Claude Desktop
com.anthropic.claudefordesktop
Claude Desktop enterprise configuration settings
Configuration Keys (52)
| Key | Type | Title |
|---|---|---|
forceLoginOrgUUIDRequire login to belong to a specific organization. Accepts a single UUID string, which also pre-selects that organization during login, or an array of UUIDs where any listed organization is accepted without pre-selection. Login fails if the authenticated account does not belong to a listed organization. | array | Force Login Organization UUID(s) |
| string | Organization UUID |
disableAutoUpdatesDisable automatic updates for Claude Desktop. Default: false | boolean | Disable Auto Updates |
autoUpdaterEnforcementHoursHours before forcefully restarting Claude to apply a prepared update. Must be between 1 and 72 hours. Default: 72 Range: 1 – 72 | integer | Auto Update Enforcement Hours |
updateViaUpdatesHostRead the update feed from releases.claude.com so api.anthropic.com can stay blocked. Defaults to false. Default: false | boolean | Check for updates on releases.claude.com |
relaunchEnforcementHoursHours a user may keep working on the old configuration after a managed-configuration change is detected. 0 = restart required at once. Blank = 24 hours. Defaults to 24. Range: 0-336. Default: 24 Range: 0 – 336 | integer | Configuration relaunch window |
configRecheckIntervalMinutesMinutes between the running app's checks for a changed managed configuration. Blank = 10 minutes. Defaults to 10. Range: 2-30. Default: 10 Range: 2 – 30 | integer | Configuration re-check interval |
isDesktopExtensionEnabledEnable or disable Claude Desktop extensions. Default: true | boolean | Enable Desktop Extensions |
isDesktopExtensionDirectoryEnabledEnable or disable access to the extension directory. Default: true | boolean | Enable Extension Directory |
isLocalDevMcpEnabledEnable or disable local Model Context Protocol (MCP) servers. Default: true | boolean | Enable Local MCP Servers |
isClaudeCodeForDesktopEnabledEnable Claude code access in desktop. Default: true | boolean | Enable Claude Code for Desktop |
secureVmFeaturesEnabledEnable Cowork access in desktop Default: true | boolean | Enable Secure VM Features |
coworkTabEnabledEnable Cowork. Claude works on longer tasks like research, analysis, and documents. Defaults to true. Default: true | boolean | Allow Cowork |
builtinBrowserEnabledClaude Desktop on third-party inference deployments. Enable the built-in browser in Cowork and Code sessions. False disables the browser pane; Code retains its localhost-only dev-server preview. Defaults to false. When bootstrapUrl is set, configure this key in the served configuration. Default: false | boolean | Enable Built-in Browser |
builtinBrowserDefaultDomainPolicyClaude Desktop on third-party inference deployments. Default policy for sites Claude may open, read, or act on when the built-in browser is enabled. Allowed domains are exceptions under block; blocked domains are exceptions under allow. Users can still view sites denied to Claude. Defaults to allow. Default: "allow" Range: Allow Sites by Default (allow), Block Sites by Default (block) | string | Built-in Browser Default Site Policy |
builtinBrowserAllowedDomainsClaude Desktop on third-party inference deployments. Sites Claude may open, read, or act on when builtinBrowserDefaultDomainPolicy is block; ignored under allow. Empty or unset allows no external sites for Claude. Users can still view other sites. Bare * and public-suffix wildcards are ignored. | array | Built-in Browser Allowed Domains |
A hostname or supported hostname wildcard. A plain hostname also matches its www form, but no other subdomain. | string | Domain |
builtinBrowserBlockedDomainsClaude Desktop on third-party inference deployments. Sites Claude may not open, read, or act on when builtinBrowserDefaultDomainPolicy is allow; ignored under block. Empty or unset adds no blocked sites. Users can still view blocked sites. * blocks every external site for Claude; localhost dev servers are unaffected. | array | Built-in Browser Blocked Domains |
A hostname or supported hostname wildcard. A plain hostname also matches its www form, but no other subdomain. | string | Domain |
microsoftAuthBrokerSet to “disabled” to force browser-based Microsoft 365 sign-in instead of the native Company Portal / Windows account broker. One of: auto, disabled. Defaults to auto. Default: "auto" Range: Auto (auto), Disabled (disabled) | string | Microsoft 365 native sign-in broker |
isDesktopExtensionSignatureRequiredWhen true, Claude Desktop rejects extensions that aren't signed by a trusted publisher. Default: false | boolean | Require Signed Desktop Extensions |
disabledBuiltinToolsRemoves the listed built-in tools from the available set in Claude Desktop. Known tools: Task, Bash, Glob, Grep, Read, Edit, Write, NotebookEdit, WebFetch, TodoWrite, WebSearch, Skill, REPL, JavaScript, AskUserQuestion. ToolSearch and SendUserMessage are also available under specific conditions. | array | Disabled Built-in Tools |
