> ## Documentation Index
> Fetch the complete documentation index at: https://www.cameronshields.co.uk/llms.txt
> Use this file to discover all available pages before exploring further.

# Cameron Code docs map

A map of every Cameron Code page with its headings, so an LLM (or a person) can find the right page before reading it.

> Generated from the handbook source on each deploy. Last updated: 2026-10-08 21:21:15 UTC

## Document Structure

* **##** marks a group of pages (for example 'Getting started')
* **###** marks a page, or **### Group > Subgroup** a nested group whose pages use **####**
* Nested bullets show the headings inside each page
* Every page title links to the full page as Markdown; drop the `.md` for the web version

## Getting started

### [overview](https://www.cameronshields.co.uk/docs/overview.md)

* Where Claude Code runs
* Install the CLI
  * Package manager alternatives
  * First run
  * Other surfaces
* What it is good at
  * Clearing the backlog of chores
  * Building features and fixing bugs
  * Git and pull requests
  * Connecting your other tools
  * Teaching it your conventions
  * Parallel and custom agents
  * Scripting and pipelines
  * Scheduled work
  * Moving between devices
* Picking the right integration
* Where to go next

### [quickstart](https://www.cameronshields.co.uk/docs/quickstart.md)

* What you need
* 1. Install
* 2. Start a session and sign in
* 3. Ask about the code
* 4. Make a small change
* 5. Use git conversationally
* 6. Fix something real
* 7. Try a few more workflows
* Commands to remember
  * From your shell
  * Inside a session
* Habits worth forming early
* Next steps

## Core concepts

### [how-claude-code-works](https://www.cameronshields.co.uk/docs/how-claude-code-works.md)

* The agentic loop
  * The model
  * The tools
  * Extending the loop
* What Claude can see and touch
* Where it runs and how you talk to it
* Sessions
  * Branches and worktrees
  * Resuming versus forking
* The context window
  * Context Claude Code adds by itself
  * When the window fills
  * Keeping context lean
* Safety nets
  * Checkpoints undo file edits
  * Permissions control what happens without asking
* Working with it well
  * Ask it how to use itself
  * Treat it as a conversation
  * Interrupt and redirect
  * Delegate rather than dictate

### [features-overview](https://www.cameronshields.co.uk/docs/features-overview.md)

* The extension menu
* Grow your setup gradually
* Telling similar features apart
  * Skill or subagent?
  * CLAUDE.md or skill?
  * CLAUDE.md or output style?
  * CLAUDE.md, rules or skills?
  * Subagent or dynamic workflow?
  * MCP or skill?
  * Hook or skill?
* How the same feature at different levels combines
* Combining features
* What each feature costs in context

### [claude-directory](https://www.cameronshields.co.uk/docs/claude-directory.md)

* The project tree
  * CLAUDE.md
  * .mcp.json
  * .worktreeinclude
  * .claude/settings.json
  * .claude/settings.local.json
  * .claude/rules/
  * .claude/skills/
  * .claude/commands/
  * .claude/agents/
  * .claude/workflows/
  * .claude/output-styles/
  * .claude/agent-memory/
* The home directory tree
  * ~/.claude.json
  * ~/.claude/CLAUDE.md
  * ~/.claude/settings.json
  * ~/.claude/keybindings.json
  * ~/.claude/themes/
  * ~/.claude/projects/ and auto memory
  * ~/.claude/output-styles/
  * Other personal folders
* Files that live elsewhere
* Which file do I edit?
* Frontmatter at a glance
* Data Claude Code writes
  * Swept automatically
  * The session scratchpad
  * Kept until you delete them
  * Reducing exposure
  * Clearing a project's data
  * Deleting by hand

### [context-window](https://www.cameronshields.co.uk/docs/context-window.md)

* Three levels of visibility
* Before you type anything
* While Claude works
* Delegating to a subagent
* Compaction
  * What comes back afterwards
* Staying ahead of a full window
  * Bigger windows
* Checking your own session

### [prompt-caching](https://www.cameronshields.co.uk/docs/prompt-caching.md)

* Prefix matching
* Where the cache lives
* Actions that break the cache
  * Switching models
  * Changing effort level
  * Turning on fast mode
  * Connecting or removing an MCP server
  * Enabling or disabling a plugin
  * Denying a whole tool
  * Compacting
  * Piling up images
  * Upgrading Claude Code
* Actions that keep the cache
* Resuming a session
* How long the cache lasts
  * Default TTLs
  * Setting the TTL yourself
* Who shares a cache
* Subagents, forks and the cache
* Checking cache performance
* Turning caching off

## Use Claude Code

### [memory](https://www.cameronshields.co.uk/docs/memory.md)

* The two systems side by side
* CLAUDE.md
  * When to add something
  * Where the files live
  * Creating a project file
  * Writing instructions that stick
  * Auditing your instruction files
  * Importing other files
  * How loading works
  * Extra directories
* Rules in .claude/rules/
  * Path-scoped rules
  * Sharing rules with symlinks
  * Personal rules
* Organisation-wide instructions
  * Excluding files you do not want
* AGENTS.md
  * What counts as "having a CLAUDE.md"
  * Choosing which files load
  * When AGENTS.md is not available
  * Differences from CLAUDE.md
  * Cleaning up old workarounds
  * One file for every tool
  * Migrating from other tools
* Auto memory
  * Turning it on and off
  * Where it is stored
  * How it is used
* /memory
* Troubleshooting
  * Claude is not following CLAUDE.md
  * AGENTS.md is not loading
  * What did auto memory save?
  * CLAUDE.md is too large
  * Instructions vanished after /compact

### [sessions](https://www.cameronshields.co.uk/docs/sessions.md)

* Getting back into a session
  * Sessions that are hidden by default
  * Resuming by ID from anywhere
  * Background sessions
* What resuming brings back
  * Permission mode after resuming
  * Resuming from a summary
* The session picker
  * What it shows
  * Shortcuts
  * Picking a session from somewhere else
  * Resuming by name
* Naming sessions
* Branching
* Managing context without leaving
* Exporting and scripting
* Where transcripts live
  * Naming the project folder yourself

### [common-workflows](https://www.cameronshields.co.uk/docs/common-workflows.md)

* Learning an unfamiliar codebase
  * Get the lay of the land
  * Find the code behind a feature
* Fixing bugs
* Refactoring
* Writing tests
* Pull requests
* Documentation
* Notes and other non-code folders
* Working with images
* Referencing files with @
* Running Claude on a schedule
* Asking Claude about Claude Code
* Picking up where you left off
* Parallel sessions with worktrees
* Planning before editing
* Delegating research to subagents
* Scripting and pipelines

### [prompt-library](https://www.cameronshields.co.uk/docs/prompt-library.md)

* Some prompts need extra setup
* Understand
* Plan and design
* Build
* Test
* Refactor and optimise
* Review
* Steer
* Ship
* Operate
* Automate
* Why these prompts work

### [best-practices](https://www.cameronshields.co.uk/docs/best-practices.md)

* The constraint behind everything: context
* Give Claude a way to check its own work
* Explore, plan, then build
* Be specific
  * Feed it rich input
* Set up your environment once
  * A lean CLAUDE.md
  * Permissions that do not nag
  * Prefer CLI tools
  * MCP servers
  * Hooks for the non-negotiables
  * Skills for knowledge and workflows
  * Custom subagents
  * Plugins
* Talk to it like a senior colleague
  * Ask questions
  * Let it interview you
* Manage the session
  * Correct early
  * Keep context clean
  * Investigate with subagents
  * Rewind instead of tiptoeing
  * Name and resume sessions
* Scale up
  * Non-interactive runs
  * Parallel sessions
  * Fan out across many files
  * Auto mode for unattended work
  * Add an adversarial review
* Failure patterns to recognise
* Build your own instincts

## Platforms and integrations

### [platforms](https://www.cameronshields.co.uk/docs/platforms.md)

* Where to run it
* Connecting your tools
* Working away from your terminal
* Where to start

### [remote-control](https://www.cameronshields.co.uk/docs/remote-control.md)

* Before you start
* Starting a session
  * Server mode (CLI)
  * Interactive session with Remote Control on (CLI)
  * From a session you are already in (CLI)
  * VS Code
  * Desktop app
* Checking the connection
* Connecting from another device
  * What the remote device sees
* Always on
* Coming back after stopping
* Security
  * Trusted Devices (beta)
* Push notifications to your phone
* Limitations
  * Commands from phone and browser
* Remote Control or a cloud session?
* Troubleshooting

### [claude-projects](https://www.cameronshields.co.uk/docs/claude-projects.md)

* When a project makes sense
  * When something else fits better
* How a project is put together
* Creating a project
  * Prerequisites
  * From scratch
  * From an existing cloud session
  * GitHub access
* Working in a project
  * Your first batch
  * Sending work and reading results
  * Pull requests from threads
  * Overview
  * Taking control of a thread
  * Models, effort and context
  * Telling Claude how to run things
  * Approvals
  * Running a thread on your own computer
* Standing context
  * Project instructions
  * Choosing repositories
  * Files and folders
  * What threads take from repositories
  * The cloud environment
  * Getting your tools into threads
* Settings reference
* Usage and cost
* How projects relate to other features
* Limitations
* Troubleshooting

### [mobile](https://www.cameronshields.co.uk/docs/mobile.md)

* Getting set up
* Four ways to work from your phone
  * Cloud sessions
  * Remote Control of a local session
  * Push notifications
* Limitations

### [chrome](https://www.cameronshields.co.uk/docs/chrome.md)

* What you can do with it
* Requirements
* Getting started in the CLI
  * When Claude asks to install the extension
  * Turning it on by default
* Permissions
  * Site permissions
  * VS Code sessions
  * Plan mode
* Worked examples
  * Check a change on your dev server
  * Hunt down console errors
  * Bulk data entry
  * Upload a file
  * Write into a web document
  * Scrape structured data
  * Work across sites
  * Record a GIF
  * Save a screenshot
* Troubleshooting
  * Extension not detected
  * Browser stops responding
  * Connection drops in long sessions
  * Windows
  * Error messages

### [computer-use](https://www.cameronshields.co.uk/docs/computer-use.md)

* Good uses
* Where it fits among Claude's tools
* Turning it on
* Approving apps
* What happens while Claude works
* Safety
* Worked examples
  * Check a native build end to end
  * Chase a layout bug
  * Drive the iOS Simulator
* CLI versus desktop app
* Troubleshooting

### [vs-code](https://www.cameronshields.co.uk/docs/vs-code.md)

* Requirements
* Installing
* First steps
  * 1. Open the panel
  * 2. Sign in
  * 3. Ask something
  * 4. Review changes
* The prompt box
  * Permission modes
  * Model and effort
  * The command menu
  * Other prompt box features
  * Mentioning files and folders
  * Pasting
  * Account and usage
* Sessions
  * History
  * Cloud sessions
  * After a reload
  * Several conversations
  * Groups and filters
  * Panel placement
  * Terminal mode
* Plugins
  * Sharing an install link
* Browser automation
* Commands and shortcuts
  * Opening a tab from other tools
* Settings
* Screen readers
* Extension versus CLI
  * Checkpoints
  * Using the CLI inside VS Code
  * Background work
  * MCP
  * Git
* Third-party providers
* Security
  * The built-in IDE MCP server
* Troubleshooting
* Uninstalling

### [jetbrains](https://www.cameronshields.co.uk/docs/jetbrains.md)

* Supported IDEs
* What the plugin adds
* Installing
* Using it
  * From the IDE terminal
  * From an external terminal
* Configuration
  * In Claude Code
  * In the plugin
  * Making Esc work
* Special set-ups
  * Remote development
  * WSL2
* Troubleshooting
* Security notes
  * The built-in IDE MCP server

### [slack](https://www.cameronshields.co.uk/docs/slack.md)

* What it is good for
* Before you start
* Set it up
  * 1. Install the Claude app
  * 2. Link your Claude account
  * 3. Get cloud sessions working
  * 4. Pick a routing mode
  * 5. Invite Claude to channels
* How a request flows
  * Buttons on the result
* Who can do what
* Where the work lives
* Writing requests that work
* Troubleshooting
  * "This workspace isn't set up for Claude Tag yet"
  * "The legacy Claude in Slack bot is retired"
  * "Claude Code is not enabled for your account"
  * Sessions do not start
  * Sessions from a Claude Tag channel fail immediately
  * Repository missing from the list
  * Claude picked the wrong repository
  * Authentication errors
* Limitations

### [claude-tag](https://www.cameronshields.co.uk/docs/claude-tag.md)

* Who can use it
* How it differs from your other Claude tools
* Anatomy of a session
  * Steering and stopping
  * What survives a quiet period
* What Claude can see and reach
  * Channels, group DMs and one-to-one DMs
  * Posting into other channels
* Bringing your Claude Code habits across
* Memory
* Commands
* Routines
* Setting it up (Owners)
* Coming from the earlier Slack app
* What admins can and cannot see

### Platforms and integrations > Claude Code in the cloud

#### [web-quickstart](https://www.cameronshields.co.uk/docs/web-quickstart.md)

* When the cloud is the right choice
* Where a session runs, compared
* What happens when you submit a task
* Step 1: connect GitHub
  * In the browser
  * From the terminal with /web-setup
* Step 2: get a cloud environment
* Step 3: start a task
* Prefilled links
* Step 4: review and iterate
* Troubleshooting
  * No repositories listed
  * Only a GitHub login button
  * "Claude Code isn't available on your account"
  * /web-setup says "Not signed in to Claude"
  * /web-setup warns about the workflow scope
  * /web-setup is "Unknown command" or not in the menu
  * "Could not create a cloud environment" or "No cloud environment available" with --cloud
  * Setup script failed
  * Sessions hang during setup
  * The session keeps going after I close the tab
* Next steps

