BuildNot yet confirmed elsewhere1 publisher2 min readPublished
In Claude Code 2.1.285, an admin-only setting decides which providers each machine may call
Anthropic's Claude Code 2.1.285 lets administrators restrict which of eight API providers a machine may use. A company that standardized on one cloud for data residency or committed spend can now hold developers to that choice inside the client.
The Engineer · Build desk
What happened
- An administrator writes the allowed providers into a managed settings file that Claude Code's documentation ranks above every other configuration level.
- A developer's settings.json, project settings and command-line flags can neither widen the allowed list nor remove it.
- The eight choices are the Anthropic API, a custom endpoint, Amazon Bedrock, Mantle, Vertex AI, Microsoft Foundry, Claude Platform on AWS and a Cloud gateway.
- Retries changed too: a failing request that could previously retry up to 21 times now shares one budget with its fallback.
- CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES, a new variable, caps how often a timed-out non-streaming fallback request is resent.
Why it matters
- constraint On a managed machine, switching providers now means asking the administrator to edit the file, since nothing a developer sets locally can reach the list.
- decision Administrators have to decide whether to allow one provider or several, and each provider they add gives developers another route for Claude Code traffic.
- cost The setup work falls on whoever builds and distributes the managed settings file, and a solo developer with no file above their own gets nothing from the setting.
The setting is enforced machine by machine. According to a walkthrough of the changelog posted on dev.to, allowedProviders governs which API providers a machine may use for Claude Code at all [2]. The list lives in the managed settings file [4], so the policy covers only the machines that file has been deployed to. A laptop that never received the file has no managed layer above its user's own settings, and nothing to enforce [17].
Within that scope the precedence is strict. We think this is the right design for a policy control. A list that a project file or a command-line flag could extend would only be a default. An administrator can allow one provider or several [11]. "It's enforced, not suggested," the post's author wrote [10].
The gap it closes is an ordinary one. Before this release, the post says, a developer was free to add a personal Anthropic API key to their own config and route traffic outside the approved path [6]. The only control before this, in the post's words, was "a Slack message asking everyone to please use the right endpoint" [18].
The retry change matters most on a pinned fleet. A machine allowed a single provider has nowhere to fail over when that provider degrades. During an incident, what its developer sees is the client's retry behavior. Under the old ceiling of 21 retries [7], one failing request could keep resending to a provider that was already struggling. The post does not give the size of the shared budget that replaced it. If that budget is smaller, every machine in a fleet sends fewer repeats during an outage and each developer gets an error sooner.
The remaining additions are smaller [16]. `claude --desktop` opens the desktop app on the current directory, or on a session picked with `--continue` or `--resume <id>` [9]. `claude plugin configure` flags a plugin's unset options and can read new values from stdin with `--values-stdin` [12]. A new form of `claude plugin install --config`, written `<server>.<key>=<value>`, sets a bundled MCP server's own settings at install time [13]. `CLAUDE_CODE_DISABLE_WEB_FETCH` turns the WebFetch tool off entirely [14].
The release, dated September 29, 2026 [1], arrived a day after 2.1.284 made Claude Sonnet 5.5 the default Sonnet model on the API [15]. A fleet-wide provider control is a lot to ship under a patch-level version number. The fix list behind it runs past eighty items, by the post author's count [16].
What to watch
- Anthropic documentation giving the size of the shared retry budget and the default for CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES.
- Whether CLAUDE_CODE_DISABLE_WEB_FETCH and other environment-variable switches move into managed settings, where developers could not unset them.
- How administrators can scope the custom endpoint and Cloud gateway options once either is on the allowed list.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anthropic shipped Claude Code 2.1.285 on September 29, 2026.
- [2]
The allowedProviders setting restricts which API providers a machine is permitted to use for Claude Code at all.
- [3]
The allowedProviders options are the Anthropic API directly, a custom endpoint, Amazon Bedrock, Mantle, Google Cloud's Vertex AI, Microsoft Foundry, Claude Platform on AWS, or a Cloud gateway: eight in total.
- [4]
An administrator writes the allowedProviders choice into a managed settings file, which Claude Code documentation describes as sitting above every other configuration level.
- [5]
A developer's own settings.json, their project settings, and flags passed on the command line cannot widen or remove the allowedProviders restriction.
- [6]
Before this setting, nothing stopped a developer from pasting a personal Anthropic API key into their own config and routing traffic outside the approved path.
- [7]
A failing request used to retry up to 21 times; it now shares one retry budget with its fallback.
- [8]
The new CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable caps how many times a timed-out non-streaming fallback request gets resent.
- [9]
claude --desktop opens the Claude desktop app on the current directory, or on a specific session with --continue or --resume <id>.
- [10]
"It's enforced, not suggested."
ReportedSupportedSource: Author of the dev.to walkthrough (RAXXO), on allowedProvidersView cited source - [11]
An administrator picks one or more of the eight providers for allowedProviders.
- [12]
claude plugin configure <plugin> shows a plugin's options, flags which are still unset, and can save new values read from stdin with --values-stdin.
- [13]
A new form of claude plugin install --config, written as <server>.<key>=<value>, sets a bundled MCP server's own settings at install time.
- [14]
CLAUDE_CODE_DISABLE_WEB_FETCH is an environment variable that turns off the WebFetch tool entirely.
- [15]
Claude Code 2.1.285 came one day after 2.1.284, which added Claude Sonnet 5.5 as the default Sonnet model on the API.
- [16]
Six additions landed in 2.1.285 alongside a fix list of more than eighty items, by the post author's count.
- [17]
"For a one person studio like mine, this setting doesn't do anything. There's no fleet of developer machines to lock down and no managed settings file sitting above my own."
- [18]
"allowedProviders closes that gap at the policy level instead of relying on a Slack message asking everyone to please use the right endpoint."
- [19]
The post's example is a company that has standardized on Bedrock for compliance reasons, such as data residency or an existing AWS spend commitment.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toClaude Code 2.1.285: What allowedProviders Actually Locks Down
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.