Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.277 Latest v2.1.284 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260928T220706Z

157 pages moved out of 255 read.

Pages moved 157 significant first
Pages read 255 in this capture
Captured 22:07 UTC
Corpus hash 9aad7bf66b91 corpus-hash

What this read moved

126-150 of 157, page 6 of 7

This capture is too large to show at once. Changes 126-150 of 157 are below, significant first; the rest are on the following screens.

third-party/claude-desktop/code Changed · +23 / -23 lines

from line 14
1414 
1515These keys are passed directly to the Claude Code process as environment variables or launch options. They take effect on every Code session and cannot be overridden by user-level Claude Code settings or by a separately deployed `managed-settings.json`.
1616 
17| Claude Desktop on 3P key | Effect in Code sessions |
18| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
19| `inferenceProvider` and all provider credential keys (`inferenceGateway*`, `inferenceAnthropicApiKey`, `inferenceVertex*`, `inferenceBedrock*`, `inferenceFoundry*`, `inferenceCredentialHelper*`) | Selects the inference backend and supplies credentials. Code sessions use the same provider, endpoint, and credentials as Cowork sessions. |
20| `inferenceModels` | Populates the model picker. The first entry is the default for new Code sessions. |
21| `autoModeEnabled` | Controls **Auto mode**. When the key is not set, Code sessions offer Auto mode and new sessions start in it unless the user has already chosen another mode or a Claude Code `permissions.defaultMode` applies. Set it to `false` to remove Auto mode from Code and Cowork. Set it to `true` to also offer **Automatically approve** in Cowork. A separately deployed Claude Code managed-settings file that sets `disableAutoMode` to `"disable"` overrides this key and keeps Auto mode hidden; see below. |
22| `scheduledTasksEnabled` | When `false`, the routines list in Code is hidden and Code sessions start without Claude Code's in-session scheduling tools, so the `/loop` command cannot schedule recurring work. Cowork's scheduled tasks are turned off by the same key. |
23| `disabledBuiltinTools` | Removes the listed tools from Code sessions. Tools your provider does not support, such as WebSearch on Amazon Bedrock, are removed automatically in addition to your list. |
24| `builtinToolPolicy` | Tools set to `"ask"` require approval on each call in Code sessions, enforced via a PreToolUse hook and Claude Code `permissions.ask` rules. |
25| `disableBypassPermissionsMode` | Removes bypass permissions mode. The app stops offering the mode and starts a session that requests it in a stricter permission mode instead, independent of Claude Code managed-settings precedence. The key requires Claude Desktop 1.46388.1 or later. A separately deployed Claude Code managed-settings file that sets `permissions.disableBypassPermissionsMode` to `"disable"` removes the mode as well. |
26| `skipWebFetchPreflight` | Turns off Claude Code's Web Fetch [domain check](/docs/third-party/claude-desktop/web-tools#web-fetch) against `api.anthropic.com`. A separately deployed Claude Code managed-settings file that sets `skipWebFetchPreflight` takes precedence. |
27| `managedMcpServers` | Makes the same managed MCP servers available in Code sessions. The app handles the connection and authentication; the Code session sees only the resulting tool list. |
28| `mcpToolTimeoutSec` | Applies your per-call MCP tool timeout to Code sessions as well, taking precedence over a user-set `MCP_TOOL_TIMEOUT`. |
29| `organizationInstructions` | Appended to the Code session's system prompt after Claude Code's own. `CLAUDE.md` instructions still apply. |
30| `otlpEndpoint`, `otlpProtocol`, `otlpHeaders`, `otlpResourceAttributes` | Routes Claude Code's OpenTelemetry metrics and logs to your collector. See [Telemetry](/docs/third-party/claude-desktop/telemetry). |
31| `disableEssentialTelemetry`, `disableNonessentialTelemetry` | Disables Claude Code's crash reporting and usage telemetry to Anthropic, mirroring Cowork. |
32| `disableAutoUpdates` | The embedded Claude Code engine never self-updates regardless of this key; its version is managed by the app's own updater. |
33| `inferenceMaxTokensPerWindow`, `inferenceTokenWindowHours` | The token budget is shared across Cowork and Code sessions and enforced before each turn. |
17| Claude Desktop on 3P key | Effect in Code sessions |
18| - | - |
19| `inferenceProvider` and all provider credential keys (`inferenceGateway*`, `inferenceAnthropicApiKey`, `inferenceVertex*`, `inferenceBedrock*`, `inferenceFoundry*`, `inferenceCredentialHelper*`) | Selects the inference backend and supplies credentials. Code sessions use the same provider, endpoint, and credentials as Cowork sessions. |
20| `inferenceModels` | Populates the model picker. The first entry is the default for new Code sessions. |
21| `autoModeEnabled` | Controls **Auto mode**. When the key is not set, Code sessions offer Auto mode and new sessions start in it unless the user has already chosen another mode or a Claude Code `permissions.defaultMode` applies. Set it to `false` to remove Auto mode from Code and Cowork. Set it to `true` to also offer **Automatically approve** in Cowork. A separately deployed Claude Code managed-settings file that sets `disableAutoMode` to `"disable"` overrides this key and keeps Auto mode hidden; see below. |
22| `scheduledTasksEnabled` | When `false`, the routines list in Code is hidden and Code sessions start without Claude Code's in-session scheduling tools, so the `/loop` command cannot schedule recurring work. Cowork's scheduled tasks are turned off by the same key. |
23| `disabledBuiltinTools` | Removes the listed tools from Code sessions. Tools your provider does not support, such as WebSearch on Amazon Bedrock, are removed automatically in addition to your list. |
24| `builtinToolPolicy` | Tools set to `"ask"` require approval on each call in Code sessions, enforced via a PreToolUse hook and Claude Code `permissions.ask` rules. |
25| `disableBypassPermissionsMode` | Removes bypass permissions mode. The app stops offering the mode and starts a session that requests it in a stricter permission mode instead, independent of Claude Code managed-settings precedence. The key requires Claude Desktop 1.46388.1 or later. A separately deployed Claude Code managed-settings file that sets `permissions.disableBypassPermissionsMode` to `"disable"` removes the mode as well. |
26| `skipWebFetchPreflight` | Turns off Claude Code's Web Fetch [domain check](/docs/third-party/claude-desktop/web-tools#web-fetch) against `api.anthropic.com`. A separately deployed Claude Code managed-settings file that sets `skipWebFetchPreflight` takes precedence. |
27| `managedMcpServers` | Makes the same managed MCP servers available in Code sessions. The app handles the connection and authentication; the Code session sees only the resulting tool list. |
28| `mcpToolTimeoutSec` | Applies your per-call MCP tool timeout to Code sessions as well, taking precedence over a user-set `MCP_TOOL_TIMEOUT`. |
29| `organizationInstructions` | Appended to the Code session's system prompt after Claude Code's own. `CLAUDE.md` instructions still apply. |
30| `otlpEndpoint`, `otlpProtocol`, `otlpHeaders`, `otlpResourceAttributes` | Routes Claude Code's OpenTelemetry metrics and logs to your collector. See [Telemetry](/docs/third-party/claude-desktop/telemetry). |
31| `disableEssentialTelemetry`, `disableNonessentialTelemetry` | Disables Claude Code's crash reporting and usage telemetry to Anthropic, mirroring Cowork. |
32| `disableAutoUpdates` | The embedded Claude Code engine never self-updates regardless of this key; its version is managed by the app's own updater. |
33| `inferenceMaxTokensPerWindow`, `inferenceTokenWindowHours` | The token budget is shared across Cowork and Code sessions and enforced before each turn. |
3434 
3535### Applied as managed policy
3636 
3737These keys are translated into Claude Code [managed settings](https://code.claude.com/docs/en/settings#settings-files) and supplied to the session as policy. They take precedence over user and project settings, but they participate in Claude Code's managed-settings precedence if you have also deployed a separate Claude Code policy.
3838 
39| Claude Desktop on 3P key | Claude Code policy it produces |
40| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
41| `coworkEgressAllowedHosts` | A network sandbox restricted to your hosts plus the inference and telemetry endpoints, `WebFetch` permission rules for the same hosts, and `allowManagedDomainsOnly`. |
42| `allowedWorkspaceFolders` | A filesystem sandbox for shell commands, which can then create or change files only inside your allowed roots and the session's temporary locations. The sandbox does not restrict which files those commands read unless you also set `blockReadsOutsideWorkingDirectories`. The roots are also passed as `additionalDirectories` at launch, which is always applied independent of managed-settings precedence, and the app keeps Claude's file tools inside the roots. The app also refuses to start a Code session outside an allowed root. |
39| Claude Desktop on 3P key | Claude Code policy it produces |
40| - | - |
41| `coworkEgressAllowedHosts` | A network sandbox restricted to your hosts plus the inference and telemetry endpoints, `WebFetch` permission rules for the same hosts, and `allowManagedDomainsOnly`. |
42| `allowedWorkspaceFolders` | A filesystem sandbox for shell commands, which can then create or change files only inside your allowed roots and the session's temporary locations. The sandbox does not restrict which files those commands read unless you also set `blockReadsOutsideWorkingDirectories`. The roots are also passed as `additionalDirectories` at launch, which is always applied independent of managed-settings precedence, and the app keeps Claude's file tools inside the roots. The app also refuses to start a Code session outside an allowed root. |
4343| `blockReadsOutsideWorkingDirectories` | Claude Code's `permissions.blockReadsOutsideWorkingDirectories` for Code sessions. Claude's file tools refuse to read outside the working directories (the session's folder plus your allowed roots, if any) in every permission mode. Where the sandbox from `allowedWorkspaceFolders` or `coworkEgressAllowedHosts` is running, it also hides the user's home directory and similar locations, such as other users' home folders and mounted volumes, from shell commands, so a sandboxed command that reads there fails without a prompt. Without a running sandbox, a shell command that reads outside the working directories, or that Claude Code cannot analyze, asks the user for approval first, even in bypass permissions mode. The key requires Claude Desktop 1.46388.1 or later. The block takes effect only in sessions that run Claude Code v2.1.257 or later; if the app cannot install its current Claude Code engine and a session runs one older than v2.1.257 that is still on the device, that session runs without the block and the app logs a warning. |
44| `managedMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]`, so the Code session does not load MCP servers that users define on Claude Code's side (`~/.claude.json`, a project's `.mcp.json`, or `claude mcp add`); your managed servers, which the app connects and supplies to the session itself, and MCP servers bundled in plugins still load. When [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`, the app also sets an `allowedMcpServers` list that admits only remote servers, with `allowManagedMcpServersOnly`, so local (stdio) servers bundled in plugins from marketplaces or that users install themselves are refused, while those plugins' remote servers still connect. Per-tool `toolPolicy` values on each server are emitted as `permissions.deny` (for `blocked`) or `permissions.ask` (for `ask`) rules against the corresponding `mcp__<server>__<tool>` names. |
45| `allowedPluginMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]` together with an `allowedMcpServers` list holding your entries and `allowManagedMcpServersOnly`, whether or not `managedMcpServers` is set. MCP servers bundled in plugins from marketplaces, or in plugins users install themselves, connect only when their URL matches an entry; no such plugin's local (stdio) server is admitted, and an empty list admits none. Your managed servers and the servers from the organization plugins directory still load. |
44| `managedMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]`, so the Code session does not load MCP servers that users define on Claude Code's side (`~/.claude.json`, a project's `.mcp.json`, or `claude mcp add`); your managed servers, which the app connects and supplies to the session itself, and MCP servers bundled in plugins still load. When [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`, the app also sets an `allowedMcpServers` list that admits only remote servers, with `allowManagedMcpServersOnly`, so local (stdio) servers bundled in plugins from marketplaces or that users install themselves are refused, while those plugins' remote servers still connect. Per-tool `toolPolicy` values on each server are emitted as `permissions.deny` (for `blocked`) or `permissions.ask` (for `ask`) rules against the corresponding `mcp__<server>__<tool>` names. |
45| `allowedPluginMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]` together with an `allowedMcpServers` list holding your entries and `allowManagedMcpServersOnly`, whether or not `managedMcpServers` is set. MCP servers bundled in plugins from marketplaces, or in plugins users install themselves, connect only when their URL matches an entry; no such plugin's local (stdio) server is admitted, and an empty list admits none. Your managed servers and the servers from the organization plugins directory still load. |
4646 
4747The network and filesystem sandboxes apply on macOS, and on Linux devices and [SSH hosts](/docs/third-party/claude-desktop/ssh-remote-sessions#managed-configuration-on-the-remote-host) with Claude Code's [sandbox dependencies](https://code.claude.com/docs/en/sandboxing) installed. Claude Code does not sandbox shell commands on Windows devices, and on a Linux device or SSH host without the dependencies commands run unsandboxed with a warning in the session. In those cases, and when neither sandbox key is set, `blockReadsOutsideWorkingDirectories` still confines Claude's file tools but can only ask the user to approve shell commands that read outside the working directories or that Claude Code cannot verify.
4848 

third-party/claude-desktop/configuration Changed · +379 / -379 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

The two sides of this change are more than 400 edits apart, too far apart to line up, so this is the differ's own diff of it and the words inside a line are not marked.

