Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260929T200709Z

7 pages moved out of 256 read.

Pages moved 7 significant first
Pages read 256 in this capture
Captured 20:07 UTC
Corpus hash fd6eca67c769 corpus-hash

What this read moved

1-7 of 7

cowork/changelog Changed · +46 / -0 lines

from line 2
22 
33> Release notes for Claude Desktop
44 
5<Update label="v2.16120.0" description="2026-09-29">
6 Bundled Claude Code version: 2.1.284.
7 
8 **General**
9 
10 * Added creating a Google Doc, Sheet or Slides deck from the new chat's Output picker with a connected Google Drive, and fixed the Google pane showing "Owner unknown".
11 * Fixed a failed message reappearing over newer typing, dictated text dropped when a queued message sent, the first message after a voice conversation replying to an earlier response, and a new chat from the command palette sending into an open incognito chat or being lost.
12 * Fixed editing a sent message starting from text missing parts of what you sent, attached files disappearing when you typed a reply to Claude's question card, a removed text file still being kept among the chat's files, and large documents from a connected app blocking sending.
13 * Fixed problems while a chat was open in its own window: the conversation could jump during streaming when the main window was minimized, usage and credits buttons in the main window could stop working, and the browser, artifact, and file preview panes could go blank.
14 * Fixed Quick Entry: prompts sent while the app was still loading could be lost, files sent to an existing chat lost their names (leaving text, code, and Office documents unreadable to Claude), and using it right after an app update could crash the app.
15 * Fixed the whole chat being replaced by an error screen when one of Claude's cards (such as a weather or map card) failed to draw; the card's place now says "Couldn't load this." and the rest of the conversation stays open.
16 * Fixed `/docx`, `/pdf`, `/pptx` and `/xlsx` being rejected as unknown skills and missing from the Cowork slash menu, and removed Cowork-only skills from the Code tab slash menu, where they could not run.
17 
18 **Code**
19 
20 * Changed Max effort to apply to the current session only, as in the Claude Code CLI, so new sessions no longer start at Max, and fixed changing the effort level in an open session also changing which model new sessions start on.
21 * Changed worktree cleanup: a session's worktree is kept until the session is archived, however long it sits idle, and worktrees you or the CLI create under `.claude/worktrees` are never removed by the app.
22 * Fixed archiving a session deleting uncommitted work in a worktree created before the worktree location was changed, on macOS and Linux.
23 * Fixed Code sessions in a worktree being refused with "This workspace isn't trusted" and never showing the trust dialog, and forked sessions being stopped by a workspace-trust check on their own worktree after an app restart.
24 * Fixed SSH sessions reopening idle instead of continuing the interrupted task when Claude Code on the remote host had stopped while the app was closed, and SSH connections on Linux not using the ssh-agent from your shell startup files.
25 * Fixed the main window being replaced by an error screen when a popped-out session's chat hit an error; the chat now shows Try again instead.
26 * Changed worktree sessions on Claude Code 2.1.275 or later to read project settings, hooks and MCP servers from the project folder you opened instead of the worktree's checked-out branch, with that folder's `.claude` config and `.mcp.json` read-only where the session runs outside it; now also on Windows SSH hosts.
27 * Fixed a conversation staying on an out-of-date Claude Code after an app update; when the API refuses it, sending again now resumes the same conversation on the current version.
28 * Fixed SSH sessions being restarted, and their running turns killed, when the remote server was slow to answer the first contact after a reconnect.
29 * Fixed worktree sessions on Windows sometimes being refused in repositories with a folder named `claude` in their path.
30 
31 **Cowork**
32 
33 * Changed organization tool policies in tasks on your computer: a connector tool set to "Restrict to Ask" now asks for your approval, including in "Skip all approvals" mode (newly started tasks only), and an ask policy on a file tool shows an approval prompt instead of refusing the call.
34 * Fixed "Failed to start Claude's workspace" on Windows when Claude is installed on a drive other than the system drive.
35 * Fixed a message sent from another window or device being stopped or lost when you restarted from or edited an earlier message at the same time.
36 * Fixed Office file previews that kept failing until the app was restarted when Claude's workspace got stuck; the preview now says what failed (workspace not responding, no permission to the folder, file gone) and, on third-party deployments, can restart the workspace in place.
37 * Fixed skills that Claude proposes or writes in a conversation being saveable from the chat cards with no instructions, which saved an empty skill or emptied the one it updated; the cards now say why.
38 * Fixed the Cowork data export keeping hidden characters in file names.
39 * Added inline playback for video outputs in the file pane, with thumbnails in the chat.
40 
41 **3P**
42 
43 * Added `deniedPluginMcpServers`: URL patterns for remote servers that plugins may not connect in Cowork, Chat and Code sessions (in Code sessions, matching servers from Claude Code's configuration files too). A match stays blocked even when `allowedPluginMcpServers` admits it; unset or empty blocks none.
44 * Changed `userPluginMarketplacesEnabled`: when set to `false`, plugin marketplaces the organization did not provision are hidden, installs and updates from them are refused, and Code and Cowork sessions are told not to load their plugins; previously only adding marketplaces was blocked.
45 * Removed `a-cdn.anthropic.com` and `a-api.anthropic.com` from the network requirements list under nonessential telemetry; the app has not contacted them since 2.110.0, so firewall allowlists may drop them, and leaving them in place is harmless.
46 * Updated the Code tab's composer to the redesigned card, with the + menu first in the row under the box, ahead of permission mode and model.
47 * Fixed the diagnostic report's network reachability check and the Setup window's connectivity test reporting a server on a non-default port as unreachable, and the firewall allowlist omitting that port.
48 * Fixed two model picker descriptions showing in English when the app is set to another language.
49</Update>
50 
551<Update label="v2.9939.4" description="2026-09-27">
652 Bundled Claude Code version: 2.1.284.
753 