#### [claude-code-on-the-web](https://www.cameronshields.co.uk/docs/claude-code-on-the-web.md)

* Ways to start a cloud session
* Environments
* Connecting GitHub
  * Quick setup (Team and Enterprise)
* From the terminal to the cloud
  * A pattern I use: plan here, execute there
  * Fan-out
  * Uploading a local repo instead of cloning
  * Sending follow-ups from any machine
* From the cloud to your terminal
* Working inside a session
  * Permission modes
  * Reviewing diffs
  * Commands and context
  * Recalling a queued message
* Share sessions
* Archive and delete
* Auto-fix pull requests
* Security and isolation
* Troubleshooting
* Limitations

#### [routines](https://www.cameronshields.co.uk/docs/routines.md)

* Triggers at a glance
* Ideas that work well
* How a run behaves
* Creating a routine on the web
  * How the prompt is treated
* Creating from the CLI
* Schedule triggers
  * One-off runs
* API triggers
  * Firing it
* GitHub triggers
  * Events
  * Pull request filters
* Managing routines
* Repositories and branches
* Connectors
* Network access
* Usage and limits
* Troubleshooting
  * /schedule returns "Unknown command"
  * "Routines are disabled by your organization's policy"

#### [ultrareview](https://www.cameronshields.co.uk/docs/ultrareview.md)

* Why use it over a local review
* Requirements
* Reviewing your branch
  * A different base
  * Adding a note (v2.1.218+)
* Reviewing a pull request
  * Posting findings to the PR (v2.1.227+)
* Diff limits and edge cases
* Pricing
* While it runs
* Running it from CI or scripts

### Platforms and integrations > Claude Code on desktop

#### [desktop-quickstart](https://www.cameronshields.co.uk/docs/desktop-quickstart.md)

* Download
* The three tabs
* Install and sign in
* Your first session
  * 1. Pick where Claude runs
  * 2. Pick a model
  * 3. Ask for something small
  * 4. Review the result
* Things to try next

#### [desktop](https://www.cameronshields.co.uk/docs/desktop.md)

* Starting a session
* Working with code
  * Prompting and steering
  * Adding context
  * Permission modes
  * Reviewing diffs
  * Having Claude review its work
  * Watching a pull request
* Previewing your app
  * .claude/launch.json
* Browsing external sites
* Arranging the workspace
  * View modes
  * Shortcuts
* Managing sessions
  * Parallel sessions and worktrees
  * Side chats
  * Background tasks
  * Working across sessions
  * Cloud sessions from Desktop
  * Moving a session elsewhere
  * Showing sessions on other devices
  * Dispatch
* Computer use
* Extending Claude Code
  * Connectors
  * Skills
  * Plugins
* Environments in detail
  * Local
  * Cloud
  * SSH
* Enterprise configuration
  * Admin console
  * Managed settings keys
  * Device management
  * Network allowlist
  * SSO and data
* Coming from the CLI
  * Flag equivalents
  * What is shared
  * Differences
* Troubleshooting

#### [desktop-linux](https://www.cameronshields.co.uk/docs/desktop-linux.md)

* Will it run on my machine?
  * Extra requirements for Cowork
* Install
  * 1. Add the repository
  * 2. Install
  * 3. Launch and sign in
  * Alternative: install a downloaded .deb
* Update
* Uninstall
* Troubleshooting
  * E: Unable to locate package claude-desktop
  * Unmet or unsatisfied dependencies
  * "Running as root without --no-sandbox is not supported"
  * "Your sign-in won't be saved on this device"
  * Cowork unavailable
* Not in the Linux beta yet

#### [desktop-wsl](https://www.cameronshields.co.uk/docs/desktop-wsl.md)

* Requirements
* Starting a WSL session
* What works
* Not yet available in WSL sessions
* Managed devices

#### [desktop-scheduled-tasks](https://www.cameronshields.co.uk/docs/desktop-scheduled-tasks.md)

* Which scheduler should I use?
* Creating a task
* Schedule options
* What happens at run time
  * Catch-up after sleep
* Permissions
* Managing tasks
  * The prompt on disk

#### [desktop-ios-simulator](https://www.cameronshields.co.uk/docs/desktop-ios-simulator.md)

* Requirements
  * Several Xcode versions installed?
* Running your app
* Driving it yourself
* Devices and sessions
* Access and consent
  * Allowing a device
  * Actions that follow your permission mode
  * Turning access off
* Limitations
* Troubleshooting
  * The pane never opens
  * "No simulators were found"

### Platforms and integrations > Code review & CI/CD

#### [security-guidance](https://www.cameronshields.co.uk/docs/security-guidance.md)

* Before you install
* Installing
  * Turning it on for the whole team
* The three checkpoints
  * Per-edit pattern check
  * End-of-turn review
  * Commit and push review
  * Independence and limits
* Adding your own rules
  * Guidance for the model reviews
  * Extra per-edit patterns
  * Where rule files are found
* Cost
* Turning parts off
* Under the bonnet
* Where it fits
* Troubleshooting

#### [claude-security](https://www.cameronshields.co.uk/docs/claude-security.md)

* What you need
* Models and providers
* Installing
* Running a full scan
  * Scanning just your changes
  * Big repositories
* The results folder
* Getting patches
  * You apply them
* Where it fits in your stack
* Troubleshooting

#### [code-review](https://www.cameronshields.co.uk/docs/code-review.md)

* How managed reviews work
  * Severity markers
  * Reacting to findings
  * The check run
* Setting it up
* Requesting a review by comment
  * Fork pull requests
* Tuning what gets flagged
  * What to put in REVIEW.md
* Usage and pricing
* Troubleshooting
* Reviewing locally with /code-review
  * Things to know
  * Effort levels
  * Letting Claude run it
  * Going deeper with ultra

#### [github-actions](https://www.cameronshields.co.uk/docs/github-actions.md)

* Setup
  * The quick way: /install-github-app
  * The manual way
  * Rolling out across an organisation
  * Removing it
  * What the app is allowed to do
* How it decides what to do
  * Who can trigger it
* Workflows
  * Answer @claude mentions
  * Run a skill as the prompt
  * Run on a schedule
* Good habits
* Cloud providers
* Inputs reference
* Troubleshooting
* Upgrading from @beta

#### [github-actions-cloud-providers](https://www.cameronshields.co.uk/docs/github-actions-cloud-providers.md)

* Pick the provider
* What you need first
* Step 1: choose how the action talks to GitHub
* Step 2: make your cloud trust GitHub
  * Amazon Bedrock
  * Google Cloud's Agent Platform
  * Microsoft Foundry
* Step 3: add secrets
* Step 4: write the workflow
  * Swapping the cloud step for Agent Platform
  * Swapping the cloud step for Foundry
  * If you chose a different GitHub identity
* Step 5: test
* Troubleshooting

#### [github-enterprise-server](https://www.cameronshields.co.uk/docs/github-enterprise-server.md)

* Feature support
* Connecting the instance (Owners)
  * Permissions the app asks for
  * When the redirect is blocked
  * Network reachability
* For developers
* Plugin marketplaces on GHES
  * Adding one from the CLI
  * Pre-registering for everyone
  * Allowing GHES under a marketplace allowlist
* Workarounds for the gaps
* Troubleshooting

#### [gitlab-ci-cd](https://www.cameronshields.co.uk/docs/gitlab-ci-cd.md)

* Why I like it on GitLab projects
* How it fits together
* Quick start with the Claude API
* Production setup
* What a request looks like
* Amazon Bedrock
* Google Cloud's Agent Platform
* Good practice
* Useful knobs
* Troubleshooting

## Agents and parallel work

### [agents](https://www.cameronshields.co.uk/docs/agents.md)

* The five approaches at a glance
* Supporting tools
* Things that look similar but are not
* Picking the right one
  * 1. Who should coordinate?
  * 2. Do the workers need to talk?
  * 3. Will they touch the same files?
* Checking on running work
* A worked example

### [sub-agents](https://www.cameronshields.co.uk/docs/sub-agents.md)

* Built-in subagents
* Your first custom subagent
* Where subagent files live
  * Defining subagents on the command line
* Writing the file
  * Frontmatter fields
  * Files that silently fail to load
* Choosing a model
  * Forcing one model everywhere
* Controlling what a subagent can do
  * Tool access
  * Limiting which subagents an agent can spawn
  * MCP servers for one subagent
  * Permission modes
  * Preloading skills
  * Persistent memory
  * Conditional rules with hooks
  * Disable specific subagents
* Hooks and subagents
* Working with subagents
  * Automatic delegation
  * Asking for a subagent explicitly
  * Foreground and background
  * Names
  * When the API fails mid-run
  * Output scanning
  * Patterns that work well
  * Nested subagents
  * Concurrency limit
* Context and resuming
  * What a subagent starts with
  * Resuming
* Fork the current conversation
  * Fork mode

### [agent-view](https://www.cameronshields.co.uk/docs/agent-view.md)

* Getting started
  * Make it the default
* Reading the list
  * State colours
  * Summaries
  * Pull request labels
* Peeking and replying
* Attaching
  * Switching from a foreground session
* Organising the list
  * Filters
  * Keys
* Dispatching work
  * From agent view
  * Choosing a directory
  * From inside a session
  * From the shell
  * Shell jobs
* How file edits are isolated
  * What deletion removes
* Model, permission mode and effort
  * Model
  * Settings and provider
  * Permission mode
  * Dispatch defaults
  * Settings, plugins and MCP
* Shell commands
  * Scripting against session state
* How it is hosted
* Troubleshooting
* Limitations

### [agent-teams](https://www.cameronshields.co.uk/docs/agent-teams.md)

* When a team earns its keep
  * Teams versus subagents
* Turning teams on
* Your first team
* Steering the team
  * Display modes
  * Team size and models
  * Plan first, then build
  * Talking to teammates directly
  * The task list
  * Shutting down
  * Quality gates with hooks
* How it works underneath
  * How a team starts
  * Parts of a team
  * Reusing subagent definitions as teammates
  * Permissions
  * Context
  * Tokens
* Two prompts I reuse
* Habits that help
* Troubleshooting
  * No teammates appear
  * Claude spawns teammates instead of subagents
  * Too many permission prompts
  * Teammates give up early
  * Leftover tmux sessions
* Limitations

### [cross-session-messaging](https://www.cameronshields.co.uk/docs/cross-session-messaging.md)

* When it helps
* Sending a message
  * Delivery
  * Ask to be told when another session goes idle
  * Seeing who Claude can reach
* Other machines and the cloud
* How the receiver treats a message
  * What you see
* Controlling inbound messages
  * The default when nothing is set
  * Headless sessions
  * The inbox socket
* Restricting messaging
  * Approval for anything leaving the machine
  * Turning it off
* Availability
* Limitations

### [workflows](https://www.cameronshields.co.uk/docs/workflows.md)

* Workflows compared with the other options
* Try the built-in workflow first
* Watching a run
* Getting Claude to write one
  * Ask in the prompt
  * Turn on ultracode for the session
* Approving a run
* Saving a workflow as a command
  * Passing input
  * Shipping a workflow in a plugin
* Prompts that suit a workflow
* Anatomy of a saved script
  * Editing rules
* What happens under the hood
  * Caching across the fan-out
  * Limits
* Managing runs
  * Pausing, stopping and resuming
  * Hitting a usage limit
  * Keeping cost under control
  * Size guideline
  * Switching workflows off

### [worktrees](https://www.cameronshields.co.uk/docs/worktrees.md)

* Starting a session in a worktree
  * Preparing the environment
  * Asking Claude to switch mid-session
* Cleaning up on exit
* Resuming a worktree session
* How isolation is enforced
* Giving subagents their own worktrees
  * The cleanup sweep
* Changing how worktrees are created
  * Base branch
  * Starting from a pull request
  * Copying ignored files into new worktrees
  * Reusing a name
  * Replacing creation with a hook
* What a worktree shares with the main checkout
* Creating worktrees by hand
* Other version control systems
* Troubleshooting
  * Cannot enter the worktree at startup
  * Creation fails on a symlinked path
  * Git LFS files are only pointers
  * "Refusing to use <path> as an isolation worktree"
  * Resume lands outside the worktree

## MCP

### [mcp-quickstart](https://www.cameronshields.co.uk/docs/mcp-quickstart.md)

* What you need
* Your first server: hosted, no sign-in
  * 1. Add it
  * 2. Check the status
  * 3. Use it
  * 4. Remove it (optional)
* Where servers are stored
* Changing scope
* A local server
* A server that needs sign-in
* Writing .mcp.json by hand
* Other ways to connect
* Troubleshooting
  * "No MCP servers configured"
  * "Failed to connect" or "Connection error"
  * Timed out at startup
  * "Server already exists"
  * Connected but no tools
  * Edits to .mcp.json are ignored
  * OAuth fails or no browser opens

### [mcp](https://www.cameronshields.co.uk/docs/mcp.md)

* What it unlocks
* Finding and building servers
* Adding servers
  * Remote HTTP (the default choice)
  * Remote SSE (deprecated)
  * Local stdio
  * Remote WebSocket
  * Translating instructions written for other clients
* Managing servers
  * Status values
  * The discovery cache
  * Configuration warnings
  * Project approvals and workspace trust
  * Switching a server off without deleting it
* Scopes
  * Which definition wins
  * Environment variables in config
* Worked examples
  * GitHub with a personal access token
  * A read-only database
* Authentication
  * Signing in
  * Fixed callback port
  * Pre-registered OAuth clients
  * Overriding metadata discovery
  * Pinning scopes
  * Generating headers at connect time
* Adding from JSON and importing
* Connectors from claude.ai
  * Where connectors come from by surface
  * Organisation tool controls
  * Turning connectors off
* Runtime behaviour
  * Client runtimes
  * Changing tool lists
  * Reconnection and retries
  * Timeouts
  * Long calls move to the background
  * Output limits
  * Schemas the API would reject
* Server author features
  * Forcing approval for a tool
  * Elicitation
  * Server instructions and tool search
* Resources and prompts
  * Resources with @
  * Prompts as commands
* Tool search
  * Always loading a server
* Plugin servers
* Claude Code as an MCP server
* Managed configuration

