{"name":"allowWrite","slug":"allowwrite","family":"setting","title":"Settings keys","noun":"settings key","description":"The sandbox builder can produce a policy-only mode, but nothing visible switches it on.","description_source":"entry","described_by":{"version":"2.1.251","anchor":"a-stripped-down-sandbox-configuration-path"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.284","builds":0,"mined_builds":127,"first_cited":null},"aliases":[],"entries":[{"version":"2.1.284","anchor":"linux-sandbox-warning-now-also-covers-read-globs-anchored-at","heading":"Linux sandbox warning now also flags broad read rules","line":"On Linux, the sandbox glob warning now also checks `filesystem.denyRead` and `filesystem.allowRead` patterns that start at the root or have no fixed folder","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-read-rules-reworked-denyread-feeds-write-allowlist","heading":"Sandbox read and write rules are now worked out together","line":"Paths Claude's sandbox may write to are now worked out from `denyRead`, `allowRead` and credentials together","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.283","anchor":"sandbox-network-and-filesystem-grants-are-withheld-when-a-re","heading":"One invalid sandbox deny entry now withholds the matching allow rules","line":"If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it","released_at":"2026-09-25 18:46:11","reason":"found in this entry's text"},{"version":"2.1.281","anchor":"git-bundle-upload-refuses-checkouts-under-a-home-directory-t","heading":"Git bundle upload refuses checkouts under a home directory that is itself a git checkout","line":"Cloud-session git upload now refuses or hardens checkouts sitting under a home directory that is itself a git repository","released_at":"2026-09-23 17:01:17","reason":"found in this entry's text"},{"version":"2.1.251","anchor":"a-stripped-down-sandbox-configuration-path","heading":"A stripped-down sandbox configuration path","line":"The sandbox builder can produce a policy-only mode, but nothing visible switches it on.","released_at":"2026-08-28 15:34:26","reason":"found in this entry's text"},{"version":"2.1.198","anchor":"windows-sandbox-per-exec-deny-flags","heading":"Windows Sandbox: Per-Exec Deny Flags","line":null,"released_at":"2026-07-01 16:50:16","reason":"found in this entry's text"}],"entries_total":6,"docs":[{"source":"claude-code","path":"managed-settings","title":"Deploy managed settings","documented":false},{"source":"claude-code","path":"sandbox-environments","title":"Choose a sandbox environment","documented":false},{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"self-hosted-environments-deploy","title":"Deploy self-hosted environments to production","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-code","path":"settings-example","title":"Example settings files","documented":false},{"source":"claude-code","path":"settings-reference","title":"All settings","documented":false}],"docs_total":7,"gates":[],"related":[],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/allowwrite","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}