cowork/guide/plugins Changed · +23 / -18 lines

## Next steps ## Related

from line 2
22 
33> Add packaged skills, connectors, and agents to Cowork from the plugin marketplace or a file.
44 
5A plugin is a package that extends what Claude can do in Cowork. Installing one can add skills, MCP connectors, subagents, slash commands, or hooks in a single step. Plugins come from the marketplace, from your organization, or from a file you upload.
5A plugin is a package that extends what Claude can do in Cowork. Installing one can add skills, MCP connectors, subagents, commands, or hooks in a single step. Plugins come from the marketplace, from your organization, or from a file you upload.
66 
7Plugins are available in Cowork and Code. They aren't used in Chat.
7A plugin you install is saved to your account, so its skills and connectors are also available in chat and in Claude Code. [Plugins](/docs/plugins/overview) covers what each surface loads; this page covers the Cowork side.
88 
9To get started, [install a plugin](#install-a-plugin) from **Customize**, or [add a Git repository as a marketplace](#use-a-git-repository-as-a-marketplace) to share plugins without publishing them.
10 
911## What a plugin can contain
1012 
11A plugin's manifest declares any combination of the following.
13A plugin can contain any combination of the following components.
1214 
1315| Component | What it adds |
1416| - | - |
from line 23
2123 
2224## Install a plugin
2325 
24Open **Customize** in the sidebar, then **Plugins**.
26You browse, install, and upload plugins from the **Plugins** page. Open **Customize** in the sidebar, then select **Plugins**.
2527 
2628<Steps>
2729 <Step title="Browse the marketplace">
28 Select **Browse plugins** to see available plugins. The default marketplace
29 is Anthropic's official catalog; you can add other marketplaces by URL.
30 Select **Discover** to see available plugins. The default marketplace is
31 Anthropic's official catalog; you can add other marketplaces by URL.
3032 </Step>
3133 
3234 <Step title="Install">
33 Select a plugin and click **Install**. If the plugin includes a connector
34 that needs authentication, you're prompted to sign in.
35 Select a plugin and click **Install**. Installing doesn't add or sign you in
36 to any connector. If the plugin includes connectors, open its **Connectors**
37 tab afterward to add or connect each one.
3538 </Step>
3639 
3740 <Step title="Review components">
3841 Open the installed plugin to see its skills, connectors, agents, and hooks.
39 Enable or disable individual components as needed.
42 Select **Disable plugin** to turn the whole plugin off, and connect or
43 disconnect each connector on its own from the **Connectors** tab.
4044 </Step>
4145</Steps>
4246 
from line 48
4448 
4549## Use a Git repository as a marketplace
4650 
47A Git repository that contains plugin packages can serve as a marketplace. This is the typical way teams distribute their own plugins without publishing to the public catalog. Repositories on GitHub (including GitHub Enterprise) are supported; public repositories on GitLab and Bitbucket also work.
51A Git repository that contains plugin packages can serve as a marketplace, which lets you share plugins without publishing to the public catalog. For a marketplace you add yourself, repositories on GitHub, including GitHub Enterprise, are supported, and public repositories on GitLab and Bitbucket also work. To distribute plugins to everyone in a Team or Enterprise organization, an Owner syncs the repository from organization settings instead, as [Manage plugins for your organization](/docs/plugins/admin#add-your-own-plugins) describes.
4852 
4953<Steps>
5054 <Step title="Add the repository">
from line 63
5963 </Step>
6064</Steps>
6165 
62Click **Update** on a marketplace to pull the latest plugins from its repository.
66Select **Check for updates** on a marketplace to pull the latest plugins from its repository, or turn on **Sync automatically**.
6367 
64For administrator-managed marketplaces, see [MCP, plugins, skills, and hooks](/docs/cowork/3p/extensions) in the deployment guide.
68For marketplaces your organization manages, see [Manage plugins for your organization](/docs/plugins/admin), or [MCP, plugins, skills, and hooks](/docs/cowork/3p/extensions) if your organization deploys Claude Desktop with its own model provider.
6569 
6670## Limits
6771 
from line 85
8185 
8286On Team and Enterprise plans, administrators can require certain plugins for everyone in the organization. Required plugins install automatically and show **This plugin is required by your organization**; you can't remove them.
8387 
84For how administrators provision plugins, see [MCP, plugins, skills, and hooks](/docs/cowork/3p/extensions) in the deployment guide.
88For how administrators provision plugins, see [Manage plugins for your organization](/docs/plugins/admin).
8589 
8690## Update and remove plugins
8791 
8892Cowork checks for plugin updates from the marketplace they came from. If you've edited a plugin's files locally, Cowork detects the change and warns you before an update would overwrite it.
8993 
90To remove a plugin you installed, open it under **Customize → Plugins** and click **Uninstall**. Organization-managed plugins can only be removed by an administrator.
94To remove a plugin you installed, open it under **Customize > Plugins** and select **Remove**. You can't remove a plugin marked **This plugin is required by your organization**.
9195 
92## Related
96## Next steps
9397 
94* [Plugins overview](/docs/plugins/overview) for how plugins work across Claude products
95* [Submit a plugin](/docs/plugins/submit) to publish your own to the marketplace
96* [MCP, plugins, skills, and hooks](/docs/cowork/3p/extensions) for administrator provisioning
98* [Plugins](/docs/plugins/overview): how plugins work across Claude products
99* [Manage plugins for your organization](/docs/plugins/admin): administrator provisioning on Team and Enterprise plans
100* [Submit a plugin](/docs/plugins/submit): publish your own to the marketplace
101* [MCP, plugins, skills, and hooks](/docs/third-party/claude-desktop/extensions): for organizations that deploy Claude Desktop with their own model provider
97102 

