PayloadKit

Claude Desktop

com.anthropic.claudefordesktop

Claude Desktop enterprise configuration settings

macOS

Configuration Keys (52)

KeyTypeTitle
forceLoginOrgUUID

Require login to belong to a specific organization. Accepts a single UUID string, which also pre-selects that organization during login, or an array of UUIDs where any listed organization is accepted without pre-selection. Login fails if the authenticated account does not belong to a listed organization.

arrayForce Login Organization UUID(s)
stringOrganization UUID
disableAutoUpdates

Disable automatic updates for Claude Desktop.

Default: false

booleanDisable Auto Updates
autoUpdaterEnforcementHours

Hours before forcefully restarting Claude to apply a prepared update. Must be between 1 and 72 hours.

Default: 72

Range: 1 – 72

integerAuto Update Enforcement Hours
updateViaUpdatesHost

Read the update feed from releases.claude.com so api.anthropic.com can stay blocked. Defaults to false.

Default: false

booleanCheck for updates on releases.claude.com
relaunchEnforcementHours

Hours a user may keep working on the old configuration after a managed-configuration change is detected. 0 = restart required at once. Blank = 24 hours. Defaults to 24. Range: 0-336.

Default: 24

Range: 0 – 336

integerConfiguration relaunch window
configRecheckIntervalMinutes

Minutes between the running app's checks for a changed managed configuration. Blank = 10 minutes. Defaults to 10. Range: 2-30.

Default: 10

Range: 2 – 30

integerConfiguration re-check interval
isDesktopExtensionEnabled

Enable or disable Claude Desktop extensions.

Default: true

booleanEnable Desktop Extensions
isDesktopExtensionDirectoryEnabled

Enable or disable access to the extension directory.

Default: true

booleanEnable Extension Directory
isLocalDevMcpEnabled

Enable or disable local Model Context Protocol (MCP) servers.

Default: true

booleanEnable Local MCP Servers
isClaudeCodeForDesktopEnabled

Enable Claude code access in desktop.

Default: true

booleanEnable Claude Code for Desktop
secureVmFeaturesEnabled

Enable Cowork access in desktop

Default: true

booleanEnable Secure VM Features
coworkTabEnabled

Enable Cowork. Claude works on longer tasks like research, analysis, and documents. Defaults to true.

Default: true

booleanAllow Cowork
builtinBrowserEnabled

Claude Desktop on third-party inference deployments. Enable the built-in browser in Cowork and Code sessions. False disables the browser pane; Code retains its localhost-only dev-server preview. Defaults to false. When bootstrapUrl is set, configure this key in the served configuration.

Default: false

booleanEnable Built-in Browser
builtinBrowserDefaultDomainPolicy

Claude Desktop on third-party inference deployments. Default policy for sites Claude may open, read, or act on when the built-in browser is enabled. Allowed domains are exceptions under block; blocked domains are exceptions under allow. Users can still view sites denied to Claude. Defaults to allow.

Default: "allow"

Range: Allow Sites by Default (allow), Block Sites by Default (block)

stringBuilt-in Browser Default Site Policy
builtinBrowserAllowedDomains

Claude Desktop on third-party inference deployments. Sites Claude may open, read, or act on when builtinBrowserDefaultDomainPolicy is block; ignored under allow. Empty or unset allows no external sites for Claude. Users can still view other sites. Bare * and public-suffix wildcards are ignored.

arrayBuilt-in Browser Allowed Domains

A hostname or supported hostname wildcard. A plain hostname also matches its www form, but no other subdomain.

stringDomain
builtinBrowserBlockedDomains

Claude Desktop on third-party inference deployments. Sites Claude may not open, read, or act on when builtinBrowserDefaultDomainPolicy is allow; ignored under block. Empty or unset adds no blocked sites. Users can still view blocked sites. * blocks every external site for Claude; localhost dev servers are unaffected.

arrayBuilt-in Browser Blocked Domains

A hostname or supported hostname wildcard. A plain hostname also matches its www form, but no other subdomain.

stringDomain
microsoftAuthBroker

Set to “disabled” to force browser-based Microsoft 365 sign-in instead of the native Company Portal / Windows account broker. One of: auto, disabled. Defaults to auto.

Default: "auto"

Range: Auto (auto), Disabled (disabled)

stringMicrosoft 365 native sign-in broker
isDesktopExtensionSignatureRequired

When true, Claude Desktop rejects extensions that aren't signed by a trusted publisher.

