inference-hooks-endpoint changedmanage-claude/inference-hooks-endpoint
Nearest release: v2.1.292, published 11 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+11added
Lines−6removed
From line
283
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits12to this page, all time
The whole hunk
from line 283, old and new numbered
/
from line 283
283283
284284A third-party tool is one on a server that Anthropic knows of, such as a claude.ai connector or an MCP server that the request names in `mcp_servers`. This doesn't mean Anthropic has vetted the server.
285285
286| Field | Present | Description |
287| ----------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
288| `type` | Always | `"third_party"` |
289| `toolset_name` | Optional | The name the request gives the server. |
290| `origin` | Optional | The scheme, host, and non-default port of the server's URL. An absent `origin` means unknown, not safe. |
291| `verified_origin` | Whenever `origin` is | `true` only when Anthropic's servers connect to the server themselves. Treat `false` as an origin that Anthropic hasn't confirmed. |
286| Field | Present | Description |
287| ----------------- | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
288| `type` | Always | `"third_party"` |
289| `toolset_name` | Optional | The name the request gives the server. |
290| `origin` | Optional | The scheme, host, and non-default port of the server's URL. It can be a private or local address, `localhost` included. An absent `origin` means unknown, not safe. |
291| `verified_origin` | Whenever `origin` is | `true` only when Anthropic's servers connect to the server themselves. Treat `false` as an origin that Anthropic hasn't confirmed. |
292292
293293A `tool_use` block for a tool on an MCP server that the request names `crm` in `mcp_servers`:
294294
from line 313
313313
314314A client tool is any other tool. The application that calls Claude declares it and receives its calls. A call to a tool the request doesn't declare is also `"client"`.
315315
316A tool on an MCP server that Claude Code connects to directly from the user's computer, such as a local MCP server, is a client tool. Its `tool_info` is `{"type": "client"}`, and its `tool_name` is the name Claude Code gives it, in the form `mcp__<server>__<tool>`.
317
318A deny stops the call before Claude Code runs it. The exchange between Claude Code and a local server doesn't pass through Anthropic, so your AI security server sees the tool's result only when Claude Code sends it back. Its text is then in a `tool_result` block in the next prompt frame.
319
316320| Field | Present | Description |
317321| -------------- | -------- | --------------------------------- |
318322| `type` | Always | `"client"` |
from line 806
802806* New `source.application` values.
803807* New `actor.type` values. `actor` is a union discriminated on `type`, and `"user"` is the only kind sent today; a future kind guarantees only that `type` is present.
804808* Content blocks with an unrecognized `type`.
809* Messages with a `role` other than `user` or `assistant`, which a later revision may add.
805810
806811Never reject a request because of an unrecognized block type or field; read the fields you know and skip the rest.
807812
No line in this hunk matches that.