Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20261009T033709Z

3 pages moved out of 265 read.

Pages moved 3 significant first
Pages read 265 in this capture
Captured 03:37 UTC
Corpus hash a2230a7fa665 corpus-hash

What this read moved

1-3 of 3

cowork/changelog Changed · +49 / -0 lines

from line 2
22 
33> Release notes for Claude Desktop
44 
5<Update label="v2.31226.0" description="2026-10-08">
6 Bundled Claude Code version: 2.1.293.
7 
8 **General**
9 
10 * Added skills and local MCP servers to Settings > Import where importing this computer’s third-party history is on: skills saved in Claude (third-party) upload to your own skills automatically, and local MCP servers can be added and started after you confirm the command and settings each one runs with.
11 * Fixed chats showing "Page not found" when they could not be loaded because of a server or connection problem; the page now says the chat could not be loaded and offers a retry.
12 * Fixed dictation continuing to record after you let go of the microphone button, when holding it was the first microphone use since the app started.
13 * Fixed messages being sent under a different organization after the page switched organizations: a message held up by a sign-in prompt is no longer sent, one reported as not sent returns to the message box instead of sending later, and a stopped button or reply send now says why.
14 * Fixed programs that a session started, such as MCP servers, and the helper processes of local MCP servers staying running on Linux after the app crashed or was force-quit.
15 
16 **Code**
17 
18 * Changed environment variables to live on your saved environments: "This computer" starts clean, existing machine-wide variables are copied into the environments created for you, and the session’s Environment card shows the saved environment you started from.
19 * Changed SSH sessions to stop continuing an interrupted task on their own: select the session in the sidebar to resume it, a stopped task shows a message with Try again instead of nothing to press, and a task dropped when the host’s sign-in expired while the app was closed now says so.
20 * Fixed closing the window with the menu-bar icon turned off (Windows and Linux) stopping running sessions without the "Claude is still working" prompt.
21 * Fixed group delete of Code sessions: when uncommitted changes turn up partway through in a worktree folder the confirmation had not listed, that session is now kept with a notice.
22 * Fixed SSH sessions dropping their connection while idle or loading a large file, failing on hosts that print a notice before file transfer, staying at "Setting up plugins...", asking you to sign in when retrying was enough, and losing earlier messages on Windows hosts using cmd.exe or PowerShell.
23 * Fixed the Files pane losing unsaved edits: leaving the session with Auto save off now prompts first, and a file deleted, moved or changed on disk no longer discards your edits or mishandles the next key press.
24 
25 **Cowork**
26 
27 * Improved computer use on macOS: it no longer saves into hidden folders or types into an app that is not responding, menu commands are no longer reported as disabled after an app was briefly busy, screenshots show under the right step, and text is no longer reported as typed when nothing was.
28 * Fixed a scheduled task created while the task list was still loading overwriting the prompt of an existing task of the same name.
29 * Fixed Claude asking for access to a folder the session already had, which left scheduled runs waiting on an approval nobody was there to give.
30 * Fixed plugin installs, updates and marketplace refreshes sometimes failing or leaving a plugin missing from the list when started right after another, and a removed marketplace leaving an entry behind that could block adding another marketplace with the same name.
31 * Fixed scheduled tasks skipping a tool that an organization’s approval policy marks "ask": the run now shows the approval prompt and waits, and a newer run of the same task retires an earlier run’s unanswered prompt.
32 * Fixed the "Scheduled task failed" notification not appearing when a scheduled task’s sandbox could not start.
33 
34 **3P**
35 
36 * Added `desktopHome` for Unified Claude (beta), which combines Chat and Cowork into one experience, with Cowork’s agentic capabilities: set it to `standard` to turn Unified Claude on, to `off` to turn Chat and Cowork off entirely (Code is not affected), or leave it out of your configuration to stay on the current Chat and Cowork split until November 10, when Unified Claude goes on for all orgs. While the key is set, `chatTabEnabled`, `chatAdvancedFileAnalysisEnabled` and `coworkTabEnabled` have no effect. A value the app does not recognize, such as `Standard`, reads as `off`.
