host
A Claude Code settings key, read out of the shipped bundle. It has been in the build since v2.1.287, including the newest one read.
Resuming into a same-named repo from a different host can now be labelled host/repo to tell them apart.
Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.219.
In the changelogs
60Releases whose published page names host.
-
v2.1.287
Stricter reading of SSH-style git addresses
Claude Code now rejects more malformed SSH-style git addresses and reads bracketed IPv6 hosts and user names differently
found in this entry's text
-
v2.1.285
Passwords inside web addresses are now scrubbed more thoroughly
Claude Code's secret redaction now catches more forms of usernames and passwords written inside URLs
found in this entry's text
-
v2.1.285
Git addresses for plugins and marketplaces are checked more strictly
Claude Code now refuses git addresses with certain odd characters when installing plugins or adding marketplaces, and explains which forms work
found in this entry's text
-
v2.1.285
Login details inside URLs are more thoroughly hidden in logs
Logs now mask usernames and passwords in URLs as :@ and also strip any extra @-separated parts that follow
found in this entry's text
-
v2.1.285
Git addresses starting with git:// are now refused with a clear message
Git addresses using git:// are now rejected because they are not encrypted, and the error lists the supported address forms
found in this entry's text
-
v2.1.285
Hiding passwords in web addresses now catches more formats
Hiding the username and password in web addresses now also covers quoted and punctuated forms
found in this entry's text
-
v2.1.283
Claude Code can now clear the git credential helper for a single host
Git settings passed through
GIT_CONFIG_PARAMETERSmay now give a per-host credential helper an empty value, which clears itfound in this entry's text
-
v2.1.283
More local development domains are treated as your own machine
Claude Code now treats localdev.me, local.gd, localhost.direct, ddev.site, lndo.site and lcl.host addresses as local
found in this entry's text
-
v2.1.282
Plugin checks refuse repository paths that lead to network share folders
When checking a plugin, Claude Code now refuses paths from a repository that lead to /net, /net/<host>, or /Network or /home on macOS
found in this entry's text
-
v2.1.281
OTEL label validation with reserved names
Custom telemetry labels are now checked: names use a limited character set, some names are reserved, and values must be short printable ASCII
found in this entry's text
-
v2.1.281
Select list drops tint hover style; approval hook gets host
Small internal changes: one select menu loses its tint hover style, tool approval now receives the host, and session roles pass through whole
found in this entry's text
-
v2.1.281
Forwarded-call dispatch schema accepts request_id and instance_id
Records of forwarded tool calls can now carry optional
request_idandinstance_idfields, and a malformed value is dropped instead of rejectedfound in this entry's text
-
v2.1.281
Directory sync protocol additions
The directory sync protocol gains new state fields, a "held" result for the trash handler, and a count of already-published commits
found in this entry's text
-
v2.1.281
Egress allowlist grammar and host placeholder strings
Settings screens gain text describing allowed outbound-host entries and a host-list placeholder; a helper cache TTL field is tagged with a version
found in this entry's text
-
v2.1.280
Proxy URL check strips credentials before hostname comparison
Proxy no_proxy hostname checks now ignore any username/password embedded in the URL
found in this entry's text
-
v2.1.280
New credential-redacting URL formatter
New helper masks usernames and passwords embedded in URLs before display
found in this entry's text
-
v2.1.277
New helper
ir()detects wildcard characters in git/URL marketplace source stringsNew helper detects wildcard characters in git or URL marketplace source addresses
found in this entry's text
-
v2.1.277
Proxy request forwarding gains an explicit header allow/deny list
Proxy request forwarding now strips sensitive headers and keeps only an allowed set of prefixes
found in this entry's text
-
v2.1.277
cancel_async_message logic unified between host and remote-control paths
cancel_async_message handling is now shared between host and remote-control sessions
found in this entry's text
-
v2.1.271
Artifact publish now checks a local host-server grant before declaring host: servers
Publishing an artifact with local MCP servers now checks a host-app grant and can drop or block servers it doesn't cover
found in this entry's text
-
v2.1.271
Session launch options gain ccrSessionUrl and sessionUploadsDir fields
Session launch options now include ccrSessionUrl and sessionUploadsDir fields
found in this entry's text
-
v2.1.269
New agent-SDK control-request: rename_session
SDK control-request rename_session refined with remote/host distinction and a get_memory_dialog request added
found in this entry's text
-
v2.1.268
New URL redaction helpers for stripping credentials/query/hash before logging or telemetry
New helper functions strip credentials, query strings, and fragments from URLs before they're logged
found in this entry's text
-
v2.1.267
New 'result_from' content block type for tool results tied to host classifier context
Assistant transcripts can now include a result_from block linking a tool result to host classifier context
found in this entry's text
-
v2.1.265
URLs with embedded credentials now rejected
URLs containing a username or password, like user:pass@host, are now rejected during normalization
found in this entry's text
-
v2.1.260
Bridge environment registration can now include a host profile
Remote environment registration can now include a host's tool and MCP server profile.
found in this entry's text
-
v2.1.260
AskUserQuestion "extended" question mode gated by env var, off by default
An extended question mode is gated behind an env var and off by default.
found in this entry's text
-
v2.1.260
Runtime-controllable browser tool exposed to published Artifacts via a built-in host server
Published artifacts can now declare Claude's own browser tools as a host MCP server.
