--disallowed-tools
A Claude Code CLI flag, read out of the shipped bundle. It has been in the build since v2.1.138, including the newest one read.
What it is
Deny rules. A bare tool name removes the matching tools from Claude's context: "Edit" removes Edit, "" removes every tool, and "mcp__" removes every MCP tool. A scoped rule such as Bash(rm *) leaves the tool available and denies only matching calls. A rule naming [EndConversation](/docs/en/tools-reference#endconversation-tool-behavior) can't remove it while any other tool remains
Anthropic's own wording. Read off CLI reference, captured 2026-08-28.
Presence across releases
| Releases | Reading | Declared type | Default |
|---|---|---|---|
| 2.1.245 – 2.1.250 5 releases | never mined | — | — |
| 2.1.138 – 2.1.243 95 releases | in the build | — | — |
A row reading never mined is a release with no archived bundle behind it. Nothing was read out of it, so nothing here says whether the name was in it. A declared type or a default is only ever what that release's own bundle stated.
Changelog entries naming it
No changelog entry here has ever named it. That is a statement about what has been written, not about the name: it has been in the build since v2.1.138 without anybody writing a line about it.
Documentation pages
- CLI reference reference table Claude Code CLI
- Claude Code changelog mentions it Claude Code CLI
- Error reference mentions it Claude Code CLI
- Fullscreen rendering mentions it Claude Code CLI
- Customize sessions in self-hosted environments mentions it Claude Code CLI
A reference table page is one whose own table defines this name, and it is where the description above came from. A page that mentions it carries the name somewhere in its text and may say nothing about it at all. Every page carrying it.
Names beside it
Every CLI flag in the inventory starting --disallowed, up to twelve of them.
--disallowedNo description from anybody. 2.1.138
--disallowedToolsDeny rules. A bare tool name removes the matching tools from Claude's context: "Edit" removes Edit, "" removes every tool, and "mcp__" removes every MCP tool. A scoped rule such as Bash(rm *) leaves the tool available and denies only matching calls. A rule naming [EndConversation](/docs/en/tools-reference#endconversation-tool-behavior) can't remove it while any other tool remains never mined
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the CLI flag does. All CLI flags.