Default: false

booleanRequire Signed Desktop Extensions
disabledBuiltinTools

Removes the listed built-in tools from the available set in Claude Desktop. Known tools: Task, Bash, Glob, Grep, Read, Edit, Write, NotebookEdit, WebFetch, TodoWrite, WebSearch, Skill, REPL, JavaScript, AskUserQuestion. ToolSearch and SendUserMessage are also available under specific conditions.

arrayDisabled Built-in Tools
disabledBuiltinToolsItem

Name of a built-in tool to disable.

stringTool
managedMcpServers

Distributes remote MCP (Model Context Protocol) servers to users. Each entry requires a unique name and an HTTPS URL. Optional fields include transport, headers, OAuth, and tool-level policies. Used in Claude Cowork deployments on third-party platforms (Bedrock, Vertex AI, Azure AI Foundry, LLM gateways).

arrayManaged MCP Servers
managedMcpServersItem
dictManaged MCP Server
namerequired

Unique name identifying this MCP server.

stringName
urlrequired

HTTPS URL of the remote MCP server.

stringURL
transport

Transport protocol used to reach the MCP server.

Default: "http"

Range: HTTP (http), SSE (sse)

stringTransport
headers

Static request headers used to authenticate to the MCP server (for example, Authorization). Mutually exclusive with the OAuth field.

dictHeaders
{{key}}
stringHeader Name
{{value}}
stringHeader Value
oauth

When true, Claude Desktop runs a PKCE OAuth flow at first use to acquire user credentials. Mutually exclusive with the Headers field.

Default: false

booleanOAuth
toolPolicy

Maps tool names exposed by the MCP server to a policy. Allowed values per tool: allow, ask, blocked. The "ask" policy prompts the user to confirm before the tool runs.

dictTool Policy
{{key}}
stringTool Name
{{value}}

Range: Allow (allow), Ask (ask), Block (blocked)

stringPolicy
mcpPersistentAlwaysAllowEnabled

Offer the persistent “Always allow” approval options for MCP tools. Disable to keep tool approvals per-call or session-scoped only. Defaults to true.

Default: true

booleanAllow persistent tool approvals
mcpToolTimeoutSec

Per-call timeout for MCP tool calls, in seconds. Default 180 (3 minutes). Range: 60-3600.

Default: 180

Range: 60 – 3600

integerMCP tool call timeout
deploymentOrganizationUuid

A UUID you generate. Tags telemetry so Anthropic support can locate your fleet's events, and namespaces each user's local data. Not used for auth.

stringOrganization UUID
disableEssentialTelemetry

Crash and performance reports to Anthropic. Defaults to false.

Default: false

booleanBlock essential telemetry
disableNonessentialTelemetry

Product-usage analytics and diagnostic-report uploads. No message content. Defaults to false.

Default: false

booleanBlock nonessential telemetry
disableNonessentialServices

Connector favicons and the artifact-preview and MCP Apps widget iframe origins. Artifacts will not render. Defaults to false.

Default: false

booleanBlock nonessential services
effortLevel

Sets the default effort level for Claude Code sessions in Claude Desktop.

Default: "high"

Range: Low (low), Medium (medium), High (high), Extra High (xhigh), Max (max)

stringEffort Level
allowedWorkspaceFolders

Folders where Claude may work. Applies to both Cowork and Code sessions. Leave unset for unrestricted access. Paths can reference ~ and these environment variables, expanded per user: %OneDrive%, %OneDriveCommercial%, %OneDriveConsumer%, %APPDATA%, %LOCALAPPDATA%, %USERNAME%, %XDG_DOCUMENTS_DIR%. The set is fixed; an entry that references any other %VAR%, or one that is unset on the device, is ignored.

arrayAllowed Workspace Folders
AllowedWorkspaceFolderItem
dict—
path

Absolute folder path. May start with ~ or one of the listed %VAR% tokens, expanded per user. Subfolders are included.

stringPath
isDefaultSelected

Shows as a folder chip on the new-task page and skips the trust prompt. Users can remove it.

Default: false

booleanSelect Default
mode

Read-only folders can be viewed and searched but not modified in Cowork. In Code, applies to file tools only; Bash and SSH do not yet enforce read-only. One of: rw, ro.

Range: Read/write (rw), Read only (ro)

stringMode
disableBypassPermissionsMode

Remove the bypass permissions mode from Code sessions and Cowork tasks, so Claude always follows the permission policy. Off by default.

Default: false

booleanDisable bypass permissions mode
blockReadsOutsideWorkingDirectories

Keep Claude from reading files outside a Code session's working directories. File tools refuse such reads; sandboxed shell commands lose the home directory.

Default: false

booleanBlock reads outside working directories
disableDeploymentModeChooser

Users see only this provider at the login screen. The option to sign in to Claude.ai is hidden. Defaults to false.

Default: false

booleanDisable Claude.ai sign-in
disableDeepLinkRegistration

Stop external apps and websites from opening Claude Desktop via claude:// links. Defaults to false.

