What
Claude Code now contains a filter for credential-helper settings. A credential helper is a setting that names a command Claude Code runs to fetch a key, a login or a header. The filter covers apiKeyHelper, awsAuthRefresh, awsCredentialExport, gcpAuthRefresh, otelHeadersHelper and proxyAuthHelper.
- Every settings source is now passed through the filter before the sources are merged. The filter can remove these keys from a source that is not allowed to supply them.
- New helpers decide whether managed policy settings (
policySettings, the settings an administrator deploys) are treated asmachine_adminoras_read. The choice depends on whether the managed source can be written by an ordinary user. - In
machine_adminmode, the helper keys are removed from the other sources and re-read only from admin-only sources. Remotely delivered settings and MDM sources (device-management profiles) that a user can write to are left out. - A helper is disabled if it was armed from a remote source or from a user-writable base. The new
helperArmedFromUserWritableBasecheck tracks the second case. - In this build, the switch that picks the mode always returns
as_read. The live settings loader also hard-codescredentialHelperKeysFrom: () => "as_read". As a result, no keys are removed yet.
Why
Nothing changes for you today, because settings are still merged exactly as read. The code is built so that, once it is switched on, a credential helper command can come only from managed settings an administrator controls, and not from a settings file an ordinary user can edit.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The finding does not say whether the key-stripping filter is also behind the switched-off check.