from line 10
1010 
1111## How keys are read
1212 
13| Platform | Managed (MDM) location | Local (user) location |
14| -------- | --------------------------------------------------------------------------------- | -------------------------------------------------------- |
15| macOS | `/Library/Managed Preferences/<user>/com.anthropic.claudefordesktop.plist` | `~/Library/Application Support/Claude-3p/configLibrary/` |
16| Windows | `HKLM\SOFTWARE\Policies\Claude` (machine), `HKCU\SOFTWARE\Policies\Claude` (user) | `%LOCALAPPDATA%\Claude-3p\configLibrary\` |
17| Linux | `/etc/claude-desktop/managed-settings.json` | `~/.config/Claude-3p/configLibrary/` |
13| Platform | Managed (MDM) location | Local (user) location |
14| - | - | - |
15| macOS | `/Library/Managed Preferences/<user>/com.anthropic.claudefordesktop.plist` | `~/Library/Application Support/Claude-3p/configLibrary/` |
16| Windows | `HKLM\SOFTWARE\Policies\Claude` (machine), `HKCU\SOFTWARE\Policies\Claude` (user) | `%LOCALAPPDATA%\Claude-3p\configLibrary\` |
17| Linux | `/etc/claude-desktop/managed-settings.json` | `~/.config/Claude-3p/configLibrary/` |
1818 
1919The local location is a directory: `_meta.json` records which saved configuration is applied, and each configuration is a `<id>.json` file alongside it. The in-app configuration window writes here.
2020 
from line 28
2828 
2929Write every value as a **string** in the OS preference store, even booleans and arrays.
3030 
31| Documented type | What to write | Example |
32| ---------------- | ---------------------------------------------- | --------------------------------------------- |
33| string | Plain string | `vertex` |
34| boolean | `"true"` or `"false"` (or `1` / `0`) | `"true"` |
35| integer | Decimal string | `"3600"` |
36| string\[] (JSON) | JSON array **encoded as a string** | `["claude-sonnet-5","claude-opus-5"]` |
37| object (JSON) | JSON object mapping name to value, as a string | `{"X-Org-Id":"team1"}` |
38| object\[] (JSON) | JSON array of objects, as a string | see [`managedMcpServers`](#managedmcpservers) |
31| Documented type | What to write | Example |
32| - | - | - |
33| string | Plain string | `vertex` |
34| boolean | `"true"` or `"false"` (or `1` / `0`) | `"true"` |
35| integer | Decimal string | `"3600"` |
36| string\[] (JSON) | JSON array **encoded as a string** | `["claude-sonnet-5","claude-opus-5"]` |
37| object (JSON) | JSON object mapping name to value, as a string | `{"X-Org-Id":"team1"}` |
38| object\[] (JSON) | JSON array of objects, as a string | see [`managedMcpServers`](#managedmcpservers) |
3939 
4040<Note>
4141 Array- and object-typed keys such as `inferenceModels`, `inferenceGatewayOidc`, `managedMcpServers`, `coworkEgressAllowedHosts`, and `otlpHeaders` are single keys whose value is a whole JSON document. The portable encoding is a JSON string, which works on every platform. In a `.mobileconfig` that is a single `<string>` element containing `[...]` or `{...}`, and on Windows a `REG_SZ` value. A macOS profile may instead carry the value as a native `<array>` or `<dict>`, which the app reads as the equivalent JSON. Separate keys with dotted names, such as `inferenceGatewayOidc.clientId`, are never read.
from line 73
7373 
7474## Connection
7575 
76| Setting | Type | Availability | Default | Description |
77| ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------- | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
78| <span id="inferencecustomheaders" />Custom inference headers<br />`inferenceCustomHeaders` | `object` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Extra headers on every inference request — routing and tenant headers only (org IDs, Bedrock Guardrails). No credentials; use the credential helper for tokens. Previously named `inferenceGatewayHeaders` (the old name is accepted until October 7, 2026). If it is still present after that, no custom inference headers will be sent. Deprecated: `inferenceCustomHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no custom inference headers will be sent. |
79| <span id="inferencesessionlifetimesec" />Sign-in session lifetime<br />`inferenceSessionLifetimeSec` | `integer` | MDM + Bootstrap<br />Added in 1.14271.0 | — | How long a sign-in stays valid under your IdP’s session policy. Shows a re-authenticate banner before it expires. |
80| <span id="inferencecredentialhelper" />Helper script<br />`inferenceCredentialHelper` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Absolute path to an executable that prints the credential, optionally with per-request headers. |
81| <span id="inferencecredentialhelperwindows" />Helper script (Windows)<br />`inferenceCredentialHelperWindows` | `string` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Absolute path of the helper executable on Windows devices, used there instead of Helper script. Leave unset to use Helper script on every operating system. |
82| <span id="inferencecredentialhelperargs" />Helper script arguments<br />`inferenceCredentialHelperArgs` | `string[]` | MDM + Bootstrap<br />Added in 2.110.0 | — | Arguments passed to the helper script, one per entry, in order. Leave unset to run it with none. |
83| <span id="inferencecredentialhelperttlsec" />Helper script TTL<br />`inferenceCredentialHelperTtlSec` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | `3600` | Helper output is cached for this many seconds; once it expires the helper re-runs without a relaunch (before the next turn when set above 120). Defaults to `3600`. |
84| <span id="inferencecredentialhelpertimeoutsec" />Credential helper timeout<br />`inferenceCredentialHelperTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.8089.0 | `60` | Maximum wait for the helper executable to finish. Raise this if the helper opens a browser for interactive sign-in. Defaults to `60`. Range: 1–600. |
85| <span id="inferencecredentialhelpersilentrefreshenabled" />Re-run helper for silent refresh<br />`inferenceCredentialHelperSilentRefreshEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.10628.0 | `true` | On credential expiry, re-run the helper (CLAUDE\_HELPER\_CONTEXT=mid-session-refresh) to recover silently. Turn off if the helper can’t run non-interactively. Defaults to `true`. |
86| <span id="egressproxyurl" />Proxy server URL<br />`egressProxyUrl` | `string` | MDM only<br />Added in 1.44121.1 | — | Send the app’s and the agent’s traffic through this HTTP proxy instead of the operating system’s proxy settings. |
87| <span id="egressproxypacurl" />Proxy auto-config (PAC) URL<br />`egressProxyPacUrl` | `string` | MDM only<br />Added in 1.44121.1 | — | URL of a PAC file that decides the proxy per request. Wins over the proxy server URL when both are set. |
88| <span id="coworkvmipv6enabled" />Enable IPv6 in the workspace VM<br />`coworkVmIpv6Enabled` | `boolean` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Give the Cowork workspace VM an IPv6 address and route so the agent’s tools can reach IPv6-only hosts through the device. macOS and Windows; off by default. |
89| <span id="usercontentrendererurl" />Artifact preview iframe origin<br />`userContentRendererUrl` | `string` | MDM + Bootstrap<br />Added in 1.24012.0 | — | HTTPS origin of the user-content-renderer deployment used for artifact and file previews. Defaults to the commercial host when unset. |
90| <span id="inferenceprovider" />Inference provider<br />`inferenceProvider` | `enum` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Selects the inference backend. Setting this key activates third-party mode. One of: `gateway`, `anthropic`, `bedrock`, `mantle`, `vertex`, `foundry`. |
91| <span id="inferencecredentialkind" />Credential kind<br />`inferenceCredentialKind` | `enum` | MDM + Bootstrap<br />Added in 1.8555.0 | — | Selects the credential source. When set, only that source is used (no fallback). One of: `static`, `helper-script`, `interactive`, `vendor-profile`, `workforce`, `external-idp`. Deprecated: `inferenceCredentialKind: "oauth" (Vertex AI)` (accepted until October 7, 2026); use "interactive" — the same Google sign-in under its new name (in hosted or nested documents, switch once every desktop is on a release that knows the Vertex "interactive" kind). If it is still present after that, "oauth" will no longer be a Vertex AI credential kind: the value will be reported as invalid and ignored — the device will then derive the kind from the credential fields present (Google sign-in when an OAuth client id is set), and the hosted editor will refuse to save the configuration until the kind is changed. Deprecated: `inferenceCredentialKind: "interactive" together with inferenceVertexWorkforceAudience (Vertex AI)` (accepted until October 7, 2026); use "workforce" — or remove inferenceVertexWorkforceAudience if Google sign-in ("interactive") is what is meant. If it is still present after that, the audience will no longer imply Workforce Identity: the kind will stay "interactive" (Google sign-in), which needs inferenceVertexOAuthClientId — without it the configuration will be reported as incomplete and inference will not start. Deprecated: `inferenceCredentialKind: "interactive" together with inferenceGatewayOidc (gateway)`; use "external-idp" once every desktop in the fleet is on a release that reads it. The original spelling will keep working ("interactive" with inferenceGatewayOidc is read as "external-idp"); no end date has been set. |
76| Setting | Type | Availability | Default | Description |
77| - | - | - | - | - |
78| <span id="inferencecustomheaders" />Custom inference headers<br />`inferenceCustomHeaders` | `object` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Extra headers on every inference request — routing and tenant headers only (org IDs, Bedrock Guardrails). No credentials; use the credential helper for tokens. Previously named `inferenceGatewayHeaders` (the old name is accepted until October 7, 2026). If it is still present after that, no custom inference headers will be sent. Deprecated: `inferenceCustomHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no custom inference headers will be sent. |
79| <span id="inferencesessionlifetimesec" />Sign-in session lifetime<br />`inferenceSessionLifetimeSec` | `integer` | MDM + Bootstrap<br />Added in 1.14271.0 | — | How long a sign-in stays valid under your IdP’s session policy. Shows a re-authenticate banner before it expires. |
80| <span id="inferencecredentialhelper" />Helper script<br />`inferenceCredentialHelper` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Absolute path to an executable that prints the credential, optionally with per-request headers. |
81| <span id="inferencecredentialhelperwindows" />Helper script (Windows)<br />`inferenceCredentialHelperWindows` | `string` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Absolute path of the helper executable on Windows devices, used there instead of Helper script. Leave unset to use Helper script on every operating system. |
82| <span id="inferencecredentialhelperargs" />Helper script arguments<br />`inferenceCredentialHelperArgs` | `string[]` | MDM + Bootstrap<br />Added in 2.110.0 | — | Arguments passed to the helper script, one per entry, in order. Leave unset to run it with none. |
83| <span id="inferencecredentialhelperttlsec" />Helper script TTL<br />`inferenceCredentialHelperTtlSec` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | `3600` | Helper output is cached for this many seconds; once it expires the helper re-runs without a relaunch (before the next turn when set above 120). Defaults to `3600`. |
84| <span id="inferencecredentialhelpertimeoutsec" />Credential helper timeout<br />`inferenceCredentialHelperTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.8089.0 | `60` | Maximum wait for the helper executable to finish. Raise this if the helper opens a browser for interactive sign-in. Defaults to `60`. Range: 1–600. |
85| <span id="inferencecredentialhelpersilentrefreshenabled" />Re-run helper for silent refresh<br />`inferenceCredentialHelperSilentRefreshEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.10628.0 | `true` | On credential expiry, re-run the helper (CLAUDE\_HELPER\_CONTEXT=mid-session-refresh) to recover silently. Turn off if the helper can’t run non-interactively. Defaults to `true`. |
86| <span id="egressproxyurl" />Proxy server URL<br />`egressProxyUrl` | `string` | MDM only<br />Added in 1.44121.1 | — | Send the app’s and the agent’s traffic through this HTTP proxy instead of the operating system’s proxy settings. |
87| <span id="egressproxypacurl" />Proxy auto-config (PAC) URL<br />`egressProxyPacUrl` | `string` | MDM only<br />Added in 1.44121.1 | — | URL of a PAC file that decides the proxy per request. Wins over the proxy server URL when both are set. |
88| <span id="coworkvmipv6enabled" />Enable IPv6 in the workspace VM<br />`coworkVmIpv6Enabled` | `boolean` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Give the Cowork workspace VM an IPv6 address and route so the agent’s tools can reach IPv6-only hosts through the device. macOS and Windows; off by default. |
89| <span id="usercontentrendererurl" />Artifact preview iframe origin<br />`userContentRendererUrl` | `string` | MDM + Bootstrap<br />Added in 1.24012.0 | — | HTTPS origin of the user-content-renderer deployment used for artifact and file previews. Defaults to the commercial host when unset. |
90| <span id="inferenceprovider" />Inference provider<br />`inferenceProvider` | `enum` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Selects the inference backend. Setting this key activates third-party mode. One of: `gateway`, `anthropic`, `bedrock`, `mantle`, `vertex`, `foundry`. |
91| <span id="inferencecredentialkind" />Credential kind<br />`inferenceCredentialKind` | `enum` | MDM + Bootstrap<br />Added in 1.8555.0 | — | Selects the credential source. When set, only that source is used (no fallback). One of: `static`, `helper-script`, `interactive`, `vendor-profile`, `workforce`, `external-idp`. Deprecated: `inferenceCredentialKind: "oauth" (Vertex AI)` (accepted until October 7, 2026); use "interactive" — the same Google sign-in under its new name (in hosted or nested documents, switch once every desktop is on a release that knows the Vertex "interactive" kind). If it is still present after that, "oauth" will no longer be a Vertex AI credential kind: the value will be reported as invalid and ignored — the device will then derive the kind from the credential fields present (Google sign-in when an OAuth client id is set), and the hosted editor will refuse to save the configuration until the kind is changed. Deprecated: `inferenceCredentialKind: "interactive" together with inferenceVertexWorkforceAudience (Vertex AI)` (accepted until October 7, 2026); use "workforce" — or remove inferenceVertexWorkforceAudience if Google sign-in ("interactive") is what is meant. If it is still present after that, the audience will no longer imply Workforce Identity: the kind will stay "interactive" (Google sign-in), which needs inferenceVertexOAuthClientId — without it the configuration will be reported as incomplete and inference will not start. Deprecated: `inferenceCredentialKind: "interactive" together with inferenceGatewayOidc (gateway)`; use "external-idp" once every desktop in the fleet is on a release that reads it. The original spelling will keep working ("interactive" with inferenceGatewayOidc is read as "external-idp"); no end date has been set. |
9292 
9393<AccordionGroup>
9494 <Accordion title="inferenceCustomHeaders details">
from line 159
159159 
160160### Anthropic
161161 
162| Setting | Type | Availability | Default | Description |
163| ------------------------------------------------------------------------------------ | -------- | -------------------------------------- | ------- | --------------------------------------------------------------------------------------------- |
164| <span id="inferenceanthropicapikey" />Claude API key<br />`inferenceAnthropicApiKey` | `string` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Leave blank to fetch a key via browser sign-in, or to supply the key via a credential helper. |
162| Setting | Type | Availability | Default | Description |
163| - | - | - | - | - |
164| <span id="inferenceanthropicapikey" />Claude API key<br />`inferenceAnthropicApiKey` | `string` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Leave blank to fetch a key via browser sign-in, or to supply the key via a credential helper. |
165165 
166166### Bedrock
167167 
168| Setting | Type | Availability | Default | Description |
169| ------------------------------------------------------------------------------------------------ | -------- | --------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------- |
170| <span id="inferencebedrockregion" />AWS region<br />`inferenceBedrockRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS region for the Bedrock runtime endpoint. |
171| <span id="inferencebedrockbaseurl" />Bedrock base URL<br />`inferenceBedrockBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | For VPC endpoints or gateway proxies. Host origin only. |
172| <span id="inferencebedrockservicetier" />Bedrock service tier<br />`inferenceBedrockServiceTier` | `enum` | MDM + Bootstrap<br />Added in 1.5186.0 | — | Sent as the X-Amzn-Bedrock-Service-Tier header. Leave unset for on-demand. One of: `flex`, `priority`. |
173| <span id="inferencebedrockbearertoken" />AWS bearer token<br />`inferenceBedrockBearerToken` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static bearer token for inference. For providers that support profile or helper-script credentials, prefer those. |
174| <span id="inferencebedrockssostarturl" />AWS SSO start URL<br />`inferenceBedrockSsoStartUrl` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | Enables in-app AWS sign-in (no AWS CLI needed). Set with the three SSO fields below. |
175| <span id="inferencebedrockssoregion" />AWS SSO region<br />`inferenceBedrockSsoRegion` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center home region. |
176| <span id="inferencebedrockssoaccountid" />AWS SSO account ID<br />`inferenceBedrockSsoAccountId` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | 12-digit AWS account ID assigned to users in IAM Identity Center. |
177| <span id="inferencebedrockssorolename" />AWS SSO role name<br />`inferenceBedrockSsoRoleName` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center permission-set name granting bedrock:InvokeModel\* on the account above. |
178| <span id="inferencebedrockprofile" />AWS profile name<br />`inferenceBedrockProfile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS named profile to use for Bedrock inference credentials. |
179| <span id="inferencebedrockawsdir" />AWS config directory<br />`inferenceBedrockAwsDir` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folder with AWS config/credentials. Defaults to \~/.aws when no bearer token is set. |
180| <span id="inferencebedrockawsclipath" />AWS CLI path<br />`inferenceBedrockAwsCliPath` | `string` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Absolute path to the aws executable. Leave unset to find it on PATH. |
168| Setting | Type | Availability | Default | Description |
169| - | - | - | - | - |
170| <span id="inferencebedrockregion" />AWS region<br />`inferenceBedrockRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS region for the Bedrock runtime endpoint. |
171| <span id="inferencebedrockbaseurl" />Bedrock base URL<br />`inferenceBedrockBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | For VPC endpoints or gateway proxies. Host origin only. |
172| <span id="inferencebedrockservicetier" />Bedrock service tier<br />`inferenceBedrockServiceTier` | `enum` | MDM + Bootstrap<br />Added in 1.5186.0 | — | Sent as the X-Amzn-Bedrock-Service-Tier header. Leave unset for on-demand. One of: `flex`, `priority`. |
173| <span id="inferencebedrockbearertoken" />AWS bearer token<br />`inferenceBedrockBearerToken` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static bearer token for inference. For providers that support profile or helper-script credentials, prefer those. |
174| <span id="inferencebedrockssostarturl" />AWS SSO start URL<br />`inferenceBedrockSsoStartUrl` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | Enables in-app AWS sign-in (no AWS CLI needed). Set with the three SSO fields below. |
175| <span id="inferencebedrockssoregion" />AWS SSO region<br />`inferenceBedrockSsoRegion` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center home region. |
176| <span id="inferencebedrockssoaccountid" />AWS SSO account ID<br />`inferenceBedrockSsoAccountId` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | 12-digit AWS account ID assigned to users in IAM Identity Center. |
177| <span id="inferencebedrockssorolename" />AWS SSO role name<br />`inferenceBedrockSsoRoleName` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center permission-set name granting bedrock:InvokeModel\* on the account above. |
178| <span id="inferencebedrockprofile" />AWS profile name<br />`inferenceBedrockProfile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS named profile to use for Bedrock inference credentials. |
179| <span id="inferencebedrockawsdir" />AWS config directory<br />`inferenceBedrockAwsDir` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folder with AWS config/credentials. Defaults to \~/.aws when no bearer token is set. |
180| <span id="inferencebedrockawsclipath" />AWS CLI path<br />`inferenceBedrockAwsCliPath` | `string` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Absolute path to the aws executable. Leave unset to find it on PATH. |
181181 
182182<AccordionGroup>
183183 <Accordion title="inferenceBedrockServiceTier details">
from line 187
187187 
188188### Foundry
189189 
190| Setting | Type | Availability | Default | Description |
191| ---------------------------------------------------------------------------------------------------- | -------- | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
192| <span id="inferencefoundryresource" />Azure AI Foundry resource name<br />`inferenceFoundryResource` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Azure AI Foundry resource name used to construct the endpoint URL. |
193| <span id="inferencefoundrybaseurl" />Azure AI Foundry base URL<br />`inferenceFoundryBaseUrl` | `string` | MDM + Bootstrap<br />Added in 2.110.0 | — | Full base URL for a gateway or proxy in front of Foundry, path included (replaces [https://RESOURCE.services.ai.azure.com/anthropic](https://RESOURCE.services.ai.azure.com/anthropic)). |
194| <span id="inferencefoundryapikey" />Azure AI Foundry API key<br />`inferenceFoundryApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for Azure AI Foundry inference. |
195| <span id="inferencefoundrytenantid" />Entra ID tenant ID<br />`inferenceFoundryTenantId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Directory (tenant) ID of the Entra ID app registration that has the Cognitive Services scope. |
196| <span id="inferencefoundryclientid" />Entra ID client ID<br />`inferenceFoundryClientId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Application (client) ID of the Entra ID app registration. Device-code sign-in requires the app to allow public client flows. |
197| <span id="inferencefoundryauthflow" />Entra ID sign-in flow<br />`inferenceFoundryAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | — | How Entra sign-in runs: device code (default), system browser, or the OS identity broker. One of: `device-code`, `browser`, `broker`. |
190| Setting | Type | Availability | Default | Description |
191| - | - | - | - | - |
192| <span id="inferencefoundryresource" />Azure AI Foundry resource name<br />`inferenceFoundryResource` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Azure AI Foundry resource name used to construct the endpoint URL. |
193| <span id="inferencefoundrybaseurl" />Azure AI Foundry base URL<br />`inferenceFoundryBaseUrl` | `string` | MDM + Bootstrap<br />Added in 2.110.0 | — | Full base URL for a gateway or proxy in front of Foundry, path included (replaces [https://RESOURCE.services.ai.azure.com/anthropic](https://RESOURCE.services.ai.azure.com/anthropic)). |
194| <span id="inferencefoundryapikey" />Azure AI Foundry API key<br />`inferenceFoundryApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for Azure AI Foundry inference. |
195| <span id="inferencefoundrytenantid" />Entra ID tenant ID<br />`inferenceFoundryTenantId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Directory (tenant) ID of the Entra ID app registration that has the Cognitive Services scope. |
196| <span id="inferencefoundryclientid" />Entra ID client ID<br />`inferenceFoundryClientId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Application (client) ID of the Entra ID app registration. Device-code sign-in requires the app to allow public client flows. |
197| <span id="inferencefoundryauthflow" />Entra ID sign-in flow<br />`inferenceFoundryAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | — | How Entra sign-in runs: device code (default), system browser, or the OS identity broker. One of: `device-code`, `browser`, `broker`. |
198198 
199199<AccordionGroup>
200200 <Accordion title="inferenceFoundryBaseUrl details">
from line 212
212212 
213213### Gateway
214214 
215| Setting | Type | Availability | Default | Description |
216| --------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
217| <span id="inferencegatewaybaseurl" />Gateway base URL<br />`inferenceGatewayBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Full URL of the inference gateway endpoint. |
218| <span id="inferencestreamidletimeoutsec" />Stream idle timeout<br />`inferenceStreamIdleTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.44121.1 | — | Extra seconds to wait for model output on a streaming response that is sending only keep-alive pings. Gateway provider only. Default 300. Range: 300–1800. |
219| <span id="inferencegatewayapikey" />Gateway API key<br />`inferenceGatewayApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for the configured inference gateway. |
220| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"` (accepted until October 7, 2026); use inferenceCredentialKind: "interactive". If it is still present after that, browser sign-in will no longer be inferred from it — the key will be reported as invalid and, unless inferenceCredentialKind or another credential field (an API key, inferenceGatewayOidc) says how to sign in, the gateway connection will have no credential and inference will not start. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
221| <span id="inferencegatewayoidcauthflow" />Gateway sign-in flow<br />`inferenceGatewayOidcAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. Deprecated: `inferenceGatewayOidcAuthFlow`; use inferenceIdpAuthFlow together with inferenceIdpOidc once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
222| <span id="inferencegatewayoidc" />Gateway SSO IdP (OIDC)<br />`inferenceGatewayOidc` | `object` | MDM + Bootstrap<br />Added in 1.6889.0 | — | External IdP for gateway sign-in. The user’s token from this issuer is sent to the gateway as the Bearer credential. Deprecated: `inferenceGatewayOidc`; use inferenceIdpOidc with inferenceCredentialKind: "external-idp" once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
223| <span id="inferenceidpauthflow" />Identity provider sign-in flow<br />`inferenceIdpAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How the identity-provider sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
224| <span id="inferenceidpoidc" />Identity provider (OIDC)<br />`inferenceIdpOidc` | `object` | MDM + Bootstrap<br />Added in 2.7032.0 | — | Your organization’s OpenID Connect identity provider. The user’s token is sent as the Bearer credential to the gateway or the Bedrock proxy. |
215| Setting | Type | Availability | Default | Description |
216| - | - | - | - | - |
217| <span id="inferencegatewaybaseurl" />Gateway base URL<br />`inferenceGatewayBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Full URL of the inference gateway endpoint. |
218| <span id="inferencestreamidletimeoutsec" />Stream idle timeout<br />`inferenceStreamIdleTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.44121.1 | — | Extra seconds to wait for model output on a streaming response that is sending only keep-alive pings. Gateway provider only. Default 300. Range: 300–1800. |
219| <span id="inferencegatewayapikey" />Gateway API key<br />`inferenceGatewayApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for the configured inference gateway. |
220| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"` (accepted until October 7, 2026); use inferenceCredentialKind: "interactive". If it is still present after that, browser sign-in will no longer be inferred from it — the key will be reported as invalid and, unless inferenceCredentialKind or another credential field (an API key, inferenceGatewayOidc) says how to sign in, the gateway connection will have no credential and inference will not start. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
221| <span id="inferencegatewayoidcauthflow" />Gateway sign-in flow<br />`inferenceGatewayOidcAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. Deprecated: `inferenceGatewayOidcAuthFlow`; use inferenceIdpAuthFlow together with inferenceIdpOidc once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
222| <span id="inferencegatewayoidc" />Gateway SSO IdP (OIDC)<br />`inferenceGatewayOidc` | `object` | MDM + Bootstrap<br />Added in 1.6889.0 | — | External IdP for gateway sign-in. The user’s token from this issuer is sent to the gateway as the Bearer credential. Deprecated: `inferenceGatewayOidc`; use inferenceIdpOidc with inferenceCredentialKind: "external-idp" once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
223| <span id="inferenceidpauthflow" />Identity provider sign-in flow<br />`inferenceIdpAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How the identity-provider sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
224| <span id="inferenceidpoidc" />Identity provider (OIDC)<br />`inferenceIdpOidc` | `object` | MDM + Bootstrap<br />Added in 2.7032.0 | — | Your organization’s OpenID Connect identity provider. The user’s token is sent as the Bearer credential to the gateway or the Bedrock proxy. |
225225 
226226<AccordionGroup>
227227 <Accordion title="inferenceStreamIdleTimeoutSec details">
from line 246
246246 
247247 **Refresh.** With `offline_access` the app renews the token silently and prompts a browser sign-in only when refresh fails. Google never returns an `id_token` on refresh, so a Google Workspace-backed gateway in `id_token` mode re-prompts about hourly; `access_token` mode is unaffected.
248248 
249 | Field | Type | Default | Description |
250 | --------------------------------- | --------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
251 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
252 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
253 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
254 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
255 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
256 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
257 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
258 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
259 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
260 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
261 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
249 | Field | Type | Default | Description |
250 | - | - | - | - |
251 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
252 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
253 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
254 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
255 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
256 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
257 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
258 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
259 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
260 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
261 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
262262 </Accordion>
263263 
264264 <Accordion title="inferenceIdpAuthFlow details">
from line 279
279279 
280280 **Older names.** Gateway configurations written before this key use `inferenceGatewayOidc` / `inferenceGatewayOidcAuthFlow` with the `interactive` kind; they stay readable and mean the same sign-in.
281281 
282 | Field | Type | Default | Description |
283 | --------------------------------- | --------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
284 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
285 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
286 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
287 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
288 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
289 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
290 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
291 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
292 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
293 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
294 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
282 | Field | Type | Default | Description |
283 | - | - | - | - |
284 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
285 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
286 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
287 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
288 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
289 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
290 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
291 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
292 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
293 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
294 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
295295 </Accordion>
296296</AccordionGroup>
297297 
298298### Models
299299 
300| Setting | Type | Availability | Default | Description |
301| --------------------------------------------------------------------------------------------------------------- | ---------- | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
302| <span id="modeldiscoveryenabled" />Model discovery<br />`modelDiscoveryEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Auto-populate the model picker from the provider at launch. |
303| <span id="modelprefer1mcontext" />Default to 1M context<br />`modelPrefer1mContext` | `boolean` | MDM + Bootstrap<br />Added in 1.28929.0 | — | When a user has no saved selection, start the picker on the 1M-context variant of the default model if it offers one. |
304| <span id="inferencemodels" />Model list<br />`inferenceModels` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Override the auto-discovered model list. First entry is the default. |
305| <span id="defaultmodeleffort" />Default model effort<br />`defaultModelEffort` | `enum` | MDM + Bootstrap<br />Added in 2.110.0 | — | Effort level the default model (the first listed model) starts at, instead of Anthropic’s recommended level: low, medium, high, xhigh or max. One of: `low`, `medium`, `high`, `xhigh`, `max`. |
306| <span id="alwaysstartwithdefaultmodel" />Always start with the default model<br />`alwaysStartWithDefaultModel` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | When true, each new conversation or task starts on the default model, and a person’s model and effort changes are no longer saved as their default. |
307| <span id="inferencemodelpricingenabled" />Show estimated cost<br />`inferenceModelPricingEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Show an estimated cost on the Usage page at Anthropic list price; turn on to set a multiplier or per-model rates. |
308| <span id="inferencemodelpricingmultiplier" />Price multiplier<br />`inferenceModelPricingMultiplier` | `number` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Scales every estimated cost (0.85 = 85% of the price); between 0 and 1. Range: 0–1. |
309| <span id="inferencemodelpricing" />Model pricing<br />`inferenceModelPricing` | `object[]` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Per-model rates replacing Anthropic list price in the Usage page’s estimate. |
310| <span id="modelcatalogenabled" />Model catalog metadata<br />`modelCatalogEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | Label and describe the model picker’s entries from the published Claude Code model catalog, instead of the app’s built-in table. |
311| <span id="modelcatalogurl" />Model catalog URL<br />`modelCatalogUrl` | `string` | MDM + Bootstrap<br />Added in 2.110.0 | — | Fetch the model catalog and its signature file from this URL (a mirror inside your network serving Anthropic’s published files) instead of downloads.claude.ai. |
300| Setting | Type | Availability | Default | Description |
301| - | - | - | - | - |
302| <span id="modeldiscoveryenabled" />Model discovery<br />`modelDiscoveryEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Auto-populate the model picker from the provider at launch. |
303| <span id="modelprefer1mcontext" />Default to 1M context<br />`modelPrefer1mContext` | `boolean` | MDM + Bootstrap<br />Added in 1.28929.0 | — | When a user has no saved selection, start the picker on the 1M-context variant of the default model if it offers one. |
304| <span id="inferencemodels" />Model list<br />`inferenceModels` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Override the auto-discovered model list. First entry is the default. |
305| <span id="defaultmodeleffort" />Default model effort<br />`defaultModelEffort` | `enum` | MDM + Bootstrap<br />Added in 2.110.0 | — | Effort level the default model (the first listed model) starts at, instead of Anthropic’s recommended level: low, medium, high, xhigh or max. One of: `low`, `medium`, `high`, `xhigh`, `max`. |
306| <span id="alwaysstartwithdefaultmodel" />Always start with the default model<br />`alwaysStartWithDefaultModel` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | When true, each new conversation or task starts on the default model, and a person’s model and effort changes are no longer saved as their default. |
307| <span id="inferencemodelpricingenabled" />Show estimated cost<br />`inferenceModelPricingEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Show an estimated cost on the Usage page at Anthropic list price; turn on to set a multiplier or per-model rates. |
308| <span id="inferencemodelpricingmultiplier" />Price multiplier<br />`inferenceModelPricingMultiplier` | `number` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Scales every estimated cost (0.85 = 85% of the price); between 0 and 1. Range: 0–1. |
309| <span id="inferencemodelpricing" />Model pricing<br />`inferenceModelPricing` | `object[]` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Per-model rates replacing Anthropic list price in the Usage page’s estimate. |
310| <span id="modelcatalogenabled" />Model catalog metadata<br />`modelCatalogEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | Label and describe the model picker’s entries from the published Claude Code model catalog, instead of the app’s built-in table. |
311| <span id="modelcatalogurl" />Model catalog URL<br />`modelCatalogUrl` | `string` | MDM + Bootstrap<br />Added in 2.110.0 | — | Fetch the model catalog and its signature file from this URL (a mirror inside your network serving Anthropic’s published files) instead of downloads.claude.ai. |
312312 
313313<AccordionGroup>
314314 <Accordion title="modelDiscoveryEnabled details">
from line 344
344344 [{"name": "us.anthropic.claude-opus-4-8", "anthropicFamilyTier": "opus"}]
345345 ```
346346 
347 | Field | Type | Default | Description |
348 | --------------------- | --------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
349 | `name` | `string` | — | Model ID exactly as the provider expects it. The first entry is the default model. |
350 | `labelOverride` | `string` | — | Shown in the model picker. Leave blank to auto-format from the ID. |
351 | `supports1m` | `boolean` | — | Adds a 1M-context variant of this model to the picker. Set only if the deployment accepts 1M-token context for it. |
352 | `prefer1m` | `boolean` | — | Make the 1M-context variant the default picker selection when this model is the default (first) entry. Users can still choose the standard variant. |
353 | `anthropicFamilyTier` | `enum` | — | Which Claude tier this model stands in for. Pins the bare alias (e.g. ‘opus’) and, for opus/fable, the refusal fallback. One of: `sonnet`, `opus`, `haiku`, `fable`, `mythos`. |
354 | `isFamilyDefault` | `boolean` | — | When several models share a tier alias, marks this one as the model the alias resolves to. Otherwise the first listed wins. |
355 | `maxEffort` | `enum` | — | Highest effort level offered for this model; higher levels are hidden and never requested by Claude Desktop. An unrecognized value caps the model at low. One of: `low`, `medium`, `high`, `xhigh`, `max`. |
347 | Field | Type | Default | Description |
348 | - | - | - | - |
349 | `name` | `string` | — | Model ID exactly as the provider expects it. The first entry is the default model. |
350 | `labelOverride` | `string` | — | Shown in the model picker. Leave blank to auto-format from the ID. |
351 | `supports1m` | `boolean` | — | Adds a 1M-context variant of this model to the picker. Set only if the deployment accepts 1M-token context for it. |
352 | `prefer1m` | `boolean` | — | Make the 1M-context variant the default picker selection when this model is the default (first) entry. Users can still choose the standard variant. |
353 | `anthropicFamilyTier` | `enum` | — | Which Claude tier this model stands in for. Pins the bare alias (e.g. ‘opus’) and, for opus/fable, the refusal fallback. One of: `sonnet`, `opus`, `haiku`, `fable`, `mythos`. |
354 | `isFamilyDefault` | `boolean` | — | When several models share a tier alias, marks this one as the model the alias resolves to. Otherwise the first listed wins. |
355 | `maxEffort` | `enum` | — | Highest effort level offered for this model; higher levels are hidden and never requested by Claude Desktop. An unrecognized value caps the model at low. One of: `low`, `medium`, `high`, `xhigh`, `max`. |
356356 </Accordion>
357357 
358358 <Accordion title="defaultModelEffort details">
from line 380
380380 
381381 These are estimates for visibility, not an invoice; your provider bills at its own rates. A machine-level Claude Code managed `modelPricing` (MDM / managed-settings.json / server-managed) takes precedence over this table.
382382 
383 | Field | Type | Default | Description |
384 | ------------------- | -------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
385 | `name` | `string` | — | A model ID from the list above, or any other ID or alias your provider serves. A built-in Claude ID also covers its dated and provider forms. |
386 | `inputPerMtok` | `number` | — | USD per million input tokens. |
387 | `outputPerMtok` | `number` | — | USD per million output tokens. |
388 | `cacheReadPerMtok` | `number` | — | USD per million prompt-cache read tokens. |
389 | `cacheWritePerMtok` | `number` | — | USD per million prompt-cache write tokens (5-minute and 1-hour writes alike). |
383 | Field | Type | Default | Description |
384 | - | - | - | - |
385 | `name` | `string` | — | A model ID from the list above, or any other ID or alias your provider serves. A built-in Claude ID also covers its dated and provider forms. |
386 | `inputPerMtok` | `number` | — | USD per million input tokens. |
387 | `outputPerMtok` | `number` | — | USD per million output tokens. |
388 | `cacheReadPerMtok` | `number` | — | USD per million prompt-cache read tokens. |
389 | `cacheWritePerMtok` | `number` | — | USD per million prompt-cache write tokens (5-minute and 1-hour writes alike). |
390390 </Accordion>
391391 
392392 <Accordion title="modelCatalogEnabled details">
from line 400
400400 
401401### Vertex
402402 
403| Setting | Type | Availability | Default | Description |
404| ------------------------------------------------------------------------------------------------------------------------------ | -------- | --------------------------------------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
405| <span id="inferencevertexprojectid" />GCP project ID<br />`inferenceVertexProjectId` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Google Cloud project ID for Vertex AI inference. |
406| <span id="inferencevertexregion" />GCP region<br />`inferenceVertexRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | GCP region where your Vertex AI Claude models are deployed. |
407| <span id="inferencevertexbaseurl" />Vertex AI base URL<br />`inferenceVertexBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | PSC endpoint, if using one. |
408| <span id="inferencevertexoauthclientid" />Vertex OAuth client ID<br />`inferenceVertexOAuthClientId` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Desktop-app OAuth client ID. Enables Sign in with Google instead of a credentials file. |
409| <span id="inferencevertexoauthclientsecret" />Vertex OAuth client secret<br />`inferenceVertexOAuthClientSecret` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Secret for the Desktop-app OAuth client above. Google classifies installed-app client secrets as non-confidential, so this may be set from hosted config. |
410| <span id="inferencevertexoauthscopes" />Vertex OAuth scopes<br />`inferenceVertexOAuthScopes` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Override the Google OAuth scopes (space-separated). Leave blank for the default. |
411| <span id="inferencevertexoauthloginhint" />Vertex OAuth login hint<br />`inferenceVertexOAuthLoginHint` | `string` | MDM + Bootstrap<br />Added in 1.12603.0 | — | Pre-fill Google's account chooser and forward to your federated IdP. \{username} expands to the OS login name. |
412| <span id="inferencevertexworkforceaudience" />Workforce Identity audience<br />`inferenceVertexWorkforceAudience` | `string` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Workforce-pool provider audience. When set, sign-in uses your own IdP plus a GCP STS exchange instead of a Google identity. |
413| <span id="inferencevertexworkforceuserproject" />Workforce Identity billing project<br />`inferenceVertexWorkforceUserProject` | `string` | MDM + Bootstrap<br />Added in 1.10628.0 | — | GCP project for STS billing and quota. Defaults to the Vertex project ID above. |
414| <span id="inferencevertexworkforceauthflow" />Workforce Identity sign-in flow<br />`inferenceVertexWorkforceAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
415| <span id="inferencevertexworkforceoidc" />Workforce Identity IdP (OIDC)<br />`inferenceVertexWorkforceOidc` | `object` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Your organization’s OIDC IdP. The app runs an authorization-code-with-PKCE flow against this issuer and exchanges the returned ID token at GCP STS. |
416| <span id="inferencevertexcredentialsfile" />GCP credentials file path<br />`inferenceVertexCredentialsFile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Absolute path to service-account JSON. Leave blank to fall back to ADC. |
403| Setting | Type | Availability | Default | Description |
404| - | - | - | - | - |
405| <span id="inferencevertexprojectid" />GCP project ID<br />`inferenceVertexProjectId` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Google Cloud project ID for Vertex AI inference. |
406| <span id="inferencevertexregion" />GCP region<br />`inferenceVertexRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | GCP region where your Vertex AI Claude models are deployed. |
407| <span id="inferencevertexbaseurl" />Vertex AI base URL<br />`inferenceVertexBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | PSC endpoint, if using one. |
408| <span id="inferencevertexoauthclientid" />Vertex OAuth client ID<br />`inferenceVertexOAuthClientId` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Desktop-app OAuth client ID. Enables Sign in with Google instead of a credentials file. |
409| <span id="inferencevertexoauthclientsecret" />Vertex OAuth client secret<br />`inferenceVertexOAuthClientSecret` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Secret for the Desktop-app OAuth client above. Google classifies installed-app client secrets as non-confidential, so this may be set from hosted config. |
410| <span id="inferencevertexoauthscopes" />Vertex OAuth scopes<br />`inferenceVertexOAuthScopes` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Override the Google OAuth scopes (space-separated). Leave blank for the default. |
411| <span id="inferencevertexoauthloginhint" />Vertex OAuth login hint<br />`inferenceVertexOAuthLoginHint` | `string` | MDM + Bootstrap<br />Added in 1.12603.0 | — | Pre-fill Google's account chooser and forward to your federated IdP. \{username} expands to the OS login name. |
412| <span id="inferencevertexworkforceaudience" />Workforce Identity audience<br />`inferenceVertexWorkforceAudience` | `string` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Workforce-pool provider audience. When set, sign-in uses your own IdP plus a GCP STS exchange instead of a Google identity. |
413| <span id="inferencevertexworkforceuserproject" />Workforce Identity billing project<br />`inferenceVertexWorkforceUserProject` | `string` | MDM + Bootstrap<br />Added in 1.10628.0 | — | GCP project for STS billing and quota. Defaults to the Vertex project ID above. |
414| <span id="inferencevertexworkforceauthflow" />Workforce Identity sign-in flow<br />`inferenceVertexWorkforceAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
415| <span id="inferencevertexworkforceoidc" />Workforce Identity IdP (OIDC)<br />`inferenceVertexWorkforceOidc` | `object` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Your organization’s OIDC IdP. The app runs an authorization-code-with-PKCE flow against this issuer and exchanges the returned ID token at GCP STS. |
416| <span id="inferencevertexcredentialsfile" />GCP credentials file path<br />`inferenceVertexCredentialsFile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Absolute path to service-account JSON. Leave blank to fall back to ADC. |
417417 
418418<AccordionGroup>
419419 <Accordion title="inferenceVertexWorkforceAuthFlow details">
from line 424
424424 </Accordion>
425425 
426426 <Accordion title="inferenceVertexWorkforceOidc details">
427 | Field | Type | Default | Description |
428 | --------------------------------- | --------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
429 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
430 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
431 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
432 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
433 | `scopes` | `string` | — | Space-separated scopes. Defaults to openid profile email offline\_access. |
434 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
435 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
436 | `omitOfflineAccess` | `boolean` | — | Only enable if your IdP rejects the offline\_access scope on this client. Without it the app prompts for sign-in each time the token expires. |
437 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
427 | Field | Type | Default | Description |
428 | - | - | - | - |
429 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
430 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
431 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
432 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
433 | `scopes` | `string` | — | Space-separated scopes. Defaults to openid profile email offline\_access. |
434 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
435 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
436 | `omitOfflineAccess` | `boolean` | — | Only enable if your IdP rejects the offline\_access scope on this client. Without it the app prompts for sign-in each time the token expires. |
437 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
438438 </Accordion>
439439</AccordionGroup>
440440 
from line 442
442442 
443443### Authentication
444444 
445| Setting | Type | Availability | Default | Description |
446| ---------------------------------------------------------------------------------------------------------------- | --------- | -------------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------- |
447| <span id="disabledeploymentmodechooser" />Disable Claude.ai sign-in<br />`disableDeploymentModeChooser` | `boolean` | MDM + Bootstrap<br />Added in 1.3834.0 | `false` | Users see only this provider at the login screen. The option to sign in to Claude.ai is hidden. Defaults to `false`. |
448| <span id="disabledeeplinkregistration" />Disable claude:// deep-link handling<br />`disableDeepLinkRegistration` | `boolean` | MDM + Bootstrap<br />Added in 1.6889.0 | `false` | Stop external apps and websites from opening Claude Desktop via claude:// links. Defaults to `false`. |
445| Setting | Type | Availability | Default | Description |
446| - | - | - | - | - |
447| <span id="disabledeploymentmodechooser" />Disable Claude.ai sign-in<br />`disableDeploymentModeChooser` | `boolean` | MDM + Bootstrap<br />Added in 1.3834.0 | `false` | Users see only this provider at the login screen. The option to sign in to Claude.ai is hidden. Defaults to `false`. |
448| <span id="disabledeeplinkregistration" />Disable claude:// deep-link handling<br />`disableDeepLinkRegistration` | `boolean` | MDM + Bootstrap<br />Added in 1.6889.0 | `false` | Stop external apps and websites from opening Claude Desktop via claude:// links. Defaults to `false`. |
449449 
450450### Built-in browser
451451 
452| Setting | Type | Availability | Default | Description |
453| ----------------------------------------------------------------------------------------------------------------------------------- | ---------- | -------------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
454| <span id="builtinbrowserenabled" />Allow the built-in browser<br />`builtinBrowserEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.2553.0 | `false` | Offer the built-in browser in Cowork and Code sessions so users and Claude can open and work with web pages. Site sign-ins stay on the device until cleared. Defaults to `false`. |
455| <span id="builtinbrowserdefaultdomainpolicy" />Default site policy in the built-in browser<br />`builtinBrowserDefaultDomainPolicy` | `enum` | MDM + Bootstrap<br />Added in 2.2553.0 | `allow` | Whether Claude may open sites in the built-in browser by default; the allowed or blocked list is the exception. Mirrors the Claude in Chrome site policy. One of: `allow`, `block`. Defaults to `allow`. |
456| <span id="builtinbrowseralloweddomains" />Allowed sites in the built-in browser<br />`builtinBrowserAllowedDomains` | `string[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Sites Claude may open, read, and act on in the built-in browser when the default site policy is block. Users can still view other sites. |
457| <span id="builtinbrowserblockeddomains" />Blocked sites in the built-in browser<br />`builtinBrowserBlockedDomains` | `string[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Sites Claude may not open, read, or act on in the built-in browser when the default site policy is allow. Users can still view them. |
452| Setting | Type | Availability | Default | Description |
453| - | - | - | - | - |
454| <span id="builtinbrowserenabled" />Allow the built-in browser<br />`builtinBrowserEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.2553.0 | `false` | Offer the built-in browser in Cowork and Code sessions so users and Claude can open and work with web pages. Site sign-ins stay on the device until cleared. Defaults to `false`. |
455| <span id="builtinbrowserdefaultdomainpolicy" />Default site policy in the built-in browser<br />`builtinBrowserDefaultDomainPolicy` | `enum` | MDM + Bootstrap<br />Added in 2.2553.0 | `allow` | Whether Claude may open sites in the built-in browser by default; the allowed or blocked list is the exception. Mirrors the Claude in Chrome site policy. One of: `allow`, `block`. Defaults to `allow`. |
456| <span id="builtinbrowseralloweddomains" />Allowed sites in the built-in browser<br />`builtinBrowserAllowedDomains` | `string[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Sites Claude may open, read, and act on in the built-in browser when the default site policy is block. Users can still view other sites. |
457| <span id="builtinbrowserblockeddomains" />Blocked sites in the built-in browser<br />`builtinBrowserBlockedDomains` | `string[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Sites Claude may not open, read, or act on in the built-in browser when the default site policy is allow. Users can still view them. |
458458 
459459<AccordionGroup>
460460 <Accordion title="builtinBrowserEnabled details">
from line 494
494494 
495495### Chat surface
496496 
497| Setting | Type | Availability | Default | Description |
498| ---------------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
499| <span id="chattabenabled" />Allow Chat<br />`chatTabEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Enable Chat. Quick questions and drafting. |
500| <span id="chatadvancedfileanalysisenabled" />Advanced file analysis<br />`chatAdvancedFileAnalysisEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.14271.0 | — | Allow Claude to run code in a local sandbox to analyze attached files it can’t read natively — like Excel and PowerPoint. Off by default. |
497| Setting | Type | Availability | Default | Description |
498| - | - | - | - | - |
499| <span id="chattabenabled" />Allow Chat<br />`chatTabEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Enable Chat. Quick questions and drafting. |
500| <span id="chatadvancedfileanalysisenabled" />Advanced file analysis<br />`chatAdvancedFileAnalysisEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.14271.0 | — | Allow Claude to run code in a local sandbox to analyze attached files it can’t read natively — like Excel and PowerPoint. Off by default. |
501501 
502502<AccordionGroup>
503503 <Accordion title="chatAdvancedFileAnalysisEnabled details">
from line 507
507507 
508508### Code surface
509509 
510| Setting | Type | Availability | Default | Description |
511| ------------------------------------------------------------------------------------------ | ---------- | ---------------------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
512| <span id="isclaudecodefordesktopenabled" />Allow Code<br />`isClaudeCodeForDesktopEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `true` | Enable Code. Claude writes and runs code. Defaults to `true`. |
513| <span id="sshhostallowlist" />SSH host allowlist<br />`sshHostAllowlist` | `string[]` | MDM + Bootstrap · Beta<br />Added in 1.40609.0 | — | SSH hosts users may connect to for Code sessions. Empty or unset: off unless the device’s Claude Code managed-settings allowlist applies. \* allows any host. |
514| <span id="sshclientpath" />SSH client program<br />`sshClientPath` | `string` | MDM + Bootstrap · Beta<br />Added in 1.46388.1 | — | Absolute path to the OpenSSH ssh program the app runs for SSH sessions. Unset: the first ssh on the user’s PATH. |
515| <span id="sshtransport" />SSH connection engine<br />`sshTransport` | `enum` | MDM + Bootstrap · Beta<br />Added in 1.52386.0 | — | Which SSH engine carries Code sessions: the OpenSSH ssh program on the device, or the app’s built-in SSH library. Unset or auto: the build’s default. One of: `auto`, `system-openssh`, `builtin`. |
510| Setting | Type | Availability | Default | Description |
511| - | - | - | - | - |
512| <span id="isclaudecodefordesktopenabled" />Allow Code<br />`isClaudeCodeForDesktopEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `true` | Enable Code. Claude writes and runs code. Defaults to `true`. |
513| <span id="sshhostallowlist" />SSH host allowlist<br />`sshHostAllowlist` | `string[]` | MDM + Bootstrap · Beta<br />Added in 1.40609.0 | — | SSH hosts users may connect to for Code sessions. Empty or unset: off unless the device’s Claude Code managed-settings allowlist applies. \* allows any host. |
514| <span id="sshclientpath" />SSH client program<br />`sshClientPath` | `string` | MDM + Bootstrap · Beta<br />Added in 1.46388.1 | — | Absolute path to the OpenSSH ssh program the app runs for SSH sessions. Unset: the first ssh on the user’s PATH. |
515| <span id="sshtransport" />SSH connection engine<br />`sshTransport` | `enum` | MDM + Bootstrap · Beta<br />Added in 1.52386.0 | — | Which SSH engine carries Code sessions: the OpenSSH ssh program on the device, or the app’s built-in SSH library. Unset or auto: the build’s default. One of: `auto`, `system-openssh`, `builtin`. |
516516 
517517<AccordionGroup>
518518 <Accordion title="sshHostAllowlist details">
from line 542
542542 
543543### Cowork surface
544544 
545| Setting | Type | Availability | Default | Description |
546| ------------------------------------------------------------------ | --------- | -------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------- |
547| <span id="coworktabenabled" />Allow Cowork<br />`coworkTabEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.9659.0 | `true` | Enable Cowork. Claude works on longer tasks like research, analysis, and documents. Defaults to `true`. |
545| Setting | Type | Availability | Default | Description |
546| - | - | - | - | - |
547| <span id="coworktabenabled" />Allow Cowork<br />`coworkTabEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.9659.0 | `true` | Enable Cowork. Claude works on longer tasks like research, analysis, and documents. Defaults to `true`. |
548548 
549549### Workspace
550550 
551| Setting | Type | Availability | Default | Description |
552| ----------------------------------------------------------------------------------------------------------------------------------- | ---------- | --------------------------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
553| <span id="userpluginmarketplacesenabled" />Allow user-added plugin marketplaces<br />`userPluginMarketplacesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add plugin marketplaces themselves. When off, the add-marketplace surfaces are hidden and in-app adds are refused. |
554| <span id="userpluginuploadsenabled" />Allow user-added plugins<br />`userPluginUploadsEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add their own plugins. When off, every in-app option for adding one is hidden and uploads that still reach the app are refused. |
555| <span id="disabledbuiltintools" />Disabled built-in tools<br />`disabledBuiltinTools` | `string[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Built-in tools, or argument-scoped permission rules such as Read(\*\*/.env), denied in Cowork and Code. |
556| <span id="disablebundledskills" />Disable bundled skills and workflows<br />`disableBundledSkills` | `boolean` | MDM + Bootstrap<br />Added in 1.15962.0 | — | Disables Claude Code’s bundled skills and workflows (deep-research and similar). Use where WebFetch/WebSearch aren’t available. |
557| <span id="skillcreationenabled" />Allow user-created skills<br />`skillCreationEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.25927.0 | — | Allow users to create and upload their own skills. When off, the creation and upload surfaces are hidden and the agent’s skill-creation tools are disabled. |
558| <span id="scheduledtasksenabled" />Allow scheduled tasks<br />`scheduledTasksEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | Allow scheduled tasks in Cowork and Code. When off, the Scheduled page is hidden, existing tasks stop running, and Claude cannot create new ones. |
559| <span id="keepawakeenabled" />Allow keep awake<br />`keepAwakeEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.7032.0 | — | Let Claude keep the computer awake. When off, Claude never prevents sleep and hides the keep-awake switches in Settings, the Scheduled page and the Code tab. |
560| <span id="builtintoolpolicy" />Built-in tool policy<br />`builtinToolPolicy` | `object` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Approval policy per built-in tool or argument-scoped rule such as Bash(curl \*). “ask” requires user approval before each matching call; “allow” is the default. Deprecated: `builtinToolPolicy: "ask-session"` (accepted until October 7, 2026); use "ask". If it is still present after that, the entry will be read as "ask" (approval on every call), like any unrecognized value. |
561| <span id="automodeenabled" />Allow Auto mode<br />`autoModeEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Offer Auto mode in the Code permission selector (on unless set to false); set to true to also offer it in Cowork. Claude decides which actions need approval. |
562| <span id="disablebypasspermissionsmode" />Disable bypass permissions mode<br />`disableBypassPermissionsMode` | `boolean` | MDM + Bootstrap<br />Added in 1.46388.1 | — | Remove the bypass permissions mode from Code sessions and Cowork tasks, so Claude always follows the permission policy. Off by default. |
563| <span id="toolsearchenabled" />Enable tool search<br />`toolSearchEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.21459.0 | `false` | Load MCP tool schemas on demand (tool search) instead of inlining every schema into context. Defaults to `false`. |
564| <span id="skipwebfetchpreflight" />Skip WebFetch domain check<br />`skipWebFetchPreflight` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Skip Claude Code’s WebFetch domain lookup against api.anthropic.com in Code sessions. Off by default; turn on when that host is blocked. |
565| <span id="allowedworkspacefolders" />Allowed workspace folders<br />`allowedWorkspaceFolders` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folders where Claude may work. Applies to both Cowork and Code sessions. Leave unset for unrestricted access. |
566| <span id="blockreadsoutsideworkingdirectories" />Block reads outside working directories<br />`blockReadsOutsideWorkingDirectories` | `boolean` | MDM + Bootstrap<br />Added in 1.46388.1 | — | Keep Claude from reading files outside a Code session’s working directories. File tools refuse such reads; sandboxed shell commands lose the home directory. |
567| <span id="coworkegressallowedhosts" />Allowed egress hosts<br />`coworkEgressAllowedHosts` | `string[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Hostnames the agent’s tools may reach from Cowork and Code sessions. Also surfaced under Egress Requirements. |
568| <span id="requirecoworkfullvmsandbox" />Require full VM sandbox<br />`requireCoworkFullVmSandbox` | `boolean` | MDM + Bootstrap · Deprecated<br />Added in 1.2581.0 | `false` | Runs tools inside an isolated VM instead of the host. Stronger isolation; slower file access and no host-process tools. Defaults to `false`. |
569| <span id="organizationinstructions" />Organization instructions<br />`organizationInstructions` | `string` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Appended to Claude’s system prompt in Chat, Cowork, and Code. Guidance the model follows, not an enforced control. Up to 3,000 characters. |
551| Setting | Type | Availability | Default | Description |
552| - | - | - | - | - |
553| <span id="userpluginmarketplacesenabled" />Allow user-added plugin marketplaces<br />`userPluginMarketplacesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add plugin marketplaces themselves. When off, the add-marketplace surfaces are hidden and in-app adds are refused. |
554| <span id="userpluginuploadsenabled" />Allow user-added plugins<br />`userPluginUploadsEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add their own plugins. When off, every in-app option for adding one is hidden and uploads that still reach the app are refused. |
555| <span id="disabledbuiltintools" />Disabled built-in tools<br />`disabledBuiltinTools` | `string[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Built-in tools, or argument-scoped permission rules such as Read(\*\*/.env), denied in Cowork and Code. |
556| <span id="disablebundledskills" />Disable bundled skills and workflows<br />`disableBundledSkills` | `boolean` | MDM + Bootstrap<br />Added in 1.15962.0 | — | Disables Claude Code’s bundled skills and workflows (deep-research and similar). Use where WebFetch/WebSearch aren’t available. |
557| <span id="skillcreationenabled" />Allow user-created skills<br />`skillCreationEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.25927.0 | — | Allow users to create and upload their own skills. When off, the creation and upload surfaces are hidden and the agent’s skill-creation tools are disabled. |
558| <span id="scheduledtasksenabled" />Allow scheduled tasks<br />`scheduledTasksEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | Allow scheduled tasks in Cowork and Code. When off, the Scheduled page is hidden, existing tasks stop running, and Claude cannot create new ones. |
559| <span id="keepawakeenabled" />Allow keep awake<br />`keepAwakeEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.7032.0 | — | Let Claude keep the computer awake. When off, Claude never prevents sleep and hides the keep-awake switches in Settings, the Scheduled page and the Code tab. |
560| <span id="builtintoolpolicy" />Built-in tool policy<br />`builtinToolPolicy` | `object` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Approval policy per built-in tool or argument-scoped rule such as Bash(curl \*). “ask” requires user approval before each matching call; “allow” is the default. Deprecated: `builtinToolPolicy: "ask-session"` (accepted until October 7, 2026); use "ask". If it is still present after that, the entry will be read as "ask" (approval on every call), like any unrecognized value. |
561| <span id="automodeenabled" />Allow Auto mode<br />`autoModeEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Offer Auto mode in the Code permission selector (on unless set to false); set to true to also offer it in Cowork. Claude decides which actions need approval. |
562| <span id="disablebypasspermissionsmode" />Disable bypass permissions mode<br />`disableBypassPermissionsMode` | `boolean` | MDM + Bootstrap<br />Added in 1.46388.1 | — | Remove the bypass permissions mode from Code sessions and Cowork tasks, so Claude always follows the permission policy. Off by default. |
563| <span id="toolsearchenabled" />Enable tool search<br />`toolSearchEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.21459.0 | `false` | Load MCP tool schemas on demand (tool search) instead of inlining every schema into context. Defaults to `false`. |
564| <span id="skipwebfetchpreflight" />Skip WebFetch domain check<br />`skipWebFetchPreflight` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Skip Claude Code’s WebFetch domain lookup against api.anthropic.com in Code sessions. Off by default; turn on when that host is blocked. |
565| <span id="allowedworkspacefolders" />Allowed workspace folders<br />`allowedWorkspaceFolders` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folders where Claude may work. Applies to both Cowork and Code sessions. Leave unset for unrestricted access. |
566| <span id="blockreadsoutsideworkingdirectories" />Block reads outside working directories<br />`blockReadsOutsideWorkingDirectories` | `boolean` | MDM + Bootstrap<br />Added in 1.46388.1 | — | Keep Claude from reading files outside a Code session’s working directories. File tools refuse such reads; sandboxed shell commands lose the home directory. |
567| <span id="coworkegressallowedhosts" />Allowed egress hosts<br />`coworkEgressAllowedHosts` | `string[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Hostnames the agent’s tools may reach from Cowork and Code sessions. Also surfaced under Egress Requirements. |
568| <span id="requirecoworkfullvmsandbox" />Require full VM sandbox<br />`requireCoworkFullVmSandbox` | `boolean` | MDM + Bootstrap · Deprecated<br />Added in 1.2581.0 | `false` | Runs tools inside an isolated VM instead of the host. Stronger isolation; slower file access and no host-process tools. Defaults to `false`. |
