Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Managed plugin marketplaces must be pinned to auto-install or be required

Admin marketplace entries asking for auto_install or required are treated as available, with a warning, unless pinned by commit SHA or manifestSha256

Group of 3 Use it now Improvements
JSON All of v2.1.281
Use it nowTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.281,
What probably matters to youSection of the release

What

Admins can list approved plugin marketplaces in allowedPluginMarketplaces and give each an installationPreference such as auto_install or required. An entry that asks for anything other than available is now shown as available, with a config warning, unless it is pinned to an exact version:

  • A url source needs manifestSha256, a fingerprint of the marketplace file.
  • Other sources need a full 40-character commit SHA in ref.

The settings documentation and the Cowork third-party config documentation now describe this. The Cowork documentation also changed in other ways:

  • The network allowlist text says an unreadable value counts as an empty list.
  • A new "End-user attribution" label appears.
  • The folder Path field is marked availableInVersion: "1.14271.0".

Why

Managed settings can no longer force-install plugins from a marketplace that is not pinned to an exact version. If you are an admin and your entry is unpinned, it stops auto-installing and only a config warning tells you. Add the pin to restore the behaviour.

Read from
What the documentation says
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up installationPreference, on MCP, plugins, skills, and hooks. This mirrors the installation preference behavior of remote-managed plugins on claude.ai. Changing a plugin's `installationPreference` takes effect at each user's next sync. third-party/claude-desktop/extensions see the edit
Confirmed since Anthropic's documentation has since written up allowedPluginMarketplaces, on Changelog. * Changed `allowedPluginMarketplaces`: a `url` marketplace's `credentialHelper` can print a JSON object of HTTP headers (the form a managed MCP server's `headersHelper` prints), which are sent on every request to that marketplace, in addit… cowork/changelog see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up allowedPluginMarketplaces, on Changelog.

See this entry in the whole of v2.1.281 →

Feedback