One read of Claude Documentationclaude-docs-20261006T190715Z
5 pages moved out of 262 read.
Pages moved
5
significant first
Pages read
262
in this capture
Captured
19:07 UTC
Corpus hash
424f1a4f092e
corpus-hash
What this read moved
1-5 of 5cowork/changelog Changed · +44 / -0 lines
from line 2
22
33> Release notes for Claude Desktop
44
5<Update label="v2.26454.0" description="2026-10-06">
6 Bundled Claude Code version: 2.1.289.
7
8 **General**
9
10 * Fixed a reply or tool step that fails to draw taking the whole chat down with it; the reply now shows as plain text, the step reads “Couldn’t load this.”, and the rest of the chat stays.
11 * Fixed editing a message spoken in voice mode, which could cut the conversation back to its first message; the edit now shows a notice and keeps your words instead.
12 * Fixed image and document attachments failing to load on Ubuntu 22.04, Debian 12 and other older Linux distributions.
13 * Fixed installed plugins disappearing after a plugin was uploaded at a moment when the app could not read its list of installed plugins.
14 * Fixed the app crashing shortly after launch for people with a very large number of Cowork tasks.
15 * Fixed the whole app closing when a built-in browser tab whose page had crashed was resized, reloaded, or switched to a device size.
16
17 **Code**
18
19 * Fixed a new session quietly switching to Local, and running the prompt on this computer, when the picked Remote Control computer or cloud environment went away while you were typing.
20 * Fixed Cmd+Q, the Quit menu item and the tray Quit skipping the “Claude is still working” prompt and stopping running sessions without asking.
21 * Fixed file edits being skipped in SSH sessions on Linux hosts that use a worktree while the app is closed or the computer is asleep.
22 * Fixed new sessions where Claude couldn’t take actions in the app, such as changing settings, opening files in your editor, or keeping your computer awake.
23 * Fixed SSH sessions stopping with no message, or sitting idle instead of picking up where they left off, after Claude Code restarted on the remote host; the session now shows an error with Try again and resumes when reopened.
24 * Fixed typed messages, pasted images and attached files being lost when a message failed to send, or when a new session failed to start or was stopped while starting.
25
26 **Cowork**
27
28 * Changed computer use on macOS to no longer edit or save hidden files and folders in your home folder, such as `~/.vimrc` or `~/.aws`.
29 * Fixed a scheduled task that was moved to the cloud showing up as a separate paused task on this computer when cloud tasks failed to load, where turning it on could run the task twice.
30 * Fixed Claude being unable to use document menu commands, such as New Slide or Undo in Keynote, or to click and drag on some canvases while the app stays in the background.
31 * Fixed Cowork tasks failing to start in a second copy of the app running on the same Windows account.
32 * Fixed the app freezing when a second message was sent to a new task before the task had finished starting.
33
34 **3P**
35
36 * Added `claudeAiImport.allowedOrganizationUuids`: the Claude.ai organizations users may import chat history from. When set, users can import only by signing in to Claude.ai, and only from an organization on the list; importing from a file is turned off.
37 * Added `microsoftAuthDefaultAccount`: when set to `enabled`, Connect on the Microsoft 365 connector on Windows signs in with the work account already signed in to Windows, with no account picker. Defaults to `disabled`.
38 * Added a “Use a different account” button and a line showing the signed-in account to the Microsoft 365 connector.
39 * Added an event sent to your OTLP collector when an SSH host isn’t running the sandbox your configuration asks for.
40 * Added the `desktop_claude_ai_import` event to the desktop OpenTelemetry export at log level `info`: it is logged for each Claude.ai history import made by sign-in or from a file, and for an import by the built-in Claude.ai sign-in it names the organization the history came from.
41 * Changed `inferenceGatewayAuthScheme: "sso"` to have no end date in this release and later: if `inferenceCredentialKind` is not set, they keep reading `sso` as `inferenceCredentialKind: "interactive"` after October 7, 2026. Earlier releases still stop accepting it on that date.
42 * Changed connectors on a computer login that several people share: each person now keeps their own built-in and OAuth connector sign-ins. A different person who signs in starts with their connectors disconnected, and the earlier person’s sign-ins are kept for when they sign in again.
