Unclear It is not clear whether these options can be used from the command-line Claude Code or only from the desktop app.
What
Managed configuration is the set of settings an administrator defines for an organisation's Claude apps. Its definitions and settings page changed in several places.
clientSecretHelper, a program that hands an MCP server's OAuth client secret to Claude Code, is now described as having to print a JSON object with a singleclientSecretkey and exit with status 0 within 30 seconds. Any other output is rejected and stops the server from connecting. Before, it was described as printing the secret on its own.clientSecretis now trimmed, and when settings are redacted it is shown as present or absent rather than dropped.- A new "Session retention" group appears under limits.
- A new credential kind, "Identity provider sign-in (OIDC)" (
external-idp), is added, and the gateway kind accepts aGATEWAY_INTERACTIVE_WITH_IDPpath. - Many fields, including several Bedrock, Vertex and extension fields, gain
executionTarget: "desktop". - The settings page section
Workspaceis renamedCapabilities. - New shared exports include
isCoworkSurfaceEnabled,autoModeSurfaces,retiredFlatKeyEffect,keepsAuthoredEmptyList,PROVIDER_SELECTOR_ENV_FLAGS,releasedHybridCredentialKindsandflatKeysForExecutionTarget. - The settings screen opened when a slash command runs with no arguments now receives a
manualDialogvalue.
Why
Administrators with a clientSecretHelper that prints only the bare secret should change it to print the JSON form, since other output is described as rejected. Organisations can also find OIDC sign-in for gateways and session retention controls in managed configuration.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear whether these options can be used from the command-line Claude Code or only from the desktop app.