add-in ID, not new storage |
48| Move from a sideloaded manifest to a store listing, or the reverse | Data intact |
44| Change | Result |
45| - | - |
46| Uninstall and reinstall the same add-in | Data intact |
47| Move to a different store listing, or to one published with a new ID | Data intact. A new listing means a new add-in ID, not new storage |
48| Move from a sideloaded manifest to a store listing, or the reverse | Data intact |
4949| Swap the standard manifest for the custom third-party manifest, or the reverse | Storage intact, but the history list changes, because the connection mode change is an identity change. See [what chat history is keyed to](#what-chat-history-is-keyed-to) |
50| Run a store install and a sideloaded manifest at the same time | Shared storage. Two entries in Office, one history. Remove one to avoid confusion |
51| Bump the manifest version, or issue a new ID to clear an Admin Center cache | Data intact |
52| Serve the add-in from a different host or port, or over `http` | A new empty store |
53| Rebuild, reimage, or wipe the profile on the device | Data destroyed. Export first |
50| Run a store install and a sideloaded manifest at the same time | Shared storage. Two entries in Office, one history. Remove one to avoid confusion |
51| Bump the manifest version, or issue a new ID to clear an Admin Center cache | Data intact |
52| Serve the add-in from a different host or port, or over `http` | A new empty store |
53| Rebuild, reimage, or wipe the profile on the device | Data destroyed. Export first |
5454 
5555## What Claude for M365 stores
5656 
from line 58
5858the signed-in user's operating system profile. The table below lists each one
5959and what it is scoped to.
6060 
61| Store | Contents | Scoped to |
62| ------------------------------- | --------------------------------------------------------------------------------- | ------------------------------------------------ |
63| `claude-chat-history` | Conversation transcripts, titles, timestamps, and the contents of attached files | One user, one organization, one Office app |
64| `claude-local-skills` | Skills the user uploaded, including any templates bundled with them | The device profile, not the individual user |
65| `claude-mcp-gateways` | Client registrations for connectors the user has authorized | The connector's address, not the individual user |
66| `claude-mail-style` | Claude for Outlook only: learned writing style, draft preferences, and scratchpad | One user |
67| `claude-office-snipped-results` | Working scratch for long conversations, cleared at the start of every session | Nothing, transient |
68| Local storage | Settings, onboarding and terms flags, and the active sign-in profile | The browser profile |
61| Store | Contents | Scoped to |
62| - | - | - |
63| `claude-chat-history` | Conversation transcripts, titles, timestamps, and the contents of attached files | One user, one organization, one Office app |
64| `claude-local-skills` | Skills the user uploaded, including any templates bundled with them | The device profile, not the individual user |
65| `claude-mcp-gateways` | Client registrations for connectors the user has authorized | The connector's address, not the individual user |
66| `claude-mail-style` | Claude for Outlook only: learned writing style, draft preferences, and scratchpad | One user |
67| `claude-office-snipped-results` | Working scratch for long conversations, cleared at the start of every session | Nothing, transient |
68| Local storage | Settings, onboarding and terms flags, and the active sign-in profile | The browser profile |
6969 
7070Conversations and the Outlook writing style guide are scoped to the
7171individual user. Uploaded skills and connector registrations are scoped to the
from line 151
151151 
152152The table below gives the result for each case.
153153 
154| Situation | Result |
155| --------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
156| A user signs out of Claude and signs back in | The same conversations. Signing out does not change the identity |
157| A different person signs in to Office on that device | They see their own conversations, not the previous user's. On Office builds that fall back to a per-installation identifier, both people resolve to the same identity and share one list |
158| The same person opens the add-in on a second device | No conversations. Storage is per device and does not sync |
159| A user's organization changes, such as joining or leaving a team plan | Earlier conversations stop appearing. They remain on disk under the previous organization |
160| A deployment moves between a Claude account sign-in and a third-party platform, in either direction | Earlier conversations stop appearing. They remain on disk under the previous identity, and the add-in has no path to reach them |
154| Situation | Result |
155| - | - |
156| A user signs out of Claude and signs back in | The same conversations. Signing out does not change the identity |
157| A different person signs in to Office on that device | They see their own conversations, not the previous user's. On Office builds that fall back to a per-installation identifier, both people resolve to the same identity and share one list |
158| The same person opens the add-in on a second device | No conversations. Storage is per device and does not sync |
159| A user's organization changes, such as joining or leaving a team plan | Earlier conversations stop appearing. They remain on disk under the previous organization |
160| A deployment moves between a Claude account sign-in and a third-party platform, in either direction | Earlier conversations stop appearing. They remain on disk under the previous identity, and the add-in has no path to reach them |
161161 
162162Changing connection mode is not a data loss event, because nothing is deleted,
163163but it is an identity change and the history list follows the identity.
from line 172
172172Claude for M365 bounds local storage in two ways, and users can clear it
173173themselves at any time.
174174 
175| Store | Retention |
176| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
177| `claude-chat-history` | The 50 most recent conversations per user, per organization, per Office app. Older conversations are deleted automatically |
178| Any store | When the browser profile runs out of storage quota, the oldest conversations are deleted to make room |
179| `claude-office-snipped-results` | Cleared at the start of every session |
180| Everything else | Kept until the user deletes it or the browser profile is wiped |
175| Store | Retention |
176| - | - |
177| `claude-chat-history` | The 50 most recent conversations per user, per organization, per Office app. Older conversations are deleted automatically |
178| Any store | When the browser profile runs out of storage quota, the oldest conversations are deleted to make room |
179| `claude-office-snipped-results` | Cleared at the start of every session |
180| Everything else | Kept until the user deletes it or the browser profile is wiped |
181181 
182182Users clear their own conversations from the add-in's settings. Under "Chat
183183history", "Delete all" removes every saved conversation for that user in that
from line 194
194194The table below covers each category and its destination, so you can scope a
195195review to the paths that carry content off the endpoint.
196196 
197| Data | Where it goes |
198| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
199| Conversation text, attachments, and the document content Claude is asked to work with | The model endpoint your deployment is configured for. In third-party platform deployments that is your own Vertex AI, Bedrock, Azure, or gateway endpoint |
200| Chat history, uploaded skills, connector registrations, and the Outlook writing style guide | Nowhere. Local only, no sync, no server-side backup |
201| Sign-in credentials | Only to the identity provider they belong to |
202| Usage telemetry sent to Anthropic | Counts, durations, and error categories. Anthropic's collector is allowlist-filtered, so it excludes conversation text, document contents, file names, and the names of your connectors and their tools |
203| Telemetry sent to a custom OpenTelemetry collector you configure | The full audit trail, including prompt content and tool inputs and outputs. That path bypasses the allowlist filter by design. See [Audit and observability](/docs/office-agents/enterprise-readiness#audit-and-observability) |
197| Data | Where it goes |
198| - | - |
199| Conversation text, attachments, and the document content Claude is asked to work with | The model endpoint your deployment is configured for. In third-party platform deployments that is your own Vertex AI, Bedrock, Azure, or gateway endpoint |
200| Chat history, uploaded skills, connector registrations, and the Outlook writing style guide | Nowhere. Local only, no sync, no server-side backup |
201| Sign-in credentials | Only to the identity provider they belong to |
202| Usage telemetry sent to Anthropic | Counts, durations, and error categories. Anthropic's collector is allowlist-filtered, so it excludes conversation text, document contents, file names, and the names of your connectors and their tools |
203| Telemetry sent to a custom OpenTelemetry collector you configure | The full audit trail, including prompt content and tool inputs and outputs. That path bypasses the allowlist filter by design. See [Audit and observability](/docs/office-agents/enterprise-readiness#audit-and-observability) |
204204 
205205## Export a user's data before a device is rebuilt
206206 

office-agents/fsi-plugins Changed · +14 / -14 lines

from line 16
1616The repository contains a core plugin and several add-on plugins that
1717build on it.
1818 
19| Plugin | What it does |
20| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
19| Plugin | What it does |
20| - | - |
2121| Financial analysis (core) | Build comparable company analyses, DCF models, LBO models, and 3-statement financials. Includes all shared MCP connectors for financial data providers. Install this first. |
22| Investment banking | Draft CIMs, teasers, and process letters. Build buyer lists, run merger models, and create strip profiles. |
23| Equity research | Write earnings updates and initiating coverage reports. Track catalysts and screen for new ideas. |
24| Private equity | Source and screen deals, run due diligence checklists, draft IC memos, and monitor portfolio company KPIs. |
25| Wealth management | Prep for client meetings, build financial plans, rebalance portfolios, and identify tax-loss harvesting opportunities. |
22| Investment banking | Draft CIMs, teasers, and process letters. Build buyer lists, run merger models, and create strip profiles. |
23| Equity research | Write earnings updates and initiating coverage reports. Track catalysts and screen for new ideas. |
24| Private equity | Source and screen deals, run due diligence checklists, draft IC memos, and monitor portfolio company KPIs. |
25| Wealth management | Prep for client meetings, build financial plans, rebalance portfolios, and identify tax-loss harvesting opportunities. |
2626 
2727The repository also includes partner-built plugins from LSEG and S\&P
2828Global, which bring their financial data and analytics directly into
from line 81
8181 qualified professional before being used in decision-making.
8282</Warning>
8383 
84| Skill | What it does |
85| ------------------------------- | --------------------------------------- |
86| `/comps [company]` | Run a comparable company analysis. |
87| `/dcf [company]` | Build a DCF valuation model. |
84| Skill | What it does |
85| - | - |
86| `/comps [company]` | Run a comparable company analysis. |
87| `/dcf [company]` | Build a DCF valuation model. |
8888| `/earnings [company] [quarter]` | Generate a post-earnings update report. |
89| `/one-pager [company]` | Create a one-page company profile. |
90| `/ic-memo [project name]` | Draft an investment committee memo. |
91| `/source [criteria]` | Source deals based on criteria. |
92| `/client-review [client]` | Prep for a client meeting. |
89| `/one-pager [company]` | Create a one-page company profile. |
90| `/ic-memo [project name]` | Draft an investment committee memo. |
91| `/source [criteria]` | Source deals based on criteria. |
92| `/client-review [client]` | Prep for a client meeting. |
9393 
9494## MCP connectors
9595 

office-agents/opentelemetry Changed · +74 / -74 lines

from line 67
6767Claude admin console under Organization settings, Office agents. Two
6868settings are available:
6969 
70| Setting | Description |
71| --------------- | --------------------------------------------------------------------------------- |
72| `otlp_endpoint` | Base URL of your OTLP collector. The add-in appends `/v1/traces` |
73| `otlp_headers` | Optional authentication headers in OpenTelemetry `key1=value1,key2=value2` format |
70| Setting | Description |
71| - | - |
72| `otlp_endpoint` | Base URL of your OTLP collector. The add-in appends `/v1/traces` |
73| `otlp_headers` | Optional authentication headers in OpenTelemetry `key1=value1,key2=value2` format |
7474 
7575### Direct-provider deployments
7676 
from line 79
7979channels described in
8080[Use Claude for M365 with third-party platforms](/docs/office-agents/third-party-platforms).
8181 
82| Key | Format | Description |
83| --------------- | ------------------------- | ------------------------------------------------- |
84| `otlp_endpoint` | HTTPS URL | Collector base URL. Trailing slashes are stripped |
85| `otlp_headers` | `key1=value1,key2=value2` | Optional authentication headers |
82| Key | Format | Description |
83| - | - | - |
84| `otlp_endpoint` | HTTPS URL | Collector base URL. Trailing slashes are stripped |
85| `otlp_headers` | `key1=value1,key2=value2` | Optional authentication headers |
8686 
8787The `claude-for-msft-365-install` setup plugin writes these for you. To
8888set them by hand, use any of the three channels below. Later channels override
from line 156
156156 
157157These are set on every span.
158158 
159| Attribute | Description |
160| ----------------- | -------------------------------------------------------- |
161| `service.name` | Fixed value `office-agent` |
159| Attribute | Description |
160| - | - |
161| `service.name` | Fixed value `office-agent` |
162162| `service.version` | Fixed value `1.0.0`. Use `git.sha` to identify the build |
163| `git.sha` | Build commit |
163| `git.sha` | Build commit |
164164 
165165### agent.query
166166 
167167Root span, one per user turn. SpanKind `INTERNAL`.
168168 
169| Attribute | Description |
170| ----------------------------------------------- | ------------------------------------------------------------- |
171| `agent.surface` | `sheet`, `doc`, `slide`, or `mail` |
172| `agent.vendor` | `m` |
173| `user.message` *content* | User prompt, truncated per the attribute cap |
174| `user.message_chars` | Pre-truncation length of the prompt |
175| `session.id` | Opaque session identifier |
176| `document.url` *content* | URL of the open Office document |
177| `agent.selected_model` | Model selected for the session |
178| `office.platform` | `PC`, `Mac`, `OfficeOnline`, `iOS`, `Android`, or `Universal` |
179| `office.version` | Office build number |
180| `user.email` *Claude sign-in only* | User email |
181| `user.account_uuid` *Claude sign-in only* | Claude account UUID |
182| `organization.id` *Claude sign-in only* | Claude organization UUID |
183| `org.rate_limit_tier` *Claude sign-in only* | Subscription tier |
184| `mcp.configured_count` *Claude sign-in only* | Configured MCP servers |
185| `mcp.connected_count` *Claude sign-in only* | Connected MCP servers |
186| `mcp.failed_count` *Claude sign-in only* | Failed MCP connections |
187| `file.upload.count` *Claude sign-in only* | Files attached to the turn |
188| `file.upload.total_bytes` *Claude sign-in only* | Total uploaded bytes |
189| `error.name` | Exception class name, on failure |
190| `agent.query_phase` | Phase at failure, on failure |
169| Attribute | Description |
170| - | - |
171| `agent.surface` | `sheet`, `doc`, `slide`, or `mail` |
172| `agent.vendor` | `m` |
173| `user.message` *content* | User prompt, truncated per the attribute cap |
174| `user.message_chars` | Pre-truncation length of the prompt |
175| `session.id` | Opaque session identifier |
176| `document.url` *content* | URL of the open Office document |
177| `agent.selected_model` | Model selected for the session |
178| `office.platform` | `PC`, `Mac`, `OfficeOnline`, `iOS`, `Android`, or `Universal` |
179| `office.version` | Office build number |
180| `user.email` *Claude sign-in only* | User email |
181| `user.account_uuid` *Claude sign-in only* | Claude account UUID |
182| `organization.id` *Claude sign-in only* | Claude organization UUID |
183| `org.rate_limit_tier` *Claude sign-in only* | Subscription tier |
184| `mcp.configured_count` *Claude sign-in only* | Configured MCP servers |
185| `mcp.connected_count` *Claude sign-in only* | Connected MCP servers |
186| `mcp.failed_count` *Claude sign-in only* | Failed MCP connections |
187| `file.upload.count` *Claude sign-in only* | Files attached to the turn |
188| `file.upload.total_bytes` *Claude sign-in only* | Total uploaded bytes |
189| `error.name` | Exception class name, on failure |
190| `agent.query_phase` | Phase at failure, on failure |
191191 
192192### agent.stream
193193 
194194One span per model API call, child of `agent.query`. SpanKind `CLIENT`.
195195 
196| Attribute | Description |
197| ----------------------- | ------------------------------------------------- |
198| `model` | Model ID used |
199| `max_tokens` | Maximum output tokens requested |
200| `agent.message_count` | Messages in the conversation at stream start |
201| `input_tokens` | Input tokens billed |
202| `output_tokens` | Output tokens billed |
203| `cache_read_tokens` | Tokens served from prompt cache |
204| `cache_creation_tokens` | Tokens written to prompt cache |
205| `stop_reason` | `end_turn`, `tool_use`, `max_tokens`, and similar |
206| `request_id` | Provider request ID for support correlation |
196| Attribute | Description |
197| - | - |
198| `model` | Model ID used |
199| `max_tokens` | Maximum output tokens requested |
200| `agent.message_count` | Messages in the conversation at stream start |
201| `input_tokens` | Input tokens billed |
202| `output_tokens` | Output tokens billed |
203| `cache_read_tokens` | Tokens served from prompt cache |
204| `cache_creation_tokens` | Tokens written to prompt cache |
205| `stop_reason` | `end_turn`, `tool_use`, `max_tokens`, and similar |
206| `request_id` | Provider request ID for support correlation |
207207 
208208The add-in requests prompt caching on every call. Cache token attributes
209209are set from the provider's response and omitted when the provider does
from line 214
214214One span per tool call, child of `agent.stream`. SpanKind `INTERNAL`.
215215This is the primary record of what the model did to the document.
216216 
217| Attribute | Description |
218| ----------------------- | --------------------------------------------------------------------------------------------------------------------- |
219| `tool_name` | Tool identifier, for example `get_cell_ranges` or `execute_office_js`. MCP connector tools are recorded as `mcp_tool` |
220| `tool.id` | Unique invocation ID |
221| `tool.caller` | `direct` for tools the add-in runs, or `server_tool` for tools the model provider runs |
222| `tool.owner` | `first_party` for built-in tools, or `third_party` for MCP connector tools |
223| `tool.read_write` | `read` or `write` |
224| `tool.accept_decision` | `manual` (user approved this action), `auto_accept` (standing approval), or `deferred` (queued for review) |
225| `tool.input` *content* | Serialized tool input, truncated per the attribute cap |
226| `tool.success` | Boolean |
227| `tool.output` *content* | Serialized tool output, truncated per the attribute cap |
228| `tool.output_chars` | Full output length in characters |
229| `tool.error_type` | Error classification, on failure |
230| `sheet.cells_read` | Cells read, sheet surface only |
231| `sheet.cells_written` | Cells written, sheet surface only |
232| `sheet.cells_copied` | Cells copied, sheet surface only |
217| Attribute | Description |
218| - | - |
219| `tool_name` | Tool identifier, for example `get_cell_ranges` or `execute_office_js`. MCP connector tools are recorded as `mcp_tool` |
220| `tool.id` | Unique invocation ID |
221| `tool.caller` | `direct` for tools the add-in runs, or `server_tool` for tools the model provider runs |
222| `tool.owner` | `first_party` for built-in tools, or `third_party` for MCP connector tools |
223| `tool.read_write` | `read` or `write` |
224| `tool.accept_decision` | `manual` (user approved this action), `auto_accept` (standing approval), or `deferred` (queued for review) |
225| `tool.input` *content* | Serialized tool input, truncated per the attribute cap |
226| `tool.success` | Boolean |
227| `tool.output` *content* | Serialized tool output, truncated per the attribute cap |
228| `tool.output_chars` | Full output length in characters |
229| `tool.error_type` | Error classification, on failure |
230| `sheet.cells_read` | Cells read, sheet surface only |
231| `sheet.cells_written` | Cells written, sheet surface only |
232| `sheet.cells_copied` | Cells copied, sheet surface only |
233233 
234234### agent.compaction
235235 
from line 239
239239`office.platform`, `office.version`, and `user.email` (Claude sign-in
240240only).
241241 
242| Attribute | Description |
243| ------------------------- | -------------------------------- |
244| `compaction.pre_tokens` | Token count before summarization |
245| `compaction.post_tokens` | Token count after summarization |
246| `compaction.tokens_saved` | Delta |
247| `compaction.success` | Boolean |
248| `compaction.trigger` | Currently always `reactive` |
242| Attribute | Description |
243| - | - |
244| `compaction.pre_tokens` | Token count before summarization |
245| `compaction.post_tokens` | Token count after summarization |
246| `compaction.tokens_saved` | Delta |
247| `compaction.success` | Boolean |
248| `compaction.trigger` | Currently always `reactive` |
249249 
250250### file.upload
251251 
from line 254
254254carries `session.id` and `user.email`. Correlate to the turn by
255255`session.id` and timestamp.
256256 
257| Attribute | Description |
258| ------------------------ | ------------------------------ |
259| `file.upload.size_bytes` | File size |
260| `file.upload.mime_type` | MIME type |
261| `file.upload.file_id` | Anthropic Files API identifier |
262| `file.upload.success` | Boolean |
257| Attribute | Description |
258| - | - |
259| `file.upload.size_bytes` | File size |
260| `file.upload.mime_type` | MIME type |
261| `file.upload.file_id` | Anthropic Files API identifier |
262| `file.upload.success` | Boolean |
263263 
264264## Span events
265265 

