What
These changes affect people who build on the Anthropic SDK bundled with Claude Code, especially its environment worker. The environment worker is the component that runs managed-agent sessions on your own machines.
unrestrictedPathsis no longer supported by the agent toolset (AgentToolContext) or byEnvironmentWorker. Passing it now throws an error. Before, it was accepted.- The file tools (read, write, edit, glob, grep) are always kept inside the working directory plus
allowedRoots. In the worker, that meansworkdirplus the memory folders. EnvironmentWorkernow takes a per-itemANTHROPIC_WORK_SECRETand reads asessions_tokenfrom it. It mounts and syncs session memory stores usingmemorySyncIntervalMsandmemorySyncDeletions.- An optional
workspace_id, sent as theanthropic-workspace-idheader, is now available on batches, deployment runs, agent versions, and memory and work calls. - New endpoints add and remove workspaces on federation rules.
- The work heartbeat, the regular check-in that keeps a work item claimed, now ends with
lease_lost,assumed_lostorheartbeat_rejectedand uses a request timeout. Before, it simply aborted the work item.
Why
Code that passes unrestrictedPaths will now fail, so remove the option and give file access through the working directory or allowedRoots instead. The heartbeat change means a lost claim on a work item ends with a clear reason rather than an abrupt abort.
Names in the bundleunrestrictedPaths
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear how much of this can be reached from the Claude Code command line rather than only through the SDK.