Skip to content
Proposals/Set CLAUDE_CODE_DISABLE_WEB_FETCH and allowedPro
proposalteamP5Worth a lookClaude Code

Set CLAUDE_CODE_DISABLE_WEB_FETCH and allowedProviders on managed machines

Claude Code v2.1.285 adds CLAUDE_CODE_DISABLE_WEB_FETCH, the allowedProviders managed setting, and claude plugin install --config <server>.<key>=<value> for bundled .mcpb servers. Lock providers and WebFetch on managed machines, pin MCP keys at install, and re-scope Artifact allow rules with --add-dir.

Why this loop

v2.1.285 adds machine-level controls that previously meant leaving WebFetch on, allowing every API provider, or visiting /plugin → Configure after each MCP install. CLAUDE_CODE_DISABLE_WEB_FETCH turns the WebFetch tool off. allowedProviders limits a machine to Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway. Bundled .mcpb MCP settings can be set at install with --config <server>.<key>=<value>, and claude plugin configure <plugin> shows options and which are unset (or writes values from --values-stdin). An Artifact allow rule ("don't ask again") no longer publishes a file outside the working directories without asking—add that folder with --add-dir for the rule to cover it. Sessions that authenticate with ANTHROPIC_AUTH_TOKEN against the Anthropic API now load the organization's policy, so token-based CI picks up the same managed rules. Apply these together so new installs start locked down and MCP servers come up without a manual configure step.

Proposed actions

  1. Persist CLAUDE_CODE_DISABLE_WEB_FETCH=1 in this machine's environment (shell profile, launchd, or systemd) so Claude Code v2.1.285+ starts with the WebFetch tool off.
  2. Add allowedProviders to this machine's Claude Code managed settings, listing only the API providers it may use: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway.
  3. For each bundled .mcpb plugin, run: claude plugin install <plugin> --config '<server>.<key>=<value>' (repeat --config per key) so that MCP server's own settings are set at install and it starts without visiting /plugin → Configure.
  4. Run: claude plugin configure <plugin> to list that plugin's options and which are unset; save replacements with: claude plugin configure <plugin> --values-stdin
  5. Relaunch Claude Code with --add-dir <folder> for every folder an Artifact tool "don't ask again" allow rule should cover; v2.1.285 no longer lets that rule publish files outside the working directories without asking.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Paste into Claude Code / CLAUDE.md task

DevAgentRadar → Claude Code

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

Context

Assistant: Claude Code Proposal: Set CLAUDE_CODE_DISABLE_WEB_FETCH and allowedProviders on managed machines Summary: Claude Code v2.1.285 adds CLAUDE_CODE_DISABLE_WEB_FETCH, the allowedProviders managed setting, and claude plugin install --config <server>.<key>=<value> for bundled .mcpb servers. Lock providers and WebFetch on managed machines, pin MCP keys at install, and re-scope Artifact allow rules with --add-dir. Primary source: https://github.com/anthropics/claude-code/releases/tag/v2.1.285

Why it matters

v2.1.285 adds machine-level controls that previously meant leaving WebFetch on, allowing every API provider, or visiting /plugin → Configure after each MCP install. CLAUDE_CODE_DISABLE_WEB_FETCH turns the WebFetch tool off. allowedProviders limits a machine to Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway. Bundled .mcpb MCP settings can be set at install with --config <server>.<key>=<value>, and claude plugin configure <plugin> shows options and which are unset (or writes values from --values-stdin). An Artifact allow rule ("don't ask again") no longer publishes a file outside the working directories without asking—add that folder with --add-dir for the rule to cover it. Sessions that authenticate with ANTHROPIC_AUTH_TOKEN against the Anthropic API now load the organization's policy, so token-based CI picks up the same managed rules. Apply these together so new installs start locked down and MCP servers come up without a manual configure step.

Suggested actions

  1. Persist CLAUDE_CODE_DISABLE_WEB_FETCH=1 in this machine's environment (shell profile, launchd, or systemd) so Claude Code v2.1.285+ starts with the WebFetch tool off.
  2. Add allowedProviders to this machine's Claude Code managed settings, listing only the API providers it may use: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway.
  3. For each bundled .mcpb plugin, run: claude plugin install <plugin> --config '<server>.<key>=<value>' (repeat --config per key) so that MCP server's own settings are set at install and it starts without visiting /plugin → Configure.
  4. Run: claude plugin configure <plugin> to list that plugin's options and which are unset; save replacements with: claude plugin configure <plugin> --values-stdin
  5. Relaunch Claude Code with --add-dir <folder> for every folder an Artifact tool "don't ask again" allow rule should cover; v2.1.285 no longer lets that rule publish files outside the working directories without asking.

Config surfaces this release may change

  • MCP servers (high confidence) — check your repo before applying
  • skills (high confidence) — check your repo before applying
  • background and headless runs — check your repo before applying
  • context and compaction settings — check your repo before applying
  • hooks — check your repo before applying
  • permission rules — check your repo before applying
  • sandbox settings — check your repo before applying
  • settings files — check your repo before applying
  • subagent definitions — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/claude-code-v2-1-285-set-claude-code-disable-web-fetch-and-allowedprovid and mark Applied, Skipped, or Failed. Proposal id: 2130fe69-e54b-478c-a5ac-afdf0dcb42d5

Your job

  1. Restate the change in one sentence.
  2. Propose a minimal plan for my repo (or a throwaway pilot).
  3. Implement only what I approve; prefer small diffs and tests.
  4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.

agentmcpmodelsecurityideRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

Claude Codev2.1.285Sep 29, 2026

v2.1.285

Added CLAUDE_CODE_DISABLE_WEB_FETCH environment variable to turn off the WebFetch tool · Added claude --desktop to open the Claude desktop app on the current directory, or on a session with --continue / --resume <id> · Added claude plugin configure <plugin> to show a plugin's options and which are unset, or save new values read from stdin with --values-stdin · Added <server>.<key>=<value> to claude plugin install --config, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without visiting /plugin → Configure · +75 more changes
Verified excerpt — the source's own words

What's changed

  • Added CLAUDE_CODE_DISABLE_WEB_FETCH environment variable to turn off the WebFetch tool
  • Added claude --desktop to open the Claude desktop app on the current directory, or on a session with --continue / --resume <id>
  • Added claude plugin configure <plugin> to show a plugin's options and which are unset, or save new values read from stdin with --values-stdin
  • Added <server>.<key>=<value> to claude plugin install --config, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without visiting /plugin → Configure
  • Added allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)
  • Added CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable to cap re-sends of a non-streaming fallback request that timed out
  • Fixed claude -p with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result

Excerpt ends here — this release continues at the source ↗.

Primary source ↗