569| <span id="organizationinstructions" />Organization instructions<br />`organizationInstructions` | `string` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Appended to Claude’s system prompt in Chat, Cowork, and Code. Guidance the model follows, not an enforced control. Up to 3,000 characters. |
570570 
571571<AccordionGroup>
572572 <Accordion title="userPluginMarketplacesEnabled details">
from line 654
654654 
655655 Each folder is interpreted on the machine the session runs on. For a Code session on an SSH host, `~` means the remote user's home, an entry that references a `%VAR%` is ignored there (environment variables belong to the machine that defines them), and the session's working directory must fall inside one of the folders as they exist on that host. One list serves every machine: `["/Users", "~"]` governs `/Users` on a managed Mac and the signed-in user's home on a Linux host. A folder that names nothing real on a given machine simply allows nothing there. An empty list allows no folder at all; unset leaves access unrestricted.
656656 
657 | Field | Type | Default | Description |
658 | ------------------- | --------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
659 | `path` | `string` | — | Absolute folder path. May start with \~ or one of the listed %VAR% tokens, expanded per user. Subfolders are included. |
660 | `isDefaultSelected` | `boolean` | — | Shows as a folder chip on the new-task page and skips the trust prompt. Users can remove it. |
661 | `mode` | `enum` | — | Read-only folders can be viewed and searched but not modified in Cowork. In Code, applies to file tools only; Bash and SSH do not yet enforce read-only. One of: `rw`, `ro`. |
657 | Field | Type | Default | Description |
658 | - | - | - | - |
659 | `path` | `string` | — | Absolute folder path. May start with \~ or one of the listed %VAR% tokens, expanded per user. Subfolders are included. |
660 | `isDefaultSelected` | `boolean` | — | Shows as a folder chip on the new-task page and skips the trust prompt. Users can remove it. |
661 | `mode` | `enum` | — | Read-only folders can be viewed and searched but not modified in Cowork. In Code, applies to file tools only; Bash and SSH do not yet enforce read-only. One of: `rw`, `ro`. |
662662 </Accordion>
663663 
664664 <Accordion title="blockReadsOutsideWorkingDirectories details">
from line 690
690690 
691691## Connectors
692692 
693| Setting | Type | Availability | Default | Description |
694| ----------------------------------------------------------------------- | -------- | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
695| <span id="claudeaiimport" />Claude.ai data import<br />`claudeAiImport` | `object` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Lets users import Claude.ai chats and projects, plus earlier Claude sessions on this computer, when `enabled` is true. `automatic3pImport` is a separate switch. |
693| Setting | Type | Availability | Default | Description |
694| - | - | - | - | - |
695| <span id="claudeaiimport" />Claude.ai data import<br />`claudeAiImport` | `object` | MDM + Bootstrap<br />Added in 1.10628.0 | — | Lets users import Claude.ai chats and projects, plus earlier Claude sessions on this computer, when `enabled` is true. `automatic3pImport` is a separate switch. |
696696 
697697<AccordionGroup>
698698 <Accordion title="claudeAiImport details">
699 | Field | Type | Default | Description |
700 | -------------------------- | --------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
701 | `enabled` | `boolean` | `false` | Lets users import a Claude.ai data export and earlier Claude sessions on this computer from Settings → Import. Doesn’t affect a provisioned sign-in import. |
702 | `automatic3pImport` · Beta | `boolean` | `false` | Copy this computer’s earlier third-party sessions into the app once, in the background. Independent of `enabled`. |
703 | `exportEnabled` | `boolean` | `false` | Lets users export this computer’s chats, Cowork tasks, and Code sessions as a zip another install can import. No effect unless `enabled` is true. |
704 | `bannerBehavior` | `enum` | — | Prompt to import on a new chat or task. Off if unset. `show`: always; needs `enabled` or a sign-in import. `detect`: if `enabled` finds earlier Claude sessions. One of: `off`, `detect`, `show`. |
699 | Field | Type | Default | Description |
700 | - | - | - | - |
701 | `enabled` | `boolean` | `false` | Lets users import a Claude.ai data export and earlier Claude sessions on this computer from Settings → Import. Doesn’t affect a provisioned sign-in import. |
702 | `automatic3pImport` · Beta | `boolean` | `false` | Copy this computer’s earlier third-party sessions into the app once, in the background. Independent of `enabled`. |
703 | `exportEnabled` | `boolean` | `false` | Lets users export this computer’s chats, Cowork tasks, and Code sessions as a zip another install can import. No effect unless `enabled` is true. |
704 | `bannerBehavior` | `enum` | — | Prompt to import on a new chat or task. Off if unset. `show`: always; needs `enabled` or a sign-in import. `detect`: if `enabled` finds earlier Claude sessions. One of: `off`, `detect`, `show`. |
705705 </Accordion>
706706</AccordionGroup>
707707 
708708### Authentication
709709 
710| Setting | Type | Availability | Default | Description |
711| ----------------------------------------------------------------------------------------------- | ------ | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
712| <span id="microsoftauthbroker" />Microsoft 365 native sign-in broker<br />`microsoftAuthBroker` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | `auto` | “disabled” forces browser-based Microsoft 365 sign-in; “required” fails sign-in when the OS broker is unavailable, so the refresh token stays broker-held. One of: `auto`, `disabled`, `required`. Defaults to `auto`. |
710| Setting | Type | Availability | Default | Description |
711| - | - | - | - | - |
712| <span id="microsoftauthbroker" />Microsoft 365 native sign-in broker<br />`microsoftAuthBroker` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | `auto` | “disabled” forces browser-based Microsoft 365 sign-in; “required” fails sign-in when the OS broker is unavailable, so the refresh token stays broker-held. One of: `auto`, `disabled`, `required`. Defaults to `auto`. |
713713 
714714<AccordionGroup>
715715 <Accordion title="microsoftAuthBroker details">
from line 719
719719 
720720### Extensions
721721 
722| Setting | Type | Availability | Default | Description |
723| --------------------------------------------------------------------------------------------------------------------- | --------- | -------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
724| <span id="isdesktopextensionenabled" />Allow desktop extensions<br />`isDesktopExtensionEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | .dxt and .mcpb installs. Defaults to `false`. Previously named `isDxtEnabled` (the old name is accepted until October 7, 2026). If it is still present after that, the old name will be reported as unreadable and the key will read as false: desktop extensions will be disabled until the name is updated. |
722| Setting | Type | Availability | Default | Description |
723| - | - | - | - | - |
724| <span id="isdesktopextensionenabled" />Allow desktop extensions<br />`isDesktopExtensionEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | .dxt and .mcpb installs. Defaults to `false`. Previously named `isDxtEnabled` (the old name is accepted until October 7, 2026). If it is still present after that, the old name will be reported as unreadable and the key will read as false: desktop extensions will be disabled until the name is updated. |
725725| <span id="isdesktopextensionsignaturerequired" />Require signed extensions<br />`isDesktopExtensionSignatureRequired` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Reject desktop extensions that are not signed by a trusted publisher. Defaults to `false`. Previously named `isDxtSignatureRequired` (the old name is accepted until October 7, 2026). If it is still present after that, the old name will be reported as unreadable and the key will read as true: only signed extensions will load until the name is updated. |
726726 
727727<AccordionGroup>
from line 732
732732 
733733### MCP
734734 
735| Setting | Type | Availability | Default | Description |
736| ----------------------------------------------------------------------------------------------------------------------------------- | ---------- | --------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
737| <span id="managedmcpservers" />Managed MCP servers<br />`managedMcpServers` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Org-pushed MCP servers: remote (HTTP/SSE) or local (stdio command). May embed bearer tokens. Deprecated: `managedMcpServers[].scopes` (accepted until October 7, 2026); use scope (one space-separated string, for example "Mail.Read Calendars.Read"). If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].toolPolicy: "ask-session"` (accepted until October 7, 2026); use "ask". If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].transport: "builtin"` (accepted until October 7, 2026); no longer needed — safe to remove. If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].authorityHost` (accepted until October 7, 2026); use azureCloud: "us-gov-high" for a GCC High tenant; otherwise nothing. If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten — the Microsoft 365 connector will disappear rather than guess a cloud. Deprecated: `managedMcpServers[].source` (accepted until October 7, 2026); no longer needed — safe to remove. If it is still present after that, it will be treated as any unrecognised entry member — ignored by the desktop (the connector still loads; the app assigns each connector's provenance itself) and refused by a customer-run Apps Gateway serving the configuration. Deprecated: `managedMcpServers[].oauth as a number or string` (accepted until October 7, 2026); use true (automatic registration) or an oauth object. If it is still present after that, it will be treated as any wrong-typed member: the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].oauth.scopes (or oauth.scope as a list)` (accepted until October 7, 2026); use oauth.scope as one space-separated string, for example "read write". If it is still present after that, it will be treated as any wrong-typed member: the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[] entry without transport` (accepted until October 7, 2026); use transport: "http" (or "sse" / "stdio") on every entry that is not a built-in server. If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. |
738| <span id="mcppersistentalwaysallowenabled" />Allow persistent tool approvals<br />`mcpPersistentAlwaysAllowEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.24012.9 | `true` | Offer the persistent “Always allow” approval options for MCP tools. Disable to keep tool approvals per-call or session-scoped only. Defaults to `true`. |
739| <span id="mcpscheduledtaskapprovallifetimedays" />Scheduled-task tool approval lifetime<br />`mcpScheduledTaskApprovalLifetimeDays` | `integer` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How many days a scheduled task may reuse a lasting MCP-tool approval before it asks again. 0 removes the lasting option. Range: 0–3650. |
740| <span id="islocaldevmcpenabled" />Allow user-added MCP servers<br />`isLocalDevMcpEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `true` | Local stdio servers added via the Developer settings. Remote servers come from the managed list above or organization plugins. Defaults to `true`. |
741| <span id="allowedpluginmcpservers" />Allowed plugin MCP servers<br />`allowedPluginMcpServers` | `object[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Servers plugins may connect in sessions, beyond the managed list above and organization plugins. An empty list allows none; unset keeps today’s rules. |
742| <span id="mcptooltimeoutsec" />MCP tool call timeout<br />`mcpToolTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Per-call timeout for MCP tool calls, in seconds. Default 180 (3 minutes). Range: 60–3600. |
735| Setting | Type | Availability | Default | Description |
736| - | - | - | - | - |
737| <span id="managedmcpservers" />Managed MCP servers<br />`managedMcpServers` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Org-pushed MCP servers: remote (HTTP/SSE) or local (stdio command). May embed bearer tokens. Deprecated: `managedMcpServers[].scopes` (accepted until October 7, 2026); use scope (one space-separated string, for example "Mail.Read Calendars.Read"). If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].toolPolicy: "ask-session"` (accepted until October 7, 2026); use "ask". If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].transport: "builtin"` (accepted until October 7, 2026); no longer needed — safe to remove. If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].authorityHost` (accepted until October 7, 2026); use azureCloud: "us-gov-high" for a GCC High tenant; otherwise nothing. If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten — the Microsoft 365 connector will disappear rather than guess a cloud. Deprecated: `managedMcpServers[].source` (accepted until October 7, 2026); no longer needed — safe to remove. If it is still present after that, it will be treated as any unrecognised entry member — ignored by the desktop (the connector still loads; the app assigns each connector's provenance itself) and refused by a customer-run Apps Gateway serving the configuration. Deprecated: `managedMcpServers[].oauth as a number or string` (accepted until October 7, 2026); use true (automatic registration) or an oauth object. If it is still present after that, it will be treated as any wrong-typed member: the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[].oauth.scopes (or oauth.scope as a list)` (accepted until October 7, 2026); use oauth.scope as one space-separated string, for example "read write". If it is still present after that, it will be treated as any wrong-typed member: the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. Deprecated: `managedMcpServers[] entry without transport` (accepted until October 7, 2026); use transport: "http" (or "sse" / "stdio") on every entry that is not a built-in server. If it is still present after that, the entry will be rejected as invalid and that connector will be unavailable until the entry is rewritten. |
738| <span id="mcppersistentalwaysallowenabled" />Allow persistent tool approvals<br />`mcpPersistentAlwaysAllowEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.24012.9 | `true` | Offer the persistent “Always allow” approval options for MCP tools. Disable to keep tool approvals per-call or session-scoped only. Defaults to `true`. |
739| <span id="mcpscheduledtaskapprovallifetimedays" />Scheduled-task tool approval lifetime<br />`mcpScheduledTaskApprovalLifetimeDays` | `integer` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How many days a scheduled task may reuse a lasting MCP-tool approval before it asks again. 0 removes the lasting option. Range: 0–3650. |
740| <span id="islocaldevmcpenabled" />Allow user-added MCP servers<br />`isLocalDevMcpEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `true` | Local stdio servers added via the Developer settings. Remote servers come from the managed list above or organization plugins. Defaults to `true`. |
741| <span id="allowedpluginmcpservers" />Allowed plugin MCP servers<br />`allowedPluginMcpServers` | `object[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Servers plugins may connect in sessions, beyond the managed list above and organization plugins. An empty list allows none; unset keeps today’s rules. |
742| <span id="mcptooltimeoutsec" />MCP tool call timeout<br />`mcpToolTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Per-call timeout for MCP tool calls, in seconds. Default 180 (3 minutes). Range: 60–3600. |
743743 
744744<AccordionGroup>
745745 <Accordion title="managedMcpServers details">
from line 751
751751 
752752 For the bundled Microsoft 365 connector, the send tools (`outlook_send_mail`, `outlook_send_draft`, `outlook_forward_mail`, `outlook_create_event`, `outlook_update_event`, `teams_send_chat_message`, `teams_send_channel_message`, `teams_reply_channel_message`) cannot be loosened below `ask`; an `allow` setting resolves to `ask`.
753753 
754 | Field | Type | Default | Description |
755 | --------------------------------------- | ---------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
756 | `name` | `string` | — | Unique name for this server. Shown to users and used to key tool policy and sign-in state. |
757 | `server` | `string` | — | Which bundled connector this entry turns on. Set instead of a transport; each built-in server has its own fields. One of: `microsoft365`, `websearch`, `github`. |
758 | `tenantId` | `string` | — | Your organization’s Microsoft Entra directory (tenant) ID. |
759 | `clientId` | `string` | — | OAuth app client ID for this built-in server. |
760 | `azureCloud` | `enum` | — | Microsoft cloud for sign-in and Graph. Leave as global for commercial Microsoft 365; US Government clouds require your own app registration (Client ID). One of: `global`, `us-gov-high`, `us-gov-dod`. |
761 | `continuousAccessEvaluation` | `enum` | `enabled` | Request CAE-capable Microsoft Graph tokens: long-lived (up to about 28 hours) but revocable within minutes. Set “disabled” to keep standard one-hour tokens. One of: `enabled`, `disabled`. |
762 | `scope` | `string` | — | What the server may request at sign-in. If blank, Desktop’s default read set is used. |
763 | `toolPolicy` | `object` | — | Lock the approval state for specific tools. Unlisted tools stay user-controlled. |
764 | `headers` | `object` | — | Static headers sent on every request — routing and tenant headers only. No credentials here; use the headers helper script for tokens and rotating values. |
765 | `headersHelper` | `string` | — | Script that prints the auth header as a JSON object to stdout. Runs before each request (cached for the TTL below). |
766 | `headersHelperTtlSec` | `integer` | — | How long the helper’s headers are reused before it runs again, in seconds. Defaults to 300. |
767 | `headersHelperRefreshBufferSec` | `integer` | — | Seconds before the TTL expires at which the helper re-runs mid-session. Defaults to 60. Keep it larger than the helper’s typical runtime. |
768 | `provider` | `enum` | — | Runs search from the desktop, for inference providers without native web search. Supply the provider’s API key through the headers helper script below. One of: `brave`, `tavily`, `exa`, `custom`. |
769 | `customUrl` | `string` | — | POST endpoint accepting \{q} JSON and returning a results\[] array. Only used when provider is Custom. |
770 | `host` | `string` | — | Leave blank for github.com. For GitHub Enterprise Server, your instance’s base URL. |
771 | `toolsets` | `string` | — | Comma-separated github-mcp-server toolsets to enable. If blank, the bundled server’s default toolsets are used. |
772 | `readOnly` | `boolean` | — | Offer only read tools — the server registers no write tools at all. |
773 | `transport` | `enum` | — | How the app connects: Streamable HTTP, legacy SSE, or a local command (stdio). policy-only connects to nothing; it only sets a plugin server’s tool policy. One of: `http`, `sse`, `stdio`, `policy-only`. |
774 | `url` | `string` | — | HTTPS endpoint of the remote MCP server. |
775 | `oauth` | `object` | — | OAuth for a remote server: true to auto-register a client, a pre-registered client ID with tenant and scope, or mode “hosted” for an Anthropic-signed identity. |
776 | `oauth.clientId` | `string` | — | OAuth client ID from your IdP app registration. Leave unset to auto-register (dynamic client registration) and only narrow scopes. |
777 | `oauth.clientSecret` | `string` | — | Only for IdPs that require one (e.g. Box). Hosted config can store only a Google Desktop-app secret (GOCSPX-…); for other IdPs use the client secret helper. |
778 | `oauth.clientSecretHelper` | `string` | — | Executable that prints the client secret on stdout as a JSON object with a single clientSecret key; any other output is rejected. Overrides the inline value. |
779 | `oauth.authorizationServer` | `string[]` | — | Issuer URLs the OAuth sign-in may use, as a JSON array. Pre-filled by presets; ask your IdP admin if unsure. |
780 | `oauth.authorizationUrl` | `string` | — | Only for IdPs that don’t serve a .well-known discovery document. Set together with Token URL; requires Client ID. |
781 | `oauth.tokenUrl` | `string` | — | Only for IdPs that don’t serve a .well-known discovery document. Set together with Authorization URL; requires Client ID. |
782 | `oauth.tenantId` | `string` | — | Required for single-tenant Entra apps. Leave blank for multi-tenant or non-Microsoft IdPs. |
783 | `oauth.authFlow` | `enum` | — | How Entra sign-in runs for this server: the system browser (default) or the OS identity broker. One of: `browser`, `broker`. |
784 | `oauth.scope` | `string` | — | Space-separated scopes sent on the authorize request. Leave unset to use the scopes the server advertises. Required when Tenant ID is set. |
785 | `oauth.appendOfflineAccess` | `boolean` | — | Adds offline\_access to the authorize request so the IdP returns a refresh token for silent renewal. |
786 | `oauth.callbackHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
787 | `oauth.callbackPort` | `integer` | — | Only set if your IdP requires an exact-match redirect port. Entra accepts any. |
788 | `oauth.additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
789 | `command` | `string` | — | Absolute path to the server executable, run on the user’s machine. |
790 | `args` | `string[]` | — | Arguments passed to the command, one per entry. |
791 | `env` | `object` | — | Environment variables set for the command. |
792 | `envHelper` | `string` | — | Script that prints environment variables as a JSON object to stdout. Runs when the local server starts (cached for the TTL below). |
793 | `envHelperTtlSec` | `integer` | `300` | Maximum age of a cached helper result, in seconds (default 300). Applies when the server starts or restarts. |
794 | `startupTimeoutSec` | `integer` | `120` | Maximum wait in seconds for the server to start and list its tools. |
754 | Field | Type | Default | Description |
755 | - | - | - | - |
756 | `name` | `string` | — | Unique name for this server. Shown to users and used to key tool policy and sign-in state. |
757 | `server` | `string` | — | Which bundled connector this entry turns on. Set instead of a transport; each built-in server has its own fields. One of: `microsoft365`, `websearch`, `github`. |
758 | `tenantId` | `string` | — | Your organization’s Microsoft Entra directory (tenant) ID. |
759 | `clientId` | `string` | — | OAuth app client ID for this built-in server. |
760 | `azureCloud` | `enum` | — | Microsoft cloud for sign-in and Graph. Leave as global for commercial Microsoft 365; US Government clouds require your own app registration (Client ID). One of: `global`, `us-gov-high`, `us-gov-dod`. |
761 | `continuousAccessEvaluation` | `enum` | `enabled` | Request CAE-capable Microsoft Graph tokens: long-lived (up to about 28 hours) but revocable within minutes. Set “disabled” to keep standard one-hour tokens. One of: `enabled`, `disabled`. |
762 | `scope` | `string` | — | What the server may request at sign-in. If blank, Desktop’s default read set is used. |
763 | `toolPolicy` | `object` | — | Lock the approval state for specific tools. Unlisted tools stay user-controlled. |
764 | `headers` | `object` | — | Static headers sent on every request — routing and tenant headers only. No credentials here; use the headers helper script for tokens and rotating values. |
765 | `headersHelper` | `string` | — | Script that prints the auth header as a JSON object to stdout. Runs before each request (cached for the TTL below). |
766 | `headersHelperTtlSec` | `integer` | — | How long the helper’s headers are reused before it runs again, in seconds. Defaults to 300. |
767 | `headersHelperRefreshBufferSec` | `integer` | — | Seconds before the TTL expires at which the helper re-runs mid-session. Defaults to 60. Keep it larger than the helper’s typical runtime. |
768 | `provider` | `enum` | — | Runs search from the desktop, for inference providers without native web search. Supply the provider’s API key through the headers helper script below. One of: `brave`, `tavily`, `exa`, `custom`. |
769 | `customUrl` | `string` | — | POST endpoint accepting \{q} JSON and returning a results\[] array. Only used when provider is Custom. |
770 | `host` | `string` | — | Leave blank for github.com. For GitHub Enterprise Server, your instance’s base URL. |
771 | `toolsets` | `string` | — | Comma-separated github-mcp-server toolsets to enable. If blank, the bundled server’s default toolsets are used. |
772 | `readOnly` | `boolean` | — | Offer only read tools — the server registers no write tools at all. |
773 | `transport` | `enum` | — | How the app connects: Streamable HTTP, legacy SSE, or a local command (stdio). policy-only connects to nothing; it only sets a plugin server’s tool policy. One of: `http`, `sse`, `stdio`, `policy-only`. |
774 | `url` | `string` | — | HTTPS endpoint of the remote MCP server. |
775 | `oauth` | `object` | — | OAuth for a remote server: true to auto-register a client, a pre-registered client ID with tenant and scope, or mode “hosted” for an Anthropic-signed identity. |
776 | `oauth.clientId` | `string` | — | OAuth client ID from your IdP app registration. Leave unset to auto-register (dynamic client registration) and only narrow scopes. |
777 | `oauth.clientSecret` | `string` | — | Only for IdPs that require one (e.g. Box). Hosted config can store only a Google Desktop-app secret (GOCSPX-…); for other IdPs use the client secret helper. |
778 | `oauth.clientSecretHelper` | `string` | — | Executable that prints the client secret on stdout as a JSON object with a single clientSecret key; any other output is rejected. Overrides the inline value. |
779 | `oauth.authorizationServer` | `string[]` | — | Issuer URLs the OAuth sign-in may use, as a JSON array. Pre-filled by presets; ask your IdP admin if unsure. |
780 | `oauth.authorizationUrl` | `string` | — | Only for IdPs that don’t serve a .well-known discovery document. Set together with Token URL; requires Client ID. |
781 | `oauth.tokenUrl` | `string` | — | Only for IdPs that don’t serve a .well-known discovery document. Set together with Authorization URL; requires Client ID. |
782 | `oauth.tenantId` | `string` | — | Required for single-tenant Entra apps. Leave blank for multi-tenant or non-Microsoft IdPs. |
783 | `oauth.authFlow` | `enum` | — | How Entra sign-in runs for this server: the system browser (default) or the OS identity broker. One of: `browser`, `broker`. |
784 | `oauth.scope` | `string` | — | Space-separated scopes sent on the authorize request. Leave unset to use the scopes the server advertises. Required when Tenant ID is set. |
785 | `oauth.appendOfflineAccess` | `boolean` | — | Adds offline\_access to the authorize request so the IdP returns a refresh token for silent renewal. |
786 | `oauth.callbackHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
787 | `oauth.callbackPort` | `integer` | — | Only set if your IdP requires an exact-match redirect port. Entra accepts any. |
788 | `oauth.additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
789 | `command` | `string` | — | Absolute path to the server executable, run on the user’s machine. |
790 | `args` | `string[]` | — | Arguments passed to the command, one per entry. |
791 | `env` | `object` | — | Environment variables set for the command. |
792 | `envHelper` | `string` | — | Script that prints environment variables as a JSON object to stdout. Runs when the local server starts (cached for the TTL below). |
793 | `envHelperTtlSec` | `integer` | `300` | Maximum age of a cached helper result, in seconds (default 300). Applies when the server starts or restarts. |
794 | `startupTimeoutSec` | `integer` | `120` | Maximum wait in seconds for the server to start and list its tools. |
795795 </Accordion>
796796 
797797 <Accordion title="mcpPersistentAlwaysAllowEnabled details">
from line 821
821821 
822822 Coexistence with another Claude Code managed-settings source on the device: see [managed settings](https://claude.com/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings).
823823 
824 | Field | Type | Default | Description |
825 | ----------- | -------- | ------- | ------------------------------------------------------------------- |
826 | `serverUrl` | `string` | — | URL pattern a plugin’s remote server must match, with \* wildcards. |
824 | Field | Type | Default | Description |
825 | - | - | - | - |
826 | `serverUrl` | `string` | — | URL pattern a plugin’s remote server must match, with \* wildcards. |
827827 </Accordion>
828828 
829829 <Accordion title="mcpToolTimeoutSec details">
from line 835
835835 
836836## Telemetry & updates
837837 
838| Setting | Type | Availability | Default | Description |
839| ---------------------------------------------------------------------------------------------------------- | --------- | -------------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
840| <span id="deploymentorganizationuuid" />Organization UUID<br />`deploymentOrganizationUuid` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | A UUID you generate. Tags telemetry so Anthropic support can locate your fleet’s events, and namespaces each user’s local data. Not used for auth. |
841| <span id="disableessentialtelemetry" />Block essential telemetry<br />`disableEssentialTelemetry` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Crash and performance reports to Anthropic. Defaults to `false`. |
842| <span id="disablenonessentialtelemetry" />Block nonessential telemetry<br />`disableNonessentialTelemetry` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Product-usage analytics and diagnostic-report uploads. No message content. Defaults to `false`. |
843| <span id="disablenonessentialservices" />Block nonessential services<br />`disableNonessentialServices` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Connector favicons and the artifact-preview and MCP Apps widget iframe origins. Artifacts will not render. Defaults to `false`. |
838| Setting | Type | Availability | Default | Description |
839| - | - | - | - | - |
840| <span id="deploymentorganizationuuid" />Organization UUID<br />`deploymentOrganizationUuid` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | A UUID you generate. Tags telemetry so Anthropic support can locate your fleet’s events, and namespaces each user’s local data. Not used for auth. |
841| <span id="disableessentialtelemetry" />Block essential telemetry<br />`disableEssentialTelemetry` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Crash and performance reports to Anthropic. Defaults to `false`. |
842| <span id="disablenonessentialtelemetry" />Block nonessential telemetry<br />`disableNonessentialTelemetry` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Product-usage analytics and diagnostic-report uploads. No message content. Defaults to `false`. |
843| <span id="disablenonessentialservices" />Block nonessential services<br />`disableNonessentialServices` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Connector favicons and the artifact-preview and MCP Apps widget iframe origins. Artifacts will not render. Defaults to `false`. |
844844 
845845<AccordionGroup>
846846 <Accordion title="deploymentOrganizationUuid details">
from line 872
872872 
873873### Auto update
874874 
875| Setting | Type | Availability | Default | Description |
876| ---------------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------- |
877| <span id="disableautoupdates" />Block auto-updates<br />`disableAutoUpdates` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Stop Claude Desktop from fetching updates entirely (no time limit). You’ll need to push new versions yourself. Defaults to `false`. |
878| <span id="autoupdaterenforcementhours" />Auto-update enforcement window<br />`autoUpdaterEnforcementHours` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Hours before a downloaded update force-installs. Only applies when auto-updates are enabled. Blank = 72-hour default. Range: 1–72. |
879| <span id="updateviaupdateshost" />Check for updates on releases.claude.com<br />`updateViaUpdatesHost` | `boolean` | MDM + Bootstrap<br />Added in 1.26832.0 | `false` | Read the update feed from releases.claude.com so api.anthropic.com can stay blocked. Defaults to `false`. |
875| Setting | Type | Availability | Default | Description |
876| - | - | - | - | - |
877| <span id="disableautoupdates" />Block auto-updates<br />`disableAutoUpdates` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `false` | Stop Claude Desktop from fetching updates entirely (no time limit). You’ll need to push new versions yourself. Defaults to `false`. |
878| <span id="autoupdaterenforcementhours" />Auto-update enforcement window<br />`autoUpdaterEnforcementHours` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Hours before a downloaded update force-installs. Only applies when auto-updates are enabled. Blank = 72-hour default. Range: 1–72. |
879| <span id="updateviaupdateshost" />Check for updates on releases.claude.com<br />`updateViaUpdatesHost` | `boolean` | MDM + Bootstrap<br />Added in 1.26832.0 | `false` | Read the update feed from releases.claude.com so api.anthropic.com can stay blocked. Defaults to `false`. |
880880 
881881<AccordionGroup>
882882 <Accordion title="autoUpdaterEnforcementHours details">
from line 894
894894 
895895### Configuration updates
896896 
897| Setting | Type | Availability | Default | Description |
898| --------------------------------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
899| <span id="relaunchenforcementhours" />Configuration relaunch window<br />`relaunchEnforcementHours` | `integer` | MDM + Bootstrap<br />Added in 1.40609.0 | `24` | Hours a user may keep working on the old configuration after a managed-configuration change is detected. 0 = restart required at once. Blank = 24 hours. Defaults to `24`. Range: 0–336. |
900| <span id="configrecheckintervalminutes" />Configuration re-check interval<br />`configRecheckIntervalMinutes` | `integer` | MDM + Bootstrap<br />Added in 1.46388.1 | `10` | Minutes between the running app’s checks for a changed managed configuration. Blank = 10 minutes. Defaults to `10`. Range: 2–30. |
901| <span id="disablelocalconfigcache" />Keep only your organization ID and restrictions on disk<br />`disableLocalConfigCache` | `boolean` | hybrid-only<br />Added in 2.7032.0 | `false` | Don’t keep your organization’s name or any permissive setting on disk between launches; only your organization ID and the restrictions you turn on are kept. Defaults to `false`. |
897| Setting | Type | Availability | Default | Description |
898| - | - | - | - | - |
899| <span id="relaunchenforcementhours" />Configuration relaunch window<br />`relaunchEnforcementHours` | `integer` | MDM + Bootstrap<br />Added in 1.40609.0 | `24` | Hours a user may keep working on the old configuration after a managed-configuration change is detected. 0 = restart required at once. Blank = 24 hours. Defaults to `24`. Range: 0–336. |
900| <span id="configrecheckintervalminutes" />Configuration re-check interval<br />`configRecheckIntervalMinutes` | `integer` | MDM + Bootstrap<br />Added in 1.46388.1 | `10` | Minutes between the running app’s checks for a changed managed configuration. Blank = 10 minutes. Defaults to `10`. Range: 2–30. |
901| <span id="disablelocalconfigcache" />Keep only your organization ID and restrictions on disk<br />`disableLocalConfigCache` | `boolean` | hybrid-only<br />Added in 2.7032.0 | `false` | Don’t keep your organization’s name or any permissive setting on disk between launches; only your organization ID and the restrictions you turn on are kept. Defaults to `false`. |
902902 
903903<AccordionGroup>
904904 <Accordion title="relaunchEnforcementHours details">
from line 922
922922 
923923### OTLP
924924 
925| Setting | Type | Availability | Default | Description |
926| --------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
927| <span id="otlpendpoint" />OpenTelemetry collector endpoint<br />`otlpEndpoint` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Where OpenTelemetry logs and metrics are sent. Leave blank to disable. |
928| <span id="otlpprotocol" />OpenTelemetry exporter protocol<br />`otlpProtocol` | `enum` | MDM + Bootstrap<br />Added in 1.2581.0 | `http/protobuf` | Transport protocol for the OpenTelemetry exporters. One of: `http/protobuf`, `http/json`, `grpc`. Defaults to `http/protobuf`. |
929| <span id="otlpheaders" />OpenTelemetry exporter headers<br />`otlpHeaders` | `object` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static collector headers — routing and tenant headers only. No credentials here; use Collector authentication or the headers helper script for tokens. Deprecated: `otlpHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no exporter headers will be sent. |
930| <span id="otlpauthmode" />Collector authentication<br />`otlpAuthMode` | `enum` | MDM + Bootstrap<br />Added in 1.30096.1 | — | inference-credential sends the user’s inference bearer token to the collector as Authorization: Bearer. One of: `none`, `inference-credential`. |
931| <span id="otlpheadershelper" />OpenTelemetry headers helper script<br />`otlpHeadersHelper` | `string` | MDM + Bootstrap<br />Added in 1.30096.1 | — | Absolute path to an executable that prints a JSON object of collector headers. Merged over the static headers and Collector authentication; the helper wins. |
932| <span id="otlpresourceattributes" />OpenTelemetry resource attributes<br />`otlpResourceAttributes` | `object` | MDM + Bootstrap<br />Added in 1.5354.0 | — | Extra resource attributes to attach to every span/metric. A static enduser.id set here always wins over the runtime identity. Deprecated: `otlpResourceAttributes as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no custom resource attributes will be attached. |
933| <span id="otlpdesktoploglevel" />Desktop telemetry export level<br />`otlpDesktopLogLevel` | `enum` | MDM + Bootstrap<br />Added in 1.9255.0 | `error` | Controls the Claude Desktop application’s events, separate from Cowork and Code sessions. Defaults to error. One of: `off`, `error`, `warn`, `info`, `debug`. Defaults to `error`. |
934| <span id="otlpcontentcapture" />Content capture categories<br />`otlpContentCapture` | `enum[]` | MDM + Bootstrap<br />Added in 1.15962.0 | — | Content categories the desktop exporter sends unredacted to your collector. Leave empty to redact all content (default). One of: `userPrompts`, `assistantResponses`, `toolDetails`, `toolContent`, `rawApiBodies`. |
935| <span id="otlptracesenabled" />Export traces<br />`otlpTracesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.22209.0 | — | Also export OpenTelemetry traces from Cowork tasks and Code sessions. Uses Claude Code’s session tracing. |
925| Setting | Type | Availability | Default | Description |
926| - | - | - | - | - |
927| <span id="otlpendpoint" />OpenTelemetry collector endpoint<br />`otlpEndpoint` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Where OpenTelemetry logs and metrics are sent. Leave blank to disable. |
928| <span id="otlpprotocol" />OpenTelemetry exporter protocol<br />`otlpProtocol` | `enum` | MDM + Bootstrap<br />Added in 1.2581.0 | `http/protobuf` | Transport protocol for the OpenTelemetry exporters. One of: `http/protobuf`, `http/json`, `grpc`. Defaults to `http/protobuf`. |
929| <span id="otlpheaders" />OpenTelemetry exporter headers<br />`otlpHeaders` | `object` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static collector headers — routing and tenant headers only. No credentials here; use Collector authentication or the headers helper script for tokens. Deprecated: `otlpHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no exporter headers will be sent. |
930| <span id="otlpauthmode" />Collector authentication<br />`otlpAuthMode` | `enum` | MDM + Bootstrap<br />Added in 1.30096.1 | — | inference-credential sends the user’s inference bearer token to the collector as Authorization: Bearer. One of: `none`, `inference-credential`. |
931| <span id="otlpheadershelper" />OpenTelemetry headers helper script<br />`otlpHeadersHelper` | `string` | MDM + Bootstrap<br />Added in 1.30096.1 | — | Absolute path to an executable that prints a JSON object of collector headers. Merged over the static headers and Collector authentication; the helper wins. |
932| <span id="otlpresourceattributes" />OpenTelemetry resource attributes<br />`otlpResourceAttributes` | `object` | MDM + Bootstrap<br />Added in 1.5354.0 | — | Extra resource attributes to attach to every span/metric. A static enduser.id set here always wins over the runtime identity. Deprecated: `otlpResourceAttributes as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no custom resource attributes will be attached. |
933| <span id="otlpdesktoploglevel" />Desktop telemetry export level<br />`otlpDesktopLogLevel` | `enum` | MDM + Bootstrap<br />Added in 1.9255.0 | `error` | Controls the Claude Desktop application’s events, separate from Cowork and Code sessions. Defaults to error. One of: `off`, `error`, `warn`, `info`, `debug`. Defaults to `error`. |
934| <span id="otlpcontentcapture" />Content capture categories<br />`otlpContentCapture` | `enum[]` | MDM + Bootstrap<br />Added in 1.15962.0 | — | Content categories the desktop exporter sends unredacted to your collector. Leave empty to redact all content (default). One of: `userPrompts`, `assistantResponses`, `toolDetails`, `toolContent`, `rawApiBodies`. |
935| <span id="otlptracesenabled" />Export traces<br />`otlpTracesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.22209.0 | — | Also export OpenTelemetry traces from Cowork tasks and Code sessions. Uses Claude Code’s session tracing. |
936936 
937937<AccordionGroup>
938938 <Accordion title="otlpProtocol details">
from line 972
972972 
973973### Session retention
974974 
975| Setting | Type | Availability | Default | Description |
976| ------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
977| <span id="chatsessionretentiondays" />Chat retention period<br />`chatSessionRetentionDays` | `integer` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Delete chats, with their files, after this many days without activity. Unset: kept until the user deletes them. Projects and memory stay. Range: 1–3650. |
978| <span id="coworksessionretentiondays" />Cowork retention period<br />`coworkSessionRetentionDays` | `integer` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Delete Cowork tasks, with their uploads and outputs, after this many days without activity. Unset: kept until the user deletes them. Spaces and memory stay. Range: 1–3650. |
979| <span id="codesessionretentiondays" />Code retention period<br />`codeSessionRetentionDays` | `integer` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Delete Code sessions, conversation included, after this many days without activity. Unset: kept until the user deletes them. Uncommitted work stays on disk. Range: 1–3650. |
980| <span id="sessionretentionhold" />Suspend session deletion<br />`sessionRetentionHold` | `boolean` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Suspend all automatic session deletion for these users (legal hold). While on, the retention periods above delete nothing. |
975| Setting | Type | Availability | Default | Description |
976| - | - | - | - | - |
977| <span id="chatsessionretentiondays" />Chat retention period<br />`chatSessionRetentionDays` | `integer` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Delete chats, with their files, after this many days without activity. Unset: kept until the user deletes them. Projects and memory stay. Range: 1–3650. |
978| <span id="coworksessionretentiondays" />Cowork retention period<br />`coworkSessionRetentionDays` | `integer` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Delete Cowork tasks, with their uploads and outputs, after this many days without activity. Unset: kept until the user deletes them. Spaces and memory stay. Range: 1–3650. |
979| <span id="codesessionretentiondays" />Code retention period<br />`codeSessionRetentionDays` | `integer` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Delete Code sessions, conversation included, after this many days without activity. Unset: kept until the user deletes them. Uncommitted work stays on disk. Range: 1–3650. |
980| <span id="sessionretentionhold" />Suspend session deletion<br />`sessionRetentionHold` | `boolean` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Suspend all automatic session deletion for these users (legal hold). While on, the retention periods above delete nothing. |
981981 
982982<AccordionGroup>
983983 <Accordion title="chatSessionRetentionDays details">
from line 999
999999 
10001000### Token limits
10011001 
1002| Setting | Type | Availability | Default | Description |
1003| ------------------------------------------------------------------------------------------------- | --------- | -------------------------------------- | ------- | ---------------------------------------------------------------------------------------------- |
1004| <span id="inferencemaxtokensperwindow" />Max tokens per window<br />`inferenceMaxTokensPerWindow` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Per-user soft cap, counted client-side over the token cap window. Not a server-enforced quota. |
1005| <span id="inferencetokenwindowhours" />Token cap window<br />`inferenceTokenWindowHours` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Tumbling window length for the token cap. Max 720 hours (30 days). Range: 1–720. |
1002| Setting | Type | Availability | Default | Description |
1003| - | - | - | - | - |
1004| <span id="inferencemaxtokensperwindow" />Max tokens per window<br />`inferenceMaxTokensPerWindow` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Per-user soft cap, counted client-side over the token cap window. Not a server-enforced quota. |
1005| <span id="inferencetokenwindowhours" />Token cap window<br />`inferenceTokenWindowHours` | `integer` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Tumbling window length for the token cap. Max 720 hours (30 days). Range: 1–720. |
10061006 
10071007<AccordionGroup>
10081008 <Accordion title="inferenceMaxTokensPerWindow details">
from line 1016
10161016 
10171017## Appearance
10181018 
1019| Setting | Type | Availability | Default | Description |
1020| ----------------------------------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
1021| <span id="enduserattribution" />End-user attribution<br />`endUserAttribution` | `boolean` | MDM + Bootstrap<br />Added in 1.25927.0 | — | Show the signed-in user’s identity-provider identity in the sidebar and account menu, and emit it as the OpenTelemetry enduser.id resource attribute. Previously named `enduserAttribution` (the old name is accepted until October 7, 2026). If it is still present after that, the key will read as false (its fail-closed value): end-user attribution will stay off — no identity shown, no enduser.id emitted — whatever the old name said. |
1022| <span id="deploymentdisplayname" />Deployment display name<br />`deploymentDisplayName` | `string` | MDM + Bootstrap<br />Added in 1.24012.0 | — | Overrides the provider label shown in the sidebar footer, user-menu header, and connection-error banner. |
1023| <span id="deploymentdisplaysubtitle" />Deployment display subtitle<br />`deploymentDisplaySubtitle` | `string` | MDM + Bootstrap<br />Added in 1.24012.0 | — | Optional detail shown after the deployment display name in the account-menu header. |
1024| <span id="disableconfigdeprecationwarnings" />Hide configuration deprecation warnings<br />`disableConfigDeprecationWarnings` | `boolean` | MDM + Bootstrap<br />Added in 1.40609.0 | — | Don’t show users the in-app warning that this configuration uses a deprecated field. The final reminder in the 24 hours before the cut-off still appears. |
1025| <span id="banner" />Organization banner<br />`banner` | `object` | MDM + Bootstrap<br />Added in 1.7196.0 | — | A persistent banner across the top of the app window after sign-in. |
1019| Setting | Type | Availability | Default | Description |
1020| - | - | - | - | - |
1021| <span id="enduserattribution" />End-user attribution<br />`endUserAttribution` | `boolean` | MDM + Bootstrap<br />Added in 1.25927.0 | — | Show the signed-in user’s identity-provider identity in the sidebar and account menu, and emit it as the OpenTelemetry enduser.id resource attribute. Previously named `enduserAttribution` (the old name is accepted until October 7, 2026). If it is still present after that, the key will read as false (its fail-closed value): end-user attribution will stay off — no identity shown, no enduser.id emitted — whatever the old name said. |
1022| <span id="deploymentdisplayname" />Deployment display name<br />`deploymentDisplayName` | `string` | MDM + Bootstrap<br />Added in 1.24012.0 | — | Overrides the provider label shown in the sidebar footer, user-menu header, and connection-error banner. |
1023| <span id="deploymentdisplaysubtitle" />Deployment display subtitle<br />`deploymentDisplaySubtitle` | `string` | MDM + Bootstrap<br />Added in 1.24012.0 | — | Optional detail shown after the deployment display name in the account-menu header. |
1024| <span id="disableconfigdeprecationwarnings" />Hide configuration deprecation warnings<br />`disableConfigDeprecationWarnings` | `boolean` | MDM + Bootstrap<br />Added in 1.40609.0 | — | Don’t show users the in-app warning that this configuration uses a deprecated field. The final reminder in the 24 hours before the cut-off still appears. |
1025| <span id="banner" />Organization banner<br />`banner` | `object` | MDM + Bootstrap<br />Added in 1.7196.0 | — | A persistent banner across the top of the app window after sign-in. |
10261026 
10271027<AccordionGroup>
10281028 <Accordion title="endUserAttribution details">
from line 1044
10441044 <Accordion title="banner details">
10451045 Use this for compliance notices, an internal-support link, or to identify the deployment. The banner is shown on every page after sign-in and cannot be dismissed by the user. Colors are six-digit hex (`#RRGGBB`); when `linkUrl` is set the banner text becomes an HTTPS link.
10461046 
1047 | Field | Type | Default | Description |
1048 | ----------------- | --------- | --------- | ------------------------------------------------------------------------------ |
1049 | `enabled` | `boolean` | — | Turns the banner on. When false or unset, the other banner fields are ignored. |
1050 | `text` | `string` | — | Single line, truncated on overflow. Maximum 200 characters. |
1051 | `backgroundColor` | `string` | `#F5F5F5` | Six-digit hex (#RRGGBB). Applied exactly as configured; not theme-adapted. |
1052 | `textColor` | `string` | `#000000` | Six-digit hex (#RRGGBB). Applied exactly as configured; not theme-adapted. |
1053 | `linkUrl` | `string` | — | Optional HTTPS URL. The banner text becomes a link when set. |
1047 | Field | Type | Default | Description |
1048 | - | - | - | - |
1049 | `enabled` | `boolean` | — | Turns the banner on. When false or unset, the other banner fields are ignored. |
1050 | `text` | `string` | — | Single line, truncated on overflow. Maximum 200 characters. |
1051 | `backgroundColor` | `string` | `#F5F5F5` | Six-digit hex (#RRGGBB). Applied exactly as configured; not theme-adapted. |
1052 | `textColor` | `string` | `#000000` | Six-digit hex (#RRGGBB). Applied exactly as configured; not theme-adapted. |
1053 | `linkUrl` | `string` | — | Optional HTTPS URL. The banner text becomes a link when set. |
10541054 </Accordion>
10551055</AccordionGroup>
10561056 
10571057### Feature discovery
10581058 
1059| Setting | Type | Availability | Default | Description |
1060| ---------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
1059| Setting | Type | Availability | Default | Description |
1060| - | - | - | - | - |
10611061| <span id="disablefeaturediscovery" />Hide feature announcements<br />`disableFeatureDiscovery` | `boolean` | MDM + Bootstrap<br />Added in 1.21459.0 | `false` | Suppress unprompted feature-announcement UI: the post-update “What’s new” nudge and new-feature tips. Users can still open release notes themselves. Defaults to `false`. |
10621062 
10631063<AccordionGroup>
from line 1070
10701070 
10711071## Plugins
10721072 
1073| Setting | Type | Availability | Default | Description |
1074| ------------------------------------------------------------------------------------------- | ---------- | --------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
1075| <span id="orgpluginsettings" />Organization plugin settings<br />`orgPluginSettings` | `object[]` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Admin policy applied to plugin-delivered MCP servers. Deprecated: `orgPluginSettings as a {"mcpServers": {…}} record` (accepted until October 7, 2026); use the array form \[\{"serverName": "…", "tools": \[\{"toolName": "…", "permission": "…"}]}] (read by desktop 1.15200.0 and later; older desktops ignore the array and enforce no tool blocks). If it is still present after that, the record will be rejected as malformed and the key will fail closed: every plugin-delivered MCP tool will be blocked until the value is rewritten. Deprecated: `orgPluginSettings[].tools[].permission: "ask-session"` (accepted until October 7, 2026); use "ask". If it is still present after that, that tool will be treated as "blocked", like any unrecognized permission. |
1076| <span id="allowedpluginmarketplaces" />Plugin marketplaces<br />`allowedPluginMarketplaces` | `object[]` | MDM + Bootstrap<br />Added in 1.17377.1 | — | Git repositories or hosted marketplace.json URLs to surface as plugin marketplaces in the Directory’s Organization tab. The app re-fetches each periodically. |
1073| Setting | Type | Availability | Default | Description |
1074| - | - | - | - | - |
1075| <span id="orgpluginsettings" />Organization plugin settings<br />`orgPluginSettings` | `object[]` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Admin policy applied to plugin-delivered MCP servers. Deprecated: `orgPluginSettings as a {"mcpServers": {…}} record` (accepted until October 7, 2026); use the array form \[\{"serverName": "…", "tools": \[\{"toolName": "…", "permission": "…"}]}] (read by desktop 1.15200.0 and later; older desktops ignore the array and enforce no tool blocks). If it is still present after that, the record will be rejected as malformed and the key will fail closed: every plugin-delivered MCP tool will be blocked until the value is rewritten. Deprecated: `orgPluginSettings[].tools[].permission: "ask-session"` (accepted until October 7, 2026); use "ask". If it is still present after that, that tool will be treated as "blocked", like any unrecognized permission. |
1076| <span id="allowedpluginmarketplaces" />Plugin marketplaces<br />`allowedPluginMarketplaces` | `object[]` | MDM + Bootstrap<br />Added in 1.17377.1 | — | Git repositories or hosted marketplace.json URLs to surface as plugin marketplaces in the Directory’s Organization tab. The app re-fetches each periodically. |
10771077 
10781078<AccordionGroup>
10791079 <Accordion title="orgPluginSettings details">
from line 1089
10891089 
10901090 For a plugin server that Claude Code launches or connects to itself (a marketplace plugin's), the permissions travel on Claude Code's managed-settings channel: another Claude Code [managed-settings source](https://claude.com/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings) on the device replaces them unless that source sets `parentSettingsBehavior` to `"merge"`. `blocked` on a server the app connects to itself holds either way.
10911091 
1092 | Field | Type | Default | Description |
1093 | ------------------ | ---------- | ------- | --------------------------------------------------------------------------------------------------------------------------- |
1094 | `serverName` | `string` | — | Name of the plugin-delivered MCP server this policy applies to. |
1095 | `tools` | `object[]` | — | Per-tool approval locks for this server. |
1096 | `tools.toolName` | `string` | — | MCP tool name as the server reports it. |
1097 | `tools.permission` | `enum` | — | Approval state locked for this tool. Unlisted tools stay user-controlled. One of: `allow`, `ask`, `ask-session`, `blocked`. |
1092 | Field | Type | Default | Description |
1093 | - | - | - | - |
1094 | `serverName` | `string` | — | Name of the plugin-delivered MCP server this policy applies to. |
1095 | `tools` | `object[]` | — | Per-tool approval locks for this server. |
1096 | `tools.toolName` | `string` | — | MCP tool name as the server reports it. |
1097 | `tools.permission` | `enum` | — | Approval state locked for this tool. Unlisted tools stay user-controlled. One of: `allow`, `ask`, `ask-session`, `blocked`. |
10981098 </Accordion>
10991099 
11001100 <Accordion title="allowedPluginMarketplaces details">
1101 | Field | Type | Default | Description |
1102 | ------------------------ | -------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
1103 | `source` | `string` | — | Where the marketplace is fetched from: a GitHub repository (set repo), any Git remote (set url), or a hosted marketplace.json file (set url). One of: `github`, `git`, `url`. |
1104 | `repo` | `string` | — | GitHub repository in owner/repo form. Case-insensitive. |
1105 | `ref` | `string` | — | Commit SHA, branch, or tag. Leave empty to track the default branch; auto\_install and required need a full 40-character commit SHA. |
1106 | `path` | `string` | — | Folder within the repository that contains the marketplace, when it isn’t at the root. |
1107 | `expectedName` | `string` | — | Rejects the marketplace if its manifest name differs. |
1108 | `installationPreference` | `enum` | — | Whether users install plugins themselves or get them automatically. One of: `available`, `auto_install`, `required`. |
1109 | `credentialKind` | `enum` | — | How fetches authenticate: anonymously, with the user’s git credentials, via a helper executable, or as the app does to its gateway or bootstrap server (url). One of: `anonymous`, `userGit`, `credentialHelper`, `inferenceCredential`. |
1110 | `credentialHelper` | `string` | — | Executable that prints an access token for this marketplace. |
1111 | `url` | `string` | — | HTTPS Git remote of the marketplace repository (git), or direct HTTPS URL of a hosted marketplace.json file (url). |
1112 | `manifestSha256` | `string` | — | SHA-256 of the exact marketplace.json to accept. Without it auto\_install and required act as available; a served manifest with any other digest is refused. |
1101 | Field | Type | Default | Description |
1102 | - | - | - | - |
1103 | `source` | `string` | — | Where the marketplace is fetched from: a GitHub repository (set repo), any Git remote (set url), or a hosted marketplace.json file (set url). One of: `github`, `git`, `url`. |
1104 | `repo` | `string` | — | GitHub repository in owner/repo form. Case-insensitive. |
1105 | `ref` | `string` | — | Commit SHA, branch, or tag. Leave empty to track the default branch; auto\_install and required need a full 40-character commit SHA. |
1106 | `path` | `string` | — | Folder within the repository that contains the marketplace, when it isn’t at the root. |
1107 | `expectedName` | `string` | — | Rejects the marketplace if its manifest name differs. |
1108 | `installationPreference` | `enum` | — | Whether users install plugins themselves or get them automatically. One of: `available`, `auto_install`, `required`. |
1109 | `credentialKind` | `enum` | — | How fetches authenticate: anonymously, with the user’s git credentials, via a helper executable, or as the app does to its gateway or bootstrap server (url). One of: `anonymous`, `userGit`, `credentialHelper`, `inferenceCredential`. |
1110 | `credentialHelper` | `string` | — | Executable that prints an access token for this marketplace. |
1111 | `url` | `string` | — | HTTPS Git remote of the marketplace repository (git), or direct HTTPS URL of a hosted marketplace.json file (url). |
1112 | `manifestSha256` | `string` | — | SHA-256 of the exact marketplace.json to accept. Without it auto\_install and required act as available; a served manifest with any other digest is refused. |
11131113 </Accordion>
11141114</AccordionGroup>
11151115 
from line 1117
11171117 
11181118### Bootstrap
11191119 
1120| Setting | Type | Availability | Default | Description |
1121| ---------------------------------------------------------------------------------------------------- | --------- | -------------------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
1122| <span id="bootstrapenabled" />Use bootstrap config<br />`bootstrapEnabled` | `boolean` | MDM only<br />Added in 1.10628.0 | `true` | Fetch and apply the URL above at launch. Turn off to keep the URL saved but skip the fetch. Defaults to `true`. |
1123| <span id="bootstrapurl" />Bootstrap config URL<br />`bootstrapUrl` | `string` | MDM only<br />Added in 1.10628.0 | — | HTTPS endpoint that returns a per-user JSON config overlay. Values from the response override local settings and become read-only. |
1124| <span id="bootstrapoidc" />Bootstrap OIDC parameters<br />`bootstrapOidc` | `object` | MDM only<br />Added in 1.10628.0 | — | When set, the bootstrap request sends a Bearer token from a browser sign-in (authorization-code-with-PKCE). |
1125| <span id="bootstrapheaders" />Bootstrap request headers<br />`bootstrapHeaders` | `object` | MDM only<br />Added in 1.32885.1 | — | HTTP headers sent on every bootstrap config fetch. Use this instead of embedding user:pass@ in the URL. Deprecated: `bootstrapHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no bootstrap request headers will be sent (the fetch may then fail to authenticate). |
1126| <span id="bootstrapheadershelper" />Bootstrap headers helper script<br />`bootstrapHeadersHelper` | `string` | MDM only<br />Added in 1.32885.1 | — | Absolute path to an executable that prints a JSON object of bootstrap request headers. Merged over the static headers; the helper wins. |
1120| Setting | Type | Availability | Default | Description |
1121| - | - | - | - | - |
1122| <span id="bootstrapenabled" />Use bootstrap config<br />`bootstrapEnabled` | `boolean` | MDM only<br />Added in 1.10628.0 | `true` | Fetch and apply the URL above at launch. Turn off to keep the URL saved but skip the fetch. Defaults to `true`. |
1123| <span id="bootstrapurl" />Bootstrap config URL<br />`bootstrapUrl` | `string` | MDM only<br />Added in 1.10628.0 | — | HTTPS endpoint that returns a per-user JSON config overlay. Values from the response override local settings and become read-only. |
1124| <span id="bootstrapoidc" />Bootstrap OIDC parameters<br />`bootstrapOidc` | `object` | MDM only<br />Added in 1.10628.0 | — | When set, the bootstrap request sends a Bearer token from a browser sign-in (authorization-code-with-PKCE). |
1125| <span id="bootstrapheaders" />Bootstrap request headers<br />`bootstrapHeaders` | `object` | MDM only<br />Added in 1.32885.1 | — | HTTP headers sent on every bootstrap config fetch. Use this instead of embedding user:pass@ in the URL. Deprecated: `bootstrapHeaders as a "Name=value,…" string or a ["Name: value", …] list` (accepted until October 7, 2026); use a JSON object such as \{"Name": "value"}. If it is still present after that, a string or list value will be rejected as malformed and no bootstrap request headers will be sent (the fetch may then fail to authenticate). |
1126| <span id="bootstrapheadershelper" />Bootstrap headers helper script<br />`bootstrapHeadersHelper` | `string` | MDM only<br />Added in 1.32885.1 | — | Absolute path to an executable that prints a JSON object of bootstrap request headers. Merged over the static headers; the helper wins. |
11271127| <span id="trustbootstrapdelivery" />Trust bootstrap-delivered settings<br />`trustBootstrapDelivery` | `boolean` | MDM only<br />Added in 1.26832.0 | `false` | Skip the per-user consent prompt for sign-in targets, inference endpoints, helper scripts, and connectors the bootstrap server delivers. Defaults to `false`. Previously named `trustBootstrapLocalExec` (the old name is accepted until October 7, 2026). If it is still present after that, the key will read as false (its fail-closed value): each user will be asked to consent to bootstrap-delivered sign-in targets, endpoints, helper scripts and connectors, even when the bootstrap URL came from a device-managed profile. |
11281128 
11291129<AccordionGroup>
from line 1132
11321132 
11331133 This is an **object-typed key** — in an MDM profile it is a single JSON-string value, not separate keys with dotted names like `bootstrapOidc.clientId`. Writing the sub-fields as separate registry values causes the app to silently fall through to device-code mode.
11341134 
1135 | Field | Type | Default | Description |
1136 | --------------------------------- | --------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
1137 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
1138 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
1139 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
1140 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
1141 | `scopes` | `string` | — | Space-separated; the token’s audience must match what your bootstrap server validates. |
1142 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
1143 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
1144 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
1135 | Field | Type | Default | Description |
1136 | - | - | - | - |
1137 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
1138 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
1139 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
1140 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
1141 | `scopes` | `string` | — | Space-separated; the token’s audience must match what your bootstrap server validates. |
1142 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
1143 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
1144 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
11451145 </Accordion>
11461146 
11471147 <Accordion title="bootstrapHeaders details">
from line 1163
11631163 <Tab title="Standard">
11641164 Recommended for most enterprise deployments. Telemetry and auto-updates stay on so Anthropic can diagnose issues and ship fixes; users can extend Claude Desktop with their own connectors.
11651165 
1166 | Key | Value |
1167 | ----------------------------------------------------------------------------- | ------------------ |
1168 | [`deploymentOrganizationUuid`](#deploymentorganizationuuid) | `<your-org-uuid>` |
1169 | [`autoUpdaterEnforcementHours`](#autoupdaterenforcementhours) | `24` |
1170 | [`isDesktopExtensionSignatureRequired`](#isdesktopextensionsignaturerequired) | `true` |
1171 | [`otlpEndpoint`](#otlpendpoint) | `<your-collector>` |
1166 | Key | Value |
1167 | - | - |
1168 | [`deploymentOrganizationUuid`](#deploymentorganizationuuid) | `<your-org-uuid>` |
1169 | [`autoUpdaterEnforcementHours`](#autoupdaterenforcementhours) | `24` |
1170 | [`isDesktopExtensionSignatureRequired`](#isdesktopextensionsignaturerequired) | `true` |
1171 | [`otlpEndpoint`](#otlpendpoint) | `<your-collector>` |
11721172 </Tab>
11731173 
11741174 <Tab title="Restricted">
11751175 For regulated environments that need to control what users can connect Claude Desktop to, while keeping Anthropic supportability.
11761176 
1177 | Key | Value |
1178 | --------------------------------------------------------------- | --------------------------------- |
1179 | [`deploymentOrganizationUuid`](#deploymentorganizationuuid) | `<your-org-uuid>` |
1180 | [`disableNonessentialTelemetry`](#disablenonessentialtelemetry) | `true` |
1181 | [`disableNonessentialServices`](#disablenonessentialservices) | `true` |
1182 | [`isLocalDevMcpEnabled`](#islocaldevmcpenabled) | `false` |
1183 | [`isDesktopExtensionEnabled`](#isdesktopextensionenabled) | `false` |
1184 | [`allowedWorkspaceFolders`](#allowedworkspacefolders) | `[{"path":"~/Documents/Claude"}]` |
1185 | [`coworkEgressAllowedHosts`](#coworkegressallowedhosts) | `["*.example.corp"]` |
1186 | [`otlpEndpoint`](#otlpendpoint) | `<your-collector>` |
1177 | Key | Value |
1178 | - | - |
1179 | [`deploymentOrganizationUuid`](#deploymentorganizationuuid) | `<your-org-uuid>` |
1180 | [`disableNonessentialTelemetry`](#disablenonessentialtelemetry) | `true` |
1181 | [`disableNonessentialServices`](#disablenonessentialservices) | `true` |
1182 | [`isLocalDevMcpEnabled`](#islocaldevmcpenabled) | `false` |
1183 | [`isDesktopExtensionEnabled`](#isdesktopextensionenabled) | `false` |
1184 | [`allowedWorkspaceFolders`](#allowedworkspacefolders) | `[{"path":"~/Documents/Claude"}]` |
1185 | [`coworkEgressAllowedHosts`](#coworkegressallowedhosts) | `["*.example.corp"]` |
1186 | [`otlpEndpoint`](#otlpendpoint) | `<your-collector>` |
11871187 </Tab>
11881188 
11891189 <Tab title="Locked down">
11901190 For air-gapped or maximally restricted environments. **The only traffic leaving the device goes to your inference endpoint and OTLP collector**, plus `downloads.claude.ai` for the VM bundle and Claude CLI binary at session start unless you deploy the [offline installer](/docs/third-party/claude-desktop/installation#offline-installation). With this profile, Anthropic receives no telemetry or logs from the app and does not deliver updates, so your team owns log collection and update distribution. On Microsoft Foundry, the Claude models behind your inference endpoint run in an Anthropic-operated service, so conversation content still reaches Anthropic-operated infrastructure under this profile, as described under [Data handling by provider](/docs/third-party/claude-desktop/overview#data-handling-by-provider).
11911191 
1192 | Key | Value |
1193 | --------------------------------------------------------------- | --------------------------------- |
1194 | [`disableEssentialTelemetry`](#disableessentialtelemetry) | `true` |
1195 | [`disableNonessentialTelemetry`](#disablenonessentialtelemetry) | `true` |
1196 | [`disableNonessentialServices`](#disablenonessentialservices) | `true` |
1197 | [`disableAutoUpdates`](#disableautoupdates) | `true` |
1198 | [`modelCatalogEnabled`](#modelcatalogenabled) | `false` |
1199 | [`isLocalDevMcpEnabled`](#islocaldevmcpenabled) | `false` |
1200 | [`isDesktopExtensionEnabled`](#isdesktopextensionenabled) | `false` |
1201 | [`skillCreationEnabled`](#skillcreationenabled) | `false` |
1202 | [`scheduledTasksEnabled`](#scheduledtasksenabled) | `false` |
1203 | [`disabledBuiltinTools`](#disabledbuiltintools) | `["WebSearch","WebFetch"]` |
1204 | [`coworkEgressAllowedHosts`](#coworkegressallowedhosts) | `[]` |
1205 | [`allowedWorkspaceFolders`](#allowedworkspacefolders) | `[{"path":"~/Documents/Claude"}]` |
1206 | [`otlpEndpoint`](#otlpendpoint) | `<your-collector>` |
1192 | Key | Value |
1193 | - | - |
1194 | [`disableEssentialTelemetry`](#disableessentialtelemetry) | `true` |
1195 | [`disableNonessentialTelemetry`](#disablenonessentialtelemetry) | `true` |
1196 | [`disableNonessentialServices`](#disablenonessentialservices) | `true` |
1197 | [`disableAutoUpdates`](#disableautoupdates) | `true` |
1198 | [`modelCatalogEnabled`](#modelcatalogenabled) | `false` |
1199 | [`isLocalDevMcpEnabled`](#islocaldevmcpenabled) | `false` |
1200 | [`isDesktopExtensionEnabled`](#isdesktopextensionenabled) | `false` |
1201 | [`skillCreationEnabled`](#skillcreationenabled) | `false` |
1202 | [`scheduledTasksEnabled`](#scheduledtasksenabled) | `false` |
1203 | [`disabledBuiltinTools`](#disabledbuiltintools) | `["WebSearch","WebFetch"]` |
1204 | [`coworkEgressAllowedHosts`](#coworkegressallowedhosts) | `[]` |
1205 | [`allowedWorkspaceFolders`](#allowedworkspacefolders) | `[{"path":"~/Documents/Claude"}]` |
1206 | [`otlpEndpoint`](#otlpendpoint) | `<your-collector>` |
12071207 </Tab>
12081208</Tabs>
12091209 
12101210 

