You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Cloud SessionsArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What
When Claude Code creates a remote session, the request now includes disallowed_tools. These are tools the session is not allowed to use. The list combines the caller's own disallowedTools with the built-in list used for device-bound sessions. The request carries disallowedTools alongside allowedTools.
Before, the request sent only the fixed built-in list, and only for device-bound sessions.
Why
Tools you block when starting a remote session are now actually passed on to that session, instead of being dropped.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up disallowedTools, on Create custom subagents.* **[Frontmatter fields](#supported-frontmatter-fields)**: `description`, `tools`, `disallowedTools`, `model`, `permissionMode`, `mcpServers`, `hooks`, `maxTurns`, `skills`, `initialPrompt`, `memory`, `effort`, `background`, `omitClaudeMd`…sub-agentssee the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up disallowedTools, on Create custom subagents.