Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20261005T183601Z

7 pages moved out of 261 read.

Pages moved 7 significant first
Pages read 261 in this capture
Captured 18:36 UTC
Corpus hash edb4b2e94585 corpus-hash

What this read moved

1-7 of 7

claude-science/safeguards Changed · +4 / -2 lines

from line 6
66 
77## When safeguards flag a message
88 
9When a model's safeguards flag a message, Claude Science pauses the session and shows a **Chat paused** card above the composer. If another model can continue, select **Retry with `<model>`** to retry on the model the card names. That model has its own safeguards. The session stays on it until you choose a different model in the composer.
9When a model's safeguards flag a message, Claude Science pauses the session and shows a **Chat paused** card above the composer, unless it [switches models automatically](#switch-models-automatically). If another model can continue, select **Retry with `<model>`** to retry on the model the card names. That model has its own safeguards. The session stays on it until you choose a different model in the composer.
1010 
1111## Switch models automatically
1212 
13To have Claude Science retry without stopping at the **Chat paused** card, turn on the **Automatically switch models when a message is flagged** switch under **Settings** > **General** > **Model**. You can also select it on the card before you retry. Claude Science then retries a flagged message on another model right away and shows a notice that names the model it switched to. If no other model can continue, or after several automatic switches in one session, you see the **Chat paused** card instead. Automatic switching is off by default and applies to every session on this computer.
13When safeguards flag a message for content related to life sciences research, Claude Science can retry it right away on another model instead of stopping at the [**Chat paused** card](#when-safeguards-flag-a-message). It does this only when a model is available for automatic switching, and at most once per message. A notice names the model it switched to, and the session stays on that model until you choose a different one in the composer.
14 
15Automatic switching is on by default and applies to every session on this computer. To turn it off, go to **Settings > General > Model** and turn off the **Switch models when a message is flagged** toggle. The **Chat paused** card shows the same toggle when it offers **Retry with `<model>`**. Turning the toggle on from the card can also retry the paused message right away.
1416 
1517## Life Sciences Verification Program (beta)
1618 

