--restricted
A Claude Code CLI flag, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.
What it is
Start in restricted mode. Use it when an evaluation harness drives claude on a shared machine and Claude Code must not run commands or read that machine's user and project settings. Claude Code removes the built-in tools that run commands or code, and WebFetch, unless you name them individually in --tools, not through its default preset. It also confines the built-in file tools to the [working directories](/docs/en/permissions#working-directories), loads only [managed settings](/docs/en/managed-settings) and --settings, and refuses [bypassPermissions](/docs/en/permission-modes#skip-all-checks-with-bypasspermissions-mode). Requires Claude Code v2.1.248 or later
Anthropic's own wording. Read off CLI reference, captured 2026-08-28.
Presence across releases
The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
Changelog entries naming it
-
v2.1.248New
--restrictedsession modeNew --restricted flag starts a locked-down session with no shell tools and no settings files.
named in this entry
-
v2.1.248Restricted sessions drop implicit file allowances and cannot be talked out of a denial
Restricted sessions drop implicit file allowances, and a denial can't be argued away.
named in this entry
-
v2.1.248Prewarmed and dispatched background sessions inherit restriction
Background sessions spawned from a restricted session stay restricted.
named in this entry
-
v2.1.248Restricted sessions handled the same way whether set by flag or environment
Setting CLAUDE_CODE_RESTRICTED now restricts a session exactly as --restricted does.
named in this entry
-
v2.1.248New sessions started from fleet view inherit
--restrictedNew background sessions started from a restricted session inherit --restricted.
named in this entry
-
v2.1.248
--restrictedconfines file tools to the working directoryRestricted sessions block file paths outside the working directory with no approval offered.
named in this entry
-
v2.1.248Claude in Chrome is now also skipped in restricted sessions
Restricted sessions skip Claude in Chrome browser wiring, same as safe mode.
named in this entry
-
v2.1.248Auto-memory is off in restricted sessions
Restricted sessions never write auto-memory, regardless of your settings.
named in this entry
-
v2.1.248
--restrictedrefuses attachments from outside the working directoryIn restricted mode, attachments from outside your working directory are rejected up front.
named in this entry
-
v2.1.248Restricted sessions deny out-of-directory file access outright
Restricted sessions now deny out-of-directory reads and writes outright, with no prompt.
named in this entry
Documentation pages
- CLI reference reference table Claude Code CLI
- Claude Code changelog mentions it Claude Code CLI
- Choose a permission mode mentions it Claude Code CLI
A reference table page is one whose own table defines this name, and it is where the description above came from. A page that mentions it carries the name somewhere in its text and may say nothing about it at all. Every page carrying it.
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the CLI flag does. All CLI flags.