2026-08-21
No configuration changes in this release.
2026-08-20
No configuration changes in this release.
2026-08-18
managedMcpServers[].oauthaccepts a newmodevalue,hosted: the app signs in to that MCP server with an Anthropic-hosted client identity (Anthropic vouches for the client on each token request) instead of a client you register yourself, pinned to the exact issuer URL(s) you list inauthorizationServer; it requires the Claude.ai sign-in and is available once the hosted signer is enabled for your organization.
2026-08-18
No configuration changes in this release.
2026-08-17
- Breaking: Managed-config URL settings now reject values that embed credentials (
https://user:password@host…). Configurations that relied on this fail to load until the credentials are removed; usebootstrapHeaders/bootstrapHeadersHelper(available from 1.32885.1) to send authentication instead. allowedPluginMarketplaces[].source(beta) accepts a newurlvalue: a hostedmarketplace.jsonwhose plugins are zip archives, fetched over HTTPS with no git on the device; seturlto the manifest address (repo,ref, andpathdo not apply).allowedPluginMarketplaces[].credentialKind(beta) accepts a newinferenceCredentialvalue, forurlmarketplaces on the inference gateway’s own origin: fetches carry the same bearer credential the app already sends the gateway for inference.
2026-08-14
No configuration changes in this release.
2026-08-13
inferenceBedrockBaseUrlandinferenceVertexBaseUrl: only affects users who entered the bootstrap server URL themselves (in Settings or a local config file). Those users are now asked once to allow a Bedrock or Vertex endpoint that server delivers (and again if it changes) before it takes effect, the sametrustBootstrapDeliveryconsent promptinferenceGatewayBaseUrlalready shows; the provider’s default endpoint is used until they allow it. Managed deployments (bootstrap URL set by device management, ortrustBootstrapDelivery: true) see no change.
2026-08-11
inferenceGatewayBaseUrldelivered by a bootstrap server now goes through thetrustBootstrapDeliveryconsent prompt: unless the bootstrap URL came from device management ortrustBootstrapDeliveryistrue, each user is asked once to allow the address, and again if it changes, before it takes effect.
2026-08-06
trustBootstrapLocalExec was renamed to trustBootstrapDelivery; the previous name is still accepted.2026-08-04
claudeAiImport,deploymentDisplayName, anddeploymentDisplaySubtitlenow accept values from MDM and a local configuration file as well as a bootstrap server, anddisableDeepLinkRegistration,microsoftAuthBroker,userContentRendererUrl,inferenceFoundryTenantId,inferenceFoundryClientId,inferenceCredentialHelper(with its TTL, timeout, and silent-refresh keys),inferenceBedrockProfile,inferenceBedrockAwsDir,inferenceBedrockAwsCliPath, andinferenceVertexCredentialsFilecan now be delivered by a bootstrap server. The keys that name a local executable go through thetrustBootstrapLocalExecconsent prompt.managedMcpServersgains a built-ingithubserver: setservertogithuband supply your own GitHub OAuth app client ID with the device flow enabled. The newhost,toolsets, andreadOnlysubfields point the connector at a GitHub Enterprise Server instance, choose which toolsets load, and offer read tools only.managedMcpServers[].oauth.authFlowis a new subfield that lets a managed connector sign in through the operating system’s Microsoft Entra account broker on Windows and macOS, so Conditional Access policies that require a managed device no longer block it. Devices without a broker keep using browser sign-in.enduserAttributionis renamed to the corrected spellingendUserAttribution. The previous spelling is still accepted and now records a configuration warning.organizationPluginsUrlis deprecated and removed from the configuration reference. The key is still honored, but organization plugins are better configured withallowedPluginMarketplaces.
2026-08-03
No configuration changes in this release.
2026-07-24
2026-07-21
2026-07-19
No configuration changes in this release.
2026-07-16
2026-07-16
No configuration changes in this release.
2026-07-14
chatTabEnabledandchatAdvancedFileAnalysisEnabledare no longer Beta: the Chat tab and advanced file analysis are generally available. Availability and defaults are unchanged, and both remain opt-in.orgPluginSettings[].tools.permissionaccepts a newask-sessionvalue. In this release the value is accepted but behaves asask(a prompt on every use); the once-per-session approval flow is not yet enabled.
2026-07-14
No configuration changes in this release.
2026-07-09
No configuration changes in this release.
2026-07-07
isDesktopExtensionEnabled— default changed fromtruetofalse: Desktop Extensions (.dxt,.mcpb) no longer load unless explicitly enabled.allowedPluginMarketplaces(beta) — can now be delivered per-user through the bootstrap server; previously MDM-only.
2026-07-07
No configuration changes in this release.
2026-07-02
Removed:
disableDefaultPlugins— third-party deployments always skip the default plugin marketplaces and standard deployments always include them, so the key no longer has an effect.
2026-07-01
No configuration changes in this release.
2026-06-30
2026-06-30
No configuration changes in this release.
2026-06-26
No configuration changes in this release.
2026-06-25
2026-06-23
No configuration changes in this release.
2026-06-18
betaFeaturesEnabled— Allow beta features (added and deprecated in this release)
2026-06-16
2026-06-11
2026-06-03
2026-06-02
2026-05-27
2026-05-25
2026-05-19
2026-05-16
2026-05-08
2026-05-06
2026-04-29
2026-04-28
2026-04-21
2026-04-16
requireCoworkFullVmSandbox— Require full VM sandbox