Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Projects sessions keep WebFetch and WebSearch approvals to the current session

In Projects sessions, 'always allow' for WebFetch or WebSearch is saved for the session only, and hooks and plugins can no longer grant these tools

Group of 3 You'll notice No documentation found Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release

What

WebFetch and WebSearch are the tools Claude uses to read web pages and search the web. In certain sessions, permission to use them can no longer be saved permanently or granted by add-ons.

  • When it applies: CLAUDE_CODE_PROJECTS_SESSION is set, or the hearthbot MCP tool has been called with a URL that passes a check, or a further check the findings did not identify passes.
  • Saved choices: every place that saves your permission choice (the host dialog, the permission prompt, PermissionRequest hook allows and the network-permission launcher) now drops allow rules for WebFetch and WebSearch. The rule for the request in hand (WebSearch itself, or WebFetch domain:<host>) is kept but saved for the current session only. Rules from the session and cliArg sources are exempt.
  • Remove and replace updates for these tools are rewritten so stored deny and ask rules are kept.
  • Hooks: a PermissionRequest hook that allows a call has any updates that would loosen WebFetch or WebSearch rules stripped, and its allow for these tools is ignored. The existing rule that a confined session only takes grants from its command line is kept.
  • Plugins: a plugin's tool.check hook can only tighten these tools, not allow them ("plugins can only tighten ... permission in a Projects session").
  • The protection is lifted only when the server payload carries bot_protected_tengu_atomic_magpie as true, plus a further condition that was not read. Nothing has been read about the tengu_atomic_magpie gate.

Why

In these sessions, choosing "always allow" for a web fetch or search no longer lasts past the session, and hooks or plugins cannot quietly open these tools up. Expect to be asked again in each new session.

Read from
Names in the bundleCLAUDE_CODE_PROJECTS_SESSION
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtApart from the environment variable, how Claude Code decides a session is a Projects session is not stated.

See this entry in the whole of v2.1.284 →

Feedback