third-party/claude-desktop/configuration-changelog Changed · +207 / -207 lines

The two sides of this change are more than 400 edits apart, too far apart to line up, so this is the differ's own diff of it and the words inside a line are not marked.

from line 17
1717 
1818<Update label="v2.7032.0" description="2026-09-22">
1919 <div className="cfg-keys">
20 | MDM key | Type | Description |
21 | ------------------------------------------------------------------------------------------------------------------------ | --------- | ------------------------------------- |
22 | [`inferenceIdpAuthFlow`](/docs/third-party/claude-desktop/configuration#inferenceidpauthflow) | `enum` | Identity provider sign-in flow |
23 | [`inferenceIdpOidc`](/docs/third-party/claude-desktop/configuration#inferenceidpoidc) | `object` | Identity provider (OIDC) |
20 | MDM key | Type | Description |
21 | - | - | - |
22 | [`inferenceIdpAuthFlow`](/docs/third-party/claude-desktop/configuration#inferenceidpauthflow) | `enum` | Identity provider sign-in flow |
23 | [`inferenceIdpOidc`](/docs/third-party/claude-desktop/configuration#inferenceidpoidc) | `object` | Identity provider (OIDC) |
2424 | [`mcpScheduledTaskApprovalLifetimeDays`](/docs/third-party/claude-desktop/configuration#mcpscheduledtaskapprovallifetimedays) | `integer` | Scheduled-task tool approval lifetime |
25 | [`keepAwakeEnabled`](/docs/third-party/claude-desktop/configuration#keepawakeenabled) | `boolean` | Allow keep awake |
25 | [`keepAwakeEnabled`](/docs/third-party/claude-desktop/configuration#keepawakeenabled) | `boolean` | Allow keep awake |
2626 </div>
2727 
2828 **Set in the Claude admin console only:**
from line 81
8181 
8282<Update label="v2.2553.0" description="2026-09-17">
8383 <div className="cfg-keys">
84 | MDM key | Type | Description |
85 | ------------------------------------------------------------------------------------------------------------------ | ---------- | ------------------------------------------- |
86 | [`inferenceCredentialHelperWindows`](/docs/third-party/claude-desktop/configuration#inferencecredentialhelperwindows) | `string` | Helper script (Windows) |
87 | [`allowedPluginMcpServers`](/docs/third-party/claude-desktop/configuration#allowedpluginmcpservers) | `object[]` | Allowed plugin MCP servers |
88 | [`builtinBrowserEnabled`](/docs/third-party/claude-desktop/configuration#builtinbrowserenabled) | `boolean` | Allow the built-in browser |
89 | [`builtinBrowserDefaultDomainPolicy`](/docs/third-party/claude-desktop/configuration#builtinbrowserdefaultdomainpolicy) | `enum` | Default site policy in the built-in browser |
90 | [`builtinBrowserAllowedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowseralloweddomains) | `string[]` | Allowed sites in the built-in browser |
91 | [`builtinBrowserBlockedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowserblockeddomains) | `string[]` | Blocked sites in the built-in browser |
84 | MDM key | Type | Description |
85 | - | - | - |
86 | [`inferenceCredentialHelperWindows`](/docs/third-party/claude-desktop/configuration#inferencecredentialhelperwindows) | `string` | Helper script (Windows) |
87 | [`allowedPluginMcpServers`](/docs/third-party/claude-desktop/configuration#allowedpluginmcpservers) | `object[]` | Allowed plugin MCP servers |
88 | [`builtinBrowserEnabled`](/docs/third-party/claude-desktop/configuration#builtinbrowserenabled) | `boolean` | Allow the built-in browser |
89 | [`builtinBrowserDefaultDomainPolicy`](/docs/third-party/claude-desktop/configuration#builtinbrowserdefaultdomainpolicy) | `enum` | Default site policy in the built-in browser |
90 | [`builtinBrowserAllowedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowseralloweddomains) | `string[]` | Allowed sites in the built-in browser |
91 | [`builtinBrowserBlockedDomains`](/docs/third-party/claude-desktop/configuration#builtinbrowserblockeddomains) | `string[]` | Blocked sites in the built-in browser |
9292 </div>
9393 
9494 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 123
123123 
124124<Update label="v2.110.0" description="2026-09-15">
125125 <div className="cfg-keys">
126 | MDM key | Type | Description |
127 | ---------------------------------------------------------------------------------------------------------- | ---------- | ----------------------------------- |
128 | [`inferenceCredentialHelperArgs`](/docs/third-party/claude-desktop/configuration#inferencecredentialhelperargs) | `string[]` | Helper script arguments |
129 | [`inferenceFoundryBaseUrl`](/docs/third-party/claude-desktop/configuration#inferencefoundrybaseurl) | `string` | Azure AI Foundry base URL |
130 | [`defaultModelEffort`](/docs/third-party/claude-desktop/configuration#defaultmodeleffort) | `enum` | Default model effort |
131 | [`alwaysStartWithDefaultModel`](/docs/third-party/claude-desktop/configuration#alwaysstartwithdefaultmodel) | `boolean` | Always start with the default model |
132 | [`modelCatalogEnabled`](/docs/third-party/claude-desktop/configuration#modelcatalogenabled) | `boolean` | Model catalog metadata |
133 | [`modelCatalogUrl`](/docs/third-party/claude-desktop/configuration#modelcatalogurl) | `string` | Model catalog URL |
134 | [`scheduledTasksEnabled`](/docs/third-party/claude-desktop/configuration#scheduledtasksenabled) | `boolean` | Allow scheduled tasks |
126 | MDM key | Type | Description |
127 | - | - | - |
128 | [`inferenceCredentialHelperArgs`](/docs/third-party/claude-desktop/configuration#inferencecredentialhelperargs) | `string[]` | Helper script arguments |
129 | [`inferenceFoundryBaseUrl`](/docs/third-party/claude-desktop/configuration#inferencefoundrybaseurl) | `string` | Azure AI Foundry base URL |
130 | [`defaultModelEffort`](/docs/third-party/claude-desktop/configuration#defaultmodeleffort) | `enum` | Default model effort |
131 | [`alwaysStartWithDefaultModel`](/docs/third-party/claude-desktop/configuration#alwaysstartwithdefaultmodel) | `boolean` | Always start with the default model |
132 | [`modelCatalogEnabled`](/docs/third-party/claude-desktop/configuration#modelcatalogenabled) | `boolean` | Model catalog metadata |
133 | [`modelCatalogUrl`](/docs/third-party/claude-desktop/configuration#modelcatalogurl) | `string` | Model catalog URL |
134 | [`scheduledTasksEnabled`](/docs/third-party/claude-desktop/configuration#scheduledtasksenabled) | `boolean` | Allow scheduled tasks |
135135 </div>
136136 
137137 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 173
173173 
174174<Update label="v1.52386.0" description="2026-09-10">
175175 <div className="cfg-keys">
176 | MDM key | Type | Description |
177 | ---------------------------------------------------------------------------------------------------- | --------- | ------------------------------- |
178 | [`sshTransport`](/docs/third-party/claude-desktop/configuration#sshtransport) · Beta | `enum` | SSH connection engine |
179 | [`chatSessionRetentionDays`](/docs/third-party/claude-desktop/configuration#chatsessionretentiondays) | `integer` | Chat retention period |
180 | [`coworkSessionRetentionDays`](/docs/third-party/claude-desktop/configuration#coworksessionretentiondays) | `integer` | Cowork retention period |
181 | [`codeSessionRetentionDays`](/docs/third-party/claude-desktop/configuration#codesessionretentiondays) | `integer` | Code retention period |
182 | [`sessionRetentionHold`](/docs/third-party/claude-desktop/configuration#sessionretentionhold) | `boolean` | Suspend session deletion |
183 | [`coworkVmIpv6Enabled`](/docs/third-party/claude-desktop/configuration#coworkvmipv6enabled) | `boolean` | Enable IPv6 in the workspace VM |
176 | MDM key | Type | Description |
177 | - | - | - |
178 | [`sshTransport`](/docs/third-party/claude-desktop/configuration#sshtransport) · Beta | `enum` | SSH connection engine |
179 | [`chatSessionRetentionDays`](/docs/third-party/claude-desktop/configuration#chatsessionretentiondays) | `integer` | Chat retention period |
180 | [`coworkSessionRetentionDays`](/docs/third-party/claude-desktop/configuration#coworksessionretentiondays) | `integer` | Cowork retention period |
181 | [`codeSessionRetentionDays`](/docs/third-party/claude-desktop/configuration#codesessionretentiondays) | `integer` | Code retention period |
182 | [`sessionRetentionHold`](/docs/third-party/claude-desktop/configuration#sessionretentionhold) | `boolean` | Suspend session deletion |
183 | [`coworkVmIpv6Enabled`](/docs/third-party/claude-desktop/configuration#coworkvmipv6enabled) | `boolean` | Enable IPv6 in the workspace VM |
184184 </div>
185185 
186186 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 224
224224 
225225<Update label="v1.46388.1" description="2026-09-04">
226226 <div className="cfg-keys">
227 | MDM key | Type | Description |
228 | ---------------------------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- |
229 | [`sshClientPath`](/docs/third-party/claude-desktop/configuration#sshclientpath) · Beta | `string` | SSH client program |
230 | [`configRecheckIntervalMinutes`](/docs/third-party/claude-desktop/configuration#configrecheckintervalminutes) | `integer` | Configuration re-check interval |
231 | [`disableBypassPermissionsMode`](/docs/third-party/claude-desktop/configuration#disablebypasspermissionsmode) | `boolean` | Disable bypass permissions mode |
227 | MDM key | Type | Description |
228 | - | - | - |
229 | [`sshClientPath`](/docs/third-party/claude-desktop/configuration#sshclientpath) · Beta | `string` | SSH client program |
230 | [`configRecheckIntervalMinutes`](/docs/third-party/claude-desktop/configuration#configrecheckintervalminutes) | `integer` | Configuration re-check interval |
231 | [`disableBypassPermissionsMode`](/docs/third-party/claude-desktop/configuration#disablebypasspermissionsmode) | `boolean` | Disable bypass permissions mode |
232232 | [`blockReadsOutsideWorkingDirectories`](/docs/third-party/claude-desktop/configuration#blockreadsoutsideworkingdirectories) | `boolean` | Block reads outside working directories |
233233 </div>
234234 
from line 264
264264 
265265<Update label="v1.44121.1" description="2026-09-02">
266266 <div className="cfg-keys">
267 | MDM key | Type | Description |
268 | ---------------------------------------------------------------------------------------------------------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
269 | [`inferenceStreamIdleTimeoutSec`](/docs/third-party/claude-desktop/configuration#inferencestreamidletimeoutsec) | `integer` | Stream idle timeout |
270 | [`egressProxyUrl`](/docs/third-party/claude-desktop/configuration#egressproxyurl) | `string` | Proxy server URL |
271 | [`egressProxyPacUrl`](/docs/third-party/claude-desktop/configuration#egressproxypacurl) | `string` | Proxy auto-config (PAC) URL |
272 | [`claudeAiImport.automatic3pImport`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `boolean` | New subfield (beta): when `true` and `deploymentOrganizationUuid` is set, the app copies this computer's earlier third-party sessions stored before an organization ID was configured into that organization's session store, once per device and in the background; independent of `enabled` (default `false`). |
267 | MDM key | Type | Description |
268 | - | - | - |
269 | [`inferenceStreamIdleTimeoutSec`](/docs/third-party/claude-desktop/configuration#inferencestreamidletimeoutsec) | `integer` | Stream idle timeout |
270 | [`egressProxyUrl`](/docs/third-party/claude-desktop/configuration#egressproxyurl) | `string` | Proxy server URL |
271 | [`egressProxyPacUrl`](/docs/third-party/claude-desktop/configuration#egressproxypacurl) | `string` | Proxy auto-config (PAC) URL |
272 | [`claudeAiImport.automatic3pImport`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `boolean` | New subfield (beta): when `true` and `deploymentOrganizationUuid` is set, the app copies this computer's earlier third-party sessions stored before an organization ID was configured into that organization's session store, once per device and in the background; independent of `enabled` (default `false`). |
273273 </div>
274274 
275275 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 302
302302 
303303<Update label="v1.40609.0" description="2026-08-27">
304304 <div className="cfg-keys">
305 | MDM key | Type | Description |
306 | ---------------------------------------------------------------------------------------------------------------- | ---------- | --------------------------------------- |
307 | [`sshHostAllowlist`](/docs/third-party/claude-desktop/configuration#sshhostallowlist) · Beta | `string[]` | SSH host allowlist |
308 | [`disableConfigDeprecationWarnings`](/docs/third-party/claude-desktop/configuration#disableconfigdeprecationwarnings) | `boolean` | Hide configuration deprecation warnings |
305 | MDM key | Type | Description |
306 | - | - | - |
307 | [`sshHostAllowlist`](/docs/third-party/claude-desktop/configuration#sshhostallowlist) · Beta | `string[]` | SSH host allowlist |
308 | [`disableConfigDeprecationWarnings`](/docs/third-party/claude-desktop/configuration#disableconfigdeprecationwarnings) | `boolean` | Hide configuration deprecation warnings |
309309 </div>
310310 
311311 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 364
364364 
365365<Update label="v1.37937.0" description="2026-08-25">
366366 <div className="cfg-keys">
367 | MDM key | Type | Description |
368 | -------------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------------ |
369 | [`inferenceModelPricingEnabled`](/docs/third-party/claude-desktop/configuration#inferencemodelpricingenabled) | `boolean` | Show estimated cost |
370 | [`inferenceModelPricingMultiplier`](/docs/third-party/claude-desktop/configuration#inferencemodelpricingmultiplier) | `number` | Price multiplier |
371 | [`inferenceModelPricing`](/docs/third-party/claude-desktop/configuration#inferencemodelpricing) | `object[]` | Model pricing |
372 | [`userPluginMarketplacesEnabled`](/docs/third-party/claude-desktop/configuration#userpluginmarketplacesenabled) | `boolean` | Allow user-added plugin marketplaces |
373 | [`userPluginUploadsEnabled`](/docs/third-party/claude-desktop/configuration#userpluginuploadsenabled) | `boolean` | Allow user-added plugins |
374 | [`mcpToolTimeoutSec`](/docs/third-party/claude-desktop/configuration#mcptooltimeoutsec) | `integer` | MCP tool call timeout |
375 | [`skipWebFetchPreflight`](/docs/third-party/claude-desktop/configuration#skipwebfetchpreflight) | `boolean` | Skip WebFetch domain check |
376 | [`organizationInstructions`](/docs/third-party/claude-desktop/configuration#organizationinstructions) | `string` | Organization instructions |
367 | MDM key | Type | Description |
368 | - | - | - |
369 | [`inferenceModelPricingEnabled`](/docs/third-party/claude-desktop/configuration#inferencemodelpricingenabled) | `boolean` | Show estimated cost |
370 | [`inferenceModelPricingMultiplier`](/docs/third-party/claude-desktop/configuration#inferencemodelpricingmultiplier) | `number` | Price multiplier |
371 | [`inferenceModelPricing`](/docs/third-party/claude-desktop/configuration#inferencemodelpricing) | `object[]` | Model pricing |
372 | [`userPluginMarketplacesEnabled`](/docs/third-party/claude-desktop/configuration#userpluginmarketplacesenabled) | `boolean` | Allow user-added plugin marketplaces |
373 | [`userPluginUploadsEnabled`](/docs/third-party/claude-desktop/configuration#userpluginuploadsenabled) | `boolean` | Allow user-added plugins |
374 | [`mcpToolTimeoutSec`](/docs/third-party/claude-desktop/configuration#mcptooltimeoutsec) | `integer` | MCP tool call timeout |
375 | [`skipWebFetchPreflight`](/docs/third-party/claude-desktop/configuration#skipwebfetchpreflight) | `boolean` | Skip WebFetch domain check |
376 | [`organizationInstructions`](/docs/third-party/claude-desktop/configuration#organizationinstructions) | `string` | Organization instructions |
377377 </div>
378378 
379379 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 424
424424 
425425<Update label="v1.32885.1" description="2026-08-18">
426426 <div className="cfg-keys">
427 | MDM key | Type | Description |
428 | -------------------------------------------------------------------------------------------- | -------- | ------------------------------- |
429 | [`bootstrapHeaders`](/docs/third-party/claude-desktop/configuration#bootstrapheaders) | `object` | Bootstrap request headers |
427 | MDM key | Type | Description |
428 | - | - | - |
429 | [`bootstrapHeaders`](/docs/third-party/claude-desktop/configuration#bootstrapheaders) | `object` | Bootstrap request headers |
430430 | [`bootstrapHeadersHelper`](/docs/third-party/claude-desktop/configuration#bootstrapheadershelper) | `string` | Bootstrap headers helper script |
431431 </div>
432432 
from line 452
452452 
453453<Update label="v1.32352.0" description="2026-08-17">
454454 <div className="cfg-keys">
455 | MDM key | Type | Description |
456 | ------------------------------------------------------------------------------------------------------------------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
457 | [`claudeAiImport.exportEnabled`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `boolean` | New subfield: lets users export this computer's chats, Cowork tasks, and Code sessions from Settings > Import & export as a zip that another install can import; no effect unless `enabled` is `true` (default `false`). |
458 | [`allowedPluginMarketplaces[].manifestSha256`](/docs/third-party/claude-desktop/configuration#allowedpluginmarketplaces) | `string` | New subfield (beta): SHA-256 of the exact hosted `marketplace.json` a `url` marketplace may serve; required when `installationPreference` is `auto_install` or `required`, and a served manifest with any other digest is refused. |
455 | MDM key | Type | Description |
456 | - | - | - |
457 | [`claudeAiImport.exportEnabled`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `boolean` | New subfield: lets users export this computer's chats, Cowork tasks, and Code sessions from Settings > Import & export as a zip that another install can import; no effect unless `enabled` is `true` (default `false`). |
458 | [`allowedPluginMarketplaces[].manifestSha256`](/docs/third-party/claude-desktop/configuration#allowedpluginmarketplaces) | `string` | New subfield (beta): SHA-256 of the exact hosted `marketplace.json` a `url` marketplace may serve; required when `installationPreference` is `auto_install` or `required`, and a served manifest with any other digest is refused. |
459459 </div>
460460 
461461 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 491
491491 
492492<Update label="v1.30096.1" description="2026-08-13">
493493 <div className="cfg-keys">
494 | MDM key | Type | Description |
495 | ------------------------------------------------------------------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
496 | [`otlpAuthMode`](/docs/third-party/claude-desktop/configuration#otlpauthmode) | `enum` | Collector authentication |
497 | [`otlpHeadersHelper`](/docs/third-party/claude-desktop/configuration#otlpheadershelper) | `string` | OpenTelemetry headers helper script |
494 | MDM key | Type | Description |
495 | - | - | - |
496 | [`otlpAuthMode`](/docs/third-party/claude-desktop/configuration#otlpauthmode) | `enum` | Collector authentication |
497 | [`otlpHeadersHelper`](/docs/third-party/claude-desktop/configuration#otlpheadershelper) | `string` | OpenTelemetry headers helper script |
498498 | [`inferenceGatewayOidc.resource`](/docs/third-party/claude-desktop/configuration#inferencegatewayoidc) | `string` | New subfield: RFC 8707 resource indicator sent on gateway sign-in and token refresh so the IdP audience-restricts the access token to the gateway; leave unset for Microsoft Entra ID. |
499499 </div>
500500 
from line 523
523523 
524524<Update label="v1.28929.0" description="2026-08-11">
525525 <div className="cfg-keys">
526 | MDM key | Type | Description |
527 | ------------------------------------------------------------------------------------------- | --------- | -------------------------------------------------------------------------------------------------------------------- |
528 | [`modelPrefer1mContext`](/docs/third-party/claude-desktop/configuration#modelprefer1mcontext) | `boolean` | Default to 1M context |
529 | [`claudeAiImport.enabled`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `boolean` | New subfield: turns history import on; the banner and import actions stay off until set to `true` (default `false`). |
530 | [`claudeAiImport.bannerBehavior`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `enum` | New subfield: when the import banner appears: `off` (default), `detect`, or `show`. |
526 | MDM key | Type | Description |
527 | - | - | - |
528 | [`modelPrefer1mContext`](/docs/third-party/claude-desktop/configuration#modelprefer1mcontext) | `boolean` | Default to 1M context |
529 | [`claudeAiImport.enabled`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `boolean` | New subfield: turns history import on; the banner and import actions stay off until set to `true` (default `false`). |
530 | [`claudeAiImport.bannerBehavior`](/docs/third-party/claude-desktop/configuration#claudeaiimport) | `enum` | New subfield: when the import banner appears: `off` (default), `detect`, or `show`. |
531531 </div>
532532 
533533 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 551
551551 
552552<Update label="v1.26832.0" description="2026-08-06">
553553 <div className="cfg-keys">
554 | MDM key | Type | Description |
555 | ----------------------------------------------------------------------------------------------------- | --------- | --------------------------------------------------------------------------------------- |
556 | [`updateViaUpdatesHost`](/docs/third-party/claude-desktop/configuration#updateviaupdateshost) | `boolean` | Check for updates on releases.claude.com |
557 | [`allowedWorkspaceFolders[].mode`](/docs/third-party/claude-desktop/configuration#allowedworkspacefolders) | `enum` | New subfield: `ro` makes the folder read-only in Cowork; Code enforces file tools only. |
554 | MDM key | Type | Description |
555 | - | - | - |
556 | [`updateViaUpdatesHost`](/docs/third-party/claude-desktop/configuration#updateviaupdateshost) | `boolean` | Check for updates on releases.claude.com |
557 | [`allowedWorkspaceFolders[].mode`](/docs/third-party/claude-desktop/configuration#allowedworkspacefolders) | `enum` | New subfield: `ro` makes the folder read-only in Cowork; Code enforces file tools only. |
558558 </div>
559559 
560560 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 572
572572 
573573<Update label="v1.25927.0" description="2026-08-04">
574574 <div className="cfg-keys">
575 | MDM key | Type | Description |
576 | ---------------------------------------------------------------------------------------------------------------- | --------- | ---------------------------------------- |
577 | [`inferenceGatewayOidcAuthFlow`](/docs/third-party/claude-desktop/configuration#inferencegatewayoidcauthflow) | `enum` | Gateway sign-in flow |
578 | [`inferenceVertexWorkforceAuthFlow`](/docs/third-party/claude-desktop/configuration#inferencevertexworkforceauthflow) | `enum` | Workforce Identity sign-in flow |
579 | [`trustBootstrapLocalExec`](/docs/third-party/claude-desktop/configuration#trustbootstrapdelivery) | `boolean` | Trust bootstrap-delivered local commands |
580 | [`skillCreationEnabled`](/docs/third-party/claude-desktop/configuration#skillcreationenabled) | `boolean` | Allow user-created skills |
575 | MDM key | Type | Description |
576 | - | - | - |
577 | [`inferenceGatewayOidcAuthFlow`](/docs/third-party/claude-desktop/configuration#inferencegatewayoidcauthflow) | `enum` | Gateway sign-in flow |
578 | [`inferenceVertexWorkforceAuthFlow`](/docs/third-party/claude-desktop/configuration#inferencevertexworkforceauthflow) | `enum` | Workforce Identity sign-in flow |
579 | [`trustBootstrapLocalExec`](/docs/third-party/claude-desktop/configuration#trustbootstrapdelivery) | `boolean` | Trust bootstrap-delivered local commands |
580 | [`skillCreationEnabled`](/docs/third-party/claude-desktop/configuration#skillcreationenabled) | `boolean` | Allow user-created skills |
581581 </div>
582582 
583583 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 613
613613 
614614<Update label="v1.24012.9" description="2026-07-24">
615615 <div className="cfg-keys">
616 | MDM key | Type | Description |
617 | -------------------------------------------------------------------------------------------------------------- | --------- | ------------------------------- |
616 | MDM key | Type | Description |
617 | - | - | - |
618618 | [`mcpPersistentAlwaysAllowEnabled`](/docs/third-party/claude-desktop/configuration#mcppersistentalwaysallowenabled) | `boolean` | Allow persistent tool approvals |
619619 </div>
620620 
from line 631
631631 
632632<Update label="v1.24012.0" description="2026-07-21">
633633 <div className="cfg-keys">
634 | MDM key | Type | Description |
635 | -------------------------------------------------------------------------------------------- | --------- | ------------------------------ |
636 | [`enduserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) | `boolean` | End-user attribution |
637 | [`userContentRendererUrl`](/docs/third-party/claude-desktop/configuration#usercontentrendererurl) | `string` | Artifact preview iframe origin |
634 | MDM key | Type | Description |
635 | - | - | - |
636 | [`enduserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) | `boolean` | End-user attribution |
637 | [`userContentRendererUrl`](/docs/third-party/claude-desktop/configuration#usercontentrendererurl) | `string` | Artifact preview iframe origin |
638638 </div>
639639 
640640 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 655
655655 
656656<Update label="v1.22209.0" description="2026-07-16">
657657 <div className="cfg-keys">
658 | MDM key | Type | Description |
659 | ---------------------------------------------------------------------------------- | --------- | -------------------- |
658 | MDM key | Type | Description |
659 | - | - | - |
660660 | [`otlpTracesEnabled`](/docs/third-party/claude-desktop/configuration#otlptracesenabled) | `boolean` | Export traces (beta) |
661661 </div>
662662 
from line 677
677677 
678678<Update label="v1.21459.0" description="2026-07-14">
679679 <div className="cfg-keys">
680 | MDM key | Type | Description |
681 | ------------------------------------------------------------------------------------------------------------------ | --------- | ------------------------------------------------------------------------------------------------------------ |
682 | [`disableFeatureDiscovery`](/docs/third-party/claude-desktop/configuration#disablefeaturediscovery) | `boolean` | Hide feature announcements |
683 | [`inferenceModels[].prefer1m`](/docs/third-party/claude-desktop/configuration#inferencemodels) | `boolean` | New subfield: make the 1M-context variant the default picker selection when this model is the default entry. |
684 | [`managedMcpServers[].envHelper`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `string` | New subfield: helper executable that prints environment variables as JSON for a managed stdio server. |
685 | [`managedMcpServers[].envHelperTtlSec`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `integer` | New subfield: maximum age in seconds of a cached `envHelper` result (default 300). |
686 | [`managedMcpServers[].headersHelperRefreshBufferSec`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `integer` | New subfield: how many seconds before credential expiry the `headersHelper` re-runs (default 60). |
687 | [`toolSearchEnabled`](/docs/third-party/claude-desktop/configuration#toolsearchenabled) | `boolean` | Enable tool search |
680 | MDM key | Type | Description |
681 | - | - | - |
682 | [`disableFeatureDiscovery`](/docs/third-party/claude-desktop/configuration#disablefeaturediscovery) | `boolean` | Hide feature announcements |
683 | [`inferenceModels[].prefer1m`](/docs/third-party/claude-desktop/configuration#inferencemodels) | `boolean` | New subfield: make the 1M-context variant the default picker selection when this model is the default entry. |
684 | [`managedMcpServers[].envHelper`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `string` | New subfield: helper executable that prints environment variables as JSON for a managed stdio server. |
685 | [`managedMcpServers[].envHelperTtlSec`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `integer` | New subfield: maximum age in seconds of a cached `envHelper` result (default 300). |
686 | [`managedMcpServers[].headersHelperRefreshBufferSec`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `integer` | New subfield: how many seconds before credential expiry the `headersHelper` re-runs (default 60). |
687 | [`toolSearchEnabled`](/docs/third-party/claude-desktop/configuration#toolsearchenabled) | `boolean` | Enable tool search |
688688 </div>
689689 
690690 **JSON (e.g. for non-MDM users or Bootstrap):**
from line 716
716716 
717717<Update label="v1.19367.0" description="2026-07-07">
718718 <div className="cfg-keys">
719 | MDM key | Type | Description |
720 | ------------------------------------------------------------------------------------------------------ | --------- | --------------------------------------------------------------------------------- |
721 | [`inferenceFoundryAuthFlow`](/docs/third-party/claude-desktop/configuration#inferencefoundryauthflow) | `enum` | Entra ID sign-in flow |
722 | [`microsoftAuthBroker`](/docs/third-party/claude-desktop/configuration#microsoftauthbroker) | `enum` | Microsoft 365 native sign-in broker |
719 | MDM key | Type | Description |
720 | - | - | - |
721 | [`inferenceFoundryAuthFlow`](/docs/third-party/claude-desktop/configuration#inferencefoundryauthflow) | `enum` | Entra ID sign-in flow |
722 | [`microsoftAuthBroker`](/docs/third-party/claude-desktop/configuration#microsoftauthbroker) | `enum` | Microsoft 365 native sign-in broker |
723723 | [`managedMcpServers[].startupTimeoutSec`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `integer` | New subfield: maximum wait in seconds for the server to start and list its tools. |
724724 </div>
725725 
from line 760
760760 
761761<Update label="v1.17377.1" description="2026-06-30">
762762 <div className="cfg-keys">
763 | MDM key | Type | Description |
764 | -------------------------------------------------------------------------------------------------------------------------- | ---------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
765 | [`allowedPluginMarketplaces`](/docs/third-party/claude-desktop/configuration#allowedpluginmarketplaces) | `object[]` | Admin-configured plugin marketplace git URLs appear under the Directory's Organization tab. (MDM-only; not settable via bootstrap JSON.) |
766 | [`inferenceVertexWorkforceOidc.omitOfflineAccess`](/docs/third-party/claude-desktop/configuration#inferencevertexworkforceoidc) | `boolean` | New subfield: omit `offline_access` from the OIDC scope request. |
763 | MDM key | Type | Description |
764 | - | - | - |
765 | [`allowedPluginMarketplaces`](/docs/third-party/claude-desktop/configuration#allowedpluginmarketplaces) | `object[]` | Admin-configured plugin marketplace git URLs appear under the Directory's Organization tab. (MDM-only; not settable via bootstrap JSON.) |
766 | [`inferenceVertexWorkforceOidc.omitOfflineAccess`](/docs/third-party/claude-desktop/configuration#inferencevertexworkforceoidc) | `boolean` | New subfield: omit `offline_access` from the OIDC scope request. |
767767 </div>
768768 
769769 **JSON (Non-MDM User, Bootstrap Remote):**
from line 791
791791 
792792<Update label="v1.15962.0" description="2026-06-25">
793793 <div className="cfg-keys">
794 | MDM key | Type | Description |
795 | ------------------------------------------------------------------------------------------- | --------- | ------------------------------------------------------------------------ |
796 | [`otlpContentCapture`](/docs/third-party/claude-desktop/configuration#otlpcontentcapture) | `enum[]` | Content capture categories |
797 | [`disableBundledSkills`](/docs/third-party/claude-desktop/configuration#disablebundledskills) | `boolean` | Disable bundled skills and workflows |
798 | [`managedMcpServers[].server`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `enum` | Gained `"websearch"` — managed web search (Brave, Tavily, Exa or custom) |
794 | MDM key | Type | Description |
795 | - | - | - |
796 | [`otlpContentCapture`](/docs/third-party/claude-desktop/configuration#otlpcontentcapture) | `enum[]` | Content capture categories |
797 | [`disableBundledSkills`](/docs/third-party/claude-desktop/configuration#disablebundledskills) | `boolean` | Disable bundled skills and workflows |
798 | [`managedMcpServers[].server`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `enum` | Gained `"websearch"` — managed web search (Brave, Tavily, Exa or custom) |
799799 </div>
800800 
801801 **JSON (Non-MDM User, Bootstrap Remote):**
from line 831
831831 
832832<Update label="v1.14271.0" description="2026-06-18">
833833 <div className="cfg-keys">
834 | MDM key | Type | Description |
835 | --------------------------------- | --------- | ------------------------ |
836 | `chatAdvancedFileAnalysisEnabled` | `boolean` | Advanced file analysis |
837 | `inferenceSessionLifetimeSec` | `integer` | Sign-in session lifetime |
834 | MDM key | Type | Description |
835 | - | - | - |
836 | `chatAdvancedFileAnalysisEnabled` | `boolean` | Advanced file analysis |
837 | `inferenceSessionLifetimeSec` | `integer` | Sign-in session lifetime |
838838 </div>
839839 
840840 **JSON (Non-MDM User, Bootstrap Remote):**
from line 857
857857 
858858<Update label="v1.13576.0" description="2026-06-16">
859859 <div className="cfg-keys">
860 | MDM key | Type | Description |
861 | ---------------------------- | --------- | -------------- |
862 | `chatTabEnabled` | `boolean` | Allow Chat tab |
863 | `inferenceBedrockAwsCliPath` | `string` | AWS CLI path |
860 | MDM key | Type | Description |
861 | - | - | - |
862 | `chatTabEnabled` | `boolean` | Allow Chat tab |
863 | `inferenceBedrockAwsCliPath` | `string` | AWS CLI path |
864864 </div>
865865 
866866 **JSON (Non-MDM User, Bootstrap Remote):**
from line 881
881881 
882882<Update label="v1.12603.0" description="2026-06-11">
883883 <div className="cfg-keys">
884 | MDM key | Type | Description |
885 | ------------------------------- | -------- | ----------------------- |
884 | MDM key | Type | Description |
885 | - | - | - |
886886 | `inferenceVertexOAuthLoginHint` | `string` | Vertex OAuth login hint |
887887 </div>
888888 
from line 901
901901 
902902<Update label="v1.10628.0" description="2026-06-02">
903903 <div className="cfg-keys">
904 | MDM key | Type | Description |
905 | ----------------------------------------------- | --------- | ---------------------------------- |
906 | `inferenceVertexWorkforceAudience` | `string` | Workforce Identity audience |
907 | `inferenceVertexWorkforceUserProject` | `string` | Workforce Identity billing project |
908 | `inferenceVertexWorkforceOidc` | `object` | Workforce Identity IdP (OIDC) |
909 | `organizationPluginsUrl` | `string` | Organization plugins endpoint |
910 | `autoModeEnabled` | `boolean` | Allow Auto mode |
911 | `inferenceCredentialHelperSilentRefreshEnabled` | `boolean` | Re-run helper for silent refresh |
912 | `bootstrapEnabled` | `boolean` | Use bootstrap config |
913 | `bootstrapUrl` | `string` | Bootstrap config URL |
914 | `bootstrapOidc` | `object` | Bootstrap OIDC parameters |
904 | MDM key | Type | Description |
905 | - | - | - |
906 | `inferenceVertexWorkforceAudience` | `string` | Workforce Identity audience |
907 | `inferenceVertexWorkforceUserProject` | `string` | Workforce Identity billing project |
908 | `inferenceVertexWorkforceOidc` | `object` | Workforce Identity IdP (OIDC) |
909 | `organizationPluginsUrl` | `string` | Organization plugins endpoint |
910 | `autoModeEnabled` | `boolean` | Allow Auto mode |
911 | `inferenceCredentialHelperSilentRefreshEnabled` | `boolean` | Re-run helper for silent refresh |
912 | `bootstrapEnabled` | `boolean` | Use bootstrap config |
913 | `bootstrapUrl` | `string` | Bootstrap config URL |
914 | `bootstrapOidc` | `object` | Bootstrap OIDC parameters |
915915 </div>
916916 
917917 **JSON (Non-MDM User, Bootstrap Remote):**
from line 939
939939 
940940<Update label="v1.9659.0" description="2026-05-27">
941941 <div className="cfg-keys">
942 | MDM key | Type | Description |
943 | ------------------ | --------- | ---------------- |
942 | MDM key | Type | Description |
943 | - | - | - |
944944 | `coworkTabEnabled` | `boolean` | Allow Cowork tab |
945945 </div>
946946 
from line 957
957957 
958958<Update label="v1.9255.0" description="2026-05-26">
959959 <div className="cfg-keys">
960 | MDM key | Type | Description |
961 | -------------------------- | -------- | ------------------------------ |
962 | `otlpDesktopLogLevel` | `enum` | Desktop telemetry export level |
963 | `inferenceFoundryTenantId` | `string` | Entra ID tenant ID |
964 | `inferenceFoundryClientId` | `string` | Entra ID client ID |
960 | MDM key | Type | Description |
961 | - | - | - |
962 | `otlpDesktopLogLevel` | `enum` | Desktop telemetry export level |
963 | `inferenceFoundryTenantId` | `string` | Entra ID tenant ID |
964 | `inferenceFoundryClientId` | `string` | Entra ID client ID |
965965 </div>
966966 
967967 **JSON (Non-MDM User, Bootstrap Remote):**
from line 983
983983 
984984<Update label="v1.8555.0" description="2026-05-21">
985985 <div className="cfg-keys">
986 | MDM key | Type | Description |
987 | ------------------------- | ------ | --------------- |
986 | MDM key | Type | Description |
987 | - | - | - |
988988 | `inferenceCredentialKind` | `enum` | Credential kind |
989989 </div>
990990 
from line 1003
10031003 
10041004<Update label="v1.8089.0" description="2026-05-19">
10051005 <div className="cfg-keys">
1006 | MDM key | Type | Description |
1007 | ------------------------------------- | --------- | ----------------------------------------------------------------- |
1008 | `inferenceAnthropicApiKey` | `string` | Claude API key |
1009 | `inferenceCustomHeaders` | `object` | Custom inference headers (renamed from `inferenceGatewayHeaders`) |
1010 | `modelDiscoveryEnabled` | `boolean` | Model discovery |
1011 | `orgPluginSettings` | `object` | Organization plugin settings |
1012 | `builtinToolPolicy` | `object` | Built-in tool policy |
1013 | `inferenceCredentialHelperTimeoutSec` | `integer` | Credential helper timeout |
1006 | MDM key | Type | Description |
1007 | - | - | - |
1008 | `inferenceAnthropicApiKey` | `string` | Claude API key |
1009 | `inferenceCustomHeaders` | `object` | Custom inference headers (renamed from `inferenceGatewayHeaders`) |
1010 | `modelDiscoveryEnabled` | `boolean` | Model discovery |
1011 | `orgPluginSettings` | `object` | Organization plugin settings |
1012 | `builtinToolPolicy` | `object` | Built-in tool policy |
1013 | `inferenceCredentialHelperTimeoutSec` | `integer` | Credential helper timeout |
10141014 </div>
10151015 
10161016 **JSON (Non-MDM User, Bootstrap Remote):**
from line 1030
10301030 
10311031<Update label="v1.7196.0" description="2026-05-12">
10321032 <div className="cfg-keys">
1033 | MDM key | Type | Description |
1034 | -------- | -------- | ------------------- |
1033 | MDM key | Type | Description |
1034 | - | - | - |
10351035 | `banner` | `object` | Organization banner |
10361036 </div>
10371037</Update>
10381038 
10391039<Update label="v1.6889.0" description="2026-05-08">
10401040 <div className="cfg-keys">
1041 | MDM key | Type | Description |
1042 | ----------------------------- | --------- | ------------------------------------ |
1041 | MDM key | Type | Description |
1042 | - | - | - |
10431043 | `disableDeepLinkRegistration` | `boolean` | Disable claude:// deep-link handling |
1044 | `inferenceGatewayOidc` | `object` | Gateway SSO IdP (OIDC) |
1044 | `inferenceGatewayOidc` | `object` | Gateway SSO IdP (OIDC) |
10451045 </div>
10461046 
10471047 **JSON (Non-MDM User, Bootstrap Remote):**
from line 1068
10681068 
10691069<Update label="v1.6259.0" description="2026-05-05">
10701070 <div className="cfg-keys">
1071 | MDM key | Type | Description |
1072 | ------------------------------ | -------- | ------------------ |
1073 | `inferenceBedrockSsoStartUrl` | `string` | AWS SSO start URL |
1074 | `inferenceBedrockSsoRegion` | `string` | AWS SSO region |
1071 | MDM key | Type | Description |
1072 | - | - | - |
1073 | `inferenceBedrockSsoStartUrl` | `string` | AWS SSO start URL |
1074 | `inferenceBedrockSsoRegion` | `string` | AWS SSO region |
10751075 | `inferenceBedrockSsoAccountId` | `string` | AWS SSO account ID |
1076 | `inferenceBedrockSsoRoleName` | `string` | AWS SSO role name |
1076 | `inferenceBedrockSsoRoleName` | `string` | AWS SSO role name |
10771077 </div>
10781078 
10791079 **JSON (Non-MDM User, Bootstrap Remote):**
from line 1094
10941094 
10951095<Update label="v1.5354.0" description="2026-04-29">
10961096 <div className="cfg-keys">
1097 | MDM key | Type | Description |
1098 | ------------------------ | -------- | --------------------------------- |
1097 | MDM key | Type | Description |
1098 | - | - | - |
10991099 | `otlpResourceAttributes` | `object` | OpenTelemetry resource attributes |
11001100 </div>
11011101 
from line 1112
11121112 
11131113<Update label="v1.5186.0" description="2026-04-28">
11141114 <div className="cfg-keys">
1115 | MDM key | Type | Description |
1116 | ----------------------------- | ------ | -------------------- |
1115 | MDM key | Type | Description |
1116 | - | - | - |
11171117 | `inferenceBedrockServiceTier` | `enum` | Bedrock service tier |
11181118 </div>
11191119 
from line 1130
11301130 
11311131<Update label="v1.3834.0" description="2026-04-21">
11321132 <div className="cfg-keys">
1133 | MDM key | Type | Description |
1134 | ------------------------------ | --------- | ------------------------- |
1133 | MDM key | Type | Description |
1134 | - | - | - |
11351135 | `disableDeploymentModeChooser` | `boolean` | Disable Claude.ai sign-in |
11361136 </div>
11371137</Update>
11381138 
11391139<Update label="v1.3036.0" description="2026-04-16">
11401140 <div className="cfg-keys">
1141 | MDM key | Type | Description |
1142 | ---------------------------- | ------ | ------------------- |
1141 | MDM key | Type | Description |
1142 | - | - | - |
11431143 | `inferenceGatewayAuthScheme` | `enum` | Gateway auth scheme |
11441144 </div>
11451145 
from line 1158
11581158 
11591159<Update label="Baseline">
11601160 <div className="cfg-keys">
1161 | MDM key | Type | Description |
1162 | ------------------------------------- | ------------------------------------- | ----------------------------------------------------------------- |
1163 | `isDesktopExtensionEnabled` | `boolean` | Allow desktop extensions (renamed from `isDxtEnabled`) |
1164 | `isDesktopExtensionSignatureRequired` | `boolean` | Require signed extensions (renamed from `isDxtSignatureRequired`) |
1165 | `isLocalDevMcpEnabled` | `boolean` | Allow user-added MCP servers |
1166 | `isClaudeCodeForDesktopEnabled` | `boolean` | Allow Claude Code tab |
1167 | `coworkEgressAllowedHosts` | `array<string>` | Allowed egress hosts |
1168 | `otlpEndpoint` | `string` | OpenTelemetry collector endpoint |
1169 | `otlpProtocol` | `enum` | OpenTelemetry exporter protocol |
1170 | `otlpHeaders` | `object` | OpenTelemetry exporter headers |
1171 | `autoUpdaterEnforcementHours` | `integer` | Auto-update enforcement window |
1172 | `disableAutoUpdates` | `boolean` | Block auto-updates |
1173 | `inferenceProvider` | `enum` | Inference provider |
1174 | `inferenceGatewayBaseUrl` | `string` | Gateway base URL |
1175 | `inferenceGatewayApiKey` | `string` | Gateway API key |
1176 | `inferenceVertexProjectId` | `string` | GCP project ID |
1177 | `inferenceVertexRegion` | `string` | GCP region |
1178 | `inferenceVertexCredentialsFile` | `string` | GCP credentials file path |
1179 | `inferenceVertexOAuthClientId` | `string` | Vertex OAuth client ID |
1180 | `inferenceVertexOAuthClientSecret` | `string` | Vertex OAuth client secret |
1181 | `inferenceVertexOAuthScopes` | `string` | Vertex OAuth scopes |
1182 | `inferenceVertexBaseUrl` | `string` | Vertex AI base URL |
1183 | `inferenceBedrockRegion` | `string` | AWS region |
1184 | `inferenceBedrockBearerToken` | `string` | AWS bearer token |
1185 | `inferenceBedrockBaseUrl` | `string` | Bedrock base URL |
1186 | `inferenceBedrockProfile` | `string` | AWS profile name |
1187 | `inferenceBedrockAwsDir` | `string` | AWS config directory |
1188 | `inferenceFoundryResource` | `string` | Azure AI Foundry resource name |
1189 | `inferenceFoundryApiKey` | `string` | Azure AI Foundry API key |
1190 | `inferenceModels` | `array<string\|object>` | Model list |
1191 | `deploymentOrganizationUuid` | `string` | Organization UUID |
1192 | `disableEssentialTelemetry` | `boolean` | Block essential telemetry |
1193 | `disableNonessentialTelemetry` | `boolean` | Block nonessential telemetry |
1194 | `disableNonessentialServices` | `boolean` | Block nonessential services |
1195 | `managedMcpServers` | `array<object\|object\|object\|null>` | Managed MCP servers |
1196 | `disabledBuiltinTools` | `array<string>` | Disabled built-in tools |
1197 | `allowedWorkspaceFolders` | `array<string\|object>` | Allowed workspace folders |
1198 | `inferenceCredentialHelper` | `string` | Helper script |
1199 | `inferenceCredentialHelperTtlSec` | `integer` | Helper script TTL |
1200 | `inferenceMaxTokensPerWindow` | `integer` | Max tokens per window |
1201 | `inferenceTokenWindowHours` | `integer` | Token cap window |
1161 | MDM key | Type | Description |
1162 | - | - | - |
1163 | `isDesktopExtensionEnabled` | `boolean` | Allow desktop extensions (renamed from `isDxtEnabled`) |
1164 | `isDesktopExtensionSignatureRequired` | `boolean` | Require signed extensions (renamed from `isDxtSignatureRequired`) |
1165 | `isLocalDevMcpEnabled` | `boolean` | Allow user-added MCP servers |
1166 | `isClaudeCodeForDesktopEnabled` | `boolean` | Allow Claude Code tab |
1167 | `coworkEgressAllowedHosts` | `array<string>` | Allowed egress hosts |
1168 | `otlpEndpoint` | `string` | OpenTelemetry collector endpoint |
1169 | `otlpProtocol` | `enum` | OpenTelemetry exporter protocol |
1170 | `otlpHeaders` | `object` | OpenTelemetry exporter headers |
1171 | `autoUpdaterEnforcementHours` | `integer` | Auto-update enforcement window |
1172 | `disableAutoUpdates` | `boolean` | Block auto-updates |
1173 | `inferenceProvider` | `enum` | Inference provider |
1174 | `inferenceGatewayBaseUrl` | `string` | Gateway base URL |
1175 | `inferenceGatewayApiKey` | `string` | Gateway API key |
1176 | `inferenceVertexProjectId` | `string` | GCP project ID |
1177 | `inferenceVertexRegion` | `string` | GCP region |
1178 | `inferenceVertexCredentialsFile` | `string` | GCP credentials file path |
1179 | `inferenceVertexOAuthClientId` | `string` | Vertex OAuth client ID |
1180 | `inferenceVertexOAuthClientSecret` | `string` | Vertex OAuth client secret |
1181 | `inferenceVertexOAuthScopes` | `string` | Vertex OAuth scopes |
1182 | `inferenceVertexBaseUrl` | `string` | Vertex AI base URL |
1183 | `inferenceBedrockRegion` | `string` | AWS region |
1184 | `inferenceBedrockBearerToken` | `string` | AWS bearer token |
1185 | `inferenceBedrockBaseUrl` | `string` | Bedrock base URL |
1186 | `inferenceBedrockProfile` | `string` | AWS profile name |
1187 | `inferenceBedrockAwsDir` | `string` | AWS config directory |
1188 | `inferenceFoundryResource` | `string` | Azure AI Foundry resource name |
1189 | `inferenceFoundryApiKey` | `string` | Azure AI Foundry API key |
1190 | `inferenceModels` | `array<string\|object>` | Model list |
1191 | `deploymentOrganizationUuid` | `string` | Organization UUID |
1192 | `disableEssentialTelemetry` | `boolean` | Block essential telemetry |
1193 | `disableNonessentialTelemetry` | `boolean` | Block nonessential telemetry |
1194 | `disableNonessentialServices` | `boolean` | Block nonessential services |
1195 | `managedMcpServers` | `array<object\|object\|object\|null>` | Managed MCP servers |
1196 | `disabledBuiltinTools` | `array<string>` | Disabled built-in tools |
1197 | `allowedWorkspaceFolders` | `array<string\|object>` | Allowed workspace folders |
1198 | `inferenceCredentialHelper` | `string` | Helper script |
1199 | `inferenceCredentialHelperTtlSec` | `integer` | Helper script TTL |
1200 | `inferenceMaxTokensPerWindow` | `integer` | Max tokens per window |
1201 | `inferenceTokenWindowHours` | `integer` | Token cap window |
12021202 </div>
12031203 
12041204 **Deprecated:**
12051205 

