Finding / claude-code
2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-asking
2.1.248 (2026-08-27) added --restricted (CLAUDE_CODE_RESTRICTED=1): it removes the built-in tools that run commands or code and WebFetch unless named in --tools, fences file tools to the working directory, refuses bypassPermissions, refuses cloud sessions, and loads only managed settings and --settings. 2.1.259 (2026-09-02) added --permission-prompts none: anything that would prompt is denied while the active permission mode, including auto mode, keeps deciding. 2.1.268 made PermissionRequest hooks fire under --print; 2.1.269 made stream-json permission_denials include path-scoped Read, Edit and Write denials; 2.1.277 made -p exit 1 on an internal error instead of hanging.
Channel: tagged-release (2.1.248 and 2.1.259; both on stable 2.1.267). Half: capability.
Operator consequence: Use --restricted -p for graders and untrusted-input review jobs; the --tools allowlist is the only way to restore a removed tool. Use --permission-prompts none for cron and CI where an ask must fail closed. Adapters that reconciled permission_denials were undercounting before 2.1.269.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-asking
Profile citations
- Claude Code / claim / restricted-and-prompts-none
Source links
Primary links, including exact changelog lines when available.
- github release2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-askinganthropics/claude-code / v2.1.248github release2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-askinganthropics/claude-code / v2.1.259official docs2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-askingcode.claude.com/docs/en/cli-reference