office-agents/outlook Changed · +5 / -5 lines

from line 235
235235(Anthropic's multi-tenant application exists only in the global cloud)
236236and set `graph_cloud` to the matching value:
237237 
238| Tenant | `graph_cloud` |
239| ----------------- | ---------------------------------- |
238| Tenant | `graph_cloud` |
239| - | - |
240240| Commercial or GCC | `global` (default; may be omitted) |
241| GCC High | `us-gov-high` |
242| DoD | `us-gov-dod` |
243| 21Vianet (China) | `china` |
241| GCC High | `us-gov-high` |
242| DoD | `us-gov-dod` |
243| 21Vianet (China) | `china` |
244244 
245245For a DoD tenant the manifest URL ends with:
246246 

office-agents/performance Changed · +30 / -30 lines

from line 31
3131 
3232These limits come from Claude for M365 and from Office itself.
3333 
34| Limit | Value | What it means for you |
35| ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
36| Wait for a step where Claude runs code | 90 seconds | A heavy step can time out |
37| Wait for other steps, such as writing cells | 5 minutes on the desktop, 2 minutes on the web | A heavy step can time out |
38| Wait for a Word text edit | 30 seconds | A heavy edit can time out |
39| Cells returned by one Claude read in Excel | 2,000 cells with data | Claude reads a large sheet in several steps |
40| Cells Office reads from one range | 5,000,000<sup id="cite-ref-3-b" className="scroll-mt-24"><a href="#cite-note-3">\[3]</a></sup> | A larger read can fail |
41| One request in Excel on the web | 5 MB<sup id="cite-ref-3-c" className="scroll-mt-24"><a href="#cite-note-3">\[3]</a></sup> | Large reads and writes can fail on the web |
42| Command batches waiting in Office | 50<sup id="cite-ref-4-a" className="scroll-mt-24"><a href="#cite-note-4">\[4]</a></sup> | More batches cause errors |
43| Workbook opened in a browser | Up to 100 MB, depending on your subscription<sup id="cite-ref-5" className="scroll-mt-24"><a href="#cite-note-5">\[5]</a></sup> | Open larger files in Excel on the desktop |
44| Memory for 32-bit Excel | Up to 4 GB on 64-bit Windows<sup id="cite-ref-6" className="scroll-mt-24"><a href="#cite-note-6">\[6]</a></sup> | Use 64-bit Office for large workbooks |
34| Limit | Value | What it means for you |
35| - | - | - |
36| Wait for a step where Claude runs code | 90 seconds | A heavy step can time out |
37| Wait for other steps, such as writing cells | 5 minutes on the desktop, 2 minutes on the web | A heavy step can time out |
38| Wait for a Word text edit | 30 seconds | A heavy edit can time out |
39| Cells returned by one Claude read in Excel | 2,000 cells with data | Claude reads a large sheet in several steps |
40| Cells Office reads from one range | 5,000,000<sup id="cite-ref-3-b" className="scroll-mt-24"><a href="#cite-note-3">\[3]</a></sup> | A larger read can fail |
41| One request in Excel on the web | 5 MB<sup id="cite-ref-3-c" className="scroll-mt-24"><a href="#cite-note-3">\[3]</a></sup> | Large reads and writes can fail on the web |
42| Command batches waiting in Office | 50<sup id="cite-ref-4-a" className="scroll-mt-24"><a href="#cite-note-4">\[4]</a></sup> | More batches cause errors |
43| Workbook opened in a browser | Up to 100 MB, depending on your subscription<sup id="cite-ref-5" className="scroll-mt-24"><a href="#cite-note-5">\[5]</a></sup> | Open larger files in Excel on the desktop |
44| Memory for 32-bit Excel | Up to 4 GB on 64-bit Windows<sup id="cite-ref-6" className="scroll-mt-24"><a href="#cite-note-6">\[6]</a></sup> | Use 64-bit Office for large workbooks |
4545 
4646## File size and risk
4747 
from line 54
5454 
5555The risk rises steadily, without a sharp threshold. Treat the bands as guides.
5656 
57| File | Works well | Higher risk, so narrow your requests | Use at your own risk |
58| ----------------------------------------- | --------------- | ------------------------------------ | -------------------- |
59| Excel, total used cells across all sheets | Under 1 million | 1 to 5 million | Over 5 million |
60| PowerPoint, slides | Under 100 | 100 to 199 | 200 or more |
57| File | Works well | Higher risk, so narrow your requests | Use at your own risk |
58| - | - | - | - |
59| Excel, total used cells across all sheets | Under 1 million | 1 to 5 million | Over 5 million |
60| PowerPoint, slides | Under 100 | 100 to 199 | 200 or more |
6161 
6262To estimate the total for a workbook, go to each sheet and press Ctrl+End to
6363move to its last cell.<sup id="cite-ref-7-a" className="scroll-mt-24"><a href="#cite-note-7">\[7]</a></sup> Multiply the number of the last row by the
from line 99
9999 
100100Excel has built-in tools that show what makes a workbook heavy.
101101 
102| Task | Where in Excel |
103| ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------- |
104| See counts of cells, formulas, and objects | Review, Workbook Statistics<sup id="cite-ref-9" className="scroll-mt-24"><a href="#cite-note-9">\[9]</a></sup> |
105| Remove formatting from empty cells | Review, Check Performance<sup id="cite-ref-10-a" className="scroll-mt-24"><a href="#cite-note-10">\[10]</a></sup> |
106| Find hidden shapes and pictures | Home, Find & Select, Selection Pane<sup id="cite-ref-11-a" className="scroll-mt-24"><a href="#cite-note-11">\[11]</a></sup> |
102| Task | Where in Excel |
103| - | - |
104| See counts of cells, formulas, and objects | Review, Workbook Statistics<sup id="cite-ref-9" className="scroll-mt-24"><a href="#cite-note-9">\[9]</a></sup> |
105| Remove formatting from empty cells | Review, Check Performance<sup id="cite-ref-10-a" className="scroll-mt-24"><a href="#cite-note-10">\[10]</a></sup> |
106| Find hidden shapes and pictures | Home, Find & Select, Selection Pane<sup id="cite-ref-11-a" className="scroll-mt-24"><a href="#cite-note-11">\[11]</a></sup> |
107107 
108108Save a copy of the workbook before you run Check Performance. It removes
109109formatting from cells that look empty, including cells used for pixel
from line 165
165165Large pictures and media make a presentation larger.<sup id="cite-ref-16-a" className="scroll-mt-24"><a href="#cite-note-16">\[16]</a></sup> Compress them
166166before you ask Claude for large changes.
167167 
168| Task | Where in PowerPoint |
169| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
170| Compress pictures | Picture Format, Compress Pictures, with "Apply only to this picture" cleared<sup id="cite-ref-16-b" className="scroll-mt-24"><a href="#cite-note-16">\[16]</a></sup> |
171| Compress audio and video | File, Info, Compress Media, in PowerPoint on Windows<sup id="cite-ref-17" className="scroll-mt-24"><a href="#cite-note-17">\[17]</a></sup> |
168| Task | Where in PowerPoint |
169| - | - |
170| Compress pictures | Picture Format, Compress Pictures, with "Apply only to this picture" cleared<sup id="cite-ref-16-b" className="scroll-mt-24"><a href="#cite-note-16">\[16]</a></sup> |
171| Compress audio and video | File, Info, Compress Media, in PowerPoint on Windows<sup id="cite-ref-17" className="scroll-mt-24"><a href="#cite-note-17">\[17]</a></sup> |
172172 
173173Save a copy of the presentation before you compress. Deleting cropped picture
174174areas and discarding editing data cannot be undone.<sup id="cite-ref-16-c" className="scroll-mt-24"><a href="#cite-note-16">\[16]</a></sup>
from line 179
179179 
180180Use this table when Office stops responding during a request.
181181 
182| Situation | What to do |
183| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
184| Claude waits on a step | Wait. Do not click repeatedly. |
185| Claude reports a timeout | Wait until Office responds, save, then ask for a smaller step. The step can still be running in Office. |
186| Office closes | Reopen the file and look for the Document Recovery pane.<sup id="cite-ref-18-a" className="scroll-mt-24"><a href="#cite-note-18">\[18]</a></sup> Start a new chat with a smaller request. |
187| It happens often | Send your IT admin the transcript and the time of the problem. |
182| Situation | What to do |
183| - | - |
184| Claude waits on a step | Wait. Do not click repeatedly. |
185| Claude reports a timeout | Wait until Office responds, save, then ask for a smaller step. The step can still be running in Office. |
186| Office closes | Reopen the file and look for the Document Recovery pane.<sup id="cite-ref-18-a" className="scroll-mt-24"><a href="#cite-note-18">\[18]</a></sup> Start a new chat with a smaller request. |
187| It happens often | Send your IT admin the transcript and the time of the problem. |
188188 
189189When something goes wrong, keep your work and the chat for your admin.
190190 