third-party/claude-desktop/connectors-box Changed · +8 / -8 lines

from line 38
3838 <Step title="Add the server in the Enterprise Admin Console">
3939 In the Enterprise Admin Console ([claude.ai](https://claude.ai) → **Organization settings**), open the **Connectors** page under **Desktop 3P**. Under **Managed MCP servers**, click **Add → Blank** and fill in the entry:
4040 
41 | Field | Value |
42 | ------------------------------- | ----------------------------------------------------------------------------------- |
43 | **Name** | `Box` |
44 | **Transport** | **Streamable HTTP** |
45 | **URL** | `https://mcp.box.com` |
46 | **OAuth** | **Bring your own client** |
47 | **Client ID** | The client ID from step 1 |
41 | Field | Value |
42 | - | - |
43 | **Name** | `Box` |
44 | **Transport** | **Streamable HTTP** |
45 | **URL** | `https://mcp.box.com` |
46 | **OAuth** | **Bring your own client** |
47 | **Client ID** | The client ID from step 1 |
4848 | **Client secret helper script** | The script's absolute path from step 2, for example `/usr/local/bin/box-mcp-secret` |
49 | **Authorization server** | `["https://api.box.com"]` |
49 | **Authorization server** | `["https://api.box.com"]` |
5050 
5151 Click **Save changes**. Users' apps pick up the new entry as described under [Configuration updates](/docs/third-party/claude-desktop/admin-console#configuration-updates). Devices need outbound HTTPS access to `mcp.box.com`, `account.box.com`, and `api.box.com`.
5252 

third-party/claude-desktop/connectors-github Changed · +22 / -22 lines

from line 8
88 
99Both connectors expose the same family of GitHub tools; they differ in where the server runs and how users authenticate. Use this table to pick one, then follow that connector's section below.
1010 
11| | Remote connector | Local connector |
12| ------------------------ | ------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------- |
13| Where the server runs | GitHub's infrastructure | On the user's device, bundled in the app |
14| Authentication | A personal access token you issue and distribute | OAuth device flow; no tokens to issue or distribute |
15| Credential handling | Token delivered through the entry's `headers` or a headers helper script | User signs in; the token is acquired and stored encrypted on the device |
16| GitHub Enterprise Server | Not available; github.com only | Supported; set `host` |
17| Tool surface controls | Per-tool [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `toolsets`, `readOnly`, and per-tool [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers) |
18| Claude Desktop version | Any version that supports managed MCP servers | Requires a version that includes the bundled server (beta) |
11| | Remote connector | Local connector |
12| - | - | - |
13| Where the server runs | GitHub's infrastructure | On the user's device, bundled in the app |
14| Authentication | A personal access token you issue and distribute | OAuth device flow; no tokens to issue or distribute |
15| Credential handling | Token delivered through the entry's `headers` or a headers helper script | User signs in; the token is acquired and stored encrypted on the device |
16| GitHub Enterprise Server | Not available; github.com only | Supported; set `host` |
17| Tool surface controls | Per-tool [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers) | `toolsets`, `readOnly`, and per-tool [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers) |
18| Claude Desktop version | Any version that supports managed MCP servers | Requires a version that includes the bundled server (beta) |
1919 
2020## Remote connector
2121 
from line 69
6969 }
7070 ```
7171 
72 | Field | Required | Description |
73 | ------------ | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
74 | `name` | Yes | Unique display name, shown to users in connector settings. |
75 | `server` | Yes | Must be `github`. |
76 | `clientId` | Yes | The client ID of the OAuth app (or GitHub App) from step 1. |
77 | `host` | No | Base URL of your GitHub Enterprise Server instance, for example `https://github.example.com`. Leave unset for github.com. HTTPS is required. |
78 | `scope` | No | Space-separated OAuth scopes to request at sign-in, for example `repo read:org`. Defaults to `repo read:org read:user`. Ignored for GitHub Apps. |
79 | `toolsets` | No | Comma-separated [github-mcp-server toolsets](https://github.com/github/github-mcp-server) to enable, for example `context,repos,issues,pull_requests`. Defaults to the bundled server's default toolsets. |
80 | `readOnly` | No | `true` starts the server with read tools only; write tools are not registered at all. |
81 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
72 | Field | Required | Description |
73 | - | - | - |
74 | `name` | Yes | Unique display name, shown to users in connector settings. |
75 | `server` | Yes | Must be `github`. |
76 | `clientId` | Yes | The client ID of the OAuth app (or GitHub App) from step 1. |
77 | `host` | No | Base URL of your GitHub Enterprise Server instance, for example `https://github.example.com`. Leave unset for github.com. HTTPS is required. |
78 | `scope` | No | Space-separated OAuth scopes to request at sign-in, for example `repo read:org`. Defaults to `repo read:org read:user`. Ignored for GitHub Apps. |
79 | `toolsets` | No | Comma-separated [github-mcp-server toolsets](https://github.com/github/github-mcp-server) to enable, for example `context,repos,issues,pull_requests`. Defaults to the bundled server's default toolsets. |
80 | `readOnly` | No | `true` starts the server with read tools only; write tools are not registered at all. |
81 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
8282 
8383 In the in-app configuration window, the GitHub form offers the client ID, GitHub Enterprise Server URL, toolsets, and read-only fields; set `scope` through exported JSON or your device-management tool if you need a non-default scope set.
8484 </Step>
from line 86
8686 <Step title="Allow the required network hosts">
8787 The server and the sign-in flow call GitHub directly from the device, so in addition to the [base egress hosts](/docs/third-party/claude-desktop/telemetry#required-egress-paths), devices need outbound HTTPS access to:
8888 
89 | Host | Purpose |
90 | ---------------- | ------------------------- |
91 | `github.com` | OAuth device-flow sign-in |
92 | `api.github.com` | GitHub API calls |
89 | Host | Purpose |
90 | - | - |
91 | `github.com` | OAuth device-flow sign-in |
92 | `api.github.com` | GitHub API calls |
9393 
9494 GitHub Enterprise Server deployments need access to the instance's own host instead. No egress to any Anthropic host is needed for GitHub data.
9595 </Step>

third-party/claude-desktop/connectors-google-cloud Changed · +13 / -13 lines

from line 24
2424 <Step title="Add the server in the Enterprise Admin Console">
2525 In the Enterprise Admin Console ([claude.ai](https://claude.ai) → **Organization settings**), open the **Connectors** page under **Desktop 3P**. Under **Managed MCP servers**, click **Add → Blank** and fill in the entry:
2626 
27 | Field | Value |
28 | ------------------------ | ------------------------------------- |
29 | **Name** | `BigQuery` |
30 | **Transport** | **Streamable HTTP** |
31 | **URL** | `https://bigquery.googleapis.com/mcp` |
32 | **OAuth** | **Bring your own client** |
33 | **Client ID** | The client ID from step 2 |
34 | **Client secret** | The client secret from step 2 |
35 | **Authorization server** | `["https://accounts.google.com"]` |
27 | Field | Value |
28 | - | - |
29 | **Name** | `BigQuery` |
30 | **Transport** | **Streamable HTTP** |
31 | **URL** | `https://bigquery.googleapis.com/mcp` |
32 | **OAuth** | **Bring your own client** |
33 | **Client ID** | The client ID from step 2 |
34 | **Client secret** | The client secret from step 2 |
35 | **Authorization server** | `["https://accounts.google.com"]` |
3636 
3737 <Frame caption="A BigQuery entry on the Connectors page with OAuth set to Bring your own client.">
3838 <img src="https://mintcdn.com/claude-ai/l0HgWAJ4dDJ1-I-u/images/third-party/admin-console-managed-mcp-oauth.png?fit=max&auto=format&n=l0HgWAJ4dDJ1-I-u&q=85&s=efa91a216efb8f99c1e4aefc0ed5b16a" alt="Managed MCP server entry named BigQuery in the Enterprise Admin Console, with Transport set to Streamable HTTP, the BigQuery MCP URL, OAuth set to Bring your own client, and the Client ID, Client secret, and Authorization server fields filled in." width="1952" height="1705" data-path="images/third-party/admin-console-managed-mcp-oauth.png" />
from line 69
6969 
7070These messages appear in `main.log` in the [logs directory](/docs/third-party/claude-desktop/data-storage#where-data-lives) on the user's device.
7171 
72| Message | Cause | Fix |
73| ------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
74| `client_secret is missing` after the browser sign-in succeeds | The entry has no **Client secret** | Enter the secret of the client named in **Client ID**, with **Authorization server** set to `["https://accounts.google.com"]` |
75| `invalid_client` | The secret doesn't belong to the client named in **Client ID**, or was deleted in Google Cloud | In **APIs & Services → Credentials**, add a new secret to that client and update **Client secret** in the server's entry. Users then click **Connect** again |
72| Message | Cause | Fix |
73| - | - | - |
74| `client_secret is missing` after the browser sign-in succeeds | The entry has no **Client secret** | Enter the secret of the client named in **Client ID**, with **Authorization server** set to `["https://accounts.google.com"]` |
75| `invalid_client` | The secret doesn't belong to the client named in **Client ID**, or was deleted in Google Cloud | In **APIs & Services → Credentials**, add a new secret to that client and update **Client secret** in the server's entry. Users then click **Connect** again |
7676 

third-party/claude-desktop/connectors-m365 Changed · +105 / -105 lines

from line 12
1212 
1313Both connectors provide the same read and search tools; they differ in data path and authentication. Write actions (sending mail, managing drafts and calendar events, working with files, and sending Teams messages) are available on the local connector when you grant [write scopes](#grant-write-scopes). For write actions on the remote connector, contact your Anthropic representative. Use this table to pick one, then follow that connector's section below.
1414 
15| | Remote connector | Local connector |
16| ------------------------------- | ------------------------------------------------------------------------ | --------------------------------------------------------------------- |
17| Microsoft 365 data path | Transits Anthropic's infrastructure (no storage) | Stays between the user's device and Microsoft |
18| App registrations you own | One desktop client app, plus tenant consent to Anthropic's connector app | One dedicated public client app |
19| Token exchange | On-behalf-of exchange in Anthropic's infrastructure | Tokens acquired and stored on the device |
20| Allowlisting with Anthropic | Required (two to three business days) | Not needed |
21| Device egress | `login.microsoftonline.com` and the connector host | `login.microsoftonline.com` and `graph.microsoft.com` |
22| Device-based Conditional Access | Not supported (the server-side exchange has no device identity) | Supported on managed Windows and Mac devices through brokered sign-in |
23| Write actions | Contact your Anthropic representative | Available with [write scopes](#grant-write-scopes) |
24| US Government clouds | Separate connector deployment; contact your Anthropic representative | Built in; set `azureCloud` |
15| | Remote connector | Local connector |
16| - | - | - |
17| Microsoft 365 data path | Transits Anthropic's infrastructure (no storage) | Stays between the user's device and Microsoft |
18| App registrations you own | One desktop client app, plus tenant consent to Anthropic's connector app | One dedicated public client app |
19| Token exchange | On-behalf-of exchange in Anthropic's infrastructure | Tokens acquired and stored on the device |
20| Allowlisting with Anthropic | Required (two to three business days) | Not needed |
21| Device egress | `login.microsoftonline.com` and the connector host | `login.microsoftonline.com` and `graph.microsoft.com` |
22| Device-based Conditional Access | Not supported (the server-side exchange has no device identity) | Supported on managed Windows and Mac devices through brokered sign-in |
23| Write actions | Contact your Anthropic representative | Available with [write scopes](#grant-write-scopes) |
24| US Government clouds | Separate connector deployment; contact your Anthropic representative | Built in; set `azureCloud` |
2525 
2626## Remote connector
2727 
from line 35
3535 
3636Three applications participate in the sign-in chain. Understanding which one each ID refers to makes the setup steps below easier to follow.
3737 
38| Application | Owner | Purpose |
39| ----------------------- | ------------------------------- | ---------------------------------------------------------------------------- |
40| Desktop client app | You (registered in your tenant) | What Claude Desktop signs in as. Public client, PKCE, no secret. |
41| Anthropic connector app | Anthropic (multi-tenant) | Receives the desktop's token and calls Microsoft Graph on the user's behalf. |
42| Microsoft Graph | Microsoft | The Microsoft 365 data APIs. |
38| Application | Owner | Purpose |
39| - | - | - |
40| Desktop client app | You (registered in your tenant) | What Claude Desktop signs in as. Public client, PKCE, no secret. |
41| Anthropic connector app | Anthropic (multi-tenant) | Receives the desktop's token and calls Microsoft Graph on the user's behalf. |
42| Microsoft Graph | Microsoft | The Microsoft 365 data APIs. |
4343 
4444Claude Desktop signs in through your desktop client app, receives a token scoped to the Anthropic connector app, and sends that token to Anthropic's connector service. The connector service exchanges it for a Graph token using the on-behalf-of flow and makes Graph calls as the signed-in user.
4545 
from line 59
5959 
6060 The consent screen lists the delegated Microsoft Graph permissions the connector requests. All are read-only:
6161 
62 | Scope | Purpose |
63 | ----------------------------------------- | ----------------------------------------------------------- |
64 | `User.Read` | Read the signed-in user's profile |
65 | `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
66 | `Calendars.Read`, `Calendars.Read.Shared` | Read events in the user's and shared calendars |
67 | `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
68 | `Sites.Read.All` | Read SharePoint site content the user can access |
69 | `Chat.Read`, `ChatMessage.Read` | Read Teams chat messages the user can access |
70 | `offline_access` | Allow the desktop to refresh its token without re-prompting |
62 | Scope | Purpose |
63 | - | - |
64 | `User.Read` | Read the signed-in user's profile |
65 | `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
66 | `Calendars.Read`, `Calendars.Read.Shared` | Read events in the user's and shared calendars |
67 | `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
68 | `Sites.Read.All` | Read SharePoint site content the user can access |
69 | `Chat.Read`, `ChatMessage.Read` | Read Teams chat messages the user can access |
70 | `offline_access` | Allow the desktop to refresh its token without re-prompting |
7171 
7272 Review the permissions and select **Accept**.
7373 
from line 99
9999 <Step title="Configure Claude Desktop">
100100 In the Claude Desktop [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration), open **Connectors**, select **Add server → Microsoft 365**, and enter the values below.
101101 
102 | Field | Value |
103 | --------- | -------------------------------------------------------------------------- |
104 | Client ID | The Application (client) ID from step 2 |
105 | Tenant ID | Your Directory (tenant) ID |
106 | Scope | `api://07c030f6-5743-41b7-ba00-0a6e85f37c17/access_as_user offline_access` |
102 | Field | Value |
103 | - | - |
104 | Client ID | The Application (client) ID from step 2 |
105 | Tenant ID | Your Directory (tenant) ID |
106 | Scope | `api://07c030f6-5743-41b7-ba00-0a6e85f37c17/access_as_user offline_access` |
107107 
108108 Select **Save**, then deploy the configuration through your device-management tool as usual.
109109 
from line 132
132132 
133133In addition to the [base egress hosts](/docs/third-party/claude-desktop/telemetry#required-egress-paths), Claude Desktop needs outbound HTTPS access to the hosts below. The connector service itself calls `graph.microsoft.com` from Anthropic's infrastructure, so user devices do not need egress to Graph.
134134 
135| Host | Purpose |
136| ----------------------------- | ------------------------------------------------------------- |
137| `login.microsoftonline.com` | Microsoft Entra sign-in |
135| Host | Purpose |
136| - | - |
137| `login.microsoftonline.com` | Microsoft Entra sign-in |
138138| `microsoft365.mcp.claude.com` | The connector service (substitute your deployment's hostname) |
139139 
140140### Troubleshoot sign-in errors
from line 141
141141 
142142The errors below are the ones most commonly seen during setup. Each maps to a specific step that was missed or misconfigured.
143143 
144| Error | Cause | Fix |
145| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | --------------------------------- |
146| `AADSTS50011` redirect mismatch | Redirect URI is not exactly `http://127.0.0.1/callback`, or was registered under *Web* instead of *Mobile and desktop applications* | Re-check step 2.1 |
147| `AADSTS50194` multi-tenant required | Tenant ID is missing from the configuration | Add Tenant ID in step 4 |
148| `AADSTS65001` admin consent required | Step 1 was not completed, or step 2.4 was skipped | Complete admin consent |
149| `Client application is not authorized for this resource` | Anthropic allowlist not yet updated | Wait for confirmation from step 3 |
150| `AADSTS9000411` duplicate prompt parameter | Older Claude Desktop build | Upgrade to the current release |
144| Error | Cause | Fix |
145| - | - | - |
146| `AADSTS50011` redirect mismatch | Redirect URI is not exactly `http://127.0.0.1/callback`, or was registered under *Web* instead of *Mobile and desktop applications* | Re-check step 2.1 |
147| `AADSTS50194` multi-tenant required | Tenant ID is missing from the configuration | Add Tenant ID in step 4 |
148| `AADSTS65001` admin consent required | Step 1 was not completed, or step 2.4 was skipped | Complete admin consent |
149| `Client application is not authorized for this resource` | Anthropic allowlist not yet updated | Wait for confirmation from step 3 |
150| `AADSTS9000411` duplicate prompt parameter | Older Claude Desktop build | Upgrade to the current release |
151151 
152152## Local connector
153153 
from line 173
173173 <Step title="Configure Claude Desktop">
174174 In the Claude Desktop [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration), open **Connectors**, select **Add server**, and choose **Microsoft 365** under the **Built-in** group. Enter the values below, then select **Test connection** to verify that the server starts and lists its tools, and select **Save**.
175175 
176 | Field | Value |
177 | ----------- | ----------------------------------------------------------------------------------------------------------- |
178 | Tenant ID | Your Directory (tenant) ID |
179 | Client ID | The Application (client) ID from step 1 |
180 | Azure cloud | `global` (default), `us-gov-high`, or `us-gov-dod` |
181 | Access | Leave empty for standard read access, or list scopes explicitly (see [Configure scopes](#configure-scopes)) |
176 | Field | Value |
177 | - | - |
178 | Tenant ID | Your Directory (tenant) ID |
179 | Client ID | The Application (client) ID from step 1 |
180 | Azure cloud | `global` (default), `us-gov-high`, or `us-gov-dod` |
181 | Access | Leave empty for standard read access, or list scopes explicitly (see [Configure scopes](#configure-scopes)) |
182182 
183183 If you manage configuration through JSON or a plist directly, add an entry to [`managedMcpServers`](/docs/third-party/claude-desktop/configuration#managedmcpservers) with the `server` field set to `microsoft365`:
184184 
from line 191
191191 }
192192 ```
193193 
194 | Field | Required | Description |
195 | ---------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
196 | `name` | Yes | Unique display name, shown to users in connector settings. |
197 | `server` | Yes | Must be `microsoft365`. Built-in entries use this field instead of `url`, `transport`, or `command`; an entry that mixes `server` with those fields is rejected. |
198 | `clientId` | Yes | The Application (client) ID of the local-mode app from step 1. |
199 | `tenantId` | Yes | Your Directory (tenant) ID. |
200 | `azureCloud` | No | `global` (default), `us-gov-high`, or `us-gov-dod`. Selects the Microsoft Entra and Microsoft Graph hosts for US Government clouds. |
201 | `continuousAccessEvaluation` | No | `enabled` (default) or `disabled`. When enabled, the connector requests Continuous Access Evaluation-capable Microsoft Graph tokens, which live up to about 28 hours and stop working within minutes after an administrator revokes the user's sessions or disables the account in Entra, and, where your tenant enforces an IP named-location or Global Secure Access compliant-network Conditional Access policy, when the token is used from outside that network. `disabled` keeps standard one-hour tokens. A change applies to tokens issued after the connector next starts, and an already-issued token stays in use until it expires (select **Disconnect**, then **Connect**, to sign in again immediately). Requires Claude Desktop 1.49585.0 or later; earlier versions ignore the field and request standard one-hour tokens. |
202 | `scope` | No | Space-separated delegated Graph scopes to request instead of the default read set. A string array named `scopes` is also accepted until October 7, 2026. See [Configure scopes](#configure-scopes). |
203 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
194 | Field | Required | Description |
195 | - | - | - |
196 | `name` | Yes | Unique display name, shown to users in connector settings. |
197 | `server` | Yes | Must be `microsoft365`. Built-in entries use this field instead of `url`, `transport`, or `command`; an entry that mixes `server` with those fields is rejected. |
198 | `clientId` | Yes | The Application (client) ID of the local-mode app from step 1. |
199 | `tenantId` | Yes | Your Directory (tenant) ID. |
200 | `azureCloud` | No | `global` (default), `us-gov-high`, or `us-gov-dod`. Selects the Microsoft Entra and Microsoft Graph hosts for US Government clouds. |
201 | `continuousAccessEvaluation` | No | `enabled` (default) or `disabled`. When enabled, the connector requests Continuous Access Evaluation-capable Microsoft Graph tokens, which live up to about 28 hours and stop working within minutes after an administrator revokes the user's sessions or disables the account in Entra, and, where your tenant enforces an IP named-location or Global Secure Access compliant-network Conditional Access policy, when the token is used from outside that network. `disabled` keeps standard one-hour tokens. A change applies to tokens issued after the connector next starts, and an already-issued token stays in use until it expires (select **Disconnect**, then **Connect**, to sign in again immediately). Requires Claude Desktop 1.49585.0 or later; earlier versions ignore the field and request standard one-hour tokens. |
202 | `scope` | No | Space-separated delegated Graph scopes to request instead of the default read set. A string array named `scopes` is also accepted until October 7, 2026. See [Configure scopes](#configure-scopes). |
203 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
204204 
205205 The server ships inside the app, so nothing else needs to be installed on the device, and it activates only from managed configuration; users cannot add it themselves. Deploy the configuration through your device-management tool as usual.
206206 </Step>
from line 208
208208 <Step title="Allow the required network hosts for local mode">
209209 The local connector calls Microsoft directly from the device, so in addition to the [base egress hosts](/docs/third-party/claude-desktop/telemetry#required-egress-paths), devices need outbound HTTPS access to:
210210 
211 | Host | Purpose |
212 | --------------------------- | ------------------------- |
213 | `login.microsoftonline.com` | Microsoft Entra sign-in |
214 | `graph.microsoft.com` | Microsoft Graph data APIs |
211 | Host | Purpose |
212 | - | - |
213 | `login.microsoftonline.com` | Microsoft Entra sign-in |
214 | `graph.microsoft.com` | Microsoft Graph data APIs |
215215 
216216 US Government cloud deployments use `login.microsoftonline.us` and `graph.microsoft.us` (or `dod-graph.microsoft.us` for `us-gov-dod`) instead, matching the `azureCloud` setting. GCC High (`us-gov-high`) support has been confirmed in customer deployments. No egress to any Anthropic host is needed for Microsoft 365 data with the local connector.
217217 </Step>
from line 221
221221 
222222With no `scope` field, the connector requests the standard read set at sign-in:
223223 
224| Scope | Purpose |
225| ----------------------------------------- | ---------------------------------------------------------------------- |
226| `User.Read` | Read the signed-in user's profile |
227| `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
224| Scope | Purpose |
225| - | - |
226| `User.Read` | Read the signed-in user's profile |
227| `Mail.Read`, `Mail.Read.Shared` | Read mail in the user's and shared mailboxes |
228228| `Calendars.Read`, `Calendars.Read.Shared` | Read events in the user's and shared calendars, and find meeting times |
229| `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
230| `Sites.Read.All` | Read SharePoint site content the user can access |
231| `Chat.Read` | Read Teams chat messages the user can access |
232| `OnlineMeetings.Read` | Read the user's online meetings |
233| `offline_access` | Refresh tokens without re-prompting |
229| `Files.Read.All` | Read files the user can access in OneDrive and SharePoint |
230| `Sites.Read.All` | Read SharePoint site content the user can access |
231| `Chat.Read` | Read Teams chat messages the user can access |
232| `OnlineMeetings.Read` | Read the user's online meetings |
233| `offline_access` | Refresh tokens without re-prompting |
234234 
235235To request a different set, list scopes in the entry's `scope` field. The connector then requests exactly that list (plus `User.Read` and `offline_access`, which are always included). Use the list to narrow the read surface, to add the optional read scopes below, or to add [write scopes](#grant-write-scopes). Whatever you list must also be consented on the app registration from step 1; keep the two lists in sync.
236236 
from line 252
252252 
253253The connector provides these read and search tools:
254254 
255| Tool | What it does |
256| ----------------------------------------------- | --------------------------------------------------------------------------------------------------- |
257| `outlook_email_search` | Search Outlook mail |
258| `outlook_calendar_search` | Search calendar events |
259| `find_meeting_availability` | Find free meeting times |
260| `outlook_find_available_time` | Find open time slots for a meeting between the user and specific participants |
261| `chat_message_search` | Search Teams chat (1:1 and group; channel messages need `ChannelMessage.Read.All`) |
262| `sharepoint_search`, `sharepoint_folder_search` | Search SharePoint and OneDrive |
263| `read_resource` | Fetch a specific item, such as a message, event, or file |
264| `teams_list_chats` | List the user's Teams chats and their members, to find a chat to read or post in |
265| `get_me` | Return the signed-in user's own profile |
266| `search_people` | Search for people by name or email address (needs `People.Read`) |
267| `teams_list_teams`, `teams_list_channels` | List the user's teams and a team's channels (need `Team.ReadBasic.All` and `Channel.ReadBasic.All`) |
268| `teams_list_channel_messages` | List a channel's messages, or the replies in one conversation (needs `ChannelMessage.Read.All`) |
255| Tool | What it does |
256| - | - |
257| `outlook_email_search` | Search Outlook mail |
258| `outlook_calendar_search` | Search calendar events |
259| `find_meeting_availability` | Find free meeting times |
260| `outlook_find_available_time` | Find open time slots for a meeting between the user and specific participants |
261| `chat_message_search` | Search Teams chat (1:1 and group; channel messages need `ChannelMessage.Read.All`) |
262| `sharepoint_search`, `sharepoint_folder_search` | Search SharePoint and OneDrive |
263| `read_resource` | Fetch a specific item, such as a message, event, or file |
264| `teams_list_chats` | List the user's Teams chats and their members, to find a chat to read or post in |
265| `get_me` | Return the signed-in user's own profile |
266| `search_people` | Search for people by name or email address (needs `People.Read`) |
267| `teams_list_teams`, `teams_list_channels` | List the user's teams and a team's channels (need `Team.ReadBasic.All` and `Channel.ReadBasic.All`) |
268| `teams_list_channel_messages` | List a channel's messages, or the replies in one conversation (needs `ChannelMessage.Read.All`) |
269269 
270270Granting write scopes enables write tools; see [Grant write scopes](#grant-write-scopes).
271271 
from line 273
273273 
274274With only read scopes granted, the connector is read-only. To let Claude take actions in Microsoft 365 (sending mail, managing drafts, labels, and calendar events, working with files in OneDrive and SharePoint, and sending Teams chat and channel messages), grant write scopes: add them to the entry's `scope` field and consent them on the app registration from step 1, the same as any other scope. Each write tool appears only when its scope is in the entry's list, so granting a subset of the write scopes exposes a matching subset of the tools, and removing the write scopes from the list returns the connector to read-only. Write tools require Claude Desktop version 1.19367.0 or later, and the Teams write tools require version 1.24012.0 or later.
275275 
276| Scope | What it enables |
277| --------------------------- | ------------------------------------------------------------------------------------------------------------- |
278| `Mail.Send` | Send mail, send drafts, and forward mail |
279| `Mail.ReadWrite` | Create, update, and delete drafts; trash, untrash, and delete messages; apply and remove labels on messages |
280| `Calendars.ReadWrite` | Create, update, delete, and respond to calendar events |
281| `Files.ReadWrite.All` | Create, update, rename, move, copy, and delete files and folders the user can edit in OneDrive and SharePoint |
282| `MailboxSettings.ReadWrite` | Create and delete mail filters, manage labels, and configure automatic replies |
283| `ChatMessage.Send` | Post messages in existing Teams chats |
284| `ChannelMessage.Send` | Post and reply to messages in Teams channels |
285| `Chat.Create` | Start 1:1 and group Teams chats |
276| Scope | What it enables |
277| - | - |
278| `Mail.Send` | Send mail, send drafts, and forward mail |
279| `Mail.ReadWrite` | Create, update, and delete drafts; trash, untrash, and delete messages; apply and remove labels on messages |
280| `Calendars.ReadWrite` | Create, update, delete, and respond to calendar events |
281| `Files.ReadWrite.All` | Create, update, rename, move, copy, and delete files and folders the user can edit in OneDrive and SharePoint |
282| `MailboxSettings.ReadWrite` | Create and delete mail filters, manage labels, and configure automatic replies |
283| `ChatMessage.Send` | Post messages in existing Teams chats |
284| `ChannelMessage.Send` | Post and reply to messages in Teams channels |
285| `Chat.Create` | Start 1:1 and group Teams chats |
286286 
287287Sending drafts and forwarding mail also require a mail read scope (one of `Mail.Read`, `Mail.ReadWrite`, or `Mail.Read.Shared`) for the pre-send checks; the standard read set already includes one.
288288 
from line 341
341341 
342342### Troubleshoot the local connector
343343 
344| Symptom | Cause | Fix |
345| ----------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
346| **Test connection** reports that the built-in server is not included | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop |
347| **Microsoft 365** is missing from the **Add server** options | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop, or author the JSON entry directly |
348| Connector missing from settings | The entry was rejected during configuration parsing: an unrecognized scope name in `scope`, a missing `tenantId` or `clientId`, or a `url`, `transport`, or `command` field mixed into the entry | Check the app's main log for a line naming the dropped entry |
349| Sign-in opens the browser on a managed device where the broker was expected | macOS: Claude Desktop is older than 1.19367.0, Company Portal is not installed, the SSO configuration profile is not deployed, or the broker redirect URI is not registered. Windows: Claude Desktop is older than 1.13576.0, the device is not Entra-joined or Entra-registered, or `microsoftAuthBroker` is set to `disabled` | Re-check the brokered sign-in requirements above |
350| `AADSTS50011` redirect mismatch | The redirect URI named in the error message (`http://localhost` for browser sign-in, or the platform's broker redirect URI for brokered sign-in) is missing from the local-mode app registration, was entered with a different value, or was added under *Web* instead of *Mobile and desktop applications* | Add or correct that URI under *Mobile and desktop applications* (step 1.2, or the brokered sign-in requirements above) |
351| `AADSTS900971` no reply address provided | The macOS broker redirect URI is not registered on the local-mode app | Register `msauth.com.anthropic.claudefordesktop://auth` as described in step 1.2 (after you save, it appears under the **iOS / macOS** section) |
352| `AADSTS65001` admin consent required | Graph delegated permissions were not admin-consented | Re-check step 1.4 |
353| `AADSTS53003` blocked by Conditional Access | A device-compliance policy is evaluating a sign-in that carries no device claim | Meet the brokered sign-in requirements for the platform, then restart Claude Desktop |
354| `AADSTS7000218` request body must contain client\_assertion or client\_secret | **Allow public client flows** is set to No on the local-mode app registration, so brokered token requests are classified as confidential | Set **Allow public client flows** to **Yes** (step 1.3) |
355| Tools return a permission error or Graph `403` | A scope the tool needs is not consented on the app registration, or is excluded by an explicit `scope` list | Add the scope in both places and grant admin consent |
356| Write tools are missing or fail | The matching write scope is not listed in the entry's `scope` field, or the installed Claude Desktop version predates write support | Add the scope to the entry and consent it on the app registration (see [Grant write scopes](#grant-write-scopes)), and upgrade Claude Desktop |
344| Symptom | Cause | Fix |
345| - | - | - |
346| **Test connection** reports that the built-in server is not included | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop |
347| **Microsoft 365** is missing from the **Add server** options | The installed Claude Desktop version predates the built-in connector | Upgrade Claude Desktop, or author the JSON entry directly |
348| Connector missing from settings | The entry was rejected during configuration parsing: an unrecognized scope name in `scope`, a missing `tenantId` or `clientId`, or a `url`, `transport`, or `command` field mixed into the entry | Check the app's main log for a line naming the dropped entry |
349| Sign-in opens the browser on a managed device where the broker was expected | macOS: Claude Desktop is older than 1.19367.0, Company Portal is not installed, the SSO configuration profile is not deployed, or the broker redirect URI is not registered. Windows: Claude Desktop is older than 1.13576.0, the device is not Entra-joined or Entra-registered, or `microsoftAuthBroker` is set to `disabled` | Re-check the brokered sign-in requirements above |
350| `AADSTS50011` redirect mismatch | The redirect URI named in the error message (`http://localhost` for browser sign-in, or the platform's broker redirect URI for brokered sign-in) is missing from the local-mode app registration, was entered with a different value, or was added under *Web* instead of *Mobile and desktop applications* | Add or correct that URI under *Mobile and desktop applications* (step 1.2, or the brokered sign-in requirements above) |
351| `AADSTS900971` no reply address provided | The macOS broker redirect URI is not registered on the local-mode app | Register `msauth.com.anthropic.claudefordesktop://auth` as described in step 1.2 (after you save, it appears under the **iOS / macOS** section) |
352| `AADSTS65001` admin consent required | Graph delegated permissions were not admin-consented | Re-check step 1.4 |
353| `AADSTS53003` blocked by Conditional Access | A device-compliance policy is evaluating a sign-in that carries no device claim | Meet the brokered sign-in requirements for the platform, then restart Claude Desktop |
354| `AADSTS7000218` request body must contain client\_assertion or client\_secret | **Allow public client flows** is set to No on the local-mode app registration, so brokered token requests are classified as confidential | Set **Allow public client flows** to **Yes** (step 1.3) |
355| Tools return a permission error or Graph `403` | A scope the tool needs is not consented on the app registration, or is excluded by an explicit `scope` list | Add the scope in both places and grant admin consent |
356| Write tools are missing or fail | The matching write scope is not listed in the entry's `scope` field, or the installed Claude Desktop version predates write support | Add the scope to the entry and consent it on the app registration (see [Grant write scopes](#grant-write-scopes)), and upgrade Claude Desktop |
357357 
358358The connector writes its sign-in and Microsoft Graph errors to its own log file in the Claude Desktop logs directory (`~/Library/Logs/Claude-3p/` on macOS, `%LOCALAPPDATA%\Claude-3p\logs\` on Windows), named `mcp-server-office365-builtin.log`. Configuration parsing and connection lifecycle messages appear in `main.log` in the same directory.
359359 

third-party/claude-desktop/connectors-salesforce Changed · +8 / -8 lines

from line 38
3838 <Step title="Add the Salesforce MCP server">
3939 **In the Enterprise Admin Console.** Go to [claude.ai](https://claude.ai) → **Organization settings** and open the **Connectors** page under **Desktop 3P**. Under **Managed MCP servers**, click **Add → Blank**, fill in the entry as below, and click **Save changes**. [Set up sign-in for managed MCP servers](/docs/third-party/claude-desktop/mcp-sign-in) explains each **OAuth** field, and users' apps pick up console changes as described under [Configuration updates](/docs/third-party/claude-desktop/admin-console#configuration-updates).
4040 
41 | Field | Value |
42 | ------------------------ | ------------------------------------------------------------------ |
43 | **Name** | `salesforce-h360` |
44 | **Transport** | **Streamable HTTP** |
45 | **URL** | `https://api.salesforce.com/platform/mcp/v1/platform/headless-360` |
46 | **OAuth** | **Bring your own client** |
47 | **Client ID** | The Consumer Key from step 1 |
48 | **Authorization server** | `["https://login.salesforce.com"]` |
41 | Field | Value |
42 | - | - |
43 | **Name** | `salesforce-h360` |
44 | **Transport** | **Streamable HTTP** |
45 | **URL** | `https://api.salesforce.com/platform/mcp/v1/platform/headless-360` |
46 | **OAuth** | **Bring your own client** |
47 | **Client ID** | The Consumer Key from step 1 |
48 | **Authorization server** | `["https://login.salesforce.com"]` |
4949 
5050 **With MDM or a bootstrap server.** Add this entry to the [`managedMcpServers`](/docs/third-party/claude-desktop/configuration#managedmcpservers) key of your managed configuration or bootstrap response:
5151 

third-party/claude-desktop/credential-helper Changed · +6 / -6 lines

from line 52
5252 
5353Claude Desktop sets the `CLAUDE_HELPER_CONTEXT` environment variable on every invocation so the script can decide whether interactive authentication (opening a browser, prompting for a device code) is appropriate.
5454 
55| Value | Meaning |
56| --------------------- | ----------------------------------------------------------------------------------------------- |
57| `interactive` | The user started a session and is present. Interactive sign-in is acceptable. |
55| Value | Meaning |
56| - | - |
57| `interactive` | The user started a session and is present. Interactive sign-in is acceptable. |
5858| `mid-session-refresh` | A running session's credential expired. Prefer a silent refresh; the user is waiting on a turn. |
59| `scheduled-task` | A scheduled task started with no user present. |
60| `setup-test` | The in-app configuration window's connection test. |
61| `background` | A background probe or health check. |
59| `scheduled-task` | A scheduled task started with no user present. |
60| `setup-test` | The in-app configuration window's connection test. |
61| `background` | A background probe or health check. |
6262 
6363A well-behaved helper should attempt its silent path (cached token, refresh-token grant) for any value other than `interactive`, and exit non-zero rather than block on user input when that path is exhausted. Claude Desktop treats a non-zero exit as a refresh failure and surfaces it to the user.
6464 

third-party/claude-desktop/data-storage Changed · +24 / -24 lines

from line 14
1414 
1515Claude Desktop on 3P stores everything under a dedicated directory, separate from standard Claude Desktop, so the two modes can coexist on one machine without interfering.
1616 
17| Platform | Application data | Logs |
18| -------- | ------------------------------------------ | -------------------------------------- |
19| macOS | `~/Library/Application Support/Claude-3p/` | `~/Library/Logs/Claude-3p/` |
20| Windows | `%LOCALAPPDATA%\Claude-3p\` | (under the application-data directory) |
21| Linux | `~/.config/Claude-3p/` | (under the application-data directory) |
17| Platform | Application data | Logs |
18| - | - | - |
19| macOS | `~/Library/Application Support/Claude-3p/` | `~/Library/Logs/Claude-3p/` |
20| Windows | `%LOCALAPPDATA%\Claude-3p\` | (under the application-data directory) |
21| Linux | `~/.config/Claude-3p/` | (under the application-data directory) |
2222 
2323<Note>
2424 On Windows, earlier Claude Desktop releases stored this data under `%APPDATA%\Claude-3p\` (the Roaming profile). On first launch after upgrading, the app moves the existing directory to `%LOCALAPPDATA%` automatically; if Roaming is redirected to a network share, conversation history and configuration are copied and large regenerable caches are re-downloaded. Update any external tooling, backup jobs, or endpoint policies that reference the old path. macOS paths are unchanged.
from line 26
2626 
2727Within the application-data directory:
2828 
29| Path | Contents |
30| ------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
31| `ant-did` | The random device identifier described above. |
32| `configLibrary/` | Locally authored configuration (from the in-app configuration window). `_meta.json` records which saved configuration is applied; each is a `<id>.json` file alongside it. Ignored when a managed profile is present. |
33| `local-agent-mode-sessions/.../cowork_account_settings.json` | User-level preferences set in the app (display name, locale, memory toggle). |
34| `local-agent-mode-sessions/` | Cowork and Chat conversation history. One `local_<uuid>.json` file plus a working directory per session, scoped by account and organization ID. The working directory includes an `uploads/` subdirectory with copies of files attached to the conversation and an `outputs/` subdirectory for files Claude creates. |
35| `local-agent-mode-sessions/.../memory/` | Cowork memory: a `CLAUDE.md` instructions file plus a `memory/` subdirectory of Markdown notes Claude writes about the user's preferences, projects, and feedback. See [Memory](#memory). |
36| `local-agent-mode-sessions/.../spaces/<projectId>/memory/` | Markdown memory notes for one project, used by Cowork sessions and Chat conversations inside that project. See [Memory](#memory). |
37| `local-agent-mode-sessions/.../<sessionId>/audit.jsonl` | Append-only log of session events (tool invocations, permission decisions, file operations). Each entry is HMAC-chained to the previous one so edits or deletions are detectable; the companion `.audit-key` file holds the per-session signing key, encrypted via the OS keychain. |
38| `claude-code-sessions/` | Code session records holding each session's working folder, settings, title, and sometimes a short summary. The conversation transcripts themselves are in Claude Code's own store at `~/.claude/projects/`, outside this directory. |
39| `claude-code/`, `claude-code-vm/` | Claude Code binary and VM workspace data for Code sessions. |
40| `vm_bundles/` | Cached copy of the VM workspace bundle that Cowork sessions run in, plus the data disk the app creates to hold those sessions' home directories inside the VM. |
41| `cowork_plugins/` | User-installed and [org-provisioned](/docs/third-party/claude-desktop/extensions#organization-plugins-admin) plugins. Created on first plugin install. |
42| `IndexedDB/`, `Local Storage/`, `Session Storage/` | Renderer-side UI state (window layout, recent folders, preferences). |
29| Path | Contents |
30| - | - |
31| `ant-did` | The random device identifier described above. |
32| `configLibrary/` | Locally authored configuration (from the in-app configuration window). `_meta.json` records which saved configuration is applied; each is a `<id>.json` file alongside it. Ignored when a managed profile is present. |
33| `local-agent-mode-sessions/.../cowork_account_settings.json` | User-level preferences set in the app (display name, locale, memory toggle). |
34| `local-agent-mode-sessions/` | Cowork and Chat conversation history. One `local_<uuid>.json` file plus a working directory per session, scoped by account and organization ID. The working directory includes an `uploads/` subdirectory with copies of files attached to the conversation and an `outputs/` subdirectory for files Claude creates. |
35| `local-agent-mode-sessions/.../memory/` | Cowork memory: a `CLAUDE.md` instructions file plus a `memory/` subdirectory of Markdown notes Claude writes about the user's preferences, projects, and feedback. See [Memory](#memory). |
36| `local-agent-mode-sessions/.../spaces/<projectId>/memory/` | Markdown memory notes for one project, used by Cowork sessions and Chat conversations inside that project. See [Memory](#memory). |
37| `local-agent-mode-sessions/.../<sessionId>/audit.jsonl` | Append-only log of session events (tool invocations, permission decisions, file operations). Each entry is HMAC-chained to the previous one so edits or deletions are detectable; the companion `.audit-key` file holds the per-session signing key, encrypted via the OS keychain. |
38| `claude-code-sessions/` | Code session records holding each session's working folder, settings, title, and sometimes a short summary. The conversation transcripts themselves are in Claude Code's own store at `~/.claude/projects/`, outside this directory. |
39| `claude-code/`, `claude-code-vm/` | Claude Code binary and VM workspace data for Code sessions. |
40| `vm_bundles/` | Cached copy of the VM workspace bundle that Cowork sessions run in, plus the data disk the app creates to hold those sessions' home directories inside the VM. |
41| `cowork_plugins/` | User-installed and [org-provisioned](/docs/third-party/claude-desktop/extensions#organization-plugins-admin) plugins. Created on first plugin install. |
42| `IndexedDB/`, `Local Storage/`, `Session Storage/` | Renderer-side UI state (window layout, recent folders, preferences). |
4343 
4444Files in this directory are written with owner-only permissions so other OS accounts on the same machine cannot read them. The app encrypts stored sign-in tokens and similar secrets with the operating system's secure storage (see [Credentials](#credentials)), but not conversations, settings, or locally applied configuration, including an API key saved from the in-app configuration window. Protection at rest for those files depends on the device's full-disk encryption, such as FileVault or BitLocker.
4545 
from line 79
7979 
8080Parts of each session run as separate processes: the sandbox VM for Cowork sessions, and the Claude Code runtime for Code sessions. Processes that cannot receive credentials through an in-memory channel read them from short-lived files that the app writes for them. All of these files are created with owner-only permissions and are cleaned up automatically:
8181 
82| Path (within the application-data directory) | Contents | Lifecycle |
83| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
84| `host-creds-<random-id>.json` | The resolved inference credential (bearer token or API key, plus the endpoint), as environment values for background Claude Code worker processes. Written atomically with owner-only permissions (mode `0600` on macOS; per-user ACLs on Windows). | Rewritten on each credential refresh; deleted when the app quits; leftovers from a crash are removed at the next launch. The random path segment is regenerated when you sign out of the inference provider or its credentials are rotated, so a process holding the old path loses access. |
85| `ccd-session-secrets/<session-id>/` | File-based credentials for Code sessions: Google Cloud application default credentials for Google Cloud's Agent Platform, or AWS configuration files for Amazon Bedrock. The directory is created with owner-only permissions (mode `0700` on macOS; per-user ACLs on Windows). | Created when the session starts; removed when the session ends; the whole directory is swept before the next Code session starts and when you sign out of the inference provider. |
86| Per-session working directory | For Cowork sessions, the same file-based credentials (Google Cloud's Agent Platform and Amazon Bedrock) are written into the session's working directory, which is mounted into the sandbox VM. | Scoped to the session; removed with the session directory. |
82| Path (within the application-data directory) | Contents | Lifecycle |
83| - | - | - |
84| `host-creds-<random-id>.json` | The resolved inference credential (bearer token or API key, plus the endpoint), as environment values for background Claude Code worker processes. Written atomically with owner-only permissions (mode `0600` on macOS; per-user ACLs on Windows). | Rewritten on each credential refresh; deleted when the app quits; leftovers from a crash are removed at the next launch. The random path segment is regenerated when you sign out of the inference provider or its credentials are rotated, so a process holding the old path loses access. |
85| `ccd-session-secrets/<session-id>/` | File-based credentials for Code sessions: Google Cloud application default credentials for Google Cloud's Agent Platform, or AWS configuration files for Amazon Bedrock. The directory is created with owner-only permissions (mode `0700` on macOS; per-user ACLs on Windows). | Created when the session starts; removed when the session ends; the whole directory is swept before the next Code session starts and when you sign out of the inference provider. |
86| Per-session working directory | For Cowork sessions, the same file-based credentials (Google Cloud's Agent Platform and Amazon Bedrock) are written into the session's working directory, which is mounted into the sandbox VM. | Scoped to the session; removed with the session directory. |
8787 
8888Aside from these files, credentials delivered through managed configuration are held in memory only.
8989 