third-party/claude-desktop/configuration Changed · +28 / -15 lines

from line 131
131131 </Accordion>
132132 
133133 <Accordion title="egressProxyUrl details">
134 Pins the app (sign-in, the connection test, model discovery, MCP servers, plugins), the Claude Code engine behind Chat, Cowork, and Code, and on macOS and Windows the Cowork workspace VM (the agent's shell, package-install, `git`, and plugin commands, and the whole engine under `requireCoworkFullVmSandbox`) to one HTTP proxy. Use it when your gateway or the internet is reachable only through a corporate proxy and you cannot rely on the system proxy. It is a reachability setting, not an egress control.
134 Pins the app (sign-in, the connection test, model discovery, MCP servers, plugins), the Claude Code engine behind Chat, Cowork, and Code, and on macOS and Windows the Cowork workspace VM (the agent's shell, package-install, `git`, and plugin commands) to one HTTP proxy. Use it when your gateway or the internet is reachable only through a corporate proxy and you cannot rely on the system proxy. It is a reachability setting, not an egress control.
135135 
136136 The value is an `http://` or `https://` URL, usually with a port. SOCKS proxies and embedded credentials (`user:pass@`) are rejected. Give a local forwarding proxy on the device as `http://127.0.0.1:port`; an `https://` loopback address cannot be verified from inside the Cowork workspace VM. Requests to `localhost`, `127.0.0.1`, `[::1]`, and `*.local` names bypass the proxy so local MCP servers keep working; everything else goes through it, and if the proxy is unreachable requests fail rather than connect directly. The engine receives it as `HTTPS_PROXY` and `HTTP_PROXY` with a matching `NO_PROXY`; if Claude Code managed settings on the device set those variables, they win for the engine on the host. Traffic that never uses this proxy: the Cowork workspace VM on Linux, credential and header helper scripts, the update download, the Windows sign-in broker, and pages opened in the system browser.
137137 
from line 145
145145 </Accordion>
146146 
147147 <Accordion title="coworkVmIpv6Enabled details">
148 When set to `true`, the Cowork workspace VM on macOS and Windows gets a static IPv6 address (a unique local `fd…` address) and an IPv6 default route on its virtual network next to its IPv4 address, and the VM's gateway forwards that traffic over the device's own IPv6 connectivity, as it already does for IPv4. Use it when the tools the agent runs in the VM (shell commands, package installs, `git`, plugin commands, and the whole engine under `requireCoworkFullVmSandbox`) must reach IPv6-only destinations. The VM's resolver then also returns IPv6 (AAAA) answers. A connection the VM makes over IPv6 succeeds only where the device's own IPv6 does; on a device without working IPv6, destinations that have both keep working over IPv4 and IPv6-only destinations stay unreachable. Because the VM's address is unique-local, most tools in it keep preferring IPv4 for destinations that have both, so IPv6 mostly carries traffic to IPv6-only destinations.
148 When set to `true`, the Cowork workspace VM on macOS and Windows gets a static IPv6 address (a unique local `fd…` address) and an IPv6 default route on its virtual network next to its IPv4 address, and the VM's gateway forwards that traffic over the device's own IPv6 connectivity, as it already does for IPv4. Use it when the tools the agent runs in the VM (shell commands, package installs, `git`, and plugin commands) must reach IPv6-only destinations. The VM's resolver then also returns IPv6 (AAAA) answers. A connection the VM makes over IPv6 succeeds only where the device's own IPv6 does; on a device without working IPv6, destinations that have both keep working over IPv4 and IPv6-only destinations stay unreachable. Because the VM's address is unique-local, most tools in it keep preferring IPv4 for destinations that have both, so IPv6 mostly carries traffic to IPv6-only destinations.
149149 
150150 This is a reachability setting, not an egress control: `coworkEgressAllowedHosts` keeps deciding which hostnames the agent's tools may reach, by name, over either protocol, and IPv6 literals are still not accepted there. Hosts your policies allow must also be reachable, and filtered the way you intend, over IPv6 on your network.
151151 
from line 227
227227 <Accordion title="inferenceStreamIdleTimeoutSec details">
228228 Raises how long Cowork, Chat and Code sessions wait for the next model event on an open streaming response (Claude Code's `CLAUDE_STREAM_IDLE_TIMEOUT_MS`). It only helps when the gateway writes SSE keep-alive `ping` events (or `:` comment lines) into the response while the upstream model is silent — for example a LiteLLM proxy with keep-alive pings enabled in front of Amazon Bedrock. With pings arriving, Claude Code accepts at least about five minutes of keep-alives and then waits this many seconds more for real model output before abandoning the request. Gateway provider only; the other providers keep Claude Code's defaults.
229229 
230 A response on which nothing at all arrives — no pings — still fails after about 5 minutes regardless of this key, because at the device a silent connection cannot be told apart from a dead one. If long generations fail behind a gateway that does not send pings, configure the gateway to send them rather than raising this value. While this key is set, the app's value takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` in Claude Code's own managed settings for sessions the app starts; when it is unset, that setting still applies. Values outside 300–1800 are rejected at parse time (the error is listed in the diagnostics report) and the default applies.
230 A response on which nothing at all arrives — no pings — still fails after about 5 minutes regardless of this key, because at the device a silent connection cannot be told apart from a dead one. If long generations fail behind a gateway that does not send pings, configure the gateway to send them rather than raising this value. A common case is automatic compaction, in which a session sends its whole conversation in one streaming request and waits for a long summary; when that request fails, the error reads `Prompt is too long · automatic compaction failed:` followed by the cause. While this key is set, the app's value takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` in Claude Code's own managed settings for sessions the app starts; when it is unset, that setting still applies. Values outside 300–1800 are rejected at parse time (the error is listed in the diagnostics report) and the default applies.
231231 </Accordion>
232232 
233233 <Accordion title="inferenceGatewayOidcAuthFlow details">
from line 550
550550 
551551| Setting | Type | Availability | Default | Description |
552552| - | - | - | - | - |
