Skip to content

Settings reference

Every settings.json key Claude Code reads, grouped by job, with the file each one belongs in, its accepted values, its default and worked examples.

This is the lookup page. When you already know roughly what you want to change and need the exact key, the values it accepts and where it is allowed to live, find the group below and scan the table. If you are still deciding which file to edit, or why a value is being ignored, start with Settings instead, which explains the file hierarchy and precedence.

I have grouped the keys by the job they do rather than alphabetically, because in practice you rarely touch one key in isolation: tightening permissions usually means touching three or four permission keys together, and turning on the sandbox means a whole sandbox block.

How to read the tables

Each table has a Where column that says which settings files are allowed to set the key. Claude Code silently ignores (or ignores with a warning) a key placed somewhere it does not accept.

LabelFiles that can set the key
AnyUser ~/.claude/settings.json, project .claude/settings.json, local .claude/settings.local.json, and managed settings
User/managedUser settings, managed settings, and usually a file passed with --settings. Project and local files are ignored so a cloned repository cannot change it for you
User/local/managedAs above, plus .claude/settings.local.json
ManagedOnly settings your organisation deploys (see Managed settings)
Global config~/.claude.json, not a settings file at all

A few conventions apply throughout:

  • Unset means the key is absent. Many Boolean keys behave identically when unset and when set to their "on" value, so the only meaningful thing to write is false.
  • Where a flag or environment variable can override a key for one session, I note it in the Notes column. The full list of variables lives on Environment variables and the flags on CLI reference.
  • Several "kill switch" keys are one-way: once any file turns the feature off, no other file can turn it back on. I call these out where they apply.
  • Version numbers such as "v2.1.267+" mean the key needs at least that Claude Code release.

Model and responses

These choose which model runs, how hard it thinks, and how the conversation is cached. For the bigger picture of aliases, effort and the /model picker, see Model configuration.

KeyWhereAcceptsDefaultNotes
modelAnyAlias (opus, sonnet, haiku, fable and so on) or full model IDAccount default--model and ANTHROPIC_MODEL both beat it for one session, even a managed value. An availableModels list still applies
fallbackModelAnyArray of aliases or IDs; "default" expands to the default modelUnset (no fallback)Tried in order when the primary is overloaded. Does not merge across files: the highest-precedence file supplies the whole chain. At most three distinct models are used. --fallback-model overrides
availableModelsAnyArray of aliases or IDsUnset (all models)Limits what /model, --model, subagents, skills and the advisor can pick. A model ID entry also permits later versions that extend it. Enforce it from managed settings
availableModelsMatchManaged"prefix" or "exact""prefix""exact" makes "claude-opus-5" permit Opus 5 only, not Opus 5.5. Family aliases still cover the whole family. v2.1.283+
deniedModelsManagedArray of aliases or IDsUnsetBlocks models even if availableModels allows them. "opus" blocks the family; "claude-opus-5" also blocks 5.x minors; write "claude-opus-5-0" for 5.0 alone. best, opusplan and default entries are ignored. v2.1.283+
enforceAvailableModelsAny (managed value wins when present)BooleanfalseWith true, the Default picker option resolves to the first allowed model when it would otherwise fall outside availableModels. v2.1.175+
modelOverridesAnyObject: Anthropic model ID to provider model IDUnsetRoutes a model version to a Bedrock inference profile ARN, a Vertex version or a Foundry deployment
modelPickerUser/managedObject with options array and optional replaceBuiltInOptionsBuilt-in lineupRelabel and reorder the /model list. One source supplies the whole lineup; never combined. v2.1.242+
modelPricingManagedObject with optional multiplier and overridesList priceMakes /usage, the status line, SDK cost fields, --max-budget-usd and OpenTelemetry cost figures use your contracted rates. v2.1.242+
modelSettingsAnyObject keyed by model nameUnsetPer-model effortLevel, maxEffortLevel and autoCompactWindow. /effort writes here. v2.1.251+
effortLevelAny"low", "medium", "high", "xhigh"UnsetFallback effort for models with no saved level. --effort beats it, CLAUDE_CODE_EFFORT_LEVEL beats both. In user settings, Opus 5.5 and newer ignore it
maxEffortLevelAny"low" to "xhigh", or "max" for no capUnsetCaps effort from every source, on every provider. The lowest cap across scopes wins. v2.1.267+
alwaysThinkingEnabledAnyBooleanUnset (thinking on)Only false does anything. No effect on models that always think. MAX_THINKING_TOKENS overrides for a session
showThinkingSummariesAnyBooleanfalsetrue shows full thinking summaries when you expand with Ctrl+O; otherwise a collapsed stub
fastModeAnyBooleanUnset (off)/fast writes and removes this. Fast mode runs on Opus 5.5, Opus 5 and Opus 4.8 only. CLAUDE_CODE_DISABLE_FAST_MODE wins
fastModePerSessionOptInAnyBooleanfalsetrue stops a saved fastMode: true from switching fast mode on at startup, so people opt in per session
advisorModelAny"fable", "opus", "sonnet" or a full IDUnset (advisor off)/advisor writes this. --advisor overrides; CLAUDE_CODE_DISABLE_ADVISOR_TOOL turns it off regardless. Not available on Bedrock or Claude Platform on AWS
outputStyleAnyName of a built-in or custom styleDefault styleSee Output styles
languageAnyAny language name, unvalidatedUnsetClaude replies in that language; also sets the voice dictation language and session title language
promptCacheTtlAny"5m" or "1h"Per-request defaultMain conversation cache lifetime. Order of precedence: FORCE_PROMPT_CACHING_5M, then CLAUDE_CODE_PROMPT_CACHE_TTL, then this key, then ENABLE_PROMPT_CACHING_1H
subagentPromptCacheTtlAny"5m" or "1h"Per-request defaultSame idea for subagents and side requests; CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL sits above it
switchModelsOnFlagAnyBooleantrueWhen a safety classifier flags a request: true switches to the fallback model and carries on; false pauses so you choose (or errors in -p runs)
ultracodeAnyBooleanUnset (off)Start sessions with ultracode on, where workflows are enabled and the model supports xhigh. /effort ultracode toggles per session

