{"version":"2.1.285","anchor":"environment-worker-memory-sync-and-work-secret-sessions-tok","canonical_anchor":"environment-worker-memory-sync-and-work-secret-sessions-tok","heading":"Bundled SDK: agent file tools reject unrestrictedPaths, plus worker and workspace changes","tier":"notice","area":"Environment Workers","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/environment-worker-memory-sync-and-work-secret-sessions-tok","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Bundled SDK: agent file tools reject unrestrictedPaths, plus worker and workspace changes\n\nThe bundled SDK's agent toolset and environment worker now refuse unrestrictedPaths and gain a workspace header, a work secret and sturdier heartbeats\n\n**Unclear.** It is not clear how much of this can be reached from the Claude Code command line rather than only through the SDK.\n\n**What**\n\nThese changes affect people who build on the Anthropic SDK bundled with Claude Code, especially its environment worker. The environment worker is the component that runs managed-agent sessions on your own machines.\n\n- `unrestrictedPaths` is no longer supported by the agent toolset (`AgentToolContext`) or by `EnvironmentWorker`. Passing it now throws an error. Before, it was accepted.\n\n- The file tools (read, write, edit, glob, grep) are always kept inside the working directory plus `allowedRoots`. In the worker, that means `workdir` plus the memory folders.\n\n- `EnvironmentWorker` now takes a per-item `ANTHROPIC_WORK_SECRET` and reads a `sessions_token` from it. It mounts and syncs session memory stores using `memorySyncIntervalMs` and `memorySyncDeletions`.\n\n- An optional `workspace_id`, sent as the `anthropic-workspace-id` header, is now available on batches, deployment runs, agent versions, and memory and work calls.\n\n- New endpoints add and remove workspaces on federation rules.\n\n- The work heartbeat, the regular check-in that keeps a work item claimed, now ends with `lease_lost`, `assumed_lost` or `heartbeat_rejected` and uses a request timeout. Before, it simply aborted the work item.\n\n**Why**\n\nCode that passes `unrestrictedPaths` will now fail, so remove the option and give file access through the working directory or `allowedRoots` instead. The heartbeat change means a lost claim on a work item ends with a clear reason rather than an abrupt abort.\n\n- Area: Environment Workers\n- Names: `unrestrictedPaths`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5"}