43 * Changed Teams chat search in the Microsoft 365 connector to need the `ChannelMessage.Read.All` permission; without it, searches return a message with a consent link. Grant Entra admin consent, then set Access (`scope`) to the permissions the connector already uses plus this one, and have users reconnect.
44 * Fixed organization plugins a user installed disappearing after the admin’s plugin folder was redeployed.
45 * Fixed saving a skill with a very long description causing every skill kept on this computer to be removed. A description over 1,024 characters is now refused with the reason.
46 * Fixed the Microsoft 365 connector’s Access setting replacing the default permissions (mail, calendar, files) with a single permission when an administrator added one. Access now shows the defaults as selected, so adding one keeps the rest, and a custom list can be reset to the default.
47</Update>
48
549<Update label="v2.19675.1" description="2026-10-05">
650 Bundled Claude Code version: 2.1.288.
751
third-party/claude-desktop/configuration Changed · +14 / -2 lines
from line 217
217217| <span id="inferencegatewaybaseurl" />Gateway base URL<br />`inferenceGatewayBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Full URL of the inference gateway endpoint. |
218218| <span id="inferencestreamidletimeoutsec" />Stream idle timeout<br />`inferenceStreamIdleTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.44121.1 | — | Extra seconds to wait for model output on a streaming response that is sending only keep-alive pings. Gateway provider only. Default 300. Range: 300–1800. |
219219| <span id="inferencegatewayapikey" />Gateway API key<br />`inferenceGatewayApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for the configured inference gateway. |
220| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"` (accepted until October 7, 2026); use inferenceCredentialKind: "interactive". If it is still present after that, browser sign-in will no longer be inferred from it — the key will be reported as invalid and, unless inferenceCredentialKind or another credential field (an API key, inferenceGatewayOidc) says how to sign in, the gateway connection will have no credential and inference will not start. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
220| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"`; use inferenceCredentialKind: "interactive". The original spelling will keep working; no end date has been set. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
221221| <span id="inferencegatewayoidcauthflow" />Gateway sign-in flow<br />`inferenceGatewayOidcAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. Deprecated: `inferenceGatewayOidcAuthFlow`; use inferenceIdpAuthFlow together with inferenceIdpOidc once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
222222| <span id="inferencegatewayoidc" />Gateway SSO IdP (OIDC)<br />`inferenceGatewayOidc` | `object` | MDM + Bootstrap<br />Added in 1.6889.0 | — | External IdP for gateway sign-in. The user’s token from this issuer is sent to the gateway as the Bearer credential. Deprecated: `inferenceGatewayOidc`; use inferenceIdpOidc with inferenceCredentialKind: "external-idp" once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
223223| <span id="inferenceidpauthflow" />Identity provider sign-in flow<br />`inferenceIdpAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How the identity-provider sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
from line 652
652652 <Accordion title="allowedWorkspaceFolders details">
653653 Paths can reference `~` and these environment variables, expanded per user: `%OneDrive%`, `%OneDriveCommercial%`, `%OneDriveConsumer%`, `%APPDATA%`, `%LOCALAPPDATA%`, `%USERNAME%`, `%XDG_DOCUMENTS_DIR%`. The set is fixed; an entry that references any other `%VAR%`, or one that is unset on the device, is ignored.
654654
655 Each folder is interpreted on the machine the session runs on. For a Code session on an SSH host, `~` means the remote user's home, an entry that references a `%VAR%` is ignored there (environment variables belong to the machine that defines them), and the session's working directory must fall inside one of the folders as they exist on that host. One list serves every machine: `["/Users", "~"]` governs `/Users` on a managed Mac and the signed-in user's home on a Linux host. A folder that names nothing real on a given machine simply allows nothing there. An empty list allows no folder at all; unset leaves access unrestricted.
