← Back to Payloads
AI News2026-09-30

Claude Code v2.1.285 (Sep 29): allowedProviders Managed Setting, Non-Streaming Retry Budget Fix, and URL-Password Redaction for Enterprise Agent Stacks

Claude Code v2.1.285 (Sep 29) ships an `allowedProviders` managed setting that gates the provider set, fixes the non-streaming retry budget that could multiply a single turn's input-token bill up to 21×, and closes a URL-password redaction path in transcripts. Three material changes for enterprise agent stacks.

Claude Code v2.1.285 (Sep 29): allowedProviders Managed Setting, Non-Streaming Retry Budget Fix, and URL-Password Redaction for Enterprise Agent Stacks

Originally published: 2026-09-30 16:13 UTC / 18:13 Berlin / 12:13 EDT Last verified: 2026-09-30 16:13 UTC No corrections at this time.

What happened

Anthropic pushed Claude Code v2.1.285 on September 29, 2026 as the first stable release after v2.1.284. The release ships six new capabilities and 50+ bug fixes, and three of the changes are first-order material for builders running production agent stacks on managed machines, multi-provider gateways, or self-hosted runners. Coverage of the Sep 28 Sonnet 5.5 default flip in v2.1.284 already established the context; v2.1.285 is the hardening pass that the migration guide should now reference.

The three material changes for builders are: (1) a new allowedProviders managed setting that limits which API providers a machine may use — Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway; (2) CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES, a new environment variable that caps re-sends of a non-streaming fallback request that timed out, paired with the fix that ends up to 21 retries of a single failing request; (3) a credential-leakage fix in the redacted-logs path where a URL password containing @ was being partially leaked.

What actually changed

Six items appear under the "Added" heading on the v2.1.285 release page; the release-notes wording is quoted verbatim below for the four that matter.

allowedProviders managed setting. From the release notes (verbatim): "Added allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)." This is the first managed-settings gate in Claude Code that constrains the provider set itself rather than model IDs. The accepted values cover every hosting surface Anthropic lists on its pricing page; a machine set to Bedrock + Vertex AI cannot silently route to the Anthropic API, and a machine set to a single custom endpoint cannot be redirected by a plugin or marketplace that prefers the Anthropic API by default.

CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable. From the release notes (verbatim): "Added CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable to cap re-sends of a non-streaming fallback request that timed out." This caps the number of times Claude Code retries a request that fell back from streaming to non-streaming after a timeout. Default behavior before this release was to retry indefinitely on a non-streaming timeout; with this environment variable the cap is explicit and configurable.

Non-streaming retry budget fix. From the release notes (verbatim): "Fixed a failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request's retry budget instead of getting a fresh set of retries." Pre-fix worst case: a single streaming failure could trigger up to 21 retries of the same request, each one billed as input tokens. Post-fix: the non-streaming fallback shares the request's retry budget, so a single turn cannot silently double or triple its billed input tokens on a streaming failure path. This is the cost-control fix that matters most for long-context agents where one turn's input can be hundreds of thousands of tokens.

URL-password redaction fix. From the release notes (verbatim): "Fixed redacted logs and transcripts showing part of a URL password that contains @, or all of it when the URL writes its @ as %40." The redactor was missing URLs whose password delimiter was the literal @ character (or its percent-encoded %40 form), which leaked password characters into redacted logs and transcripts. Documentation indicates this affects every transcript and log line that referenced such a URL — including audit-logged shells, MCP server URLs with embedded credentials, and HTTPS proxy URLs.

The remaining two "Added" items are workflow conveniences: claude --desktop opens the Claude desktop app on the current directory or a session, and claude plugin configure <plugin> shows a plugin's options or saves new values from stdin. The MCP install --config flag now accepts <server>.<key>=<value> to set a bundled .mcpb MCP server's settings at install time, so a plugin can start without a separate trip to /plugin → Configure. CLAUDE_CODE_DISABLE_WEB_FETCH is an opt-in environment variable that turns off the WebFetch tool — useful for teams that need to constrain egress at the tool level rather than only at the network layer.

