What probably matters to youSection of the release
What
Admins can list approved plugin marketplaces in allowedPluginMarketplaces and give each an installationPreference such as auto_install or required. An entry that asks for anything other than available is now shown as available, with a config warning, unless it is pinned to an exact version:
A url source needs manifestSha256, a fingerprint of the marketplace file.
Other sources need a full 40-character commit SHA in ref.
The settings documentation and the Cowork third-party config documentation now describe this. The Cowork documentation also changed in other ways:
The network allowlist text says an unreadable value counts as an empty list.
A new "End-user attribution" label appears.
The folder Path field is marked availableInVersion: "1.14271.0".
Why
Managed settings can no longer force-install plugins from a marketplace that is not pinned to an exact version. If you are an admin and your entry is unpinned, it stops auto-installing and only a config warning tells you. Add the pin to restore the behaviour.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up installationPreference, on MCP, plugins, skills, and hooks.This mirrors the installation preference behavior of remote-managed plugins on claude.ai. Changing a plugin's `installationPreference` takes effect at each user's next sync.third-party/claude-desktop/extensionssee the edit
Confirmed sinceAnthropic's documentation has since written up allowedPluginMarketplaces, on Changelog.* Changed `allowedPluginMarketplaces`: a `url` marketplace's `credentialHelper` can print a JSON object of HTTP headers (the form a managed MCP server's `headersHelper` prints), which are sent on every request to that marketplace, in addit…cowork/changelogsee the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up allowedPluginMarketplaces, on Changelog.