You'll notice
The 'ask-session' tool policy value is deprecated and now just rewritten to 'ask'.
Setting a builtinToolPolicy entry to "ask-session" is now a formally deprecated value. It is flagged via BUILTIN_TOOL_POLICY_ASK_SESSION and is rewritten and read back as "ask".
Names in the bundlebuiltinToolPolicyask-session
Documented inclaude-code/claude-apps-gateway-config
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed since
Anthropic's documentation has since written up ask-session, on Configuration reference.
| <span id="builtintoolpolicy" />Built-in tool policy<br />`builtinToolPolicy` | `object` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Approval policy per built-in tool or argument-scoped rule such as Bash(curl \*). “ask” requires user a…third-party/claude-desktop/configuration see the edit
Confirmed since
Anthropic's documentation has since written up builtinToolPolicy, on Configuration reference.
| <span id="builtintoolpolicy" />Built-in tool policy<br />`builtinToolPolicy` | `object` | MDM + Bootstrap<br />Added in 1.8089.0 | — | Approval policy per built-in tool or argument-scoped rule such as Bash(curl \*). “ask” requires user a…third-party/claude-desktop/configuration see the edit
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees
Anthropic's documentation has since written up builtinToolPolicy, on Configuration reference.