third-party/claude-desktop/entra-broker Changed · +11 / -11 lines

from line 16
1616 
1717## Where the broker is used
1818 
19| Feature | How to enable it | Page |
20| ------------------------------------------------------------ | -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
21| Microsoft Foundry inference provider | Set `inferenceFoundryAuthFlow` to `broker` | [Microsoft Foundry](/docs/third-party/claude-desktop/foundry#in-app-entra-id-sign-in) |
22| LLM gateway single sign-on | Set `inferenceGatewayOidcAuthFlow` to `broker` | [LLM gateway](/docs/third-party/claude-desktop/gateway#single-sign-on-configuration-keys) |
23| Workforce Identity sign-in for Google Cloud's Agent Platform | Set `inferenceVertexWorkforceAuthFlow` to `broker` | [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex#in-app-workforce-identity-sign-in) |
24| Amazon Bedrock identity provider sign-in (through a proxy) | Set `inferenceIdpAuthFlow` to `broker` | [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock#sign-in-with-your-identity-provider) |
25| Managed MCP server | Set `authFlow` to `broker` in the entry's `oauth` object | [Managed MCP servers](/docs/third-party/claude-desktop/extensions#managed-mcp-servers-admin) |
19| Feature | How to enable it | Page |
20| - | - | - |
21| Microsoft Foundry inference provider | Set `inferenceFoundryAuthFlow` to `broker` | [Microsoft Foundry](/docs/third-party/claude-desktop/foundry#in-app-entra-id-sign-in) |
22| LLM gateway single sign-on | Set `inferenceGatewayOidcAuthFlow` to `broker` | [LLM gateway](/docs/third-party/claude-desktop/gateway#single-sign-on-configuration-keys) |
23| Workforce Identity sign-in for Google Cloud's Agent Platform | Set `inferenceVertexWorkforceAuthFlow` to `broker` | [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex#in-app-workforce-identity-sign-in) |
24| Amazon Bedrock identity provider sign-in (through a proxy) | Set `inferenceIdpAuthFlow` to `broker` | [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock#sign-in-with-your-identity-provider) |
25| Managed MCP server | Set `authFlow` to `broker` in the entry's `oauth` object | [Managed MCP servers](/docs/third-party/claude-desktop/extensions#managed-mcp-servers-admin) |
2626 
2727For the gateway, Amazon Bedrock, and Workforce Identity flows, the broker is available only when your identity provider is Microsoft Entra ID: the `issuer` in `inferenceGatewayOidc`, `inferenceIdpOidc`, or `inferenceVertexWorkforceOidc` must have the form `https://login.microsoftonline.com/TENANT_ID/v2.0`. For a managed MCP server, the `oauth` object must also set `tenantId`, `clientId`, and `scope`.
2828 
from line 42
4242 
4343Under **Authentication**, add the broker redirect URI for each platform you deploy to under the **Mobile and desktop applications** platform:
4444 
45| Platform | Redirect URI |
46| -------- | ---------------------------------------------------------------- |
47| Windows | `ms-appx-web://Microsoft.AAD.BrokerPlugin/APPLICATION_CLIENT_ID` |
48| macOS | `msauth.com.anthropic.claudefordesktop://auth` |
45| Platform | Redirect URI |
46| - | - |
47| Windows | `ms-appx-web://Microsoft.AAD.BrokerPlugin/APPLICATION_CLIENT_ID` |
48| macOS | `msauth.com.anthropic.claudefordesktop://auth` |
4949 
5050Replace `APPLICATION_CLIENT_ID` in the Windows value with the registration's own Application (client) ID. The macOS value is a fixed string.
5151 

third-party/claude-desktop/extensions Changed · +59 / -59 lines

from line 6
66 
77There are three layers, in order of precedence:
88 
9| Layer | Provisioned by | Delivered via |
10| -------------------- | -------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
11| Managed MCP servers | Admin | `managedMcpServers` configuration key |
12| Organization plugins | Admin | A [plugin marketplace](#plugin-marketplaces-admin) hosted in git or over HTTPS (recommended), or a [system-wide directory](#organization-plugins-admin) on each device |
13| User extensions | End user | In-app Connectors and Plugins UI |
9| Layer | Provisioned by | Delivered via |
10| - | - | - |
11| Managed MCP servers | Admin | `managedMcpServers` configuration key |
12| Organization plugins | Admin | A [plugin marketplace](#plugin-marketplaces-admin) hosted in git or over HTTPS (recommended), or a [system-wide directory](#organization-plugins-admin) on each device |
13| User extensions | End user | In-app Connectors and Plugins UI |
1414 
1515Admins can disable the user layer entirely; see [Controlling user extensions](#controlling-user-extensions).
1616 
from line 91
9191 
9292For short-lived header credentials, configure the helper per server:
9393 
94| Key | Default | What it does |
95| ------------------------------- | ------- | ----------------------------------------------------------------------------------------- |
96| `headersHelper` | None | Executable that prints the request headers as a flat JSON object to stdout. |
97| `headersHelperTtlSec` | 300 | Seconds the returned headers stay valid. |
98| `headersHelperRefreshBufferSec` | 60 | Seconds before expiry that the helper re-runs. Set it above the helper's typical runtime. |
94| Key | Default | What it does |
95| - | - | - |
96| `headersHelper` | None | Executable that prints the request headers as a flat JSON object to stdout. |
97| `headersHelperTtlSec` | 300 | Seconds the returned headers stay valid. |
98| `headersHelperRefreshBufferSec` | 60 | Seconds before expiry that the helper re-runs. Set it above the helper's typical runtime. |
9999 
100100The helper follows the [`inferenceCredentialHelper`](/docs/third-party/claude-desktop/credential-helper) execution model, with four differences: no arguments, a 30-second time limit, no `CLAUDE_HELPER_CONTEXT`, and no prompting for input. The helper applies only to servers provisioned through managed configuration and never replaces the `Authorization` header on `oauth` entries.
101101 
from line 216
216216[{"source":"url","url":"https://plugins.acme.example.com/claude/marketplace.json","credentialKind":"inferenceCredential","installationPreference":"available"}]
217217```
218218 
219| Field | Description |
220| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
221| `source` | **Required.** `"github"` (with `repo`), `"git"` (with `url`), or `"url"` (with `url` pointing at a hosted `marketplace.json`). |
222| `repo` | GitHub repository in `owner/name` format. `github` sources only. |
223| `url` | For `git` sources, the full HTTPS clone URL. For `url` sources, the HTTPS address of the `marketplace.json` file. Use a bare URL with no embedded credentials or query string, and set `credentialKind` for authentication. |
224| `ref` | Branch name, tag name, or full 40-character commit SHA. Git sources only. **Required, and must be a full commit SHA,** when `installationPreference` is `"auto_install"` or `"required"`. |
225| `path` | Subdirectory containing `.claude-plugin/marketplace.json` when not at the repository root. Git sources only. |
226| `manifestSha256` | 64-character hex SHA-256 of the exact `marketplace.json` file to accept. `url` sources only. **Required** when `installationPreference` is `"auto_install"` or `"required"`; a served manifest with any other digest is refused. |
227| `expectedName` | If set, the fetch is rejected unless the `name` in `marketplace.json` matches this value exactly, so a change to the manifest name cannot silently replace another configured marketplace. |
228| `credentialKind` | `"anonymous"` (default), `"userGit"`, `"credentialHelper"`, or (for `url` sources) `"inferenceCredential"`. See [Marketplace credentials](#marketplace-credentials). |
229| `credentialHelper` | Path to an executable that prints an access token on stdout. Required, and only valid, when `credentialKind` is `"credentialHelper"`. |
230| `installationPreference` | `"available"` (default), `"auto_install"`, or `"required"`. See [Marketplace installation preferences](#marketplace-installation-preferences). |
219| Field | Description |
220| - | - |
221| `source` | **Required.** `"github"` (with `repo`), `"git"` (with `url`), or `"url"` (with `url` pointing at a hosted `marketplace.json`). |
222| `repo` | GitHub repository in `owner/name` format. `github` sources only. |
223| `url` | For `git` sources, the full HTTPS clone URL. For `url` sources, the HTTPS address of the `marketplace.json` file. Use a bare URL with no embedded credentials or query string, and set `credentialKind` for authentication. |
224| `ref` | Branch name, tag name, or full 40-character commit SHA. Git sources only. **Required, and must be a full commit SHA,** when `installationPreference` is `"auto_install"` or `"required"`. |
225| `path` | Subdirectory containing `.claude-plugin/marketplace.json` when not at the repository root. Git sources only. |
226| `manifestSha256` | 64-character hex SHA-256 of the exact `marketplace.json` file to accept. `url` sources only. **Required** when `installationPreference` is `"auto_install"` or `"required"`; a served manifest with any other digest is refused. |
227| `expectedName` | If set, the fetch is rejected unless the `name` in `marketplace.json` matches this value exactly, so a change to the manifest name cannot silently replace another configured marketplace. |
228| `credentialKind` | `"anonymous"` (default), `"userGit"`, `"credentialHelper"`, or (for `url` sources) `"inferenceCredential"`. See [Marketplace credentials](#marketplace-credentials). |
229| `credentialHelper` | Path to an executable that prints an access token on stdout. Required, and only valid, when `credentialKind` is `"credentialHelper"`. |
230| `installationPreference` | `"available"` (default), `"auto_install"`, or `"required"`. See [Marketplace installation preferences](#marketplace-installation-preferences). |
231231 
232232You can configure multiple marketplaces, and each appears as its own sub-tab under **Organization** in the **Directory**. If an admin-configured marketplace has the same `repo`, `url`, or manifest `name` as one the user added themselves, the admin entry replaces the user's.
233233 
234234### Marketplace installation preferences
235235 
236| `installationPreference` | Behavior |
237| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
238| `"available"` | Plugins appear in the Organization tab for users to install manually. Nothing is installed automatically. |
239| `"auto_install"` | Every plugin is installed automatically the first time the pinned `ref` is seen. Users can uninstall individual plugins; when you later change the `ref`, each plugin is installed again at the new revision. |
240| `"required"` | Every plugin is installed automatically and re-asserted on every sync. Users cannot uninstall or disable required plugins. |
236| `installationPreference` | Behavior |
237| - | - |
238| `"available"` | Plugins appear in the Organization tab for users to install manually. Nothing is installed automatically. |
239| `"auto_install"` | Every plugin is installed automatically the first time the pinned `ref` is seen. Users can uninstall individual plugins; when you later change the `ref`, each plugin is installed again at the new revision. |
240| `"required"` | Every plugin is installed automatically and re-asserted on every sync. Users cannot uninstall or disable required plugins. |
241241 
242242<Warning>
243243 `"auto_install"` and `"required"` marketplaces must carry an admin-side content pin so the exact plugin content deployed to every device is deterministic and auditable. Git sources must set `ref` to a full 40-character commit SHA; Claude Desktop refuses to auto-install from a branch or tag name. `url` sources must set `manifestSha256` to the SHA-256 of the exact `marketplace.json` bytes and give every archive a `sha256`; Claude Desktop refuses a served manifest with a different digest and skips unpinned archives.
from line 273
273273 
274274Claude Desktop fetches marketplaces on the host operating system, outside the Cowork VM. The credential is used only for this fetch and is never passed into the VM or exposed to the model.
275275 
276| `credentialKind` | How it authenticates |
277| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
278| `"anonymous"` | No credential is sent. Use for public repositories or unauthenticated file hosts. |
279| `"userGit"` | Uses the git credential helpers already configured for the signed-in OS user (for example, `git-credential-manager`, macOS Keychain, or a GitHub CLI credential helper). Use when each user already has read access through their own account. For `url` sources, the same credential is sent as HTTP Basic on the manifest and archive requests. |
280| `"credentialHelper"` | Runs the executable at `credentialHelper`. If it prints a bare token, the token is used as the git password for username `x-access-token` (accepted by GitHub, GitLab, and Azure DevOps) and, for `url` sources, sent as `Authorization: Bearer <token>` on the manifest and archive requests. For hosts that need a particular username, print git-credential lines `username=<user>` and `password=<token>` instead (for example `x-token-auth` for Bitbucket Data Center access tokens, or `gitlab+deploy-token-N` for a GitLab deploy token); `url` sources then use HTTP Basic. Print `authtype=Bearer` and `credential=<token>` to force a bearer header. For `url` sources, the helper can instead print a flat JSON object of HTTP headers, such as `{"Authorization": "Bearer …", "X-Tenant": "acme"}` (the form a managed MCP server's `headersHelper` prints, not an inference credential helper's `{"token": …}` object), and Claude Desktop sends every header in it on each request to that marketplace. `github` and `git` sources refuse this form. Output that opens with `{` must be a valid header object, or the fetch is refused. Username forms require Claude Desktop 1.37937.0 or later. Otherwise follows the execution model of an [inference credential helper](/docs/third-party/claude-desktop/credential-helper). |
281| `"inferenceCredential"` | `url` sources only. Sends the credentials Claude Desktop already sends to your inference gateway or to your [bootstrap server](/docs/third-party/claude-desktop/bootstrap), so a marketplace hosted on either is private to signed-in members without a separate credential. On the gateway's origin it sends the same `Authorization` bearer as inference and works for [gateway single sign-on](/docs/third-party/claude-desktop/gateway#single-sign-on-with-your-identity-provider), a [credential helper](/docs/third-party/claude-desktop/credential-helper), and bearer-scheme API keys. On the bootstrap server's origin (Claude Desktop 1.37937.0 or later) it sends the bootstrap sign-in token or your `bootstrapHeaders` and `bootstrapHeadersHelper` headers. Claude Desktop sends a credential only when the marketplace URL is on one of those two origins. When there is nothing to send yet (no sign-in held and no bootstrap headers configured, or a gateway API key sent as `x-api-key` rather than a bearer), no request is made and the entry reports why in the diagnostic report. |
276| `credentialKind` | How it authenticates |
277| - | - |
278| `"anonymous"` | No credential is sent. Use for public repositories or unauthenticated file hosts. |
279| `"userGit"` | Uses the git credential helpers already configured for the signed-in OS user (for example, `git-credential-manager`, macOS Keychain, or a GitHub CLI credential helper). Use when each user already has read access through their own account. For `url` sources, the same credential is sent as HTTP Basic on the manifest and archive requests. |
280| `"credentialHelper"` | Runs the executable at `credentialHelper`. If it prints a bare token, the token is used as the git password for username `x-access-token` (accepted by GitHub, GitLab, and Azure DevOps) and, for `url` sources, sent as `Authorization: Bearer <token>` on the manifest and archive requests. For hosts that need a particular username, print git-credential lines `username=<user>` and `password=<token>` instead (for example `x-token-auth` for Bitbucket Data Center access tokens, or `gitlab+deploy-token-N` for a GitLab deploy token); `url` sources then use HTTP Basic. Print `authtype=Bearer` and `credential=<token>` to force a bearer header. For `url` sources, the helper can instead print a flat JSON object of HTTP headers, such as `{"Authorization": "Bearer …", "X-Tenant": "acme"}` (the form a managed MCP server's `headersHelper` prints, not an inference credential helper's `{"token": …}` object), and Claude Desktop sends every header in it on each request to that marketplace. `github` and `git` sources refuse this form. Output that opens with `{` must be a valid header object, or the fetch is refused. Username forms require Claude Desktop 1.37937.0 or later. Otherwise follows the execution model of an [inference credential helper](/docs/third-party/claude-desktop/credential-helper). |
281| `"inferenceCredential"` | `url` sources only. Sends the credentials Claude Desktop already sends to your inference gateway or to your [bootstrap server](/docs/third-party/claude-desktop/bootstrap), so a marketplace hosted on either is private to signed-in members without a separate credential. On the gateway's origin it sends the same `Authorization` bearer as inference and works for [gateway single sign-on](/docs/third-party/claude-desktop/gateway#single-sign-on-with-your-identity-provider), a [credential helper](/docs/third-party/claude-desktop/credential-helper), and bearer-scheme API keys. On the bootstrap server's origin (Claude Desktop 1.37937.0 or later) it sends the bootstrap sign-in token or your `bootstrapHeaders` and `bootstrapHeadersHelper` headers. Claude Desktop sends a credential only when the marketplace URL is on one of those two origins. When there is nothing to send yet (no sign-in held and no bootstrap headers configured, or a gateway API key sent as `x-api-key` rather than a bearer), no request is made and the entry reports why in the diagnostic report. |
282282 
283283Because the fetch happens on the host, the marketplace host does not need to be on the [`coworkEgressAllowedHosts`](/docs/third-party/claude-desktop/configuration#coworkegressallowedhosts) allowlist. It does need to be reachable from end-user devices.
284284 
from line 296
296296 
297297### Plugin directory location
298298 
299| Platform | Path |
300| -------- | -------------------------------------------------- |
301| macOS | `/Library/Application Support/Claude/org-plugins/` |
302| Windows | `C:\Program Files\Claude\org-plugins\` |
299| Platform | Path |
300| - | - |
301| macOS | `/Library/Application Support/Claude/org-plugins/` |
302| Windows | `C:\Program Files\Claude\org-plugins\` |
303303 
304304On Windows, the directory is under `Program Files` (not `ProgramData`) so that only administrators can create or modify it. Claude Desktop treats the presence of this directory as an admin-provisioned source.
305305 
from line 323
323323 └── SKILL.md
324324```
325325 
326| File | Purpose |
327| ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
328| `.claude-plugin/plugin.json` | Plugin manifest (name, description, version). Required unless a top-level `SKILL.md` serves as the manifest; see the note below this table. A directory with neither is ignored. |
329| `version.json` | `{"version": "1.2.3"}`. When this string changes, Claude Desktop re-syncs the plugin on next launch. Any string change triggers re-sync (there's no semver ordering, so a downgrade is just another version string). If absent, the directory's modification time is used instead. |
330| `.mcp.json` | MCP servers bundled with this plugin. A JSON object keyed by server name: `{"mcpServers": {"<name>": {"type": "http", "url": "...", "oauth": true}}}`. A remote entry uses `type` (`http` or `sse`), not `transport`, and supports `url`, `headers`, and `oauth` only. `toolPolicy`, `headersHelper`, and `headersHelperTtlSec` are not read from this file. A local entry gives a `command` with optional `args` and `env` (`type` is `"stdio"` or omitted). Give `command` as a program name on `PATH` or an absolute path, using `${CLAUDE_PLUGIN_ROOT}` for the plugin's directory under `org-plugins/`. Claude Desktop starts these local servers itself, including when [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`. Local entries require Claude Desktop 1.49585.0 or later. A local entry that references `${user_config.<key>}` is skipped, because per-user plugin settings are not available to organization plugins. The diagnostic report's **MCP servers** section lists each server, with the reason for any it skipped. |
331| `agents/` | Sub-agent definitions. |
332| `commands/` | Slash-command definitions. |
333| `skills/` | [Skill](/docs/skills/overview) directories. |
334| `hooks/` | Hook definitions that run on agent lifecycle events. See [Plugin hooks](#plugin-hooks) for where they run. |
326| File | Purpose |
327| - | - |
328| `.claude-plugin/plugin.json` | Plugin manifest (name, description, version). Required unless a top-level `SKILL.md` serves as the manifest; see the note below this table. A directory with neither is ignored. |
329| `version.json` | `{"version": "1.2.3"}`. When this string changes, Claude Desktop re-syncs the plugin on next launch. Any string change triggers re-sync (there's no semver ordering, so a downgrade is just another version string). If absent, the directory's modification time is used instead. |
330| `.mcp.json` | MCP servers bundled with this plugin. A JSON object keyed by server name: `{"mcpServers": {"<name>": {"type": "http", "url": "...", "oauth": true}}}`. A remote entry uses `type` (`http` or `sse`), not `transport`, and supports `url`, `headers`, and `oauth` only. `toolPolicy`, `headersHelper`, and `headersHelperTtlSec` are not read from this file. A local entry gives a `command` with optional `args` and `env` (`type` is `"stdio"` or omitted). Give `command` as a program name on `PATH` or an absolute path, using `${CLAUDE_PLUGIN_ROOT}` for the plugin's directory under `org-plugins/`. Claude Desktop starts these local servers itself, including when [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`. Local entries require Claude Desktop 1.49585.0 or later. A local entry that references `${user_config.<key>}` is skipped, because per-user plugin settings are not available to organization plugins. The diagnostic report's **MCP servers** section lists each server, with the reason for any it skipped. |
331| `agents/` | Sub-agent definitions. |
332| `commands/` | Slash-command definitions. |
333| `skills/` | [Skill](/docs/skills/overview) directories. |
334| `hooks/` | Hook definitions that run on agent lifecycle events. See [Plugin hooks](#plugin-hooks) for where they run. |
335335 
336336<Note>
337337 Each entry in `org-plugins/` must carry a valid manifest: a `.claude-plugin/plugin.json`, or a top-level `SKILL.md` whose frontmatter declares `agents` or `mcpServers` (a skill folder that also acts as a plugin). A plain skill folder does not qualify on its own. To distribute a single skill, place it under `skills/<name>/SKILL.md` in a plugin that has a `plugin.json`. A directory with no valid manifest is not loaded and never appears in the user's plugin browser. The diagnostic report's plugin section shows the rejected entry and why. To distribute an MCP connector, declare it in a plugin's `.mcp.json` or use [`managedMcpServers`](#managed-mcp-servers-admin).
from line 360
360360}
361361```
362362 
363| Value | Behavior |
364| -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
365| `"required"` | Installs automatically the next time the app syncs organization plugins (at launch or when a session starts). The Uninstall action is hidden. If a user's installed copy is removed, it reinstalls on the next sync. |
366| `"auto_install"` | Installs automatically on the next sync. Users can uninstall it, and it stays uninstalled for that user. |
367| `"available"` (or omitted) | Default. Users install manually from the plugin browser. |
363| Value | Behavior |
364| - | - |
365| `"required"` | Installs automatically the next time the app syncs organization plugins (at launch or when a session starts). The Uninstall action is hidden. If a user's installed copy is removed, it reinstalls on the next sync. |
366| `"auto_install"` | Installs automatically on the next sync. Users can uninstall it, and it stays uninstalled for that user. |
367| `"available"` (or omitted) | Default. Users install manually from the plugin browser. |
368368 
369369This mirrors the installation preference behavior of remote-managed plugins on claude.ai. Changing a plugin's `installationPreference` takes effect at each user's next sync.
370370 
from line 404
404404 
405405Admins can restrict or disable each user-extension surface independently via managed configuration:
406406 
407| Key | Default | Effect when `false` |
408| ------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
409| `isLocalDevMcpEnabled` | `true` | Users cannot add their own local MCP servers from **Settings → Developer**. |
410| `isDesktopExtensionEnabled` | `false` | Desktop extensions (`.mcpb`) bundled in plugins are not loaded. Set to `true` to allow them. |
411| `isDesktopExtensionSignatureRequired` | `false` | (When `true`) Unsigned `.mcpb` extensions are rejected. |
412| `skillCreationEnabled` | `true` | Users cannot create or upload skills in the app. Claude does not offer to create or update skills in conversations. |
413| `userPluginMarketplacesEnabled` | `true` | Users cannot add plugin marketplaces of their own; the add-marketplace options are hidden. Marketplaces you provision with `allowedPluginMarketplaces` are unaffected. Requires Claude Desktop 1.37937.0 or later. |
414| `userPluginUploadsEnabled` | `true` | Users cannot upload plugin files or create plugins with Claude; every in-app option for adding a plugin of their own is hidden. Plugins from your marketplaces and the organization plugins directory are unaffected. Requires Claude Desktop 1.37937.0 or later. |
407| Key | Default | Effect when `false` |
408| - | - | - |
409| `isLocalDevMcpEnabled` | `true` | Users cannot add their own local MCP servers from **Settings → Developer**. |
410| `isDesktopExtensionEnabled` | `false` | Desktop extensions (`.mcpb`) bundled in plugins are not loaded. Set to `true` to allow them. |
411| `isDesktopExtensionSignatureRequired` | `false` | (When `true`) Unsigned `.mcpb` extensions are rejected. |
412| `skillCreationEnabled` | `true` | Users cannot create or upload skills in the app. Claude does not offer to create or update skills in conversations. |
413| `userPluginMarketplacesEnabled` | `true` | Users cannot add plugin marketplaces of their own; the add-marketplace options are hidden. Marketplaces you provision with `allowedPluginMarketplaces` are unaffected. Requires Claude Desktop 1.37937.0 or later. |
414| `userPluginUploadsEnabled` | `true` | Users cannot upload plugin files or create plugins with Claude; every in-app option for adding a plugin of their own is hidden. Plugins from your marketplaces and the organization plugins directory are unaffected. Requires Claude Desktop 1.37937.0 or later. |
415415 
416416Setting `isLocalDevMcpEnabled` to `false` and leaving `isDesktopExtensionEnabled` at `false` restricts MCP servers and connectors to those delivered through `managedMcpServers` and `org-plugins/`, plus any that installed plugins bundle, whether from your marketplaces or added by users. To limit plugin-bundled servers to ones you name, or to none, set [`allowedPluginMcpServers`](/docs/third-party/claude-desktop/configuration#allowedpluginmcpservers) to a list of URL patterns. An empty list admits no plugin-bundled server. Setting [`skillCreationEnabled`](/docs/third-party/claude-desktop/configuration#skillcreationenabled) to `false` turns off skill creation and upload in the app. Skills already on the device keep working, as do skills from [organization plugins](#organization-plugins-admin). Users can still install plugins from the marketplaces you provision regardless of these settings. Setting `userPluginMarketplacesEnabled` and `userPluginUploadsEnabled` to `false` removes only the options for adding marketplaces and plugins of their own, and anything a user added earlier stays in place. See the [Locked down profile](/docs/third-party/claude-desktop/configuration#recommended-security-profiles) for a complete example.
417417 

third-party/claude-desktop/feature-matrix Changed · +46 / -46 lines

from line 18
1818 
1919## User features
2020 
21| Feature | Claude Enterprise | Claude Desktop on 3P |
22| ----------------------------------------------------------------------------------------------------------------------------------- | :---------------: | :------------------: |
23| Chat | ✓ | ✓ |
24| Cowork | ✓ | ✓ |
25| Code | ✓ | ✓ |
26| Auto mode (Code) | ✓ | ✓ |
27| [SSH remote Code sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) | ✓ | ✓ |
28| Automatically approve (Cowork) | — ¶ | ✓ Δ |
29| Skip all approvals (Cowork) | — ¶ | — |
30| Projects | ✓ | ✓ |
31| Code execution for analysis | ✓ | ✓ |
32| Web search | ✓ | ✓ § |
33| [Built-in browser](/docs/third-party/claude-desktop/browser) | ✓ | ✓ |
34| File access, upload, and export | ✓ | ✓ |
35| Local MCP | ✓ | ✓ |
36| Remote MCP | ✓ | ✓ |
37| [Microsoft 365](/docs/third-party/claude-desktop/connectors-m365) and [GitHub](/docs/third-party/claude-desktop/connectors-github) connectors | ✓ | ✓ |
38| Skills, plugins, and hooks | ✓ | ✓ |
39| Artifacts | ✓ | ✓ |
40| Memory | ✓ | ✓ † |
41| Scheduled tasks | ✓ | ✓ |
42| Global languages | ✓ | ✓ |
43| Project and plugin sharing | ✓ | — |
44| Plugin marketplaces | ✓ | ✓ |
45| Mobile | ✓ | — |
46| claude.ai web-based access | ✓ | — |
47| Voice mode | ✓ | — |
48| [Claude in Chrome](/docs/third-party/claude-desktop/browser#claude-in-chrome) | ✓ | ✓ ‖ |
49| Claude Design | ✓ | — |
50| Claude Security | ✓ | — |
51| Claude Tag | ✓ | — |
52| Computer use | — | — |
21| Feature | Claude Enterprise | Claude Desktop on 3P |
22| - | :-: | :-: |
23| Chat | ✓ | ✓ |
24| Cowork | ✓ | ✓ |
25| Code | ✓ | ✓ |
26| Auto mode (Code) | ✓ | ✓ |
27| [SSH remote Code sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) | ✓ | ✓ |
28| Automatically approve (Cowork) | — ¶ | ✓ Δ |
29| Skip all approvals (Cowork) | — ¶ | — |
30| Projects | ✓ | ✓ |
31| Code execution for analysis | ✓ | ✓ |
32| Web search | ✓ | ✓ § |
33| [Built-in browser](/docs/third-party/claude-desktop/browser) | ✓ | ✓ |
34| File access, upload, and export | ✓ | ✓ |
35| Local MCP | ✓ | ✓ |
36| Remote MCP | ✓ | ✓ |
37| [Microsoft 365](/docs/third-party/claude-desktop/connectors-m365) and [GitHub](/docs/third-party/claude-desktop/connectors-github) connectors | ✓ | ✓ |
38| Skills, plugins, and hooks | ✓ | ✓ |
39| Artifacts | ✓ | ✓ |
40| Memory | ✓ | ✓ † |
41| Scheduled tasks | ✓ | ✓ |
42| Global languages | ✓ | ✓ |
43| Project and plugin sharing | ✓ | — |
44| Plugin marketplaces | ✓ | ✓ |
45| Mobile | ✓ | — |
46| claude.ai web-based access | ✓ | — |
47| Voice mode | ✓ | — |
48| [Claude in Chrome](/docs/third-party/claude-desktop/browser#claude-in-chrome) | ✓ | ✓ ‖ |
49| Claude Design | ✓ | — |
50| Claude Security | ✓ | — |
51| Claude Tag | ✓ | — |
52| Computer use | — | — |
5353 
5454§ Amazon Bedrock deployments and gateways that do not forward Anthropic server tools need a web search provider configured first; see [Web search options](/docs/third-party/claude-desktop/web-tools#web-search-options).
5555 
from line 63
6363 
6464## Admin features
6565 
66| Feature | Claude Enterprise | Claude Desktop on 3P |
67| ------------------------------------------------------------------------------------------------------- | :---------------: | :------------------: |
68| Endpoint / gateway configuration | — | ✓ |
69| Skills, hooks, and plugins distribution | ✓ | ✓ |
70| MCP server allowlist | ✓ | ✓ |
71| Feature toggles (web search, local MCP, etc.) | ✓ | ✓ |
72| Auto-updates | ✓ | ✓ |
73| Per-user usage caps | ✓ | ✓ |
74| [Data retention policies](/docs/third-party/claude-desktop/data-storage#automatic-deletion-of-idle-sessions) | ✓ | ✓ |
75| Compliance API | ✓ | — ‡ |
76| Analytics API | ✓ | — ‡ |
77| OpenTelemetry export | ✓ | ✓ |
78| User management via UI | ✓ | ✓ ◊ |
79| RBAC | ✓ | ✓ ◊ |
66| Feature | Claude Enterprise | Claude Desktop on 3P |
67| - | :-: | :-: |
68| Endpoint / gateway configuration | — | ✓ |
69| Skills, hooks, and plugins distribution | ✓ | ✓ |
70| MCP server allowlist | ✓ | ✓ |
71| Feature toggles (web search, local MCP, etc.) | ✓ | ✓ |
72| Auto-updates | ✓ | ✓ |
73| Per-user usage caps | ✓ | ✓ |
74| [Data retention policies](/docs/third-party/claude-desktop/data-storage#automatic-deletion-of-idle-sessions) | ✓ | ✓ |
75| Compliance API | ✓ | — ‡ |
76| Analytics API | ✓ | — ‡ |
77| OpenTelemetry export | ✓ | ✓ |
78| User management via UI | ✓ | ✓ ◊ |
79| RBAC | ✓ | ✓ ◊ |
8080 
8181‡ Many of these capabilities can be achieved via OpenTelemetry export to your own collector. See [Monitoring](/docs/cowork/monitoring).
8282 

third-party/claude-desktop/foundry Changed · +27 / -27 lines

from line 12
1212 
1313## Choose an authentication approach
1414 
15| Scenario | Use | Per-user identity | Notes |
16| --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
17| Proof of concept, single team | [API key](#api-key) (`inferenceFoundryApiKey`) | No (shared key) | A long-lived secret distributed in the managed profile. Simplest to start. |
18| Broad rollout with per-user identity | [In-app Entra ID sign-in](#in-app-entra-id-sign-in) (`inferenceFoundryTenantId`, `inferenceFoundryClientId`, `inferenceFoundryAuthFlow`) | Yes | Users sign in with their Entra ID account inside the app, through a device code, the system browser, or the OS identity broker. The device-code flow requires app version 1.9255.0 or later; the browser flow requires app version 1.19367.0 or later. |
19| Your organization already has tooling that obtains a Microsoft Foundry credential | [Credential helper](/docs/third-party/claude-desktop/configuration#inferencecredentialhelper) (`inferenceCredentialHelper`) | Depends on what the helper obtains | An executable that prints the credential to stdout at runtime. |
15| Scenario | Use | Per-user identity | Notes |
16| - | - | - | - |
17| Proof of concept, single team | [API key](#api-key) (`inferenceFoundryApiKey`) | No (shared key) | A long-lived secret distributed in the managed profile. Simplest to start. |
18| Broad rollout with per-user identity | [In-app Entra ID sign-in](#in-app-entra-id-sign-in) (`inferenceFoundryTenantId`, `inferenceFoundryClientId`, `inferenceFoundryAuthFlow`) | Yes | Users sign in with their Entra ID account inside the app, through a device code, the system browser, or the OS identity broker. The device-code flow requires app version 1.9255.0 or later; the browser flow requires app version 1.19367.0 or later. |
19| Your organization already has tooling that obtains a Microsoft Foundry credential | [Credential helper](/docs/third-party/claude-desktop/configuration#inferencecredentialhelper) (`inferenceCredentialHelper`) | Depends on what the helper obtains | An executable that prints the credential to stdout at runtime. |
2020 
2121## Set up Azure
2222 
from line 96
9696 
9797Open the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration#open-the-configuration-window) (**Developer → Configure Third-Party Inference…**). In the **Connection** section, set **Inference provider** to **Foundry**, then fill in the **Foundry credentials** card with the values for whichever authentication approach you chose:
9898 
99| Field | API key | In-app Entra ID sign-in |
100| ------------------------------ | ------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
101| Azure AI Foundry resource name | `your-foundry-resource` | `your-foundry-resource` |
102| Azure AI Foundry API key | your resource key | *leave empty* |
103| Entra ID tenant ID | *leave empty* | `00000000-0000-0000-0000-000000000000` |
104| Entra ID client ID | *leave empty* | `11111111-1111-1111-1111-111111111111` |
105| Entra ID sign-in flow | *leave empty* | `browser` or `broker`, or leave empty for the default device-code flow |
106| Azure AI Foundry base URL | *optional*, see [Route requests through a gateway](#route-requests-through-a-gateway) | *optional* |
99| Field | API key | In-app Entra ID sign-in |
100| - | - | - |
101| Azure AI Foundry resource name | `your-foundry-resource` | `your-foundry-resource` |
102| Azure AI Foundry API key | your resource key | *leave empty* |
103| Entra ID tenant ID | *leave empty* | `00000000-0000-0000-0000-000000000000` |
104| Entra ID client ID | *leave empty* | `11111111-1111-1111-1111-111111111111` |
105| Entra ID sign-in flow | *leave empty* | `browser` or `broker`, or leave empty for the default device-code flow |
106| Azure AI Foundry base URL | *optional*, see [Route requests through a gateway](#route-requests-through-a-gateway) | *optional* |
107107 
108108Under **Models**, add at least one **Model list** entry using the Microsoft Foundry deployment name.
109109 
from line 113
113113 
114114The full set of `inferenceFoundry*` keys is below. Set `inferenceProvider` to `foundry`, supply the resource name, and provide exactly one credential source.
115115 
116| Setting | Type | Availability | Default | Description |
117| ---------------------------------------------------------------------------------------------------- | -------- | --------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
118| <span id="inferencefoundryresource" />Azure AI Foundry resource name<br />`inferenceFoundryResource` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Azure AI Foundry resource name used to construct the endpoint URL. |
119| <span id="inferencefoundrybaseurl" />Azure AI Foundry base URL<br />`inferenceFoundryBaseUrl` | `string` | MDM + Bootstrap<br />Added in 2.110.0 | — | Full base URL for a gateway or proxy in front of Foundry, path included (replaces [https://RESOURCE.services.ai.azure.com/anthropic](https://RESOURCE.services.ai.azure.com/anthropic)). |
120| <span id="inferencefoundryapikey" />Azure AI Foundry API key<br />`inferenceFoundryApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for Azure AI Foundry inference. |
121| <span id="inferencefoundrytenantid" />Entra ID tenant ID<br />`inferenceFoundryTenantId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Directory (tenant) ID of the Entra ID app registration that has the Cognitive Services scope. |
122| <span id="inferencefoundryclientid" />Entra ID client ID<br />`inferenceFoundryClientId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Application (client) ID of the Entra ID app registration. Device-code sign-in requires the app to allow public client flows. |
123| <span id="inferencefoundryauthflow" />Entra ID sign-in flow<br />`inferenceFoundryAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | — | How Entra sign-in runs: device code (default), system browser, or the OS identity broker. One of: `device-code`, `browser`, `broker`. |
116| Setting | Type | Availability | Default | Description |
117| - | - | - | - | - |
118| <span id="inferencefoundryresource" />Azure AI Foundry resource name<br />`inferenceFoundryResource` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Azure AI Foundry resource name used to construct the endpoint URL. |
119| <span id="inferencefoundrybaseurl" />Azure AI Foundry base URL<br />`inferenceFoundryBaseUrl` | `string` | MDM + Bootstrap<br />Added in 2.110.0 | — | Full base URL for a gateway or proxy in front of Foundry, path included (replaces [https://RESOURCE.services.ai.azure.com/anthropic](https://RESOURCE.services.ai.azure.com/anthropic)). |
120| <span id="inferencefoundryapikey" />Azure AI Foundry API key<br />`inferenceFoundryApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for Azure AI Foundry inference. |
121| <span id="inferencefoundrytenantid" />Entra ID tenant ID<br />`inferenceFoundryTenantId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Directory (tenant) ID of the Entra ID app registration that has the Cognitive Services scope. |
122| <span id="inferencefoundryclientid" />Entra ID client ID<br />`inferenceFoundryClientId` | `string` | MDM + Bootstrap<br />Added in 1.9255.0 | — | Application (client) ID of the Entra ID app registration. Device-code sign-in requires the app to allow public client flows. |
123| <span id="inferencefoundryauthflow" />Entra ID sign-in flow<br />`inferenceFoundryAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | — | How Entra sign-in runs: device code (default), system browser, or the OS identity broker. One of: `device-code`, `browser`, `broker`. |
124124 
125125<AccordionGroup>
126126 <Accordion title="inferenceFoundryBaseUrl details">
from line 140
140140 
141141## What users experience
142142 
143| Approach | First launch | Re-authentication |
144| ----------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
145| API key | The app opens directly; no user action. | Never, until you rotate the key in the managed profile. |
146| In-app Entra ID sign-in, device-code flow | The app shows a **Sign in with Microsoft** page; the user approves a device code in the browser, and the app returns to Cowork. | When the stored refresh token expires or is revoked under your tenant's policy. The app prompts in-app. |
147| In-app Entra ID sign-in, browser flow | The app shows a **Sign in with Microsoft** page; the user signs in through the system browser, with no code to enter, and the app returns to Cowork. | When the app can no longer renew the stored token. The app prompts in-app. |
148| In-app Entra ID sign-in, broker flow | The app shows a **Sign in with Microsoft** page; the user picks or signs in to a work account in the operating system's native account picker, and the app returns to Cowork. | When the broker can no longer renew the token silently. The app prompts in-app. |
143| Approach | First launch | Re-authentication |
144| - | - | - |
145| API key | The app opens directly; no user action. | Never, until you rotate the key in the managed profile. |
146| In-app Entra ID sign-in, device-code flow | The app shows a **Sign in with Microsoft** page; the user approves a device code in the browser, and the app returns to Cowork. | When the stored refresh token expires or is revoked under your tenant's policy. The app prompts in-app. |
147| In-app Entra ID sign-in, browser flow | The app shows a **Sign in with Microsoft** page; the user signs in through the system browser, with no code to enter, and the app returns to Cowork. | When the app can no longer renew the stored token. The app prompts in-app. |
148| In-app Entra ID sign-in, broker flow | The app shows a **Sign in with Microsoft** page; the user picks or signs in to a work account in the operating system's native account picker, and the app returns to Cowork. | When the broker can no longer renew the token silently. The app prompts in-app. |
149149 
150150## Troubleshoot
151151 