Effort per model

effortLevel is the blunt instrument; modelSettings lets each model keep its own level, and maxEffortLevel caps what any source can ask for. Here I let Opus run at xhigh for design work, keep Sonnet cheap, and cap everything else at high:

{
  "maxEffortLevel": "high",
  "modelSettings": {
    "claude-opus-5-5": { "effortLevel": "xhigh", "maxEffortLevel": "max" },
    "claude-sonnet-5": { "effortLevel": "medium", "autoCompactWindow": 400000 }
  }
}

Rules worth remembering:

  • Inside one file, a model's own effortLevel beats the top-level one. Across files, the highest-precedence file that sets either form for that model decides.
  • A per-model maxEffortLevel only replaces the top-level cap from the same source. Setting "max" exempts the model from that source's cap, not from caps in other files.
  • autoCompactWindow inside modelSettings takes 100000 to 1000000 or "auto", and needs v2.1.288+.
  • /effort auto clears the saved level for the current model.

modelPicker fields

FieldTypeBehaviour
optionsArray of rows, each with required model and optional label, description, behavesAsShown in your order. model is passed through verbatim, so provider-format IDs work. behavesAs (v2.1.257+) names a model your version knows so a newer model inherits its capabilities
replaceBuiltInOptionsBoolean, default falsetrue shows only your rows plus Default and the current model. false appends them after the built-in lineup

Rows the session cannot serve are dropped; rows not yet selectable are greyed out and moved to the bottom; if nothing survives you get the built-in list back.

modelPricing fields

FieldTypeBehaviour
multiplierNumber above 0, up to 10Scales every computed cost. Below 1 is a discount; above 1 is a markup (markups need v2.1.271+)
overridesMap of model ID to { input, output, cacheRead, cacheWrite } in USD per million tokens, each 0 to 10000All four rates are required. cacheWrite covers both cache lifetimes. Rates are used as written, without fast-mode or regional surcharges

A row keyed by a built-in model ID also covers that model's dated and provider-specific IDs. Any other key (a gateway alias, say) matches that exact ID only.

Permissions

These keys decide what Claude can do unprompted. The concepts are covered in Permissions and Permission modes; this is the key list.

KeyWhereAcceptsDefaultNotes
permissionsAnyObjectUnsetContainer for every permissions.* key below
permissions.allowAnyArray of rule stringsUnsetApproved without a prompt. Project-file rules apply only after you accept workspace trust. --allowedTools adds more for a session
permissions.askAnyArray of rule stringsUnsetAlways prompts
permissions.denyAnyArray of rule stringsUnsetBlocked outright. --disallowedTools adds more for a session
permissions.additionalDirectoriesAnyArray of directory pathsUnsetExtra working directories. --add-dir and /add-dir add per session. Most .claude/ config is not discovered from these
permissions.defaultModeAny (see notes)Mode name, see belowUnsetauto and bypassPermissions are ignored from project and local files. --permission-mode overrides
permissions.disableBypassPermissionsModeAny"disable"UnsetBlocks bypass mode; --dangerously-skip-permissions is then rejected
permissions.disableAutoMode / disableAutoModeAny"disable"UnsetRemoves auto mode from the Shift+Tab cycle; sessions that would start in auto start in default
permissions.blockReadsOutsideWorkingDirectoriesAnyBooleanUnsettrue from any file wins, so a repo can switch it on but not off. File tools refuse reads outside working directories in every mode. v2.1.257+
allowManagedPermissionRulesOnlyManagedBooleanUnsetOnly managed allow/ask/deny rules apply; --allowedTools is ignored and "always allow" choices disappear. Also ignores allowed-tools frontmatter in user and repo skills (v2.1.282+)
autoModeUser/managedObject with environment, allow, soft_deny, hard_deny arrays and classifyAllShellBuilt-in rules onlyProse rules for the auto mode classifier. Include "$defaults" in an array to keep the built-ins at that position. Arrays concatenate across files. See Auto mode configuration
autoMode.classifyAllShellUser/managedBooleanfalsetrue routes every Bash and PowerShell command through the classifier in auto mode, suspending shell allow rules. v2.1.193+
useAutoModeDuringPlanUser/local/managedBooleantruefalse brings back prompts for non-read-only commands in plan mode
skipAutoPermissionPromptUser/managedBooleanUnsetSkip the one-time notice on first entering auto mode yourself
skipDangerousModePermissionPromptUser/local/managedBooleanUnsetSkip the confirmation before entering bypassPermissions

