One read of Claude Documentationclaude-docs-20261006T220708Z
1 pages moved out of 262 read.
Pages moved
1
significant first
Pages read
262
in this capture
Captured
22:07 UTC
Corpus hash
aae8415d5a6c
corpus-hash
What this read moved
1-1 of 1third-party/claude-desktop/code Changed · +23 / -0 lines
## Claude Code mods
from line 71
7171 In a third-party deployment there is no Anthropic authentication, so Claude Code's server-managed settings tier is never present. If you have not separately deployed a Claude Code `managed-settings.json` or OS profile, Claude Desktop's policy applies automatically and you do not need to set `parentSettingsBehavior`.
7272</Note>
7373
74## Claude Code mods
75
76Code sessions support Claude Code [mods](https://code.claude.com/docs/en/plugins/mods/overview), code that a plugin runs inside Claude Code, and users can load their own. To stop users' own mods from loading in local Code sessions, deploy this Claude Code managed-settings file on each device:
77
78```json managed-settings.json theme={null}
79{
80 "parentSettingsBehavior": "merge",
81 "pluginConfigs": {
82 "cc-plugin-sec-default@builtin": {
83 "options": {
84 "allowManagedModsOnly": true
85 }
86 }
87 }
88}
89```
90
91* **Keep `parentSettingsBehavior`.** Without it, Claude Code ignores the sandbox and the other [managed policy](#applied-as-managed-policy) values that Claude Desktop supplies.
92* **Leave out `disableSideloadFlags`**, which a longer sample in the Claude Code docs includes. With it, Code sessions start without the skills and organization plugins that Claude Desktop delivers.
93* **Optionally, remove the `/plugin-authoring` command**, which has Claude write a mod. Add `"enabledPlugins": { "cc-plugin-plugin-authoring@builtin": false }` to the file.
94
95[Manage mods for your organization](https://code.claude.com/docs/en/plugins/mods/admin) covers the other controls. For sessions on an SSH host, see [Managed configuration on the remote host](/docs/third-party/claude-desktop/ssh-remote-sessions#managed-configuration-on-the-remote-host).
96
7497## Remote sessions over SSH
7598
7699A Code session can run its Claude Code engine on a remote host over SSH while the session's interface stays in Claude Desktop on the user's device. In a 3P deployment this is off until you set [`sshHostAllowlist`](/docs/third-party/claude-desktop/configuration#sshhostallowlist), because the app forwards the session's inference credential to the host. [SSH remote sessions](/docs/third-party/claude-desktop/ssh-remote-sessions) lists the credential kinds that work on a remote host and which of the keys above apply there.