{"version":"2.1.296","anchor":"gateway-probe-managed-settings-fetch-uses-a-status-only-req","canonical_anchor":"gateway-probe-managed-settings-fetch-uses-a-status-only-req","heading":"Managed settings gain a gateway probe and signed proof of absence","tier":"internal","area":"Gateway","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296\/e\/gateway-probe-managed-settings-fetch-uses-a-status-only-req","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296","markdown":"### Managed settings gain a gateway probe and signed proof of absence\n\nNew managed-settings plumbing can detect a gateway serving \/managed\/settings and verify signed documents saying no settings exist, with an expiry\n\n**Unclear.** Nothing was seen using this check, so whether it runs at all in this version is not known.\n\n**What**\n\nManaged settings are settings an organisation pushes to Claude Code. Two new pieces deal with where they come from:\n\n- A gateway probe requests `\/managed\/settings` in a status-only mode, with a custom User-Agent (`claude-cli\/<version> (external, ...)`), `If-None-Match: *` and no-cache headers, and closes the response after reading the headers. It decides a gateway owns the settings only when an `x-cc-gateway-version` header is present and `cache-control` contains no-store. A 304 answer counts as yes, a 404 as no, and anything else as unknown. No caller of the probe was traced, so it may not be in use yet.\n\n- The signature check for managed settings and plugins now accepts a second kind of document saying that no settings exist (an absence document), with an `abs` flag, an optional `exp` expiry and a `plan`. A valid result now says whether it is an absence or a normal document.\n\n- New failure reasons are `unsupported_version` and `abs_mismatch`.\n\n- The window for treating a document as fresh is now capped by the document's own expiry, not only a fixed maximum age per type.\n\n**Why**\n\nThis is groundwork. It lets Claude Code verify that an organisation truly has no managed settings, for a limited time, and work out whether a gateway is serving them.\n\n- Area: Gateway\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: org\n- Heads-up: no"}