37 * Added `otlpAttrMaxChars`, which sets the length at which Cowork tasks and Code sessions cut captured content, such as a raw API body, in the OpenTelemetry export (256 to 15,000,000 characters; 61,440 when unset).
38 * Added more to what `claudeAiImport.automatic3pImport` brings to a computer’s new organization: Cowork artifacts, projects, memory and global instructions, scheduled tasks from Cowork and Code, uploaded plugins, saved skills, and the optional plugins a user had on from the organization’s plugins directory or a marketplace served from its gateway’s or bootstrap server’s own address.
39 * Added two switches for `desktopHome` to the Setup window’s Allowed surfaces section: "Opt into the new Chat and Cowork unified view" and "Chat and Cowork unified view". While the key is set, Allow Chat, Allow Cowork and Advanced file analysis are hidden (their values are kept), and one "Chat and Cowork unified retention period" sets both retention periods.
40 * Changed `allowedWorkspaceFolders`: in SSH sessions Claude’s file tools can no longer modify a folder marked `ro`, as in a local Code session. Not enforced on Windows hosts, or on a host with Claude Code managed settings of its own; the key’s help text lists the other limits.
41 * Changed `inferenceModels[].prefer1m` and `modelPrefer1mContext`: each model that offers 1M and has the preference now shows as one model picker entry, with no standard entry beside it. New sessions on it use the 1M context window, also for people who had picked the standard entry; sessions already started keep theirs. Before, the preference only moved the starting selection, and only for the first model.
42 * Changed what `claudeAiImport.automatic3pImport` does without asking: the Cowork memory and global instructions it now brings over are used at once, and the scheduled tasks, plugins and skills arrive on or off as they were; only a brought-over project’s instructions wait for the user to accept them before new tasks use them. This can also reach computers that moved under an earlier release, at their first launch on this version.
43 * Removed the "Send to cloud" option from the Code tab’s suggested-task cards, which third-party deployments cannot use.
44 * Fixed a skill switched off in Customize still being offered to Claude and still running when asked for by name, and a skill deleted there still being offered in a Code session that was already running.
45 * Fixed Claude’s file edits in a worktree session sometimes landing in the main checkout or in another session’s worktree, except in SSH sessions on a Linux host over OpenSSH.
46 * Fixed Cowork tasks failing to start on Linux when the memory index is very long.
47 * Fixed the "Can’t reach" connection warning appearing when the inference provider is reachable but slow to respond.
48 * Fixed the command palette’s first row ("New chat" or "New session") not starting a conversation.
49 * Fixed the model picker showing identical rows when the model catalog or an administrator’s model list gives several model ids one name: each such row now shows the part of its id that differs, and its full id on hover.
50 * Fixed the OpenTelemetry export counting sessions nobody opened: background reads of the Code tab’s slash command and agent lists no longer send records or add to `claude_code.session.count`.
51 * Fixed tool calls to an OAuth-authenticated server in `managedMcpServers` failing until the next scheduled token refresh when the server rejected the token early, sometimes with a blank error, and failing for up to 30 minutes after the device came back online from a long offline period.
