denyRead
A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.
Under a relaxed sandbox filesystem policy, the outside-reads block does nothing and this is now logged.
Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.257.
In the changelogs
10Releases whose published page names denyRead.
-
v2.1.284
macOS sandbox blocks reading more paths
On macOS, the sandbox now blocks reading hidden files and some other paths even when you have not set any read restrictions
named in this entry, found in this entry's text
-
v2.1.284
Sandbox path rules now follow symbolic links and respect read-deny rules
Sandbox path patterns now match through linked folders, and
denyReadrules are no longer undercut by default writable foldersfound in this entry's text
-
v2.1.284
Sandbox read and write rules are now worked out together
Paths Claude's sandbox may write to are now worked out from
denyRead,allowReadand credentials togethernamed in this entry, found in this entry's text
-
v2.1.284
Sandbox no longer keeps npm logs and Claude debug folders writable when you deny reading them
The sandbox's default-writable ~/.npm/_logs and ~/.claude/debug folders now respect denyRead and denied credential files unless allowRead re-allows them
found in this entry's text
-
v2.1.283
One invalid sandbox deny entry now withholds the matching allow rules
If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it
found in this entry's text
-
v2.1.257
Relaxed filesystem policy disables the new block
Under a relaxed sandbox filesystem policy, the outside-reads block does nothing and this is now logged.
found in this entry's text
-
v2.1.198
Windows Sandbox: Per-Exec Deny Flags
found in this entry's text
- v2.1.186
-
v2.1.90
Linux Sandbox Improvements
found in this entry's text
-
v2.1.77
Sandbox
allowReadSettingfound in this entry's text
First cited
4The earliest release whose published evidence quoted denyRead was v2.1.90, 1 Apr 2026. That is the oldest release this project wrote about it, so it is a floor on the name's age and not the release that introduced it. It is not a presence reading: which builds carried the name is the table below.
Presence across releases
0The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.