office-agents/third-party-platforms Changed · +112 / -112 lines

from line 13
1313Four connection paths are available. Your IT admin selects one during
1414deployment. End users see the same interface regardless.
1515 
16| Path | How it works |
17| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
18| LLM gateway | Requests route through your gateway (LiteLLM, Portkey, Kong, and others) to your chosen provider. Matches the pattern used by Claude Code. |
19| Bedrock direct | The add-in authenticates via Microsoft Entra ID and calls Amazon Bedrock directly without intermediaries. |
20| Vertex AI direct | The add-in authenticates through Google OAuth and calls Vertex AI directly. |
21| Foundry direct | The add-in calls your Azure AI Foundry resource directly, authenticating with each user's Microsoft Entra ID token (keyless) or with the resource API key. |
16| Path | How it works |
17| - | - |
18| LLM gateway | Requests route through your gateway (LiteLLM, Portkey, Kong, and others) to your chosen provider. Matches the pattern used by Claude Code. |
19| Bedrock direct | The add-in authenticates via Microsoft Entra ID and calls Amazon Bedrock directly without intermediaries. |
20| Vertex AI direct | The add-in authenticates through Google OAuth and calls Vertex AI directly. |
21| Foundry direct | The add-in calls your Azure AI Foundry resource directly, authenticating with each user's Microsoft Entra ID token (keyless) or with the resource API key. |
2222 
2323## Requirements by connection path
2424 
from line 31
3131 `Calendars.Read`, `User.Read`, and `offline_access`, granted via
3232 Anthropic's app or your own Entra app registration.
3333 
34| Path | Additional requirements |
35| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
36| LLM gateway | Gateway URL and API token from your IT team. |
37| Bedrock direct | AWS account with Claude model access enabled in target region. IAM OIDC identity provider and role configured to trust Microsoft Entra ID tokens. |
38| Vertex AI direct | Google Cloud project with Vertex AI API enabled and Claude model access. Google OAuth client configured with the add-in's redirect URI. |
39| Foundry direct | Azure AI Foundry resource with at least one Claude model deployed. Deployment names must use default model IDs (for example, `claude-opus-4-6`), not custom names. Then one credential path: **keyless**, your own Entra app registration with the Azure Cognitive Services `user_impersonation` delegated permission (admin-consented) and users holding the Cognitive Services User role on the resource (see [Foundry direct without an API key](#foundry-direct-without-an-api-key)); or the resource API key from Azure Portal, your Foundry resource, Keys and Endpoint, KEY 1. |
34| Path | Additional requirements |
35| - | - |
36| LLM gateway | Gateway URL and API token from your IT team. |
37| Bedrock direct | AWS account with Claude model access enabled in target region. IAM OIDC identity provider and role configured to trust Microsoft Entra ID tokens. |
38| Vertex AI direct | Google Cloud project with Vertex AI API enabled and Claude model access. Google OAuth client configured with the add-in's redirect URI. |
39| Foundry direct | Azure AI Foundry resource with at least one Claude model deployed. Deployment names must use default model IDs (for example, `claude-opus-4-6`), not custom names. Then one credential path: **keyless**, your own Entra app registration with the Azure Cognitive Services `user_impersonation` delegated permission (admin-consented) and users holding the Cognitive Services User role on the resource (see [Foundry direct without an API key](#foundry-direct-without-an-api-key)); or the resource API key from Azure Portal, your Foundry resource, Keys and Endpoint, KEY 1. |
4040 
4141Your organization's IT team manages these resources. Anthropic cannot
4242provide or reset credentials.
from line 59
5959Use this table if your organization signs in with Claude accounts and
6060inference goes to `api.anthropic.com`.
6161 
62| Domain | Required when | Purpose |
63| ------------------------------ | ------------------------- | ------------------------------------------------------------------------------------------ |
64| `pivot.claude.ai` | Always | Add-in host serving task pane UI, analytics, icon search, skill downloads, and telemetry. |
65| `claude.ai` | Always | Anthropic OAuth sign-in and feature-flag evaluation. |
66| `api.anthropic.com` | Always | Claude inference API, file uploads, code-execution containers, and MCP connector registry. |
67| `appsforoffice.microsoft.com` | Always | Microsoft Office.js runtime script (required by all Office add-ins). |
68| `login.microsoftonline.com` | If using Outlook | Microsoft Entra ID sign-in via Nested App Auth for the Graph token. |
69| `o1158394.ingest.us.sentry.io` | Optional | Crash and error reporting; blocking degrades diagnostics only. |
70| `mcp-proxy.anthropic.com` | If using MCP connectors | Proxy for MCP connector tool calls. |
71| `bridge.claudeusercontent.com` | If using work across apps | WebSocket bridge for the work-across-apps feature. |
72| `graph.microsoft.com` | If using Outlook | Microsoft Graph mailbox and calendar API. |
62| Domain | Required when | Purpose |
63| - | - | - |
64| `pivot.claude.ai` | Always | Add-in host serving task pane UI, analytics, icon search, skill downloads, and telemetry. |
65| `claude.ai` | Always | Anthropic OAuth sign-in and feature-flag evaluation. |
66| `api.anthropic.com` | Always | Claude inference API, file uploads, code-execution containers, and MCP connector registry. |
67| `appsforoffice.microsoft.com` | Always | Microsoft Office.js runtime script (required by all Office add-ins). |
68| `login.microsoftonline.com` | If using Outlook | Microsoft Entra ID sign-in via Nested App Auth for the Graph token. |
69| `o1158394.ingest.us.sentry.io` | Optional | Crash and error reporting; blocking degrades diagnostics only. |
70| `mcp-proxy.anthropic.com` | If using MCP connectors | Proxy for MCP connector tool calls. |
71| `bridge.claudeusercontent.com` | If using work across apps | WebSocket bridge for the work-across-apps feature. |
72| `graph.microsoft.com` | If using Outlook | Microsoft Graph mailbox and calendar API. |
7373 
7474If your organization has
7575[IP allowlisting](https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting)
from line 94
9494and inference goes to your LLM gateway, Bedrock, Vertex AI, or Azure
9595AI Foundry.
9696 
97| Domain | Required when | Purpose |
98| ---------------------------------------- | ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ |
99| `pivot.claude.ai` | Always | Add-in host serving task pane UI, analytics, and telemetry. |
100| `claude.ai/api/` | Always | Feature-flag evaluation without sign-in. |
101| `appsforoffice.microsoft.com` | Always | Microsoft Office.js runtime script. |
102| `login.microsoftonline.com` | Always | Microsoft Entra ID sign-in via Nested App Auth; reads admin config and issues tokens. |
103| `o1158394.ingest.us.sentry.io` | Optional | Crash and error reporting; blocking degrades diagnostics only. |
104| Your LLM gateway URL | If using LLM gateway | Organization's LLM gateway for inference. |
105| `sts.amazonaws.com` | If using Bedrock direct | AWS STS for exchanging Entra ID token for temporary Bedrock credentials. |
106| `bedrock-runtime.<region>.amazonaws.com` | If using Bedrock direct | Bedrock inference endpoint; replace `<region>` with your configured AWS region. |
107| `accounts.google.com` | If using Vertex AI direct | Google OAuth consent screen. |
108| `oauth2.googleapis.com` | If using Vertex AI direct | Google OAuth token exchange and refresh. |
109| `aiplatform.googleapis.com` | If using Vertex AI direct | Vertex AI global inference endpoint. |
110| `<region>-aiplatform.googleapis.com` | If using Vertex AI direct | Vertex AI regional inference endpoint; replace `<region>` with your GCP region. |
111| `<resource>.services.ai.azure.com` | If using Foundry direct | Azure AI Foundry inference endpoint; replace `<resource>` with your resource name. |
112| Your Foundry gateway URL | If using Foundry direct through your own gateway | The gateway or proxy set in `azure_base_url`. Connections made while it is set do not call `<resource>.services.ai.azure.com`. |
113| `graph.microsoft.com` | If using Outlook | Microsoft Graph mailbox and calendar API. |
97| Domain | Required when | Purpose |
98| - | - | - |
99| `pivot.claude.ai` | Always | Add-in host serving task pane UI, analytics, and telemetry. |
100| `claude.ai/api/` | Always | Feature-flag evaluation without sign-in. |
101| `appsforoffice.microsoft.com` | Always | Microsoft Office.js runtime script. |
102| `login.microsoftonline.com` | Always | Microsoft Entra ID sign-in via Nested App Auth; reads admin config and issues tokens. |
103| `o1158394.ingest.us.sentry.io` | Optional | Crash and error reporting; blocking degrades diagnostics only. |
104| Your LLM gateway URL | If using LLM gateway | Organization's LLM gateway for inference. |
105| `sts.amazonaws.com` | If using Bedrock direct | AWS STS for exchanging Entra ID token for temporary Bedrock credentials. |
106| `bedrock-runtime.<region>.amazonaws.com` | If using Bedrock direct | Bedrock inference endpoint; replace `<region>` with your configured AWS region. |
107| `accounts.google.com` | If using Vertex AI direct | Google OAuth consent screen. |
108| `oauth2.googleapis.com` | If using Vertex AI direct | Google OAuth token exchange and refresh. |
109| `aiplatform.googleapis.com` | If using Vertex AI direct | Vertex AI global inference endpoint. |
110| `<region>-aiplatform.googleapis.com` | If using Vertex AI direct | Vertex AI regional inference endpoint; replace `<region>` with your GCP region. |
111| `<resource>.services.ai.azure.com` | If using Foundry direct | Azure AI Foundry inference endpoint; replace `<resource>` with your resource name. |
112| Your Foundry gateway URL | If using Foundry direct through your own gateway | The gateway or proxy set in `azure_base_url`. Connections made while it is set do not call `<resource>.services.ai.azure.com`. |
113| `graph.microsoft.com` | If using Outlook | Microsoft Graph mailbox and calendar API. |
114114 
115115If Anthropic serves your add-in settings from your Claude organization,
116116as described in
from line 186
186186 
187187The plugin exposes the following slash commands once installed.
188188 
189| Command | Function |
190| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
191| `/claude-for-msft-365-install:setup` | Interactive wizard: provisions cloud resources, handles admin consent, writes manifest. |
192| `/claude-for-msft-365-install:manifest` | Generates a customized add-in manifest XML. |
193| `/claude-for-msft-365-install:consent` | Generates the Azure admin-consent URL for the add-in's app registration. |
194| `/claude-for-msft-365-install:update-user-attrs` | Writes per-user configuration via Microsoft Graph extension attributes. |
195| `/claude-for-msft-365-install:bootstrap` | Builds a bootstrap endpoint for per-user MCP servers, skills, and dynamic config. |
196| `/claude-for-msft-365-install:debug` | Diagnoses deployment issues: stale config after a manifest update, connection failures, an add-in that does not appear, sign-in or admin-consent loops, and reading the add-in's error paste. |
197| `/claude-for-msft-365-install:export-data` | Makes a read-only copy of a user's chat history, skills, connector registrations, and settings before a device is rebuilt. See [Data storage and retention](/docs/office-agents/data-storage). |
189| Command | Function |
190| - | - |
191| `/claude-for-msft-365-install:setup` | Interactive wizard: provisions cloud resources, handles admin consent, writes manifest. |
192| `/claude-for-msft-365-install:manifest` | Generates a customized add-in manifest XML. |
193| `/claude-for-msft-365-install:consent` | Generates the Azure admin-consent URL for the add-in's app registration. |
194| `/claude-for-msft-365-install:update-user-attrs` | Writes per-user configuration via Microsoft Graph extension attributes. |
195| `/claude-for-msft-365-install:bootstrap` | Builds a bootstrap endpoint for per-user MCP servers, skills, and dynamic config. |
196| `/claude-for-msft-365-install:debug` | Diagnoses deployment issues: stale config after a manifest update, connection failures, an add-in that does not appear, sign-in or admin-consent loops, and reading the add-in's error paste. |
197| `/claude-for-msft-365-install:export-data` | Makes a read-only copy of a user's chat history, skills, connector registrations, and settings before a device is rebuilt. See [Data storage and retention](/docs/office-agents/data-storage). |
198198 
199199Run `/claude-for-msft-365-install:debug` whenever a connection or sign-in
200200does not behave as expected. It triages from the symptom, reads the "Copy
from line 207
207207The setup wizard creates resources in your cloud account based on the
208208connection path you choose.
209209 
210| Path | Provisioned resources |
211| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
212| LLM gateway | None. Collects your gateway URL and token, then generates the manifest. |
213| Bedrock direct | IAM OIDC identity provider trusting Microsoft Entra ID tokens, role with `bedrock:InvokeModel` and `bedrock:InvokeModelWithResponseStream` permissions, trust policy scoped to the Claude add-in's application ID. |
214| Vertex AI direct | Walks through creating a Google OAuth client in the GCP Console (not automatable via CLI), enables the Vertex AI API, captures client ID and secret for the manifest. |
215| Foundry direct | None. Collects resource name and API key for the manifest. |
210| Path | Provisioned resources |
211| - | - |
212| LLM gateway | None. Collects your gateway URL and token, then generates the manifest. |
213| Bedrock direct | IAM OIDC identity provider trusting Microsoft Entra ID tokens, role with `bedrock:InvokeModel` and `bedrock:InvokeModelWithResponseStream` permissions, trust policy scoped to the Claude add-in's application ID. |
214| Vertex AI direct | Walks through creating a Google OAuth client in the GCP Console (not automatable via CLI), enables the Vertex AI API, captures client ID and secret for the manifest. |
215| Foundry direct | None. Collects resource name and API key for the manifest. |
216216 
217217### Per-user configuration
218218 
from line 260
260260attributes (comma-separated), or a bootstrap endpoint (JSON array), so it
261261can apply org-wide from one manifest or vary per user.
262262 
263| Slug | Effect |
264| ------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
265| `skills.authoring` | Blocks creating, editing, and uploading skills. Running admin-provisioned skills is unaffected. |
266| `thumbs` | Blocks response feedback (thumbs up / down and the follow-up prompt). |
267| `addin.access` | Kill switch: the add-in refuses to run. |
268| `file.upload` | Blocks attaching files to the conversation. |
269| `web_search` | Removes the built-in web search and web fetch tools, whose queries are served by Anthropic's search provider, along with the user-facing web search toggle. Code execution is unaffected. |
263| Slug | Effect |
264| - | - |
265| `skills.authoring` | Blocks creating, editing, and uploading skills. Running admin-provisioned skills is unaffected. |
266| `thumbs` | Blocks response feedback (thumbs up / down and the follow-up prompt). |
267| `addin.access` | Kill switch: the add-in refuses to run. |
268| `file.upload` | Blocks attaching files to the conversation. |
269| `web_search` | Removes the built-in web search and web fetch tools, whose queries are served by Anthropic's search provider, along with the user-facing web search toggle. Code execution is unaffected. |
270270 
271271Unknown slugs are ignored, so setting a slug from a newer add-in version
272272on an older deployment is safe.
from line 594
594594 User** role on the Foundry resource.
5955953. Put these parameters in the manifest URL (no `azure_api_key`):
596596 
597| Parameter | Value |
598| --------------------- | ----------------------------------------------------------- |
599| `azure_resource_name` | Your Foundry resource name. |
600| `entra_sso` | `1` |
601| `graph_client_id` | The application (client) ID of your Entra app registration. |
602| `entra_scope` | `https://cognitiveservices.azure.com/.default` |
603| `gateway_auth_source` | `entra` |
597| Parameter | Value |
598| - | - |
599| `azure_resource_name` | Your Foundry resource name. |
600| `entra_sso` | `1` |
601| `graph_client_id` | The application (client) ID of your Entra app registration. |
602| `entra_scope` | `https://cognitiveservices.azure.com/.default` |
603| `gateway_auth_source` | `entra` |
604604 
605605When `gateway_auth_source=entra` is set, the add-in ignores any
606606`azure_api_key` it receives: the administrator chose keyless sign-in.
from line 637
637637 
638638The following manifest parameters configure this path.
639639 
640| Parameter | Value |
641| --------------------- | ------------------------------------------------------------------------------------- |
642| `azure_resource_name` | Your Foundry resource name. |
643| `azure_base_url` | The gateway base URL, for example `https://ai-gateway.example.com/foundry/anthropic`. |
644| `azure_api_key` | The key the gateway expects as `x-api-key`. Omit it with keyless sign-in. |
640| Parameter | Value |
641| - | - |
642| `azure_resource_name` | Your Foundry resource name. |
643| `azure_base_url` | The gateway base URL, for example `https://ai-gateway.example.com/foundry/anthropic`. |
644| `azure_api_key` | The key the gateway expects as `x-api-key`. Omit it with keyless sign-in. |
645645 
646646### Change or update your gateway connection
647647 
from line 679
679679 
680680**`gateway_api_format: anthropic` (default):**
681681 
682| Endpoint | Description |
683| ------------------- | ----------------------------------------------------------------------------- |
682| Endpoint | Description |
683| - | - |
684684| `POST /v1/messages` | Send messages to Claude; supports both streaming and non-streaming responses. |
685| `GET /v1/models` | List available models. |
685| `GET /v1/models` | List available models. |
686686 
687687**`gateway_api_format: bedrock`:**
688688 
689| Endpoint | Description |
690| ---------------------------------------------------- | -------------------------------------------- |
691| `POST /model/{model-id}/invoke` | Send message and receive complete response. |
689| Endpoint | Description |
690| - | - |
691| `POST /model/{model-id}/invoke` | Send message and receive complete response. |
692692| `POST /model/{model-id}/invoke-with-response-stream` | Send message and receive streaming response. |
693693 
694694Native Bedrock `InvokeModel` pass-through. `gateway_url` must point at
from line 696
696696 
697697**`gateway_api_format: vertex`:**
698698 
699| Endpoint | Description |
700| ----------------------------------------------------------------------------------------------------- | -------------------------------------------- |
701| `POST /projects/{project}/locations/{region}/publishers/anthropic/models/{model-id}:rawPredict` | Send message and receive complete response. |
699| Endpoint | Description |
700| - | - |
701| `POST /projects/{project}/locations/{region}/publishers/anthropic/models/{model-id}:rawPredict` | Send message and receive complete response. |
702702| `POST /projects/{project}/locations/{region}/publishers/anthropic/models/{model-id}:streamRawPredict` | Send message and receive streaming response. |
703703 
704704Native Vertex pass-through. `gateway_url` must include the API-version
from line 740
740740If your team already runs Claude Code through a gateway, the table
741741below summarizes how the Office add-in setup differs.
742742 
743| Aspect | Claude Code | Office add-ins |
744| ------------------ | ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
745| Credential storage | OS keychain or environment variables | Browser localStorage (sandboxed iframe) |
746| Auth configuration | Environment variables, settings file, helper scripts | Manual entry in add-in UI (gateway), Entra ID (Bedrock, keyless Foundry), Google OAuth (Vertex AI), or Azure API key (Foundry) |
747| Token refresh | Supports helper scripts for rotation | Automatic via a bootstrap endpoint (gateway), Entra ID (Bedrock, keyless Foundry), or Google OAuth (Vertex AI); gateway tokens entered manually in the add-in UI require signing out and back in when they rotate |
748| Custom model names | Configurable via environment variables | Not configurable in v1 |
743| Aspect | Claude Code | Office add-ins |
744| - | - | - |
745| Credential storage | OS keychain or environment variables | Browser localStorage (sandboxed iframe) |
746| Auth configuration | Environment variables, settings file, helper scripts | Manual entry in add-in UI (gateway), Entra ID (Bedrock, keyless Foundry), Google OAuth (Vertex AI), or Azure API key (Foundry) |
747| Token refresh | Supports helper scripts for rotation | Automatic via a bootstrap endpoint (gateway), Entra ID (Bedrock, keyless Foundry), or Google OAuth (Vertex AI); gateway tokens entered manually in the add-in UI require signing out and back in when they rotate |
748| Custom model names | Configurable via environment variables | Not configurable in v1 |
749749 
750750When gateway configuration comes from a bootstrap endpoint, the add-in
751751keeps the token current without user action. It calls the bootstrap
from line 961
961961When you review the consent prompt or the resulting enterprise
962962application in your tenant, confirm it matches these values.
963963 
964| Field | Value |
965| ----------------------- | ---------------------------------------- |
966| Display name | Claude for Office |
967| Application (client) ID | `c2995f31-11e7-4882-b7a7-ef9def0a0266` |
968| Publisher | Anthropic, PBC (verified publisher) |
964| Field | Value |
965| - | - |
966| Display name | Claude for Office |
967| Application (client) ID | `c2995f31-11e7-4882-b7a7-ef9def0a0266` |
968| Publisher | Anthropic, PBC (verified publisher) |
969969| Supported account types | Accounts in any organizational directory |
970970 
971971The add-in uses the following redirect URIs with this application. Each
from line 972
972972one exists for a specific Microsoft sign-in path, and none of them
973973receives a Microsoft access token in the URL.
974974 
975| Redirect URI | Platform | Purpose |
976| -------------------------------------------- | ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
977| `https://pivot.claude.ai/auth/callback` | Web | admin consent confirmation page, receives only `admin_consent` and `tenant` from Microsoft. Google sign-in for Vertex AI reuses this URI for its [OAuth authorization-code redirect](#oauth-authorization-code-redirects) |
978| `https://pivot.claude.ai/msal-redirect.html` | Single-page application | MSAL response bridge for Office on the web, where the host cannot broker tokens natively |
979| `brk-multihub://pivot.claude.ai` | Single-page application | Nested App Authentication broker on Office desktop and Mac |
980| `https://pivot.claude.ai/auth/3p` | Web | legacy entry from earlier builds, not used by current builds, scheduled for removal |
975| Redirect URI | Platform | Purpose |
976| - | - | - |
977| `https://pivot.claude.ai/auth/callback` | Web | admin consent confirmation page, receives only `admin_consent` and `tenant` from Microsoft. Google sign-in for Vertex AI reuses this URI for its [OAuth authorization-code redirect](#oauth-authorization-code-redirects) |
978| `https://pivot.claude.ai/msal-redirect.html` | Single-page application | MSAL response bridge for Office on the web, where the host cannot broker tokens natively |
979| `brk-multihub://pivot.claude.ai` | Single-page application | Nested App Authentication broker on Office desktop and Mac |
980| `https://pivot.claude.ai/auth/3p` | Web | legacy entry from earlier builds, not used by current builds, scheduled for removal |
981981 
982982### Verify this in your own environment
983983 
from line 1010
10101010serves is in the third-party platform column too, because inference
10111011goes to the organization's provider.
10121012 
1013| Feature | Claude account | Third-party platform |
1014| ------------------------------------------------------------ | -------------- | ---------------------------------------------------------------------------------------------------------- |
1015| Chat with your spreadsheet, deck, document, or email | Yes | Yes |
1016| Read and edit cells, slides, formulas, and document text | Yes | Yes |
1017| Read, search, and triage your mailbox and calendar (Outlook) | Yes | Yes |
1018| Connectors (S\&P, FactSet, and others) | Yes | Coming soon |
1019| Working across apps | Yes | No |
1020| Dictation | Yes | No |
1021| Skills | Yes | Coming soon |
1022| File uploads | Yes | No |
1023| Web search | Yes | Vertex direct, Foundry direct, and gateways the add-in detects as routing to a Foundry-compatible upstream |
1024| Code execution | Yes | Foundry direct, and gateways the add-in detects as routing to a Foundry-compatible upstream |
1013| Feature | Claude account | Third-party platform |
1014| - | - | - |
1015| Chat with your spreadsheet, deck, document, or email | Yes | Yes |
1016| Read and edit cells, slides, formulas, and document text | Yes | Yes |
1017| Read, search, and triage your mailbox and calendar (Outlook) | Yes | Yes |
1018| Connectors (S\&P, FactSet, and others) | Yes | Coming soon |
1019| Working across apps | Yes | No |
1020| Dictation | Yes | No |
1021| Skills | Yes | Coming soon |
1022| File uploads | Yes | No |
1023| Web search | Yes | Vertex direct, Foundry direct, and gateways the add-in detects as routing to a Foundry-compatible upstream |
1024| Code execution | Yes | Foundry direct, and gateways the add-in detects as routing to a Foundry-compatible upstream |
10251025 
10261026If your team needs these features, talk to your Claude admin about
10271027which sign-in path fits your organization.

plugins/admin Changed · +11 / -11 lines

from line 133
133133 
134134Each availability value decides what members see and whether they can remove the plugin:
135135 
136| Setting | What members see | Can members remove it |
137| :----------------------- | :--------------------------------------------------------------------------------------------- | :----------------------------------------- |
138| **Not available** | Nothing; the plugin is hidden from **Customize > Plugins** and can't be installed | Not applicable |
139| **Available to install** | The plugin appears under **Discover** and members install it if they want it | Yes |
140| **Installed by default** | The plugin is already installed for every member | Members can turn it off |
141| **Required** | The plugin is installed and always on, marked **This plugin is required by your organization** | No; members can't turn it off or remove it |
136| Setting | What members see | Can members remove it |
137| :- | :- | :- |
138| **Not available** | Nothing; the plugin is hidden from **Customize > Plugins** and can't be installed | Not applicable |
139| **Available to install** | The plugin appears under **Discover** and members install it if they want it | Yes |
140| **Installed by default** | The plugin is already installed for every member | Members can turn it off |
141| **Required** | The plugin is installed and always on, marked **This plugin is required by your organization** | No; members can't turn it off or remove it |
142142 
143143Availability doesn't add a plugin's bundled connectors. If a plugin you install by default or require includes a connector, an Owner also adds that connector in [**Organization settings > Connectors**](https://claude.ai/admin-settings/connectors), and members then connect it with their own account.
144144 
from line 262
262262 
263263The **Publishing** setting decides whether members can publish to your organization and whether each request waits for review. Set it in [**Organization settings > Plugins & skills > Policy**](https://claude.ai/admin-settings/skills?tab=policy). Owners and Primary Owners can change it. The same setting covers skills and plugins, and it has these values:
264264 
265| Publishing | What members can do |
266| :------------------ | :------------------------------------------------------------------------------------------------------------------------------------------- |
267| **Requires review** | Submit a plugin for review. Nothing reaches other members until a reviewer approves the request. |
268| **Open** | Publish without review. Where your organization scans what members publish, the plugin goes live after the security scan passes. |
269| **Off** | Nothing. **Publish to org** doesn't appear for members, and requests that were already waiting are hidden until you turn publishing back on. |
265| Publishing | What members can do |
266| :- | :- |
267| **Requires review** | Submit a plugin for review. Nothing reaches other members until a reviewer approves the request. |
268| **Open** | Publish without review. Where your organization scans what members publish, the plugin goes live after the security scan passes. |
269| **Off** | Nothing. **Publish to org** doesn't appear for members, and requests that were already waiting are hidden until you turn publishing back on. |
270270 
271271If nobody in your organization has chosen a **Publishing** value, your plan's default applies:
272272 

plugins/org-rollout Changed · +7 / -7 lines

from line 18
1818 
1919The table compares organization settings on claude.ai with Claude Code managed settings on who receives the plugin and what each route asks of you.
2020 
21| | Organization settings on claude.ai | Claude Code managed settings |
22| :------------------------ | :----------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------ |
23| Who receives the plugin | Members, on their claude.ai account: in chat, in Cowork, and in Claude Code sessions that sync from that account | Claude Code on every machine that receives the settings |
24| Where you set it up | [**Organization settings > Plugins & skills**](https://claude.ai/admin-settings/skills?tab=inventory) | Server-managed settings, an MDM policy, or a `managed-settings.json` file |
25| What you set | An availability for each plugin, such as **Installed by default** or **Required** | `extraKnownMarketplaces` to register your marketplace and `enabledPlugins` to install plugins from it |
21| | Organization settings on claude.ai | Claude Code managed settings |
22| :- | :- | :- |
23| Who receives the plugin | Members, on their claude.ai account: in chat, in Cowork, and in Claude Code sessions that sync from that account | Claude Code on every machine that receives the settings |
24| Where you set it up | [**Organization settings > Plugins & skills**](https://claude.ai/admin-settings/skills?tab=inventory) | Server-managed settings, an MDM policy, or a `managed-settings.json` file |
25| What you set | An availability for each plugin, such as **Installed by default** or **Required** | `extraKnownMarketplaces` to register your marketplace and `enabledPlugins` to install plugins from it |
2626| Access to your repository | Members need none. Organization sync reads the repository through your organization's GitHub or GitLab connection. | Each machine fetches the marketplace itself. For a private Git repository, it uses the Git credentials already on that machine. |
27| Which components load | Depends on the surface. See [Plugin feature support across platforms](/docs/plugins/platform-support). | Every component |
28| Full setup steps | [Manage plugins for your organization](/docs/plugins/admin) | [Manage Claude Code plugins for your organization](https://code.claude.com/docs/en/plugins/org) in the Claude Code docs |
27| Which components load | Depends on the surface. See [Plugin feature support across platforms](/docs/plugins/platform-support). | Every component |
28| Full setup steps | [Manage plugins for your organization](/docs/plugins/admin) | [Manage Claude Code plugins for your organization](https://code.claude.com/docs/en/plugins/org) in the Claude Code docs |
2929 
3030A plugin on a member's account reaches Claude Code as a synced plugin in Cowork and in terminal sessions where the member signs in with their claude.ai account on Claude Code v2.1.273 or later. [Plugins synced from claude.ai](https://code.claude.com/docs/en/plugins/loading#synced-plugins) has the sign-in and timing rules. For developers whose terminal sessions don't sync from a claude.ai account, use managed settings.
3131 

