{"version":"2.1.281","anchor":"disallowed-tools-is-now-accepted-when-starting-a-cloud-ses","canonical_anchor":"disallowed-tools-is-now-accepted-when-starting-a-cloud-ses","heading":"Cloud sessions now accept --disallowed-tools when starting, with clear errors on attach and for unclosed rules","tier":"use","area":"Cloud Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/disallowed-tools-is-now-accepted-when-starting-a-cloud-ses","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Cloud sessions now accept --disallowed-tools when starting, with clear errors on attach and for unclosed rules\n\n--disallowed-tools now passes through to new cloud sessions; attaching with a deny list or an unclosed rule gets a clear error\n\n**What**\n\n`--disallowed-tools` sets deny rules, which list the tools or tool uses Claude may not use. When starting a cloud-hosted session, it used to be refused outright. It is now passed through for new sessions.\n\n- Attaching to an existing cloud session with flags that would change its deny list is refused. The message says the flag \"cannot change an existing cloud session, which keeps the deny list it was created with\" and tells you to drop the flag, or start a new session with it.\n\n- A rule that opens a parenthesis and never closes it, such as `Bash(rm *`, is refused with its own error instead of being silently dropped. The message asks you to close the parenthesis and run the command again.\n\n- The general refusal for restrictions a cloud session cannot enforce now reads \"does not enforce these tool restrictions yet\" instead of \"does not enforce tool restrictions yet\".\n\nThe new refusal reasons are `attach_restriction` and `deny_rule_unclosed`.\n\n**Why**\n\nIf you script remote runs, you can now set a deny list when a cloud session is created. The new errors tell you when a deny rule would not take effect, instead of the rule quietly disappearing.\n\n- Area: Cloud Sessions\n- Names: `--disallowed-tools`\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 1\/5"}