permissions.defaultMode values

ValueWhat Claude may do without asking
"default" (alias "manual")Reads only
"acceptEdits"Reads, file edits, and routine filesystem commands such as mkdir and mv
"plan"Reads and plans; edits wait for plan approval
"auto"Most actions, with a background classifier checking risky ones
"dontAsk"Anything pre-approved; everything that would prompt is denied instead
"bypassPermissions"Everything

Rule syntax in one minute

Rules are Tool or Tool(specifier). Deny is checked first, then ask, then allow, and the first match wins regardless of specificity. A small, realistic block for a Next.js repo:

{
  "permissions": {
    "allow": ["Bash(pnpm lint)", "Bash(pnpm test *)", "WebFetch(domain:nextjs.org)"],
    "ask": ["Bash(git push *)", "Bash(vercel *)"],
    "deny": ["Read(./.env.local)", "Read(./secrets/**)"],
    "defaultMode": "acceptEdits"
  }
}

In MCP rules, * may appear only in the tool part after mcp__<server>__, for example mcp__linear__list_*. The full grammar, including path anchors for Read and Edit, is on Permissions.

Sandbox

The sandbox object isolates Bash commands from your filesystem and network on macOS, Linux and WSL2. Read Sandboxing first; this section lists every key. Many keys carry extra limits when set from project or local files under an admin-required sandbox, which the sandboxing page explains.

Core switches

KeyWhereAcceptsDefaultNotes
sandbox.enabledAnyBooleanfalseTurns sandboxing on
sandbox.failIfUnavailableAnyBooleanfalsetrue exits at startup if the sandbox cannot start, instead of running unsandboxed
sandbox.autoAllowBashIfSandboxedAnyBooleantrueSandboxed commands skip the permission prompt (deny and content-scoped ask rules still apply)
sandbox.allowUnsandboxedCommandsAnyBooleantruefalse ignores Claude's dangerouslyDisableSandbox retry, so commands stay sandboxed unless excluded
sandbox.excludedCommandsAnyArray of command patternsUnsetCommands that always run outside the sandbox
sandbox.ignoreViolationsAnyObject: command substring to array of violation substringsUnsetSilences expected violation reports
sandbox.enableWeakerNestedSandboxAnyBooleanfalseReuse the container's /proc; needed inside unprivileged Docker
sandbox.enableWeakerNetworkIsolationAnyBooleanfalsemacOS: lets sandboxed tools reach com.apple.trustd.agent, fixing TLS checks in Go CLIs behind a proxy
sandbox.allowAppleEventsUser/managedBooleanfalsemacOS: permits Apple Events, so open and osascript work
sandbox.ripgrepUser/managedObject with command and optional argsClaude Code's ripgrepSwap in your own rg binary
sandbox.bwrapPathManagedAbsolute pathbwrap on PATHRelative paths are dropped
sandbox.socatPathManagedAbsolute pathsocat on PATHRelative paths are dropped

Filesystem

KeyWhereAcceptsDefaultNotes
sandbox.filesystem.allowWriteAnyArray of pathsWorking dir, temp dir, added dirsExtra writable paths
sandbox.filesystem.denyWriteAnyArray of pathsUnsetBlocks writes even inside allowed areas
sandbox.filesystem.denyReadAnyArray of pathsUnsetDefault reads include files like ~/.aws/credentials, so this is where you hide them
sandbox.filesystem.allowReadAnyArray of pathsUnsetRe-opens part of a denyRead region
sandbox.filesystem.allowManagedReadPathsOnlyManagedBooleanfalseOnly managed allowRead entries count
sandbox.filesystem.disabledUser/managedBooleanfalseDrop filesystem isolation but keep network isolation. Managed-only once managed settings configure sandbox.filesystem or a deny credential file

Path prefixes in these lists follow normal Unix conventions, which is the opposite of permission rules:

PrefixResolves to
/tmp/cacheAbsolute path (so does //tmp/cache)
~/.kubeUnder your home directory
./dist or distProject root for project settings, ~/.claude for user settings

Trailing / and /** are stripped. Wildcards work in denyRead and allowRead on every platform, but in allowWrite and denyWrite they work only on macOS: on Linux and WSL2 an entry containing *, ? or [ is skipped.

