Who this is for: IT administrators who install the Claude Code command-line tool on agency devices and connect it to Claude for Government.In Claude for Government, Claude Code is in early access. To request access for your agency, contact your Anthropic representative. A fresh install of Claude Code asks the user to sign in with a claude.ai or Claude Console account. To connect it to Claude for Government instead, each device needs a small managed settings file that sends users to your agency’s Claude for Government sign-in. Everything else that governs Claude Code is set on the Config page in this portal and delivered to Claude Code after the user signs in. This page covers the device side: the managed settings, where to put them on each operating system, how a user signs in, and how to confirm a device is set up. Claude Code built into Claude Desktop (the Code tab) is configured through Claude Desktop instead, as Connect Claude Desktop to Claude for Government describes.
Before you begin
- Claude Code is turned on for the organization. A tenant administrator or organization owner turns on the Claude Code switch under Product availability on the Config page. It is off by default, and while it is off Claude Code exits right after the user signs in.
- User accounts exist. Claude Code signs users in to the same accounts as this portal. Each user needs a routing rule that covers them and a seat tier with at least one model enabled.
- Claude Code is current. This setup requires Claude Code 2.1.267 or later (
claude --version). - Claude Desktop is current. Update Claude Desktop to the supported version before turning on Claude Code for the terminal.
- Devices can reach Claude for Government. Claude Code must reach the gateway address over HTTPS on port 443, and the user’s browser must reach the Claude for Government host, its sign-in service, and your agency’s identity provider, the same hosts that Claude Desktop sign-in needs.
- You can place a system-level file or policy. The settings count only from a system-level location: a file in a system directory, a macOS configuration profile, or a machine-level Windows registry policy. Deliver them through your device management system or by hand with administrator rights.
The managed settings
Claude Code reads device-level policy from what it calls managed settings. For Claude for Government they contain two keys that turn on gateway sign-in, anenv block, and one key recommended on devices that also run Claude Desktop.
As a
managed-settings.json file:
<claude-for-government-gateway-address> with it so the value is the full address starting with a single https://, including any path. The address is the same for every device and contains no credentials, so one file serves your whole fleet.
Claude Code honors the two sign-in keys only from a system-level location and ignores them in a user’s own settings or a per-user registry policy.
Before sign-in
Your organization’s settings reach Claude Code only after a user has signed in. Until then, the first four variables keep Claude Code’s release-notes download, update checks, automatic setup of the official plugin marketplace, and usage telemetry and error reporting to Anthropic off from the first launch. After sign-in the organization’s settings keep them off. The last four variables are required as shown.ANTHROPIC_CUSTOM_HEADERS and CLAUDE_CODE_EXTRA_BODY set to empty strings keep extra request headers and extra request body fields off. NODE_TLS_REJECT_UNAUTHORIZED set to "1" keeps certificate checking on. NODE_EXTRA_CA_CERTS names your agency’s certificate authority bundle if your devices need one, and is otherwise left empty.
For what each variable controls, see Environment variables in the Claude Code documentation.
Optional: web proxy settings in the managed settings
If your devices use a web proxy that you manage, addHTTPS_PROXY and HTTP_PROXY (the proxy’s address, for example http://proxy.example.gov:8080) and NO_PROXY (your bypass list, keeping localhost, 127.0.0.1, and ::1) to the same env block, each under both its uppercase and lowercase name. Claude Code then uses that proxy wherever the device connects from, in place of any other proxy setting on the device. If your devices connect directly, leave these variables out rather than setting them to empty strings, because an empty value switches off a proxy a user would otherwise use. On a device that also runs Claude Desktop, Claude Desktop applies the same proxy values to the sessions it runs, as Interaction with Claude Code managed settings describes.
Deploy the settings
Deliver the settings through your device management system wherever you can, and before users start Claude Code for the first time, so that their first launch lands on the Cloud gateway screen. Claude Code reads managed settings when it starts; a user who had it open when the settings arrived quits and starts it again. Use one location per device. If a device receives more than one, Claude Code uses the macOS profile or machine-level Windows policy and ignores the file.macOS
Place the JSON above at/Library/Application Support/ClaudeCode/managed-settings.json, or deploy a configuration profile that sets the same top-level keys in the com.anthropic.claudecode managed preferences domain, with env as a dictionary of strings.
