{"version":"2.1.284","anchor":"managed-permissions-policy-marketplace-npm-sources-must-pin","canonical_anchor":"managed-permissions-policy-marketplace-npm-sources-must-pin","heading":"Admin-only permission rules require npm plugin marketplaces to pin a registry","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/managed-permissions-policy-marketplace-npm-sources-must-pin","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Admin-only permission rules require npm plugin marketplaces to pin a registry\n\nWith `allowManagedPermissionRulesOnly` set, npm-based marketplaces keep their plugins' allowed-tools only when a registry is pinned\n\n**Unclear.** The rule is stated in the settings descriptions, and where Claude Code enforces it is not settled.\n\n**What**\n\n`allowManagedPermissionRulesOnly` is a managed setting. Managed settings are pushed by an organisation's administrators, and this one makes them the only place permission rules can come from. When it is set, the settings now describe an extra condition for plugin marketplaces. A marketplace is a catalogue that plugins are installed from.\n\n- Marketplace source: a marketplace defined in settings keeps its plugins' allowed-tools only when every npm entry pins a `registry` on a bare package name. Allowed-tools is the list of tools a plugin may use without asking.\n\n- Registry field: an npm marketplace keeps plugin allowed-tools only when the policy entry and the marketplace registration both pin the same registry.\n\nWhile the setting is on, marketplace sync also downloads the marketplace again every time. It no longer skips the download when the server reports that nothing has changed.\n\n**Why**\n\nAdministrators who rely on npm-sourced plugin marketplaces can lose those plugins' tool grants unless they pin a registry. Check your managed configuration if plugins stop getting the tools they had before.\n\n- Area: Permissions\n- Names: `allowManagedPermissionRulesOnly`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}