{"name":"allowRead","slug":"allowread","family":"setting","title":"Settings keys","noun":"settings key","description":"The runner can warn about or block repo-committed settings that grant access outside the workspace.","description_source":"entry","described_by":{"version":"2.1.224","anchor":"runner-can-refuse-repo-committed-settings-that-reach-outside"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.284","builds":0,"mined_builds":127,"first_cited":{"version":"2.1.257","released_at":"2026-09-01 17:15:33","spans":2}},"aliases":[],"entries":[{"version":"2.1.284","anchor":"sandbox-glob-expansion-rewritten-to-follow-symlinks-plus-de","heading":"Sandbox path rules now follow symbolic links and respect read-deny rules","line":"Sandbox path patterns now match through linked folders, and `denyRead` rules are no longer undercut by default writable folders","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-read-rules-reworked-denyread-feeds-write-allowlist","heading":"Sandbox read and write rules are now worked out together","line":"Paths Claude's sandbox may write to are now worked out from `denyRead`, `allowRead` and credentials together","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-default-writable-npm-logs-and-claudedebug-n","heading":"Sandbox no longer keeps npm logs and Claude debug folders writable when you deny reading them","line":"The sandbox's default-writable ~\/.npm\/_logs and ~\/.claude\/debug folders now respect denyRead and denied credential files unless allowRead re-allows them","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.283","anchor":"sandbox-network-and-filesystem-grants-are-withheld-when-a-re","heading":"One invalid sandbox deny entry now withholds the matching allow rules","line":"If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it","released_at":"2026-09-25 18:46:11","reason":"found in this entry's text"},{"version":"2.1.268","anchor":"gatewayinternalnetworks-added-to-managed-settings-merge-exce","heading":"gatewayInternalNetworks added to managed-settings merge exception list","line":"gatewayInternalNetworks added to the list of managed-settings fields that replace rather than merge","released_at":"2026-09-10 18:41:11","reason":"found in this entry's text"},{"version":"2.1.260","anchor":"new-telemetry-event-tracks-sandbox-filesystem-rule-sync-comp","heading":"New telemetry event tracks sandbox filesystem rule sync completeness","line":"New telemetry tracks completeness of sandbox filesystem rule syncing.","released_at":"2026-09-03 22:32:02","reason":"found in this entry's text"},{"version":"2.1.257","anchor":"managedsettings-merge-mode-composition-rules-made-explicit","heading":"managedSettings 'merge' mode composition rules made explicit and expanded","line":"Managed settings merge mode now documents which fields the helper replaces wholesale rather than merging.","released_at":"2026-09-01 17:15:33","reason":"found in this entry's text"},{"version":"2.1.251","anchor":"a-stripped-down-sandbox-configuration-path","heading":"A stripped-down sandbox configuration path","line":"The sandbox builder can produce a policy-only mode, but nothing visible switches it on.","released_at":"2026-08-28 15:34:26","reason":"found in this entry's text"},{"version":"2.1.224","anchor":"runner-can-refuse-repo-committed-settings-that-reach-outside","heading":"Runner can refuse repo-committed settings that reach outside the workspace","line":"The runner can warn about or block repo-committed settings that grant access outside the workspace.","released_at":"2026-08-07 01:36:32","reason":"found in this entry's text"},{"version":"2.1.77","anchor":"sandbox-allowread-setting","heading":"Sandbox allowRead Setting","line":null,"released_at":"2026-03-16 22:16:52","reason":"found in this entry's text"}],"entries_total":10,"docs":[{"source":"claude-code","path":"claude-apps-gateway","title":"Claude apps gateway for Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry","documented":false},{"source":"claude-code","path":"managed-settings","title":"Deploy managed settings","documented":false},{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"self-hosted-environments-deploy","title":"Deploy self-hosted environments to production","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-code","path":"settings-reference","title":"All settings","documented":false},{"source":"claude-docs","path":"third-party\/claude-desktop\/code","title":"Code in Claude Desktop on 3P","documented":false},{"source":"claude-docs","path":"third-party\/claude-desktop\/configuration","title":"Configuration reference","documented":false}],"docs_total":8,"gates":[],"related":[],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/allowread","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}