What
When Claude Code runs without its own screen (headless, for example under the Agent SDK, the library that lets your program drive Claude Code), it asks the host program for permission through a can_use_tool request handled by canUseTool. That request has changed.
titleis a new field on the request.provenance_prompt_lineis a new internal field with the valueone_at_a_timeorall_at_once. It says whether WebFetch prompts refused by the URL proxy were queued in a line.provenancePromptLineis the matching value on the ask result made when the session's URL provenance check (a check on where a web address came from) denies a fetch. It is set fromoneAtATime.- A new recheck runs while a prompt is waiting. If the recheck allows the call, the waiting prompt is dropped. Before, the prompt only waited for the hook or host to answer.
Why
Host programs receive more detail about each permission request, including how blocked web fetches were grouped. Prompts that no longer need an answer can now go away by themselves instead of waiting.