01
Login pinned to your organisation
forceLoginMethod and forceLoginOrgUUID deployed as managed settings, so a session holding a personal credential exits at startup instead of being found in a log later. We also close what those keys do not cover: claude setup-token and the GitHub app install enforce only the login method, and cloud provider sessions authenticate against your cloud provider, so both are restricted elsewhere. On Claude for Enterprise this sits next to SSO, domain capture and role-based permissions.
