-
v2.1.277Host filesystem bridge gains read/stat options and ancestor-search bound
Plugin filesystem read and stat calls gain configurable options, and ancestor search gets an optional lower bound
found in this entry's text
-
v2.1.275'icon' field replaces deprecated 'favicon' in artifact publish, with new writer-access disclosure on read/list
Artifact icon field replaces the deprecated favicon parameter, and read/list now shows write access
found in this entry's text
-
v2.1.275Artifacts read/list now reports and enforces writer vs viewer access
Artifact read/list actions now report and enforce whether you have edit access, not just view access
found in this entry's text
-
v2.1.275artifact read: falls back to reading it as a frozen artifact type link on a 404
Reading an artifact that 404s now falls back to returning its type declaration if it's a frozen artifact type
found in this entry's text
-
v2.1.275Artifact list/read results now report per-artifact writer access instead of an org-wide 'shared' bucket
Artifact permissions now check per-artifact edit access instead of whether you belong to the artifact's organization
found in this entry's text
-
v2.1.274Reading public artifacts from outside your org now goes through a consent check instead of a flat block
Reading files from public, out-of-org artifacts now goes through a consent check instead of being flatly blocked
found in this entry's text
-
v2.1.271"quickstart" artifact action added to the non-mutating action allowlist
The artifact tool's new "quickstart" action no longer requires write confirmation
found in this entry's text
-
v2.1.268Artifact tool: list_files/read_file now resolve and return a
type object for type-locked files
Artifact file listing and reading now include the artifact's declared type when the file is type-locked
found in this entry's text
-
v2.1.268Artifact read-permission denial path unified across list_files/read_file/verify/read actions
Artifact read-permission errors now use the same wording across list_files, read_file, verify, and read actions
found in this entry's text
-
v2.1.267fs.readFile/fs.writeFile/fs.listDir renamed to fs.read/fs.write/fs.list; 'readFile' IPC event renamed to 'read'
File-system permission events renamed: fs.readFile/writeFile/listDir become fs.read/write/list
found in this entry's text
-
v2.1.265Artifact tool actions being consolidated into list/read with a scope parameter
Artifact tool messages now describe actions as unified list/read calls with a scope, not old per-type names
found in this entry's text
-
v2.1.261Per-URL ask/deny rules for artifact reads, page-data reads, diagnostics, and database reads
Artifact reads, diagnostics, and database reads now check per-URL deny/ask rules before falling back to session consent.
found in this entry's text
-
v2.1.261Artifact tool 'verify' action gains an approval/target-changed check
Artifact verify actions now re-check approval before proceeding, matching other read actions.
found in this entry's text
-
v2.1.260Artifact
get_endpoints/call_endpoint actions renamed and scoped to remote-cowork entrypoints only
Renamed endpoint actions remain invisible outside remote-cowork sessions.
found in this entry's text
-
v2.1.260Artifact 'read' action's inline threshold made configurable
The artifact inline-read threshold is now configurable rather than fixed.
found in this entry's text
-
v2.1.260Artifact read now passes a files-listed hint for artifact reads
Artifact reads now pass a hint indicating whether files were already listed.
found in this entry's text
-
v2.1.260Artifact tool now enforces deny permission rules on all non-read actions
The artifact tool now checks deny rules before running any non-read action.
found in this entry's text
-
v2.1.259Artifact pin/unpin — gated off by default
Artifacts gain full pin and unpin actions, wired end to end but off by default behind a gate with an env override.
found in this entry's text
-
v2.1.257Artifact comments/watch tool renames its action vocabulary
Artifact comment actions are respelled: read replaces comments, watch with on false replaces unwatch, and old names now error.
named in this entry, found in this entry's text
-
v2.1.251MCP auth now tracks which kind of login token it used
MCP connection failures now record which kind of login token was in play.
found in this entry's text
-
v2.1.248Claude Design 403 message says whether your credential has access
A Claude Design 403 now says whether your credential actually grants access.
found in this entry's text
-
v2.1.239Artifact tool gains a
read action, with multi-file browsing and delete built but gated off
Claude can now read back a published artifact's contents; browsing, multi-file publishing and deletion are built but off.
found in this entry's text
-
v2.1.239Artifact failure messages point at the tool's own read action instead of WebFetch
Failed artifact publishes now tell Claude to re-read via the artifact tool, not WebFetch.
found in this entry's text
-
v2.1.239Workflow tool gains run operations, with the auto-approval hook switched off
The workflow tool understands run-based commands that bypass the usual allow and deny rule lookup.
found in this entry's text
-
v2.1.228Bundled SDK ships a runtime for server-managed agent work
The bundled SDK carries a worker that polls a server for agent work, unreachable from normal CLI use.
found in this entry's text
-
v2.1.223Skills and jobs load through the storage sidecar
Skill listing and job tracking now go through the storage layer instead of touching files directly.
found in this entry's text
-
v2.1.182Design MCP Connector Scope Auto-Expansion
found in this entry's text
-
v2.1.178/design-login — Standalone Design-System Authorization
found in this entry's text
-
v2.1.174Projects Tool — Read and Write claude.ai Project Docs
found in this entry's text
-
v2.1.169
/design-sync Skill — Sync React Design Systems to Claude Design
found in this entry's text
-
v2.0.50MCP CLI Endpoint
found in this entry's text
-
v2.0.2Fixed Stale Credential Cache
found in this entry's text