Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

host

setting in the build JSON

A Claude Code settings key, read out of the shipped bundle. It has been in the build since v2.1.287, including the newest one read.

Resuming into a same-named repo from a different host can now be labelled host/repo to tell them apart.

Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.219.

First seen v2.1.287 1 Oct 2026
Last seen v2.1.288 2 Oct 2026
Builds2 / 131on this box, as of v2.1.288
Written about v2.0.55 first named in a changelog, 26 Nov 2025
v2.1.287in the build not in the build never minedv2.1.288

In the changelogs

60

Releases whose published page names host.

  1. v2.1.287
    Stricter reading of SSH-style git addresses

    Claude Code now rejects more malformed SSH-style git addresses and reads bracketed IPv6 hosts and user names differently

    found in this entry's text

  2. v2.1.285
    Passwords inside web addresses are now scrubbed more thoroughly

    Claude Code's secret redaction now catches more forms of usernames and passwords written inside URLs

    found in this entry's text

  3. v2.1.285
    Git addresses for plugins and marketplaces are checked more strictly

    Claude Code now refuses git addresses with certain odd characters when installing plugins or adding marketplaces, and explains which forms work

    found in this entry's text

  4. v2.1.285
    Login details inside URLs are more thoroughly hidden in logs

    Logs now mask usernames and passwords in URLs as :@ and also strip any extra @-separated parts that follow

    found in this entry's text

  5. v2.1.285
    Git addresses starting with git:// are now refused with a clear message

    Git addresses using git:// are now rejected because they are not encrypted, and the error lists the supported address forms

    found in this entry's text

  6. v2.1.285
    Hiding passwords in web addresses now catches more formats

    Hiding the username and password in web addresses now also covers quoted and punctuated forms

    found in this entry's text

  7. v2.1.283
    Claude Code can now clear the git credential helper for a single host

    Git settings passed through GIT_CONFIG_PARAMETERS may now give a per-host credential helper an empty value, which clears it

    found in this entry's text

  8. v2.1.283
    More local development domains are treated as your own machine

    Claude Code now treats localdev.me, local.gd, localhost.direct, ddev.site, lndo.site and lcl.host addresses as local

    found in this entry's text

  9. v2.1.282
    Plugin checks refuse repository paths that lead to network share folders

    When checking a plugin, Claude Code now refuses paths from a repository that lead to /net, /net/<host>, or /Network or /home on macOS

    found in this entry's text

  10. v2.1.281
    OTEL label validation with reserved names

    Custom telemetry labels are now checked: names use a limited character set, some names are reserved, and values must be short printable ASCII

    found in this entry's text

  11. v2.1.281
    Select list drops tint hover style; approval hook gets host

    Small internal changes: one select menu loses its tint hover style, tool approval now receives the host, and session roles pass through whole

    found in this entry's text

  12. v2.1.281
    Forwarded-call dispatch schema accepts request_id and instance_id

    Records of forwarded tool calls can now carry optional request_id and instance_id fields, and a malformed value is dropped instead of rejected

    found in this entry's text

  13. v2.1.281
    Directory sync protocol additions

    The directory sync protocol gains new state fields, a "held" result for the trash handler, and a count of already-published commits

    found in this entry's text

  14. v2.1.281
    Egress allowlist grammar and host placeholder strings

    Settings screens gain text describing allowed outbound-host entries and a host-list placeholder; a helper cache TTL field is tagged with a version

    found in this entry's text

  15. v2.1.280
    Proxy URL check strips credentials before hostname comparison

    Proxy no_proxy hostname checks now ignore any username/password embedded in the URL

    found in this entry's text

  16. v2.1.280
    New credential-redacting URL formatter

    New helper masks usernames and passwords embedded in URLs before display

    found in this entry's text

  17. v2.1.277
    New helper ir() detects wildcard characters in git/URL marketplace source strings

