Claude Managed Agents Gets Per-Session Config Overrides and Event Deltas: What Changes for Your Agent Routing Architecture

Anthropic's June 30 platform update gives operators dynamic per-session config overrides for Claude Managed Agents, streaming event deltas, lifecycle webhooks, and vault credential injection control — reshaping how teams route model and tool choices at runtime.

TheRouter Newsroomvia Anthropic
Architectural diagram showing per-session agent configuration override flow in Claude Managed Agents platform

Anthropic's June 30 platform release quietly changed the control plane for Claude Managed Agents in four ways that matter to operators: per-session config overrides, event deltas for streaming, backward-paginated session listing, and lifecycle webhooks that eliminate polling. Together they signal that Managed Agents is evolving from a static deployment model into a dynamic routing layer.

What happened

The June 30 Claude Platform release notes added the following to Claude Managed Agents:

Per-session config overrides. When creating a session, operators can now pass agent with type: "agent_with_overrides" to replace the model, system prompt, tools, MCP servers, or skills for that session only. The agent definition in the console is unchanged. This means a single agent deployment can serve multiple routing paths — a premium session routes to Sonnet 5, a cost-sensitive session routes to Haiku, a security-sensitive session strips MCP servers — all without forking the agent or maintaining multiple deployments.

Event deltas for streaming. Sessions now support event_deltas[] as a query parameter on GET /v1/sessions/{session_id}/events/stream. The event_start and event_delta events stream partial text before the full agent.message event arrives. Teams building real-time UIs or observability pipelines on Managed Agents no longer need to wait for message completion to surface output to users or monitoring systems.

Backward pagination. GET /v1/sessions now returns a prev_page cursor alongside next_page, enabling bidirectional traversal of session histories. This matters for audit and billing reconciliation workflows that need to walk session lists in both directions without rebuilding cursors.

Vault credential injection control. The injection_location field on vault environment variable credentials now lets operators specify whether the credential is injected into outbound request headers, the request body, or both. Previously, credential injection behavior was fixed at the vault level. Fine-grained control reduces over-injection surface for secrets that should only appear in one channel.

Lifecycle webhooks. Managed Agents webhooks now cover agent, deployment, and deployment run events: a newly published agent version, a paused deployment, or a failed scheduled run can all trigger a webhook without requiring the caller to poll. This closes the last gap where teams had to maintain polling loops for deployment health monitoring.

Why it matters for AI engineering teams

The agent_with_overrides feature is the most architecturally significant change. Prior to this release, Claude Managed Agents operated on a static binding: a session inherited the model and tool configuration from the agent definition at deployment time. If you needed different models for different request types, you needed different agents. That meant separate deployments, separate webhook registrations, and separate vault configurations for what was often the same logical agent serving different cost or capability tiers.

With per-session overrides, an operator can encode routing logic upstream — in their own application layer or in a routing gateway — and express the result as a session-creation parameter rather than as a separate agent deployment. The implications for cost control and governance are direct:

  • A single agent deployment can serve a "cheap" and an "expensive" routing tier with different model parameters
  • Compliance paths that require different tool restrictions no longer need separate deployments
  • A/B testing of system prompts or model versions can be done at the session level without changing the base agent definition

For teams using TheRouter or a compatible AI gateway to route requests to Claude, this introduces a new decision point: model selection can now happen downstream of the gateway, at session creation time on the Managed Agents API, rather than only at the API call level. Teams need to decide where in the stack model routing lives.

The event delta streaming change is straightforward but operationally meaningful: it reduces the end-to-end latency for surfacing agent output in UI layers and enables streaming-first observability pipelines. Teams that have built polling-based progress UIs can migrate to the streaming endpoint and reduce both latency and request overhead.

The router/operator angle

Per-session override as a routing control surface. The agent_with_overrides pattern creates a two-layer routing architecture: the agent defines the default envelope (system prompt, default model, tool whitelist), and the session-creation call fills in the routing parameters for the specific request. Operators using a gateway that injects routing context into downstream API calls — selecting model tier by user plan, by request latency budget, or by compliance scope — can now pass that routing decision into the agent field at session creation rather than routing at the model API level.

Lifecycle webhooks replace polling contracts. For teams running multiple agent deployments with scheduled runs, the new deployment run lifecycle events mean monitoring can move from cron-based polling to push-based alerting. A failed scheduled run fires a webhook; no polling loop required. Teams that currently check scheduled run status on a timer should migrate to webhooks when uptime sensitivity for agent cron jobs requires sub-1-minute response SLA.

Vault injection_location and the secrets surface. The new injection_location field is a defense-in-depth control. If a credential should only appear in a header (e.g., an Authorization token) but the prior behavior injected it into body parameters as well, the new field lets operators restrict it. Teams with SOC 2 or ISO 27001 audit requirements should review existing vault credentials against the new field and explicitly set the intended injection location.

Claude Opus 4.6 fast mode removal (June 29 context). The release notes also note that fast mode was removed from claude-opus-4-6 on June 29. Requests with speed: "fast" now run at standard speed and billing without error. Teams routing Opus 4.6 with fast mode should audit request logs and migrate to claude-opus-4-8 if they need fast mode; silent behavior changes are harder to catch than error returns.

What TheRouter users should watch or try

Per-session model overrides in Managed Agents are a new routing control surface that sits between the gateway and the model API. For teams using TheRouter to route to Claude, the architecture question is: do you route at the gateway level (before Managed Agents) or at the session-creation level (inside Managed Agents)? These are not mutually exclusive — gateway-level routing can select which Managed Agent deployment to target, while session-level overrides fine-tune the model and tools per request.

Lifecycle webhooks are immediately actionable for teams that currently poll deployment run status. Migrating to webhook-based monitoring reduces polling overhead and improves incident response time for agent infrastructure failures.

The vault injection_location control is worth reviewing in your next security audit cycle. If you manage secrets through Managed Agents vaults, auditing the new field against your existing credentials takes a few minutes and closes a potential over-injection gap.

Watch also for the prev_page cursor to become useful in billing reconciliation tooling — bidirectional session list traversal enables tools that do forward-pass collection and backward-pass verification in audit workflows.

Help & contact