Claude Code

Enterprise deployment overview

Choose providers, authentication, managed settings, permissions, monitoring, Claude Platform on AWS and Passion8 boundaries.

Deployment involves providers, identity, policy delivery, models, egress, usage, retention and cost attribution. Distinguish Claude Code client capabilities from gateway capabilities.

ANTHROPIC_BASE_URL=https://passion8.cc does not grant subscription, official web, Remote Control, Routines or apps-gateway account capabilities.

#Decision order

DecisionWhat you chooseCommon options
API providerBilling, identity, regions and capabilitiesTeam/Enterprise, Console, Bedrock, Vertex, Foundry, AWS Platform, Passion8
Policy deliveryWho overrides local settingsServer settings, MDM, system files, registry, policy helper
PermissionsTools, commands, paths, MCP and pluginsManaged permissions, sandbox, managed MCP and marketplace restrictions
ObservabilityCosts, tokens, tools and adoptionOTel, analytics, provider billing and gateway limits
Data boundariesPrompt, transcript, log, telemetry and cache locationProvider/cloud policy, gateway logs and local .claude

The official admin setup emphasizes these decisions before distributing installers. Larger teams should define providers and managed settings before rollout.

#Provider selection

ProviderBest fitConsideration
Team/EnterpriseUnified Code, web, desktop and administrationMore complete cloud/account features
Console APIAPI-first or metered usageNo subscription account capabilities
BedrockAWS-native compliance/billingVerify region, model IDs, IAM and parity
Claude Platform on AWSMarketplace billing with direct Anthropic APISigV4 or workspace keys; separate organization
Vertex AIGCP billing and IAMVerify region, aliases and caching
FoundryAzure identity and billingStandardize Entra, endpoint and deployment names
Passion8/custom gatewayCentral routing, billing, models or existing keysOfficial account features and settings do not automatically apply

If you need both official cloud capabilities and Passion8 routing, document separate paths: local CLI through Passion8, official web/cloud through authorized Anthropic accounts.

#Managed-settings sources

SourcePriorityBest fit
Server-managedHighestTeam/Enterprise or apps-gateway login
macOS plist / Windows HKLMHighManaged enterprise devices
System managed-settings.jsonMediumLinux, WSL, containers and non-MDM devices
Windows HKCULowConvenient defaults, not strong enforcement
policyHelperOverrides managed sourcesDynamic device/user/group policies

Put mandatory controls in administrator-writable locations such as MDM, HKLM or /etc/claude-code/managed-settings.json. Repository settings provide defaults, not anti-bypass enforcement.

#Controls to enforce

ControlConfiguration direction
PermissionsManage allow/deny and managed-only rules where needed
BypassDisable dangerously-skip-permissions for production repositories
SandboxEnable sandbox and limit domains/credentials
MCPManaged server files or allowlists
MarketplacesRestrict sources and sideload flags
HooksManaged-only hooks and bounded HTTP URLs
ModelsavailableModels, enforceAvailableModels and provider restrictions
VersionsminimumVersion or required range

These controls supplement code review and CI by establishing consistent safer defaults.

#Claude Platform on AWS

Claude Platform on AWS is operated by Anthropic with Marketplace billing and IAM/workspace-key authentication. Unlike Bedrock, requests reach Anthropic API and follow its model/API release cadence.

ItemExplanation
OrganizationMarketplace creates an AWS-linked Anthropic organization; do not mix old Console workspaces
AuthenticationSigV4 credential chain or workspace key
BillingAWS Marketplace and cost systems
Code configurationPlatform-specific URL, workspace, profile or key
Passion8Verify upstream signing, usage and error forwarding if layered through a gateway

#Passion8 rollout

  1. Decide which users use Passion8 and which retain official login.
  2. Deliver URL and token helpers via MDM/system settings; no keys in repositories.
  3. Identify official-account requirements for Web, Routines, Remote Control and Code Review.
  4. Attribute costs with gateway spend limits and OpenTelemetry.
  5. Use feature availability as the acceptance matrix.

#Caching and cost

ScenarioCache effect
Continuous local sessionsStable prompts/settings/tools favor five-minute reuse
Uniform managed settingsMore consistent prefixes, but users/repos remain separate caches
Provider/Base URL changesUsually establish a new cache prefix
AWS PlatformOne-hour TTL depends on client, upstream and forwarding
Passion8Preserve cache_control, beta headers and usage for accurate accounting
Official cloudIndependent context/cache, not shared with local Passion8

See command cache effects for details.

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.