{"name":"denyRead","slug":"denyread","family":"setting","title":"Settings keys","noun":"settings key","description":"Under a relaxed sandbox filesystem policy, the outside-reads block does nothing and this is now logged.","description_source":"entry","described_by":{"version":"2.1.257","anchor":"relaxed-filesystem-policy-disables-the-new-block"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.284","builds":0,"mined_builds":127,"first_cited":{"version":"2.1.90","released_at":"2026-04-01 23:31:39","spans":4}},"aliases":[],"entries":[{"version":"2.1.284","anchor":"macos-sandbox-masked-files-and-degraded-paths-become-read-d","heading":"macOS sandbox blocks reading more paths","line":"On macOS, the sandbox now blocks reading hidden files and some other paths even when you have not set any read restrictions","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-glob-expansion-rewritten-to-follow-symlinks-plus-de","heading":"Sandbox path rules now follow symbolic links and respect read-deny rules","line":"Sandbox path patterns now match through linked folders, and `denyRead` rules are no longer undercut by default writable folders","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-read-rules-reworked-denyread-feeds-write-allowlist","heading":"Sandbox read and write rules are now worked out together","line":"Paths Claude's sandbox may write to are now worked out from `denyRead`, `allowRead` and credentials together","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.284","anchor":"sandbox-default-writable-npm-logs-and-claudedebug-n","heading":"Sandbox no longer keeps npm logs and Claude debug folders writable when you deny reading them","line":"The sandbox's default-writable ~\/.npm\/_logs and ~\/.claude\/debug folders now respect denyRead and denied credential files unless allowRead re-allows them","released_at":"2026-09-28 17:11:59","reason":"found in this entry's text"},{"version":"2.1.283","anchor":"sandbox-network-and-filesystem-grants-are-withheld-when-a-re","heading":"One invalid sandbox deny entry now withholds the matching allow rules","line":"If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it","released_at":"2026-09-25 18:46:11","reason":"found in this entry's text"},{"version":"2.1.257","anchor":"relaxed-filesystem-policy-disables-the-new-block","heading":"Relaxed filesystem policy disables the new block","line":"Under a relaxed sandbox filesystem policy, the outside-reads block does nothing and this is now logged.","released_at":"2026-09-01 17:15:33","reason":"found in this entry's text"},{"version":"2.1.198","anchor":"windows-sandbox-per-exec-deny-flags","heading":"Windows Sandbox: Per-Exec Deny Flags","line":null,"released_at":"2026-07-01 16:50:16","reason":"found in this entry's text"},{"version":"2.1.186","anchor":"bug-fixes","heading":"","line":null,"released_at":"2026-06-22 18:03:48","reason":"found in this entry's text"},{"version":"2.1.90","anchor":"linux-sandbox-improvements","heading":"Linux Sandbox Improvements","line":null,"released_at":"2026-04-01 23:31:39","reason":"found in this entry's text"},{"version":"2.1.77","anchor":"sandbox-allowread-setting","heading":"Sandbox allowRead Setting","line":null,"released_at":"2026-03-16 22:16:52","reason":"found in this entry's text"}],"entries_total":10,"docs":[{"source":"claude-code","path":"claude-apps-gateway","title":"Claude apps gateway for Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry","documented":false},{"source":"claude-code","path":"communications-kit","title":"Communications kit","documented":false},{"source":"claude-code","path":"managed-settings","title":"Deploy managed settings","documented":false},{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"security","title":"Security","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-code","path":"settings-example","title":"Example settings files","documented":false},{"source":"claude-code","path":"settings-reference","title":"All settings","documented":false}],"docs_total":8,"gates":[],"related":[],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/denyread","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}