553| <span id="userpluginmarketplacesenabled" />Allow user-added plugin marketplaces<br />`userPluginMarketplacesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add plugin marketplaces themselves. When off, the add-marketplace surfaces are hidden and in-app adds are refused. |
553| <span id="userpluginmarketplacesenabled" />Allow user-added plugin marketplaces<br />`userPluginMarketplacesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add plugin marketplaces. When off, marketplaces your organization did not provision are hidden and the app’s sessions do not load their plugins. |
554554| <span id="userpluginuploadsenabled" />Allow user-added plugins<br />`userPluginUploadsEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Allow users to add their own plugins. When off, every in-app option for adding one is hidden and uploads that still reach the app are refused. |
555| <span id="disabledbuiltintools" />Disabled built-in tools<br />`disabledBuiltinTools` | `string[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Built-in tools, or argument-scoped permission rules such as Read(\*\*/.env), denied in Cowork and Code. |
555| <span id="disabledbuiltintools" />Disabled built-in tools<br />`disabledBuiltinTools` | `string[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Built-in tools, or argument-scoped permission rules such as Read(//\*\*/.env), denied in Cowork and Code. |
556556| <span id="disablebundledskills" />Disable bundled skills and workflows<br />`disableBundledSkills` | `boolean` | MDM + Bootstrap<br />Added in 1.15962.0 | — | Disables Claude Code’s bundled skills and workflows (deep-research and similar). Use where WebFetch/WebSearch aren’t available. |
557557| <span id="skillcreationenabled" />Allow user-created skills<br />`skillCreationEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.25927.0 | — | Allow users to create and upload their own skills. When off, the creation and upload surfaces are hidden and the agent’s skill-creation tools are disabled. |
558558| <span id="scheduledtasksenabled" />Allow scheduled tasks<br />`scheduledTasksEnabled` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | Allow scheduled tasks in Cowork and Code. When off, the Scheduled page is hidden, existing tasks stop running, and Claude cannot create new ones. |
from line 570
570570 
571571<AccordionGroup>
572572 <Accordion title="userPluginMarketplacesEnabled details">
573 When on (default), users can add plugin marketplaces from the plugin browser. Set to `false` to block user marketplace adds: the add-marketplace surfaces are hidden, and the app refuses adds that still reach it (deep links, stale UI).
573 When on (default), users can add plugin marketplaces from the plugin browser. Set to `false` to restrict plugins to your organization's marketplaces: the add-marketplace surfaces are hidden, and the app refuses adds that still reach it (deep links, stale UI). Any other marketplace present on the device is then hidden in every tab, whether a user added it in the app earlier or something outside the app registered it (for example Claude Code in a terminal, under `~/.claude`): its plugins are not listed, and installs and updates from it are refused. The sessions the app starts load plugins only from your organization's marketplaces, the organization plugins directory, the app's own uploads and the user's own skills folder, enforced through Claude Code's marketplace allowlist (`strictKnownMarketplaces`, passed as the app's managed settings). Nothing is deleted: removing the key or setting it back to `true` restores them. Marketplaces provisioned by your organization (`allowedPluginMarketplaces`) and the organization plugins directory are unaffected, and plugins users uploaded are governed by `userPluginUploadsEnabled`, not this key.
574574 
575 This is a feature-availability control enforced in the app, not a data boundary: marketplaces already registered on the user's machine (or registered outside the app, for example by the Claude Code CLI or by editing Claude Code's plugin files) are not removed or blocked by this key. Marketplaces provisioned by your organization (`allowedPluginMarketplaces`) are unaffected.
575 This is a feature-availability control, not a data boundary. Claude Code in a terminal reads the same `~/.claude` folder and is governed only by its own managed settings, not by this key. Claude Code may ignore this allowlist on a device that deploys its own Claude Code managed settings; restrict marketplaces in those settings as well.
576576 
577577 This key applies only while the app runs in third-party mode. If users could otherwise sign in to Claude.ai on the device, also set `disableDeploymentModeChooser` so the app stays in third-party mode.
578578 </Accordion>
from line 586
586586 </Accordion>
587587 
588588 <Accordion title="disabledBuiltinTools details">
589 Each entry is a Claude Code tool name (`Bash`, `Read`, `Write`, `Edit`, `Glob`, `Grep`, `NotebookEdit`, `WebFetch`, `WebSearch`, `Task`, `TodoWrite`, `TaskCreate`, `TaskUpdate`, `TaskGet`, `TaskList`, `TaskStop`, `Skill`, `REPL`, `JavaScript`, `AskUserQuestion`, `ToolSearch`, `SendUserMessage`) or an argument-scoped [permission rule](https://code.claude.com/docs/en/permissions#permission-rule-syntax) such as `Bash(curl *)` or `Edit(**/*.env)`. A bare name covers every call (a bare `Bash` entry also covers the `PowerShell` tool); a scoped rule covers matching calls in every permission mode, including Auto and bypass. Scopes are matched for `Bash(…)` (a command pattern) and for file paths written as `Read(…)` (covers `Read`, `Grep`, `Glob`) or `Edit(…)` (covers `Edit`, `Write`, `NotebookEdit`); other tools take `Tool(<field>:<pattern>)`. `WebSearch` and `WebFetch` are bare-name only: per-host web access is `coworkEgressAllowedHosts`.
589 Each entry is a Claude Code tool name (`Bash`, `Read`, `Write`, `Edit`, `Glob`, `Grep`, `NotebookEdit`, `WebFetch`, `WebSearch`, `Task`, `TodoWrite`, `TaskCreate`, `TaskUpdate`, `TaskGet`, `TaskList`, `TaskStop`, `Skill`, `REPL`, `JavaScript`, `AskUserQuestion`, `ToolSearch`, `SendUserMessage`) or an argument-scoped [permission rule](https://code.claude.com/docs/en/permissions#permission-rule-syntax) such as `Bash(curl *)` or `Edit(//**/*.env)`. A bare name covers every call (a bare `Bash` entry also covers the `PowerShell` tool); a scoped rule covers matching calls in every permission mode, including Auto and bypass. Scopes are matched for `Bash(…)` (a command pattern) and for file paths written as `Read(…)` (covers `Read`, `Grep`, `Glob`) or `Edit(…)` (covers `Edit`, `Write`, `NotebookEdit`); other tools take `Tool(<field>:<pattern>)`. `WebSearch` and `WebFetch` are bare-name only: per-host web access is `coworkEgressAllowedHosts`.
590590 