Network

KeyWhereAcceptsDefaultNotes
sandbox.network.allowedDomainsAnyDomains, wildcards or IPs, optional :portUnsetPre-approved hosts. Managed-only when allowManagedDomainsOnly is on
sandbox.network.deniedDomainsAnySame formatUnsetWins even inside an allowed wildcard
sandbox.network.strictAllowlistUser/managedBooleanfalseDeny unknown hosts instead of letting your permission mode decide
sandbox.network.allowManagedDomainsOnlyManagedBooleanfalseOnly managed allowedDomains and WebFetch(domain:...) rules count; others are blocked without a prompt
sandbox.network.allowUnixSocketsAnyArray of socket pathsUnsetmacOS allow list for Unix sockets
sandbox.network.allowAllUnixSocketsAnyBooleanfalseAllow every Unix socket
sandbox.network.allowLocalBindingAnyBooleanfalsemacOS: listen on ports and connect to localhost
sandbox.network.allowMachLookupAnyArray of XPC service names; trailing * prefix matchUnsetmacOS: for the iOS Simulator, Playwright and similar
sandbox.network.httpProxyPortAnyLocal TCP portBuilt-in proxyUse your own HTTP proxy
sandbox.network.socksProxyPortAnyLocal TCP portBuilt-in proxyUse your own SOCKS proxy
sandbox.network.tlsTerminateUser/managedObject with optional caCertPath, caKeyPathUnsetProxy terminates TLS so it can inspect HTTPS (needed for credential masking)

Credentials

sandbox.credentials hides or masks secrets that sandboxed commands would otherwise see. mask entries, allowPlaintextInject, awsPairs and sigv4 are honoured only from user settings, managed settings and --settings; mask entries in project or local files are dropped.

KeyWhereAcceptsDefaultNotes
sandbox.credentials.filesAnyArray of { path, mode } where mode is "deny" or "mask"UnsetBlock or mask a credential file
sandbox.credentials.envVarsAnyArray of { name, mode }UnsetUnset or mask an environment variable
sandbox.credentials.allowPlaintextInjectUser/managedBooleanfalseAllow masked values to be substituted on plain HTTP, for trusted test networks
sandbox.credentials.awsPairsUser/managedArray of { accessKeyIdVar, secretAccessKeyVar, sessionTokenVar? }Standard AWS trio onlyPair custom-named AWS variables for request re-signing
sandbox.credentials.sigv4User/managedObject with streaming, presigned, sigv4a, each "deny" or "passthrough"All "deny"What the proxy does with AWS request forms it cannot re-sign

Optional fields on a mask entry:

FieldFilesEnv varsPurpose
extractYesYesRegex; only capture group 1 is masked, so the rest stays parseable
onExtractNoMatchYesYes"warn" (default), "deny" or "error" when nothing matched
decodeYesYes"jwt": replace verified JWTs with valid-looking fakes
maskClaimsYesYesWith decode, mask only named payload claims
maskDuplicatesYesNoAlso replace verbatim copies of a masked value elsewhere in the file
injectHostsYesYesNarrow which allowed hosts receive the real value on egress

An example I use for a Postgres connection string and a Stripe key, where the real values are only substituted on the way out to the right hosts:

{
  "sandbox": {
    "enabled": true,
    "network": { "allowedDomains": ["api.stripe.com", "db.internal.example"] },
    "credentials": {
      "envVars": [
        { "name": "DATABASE_URL", "mode": "mask", "extract": ":([^:@/]+)@", "onExtractNoMatch": "deny" },
        { "name": "STRIPE_SECRET_KEY", "mode": "mask", "injectHosts": ["api.stripe.com"] }
      ],
      "files": [{ "path": "~/.npmrc", "mode": "deny" }]
    }
  }
}

If a managed credential entry fails validation but still has a valid path or name, Claude Code degrades it to deny with a warning rather than dropping it.