found in this entry's text
-
v2.1.260
URL schema now rejects credentialed URLs and gained an allowHttp option
MCP server URLs with embedded credentials are now rejected, and plain-http can be explicitly allowed.
found in this entry's text
-
v2.1.259
New
--permission-prompts host|noneCLI/SDK option to silently auto-deny promptsA new --permission-prompts option lets print sessions auto-deny anything that would prompt instead of asking the host.
found in this entry's text
-
v2.1.259
New SDK option
permissionPromptsalongside permissionPromptToolNameThe Agent SDK query builder accepts a permissionPrompts option of host or none, passed through to the CLI.
found in this entry's text
-
v2.1.259
New
--permission-prompts noneCLI flag for headless print sessionsIn print mode you can pick who answers permission prompts: the host, or none, which auto-denies without asking.
found in this entry's text
-
v2.1.257
Diskless session hardening for device-hook templates and temp dir
In a diskless session the device-hook template runner and the shared temp-directory helper now throw instead of touching disk.
found in this entry's text
-
v2.1.257
Init frame schema gains 'host' and 'serving' fields for local tool serving to cloud sessions
The init frame can announce the local machine and whether it serves Bash, Read, Write and Edit calls to a cloud session.
found in this entry's text
-
v2.1.251
Connector names accept far more characters
Connector names now allow almost any characters, with new checks against host-prefix and id-like names.
found in this entry's text
-
v2.1.247
Directory trust can be judged strictly from saved state
Directory trust can now be decided strictly from saved state when the host serves your files.
found in this entry's text
-
v2.1.246
Artifact tool results go through a handler lookup
Artifact tool results are rendered through a handler lookup instead of a long inline chain.
found in this entry's text
-
v2.1.246
Model pricing can fall back to the host application
When no pricing table is set, Claude Code can take one from the app it's embedded in.
found in this entry's text
-
v2.1.246
Storage backend gains two host-supplied options with no caller
Storage can accept a host-supplied config path and per-space service declarations, but nothing passes them.
found in this entry's text
-
v2.1.239
Plugin ids with an @ earlier in the source resolve correctly
Plugin sources containing an earlier @, like scoped packages, no longer get truncated ids.
found in this entry's text
-
v2.1.238
Plugin marketplaces and archives can mint HTTP headers from a command
Marketplaces and plugins can run a command to mint short-lived HTTP headers for fetching archives.
found in this entry's text
-
v2.1.234
Git remote URLs can no longer smuggle a different host
A crafted git remote URL can no longer trick Claude Code into using the wrong repo identity.
found in this entry's text
-
v2.1.234
Network and Windows device paths refused in more places
Windows device paths and network automount roots are now refused in more places, like memory files and edits.
found in this entry's text
-
v2.1.233
macOS
/net/<host>autofs paths treated as network pathsmacOS /net autofs paths are now treated as network paths, so previews are skipped and attaching one is refused.
found in this entry's text
-
v2.1.233
Windows device-namespace paths are treated as network paths
On Windows, odd device-style paths are now blocked from attachments, uploads and deep-link directories.
found in this entry's text
-
v2.1.233
Network path detection now covers /net automount paths
Automounted /net paths now count as network paths for file reads, writes and attachments.
found in this entry's text
-
v2.1.233
Windows Bash argument scanning sees through
--flag=valueand NT device pathsWindows command scanning now unwraps flag=value arguments and spots NT object-manager paths.
found in this entry's text
-
v2.1.232
Log redaction now covers hostnames, IP addresses and domain lists
Logs now hide hostnames and IPs and collapse long domain lists to a count.
found in this entry's text
-
v2.1.229
TLS certificate details redacted from error text
Certificate hostnames and IPs are replaced with placeholders in logs and error reports.
found in this entry's text
-
v2.1.229
Per-session state replaces one process-wide globals object
Process-wide state moved into per-session objects, groundwork for isolating multiple sessions in one process.
found in this entry's text
-
v2.1.223
Stricter owner/repo validation for gh commands
Malformed or sneaky owner/repo names are rejected before any gh command is built.
found in this entry's text
-
v2.1.219
Repo-mismatch display disambiguates by host
Resuming into a same-named repo from a different host can now be labelled host/repo to tell them apart.
found in this entry's text
-
v2.1.213
Host OTLP Telemetry for SDK Integrations
found in this entry's text
-
v2.1.212
GrowthBook Authenticated Feature Flag Fetch [Gradual Rollout]
found in this entry's text
-
v2.1.205
Auto-mode repo visibility lookup
found in this entry's text
- v2.1.196
-
v2.1.176
Footer Link Badges
found in this entry's text
-
v2.1.119
New Settings
found in this entry's text
-
v2.1.26
InboxPoller Validation Improvements
found in this entry's text
-
v2.0.55
Repository Hash Telemetry
found in this entry's text
First cited
0No release's published evidence quotes this name. The ledger indexes the Evidence lines of every changelog on this site, so this says nobody here has ever quoted it; it says nothing about how old the name is.
Presence across releases
1Build by build
2One row per release since the first build this name was read out of. Absent means the build was read and the name was not in it, never mined means no bundle for that release was ever archived, and a declared type or a default is only ever what that release's own bundle stated.
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.