4 pages for filesystem.denyread.
Titles and paths first, then pages whose text carries it. Each row opens that page as this site last read it.
Deploy managed settings
Claude Code CLI · in the page
managed-settings
…anaged allowlist grants nothing until you fix the deny list. * While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allow…
Configure the sandboxed Bash tool
Claude Code CLI · in the page
sandboxing
…rite or read access using `sandbox.filesystem.denyWrite` and `sandbox.filesystem.denyRead`, and re-allow specific paths within a denied region using `sandbox.filesystem.allowRead`. When read rules ove…
Claude Code settings
Claude Code CLI · in the page
settings
…usr/local/bin"]` | | `filesystem.denyRead` | Paths where sandboxed commands cannot read. Arrays are merged across all settings scopes…
All settings
Claude Code CLI · in the page
settings-reference
…ox settings | Any file | | [`sandbox.filesystem.denyRead`](#sandbox-filesystem-denyread) | Block [sandboxed](/docs/en/sandboxin…