Windows
Place the JSON above atC:\Program Files\ClaudeCode\managed-settings.json, or deliver it as machine policy: a string (REG_SZ) value named Settings under HKLM\SOFTWARE\Policies\ClaudeCode whose data is the whole JSON document on one line. As a .reg file:
HKEY_CURRENT_USER does not turn on gateway sign-in.
Linux and Windows Subsystem for Linux
On Linux, place the JSON above at/etc/claude-code/managed-settings.json (root required).
Claude Code inside Windows Subsystem for Linux (WSL) reads that same path inside each distribution. To manage the setting from Windows instead, add "wslInheritsWindowsSettings": true to the machine-level Windows policy or file alongside the keys above; Claude Code inside WSL then reads the Windows settings first and needs no file inside the distribution.
A single machine set up by hand
To try the setup before a fleet rollout, create the file at the path for the machine’s operating system from an administrator account, then start Claude Code as an ordinary user.Sign in
With the settings in place, a user’s first sign-in on a device goes as follows.1
Start Claude Code
The user runs
claude in a terminal. After the first-run theme choice, the Cloud gateway screen shows the gateway address, and the user presses Enter to connect.2
Confirm the gateway certificate
The first time each user connects from a device, Claude Code shows the first 16 characters of the gateway’s TLS certificate fingerprint (SHA-256) and asks them to trust it. Publish the expected fingerprint to your users with the rollout (they compare it ignoring colons and letter case), and again when Anthropic renews the certificate, because users are asked again after a renewal. Your Anthropic representative provides it.
3
Finish sign-in in the browser
Claude Code opens the Claude for Government sign-in page in the default browser and shows a one-time code in the terminal. The user signs in with your identity provider, checks that the code on the page matches the terminal, and approves.
4
Return to the terminal
If the terminal shows Signed in to Cloud gateway as followed by the user’s email address, the user confirms with Yes, continue. The terminal then shows Connected to Cloud gateway, and Claude Code downloads the organization’s settings and restarts to apply them. If those settings include items Claude Code asks users to approve, such as a Telemetry endpoint, it shows a Managed settings require approval prompt the first time and whenever those settings change; No exits Claude Code. Unattended runs such as
claude -p apply the settings without prompting./login.
Confirm it worked
Run through these checks on one configured device before the wider rollout.1
Check the sign-in screen
Start
claude as a user who has not signed in. The only sign-in option is the Cloud gateway screen showing your gateway address. If Claude Code offers claude.ai or Claude Console sign-in instead, the managed settings did not reach it.2
Check the background connections are off
Before signing in, run
claude doctor. On the standard installer it reports auto-updates as disabled by CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC, which shows the env block reached Claude Code. (Homebrew, WinGet, and Linux package installs report updates as managed by the package manager instead.)3
Check the setting sources
After sign-in, run
/status inside Claude Code. The API provider reads Cloud gateway with your gateway address, and Setting sources lists Enterprise managed settings (remote).4
Check that organization settings arrived
Change one visible Claude Code setting on the Config page for a test organization, start a new Claude Code session as a member of it, and confirm the change took effect.
Troubleshooting
Things to know
- Only the gateway sign-in described on this page delivers the organization’s settings to Claude Code.
- A claude.ai sign-in left on a device from earlier use is ignored once these settings are in place. A leftover
ANTHROPIC_API_KEY,ANTHROPIC_AUTH_TOKEN,apiKeyHelper, or saved Claude Console key is not: until the user has signed in through the gateway, Claude Code stops and asks for its removal, as Troubleshooting describes. - Where the Claude Code extension for VS Code is used, have users remove an earlier claude.ai sign-in with
claude auth logoutor the extension’s Claude Code: Logout command before they sign in through the gateway, not after: both commands clear every credential Claude Code has stored, the gateway sign-in included. - To take a device out of this setup, have its users sign out with
claude auth logoutbefore you remove the settings. - After sign-in, the organization’s settings turn off the Claude Code settings that run a helper command (
apiKeyHelper,proxyAuthHelper,awsAuthRefresh,awsCredentialExport,gcpAuthRefresh,otelHeadersHelper), wherever it is set. If your devices reach the network through a proxy that needs a helper command to authenticate, raise this with your Anthropic representative before you deploy. - With these settings Claude Code does not check for or install updates in the background. Distribute new versions through your software deployment tooling, or have users run
claude update(standard installer) or their package manager. - Code sessions inside Claude Desktop sign in through Claude Desktop, not through these settings, but on a device that has this file its
envblock applies to them too, andparentSettingsBehaviorset to"merge"keeps Claude Desktop’s own restrictions in force alongside it.