plugins/overview Changed · +6 / -6 lines

from line 87
8787 
8888A plugin can contain skills, commands, MCP connectors, and agents. Chat, Cowork, and Claude Code each load the components they support and skip the others, so one plugin can do more in Cowork than in a chat conversation.
8989 
90| Component | What it adds for you | Where it works |
91| :------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------ |
92| Skills | Instructions Claude follows when a task matches, such as your team's process for a weekly report. They're listed in **Customize > Skills** alongside your own skills. | Chat, Cowork, Claude Code |
93| Commands | Named actions. In Cowork and Claude Code you run one by typing `/plugin-name:command`. In chat a command loads as a skill. | Chat, Cowork, Claude Code |
94| MCP connectors | Access to an external tool or data source. You add or connect each one from the plugin's **Connectors** tab. | Chat, Cowork, Claude Code |
95| Agents | Specialists Claude can delegate part of a task to | Cowork, Claude Code |
90| Component | What it adds for you | Where it works |
91| :- | :- | :- |
92| Skills | Instructions Claude follows when a task matches, such as your team's process for a weekly report. They're listed in **Customize > Skills** alongside your own skills. | Chat, Cowork, Claude Code |
93| Commands | Named actions. In Cowork and Claude Code you run one by typing `/plugin-name:command`. In chat a command loads as a skill. | Chat, Cowork, Claude Code |
94| MCP connectors | Access to an external tool or data source. You add or connect each one from the plugin's **Connectors** tab. | Chat, Cowork, Claude Code |
95| Agents | Specialists Claude can delegate part of a task to | Cowork, Claude Code |
9696 
9797[Plugin feature support across platforms](/docs/plugins/platform-support) lists every component by app.
9898 

plugins/platform-support Changed · +21 / -21 lines

from line 23
2323 
2424A component marked "Ignored" is skipped on that surface, and a component marked "Can't be installed" makes that surface refuse the whole plugin.
2525 
26| Component | Chat | Cowork | Claude Code | Notes |
27| :-------------------------------------------------------------------- | :-------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------- | :-------------------------------- | :------------------------------------------------------------------------------------------ |
28| Skills (`skills/<name>/SKILL.md`) | Loads | Loads | Loads | [Create custom skills](/docs/skills/how-to) |
29| Commands (`commands/*.md`) | Loads as a skill; Claude applies it when it fits | Loads; you run it by typing `/plugin-name:command` | Loads | |
30| Agents (`agents/*.md`) | Ignored | Loads | Loads | |
31| Hooks (`hooks/hooks.json`) | Ignored | Loads | Loads | [Hooks](https://code.claude.com/docs/en/plugins/components#hooks) in the Claude Code docs |
32| Remote MCP server, `http` or `sse` with a fixed URL | Listed on the plugin's **Connectors** tab; works once you add or connect it there | Loads; connect it from the plugin's **Connectors** tab | Loads | [Bundle a connector with its skill](/docs/plugins/build#bundle-an-mcp-connector-with-its-skill) |
33| Local MCP server, a command the app starts, including `.mcpb` bundles | Ignored | Loads when the Cowork session runs on your computer | Loads | On the web, the plugin's **Connectors** tab marks it **Runs in each session** |
34| MCP server that references `${user_config.*}` values | Ignored when the URL contains the reference | Ignored when a referenced option has no default; Cowork doesn't prompt for values | Loads; prompts you for the values | [User configuration](https://code.claude.com/docs/en/plugins/components#user-configuration) |
35| Executables in a top-level `bin/` directory | Can't be installed | Can't be installed | Loads | |
36| LSP servers, output styles, themes, `settings` | Ignored | Ignored | Loads | [Plugin components](https://code.claude.com/docs/en/plugins/components) |
26| Component | Chat | Cowork | Claude Code | Notes |
27| :- | :- | :- | :- | :- |
28| Skills (`skills/<name>/SKILL.md`) | Loads | Loads | Loads | [Create custom skills](/docs/skills/how-to) |
29| Commands (`commands/*.md`) | Loads as a skill; Claude applies it when it fits | Loads; you run it by typing `/plugin-name:command` | Loads | |
30| Agents (`agents/*.md`) | Ignored | Loads | Loads | |
31| Hooks (`hooks/hooks.json`) | Ignored | Loads | Loads | [Hooks](https://code.claude.com/docs/en/plugins/components#hooks) in the Claude Code docs |
32| Remote MCP server, `http` or `sse` with a fixed URL | Listed on the plugin's **Connectors** tab; works once you add or connect it there | Loads; connect it from the plugin's **Connectors** tab | Loads | [Bundle a connector with its skill](/docs/plugins/build#bundle-an-mcp-connector-with-its-skill) |
33| Local MCP server, a command the app starts, including `.mcpb` bundles | Ignored | Loads when the Cowork session runs on your computer | Loads | On the web, the plugin's **Connectors** tab marks it **Runs in each session** |
34| MCP server that references `${user_config.*}` values | Ignored when the URL contains the reference | Ignored when a referenced option has no default; Cowork doesn't prompt for values | Loads; prompts you for the values | [User configuration](https://code.claude.com/docs/en/plugins/components#user-configuration) |
35| Executables in a top-level `bin/` directory | Can't be installed | Can't be installed | Loads | |
36| LSP servers, output styles, themes, `settings` | Ignored | Ignored | Loads | [Plugin components](https://code.claude.com/docs/en/plugins/components) |
3737 
3838When you submit a plugin to the directory, the portal derives the surfaces it supports from these same rules and shows them to you before you submit.
3939 
from line 41
4141 
4242Chat and Cowork read plugins from your claude.ai account, and Claude Code reads them from the machine it runs on.
4343 
44| | Chat and Cowork | Claude Code | Notes |
45| :--------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------- |
46| Where you add plugins | [**Customize > Plugins**](https://claude.ai/customize/plugins) in claude.ai or the desktop app | `/plugin` in a session, or `claude plugin install` | [Plugins](/docs/plugins/overview), [Install plugins](https://code.claude.com/docs/en/plugins/install) |
47| What an install is attached to | Your account, for the organization you're in | The machine, at user, project, or local scope | |
48| Which way installs travel | A plugin you install on your account also appears in Claude Code as a synced plugin at the next session start | A plugin you install from the command line stays on that machine and isn't added to your account | [Synced plugins](https://code.claude.com/docs/en/plugins/loading#synced-plugins) |
49| Hosts for a marketplace you add yourself | GitHub and GitHub Enterprise repositories, and public GitLab and Bitbucket repositories | Any Git repository, GitHub shorthand, URL, or local path | Repositories your organization syncs to distribute plugins follow [different rules](/docs/plugins/org-sync#plugin-sources-that-organization-sync-accepts) |
50| Marketplace and plugin limits | Up to 25 marketplaces that you add yourself, counted for your account in each organization. Each plugin can contain up to 5,000 files and 200 MB, and 200 MB is also the largest file that **Upload plugin** accepts. | No account limits apply; installs are per machine | |
51| Install from a file | **Add > Upload plugin** with a zip of the folder | `claude --plugin-dir <path>` for one session | [Plugin structure and testing](/docs/plugins/build#test-the-plugin-on-each-surface) |
52| Browse the directory | **Discover** in **Customize > Plugins**, on Pro, Max, Team, and Enterprise plans. On Team and Enterprise plans, an Owner can [remove the directory as a source](/docs/plugins/admin#manage-synced-marketplaces) for the organization. | Not in `/plugin`; a plugin added from the directory on claude.ai reaches Claude Code as a synced plugin | [Publish to the directory](/docs/directory/publish) |
53| Organization controls | An Owner sets each plugin to **Not available**, **Available to install**, **Installed by default**, or **Required** | In managed settings, an admin allowlists or blocks marketplaces and force-installs plugins | [Manage plugins for your organization](/docs/plugins/admin), and the [Claude Code equivalent](https://code.claude.com/docs/en/plugins/org) |
44| | Chat and Cowork | Claude Code | Notes |
45| :- | :- | :- | :- |
46| Where you add plugins | [**Customize > Plugins**](https://claude.ai/customize/plugins) in claude.ai or the desktop app | `/plugin` in a session, or `claude plugin install` | [Plugins](/docs/plugins/overview), [Install plugins](https://code.claude.com/docs/en/plugins/install) |
47| What an install is attached to | Your account, for the organization you're in | The machine, at user, project, or local scope | |
48| Which way installs travel | A plugin you install on your account also appears in Claude Code as a synced plugin at the next session start | A plugin you install from the command line stays on that machine and isn't added to your account | [Synced plugins](https://code.claude.com/docs/en/plugins/loading#synced-plugins) |
49| Hosts for a marketplace you add yourself | GitHub and GitHub Enterprise repositories, and public GitLab and Bitbucket repositories | Any Git repository, GitHub shorthand, URL, or local path | Repositories your organization syncs to distribute plugins follow [different rules](/docs/plugins/org-sync#plugin-sources-that-organization-sync-accepts) |
50| Marketplace and plugin limits | Up to 25 marketplaces that you add yourself, counted for your account in each organization. Each plugin can contain up to 5,000 files and 200 MB, and 200 MB is also the largest file that **Upload plugin** accepts. | No account limits apply; installs are per machine | |
51| Install from a file | **Add > Upload plugin** with a zip of the folder | `claude --plugin-dir <path>` for one session | [Plugin structure and testing](/docs/plugins/build#test-the-plugin-on-each-surface) |
52| Browse the directory | **Discover** in **Customize > Plugins**, on Pro, Max, Team, and Enterprise plans. On Team and Enterprise plans, an Owner can [remove the directory as a source](/docs/plugins/admin#manage-synced-marketplaces) for the organization. | Not in `/plugin`; a plugin added from the directory on claude.ai reaches Claude Code as a synced plugin | [Publish to the directory](/docs/directory/publish) |
53| Organization controls | An Owner sets each plugin to **Not available**, **Available to install**, **Installed by default**, or **Required** | In managed settings, an admin allowlists or blocks marketplaces and force-installs plugins | [Manage plugins for your organization](/docs/plugins/admin), and the [Claude Code equivalent](https://code.claude.com/docs/en/plugins/org) |
5454 
5555## Related resources
5656 

