4 pages for filesystem.denywrite.
Titles and paths first, then pages whose text carries it. Each row opens that page as this site last read it.
Deploy managed settings
Claude Code CLI · in the page
managed-settings
…nothing until you fix the deny list. * While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.a…
Configure the sandboxed Bash tool
Claude Code CLI · in the page
sandboxing
…ath-prefixes). You can also deny write or read access using `sandbox.filesystem.denyWrite` and `sandbox.filesystem.denyRead`, and re-allow specific paths within a denied region using `sandbox.filesys…
Claude Code settings
Claude Code CLI · in the page
settings
…d", "~/.kube"]` | | `filesystem.denyWrite` | Paths where sandboxed commands cannot write. Arrays are merged across all settings scope…
All settings
Claude Code CLI · in the page
settings-reference
…ox settings | Any file | | [`sandbox.filesystem.denyWrite`](#sandbox-filesystem-denywrite) | Block [sandboxed](/docs/en/sandboxin…