{"version":"2.1.281","anchor":"remote-managed-settings-are-not-written-to-disk-when-the-pro","canonical_anchor":"remote-managed-settings-are-not-written-to-disk-when-the-pro","heading":"Managed settings in host-managed gateway sessions: merge by default and no disk cache","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/remote-managed-settings-are-not-written-to-disk-when-the-pro","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Managed settings in host-managed gateway sessions: merge by default and no disk cache\n\nIn host-managed gateway sessions, parentSettingsBehavior defaults to merge and remote managed settings are no longer cached on disk\n\n**Unclear.** The finding does not say which entrypoints qualify for the new \"merge\" default.\n\n**What**\n\nManaged settings are policies an organisation pushes to Claude Code. A host-managed gateway session is one where both `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` and `CLAUDE_CODE_USE_GATEWAY` are set. In these sessions, managed settings now behave differently.\n\n- `parentSettingsBehavior` controls whether restrictions passed in by an embedding host, such as the Claude Desktop app, are dropped or merged in. When a managed settings source does not set it, it now defaults to \"merge\" in a host-managed gateway session with a qualifying entrypoint, such as Claude Desktop's Code tab. Everywhere else it stays \"first-wins\". The setting's description was updated to match. Before, merging happened only when it was set to \"merge\" explicitly, or when there were no other managed settings at all.\n\n- Remote managed settings are no longer saved to disk in these sessions unless `CLAUDE_CODE_REMOTE_SETTINGS_PATH` is set. Reading the disk cache and preparing the storage backend also return early.\n\n- When the server replies that the settings have not changed, Claude Code skips writing the signature and skips the reset check under the same condition.\n\n- Each attempt to sign in for the settings fetch is now labelled with its sign-in method: `gateway_jwt`, `oauth`, `api_key`, `profile` or `none`. The gateway fingerprint is only worked out when the token is pinned.\n\n**Why**\n\nFor Claude Desktop gateway users, the host's restrictions now combine with the organisation's policy by default instead of being dropped. These deployments also stop leaving a copy of the organisation's settings on disk.\n\n- Area: Managed Settings\n- Names: `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST`, `CLAUDE_CODE_USE_GATEWAY`, `CLAUDE_CODE_REMOTE_SETTINGS_PATH`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}