{"version":"2.1.293","anchor":"managed-config-settings-client-secret-helper-and-hosted-con","canonical_anchor":"managed-config-session-retention-group-external-idp-oidc","heading":"Managed configuration: clientSecretHelper must print JSON, OIDC sign-in, session retention and desktop-only fields","tier":"use","area":"MCP","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/managed-config-settings-client-secret-helper-and-hosted-con","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Managed configuration: clientSecretHelper must print JSON, OIDC sign-in, session retention and desktop-only fields\n\nThe MCP clientSecretHelper must now print a JSON object, managed config adds OIDC sign-in and session retention, and Workspace becomes Capabilities\n\n**What**\n\nManaged configuration is the set of settings an administrator defines for an organisation's Claude apps. Its definitions and settings page changed in several places.\n\n- `clientSecretHelper`, a program that hands an MCP server's OAuth client secret to Claude Code, is now described as having to print a JSON object with a single `clientSecret` key and exit with status 0 within 30 seconds. Any other output is rejected and stops the server from connecting. Before, it was described as printing the secret on its own.\n\n- `clientSecret` is now trimmed, and when settings are redacted it is shown as present or absent rather than dropped.\n\n- A new \"Session retention\" group appears under limits.\n\n- A new credential kind, \"Identity provider sign-in (OIDC)\" (`external-idp`), is added, and the gateway kind accepts a `GATEWAY_INTERACTIVE_WITH_IDP` path.\n\n- Many fields, including several Bedrock, Vertex and extension fields, gain `executionTarget: \"desktop\"`.\n\n- The settings page section `Workspace` is renamed `Capabilities`.\n\n- New shared exports include `isCoworkSurfaceEnabled`, `autoModeSurfaces`, `retiredFlatKeyEffect`, `keepsAuthoredEmptyList`, `PROVIDER_SELECTOR_ENV_FLAGS`, `releasedHybridCredentialKinds` and `flatKeysForExecutionTarget`.\n\n- The settings screen opened when a slash command runs with no arguments now receives a `manualDialog` value.\n\n**Why**\n\nAdministrators with a `clientSecretHelper` that prints only the bare secret should change it to print the JSON form, since other output is described as rejected. Organisations can also find OIDC sign-in for gateways and session retention controls in managed configuration.\n\n- Area: MCP\n- Names: `clientSecretHelper`\n- Tier: Use it now\n- Useful: 4\/5\n- Signal: 4\/5\n- Scope: both\n- Heads-up: yes"}