third-party/claude-desktop/gateway Changed · +83 / -83 lines

from line 13
1313 
1414## Choose an authentication approach
1515 
16| Scenario | Use | Notes |
17| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
18| Proof of concept, or your gateway already issues per-team keys | [Static API key](#static-api-key) (`inferenceGatewayApiKey`) | A long-lived secret distributed in the managed profile. |
19| Per-user attribution and identity-provider enforcement (MFA, conditional access) | [Single sign-on](#single-sign-on-with-your-identity-provider) (`inferenceGatewayOidc`) | Each user signs in with their own work account. Requires app version 1.6889.0 or later. |
20| Your organization already has tooling that obtains a gateway credential | [Credential helper](/docs/third-party/claude-desktop/configuration#inferencecredentialhelper) (`inferenceCredentialHelper`) | An executable that prints the gateway credential to stdout at runtime. |
16| Scenario | Use | Notes |
17| - | - | - |
18| Proof of concept, or your gateway already issues per-team keys | [Static API key](#static-api-key) (`inferenceGatewayApiKey`) | A long-lived secret distributed in the managed profile. |
19| Per-user attribution and identity-provider enforcement (MFA, conditional access) | [Single sign-on](#single-sign-on-with-your-identity-provider) (`inferenceGatewayOidc`) | Each user signs in with their own work account. Requires app version 1.6889.0 or later. |
20| Your organization already has tooling that obtains a gateway credential | [Credential helper](/docs/third-party/claude-desktop/configuration#inferencecredentialhelper) (`inferenceCredentialHelper`) | An executable that prints the gateway credential to stdout at runtime. |
2121 
2222## Prepare devices
2323 
from line 79
7979 <Step title="Configure in the app">
8080 Open the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration#open-the-configuration-window) (**Developer → Configure Third-Party Inference…**). In the **Connection** section, set **Inference provider** to **Gateway** and **Credential kind** to **Interactive sign-in**. This hides the API-key field and reveals **Gateway SSO IdP (OIDC)**:
8181 
82 | Field | Value |
83 | -------------------------------------- | ------------------------------------------------------- |
84 | Gateway base URL | `https://llm-gateway.example.corp` |
85 | Credential kind | **Interactive sign-in** |
86 | Gateway SSO IdP (OIDC) → Client ID | `YOUR_CLIENT_ID` |
87 | Gateway SSO IdP (OIDC) → Issuer URL | `https://login.microsoftonline.com/YOUR_TENANT_ID/v2.0` |
88 | Gateway SSO IdP (OIDC) → Scopes | *leave empty for the default* |
89 | Gateway SSO IdP (OIDC) → Redirect port | *leave empty* |
82 | Field | Value |
83 | - | - |
84 | Gateway base URL | `https://llm-gateway.example.corp` |
85 | Credential kind | **Interactive sign-in** |
86 | Gateway SSO IdP (OIDC) → Client ID | `YOUR_CLIENT_ID` |
87 | Gateway SSO IdP (OIDC) → Issuer URL | `https://login.microsoftonline.com/YOUR_TENANT_ID/v2.0` |
88 | Gateway SSO IdP (OIDC) → Scopes | *leave empty for the default* |
89 | Gateway SSO IdP (OIDC) → Redirect port | *leave empty* |
9090 
9191 Then click **Export** to produce a `.mobileconfig` (macOS) or `.reg` (Windows) file for your MDM. See [Deploy with MDM](/docs/third-party/claude-desktop/mdm) for the export and deployment workflow.
9292 
from line 98
9898 
9999In the Okta Admin Console, create a **Native** application with the **Authorization Code** and **Refresh Token** grant types. Okta requires the redirect URI to match exactly, including the port, so pick a fixed port (for example `53180`), register `http://127.0.0.1:53180/callback`, and set that same port in **Gateway SSO IdP (OIDC)**:
100100 
101| Field | Value |
102| ------------- | ----------------------------- |
103| Client ID | `YOUR_CLIENT_ID` |
104| Issuer URL | `https://YOUR_ORG.okta.com` |
105| Scopes | *leave empty for the default* |
106| Redirect port | `53180` |
101| Field | Value |
102| - | - |
103| Client ID | `YOUR_CLIENT_ID` |
104| Issuer URL | `https://YOUR_ORG.okta.com` |
105| Scopes | *leave empty for the default* |
106| Redirect port | `53180` |
107107 
108108<Note>
109109 Use the **issuer** value, not the **Metadata URI**. Okta's admin console shows the metadata URI (ending in `/.well-known/openid-configuration`) prominently — that is the discovery document the app fetches *from* the issuer, not the issuer itself. If you are unsure, open the metadata URI in a browser and copy the `"issuer"` field from the JSON response. For a custom Okta authorization server the issuer is `https://YOUR_ORG.okta.com/oauth2/AUTH_SERVER_ID`.
from line 117
117117 
118118Key the gateway's user record on the provider's immutable user ID rather than email, so the record survives email or name changes:
119119 
120| Provider | Stable user-ID claim |
121| ---------------------------------- | -------------------- |
122| Entra ID | `oid` |
123| Okta and most other OIDC providers | `sub` |
120| Provider | Stable user-ID claim |
121| - | - |
122| Entra ID | `oid` |
123| Okta and most other OIDC providers | `sub` |
124124 
125125If your gateway has no existing user records to preserve, the simplest setup is to auto-provision on first sign-in. For LiteLLM, extend the validation block from step 2:
126126 
from line 155
155155 
156156Open the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration#open-the-configuration-window) (**Developer → Configure Third-Party Inference…**). In the **Connection** section, set **Inference provider** to **Gateway**, then fill in the **Gateway credentials** card:
157157 
158| Field | Value |
159| ------------------- | -------------------------------------------------------------------------------------------------------------------------- |
160| Gateway base URL | `https://llm-gateway.example.corp` |
161| Gateway API key | your gateway key (or a placeholder if your gateway has none) |
162| Credential kind | **Static API key** (default), or **Interactive sign-in** for [single sign-on](#single-sign-on-with-your-identity-provider) |
163| Gateway auth scheme | **Bearer** (default) or **x-api-key** |
158| Field | Value |
159| - | - |
160| Gateway base URL | `https://llm-gateway.example.corp` |
161| Gateway API key | your gateway key (or a placeholder if your gateway has none) |
162| Credential kind | **Static API key** (default), or **Interactive sign-in** for [single sign-on](#single-sign-on-with-your-identity-provider) |
163| Gateway auth scheme | **Bearer** (default) or **x-api-key** |
164164 
165165Then click **Export** to produce a `.mobileconfig` (macOS) or `.reg` (Windows) file for your MDM. See [Deploy with MDM](/docs/third-party/claude-desktop/mdm) for the export and deployment workflow.
166166 
167167### Configuration keys
168168 
169| Setting | Type | Availability | Default | Description |
170| --------------------------------------------------------------------------------------------------- | --------- | --------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
171| <span id="inferencegatewaybaseurl" />Gateway base URL<br />`inferenceGatewayBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Full URL of the inference gateway endpoint. |
172| <span id="inferencestreamidletimeoutsec" />Stream idle timeout<br />`inferenceStreamIdleTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.44121.1 | — | Extra seconds to wait for model output on a streaming response that is sending only keep-alive pings. Gateway provider only. Default 300. Range: 300–1800. |
173| <span id="inferencegatewayapikey" />Gateway API key<br />`inferenceGatewayApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for the configured inference gateway. |
174| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"` (accepted until October 7, 2026); use inferenceCredentialKind: "interactive". If it is still present after that, browser sign-in will no longer be inferred from it — the key will be reported as invalid and, unless inferenceCredentialKind or another credential field (an API key, inferenceGatewayOidc) says how to sign in, the gateway connection will have no credential and inference will not start. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
175| <span id="inferencegatewayoidcauthflow" />Gateway sign-in flow<br />`inferenceGatewayOidcAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. Deprecated: `inferenceGatewayOidcAuthFlow`; use inferenceIdpAuthFlow together with inferenceIdpOidc once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
176| <span id="inferencegatewayoidc" />Gateway SSO IdP (OIDC)<br />`inferenceGatewayOidc` | `object` | MDM + Bootstrap<br />Added in 1.6889.0 | — | External IdP for gateway sign-in. The user’s token from this issuer is sent to the gateway as the Bearer credential. Deprecated: `inferenceGatewayOidc`; use inferenceIdpOidc with inferenceCredentialKind: "external-idp" once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
177| <span id="inferenceidpauthflow" />Identity provider sign-in flow<br />`inferenceIdpAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How the identity-provider sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
178| <span id="inferenceidpoidc" />Identity provider (OIDC)<br />`inferenceIdpOidc` | `object` | MDM + Bootstrap<br />Added in 2.7032.0 | — | Your organization’s OpenID Connect identity provider. The user’s token is sent as the Bearer credential to the gateway or the Bedrock proxy. |
169| Setting | Type | Availability | Default | Description |
170| - | - | - | - | - |
171| <span id="inferencegatewaybaseurl" />Gateway base URL<br />`inferenceGatewayBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Full URL of the inference gateway endpoint. |
172| <span id="inferencestreamidletimeoutsec" />Stream idle timeout<br />`inferenceStreamIdleTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.44121.1 | — | Extra seconds to wait for model output on a streaming response that is sending only keep-alive pings. Gateway provider only. Default 300. Range: 300–1800. |
173| <span id="inferencegatewayapikey" />Gateway API key<br />`inferenceGatewayApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for the configured inference gateway. |
174| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"` (accepted until October 7, 2026); use inferenceCredentialKind: "interactive". If it is still present after that, browser sign-in will no longer be inferred from it — the key will be reported as invalid and, unless inferenceCredentialKind or another credential field (an API key, inferenceGatewayOidc) says how to sign in, the gateway connection will have no credential and inference will not start. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
175| <span id="inferencegatewayoidcauthflow" />Gateway sign-in flow<br />`inferenceGatewayOidcAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. Deprecated: `inferenceGatewayOidcAuthFlow`; use inferenceIdpAuthFlow together with inferenceIdpOidc once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
176| <span id="inferencegatewayoidc" />Gateway SSO IdP (OIDC)<br />`inferenceGatewayOidc` | `object` | MDM + Bootstrap<br />Added in 1.6889.0 | — | External IdP for gateway sign-in. The user’s token from this issuer is sent to the gateway as the Bearer credential. Deprecated: `inferenceGatewayOidc`; use inferenceIdpOidc with inferenceCredentialKind: "external-idp" once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
177| <span id="inferenceidpauthflow" />Identity provider sign-in flow<br />`inferenceIdpAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How the identity-provider sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
178| <span id="inferenceidpoidc" />Identity provider (OIDC)<br />`inferenceIdpOidc` | `object` | MDM + Bootstrap<br />Added in 2.7032.0 | — | Your organization’s OpenID Connect identity provider. The user’s token is sent as the Bearer credential to the gateway or the Bedrock proxy. |
179179 
180180<AccordionGroup>
181181 <Accordion title="inferenceStreamIdleTimeoutSec details">
from line 200
200200 
201201 **Refresh.** With `offline_access` the app renews the token silently and prompts a browser sign-in only when refresh fails. Google never returns an `id_token` on refresh, so a Google Workspace-backed gateway in `id_token` mode re-prompts about hourly; `access_token` mode is unaffected.
202202 
203 | Field | Type | Default | Description |
204 | --------------------------------- | --------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
205 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
206 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
207 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
208 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
209 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
210 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
211 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
212 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
213 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
214 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
215 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
203 | Field | Type | Default | Description |
204 | - | - | - | - |
205 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
206 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
207 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
208 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
209 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
210 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
211 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
212 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
213 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
214 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
215 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
216216 </Accordion>
217217 
218218 <Accordion title="inferenceIdpAuthFlow details">
from line 233
233233 
234234 **Older names.** Gateway configurations written before this key use `inferenceGatewayOidc` / `inferenceGatewayOidcAuthFlow` with the `interactive` kind; they stay readable and mean the same sign-in.
235235 
236 | Field | Type | Default | Description |
237 | --------------------------------- | --------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
238 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
239 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
240 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
241 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
242 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
243 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
244 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
245 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
246 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
247 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
248 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
236 | Field | Type | Default | Description |
237 | - | - | - | - |
238 | `clientId` | `string` | — | OAuth client ID of the desktop app registration at your identity provider (public client, PKCE). |
239 | `issuer` | `string` | — | HTTPS issuer with OIDC discovery. Set this, or set the authorization and token URLs instead. |
240 | `authorizationUrl` | `string` | — | HTTPS authorization endpoint. Used with the token URL when no issuer is set. |
241 | `tokenUrl` | `string` | — | HTTPS token endpoint. Used with the authorization URL when no issuer is set. |
242 | `bearerTokenType` | `enum` | `id_token` | Which token to send as the bearer. Use access token for a gateway or proxy that validates as an OAuth resource server. One of: `id_token`, `access_token`. |
243 | `scopes` | `string` | — | Space-separated scopes. Required in access-token mode: set the gateway or proxy API scope. offline\_access is appended automatically unless disabled below. |
244 | `appendOfflineAccess` | `boolean` | `true` | Automatically append offline\_access to scopes so the IdP returns a refresh token for silent refresh. |
245 | `resource` | `string` | — | Access-token audience of the gateway or proxy: an https URL or an AD FS relying-party identifier, sent as the RFC 8707 resource. Leave unset for Entra ID. |
246 | `redirectPort` | `integer` | — | Fixed loopback port for the sign-in redirect. Leave unset to use a free port each time. |
247 | `redirectHost` | `enum` | — | Use localhost only if your IdP’s registered redirect URI specifies it. One of: `127.0.0.1`, `localhost`. |
248 | `additionalRedirectReferrerHosts` | `string` | — | Space-separated hostnames also accepted as the referrer of the sign-in callback. Only needed when the IdP completes sign-in from a different host. |
249249 </Accordion>
250250</AccordionGroup>
251251 
from line 255
255255 
256256Single sign-on is enabled by setting `inferenceCredentialKind` to `interactive` **and** supplying `inferenceGatewayOidc`. Both are required — `interactive` alone (without `inferenceGatewayOidc`) selects a different mode where the gateway itself acts as the authorization server.
257257 
258| Setting | MDM key | Required | Description |
259| ---------------------- | ------------------------------ | --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
260| Credential kind | `inferenceCredentialKind` | Yes — must be `interactive` | Selects sign-in instead of an API key. |
261| Gateway SSO IdP (OIDC) | `inferenceGatewayOidc` | Yes | A **single JSON object** describing the identity provider (fields below). The resulting token is sent to the gateway as the bearer credential. |
262| Sign-in flow | `inferenceGatewayOidcAuthFlow` | No | `browser` (the default) runs the sign-in in the system browser. `broker` runs it through the [OS identity broker](/docs/third-party/claude-desktop/entra-broker) on Windows and macOS, which requires `issuer` to be a Microsoft Entra ID issuer (`https://login.microsoftonline.com/TENANT_ID/v2.0`) and needs no loopback redirect. |
258| Setting | MDM key | Required | Description |
259| - | - | - | - |
260| Credential kind | `inferenceCredentialKind` | Yes — must be `interactive` | Selects sign-in instead of an API key. |
261| Gateway SSO IdP (OIDC) | `inferenceGatewayOidc` | Yes | A **single JSON object** describing the identity provider (fields below). The resulting token is sent to the gateway as the bearer credential. |
262| Sign-in flow | `inferenceGatewayOidcAuthFlow` | No | `browser` (the default) runs the sign-in in the system browser. `broker` runs it through the [OS identity broker](/docs/third-party/claude-desktop/entra-broker) on Windows and macOS, which requires `issuer` to be a Microsoft Entra ID issuer (`https://login.microsoftonline.com/TENANT_ID/v2.0`) and needs no loopback redirect. |
263263 
264264The `inferenceGatewayOidc` value is one JSON object with these fields:
265265 
266| Field | Required | Description |
267| --------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
268| `clientId` | Yes | Application (client) ID registered with the identity provider. |
269| `issuer` | Yes\* | OIDC issuer URL — the base URL only, **without** `/.well-known/openid-configuration`. The app appends that path itself to discover the authorization and token endpoints. |
270| `authorizationUrl` | No\* | Explicit OIDC authorization endpoint. Use together with `tokenUrl` instead of `issuer` when the identity provider does not serve `/.well-known/openid-configuration`. Ignored when `issuer` is set. |
271| `tokenUrl` | No\* | Explicit OIDC token endpoint. Must be set together with `authorizationUrl`. Ignored when `issuer` is set. |
272| `scopes` | No | Space-separated OIDC scopes. Defaults to `openid profile email offline_access`. Required when `bearerTokenType` is `access_token`. See [Refresh tokens and session lifetime](#refresh-tokens-and-session-lifetime) for how this field interacts with silent refresh. |
273| `redirectPort` | No | Fixed local port for the loopback redirect. Leave unset to let the app choose an ephemeral port (Entra). Set when the provider requires an exact port match (Okta). |
274| `redirectHost` | No | Host in the loopback redirect URI, `127.0.0.1` (the default) or `localhost`. Set to `localhost` when the identity provider accepts only `localhost` in a registered redirect URI, and register the `localhost` form of the URI instead (`http://localhost/callback`, or `http://localhost:<port>/callback` with `redirectPort`). |
275| `bearerTokenType` | No | Which token the app sends to the gateway as the `Authorization: Bearer` value. `id_token` (the default) sends the OIDC ID token — the gateway validates it offline against the provider's JWKS with `aud` equal to the client ID. `access_token` sends the OAuth access token instead — use this for gateways that validate as an OAuth resource server rather than validating the ID token directly. When set to `access_token`, `scopes` is required. |
276| `appendOfflineAccess` | No | Whether to automatically append `offline_access` to `scopes` in `access_token` mode. Defaults to `true`. Set to `false` only if your authorization server rejects `offline_access` as an unrecognized scope. See [Refresh tokens and session lifetime](#refresh-tokens-and-session-lifetime). |
277| `resource` | No | RFC 8707 resource indicator naming the gateway as the access-token audience: an `https://` URL, or, for AD FS, one of the relying-party trust's identifiers that has a scheme, such as `https://…` or `urn:…`, spelled as it is registered. A value with no scheme is sent as `https://<value>`; an identifier with a scheme of its own is sent exactly as written. When set, the app sends `resource=<value>` on the authorization, token, and refresh requests. Use only with `bearerTokenType: "access_token"` and an identity provider that implements RFC 8707 (for example AD FS); leave unset for Microsoft Entra ID, which rejects the parameter; request the gateway's API scope in `scopes` instead. Changing it signs users in again. Ignored by the OS-broker sign-in flow (`inferenceGatewayOidcAuthFlow: broker`). |
278| `additionalRedirectReferrerHosts` | No | Space-separated hostnames also accepted as the referrer of the sign-in callback, for identity providers that complete sign-in from a different host than the authorization URL's (for example a portal or step-up page on a sibling host). When a callback is rejected for a referrer mismatch, the app log names the host to add. |
266| Field | Required | Description |
267| - | - | - |
268| `clientId` | Yes | Application (client) ID registered with the identity provider. |
269| `issuer` | Yes\* | OIDC issuer URL — the base URL only, **without** `/.well-known/openid-configuration`. The app appends that path itself to discover the authorization and token endpoints. |
270| `authorizationUrl` | No\* | Explicit OIDC authorization endpoint. Use together with `tokenUrl` instead of `issuer` when the identity provider does not serve `/.well-known/openid-configuration`. Ignored when `issuer` is set. |
271| `tokenUrl` | No\* | Explicit OIDC token endpoint. Must be set together with `authorizationUrl`. Ignored when `issuer` is set. |
272| `scopes` | No | Space-separated OIDC scopes. Defaults to `openid profile email offline_access`. Required when `bearerTokenType` is `access_token`. See [Refresh tokens and session lifetime](#refresh-tokens-and-session-lifetime) for how this field interacts with silent refresh. |
273| `redirectPort` | No | Fixed local port for the loopback redirect. Leave unset to let the app choose an ephemeral port (Entra). Set when the provider requires an exact port match (Okta). |
274| `redirectHost` | No | Host in the loopback redirect URI, `127.0.0.1` (the default) or `localhost`. Set to `localhost` when the identity provider accepts only `localhost` in a registered redirect URI, and register the `localhost` form of the URI instead (`http://localhost/callback`, or `http://localhost:<port>/callback` with `redirectPort`). |
275| `bearerTokenType` | No | Which token the app sends to the gateway as the `Authorization: Bearer` value. `id_token` (the default) sends the OIDC ID token — the gateway validates it offline against the provider's JWKS with `aud` equal to the client ID. `access_token` sends the OAuth access token instead — use this for gateways that validate as an OAuth resource server rather than validating the ID token directly. When set to `access_token`, `scopes` is required. |
276| `appendOfflineAccess` | No | Whether to automatically append `offline_access` to `scopes` in `access_token` mode. Defaults to `true`. Set to `false` only if your authorization server rejects `offline_access` as an unrecognized scope. See [Refresh tokens and session lifetime](#refresh-tokens-and-session-lifetime). |
277| `resource` | No | RFC 8707 resource indicator naming the gateway as the access-token audience: an `https://` URL, or, for AD FS, one of the relying-party trust's identifiers that has a scheme, such as `https://…` or `urn:…`, spelled as it is registered. A value with no scheme is sent as `https://<value>`; an identifier with a scheme of its own is sent exactly as written. When set, the app sends `resource=<value>` on the authorization, token, and refresh requests. Use only with `bearerTokenType: "access_token"` and an identity provider that implements RFC 8707 (for example AD FS); leave unset for Microsoft Entra ID, which rejects the parameter; request the gateway's API scope in `scopes` instead. Changing it signs users in again. Ignored by the OS-broker sign-in flow (`inferenceGatewayOidcAuthFlow: broker`). |
278| `additionalRedirectReferrerHosts` | No | Space-separated hostnames also accepted as the referrer of the sign-in callback, for identity providers that complete sign-in from a different host than the authorization URL's (for example a portal or step-up page on a sibling host). When a callback is rejected for a referrer mismatch, the app log names the host to add. |
279279 
280280\* Either `issuer`, or both `authorizationUrl` and `tokenUrl`, is required.
281281 

third-party/claude-desktop/in-app-configuration Changed · +8 / -8 lines

from line 20
2020 
2121Use the **Export** menu to generate deployment artifacts for a fleet:
2222 
23| Export option | Use with |
24| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
25| `.mobileconfig` profile | Jamf or any macOS MDM |
26| `.reg` policy file | Intune, Group Policy, or any Windows MDM |
27| ADMX template (`.zip`) | Intune or Group Policy; a schema-only template, you enter values in the management console |
28| Profile Manifest (`.plist`) | Jamf, ProfileCreator, or similar macOS tools; a schema-only template, you enter values in your tool |
29| JSON config | The response body for a [bootstrap server](/docs/third-party/claude-desktop/bootstrap), or a configuration file for a device without MDM |
30| Egress allowlist | Your firewall or network team |
23| Export option | Use with |
24| - | - |
25| `.mobileconfig` profile | Jamf or any macOS MDM |
26| `.reg` policy file | Intune, Group Policy, or any Windows MDM |
27| ADMX template (`.zip`) | Intune or Group Policy; a schema-only template, you enter values in the management console |
28| Profile Manifest (`.plist`) | Jamf, ProfileCreator, or similar macOS tools; a schema-only template, you enter values in your tool |
29| JSON config | The response body for a [bootstrap server](/docs/third-party/claude-desktop/bootstrap), or a configuration file for a device without MDM |
30| Egress allowlist | Your firewall or network team |
3131 
3232See [Deploy with MDM](/docs/third-party/claude-desktop/mdm) or [Deploy with a bootstrap server](/docs/third-party/claude-desktop/bootstrap) to distribute what you exported.
3333 

third-party/claude-desktop/installation Changed · +25 / -25 lines

from line 8
88 
99Cowork, the agent workspace at the center of Claude Desktop on 3P, has the following device requirements:
1010 
11| Requirement | macOS | Windows |
12| ---------------- | ---------------------------- | -------------------------------------------------------------------- |
13| Operating system | macOS 14 (Sonoma) or later | Windows 10 build 19041 (version 2004) or later, including Windows 11 |
14| CPU architecture | Apple silicon or Intel (x64) | x64 or Arm64 |
15| Installer | `.dmg` | `.msix` |
11| Requirement | macOS | Windows |
12| - | - | - |
13| Operating system | macOS 14 (Sonoma) or later | Windows 10 build 19041 (version 2004) or later, including Windows 11 |
14| CPU architecture | Apple silicon or Intel (x64) | x64 or Arm64 |
15| Installer | `.dmg` | `.msix` |
1616 
1717On Windows, Cowork requires the `.msix` package: fleets provisioned with the legacy `.exe` installer get Claude Desktop without Cowork, and migrating them to `.msix` enables it. Cowork also requires working hardware virtualization and, on Windows, the Virtual Machine Platform optional feature. The [readiness check](#check-device-readiness) verifies both along with the requirements above.
1818 
from line 20
2020 
2121Before installing Claude Desktop, you can confirm that a device supports Cowork by running the readiness check: a small standalone program that requires no installation or sign-in.
2222 
23| Platform | Download |
24| ------------- | ---------------------------------------------------------------------------------------------------------------------------- |
25| macOS | [Cowork readiness check for macOS](https://claude.ai/api/desktop/darwin/universal/cowork-readiness-check/latest/redirect) |
23| Platform | Download |
24| - | - |
25| macOS | [Cowork readiness check for macOS](https://claude.ai/api/desktop/darwin/universal/cowork-readiness-check/latest/redirect) |
2626| Windows (Arm) | [Cowork readiness check for Windows arm64](https://claude.ai/api/desktop/win32/arm64/cowork-readiness-check/latest/redirect) |
27| Windows (x64) | [Cowork readiness check for Windows x64](https://claude.ai/api/desktop/win32/x64/cowork-readiness-check/latest/redirect) |
27| Windows (x64) | [Cowork readiness check for Windows x64](https://claude.ai/api/desktop/win32/x64/cowork-readiness-check/latest/redirect) |
2828 
2929Open the downloaded program to run the check. A ready device reports **This computer is ready for Cowork**.
3030 
from line 34
3434 
3535Download the installer for your platform from [claude.com/download](https://claude.com/download).
3636 
37| Platform | Installer | Notes |
38| -------- | --------- | ----------------------------------------------------------- |
39| macOS | `.dmg` | Drag **Claude.app** to Applications |
40| Windows | `.msix` | Supports per-machine provisioning for enterprise deployment |
37| Platform | Installer | Notes |
38| - | - | - |
39| macOS | `.dmg` | Drag **Claude.app** to Applications |
40| Windows | `.msix` | Supports per-machine provisioning for enterprise deployment |
4141 
4242For fleet rollouts, distribute the installer through your standard software-distribution mechanism. On the MDM and bootstrap paths, distribute it after the configuration reaches devices; [Choose a configuration delivery model](#choose-a-configuration-delivery-model) covers how the configuration gets there.
4343 
from line 45
4545 
4646Configuration reaches devices in one of three ways. With the Enterprise Admin Console, Anthropic hosts the configuration and users receive it by signing in to the app. With MDM or a bootstrap server, you typically push a profile to devices with your MDM tooling, and the two differ in what the profile contains.
4747 
48| | Enterprise Admin Console | MDM profile | Bootstrap server |
49| -------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- |
50| What you deploy to devices | Only the app, which downloads each user's configuration when they sign in with their work account | The full configuration, exported as a `.mobileconfig` or `.reg` profile | A minimal profile containing only the bootstrap keys (`bootstrapUrl`, optionally `bootstrapOidc` or request headers) |
51| Where settings live | In the Enterprise Admin Console, which Anthropic hosts and your administrators edit in a browser | In the profile, identical for every device the profile targets | On an HTTPS endpoint you operate, which returns each user's configuration at sign-in |
52| Per-user values | Permission policies per group of users | Separate profiles per device group | The server keys its response to the signed-in user |
53| Changing settings | Save the change in the console. Running apps pick it up at their next check and, for most settings, ask the user to relaunch | Export and push an updated profile | Change your server's response; devices pick it up at the next fetch, with no profile push |
48| | Enterprise Admin Console | MDM profile | Bootstrap server |
49| - | - | - | - |
50| What you deploy to devices | Only the app, which downloads each user's configuration when they sign in with their work account | The full configuration, exported as a `.mobileconfig` or `.reg` profile | A minimal profile containing only the bootstrap keys (`bootstrapUrl`, optionally `bootstrapOidc` or request headers) |
51| Where settings live | In the Enterprise Admin Console, which Anthropic hosts and your administrators edit in a browser | In the profile, identical for every device the profile targets | On an HTTPS endpoint you operate, which returns each user's configuration at sign-in |
52| Per-user values | Permission policies per group of users | Separate profiles per device group | The server keys its response to the signed-in user |
53| Changing settings | Save the change in the console. Running apps pick it up at their next check and, for most settings, ask the user to relaunch | Export and push an updated profile | Change your server's response; devices pick it up at the next fetch, with no profile push |
5454 
5555Choose the Enterprise Admin Console when you want to manage the configuration centrally without operating MDM profiles or a server, and your users can sign in to Claude Desktop with a Claude account tied to their work email. Anthropic stores your user list and the settings you save. Prompts still go only to your inference provider, and conversations stay on the device. Contact your Anthropic representative to have an organization provisioned.
5656 
from line 150
150150 
151151Each supported platform and architecture has a fixed download URL that serves the current offline installer:
152152 
153| Platform | Format | Download URL |
154| --------------------- | ------- | -------------------------------------------------------------------- |
155| Windows (x64) | `.msix` | `https://claude.ai/api/desktop/win32/x64/offline/latest/redirect` |
156| Windows (Arm) | `.msix` | `https://claude.ai/api/desktop/win32/arm64/offline/latest/redirect` |
157| macOS (Apple silicon) | `.dmg` | `https://claude.ai/api/desktop/darwin/arm64/offline/latest/redirect` |
158| macOS (Intel) | `.dmg` | `https://claude.ai/api/desktop/darwin/x64/offline/latest/redirect` |
153| Platform | Format | Download URL |
154| - | - | - |
155| Windows (x64) | `.msix` | `https://claude.ai/api/desktop/win32/x64/offline/latest/redirect` |
156| Windows (Arm) | `.msix` | `https://claude.ai/api/desktop/win32/arm64/offline/latest/redirect` |
157| macOS (Apple silicon) | `.dmg` | `https://claude.ai/api/desktop/darwin/arm64/offline/latest/redirect` |
158| macOS (Intel) | `.dmg` | `https://claude.ai/api/desktop/darwin/x64/offline/latest/redirect` |
159159 
160160Each URL responds with an HTTP redirect to a versioned installer file, so any HTTP client that follows redirects downloads the installer directly. New versions of Claude Desktop roll out to connected devices gradually; these URLs serve the newest version whose rollout has completed. The redirect's `Location` header contains the version number, so tooling can detect a new version by requesting the URL without following the redirect.
161161 

third-party/claude-desktop/local-access Changed · +10 / -10 lines

from line 10
1010 
1111Set [`allowedWorkspaceFolders`](/docs/third-party/claude-desktop/configuration#allowedworkspacefolders) in the managed configuration to restrict which paths users may attach as workspace folders. The [Configuration reference](/docs/third-party/claude-desktop/configuration) covers where the managed configuration lives on each platform and how to deploy it.
1212 
13| Value | Behavior |
14| ---------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
15| Unset | Unrestricted. Users can attach any folder they have OS-level access to, matching standard Claude Desktop. |
16| `["~/Documents/Claude", "/Volumes/Shared/Projects"]` | Users may attach only folders **inside** one of the listed roots. |
17| `[]` | No folders may be attached. The agent can still create files in its own sandbox scratch space, but cannot read or write the user's filesystem. |
13| Value | Behavior |
14| - | - |
15| Unset | Unrestricted. Users can attach any folder they have OS-level access to, matching standard Claude Desktop. |
16| `["~/Documents/Claude", "/Volumes/Shared/Projects"]` | Users may attach only folders **inside** one of the listed roots. |
17| `[]` | No folders may be attached. The agent can still create files in its own sandbox scratch space, but cannot read or write the user's filesystem. |
1818 
1919A leading `~` expands to the user's home directory, so a single profile can express per-user roots like `~/Documents/Claude` across the fleet. A path may also reference one of a fixed set of environment-variable tokens, such as `%OneDrive%` or `%USERNAME%`, listed in the [configuration reference](/docs/third-party/claude-desktop/configuration#allowedworkspacefolders). An entry that references any other `%VAR%`, or one that is unset on the device, is ignored.
2020 
2121Each entry is either a plain path string or an object with these fields:
2222 
23| Field | Description |
24| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
25| `path` | The folder path (required). Subfolders are included. |
26| `mode` | `rw` (the default) or `ro`. The agent can view and search a read-only folder but cannot modify it in Cowork. In Code sessions, read-only applies to Claude's file tools only; shell commands and [SSH remote sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) do not enforce it. |
27| `isDefaultSelected` | When `true`, the folder appears already selected on the new-task page and skips the trust prompt. Users can remove it. |
23| Field | Description |
24| - | - |
25| `path` | The folder path (required). Subfolders are included. |
26| `mode` | `rw` (the default) or `ro`. The agent can view and search a read-only folder but cannot modify it in Cowork. In Code sessions, read-only applies to Claude's file tools only; shell commands and [SSH remote sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) do not enforce it. |
27| `isDefaultSelected` | When `true`, the folder appears already selected on the new-task page and skips the trust prompt. Users can remove it. |
2828 
2929For example, `[{"path": "~/Documents/Claude"}, {"path": "/Volumes/Shared/Reference", "mode": "ro"}]` lets users work in their own folder and consult the shared reference folder without changing it.
3030 

third-party/claude-desktop/mantle Changed · +20 / -20 lines

from line 8
88 
99Mantle supports a bearer token only. There is no in-app AWS sign-in or named-profile support for this provider; if you need per-user IAM Identity Center authentication, use the standard [Amazon Bedrock provider](/docs/third-party/claude-desktop/bedrock) instead.
1010 
11| Scenario | Use | Notes |
12| ----------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------- |
13| Any Mantle deployment | [Bearer token](#bearer-token) (`inferenceBedrockBearerToken`) | A long-lived token distributed in the managed profile. |
11| Scenario | Use | Notes |
12| - | - | - |
13| Any Mantle deployment | [Bearer token](#bearer-token) (`inferenceBedrockBearerToken`) | A long-lived token distributed in the managed profile. |
1414| Token must not be stored statically | [Credential helper](/docs/third-party/claude-desktop/configuration#inferencecredentialhelper) (`inferenceCredentialHelper`) | An executable that prints the bearer token to stdout at runtime. |
1515 
1616## Set up AWS
from line 29
2929 
3030Open the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration#open-the-configuration-window) (**Developer → Configure Third-Party Inference…**). In the **Connection** section, set **Inference provider** to **Bedrock Mantle**, then fill in the credentials card:
3131 
32| Field | Value |
33| ---------------- | ------------------------ |
34| AWS region | e.g. `us-east-1` |
32| Field | Value |
33| - | - |
34| AWS region | e.g. `us-east-1` |
3535| AWS bearer token | your Mantle bearer token |
36| Bedrock base URL | *optional* |
36| Bedrock base URL | *optional* |
3737 
3838If you set **Bedrock base URL**, provide the full SDK base URL including the `/anthropic` path (for example `https://bedrock-mantle.us-east-1.api.aws/anthropic`); it replaces the default `bedrock-mantle.<region>.api.aws/anthropic` endpoint.
3939 
from line 45
4545 
4646Mantle reuses the `inferenceBedrock*` key names. Only `inferenceBedrockRegion`, `inferenceBedrockBearerToken`, and `inferenceBedrockBaseUrl` apply; the other keys below (`inferenceBedrockProfile`, `inferenceBedrockSso*`, `inferenceBedrockAwsDir`, `inferenceBedrockAwsCliPath`, `inferenceBedrockServiceTier`) are ignored for this provider.
4747 
48| Setting | Type | Availability | Default | Description |
49| ------------------------------------------------------------------------------------------------ | -------- | --------------------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------- |
50| <span id="inferencebedrockregion" />AWS region<br />`inferenceBedrockRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS region for the Bedrock runtime endpoint. |
51| <span id="inferencebedrockbaseurl" />Bedrock base URL<br />`inferenceBedrockBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | For VPC endpoints or gateway proxies. Host origin only. |
52| <span id="inferencebedrockservicetier" />Bedrock service tier<br />`inferenceBedrockServiceTier` | `enum` | MDM + Bootstrap<br />Added in 1.5186.0 | — | Sent as the X-Amzn-Bedrock-Service-Tier header. Leave unset for on-demand. One of: `flex`, `priority`. |
53| <span id="inferencebedrockbearertoken" />AWS bearer token<br />`inferenceBedrockBearerToken` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static bearer token for inference. For providers that support profile or helper-script credentials, prefer those. |
54| <span id="inferencebedrockssostarturl" />AWS SSO start URL<br />`inferenceBedrockSsoStartUrl` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | Enables in-app AWS sign-in (no AWS CLI needed). Set with the three SSO fields below. |
55| <span id="inferencebedrockssoregion" />AWS SSO region<br />`inferenceBedrockSsoRegion` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center home region. |
56| <span id="inferencebedrockssoaccountid" />AWS SSO account ID<br />`inferenceBedrockSsoAccountId` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | 12-digit AWS account ID assigned to users in IAM Identity Center. |
57| <span id="inferencebedrockssorolename" />AWS SSO role name<br />`inferenceBedrockSsoRoleName` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center permission-set name granting bedrock:InvokeModel\* on the account above. |
58| <span id="inferencebedrockprofile" />AWS profile name<br />`inferenceBedrockProfile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS named profile to use for Bedrock inference credentials. |
59| <span id="inferencebedrockawsdir" />AWS config directory<br />`inferenceBedrockAwsDir` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folder with AWS config/credentials. Defaults to \~/.aws when no bearer token is set. |
60| <span id="inferencebedrockawsclipath" />AWS CLI path<br />`inferenceBedrockAwsCliPath` | `string` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Absolute path to the aws executable. Leave unset to find it on PATH. |
48| Setting | Type | Availability | Default | Description |
49| - | - | - | - | - |
50| <span id="inferencebedrockregion" />AWS region<br />`inferenceBedrockRegion` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS region for the Bedrock runtime endpoint. |
51| <span id="inferencebedrockbaseurl" />Bedrock base URL<br />`inferenceBedrockBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | For VPC endpoints or gateway proxies. Host origin only. |
52| <span id="inferencebedrockservicetier" />Bedrock service tier<br />`inferenceBedrockServiceTier` | `enum` | MDM + Bootstrap<br />Added in 1.5186.0 | — | Sent as the X-Amzn-Bedrock-Service-Tier header. Leave unset for on-demand. One of: `flex`, `priority`. |
53| <span id="inferencebedrockbearertoken" />AWS bearer token<br />`inferenceBedrockBearerToken` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Static bearer token for inference. For providers that support profile or helper-script credentials, prefer those. |
54| <span id="inferencebedrockssostarturl" />AWS SSO start URL<br />`inferenceBedrockSsoStartUrl` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | Enables in-app AWS sign-in (no AWS CLI needed). Set with the three SSO fields below. |
55| <span id="inferencebedrockssoregion" />AWS SSO region<br />`inferenceBedrockSsoRegion` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center home region. |
56| <span id="inferencebedrockssoaccountid" />AWS SSO account ID<br />`inferenceBedrockSsoAccountId` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | 12-digit AWS account ID assigned to users in IAM Identity Center. |
57| <span id="inferencebedrockssorolename" />AWS SSO role name<br />`inferenceBedrockSsoRoleName` | `string` | MDM + Bootstrap<br />Added in 1.6259.0 | — | IAM Identity Center permission-set name granting bedrock:InvokeModel\* on the account above. |
58| <span id="inferencebedrockprofile" />AWS profile name<br />`inferenceBedrockProfile` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | AWS named profile to use for Bedrock inference credentials. |
59| <span id="inferencebedrockawsdir" />AWS config directory<br />`inferenceBedrockAwsDir` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Folder with AWS config/credentials. Defaults to \~/.aws when no bearer token is set. |
60| <span id="inferencebedrockawsclipath" />AWS CLI path<br />`inferenceBedrockAwsCliPath` | `string` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Absolute path to the aws executable. Leave unset to find it on PATH. |
6161 
6262<AccordionGroup>
6363 <Accordion title="inferenceBedrockServiceTier details">

third-party/claude-desktop/mcp-sign-in Changed · +27 / -27 lines

from line 10
1010 
1111In the Enterprise Admin Console ([claude.ai](https://claude.ai) → **Organization settings**), open the **Connectors** page under **Desktop 3P**. Each remote entry under **Managed MCP servers** has an **OAuth** menu. Choose the setting that matches what the server's identity provider requires.
1212 
13| If the identity provider | **OAuth** setting | What you register at the identity provider | Fields to fill in |
14| ------------------------------------------------------------------------------------------ | ----------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- |
15| Supports dynamic client registration | **Auto-register (dynamic client registration)** | Nothing. Claude Desktop registers itself as a client on each device when the user first clicks **Connect** | None |
16| Requires an OAuth client that you register (no dynamic client registration) | **Bring your own client** | A public OAuth client (native or desktop application type) with redirect URI `http://127.0.0.1:53280/callback` and no secret | **Client ID** |
17| Requires a registered client and rejects token requests that don't carry the client secret | **Bring your own client** | An OAuth client with redirect URI `http://127.0.0.1:53280/callback`, plus its client secret | **Client ID**, **Authorization server**, and the secret in **Client secret** or **Client secret helper script** |
13| If the identity provider | **OAuth** setting | What you register at the identity provider | Fields to fill in |
14| - | - | - | - |
15| Supports dynamic client registration | **Auto-register (dynamic client registration)** | Nothing. Claude Desktop registers itself as a client on each device when the user first clicks **Connect** | None |
16| Requires an OAuth client that you register (no dynamic client registration) | **Bring your own client** | A public OAuth client (native or desktop application type) with redirect URI `http://127.0.0.1:53280/callback` and no secret | **Client ID** |
17| Requires a registered client and rejects token requests that don't carry the client secret | **Bring your own client** | An OAuth client with redirect URI `http://127.0.0.1:53280/callback`, plus its client secret | **Client ID**, **Authorization server**, and the secret in **Client secret** or **Client secret helper script** |
1818 
1919Leave the **OAuth** menu set to **None** for a server that needs no sign-in or that authenticates with request headers. The menu also lists **Anthropic-hosted client identity (requires Claude.ai sign-in)**, which this page doesn't cover.
2020 
from line 34
3434 
3535These fields appear when **OAuth** is set to **Bring your own client**. The [`managedMcpServers` reference](/docs/third-party/claude-desktop/configuration#managedmcpservers) lists every `oauth` key and its minimum Claude Desktop version.
3636 
37| Field | When to set | What to enter |
38| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
39| **Client ID** | You registered a client at the identity provider | The client ID from that registration |
40| **Client secret** | The identity provider requires the secret and the client is a Google Desktop-app client | The secret, beginning `GOCSPX-` |
41| **Client secret helper script** | The identity provider requires the secret (any identity provider) | The absolute path of the script on the device. Set this or **Client secret**, not both; in a configuration file that sets both, the script wins |
42| **Authorization server** | Required with a secret or secret helper script. Optional otherwise, to pin sign-in to a known issuer | A JSON array holding the authorization server's `issuer` value exactly as its metadata states it, for example `["https://accounts.google.com"]` (no trailing slash) or `["https://api.box.com"]` |
43| **Authorization URL** and **Token URL** | The identity provider publishes no discovery document | Both HTTPS endpoints, always as a pair. Hidden when **Tenant ID** or **Authorization server** is set |
44| **Tenant ID** | The client is a single-tenant Microsoft Entra app | Your Directory (tenant) ID. Requires **Scope** |
45| **Scope** | Required with **Tenant ID**. Optional otherwise | Space-separated scopes for the authorize request. Leave empty to request the scopes the server advertises |
46| **Sign-in flow** | Shown after you enter **Tenant ID**. Set it when your devices have the [OS identity broker](/docs/third-party/claude-desktop/entra-broker) | **OS identity broker (WAM / Company Portal)**. The default is **System browser** |
47| **Callback host** and **Callback port** | The redirect URI you registered uses `localhost` or a port other than `53280` | The host and port from that registration. Microsoft Entra ID accepts any loopback port, so leave both empty for Entra |
48| **Additional redirect referrer hosts** | The identity provider completes sign-in from a host other than the one in its authorization URL, and `main.log` names a rejected referrer host | That hostname. Separate several with spaces |
37| Field | When to set | What to enter |
38| - | - | - |
39| **Client ID** | You registered a client at the identity provider | The client ID from that registration |
40| **Client secret** | The identity provider requires the secret and the client is a Google Desktop-app client | The secret, beginning `GOCSPX-` |
41| **Client secret helper script** | The identity provider requires the secret (any identity provider) | The absolute path of the script on the device. Set this or **Client secret**, not both; in a configuration file that sets both, the script wins |
42| **Authorization server** | Required with a secret or secret helper script. Optional otherwise, to pin sign-in to a known issuer | A JSON array holding the authorization server's `issuer` value exactly as its metadata states it, for example `["https://accounts.google.com"]` (no trailing slash) or `["https://api.box.com"]` |
43| **Authorization URL** and **Token URL** | The identity provider publishes no discovery document | Both HTTPS endpoints, always as a pair. Hidden when **Tenant ID** or **Authorization server** is set |
44| **Tenant ID** | The client is a single-tenant Microsoft Entra app | Your Directory (tenant) ID. Requires **Scope** |
45| **Scope** | Required with **Tenant ID**. Optional otherwise | Space-separated scopes for the authorize request. Leave empty to request the scopes the server advertises |
46| **Sign-in flow** | Shown after you enter **Tenant ID**. Set it when your devices have the [OS identity broker](/docs/third-party/claude-desktop/entra-broker) | **OS identity broker (WAM / Company Portal)**. The default is **System browser** |
47| **Callback host** and **Callback port** | The redirect URI you registered uses `localhost` or a port other than `53280` | The host and port from that registration. Microsoft Entra ID accepts any loopback port, so leave both empty for Entra |
48| **Additional redirect referrer hosts** | The identity provider completes sign-in from a host other than the one in its authorization URL, and `main.log` names a rejected referrer host | That hostname. Separate several with spaces |
4949 
5050## Settings for common servers
5151 
5252Add each server in this table with **Add → Blank**, the **Streamable HTTP** transport, and the values shown.
5353 
54| Server | URL | **OAuth** setting | What you register |
55| ------ | ---------------------------- | ----------------------------------------------- | ----------------- |
56| Linear | `https://mcp.linear.app/mcp` | **Auto-register (dynamic client registration)** | Nothing |
57| Notion | `https://mcp.notion.com/mcp` | **Auto-register (dynamic client registration)** | Nothing |
58| Sentry | `https://mcp.sentry.dev/mcp` | **Auto-register (dynamic client registration)** | Nothing |
54| Server | URL | **OAuth** setting | What you register |
55| - | - | - | - |
56| Linear | `https://mcp.linear.app/mcp` | **Auto-register (dynamic client registration)** | Nothing |
57| Notion | `https://mcp.notion.com/mcp` | **Auto-register (dynamic client registration)** | Nothing |
58| Sentry | `https://mcp.sentry.dev/mcp` | **Auto-register (dynamic client registration)** | Nothing |
5959 
6060## Troubleshoot sign-in
6161 
6262These messages appear in Claude Desktop, or in `main.log` in the [logs directory](/docs/third-party/claude-desktop/data-storage#where-data-lives) on the user's device.
6363 
64| What the user sees or `main.log` records | Cause | Fix |
65| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
66| "Couldn't connect to \{server} because it doesn't support automatic client registration" (Claude Desktop 2.110.0 or later), or `main.log` records that the authorization server does not support dynamic client registration | **OAuth** is **Auto-register** but the identity provider requires a client that you register | Register a public client with redirect URI `http://127.0.0.1:53280/callback`, set **OAuth** to **Bring your own client**, and fill in **Client ID** |
67| The browser step succeeds, then the connection fails and `main.log` records the token endpoint's error, for example `client_secret is missing` | The entry has a **Client ID** but the identity provider also requires the secret | Add the secret and **Authorization server** as described under [Where the client secret goes](#where-the-client-secret-goes) |
68| `main.log` names a rejected referrer host during sign-in | The identity provider completes sign-in from a host other than the one in its authorization URL | Add that hostname to **Additional redirect referrer hosts** |
64| What the user sees or `main.log` records | Cause | Fix |
65| - | - | - |
66| "Couldn't connect to \{server} because it doesn't support automatic client registration" (Claude Desktop 2.110.0 or later), or `main.log` records that the authorization server does not support dynamic client registration | **OAuth** is **Auto-register** but the identity provider requires a client that you register | Register a public client with redirect URI `http://127.0.0.1:53280/callback`, set **OAuth** to **Bring your own client**, and fill in **Client ID** |
67| The browser step succeeds, then the connection fails and `main.log` records the token endpoint's error, for example `client_secret is missing` | The entry has a **Client ID** but the identity provider also requires the secret | Add the secret and **Authorization server** as described under [Where the client secret goes](#where-the-client-secret-goes) |
68| `main.log` names a rejected referrer host during sign-in | The identity provider completes sign-in from a host other than the one in its authorization URL | Add that hostname to **Additional redirect referrer hosts** |
6969 
7070## Related connector guides
7171 