591 Scoped `Bash(…)` rules apply in Code sessions and in VM-sandboxed Cowork sessions (`requireCoworkFullVmSandbox`); Cowork's own sandboxed shell honors bare names only. Anchor file patterns with `**/` (`Read(**/secrets/**)`), because in the VM sandbox a host absolute path does not match. Scoped rules need fleet-wide build support (`disableAutoUpdates` pins builds): an older build passes a scoped entry to Claude Code unchecked. An entry whose pattern contains `)` followed by a space or comma is enforced only through Claude Code's managed-settings channel, so another Claude Code [managed-settings source](https://claude.com/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings) replaces it unless that source sets `parentSettingsBehavior` to `"merge"`; every other entry is enforced either way.
591 Scoped `Bash(…)` rules apply in Code sessions only; Cowork's shell follows only a bare `Bash` entry. Start absolute file paths with `//`, not `/`: a relative pattern such as `Read(**/.env)` covers only a Code session's project folder and none of Cowork's connected folders. Scoped rules need fleet-wide build support (`disableAutoUpdates` pins builds): an older build passes a scoped entry to Claude Code unchecked. An entry whose pattern contains `)` followed by a space or comma is enforced only through Claude Code's managed-settings channel, so another Claude Code [managed-settings source](https://claude.com/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings) replaces it unless that source sets `parentSettingsBehavior` to `"merge"`; every other entry is enforced either way.
592592 
593593 An unusable entry (a lowercase tool name, an unbalanced parenthesis, a scoped `WebSearch(…)` or `WebFetch(…)`) is kept, because the deny list is served exactly as written, and raises a configuration warning.
594594 </Accordion>
from line 608
608608 </Accordion>
609609 
610610 <Accordion title="keepAwakeEnabled details">
611 When on (default), users can turn on **Keep computer awake** (Settings → Desktop app → General, also shown as **Keep awake** on the Scheduled page in Cowork and the Routines page in Code) so the computer does not idle-sleep while Claude is open and scheduled tasks keep running on an idle machine. The Code tab can also keep the computer awake while a session is working (**Keep computer awake while Claude works** in Settings → Claude Code, and a session's **Keep computer awake** menu item).
611 When on (default), users can turn on **Keep computer awake** (Settings → This computer → System, also shown as **Keep awake** on the Scheduled page in Cowork and the Routines page in Code) so the computer does not idle-sleep while Claude is open and scheduled tasks keep running on an idle machine. The Code tab can also keep the computer awake while a session is working (**Keep computer awake while Claude works** in Settings → Claude Code, and a session's **Keep computer awake** menu item).
612612 
613613 Set to `false` to make sure Claude never prevents the computer from sleeping: those switches are hidden and no part of the app keeps the computer awake. Users' saved choices are kept but ignored, and apply again once the key is removed or set to `true`. Scheduled tasks are unaffected and still run only while the computer is awake and the app is open.
614614 
from line 618
618618 <Accordion title="builtinToolPolicy details">
619619 Keys use the same tool names and argument-scoped rule syntax as **Disabled built-in tools** (`disabledBuiltinTools`), and scopes apply in the same sessions. A bare `Bash` key also governs Claude Code's `PowerShell` tool (its shell on Windows PCs without Git for Windows); argument-scoped `Bash(…)` keys do not. Scoped **ask** rules reach sessions only through Claude Code's managed-settings channel, so another Claude Code managed-settings source replaces them unless it sets `parentSettingsBehavior` to `"merge"` (bare names hold either way). They need the same fleet-wide build support, and an older build drops a scoped **ask** entry as a configuration error (which also blocks WSL sessions on Windows until that client updates), so the tool runs unprompted.
620620 
621 An **ask** entry, bare or scoped, also turns off the app's remembered “always allow” choices for that tool, so each prompted call is confirmed individually. In Code side chats, and in Cowork sessions that run tools on the host, **ask** on a file tool (`Read`, `Write`, `Edit`, `Glob`, `Grep`) blocks matching calls instead of prompting; Code sessions and VM-sandboxed Cowork sessions show the prompt. An unusable entry is dropped and recorded as a configuration error; a value other than `allow` or `ask` is treated as `ask` and reported. To remove a tool or deny a rule outright, use **Disabled built-in tools** instead.
621 An **ask** entry, bare or scoped, also turns off the app's remembered “always allow” choices for that tool, so each prompted call is confirmed individually. **ask** on a file tool (`Read`, `Write`, `Edit`, `Glob`, `Grep`) prompts in Cowork, Chat and Code sessions. Calls that Cowork and Chat always refuse are still refused without a prompt: paths outside the session's connected folders (in Chat, outside its scratch directory) and protected or sensitive files inside them. A Cowork task running unattended (a scheduled run) refuses a call that needs approval rather than waiting for someone to approve it. Code side chats cannot prompt, so they block matching calls. An unusable entry is dropped and recorded as a configuration error; a value other than `allow` or `ask` is treated as `ask` and reported. To remove a tool or deny a rule outright, use **Disabled built-in tools** instead.
622622 </Accordion>
623623 
624624 <Accordion title="autoModeEnabled details">
from line 699
699699 | Field | Type | Default | Description |
700700 | - | - | - | - |
701701 | `enabled` | `boolean` | `false` | Lets users import a Claude.ai data export and earlier Claude sessions on this computer from Settings → Import. Doesn’t affect a provisioned sign-in import. |
702 | `automatic3pImport` · Beta | `boolean` | `false` | Copy this computer’s earlier third-party sessions into the app once, in the background. Independent of `enabled`. |
702 | `automatic3pImport` | `boolean` | — | Copy this computer’s earlier third-party sessions into the app once, in the background. Independent of `enabled`. |
703703 | `exportEnabled` | `boolean` | `false` | Lets users export this computer’s chats, Cowork tasks, and Code sessions as a zip another install can import. No effect unless `enabled` is true. |
704704 | `bannerBehavior` | `enum` | — | Prompt to import on a new chat or task. Off if unset. `show`: always; needs `enabled` or a sign-in import. `detect`: if `enabled` finds earlier Claude sessions. One of: `off`, `detect`, `show`. |
705705 </Accordion>
from line 739
739739| <span id="mcpscheduledtaskapprovallifetimedays" />Scheduled-task tool approval lifetime<br />`mcpScheduledTaskApprovalLifetimeDays` | `integer` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How many days a scheduled task may reuse a lasting MCP-tool approval before it asks again. 0 removes the lasting option. Range: 0–3650. |