disabledBuiltinToolsItemName of a built-in tool to disable. | string | Tool |
managedMcpServersDistributes remote MCP (Model Context Protocol) servers to users. Each entry requires a unique name and an HTTPS URL. Optional fields include transport, headers, OAuth, and tool-level policies. Used in Claude Cowork deployments on third-party platforms (Bedrock, Vertex AI, Azure AI Foundry, LLM gateways). | array | Managed MCP Servers |
managedMcpServersItem | dict | Managed MCP Server |
namerequiredUnique name identifying this MCP server. | string | Name |
urlrequiredHTTPS URL of the remote MCP server. | string | URL |
transportTransport protocol used to reach the MCP server. Default: "http" Range: HTTP (http), SSE (sse) | string | Transport |
headersStatic request headers used to authenticate to the MCP server (for example, Authorization). Mutually exclusive with the OAuth field. | dict | Headers |
{{key}} | string | Header Name |
{{value}} | string | Header Value |
oauthWhen true, Claude Desktop runs a PKCE OAuth flow at first use to acquire user credentials. Mutually exclusive with the Headers field. Default: false | boolean | OAuth |
toolPolicyMaps tool names exposed by the MCP server to a policy. Allowed values per tool: allow, ask, blocked. The "ask" policy prompts the user to confirm before the tool runs. | dict | Tool Policy |
{{key}} | string | Tool Name |
{{value}}Range: Allow (allow), Ask (ask), Block (blocked) | string | Policy |
mcpPersistentAlwaysAllowEnabledOffer the persistent “Always allow” approval options for MCP tools. Disable to keep tool approvals per-call or session-scoped only. Defaults to true. Default: true | boolean | Allow persistent tool approvals |
mcpToolTimeoutSecPer-call timeout for MCP tool calls, in seconds. Default 180 (3 minutes). Range: 60-3600. Default: 180 Range: 60 – 3600 | integer | MCP tool call timeout |
deploymentOrganizationUuidA UUID you generate. Tags telemetry so Anthropic support can locate your fleet's events, and namespaces each user's local data. Not used for auth. | string | Organization UUID |
disableEssentialTelemetryCrash and performance reports to Anthropic. Defaults to false. Default: false | boolean | Block essential telemetry |
disableNonessentialTelemetryProduct-usage analytics and diagnostic-report uploads. No message content. Defaults to false. Default: false | boolean | Block nonessential telemetry |
disableNonessentialServicesConnector favicons and the artifact-preview and MCP Apps widget iframe origins. Artifacts will not render. Defaults to false. Default: false | boolean | Block nonessential services |
effortLevelSets the default effort level for Claude Code sessions in Claude Desktop. Default: "high" Range: Low (low), Medium (medium), High (high), Extra High (xhigh), Max (max) | string | Effort Level |
allowedWorkspaceFoldersFolders where Claude may work. Applies to both Cowork and Code sessions. Leave unset for unrestricted access. Paths can reference ~ and these environment variables, expanded per user: %OneDrive%, %OneDriveCommercial%, %OneDriveConsumer%, %APPDATA%, %LOCALAPPDATA%, %USERNAME%, %XDG_DOCUMENTS_DIR%. The set is fixed; an entry that references any other %VAR%, or one that is unset on the device, is ignored. | array | Allowed Workspace Folders |
AllowedWorkspaceFolderItem | dict | — |
pathAbsolute folder path. May start with ~ or one of the listed %VAR% tokens, expanded per user. Subfolders are included. | string | Path |
isDefaultSelectedShows as a folder chip on the new-task page and skips the trust prompt. Users can remove it. Default: false | boolean | Select Default |
modeRead-only folders can be viewed and searched but not modified in Cowork. In Code, applies to file tools only; Bash and SSH do not yet enforce read-only. One of: rw, ro. Range: Read/write (rw), Read only (ro) | string | Mode |
disableBypassPermissionsModeRemove the bypass permissions mode from Code sessions and Cowork tasks, so Claude always follows the permission policy. Off by default. Default: false | boolean | Disable bypass permissions mode |
blockReadsOutsideWorkingDirectoriesKeep Claude from reading files outside a Code session's working directories. File tools refuse such reads; sandboxed shell commands lose the home directory. Default: false | boolean | Block reads outside working directories |
disableDeploymentModeChooserUsers see only this provider at the login screen. The option to sign in to Claude.ai is hidden. Defaults to false. Default: false | boolean | Disable Claude.ai sign-in |
disableDeepLinkRegistrationStop external apps and websites from opening Claude Desktop via claude:// links. Defaults to false. Default: false | boolean | Disable claude:// deep-link handling |
chatTabEnabledEnable Chat. Quick questions and drafting. Default: true | boolean | Allow Chat |