third-party/claude-desktop/configuration Changed · +6 / -6 lines

from line 326
326326 
327327 **Extended context** (`supports1m`) is a capability assertion you make about your deployment; only set it for models you've confirmed support the 1M-token window:
328328 
329 ```json theme={null}
329 ```json theme={null} theme={null} theme={null}
330330 [{"name": "claude-sonnet-5", "supports1m": true}, "claude-opus-4-8"]
331331 ```
332332 
from line 334
334334 
335335 **Display label** (`labelOverride`) is for IDs the picker can't derive a friendly name from (Bedrock ARNs, gateway routing aliases). Display-only; `name` is still what the app sends:
336336 
337 ```json theme={null}
337 ```json theme={null} theme={null} theme={null}
338338 [{"name": "arn:aws:bedrock:us-east-1:123:application-inference-profile/abc", "labelOverride": "Claude Opus (Prod)"}]
339339 ```
340340 
341341 **Tier mapping** (`anthropicFamilyTier`) tells the app which Claude tier (`haiku`/`sonnet`/`opus`/`fable`/`mythos`) an entry stands in for, so bare tier aliases (e.g. in Code sessions) resolve to your model. `isFamilyDefault: true` picks the winner when several entries share a tier:
342342 
343 ```json theme={null}
343 ```json theme={null} theme={null} theme={null}
344344 [{"name": "us.anthropic.claude-opus-4-8", "anthropicFamilyTier": "opus"}]
345345 ```
346346 
from line 374
374374 <Accordion title="inferenceModelPricing details">
375375 Each row replaces Anthropic list price for one model in the Usage page's estimate, in USD per million tokens (`inputPerMtok`, `outputPerMtok`, `cacheReadPerMtok`, `cacheWritePerMtok`, all four required; `cacheWritePerMtok` prices both 5-minute and 1-hour cache writes); rows apply only while `inferenceModelPricingEnabled` is `true` and do not turn the estimate on by themselves. Mirrors Claude Code's managed `modelPricing.overrides`, and `name` is matched the same way: a built-in Claude model ID (e.g. `claude-sonnet-4-6`, or its Bedrock, Vertex, or Foundry ID) covers every dated and provider spelling of that model; any other value (a gateway alias, an inference-profile ARN) matches that exact ID only (case-insensitive) and wins over a built-in row. An ID Claude Code cannot map to a Claude model at all gets no estimate until a row here prices it. `inferenceModelPricingMultiplier` still applies on top of a row.
376376 
377 ```json theme={null}
377 ```json theme={null} theme={null} theme={null}
378378 {"inferenceModelPricingEnabled": true, "inferenceModelPricingMultiplier": 0.9, "inferenceModelPricing": [{"name": "claude-sonnet-4-6", "inputPerMtok": 2.4, "outputPerMtok": 12, "cacheReadPerMtok": 0.24, "cacheWritePerMtok": 3}]}
379379 ```
380380 
from line 1094
10941094 <Accordion title="orgPluginSettings details">
10951095 Locks per-tool permissions on MCP servers provided by any installed plugin — from the org-plugins directory or a plugin marketplace, remote or run locally — one entry per server name (compared case-insensitively):
10961096 
1097 ```json theme={null}
1097 ```json theme={null} theme={null} theme={null}
10981098 [{"serverName": "internal-search", "tools": [{"toolName": "delete_document", "permission": "blocked"}]}]
10991099 ```
11001100 
from line 1230
12301230* `"ask"` — the user approves every call; no session-scoped or standing grants are offered.
12311231* `"blocked"` — the tool is removed from Claude's session; connector settings show it as blocked by your organization.
12321232 
1233Tools with no policy entry stay user-controlled (built-in connectors apply default policies to some tools — see the reference above): the user is prompted and can approve once, approve for the rest of the task (offered for tools that can modify data), or grant a standing approval unless [`mcpPersistentAlwaysAllowEnabled`](#mcppersistentalwaysallowenabled) is `false`. Full prompt options require version 1.22209.0 or later; earlier third-party builds offered only per-call approval. The reference above also lists an `"ask-session"` value, which behaves exactly as `"ask"` and is accepted until October 7, 2026. After that date the app rejects an entry that uses it, so write `"ask"`. Managed policies take precedence over user grants, and enforcement happens in the desktop host process, not only in the prompt UI. A deny-by-default posture — `"*": "blocked"` plus exact `"allow"` entries for approved tools — is supported, including in Code sessions (where an allowed tool still gets Claude Code's own approval prompt). See the [`managedMcpServers` reference](#managedmcpservers) for wildcard matching, precedence rules, and built-in connector defaults.
1233Tools with no policy entry stay user-controlled (built-in connectors apply default policies to some tools — see the reference above): the user is prompted and can approve once, approve for the rest of the task (offered for tools that can modify data), or grant a standing approval unless [`mcpPersistentAlwaysAllowEnabled`](#mcppersistentalwaysallowenabled) is `false`. Full prompt options require version 1.22209.0 or later; earlier third-party builds offered only per-call approval. The reference above also lists an `"ask-session"` value. Before 12:00 PM Pacific Time (19:00 UTC) on October 7, 2026, the app treats it exactly as `"ask"`. From then on, the app rejects an entry that uses it, so write `"ask"`. Managed policies take precedence over user grants, and enforcement happens in the desktop host process, not only in the prompt UI. A deny-by-default posture — `"*": "blocked"` plus exact `"allow"` entries for approved tools — is supported, including in Code sessions (where an allowed tool still gets Claude Code's own approval prompt). See the [`managedMcpServers` reference](#managedmcpservers) for wildcard matching, precedence rules, and built-in connector defaults.
12341234 
12351235On a scheduled Cowork task, the prompt can also offer an **Allow for all scheduled runs** option. See [Tool approvals on scheduled tasks](#tool-approvals-on-scheduled-tasks).
12361236 

third-party/claude-desktop/bootstrap Changed · +1 / -1 lines

from line 348
348348* Deployed through machine-scoped device management (`HKLM` policy on Windows, a configuration profile on macOS, `/etc/claude-desktop` on Linux): delivered values are trusted without prompting, because the admin already made a device-level decision.
349349* Read from a local configuration file, or from user-scope registry policy: the dialog is shown by default.
350350 
351The `trustBootstrapDelivery` key overrides the default in either direction, and the previous name `trustBootstrapLocalExec` is accepted until October 7, 2026. The key is accepted from device management or the local configuration file only, never from the bootstrap response itself. When the rest of your configuration is a local file, set the key in that same file next to `bootstrapUrl`. Delivering only this key through device management makes the whole installation managed, and the app then ignores the local file entirely, including its `bootstrapUrl`.
351The `trustBootstrapDelivery` key overrides the default in either direction, and the previous name `trustBootstrapLocalExec` is accepted only before 12:00 PM Pacific Time (19:00 UTC) on October 7, 2026. The key is accepted from device management or the local configuration file only, never from the bootstrap response itself. When the rest of your configuration is a local file, set the key in that same file next to `bootstrapUrl`. Delivering only this key through device management makes the whole installation managed, and the app then ignores the local file entirely, including its `bootstrapUrl`.
352352 
353353Consent gates only bootstrap-delivered values. The same keys delivered through device management apply without prompting. Versions that predate a key's availability ignore that key in a bootstrap response (the [configuration changelog](/docs/third-party/claude-desktop/configuration-changelog) records when each key became available), so a response can safely carry keys ahead of a fleet upgrade.
354354 