plugins/pre-submission-checklist Changed · +49 / -49 lines

from line 79
7979 
8080The repository and folder layout checks cover the plugin's location in the repository and what the repository as a whole contains.
8181 
82| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
83| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
84| Submit a folder that contains `.claude-plugin/plugin.json` | Blocks, except that a folder with no `plugin.json` anywhere and at least one `skills/<name>/SKILL.md` passes with a note and is listed for Claude Code only | |
85| Submit one plugin at a time. In a [marketplace repository](https://code.claude.com/docs/en/plugins/create-marketplace) with several plugins, validate and submit each plugin folder on its own. | Blocks | **Pick one plugin first**, when you select **Submit for review** |
86| Keep every file that a hook, an MCP server command, or a script uses inside the plugin folder, and point every component path in `plugin.json` inside it | Blocks for a `plugin.json` path that points outside the plugin folder | |
87| Commit regular files and folders for everything the plugin loads, not symbolic links, Git submodules, or Git LFS pointer files | Blocks where the plugin loads the entry. Warning elsewhere. | |
88| Remove `.DS_Store`, `Thumbs.db`, `desktop.ini`, and `__MACOSX` entries from the plugin folder | Blocks | In validation, a message that begins "This is a macOS or Windows system file". After you submit, **Files in the repository the scanner won’t accept**. |
89| Use file and folder names that are valid on both Windows and macOS: no colon, no trailing dot or space, no Windows device name such as `con.md` or `prn`, and no two names that differ only by capitalization | Validation stops | **Couldn’t validate that repository** |
90| Name each folder on the path to the plugin with letters, digits, dots, hyphens, and underscores only, and enter the plugin path with the same capitalization as the repository | Validation stops | **Couldn’t validate that repository** |
91| Keep `export-ignore` and `export-subst` out of every `.gitattributes` file. Keep `filter`, Git LFS included, and other attributes that rewrite file contents out of `.gitattributes` files at the repository root, above the plugin folder, and inside it. | Validation stops | **Couldn’t validate that repository** |
92| Keep the repository under 50 MiB as GitHub archives it and under 256 MiB unpacked, with fewer than 10,000 files and folders, and keep every file in the plugin folder under 5 MiB | Validation stops | **Repository too large to validate** |
82| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
83| - | - | - |
84| Submit a folder that contains `.claude-plugin/plugin.json` | Blocks, except that a folder with no `plugin.json` anywhere and at least one `skills/<name>/SKILL.md` passes with a note and is listed for Claude Code only | |
85| Submit one plugin at a time. In a [marketplace repository](https://code.claude.com/docs/en/plugins/create-marketplace) with several plugins, validate and submit each plugin folder on its own. | Blocks | **Pick one plugin first**, when you select **Submit for review** |
86| Keep every file that a hook, an MCP server command, or a script uses inside the plugin folder, and point every component path in `plugin.json` inside it | Blocks for a `plugin.json` path that points outside the plugin folder | |
87| Commit regular files and folders for everything the plugin loads, not symbolic links, Git submodules, or Git LFS pointer files | Blocks where the plugin loads the entry. Warning elsewhere. | |
88| Remove `.DS_Store`, `Thumbs.db`, `desktop.ini`, and `__MACOSX` entries from the plugin folder | Blocks | In validation, a message that begins "This is a macOS or Windows system file". After you submit, **Files in the repository the scanner won’t accept**. |
89| Use file and folder names that are valid on both Windows and macOS: no colon, no trailing dot or space, no Windows device name such as `con.md` or `prn`, and no two names that differ only by capitalization | Validation stops | **Couldn’t validate that repository** |
90| Name each folder on the path to the plugin with letters, digits, dots, hyphens, and underscores only, and enter the plugin path with the same capitalization as the repository | Validation stops | **Couldn’t validate that repository** |
91| Keep `export-ignore` and `export-subst` out of every `.gitattributes` file. Keep `filter`, Git LFS included, and other attributes that rewrite file contents out of `.gitattributes` files at the repository root, above the plugin folder, and inside it. | Validation stops | **Couldn’t validate that repository** |
92| Keep the repository under 50 MiB as GitHub archives it and under 256 MiB unpacked, with fewer than 10,000 files and folders, and keep every file in the plugin folder under 5 MiB | Validation stops | **Repository too large to validate** |
9393 
9494The file-name, plugin-path, and `.gitattributes` checks all produce **Couldn’t validate that repository**. The error doesn't say which cause applies, so check each of them. [Files in the plugin folder](#files-in-the-plugin-folder) has tighter file limits that hold a version for a reviewer.
9595 
from line 97
9797 
9898`plugin.json` is the plugin's manifest. Beyond the syntax and schema errors that `claude plugin validate` catches, the directory runs the checks in this table. Settle the name before you submit, and raise `version` with every release, as [version management](https://code.claude.com/docs/en/plugins/loading#versions-and-updates) describes.
9999 
100| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
101| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
102| Use a `name` made of lowercase letters, digits, and hyphens, up to 64 characters, that starts and ends with a letter or digit | Blocks for non-ASCII characters. Warning for any other name that breaks the pattern, such as uppercase letters. | **Non-ASCII identifier** when blocked |
103| Build the name around your own distinctive product or project name: not a reserved word such as `claude`, `anthropic`, `official`, `plugin`, `mcp`, or `test` as the whole name, not a [marketplace name reserved for Anthropic](https://code.claude.com/docs/en/plugins/marketplace-reference#reserved-names), and nothing that presents the plugin as official | Blocks. Held for a reviewer for a name made only of generic words, such as `test-plugin`. | **Name is taken** when blocked. **Name may be confused with an existing listing** when held. |
104| Choose a name that no other organization's plugin uses. A name that differs only in capitalization or punctuation counts as the same name. | Blocks for the same name. Held for a reviewer for a look-alike. | **Name is taken** when blocked. **Name may be confused with an existing listing** when held. |
105| Choose a name, `displayName`, and `author.name` that can't be mistaken for an existing plugin, publisher, connector, or well-known brand that isn't yours | Held for a reviewer | **Name matches a known brand**, **Name may be confused with an existing listing**, or **Publisher name may be confused with another** for `author.name` |
106| In a fork, give the plugin a name of its own. Forks are allowed. | Held for a reviewer | **Fork uses the upstream project’s name** |
107| Write `displayName` and `author.name` in one writing system, without look-alike letters or invisible characters | Blocks | |
108| Spell the keys that declare components, such as `hooks` and `mcpServers`, exactly as the [plugins reference](https://code.claude.com/docs/en/plugins/manifest-reference) does, and keep them out of the `experimental` object | Blocks | |
109| Set `description`, `author`, and `version` | Warning | |
100| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
101| - | - | - |
102| Use a `name` made of lowercase letters, digits, and hyphens, up to 64 characters, that starts and ends with a letter or digit | Blocks for non-ASCII characters. Warning for any other name that breaks the pattern, such as uppercase letters. | **Non-ASCII identifier** when blocked |
103| Build the name around your own distinctive product or project name: not a reserved word such as `claude`, `anthropic`, `official`, `plugin`, `mcp`, or `test` as the whole name, not a [marketplace name reserved for Anthropic](https://code.claude.com/docs/en/plugins/marketplace-reference#reserved-names), and nothing that presents the plugin as official | Blocks. Held for a reviewer for a name made only of generic words, such as `test-plugin`. | **Name is taken** when blocked. **Name may be confused with an existing listing** when held. |
104| Choose a name that no other organization's plugin uses. A name that differs only in capitalization or punctuation counts as the same name. | Blocks for the same name. Held for a reviewer for a look-alike. | **Name is taken** when blocked. **Name may be confused with an existing listing** when held. |
105| Choose a name, `displayName`, and `author.name` that can't be mistaken for an existing plugin, publisher, connector, or well-known brand that isn't yours | Held for a reviewer | **Name matches a known brand**, **Name may be confused with an existing listing**, or **Publisher name may be confused with another** for `author.name` |
106| In a fork, give the plugin a name of its own. Forks are allowed. | Held for a reviewer | **Fork uses the upstream project’s name** |
107| Write `displayName` and `author.name` in one writing system, without look-alike letters or invisible characters | Blocks | |
108| Spell the keys that declare components, such as `hooks` and `mcpServers`, exactly as the [plugins reference](https://code.claude.com/docs/en/plugins/manifest-reference) does, and keep them out of the `experimental` object | Blocks | |
109| Set `description`, `author`, and `version` | Warning | |
110110 
111111### README and license
112112 
113113The directory shows your README as the listing's description and requires a license before it lists the plugin.
114114 
115| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
116| --------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------ | ---------------------------------------- |
117| Put a README of at least 40 words in the plugin folder, preferably named `README.md`. Words inside code blocks don't count. | Blocks | **README missing**, **README too short** |
118| Add a `LICENSE` file to the plugin folder, or set `license` in `plugin.json` | Blocks | **License missing** |
115| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
116| - | - | - |
117| Put a README of at least 40 words in the plugin folder, preferably named `README.md`. Words inside code blocks don't count. | Blocks | **README missing**, **README too short** |
118| Add a `LICENSE` file to the plugin folder, or set `license` in `plugin.json` | Blocks | **License missing** |
119119 
120120### Files in the plugin folder
121121 
122122The file checks apply to every file in the plugin folder, including images and documents.
123123 
124| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
125| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ | ----------------------------------------------------- |
126| Keep every file that isn't an image or font under 256 KiB | Held for a reviewer | **Files or downloads the validator couldn’t inspect** |
127| Keep the plugin to 512 files or fewer | Held for a reviewer | **Files or downloads the validator couldn’t inspect** |
128| Include only text files, SVG included, complete PNG, JPEG, GIF, and WebP images, and font files. Any other binary file, such as an `.ico`, `.pdf`, or `.zip` file or a compiled executable, is held. | Held for a reviewer | **Files or downloads the validator couldn’t inspect** |
129| To show a bundled image in the README, use Markdown image syntax. Don't refer to bundled images or fonts from commands, hooks, or scripts, or write their paths in backticks or a code block. | Held for a reviewer | |
130| Declare each MCP server with `command` and `args` or with `url`, not a `.mcpb` or `.dxt` bundle | Held for a reviewer. Blocks for a bundle fetched from a URL. | **Bundled MCP server not inspected** when held |
124| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
125| - | - | - |
126| Keep every file that isn't an image or font under 256 KiB | Held for a reviewer | **Files or downloads the validator couldn’t inspect** |
127| Keep the plugin to 512 files or fewer | Held for a reviewer | **Files or downloads the validator couldn’t inspect** |
128| Include only text files, SVG included, complete PNG, JPEG, GIF, and WebP images, and font files. Any other binary file, such as an `.ico`, `.pdf`, or `.zip` file or a compiled executable, is held. | Held for a reviewer | **Files or downloads the validator couldn’t inspect** |
129| To show a bundled image in the README, use Markdown image syntax. Don't refer to bundled images or fonts from commands, hooks, or scripts, or write their paths in backticks or a code block. | Held for a reviewer | |
130| Declare each MCP server with `command` and `args` or with `url`, not a `.mcpb` or `.dxt` bundle | Held for a reviewer. Blocks for a bundle fetched from a URL. | **Bundled MCP server not inspected** when held |
131131 
132132### Review what the plugin runs and connects to
133133 
134134A package launcher is a command that downloads a package and runs it: `npx`, `bunx`, `pnpm dlx`, `yarn dlx`, `uvx`, `pipx run`, and `uv run` all count. `${CLAUDE_PLUGIN_ROOT}` is the variable that Claude Code sets to the plugin's installation directory.
135135 
136| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
137| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- | --------------------------------------------------------------------- |
138| Pin every package that a launcher runs to an exact version, such as `npx <package>@1.2.3` or `uvx <package>==1.2.3`, not a range or `@latest`. Run `uv run` with `--locked` or `--frozen`. | Blocks | **Unpinned npx launcher**, **Unpinned uvx launcher** |
139| In a plugin that uses a launcher or runs a package install, don't include a package-manager configuration file that sets a registry, index, proxy, or other package source, such as `.npmrc`, `bunfig.toml`, or `uv.toml` | Blocks with a launcher. Held for a reviewer with a package install. | **Install may use a custom registry or package source** when held |
140| Keep real credentials out of every file, documentation and examples included. Ask for each value through a `userConfig` entry in `plugin.json` with `sensitive: true`, and refer to it as `${user_config.KEY}`. | Blocks | **Secret in MCP headers** for a credential in an MCP server's headers |
141| Don't read a credential that is already set in the user's environment, such as `$GITHUB_TOKEN`, and send it to a server, even in a README example. Ask for it through `userConfig` instead. | Held for a reviewer. Blocks for an HTTP hook that sends the credential. | **Uses a credential from the user’s machine** when held |
142| Make `.mcp.json` valid JSON in which every server entry matches the schema in the [MCP documentation](https://code.claude.com/docs/en/mcp) | Blocks | **.mcp.json can’t be parsed** for invalid JSON |
143| Give each remote MCP server a `type` of `http`, `sse`, or `ws` and a `url` that is an absolute `https://` or `wss://` URL, a `${user_config.KEY}` reference, or `""` when the plugin has no fixed endpoint | Blocks | **MCP server URL is not https** for a URL with another scheme |
144| Start each local MCP server by running a file in the plugin with plain arguments, such as `node ${CLAUDE_PLUGIN_ROOT}/server.js`, not through a shell, an inline program such as `-c`, or a package-manager script such as `npm run` | Held for a reviewer | **MCP server command wasn’t read** |
145| In the command of a hook or an MCP server, write each path in full from `${CLAUDE_PLUGIN_ROOT}`, with no other variable, command substitution, wildcard, or inline program such as `python3 -c` | Blocks when the plugin folder is a subfolder of the repository | |
146| Keep launchers and package installs out of each script that a hook or an MCP server runs. When the plugin folder is a subfolder of the repository, also keep shell variables other than `${CLAUDE_PLUGIN_ROOT}`, command substitutions, and calls to other files in the plugin out of those scripts. | Held for a reviewer | **Scripts the validator couldn’t follow** |
136| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
137| - | - | - |
138| Pin every package that a launcher runs to an exact version, such as `npx <package>@1.2.3` or `uvx <package>==1.2.3`, not a range or `@latest`. Run `uv run` with `--locked` or `--frozen`. | Blocks | **Unpinned npx launcher**, **Unpinned uvx launcher** |
139| In a plugin that uses a launcher or runs a package install, don't include a package-manager configuration file that sets a registry, index, proxy, or other package source, such as `.npmrc`, `bunfig.toml`, or `uv.toml` | Blocks with a launcher. Held for a reviewer with a package install. | **Install may use a custom registry or package source** when held |
140| Keep real credentials out of every file, documentation and examples included. Ask for each value through a `userConfig` entry in `plugin.json` with `sensitive: true`, and refer to it as `${user_config.KEY}`. | Blocks | **Secret in MCP headers** for a credential in an MCP server's headers |
141| Don't read a credential that is already set in the user's environment, such as `$GITHUB_TOKEN`, and send it to a server, even in a README example. Ask for it through `userConfig` instead. | Held for a reviewer. Blocks for an HTTP hook that sends the credential. | **Uses a credential from the user’s machine** when held |
142| Make `.mcp.json` valid JSON in which every server entry matches the schema in the [MCP documentation](https://code.claude.com/docs/en/mcp) | Blocks | **.mcp.json can’t be parsed** for invalid JSON |
143| Give each remote MCP server a `type` of `http`, `sse`, or `ws` and a `url` that is an absolute `https://` or `wss://` URL, a `${user_config.KEY}` reference, or `""` when the plugin has no fixed endpoint | Blocks | **MCP server URL is not https** for a URL with another scheme |
144| Start each local MCP server by running a file in the plugin with plain arguments, such as `node ${CLAUDE_PLUGIN_ROOT}/server.js`, not through a shell, an inline program such as `-c`, or a package-manager script such as `npm run` | Held for a reviewer | **MCP server command wasn’t read** |
145| In the command of a hook or an MCP server, write each path in full from `${CLAUDE_PLUGIN_ROOT}`, with no other variable, command substitution, wildcard, or inline program such as `python3 -c` | Blocks when the plugin folder is a subfolder of the repository | |
146| Keep launchers and package installs out of each script that a hook or an MCP server runs. When the plugin folder is a subfolder of the repository, also keep shell variables other than `${CLAUDE_PLUGIN_ROOT}`, command substitutions, and calls to other files in the plugin out of those scripts. | Held for a reviewer | **Scripts the validator couldn’t follow** |
147147 
148148### Choices a reviewer always checks
149149 
from line 159
159159 
160160The component checks confirm that Claude Code can load each hook, skill, command, and agent file in the plugin.
161161 
162| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
163| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
164| Make `hooks/hooks.json` valid JSON with a top-level `hooks` object, only the hook events and hook types in the [hooks reference](https://code.claude.com/docs/en/hooks), and an `https://` URL on each HTTP hook | Blocks | **hooks.json is invalid** for invalid JSON |
165| Leave `hooks/hooks.json` out of the `hooks` field in `plugin.json`, because Claude Code loads that file automatically | Warning | |
166| Write valid YAML front matter in each skill, command, and agent file, with `description` as a single text value, not a list | Blocks for front matter that doesn't parse or a `description` that isn't text. Warning for no front matter or no `description`. | |
167| Name component folders and files with the exact spelling and capitalization Claude Code expects, such as `hooks/`, `skills/`, and `SKILL.md` | Blocks | |
162| What to do | [Result if you don't](#read-a-validation-result) | Title in the report, if it has one |
163| - | - | - |
164| Make `hooks/hooks.json` valid JSON with a top-level `hooks` object, only the hook events and hook types in the [hooks reference](https://code.claude.com/docs/en/hooks), and an `https://` URL on each HTTP hook | Blocks | **hooks.json is invalid** for invalid JSON |
165| Leave `hooks/hooks.json` out of the `hooks` field in `plugin.json`, because Claude Code loads that file automatically | Warning | |
166| Write valid YAML front matter in each skill, command, and agent file, with `description` as a single text value, not a list | Blocks for front matter that doesn't parse or a `description` that isn't text. Warning for no front matter or no `description`. | |
167| Name component folders and files with the exact spelling and capitalization Claude Code expects, such as `hooks/`, `skills/`, and `SKILL.md` | Blocks | |
168168 
169169## Prepare for the security scan
170170 

skills/how-to Changed · +3 / -3 lines

from line 479
479479 
480480Both frontmatter fields are required:
481481 
482| Field | Type | Description |
483| :------------ | :----- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
484| `name` | string | Lowercase letters, numbers, and hyphens only, up to 64 characters. Must match the skill's directory name |
482| Field | Type | Description |
483| :- | :- | :- |
484| `name` | string | Lowercase letters, numbers, and hyphens only, up to 64 characters. Must match the skill's directory name |
485485| `description` | string | What the skill does and when to use it. Claude reads this to decide when to load the skill. Up to 1,024 characters, the limit in the [Agent Skills specification](https://agentskills.io/specification) |
486486 
487487### Write the instructions

skills/overview Changed · +6 / -6 lines

from line 56
5656 
5757## Compare skills with other features
5858 
59| Feature | Purpose |
60| -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |
61| **Skills** | Task-specific procedures that Claude loads when a request matches |
62| **[Plugins](/docs/plugins/overview)** | Packages that contain several skills together with connectors, commands, and agents, so that you add them as one unit |
63| **[Projects](https://support.claude.com/en/articles/9517075-what-are-projects)** | Background knowledge that's always loaded in that project's chats |
64| **[MCP connectors](/docs/connectors/getting-started)** | Connections that let Claude reach external services and data |
59| Feature | Purpose |
60| - | - |
61| **Skills** | Task-specific procedures that Claude loads when a request matches |
62| **[Plugins](/docs/plugins/overview)** | Packages that contain several skills together with connectors, commands, and agents, so that you add them as one unit |
63| **[Projects](https://support.claude.com/en/articles/9517075-what-are-projects)** | Background knowledge that's always loaded in that project's chats |
64| **[MCP connectors](/docs/connectors/getting-started)** | Connections that let Claude reach external services and data |
6565 
6666## Use skills beyond Claude
6767 