52</Update>
53 
554<Update label="v2.26454.2" description="2026-10-07">
655 Bundled Claude Code version: 2.1.293.
756 

third-party/claude-desktop/configuration Changed · +30 / -14 lines

from line 300
300300| Setting | Type | Availability | Default | Description |
301301| - | - | - | - | - |
302302| <span id="modeldiscoveryenabled" />Model discovery<br />`modelDiscoveryEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Auto-populate the model picker from the provider at launch. |
303| <span id="modelprefer1mcontext" />Default to 1M context<br />`modelPrefer1mContext` | `boolean` | MDM + Bootstrap<br />Added in 1.28929.0 | — | When a user has no saved selection, start the picker on the 1M-context variant of the default model if it offers one. |
303| <span id="modelprefer1mcontext" />Use 1M wherever it’s available<br />`modelPrefer1mContext` | `boolean` | MDM + Bootstrap<br />Added in 1.28929.0 | — | Every model that offers 1M, in your list or from your gateway, shows one option and requests 1M. |
304304| <span id="inferencemodels" />Model list<br />`inferenceModels` | `object[]` | MDM + Bootstrap<br />Added in 1.2581.0 | — | Override the auto-discovered model list. First entry is the default. |
305305| <span id="defaultmodeleffort" />Default model effort<br />`defaultModelEffort` | `enum` | MDM + Bootstrap<br />Added in 2.110.0 | — | Effort level the default model (the first listed model) starts at, instead of Anthropic’s recommended level: low, medium, high, xhigh or max. One of: `low`, `medium`, `high`, `xhigh`, `max`. |
306306| <span id="alwaysstartwithdefaultmodel" />Always start with the default model<br />`alwaysStartWithDefaultModel` | `boolean` | MDM + Bootstrap<br />Added in 2.110.0 | — | When true, each new conversation or task starts on the default model, and a person’s model and effort changes are no longer saved as their default. |
from line 316
316316 </Accordion>
317317 
318318 <Accordion title="modelPrefer1mContext details">
319 When a user has no saved selection, start the picker on the 1M-context variant of the default model (the first listed model, or the first model your endpoint returns under discovery) if it offers one. A saved selection is always kept; users who picked a model before this version need to pick the 1M row once, after which it persists. Equivalent to setting `prefer1m` on the default entry of `inferenceModels`, but also applies under dynamic discovery.
319 Every model that offers a 1M-token context window shows one option in the model picker, and sessions on it request 1M from your provider. A model offers 1M when its `inferenceModels` entry sets `supports1m` or, under discovery, when your gateway's model list marks it. Equivalent to setting `prefer1m` on each of those entries, but also applies under dynamic discovery. To leave one listed model out, remove its `supports1m`. Beside a model list in which no entry sets `supports1m`, this setting does nothing. Older Claude Desktop versions show both options and only start the default model on its 1M option.
320320 </Accordion>
321321 
322322 <Accordion title="inferenceModels details">
from line 330
330330 [{"name": "claude-sonnet-5", "supports1m": true}, "claude-opus-4-8"]
331331 ```
332332 
333 `"claude-sonnet-5[1m]"` is shorthand for the same entry. When an ID is listed both bare and with `[1m]` (as a gateway lists it), the picker shows one model with a 1M variant; put `labelOverride` on the bare entry (a label on the `[1m]` spelling is ignored there); tier-tagged entries are not folded. `prefer1m: true` (no effect without `supports1m`) makes the 1M variant the default picker selection when this entry is the default model; users can still switch, and an explicit pick is kept. Under dynamic discovery (no explicit list), set `modelPrefer1mContext` instead.
333 `"claude-sonnet-5[1m]"` is shorthand for the same entry. When an ID is listed both bare and with `[1m]` (as a gateway lists it), the picker shows one model with a 1M variant; put `labelOverride` on the bare entry (a label on the `[1m]` spelling is ignored there); tier-tagged entries are not folded. `prefer1m: true` (no effect without `supports1m`) shows only the 1M variant of the model. Under dynamic discovery (no explicit list), set `modelPrefer1mContext` instead.
