What
Managed settings are policies an organisation pushes to Claude Code. A host-managed gateway session is one where both CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST and CLAUDE_CODE_USE_GATEWAY are set. In these sessions, managed settings now behave differently.
parentSettingsBehaviorcontrols whether restrictions passed in by an embedding host, such as the Claude Desktop app, are dropped or merged in. When a managed settings source does not set it, it now defaults to "merge" in a host-managed gateway session with a qualifying entrypoint, such as Claude Desktop's Code tab. Everywhere else it stays "first-wins". The setting's description was updated to match. Before, merging happened only when it was set to "merge" explicitly, or when there were no other managed settings at all.- Remote managed settings are no longer saved to disk in these sessions unless
CLAUDE_CODE_REMOTE_SETTINGS_PATHis set. Reading the disk cache and preparing the storage backend also return early. - When the server replies that the settings have not changed, Claude Code skips writing the signature and skips the reset check under the same condition.
- Each attempt to sign in for the settings fetch is now labelled with its sign-in method:
gateway_jwt,oauth,api_key,profileornone. The gateway fingerprint is only worked out when the token is pinned.
Why
For Claude Desktop gateway users, the host's restrictions now combine with the organisation's policy by default instead of being dropped. These deployments also stop leaving a copy of the organisation's settings on disk.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
When a host platform that embeds Claude Code sets [`CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST`](/docs/en/env-vars), `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` doesn't stop auto mode sessions on Amazon Bedrock, Google Cloud's Agent Platform, Micro…llm-gateway-protocol see the edit
The finding does not say which entrypoints qualify for the new "merge" default.
A small documentation edit on Claude Code gateway compatibility guide touched a line naming CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST after this…