What
An SDK host is a program that runs Claude Code through its software development kit and answers its permission questions. Those answers can add permission rules, such as "deny" (never allow) or "ask" (check with the user first). Previously the updated rules in an answer were applied without further checking.
Now Claude Code refuses:
- a permission answer whose result drops deny or ask rules that it added
- a sandbox network answer, meaning an answer about network access from the restricted environment commands run in, when a deny or ask rule it added, or may have added, is not among the session's rules; a log line records the refusal
Why
This tightens the permission flow for programs that embed Claude Code, so a stricter rule an answer asked for cannot quietly go missing.