334334 
335335 **Display label** (`labelOverride`) is for IDs the picker can't derive a friendly name from (Bedrock ARNs, gateway routing aliases). Display-only; `name` is still what the app sends:
336336 
from line 349
349349 | `name` | `string` | — | Model ID exactly as the provider expects it. The first entry is the default model. |
350350 | `labelOverride` | `string` | — | Shown in the model picker. Leave blank to auto-format from the ID. |
351351 | `supports1m` | `boolean` | — | Adds a 1M-context variant of this model to the picker. Set only if the deployment accepts 1M-token context for it. |
352 | `prefer1m` | `boolean` | — | Make the 1M-context variant the default picker selection when this model is the default (first) entry. Users can still choose the standard variant. |
352 | `prefer1m` | `boolean` | — | Shows one option for this model and requests 1M from your provider. Does nothing unless the entry offers 1M. |
353353 | `anthropicFamilyTier` | `enum` | — | Which Claude tier this model stands in for. Pins the bare alias (e.g. ‘opus’) and, for opus/fable, the refusal fallback. One of: `sonnet`, `opus`, `haiku`, `fable`, `mythos`. |
354354 | `isFamilyDefault` | `boolean` | — | When several models share a tier alias, marks this one as the model the alias resolves to. Otherwise the first listed wins. |
355355 | `maxEffort` | `enum` | — | Highest effort level offered for this model; higher levels are hidden and never requested by Claude Desktop. An unrecognized value caps the model at low. One of: `low`, `medium`, `high`, `xhigh`, `max`. |
from line 498
498498| - | - | - | - | - |
499499| <span id="chattabenabled" />Allow Chat<br />`chatTabEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.13576.0 | — | Enable Chat. Quick questions and drafting. |
500500| <span id="chatadvancedfileanalysisenabled" />Advanced file analysis<br />`chatAdvancedFileAnalysisEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.14271.0 | — | Allow Claude to run code in a local sandbox to analyze attached files it can’t read natively — like Excel and PowerPoint. Off by default. |
501| <span id="desktophome" />Desktop home<br />`desktopHome` | `enum` | MDM + Bootstrap<br />Added in 1.52386.0 | — | Unifies Chat and Cowork into one home. When set, it replaces Allow Chat, Advanced file analysis, and Allow Cowork. Leave unset to keep those. One of: `standard`, `off`. |
501502 
502503<AccordionGroup>
503504 <Accordion title="chatAdvancedFileAnalysisEnabled details">
504505 Also enables inline data analysis. The sandbox can only read files attached to the conversation and, read-only, the folders added to the chat's project through the app; it has no network access. Project folders are not available in the sandbox of a chat started while a rule on `Read`, `Grep` or `Glob` is set: in `disabledBuiltinTools`, in `builtinToolPolicy` with a value other than `allow`, or as a deny or ask rule in Claude Code's own managed settings on the device, whether or not the rule covers the folder. They are not available either where those managed settings cannot be read, or where Claude Code takes its managed settings from a gateway. Claude's file tools still read what the rules allow.
505506 </Accordion>
507 
508 <Accordion title="desktopHome details">
509 `standard` turns on Unified Claude, which combines Chat and Cowork into one experience, with Cowork's agentic capabilities. `off` turns Chat, file analysis, and Cowork off. `isClaudeCodeForDesktopEnabled` still decides Code. Remove the key to hand control back to `chatTabEnabled`, `chatAdvancedFileAnalysisEnabled`, and `coworkTabEnabled`. Values are case-sensitive, so `Standard` is not recognized. A value that the app does not recognize is read as `off`, so update the app on devices before you deploy a value added in a later version.
510 </Accordion>
506511</AccordionGroup>
507512 
508513### Code surface
from line 523
518523 <Accordion title="sshHostAllowlist details">
519524 When off, the SSH option is hidden and any connection attempt is refused.
520525 
521 Entries are exact hostnames (`build01.corp.example.com`) or `*.` wildcards (`*.corp.example.com` matches the apex and subdomains at any depth); matching is case-insensitive and ignores a `user@` prefix. Both the host the user entered and the `HostName` their `~/.ssh/config` resolves it to must match, so an alias cannot reach a host outside the list. `ProxyCommand` is permitted when the resolved host matches (this key governs which hosts the app offers, not network egress); `ProxyJump` is permitted likewise on the system-OpenSSH engine (the default on macOS and Linux; see `sshTransport`) and refused, with a message suggesting `ProxyCommand`, by the built-in SSH library.
526 Entries are exact hostnames (`build01.corp.example.com`) or `*.` wildcards (`*.corp.example.com` matches the apex and subdomains at any depth); matching is case-insensitive and ignores a `user@` prefix. The list is compared with the `HostName` that the user's SSH configuration (`~/.ssh/config`) gives for the host they entered, or with the entered host itself when the configuration has no entry for it or cannot be evaluated. So an alias is allowed when the host it points to is listed, whatever the alias is called, and refused when it is not. `ProxyCommand` is permitted when the resolved host matches (this key governs which hosts the app offers, not network egress); `ProxyJump` is permitted likewise on the system-OpenSSH engine (the default on macOS and Linux; see `sshTransport`) and refused, with a message suggesting `ProxyCommand`, by the built-in SSH library.