740740| <span id="islocaldevmcpenabled" />Allow user-added MCP servers<br />`isLocalDevMcpEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.2581.0 | `true` | Local stdio servers added via the Developer settings. Remote servers come from the managed list above or organization plugins. Defaults to `true`. |
741741| <span id="allowedpluginmcpservers" />Allowed plugin MCP servers<br />`allowedPluginMcpServers` | `object[]` | MDM + Bootstrap<br />Added in 2.2553.0 | — | Servers plugins may connect in sessions, beyond the managed list above and organization plugins. An empty list allows none; unset keeps today’s rules. |
742| <span id="deniedpluginmcpservers" />Blocked plugin MCP servers<br />`deniedPluginMcpServers` | `object[]` | MDM + Bootstrap<br />Added in 2.16120.0 | — | Remote servers plugins may not connect, even if the allowed list admits them; in Code sessions, configuration-file servers too. Unset or empty blocks none. |
742743| <span id="mcptooltimeoutsec" />MCP tool call timeout<br />`mcpToolTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.37937.0 | — | Per-call timeout for MCP tool calls, in seconds. Default 180 (3 minutes). Range: 60–3600. |
743744 
744745<AccordionGroup>
from line 827
826827 | `serverUrl` | `string` | — | URL pattern a plugin’s remote server must match, with \* wildcards. |
827828 </Accordion>
828829 
830 <Accordion title="deniedPluginMcpServers details">
831 Unset (default) or an empty list: nothing is blocked.
832 
833 When set, Cowork, Chat and Code sessions do not connect a plugin's remote server whose URL matches an entry. The key works with or without `allowedPluginMcpServers`; a server that matches both lists stays blocked. In a Code session that reads Claude Code configuration-file servers (`~/.claude.json`, a project's `.mcp.json`, `claude mcp add`), a matching remote server from those files is refused as well. The managed list above, the servers the desktop serves from the administrator's org-plugins directory, user-added local servers and extensions are not affected: remove those at their own keys. Each entry is a URL pattern in Claude Code's form, `{"serverUrl": "https://*.example.com/*"}` (`*` wildcards; a host `*` spans `a.b`). An entry matches an address, not a server: the same server under another host name or an IP address, or behind a plugin's local (stdio) server, which has no URL, is not matched. `https://*.example.com/*` does not match `http://`, `wss://` or the bare `example.com`; a pattern such as `example.com/*`, which names no scheme, matches nothing, and a lone `*` matches every URL. To keep a plugin's servers out whatever address they use, set `allowedPluginMcpServers`, which admits only the servers it lists. The desktop reads no other shape, the `serverName` and `serverCommand` forms included: a value that is not a list, or that holds any entry the desktop cannot read, is reported and blocks every plugin's remote server (and those configuration-file remote servers), because skipping an entry of a block list would let its server connect. The servers named above as not affected still connect.
834 
835 Coexistence with another Claude Code managed-settings source on the device: see [managed settings](https://claude.com/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings).
836 
837 | Field | Type | Default | Description |
838 | - | - | - | - |
839 | `serverUrl` | `string` | — | URL pattern of the remote servers to block, with \* wildcards. |
840 </Accordion>
841 
829842 <Accordion title="mcpToolTimeoutSec details">
830843 Sets the per-call timeout the agent applies to every MCP tool call; a call that runs longer fails with a timeout error the model can see. Cowork and chat sessions default to 180 seconds. Code sessions have no desktop-imposed MCP tool timeout today, so setting this key introduces one there as well. The desktop's own request deadlines toward MCP servers — the managed servers above and, where `isLocalDevMcpEnabled` permits them, user-added local servers — follow this value so they never cut a call short first; while the key is unset, calls to user-added local servers are additionally limited to 60 seconds by the desktop. Values outside 60–3600 are rejected at parse time (the error is listed in the diagnostics report) and the defaults apply.
831844 
from line 957
944957 </Accordion>
945958 
946959 <Accordion title="otlpHeadersHelper details">
947 Absolute path to an executable that prints a single JSON object of HTTP headers on stdout, e.g. `{"Authorization": "Bearer …"}`. The desktop runs it (no arguments; output cached for a few minutes, and a failure is not retried for 30 seconds) whenever it needs collector headers and merges the result over **OpenTelemetry exporter headers** and the **Collector authentication** header (the helper wins on conflict). Cowork tasks get the current output when they start; Code sessions and host-run Cowork sessions are also given the script as Claude Code’s own `otelHeadersHelper`, so an open session re-runs it as tokens rotate (on Windows this applies to `.exe`, `.cmd` and `.bat` helpers; a `.ps1` helper applies at session start only); the desktop’s own event exporter re-runs it per flush. Session start waits at most two seconds for a slow helper and otherwise proceeds without its headers until it finishes. Use this when the collector needs a credential the inference sign-in cannot provide, when the collector token rotates, or when the config comes from a hosted admin console, which cannot store header values. If the helper fails, telemetry is sent without its headers — check the app log.
960 Absolute path to an executable that prints a single JSON object of HTTP headers on stdout, e.g. `{"Authorization": "Bearer …"}`. The desktop runs it (no arguments; output cached for a few minutes, and a failure is not retried for 30 seconds) whenever it needs collector headers and merges the result over **OpenTelemetry exporter headers** and the **Collector authentication** header (the helper wins on conflict). Cowork tasks get the current output when they start; Code and Cowork sessions are also given the script as Claude Code’s own `otelHeadersHelper`, so an open session re-runs it as tokens rotate (on Windows this applies to `.exe`, `.cmd` and `.bat` helpers; a `.ps1` helper applies at session start only); the desktop’s own event exporter re-runs it per flush. Session start waits at most two seconds for a slow helper and otherwise proceeds without its headers until it finishes. Use this when the collector needs a credential the inference sign-in cannot provide, when the collector token rotates, or when the config comes from a hosted admin console, which cannot store header values. If the helper fails, telemetry is sent without its headers — check the app log.
948961 </Accordion>
949962 
950963 <Accordion title="otlpResourceAttributes details">