    New helper detects wildcard characters in git or URL marketplace source addresses

    found in this entry's text

  18. v2.1.277
    Proxy request forwarding gains an explicit header allow/deny list

    Proxy request forwarding now strips sensitive headers and keeps only an allowed set of prefixes

    found in this entry's text

  19. v2.1.277
    cancel_async_message logic unified between host and remote-control paths

    cancel_async_message handling is now shared between host and remote-control sessions

    found in this entry's text

  20. v2.1.271
    Artifact publish now checks a local host-server grant before declaring host: servers

    Publishing an artifact with local MCP servers now checks a host-app grant and can drop or block servers it doesn't cover

    found in this entry's text

  21. v2.1.271
    Session launch options gain ccrSessionUrl and sessionUploadsDir fields

    Session launch options now include ccrSessionUrl and sessionUploadsDir fields

    found in this entry's text

  22. v2.1.269
    New agent-SDK control-request: rename_session

    SDK control-request rename_session refined with remote/host distinction and a get_memory_dialog request added

    found in this entry's text

  23. v2.1.268
    New URL redaction helpers for stripping credentials/query/hash before logging or telemetry

    New helper functions strip credentials, query strings, and fragments from URLs before they're logged

    found in this entry's text

  24. v2.1.267
    New 'result_from' content block type for tool results tied to host classifier context

    Assistant transcripts can now include a result_from block linking a tool result to host classifier context

    found in this entry's text

  25. v2.1.265
    URLs with embedded credentials now rejected

    URLs containing a username or password, like user:pass@host, are now rejected during normalization

    found in this entry's text

  26. v2.1.260
    Bridge environment registration can now include a host profile

    Remote environment registration can now include a host's tool and MCP server profile.

    found in this entry's text

  27. v2.1.260
    AskUserQuestion "extended" question mode gated by env var, off by default

    An extended question mode is gated behind an env var and off by default.

    found in this entry's text

  28. v2.1.260
    Runtime-controllable browser tool exposed to published Artifacts via a built-in host server

    Published artifacts can now declare Claude's own browser tools as a host MCP server.

    found in this entry's text

  29. v2.1.260
    URL schema now rejects credentialed URLs and gained an allowHttp option

    MCP server URLs with embedded credentials are now rejected, and plain-http can be explicitly allowed.

    found in this entry's text

  30. v2.1.259
    New --permission-prompts host|none CLI/SDK option to silently auto-deny prompts

    A new --permission-prompts option lets print sessions auto-deny anything that would prompt instead of asking the host.

    found in this entry's text

  31. v2.1.259
    New SDK option permissionPrompts alongside permissionPromptToolName

    The Agent SDK query builder accepts a permissionPrompts option of host or none, passed through to the CLI.

    found in this entry's text

  32. v2.1.259
    New --permission-prompts none CLI flag for headless print sessions

    In print mode you can pick who answers permission prompts: the host, or none, which auto-denies without asking.

    found in this entry's text

  33. v2.1.257
    Diskless session hardening for device-hook templates and temp dir

    In a diskless session the device-hook template runner and the shared temp-directory helper now throw instead of touching disk.

    found in this entry's text

  34. v2.1.257
    Init frame schema gains 'host' and 'serving' fields for local tool serving to cloud sessions

    The init frame can announce the local machine and whether it serves Bash, Read, Write and Edit calls to a cloud session.

    found in this entry's text

  35. v2.1.251
    Connector names accept far more characters

    Connector names now allow almost any characters, with new checks against host-prefix and id-like names.

    found in this entry's text

  36. v2.1.247
    Directory trust can be judged strictly from saved state

    Directory trust can now be decided strictly from saved state when the host serves your files.

    found in this entry's text

  37. v2.1.246
    Artifact tool results go through a handler lookup

    Artifact tool results are rendered through a handler lookup instead of a long inline chain.

    found in this entry's text

  38. v2.1.246
    Model pricing can fall back to the host application

    When no pricing table is set, Claude Code can take one from the app it's embedded in.