522527 
523 This is opt-in because a remote session runs Claude Code on the SSH host and the app forwards the session's inference credential to it, plus your OTLP collector endpoint and auth headers when `otlpEndpoint` is set. List only hosts you trust with those. Token-based credentials are forwarded; file-based kinds (Bedrock IAM Identity Center sign-in or AWS profile, Vertex Google sign-in or a credentials file) are refused at session start.
528 This is opt-in because a remote session runs Claude Code on the SSH host and the app forwards the session's inference credential to it, plus your OTLP collector endpoint and auth headers when `otlpEndpoint` is set. List only hosts you trust with those. Token-based credentials are forwarded. File-based credentials (Bedrock IAM Identity Center sign-in or AWS profile, Vertex Google sign-in or a credentials file) are never forwarded, and a session that needs one from the device is refused.
524529 
525 If this key is unset, an `sshHostAllowlist` in Claude Code's own managed-settings file on the device still applies; when both are set, this key wins where the app's configuration is admin-managed (MDM, the admin console, or a device-managed bootstrap URL) and otherwise applies only while that file sets none. `allowedWorkspaceFolders` still applies on the remote host.
530 If this key is unset, an `sshHostAllowlist` in Claude Code's own managed-settings file on the device still applies; when both are set, this key wins where the app's configuration is admin-managed (MDM, the admin console, or a device-managed bootstrap URL) and otherwise applies only while that file sets none. `allowedWorkspaceFolders` still applies on the remote host. Claude Code's managed settings on a host replace the sandbox, network, permission, and MCP rules this app sends unless they set `parentSettingsBehavior` to `"merge"`.
526531 </Accordion>
527532 
528533 <Accordion title="sshClientPath details">
from line 623
618623 <Accordion title="builtinToolPolicy details">
619624 Keys use the same tool names and argument-scoped rule syntax as **Disabled built-in tools** (`disabledBuiltinTools`), and scopes apply in the same sessions. A bare `Bash` key also governs Claude Code's `PowerShell` tool (its shell on Windows PCs without Git for Windows); argument-scoped `Bash(…)` keys do not. Scoped **ask** rules reach sessions only through Claude Code's managed-settings channel, so another Claude Code managed-settings source replaces them unless it sets `parentSettingsBehavior` to `"merge"` (bare names hold either way). They need the same fleet-wide build support, and an older build drops a scoped **ask** entry as a configuration error (which also blocks WSL sessions on Windows until that client updates), so the tool runs unprompted.
620625 
621 An **ask** entry, bare or scoped, also turns off the app's remembered “always allow” choices for that tool, so each prompted call is confirmed individually. **ask** on a file tool (`Read`, `Write`, `Edit`, `Glob`, `Grep`) prompts in Cowork, Chat and Code sessions. Calls that Cowork and Chat always refuse are still refused without a prompt: paths outside the session's connected folders (in Chat, outside its scratch directory and its project's folders) and protected or sensitive files inside them. A Cowork task running unattended (a scheduled run) refuses a call that needs approval rather than waiting for someone to approve it. Code side chats cannot prompt, so they block matching calls. An unusable entry is dropped and recorded as a configuration error; a value other than `allow` or `ask` is treated as `ask` and reported. To remove a tool or deny a rule outright, use **Disabled built-in tools** instead.
626 An **ask** entry, bare or scoped, also turns off the app's remembered “always allow” choices for that tool, so each prompted call is confirmed individually. **ask** on a file tool (`Read`, `Write`, `Edit`, `Glob`, `Grep`) prompts in Cowork, Chat and Code sessions. Calls that Cowork and Chat always refuse are still refused without a prompt: paths outside the session's connected folders (in Chat, outside its scratch directory and its project's folders) and protected or sensitive files inside them. A scheduled task in Cowork waits at the prompt, which appears in the task's session and, when that session is not in view, as a desktop notification. Code side chats cannot prompt, so they block matching calls. An unusable entry is dropped and recorded as a configuration error; a value other than `allow` or `ask` is treated as `ask` and reported. To remove a tool or deny a rule outright, use **Disabled built-in tools** instead.
