{"version":"2.1.296","anchor":"background-session-write-guard-paths","canonical_anchor":"background-session-write-guard-paths","heading":"Claude Code refuses credential paths in folders background sessions can write to","tier":"notice","area":"Sessions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296\/e\/background-session-write-guard-paths","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296","markdown":"### Claude Code refuses credential paths in folders background sessions can write to\n\nClaude Code now refuses paths in its temp folders or in folders background sessions write to freely, including for cloud credential settings\n\n**Unclear.** It is not clear exactly when this check runs or what Claude Code does when it refuses a path.\n\n**What**\n\nBackground sessions are Claude Code sessions that run while you do something else. Some folders let them write files without asking you. A new check refuses paths that point into:\n\n- a Claude Code temporary folder\n\n- a folder background sessions can write to without asking, such as project folders under `CLAUDE_CODE_REMOTE_MEMORY_DIR` and agent memory folders\n\nFor these environment variables, the `~\/.claude` folder is refused as well:\n\n- `AWS_CONFIG_FILE`\n\n- `AWS_SHARED_CREDENTIALS_FILE`\n\n- `GOOGLE_APPLICATION_CREDENTIALS`\n\n**Why**\n\nIf a credential file sat in a folder a background session can change without asking, that session could alter it. The check stops these settings from pointing at such places. If you keep your AWS or Google Cloud credential files inside `~\/.claude`, they may now be refused.\n\n- Area: Sessions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}