third-party/claude-desktop/mdm Changed · +27 / -27 lines

from line 34
3434 
3535The window is organized into sections in the left sidebar. Work through them in order; each maps to a group of [configuration keys](/docs/third-party/claude-desktop/configuration), and the window validates values as you enter them.
3636 
37| Section | What you set |
38| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
39| **Connection** | Inference provider (Gateway, Claude API, Google Cloud's Agent Platform, Bedrock, Bedrock Mantle, or Foundry) and its credentials<br />Model list<br />Organization UUID<br />Optional credential-helper script |
40| **Capabilities** | Which of Cowork, Code, and Chat are available<br />Allowed egress hosts for the sandbox<br />Disabled built-in tools<br />Allowed workspace folders |
41| **Connectors** | Managed MCP servers pushed to all users<br />Whether users can add their own local MCP servers<br />Whether desktop extensions (`.mcpb`) are allowed<br />Whether unsigned extensions are rejected |
42| **Telemetry & updates** | OpenTelemetry collector endpoint<br />Whether auto-updates are blocked, and the enforcement window if not<br />The three Anthropic-bound telemetry toggles (essential, nonessential, nonessential services) |
43| **Limits** | Per-device token cap and its window length<br />Retention periods after which idle chats, Cowork tasks, and Code sessions are deleted, and the hold that suspends deletion |
44| **Appearance** | Persistent banner shown across the app window<br />Deployment display name and subtitle<br />Whether the signed-in user's identity is shown and exported (end-user attribution)<br />Whether feature announcements are shown |
45| **Plugins** | [Plugin marketplaces](/docs/third-party/claude-desktop/extensions#plugin-marketplaces-admin), added by GitHub repo, git URL, or hosted `marketplace.json` URL<br />Shows the org-plugins folder path for your platform; plugin bundles are mounted to that folder via your MDM, not through this window |
46| **Egress** | A read-only firewall allowlist derived from everything you've entered above, grouped by feature<br />**Copy hostnames**, **Download .txt**, and **Test connectivity** actions |
47| **Source** | The bootstrap keys, if you are using the [bootstrap server](/docs/third-party/claude-desktop/bootstrap) delivery model instead of a full MDM profile<br />Bootstrap-delivered configuration takes priority over MDM-delivered values: it replaces them wholesale rather than merging key by key |
37| Section | What you set |
38| - | - |
39| **Connection** | Inference provider (Gateway, Claude API, Google Cloud's Agent Platform, Bedrock, Bedrock Mantle, or Foundry) and its credentials<br />Model list<br />Organization UUID<br />Optional credential-helper script |
40| **Capabilities** | Which of Cowork, Code, and Chat are available<br />Allowed egress hosts for the sandbox<br />Disabled built-in tools<br />Allowed workspace folders |
41| **Connectors** | Managed MCP servers pushed to all users<br />Whether users can add their own local MCP servers<br />Whether desktop extensions (`.mcpb`) are allowed<br />Whether unsigned extensions are rejected |
42| **Telemetry & updates** | OpenTelemetry collector endpoint<br />Whether auto-updates are blocked, and the enforcement window if not<br />The three Anthropic-bound telemetry toggles (essential, nonessential, nonessential services) |
43| **Limits** | Per-device token cap and its window length<br />Retention periods after which idle chats, Cowork tasks, and Code sessions are deleted, and the hold that suspends deletion |
44| **Appearance** | Persistent banner shown across the app window<br />Deployment display name and subtitle<br />Whether the signed-in user's identity is shown and exported (end-user attribution)<br />Whether feature announcements are shown |
45| **Plugins** | [Plugin marketplaces](/docs/third-party/claude-desktop/extensions#plugin-marketplaces-admin), added by GitHub repo, git URL, or hosted `marketplace.json` URL<br />Shows the org-plugins folder path for your platform; plugin bundles are mounted to that folder via your MDM, not through this window |
46| **Egress** | A read-only firewall allowlist derived from everything you've entered above, grouped by feature<br />**Copy hostnames**, **Download .txt**, and **Test connectivity** actions |
47| **Source** | The bootstrap keys, if you are using the [bootstrap server](/docs/third-party/claude-desktop/bootstrap) delivery model instead of a full MDM profile<br />Bootstrap-delivered configuration takes priority over MDM-delivered values: it replaces them wholesale rather than merging key by key |
4848 
4949<Note>
5050 When a managed (MDM-delivered) configuration is already present on the device, the configuration window opens read-only: it shows what the admin deployed, marks the configuration as organization-managed, and directs users to their IT administrator. To author a new configuration, use a device without a managed profile, or temporarily remove the profile. Profiles that set [only app-behavior keys](#update-keys-and-managed-precedence) (the update, configuration re-check, relaunch window, and network proxy keys) leave the window editable.
from line 54
5454 
5555Once your configuration tests successfully, click **Export** and choose a format:
5656 
57| Format | Platform | Deploy with |
58| --------------------------- | -------- | --------------------------------------------------------------------------------------------------------------- |
59| `.mobileconfig` | macOS | Jamf, Kandji, Mosyle, Workspace ONE, or any Apple MDM |
60| `.reg` | Windows | Group Policy (import into a GPO), Intune (via custom ADMX or script), or any MDM that can write registry policy |
61| `.zip` (ADMX template) | Windows | Schema-only template for Intune or Group Policy; you enter values in the management console |
62| `.plist` (Profile Manifest) | macOS | Schema-only template for Jamf, ProfileCreator, or similar macOS tools |
57| Format | Platform | Deploy with |
58| - | - | - |
59| `.mobileconfig` | macOS | Jamf, Kandji, Mosyle, Workspace ONE, or any Apple MDM |
60| `.reg` | Windows | Group Policy (import into a GPO), Intune (via custom ADMX or script), or any MDM that can write registry policy |
61| `.zip` (ADMX template) | Windows | Schema-only template for Intune or Group Policy; you enter values in the management console |
62| `.plist` (Profile Manifest) | macOS | Schema-only template for Jamf, ProfileCreator, or similar macOS tools |
6363 
6464**Apply Changes** and **Export** do different things:
6565 
from line 101
101101 
102102<Tabs>
103103 <Tab title="macOS">
104 | Source | Path | Precedence |
105 | ------------------ | -------------------------------------------------------------------------- | ---------- |
106 | Managed (per-user) | `/Library/Managed Preferences/<user>/com.anthropic.claudefordesktop.plist` | Highest |
107 | Managed (machine) | `/Library/Managed Preferences/com.anthropic.claudefordesktop.plist` | |
108 | Local (user) | `~/Library/Application Support/Claude-3p/configLibrary/` | Lowest |
104 | Source | Path | Precedence |
105 | - | - | - |
106 | Managed (per-user) | `/Library/Managed Preferences/<user>/com.anthropic.claudefordesktop.plist` | Highest |
107 | Managed (machine) | `/Library/Managed Preferences/com.anthropic.claudefordesktop.plist` | |
108 | Local (user) | `~/Library/Application Support/Claude-3p/configLibrary/` | Lowest |
109109 
110110 A `.mobileconfig` profile delivered by MDM lands in the Managed Preferences locations automatically. Both managed paths are read; where a key appears in both, the per-user value wins.
111111 </Tab>
112112 
113113 <Tab title="Windows">
114 | Source | Path | Precedence |
115 | -------------- | ----------------------------------------- | ---------- |
116 | Machine policy | `HKLM\SOFTWARE\Policies\Claude` | Highest |
117 | User policy | `HKCU\SOFTWARE\Policies\Claude` | |
118 | Local (user) | `%LOCALAPPDATA%\Claude-3p\configLibrary\` | Lowest |
114 | Source | Path | Precedence |
115 | - | - | - |
116 | Machine policy | `HKLM\SOFTWARE\Policies\Claude` | Highest |
117 | User policy | `HKCU\SOFTWARE\Policies\Claude` | |
118 | Local (user) | `%LOCALAPPDATA%\Claude-3p\configLibrary\` | Lowest |
119119 
120120 A Group Policy Object or Intune configuration profile writes to the registry policy paths. The hives are not merged: when machine policy is present (any `REG_SZ`, `REG_EXPAND_SZ`, or `REG_DWORD` value directly under `HKLM\SOFTWARE\Policies\Claude`, including an empty string, and the key's unnamed default value when set), the app ignores `HKCU\SOFTWARE\Policies\Claude` entirely. Deploy the complete configuration to one hive; machine policy (`HKLM`) is the recommended location.
121121 

third-party/claude-desktop/network-proxy Changed · +20 / -20 lines

from line 32
3232 
3333If you want the app, the agent, and (on macOS and Windows) Cowork's sandboxed shell to use a specific proxy regardless of what the device's OS settings say, set one of two managed configuration keys:
3434 
35| Key | Value | Effect |
36| ------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
37| `egressProxyUrl` | An `http://` or `https://` proxy URL, for example `http://proxy.example.com:8080` | The app sends its traffic through this proxy, and the agent receives it as `HTTPS_PROXY` and `HTTP_PROXY` in every session on the device. On macOS and Windows, commands in Cowork's sandboxed shell receive the same variables. Loopback and `.local` hosts still connect directly. |
35| Key | Value | Effect |
36| - | - | - |
37| `egressProxyUrl` | An `http://` or `https://` proxy URL, for example `http://proxy.example.com:8080` | The app sends its traffic through this proxy, and the agent receives it as `HTTPS_PROXY` and `HTTP_PROXY` in every session on the device. On macOS and Windows, commands in Cowork's sandboxed shell receive the same variables. Loopback and `.local` hosts still connect directly. |
3838| `egressProxyPacUrl` | An `http://` or `https://` URL to a PAC script, for example `http://wpad.example.com/proxy.pac` | The app evaluates the script per request. The agent receives the single proxy the script returns for your inference endpoint. On macOS and Windows, Cowork's sandboxed shell is handed a copy of the script when the sandbox starts and evaluates it per request itself. If both keys are set, this one wins. |
3939 
4040Both keys are read once at launch; a change takes effect the next time the app starts. While either key is set, the OS proxy settings are ignored for the app, the agent, and (on macOS and Windows) Cowork's sandboxed shell; with neither key set, the sandboxed shell keeps following the OS settings as described under [Default behavior](#default-behavior). SOCKS URLs and URLs with embedded credentials (`user:password@`) are rejected.
from line 63
6363 
6464The table summarizes which proxy source each kind of traffic follows. "App proxy" means the pinned key if one is set, otherwise the OS settings, with PAC rules applied per request.
6565 
66| Traffic | Proxy it follows |
67| ------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------- |
68| App window, in-app sign-in, connection test, model list | App proxy |
69| Inference requests from Chat, Cowork, and Code sessions | The single proxy resolved for the inference endpoint (from the pinned key or the OS), or Claude Code managed settings if deployed |
70| Agent web fetch, remote MCP servers, and plugin installs in Code sessions | Same single proxy as inference |
71| Web Fetch and managed MCP servers in Chat and Cowork sessions | App proxy (the app makes these connections) |
72| Plugin marketplace sync and `aws` CLI calls the app makes for Bedrock sign-in | App proxy, resolved for the specific host |
73| Cowork sandbox download from `downloads.claude.ai` | App proxy |
74| Telemetry and crash reports to Anthropic, if enabled | App proxy |
75| OpenTelemetry export to your collector | App proxy for the app's own events; the same single proxy as inference for Claude Code metrics and logs |
76| Commands in Cowork's sandboxed shell on macOS and Windows | The pinned key if one is set (a pinned PAC script is evaluated per request inside the sandbox), otherwise the OS proxy settings |
77| Commands in Cowork's sandboxed shell on Linux | None; commands connect directly |
78| The agent in an [SSH remote Code session](/docs/third-party/claude-desktop/ssh-remote-sessions) | None from the device; the remote host's own network route applies |
79| App update check and download | OS proxy settings only |
80| Credential helper and header helper scripts you configure | None injected; the script's own environment applies |
81| Brokered Microsoft Entra sign-in (Company Portal on macOS, Web Account Manager on Windows) | The OS broker's own settings |
82| Pages opened in the system browser | The browser's own settings |
66| Traffic | Proxy it follows |
67| - | - |
68| App window, in-app sign-in, connection test, model list | App proxy |
69| Inference requests from Chat, Cowork, and Code sessions | The single proxy resolved for the inference endpoint (from the pinned key or the OS), or Claude Code managed settings if deployed |
70| Agent web fetch, remote MCP servers, and plugin installs in Code sessions | Same single proxy as inference |
71| Web Fetch and managed MCP servers in Chat and Cowork sessions | App proxy (the app makes these connections) |
72| Plugin marketplace sync and `aws` CLI calls the app makes for Bedrock sign-in | App proxy, resolved for the specific host |
73| Cowork sandbox download from `downloads.claude.ai` | App proxy |
74| Telemetry and crash reports to Anthropic, if enabled | App proxy |
75| OpenTelemetry export to your collector | App proxy for the app's own events; the same single proxy as inference for Claude Code metrics and logs |
76| Commands in Cowork's sandboxed shell on macOS and Windows | The pinned key if one is set (a pinned PAC script is evaluated per request inside the sandbox), otherwise the OS proxy settings |
77| Commands in Cowork's sandboxed shell on Linux | None; commands connect directly |
78| The agent in an [SSH remote Code session](/docs/third-party/claude-desktop/ssh-remote-sessions) | None from the device; the remote host's own network route applies |
79| App update check and download | OS proxy settings only |
80| Credential helper and header helper scripts you configure | None injected; the script's own environment applies |
81| Brokered Microsoft Entra sign-in (Company Portal on macOS, Web Account Manager on Windows) | The OS broker's own settings |
82| Pages opened in the system browser | The browser's own settings |
8383 
8484## Traffic that bypasses the app proxy
8585 

third-party/claude-desktop/overview Changed · +8 / -8 lines

from line 21
2121 
2222Claude Desktop on 3P keeps the standard feature set and relocates inference to the provider you configure.
2323 
24| Component | Standard Claude Desktop | Claude Desktop on 3P |
25| ---------------------- | -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
26| Model inference | Anthropic API | Your configured provider endpoint (Google Cloud's Agent Platform, Amazon Bedrock, Microsoft Foundry, or gateway), or the Anthropic API |
27| Web application | Loaded from claude.ai | Bundled inside the desktop app |
28| User identity | Anthropic account | Local device identity only (Anthropic account when managed from the claude.ai admin console) |
29| Conversation storage | Anthropic backend | Local disk on the user's machine |
30| Code execution sandbox | Local VM | Local VM (identical) |
31| Configuration | Admin console at claude.ai | OS-native configuration (MDM-managed or per-user), a bootstrap server, or the claude.ai admin console |
24| Component | Standard Claude Desktop | Claude Desktop on 3P |
25| - | - | - |
26| Model inference | Anthropic API | Your configured provider endpoint (Google Cloud's Agent Platform, Amazon Bedrock, Microsoft Foundry, or gateway), or the Anthropic API |
27| Web application | Loaded from claude.ai | Bundled inside the desktop app |
28| User identity | Anthropic account | Local device identity only (Anthropic account when managed from the claude.ai admin console) |
29| Conversation storage | Anthropic backend | Local disk on the user's machine |
30| Code execution sandbox | Local VM | Local VM (identical) |
31| Configuration | Admin console at claude.ai | OS-native configuration (MDM-managed or per-user), a bootstrap server, or the claude.ai admin console |
3232 
3333The desktop app detects 3P mode at launch from the configured inference provider. When a provider and its credentials are present, the sign-in screen offers the option to skip Anthropic authentication and start the app using your inference-provider configuration instead.
3434 

third-party/claude-desktop/ssh-remote-sessions Changed · +22 / -22 lines

from line 23
2323 
2424Set [`sshHostAllowlist`](/docs/third-party/claude-desktop/configuration#sshhostallowlist) in your managed configuration. It appears in the **Code surface** section of the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration) while Code is enabled.
2525 
26| Value | Behavior |
27| --------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
28| Unset | Off, unless a Claude Code managed-settings `sshHostAllowlist` on the device allows hosts (see [Interaction with Claude Code managed settings](#interaction-with-claude-code-managed-settings-on-the-device)) |
29| `[]` | Off. Delivered by an administrator, `[]` also overrides a Claude Code managed-settings allowlist on the device |
30| `["*"]` | Users can connect to any host |
31| `["build01.corp.example.com", "*.dev.example.com"]` | Users can connect only to hosts that match an entry |
26| Value | Behavior |
27| - | - |
28| Unset | Off, unless a Claude Code managed-settings `sshHostAllowlist` on the device allows hosts (see [Interaction with Claude Code managed settings](#interaction-with-claude-code-managed-settings-on-the-device)) |
29| `[]` | Off. Delivered by an administrator, `[]` also overrides a Claude Code managed-settings allowlist on the device |
30| `["*"]` | Users can connect to any host |
31| `["build01.corp.example.com", "*.dev.example.com"]` | Users can connect only to hosts that match an entry |
3232 
3333While SSH remote sessions are off, the environment picker shows local sessions only, and any attempt to connect to a saved host is refused.
3434 
from line 71
7171 
7272The remote engine uses only the credential Claude Desktop passes in its environment. It ignores credentials already on the host, such as an AWS profile or application default credentials, and Claude Desktop copies no credential files there. Credential kinds that live in a file on the device are refused at session start.
7373 
74| Provider | Works on a remote host | Refused at session start |
75| ------------------------------------------------------------------- | -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
76| [LLM gateway](/docs/third-party/claude-desktop/gateway) | Static API key, single sign-on, credential helper | |
77| [Claude API](/docs/third-party/claude-desktop/claude-api) | Static API key, Sign in with Claude Console, credential helper | |
78| [Microsoft Foundry](/docs/third-party/claude-desktop/foundry) | API key, in-app Entra ID sign-in, credential helper | |
79| [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock) | Bearer token, identity provider sign-in, credential helper | In-app AWS sign-in (IAM Identity Center), named profile |
80| [Amazon Bedrock Mantle](/docs/third-party/claude-desktop/mantle) | Bearer token, credential helper | |
81| [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex) | In-app Workforce Identity sign-in, credential helper | In-app Google sign-in, service-account key or credentials file, application default credentials on the device |
74| Provider | Works on a remote host | Refused at session start |
75| - | - | - |
76| [LLM gateway](/docs/third-party/claude-desktop/gateway) | Static API key, single sign-on, credential helper | |
77| [Claude API](/docs/third-party/claude-desktop/claude-api) | Static API key, Sign in with Claude Console, credential helper | |
78| [Microsoft Foundry](/docs/third-party/claude-desktop/foundry) | API key, in-app Entra ID sign-in, credential helper | |
79| [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock) | Bearer token, identity provider sign-in, credential helper | In-app AWS sign-in (IAM Identity Center), named profile |
80| [Amazon Bedrock Mantle](/docs/third-party/claude-desktop/mantle) | Bearer token, credential helper | |
81| [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex) | In-app Workforce Identity sign-in, credential helper | In-app Google sign-in, service-account key or credentials file, application default credentials on the device |
8282 
8383When the configured credential is a refused kind, the session fails before anything is deployed to the host, with the card [Remote sessions aren't available with this inference setup](#remote-sessions-aren%E2%80%99t-available-with-this-inference-setup).
8484 
from line 117
117117 
118118Claude Desktop writes the following into the SSH user's home directory on the host. Each user who connects gets their own copy.
119119 
120| Path on the host | Contents |
121| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------- |
122| `~/.claude/remote/srv/<version>/` | The remote server that Claude Desktop talks to |
123| `~/.claude/remote/ccd-cli/<version>` | The Claude Code engine, one file per version (the three most recent versions are kept) |
124| `~/.claude/remote/run/<id>/` | The server's socket, token, and log |
125| `~/.claude/remote/plugins/<hash>/` | Plugins synced from the device |
126| `~/.claude/uploads/<session-id>/` | Files the user attached to a message. Not removed when the session ends |
127| `~/.claude/` and `~/.claude.json` | Claude Code's own data, including session transcripts. See [Data storage](/docs/third-party/claude-desktop/data-storage) |
120| Path on the host | Contents |
121| - | - |
122| `~/.claude/remote/srv/<version>/` | The remote server that Claude Desktop talks to |
123| `~/.claude/remote/ccd-cli/<version>` | The Claude Code engine, one file per version (the three most recent versions are kept) |
124| `~/.claude/remote/run/<id>/` | The server's socket, token, and log |
125| `~/.claude/remote/plugins/<hash>/` | Plugins synced from the device |
126| `~/.claude/uploads/<session-id>/` | Files the user attached to a message. Not removed when the session ends |
127| `~/.claude/` and `~/.claude.json` | Claude Code's own data, including session transcripts. See [Data storage](/docs/third-party/claude-desktop/data-storage) |
128128 
129129Each side of a remote session needs its own network access.
130130 

third-party/claude-desktop/telemetry Changed · +92 / -92 lines

from line 14
1414 
1515Crash reports, error stack traces, and performance timings. Contains diagnostic metadata (app version, OS, error type, redacted stack frames) but **never prompt or response content**. Attributed to your organization via `deploymentOrganizationUuid` so Anthropic support can find issues you report.
1616 
17| Setting | Default | Effect when `true` |
18| --------------------------- | ------- | ----------------------------------------- |
17| Setting | Default | Effect when `true` |
18| - | - | - |
1919| `disableEssentialTelemetry` | `false` | No crash or error data leaves the device. |
2020 
2121On Claude Desktop 2.7032.0 and later, the [**Keep only your organization ID and restrictions on disk**](/docs/third-party/claude-desktop/admin-console#configuration-kept-on-devices) switch in the [Enterprise Admin Console](/docs/third-party/claude-desktop/admin-console) also stops the app's crash and performance reports, even while `disableEssentialTelemetry` is `false`.
from line 28
2828 
2929Product-usage analytics: feature adoption, session counts, UI interactions. Used to understand how Claude Desktop is used in aggregate. Contains no prompt or response content. Also gates the **Send** button in Help → Generate Diagnostic Report; with this disabled, diagnostic bundles can only be saved locally.
3030 
31| Setting | Default | Effect when `true` |
32| ------------------------------ | ------- | -------------------------------------- |
31| Setting | Default | Effect when `true` |
32| - | - | - |
3333| `disableNonessentialTelemetry` | `false` | No product analytics leave the device. |
3434 
3535Leaving this enabled also adds `api.anthropic.com` to the [agent egress allowlist](#required-egress-paths) automatically, so Claude Code can deliver its usage telemetry from inside the sandbox. Allow that host at the perimeter too; it appears in the non-essential telemetry table below.
from line 38
3838 
3939Cosmetic third-party fetches: favicons for connectors shown in the UI, the sandboxed iframe that renders interactive artifact previews, and the sandboxed iframes that render [MCP Apps](/docs/connectors/building/mcp-apps/getting-started), the interactive widgets connectors can display. Disabling these degrades the UI (generic icons, static artifact previews, and connector tool results shown as text instead of widgets) but doesn't affect functionality.
4040 
41| Setting | Default | Effect when `true` |
42| ----------------------------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
41| Setting | Default | Effect when `true` |
42| - | - | - |
4343| `disableNonessentialServices` | `false` | Favicon, artifact-preview, and MCP App widget fetches are blocked. Connectors that return MCP Apps show the tool's text result instead of the widget. |
4444 
4545### Auto-updates
from line 46
4646 
4747Checks Anthropic's update feed and downloads new builds.
4848 
49| Setting | Default | Effect when `true` |
50| -------------------- | ------- | ----------------------------------------------------------------------------------------- |
49| Setting | Default | Effect when `true` |
50| - | - | - |
5151| `disableAutoUpdates` | `false` | The app never checks for or downloads updates. Your IT team must redistribute new builds. |
5252 
5353## Sending telemetry to your own collector
from line 97
9797 
9898To include content in the export, set `otlpContentCapture` to an array of categories:
9999 
100| Category | Captures |
101| -------------------- | --------------------------------------------------------------- |
102| `userPrompts` | User message text and conversation titles |
103| `assistantResponses` | Model response text |
104| `toolDetails` | Tool input arguments (for example, the web-search query string) |
105| `toolContent` | Tool output content |
106| `rawApiBodies` | Full inference request and response bodies |
100| Category | Captures |
101| - | - |
102| `userPrompts` | User message text and conversation titles |
103| `assistantResponses` | Model response text |
104| `toolDetails` | Tool input arguments (for example, the web-search query string) |
105| `toolContent` | Tool output content |
106| `rawApiBodies` | Full inference request and response bodies |
107107 
108108On Claude Desktop version 1.17377 or later, enabling `userPrompts` also captures model responses, even if `assistantResponses` is not listed. On those versions, no `otlpContentCapture` configuration captures user prompts without model responses.
109109 
from line 143
143143 
144144### Always required
145145 
146| Host | Purpose |
147| --------------------- | ----------------------------------------------------------------------------- |
148| `downloads.claude.ai` | VM workspace bundle and Claude CLI binary, fetched at session start |
146| Host | Purpose |
147| - | - |
148| `downloads.claude.ai` | VM workspace bundle and Claude CLI binary, fetched at session start |
149149| `downloads.claude.ai` | Claude Code model catalog (signed picker metadata), polled every 5–15 minutes |
150150 
151151Without this host reachable, Chat conversations, Cowork tasks, and Code sessions cannot start on a device that has not yet downloaded these components. App updates often change one or both of these components, and the app then downloads the new versions from the same host. Devices installed with the [offline installer variant](/docs/third-party/claude-desktop/installation#offline-installation), which includes both components in the installer package, are not affected. The model catalog fetch is not needed to run the app: set [`modelCatalogEnabled`](/docs/third-party/claude-desktop/configuration#modelcatalogenabled) to `false` to turn it off, or [`modelCatalogUrl`](/docs/third-party/claude-desktop/configuration#modelcatalogurl) to fetch the catalog from a mirror inside your network. While the catalog is unreachable, sessions still start and the model picker keeps the names and effort options the app last fetched or shipped with.
from line 156
156156 
157157<Tabs>
158158 <Tab title="Google Cloud's Agent Platform">
159 | Host | Purpose |
160 | ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
159 | Host | Purpose |
160 | - | - |
161161 | `<region>-aiplatform.googleapis.com` | Model inference for single regions. The `global` region uses `aiplatform.googleapis.com`, and the `eu` / `us` multi-regions use `aiplatform.eu.rep.googleapis.com` / `aiplatform.us.rep.googleapis.com`. Replaced by the host of `inferenceVertexBaseUrl` if set. |
162 | `oauth2.googleapis.com` | Google auth token exchange |
163 | `sts.googleapis.com` | Google auth token exchange |
164 | `accounts.google.com` | Google auth token exchange |
165 | `iamcredentials.googleapis.com` | Google auth token exchange |
162 | `oauth2.googleapis.com` | Google auth token exchange |
163 | `sts.googleapis.com` | Google auth token exchange |
164 | `accounts.google.com` | Google auth token exchange |
165 | `iamcredentials.googleapis.com` | Google auth token exchange |
166166 </Tab>
167167 
168168 <Tab title="Amazon Bedrock">
169 | Host | Purpose |
170 | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
171 | `bedrock-runtime.<region>.amazonaws.com` | Model inference. Replaced by the host of `inferenceBedrockBaseUrl` if set. |
172 | `bedrock.<region>.amazonaws.com` | Control plane (model discovery) |
173 | `sts.amazonaws.com`, `sts.<region>.amazonaws.com` | STS token exchange (profile auth only) |
169 | Host | Purpose |
170 | - | - |
171 | `bedrock-runtime.<region>.amazonaws.com` | Model inference. Replaced by the host of `inferenceBedrockBaseUrl` if set. |
172 | `bedrock.<region>.amazonaws.com` | Control plane (model discovery) |
173 | `sts.amazonaws.com`, `sts.<region>.amazonaws.com` | STS token exchange (profile auth only) |
174174 | `portal.sso.<sso-region>.amazonaws.com`, `oidc.<sso-region>.amazonaws.com` | IAM Identity Center sign-in and token refresh, for [in-app AWS sign-in](/docs/third-party/claude-desktop/bedrock#in-app-aws-sign-in) and for named profiles that use IAM Identity Center. `<sso-region>` is `inferenceBedrockSsoRegion` (or the profile's `sso_region`) and can differ from the inference region. |
175175 
176176 With `inferenceBedrockBearerToken` set, the runtime and control-plane hosts are required.
from line 179
179179 </Tab>
180180 
181181 <Tab title="Amazon Bedrock Mantle">
182 | Host | Purpose |
183 | --------------------------------- | -------------------------------------------------------------------------- |
182 | Host | Purpose |
183 | - | - |
184184 | `bedrock-mantle.<region>.api.aws` | Model inference. Replaced by the host of `inferenceBedrockBaseUrl` if set. |
185185 </Tab>
186186 
187187 <Tab title="Microsoft Foundry">
188 | Host | Purpose |
189 | ---------------------------------- | -------------------------------------------------------------------------- |
188 | Host | Purpose |
189 | - | - |
190190 | `<resource>.services.ai.azure.com` | Model inference. Replaced by the host of `inferenceFoundryBaseUrl` if set. |
191 | `login.microsoftonline.com` | Entra ID auth (interactive sign-in only) |
191 | `login.microsoftonline.com` | Entra ID auth (interactive sign-in only) |
192192 </Tab>
193193 
194194 <Tab title="Gateway">
195 | Host | Purpose |
196 | --------------------------------- | --------------- |
195 | Host | Purpose |
196 | - | - |
197197 | Host of `inferenceGatewayBaseUrl` | Model inference |
198198 </Tab>
199199 
200200 <Tab title="Claude API">
201 | Host | Purpose |
202 | --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
203 | `api.anthropic.com` | Model inference; token exchange and API-key creation during browser sign-in |
201 | Host | Purpose |
202 | - | - |
203 | `api.anthropic.com` | Model inference; token exchange and API-key creation during browser sign-in |
204204 | `platform.claude.com` | Browser sign-in page. Dialed only when no static key or credential helper is configured; the in-app Egress list includes it for every Claude API deployment. |
205205 </Tab>
206206</Tabs>
from line 207
207207 
208208### Auto-updates (`disableAutoUpdates: false`)
209209 
210| Host | Purpose |
211| --------------------- | ------------------------------------------------------------------ |
212| `claude.ai` | Update feed |
213| `api.anthropic.com` | Update feed (releases.claude.com when updateViaUpdatesHost is set) |
214| `downloads.claude.ai` | Update binaries |
210| Host | Purpose |
211| - | - |
212| `claude.ai` | Update feed |
213| `api.anthropic.com` | Update feed (releases.claude.com when updateViaUpdatesHost is set) |
214| `downloads.claude.ai` | Update binaries |
215215 
216216With [`updateViaUpdatesHost`](/docs/third-party/claude-desktop/configuration#updateviaupdateshost) set to `true`, the app reads the update feed from `releases.claude.com` instead of `claude.ai` and `api.anthropic.com`, so those two hosts are no longer needed for updates. Update binaries still come from `downloads.claude.ai`.
217217 
218218### Essential telemetry (`disableEssentialTelemetry: false`)
219219 
220| Host | Purpose |
221| ---------------------------------- | ------------------------- |
222| `*.sentry.io` | Crash and error reporting |
223| `*.ingest.us.sentry.io` | Crash and error reporting |
224| `sentry.io` | Crash and error reporting |
225| `claude.ai` | Performance timing |
226| `browser-intake-datadoghq.com` | Performance timing |
227| `browser-intake-us3-datadoghq.com` | Performance timing |
228| `browser-intake-us5-datadoghq.com` | Performance timing |
229| `browser-intake-ap1-datadoghq.com` | Performance timing |
230| `browser-intake-ap2-datadoghq.com` | Performance timing |
231| `browser-intake-datadoghq.eu` | Performance timing |
232| `browser-intake-ddog-gov.com` | Performance timing |
220| Host | Purpose |
221| - | - |
222| `*.sentry.io` | Crash and error reporting |
223| `*.ingest.us.sentry.io` | Crash and error reporting |
224| `sentry.io` | Crash and error reporting |
225| `claude.ai` | Performance timing |
226| `browser-intake-datadoghq.com` | Performance timing |
227| `browser-intake-us3-datadoghq.com` | Performance timing |
228| `browser-intake-us5-datadoghq.com` | Performance timing |
229| `browser-intake-ap1-datadoghq.com` | Performance timing |
230| `browser-intake-ap2-datadoghq.com` | Performance timing |
231| `browser-intake-datadoghq.eu` | Performance timing |
232| `browser-intake-ddog-gov.com` | Performance timing |
233233 
234234The `sentry.io` apex is listed alongside the wildcards because some firewalls don't match it under `*.sentry.io`, and `*.ingest.us.sentry.io` is listed separately for firewalls that match wildcards one label deep.
235235 
236236### Non-essential telemetry (`disableNonessentialTelemetry: false`)
237237 
238| Host | Purpose |
239| --------------------- | --------------------------------------------------------------- |
240| `a-cdn.anthropic.com` | Analytics SDK |
241| `a-api.anthropic.com` | Analytics events |
242| `claude.ai` | Analytics events |
243| `api.anthropic.com` | Claude Code usage telemetry, sent from inside the agent sandbox |
238| Host | Purpose |
239| - | - |
240| `a-cdn.anthropic.com` | Analytics SDK |
241| `a-api.anthropic.com` | Analytics events |
242| `claude.ai` | Analytics events |
243| `api.anthropic.com` | Claude Code usage telemetry, sent from inside the agent sandbox |
244244 
245245### Non-essential services (`disableNonessentialServices: false`)
246246 
247| Host | Purpose |
248| --------------------------- | -------------------------------------- |
249| `www.google.com` | Connector favicons |
250| `*.gstatic.com` | Connector favicons |
251| `www.claudeusercontent.com` | Artifact preview iframe |
252| `cdnjs.cloudflare.com` | Artifact preview asset CDNs |
253| `fonts.googleapis.com` | Artifact preview asset CDNs |
254| `cdn.jsdelivr.net` | Artifact preview asset CDNs |
255| `*.claudemcpcontent.com` | MCP App widget iframe |
256| `assets.claude.ai` | Fonts loaded by MCP App widget iframes |
247| Host | Purpose |
248| - | - |
249| `www.google.com` | Connector favicons |
250| `*.gstatic.com` | Connector favicons |
251| `www.claudeusercontent.com` | Artifact preview iframe |
252| `cdnjs.cloudflare.com` | Artifact preview asset CDNs |
253| `fonts.googleapis.com` | Artifact preview asset CDNs |
254| `cdn.jsdelivr.net` | Artifact preview asset CDNs |
255| `*.claudemcpcontent.com` | MCP App widget iframe |
256| `assets.claude.ai` | Fonts loaded by MCP App widget iframes |
257257 
258258`*.claudemcpcontent.com` serves [MCP Apps](/docs/connectors/building/mcp-apps/getting-started), the interactive widgets connectors can render. Each widget loads in a sandboxed iframe on its own generated subdomain, so allowlist the wildcard.
259259 
260260### Optional features
261261 
262| Host | Required when |
263| ----------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
264| Host of `otlpEndpoint` | OpenTelemetry export is configured |
265| `github.com`, `objects.githubusercontent.com`, `pypi.org`, `files.pythonhosted.org` | Python-based desktop extensions are enabled |
266| Hosts of each entry in `managedMcpServers` (server URL, plus `oauth.authorizationServer` and `login.microsoftonline.com` if configured) | Managed MCP servers are configured |
267| Search provider host of a built-in `websearch` server (`api.search.brave.com`, `api.tavily.com`, `api.exa.ai`, or the host of your `customUrl`) | [Built-in web search](/docs/third-party/claude-desktop/web-tools#built-in-web-search) is configured |
268| Hosts in `coworkEgressAllowedHosts` | Sandbox web access is configured |
269| `api.anthropic.com` | [Code](/docs/third-party/claude-desktop/code) sessions can use Web Fetch and [`skipWebFetchPreflight`](/docs/third-party/claude-desktop/configuration#skipwebfetchpreflight) is not `true` (Claude Code's Web Fetch [domain check](/docs/third-party/claude-desktop/web-tools#web-fetch)) |
270| `claude.ai`, `api.anthropic.com`, `storage.googleapis.com` | [Import from claude.ai](/docs/third-party/claude-desktop/import) is enabled (`claudeAiImport` with `enabled` set to `true`). Used only while a user signs in to claude.ai and fetches an export in the import wizard; importing a downloaded export file needs none of them |
271| `releases.claude.com` | The [built-in browser](/docs/third-party/claude-desktop/browser) is turned on (`builtinBrowserEnabled` set to `true`), for its [site safety check](/docs/third-party/claude-desktop/browser#site-safety-check) |
272| `downloads.claude.ai` | [SSH remote sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) are enabled (`sshHostAllowlist` set). With the offline installer, needed only for connections to hosts other than Linux x64 and arm64, because that installer bundles the remote components for those hosts (see [Host requirements](/docs/third-party/claude-desktop/ssh-remote-sessions#host-requirements)) |
262| Host | Required when |
263| - | - |
264| Host of `otlpEndpoint` | OpenTelemetry export is configured |
265| `github.com`, `objects.githubusercontent.com`, `pypi.org`, `files.pythonhosted.org` | Python-based desktop extensions are enabled |
266| Hosts of each entry in `managedMcpServers` (server URL, plus `oauth.authorizationServer` and `login.microsoftonline.com` if configured) | Managed MCP servers are configured |
267| Search provider host of a built-in `websearch` server (`api.search.brave.com`, `api.tavily.com`, `api.exa.ai`, or the host of your `customUrl`) | [Built-in web search](/docs/third-party/claude-desktop/web-tools#built-in-web-search) is configured |
268| Hosts in `coworkEgressAllowedHosts` | Sandbox web access is configured |
269| `api.anthropic.com` | [Code](/docs/third-party/claude-desktop/code) sessions can use Web Fetch and [`skipWebFetchPreflight`](/docs/third-party/claude-desktop/configuration#skipwebfetchpreflight) is not `true` (Claude Code's Web Fetch [domain check](/docs/third-party/claude-desktop/web-tools#web-fetch)) |
270| `claude.ai`, `api.anthropic.com`, `storage.googleapis.com` | [Import from claude.ai](/docs/third-party/claude-desktop/import) is enabled (`claudeAiImport` with `enabled` set to `true`). Used only while a user signs in to claude.ai and fetches an export in the import wizard; importing a downloaded export file needs none of them |
271| `releases.claude.com` | The [built-in browser](/docs/third-party/claude-desktop/browser) is turned on (`builtinBrowserEnabled` set to `true`), for its [site safety check](/docs/third-party/claude-desktop/browser#site-safety-check) |
272| `downloads.claude.ai` | [SSH remote sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) are enabled (`sshHostAllowlist` set). With the offline installer, needed only for connections to hosts other than Linux x64 and arm64, because that installer bundles the remote components for those hosts (see [Host requirements](/docs/third-party/claude-desktop/ssh-remote-sessions#host-requirements)) |
273273 
274274## Disabling all Anthropic-bound connections
275275 
276276Each connection in the following table has a managed-configuration key that turns it off.
277277 
278| Connection | What it carries | Key that turns it off |
279| --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
280| Crash, error, and performance reporting | Diagnostic metadata, never prompt or response content. See [Essential telemetry](#essential-telemetry). | [`disableEssentialTelemetry`](/docs/third-party/claude-desktop/configuration#disableessentialtelemetry) set to `true` |
281| Product analytics and diagnostic-report uploads | Feature adoption, session counts, and UI interactions, plus Claude Code usage telemetry. No prompt or response content. See [Non-essential telemetry](#non-essential-telemetry). | [`disableNonessentialTelemetry`](/docs/third-party/claude-desktop/configuration#disablenonessentialtelemetry) set to `true` |
282| Connector favicons, artifact previews, and MCP App widgets | Icon fetches, and the sandboxed iframe pages that render previews and widgets. See [Non-essential services](#non-essential-services). | [`disableNonessentialServices`](/docs/third-party/claude-desktop/configuration#disablenonessentialservices) set to `true` |
283| Auto-updates | Requests to Anthropic's update feed, and downloads of new builds. See [Auto-updates](#auto-updates). | [`disableAutoUpdates`](/docs/third-party/claude-desktop/configuration#disableautoupdates) set to `true` |
284| Model catalog | The signed model catalog that labels the model picker, fetched from `downloads.claude.ai` at launch and then every 5 to 15 minutes, including on devices installed with the offline installer. A blocked catalog request affects nothing else. | [`modelCatalogEnabled`](/docs/third-party/claude-desktop/configuration#modelcatalogenabled) set to `false`, or [`modelCatalogUrl`](/docs/third-party/claude-desktop/configuration#modelcatalogurl) set to a mirror inside your network |
285| Web Fetch domain check in [Code](/docs/third-party/claude-desktop/code) sessions | The hostname of each page Claude Code fetches, sent to `api.anthropic.com` before the fetch. See [Web Fetch](/docs/third-party/claude-desktop/web-tools#web-fetch). | [`skipWebFetchPreflight`](/docs/third-party/claude-desktop/configuration#skipwebfetchpreflight) set to `true`, or `WebFetch` added to [`disabledBuiltinTools`](/docs/third-party/claude-desktop/configuration#disabledbuiltintools) |
278| Connection | What it carries | Key that turns it off |
279| - | - | - |
280| Crash, error, and performance reporting | Diagnostic metadata, never prompt or response content. See [Essential telemetry](#essential-telemetry). | [`disableEssentialTelemetry`](/docs/third-party/claude-desktop/configuration#disableessentialtelemetry) set to `true` |
281| Product analytics and diagnostic-report uploads | Feature adoption, session counts, and UI interactions, plus Claude Code usage telemetry. No prompt or response content. See [Non-essential telemetry](#non-essential-telemetry). | [`disableNonessentialTelemetry`](/docs/third-party/claude-desktop/configuration#disablenonessentialtelemetry) set to `true` |
282| Connector favicons, artifact previews, and MCP App widgets | Icon fetches, and the sandboxed iframe pages that render previews and widgets. See [Non-essential services](#non-essential-services). | [`disableNonessentialServices`](/docs/third-party/claude-desktop/configuration#disablenonessentialservices) set to `true` |
283| Auto-updates | Requests to Anthropic's update feed, and downloads of new builds. See [Auto-updates](#auto-updates). | [`disableAutoUpdates`](/docs/third-party/claude-desktop/configuration#disableautoupdates) set to `true` |
284| Model catalog | The signed model catalog that labels the model picker, fetched from `downloads.claude.ai` at launch and then every 5 to 15 minutes, including on devices installed with the offline installer. A blocked catalog request affects nothing else. | [`modelCatalogEnabled`](/docs/third-party/claude-desktop/configuration#modelcatalogenabled) set to `false`, or [`modelCatalogUrl`](/docs/third-party/claude-desktop/configuration#modelcatalogurl) set to a mirror inside your network |
285| Web Fetch domain check in [Code](/docs/third-party/claude-desktop/code) sessions | The hostname of each page Claude Code fetches, sent to `api.anthropic.com` before the fetch. See [Web Fetch](/docs/third-party/claude-desktop/web-tools#web-fetch). | [`skipWebFetchPreflight`](/docs/third-party/claude-desktop/configuration#skipwebfetchpreflight) set to `true`, or `WebFetch` added to [`disabledBuiltinTools`](/docs/third-party/claude-desktop/configuration#disabledbuiltintools) |
286286 
287287With all six connections turned off, the only remaining Anthropic-operated egress is `downloads.claude.ai`, for the VM workspace bundle and Claude CLI binary at session start. The only other required egress is your inference provider. With the [offline installer variant](/docs/third-party/claude-desktop/installation#offline-installation), `downloads.claude.ai` is not needed either, and your inference provider is the only required egress.
288288 
Feedback