655 Each folder is interpreted on the machine the session runs on. For a Code session on an SSH host, `~` means the remote user's home, an entry that references a `%VAR%` is ignored there (environment variables belong to the machine that defines them), and the session's working directory must fall inside one of the folders as they exist on that host. One list serves every machine: `["~/work", "/srv/work"]` governs `~/work` for each user, on a managed Mac or a Linux host, and `/srv/work` on a host that has it. A folder that names nothing real on a given machine simply allows nothing there. An empty list allows no folder at all; unset leaves access unrestricted.
656656
657 A listed folder is one Claude may write as well as read, unless the entry's `mode` (Access mode in Setup) makes it read-only; that field's own description says how far read-only reaches. A Code session can reach every listed folder, not only the one it was opened in. Setting this key also turns on Claude Code's sandbox where it runs (macOS, or Linux and SSH hosts with bubblewrap): there a shell command normally writes in the listed folders without an approval prompt, and its writes to most other places, such as a package cache in the home directory, are refused. A home directory holds shell start-up files and SSH keys, so list work folders, not a whole home directory.
658
657659 The list also limits which folders of a project a chat reads.
658660
659661 | Field | Type | Default | Description |
from line 703
701703 | Field | Type | Default | Description |
702704 | - | - | - | - |
703705 | `enabled` | `boolean` | `false` | Lets users import a Claude.ai data export and earlier Claude sessions on this computer from Settings → Import. Doesn’t affect a provisioned sign-in import. |
706 | `allowedOrganizationUuids` | `string[]` | — | When set, users import by sign-in only, and only from the Claude.ai organizations with these IDs. |
704707 | `automatic3pImport` | `boolean` | — | Copy this computer’s earlier third-party sessions into the app once, in the background. Independent of `enabled`. |
705708 | `exportEnabled` | `boolean` | `false` | Lets users export this computer’s chats, Cowork tasks, and Code sessions as a zip another install can import. No effect unless `enabled` is true. |
706709 | `bannerBehavior` | `enum` | — | Prompt to import on a new chat or task. Off if unset. `show`: always; needs `enabled` or a sign-in import. `detect`: if `enabled` finds earlier Claude sessions. One of: `off`, `detect`, `show`. |
from line 715
712715| Setting | Type | Availability | Default | Description |
713716| - | - | - | - | - |
714717| <span id="microsoftauthbroker" />Microsoft 365 native sign-in broker<br />`microsoftAuthBroker` | `enum` | MDM + Bootstrap<br />Added in 1.19367.0 | `auto` | “disabled” forces browser-based Microsoft 365 sign-in; “required” fails sign-in when the OS broker is unavailable, so the refresh token stays broker-held. One of: `auto`, `disabled`, `required`. Defaults to `auto`. |
718| <span id="microsoftauthdefaultaccount" />Microsoft 365 sign-in with the Windows account<br />`microsoftAuthDefaultAccount` | `enum` | MDM + Bootstrap<br />Added in 2.26454.0 | `disabled` | “enabled”: when a user clicks Connect on Windows, Microsoft 365 signs in with the work account already signed in to Windows, without the account picker. One of: `enabled`, `disabled`. Defaults to `disabled`. |
715719
716720<AccordionGroup>
717721 <Accordion title="microsoftAuthBroker details">
718722 `auto` (default): use the OS sign-in broker where available (WAM on Windows, the Company Portal SSO extension on macOS) and fall back to a browser sign-in otherwise. `disabled`: always use the browser sign-in. `required`: fail sign-in when the broker is unavailable rather than falling back to the browser, so the refresh token stays broker-held. Linux has no broker, so `required` is not supported there. Desktop builds older than the version that introduced `required` treat it as `disabled` (browser-only sign-in) — the opposite posture — so gate rollout on client version.
719723 </Accordion>
724
725 <Accordion title="microsoftAuthDefaultAccount details">
726 `disabled` (default): Connect shows the account picker when no account is connected. `enabled`: on Windows, when `microsoftAuthBroker` is not `disabled`, Connect first signs in silently with the account Windows already uses. The `tenantId` on the `microsoft365` entry in managed MCP servers must be a tenant GUID. With `common`, `organizations` or `consumers`, users always get the picker. Users also get the picker for accounts from another tenant, guest accounts and personal Microsoft accounts, when the silent sign-in fails, and when the computer cannot store credentials securely. A user who already signed in to Microsoft 365 through the browser keeps that account. After a user disconnects Microsoft 365, or a different person signs in to Claude on this computer, Connect always shows the picker for that connector on this computer, including for a disconnect that happened before this setting was turned on. Turning this setting off stops new silent sign-ins and signs nobody out: users already connected keep their account until they disconnect. macOS and Linux are not affected. Third-party deployments only: first-party installs ignore this setting.