chatAdvancedFileAnalysisEnabledAllow Claude to run code in a local sandbox to analyze attached files it can't read natively — like Excel and PowerPoint. Off by default. Default: false | boolean | Advanced file analysis |
inferenceMaxTokensPerWindowPer-user soft cap, counted client-side over the token cap window. Not a server-enforced quota. Requires inferenceTokenWindowHours to also be set — without a window length the cap is inert and no limit is enforced. | integer | Max tokens per window |
inferenceTokenWindowHoursTumbling window length for the token cap. Max 720 hours (30 days). Range: 1-720. Required when inferenceMaxTokensPerWindow is set — the cap only takes effect once both are configured. Range: 1 – 720 | integer | Token cap window |
endUserAttributionShow the signed-in user's identity-provider identity in the sidebar and account menu, and emit it as the OpenTelemetry enduser.id resource attribute. Default: false | boolean | End-user attribution |
deploymentDisplayNameOverrides the provider label shown in the sidebar footer, user-menu header, and connection-error banner. | string | Deployment display name |
deploymentDisplaySubtitleOptional detail shown after the deployment display name in the account-menu header. | string | Deployment display subtitle |
disableConfigDeprecationWarningsDon't show users the in-app warning that this configuration uses a deprecated field. The final reminder in the 24 hours before the cut-off still appears. Default: false | boolean | Hide configuration deprecation warnings |
bannerA persistent banner across the top of the app window after sign-in. | dict | Organization banner |
enabledTurns the banner on or off. Default: false | boolean | Enabled |
textText shown in the banner. | string | Text |
backgroundColorBanner background color, as a hex code. | string | Background color |
textColorBanner text color, as a hex code. | string | Text color |
linkUrlURL the banner links to when clicked. | string | Link URL |
disableFeatureDiscoverySuppress unprompted feature-announcement UI: the post-update “What's new” nudge and new-feature tips. Users can still open release notes themselves. Defaults to false. Default: false | boolean | Hide feature announcements |
claudeAiImportLets users import Claude.ai chats and projects, plus earlier Claude sessions on this computer, when enabled is true. automatic3pImport is a separate switch. | dict | Claude.ai data import |
enabledTurns history import on. The banner and import actions stay off until this is true. Default: false | boolean | Enabled |
exportEnabledLets users export Claude.ai chats and projects. automatic3pImport is a separate switch. Default: false | boolean | Export enabled |
bannerBehaviorWhen the import banner appears. Default: "off" Range: Off (off), Detect (detect), Show (show) | string | Banner behavior |
otlpEndpointWhere OpenTelemetry logs and metrics are sent. Leave blank to disable. | string | OpenTelemetry collector endpoint |
otlpProtocolgrpc or http/protobuf. One of: http/protobuf, http/json, grpc. Defaults to http/protobuf. Default: "http/protobuf" Range: http/protobuf, http/json, grpc | string | OpenTelemetry exporter protocol |
otlpHeadersStatic collector headers — routing and tenant headers only. No credentials here; use Collector authentication or the headers helper script for tokens. | string | OpenTelemetry exporter headers |
otlpAuthModeinference-credential sends the user's inference bearer token to the collector as Authorization: Bearer. One of: none, inference-credential. Range: None (none), Inference Credential (inference-credential) | string | Collector authentication |
otlpHeadersHelperAbsolute path to an executable that prints a JSON object of collector headers. Merged over the static headers and Collector authentication; the helper wins. | string | OpenTelemetry headers helper script |
otlpResourceAttributesExtra resource attributes to attach to every span/metric. A static enduser.id set here always wins over the runtime identity. | string | OpenTelemetry resource attributes |
otlpDesktopLogLevelControls the Claude Desktop application's events, separate from Cowork and Code sessions. Defaults to error. One of: off, error, warn, info, debug. Defaults to error. Default: "error" Range: Off (off), Error (error), Warn (warn), Info (info), Debug (debug) | string | Desktop telemetry export level |
otlpContentCaptureContent categories the desktop exporter sends unredacted to your collector. Leave empty to redact all content (default). One of: userPrompts, assistantResponses, toolDetails, toolContent, rawApiBodies. | array | Content capture categories |
otlpContentCaptureItemName of a content capture category to enable a class of raw content in OpenTelemetry events sent to your collector (this data never reaches Anthropic) | string | Content capture category |
otlpTracesEnabledAlso export OpenTelemetry traces from Cowork tasks and Code sessions. Uses Claude Code's session tracing. Default: false | boolean | Export traces |