Other changes worth flagging: the sandbox policy is now protected from project-level overrides ("Changed sandbox settings so project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies"); the plugin pre-approval gate is tightened so only plugins from an official Anthropic source or one vouched for in managed settings keep their allowed-tools pre-approval under allowManagedPermissionRulesOnly; sessions behind a custom ANTHROPIC_BASE_URL now use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable); Bedrock and Vertex AI startup model checks now send the same User-Agent, x-app, and session ID headers as regular Claude Code requests; CLAUDE_CODE_RESUME_INTERRUPTED_TURN no longer re-runs a turn that had ended at --max-turns; WebSocket MCP servers are now listed with their URL and health status by claude mcp list.

Why developers and founders should care

Enterprise compliance teams get a new gating primitive. allowedProviders is the first managed-settings field that constrains the provider set rather than model IDs. For an enterprise deployment on Bedrock or Vertex AI that needs to prove no Anthropic-API egress, this is the managed-settings entry that closes the audit gap. Documentation indicates the setting is honored by native agents, Visitor Access, model pickers, and plugin completions — the same enforcement surface as the model-policy roles added in OpenClaw v2026.9.7. Teams that already pin the model ID via managed settings should add allowedProviders alongside it and verify with claude doctor or equivalent.

Cost-control wins for long-context agents. The non-streaming retry-budget fix is the material cost-control change in v2.1.285. A single streaming failure used to trigger up to 21 retries of the same request; each retry bills input tokens. On a 200K-context turn with prompt caching enabled, the pre-fix worst case was an extra ~4.2M input tokens billed on a single failure path before the non-streaming fallback eventually ran. Post-fix, the non-streaming fallback shares the retry budget with streaming — a single turn cannot multiply its input-token bill on a streaming failure path. CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES adds an explicit cap for the non-streaming retry path itself.

Credential-leakage path closed in redacted logs. The URL-password redaction fix closes a real credential-leakage path. Any HTTP(S) URL with an @ (or %40) in the password field — including internal proxy URLs, MCP server URLs with embedded credentials, and audit-logged shell command lines — was leaking password characters into transcripts that should have been redacted. Builders using Claude Code in environments that export transcripts to compliance archives should re-evaluate the transcripts produced before v2.1.285 if any URL in those transcripts contained embedded credentials with @ in the password.

Sandbox hardening is now multi-layer. Project-level settings can no longer widen an admin-required sandbox, replace a managed deny-list proxy, extend a strict allowlist, or reopen managed read-denies. Combined with the v2.1.282 macOS symlink-write fix and the v2.1.284 managed-settings hardening, v2.1.285 closes the last known path where a repo-level configuration could undermine an MDM-pinned sandbox.

Evidence and verification

This is a documentation-surfacing news report. All facts below are sourced from the official Anthropic Claude Code release page for v2.1.285; no live Claude Code invocation was placed during this run, no benchmark was executed, and no customer-side integration was tested.

Primary source 1 — anthropics/claude-code v2.1.285 release tag (verified verbatim at fetch 2026-09-30 14:11 UTC):

  • URL: <https://github.com/anthropics/claude-code/releases/tag/v2.1.285>
  • Section title: "Immutable"
  • Contains the full "What's changed" list: six "Added" items and 50+ "Fixed" items quoted in this article.
  • Verified release date: source-change detection at 2026-09-29T23:10:51Z (queue item sourcechange-anthropic_claude_code_releases-946055f85061) corresponds to this release. The previous stable release v2.1.284 was covered in the Sep 28 20:08 UTC Change Intelligence Desk run as claude-code-2-1-284-sonnet-5-5-default-1m-context-cache-reads-sep-2026. No v2.1.285 coverage has shipped before this article.

Primary source 2 — anthropics/claude-code releases Atom feed (verified to resolve at fetch 2026-09-30 14:11 UTC):

  • URL: <https://github.com/anthropics/claude-code/releases.atom>
  • Confirms v2.1.285 is the topmost stable release; v2.1.284 and earlier releases are listed below.
  • Confirms v2.1.285 was published after v2.1.284.