## Skills

### [skills](https://www.cameronshields.co.uk/docs/skills.md)

* Your first skill
* Where skills live
  * Monorepos and subfolders
  * Additional directories
  * When two skills share a name
  * Cowork, cloud sessions and routines
  * Skills synced from claude.ai
  * Editing, reloading and removing
* Writing skills
  * Two kinds of content
  * Frontmatter reference
  * Frontmatter outside Claude Code
  * How the command name is chosen
  * Substitutions
  * Supporting files
  * Who can invoke a skill
  * What happens after a skill loads
  * Pre-approving and removing tools
  * Passing arguments
* Advanced patterns
  * Injecting live context
  * Running a skill in a subagent
  * Controlling which skills Claude may use
  * Overriding visibility from settings
  * Finding skills you never use
* Bundled skills
  * /doctor
  * /run, /verify and /run-skill-generator
  * /claude-api
* Testing a skill
* Sharing skills
* Troubleshooting
  * It never triggers
  * It triggers too often
  * Claude drifts away from it
  * Descriptions are being cut
  * Personal skills vanished

## Artifacts

### [artifacts](https://www.cameronshields.co.uk/docs/artifacts.md)

* Good uses and poor uses
* Publishing your first artifact
* Updating a page
* Finding an artifact again
* Sharing
  * Editors
* Reading an artifact someone shared with you
* Comments
  * Automatic replies
* Live data through connectors
  * Whose account the calls use
  * Live sections are empty
* File downloads
* Ideas for pages
* Making pages look like your brand
* Templates: slides, designs and docs
* Page constraints
* Availability
* Turning artifacts off for yourself
* Admin controls (Team and Enterprise)

## Automation

### [hooks-guide](https://www.cameronshields.co.uk/docs/hooks-guide.md)

* Your first hook: a ping when Claude is waiting
  * Notification commands for other platforms
  * Narrowing notifications
* Recipes
  * Format every file Claude edits
  * Refuse edits to sensitive files
  * Put key facts back after compaction
  * Log configuration changes
  * Keep direnv (or devbox) in sync
  * Skip the "proceed with this plan?" prompt
* How hooks run
  * Events
  * Handler types
  * Input
  * Output: exit codes
  * Output: structured JSON
  * When several hooks match
  * Matchers
  * The if field
  * Where hooks can live
* Model-powered hooks
  * Prompt hooks
  * Agent hooks
* HTTP hooks
* Limits worth knowing
  * Hooks and permission modes
* Troubleshooting

### [channels](https://www.cameronshields.co.uk/docs/channels.md)

* Try it locally with fakechat
* Connecting a real platform
  * Telegram
  * Discord
  * iMessage (macOS only)
* Working unattended
* Security model
* Admin controls
  * Switching channels on
  * Restricting which plugins may run
* Research preview caveats
* Choosing between channels and similar features

### [scheduled-tasks](https://www.cameronshields.co.uk/docs/scheduled-tasks.md)

* Picking the right scheduler
* /loop in three forms
  * Fixed intervals
  * Self-paced loops
  * The built-in maintenance prompt
  * Your own default with loop.md
  * Stopping a loop
* One-off reminders
* Listing and cancelling
* How firing works
  * Jitter
  * Seven-day expiry
* Cron syntax
* Turning the scheduler off
* Limitations

### [goal](https://www.cameronshields.co.uk/docs/goal.md)

* /goal versus /loop versus a Stop hook
* Using the command
  * Setting a goal
  * Writing a condition that works
  * Checking status
  * Clearing
  * Resuming
  * Headless use
* How the evaluator decides
  * When a turn fails
  * Background work and check-ins
  * Evaluator model and cost
* When /goal is unavailable

### [headless](https://www.cameronshields.co.uk/docs/headless.md)

* The basics
* Bare mode for reproducible runs
  * What bare mode changes
* Lifecycle details
  * Background work when the result is ready
  * SIGTERM
  * Deleted working directory
* Recipes
  * Pipe in, redirect out
  * A project-specific linter
  * Output formats
  * Schema-shaped answers
  * Streaming tokens
  * Subagent messages in the stream
  * Retry events
  * Session metadata and CI gates
  * Plugin install events
* Permissions in unattended runs
  * Pre-approving tools
  * Choosing a permission mode
  * --permission-prompts none
* Commands inside -p
* Changing the system prompt
* Multi-step conversations

### [deep-links](https://www.cameronshields.co.uk/docs/deep-links.md)

* What happens when you click
  * Safety
* Building a link
  * cwd or repo?
* Examples
  * In a runbook
  * From a shell or script
* Handler registration
* Other link types
* Troubleshooting

## Guides

### [large-codebases](https://www.cameronshields.co.uk/docs/large-codebases.md)

* The toolkit at a glance
* A running example
* Where you start Claude matters
* Layered CLAUDE.md files
  * Per-directory CLAUDE.md or path-scoped rules?
  * Excluding CLAUDE.md files
* Cutting down file reads
  * Deny reads of generated and vendored code
  * Code intelligence
* Worktrees and cross-package access
  * Sparse worktrees
  * Reaching sibling packages or other repos
* Per-directory skills
  * Keeping the skill list manageable
* When layering stops scaling
  * Pointing people at the right plugin
* Putting it together
* Changes that cross packages

## Troubleshooting

### [troubleshoot-install](https://www.cameronshields.co.uk/docs/troubleshoot-install.md)

* Match your error
* Diagnostic checks
  * Check network connectivity
  * Verify your PATH
  * Check for conflicting installations
  * Check directory permissions
  * Verify the binary runs
* Common installation problems
  * The installer returned a web page
  * curl (23) or (56) failure writing output
  * Homebrew cask unavailable or out of date
  * TLS and certificate errors
  * Failed to fetch version from downloads.claude.ai
  * Wrong install command on Windows
  * Running scripts is disabled on this system
  * File in use during Windows install
  * claude.exe missing after a Windows update
  * Install killed on a low-memory server
  * Install hangs in Docker
  * Raw mode is not supported during install
  * claude update or claude doctor hangs
  * Claude Desktop hijacks the claude command on Windows
  * No shell found on Windows
  * 32-bit Windows error
  * musl or glibc mismatch on Linux
  * Illegal instruction
  * dyld errors on macOS
  * Bus error during a session
  * Exec format error on WSL1
  * npm installs inside WSL
  * Native binary missing after npm install
  * npm ENOTEMPTY
* Login and authentication
  * Reset your login
  * OAuth error: Invalid code
  * 403 Forbidden after login
  * Access not granted for this account
  * "This organization has been disabled" with a working subscription
  * OAuth in WSL2, SSH or containers
  * Not logged in or token expired
  * Cloud provider credentials not loading
* Still stuck

### [troubleshooting](https://www.cameronshields.co.uk/docs/troubleshooting.md)

* Start in the right place
* High CPU or memory
  * Capture a heap dump
* The context keeps refilling: "Autocompact is thrashing"
* Long tables are cut off
* Claude Code hangs or freezes
* Garbled text in an editor's terminal
* Mouse wheel scrolls too slowly in fullscreen
* Copying to the clipboard
  * Inside the sandbox
  * Over SSH
* Search, @-mentions or custom agents can't find files
  * Thin results on WSL
* Getting more help

### [debug-your-config](https://www.cameronshields.co.uk/docs/debug-your-config.md)

* Step 1: see what is in context
  * Loaded but ignored
* Step 2: check which setting wins
* Step 3: check MCP servers
* Step 4: check hooks
* Step 5: test against a clean setup
* Common causes at a glance

### [errors](https://www.cameronshields.co.uk/docs/errors.md)

* How automatic retries work
  * What the spinner shows
  * Tuning retries
* Server errors
  * The response above may be incomplete
  * Auto mode errors
* Usage limits
* Authentication errors
  * Claude login and API keys
  * Remote Control sign-in messages
  * MCP server sign-in
  * Cloud providers and gateways
* Network and connection errors
* Request errors
  * Context and size
  * Malformed requests
  * Models, thinking and effort
  * Safety and policy refusals
* Installation errors
* Command-line errors
  * Flags and input
  * Directories, trust and environment
  * MCP commands
  * Skills, review and GitHub
  * Sessions and UI
* Plugin errors
* Tool errors
* Background session errors
* Wrapper and IDE errors
* Rewind and session saving
* Configuration warnings
* Responses seem worse than usual
* Reporting an error

## Plugins

### [overview](https://www.cameronshields.co.uk/docs/plugins/overview.md)

* What is inside a plugin
* Do you actually need a plugin?
* The cost of an enabled plugin
* Marketplaces
  * Three layers before a skill appears
* Trust tiers
* Install scopes
* Where to go next

## Use plugins

### [install](https://www.cameronshields.co.uk/docs/plugins/install.md)

* Install a plugin
  * In the terminal
  * In the desktop app
  * In VS Code
  * In a cloud session
  * JetBrains, claude -p and the Agent SDK
* Choose an install scope
* Plugins from your claude.ai account
* Install from your shell
* Add a marketplace
  * Add and install in one go
  * Private marketplaces
  * Marketplaces listed by claude.ai
* Manage installed plugins
  * Synced plugins
  * Uninstalling a project-enabled plugin
  * Footprint and idle plugins
  * Dependencies
  * From the shell
* Keep plugins updated
* Manage marketplaces

### [anthropic-marketplaces](https://www.cameronshields.co.uk/docs/plugins/anthropic-marketplaces.md)

* The three marketplaces side by side
* Watch out for the demo marketplace
* What is in the official marketplace
* Browsing and searching
  * The directory is something else
* Adding the community or demo marketplace
* Third-party marketplaces

### [code-intelligence](https://www.cameronshields.co.uk/docs/plugins/code-intelligence.md)

* Install one
  * 1. Install the language server binary
  * 2. Install the plugin
  * 3. Prove the server starts
  * Reading the diagnostics yourself
* The LSP recommendation dialog
  * When it shows up
  * Your choices
  * Turning recommendations back on
* When things go wrong
* Languages without an official plugin

### [security](https://www.cameronshields.co.uk/docs/plugins/security.md)

* What a plugin can do
* Know which marketplaces are Anthropic's
* Review a plugin before installing
* Remove a plugin you no longer trust
* Warnings and refusals you will see
  * The trust warning
  * Hard refusals
* Organisation controls
* Plugins in telemetry

## Create plugins

### [create](https://www.cameronshields.co.uk/docs/plugins/create.md)

* What changes when something moves into a plugin
* Build your first plugin
  * 1. Make the folders
  * 2. Write the manifest
  * 3. Add the skill
  * 4. Validate
  * 5. Run it
* Plugin layout
* Load a plugin without a marketplace
  * --plugin-dir
  * --plugin-url
  * CLAUDECODEPLUGINDIRS
  * claude plugin init: always loaded
* Share it
* Test and debug
  * Common development failures
  * Does it actually change Claude's behaviour?
* Convert an existing .claude/ setup

### [components](https://www.cameronshields.co.uk/docs/plugins/components.md)

* The full map
* Manifest
* Skills
* Commands
* Agents
  * Subfolders
  * Frontmatter support
* Hooks
  * Behaviour worth knowing
* MCP servers
  * Packaged MCPB servers
* LSP servers
* Executables
* Default settings
* Themes and output styles
* Channels
* Monitors
* Workflows
* Ask users for configuration
* Paths and persistent data
  * Installing dependencies once

### [dependencies](https://www.cameronshields.co.uk/docs/plugins/dependencies.md)

* Why pin a version
* Declaring dependencies
* A bundle plugin for a team
* Depending across marketplaces
* Developing two plugins together
* Releasing a plugin others depend on
  * Tag format
  * Non-git sources
* What users experience
  * Resolving against tags
  * Checking what resolved
  * When several plugins constrain the same dependency

### [plugin-evals](https://www.cameronshields.co.uk/docs/plugin-evals.md)

* Requirements
* How it works
  * Cases, runs and scores
  * The baseline
* Your first suite
  * 1. Let Claude write the cases
  * 2. Run it
  * 3. Read the summary
  * 4. Iterate
* Writing cases by hand
  * The prompt
  * The graders
  * Choosing graders that give a stable signal
  * Scoring against the baseline
  * A different eval folder
* Fixtures and mocks
  * Seeding the workspace or conversation
  * Mocking MCP servers
* Running evals
  * Targets
  * Granting tools
  * Options
  * In CI
* Reading results
  * The HTML report
  * The JSON document
* What a run can access
  * Trust
  * Isolation
* Suite reference
  * prompt.md frontmatter
  * case.yaml
  * Grader keys and types
  * Mock files
* Troubleshooting

### [publish](https://www.cameronshields.co.uk/docs/plugins/publish.md)

* Pick a route
* Pre-release checklist
* Sharing without a marketplace
  * Shipping a plugin alongside your own tool
* Publishing through your own marketplace
* Submitting to Anthropic's directory
* Updates, renames and removals
  * New versions
  * Tagging
  * Renaming and removing
* Declaring dependencies