third-party/claude-desktop/admin-console Changed · +56 / -56 lines

from line 24
2424 
2525Anthropic stores your organization's user accounts and the configuration you save, and delivers that configuration to users' apps. If you turn on usage analytics, Anthropic also stores the token and session counts that users' apps report. As with MDM or bootstrap delivery, prompts and model responses go to your inference provider and conversations stay on the device.
2626 
27| Data | Does Anthropic store it? |
28| --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
29| Prompts, model responses, and tool inputs and outputs | **No.** They go to your inference provider, and tool calls go to the connectors you configure. Data handling at the provider depends on the provider, as described under [Data handling by provider](/docs/third-party/claude-desktop/overview#data-handling-by-provider). |
30| Conversation history, projects, memory, and uploaded files | **No.** They stay on the device. |
31| Provider credentials, API keys, bearer tokens, and MCP secrets | **No**, except the client secret of a Google Desktop-app OAuth client, which Google doesn't treat as confidential. You can enter one for [Google sign-in to your provider](#choose-how-users-authenticate-to-your-provider) or for a [managed MCP server that signs in with Google](/docs/third-party/claude-desktop/mcp-sign-in#where-the-client-secret-goes). Everything else stays on the device, and the console refuses to save it. |
32| Plugin and skill content | **No.** It stays in your own repositories or on devices. The console stores marketplace locations and installation settings, not content. |
33| OpenTelemetry export, if you configure a collector | **No.** It goes to your collector only. |
34| User accounts (name and work email), group membership, and administrator roles | **Yes.** |
35| Single sign-on and SCIM connection settings, if you use them | **Yes.** |
36| The configuration your administrators save, organization-wide and per group | **Yes.** Anthropic delivers it to users' apps. It contains no credentials other than a Google Desktop-app OAuth client secret, if you enter one. |
37| Essential telemetry (crash and error reports) and non-essential telemetry (product analytics) | **Yes**, unless you turn them off on the **Telemetry & updates** page. Neither contains prompt or response content. [Telemetry and egress](/docs/third-party/claude-desktop/telemetry) describes what each category contains. |
38| Usage analytics: session, token, and estimated-cost counts per user, conversation, and model | **Yes**, if you turn on the **Report desktop usage to this organization** switch on the **Telemetry & updates** page. The switch is off by default. Users' apps report new counts only while the switch is on, and turning the switch off doesn't delete counts that Anthropic has already received. The counts contain no prompt, response, or file content. [Usage analytics](#usage-analytics) lists exactly what each report contains. |
27| Data | Does Anthropic store it? |
28| - | - |
29| Prompts, model responses, and tool inputs and outputs | **No.** They go to your inference provider, and tool calls go to the connectors you configure. Data handling at the provider depends on the provider, as described under [Data handling by provider](/docs/third-party/claude-desktop/overview#data-handling-by-provider). |
30| Conversation history, projects, memory, and uploaded files | **No.** They stay on the device. |
31| Provider credentials, API keys, bearer tokens, and MCP secrets | **No**, except the client secret of a Google Desktop-app OAuth client, which Google doesn't treat as confidential. You can enter one for [Google sign-in to your provider](#choose-how-users-authenticate-to-your-provider) or for a [managed MCP server that signs in with Google](/docs/third-party/claude-desktop/mcp-sign-in#where-the-client-secret-goes). Everything else stays on the device, and the console refuses to save it. |
32| Plugin and skill content | **No.** It stays in your own repositories or on devices. The console stores marketplace locations and installation settings, not content. |
33| OpenTelemetry export, if you configure a collector | **No.** It goes to your collector only. |
34| User accounts (name and work email), group membership, and administrator roles | **Yes.** |
35| Single sign-on and SCIM connection settings, if you use them | **Yes.** |
36| The configuration your administrators save, organization-wide and per group | **Yes.** Anthropic delivers it to users' apps. It contains no credentials other than a Google Desktop-app OAuth client secret, if you enter one. |
37| Essential telemetry (crash and error reports) and non-essential telemetry (product analytics) | **Yes**, unless you turn them off on the **Telemetry & updates** page. Neither contains prompt or response content. [Telemetry and egress](/docs/third-party/claude-desktop/telemetry) describes what each category contains. |
38| Usage analytics: session, token, and estimated-cost counts per user, conversation, and model | **Yes**, if you turn on the **Report desktop usage to this organization** switch on the **Telemetry & updates** page. The switch is off by default. Users' apps report new counts only while the switch is on, and turning the switch off doesn't delete counts that Anthropic has already received. The counts contain no prompt, response, or file content. [Usage analytics](#usage-analytics) lists exactly what each report contains. |
3939 
4040The app contacts `api.anthropic.com` at every launch to check the user's sign-in and download the configuration. While the app runs, it contacts `api.anthropic.com` again every 10 minutes by default to check for configuration changes. The app contacts `claude.ai` when the user signs in. Both hosts are in addition to the hosts listed on [Telemetry and egress](/docs/third-party/claude-desktop/telemetry). While usage analytics is on, the app also sends its token and session counts to `api.anthropic.com` every few minutes during use and when it quits, so usage analytics needs no additional firewall entry.
4141 
from line 87
8787 
8888From the console you can set the same [configuration keys](/docs/third-party/claude-desktop/configuration) that MDM and bootstrap delivery support, apart from the items listed under [Limitations](#limitations). The **Desktop 3P** section of the left navigation has these pages:
8989 
90| Page | What you configure there |
91| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
92| **Connection** | The inference provider ([gateway](/docs/third-party/claude-desktop/gateway), [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock), [Bedrock Mantle](/docs/third-party/claude-desktop/mantle), [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex), or [Microsoft Foundry](/docs/third-party/claude-desktop/foundry)), its endpoint, region, or project, how users authenticate to it, custom request headers, and, under **Models**, the model list, default model, model discovery, and cost-estimate rates. **Desktop sign-in** on this page holds the **Require this organization in Claude Desktop** switch described under [Users in more than one Claude organization](#users-in-more-than-one-claude-organization). |
93| **Capabilities** | Whether Chat, Cowork, and Code are each available, the folders and network hosts the app may use, permission modes and built-in tool policy, the [built-in browser](/docs/third-party/claude-desktop/browser#manage-the-built-in-browser-from-the-enterprise-admin-console) and its site permissions, whether users may add their own skills and plugins, and organization instructions |
94| **Connectors** | Managed MCP servers, including the [built-in connectors](/docs/third-party/claude-desktop/built-in-connectors), whether users may add their own MCP servers, desktop extension policy, and [**Claude.ai data import**](/docs/third-party/claude-desktop/import) |
95| **Telemetry & updates** | Which telemetry categories go to Anthropic, whether users' apps report [usage analytics](#usage-analytics) to your organization, OpenTelemetry export to your collector, update policy, the [configuration relaunch window](#configuration-updates), the configuration re-check interval, and [how much of the configuration devices keep on disk](#configuration-kept-on-devices) |
96| **Limits** | A per-user token limit and its window |
97| **Appearance** | Banner text and colors, end-user attribution, and whether the app shows feature announcements and configuration deprecation warnings |
98| **Plugins** | The [plugin marketplaces](#plugin-marketplaces) that users' apps fetch, and how each one installs |
90| Page | What you configure there |
91| - | - |
92| **Connection** | The inference provider ([gateway](/docs/third-party/claude-desktop/gateway), [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock), [Bedrock Mantle](/docs/third-party/claude-desktop/mantle), [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex), or [Microsoft Foundry](/docs/third-party/claude-desktop/foundry)), its endpoint, region, or project, how users authenticate to it, custom request headers, and, under **Models**, the model list, default model, model discovery, and cost-estimate rates. **Desktop sign-in** on this page holds the **Require this organization in Claude Desktop** switch described under [Users in more than one Claude organization](#users-in-more-than-one-claude-organization). |
93| **Capabilities** | Whether Chat, Cowork, and Code are each available, the folders and network hosts the app may use, permission modes and built-in tool policy, the [built-in browser](/docs/third-party/claude-desktop/browser#manage-the-built-in-browser-from-the-enterprise-admin-console) and its site permissions, whether users may add their own skills and plugins, and organization instructions |
94| **Connectors** | Managed MCP servers, including the [built-in connectors](/docs/third-party/claude-desktop/built-in-connectors), whether users may add their own MCP servers, desktop extension policy, and [**Claude.ai data import**](/docs/third-party/claude-desktop/import) |
95| **Telemetry & updates** | Which telemetry categories go to Anthropic, whether users' apps report [usage analytics](#usage-analytics) to your organization, OpenTelemetry export to your collector, update policy, the [configuration relaunch window](#configuration-updates), the configuration re-check interval, and [how much of the configuration devices keep on disk](#configuration-kept-on-devices) |
96| **Limits** | A per-user token limit and its window |
97| **Appearance** | Banner text and colors, end-user attribution, and whether the app shows feature announcements and configuration deprecation warnings |
98| **Plugins** | The [plugin marketplaces](#plugin-marketplaces) that users' apps fetch, and how each one installs |
9999 
100100The console refuses API keys, tokens, and secrets anywhere in the configuration, including in request headers and MCP server settings. The one exception is the client secret of a Google Desktop-app OAuth client, for [Google sign-in to your inference provider](#choose-how-users-authenticate-to-your-provider) or a [managed MCP server that signs in with Google](/docs/third-party/claude-desktop/mcp-sign-in#where-the-client-secret-goes), which Google doesn't treat as confidential. Users authenticate to your provider on the device, as described under [Choose how users authenticate to your provider](#choose-how-users-authenticate-to-your-provider).
101101 
from line 109
109109 
110110The console never holds a provider credential. The **Credential kind** field on the **Connection** page tells Claude Desktop how each user's device obtains one, and offers the kinds your provider supports: **Interactive sign-in** in the app, **Workforce Identity** (Google Cloud's Agent Platform only), **Cloud vendor profile** (an AWS profile or Google Cloud credentials file already on the device), or **Helper script** (a [credential helper](/docs/third-party/claude-desktop/credential-helper) on the device). Static API keys and bearer tokens aren't offered, because the console refuses to store them. The same **Connection** settings go to every user, so a credential kind that depends on something present on each device works only if your device management puts it there.
111111 
112| Provider | Recommended credential kind | Credential fields on the **Connection** page | What users do at first launch |
113| ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
114| [LLM gateway](/docs/third-party/claude-desktop/gateway#single-sign-on-with-your-identity-provider) | **Interactive sign-in** with your identity provider | **Gateway SSO IdP (OIDC)** with your identity provider's issuer URL and the client ID of the application you registered for Claude Desktop | The app shows a **Sign in to your organization** button that opens your identity provider's sign-in page in the browser. After sign-in, the app sends that user's token to your gateway on every request, and your gateway validates it. |
115| [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock#in-app-aws-sign-in) | **Interactive sign-in** through IAM Identity Center | **AWS SSO start URL**, **AWS SSO region**, **AWS SSO account ID**, and **AWS SSO role name** | The app shows a **Sign in with AWS** page and the user approves in the browser. No AWS CLI is needed. |
116| [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex#in-app-google-sign-in), users with Google accounts | **Interactive sign-in** with Google | **Vertex OAuth client ID** and **Vertex OAuth client secret** from a Desktop-app OAuth client in your own Google Cloud project. Google doesn't treat a Desktop-app client secret as confidential, so the console accepts it. | The app shows a **Sign in with Google** page and the user approves Google's consent screen in the browser |
117| [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex#in-app-workforce-identity-sign-in), users who sign in with another identity provider | **Workforce Identity** | **Workforce Identity audience** and **Workforce Identity IdP (OIDC)** with your identity provider's issuer URL and client ID | The app shows a **Sign in** page and the user signs in to your identity provider in the browser. No Google identity is needed. |
118| [Microsoft Foundry](/docs/third-party/claude-desktop/foundry#in-app-entra-id-sign-in) | **Interactive sign-in** with Microsoft Entra ID | **Entra ID tenant ID** and **Entra ID client ID**, and optionally **Entra ID sign-in flow** | The app shows a **Sign in with Microsoft** page and the user signs in with a device code, in the browser, or through the operating system's account picker |
119| [Bedrock Mantle](/docs/third-party/claude-desktop/mantle) | **Helper script**, because Mantle has no interactive sign-in | **Helper script** with the absolute path of a script that prints the bearer token | The app shows no sign-in page and runs the script whenever it needs a token |
112| Provider | Recommended credential kind | Credential fields on the **Connection** page | What users do at first launch |
113| - | - | - | - |
114| [LLM gateway](/docs/third-party/claude-desktop/gateway#single-sign-on-with-your-identity-provider) | **Interactive sign-in** with your identity provider | **Gateway SSO IdP (OIDC)** with your identity provider's issuer URL and the client ID of the application you registered for Claude Desktop | The app shows a **Sign in to your organization** button that opens your identity provider's sign-in page in the browser. After sign-in, the app sends that user's token to your gateway on every request, and your gateway validates it. |
115| [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock#in-app-aws-sign-in) | **Interactive sign-in** through IAM Identity Center | **AWS SSO start URL**, **AWS SSO region**, **AWS SSO account ID**, and **AWS SSO role name** | The app shows a **Sign in with AWS** page and the user approves in the browser. No AWS CLI is needed. |
116| [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex#in-app-google-sign-in), users with Google accounts | **Interactive sign-in** with Google | **Vertex OAuth client ID** and **Vertex OAuth client secret** from a Desktop-app OAuth client in your own Google Cloud project. Google doesn't treat a Desktop-app client secret as confidential, so the console accepts it. | The app shows a **Sign in with Google** page and the user approves Google's consent screen in the browser |
117| [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex#in-app-workforce-identity-sign-in), users who sign in with another identity provider | **Workforce Identity** | **Workforce Identity audience** and **Workforce Identity IdP (OIDC)** with your identity provider's issuer URL and client ID | The app shows a **Sign in** page and the user signs in to your identity provider in the browser. No Google identity is needed. |
118| [Microsoft Foundry](/docs/third-party/claude-desktop/foundry#in-app-entra-id-sign-in) | **Interactive sign-in** with Microsoft Entra ID | **Entra ID tenant ID** and **Entra ID client ID**, and optionally **Entra ID sign-in flow** | The app shows a **Sign in with Microsoft** page and the user signs in with a device code, in the browser, or through the operating system's account picker |
119| [Bedrock Mantle](/docs/third-party/claude-desktop/mantle) | **Helper script**, because Mantle has no interactive sign-in | **Helper script** with the absolute path of a script that prints the bearer token | The app shows no sign-in page and runs the script whenever it needs a token |
120120 
121121Tokens from these sign-ins are stored only on the user's device. The linked provider pages cover setup at the provider, network egress, and session lifetime for each option.
122122 
from line 186
186186 
187187Each report contains only the following:
188188 
189| Data | Example |
190| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------- |
191| A session count: one for each Chat, Cowork, or Code conversation | `1` |
192| Token counts for each conversation and model: input, output, cache read, and cache write | `1300` input tokens |
193| An estimated cost in US dollars for each conversation and model. The app calculates the estimate on the device, at Anthropic list prices or at the rates you set under **Models** on the **Connection** page, and labels which it used (`list` or `managed`). A model ID that the app can't match to a Claude model (such as a gateway alias) has no estimate unless you [set a rate](/docs/third-party/claude-desktop/configuration#inferencemodelpricing) for that exact ID | `0.0133`, `list` |
194| The tab the activity happened in | `cowork` |
195| The model identifier, exactly as your provider or configuration identifies the model. For Amazon Bedrock, the identifier can be an inference profile ARN, which includes your AWS region and account ID. Claude Desktop 1.52386.0 and later mask the account ID before sending. For Google Cloud, the identifier can be a resource path that includes your project ID | `claude-sonnet-4-5` |
196| The date and time of the counted activity | `2026-08-27T21:00:01Z` |
197| A random identifier for the conversation | `local_c34fa9b2-…` |
198| A random identifier for the app installation. Crash reports and product analytics carry the same identifier | `49819623-…` |
199| The app version, the operating system type and version, the processor architecture, and a fixed product label | `1.49585.0`, `darwin`, `24.6.0`, `arm64`, `claude-desktop` |
189| Data | Example |
190| - | - |
191| A session count: one for each Chat, Cowork, or Code conversation | `1` |
192| Token counts for each conversation and model: input, output, cache read, and cache write | `1300` input tokens |
193| An estimated cost in US dollars for each conversation and model. The app calculates the estimate on the device, at Anthropic list prices or at the rates you set under **Models** on the **Connection** page, and labels which it used (`list` or `managed`). A model ID that the app can't match to a Claude model (such as a gateway alias) has no estimate unless you [set a rate](/docs/third-party/claude-desktop/configuration#inferencemodelpricing) for that exact ID | `0.0133`, `list` |
194| The tab the activity happened in | `cowork` |
195| The model identifier, exactly as your provider or configuration identifies the model. For Amazon Bedrock, the identifier can be an inference profile ARN, which includes your AWS region and account ID. Claude Desktop 1.52386.0 and later mask the account ID before sending. For Google Cloud, the identifier can be a resource path that includes your project ID | `claude-sonnet-4-5` |
196| The date and time of the counted activity | `2026-08-27T21:00:01Z` |
197| A random identifier for the conversation | `local_c34fa9b2-…` |
198| A random identifier for the app installation. Crash reports and product analytics carry the same identifier | `49819623-…` |
199| The app version, the operating system type and version, the processor architecture, and a fixed product label | `1.49585.0`, `darwin`, `24.6.0`, `arm64`, `claude-desktop` |
200200 
201201The reports never contain prompts, responses, file names or contents, tool names, tool inputs or outputs, folder or project names, connector names, or host names.
202202 
from line 281
281281 
282282The response has these fields:
283283 
284| Field | Contents |
285| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
286| `config` | The organization-wide configuration as nested JSON, in the v2 format described under [Response schema](/docs/third-party/claude-desktop/bootstrap#response-schema) for bootstrap servers. Stored header values appear as a placeholder, as described under [Replace the configuration](#replace-the-configuration). |
287| `status` | `active` or `disabled`. A `disabled` configuration isn't served to users' apps, as the warning under [Replace the configuration](#replace-the-configuration) describes. |
288| `group_settings` | An object whose `entries` list holds the [per-group permission policies](#per-group-permission-policies) in rank order, highest first, each with a `group_id` and its `config`. A `group_id` that matches no group is accepted and applies to nobody until a group with that ID exists. |
289| `version` | An integer that increases with every change. |
290| `checksum` | A digest of `config` and `group_settings` as returned. It leaves out `status`, so compare `version` to detect changes. |
291| `updated_at` | The time of the last change. |
284| Field | Contents |
285| - | - |
286| `config` | The organization-wide configuration as nested JSON, in the v2 format described under [Response schema](/docs/third-party/claude-desktop/bootstrap#response-schema) for bootstrap servers. Stored header values appear as a placeholder, as described under [Replace the configuration](#replace-the-configuration). |
287| `status` | `active` or `disabled`. A `disabled` configuration isn't served to users' apps, as the warning under [Replace the configuration](#replace-the-configuration) describes. |
288| `group_settings` | An object whose `entries` list holds the [per-group permission policies](#per-group-permission-policies) in rank order, highest first, each with a `group_id` and its `config`. A `group_id` that matches no group is accepted and applies to nobody until a group with that ID exists. |
289| `version` | An integer that increases with every change. |
290| `checksum` | A digest of `config` and `group_settings` as returned. It leaves out `status`, so compare `version` to detect changes. |
291| `updated_at` | The time of the last change. |
292292 
293293### Replace the configuration
294294 
from line 319
319319 
320320### Admin API errors
321321 
322| Status | Meaning |
323| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
324| `400` | The server refused the document. The message names the field and the rule, for example `config.inference.baseUrl: must not embed credentials in the URL`. Nothing is stored. |
325| `401` | The key in `x-api-key` is unknown, deleted, disabled, or expired. |
326| `403` | The key lacks the scope the request needs, or isn't an organization-level key. For a missing scope, the message lists the scopes the key has and the one required. |
327| `404` | The key was created in an organization other than your Claude Desktop deployment's, the `x-api-key` header is missing or its key is malformed, or (on a read) no configuration has been saved yet. |
328| `409` | `expected_version` is not the current version. Read the configuration again and reapply your change. |
329| `429` | Admin API requests share a per-organization limit of 100 requests per minute, as described under [Rate limits](https://platform.claude.com/docs/en/manage-claude/user-management#rate-limits). Retry after the number of seconds in the `retry-after` header. |
322| Status | Meaning |
323| - | - |
324| `400` | The server refused the document. The message names the field and the rule, for example `config.inference.baseUrl: must not embed credentials in the URL`. Nothing is stored. |
325| `401` | The key in `x-api-key` is unknown, deleted, disabled, or expired. |
326| `403` | The key lacks the scope the request needs, or isn't an organization-level key. For a missing scope, the message lists the scopes the key has and the one required. |
327| `404` | The key was created in an organization other than your Claude Desktop deployment's, the `x-api-key` header is missing or its key is malformed, or (on a read) no configuration has been saved yet. |
328| `409` | `expected_version` is not the current version. Read the configuration again and reapply your change. |
329| `429` | Admin API requests share a per-organization limit of 100 requests per minute, as described under [Rate limits](https://platform.claude.com/docs/en/manage-claude/user-management#rate-limits). Retry after the number of seconds in the `retry-after` header. |
330330 
331331## Limitations
332332 

