Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.282 ·

A malformed strictPluginOnlyCustomization policy now locks down instead of being ignored

An invalid strictPluginOnlyCustomization value in managed settings is now treated as true, and bad payloads are rejected with an error

You'll notice Improvements
JSON All of v2.1.282
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release
What

Claude Code now checks the managed setting strictPluginOnlyCustomization more strictly. Managed settings are settings an organization's administrator deploys to control Claude Code on its computers.

  • A value that is present but invalid is treated as true until it is fixed, so skills, agents, hooks and MCP servers load only from managed settings and plugins.
  • Entries in the list that Claude Code does not recognise produce a warning in the status output.
  • A managed-settings payload whose value is not true, false, a list or empty is rejected with an error saying the value must be true, false, or a list of surface names.
  • The settings validator reports the same problem with a message naming the key and asking you to fix the value.
Why

A typo in an organization's lockdown policy now either tightens the restrictions or gets flagged, instead of quietly leaving skills, agents, hooks and MCP servers open to user and project sources.

Read from
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up strictPluginOnlyCustomization, on Set up Claude Code for your organization. | [Customization lockdown](/docs/en/settings-reference#strictpluginonlycustomization) | Block skills, agents, hooks, and MCP servers from user and project sources, so they can only come from plugins or managed settings. Locking skills also… admin-setup see the edit
Added since A small documentation edit on Code in Claude Desktop on 3P touched a line naming strictPluginOnlyCustomization after this was published. | `allowedPluginMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]` together with an `allowedMcpServers` list holding your entries and `allowManagedMcpServersOnly`, whether or not `managedMcpServers` is set. MCP servers bundled … third-party/claude-desktop/code see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesA small documentation edit on Code in Claude Desktop on 3P touched a line naming strictPluginOnlyCustomization after this was published.

See this entry in the whole of v2.1.282 →

Feedback