### [measure](https://www.cameronshields.co.uk/docs/plugins/measure.md)

* Read a plugin's cost
  * Shrinking the always-on figure
  * What users see before installing
* Is anyone still using it?
  * The four per-user signals
* Measuring across an organisation
  * Which OpenTelemetry signal answers which question
  * Redacted names
  * The Analytics API

### [cli-hints](https://www.cameronshields.co.uk/docs/plugins/cli-hints.md)

* Detect that you are running under Claude Code
* Emit the hint
  * Test the emitter
* Tag format
* When users actually see a prompt
* What the user sees

## Mods

### [overview](https://www.cameronshields.co.uk/docs/plugins/mods/overview.md)

* What mods can do that nothing else can
* A complete small mod
  * Observe, rewrite or answer
* Getting a mod
  * Sample mods
* Deciding whether to trust a mod
  * Inspect before installing
* Turning mods on and off
  * Which mods did this session load?
* Where mods run
* Mods versus the alternatives
* Mods built into Claude Code

### [create](https://www.cameronshields.co.uk/docs/plugins/mods/create.md)

* Ask Claude for a mod
  * What happens next
  * Keeping it
  * When a Claude-written mod will not load
* Write a mod yourself
  * 1. Folders and manifest
  * 2. Point at your code
  * 3. Write the module
  * 4. Load and try it
  * 5. Edit while it runs
  * How the module works
* Keep working on a mod
  * Have Claude change it
  * Generated type definitions
  * See what Claude Code reads from your code
  * Rules that keep static analysis happy
  * Test it
* Sharing a mod

### [reference](https://www.cameronshields.co.uk/docs/plugins/mods/reference.md)

* Files
* The on function
* Events
  * Tools
  * Prompts and what Claude reads
  * Commands and configuration
  * Turns
  * Session
  * Subagents
  * Interface
  * Other mods
  * Telemetry
  * Settings hook events and API calls as events
* Mods API namespaces
* Render sites
* Elements
  * Box border styles
* Limits
* Settings and environment variables
* Commands

### Mods > Build

#### [interface](https://www.cameronshields.co.uk/docs/plugins/mods/interface.md)

* Worked example: a context gauge pane
  * Files
  * The module
  * Try it
  * What is going on
* Choosing where to draw
  * Changing what Claude Code already draws
  * Opening a pane
* Building trees
  * A grid of coloured cells
* Presses and typing
  * Focus and keys
  * A field with a list
* Redrawing
* Keeping state
  * Reactive $.state
  * Reloading saved values after /clear
  * Several sessions, one store

#### [gallery](https://www.cameronshields.co.uk/docs/plugins/mods/gallery.md)

* A harness for trying samples
* Text
  * Text
  * Markdown
  * Link
* Code and diffs
  * Code
  * Code as a diff
* Layout
  * Box
* Input controls
  * Button
  * Input
  * Select
* Pictures
  * Raster (terminal only)
  * Svg (Desktop only)
  * Image and Client
* Places beyond panes

#### [events](https://www.cameronshields.co.uk/docs/plugins/mods/events.md)

* The middleware model
  * Observe
  * Rewrite
  * Answer
* Filtering with a matcher
* Tool calls
  * Guard or change a call
  * Hold a call and ask the user
  * Decide permission yourself: tool.check
* Prompts
* Turns
* Settings hook events
* Living alongside other mods
  * Run order
  * Where settings hooks sit
  * When a hook fails

#### [api](https://www.cameronshields.co.uk/docs/plugins/mods/api.md)

* Commands and tools
  * A command for the user
  * A tool for Claude
* Calling a model
* Background work
  * Showing something without a turn
  * Starting a turn from the background
  * Stopping long work
* Messaging other sessions
* Files, processes and the network
  * Other mods can intercept your calls

### Mods > Test and troubleshoot

#### [test](https://www.cameronshields.co.uk/docs/plugins/mods/test.md)

* A first test
* Two kinds of $, plus stubs
  * What a stub returns
  * Example: stubbing a model call
  * Built-in mocks
* Kit rules that trip people up
* Stub cheat sheet
* Testing timers
* Testing a drawing
  * After /clear
* Testing a policy mod

#### [troubleshoot](https://www.cameronshields.co.uk/docs/plugins/mods/troubleshoot.md)

* First two moves
* Can mods load here at all?
* Nothing from the mod appears
  * Refusal reasons
  * Messages from the built-in guard
* A hook is skipped or the mod is unloaded
* A tool call is unexpectedly denied
* A drawing is missing or unresponsive
* Edits or values go missing
* The debug log

## Run a marketplace

### [create-marketplace](https://www.cameronshields.co.uk/docs/plugins/create-marketplace.md)

* Build one end to end
  * 1. Lay out the directory
  * 2. Write the catalogue
  * 3. Validate the catalogue
  * 4. Register it and install
  * 5. Check it loaded
* Adding more plugins
* Two rules that prevent most failures
  * Relative paths start at the marketplace root
  * Keep the two names identical
* Picking a source type
* Validate, then install for real
  * What validation catches
  * What only shows up later
  * Iterating on a plugin
  * Starting again
* Sharing it

### [host-marketplace](https://www.cameronshields.co.uk/docs/plugins/host-marketplace.md)

* Choosing where to host
  * Registering for a whole repository
  * Hosting a bare catalogue URL
  * Download limits
  * Shared folders load live
  * Avoid Git LFS
  * Sharing files with symlinks
* Distributing through claude.ai organisation settings
* Private repositories and credentials
  * Users without a git account
  * Background updates and credentials
* Rolling out to a company
* Getting updates to users
  * Turning on auto-update
  * Versioning releases
  * Holding users on a version
  * Changing a command source
* Release channels
* Renaming and removing plugins
  * The renames map
  * Cleaning up removed plugins
* Authenticating archive downloads
  * Example entry
  * Rules for the helper command
  * When headers are skipped or dropped
  * Accepting an entry's helper
  * When a marketplace-level helper runs
* Dependencies and suggestions
* Things a marketplace cannot do

### [relevance](https://www.cameronshields.co.uk/docs/plugins/relevance.md)

* How suggestions work
* Writing a relevance block
  * The relevance object
  * Signals
  * Compatibility and limits
* Validating
* Allowlisting the marketplace (administrators)
* What the user actually sees

## Manage plugins for your organization

### [org](https://www.cameronshields.co.uk/docs/plugins/org.md)

* Getting plugins onto every machine
  * Delivery mechanisms
  * Requiring a marketplace and its plugins
  * Requiring plugins for one repository
  * When each surface applies the keys
  * Checking it worked
* Seeding containers and CI
* Restricting sources
  * Control matrix
  * Allowlist entry types
  * Blocklist behaviour
  * Allowing the official marketplace and your own
* Update policy
  * Per marketplace
  * Fleet-wide off switch
  * Release channels per group
* Recommending plugins
* Auditing
* Gaps and workarounds
* Troubleshooting policy

### [admin](https://www.cameronshields.co.uk/docs/plugins/mods/admin.md)

* The quick answer: block user mods
* What happens if you do nothing
  * Controls that still apply alongside mods
* Deciding whether to leave mods on
  * Reviewing a mod before approving it
* Policy recipes
  * Recipe: only your organisation's mods
  * Your plugin controls apply to mods too
  * Options on the built-in guard
* Shipping your own mods
  * What makes a mod "yours"
  * Ordering
* Writing a policy mod
  * Failing closed

## Troubleshooting

### [troubleshooting](https://www.cameronshields.co.uk/docs/plugins/troubleshooting.md)

* Typing /plugin in the wrong place
  * /plugin isn't available in this environment
  * zsh: no such file or directory: /plugin
  * The term '/plugin' is not recognized as the name of a cmdlet
  * claude: command not found after claude plugin ...
  * Unknown command and commands that do not exist
* Adding a marketplace
  * Marketplace "claude-plugins-official" not found
  * Marketplace "<name>" not found
  * Invalid marketplace source format
  * '<source>' is not a valid GitHub owner/repo shorthand
  * Invalid git URL
  * Path does not exist: <path>
  * Marketplace file not found at <path>/.claude-plugin/marketplace.json
  * SSH authentication failed or HTTPS authentication failed
  * SSH host key is not in your knownhosts file
  * Command 'git' not found or is in an unsafe location
  * Git clone timed out after 120s
  * Marketplace updates keep failing when offline
  * Adding from GitHub Enterprise Server fails
* Installing a plugin
  * Plugin "<name>" not found in marketplace "<marketplace>"
  * Plugin "<name>" not found in any marketplace
  * Plugin '<name>@<marketplace>' is already installed globally
  * "<plugin>" was not installed: it would share its folder with "<other>"
  * This plugin uses a source type your Claude Code version does not support
  * Plugin archive integrity check failed
  * An npm plugin source must name a registry package
  * Marketplace "<name>" is registered from an untrusted source
  * Marketplace "<name>" is added but ignored
  * Plugin <name> has a corrupt manifest file / has an invalid manifest file
  * Plugin directory not found at path: <path>
  * No plugins available / No marketplaces configured
  * Marketplace "<name>" is already added from a different source
  * Cannot add marketplace "<name>": its source doesn't match its extraKnownMarketplaces entry in user or managed settings
  * Failed to install: <plugin> (<reason>)
  * Could not move the new copy of this plugin version into <path>
  * Dependency errors
* Installed, but not working
  * Start here: the plugin or its skills do not show up
  * Run /reload-plugins to apply.
  * The packages it lists are not installed / were not installed, because ...
  * Plugin "<name>" not cached at <path>
  * installedplugins.json holds a record under "<id>" that this version of Claude Code cannot read
  * installedplugins.json could not be read and was rebuilt
  * install records under names that no version of Claude Code can use were removed from installedplugins.json
  * Disabled in ~/.claude/settings.json but still loads
  * Plugin "<name>" is enabled in project settings but isn't installed here
  * Plugin hooks fail to load, error, block, or never fire
  * Plugin MCP servers that fail or never connect
  * Language server problems
* Building a plugin
  * commands path not found: <path>
  * --plugin-dir pointed at a marketplace loads nothing
  * Files outside the plugin folder are not found
  * ${CLAUDEPLUGINROOT} has forward slashes on Windows
  * Plugin loads but its skills are missing
  * Skill works when typed, but Claude never uses it
  * <directory> is not a plugin or skill folder from claude plugin eval init
  * The userConfig dialog never appears
  * claude plugin validate reports errors
  * Plugin <name> has conflicting manifests
  * Warning: No commands found in plugin <name> custom directory
* Hosting a marketplace
  * Relative paths fail for URL-hosted marketplaces
  * Marketplace validation errors
* Blocked by your organisation
  * Marketplace source '<source>' is blocked by enterprise policy
  * Marketplace "<name>" is not in the allowed marketplace list
  * Plugin "<name>" is blocked by your organization's policy and cannot be installed
  * --plugin-dir is disabled by your organization's managed settings (disableSideloadFlags)
  * Plugins from ~/.claude/skills/ are blocked by your organization's managed settings
  * Command-sourced plugins are disabled by your organization's managed settings
  * Marketplace '<name>' is seed-managed

### [loading](https://www.cameronshields.co.uk/docs/plugins/loading.md)

* The three stages
  * Things missing from disk at start-up
* Identifying where a plugin came from
  * Two names for one plugin
  * Plugins shared via a repository
  * Plugins synced from claude.ai
* Finding where a plugin is enabled
  * "I disabled it, but it still loads"
  * "Enabled in project settings but not installed"
* What is on disk
  * In place or copied
  * Paths that escape the plugin
  * Old versions are cleaned up later
  * Node.js dependencies
* Versions and updates
  * How the version is computed
  * When an install refreshes the catalogue
  * When auto-update runs
  * When a command source re-runs
* Name conflicts

## Reference

### [manifest-reference](https://www.cameronshields.co.uk/docs/plugins/manifest-reference.md)

* Do you need a manifest at all?
  * A fuller example
  * Unknown fields
  * Validating
* Top-level fields
  * Identity and metadata
  * Directory listing fields
  * Behaviour
  * Component locations
  * Naming rules
* Component shapes in detail
  * Path-only components
  * commands
  * hooks
  * mcpServers
  * lspServers
  * monitors
* Path rules
  * Containment and existence
  * Replace, add or merge
* User configuration
  * Fixed choices
  * Where values are kept
  * Using a value
  * Fields that pass through a shell
* Channels
* Path variables
  * Where they resolve
  * Quoting
* Standard layout
* Marketplace entries versus the manifest

### [marketplace-reference](https://www.cameronshields.co.uk/docs/plugins/marketplace-reference.md)

* The catalogue file
  * Top-level fields
  * Reserved names
* Plugin entries
  * How an entry and plugin.json combine
  * Strict mode
* Plugin sources
  * Relative path
  * github
  * url
  * git-subdir
  * npm
  * archive
  * command
* Marketplace sources
  * Every type and where it is valid
  * Field details
  * Policy-only values
  * Writing sources in settings
* Validation messages
  * Errors
  * Warnings
  * "Invalid input" on a source
  * What validation cannot see

### [cli-reference](https://www.cameronshields.co.uk/docs/plugins/cli-reference.md)

* Conventions for claude plugin
* Authoring commands
  * plugin init
  * plugin validate
  * plugin details
  * plugin tag
  * plugin test
  * plugin eval
  * plugin eval init
* Install and lifecycle commands
  * plugin install
  * plugin uninstall
  * plugin enable and plugin disable
  * plugin update
  * plugin list
  * plugin configure
  * plugin prune
* Marketplace commands
  * plugin marketplace add
  * plugin marketplace list
  * plugin marketplace remove
  * plugin marketplace update
* /plugin in a session
* /reload-plugins
* Loading a plugin for one session

