Unclear It is not clear what decides whether the option is shown and available, or whether it is live for all users.
What
claude remote-control connects cloud sessions to your computer. It gains a new option, --allow-unattended-tool-calls. With it, cloud sessions can use the current folder for one run. Commands from auto mode, where Claude decides without asking you, then run without a prompt, but only inside the sandbox. A sandbox is a walled-off area that limits what commands can touch.
- It writes a grant under
~/.claude/state, and exits with an error if it cannot. It says to start from your own terminal, because a sandbox cannot write there. - It starts a tool host in the foreground, unless the spawn mode is single-session. A tool host is the part that runs commands for the cloud session on this computer.
- It cannot be combined with
--spawn=session,--session-idor--continue. - It needs you at a real terminal. It refuses to start from a script, a pipe or a Claude Code session.
- The setting
remoteTools.allowUnattendedServingset to false blocks it. - New status messages cover auto mode on or off, why a folder is unavailable, and sessions starting, being refused and disconnecting. One reads: "Your auto-mode cloud sessions can run commands on this computer without asking. Deny rules and hooks still apply. Ctrl+C to stop." Hooks are your own commands that run at set points.
- The option's help text appears only when a condition that was not traced is met.
The unattended path is tied to the gate tengu_violin_luthier. Readings taken before this release found it off for this site's account and for an anonymous baseline. No reading has been taken under this release.
Why
This is a security-relevant new ability: a cloud session can run commands on your machine without a prompt for each one. It is limited to the sandbox, deny rules and hooks still apply, and you must start it yourself at a terminal and can stop it with Ctrl+C.
tengu_violin_luthier Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.290: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.290. It isn't a statement about your account. What a flag value here can and cannot tell you
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
* Fixed PushNotification reporting "Remote Control inactive" in sessions started with `claude remote-control`changelog see the edit
It is not clear what decides whether the option is shown and available, or whether it is live for all users.
Anthropic's documentation has since written up claude remote-control, on Claude Code changelog.
Fixed plan mode not being restored when resuming a session with --continue or --resume <session-id> in the terminal
New in this build: tengu_violin_luthier