Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Claude Desktop admin config schema: new keys, stricter validation and a November deprecation

The bundled Claude Desktop admin schema adds dictation, SSH, M365 and stream-timeout keys, validates forceLoginOrgUUID and deprecates allowOptionalClientAuth

Group of 7 Use it now New Features
JSON All of v2.1.281
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
4Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
New FeaturesKind: in v2.1.281,
What probably matters to youSection of the release

What

Claude Code carries a copy of the configuration schema that administrators use to manage Claude Desktop. This schema is the list of admin keys, their allowed values and their descriptions, and it comes from a config package the two apps share. These are mostly Desktop settings. The version numbers below are the Claude Desktop versions each key needs.

New keys:

  • inferenceStreamIdleTimeoutSec: a gateway-only key from 1.44121.1, accepting 300 to 1800 seconds. It maps to Claude Code's CLAUDE_STREAM_IDLE_TIMEOUT_MS for sessions the app starts, and overrides the managed setting.
  • dictationEnabled: from 1.44121.1, marked public-undocumented. If a gateway-served config sets it to true and the gateway has no dictation route, a warning says the dictation control in Claude Desktop will fail and the key should be removed. Dictation no longer turns itself off when allowOptionalClientAuth is true.
  • sshClientPath: from 1.46388.1, behind the sshRemoteSessions beta key. It fails closed if the program is missing.
  • continuousAccessEvaluation: an option for the built-in Microsoft 365 connector, from 1.49585.0, either enabled or disabled, with enabled as the default. It requests Continuous Access Evaluation Graph tokens that last about 28 hours but can be revoked within minutes.
  • disableMultiAccount: "Single account only", marked public-undocumented and first-party only.

Changed keys:

  • forceLoginOrgUUID is now validated. It must be a UUID or a JSON array of UUIDs, and an invalid value fails closed to []. Before, it was a plain optional string.
  • microsoftAuthBroker gains a required value alongside auto and disabled. Desktop builds older than 1.49585.0 treat required as disabled.
  • allowOptionalClientAuth is deprecated in a new batch, BATCH_2026_11. Warnings start on 2026-11-03 and support ends on 2026-11-17. The replacement advice is to run Claude Desktop 1.49585.0 or later on every device, then remove the key.
  • The OTLP protocol hint (OTLP is the format for sending OpenTelemetry monitoring data) gets a long description.

Why

If you administer Claude Desktop, check for allowOptionalClientAuth before the November dates, and check that forceLoginOrgUUID holds a valid UUID or array, because an invalid value now fails closed. Gateway admins get an explicit warning about a dictation setting that cannot work, instead of a silent failure.

Read from
Names in the bundlecontinuousAccessEvaluation
What the documentation says
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up continuousAccessEvaluation, on Claude apps gateway configuration. `blockReadsOutsideWorkingDirectories`, `disableBypassPermissionsMode`, `configRecheckIntervalMinutes`, and `sshClientPath` need Claude Code v2.1.281 or later on the gateway server. So do the `required` value of `microsoftAuthBroker` and th… claude-apps-gateway-config see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up continuousAccessEvaluation, on Claude apps gateway configuration.

See this entry in the whole of v2.1.281 →

Feedback