622627 </Accordion>
623628 
624629 <Accordion title="autoModeEnabled details">
from line 667
662667 | - | - | - | - |
663668 | `path` | `string` | — | Absolute folder path. May start with \~ or one of the listed %VAR% tokens, expanded per user. Subfolders are included. |
664669 | `isDefaultSelected` | `boolean` | — | Shows as a folder chip on the new-task page and skips the trust prompt. Users can remove it. |
665 | `mode` | `enum` | — | Read-only folders can be viewed and searched but not modified in Cowork. In Code, applies to file tools only; Bash and SSH do not yet enforce read-only. One of: `rw`, `ro`. |
670 | `mode` | `enum` | — | Read-only folders can be viewed and searched but not modified in Cowork. In Code, applies to file tools only. Over SSH, also to Bash in its sandbox. One of: `rw`, `ro`. |
666671 </Accordion>
667672 
668673 <Accordion title="blockReadsOutsideWorkingDirectories details">
669 When set to `true`, Code sessions refuse reads outside their working directories (the session folder plus any `allowedWorkspaceFolders`). The file tools (Read, Grep, Glob) refuse them in every permission mode; where Claude Code's sandbox runs (macOS, or Linux and SSH hosts with bubblewrap, once `allowedWorkspaceFolders` or an egress allowlist is also configured) shell commands cannot see the home directory and other user folders (`/Users`, `/home`, mounted volumes) and a read there is refused with no prompt; elsewhere (Windows, Linux without bubblewrap, or neither folders nor an egress allowlist configured) such shell reads prompt for approval. The app keeps the user's git configuration files (which may themselves embed credentials such as URL tokens; a symlinked one stays hidden), its own Claude Code installation, and the session's plugin and attachment folders readable (not on a Windows SSH host, where plugin files and attachments stay out of the file tools' reach under the block). An allowed folder that is or contains the home directory leaves it readable.
674 When set to `true`, Code sessions refuse reads outside their working directories (the session folder plus any `allowedWorkspaceFolders`). The file tools (Read, Grep, Glob) refuse them in every permission mode; where Claude Code's sandbox runs (macOS, or Linux and SSH hosts with bubblewrap, once `allowedWorkspaceFolders` is set or an egress allowlist applies: in third-party deployments one applies unless `coworkEgressAllowedHosts` contains `*`, in first-party deployments none does) shell commands cannot see the home directory and other user folders (`/Users`, `/home`, mounted volumes) and a read there is refused with no prompt; elsewhere (Windows, Linux without bubblewrap, or neither folders nor an egress allowlist in effect) such shell reads prompt for approval. The app keeps the user's git configuration files (which may themselves embed credentials such as URL tokens; a symlinked one stays hidden), its own Claude Code installation, and the session's plugin and attachment folders readable (not on a Windows SSH host, where plugin files and attachments stay out of the file tools' reach under the block). An allowed folder that is or contains the home directory leaves it readable.
670675 
671676 Users can re-open folders (even their whole home) in their own Claude Code settings with `sandbox.filesystem.allowRead` or `permissions.additionalDirectories`; settings files tracked in a git repository cannot. The key travels on Claude Code's managed-settings channel: another Claude Code managed-settings source replaces it unless that source sets `parentSettingsBehavior` to `"merge"`, and one that sets `sandbox.filesystem.allowManagedReadPathsOnly` reduces it to approval prompts. This is `permissions.blockReadsOutsideWorkingDirectories` in Claude Code's [managed settings](https://claude.com/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings).
672677 
from line 761
756761 <Accordion title="managedMcpServers details">
757762 For OAuth-authenticated entries, the app builds the redirect URI as `http://<callbackHost>:<callbackPort>/callback`; register that exact value with the OAuth provider. Tokens refresh automatically during a session.
758763 
759 `toolPolicy` locks the per-tool approval state, keyed by tool name: `"blocked"` removes the tool from the session and labels it admin-blocked, `"ask"` requires approval on every call (Allow once / Deny only; no persistent always-allow), `"allow"` pre-approves. Tools **not listed** follow the user's choice: the prompt offers a persistent Always allow, except for tools that can modify data, which show a session-scoped **Allow for this task** alongside **Allow for all tasks** with a malicious-instruction warning. In Code sessions, `blocked` and `ask` are forwarded as Claude Code permission rules; `allow` is not.