third-party/claude-desktop/bedrock Changed · +39 / -39 lines

from line 8
88 
99Amazon Bedrock supports several ways to authenticate, and the right one depends on whether your end users already work with AWS and whether you need per-user identity in CloudTrail. Use the table below to pick a path before doing any AWS or device setup.
1010 
11| Scenario | Use | Per-device prerequisite | Per-user CloudTrail identity | Notes |
12| ----------------------------------------------------------- | -------------------------------------------------------------------------------------- | --------------------------------------- | ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
13| Proof of concept, single team | [Bearer token](#bearer-token) (`inferenceBedrockBearerToken`) | None | No (shared key) | A long-lived secret distributed in the managed profile. Simplest to start; not recommended for broad rollout. |
14| Broad rollout to users without AWS tooling | [In-app AWS sign-in](#in-app-aws-sign-in) (`inferenceBedrockSso*`) | None | Yes | Users sign in through IAM Identity Center inside the app. No AWS CLI required. Requires app version 1.6259.0 or later. |
15| Developers who already use the AWS CLI | [Named profile](#named-profile) (`inferenceBedrockProfile`) | AWS CLI v2 and a pushed `~/.aws/config` | Yes | IT can distribute the AWS config file directly; the app runs `aws sso login` for the user when the session expires. |
16| You run an authenticating proxy in front of Amazon Bedrock | [Identity provider sign-in](#sign-in-with-your-identity-provider) (`inferenceIdpOidc`) | None | At your proxy | Users sign in with your identity provider; the proxy calls Amazon Bedrock with its own AWS credentials. Requires app version 2.7032.0 or later. |
17| You already operate an LLM gateway (Anthropic Messages API) | [Gateway provider](/docs/third-party/claude-desktop/gateway) instead of Amazon Bedrock | None | At your gateway | The gateway holds the AWS credentials; the app authenticates only to the gateway. |
11| Scenario | Use | Per-device prerequisite | Per-user CloudTrail identity | Notes |
12| - | - | - | - | - |
13| Proof of concept, single team | [Bearer token](#bearer-token) (`inferenceBedrockBearerToken`) | None | No (shared key) | A long-lived secret distributed in the managed profile. Simplest to start; not recommended for broad rollout. |
14| Broad rollout to users without AWS tooling | [In-app AWS sign-in](#in-app-aws-sign-in) (`inferenceBedrockSso*`) | None | Yes | Users sign in through IAM Identity Center inside the app. No AWS CLI required. Requires app version 1.6259.0 or later. |
15| Developers who already use the AWS CLI | [Named profile](#named-profile) (`inferenceBedrockProfile`) | AWS CLI v2 and a pushed `~/.aws/config` | Yes | IT can distribute the AWS config file directly; the app runs `aws sso login` for the user when the session expires. |
16| You run an authenticating proxy in front of Amazon Bedrock | [Identity provider sign-in](#sign-in-with-your-identity-provider) (`inferenceIdpOidc`) | None | At your proxy | Users sign in with your identity provider; the proxy calls Amazon Bedrock with its own AWS credentials. Requires app version 2.7032.0 or later. |
17| You already operate an LLM gateway (Anthropic Messages API) | [Gateway provider](/docs/third-party/claude-desktop/gateway) instead of Amazon Bedrock | None | At your gateway | The gateway holds the AWS credentials; the app authenticates only to the gateway. |
1818 
1919If a static credential in the managed profile is acceptable but an Amazon Bedrock API key is not, you can also set [`inferenceCredentialHelper`](/docs/third-party/claude-desktop/configuration#inferencecredentialhelper) to an executable that prints an Amazon Bedrock bearer token to stdout at runtime.
2020 
from line 166
166166 
167167With AWS set up and devices prepared, open the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration#open-the-configuration-window) (**Developer → Configure Third-Party Inference…**) on an evaluation device. In the **Connection** section, set **Inference provider** to **Bedrock** and fill in the **Bedrock credentials** card with the values for whichever authentication approach you chose:
168168 
169| Field | Bearer token | In-app AWS sign-in | Named profile |
170| -------------------- | --------------------------- | ---------------------------------------- | ---------------------- |
171| AWS region | e.g. `us-west-2` | e.g. `us-west-2` | e.g. `us-west-2` |
172| AWS bearer token | your Amazon Bedrock API key | *leave empty* | *leave empty* |
173| Bedrock base URL | *optional* | *optional* | *optional* |
174| AWS profile name | *leave empty* | *leave empty* | `claude-cowork` |
175| AWS config directory | *leave empty* | *leave empty* | *only if not `~/.aws`* |
176| AWS CLI path | *leave empty* | *leave empty* | *optional* |
177| AWS SSO start URL | *leave empty* | `https://d-xxxxxxxxxx.awsapps.com/start` | *leave empty* |
178| AWS SSO region | *leave empty* | e.g. `us-east-1` | *leave empty* |
179| AWS SSO account ID | *leave empty* | `123456789012` | *leave empty* |
180| AWS SSO role name | *leave empty* | `BedrockInference` | *leave empty* |
181| Bedrock service tier | *optional* | *optional* | *optional* |
169| Field | Bearer token | In-app AWS sign-in | Named profile |
170| - | - | - | - |
171| AWS region | e.g. `us-west-2` | e.g. `us-west-2` | e.g. `us-west-2` |
172| AWS bearer token | your Amazon Bedrock API key | *leave empty* | *leave empty* |
173| Bedrock base URL | *optional* | *optional* | *optional* |
174| AWS profile name | *leave empty* | *leave empty* | `claude-cowork` |
175| AWS config directory | *leave empty* | *leave empty* | *only if not `~/.aws`* |
176| AWS CLI path | *leave empty* | *leave empty* | *optional* |
177| AWS SSO start URL | *leave empty* | `https://d-xxxxxxxxxx.awsapps.com/start` | *leave empty* |
178| AWS SSO region | *leave empty* | e.g. `us-east-1` | *leave empty* |
179| AWS SSO account ID | *leave empty* | `123456789012` | *leave empty* |
180| AWS SSO role name | *leave empty* | `BedrockInference` | *leave empty* |
181| Bedrock service tier | *optional* | *optional* | *optional* |
182182 
183183Under **Models**, add a **Model list** entry using the Amazon Bedrock inference-profile ID (optional for bearer-token or credential-helper auth, which auto-discover models; required otherwise), for example `us.anthropic.claude-sonnet-5`.
184184 
from line 188
188188 
189189The full set of `inferenceBedrock*` keys is below. Set `inferenceProvider` to `bedrock`, supply a region, and provide exactly one credential source.
190190 
191| Setting | Type | Availability | Default | Description |
192| ------------------------------------------------------------------------------------------------ | -------- | --------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------- |
193| <span id="inferencebedrockregion" />AWS region<br />`inferenceBedrockRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS region for the Bedrock runtime endpoint. |
194| <span id="inferencebedrockbaseurl" />Bedrock base URL<br />`inferenceBedrockBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | For VPC endpoints or gateway proxies. Host origin only. |
195| <span id="inferencebedrockservicetier" />Bedrock service tier<br />`inferenceBedrockServiceTier` | `enum` | MDM + Bootstrap<br />Added in 1.5186.0 | — | Sent as the X-Amzn-Bedrock-Service-Tier header. Leave unset for on-demand. One of: `flex`, `priority`. |
196| <span id="inferencebedrockbearertoken" />AWS bearer token<br />`inferenceBedrockBearerToken` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static bearer token for inference. For providers that support profile or helper-script credentials, prefer those. |
197| <span id="inferencebedrockssostarturl" />AWS SSO start URL<br />`inferenceBedrockSsoStartUrl` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | Enables in-app AWS sign-in (no AWS CLI needed). Set with the three SSO fields below. |
198| <span id="inferencebedrockssoregion" />AWS SSO region<br />`inferenceBedrockSsoRegion` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center home region. |
199| <span id="inferencebedrockssoaccountid" />AWS SSO account ID<br />`inferenceBedrockSsoAccountId` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | 12-digit AWS account ID assigned to users in IAM Identity Center. |
200| <span id="inferencebedrockssorolename" />AWS SSO role name<br />`inferenceBedrockSsoRoleName` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center permission-set name granting bedrock:InvokeModel\* on the account above. |
201| <span id="inferencebedrockprofile" />AWS profile name<br />`inferenceBedrockProfile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS named profile to use for Bedrock inference credentials. |
202| <span id="inferencebedrockawsdir" />AWS config directory<br />`inferenceBedrockAwsDir` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folder with AWS config/credentials. Defaults to \~/.aws when no bearer token is set. |
203| <span id="inferencebedrockawsclipath" />AWS CLI path<br />`inferenceBedrockAwsCliPath` | `string` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Absolute path to the aws executable. Leave unset to find it on PATH. |
191| Setting | Type | Availability | Default | Description |
192| - | - | - | - | - |
193| <span id="inferencebedrockregion" />AWS region<br />`inferenceBedrockRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS region for the Bedrock runtime endpoint. |
194| <span id="inferencebedrockbaseurl" />Bedrock base URL<br />`inferenceBedrockBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | For VPC endpoints or gateway proxies. Host origin only. |
195| <span id="inferencebedrockservicetier" />Bedrock service tier<br />`inferenceBedrockServiceTier` | `enum` | MDM + Bootstrap<br />Added in 1.5186.0 | — | Sent as the X-Amzn-Bedrock-Service-Tier header. Leave unset for on-demand. One of: `flex`, `priority`. |
196| <span id="inferencebedrockbearertoken" />AWS bearer token<br />`inferenceBedrockBearerToken` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static bearer token for inference. For providers that support profile or helper-script credentials, prefer those. |
197| <span id="inferencebedrockssostarturl" />AWS SSO start URL<br />`inferenceBedrockSsoStartUrl` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | Enables in-app AWS sign-in (no AWS CLI needed). Set with the three SSO fields below. |
198| <span id="inferencebedrockssoregion" />AWS SSO region<br />`inferenceBedrockSsoRegion` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center home region. |
199| <span id="inferencebedrockssoaccountid" />AWS SSO account ID<br />`inferenceBedrockSsoAccountId` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | 12-digit AWS account ID assigned to users in IAM Identity Center. |
200| <span id="inferencebedrockssorolename" />AWS SSO role name<br />`inferenceBedrockSsoRoleName` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center permission-set name granting bedrock:InvokeModel\* on the account above. |
201| <span id="inferencebedrockprofile" />AWS profile name<br />`inferenceBedrockProfile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS named profile to use for Bedrock inference credentials. |
202| <span id="inferencebedrockawsdir" />AWS config directory<br />`inferenceBedrockAwsDir` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folder with AWS config/credentials. Defaults to \~/.aws when no bearer token is set. |
203| <span id="inferencebedrockawsclipath" />AWS CLI path<br />`inferenceBedrockAwsCliPath` | `string` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Absolute path to the aws executable. Leave unset to find it on PATH. |
204204 
205205<AccordionGroup>
206206 <Accordion title="inferenceBedrockServiceTier details">
from line 214
214214 
215215The first-launch and re-authentication behavior depends on the authentication approach.
216216 
217| Approach | First launch | Re-authentication |
218| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
219| Bearer token | The app opens directly; no user action. | Never, until you rotate the key in the managed profile. |
220| In-app AWS sign-in | The app shows a **Sign in with AWS** page; the user approves in the browser, and the app returns to Cowork. | When the IAM Identity Center access portal session expires (defaults to 8 hours; configurable up to 90 days). The app prompts in-app; no terminal needed. |
221| Named profile | The app opens directly if the AWS SSO cache is fresh; otherwise it prompts in-app and runs `aws sso login` for you, which opens the browser. | When the IAM Identity Center session expires, the app prompts in-app and re-runs `aws sso login`. |
222| Identity provider sign-in | The app shows a sign-in page; the user signs in at your identity provider. | When the token expires, the app renews it silently; it prompts again only if the renewal fails or [`inferenceSessionLifetimeSec`](/docs/third-party/claude-desktop/configuration#inferencesessionlifetimesec) elapses. |
217| Approach | First launch | Re-authentication |
218| - | - | - |
219| Bearer token | The app opens directly; no user action. | Never, until you rotate the key in the managed profile. |
220| In-app AWS sign-in | The app shows a **Sign in with AWS** page; the user approves in the browser, and the app returns to Cowork. | When the IAM Identity Center access portal session expires (defaults to 8 hours; configurable up to 90 days). The app prompts in-app; no terminal needed. |
221| Named profile | The app opens directly if the AWS SSO cache is fresh; otherwise it prompts in-app and runs `aws sso login` for you, which opens the browser. | When the IAM Identity Center session expires, the app prompts in-app and re-runs `aws sso login`. |
222| Identity provider sign-in | The app shows a sign-in page; the user signs in at your identity provider. | When the token expires, the app renews it silently; it prompts again only if the renewal fails or [`inferenceSessionLifetimeSec`](/docs/third-party/claude-desktop/configuration#inferencesessionlifetimesec) elapses. |
223223 
224224For in-app AWS sign-in, the browser flow runs on the host (outside the Cowork sandbox), so it uses the user's existing identity-provider session and any security keys or passkeys configured on the device. The **AWS access portal session duration** setting (IAM Identity Center → **Settings** → **Authentication**) controls how long users stay signed in across app restarts. To force a user to sign in again sooner, delete their active session from the IAM Identity Center console.
225225 

third-party/claude-desktop/bootstrap Changed · +66 / -66 lines

from line 63
6363 
6464**Authorize.** Verifying the token proves *who* the caller is, not that they're entitled to a configuration. Check the caller's identity claim against your directory before returning a response:
6565 
66| Identity provider | Stable per-user claim | Group/role claim |
67| ------------------ | --------------------------- | ---------------------------------- |
68| Microsoft Entra ID | `oid` (directory object ID) | `roles` (app roles) or `groups` |
69| Okta | `uid` or `sub` | `groups` (via a custom claim rule) |
70| Generic OIDC | `sub` | provider-specific |
66| Identity provider | Stable per-user claim | Group/role claim |
67| - | - | - |
68| Microsoft Entra ID | `oid` (directory object ID) | `roles` (app roles) or `groups` |
69| Okta | `uid` or `sub` | `groups` (via a custom claim rule) |
70| Generic OIDC | `sub` | provider-specific |
7171 
7272Return `403` when the token is valid but the caller is not entitled. Do not authorize on `email` or `preferred_username` alone; those claims are mutable and may be absent for guest or external-identity users.
7373 
from line 135
135135 
136136The bootstrap request is always authenticated: either each user signs in and the app sends their bearer token, or the device sends request headers you configure. The mode is chosen by which keys you set alongside `bootstrapUrl`:
137137 
138| Mode | When to use it | MDM keys |
139| ---------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------ |
140| **Separate identity provider (PKCE)** | Users sign in through your existing OIDC provider (Microsoft Entra ID, Okta, Ping, or any compliant provider). The app runs an OAuth authorization-code grant with PKCE in the system browser. | `bootstrapUrl` and `bootstrapOidc` |
141| **Bootstrap server as authorization server (device code)** | Your bootstrap server (or the gateway it fronts) implements RFC 8414 discovery and the RFC 8628 device-code grant. One sign-in covers both the configuration fetch and inference when they share an origin. | `bootstrapUrl` only |
142| **Request headers (no per-user sign-in)** | The endpoint authenticates the device or a service account rather than the user: a static `Authorization: Basic …` or API-key header, or a short-lived token a script on the device fetches from your secrets manager. No browser step; the response cannot vary by signed-in user unless your headers identify one. | `bootstrapUrl` and `bootstrapHeaders` and/or `bootstrapHeadersHelper` (1.32885.1 or later) |
138| Mode | When to use it | MDM keys |
139| - | - | - |
140| **Separate identity provider (PKCE)** | Users sign in through your existing OIDC provider (Microsoft Entra ID, Okta, Ping, or any compliant provider). The app runs an OAuth authorization-code grant with PKCE in the system browser. | `bootstrapUrl` and `bootstrapOidc` |
141| **Bootstrap server as authorization server (device code)** | Your bootstrap server (or the gateway it fronts) implements RFC 8414 discovery and the RFC 8628 device-code grant. One sign-in covers both the configuration fetch and inference when they share an origin. | `bootstrapUrl` only |
142| **Request headers (no per-user sign-in)** | The endpoint authenticates the device or a service account rather than the user: a static `Authorization: Basic …` or API-key header, or a short-lived token a script on the device fetches from your secrets manager. No browser step; the response cannot vary by signed-in user unless your headers identify one. | `bootstrapUrl` and `bootstrapHeaders` and/or `bootstrapHeadersHelper` (1.32885.1 or later) |
143143 
144144### Separate identity provider (PKCE)
145145 
from line 153
153153 <Step title="Choose the scope your server will validate">
154154 The app sends the OAuth **access token** as the bearer. Your server validates that token's `aud`, so the scope you request must produce a token whose audience your server accepts. This is provider-specific:
155155 
156 | Provider | Scope to request | Resulting `aud` |
157 | ---------------------------------- | ------------------------------------------------------ | ------------------------------------ |
158 | Microsoft Entra ID | `openid offline_access CLIENT_ID/.default` | your client ID |
159 | Okta (custom authorization server) | `openid offline_access YOUR_API_SCOPE` | your authorization server's audience |
160 | Generic OIDC | `openid offline_access` plus your API's resource scope | provider-specific |
156 | Provider | Scope to request | Resulting `aud` |
157 | - | - | - |
158 | Microsoft Entra ID | `openid offline_access CLIENT_ID/.default` | your client ID |
159 | Okta (custom authorization server) | `openid offline_access YOUR_API_SCOPE` | your authorization server's audience |
160 | Generic OIDC | `openid offline_access` plus your API's resource scope | provider-specific |
161161 
162162 Include `offline_access` so the app receives a refresh token and can renew silently between launches.
163163 
from line 169
169169 <Step title="Validate the token in your server">
170170 See [Server responsibilities](#server-responsibilities). What the token's `iss` and `aud` look like depends on your provider:
171171 
172 | Provider | `iss` to expect | `aud` to expect | JWKS URL |
173 | -------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | -------------------------------------------------------------- |
174 | Microsoft Entra ID (token version `2`) | `https://login.microsoftonline.com/TENANT/v2.0` | your client ID | `https://login.microsoftonline.com/TENANT/discovery/v2.0/keys` |
175 | Okta (custom authorization server) | `https://YOUR_DOMAIN.okta.com/oauth2/AUTH_SERVER_ID` | the audience configured on that authorization server | `<issuer>/v1/keys` |
172 | Provider | `iss` to expect | `aud` to expect | JWKS URL |
173 | - | - | - | - |
174 | Microsoft Entra ID (token version `2`) | `https://login.microsoftonline.com/TENANT/v2.0` | your client ID | `https://login.microsoftonline.com/TENANT/discovery/v2.0/keys` |
175 | Okta (custom authorization server) | `https://YOUR_DOMAIN.okta.com/oauth2/AUTH_SERVER_ID` | the audience configured on that authorization server | `<issuer>/v1/keys` |
176176 
177177 **Entra token version.** A new Entra app registration emits v1-format access tokens by default, with `iss` = `https://sts.windows.net/TENANT/` and `aud` = `api://CLIENT_ID`. Set the accepted-token-version field in the registration's **Manifest** to `2` so tokens match the table above. The portal shows this field as either `accessTokenAcceptedVersion` or `api.requestedAccessTokenVersion` depending on the manifest view; set whichever you see. If you cannot change it, your server must accept both the v1 and v2 forms.
178178 
from line 182
182182 <Step title="Configure and export from Claude Desktop">
183183 Install Claude Desktop on an admin workstation (see [Installation](/docs/third-party/claude-desktop/installation)). From the menu bar, open **Developer → Configure Third-Party Inference…**. In the **Source** section, fill in the **Bootstrap config URL** card:
184184 
185 | Field | Value |
186 | ----------------------------------------- | ------------------------------------------------------- |
187 | Bootstrap config URL | `https://YOUR_BOOTSTRAP_HOST/user/bootstrap` |
188 | Bootstrap OIDC parameters → Client ID | `YOUR_CLIENT_ID` |
189 | Bootstrap OIDC parameters → Issuer URL | `https://login.microsoftonline.com/YOUR_TENANT_ID/v2.0` |
190 | Bootstrap OIDC parameters → Scopes | `openid offline_access YOUR_CLIENT_ID/.default` |
191 | Bootstrap OIDC parameters → Redirect port | leave empty for Entra; set for Okta |
185 | Field | Value |
186 | - | - |
187 | Bootstrap config URL | `https://YOUR_BOOTSTRAP_HOST/user/bootstrap` |
188 | Bootstrap OIDC parameters → Client ID | `YOUR_CLIENT_ID` |
189 | Bootstrap OIDC parameters → Issuer URL | `https://login.microsoftonline.com/YOUR_TENANT_ID/v2.0` |
190 | Bootstrap OIDC parameters → Scopes | `openid offline_access YOUR_CLIENT_ID/.default` |
191 | Bootstrap OIDC parameters → Redirect port | leave empty for Entra; set for Okta |
192192 
193193 Click **Sign in** to test against your typed values. Once authenticated, the card shows the keys your server supplied. Click **Export** and choose the template format your MDM expects (`.mobileconfig`, ADMX, Intune OMA-URI JSON, or `.reg`). See [Deploy the configuration](/docs/third-party/claude-desktop/mdm#4-deploy-the-configuration) for per-platform instructions.
194194 </Step>
from line 196
196196 
197197#### Provider notes
198198 
199| Provider | Redirect URI to register | Redirect port field | Additional setup |
200| ------------------ | ------------------------------------------------------------------------------ | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
201| Microsoft Entra ID | `http://127.0.0.1/callback` under **Mobile and desktop applications** | Leave empty (any local port allowed) | Manifest: set the accepted-token-version field to `2`. **Expose an API**: set the Application ID URI. **Token configuration**: add the `groups` claim if your server authorizes on groups. |
202| Okta | `http://127.0.0.1:53180/callback` (any fixed port) on a **Native** application | Set to the registered port | Create a custom authorization server with an audience your bootstrap server validates. |
203| Other OIDC | `http://127.0.0.1/callback` | Set only if exact-port match is enforced | None |
199| Provider | Redirect URI to register | Redirect port field | Additional setup |
200| - | - | - | - |
201| Microsoft Entra ID | `http://127.0.0.1/callback` under **Mobile and desktop applications** | Leave empty (any local port allowed) | Manifest: set the accepted-token-version field to `2`. **Expose an API**: set the Application ID URI. **Token configuration**: add the `groups` claim if your server authorizes on groups. |
202| Okta | `http://127.0.0.1:53180/callback` (any fixed port) on a **Native** application | Set to the registered port | Create a custom authorization server with an audience your bootstrap server validates. |
203| Other OIDC | `http://127.0.0.1/callback` | Set only if exact-port match is enforced | None |
204204 
205205Register the redirect URI with `127.0.0.1` rather than `localhost`, because the app sends `http://127.0.0.1:<port>/callback` by default. If your identity provider accepts only `localhost` in a registered redirect URI, set the `redirectHost` field of [`bootstrapOidc`](/docs/third-party/claude-desktop/configuration#bootstrapoidc) to `localhost` and register `http://localhost/callback` instead, or `http://localhost:<port>/callback` when you set a redirect port.
206206 
from line 297
297297}
298298```
299299 
300| Status | App behavior |
301| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
302| `200` | Parse and apply. |
303| `304` | Re-serve the cached response (the app sends `If-None-Match` when it has one). |
304| `401`, `403` | Discard the cached token and prompt the user to sign in again. A `401` on a background refresh keeps the running configuration. When the same sign-in also serves inference, the app treats it as an ended session and asks the user to sign in again (1.34493.0 and later); otherwise it retries at the next check without prompting. Return `401` when the token is missing, expired, or the wrong audience; return `403` when the token is valid but the caller is not entitled. |
305| Other non-2xx, or `3xx` | Fetch error. Falls back to the last good response from this session if one exists; otherwise the app stays in the degraded sign-in state. |
300| Status | App behavior |
301| - | - |
302| `200` | Parse and apply. |
303| `304` | Re-serve the cached response (the app sends `If-None-Match` when it has one). |
304| `401`, `403` | Discard the cached token and prompt the user to sign in again. A `401` on a background refresh keeps the running configuration. When the same sign-in also serves inference, the app treats it as an ended session and asks the user to sign in again (1.34493.0 and later); otherwise it retries at the next check without prompting. Return `401` when the token is missing, expired, or the wrong audience; return `403` when the token is valid but the caller is not entitled. |
305| Other non-2xx, or `3xx` | Fetch error. Falls back to the last good response from this session if one exists; otherwise the app stays in the degraded sign-in state. |
306306 
307307<Warning>
308308 A `200` that is not a JSON object (an empty body, an HTML page from a captive portal or load balancer, or a JSON array) is a parse error. Make sure intermediate proxies do not rewrite the response.
from line 354
354354 
355355### Caching and `expiresAt`
356356 
357| Field | Type | Description |
358| ---------------- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
357| Field | Type | Description |
358| - | - | - |
359359| `$schemaVersion` | `integer` | Wire-format marker: `2` for the nested format (bootstrap-config-v2, what the app's own JSON export writes), `1` for the flat format (bootstrap-config-v1). Optional: the client infers the format from the document shape; set it to state the format explicitly. |
360| `expiresAt` | `number` | Unix epoch (seconds or milliseconds) after which the client should re-fetch this document. Optional; when absent the client uses its default refresh interval. |
360| `expiresAt` | `number` | Unix epoch (seconds or milliseconds) after which the client should re-fetch this document. Optional; when absent the client uses its default refresh interval. |
361361 
362362<AccordionGroup>
363363 <Accordion title="$schemaVersion details">
from line 379
379379 
380380## MDM configuration keys
381381 
382| Setting | Type | Availability | Default | Description |
383| ---------------------------------------------------------------------------------------------------- | --------- | -------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
384| <span id="bootstrapenabled" />Use bootstrap config<br />`bootstrapEnabled` | `boolean` | MDM only<br />Added in 1.10628.0 | `true` | Fetch and apply the URL above at launch. Turn off to keep the URL saved but skip the fetch. Defaults to `true`. |
385| <span id="bootstrapurl" />Bootstrap config URL<br />`bootstrapUrl` | `string` | MDM only<br />Added in 1.10628.0 | — | HTTPS endpoint that returns a per-user JSON config overlay. Values from the response override local settings and become read-only. |
386| <span id="bootstrapoidc" />Bootstrap OIDC parameters<br />`bootstrapOidc` | `object` | MDM only<br />Added in 1.10628.0 | — | When set, the bootstrap request sends a Bearer token from a browser sign-in (authorization-code-with-PKCE). |
387| <span id="bootstrapheaders" />Bootstrap request headers<br />`bootstrapHeaders` | `object` | MDM only<br />Added in 1.32885.1 | — | HTTP headers sent on every bootstrap config fetch. Use this instead of embedding user:pass@ in the URL. Deprecated: `bootstrapHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no bootstrap request headers will be sent (the fetch may then fail to authenticate). |
388| <span id="bootstrapheadershelper" />Bootstrap headers helper script<br />`bootstrapHeadersHelper` | `string` | MDM only<br />Added in 1.32885.1 | — | Absolute path to an executable that prints a JSON object of bootstrap request headers. Merged over the static headers; the helper wins. |
382| Setting | Type | Availability | Default | Description |
383| - | - | - | - | - |
384| <span id="bootstrapenabled" />Use bootstrap config<br />`bootstrapEnabled` | `boolean` | MDM only<br />Added in 1.10628.0 | `true` | Fetch and apply the URL above at launch. Turn off to keep the URL saved but skip the fetch. Defaults to `true`. |
385| <span id="bootstrapurl" />Bootstrap config URL<br />`bootstrapUrl` | `string` | MDM only<br />Added in 1.10628.0 | — | HTTPS endpoint that returns a per-user JSON config overlay. Values from the response override local settings and become read-only. |
386| <span id="bootstrapoidc" />Bootstrap OIDC parameters<br />`bootstrapOidc` | `object` | MDM only<br />Added in 1.10628.0 | — | When set, the bootstrap request sends a Bearer token from a browser sign-in (authorization-code-with-PKCE). |
387| <span id="bootstrapheaders" />Bootstrap request headers<br />`bootstrapHeaders` | `object` | MDM only<br />Added in 1.32885.1 | — | HTTP headers sent on every bootstrap config fetch. Use this instead of embedding user:pass@ in the URL. Deprecated: `bootstrapHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no bootstrap request headers will be sent (the fetch may then fail to authenticate). |
388| <span id="bootstrapheadershelper" />Bootstrap headers helper script<br />`bootstrapHeadersHelper` | `string` | MDM only<br />Added in 1.32885.1 | — | Absolute path to an executable that prints a JSON object of bootstrap request headers. Merged over the static headers; the helper wins. |
389389| <span id="trustbootstrapdelivery" />Trust bootstrap-delivered settings<br />`trustBootstrapDelivery` | `boolean` | MDM only<br />Added in 1.26832.0 | `false` | Skip the per-user consent prompt for sign-in targets, inference endpoints, helper scripts, and connectors the bootstrap server delivers. Defaults to `false`. Previously named `trustBootstrapLocalExec` (the old name is accepted until October 7, 2026). If it is still present after that, the key will read as false (its fail-closed value): each user will be asked to consent to bootstrap-delivered sign-in targets, endpoints, helper scripts and connectors, even when the bootstrap URL came from a device-managed profile. |
390390 
391391<AccordionGroup>
from line 394
394394 
395395 This is an **object-typed key** — in an MDM profile it is a single JSON-string value, not separate keys with dotted names like `bootstrapOidc.clientId`. Writing the sub-fields as separate registry values causes the app to silently fall through to device-code mode.
396396 
397 | Field | Type | Default | Description |
398 | --------------------------------- | --------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
399 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
400 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
401 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
402 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
403 | `scopes` | `string` | — | Space-separated; the token’s audience must match what your bootstrap server validates. |
404 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
405 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
406 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
397 | Field | Type | Default | Description |
398 | - | - | - | - |
399 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
400 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
401 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
402 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
403 | `scopes` | `string` | — | Space-separated; the token’s audience must match what your bootstrap server validates. |
404 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
405 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
406 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
407407 </Accordion>
408408 
409409 <Accordion title="bootstrapHeaders details">
from line 419
419419 
420420## Troubleshooting
421421 
422| Symptom | Likely cause |
423| ---------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
424| Identity provider shows `AADSTS900144` (Entra) or `invalid_request: scope` | `bootstrapOidc.scopes` is empty. It is required. |
425| Server logs `unexpected "iss"` or `unexpected "aud"` for a valid Entra token | The app registration's accepted-token-version is at its default. Set it to `2` in the Manifest, or accept both v1 (`sts.windows.net` / `api://CLIENT_ID`) and v2 forms in your server. |
426| Sign-in succeeds in the browser but the app immediately re-prompts | Your server returned `401` or `403`. For `401`, check the `aud` match: the requested scope must produce a token whose audience your server validates. For `403`, the user authenticated but is not in the entitled group or role. |
427| Entra returns `AADSTS500011` ("resource principal not found") | The app registration has no Application ID URI. Set one under **Expose an API**. |
428| Silent refresh fails after \~1 hour with `AADSTS90009` | `scopes` uses the `api://CLIENT_ID/.default` form. Use the bare-GUID `CLIENT_ID/.default` form. |
429| Some keys you returned are not applied | They failed schema validation, are structurally excluded, or were dropped by origin pinning. If the app instead shows an **Apply settings from your organization?** dialog, the whole response is waiting for [user consent](#keys-that-require-user-consent) and none of it has been applied yet. The desktop log (`~/Library/Logs/Claude-3p/main.log` on macOS, `%LOCALAPPDATA%\Claude-3p\logs\main.log` on Windows) records which keys were dropped and why. |
430| Browser opens to your identity provider's device page instead of yours | In device-code mode, `verification_uri` must share the `bootstrapUrl` origin. Federate behind your own page. |
422| Symptom | Likely cause |
423| - | - |
424| Identity provider shows `AADSTS900144` (Entra) or `invalid_request: scope` | `bootstrapOidc.scopes` is empty. It is required. |
425| Server logs `unexpected "iss"` or `unexpected "aud"` for a valid Entra token | The app registration's accepted-token-version is at its default. Set it to `2` in the Manifest, or accept both v1 (`sts.windows.net` / `api://CLIENT_ID`) and v2 forms in your server. |
426| Sign-in succeeds in the browser but the app immediately re-prompts | Your server returned `401` or `403`. For `401`, check the `aud` match: the requested scope must produce a token whose audience your server validates. For `403`, the user authenticated but is not in the entitled group or role. |
427| Entra returns `AADSTS500011` ("resource principal not found") | The app registration has no Application ID URI. Set one under **Expose an API**. |
428| Silent refresh fails after \~1 hour with `AADSTS90009` | `scopes` uses the `api://CLIENT_ID/.default` form. Use the bare-GUID `CLIENT_ID/.default` form. |
429| Some keys you returned are not applied | They failed schema validation, are structurally excluded, or were dropped by origin pinning. If the app instead shows an **Apply settings from your organization?** dialog, the whole response is waiting for [user consent](#keys-that-require-user-consent) and none of it has been applied yet. The desktop log (`~/Library/Logs/Claude-3p/main.log` on macOS, `%LOCALAPPDATA%\Claude-3p\logs\main.log` on Windows) records which keys were dropped and why. |
430| Browser opens to your identity provider's device page instead of yours | In device-code mode, `verification_uri` must share the `bootstrapUrl` origin. Federate behind your own page. |
431431 