## Setup and access

### [admin-setup](https://www.cameronshields.co.uk/docs/admin-setup.md)

* The decisions at a glance
* Step 1: choose an API provider
* Step 2: decide how policy reaches devices
  * Claude Desktop and WSL sessions
* Step 3: decide what to enforce
  * Controls that need no deployment
  * Linked GitHub accounts
* Step 4: set up usage visibility
* Step 5: review data handling
* Verify and onboard

### [setup](https://www.cameronshields.co.uk/docs/setup.md)

* What you need
* Install
  * Native installer (recommended)
  * Homebrew
  * WinGet
  * Linux package managers
  * npm
  * Installing a particular version or channel
* Windows: native or WSL?
* Alpine and other musl systems
* Check the install
* Updates
  * How auto-update works
  * Release channels
  * Version floors and ranges
  * Turning updates off
  * Updating by hand
* Network home directories
* Verifying the binary
* Uninstalling

### [authentication](https://www.cameronshields.co.uk/docs/authentication.md)

* Logging in for the first time
  * Which account types work
  * Keeping work and personal accounts apart
* Team access
  * Console sign-in without an API key
* Restricting logins to your organisation
* Restricting providers
* Where credentials are stored
  * Credential helper scripts
  * Expiring logins
* Which credential wins
  * Anthropic profiles and federation
* Tokens for CI and scripts

### [managed-settings](https://www.cameronshields.co.uk/docs/managed-settings.md)

* The fastest route: one file
* Choosing a delivery mechanism
  * Splitting a file policy between teams
  * Which sessions see the policy
* How Claude Code combines several managed sources
  * Keys read from every admin source
  * Turning on merge
  * Policy helpers
  * Policy supplied by a host application
* What developers can still change
* Checking that a policy is in force
  * Reading /status
  * Finding entries that were dropped
  * Fail-closed keys
* Keys only a managed source can set
* Turning telemetry off for everyone

### [server-managed-settings](https://www.cameronshields.co.uk/docs/server-managed-settings.md)

* What you need
* Server-managed or endpoint-managed?
* Setting it up
* Checking delivery
* Limitations
* How it fits with other managed sources
  * Keys that combine across sources
* Fetching and caching
  * Invalid entries
* Fail-closed startup
* Approval dialogs
  * Which env variables need approval
  * How approvals are remembered
* Who receives server-managed settings
* Auditing
* Security realities

### [managed-mcp](https://www.cameronshields.co.uk/docs/managed-mcp.md)

* Picking a pattern
* Exclusive control with managed-mcp.json
  * Deploying the file
  * The --mcp-config and --strict-mcp-config flags
  * Lists and the managed set
  * Checking it works
  * Switching MCP off
  * Letting claude.ai connectors through
  * Letting Claude in Chrome through
* Providing servers with managedMcpServers
  * Validation rules
  * How provided servers interact with everything else
  * Which sources count
  * Timing
* Allowlists and denylists
  * Entry types
  * Variables in entries
  * Evaluation order
  * A worked policy
* What users see
* Seeing what people actually use
* Summary

### [auto-mode-config](https://www.cameronshields.co.uk/docs/auto-mode-config.md)

* What is allowed by default
  * Adding a human checkpoint
* Where the classifier gets its configuration
* Describing your environment
  * Keeping the defaults and adding yours
* Drafting entries with /auto-mode-setup
* Changing the block and allow rules
  * Editing from /permissions
* Sending every shell command to the classifier
* The auto-mode subcommands
* Working through denials

## Deployment

### [third-party-integrations](https://www.cameronshields.co.uk/docs/third-party-integrations.md)

* Side by side
  * Setup guides
* Proxies and gateways
* Rollout habits that work
* Next steps

### [feature-availability](https://www.cameronshields.co.uk/docs/feature-availability.md)

* Finding your column
* Works everywhere
* Needs a Claude subscription
* Server-side capabilities by provider
* Admin and analytics by provider
* Gateways
* What each provider is missing
  * Amazon Bedrock
  * Claude Platform on AWS
  * Google Vertex AI
  * Microsoft Foundry
  * Anthropic Console
* By subscription plan
* Models

### [amazon-bedrock](https://www.cameronshields.co.uk/docs/amazon-bedrock.md)

* Before you start
* The quick route: the login wizard
* The manual route
  * 1. Submit the use case form
  * 2. Provide AWS credentials
  * 3. Point Claude Code at Bedrock
  * 4. Pin your models
* Startup model checks
* Cross-region prefixes
* IAM permissions
* 1M context, service tiers and guardrails
* The Mantle endpoint
* Troubleshooting

### [claude-platform-on-aws](https://www.cameronshields.co.uk/docs/claude-platform-on-aws.md)

* What you need
* Step 1: choose how to authenticate
  * SigV4 with AWS credentials
  * Workspace API key
* Step 2: route Claude Code to the platform
* Step 3: pin your models
* Step 4: check it
* Using it from the Agent SDK
* Going through a proxy or gateway
* Troubleshooting

### [google-vertex-ai](https://www.cameronshields.co.uk/docs/google-vertex-ai.md)

* Before you start
* The quick route: the login wizard
* Regions and locations
* The manual route
  * 1. Enable the API
  * 2. Request model access
  * 3. Provide credentials
  * 4. Point Claude Code at Vertex AI
  * 5. Pin your models
  * 6. Check it
* Startup model checks
* IAM
* 1M context
* Troubleshooting

### [microsoft-foundry](https://www.cameronshields.co.uk/docs/microsoft-foundry.md)

* Before you start
* Step 1: create the resource and deployments
* Step 2: choose how to authenticate
* Step 3: point Claude Code at Foundry
* Step 4: pin your deployments
* Step 5: run and check
* Azure RBAC
* Troubleshooting

### [network-config](https://www.cameronshields.co.uk/docs/network-config.md)

* Proxies
* Certificate trust
* Client certificates (mTLS)
  * Rotating certificates
  * Where these variables are ignored
* Checking your setup
* Background agents
* Streaming watchdogs
* Hosts to allowlist
  * IP allowlisting for Claude
  * GitHub IP restrictions
  * Desktop and the browser

### [corporate-launcher](https://www.cameronshields.co.uk/docs/corporate-launcher.md)

* What is covered
  * What still starts outside it
* Setting it up
  * 1. Write the launcher
  * 2. Configure it in settings, not the shell
  * 3. Restart the service and sessions
  * 4. Verify
* The launcher contract
  * Value format
* Not the same as CLAUDECODESHELLPREFIX

### [devcontainer](https://www.cameronshields.co.uk/docs/devcontainer.md)

* How the pieces fit
* Adding Claude Code
  * 1. Add the feature
  * 2. Rebuild
  * 3. Sign in
* Keeping the login across rebuilds
* Baking in organisation policy
* Restricting network egress
* Running without permission prompts
* Trying the reference container

## Gateways

### [gateways](https://www.cameronshields.co.uk/docs/gateways.md)

* The request path
* Choosing a gateway
  * Claude apps gateway
  * A gateway you already run
* Subscriptions and billing
* What a gateway does not control
* Where to go next

### Gateways > Claude apps gateway

#### [claude-apps-gateway](https://www.cameronshields.co.uk/docs/claude-apps-gateway.md)

* What the gateway gives you
  * When to use something else
* Before you start
* A first deployment
  * 1. Register an OAuth client
  * 2. Create the database
  * 3. Write gateway.yaml
  * 4. Run it
  * 5. Check the sign-in path
  * 6. Sign a developer in
* Connecting developer machines
  * Point machines at the gateway
  * Certificate pinning on first connect
  * What happens after sign-in
  * Gateways on public address space you own
  * Policy for Claude Desktop sessions
  * Locking down parent settings
  * Connecting Claude Desktop itself
  * CI and headless machines
* What is enforced on developers
  * What the organisation can see
* Feature support through the gateway
* Where to go next

#### [claude-apps-gateway-config](https://www.cameronshields.co.uk/docs/claude-apps-gateway-config.md)

* Shape of the file
* Keeping secrets out of the file
* Required sections
  * listen
  * oidc
  * session
  * store
  * upstreams
* Optional sections
  * admin
  * enforcement
  * pricing
  * models
  * managed
  * telemetry
  * HTTP tuning
  * loadtestmode
* A fuller example
* Client-side managed settings

#### [claude-apps-gateway-spend-limits](https://www.cameronshields.co.uk/docs/claude-apps-gateway-spend-limits.md)

* Turning it on
  * Authenticating
* Setting caps
  * Request fields
  * How a developer's cap is resolved
* What enforcement looks like
  * Pricing each request
  * When Postgres is down
* What developers see in Claude Code
* Admin API reference
  * The effective view
  * Paging
* Data kept and for how long

#### [claude-apps-gateway-deploy](https://www.cameronshields.co.uk/docs/claude-apps-gateway-deploy.md)

* Identity provider
  * Provider quirks
  * Refresh tokens matter
* Deployment
  * Behind a proxy
  * Choosing the address
  * Building the image
  * Kubernetes
  * Cloud Run
  * Pointing laptops at it
  * Sizing sign-in rate limits for a big launch
* Operations
  * Logs
  * Health checks
  * Concurrency
  * When dependencies fail
  * Rotating the JWT secret
  * Postgres
  * Upgrades
* Security
  * Data flow
  * Threat model
  * Sign-in code guessing
  * Questionnaire answers
  * Plugin marketplace traffic
* Troubleshooting
  * Sign-in and connection errors
  * Boot and database errors
  * IdP and session errors
  * TLS, load and header errors
  * 431 after sign-in

#### [claude-apps-gateway-on-aws](https://www.cameronshields.co.uk/docs/claude-apps-gateway-on-aws.md)

* What gets built
* Prerequisites
  * Shell variables
* Step 1: security groups
* Step 2: IAM roles and the Bedrock use case form
* Step 3: RDS for PostgreSQL
* Step 4: gateway.yaml
* Step 5: secrets
* Step 6: build and push to ECR
* Step 7: deploy
  * Option A: ECS Fargate
  * Option B: EKS
* Step 8: point laptops at it
* The companion bundle
* AWS-specific troubleshooting
* Telemetry on AWS
* Splitting the Bedrock bill
  * Per developer: assume a role per person
  * Per team: application inference profiles

#### [claude-apps-gateway-on-gcp](https://www.cameronshields.co.uk/docs/claude-apps-gateway-on-gcp.md)

* What gets built
* Prerequisites
* Step 1: enable APIs
* Step 2: service account
* Step 3: build and push the image
* Step 4: Cloud SQL on a private VPC
* Step 5: gateway.yaml
* Step 6: secrets
* Step 7: deploy
  * Option A: Cloud Run
  * Option B: GKE
* Step 8: point laptops at it
* Reference assets
* Google Cloud troubleshooting

### Gateways > Other gateways

#### [llm-gateway](https://www.cameronshields.co.uk/docs/llm-gateway.md)

* Why put a gateway in the path
* The rollout in four steps
  * Locking machines to the gateway
* Subscriptions and gateways

#### [llm-gateway-connect](https://www.cameronshields.co.uk/docs/llm-gateway-connect.md)

* Is it already configured?
* Configure it yourself
  * Pick the credential variable
  * Set the base URL and credential
  * Test the connection
  * When you also have a claude.ai login
* Other surfaces
  * VS Code extension
  * Desktop app
  * GitHub Actions
  * Agent SDK
  * Slack, cloud sessions, Remote Control and voice
* Optional extras
  * Extra headers
  * Gateway models in the picker
  * Rotating credentials with apiKeyHelper
  * Silencing traffic outside the gateway
  * Gateways that speak a cloud provider's format
* Troubleshooting

#### [llm-gateway-rollout](https://www.cameronshields.co.uk/docs/llm-gateway-rollout.md)

* Before you start
  * What the gateway must do
* Three credentials, three placeholders
* Step 1: prove the gateway routes your models
* Step 2: issue a key per developer
* Step 3: run Claude Code through it yourself
* Step 4: distribute the configuration
  * What to send
  * Through managed settings (recommended)
  * HIPAA and gateways
  * Without settings distribution
* Step 5: verify from a developer machine
* Keeping it healthy
  * Controlling upgrades

#### [llm-gateway-protocol](https://www.cameronshields.co.uk/docs/llm-gateway-protocol.md)

* API formats
  * Paths and incidental traffic
  * Streaming rules
  * Format mismatches
* How the connection method changes what the client sends
  * Unrecognised model IDs
* Request headers
  * Gateway hint headers
  * Treat everything as an open list
* Response headers
* The attribution block in the system prompt
* Feature pass-through
  * Retries and error forwarding
  * Disabling pre-release capabilities
* Model discovery
  * When it runs
  * The request
  * The response
  * How entries appear

## Usage and costs

### [monitoring-usage](https://www.cameronshields.co.uk/docs/monitoring-usage.md)

* Five-minute start
* Rolling it out to everyone
  * How managed settings pin the destination
* Configuration reference
  * Core variables
  * Content gates
  * mTLS
  * Controlling metric cardinality
  * Dynamic headers
  * Team and cost-centre attributes
  * Traces (beta)
  * Example set-ups
* Cloud sessions and Claude Tag
* Attributes on everything
  * Standard attributes
  * Repository attributes
* Metrics
* Events
  * Correlation
  * Conversation and API events
  * Tool and permission events
  * Session, auth and extension events
  * Retention sweep event
  * Managed settings resolved event
* Turning the data into answers
  * Usage and cost
  * Spotting retry exhaustion
  * Tool patterns and performance
  * Mapping to GenAI semantic conventions
* Security auditing
  * Who did it
  * MCP activity
  * Detection cheat sheet
  * Egress paths, controls and evidence
  * Verifying retention
  * Shipping events to a SIEM
* Choosing backends
* Resource attributes
* Privacy summary