third-party/claude-desktop/code Changed · +1 / -0 lines

from line 43
4343| `blockReadsOutsideWorkingDirectories` | Claude Code's `permissions.blockReadsOutsideWorkingDirectories` for Code sessions. Claude's file tools refuse to read outside the working directories (the session's folder plus your allowed roots, if any) in every permission mode. Where the sandbox from `allowedWorkspaceFolders` or `coworkEgressAllowedHosts` is running, it also hides the user's home directory and similar locations, such as other users' home folders and mounted volumes, from shell commands, so a sandboxed command that reads there fails without a prompt. Without a running sandbox, a shell command that reads outside the working directories, or that Claude Code cannot analyze, asks the user for approval first, even in bypass permissions mode. The key requires Claude Desktop 1.46388.1 or later. The block takes effect only in sessions that run Claude Code v2.1.257 or later; if the app cannot install its current Claude Code engine and a session runs one older than v2.1.257 that is still on the device, that session runs without the block and the app logs a warning. |
4444| `managedMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]`, so the Code session does not load MCP servers that users define on Claude Code's side (`~/.claude.json`, a project's `.mcp.json`, or `claude mcp add`); your managed servers, which the app connects and supplies to the session itself, and MCP servers bundled in plugins still load. When [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`, the app also sets an `allowedMcpServers` list that admits only remote servers, with `allowManagedMcpServersOnly`, so local (stdio) servers bundled in plugins from marketplaces or that users install themselves are refused, while those plugins' remote servers still connect. Per-tool `toolPolicy` values on each server are emitted as `permissions.deny` (for `blocked`) or `permissions.ask` (for `ask`) rules against the corresponding `mcp__<server>__<tool>` names. |
4545| `allowedPluginMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]` together with an `allowedMcpServers` list holding your entries and `allowManagedMcpServersOnly`, whether or not `managedMcpServers` is set. MCP servers bundled in plugins from marketplaces, or in plugins users install themselves, connect only when their URL matches an entry; no such plugin's local (stdio) server is admitted, and an empty list admits none. Your managed servers and the servers from the organization plugins directory still load. |
46| `deniedPluginMcpServers` | The app sets a `deniedMcpServers` list holding your entries, whether or not `allowedPluginMcpServers` is set. When the key is unset or its list is empty, the app sets no `deniedMcpServers` list. When the value is not a list, or holds an entry that the app can't read, the app sets a list whose one entry is `*`, a pattern that matches every URL. See the [`deniedPluginMcpServers` reference](/docs/third-party/claude-desktop/configuration#deniedpluginmcpservers) for what the setting does and what an entry matches. |
4647 
4748The network and filesystem sandboxes apply on macOS, and on Linux devices and [SSH hosts](/docs/third-party/claude-desktop/ssh-remote-sessions#managed-configuration-on-the-remote-host) with Claude Code's [sandbox dependencies](https://code.claude.com/docs/en/sandboxing) installed. Claude Code does not sandbox shell commands on Windows devices, and on a Linux device or SSH host without the dependencies commands run unsandboxed with a warning in the session. In those cases, and when neither sandbox key is set, `blockReadsOutsideWorkingDirectories` still confines Claude's file tools but can only ask the user to approve shell commands that read outside the working directories or that Claude Code cannot verify.
4849 

