Claude Code 2.1.285 lets admins lock down API providers

If your company wants every developer laptop talking to Bedrock and nothing else, Claude Code now has a single managed setting for that. The same release also puts a 30-minute default limit on background shell commands. Both items are in the v2.1.285 release notes on Github, a long list that is mostly fixes.
At a glance
- The new allowedProviders managed setting lets administrators restrict a machine to named API providers, from the Anthropic API and custom endpoints to Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS and Cloud gateways.
- A failing request could previously be retried up to 21 times when streaming kept failing, because the non-streaming fallback got fresh retries. Now it shares the original request's budget.
- Background Bash and PowerShell commands now stop at their timeout, 30 minutes by default and two hours at most, so a long overnight build started in the background needs its own explicit timeout.
If you have not run Claude Code for a team, managed settings are the policy layer an administrator pushes to a machine, through MDM or a managed-settings file. Project and user settings are not supposed to override it. Several items in 2.1.285 tighten that layer, and the provider allowlist is the one new control.
allowedProviders names eight kinds of provider a machine may use
The setting takes a list drawn from eight options: the Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS and a Cloud gateway. Anything left off the list is off limits for that machine. Several fixes in the same release close gaps in how policy reaches a session.
Sessions that authenticated with ANTHROPIC_AUTH_TOKEN against the Anthropic API never loaded the organization's policy. That is fixed. If the OS denies read access to the managed settings file, Claude Code used to refuse to start. Now it warns and starts without that file's policies, while other read errors and unparseable files still stop every session. Team and Enterprise sessions, plus sessions whose plan Claude Code cannot determine, now hold back WebFetch until the organization policy loads if it failed to load at startup. Project settings also lose the ability to widen or turn off an admin-required sandbox, extend a strict allowlist or reopen managed read-denies.
Background commands get a 30-minute default and a two-hour ceiling
Bash and PowerShell commands launched with run_in_background now stop when they hit their timeout. The default is 30 minutes and the maximum is two hours. When a command is stopped, Claude gets a notice, so the session knows the job did not finish on its own.
Background work gets tidier elsewhere too. In auto mode, a subagent's run now ends as soon as it hands its report back to the caller, where it used to take extra turns that reached no one. A related bug that made background subagents ask for a second, redundant reply after each report is fixed. /tasks now groups the work Claude Code runs for itself under one "System tasks" row. Running /resume or claude --resume on a session already running in the background now opens that session instead of refusing, and a prompt passed with the command becomes its next turn.
Why could one failing request be tried 21 times?
The retry counters were stacked on top of each other. When a streaming request kept failing, Claude Code fell back to a non-streaming request, and that fallback started with a fresh set of retries. Together they could reach 21 attempts. The fallback now draws from the original request's retry budget.
Think of a caller who redials a busy number five times, switches to a landline and starts counting from zero again. The fix gives both phones one shared counter. A new environment variable, CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES, caps how many times a timed-out non-streaming fallback is re-sent. Responses blocked by the API's output content filter used to be retried, sometimes for minutes. Now the filter's error shows right away. With partial messages on, the SDK also sends a ping event every 30 seconds during a non-streaming fallback on the Anthropic API, Claude Platform on AWS and gateways.
Custom gateways get the 1M window, and the terminal gets four new switches
Sessions behind a custom ANTHROPIC_BASE_URL now use the 1M context window on models that support it: Opus 4.7 and later, Sonnet 5 and later, and Fable. If your gateway stops at 200K, the notes tell you to run /autocompact 200k.
claude --desktop opens the Claude desktop app on the current directory, or on a specific session when combined with --continue or --resume. claude plugin configure lists a plugin's options, marks the ones still unset and can save new values read from stdin with --values-stdin. claude plugin install --config now accepts server.key=value pairs, so a bundled .mcpb MCP server can be configured at install time without a trip to /plugin. CLAUDE_CODE_DISABLE_WEB_FETCH turns the WebFetch tool off entirely.
The notes do not say what a user sees when they try a provider their machine's allowedProviders list excludes, or how the setting treats a Cloud gateway that sits in front of several backends. In our view, the two-hour ceiling is the design choice most likely to bite. The 30-minute default can be raised, but the notes offer no way past two hours, so longer jobs appear to belong outside run_in_background altogether.
Before the overnight build runs
The release notes give no date for the next version. If you work behind a custom ANTHROPIC_BASE_URL, your next session will show whether your gateway accepts the 1M window or stops at 200K, and /autocompact 200k is the stated fix for the second case. If you have background builds that run longer than 30 minutes, set their timeout before you update, because the stop now happens automatically.
Related stories
- Claude Code 2.1.284 ships Sonnet 5.5 at the leaked price
- Claude Code 2.1.281 adds Bedrock guardrails to its gateway
- Claude Code writes the eval, grader included
- Leak puts expandable usage limits in Claude Code desktop
- Claude Code 2.1.283 keeps new models out until admins say so
- Claude Code gets a wrap-up budget at the 5-hour limit
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