### [costs](https://www.cameronshields.co.uk/docs/costs.md)

* Track your own usage
  * /usage
  * /insights
  * Usage credits on a subscription
* Manage costs for an organisation
  * Report at contracted rates
  * Claude for Teams and Enterprise
  * Claude Console
  * Cloud providers
  * Decoding a developer's limit message
  * Agent teams
* Reduce token use
  * Keep context lean
  * Pick the right model
  * Trim MCP overhead
  * Use code intelligence for typed languages
  * Preprocess with hooks, pre-load with skills
  * Move specialist instructions out of CLAUDE.md
  * Tune extended thinking
  * Push noisy work to subagents
  * Prompt precisely and work in small steps
* Background token use
* Why a long session gets expensive
* Getting help with billing

### [analytics](https://www.cameronshields.co.uk/docs/analytics.md)

* Team and Enterprise dashboard
  * Turning on contribution metrics
  * The headline numbers
  * Charts
* How PR attribution works
* Using the data
  * Programmatic access
* Console (API) dashboard

## Security and data

### [security](https://www.cameronshields.co.uk/docs/security.md)

* Permission modes decide what runs unasked
* Built-in protections
* Prompt injection
* MCP servers
* IDE use
* Cloud sessions
* Best practice
  * Sensitive repositories
  * Across a team
  * Reporting a vulnerability

### [data-usage](https://www.cameronshields.co.uk/docs/data-usage.md)

* Training
* Feedback and surveys
  * /feedback, /bug and /share
  * Session quality survey
* Retention
* Where data goes
  * Local sessions
  * Cloud sessions
* Telemetry streams
* Defaults by provider
  * The WebFetch domain safety check

### [zero-data-retention](https://www.cameronshields.co.uk/docs/zero-data-retention.md)

* Where ZDR fits
  * ZDR and HIPAA
* Scope
  * Make sure traffic actually lands in the ZDR organisation
  * What ZDR does not cover
* Features switched off under ZDR
  * Model availability
* Retention for policy violations
* Getting ZDR

### [hipaa-setup](https://www.cameronshields.co.uk/docs/hipaa-setup.md)

* The plan at a glance
* Before it is applied
  * 1. Check how developers connect
  * 2. Update the apps
  * 3. Open the network
  * 4. Deploy managed settings
* After it is applied: verify on one machine
* What developers will notice
  * Credentials in commands, hooks and MCP servers
* Local session data
  * Claude Code
  * The Code tab
  * Deleting data immediately
  * Offboarding

## Adoption

### [communications-kit](https://www.cameronshields.co.uk/docs/communications-kit.md)

* Before you announce anything
* The launch announcement
  * Email version
  * Chat version
  * Executive sponsor version
  * Pilot cohort invite
  * Recruiting champions
* Weekly tips campaign
  * Choosing a model
  * Your first ten minutes
  * Project memory with /init
  * Pointing at files with @
  * Permission modes
  * Undo with /rewind
  * Connecting your tracker with MCP
  * Skills for repeated prompts
  * Hooks for notifications
  * Screenshots
  * Git chores
  * Plugins
  * The security answer
  * Habits that stick
* FAQ replies
* Starter prompts

### [champion-kit](https://www.cameronshields.co.uk/docs/champion-kit.md)

* The job in three parts
  * Time budget
* Show your work
  * What is worth posting
  * Where to post
  * Keep it short
* Be the person people ask
  * Reply with the prompt
  * Point at the feature, not the manual
  * Questions you will get
* Make it self-sustaining
  * A 30-day plan
  * When someone wants more
* Handling sceptics
* Cheat sheet to pin

## Settings

### [settings](https://www.cameronshields.co.uk/docs/settings.md)

* The four files and who they affect
  * A worked example of scope
  * Where the files come from
  * Sharing settings with a team
  * Keeping personal settings out of git
  * What your organisation enforces
* Changing a setting
  * The /config menu
  * Editing a file
  * Overriding for one session
  * When edits take effect
  * Confirming what loaded
  * When a file is broken
* Settings precedence
  * Arrays merge
  * Four scenarios
  * Troubleshoot a setting that does not apply
  * Exceptions to managed precedence
* Settings in cloud sessions

### [settings-reference](https://www.cameronshields.co.uk/docs/settings-reference.md)

* How to read the tables
* Model and responses
  * Effort per model
  * modelPicker fields
  * modelPricing fields
* Permissions
  * permissions.defaultMode values
  * Rule syntax in one minute
* Sandbox
  * Core switches
  * Filesystem
  * Network
  * Credentials
* Memory, context and environment
  * How env behaves
* Interface and terminal
  * Custom @ file suggestions
  * Footer link badges
  * Custom spinner tips
* Git and attribution
* Hooks and workflows
* Plugins, skills and marketplaces
  * Marketplace sources
* MCP servers
* Agents, sessions and worktrees
* Remote, desktop and notifications
* Authentication and providers
* Updates and versions
* Desktop tools
* Privacy and retention
* Managed-only control keys
* Global config keys (~/.claude.json)
* Deprecated and removed keys

### [settings-example](https://www.cameronshields.co.uk/docs/settings-example.md)

* Your own settings
* A team's shared settings
* An organisation's managed settings

## Permissions and sandboxing

### [permissions](https://www.cameronshields.co.uk/docs/permissions.md)

* What asks by default
  * Where saved approvals go
  * Leaving a note with your answer
* The /permissions dialog
* Permission modes at a glance
* Rule syntax
  * Whole-tool rules
  * Scoped rules
  * Matching a tool parameter
  * Wildcards in Bash rules
  * Wildcards in the tool name
* Rules for specific tools
  * Bash
  * PowerShell
  * Read and Edit
  * WebFetch
  * MCP
  * Agent (subagents)
  * Cd
* Adding logic with hooks
* Working directories
  * Moving with /cd
  * Added directories give file access, not configuration
* Permissions and the sandbox
* Managed settings
* How rules combine across files
* Project allow rules and workspace trust
  * When your local file needs trust
  * What runs before you trust a folder

### [permission-modes](https://www.cameronshields.co.uk/docs/permission-modes.md)

* The six modes at a glance
  * Things no mode will approve on its own
* Picking a setup
* How a session chooses its starting mode
  * Setting a different starting mode
  * Organisations with the HIPAA configuration
* Switching modes during a session
  * Terminal and JetBrains
  * VS Code
  * Desktop app
  * Web, mobile and Remote Control
* acceptEdits: edit freely, review later
* plan: research before changing anything
  * Approving the plan
* auto: a classifier instead of prompts
  * Availability
  * Server-side review
  * What gets blocked and allowed by default
  * The first read outside your working directories
  * What you say in conversation counts
  * When auto mode steps back
  * How each action is evaluated
* dontAsk: pre-approved only
* bypassPermissions: no checks at all
* Protected paths
* Critical paths
  * What each mode does with a critical-path removal
  * Remove-Item and cmd on Windows

### [sandboxing](https://www.cameronshields.co.uk/docs/sandboxing.md)

* What a sandboxed command can reach
  * What the sandbox does not cover
* Getting started
  * Check it is actually working
  * Linux and WSL2 setup
* Sandbox modes
  * Auto-allow
  * Regular permissions
  * The unsandboxed retry
  * Turn off the retry with strict sandbox mode
  * Temporary directories
* Configuring the boundary
  * Extra write locations
  * Read restrictions
  * Taking commands out with excludedCommands
  * Turning off filesystem isolation
* Protecting credentials
  * Masking instead of hiding
* How the enforcement works
  * Filesystem
  * Protected paths
  * Network
  * OS primitives
* Sandbox, rules and modes together
* Enforcing it across an organisation
  * Stopping developers widening it
  * Repository settings under an admin-required sandbox
  * Using your own proxy
* Troubleshooting
* Limitations

### [sandbox-environments](https://www.cameronshields.co.uk/docs/sandbox-environments.md)

* The options side by side
* Which one should I use?
  * Isolation and permission modes
* Built-in Bash sandbox
* Sandbox runtime
  * Setting it up
  * What it blocks without being told
  * After an unattended run
* Dev containers
* Custom containers
* Virtual machines
* Cloud sessions
* Enforcing isolation across an organisation

## Environments

### [cloud-environments](https://www.cameronshields.co.uk/docs/cloud-environments.md)

* The Default environment
  * Which environment a session uses
* Create and edit environments
  * Environment variables
  * Network secrets
  * Pick a default from the CLI
  * Archive an environment
  * Organisation-shared environments
  * Environments for Claude Tag channels
* Network access
  * A custom allowlist
  * GitHub proxy
  * Security proxy
* What's inside a cloud session
  * What carries over from your machine
  * Installed tools
  * GitHub issues and pull requests
  * Linking work back to the session
  * Tests, services and packages
  * Resource limits
  * Time limits
* Setup scripts
  * Rules the script must follow
  * Environment caching
  * Setup scripts or SessionStart hooks?
  * Cloud-only dependency installs with a hook
* Default allowed domains

### Environments > Self-hosted environments

#### [self-hosted-environments](https://www.cameronshields.co.uk/docs/self-hosted-environments.md)

* The moving parts
* How a session reaches your runner
* Availability and limitations
* When self-hosting is worth it
* Runner ownership
* Session lifecycle
* Runner lifecycle
  * Stopping runners cleanly
* Network paths
* What stays on your side
* Where to go next

#### [self-hosted-environments-quickstart](https://www.cameronshields.co.uk/docs/self-hosted-environments-quickstart.md)

* Before you start
  * On claude.ai
  * On the host
* Option A: guided setup
* Option B: manual setup
  * 1. Create the environment
  * 2. Store the secret on the host
  * 3. Start the runner
  * 4. Check it registered
  * 5. Send it a session
* Message the session from your terminal
* What to do next

#### [self-hosted-environments-deploy](https://www.cameronshields.co.uk/docs/self-hosted-environments-deploy.md)

* Hardening checklist
* Network requirements
  * Default-deny egress
  * Proxies that need a Proxy-Authorization header
* Configure git
  * Option 1: let the runner write the config
  * Option 2: ship your own config in the image
  * The Anthropic git proxy
  * Rewriting URLs on private networks
* Build the runner image
* Size CPU and memory
* Kubernetes recipe
* Docker Compose recipe
* Shutdown timing
  * Deferring the drain
  * How signals reach a running post-session hook
* Keep base directory and capacity identical
* Pre-warmed checkouts for big repositories
* Pin the Claude Code version
* Scale the fleet
* Known limitations
* Troubleshooting
  * When the runner exits

#### [self-hosted-environments-configuration](https://www.cameronshields.co.uk/docs/self-hosted-environments-configuration.md)

* Choosing an extension point
* Wrapper scripts
  * What the wrapper's environment contains
  * Keep stdin and file descriptor 3 attached
  * Do not touch the system prompt flags
  * Mint credentials for the person who started the session
* Lifecycle hooks
  * The checkout hook
  * The post-session hook
  * Git configuration inside lifecycle hooks
  * The command hook
* On-demand runners
  * The spawn-runner hook
* Send model requests to Bedrock or Agent Platform
  * How these sessions differ
* MCP servers
  * Turning off the built-in Claude Code Remote server
* Prompt sessions to push their work
* Permissions and tool approval
  * How each session's config is assembled
  * Rules committed to a repository

#### [self-hosted-environments-testing](https://www.cameronshields.co.uk/docs/self-hosted-environments-testing.md)

* How the test reads replies
* Install the capture hook
* The dispatch commands
* The test script
* Remote test runners
* Authenticate from CI
  * A long-lived CI host
  * Ephemeral CI runners
* A fresh environment per CI run
  * The admin token
  * Create
  * Delete

#### [self-hosted-environments-reference](https://www.cameronshields.co.uk/docs/self-hosted-environments-reference.md)

* Naming: environment versus pool
* How flags and variables relate
* Runner flags
  * Identity and registration
  * Workspace and sessions
  * Timeouts and session lifetime
  * Shutdown and retirement
  * Git
  * Network, health and logging
  * A worked example
* Orchestrator flags
  * SCM connector flags
* Variables with no flag
* Telemetry controls
* Health endpoints
  * Runner
  * Orchestrator
* Prometheus metrics
  * Runner series
  * Orchestrator series
  * Autoscaling signals
  * Scraping and alerting
  * Passing through session metrics
  * How the session counters classify endings

#### [self-hosted-environments-identity](https://www.cameronshields.co.uk/docs/self-hosted-environments-identity.md)

* What the token does and doesn't prove
* Token format
* Verifying in your service
  * Example: Express middleware with jose
  * Example: FastAPI dependency with PyJWT
* Verifying inside the session
* Claims reference
  * The act chain
* Scope what you grant
* Unverified identity variables

## Model and responses

### [model-config](https://www.cameronshields.co.uk/docs/model-config.md)

* What you can put in the model setting
  * Aliases
  * When an alias changed
* Working with Fable
  * Fable billed to usage credits
* Choosing a model
  * How /model saves your choice
  * Setting a default for brand-new sessions
  * Why did my session start on a different model?
* The default model
* opusplan: Opus to plan, Sonnet to build
* Effort and thinking
  * Effort levels
  * Picking a level
  * Ways to set effort
  * Ultracode
  * ultrathink
  * Adaptive reasoning versus fixed budgets
  * Extended thinking switches
* Context window
  * The 1M window
  * Auto-compaction
  * Unrecognised model IDs on gateways
* Fallbacks
  * Fallback chains for outages
  * Automatic fallback on flagged requests
* Organisation defaults and limits
  * Restricting models with availableModels
  * Holding back specific versions
  * Locking the experience down
  * Enterprise console controls
* Third-party deployments
  * Pin every alias before rollout
  * Picker labels and capabilities
  * modelOverrides for per-version routing
  * A custom picker entry
* Prompt caching switches

### [fast-mode](https://www.cameronshields.co.uk/docs/fast-mode.md)

* Which models support it
* Turning it on and off
  * Fast mode in -p runs
  * Fast mode in cloud sessions
* Switching models with fast mode on
* What it costs
  * Finding the spend
* When it is worth it
  * Fast mode versus lower effort
* Requirements
  * Why /fast might refuse
  * Enabling it for an organisation
* Behind proxies and LLM gateways
* Require per-session opt-in
* Rate limits and running out of credits

### [advisor](https://www.cameronshields.co.uk/docs/advisor.md)

* Where it earns its keep
* Turning it on
  * The /advisor command
  * The advisorModel setting
  * The --advisor flag
* Which advisor models are allowed
  * How a bad pairing is handled
  * Fable as the advisor and usage credits
  * Pairings worth trying
* When Claude calls it
* What the transcript shows
* Cost and caching
* Requirements
* Turning it off
* Advisor versus the alternatives

### [output-styles](https://www.cameronshields.co.uk/docs/output-styles.md)

* The built-in styles
  * Default
  * Proactive
  * Concise
  * Explanatory
  * Learning
* Switching styles
* Writing a custom style
  * 1. Choose where it lives
  * 2. Write frontmatter and instructions
  * 3. Select it
  * Frontmatter fields
* How styles work under the hood
* Style or something else?