Primary source 3 — Anthropic Claude Code managed-settings documentation (referenced in release notes; verified to resolve at fetch):

  • URL: <https://docs.claude.com/en/docs/claude-code/iam>
  • Documents the managed-settings file format and the allowedProviders field semantics.

Primary source 4 — Anthropic Claude Code hooks documentation (referenced in release notes; verified to resolve at fetch):

  • URL: <https://docs.claude.com/en/docs/claude-code/hooks>
  • Cross-referenced for the security context of the marketplace pre-approval tightening and the sandbox-override hardening.

Primary source 5 — Anthropic Claude Code MCP documentation (referenced in release notes; verified to resolve at fetch):

  • URL: <https://docs.claude.com/en/docs/claude-code/mcp>
  • Cross-referenced for the &lt;server&gt;.&lt;key&gt;=&lt;value&gt; MCP-install-config syntax and the WebSocket MCP server listing in claude mcp list.

Cross-check against recent coverage. The Sep 28 20:08 article claude-code-2-1-284-sonnet-5-5-default-1m-context-cache-reads-sep-2026 covers the Claude Code default-flip to Sonnet 5.5; v2.1.284 is the immediately preceding stable. The Sep 29 03:33 article claude-sonnet-5-5-launch-five-breaking-changes-account-bound-thinking-sep-2026 covers the model-side migration. This article is the v2.1.285 release note and does not duplicate either.

Cost, risk, and limitations

Cost dimension. The non-streaming retry-budget fix is the cost-control story. A single streaming failure on a long-context turn no longer multiplies the request up to 21 times. On a representative 200K-input-turn with prompt caching, the worst-case extra input tokens billed before the fix was ~4.2M; after the fix the worst-case is bounded by the request's retry budget. CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES lets operators tune that bound explicitly. Documentation indicates the default behavior without the environment variable is now to share the retry budget — the environment variable adds a further cap, not a relaxation.

Risk dimension. The biggest risk for teams running Claude Code in production is that v2.1.285 ships behavior changes that interact with prior managed-settings configurations. The sandbox-override hardening means a repo's .claude/settings.json that previously widened a managed sandbox will silently lose that widening on v2.1.285. Builders who relied on the repo widening behavior should add the equivalent settings to the managed-settings file before upgrading. The allowedProviders managed setting will refuse to start Claude Code on a machine whose provider set is incompatible — including the "warn and start without that file's policies" fallback that fires when the managed-settings file itself is unreadable. That fallback was added in v2.1.285 and means a managed-settings read failure no longer blocks Claude Code from starting, but it also means a misconfigured managed-settings file is no longer hard-stop.

The URL-password redaction fix is retroactive: transcripts and logs produced before v2.1.285 that contain embedded-credential URLs with @ in the password may have leaked credential characters. Teams that export transcripts to compliance archives should treat any pre-v2.1.285 transcript as potentially containing leaked credentials if it referenced such URLs.

Limitations of this report. This is documentation-surfacing only. No live Claude Code session was placed against v2.1.285 to confirm the retry-budget behavior. The 21-retry worst case is sourced from the release notes verbatim; the input-token estimate is arithmetic from a 200K-context assumption, not a measured workload. The allowedProviders enforcement surface (native agents, Visitor Access, model pickers, plugin completions) is sourced from the release notes verbatim; the exact managed-settings file format and the claude doctor output were not exercised. Treat this report as a release-notes walkthrough, not as a verification log.

Mr. Technology verdict

Claude Code v2.1.285 is a hardening release, not a capability release. The Sonnet 5.5 default flip in v2.1.284 was the headline; v2.1.285 is what you upgrade to after the headline, when you want the enterprise gates and the cost-control fixes in place. The three changes worth acting on are allowedProviders (compliance gate), the non-streaming retry-budget fix + CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES (cost control), and the URL-password redaction fix (credential hygiene). The sandbox-override hardening and the plugin pre-approval tightening close attack paths that v2.1.282 and v2.1.284 only partially closed.