764 `toolPolicy` locks the per-tool approval state, keyed by tool name: `"blocked"` removes the tool from the session and labels it admin-blocked, `"ask"` requires approval on every call (Allow once / Deny only; no persistent always-allow; a scheduled Cowork task waits at that prompt), `"allow"` pre-approves. Tools **not listed** follow the user's choice: the prompt offers a persistent Always allow, except for tools that can modify data, which show a session-scoped **Allow for this task** alongside **Allow for all tasks** with a malicious-instruction warning. In Code sessions, `blocked` and `ask` are forwarded as Claude Code permission rules; `allow` is not.
760765 
761766 Keys may contain `*` wildcards (`"read_*"` matches every tool whose name starts with `read_`; anchored, and `*` is the only wildcard). When several wildcard keys match, the strictest applies (blocked > ask > allow). An exact-name key wins over matching wildcards, with two exceptions in the stricter direction: in Code sessions a wildcard `ask`, or a wildcard `blocked` other than the bare `"*"`, beats a less strict exact key (so `"*": "blocked"` plus exact `"allow"` entries still works as deny-by-default there); and in chat approval prompts and always-allow persistence a wildcard `ask` keeps every matching tool behind a per-call prompt even when a more permissive exact key matches, while direct tool invocations such as artifact or widget calls follow the exact key.
762767 
from line 965
960965| <span id="otlpdesktoploglevel" />Desktop telemetry export level<br />`otlpDesktopLogLevel` | `enum` | MDM + Bootstrap<br />Added in 1.9255.0 | `error` | Controls the Claude Desktop application’s events, separate from Cowork and Code sessions. Defaults to error. One of: `off`, `error`, `warn`, `info`, `debug`. Defaults to `error`. |
961966| <span id="otlpcontentcapture" />Content capture categories<br />`otlpContentCapture` | `enum[]` | MDM + Bootstrap<br />Added in 1.15962.0 | — | Content categories the desktop exporter sends unredacted to your collector. Leave empty to redact all content (default). One of: `userPrompts`, `assistantResponses`, `toolDetails`, `toolContent`, `rawApiBodies`. |
962967| <span id="otlptracesenabled" />Export traces<br />`otlpTracesEnabled` | `boolean` | MDM + Bootstrap<br />Added in 1.22209.0 | — | Also export OpenTelemetry traces from Cowork tasks and Code sessions. Uses Claude Code’s session tracing. |
968| <span id="otlpattrmaxchars" />Telemetry attribute length limit<br />`otlpAttrMaxChars` | `integer` | MDM + Bootstrap<br />Added in 2.31226.0 | — | Maximum length, in characters, of captured content such as a raw API body (256–15,000,000). Cowork tasks and Code sessions use 61,440 when unset. Range: 256–15000000. |
963969 
964970<AccordionGroup>
965971 <Accordion title="otlpProtocol details">
from line 991
985991 * `assistantResponses` — assistant message text
986992 * `toolDetails` — tool input arguments, e.g. the web-search query string
987993 * `toolContent` — tool output content, e.g. fetched page text or command stdout
988 * `rawApiBodies` — full inference API request and response bodies
994 * `rawApiBodies` — inference API request and response bodies, each cut at 61,440 characters by default
989995 
990996 These mirror Claude Code's `OTEL_LOG_*` env vars; see the [Claude Code monitoring docs](https://code.claude.com/docs/en/monitoring-usage).
