Some programs embed Claude Code and show its permission prompts in their own dialog. A permission prompt is the question Claude Code asks before it runs a tool, such as editing a file or running a command. In that setup, Claude Code now keeps its own record of which can_use_tool requests it actually sent to the host's dialog.
- A request is recorded when Claude Code sends it to the host's permission prompt.
- A successful answer counts as answered in the host's dialog only if Claude Code recorded that request first.
- Once Claude Code has used that record, it is cleared, so a single answer counts one time only.
Previously, any matching answer was recorded as answered in the host's dialog, with no check that the request had gone through the host's prompt.
A stray or forged answer can no longer mark a tool approval as given by a person in the host's dialog when that dialog never showed the request.
It is not clear whether the previous build already let each answer count only once.