Claude Code v2.1.285: WebFetch off switch, provider allowlists, plugin configure#
Published by Alex Sorokoletov
Part of the Claude Code Version Tracker series. | Official Env Vars | Official Changelog
Claude Code v2.1.285 adds CLAUDE_CODE_DISABLE_WEB_FETCH to turn the WebFetch tool off, an allowedProviders managed setting that limits which API providers a machine may use, and claude plugin configure for reading and setting a plugin's options from the command line. It builds on v2.1.284 with those additions and a large batch of request-path and Remote Control reliability fixes.
Turning off WebFetch, and a cap on timed-out retries#
Set CLAUDE_CODE_DISABLE_WEB_FETCH and the WebFetch tool turns off. It is an environment variable, so it disables WebFetch without a managed-settings file.
The other new request-path control, CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES, caps re-sends of a timed-out non-streaming request. A third variable, CLAUDE_CODE_DISABLE_MODEL_ACCESS_FALLBACK, is present in the build and absent from the notes.
| Variable | What It Does |
|---|---|
CLAUDE_CODE_DISABLE_WEB_FETCH | Turns off the WebFetch tool. An environment variable, so it disables WebFetch without a managed-settings file. Added in v2.1.285. |
CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES | Caps how many times a timed-out non-streaming fallback request is re-sent. Added in v2.1.285. |
CLAUDE_CODE_DISABLE_MODEL_ACCESS_FALLBACK | Present in the v2.1.285 build and absent from that release's notes. |
allowedProviders: restricting API endpoints#
The allowedProviders managed setting limits which API providers a machine may use.[1]
The providers it can name span Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, and a Cloud gateway.
Configuring plugins from the command line#
claude plugin configure <plugin> shows a plugin's options and which of them are unset, or saves new values read from stdin with --values-stdin.
Separately, claude plugin install --config now accepts <server>.<key>=<value>, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without a trip to /plugin → Configure. Plugins that ship an MCP server still needing configuration now say so in /plugin, the install message, and claude plugin install. The release also adds claude --desktop, which opens the Claude desktop app on the current directory or on a session resumed with --continue or --resume.
Reliability fixes#
The rest of v2.1.285 is fixes, most on the request path and Remote Control.[1] Responses blocked by the API's output content filter were being re-sent and retried, sometimes for minutes; they now surface the filter's error right away. WebFetch stopped reporting a rate-limited domain safety check as a network or enterprise-policy block. Amazon Bedrock mid-stream modelTimeoutException and serviceUnavailableException errors now show the message instead of a raw JSON body. A sign-in that could hang after the browser reported success was fixed, along with a leak that left part of a URL password in redacted logs when the password contained @. Switching models mid-session with a set_model request no longer leaves the new model stuck on the built-in output-token limit and auto-compact window until restart.
What These Tell Us#
Three of the additions widen what an administrator can pin per machine. allowedProviders limits which API providers a machine may use, CLAUDE_CODE_DISABLE_WEB_FETCH drops a network tool without a policy file, and claude plugin install --config sets a bundled MCP server's own settings at install time.
On the request path, CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES gives a ceiling to non-streaming timeout re-sends, and the content-filter fix stops a blocked response from being retried for minutes. Both trade open-ended retrying for a bounded, visible outcome.
CLAUDE_CODE_DISABLE_MODEL_ACCESS_FALLBACK is present in this build and is not named in the release notes.
Sources#
- Claude Code Official Changelog, v2.1.285 release notes
This analysis is conducted for educational and research purposes under fair use principles. All trademarks and software referenced belong to their respective owners.
Related Versions#
- Claude Code v2.1.284: Sonnet 5.5 and auto mode as the default
- Claude Code v2.1.283: exact model allowlists, model deny rules, and grouped gateway requests
- Claude Code v2.1.269: plugin eval reports and Bash command diffs
- Claude Code v2.1.266: Fable 5.1 becomes the default Fable model and a fullscreen /diff panel
Previous Claude Code analysis: v2.1.284 (September 28, 2026)
All 59 Claude Code analyses: Claude Code Version Tracker · Official Claude Code changelog