third-party/claude-desktop/browser Changed · +3 / -3 lines

from line 40
4040 
4141[`builtinBrowserDefaultDomainPolicy`](/docs/third-party/claude-desktop/configuration#builtinbrowserdefaultdomainpolicy) decides whether Claude can open every site except the ones you block, or only the sites you allow. Under either value, a site that Anthropic's [site safety check](#site-safety-check) blocks stays blocked to Claude, even when `builtinBrowserAllowedDomains` lists it.
4242 
43| Value | Behavior |
44| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
43| Value | Behavior |
44| - | - |
4545| Unset or `allow` | Claude can open every site except the entries in [`builtinBrowserBlockedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowserblockeddomains) |
46| `block` | Claude can open only the entries in [`builtinBrowserAllowedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowseralloweddomains) |
46| `block` | Claude can open only the entries in [`builtinBrowserAllowedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowseralloweddomains) |
4747 
4848The policy also governs sites that the site safety check flags for confirmation rather than blocks. Under the default `allow` policy, Claude asks the user before each of its actions on such a site. Under `block`, listing the site in `builtinBrowserAllowedDomains` is your organization vouching for it, so Claude works with it without asking before each action. For a site on your private network, Claude Desktop still asks before each action until the user chooses **Always allow** for that site.
4949 

third-party/claude-desktop/built-in-connectors Changed · +5 / -5 lines

from line 8
88 
99## Available servers
1010 
11| Server | `server` value | What Claude can reach | Setup guide |
12| ------------- | -------------- | ----------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
13| Microsoft 365 | `microsoft365` | Outlook mail and calendar, OneDrive, SharePoint, and Teams, through Microsoft Graph | [Connect to Microsoft 365, local connector](/docs/third-party/claude-desktop/connectors-m365#local-connector) |
14| Web search | `websearch` | Web search through Brave, Tavily, Exa, or a search endpoint you host | [Built-in web search](/docs/third-party/claude-desktop/web-tools#built-in-web-search) |
15| GitHub (beta) | `github` | Repositories, issues, pull requests, and other GitHub data, on github.com or GitHub Enterprise Server | [Connect to GitHub, local connector](/docs/third-party/claude-desktop/connectors-github#local-connector) |
11| Server | `server` value | What Claude can reach | Setup guide |
12| - | - | - | - |
13| Microsoft 365 | `microsoft365` | Outlook mail and calendar, OneDrive, SharePoint, and Teams, through Microsoft Graph | [Connect to Microsoft 365, local connector](/docs/third-party/claude-desktop/connectors-m365#local-connector) |
14| Web search | `websearch` | Web search through Brave, Tavily, Exa, or a search endpoint you host | [Built-in web search](/docs/third-party/claude-desktop/web-tools#built-in-web-search) |
15| GitHub (beta) | `github` | Repositories, issues, pull requests, and other GitHub data, on github.com or GitHub Enterprise Server | [Connect to GitHub, local connector](/docs/third-party/claude-desktop/connectors-github#local-connector) |
1616 
1717Each guide covers its server in full, including how the built-in server compares with the remote alternative where one exists. The GitHub built-in server is in beta, and the **Add server** menu marks it with a **Beta** pill.
1818 

third-party/claude-desktop/chat Changed · +14 / -14 lines

from line 8
88 
99## What a Chat conversation can reach
1010 
11| Capability | Scope |
12| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
13| Web search | Same options and rules as Cowork and Code sessions; depends on your provider or a configured search server. See [Web search](/docs/third-party/claude-desktop/web-tools#web-search). |
14| Web fetch | Runs in the app on the device, never inside a sandbox. Every fetch is checked against `coworkEgressAllowedHosts`; with no allowlist configured, fetch is disabled. See [Web fetch](/docs/third-party/claude-desktop/web-tools#web-fetch). |
15| Attached files | Read-only access to files the user attaches to the conversation. Each attachment is copied or hard-linked into the conversation's local uploads directory. |
16| Project memory | For a conversation inside a project, read-only access to that project's [memory](/docs/third-party/claude-desktop/data-storage#memory): the notes written during Cowork sessions in that project. Not used if memory was paused when the conversation started, or for conversations outside a project. |
17| Scratch directory | A per-conversation working directory where Claude can create and edit files (documents, data files, HTML artifacts) and offer them to the user for download or preview. |
18| Managed MCP servers | The servers you provision via [`managedMcpServers`](/docs/third-party/claude-desktop/configuration#managedmcpservers) are available in Chat with the same approval model as Cowork sessions: a tool's `toolPolicy` of `"allow"` pre-approves it, `"blocked"` blocks it, and `"ask"` requires user approval on every call. A tool with no policy asks the user, who can allow it once or grant standing approval, as in Cowork. |
19| Clarifying questions | Claude can present multiple-choice questions to the user (the `AskUserQuestion` tool). |
11| Capability | Scope |
12| - | - |
13| Web search | Same options and rules as Cowork and Code sessions; depends on your provider or a configured search server. See [Web search](/docs/third-party/claude-desktop/web-tools#web-search). |
14| Web fetch | Runs in the app on the device, never inside a sandbox. Every fetch is checked against `coworkEgressAllowedHosts`; with no allowlist configured, fetch is disabled. See [Web fetch](/docs/third-party/claude-desktop/web-tools#web-fetch). |
15| Attached files | Read-only access to files the user attaches to the conversation. Each attachment is copied or hard-linked into the conversation's local uploads directory. |
16| Project memory | For a conversation inside a project, read-only access to that project's [memory](/docs/third-party/claude-desktop/data-storage#memory): the notes written during Cowork sessions in that project. Not used if memory was paused when the conversation started, or for conversations outside a project. |
17| Scratch directory | A per-conversation working directory where Claude can create and edit files (documents, data files, HTML artifacts) and offer them to the user for download or preview. |
18| Managed MCP servers | The servers you provision via [`managedMcpServers`](/docs/third-party/claude-desktop/configuration#managedmcpservers) are available in Chat with the same approval model as Cowork sessions: a tool's `toolPolicy` of `"allow"` pre-approves it, `"blocked"` blocks it, and `"ask"` requires user approval on every call. A tool with no policy asks the user, who can allow it once or grant standing approval, as in Cowork. |
19| Clarifying questions | Claude can present multiple-choice questions to the user (the `AskUserQuestion` tool). |
2020| Plugin skills and hooks | Skills from the plugins you provision through [organization plugins](/docs/third-party/claude-desktop/extensions#organization-plugins-admin) or [plugin marketplaces](/docs/third-party/claude-desktop/extensions#plugin-marketplaces-admin) are available in Chat, including as slash commands. Hooks from those plugins also run in Chat conversations as they do in Cowork sessions, as described under [Plugin hooks](/docs/third-party/claude-desktop/extensions#plugin-hooks). Plugin sub-agents do not run in Chat, and a skill that runs scripts needs [advanced file analysis](#advanced-file-analysis). Plugin skills require Claude Desktop 1.44121.4 or later, and plugin hooks run in Chat on Claude Desktop 1.52386.0 or later. |
21| Code execution | Off by default. When you enable [advanced file analysis](#advanced-file-analysis), Claude can additionally run code in an offline local sandbox against attached files. |
21| Code execution | Off by default. When you enable [advanced file analysis](#advanced-file-analysis), Claude can additionally run code in an offline local sandbox against attached files. |
2222 
2323`disabledBuiltinTools` and `builtinToolPolicy` apply in Chat the same way they do in Cowork and Code sessions. For example, adding `"WebFetch"` removes web fetch from Chat conversations too.
2424 
from line 55
5555 
5656## Configuration
5757 
58| Key | Default | Effect |
59| -------------------------------------------------------------------------------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------- |
60| [`chatTabEnabled`](/docs/third-party/claude-desktop/configuration#chattabenabled) | off | Makes Chat available. Chat is opt-in: it appears in the app only when this key is explicitly `true`. |
61| [`chatAdvancedFileAnalysisEnabled`](/docs/third-party/claude-desktop/configuration#chatadvancedfileanalysisenabled) | off | Allows code execution on attached files in the offline sandbox, as described above. Has no effect unless Chat is enabled. |
58| Key | Default | Effect |
59| - | - | - |
60| [`chatTabEnabled`](/docs/third-party/claude-desktop/configuration#chattabenabled) | off | Makes Chat available. Chat is opt-in: it appears in the app only when this key is explicitly `true`. |
61| [`chatAdvancedFileAnalysisEnabled`](/docs/third-party/claude-desktop/configuration#chatadvancedfileanalysisenabled) | off | Allows code execution on attached files in the offline sandbox, as described above. Has no effect unless Chat is enabled. |
6262 
6363When `chatTabEnabled` is `true`, Claude Desktop presents Chat and Cowork together as **Home** in its sidebar, next to **Code**. From Home, the user chooses **Chat** or **Cowork** in the message box, and the sidebar lists chats and tasks together. When the key is unset or `false`, the sidebar shows **Cowork** in place of Home and the message box offers no choice. If [`coworkTabEnabled`](/docs/third-party/claude-desktop/configuration#coworktabenabled) is `false` while Chat is enabled, the message box offers Chat only.
6464 

third-party/claude-desktop/claude-api Changed · +3 / -3 lines

from line 16
1616 
1717### Configuration keys
1818 
19| Setting | Type | Availability | Default | Description |
20| ------------------------------------------------------------------------------------ | -------- | -------------------------------------- | ------- | --------------------------------------------------------------------------------------------- |
21| <span id="inferenceanthropicapikey" />Claude API key<br />`inferenceAnthropicApiKey` | `string` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Leave blank to fetch a key via browser sign-in, or to supply the key via a credential helper. |
19| Setting | Type | Availability | Default | Description |
20| - | - | - | - | - |
21| <span id="inferenceanthropicapikey" />Claude API key<br />`inferenceAnthropicApiKey` | `string` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Leave blank to fetch a key via browser sign-in, or to supply the key via a credential helper. |
2222 
Feedback