allowRead
A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.
The runner can warn about or block repo-committed settings that grant access outside the workspace.
Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.224.
In the changelogs
10Releases whose published page names allowRead.
-
v2.1.284
Sandbox path rules now follow symbolic links and respect read-deny rules
Sandbox path patterns now match through linked folders, and
denyReadrules are no longer undercut by default writable foldersfound in this entry's text
-
v2.1.284
Sandbox read and write rules are now worked out together
Paths Claude's sandbox may write to are now worked out from
denyRead,allowReadand credentials togethernamed in this entry, found in this entry's text
-
v2.1.284
Sandbox no longer keeps npm logs and Claude debug folders writable when you deny reading them
The sandbox's default-writable ~/.npm/_logs and ~/.claude/debug folders now respect denyRead and denied credential files unless allowRead re-allows them
named in this entry, found in this entry's text
-
v2.1.283
One invalid sandbox deny entry now withholds the matching allow rules
If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it
found in this entry's text
-
v2.1.268
gatewayInternalNetworks added to managed-settings merge exception list
gatewayInternalNetworks added to the list of managed-settings fields that replace rather than merge
found in this entry's text
-
v2.1.260
New telemetry event tracks sandbox filesystem rule sync completeness
New telemetry tracks completeness of sandbox filesystem rule syncing.
found in this entry's text
-
v2.1.257
managedSettings 'merge' mode composition rules made explicit and expanded
Managed settings merge mode now documents which fields the helper replaces wholesale rather than merging.
found in this entry's text
-
v2.1.251
A stripped-down sandbox configuration path
The sandbox builder can produce a policy-only mode, but nothing visible switches it on.
found in this entry's text
-
v2.1.224
Runner can refuse repo-committed settings that reach outside the workspace
The runner can warn about or block repo-committed settings that grant access outside the workspace.
found in this entry's text
-
v2.1.77
Sandbox
allowReadSettingfound in this entry's text
First cited
2The earliest release whose published evidence quoted allowRead was v2.1.257, 1 Sep 2026. That is the oldest release this project wrote about it, so it is a floor on the name's age and not the release that introduced it. It is not a presence reading: which builds carried the name is the table below.
Presence across releases
0The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.