apps/opik-documentation/documentation/fern/docs-v2/cost_intelligence/install/managed-settings.mdx
Claude Code's server-managed settings let you deliver configuration from Anthropic's admin console to every authenticated user in your organization, with no MDM and no per-device work, and it follows the user to whatever machine they sign in on.
This is the fastest path to a working rollout. The trade-off is that it has no targeting: the configuration applies to every authenticated user in the organization as soon as you save it, so you can't pilot with a single team first.
<Note> Requires **Claude for Teams or Enterprise**.If you want to stage the rollout (one team first, then widen), use MDM instead. That's our general recommendation, and it's also the path to use if your developers are on personal Claude accounts or you need to cover machines whose accounts you don't control. </Note>
You can hand-write the JSON, but the product will build it for you, including any cost policies you've already configured.
In Opik, go to Cost Intelligence → Organization Policies and use Copy settings file. The generated JSON contains the plugin bootstrap that you can use in the Claude Code admin console.
In Claude.ai, go to Admin Settings → Claude Code → Managed settings.
If you generated it above, paste it as-is. Otherwise start from this template:
{
"extraKnownMarketplaces": {
"opik-enterprise": {
"source": { "source": "github", "repo": "comet-ml/cost-intelligence-proxy" },
"autoUpdate": true
}
},
"enabledPlugins": {
"opik-cipx@opik-enterprise": true
},
"env": {
"OPIK_CIPX_BASE_URL": "https://www.comet.com/opik/api",
"OPIK_CIPX_WORKSPACE": "your-org-cc-workspace",
"OPIK_CIPX_API_KEY": "<workspace-scoped API key>",
"OPIK_CIPX_PROJECT": "claude-code"
},
"forceRemoteSettingsRefresh": true
}
Clients pick the configuration up at their next startup, or within the hourly poll for sessions already running.
</Steps>| Key | Effect |
|---|---|
extraKnownMarketplaces | Registers the Comet plugin marketplace. autoUpdate: true keeps the plugin current without another admin action. |
enabledPlugins | Force-enables the plugin for every user. It appears to them as managed and cannot be disabled. |
OPIK_CIPX_BASE_URL | The Opik installation traces are shipped to. |
OPIK_CIPX_WORKSPACE | Target workspace. Keeps fleet traffic isolated from developers' personal Opik projects. |
OPIK_CIPX_API_KEY | Workspace-scoped service-account key. |
OPIK_CIPX_PROJECT | Opik project the traces land in. |
forceRemoteSettingsRefresh | Makes clients re-read settings promptly rather than waiting out the cache. |
Nothing they have to do. On the next Claude Code launch:
SessionStart hook.opik-cipx sync, which is idempotent: it installs an OS supervisor (launchd on macOS, systemd on Linux) so the daemon restarts on crash, starts the daemon if it isn't running, and points Claude Code at the local proxy by setting ANTHROPIC_BASE_URL in ~/.claude/settings.json.The proxy binds loopback only and Claude Code talks plain HTTP to it, so no certificate is installed and no TLS is intercepted.
<Tip> The hook tolerates a missing binary: if anything about the install is incomplete it prints a hint and lets the session continue. Cost Intelligence is designed never to be the reason a developer can't work. </Tip>On a developer machine, in a fresh Claude Code session:
claude plugin list # opik-cipx@opik-enterprise -> enabled / managed
opik-cipx status # daemon up, config resolved, spans shipped
Then confirm traces are landing in the target Opik workspace. That's the check that actually proves the rollout worked.
If your traffic goes through a corporate LLM gateway, LiteLLM, or an AWS Bedrock access gateway rather than straight to the provider, add its origin:
{
"env": {
"OPIK_CIPX_UPSTREAM_BASE_URL": "https://gateway.internal.example.com"
}
}
The gateway must expose the Anthropic Messages API. Because a gateway bills under its own account, sessions are reported as API-priced with no subscription plan, and user identity comes from the environment channel rather than an OAuth profile. Set OPIK_CIPX_USER_EMAIL and OPIK_CIPX_USERNAME alongside it if git and OS identity aren't reliable on your fleet.