Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Claude Desktop admin config schema: new keys, stricter validation and a November deprecation

The bundled Claude Desktop admin schema adds dictation, SSH, M365 and stream-timeout keys, validates forceLoginOrgUUID and deprecates allowOptionalClientAuth

Group of 7 You'll notice No documentation found Improvements
JSON All of v2.1.281
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release

What

Claude Code carries a copy of the configuration schema that administrators use to manage Claude Desktop. This schema is the list of admin keys, their allowed values and their descriptions, and it comes from a config package the two apps share. These are mostly Desktop settings. The version numbers below are the Claude Desktop versions each key needs.

New keys:

  • inferenceStreamIdleTimeoutSec: a gateway-only key from 1.44121.1, accepting 300 to 1800 seconds. It maps to Claude Code's CLAUDE_STREAM_IDLE_TIMEOUT_MS for sessions the app starts, and overrides the managed setting.
  • dictationEnabled: from 1.44121.1, marked public-undocumented. If a gateway-served config sets it to true and the gateway has no dictation route, a warning says the dictation control in Claude Desktop will fail and the key should be removed. Dictation no longer turns itself off when allowOptionalClientAuth is true.
  • sshClientPath: from 1.46388.1, behind the sshRemoteSessions beta key. It fails closed if the program is missing.
  • continuousAccessEvaluation: an option for the built-in Microsoft 365 connector, from 1.49585.0, either enabled or disabled, with enabled as the default. It requests Continuous Access Evaluation Graph tokens that last about 28 hours but can be revoked within minutes.
  • disableMultiAccount: "Single account only", marked public-undocumented and first-party only.

Changed keys:

  • forceLoginOrgUUID is now validated. It must be a UUID or a JSON array of UUIDs, and an invalid value fails closed to []. Before, it was a plain optional string.
  • microsoftAuthBroker gains a required value alongside auto and disabled. Desktop builds older than 1.49585.0 treat required as disabled.
  • allowOptionalClientAuth is deprecated in a new batch, BATCH_2026_11. Warnings start on 2026-11-03 and support ends on 2026-11-17. The replacement advice is to run Claude Desktop 1.49585.0 or later on every device, then remove the key.
  • The OTLP protocol hint (OTLP is the format for sending OpenTelemetry monitoring data) gets a long description.

Why

If you administer Claude Desktop, check for allowOptionalClientAuth before the November dates, and check that forceLoginOrgUUID holds a valid UUID or array, because an invalid value now fails closed. Gateway admins get an explicit warning about a dictation setting that cannot work, instead of a silent failure.

Read from
Names in the bundleallowOptionalClientAuth

See this entry in the whole of v2.1.281 →

Feedback