Memory, context and environment

KeyWhereAcceptsDefaultNotes
autoCompactEnabledAnyBooleantrueDISABLE_AUTO_COMPACT can also turn it off; neither can undo the other's "off"
autoCompactWindowAnyTokens, 100000 to 1000000Tuned per modelCapped at the model's window. --autocompact beats it, CLAUDE_CODE_AUTO_COMPACT_WINDOW beats both
autoMemoryEnabledAnyBooleantruefalse stops reading and writing auto memory. CLAUDE_CODE_DISABLE_AUTO_MEMORY overrides either way
autoMemoryDirectoryAnyAbsolute or ~/ path~/.claude/projects/<project>/memory/See Memory
claudeMdManagedString of CLAUDE.md content (\n for line breaks)UnsetOrganisation-wide instructions
claudeMdExcludesAnyArray of globs or absolute pathsUnsetSkip specific CLAUDE.md files
fileCheckpointingEnabledAnyBooleantruefalse means /rewind cannot restore files. CLAUDE_CODE_DISABLE_FILE_CHECKPOINTING also turns it off
plansDirectoryAnyPath relative to project root~/.claude/plansWhere plan mode writes plans
bashOutputMaxCharsAnyPositive integer, clamped to 4000 to 12800030,000 charactersInline output size for successful commands
skillListingBudgetFractionAnyNumber above 0 and at most 10.01 (1% of context)Space reserved for the skill list
skillListingMaxDescCharsAnyPositive integer1536Per-skill description cap in the listing
envAnyObject of variable name to stringUnsetVariables for every session and subprocess

How env behaves

env looks simple but has sharp edges:

  • A value here overrides the same variable exported in your shell. To cancel a shell export, set it to "".
  • When the desktop app or a self-hosted environment runner launches the session, its launch environment wins over every env value.
  • NO_COLOR and FORCE_COLOR set here reach subprocesses only, not Claude Code's own interface.
  • User, managed and --settings values apply at startup; project and local values apply once you trust the workspace (or immediately in -p mode). A saved change to the merged env is picked up mid-session.
  • Values are plain text in a file and reach every subprocess. Use apiKeyHelper or otelHeadersHelper for secrets instead.

Project and local files cannot set variables a cloned repository should not control. Claude Code drops these (logging a warning visible with claude --debug):

  • Location variables: CLAUDE_CONFIG_DIR, CLAUDE_CODE_TMPDIR, HOME, TMPDIR, TMP, TEMP and the XDG_* family.
  • Windows program and machine paths such as SystemRoot, ComSpec, ProgramData, LOCALAPPDATA, PATHEXT, PSModulePath and the ProgramFiles family.
  • Variables that export session content, such as OTEL_LOG_RAW_API_BODIES, ENABLE_BETA_TRACING_DETAILED and BETA_TRACING_ENDPOINT.
  • OpenTelemetry switches and destinations: CLAUDE_CODE_ENABLE_TELEMETRY, the enhanced telemetry beta pair, the OTEL_*_EXPORTER selectors, the OTEL_LOG_* content variables, OTEL_EXPORTER_OTLP_* endpoint, header, protocol and certificate variables, and the Prometheus host and port (v2.1.282+). Values that switch telemetry off, such as none for an exporter, still apply.
  • Startup and sync variables such as CLAUDE_CODE_PROCESS_WRAPPER, CLAUDE_CODE_SYNC_SKILLS, CLAUDE_CODE_SYNC_PLUGINS, CLAUDE_CODE_PLUGIN_CACHE_DIR and CLAUDE_CODE_PLUGIN_SEED_DIR.

A handful are ignored from every settings file because only the launch environment may set them: hosting identity variables such as CLAUDE_CODE_REMOTE and CLAUDE_CODE_ACCOUNT_UUID, CLAUDE_CODE_MESSAGING_SOCKET, CLAUDE_CODE_MESSAGING_TOKEN, CLAUDE_CODE_PROJECT_DIR_NAME, CLAUDE_CODE_RESTRICTED, and the rm safety toggles (CLAUDE_CODE_DISABLE_POWERSHELL_CMD_RM_DENY, CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT, CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT, CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT).