    found in this entry's text

  39. v2.1.246
    Storage backend gains two host-supplied options with no caller

    Storage can accept a host-supplied config path and per-space service declarations, but nothing passes them.

    found in this entry's text

  40. v2.1.239
    Plugin ids with an @ earlier in the source resolve correctly

    Plugin sources containing an earlier @, like scoped packages, no longer get truncated ids.

    found in this entry's text

  41. v2.1.238
    Plugin marketplaces and archives can mint HTTP headers from a command

    Marketplaces and plugins can run a command to mint short-lived HTTP headers for fetching archives.

    found in this entry's text

  42. v2.1.234
    Git remote URLs can no longer smuggle a different host

    A crafted git remote URL can no longer trick Claude Code into using the wrong repo identity.

    found in this entry's text

  43. v2.1.234
    Network and Windows device paths refused in more places

    Windows device paths and network automount roots are now refused in more places, like memory files and edits.

    found in this entry's text

  44. v2.1.233
    macOS /net/<host> autofs paths treated as network paths

    macOS /net autofs paths are now treated as network paths, so previews are skipped and attaching one is refused.

    found in this entry's text

  45. v2.1.233
    Windows device-namespace paths are treated as network paths

    On Windows, odd device-style paths are now blocked from attachments, uploads and deep-link directories.

    found in this entry's text

  46. v2.1.233
    Network path detection now covers /net automount paths

    Automounted /net paths now count as network paths for file reads, writes and attachments.

    found in this entry's text

  47. v2.1.233
    Windows Bash argument scanning sees through --flag=value and NT device paths

    Windows command scanning now unwraps flag=value arguments and spots NT object-manager paths.

    found in this entry's text

  48. v2.1.232
    Log redaction now covers hostnames, IP addresses and domain lists

    Logs now hide hostnames and IPs and collapse long domain lists to a count.

    found in this entry's text

  49. v2.1.229
    TLS certificate details redacted from error text

    Certificate hostnames and IPs are replaced with placeholders in logs and error reports.

    found in this entry's text

  50. v2.1.229
    Per-session state replaces one process-wide globals object

    Process-wide state moved into per-session objects, groundwork for isolating multiple sessions in one process.

    found in this entry's text

  51. v2.1.223
    Stricter owner/repo validation for gh commands

    Malformed or sneaky owner/repo names are rejected before any gh command is built.

    found in this entry's text

  52. v2.1.219
    Repo-mismatch display disambiguates by host

    Resuming into a same-named repo from a different host can now be labelled host/repo to tell them apart.

    found in this entry's text

  53. v2.1.213
    Host OTLP Telemetry for SDK Integrations

    found in this entry's text

  54. v2.1.212
  55. v2.1.205
    Auto-mode repo visibility lookup

    found in this entry's text

  56. v2.1.196

    found in this entry's text

  57. v2.1.176
    Footer Link Badges

    found in this entry's text

  58. v2.1.119
    New Settings

    found in this entry's text

  59. v2.1.26
    InboxPoller Validation Improvements

    found in this entry's text

  60. v2.0.55
    Repository Hash Telemetry

    found in this entry's text

First cited

0

No release's published evidence quotes this name. The ledger indexes the Evidence lines of every changelog on this site, so this says nobody here has ever quoted it; it says nothing about how old the name is.

Presence across releases

1
BuildsHow manyDatesReading
v2.1.287 – v2.1.2882 builds1 Oct 2026 → 2 Oct 2026 ◆in the build

Build by build

2

One row per release since the first build this name was read out of. Absent means the build was read and the name was not in it, never mined means no bundle for that release was ever archived, and a declared type or a default is only ever what that release's own bundle stated.

BuildDateStateThe record behind it
v2.1.2871 Oct 2026·addedverdict: added
v2.1.2882 Oct 2026·presentverdict: present

Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.

Feedback