Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.223 Home All releases olderv2.1.222 v2.1.224newer

SDK stream emits a permission_denied system message

You'll notice
Useful3 Signal0
SDK Notable not in their notes

SDK clients now get an explicit system message when a tool call is denied instead of guessing.

permission_denied
What

The control-protocol session can now push a system message to the SDK stream whenever a tool call is denied, so clients can react to denials instead of inferring them from the tool result.

Details
  • New emitPermissionDenied method on the control-protocol session class enqueues a message with type: "system" and subtype: "permission_denied".
  • Payload carries tool_name, tool_use_id, agent_id, decision_reason_type, a serialized decision_reason, the deny message, a uuid and the session id.
  • On the stdio createCanUseTool path it fires on any deny.
  • On the non-stdio path it fires only when a new helper confirms the tool_use id actually appears in the message content and the abort signal has not fired.
Evidence

decision_reason_type

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.223 →