What
WebFetch and WebSearch are the tools Claude uses to read web pages and search the web. In certain sessions, permission to use them can no longer be saved permanently or granted by add-ons.
- When it applies:
CLAUDE_CODE_PROJECTS_SESSIONis set, or thehearthbotMCP tool has been called with a URL that passes a check, or a further check the findings did not identify passes. - Saved choices: every place that saves your permission choice (the host dialog, the permission prompt,
PermissionRequesthook allows and the network-permission launcher) now drops allow rules for WebFetch and WebSearch. The rule for the request in hand (WebSearch itself, or WebFetchdomain:<host>) is kept but saved for the current session only. Rules from thesessionandcliArgsources are exempt. - Remove and replace updates for these tools are rewritten so stored deny and ask rules are kept.
- Hooks: a
PermissionRequesthook that allows a call has any updates that would loosen WebFetch or WebSearch rules stripped, and its allow for these tools is ignored. The existing rule that a confined session only takes grants from its command line is kept. - Plugins: a plugin's
tool.checkhook can only tighten these tools, not allow them ("plugins can only tighten ... permission in a Projects session"). - The protection is lifted only when the server payload carries
bot_protected_tengu_atomic_magpieas true, plus a further condition that was not read. Nothing has been read about thetengu_atomic_magpiegate.
Why
In these sessions, choosing "always allow" for a web fetch or search no longer lasts past the session, and hooks or plugins cannot quietly open these tools up. Expect to be asked again in each new session.
Names in the bundleCLAUDE_CODE_PROJECTS_SESSION
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Apart from the environment variable, how Claude Code decides a session is a Projects session is not stated.