third-party/claude-desktop/configuration-changelog Changed · +26 / -0 lines

from line 4
44 
55Configuration keys by Claude Desktop release. Each section lists keys added in that release, with the MDM key name (for plist/registry deployment) and the equivalent JSON shape (for local-file or bootstrap remote configuration).
66 
7<Update label="v2.16120.0" description="2026-09-29">
8 <div className="cfg-keys">
9 | MDM key | Type | Description |
10 | - | - | - |
11 | [`deniedPluginMcpServers`](/docs/third-party/claude-desktop/configuration#deniedpluginmcpservers) | `object[]` | Blocked plugin MCP servers |
12 </div>
13 
14 **JSON (e.g. for non-MDM users or Bootstrap):**
15 
16 ```json theme={null}
17 {
18 "mcp": {
19 "deniedPluginServers": [
20 {
21 "serverUrl": "<string>"
22 }
23 ]
24 }
25 }
26 ```
27 
28 **Changed:**
29 
30 * `userPluginMarketplacesEnabled`: when set to `false`, plugin marketplaces your organization did not provision are now hidden in every tab, installs and updates from them are refused, and the sessions the app starts load plugins only from your organization's marketplaces, the organization plugins directory, the app's own uploads and the user's own skills folder; nothing is deleted, and removing the key or setting it to `true` restores them. Earlier releases only blocked adding marketplaces, so on devices where the key is already `false`, plugins from marketplaces users added before stop loading once the app updates.
31</Update>
32 
733<Update label="v2.9939.4" description="2026-09-27">
834 No configuration changes in this release.
935</Update>