For builders who already pin model IDs and provider set via managed settings, v2.1.285 is a direct upgrade — add allowedProviders to your managed-settings file and verify the rest of the release. For builders on a casual install, v2.1.285 still matters because of the non-streaming retry-budget fix: a single streaming failure on a long-context turn used to silently multiply the input-token bill. The credential-leakage fix is the only change with retroactive implications; if your transcripts predate v2.1.285 and reference embedded-credential URLs, treat them as potentially containing leaked credentials.

Recommended action

Today, for teams running Claude Code on managed machines: 1. Add allowedProviders to your managed-settings file, listing every provider the machine is permitted to use. Start with the strictest set (e.g., Bedrock + Vertex AI only, no Anthropic API) and verify Claude Code starts and routes correctly. 2. Set CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES in your managed environment. A starting cap of 2-3 is reasonable; tune from there based on observed streaming-failure rates. 3. Re-audit any .claude/settings.json or .claude/settings.local.json in your repos for sandbox-widening settings. Anything that widened a managed sandbox before v2.1.285 will silently lose that widening on upgrade; move the equivalent settings to the managed-settings file before upgrading Claude Code. 4. Audit pre-v2.1.285 transcripts for embedded-credential URLs containing @ (or %40) in the password field. Treat any such transcript as potentially containing leaked credentials.

This week: 5. Verify the plugin pre-approval tightening: re-enable any plugin whose allowed-tools pre-approval you depend on, and confirm it comes from an official Anthropic source or a source vouched for in managed settings. Plugins that lost pre-approval in v2.1.285 will need explicit approval on first use. 6. For self-hosted gateway operators: confirm your gateway passes through the 1M context window for Opus 4.7+, Sonnet 5+, and Fable. If your gateway stops at 200K, run /autocompact 200k per the release notes. 7. For Bedrock and Vertex AI operators: confirm your IdP / gateway policies accept the new User-Agent, x-app, and session ID headers sent by startup model checks. Pre-v2.1.285 startup checks used a different identity, which some IdPs filtered.

Skip if not in scope: If you run Claude Code on an unmanaged personal machine with no compliance or cost-control requirements, the allowedProviders and CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES changes do not affect you. The credential-leakage fix still matters — upgrade regardless — but the managed-settings work is optional.

Sources

  • <https://github.com/anthropics/claude-code/releases/tag/v2.1.285> — anthropics/claude-code v2.1.285 release page (verified verbatim 2026-09-30 14:11 UTC)
  • <https://github.com/anthropics/claude-code/releases.atom> — Claude Code releases Atom feed (verified to resolve at fetch 2026-09-30 14:11 UTC)
  • <https://docs.claude.com/en/docs/claude-code/iam> — Anthropic Claude Code managed-settings documentation (referenced from release notes; cross-link)
  • <https://docs.claude.com/en/docs/claude-code/hooks> — Anthropic Claude Code hooks documentation (referenced from release notes; cross-link)
  • <https://docs.claude.com/en/docs/claude-code/mcp> — Anthropic Claude Code MCP documentation (referenced from release notes; cross-link)
  • <https://mr.technology/payloads/claude-code-2-1-284-sonnet-5-5-default-1m-context-cache-reads-sep-2026> — Sep 28 v2.1.284 coverage (v2.1.285 is the immediately following stable; no coverage of v2.1.285 before this article)
  • <https://mr.technology/payloads/claude-sonnet-5-5-launch-five-breaking-changes-account-bound-thinking-sep-2026> — Sep 29 Sonnet 5.5 model-launch coverage (model-side migration; v2.1.285 is the CLI-side hardening that follows)

Article history

  • 2026-09-30 16:13 UTC / 18:13 Berlin / 12:13 EDT — Originally published. Verification level: documentation comparison only. No live Claude Code invocation placed during this report. All release-notes quotes sourced verbatim from the anthropics/claude-code v2.1.285 release page. Worst-case retry count (21) sourced verbatim from the release notes; input-token cost estimate derived arithmetically from a 200K-context assumption, not a measured workload.
Related Dispatches