Claude Managed Agents Gets Per-Session Config Overrides and Event Deltas: What Changes for Your Agent Routing Architecture
Anthropic's June 30 platform update gives operators dynamic per-session config overrides for Claude Managed Agents, streaming event deltas, lifecycle webhooks, and vault credential injection control — reshaping how teams route model and tool choices at runtime.

Anthropic's June 30 platform release quietly changed the control plane for Claude Managed Agents in four ways that matter to operators: per-session config overrides, event deltas for streaming, backward-paginated session listing, and lifecycle webhooks that eliminate polling. Together they signal that Managed Agents is evolving from a static deployment model into a dynamic routing layer.
What happened
The June 30 Claude Platform release notes added the following to Claude Managed Agents:
Per-session config overrides. When creating a session, operators can now pass agent with type: "agent_with_overrides" to replace the model, system prompt, tools, MCP servers, or skills for that session only. The agent definition in the console is unchanged. This means a single agent deployment can serve multiple routing paths — a premium session routes to Sonnet 5, a cost-sensitive session routes to Haiku, a security-sensitive session strips MCP servers — all without forking the agent or maintaining multiple deployments.
Event deltas for streaming. Sessions now support event_deltas[] as a query parameter on GET /v1/sessions/{session_id}/events/stream. The event_start and event_delta events stream partial text before the full agent.message event arrives. Teams building real-time UIs or observability pipelines on Managed Agents no longer need to wait for message completion to surface output to users or monitoring systems.
Backward pagination. GET /v1/sessions now returns a prev_page cursor alongside next_page, enabling bidirectional traversal of session histories. This matters for audit and billing reconciliation workflows that need to walk session lists in both directions without rebuilding cursors.
Vault credential injection control. The injection_location field on vault environment variable credentials now lets operators specify whether the credential is injected into outbound request headers, the request body, or both. Previously, credential injection behavior was fixed at the vault level. Fine-grained control reduces over-injection surface for secrets that should only appear in one channel.
Lifecycle webhooks. Managed Agents webhooks now cover agent, deployment, and deployment run events: a newly published agent version, a paused deployment, or a failed scheduled run can all trigger a webhook without requiring the caller to poll. This closes the last gap where teams had to maintain polling loops for deployment health monitoring.
Why it matters for AI engineering teams
The agent_with_overrides feature is the most architecturally significant change. Prior to this release, Claude Managed Agents operated on a static binding: a session inherited the model and tool configuration from the agent definition at deployment time. If you needed different models for different request types, you needed different agents. That meant separate deployments, separate webhook registrations, and separate vault configurations for what was often the same logical agent serving different cost or capability tiers.
With per-session overrides, an operator can encode routing logic upstream — in their own application layer or in a routing gateway — and express the result as a session-creation parameter rather than as a separate agent deployment. The implications for cost control and governance are direct:
- A single agent deployment can serve a "cheap" and an "expensive" routing tier with different model parameters
- Compliance paths that require different tool restrictions no longer need separate deployments
- A/B testing of system prompts or model versions can be done at the session level without changing the base agent definition
For teams using TheRouter or a compatible AI gateway to route requests to Claude, this introduces a new decision point: model selection can now happen downstream of the gateway, at session creation time on the Managed Agents API, rather than only at the API call level. Teams need to decide where in the stack model routing lives.
The event delta streaming change is straightforward but operationally meaningful: it reduces the end-to-end latency for surfacing agent output in UI layers and enables streaming-first observability pipelines. Teams that have built polling-based progress UIs can migrate to the streaming endpoint and reduce both latency and request overhead.
The router/operator angle
Per-session override as a routing control surface. The agent_with_overrides pattern creates a two-layer routing architecture: the agent defines the default envelope (system prompt, default model, tool whitelist), and the session-creation call fills in the routing parameters for the specific request. Operators using a gateway that injects routing context into downstream API calls — selecting model tier by user plan, by request latency budget, or by compliance scope — can now pass that routing decision into the agent field at session creation rather than routing at the model API level.
Lifecycle webhooks replace polling contracts. For teams running multiple agent deployments with scheduled runs, the new deployment run lifecycle events mean monitoring can move from cron-based polling to push-based alerting. A failed scheduled run fires a webhook; no polling loop required. Teams that currently check scheduled run status on a timer should migrate to webhooks when uptime sensitivity for agent cron jobs requires sub-1-minute response SLA.
Vault injection_location and the secrets surface. The new injection_location field is a defense-in-depth control. If a credential should only appear in a header (e.g., an Authorization token) but the prior behavior injected it into body parameters as well, the new field lets operators restrict it. Teams with SOC 2 or ISO 27001 audit requirements should review existing vault credentials against the new field and explicitly set the intended injection location.
Claude Opus 4.6 fast mode removal (June 29 context). The release notes also note that fast mode was removed from claude-opus-4-6 on June 29. Requests with speed: "fast" now run at standard speed and billing without error. Teams routing Opus 4.6 with fast mode should audit request logs and migrate to claude-opus-4-8 if they need fast mode; silent behavior changes are harder to catch than error returns.
What TheRouter users should watch or try
Per-session model overrides in Managed Agents are a new routing control surface that sits between the gateway and the model API. For teams using TheRouter to route to Claude, the architecture question is: do you route at the gateway level (before Managed Agents) or at the session-creation level (inside Managed Agents)? These are not mutually exclusive — gateway-level routing can select which Managed Agent deployment to target, while session-level overrides fine-tune the model and tools per request.
Lifecycle webhooks are immediately actionable for teams that currently poll deployment run status. Migrating to webhook-based monitoring reduces polling overhead and improves incident response time for agent infrastructure failures.
The vault injection_location control is worth reviewing in your next security audit cycle. If you manage secrets through Managed Agents vaults, auditing the new field against your existing credentials takes a few minutes and closes a potential over-injection gap.
Watch also for the prev_page cursor to become useful in billing reconciliation tooling — bidirectional session list traversal enables tools that do forward-pass collection and backward-pass verification in audit workflows.

Fable 5 Biology Classifier Fix: The Silent Model-Swap Your API Billing Never Warned You About
Fable 5 biology classifier false-positive fix cuts fallbacks 85%. For API operators, this exposed a silent billing risk: Fable 5 requests were being served by Opus 5 without warning. Here is what to audit before assuming model parity returns.

Claude in Azure Foundry Goes GA: What the New Hosting Architecture Means for Enterprise Routing
Claude is now generally available in Microsoft Foundry with a dual-hosting model: inference on Azure or Anthropic, Azure-native CCU billing, MACC drawdown, Entra ID auth, and a US data zone for enterprise teams.

Anthropic Unifies Claude API Rate Limits Across Tiers: What Sonnet/Haiku/Opus Parity Means for Routing Teams
Anthropic's June 26 rate limit overhaul gives Sonnet and Haiku the same RPM, ITPM, and OTPM as Opus at every tier — and consolidates five usage tiers into three. Here's what the new Start/Build/Scale structure means for fallback routing policy and spend cap management.