third-party/claude-desktop/extensions Changed · +8 / -4 lines

from line 410
410410| `isDesktopExtensionEnabled` | `false` | Desktop extensions (`.mcpb`) bundled in plugins are not loaded. Set to `true` to allow them. |
411411| `isDesktopExtensionSignatureRequired` | `false` | (When `true`) Unsigned `.mcpb` extensions are rejected. |
412412| `skillCreationEnabled` | `true` | Users cannot create or upload skills in the app. Claude does not offer to create or update skills in conversations. |
413| `userPluginMarketplacesEnabled` | `true` | Users cannot add plugin marketplaces of their own; the add-marketplace options are hidden. Marketplaces you provision with `allowedPluginMarketplaces` are unaffected. Requires Claude Desktop 1.37937.0 or later. |
414| `userPluginUploadsEnabled` | `true` | Users cannot upload plugin files or create plugins with Claude; every in-app option for adding a plugin of their own is hidden. Plugins from your marketplaces and the organization plugins directory are unaffected. Requires Claude Desktop 1.37937.0 or later. |
413| `userPluginMarketplacesEnabled` | `true` | Users cannot add plugin marketplaces of their own, and the add-marketplace options are hidden. Marketplaces your organization did not [provision](#plugin-marketplaces-admin) are hidden too, and the app neither installs nor loads their plugins. The organization plugins directory, plugins users uploaded, and marketplaces you provision with `allowedPluginMarketplaces` are unaffected. |
414| `userPluginUploadsEnabled` | `true` | Users cannot upload plugin files or create plugins with Claude; every in-app option for adding a plugin of their own is hidden. Plugins from your marketplaces and the organization plugins directory are unaffected. |
415415 
416Setting `isLocalDevMcpEnabled` to `false` and leaving `isDesktopExtensionEnabled` at `false` restricts MCP servers and connectors to those delivered through `managedMcpServers` and `org-plugins/`, plus any that installed plugins bundle, whether from your marketplaces or added by users. To limit plugin-bundled servers to ones you name, or to none, set [`allowedPluginMcpServers`](/docs/third-party/claude-desktop/configuration#allowedpluginmcpservers) to a list of URL patterns. An empty list admits no plugin-bundled server. Setting [`skillCreationEnabled`](/docs/third-party/claude-desktop/configuration#skillcreationenabled) to `false` turns off skill creation and upload in the app. Skills already on the device keep working, as do skills from [organization plugins](#organization-plugins-admin). Users can still install plugins from the marketplaces you provision regardless of these settings. Setting `userPluginMarketplacesEnabled` and `userPluginUploadsEnabled` to `false` removes only the options for adding marketplaces and plugins of their own, and anything a user added earlier stays in place. See the [Locked down profile](/docs/third-party/claude-desktop/configuration#recommended-security-profiles) for a complete example.
416Setting `isLocalDevMcpEnabled` to `false` and leaving `isDesktopExtensionEnabled` at `false` restricts MCP servers and connectors to those delivered through `managedMcpServers` and `org-plugins/`, plus any that installed plugins bundle, whether from your marketplaces or added by users. To limit plugin-bundled servers to ones you name, or to none, set [`allowedPluginMcpServers`](/docs/third-party/claude-desktop/configuration#allowedpluginmcpservers) to a list of URL patterns. An empty list admits no plugin-bundled server. Setting [`skillCreationEnabled`](/docs/third-party/claude-desktop/configuration#skillcreationenabled) to `false` turns off skill creation and upload in the app. Skills already on the device keep working, as do skills from [organization plugins](#organization-plugins-admin). Users can still install plugins from the marketplaces you provision regardless of these settings. Setting `userPluginUploadsEnabled` to `false` removes only users' options for adding plugins themselves. Plugins a user uploaded earlier stay in place. See the [Locked down profile](/docs/third-party/claude-desktop/configuration#recommended-security-profiles) for a complete example.
417 
418Setting [`userPluginMarketplacesEnabled`](/docs/third-party/claude-desktop/configuration#userpluginmarketplacesenabled) to `false` also hides every marketplace already on the device that your organization didn't [provision](#plugin-marketplaces-admin), whether a user added it in the app earlier or Claude Code registered it from a terminal on the same device. By default, Claude Code adds [Anthropic's official marketplace](https://code.claude.com/docs/en/plugins/anthropic-marketplaces) the first time a user starts an interactive terminal session, so that marketplace is hidden too unless you provision it. The app doesn't install or update plugins from a hidden marketplace. Plugins already installed from a hidden marketplace stay on the device, but they don't appear in the app or load in its sessions until you remove the key or set it back to `true`.
419 
420`userPluginMarketplacesEnabled` doesn't govern Claude Code in a terminal. To limit the marketplaces Claude Code can use in a terminal, set [marketplace restrictions in its managed settings](https://code.claude.com/docs/en/plugins/org#restrict-what-users-can-install). If you deploy Claude Code managed settings to the device, restrict marketplaces there too, because in Code sessions those settings can take precedence over the app's restrictions.
417421 
418422## Related topics
419423 

third-party/claude-desktop/gateway Changed · +1 / -1 lines

from line 181
181181 <Accordion title="inferenceStreamIdleTimeoutSec details">
182182 Raises how long Cowork, Chat and Code sessions wait for the next model event on an open streaming response (Claude Code's `CLAUDE_STREAM_IDLE_TIMEOUT_MS`). It only helps when the gateway writes SSE keep-alive `ping` events (or `:` comment lines) into the response while the upstream model is silent — for example a LiteLLM proxy with keep-alive pings enabled in front of Amazon Bedrock. With pings arriving, Claude Code accepts at least about five minutes of keep-alives and then waits this many seconds more for real model output before abandoning the request. Gateway provider only; the other providers keep Claude Code's defaults.
183183 
184 A response on which nothing at all arrives — no pings — still fails after about 5 minutes regardless of this key, because at the device a silent connection cannot be told apart from a dead one. If long generations fail behind a gateway that does not send pings, configure the gateway to send them rather than raising this value. While this key is set, the app's value takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` in Claude Code's own managed settings for sessions the app starts; when it is unset, that setting still applies. Values outside 300–1800 are rejected at parse time (the error is listed in the diagnostics report) and the default applies.
184 A response on which nothing at all arrives — no pings — still fails after about 5 minutes regardless of this key, because at the device a silent connection cannot be told apart from a dead one. If long generations fail behind a gateway that does not send pings, configure the gateway to send them rather than raising this value. A common case is automatic compaction, in which a session sends its whole conversation in one streaming request and waits for a long summary; when that request fails, the error reads `Prompt is too long · automatic compaction failed:` followed by the cause. While this key is set, the app's value takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` in Claude Code's own managed settings for sessions the app starts; when it is unset, that setting still applies. Values outside 300–1800 are rejected at parse time (the error is listed in the diagnostics report) and the default applies.
185185 </Accordion>
186186 
187187 <Accordion title="inferenceGatewayOidcAuthFlow details">

third-party/claude-desktop/telemetry Changed · +0 / -2 lines

from line 237
237237 
238238| Host | Purpose |
239239| - | - |
240| `a-cdn.anthropic.com` | Analytics SDK |
241| `a-api.anthropic.com` | Analytics events |
242240| `claude.ai` | Analytics events |
243241| `api.anthropic.com` | Claude Code usage telemetry, sent from inside the agent sandbox |
244242 
Feedback