727 </Accordion>
720728</AccordionGroup>
721729
722730### Extensions
from line 902
894902| <span id="updateviaupdateshost" />Check for updates on releases.claude.com<br />`updateViaUpdatesHost` | `boolean` | MDM + Bootstrap<br />Added in 1.26832.0 | `false` | Read the update feed from releases.claude.com so api.anthropic.com can stay blocked. Defaults to `false`. |
895903
896904<AccordionGroup>
905 <Accordion title="disableAutoUpdates details">
906 In third-party deployments this also keeps Cowork's workspace image and tools from being fetched ahead of use; they are then fetched when a task first needs them.
907 </Accordion>
908
897909 <Accordion title="autoUpdaterEnforcementHours details">
898910 Has no effect when `disableAutoUpdates` is in place at launch: the updater never starts, so nothing is downloaded and this timer never arms. If the policy reaches an already-running app after an update has downloaded, that one staged update still installs on this timer; no further updates are fetched.
899911
third-party/claude-desktop/configuration-changelog Changed · +30 / -1 lines
from line 4
44
55Configuration keys by Claude Desktop release. Each section lists keys added in that release, with the MDM key name (for plist/registry deployment) and the equivalent JSON shape (for local-file or bootstrap remote configuration).
66
7<Update label="v2.26454.0" description="2026-10-06">
8 <div className="cfg-keys">
9 | MDM key | Type | Description |
10 | - | - | - |
11 | [`microsoftAuthDefaultAccount`](/docs/third-party/claude-desktop/configuration#microsoftauthdefaultaccount) | `enum` | Microsoft 365 sign-in with the Windows account |
12 </div>
13
14 **JSON (e.g. for non-MDM users or Bootstrap):**
15
16 ```json theme={null}
17 {
18 "authentication": {
19 "microsoftAuthDefaultAccount": "<enabled|disabled>"
20 }
21 }
22 ```
23
24 **Changed:**
25
26 * `claudeAiImport` accepts a new `allowedOrganizationUuids` value, a list of Claude.ai organization IDs: when set, users can import history only by signing in to Claude.ai, and only from an organization on the list; a sign-in to any other organization or to a personal account is refused, and importing from a file or from earlier sessions on this computer is turned off. The list turns nothing on by itself, and `automatic3pImport` is not affected. Earlier releases ignore the list and keep allowing every import they allowed before, so the list limits imports only on devices running this release or later.
27 * `disableAutoUpdates` now also decides when Cowork's workspace is downloaded: in the background, instead of at the first task, unless it is `true`.
28
29 **Deprecated** (no end date has been set; this release and later keep reading the original spelling):
30
31 * `inferenceGatewayAuthScheme: "sso"`: use `inferenceCredentialKind: "interactive"` instead. If `inferenceCredentialKind` is not set, this release and later keep reading the original spelling as `inferenceCredentialKind: "interactive"` after October 7, 2026. Earlier releases stop reading it on that date, as announced under v1.40609.0.
32</Update>
33
734<Update label="v2.19675.1" description="2026-10-05">
8 No configuration changes in this release.
35 **Changed:**
36
37 * `allowedWorkspaceFolders`, when set, now also limits which of a project's folders a chat can read: only those inside a listed folder.
