You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
SDKArea: what it touches
RemovedKind: in v2.1.285,
ImprovementsSection of the release
What
These changes affect people who build on the Anthropic SDK bundled with Claude Code, especially its environment worker. The environment worker is the component that runs managed-agent sessions on your own machines.
unrestrictedPaths is no longer supported by the agent toolset (AgentToolContext) or by EnvironmentWorker. Passing it now throws an error. Before, it was accepted.
The file tools (read, write, edit, glob, grep) are always kept inside the working directory plus allowedRoots. In the worker, that means workdir plus the memory folders.
EnvironmentWorker now takes a per-item ANTHROPIC_WORK_SECRET and reads a sessions_token from it. It mounts and syncs session memory stores using memorySyncIntervalMs and memorySyncDeletions.
An optional workspace_id, sent as the anthropic-workspace-id header, is now available on batches, deployment runs, agent versions, and memory and work calls.
New endpoints add and remove workspaces on federation rules.
The work heartbeat, the regular check-in that keeps a work item claimed, now ends with lease_lost, assumed_lost or heartbeat_rejected and uses a request timeout. Before, it simply aborted the work item.
Why
Code that passes unrestrictedPaths will now fail, so remove the option and give file access through the working directory or allowedRoots instead. The heartbeat change means a lost claim on a work item ends with a clear reason rather than an abrupt abort.