third-party/claude-desktop/connectors-m365 Changed · +1 / -1 lines

from line 199
199199 | `tenantId` | Yes | Your Directory (tenant) ID. |
200200 | `azureCloud` | No | `global` (default), `us-gov-high`, or `us-gov-dod`. Selects the Microsoft Entra and Microsoft Graph hosts for US Government clouds. |
201201 | `continuousAccessEvaluation` | No | `enabled` (default) or `disabled`. When enabled, the connector requests Continuous Access Evaluation-capable Microsoft Graph tokens, which live up to about 28 hours and stop working within minutes after an administrator revokes the user's sessions or disables the account in Entra, and, where your tenant enforces an IP named-location or Global Secure Access compliant-network Conditional Access policy, when the token is used from outside that network. `disabled` keeps standard one-hour tokens. A change applies to tokens issued after the connector next starts, and an already-issued token stays in use until it expires (select **Disconnect**, then **Connect**, to sign in again immediately). Requires Claude Desktop 1.49585.0 or later; earlier versions ignore the field and request standard one-hour tokens. |
202 | `scope` | No | Space-separated delegated Graph scopes to request instead of the default read set. A string array named `scopes` is also accepted until October 7, 2026. See [Configure scopes](#configure-scopes). |
202 | `scope` | No | Space-separated delegated Graph scopes to request instead of the default read set. A string array named `scopes` is also accepted only before 12:00 PM Pacific Time (19:00 UTC) on October 7, 2026. See [Configure scopes](#configure-scopes). |
203203 | `toolPolicy` | No | Per-tool approval locks, the same as for any managed server. See [`toolPolicy`](/docs/third-party/claude-desktop/configuration#managedmcpservers). |
204204 
205205 The server ships inside the app, so nothing else needs to be installed on the device, and it activates only from managed configuration; users cannot add it themselves. Deploy the configuration through your device-management tool as usual.

third-party/claude-desktop/gateway Changed · +1 / -1 lines

from line 294
294294 
295295From Claude Desktop 2.7032.0, `inferenceCredentialKind: "external-idp"` with [`inferenceIdpOidc`](/docs/third-party/claude-desktop/configuration#inferenceidpoidc) and `inferenceIdpAuthFlow`, the keys [Amazon Bedrock identity provider sign-in](/docs/third-party/claude-desktop/bedrock#sign-in-with-your-identity-provider) uses, is an equivalent spelling of this configuration; `interactive` with `inferenceGatewayOidc` keeps working, so keep it until every device runs 2.7032.0 or later.
296296 
297Earlier app versions used `inferenceGatewayAuthScheme: "sso"` to select this mode. That value is deprecated; set `inferenceCredentialKind: "interactive"` instead. Existing deployments that still send `inferenceGatewayAuthScheme: "sso"` continue to work until October 7, 2026. After that date the value no longer selects browser sign-in, so set `inferenceCredentialKind: "interactive"` before then.
297Earlier app versions used `inferenceGatewayAuthScheme: "sso"` to select this mode. That value is deprecated; set `inferenceCredentialKind: "interactive"` instead. Existing deployments that still send `inferenceGatewayAuthScheme: "sso"` work only before 12:00 PM Pacific Time (19:00 UTC) on October 7, 2026. From then on, the value doesn't select browser sign-in, so set `inferenceCredentialKind: "interactive"`.
298298 
299299### Models
300300 

third-party/claude-desktop/telemetry Changed · +2 / -2 lines

from line 36
3636 
3737### Non-essential services
3838 
39Cosmetic third-party fetches: favicons for connectors shown in the UI, the sandboxed iframe that renders interactive artifact previews, and the sandboxed iframes that render [MCP Apps](/docs/connectors/building/mcp-apps/getting-started), the interactive widgets connectors can display. Disabling these degrades the UI (generic icons, static artifact previews, and connector tool results shown as text instead of widgets) but doesn't affect functionality.
39Cosmetic third-party fetches: favicons for connectors shown in the UI, the sandboxed iframe that renders interactive artifact previews, and the sandboxed iframes that render [MCP Apps](/docs/connectors/building/mcp-apps/getting-started), the interactive widgets connectors can display. Disabling these degrades the UI (generic icons, static artifact previews, and connector tool results shown as text instead of widgets) but doesn't affect functionality. On Linux, `disableNonessentialServices` also applies to the spellcheck dictionary, which the built-in spellchecker downloads from the hosts listed under [Required egress paths](#required-egress-paths). Without the dictionary, misspelled words aren't underlined.
4040 
4141| Setting | Default | Effect when `true` |
4242| - | - | - |
43| `disableNonessentialServices` | `false` | Favicon, artifact-preview, and MCP App widget fetches are blocked. Connectors that return MCP Apps show the tool's text result instead of the widget. |
43| `disableNonessentialServices` | `false` | Favicon, artifact-preview, and MCP App widget fetches are blocked. Connectors that return MCP Apps show the tool's text result instead of the widget. On Linux, the setting also applies to the spellcheck dictionary download. Without the dictionary, misspelled words aren't underlined. |
4444 
4545### Auto-updates
4646 
Feedback