938</Update>
1039
1140<Update label="v2.19675.0" description="2026-10-01">
third-party/claude-desktop/gateway Changed · +1 / -1 lines
from line 171
171171| <span id="inferencegatewaybaseurl" />Gateway base URL<br />`inferenceGatewayBaseUrl` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Full URL of the inference gateway endpoint. |
172172| <span id="inferencestreamidletimeoutsec" />Stream idle timeout<br />`inferenceStreamIdleTimeoutSec` | `integer` | MDM + Bootstrap<br />Added in 1.44121.1 | — | Extra seconds to wait for model output on a streaming response that is sending only keep-alive pings. Gateway provider only. Default 300. Range: 300–1800. |
173173| <span id="inferencegatewayapikey" />Gateway API key<br />`inferenceGatewayApiKey` | `string` | MDM + Bootstrap<br />Added in 1.2581.0 | — | API key for the configured inference gateway. |
174| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"` (accepted until October 7, 2026); use inferenceCredentialKind: "interactive". If it is still present after that, browser sign-in will no longer be inferred from it — the key will be reported as invalid and, unless inferenceCredentialKind or another credential field (an API key, inferenceGatewayOidc) says how to sign in, the gateway connection will have no credential and inference will not start. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
174| <span id="inferencegatewayauthscheme" />Gateway auth scheme<br />`inferenceGatewayAuthScheme` | `enum` | MDM + Bootstrap<br />Added in 1.3036.0 | `bearer` | How the gateway credential is sent on the wire (Authorization: Bearer vs x-api-key header). One of: `bearer`, `x-api-key`. Defaults to `bearer`. Deprecated: `inferenceGatewayAuthScheme: "sso"`; use inferenceCredentialKind: "interactive". The original spelling will keep working; no end date has been set. Deprecated: `inferenceGatewayAuthScheme: "auto"` (accepted until October 7, 2026); use "bearer" (or remove the key — bearer is the default). If it is still present after that, the value will be reported as invalid and ignored like any unrecognised scheme; the key will then take its default, "bearer", so the credential will still be sent as an Authorization: Bearer header. |
175175| <span id="inferencegatewayoidcauthflow" />Gateway sign-in flow<br />`inferenceGatewayOidcAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 1.25927.0 | — | How the IdP sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. Deprecated: `inferenceGatewayOidcAuthFlow`; use inferenceIdpAuthFlow together with inferenceIdpOidc once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
176176| <span id="inferencegatewayoidc" />Gateway SSO IdP (OIDC)<br />`inferenceGatewayOidc` | `object` | MDM + Bootstrap<br />Added in 1.6889.0 | — | External IdP for gateway sign-in. The user’s token from this issuer is sent to the gateway as the Bearer credential. Deprecated: `inferenceGatewayOidc`; use inferenceIdpOidc with inferenceCredentialKind: "external-idp" once every desktop in the fleet is on a release that reads them. The original spelling will keep working; no end date has been set. |
177177| <span id="inferenceidpauthflow" />Identity provider sign-in flow<br />`inferenceIdpAuthFlow` | `enum` | MDM + Bootstrap<br />Added in 2.7032.0 | — | How the identity-provider sign-in runs: system browser (default) or the OS Microsoft Entra broker. One of: `browser`, `broker`. |
third-party/claude-desktop/telemetry Changed · +1 / -1 lines
from line 145
145145
146146| Host | Purpose |
147147| - | - |
148| `downloads.claude.ai` | VM workspace bundle and Claude CLI binary, fetched at session start |
148| `downloads.claude.ai` | VM workspace bundle and Claude CLI binary, fetched in the background or at session start |
149149| `downloads.claude.ai` | Claude Code model catalog (signed picker metadata), polled every 5–15 minutes |
150150
151151Without this host reachable, Chat conversations, Cowork tasks, and Code sessions cannot start on a device that has not yet downloaded these components. App updates often change one or both of these components, and the app then downloads the new versions from the same host. Devices installed with the [offline installer variant](/docs/third-party/claude-desktop/installation#offline-installation), which includes both components in the installer package, are not affected. The model catalog fetch is not needed to run the app: set [`modelCatalogEnabled`](/docs/third-party/claude-desktop/configuration#modelcatalogenabled) to `false` to turn it off, or [`modelCatalogUrl`](/docs/third-party/claude-desktop/configuration#modelcatalogurl) to fetch the catalog from a mirror inside your network. While the catalog is unreachable, sessions still start and the model picker keeps the names and effort options the app last fetched or shipped with.