## Interface

### [terminal-config](https://www.cameronshields.co.uk/docs/terminal-config.md)

* Multiline prompts
  * What /terminal-setup changes
* Option as Meta on macOS
* Bells and notifications
* tmux settings
* Backspace on Windows
* Flicker and the fullscreen renderer
* Wide terminals and long prose
* Themes
  * Custom themes
  * Colour tokens
* Pasting large content
* Vim editor mode

### [fullscreen](https://www.cameronshields.co.uk/docs/fullscreen.md)

* Turning it on and off
  * Which renderer you start in
* What feels different
* Mouse support
  * Copying
* Scrolling
  * Auto-follow
  * Wheel speed
  * JetBrains terminals
* Searching and reviewing
* Redrawing and clearing
* tmux
* Keeping native text selection
* Troubleshooting
  * Leftover fragments on screen
  * "Claude Code's fullscreen renderer didn't finish starting last time"
  * Reporting problems

### [accessibility](https://www.cameronshields.co.uk/docs/accessibility.md)

* Turning screen reader mode on
* Turning it off
* How output is spoken
  * Labels
  * Typing and editing
  * Reading back without being dragged to the prompt
  * Jumping between turns
* Menus and prompts
* Audible alerts
* Other accessibility options
* Known limitations
* Reporting problems

### [voice-dictation](https://www.cameronshields.co.uk/docs/voice-dictation.md)

* What you need
* Switching it on
* Hold mode
* Tap mode
* Cancelling
* Dictation language
* Changing the dictation key
* Troubleshooting
  * Terminal missing from macOS Microphone settings

### [statusline](https://www.cameronshields.co.uk/docs/statusline.md)

* Quick setup with /statusline
* Manual setup
* A first script, step by step
* When the script runs
* What the script can print
* The JSON input
  * Session and workspace
  * Model and reasoning
  * Cost and activity
  * Context window
  * Pull requests and worktrees
  * Rate and spend limits
  * Prompt cache
  * Absent versus null
* Worked examples
  * Context bar that changes colour
  * Two lines: repo and spend (Python)
  * PR link and review state (Node)
  * Subscription rate limits and gateway spend
  * Caching slow git calls
* Windows
* Subagent rows
* Tips
* Troubleshooting

### [keybindings](https://www.cameronshields.co.uk/docs/keybindings.md)

* File format
* Contexts
* Actions by context
  * Global
  * History
  * Chat
  * Voice (Chat context)
  * Autocomplete
  * Confirmation and permissions
  * Transcript
  * History search
  * Task, theme, help
  * Tabs
  * Attachments
  * Footer
  * Select
  * Message selector (rewind)
  * Model picker and effort slider
  * Plugin
  * Settings
  * Agents (agent view)
  * Scroll and selection (fullscreen)
  * Diff viewer (older dialog)
  * Diff panel (fullscreen)
  * Band above the prompt
  * Panes
* Keystroke syntax
  * Modifiers
  * Case
  * Non-US layouts
  * Chords
  * Special key names
* Unbinding and chord prefixes
* Reserved keys
* Clashes with multiplexers and the shell
* Bare keys and text fields
* Vim mode
* Validation

## Reference

### [cli-reference](https://www.cameronshields.co.uk/docs/cli-reference.md)

* Starting and resuming sessions
* Subcommands
  * Account and installation
  * Background sessions and agent view
  * Integrations and services
* Flags
  * Choosing the model and how hard it thinks
  * Permissions and tools
  * System prompt
  * Context, configuration and directories
  * Sessions, naming and background work
  * Cloud, remote and other surfaces
  * Print mode and scripting
  * Output, debugging and accessibility
* How the system prompt flags combine
  * Resumed conversations

### [commands](https://www.cameronshields.co.uk/docs/commands.md)

* A typical day, in commands
* Reference
  * Sessions and conversation
  * Context, memory and model
  * Permissions, safety and review
  * Parallel and background work
  * Configuration and interface
  * Plugins, skills, MCP and hooks
  * Integrations and platforms
  * Artifacts and design
  * Running and verifying
  * Account, usage and help
  * Removed commands
* How the / menu matches

### [env-vars](https://www.cameronshields.co.uk/docs/env-vars.md)

* Setting a variable
  * In your shell
  * In a settings file
* Which value wins
* Value formats
* Authentication
* Choosing a provider
  * Amazon Bedrock and Mantle
  * Google Cloud's Agent Platform
  * Microsoft Foundry
  * Claude Platform on AWS
  * Request shaping for gateways
* Models
* Thinking, effort, output and context
* Prompt caching
* Network, timeouts and retries
* Shell, tools and files
* MCP
* Subagents, background work and workflows
* Plugins and skills
* Sessions, history and configuration
* Interface and accessibility
* Switching features off
* Updates, telemetry and privacy
* OpenTelemetry
* Security hardening
  * The subprocess credential scrub
* Variables Claude Code sets for you
* Agent Platform region overrides
* Removed variables
* Features that need feature-flag fetching
  * The first session after install or upgrade

### [tools-reference](https://www.cameronshields.co.uk/docs/tools-reference.md)

* The full list
  * Files and code
  * Shell and processes
  * Agents, planning and coordination
  * Web
  * Scheduling, notifications and sharing
  * MCP plumbing
* Naming tools in rules and hooks
* Agent
* AskUserQuestion
* Bash
  * What carries over between commands
  * Timeouts
  * Output
  * Background commands
  * Memory cap on Linux and WSL
* Edit
* EndConversation
* Glob and Grep
* LSP
* Monitor
  * WebSocket watches
* NotebookEdit
* PowerShell
* Read
* SendFeedback
* Task tools
* WebFetch
* WebSearch
* Write

### [interactive-mode](https://www.cameronshields.co.uk/docs/interactive-mode.md)

* Keyboard shortcuts
  * Controlling the session
  * Editing text
  * New lines
  * Prefixes
  * In the transcript viewer
  * Voice
* The command menu
  * Completing a command mid-prompt
* Vim mode
  * Switching modes
  * Escaping with a two-key sequence
  * Movement (NORMAL)
  * Editing (NORMAL)
  * Visual mode
* History
  * Searching with Ctrl+R
* Background commands
  * Shell mode
* Queueing messages while Claude works
* Side questions with /btw
* Reviewing changes with /diff
  * The panel (fullscreen)
  * The dialog (classic renderer)
* Claude's task checklist
* Prompt suggestions
* Emoji shortcodes
* Spell checking
* Invisible characters are stripped
* Session recap
* Waiting out a usage limit
* Pull request and merge request badges
* Issue links

### [checkpointing](https://www.cameronshields.co.uk/docs/checkpointing.md)

* What gets captured
* Opening the rewind menu
  * Getting back to a conversation you cleared
  * Steering a summary
* When checkpoints earn their keep
* What checkpoints cannot undo
  * Shell commands
  * Most subagent edits
  * Changes made outside the session
  * Messages that join a running turn
  * Symlinks and hard links
  * Real version history

### [hooks](https://www.cameronshields.co.uk/docs/hooks.md)

* How a hook fires
* Events at a glance
* Configuration
  * Where hooks live
  * Matchers
  * Handler types
  * Path placeholders
  * Hooks in skills and subagents
  * Inspecting and disabling hooks
* Hook input
  * Fields common to most events
* Hook output
  * Exit codes
  * Timeouts
  * What exit 2 does, per event
  * HTTP responses
  * JSON output
  * Decision control by event
* Event reference
  * SessionStart
  * Setup
  * InstructionsLoaded
  * UserPromptSubmit
  * UserPromptExpansion
  * MessageDisplay
  * PreToolUse
  * PermissionRequest
  * PostToolUse
  * PostToolUseFailure
  * PostToolBatch
  * PermissionDenied
  * Notification
  * SubagentStart
  * SubagentStop
  * TaskCreated
  * TaskCompleted
  * Stop
  * StopFailure
  * TeammateIdle
  * ConfigChange
  * CwdChanged
  * DirectoryAdded
  * FileChanged
  * WorktreeCreate
  * WorktreeRemove
  * PreCompact and PostCompact
  * PreModelSwitch
  * PostModelSwitch
  * SessionEnd
  * Elicitation and ElicitationResult
* Prompt-based hooks
* Agent-based hooks
* Background (async) hooks
* Security
* PowerShell hooks on Windows
* Debugging hooks

### [channels-reference](https://www.cameronshields.co.uk/docs/channels-reference.md)

* How a channel fits together
* Worked example: a deploy alert channel
  * Set up the project
  * Write the server
  * Register it
  * Try it
* Testing during the research preview
* Server options
* Notification format
* Adding a reply tool
* Gating inbound messages
* Permission relay
  * The relay loop
  * Request fields
  * The verdict
  * Adding relay to a two-way channel
  * Testing relay locally
* Packaging as a plugin

## Glossary

### [glossary](https://www.cameronshields.co.uk/docs/glossary.md)

* A
  * AGENTS.md
  * Agent teams
  * Agentic coding
  * Agentic harness
  * Agentic loop
  * Artifact
  * Auto memory
  * Auto mode
* B
  * Bare mode
  * Bundled skills
* C
  * Channel
  * Checkpoint
  * .claude directory
  * CLAUDE.md
  * Cloud session
  * Command
  * Compaction
  * Connector
  * Context window
* D
  * Dispatch
* E
  * Effort level
  * Extended thinking
* F
  * Frontmatter
* H
  * Hook
* M
  * Managed settings
  * MCP
  * MCP server
  * MCP Tool Search
* N
  * Non-interactive mode
* O
  * Output style
* P
  * Permission mode
  * Permission rule
  * Plan mode
  * Plugin
  * Project trust
  * Prompt injection
* R
  * Remote Control
  * Rules
* S
  * Sandboxing
  * Session
  * Settings layers
  * Skill
  * Subagent
  * Surface
  * System prompt
  * System reminder
* T
  * Teleport
  * Tool
  * Transcript
  * Turn
* V
  * Verification loop
* W
  * Worktree isolation
* Old names you may still see

## Agent SDK

### [overview](https://www.cameronshields.co.uk/docs/agent-sdk/overview.md)

* Choosing between the SDK and other options
* What you can use from Claude Code
* Packages and installation
* A taste of the API
* Authentication and terms
* Naming your product
* Changelogs and bug reports

### [quickstart](https://www.cameronshields.co.uk/docs/agent-sdk/quickstart.md)

* Before you start
* Set up a project
  * TypeScript, new project
  * TypeScript, existing project
  * Python with uv
  * Python with pip
* Set your credentials
* Give the agent something to fix
* Write the agent
* Run it
* Try a few variations
* Picking a tool set

### [migration-guide](https://www.cameronshields.co.uk/docs/agent-sdk/migration-guide.md)

* What changed at a glance
* TypeScript and JavaScript projects
* Python projects
* Breaking changes
  * ClaudeCodeOptions is now ClaudeAgentOptions (Python)
  * The Claude Code system prompt is no longer the default
  * Filesystem settings: no action needed
* Coming from the OpenAI Agents SDK
* A migration checklist

### [troubleshooting](https://www.cameronshields.co.uk/docs/agent-sdk/troubleshooting.md)

* Where to look for other symptoms
* The binary cannot be found
  * Python: CLINotFoundError
  * TypeScript: native binary not found
* The binary is found but will not start
  * Windows: Refusing to execute batch script
  * Failed to start or failed to launch
  * Python: Not connected. Call connect() first.
* The process exits partway through
  * Python: ProcessError
  * TypeScript: Claude Code process exited with code N
  * Claude Code returned an error result
* Successful run, no structured output
* Still stuck

## Build agents

### [configuration](https://www.cameronshields.co.uk/docs/agent-sdk/configuration.md)

* The options object
* Settings files
* Model and fallback
* Environment variables
* Working directory
* Turn and budget caps
* Changing configuration mid-session
* Which option does what

### [examples](https://www.cameronshields.co.uk/docs/agent-sdk/examples.md)

* Start small
* Demo applications
* Python recipes in the Claude Cookbook
* Patterns worth stealing
  * Read-only auditor
  * Domain tools agent
  * Human in the loop
  * Long-running assistant
  * Orchestrator with specialists

## Core concepts

### [agent-loop](https://www.cameronshields.co.uk/docs/agent-sdk/agent-loop.md)

* The cycle
* A worked trace
* Message types
  * Reading messages in each language
* Tools
  * What is built in
  * Who decides whether a tool runs
  * Parallel calls
* Controlling the loop
  * Turns and budget
  * Effort
  * Permission modes
  * Model
* Context
  * What fills it
  * Automatic compaction
  * Keeping context lean
* Sessions
* Reading the result
* Hooks in the loop
* Putting it together

### [claude-code-features](https://www.cameronshields.co.uk/docs/agent-sdk/claude-code-features.md)

* The default: same as the CLI
* Choosing sources with settingSources
  * What each source loads
* What settingSources does not cover
* CLAUDE.md and rules
* Skills
* Hooks
  * Filesystem or programmatic?
* Picking the right feature

### [sessions](https://www.cameronshields.co.uk/docs/agent-sdk/sessions.md)

* Do you need session handling at all?
* Continue, resume and fork
* Letting the SDK track the session
  * Python: ClaudeSDKClient
  * TypeScript: continue
* Managing IDs yourself
  * Capturing the ID
  * Resuming
  * Where sessions live on disk
  * Forking
* Resuming on another machine
* Listing and organising sessions

### [session-storage](https://www.cameronshields.co.uk/docs/agent-sdk/session-storage.md)

* The adapter contract
  * Keys
  * Methods
  * Summaries
* Trying it with the in-memory store
* Writing an adapter
* Reference adapters
  * Conformance tests
* How it behaves
  * Local disk first, store second
  * Resuming from the store
  * Mirror writes are best effort
  * Reading messages back
  * Forking rewrites entries
  * Subagents
  * Retention is yours
* Which functions accept a store

## Input and output

### [streaming-vs-single-mode](https://www.cameronshields.co.uk/docs/agent-sdk/streaming-vs-single-mode.md)

* Side by side
* Streaming input
  * TypeScript
  * Python
  * Debugging a streaming session
* Single message input
* Which should I pick?

