Plugins and hooks gain renamed filesystem actions, new capabilities for settings/env/session usage, stricter validation, and a new terminal UI system
What
- The plugin capability actions
fs.readFile,fs.writeFile, andfs.listDirare renamed tofs.read,fs.write, andfs.list(including the underlying IPC event name). - Plugins and hooks gain four new capabilities:
session.usage(read session usage stats),settings.read(read merged settings from a named source), andenv.get/env.set(read and write environment variables) — all fully wired with permission checks and handlers. - New validation guards these and other hook APIs: a hook's
on('event')matcher can't be a nested object matched against a primitive;next(e)handlers forenv.get/env.setcan only change the value's data, not other fields; andui.messagecalls can't rewrite fields likesurface,component,requestId,element, ormodule(onlydatamay change), and are rejected if their serialized data is too deeply nested or too large. - A large new subsystem lets plugins mount custom terminal UI elements ("Clients") declared via a
surfacefield inhooks.json. It handles rendering, mounting/unmounting, resizing, mouse and keyboard input, hover/focus state, a row-budget that can reject renders pushing a dialog over its row limit, and message dispatch between the plugin and its UI.
Why Together these give plugins and hooks a broader, more capable API — access to environment variables, settings, and session usage, plus the ability to draw real interactive terminal UI — while the renamed, more consistent action names and new validation keep that expanded surface from letting a plugin corrupt data it shouldn't touch or send oversized payloads.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
In [plan mode](/docs/en/permission-modes#analyze-before-you-edit-with-plan-mode), a permission prompt appears before Claude records a GIF, opens a new tab, or runs a shortcut. If [bypass permissions mode is available](/docs/en/permission-m…chrome see the edit
Most of the silence problems in this section span a whole workspace or channel and come down to configuration. If Claude stays silent in one thread but answers everywhere else, a setting isn't the cause. Either Claude's session for that th…claude-tag/admins/troubleshooting see the edit
* Fixed read-only git commands in Bash unexpectedly asking for permission after a session had been running for a while (regression in 2.1.269)changelog see the edit
Claude can call the endpoint with `curl`, an AWS SDK, or the AWS CLI. The sandbox holds no real AWS credentials, so a CLI or SDK signs the request with placeholder values; Agent Proxy strips that signature and re-signs with the stored cred…claude-tag/admins/connections/custom see the edit
- `type: "session.usage"`api/beta/sessions/events see the edit
Anthropic's documentation has since written up session.usage, on Events.