Interface and terminal

KeyWhereAcceptsDefaultNotes
themeAny"auto", "dark", "light", "dark-daltonized", "light-daltonized", "dark-ansi", "light-ansi", "custom:<slug>", "custom:<plugin>:<slug>""dark"Custom themes live in ~/.claude/themes/ or a plugin
tuiAny"default" (classic) or "fullscreen"Chosen for youCLAUDE_CODE_NO_FLICKER and CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN override. See Fullscreen
viewModeAny"default", "verbose", "focus"UnsetFocus view needs the fullscreen renderer. Takes precedence over verbose
verboseAnyBooleanfalseFull tool output. --verbose overrides
editorModeAny"normal" or "vim""normal"Vim-style prompt editing
vimInsertModeRemapsUser/managedObject: two-character sequence to "<Esc>"UnsetFor example { "jk": "<Esc>" }
axScreenReaderAnyBooleanUnsetFlat, screen-reader-friendly output. --ax-screen-reader and CLAUDE_AX_SCREEN_READER override. See Accessibility
prefersReducedMotionAnyBooleanfalseTones down spinner, shimmer and flash animations
maxProseWidthAnyWhole number of columns, minimum 40Terminal widthKeeps prose readable on wide screens
syntaxHighlightingDisabledAnyBooleanfalseTurns off highlighting in diffs and code
autoScrollEnabledAnyBooleantrueFullscreen: follow new output
wheelScrollAccelerationEnabledAnyBooleantrueFullscreen: accelerate fast wheel scrolling
statusLineAny{ type: "command", command, padding?, refreshInterval?, hideVimModeIndicator? }NonerefreshInterval is seconds, minimum 1. See Status line
subagentStatusLineAny{ type: "command", command }Default rowsRewrites subagent rows in the task display
fileSuggestionAny{ type: "command", command }Built-in searchCustom @ autocomplete, see below
footerLinksRegexesUser/managedArray of { type: "regex", pattern, url, label? }UnsetTurns IDs in output into clickable footer badges
respectGitignoreAnyBooleantrueKeep ignored files out of the @ picker
emojiCompletionEnabledAnyBooleantrue:shortcode: suggestions and replacement
promptSuggestionEnabledAnyBooleantrueGreyed-out suggested prompts. CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION overrides
spellcheckUser/managedObject with enabled, checker ("aspell", "hunspell", "ispell", "auto"), language, colorOffNeeds a checker installed; the highest tier's block applies whole
spinnerTipsEnabledAnyBooleantruefalse hides all tips, including custom ones
spinnerTipsOverrideAnyObject with tips, tipsFile, label, excludeDefaultBuilt-in tipsCustom tips, see below
spinnerVerbsAny{ mode: "append" or "replace", verbs: [...] }Built-in verbsWords shown while a turn runs
showTurnDurationAnyBooleantrueThe "Cooked for" line after each reply
showClearContextOnPlanAcceptAnyBooleanfalseAdds a "clear context" option when approving a plan
terminalProgressBarEnabledAnyBooleantrueProgress bar in terminals that support it
terminalTitleFromRenameAnyBooleantrue/rename and --name set the tab title
timeFormatAny"auto", "12-hour", "24-hour", "24-hour-utc""auto"The UTC preset ignores timeZone
timeZoneAnyIANA name such as "Europe/London"System zoneUnknown names fall back to the system zone
defaultShellAny"bash" or "powershell""bash" (PowerShell on Windows without Bash)Shell for ! commands
respondToBashCommandsAnyBooleantruefalse adds ! output to context without Claude replying
companyAnnouncementsAnyArray of stringsNoneShown at startup
askUserQuestionTimeoutUser/managed"60s", "5m", "10m", "never""never"Unanswered questions auto-continue. CLAUDE_AFK_TIMEOUT_MS overrides
dialogExpiryUser/managed"60s", "5m", "10m", "never""5m"How long a dialog forwarded to Remote Control or an SDK host waits. CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS overrides
autoContinueAtUsageLimitUser/managedBooleantrueWait and resume after a claude.ai usage limit resets. A project or local value can only turn it off
bashEditDiffEnabledUser/managed (false from any file)BooleanUnsetRecords files changed by Bash in every mode; by default only in auto and bypass modes. CLAUDE_CODE_BASH_EDIT_DIFF overrides
voiceAny{ enabled, mode: "hold" or "tap", autoSubmit }Offmode defaults to "hold"; autoSubmit applies to hold mode. See Voice dictation
voiceEnabledAnyBooleanUnsetOlder single-key form; voice.enabled wins when set

Custom @ file suggestions

The command receives {"query": "..."} on stdin, gets the same environment as hooks (including CLAUDE_PROJECT_DIR), must answer within five seconds, and prints one path per line. Only the first 15 are shown. For a big monorepo I point it at git ls-files, which is faster than a filesystem walk:

#!/usr/bin/env bash
q=$(jq -r '.query')
git -C "$CLAUDE_PROJECT_DIR" ls-files | grep -i -- "$q" | head -15
{ "fileSuggestion": { "type": "command", "command": "~/.claude/bin/suggest-files.sh" } }

Each footerLinksRegexes entry matches a regex against the finished turn's output and builds a link from named capture groups. Limits: the built URL must keep the template's literal origin, at most 2,048 characters; schemes are https, http or a known editor or app scheme (vscode, vscode-insiders, cursor, windsurf, zed, jetbrains, idea, slack, linear, notion, figma); labels are cut to 28 columns; at most five badges show, and /clear removes them. Keep patterns linear, because they run on the main thread.

{
  "footerLinksRegexes": [
    { "type": "regex", "pattern": "\\b(?<key>ENG-\\d+)\\b", "url": "https://linear.app/acme/issue/{key}", "label": "{key}" }
  ]
}

Custom spinner tips

Each tips entry is either a plain string or an object with id (required, up to 64 characters of letters, digits, ., _, -), text (required, one line, up to 500 characters), cooldownSessions (0 to 1000, default 0) and priority (-10 to 10, default 0). tipsFile points at a local JSON file of the same entries (up to 256 KB, read once per process, not deliverable through server-managed settings). label replaces the Tip prefix (up to 40 characters) and excludeDefault: true hides the built-in tips. Up to 200 tips are read. Project and local files may contribute plain strings only; the richer fields need v2.1.247+.