### [user-input](https://www.cameronshields.co.uk/docs/agent-sdk/user-input.md)

* Two kinds of request
* Wiring up the callback
* Approving and denying tool calls
  * A terminal approver in TypeScript
  * The Python equivalent, and a quirk
  * Richer responses
* Answering clarifying questions
  * Make sure the tool is available
  * What you receive
  * What you send back
  * Letting people type their own answer
  * A complete terminal handler
  * Option previews (TypeScript)
  * Limits
* Other ways to involve a person

### [streaming-output](https://www.cameronshields.co.uk/docs/agent-sdk/streaming-output.md)

* Switching it on
* What a stream event contains
  * Event types you will see
* Order of messages
* Streaming tool calls
* A progress display
* Limitations

### [structured-outputs](https://www.cameronshields.co.uk/docs/agent-sdk/structured-outputs.md)

* Why bother
* Getting started
* The outputFormat option
* Typed schemas with Zod and Pydantic
* Structured output after real work
* Handling failures
  * Making failures rarer
* With streaming

## Extend with tools

### [custom-tools](https://www.cameronshields.co.uk/docs/agent-sdk/custom-tools.md)

* Cheat sheet
* Anatomy of a tool
* A first tool
* Calling it
* Optional arguments and more tools
* Annotations
* Controlling which tools Claude sees
* Errors
* Images, files and other content
  * Images
  * Resources
* Structured data
* Worked example: a VAT calculator
* Where next

### [mcp](https://www.cameronshields.co.uk/docs/agent-sdk/mcp.md)

* A quick example
* Adding servers
  * In code
  * From .mcp.json
* Choosing a transport
* Approving MCP tools
  * Names
  * allowedTools
  * Finding out what a server offers
* Connection timing
  * Tuning the wait
* Tool search
* Authentication
  * Environment variables for local servers
  * Headers for remote servers
  * OAuth
* Example: read-only database questions
* When things go wrong
  * Reading server status
  * Server shows failed
  * Claude sees the tools but never calls them
  * A tool is missing from your SDK server
  * Timeouts
  * Output too large

### [tool-search](https://www.cameronshields.co.uk/docs/agent-sdk/tool-search.md)

* Why it matters
* What happens at runtime
* When it is on
* The ENABLETOOLSEARCH variable
  * Passing it in TypeScript and Python
* Help the agent find the right tool
* Limits

### [subagents](https://www.cameronshields.co.uk/docs/agent-sdk/subagents.md)

* Three ways to get a subagent
* What you gain
* Defining subagents in code
  * Definition fields
  * Background by default
  * Building definitions at runtime
* What a subagent can see
  * What comes back
* Getting Claude to delegate
* Detecting subagent runs
* Resuming a subagent
* Restricting tools
* Capping depth, concurrency and spend
  * Opus 5 delegates more
* Many agents: workflows
* Troubleshooting

## Customize behavior

### [modifying-system-prompts](https://www.cameronshields.co.uk/docs/agent-sdk/modifying-system-prompts.md)

* The four starting points
  * Which one to choose
* Appending to the preset
  * Sharing a cache across users and machines
* Writing a custom prompt
  * Large prompts in Python
  * Caching the static part of a custom prompt (TypeScript)
* Changing the prompt on a resumed session
  * Turning recording off while you tune wording
* Shaping behaviour outside the prompt
  * CLAUDE.md
  * Output styles
  * Skills, hooks and permissions
* Context Claude Code adds on its own
  * Switching off what you replace
  * Seeing exactly what Claude received
* Comparing the approaches

### [skills](https://www.cameronshields.co.uk/docs/agent-sdk/skills.md)

* How the SDK handles skills
  * Where skills are found
* The skills option
  * Rules for the allowlist
  * Confirming what loaded
* Writing a skill
  * Pre-approving tools a skill needs
* Commands in SDK sessions
  * Listing available commands
  * Running a command
  * /compact
  * /clear
* Troubleshooting
  * Skills are not found
  * Claude does not use the skill
  * "Invalid skill name"

### [plugins](https://www.cameronshields.co.uk/docs/agent-sdk/plugins.md)

* What a plugin can contribute
* Loading plugins
  * Path rules
  * Marketplace and CLI-installed plugins
* Checking what loaded
* Using plugin skills
* Plugin layout
* Troubleshooting

## Control and observability

### [permissions](https://www.cameronshields.co.uk/docs/agent-sdk/permissions.md)

* The evaluation order
  * The shadowed-callback warning
* Allow and deny rules
  * A locked-down agent
* Permission modes
  * Which mode you start in
  * The six modes
  * acceptEdits limits
  * dontAsk in practice
  * bypassPermissions cautions
  * plan and later switching
  * Subagents and modes
* Setting and changing the mode

### [hooks](https://www.cameronshields.co.uk/docs/agent-sdk/hooks.md)

* The life of a hook
* Events
  * Tool events
  * Prompt and message events
  * Lifecycle events
  * Team, task and MCP events (TypeScript only)
* Registering hooks
* Callback inputs
* Callback outputs
  * Rewriting input
  * Telling both Claude and the user
* Fire-and-forget hooks
* Worked examples
  * Posting to a webhook after each tool
  * Recording subagent completions
  * Notifications
* Timeouts
* Troubleshooting

### [file-checkpointing](https://www.cameronshields.co.uk/docs/agent-sdk/file-checkpointing.md)

* What is and is not tracked
* Switching it on
* The basic flow
  * Rewinding from the command line
* Patterns
  * Roll back as soon as something goes wrong
  * Keep every restore point
* Trying it locally
* Limitations
* Troubleshooting

### [cost-tracking](https://www.cameronshields.co.uk/docs/agent-sdk/cost-tracking.md)

* Three scopes
* Field names in each SDK
* The total for a call
  * What each result field counts
* Per-step usage without double counting
  * Output tokens: read them from the result
* Per-model breakdown
* Totals across several calls
* Streaming input mode
* Failed runs
  * Recovering after a crash
* Prompt caching
  * Longer cache lifetimes

### [observability](https://www.cameronshields.co.uk/docs/agent-sdk/observability.md)

* How it works
  * The three signals
* Turning export on
  * Checking it works
  * Short-lived runs
* Reading traces
* Joining agent traces to your app's traces
* Tagging by agent
* Attributing actions to end users
* What content gets exported

### [todo-tracking](https://www.cameronshields.co.uk/docs/agent-sdk/todo-tracking.md)

* Which models have the tools
  * Opting in
* Lifecycle of a task
* Where the data appears
* A simple activity log
* A live progress panel

## Deployment

### [hosting](https://www.cameronshields.co.uk/docs/agent-sdk/hosting.md)

* The process model
  * State on local disk
* Pick a session pattern
  * Ephemeral
  * Long-running
  * Hybrid
  * Multi-agent
* Provisioning
  * Choosing a sandbox
  * Runtime
  * Resources
  * Network
* Production checklist
  * Persistence
  * Observability
  * Credentials
  * Scaling
  * Cost
  * Tenant isolation
* Known limitations
* When it works locally but not deployed

### [secure-deployment](https://www.cameronshields.co.uk/docs/agent-sdk/secure-deployment.md)

* A simple threat model
* What Claude Code gives you already
* Three principles
* Choosing an isolation technology
  * sandbox-runtime
  * Hardened containers
  * gVisor
  * MicroVMs
  * In the cloud
* Credentials
  * The proxy pattern
  * Pointing Claude Code at a proxy
  * Credentials for git, databases and internal APIs
* Filesystem
  * Read-only mounts still leak
  * Where the agent may write

## SDK references

### [typescript](https://www.cameronshields.co.uk/docs/agent-sdk/typescript.md)

* Installing
  * Single-file executables with Bun
  * The /core entry point for bundlers
* Functions
  * query()
  * startup()
  * prewarm()
  * tool()
  * createSdkMcpServer()
  * Session helpers
  * resolveSettings()
* Options
  * Tools and permissions
  * Prompt, model and reasoning
  * Limits
  * Sessions
  * Process and environment
  * Configuration sources and extensions
  * Stream shape and extras
  * Slow or stalled APIs
* The Query object
  * applyFlagSettings()
  * updateSettings()
  * toggleMcpServer() version notes
  * WarmQuery
  * SpareProcess
* Control responses
  * SDKControlInitializeResponse
  * SDKControlInterruptResponse
  * SDKControlGetContextUsageResponse
  * Other control responses
* Configuration types
  * AgentDefinition
  * SettingSource and precedence
  * PermissionMode
  * CanUseTool
  * ToolConfig
  * MCP server configs
  * SdkPluginConfig
* Messages
  * The SDKMessage union
  * SDKAssistantMessage
  * SDKUserMessage
  * Reading tooluseresult
  * SDKUserMessageReplay
  * SDKResultMessage
  * Matching replies to your messages
  * SDKSystemMessage (init)
  * Other common messages
  * SDKPermissionDeniedMessage
  * SDKContextUsage
  * SDKMessageOrigin
  * Background task messages
  * Progress and state messages
  * SDKRateLimitEvent
  * SDKConversationResetMessage
  * AbortError
* Hooks
  * Base input
  * Inputs by event
  * Outputs
* Tool input types
  * Files and search
  * Shell and background work
  * Web
  * Agents, workflows and planning
  * Tasks
  * Scheduling and notifications
  * MCP and claude.ai
* Tool output types
  * Files and search
  * Shell
  * Web
  * Agents and workflows
  * Planning, worktrees and questions
  * Tasks, scheduling and notifications
  * MCP and claude.ai
* Permission types
* Other types
  * Account, models and agents
  * MCP status and provenance
  * Usage
  * Thinking
  * Custom process spawning
  * RewindFilesResult
* Sandbox
  * SandboxSettings
  * SandboxNetworkConfig
  * Gating unsandboxed requests

### [typescript-v2-preview](https://www.cameronshields.co.uk/docs/agent-sdk/typescript-v2-preview.md)

* Version boundary
* The V2 surface
* How V2 code looked
  * One-shot
  * A conversation
  * Resuming
  * What V2 never supported
* Migrating to query()
  * One-shot
  * Multi-turn with an input stream
  * Resume

### [python](https://www.cameronshields.co.uk/docs/agent-sdk/python.md)

* Installing
* query() or ClaudeSDKClient?
* Functions
  * query()
  * tool()
  * createsdkmcpserver()
  * Session helpers
* ClaudeSDKClient
  * Streaming input with the client
  * Interrupting
  * Custom permission logic
* Types: dataclass or TypedDict?
* ClaudeAgentOptions
  * Tools and permissions
  * Prompt, model and reasoning
  * Limits
  * Sessions
  * Environment and process
  * Configuration sources and extensions
  * Stream shape
  * Timeouts for slow APIs
* Settings sources
* System prompt types
* AgentDefinition
* Enumerations
  * ThinkingConfig
  * Other small types
* Permission callback types
* MCP configuration types
  * Status types
  * ContextUsageResponse
* Messages
  * UserMessage
  * AssistantMessage
  * SystemMessage
  * ResultMessage
  * StreamEvent
  * RateLimitEvent and RateLimitInfo
  * ConversationResetMessage
  * Background task messages
* Content blocks
* Errors
* Hook types
  * Hook inputs
  * Hook outputs
* Built-in tool schemas
  * Agent
  * AskUserQuestion
  * Bash
  * Monitor
  * Edit
  * Read
  * Write
  * Glob
  * Grep
  * NotebookEdit
  * WebFetch and WebSearch
  * Task list tools
  * Background task tools
  * ExitPlanMode
  * MCP resources
* A complete chat loop
* Sandbox
  * SandboxSettings
  * SandboxNetworkConfig
  * Handling unsandboxed requests