991997 </Accordion>
from line 998
992998 
993999 <Accordion title="otlpTracesEnabled details">
9941000 Enables Claude Code's session tracing (`CLAUDE_CODE_ENHANCED_TELEMETRY_BETA=1` + `OTEL_TRACES_EXPORTER=otlp`) in spawned Cowork tasks and Code sessions. Each user interaction exports a trace whose spans and events carry `trace_id`/`span_id`, enabling end-to-end correlation in your observability backend (metrics do not carry trace context; correlate those via `session.id`). Traces go to the collector endpoint and protocol configured above. When `otlpEndpoint` is set, this key alone decides whether those sessions export traces: leaving it unset or `false` keeps traces off even if Claude Code's own settings or managed settings (for example a `managed-settings.json` on the device) turn tracing on. Without `otlpEndpoint` it has no effect. The span structure may evolve between Claude Code releases; see the [Claude Code monitoring docs](https://code.claude.com/docs/en/monitoring-usage).
1001 </Accordion>
1002 
1003 <Accordion title="otlpAttrMaxChars details">
1004 Captured content longer than this is cut at the end and marked as truncated.
1005 
1006 * Cowork tasks and Code sessions: 61,440 when unset. Applies to model responses, tool content and raw API bodies. User prompts are not cut, and `tool_input` keeps its own smaller limits. A cut request body keeps the oldest messages and loses the newest, so to capture whole bodies with `rawApiBodies`, set this just above your longest body, not at the maximum. Lower it to reduce volume. While this key and `otlpEndpoint` are set, Claude Code's own settings and managed settings (for example a `managed-settings.json` on the device) cannot change the limit or the export interval.
1007 * Claude add-in for Microsoft 365: 4,000 when unset. Values above 32,000 count as 32,000.
1008 * The desktop application's own events are not affected.
1009 
1010 A collector refuses an export over its size limit, and every event in that export is lost. By default an OpenTelemetry Collector accepts 20 MiB per OTLP/HTTP request (`max_request_body_size`) and 4 MiB per gRPC message (`max_recv_msg_size_mib`). Keep that limit at a few times the size of your longest body: one export can carry several, and a character takes one byte in Latin text and up to three otherwise. With this key set, Code sessions export events as they happen, not every five seconds, as Cowork tasks already do, so the collector sees more, smaller requests.
9951011 </Accordion>
9961012</AccordionGroup>
9971013 

third-party/claude-desktop/configuration-changelog Changed · +28 / -0 lines

from line 4
44 
55Configuration keys by Claude Desktop release. Each section lists keys added in that release, with the MDM key name (for plist/registry deployment) and the equivalent JSON shape (for local-file or bootstrap remote configuration).
66 
7<Update label="v2.31226.0" description="2026-10-08">
8 <div className="cfg-keys">
9 | MDM key | Type | Description |
10 | - | - | - |
11 | [`otlpAttrMaxChars`](/docs/third-party/claude-desktop/configuration#otlpattrmaxchars) | `integer` | Telemetry attribute length limit |
12 | [`desktopHome`](/docs/third-party/claude-desktop/configuration#desktophome) | `enum` | Desktop home |
13 </div>
14 
15 **JSON (e.g. for non-MDM users or Bootstrap):**
16 
17 ```json theme={null}
18 {
19 "otlp": {
20 "attrMaxChars": "<integer>"
21 },
22 "chatSurface": {
23 "desktopHome": "<standard|off>"
24 }
25 }
26 ```
27 
28 **Changed:**
29 
30 * `allowedWorkspaceFolders`: in SSH sessions Claude's file tools can no longer modify a folder marked `ro`, as in a local Code session. Not enforced on Windows hosts, or on a host with Claude Code managed settings of its own (unless they set `parentSettingsBehavior` to `merge`).
31 * `claudeAiImport.automatic3pImport` now also brings over Cowork artifacts, projects, memory and global instructions, scheduled tasks from Cowork and Code, uploaded plugins (unless `userPluginUploadsEnabled` is off), saved skills (unless `skillCreationEnabled` is off) and the optional plugins a user had on from the organization's plugins directory or a marketplace served from its gateway's or bootstrap server's own address, also on computers that moved under an earlier release.
32 * `inferenceModels[].prefer1m` and `modelPrefer1mContext` now show one model picker entry for each model that offers 1M and has the preference, and start its new sessions at 1M, whichever entry a user had picked. Earlier releases only moved the starting selection of the first model.
33</Update>
34 
735<Update label="v2.26454.2" description="2026-10-07">
836 No configuration changes in this release.
937</Update>
Feedback