Git and attribution

KeyWhereAcceptsDefaultNotes
attributionAnyObject with commit, pr, sessionUrl; or false to hide everythingStandard attributionThe false form needs v2.1.281+; older versions reject the whole file
attribution.commitAnyString (empty hides it)Co-Authored-By: trailer naming the model in useA subagent's commit names the subagent's model
attribution.prAnyString (empty hides it)A "Generated with Claude Code" lineAppended to PR descriptions
attribution.sessionUrlAnyBooleantrueAdds the claude.ai session link to commits and PRs from cloud and Remote Control sessions
includeCoAuthoredByAnyBooleantrueDeprecated; use attribution
includeGitInstructionsAnyBooleantruefalse drops the built-in commit and PR instructions and the git status snapshot. CLAUDE_CODE_DISABLE_GIT_INSTRUCTIONS overrides
prUrlTemplateAnyURL using {host}, {owner}, {repo}, {number}, {url}UnsetPoints rendered PR links at an internal review tool; GitLab merge request links are left alone

Hooks and workflows

KeyWhereAcceptsDefaultNotes
hooksAnyObject keyed by event; each value an array of { matcher, hooks } groups. Hook type is "command", "prompt", "agent", "http" or "mcp_tool"NoneMerges across files; managed hooks cannot be removed. See Hooks
disableAllHooksAnyBooleanUnsetTurns off hooks, the custom status line and the custom file suggestion together. Only managed settings can disable managed hooks
allowManagedHooksOnlyManagedBooleanUnsetOnly managed hooks, SDK hooks and hooks from force-enabled plugins run
allowedHttpHookUrlsAnyArray of URL patterns with *Any URLArrays merge across files
httpHookAllowedEnvVarsAnyArray of variable namesEach hook's own listWhich variables HTTP hooks may put in headers; arrays merge
enableWorkflowsAnyBooleanOn, except Pro planYour personal on/off for workflows
disableWorkflowsAnyBooleanfalseOrganisation-wide off switch. CLAUDE_CODE_DISABLE_WORKFLOWS also turns them off
workflowKeywordTriggerEnabledAnyBooleantruefalse lets you type "ultracode" without starting a workflow
workflowSizeGuidelineAny"unrestricted", "small" (under 5 agents), "medium" (under 10), "large" (under 50)"medium" ("small" on Pro, v2.1.271+)Overrides the /config choice and hides that row

When allowManagedHooksOnly is on, or disableAllHooks is set outside managed settings, only a managed statusLine, subagentStatusLine or fileSuggestion runs; yours is skipped without warning.

Plugins, skills and marketplaces

KeyWhereAcceptsDefaultNotes
enabledPluginsAnyObject: "plugin@marketplace" to BooleanEach plugin's defaultEnabledPer-scope on/off
extraKnownMarketplacesAnyObject: name to { source, autoUpdate? }UnsetRepo entries need workspace trust. Alias additionalMarketplaces (v2.1.232+)
pluginConfigsUser/managedObject: plugin ID to { options, mcpServers? }UnsetStored answers to a plugin's configuration dialog
prependPluginsUser/managedArray of "plugin@marketplace"UnsetOrganisation mods that run before user mods. User value only read with no managed settings and no Team or Enterprise sign-in
appendPluginsUser/managedSameUnsetMods that run after user mods; same read rules
strictKnownMarketplacesManagedArray of source objectsUnset (anything allowed)Allowlist of marketplace sources. An empty array blocks everything, including the official marketplace. Alias allowedMarketplaces
blockedMarketplacesManagedArray of source objectsUnsetBlocklist
pluginSuggestionMarketplacesManagedArray of marketplace namesUnsetWhich marketplaces can surface install suggestions in /plugin
pluginTrustMessageManagedStringStandard warningExtra text on the trust warning
disableCommandPluginSourcesManagedBooleanFollows allowManagedHooksOnlyBlocks plugins installed by running a marketplace-declared command
strictPluginOnlyCustomizationManagedtrue, or an array of "skills", "agents", "hooks", "mcp"UnsetLocks those kinds to plugin and managed sources
syncClaudeAiPluginsUser/local/managedBooleanSync onfalse stops loading plugins enabled on your claude.ai account; in user or managed settings it also moves them to ~/.claude/plugins/.trash/
syncClaudeAiSkillsUser/local/managedBooleanSync onSame for skills, under ~/.claude/skills/synced/
skillOverridesAnyObject: skill name to "on", "name-only", "user-invocable-only", "off"All "on"The /skills menu writes to .claude/settings.local.json
disableBundledSkillsAnyBooleanUnsetRemoves bundled skills and workflows and hides built-in commands such as /init from the model
disableSkillShellExecutionAnyBooleanUnsetReplaces inline shell in skills and commands with a "disabled by policy" placeholder
channelsEnabledManagedBooleanBlocked on Team, Enterprise and managed Console; allowed otherwiseAllows channels
allowedChannelPluginsManagedArray of { marketplace, plugin } or "plugin@marketplace" stringsAnthropic default listWhich channel plugins may push messages. String form v2.1.267+