Default: false

booleanDisable claude:// deep-link handling
chatTabEnabled

Enable Chat. Quick questions and drafting.

Default: true

booleanAllow Chat
chatAdvancedFileAnalysisEnabled

Allow Claude to run code in a local sandbox to analyze attached files it can't read natively — like Excel and PowerPoint. Off by default.

Default: false

booleanAdvanced file analysis
inferenceMaxTokensPerWindow

Per-user soft cap, counted client-side over the token cap window. Not a server-enforced quota. Requires inferenceTokenWindowHours to also be set — without a window length the cap is inert and no limit is enforced.

integerMax tokens per window
inferenceTokenWindowHours

Tumbling window length for the token cap. Max 720 hours (30 days). Range: 1-720. Required when inferenceMaxTokensPerWindow is set — the cap only takes effect once both are configured.

Range: 1 – 720

integerToken cap window
endUserAttribution

Show the signed-in user's identity-provider identity in the sidebar and account menu, and emit it as the OpenTelemetry enduser.id resource attribute.

Default: false

booleanEnd-user attribution
deploymentDisplayName

Overrides the provider label shown in the sidebar footer, user-menu header, and connection-error banner.

stringDeployment display name
deploymentDisplaySubtitle

Optional detail shown after the deployment display name in the account-menu header.

stringDeployment display subtitle
disableConfigDeprecationWarnings

Don't show users the in-app warning that this configuration uses a deprecated field. The final reminder in the 24 hours before the cut-off still appears.

Default: false

booleanHide configuration deprecation warnings
banner

A persistent banner across the top of the app window after sign-in.

dictOrganization banner
enabled

Turns the banner on or off.

Default: false

booleanEnabled
text

Text shown in the banner.

stringText
backgroundColor

Banner background color, as a hex code.

stringBackground color
textColor

Banner text color, as a hex code.

stringText color
linkUrl

URL the banner links to when clicked.

stringLink URL
disableFeatureDiscovery

Suppress unprompted feature-announcement UI: the post-update “What's new” nudge and new-feature tips. Users can still open release notes themselves. Defaults to false.

Default: false

booleanHide feature announcements
claudeAiImport

Lets users import Claude.ai chats and projects, plus earlier Claude sessions on this computer, when enabled is true. automatic3pImport is a separate switch.

dictClaude.ai data import
enabled

Turns history import on. The banner and import actions stay off until this is true.

Default: false

booleanEnabled
exportEnabled

Lets users export Claude.ai chats and projects. automatic3pImport is a separate switch.

Default: false

booleanExport enabled
bannerBehavior

When the import banner appears.

Default: "off"

Range: Off (off), Detect (detect), Show (show)

stringBanner behavior
otlpEndpoint

Where OpenTelemetry logs and metrics are sent. Leave blank to disable.

stringOpenTelemetry collector endpoint
otlpProtocol

grpc or http/protobuf. One of: http/protobuf, http/json, grpc. Defaults to http/protobuf.

Default: "http/protobuf"

Range: http/protobuf, http/json, grpc

stringOpenTelemetry exporter protocol
otlpHeaders

Static collector headers — routing and tenant headers only. No credentials here; use Collector authentication or the headers helper script for tokens.

stringOpenTelemetry exporter headers
otlpAuthMode

inference-credential sends the user's inference bearer token to the collector as Authorization: Bearer. One of: none, inference-credential.

Range: None (none), Inference Credential (inference-credential)

stringCollector authentication
otlpHeadersHelper

Absolute path to an executable that prints a JSON object of collector headers. Merged over the static headers and Collector authentication; the helper wins.

stringOpenTelemetry headers helper script
otlpResourceAttributes

Extra resource attributes to attach to every span/metric. A static enduser.id set here always wins over the runtime identity.

stringOpenTelemetry resource attributes
otlpDesktopLogLevel

Controls the Claude Desktop application's events, separate from Cowork and Code sessions. Defaults to error. One of: off, error, warn, info, debug. Defaults to error.

Default: "error"

Range: Off (off), Error (error), Warn (warn), Info (info), Debug (debug)

stringDesktop telemetry export level
otlpContentCapture

Content categories the desktop exporter sends unredacted to your collector. Leave empty to redact all content (default). One of: userPrompts, assistantResponses, toolDetails, toolContent, rawApiBodies.

arrayContent capture categories
otlpContentCaptureItem

Name of a content capture category to enable a class of raw content in OpenTelemetry events sent to your collector (this data never reaches Anthropic)

stringContent capture category
otlpTracesEnabled

Also export OpenTelemetry traces from Cowork tasks and Code sessions. Uses Claude Code's session tracing.

Default: false

booleanExport traces