Marketplace sources

Allowlists, blocklists and extraKnownMarketplaces describe marketplaces with a source object:

sourceFieldsWhere it is valid
githubrepo, optional ref, pathEverywhere. "owner/*" wildcards only in the allow and block lists (v2.1.223+)
giturl, optional ref, pathEverywhere; uses your normal git credentials
urlurl, optional headers, headersHelperEverywhere; plugins must not use relative paths
filepath to a marketplace.jsonEverywhere
directorypath to a folder containing .claude-plugin/marketplace.jsonEverywhere
settingsname, plugins (inline marketplace)extraKnownMarketplaces
hostPatternRegex matched against the hostAllow and block lists
pathPatternRegex matched against file and directory pathsAllow and block lists
skills-dirNoneAllow and block lists; opts the ~/.claude/skills/ plugin scan back in, which any allowlist otherwise stops

Allowlist matching is exact for github and git, including ref and path, so { "repo": "acme/plugins" } and { "repo": "acme/plugins", "ref": "main" } are different entries. Blocklists are looser: an entry without ref or path blocks all of them, and owner names compare case-insensitively.

MCP servers

KeyWhereAcceptsDefaultNotes
enableAllProjectMcpServersAnyBooleanUnset (prompt per server)Approve every server in .mcp.json. In untrusted folders, the project file's value is ignored
enabledMcpjsonServersAnyArray of .mcp.json server namesUnsetApprove named servers
disabledMcpjsonServersAnyArray of server namesUnsetReject named servers
allowedMcpServersAnyArray of objects with exactly one of serverName, serverCommand (exact argv), serverUrl (* wildcards)Unset (all allowed)Merges across files unless allowManagedMcpServersOnly is set. Empty array blocks every user-added server
deniedMcpServersAnySame shape; serverName can be a connector's display name such as "claude.ai Linear"UnsetAlways merges across files
allowManagedMcpServersOnlyManagedBooleanfalseOnly the managed allowlist counts
managedMcpServersManagedObject of server name to an http or sse server entry with an https:// URLUnsetPushes remote servers to everyone. See Managed MCP
disableClaudeAiConnectorsAnyBooleanfalseStop fetching claude.ai connectors. ENABLE_CLAUDEAI_MCP_SERVERS=false also does this
allowAllClaudeAiMcpsManagedBooleanfalseKeep claude.ai connectors alongside a deployed managed-mcp.json
allowClaudeInChromeWithManagedMcpManaged (device sources only)BooleanfalseLet Claude in Chrome run alongside managed-mcp.json. Ignored from server-managed settings and HKCU

Agents, sessions and worktrees

KeyWhereAcceptsDefaultNotes
agentAnyBuilt-in or custom agent nameDefault agentStart the main thread as that subagent. --agent overrides
teammateModeAny"in-process", "auto", "tmux", "iterm2""in-process"How agent team members display. --teammate-mode overrides
disableAgentViewAnyBooleanUnsetTurns off claude agents, --bg, /background and the supervisor. CLAUDE_CODE_DISABLE_AGENT_VIEW also does
crossSessionInboundAny"accept", "hold", "refuse"Decided per messageProject and local values apply only when stricter. See Cross-session messaging
isolatePeerMachinesAnyBooleanUnsetAsk before Claude messages your sessions on other machines. true from any file wins
processWrapperUser/managedLauncher command as an argv prefixUnsetRuns background processes through a corporate launcher. CLAUDE_CODE_PROCESS_WRAPPER overrides
worktree.baseRefAny"fresh" (from origin/<default>) or "head" (local HEAD)"fresh"Where new worktrees branch from
worktree.symlinkDirectoriesAnyArray of repo-relative directoriesUnsetSymlink heavy folders such as node_modules instead of copying
worktree.sparsePathsAnyArray of repo-relative directoriesWhole treeSparse checkout per worktree
worktree.bgIsolationAny"worktree" or "none""worktree""worktree" blocks edits to the main checkout from background sessions until they enter a worktree

For a pnpm monorepo this saves me gigabytes of disk:

{
  "worktree": {
    "baseRef": "head",
    "symlinkDirectories": ["node_modules", ".turbo"],
    "sparsePaths": ["apps/web", "packages/ui", "packages/config"]
  }
}

Remote, desktop and notifications

KeyWhereAcceptsDefaultNotes
remoteControlAtStartupAnyBooleanAuto-connect defaultConnect Remote Control at startup. --remote-control forces it on
disableRemoteControlAnyBooleanfalseRefuses every way of starting Remote Control
remote.defaultEnvironmentIdAny (self-hosted ccpool_ IDs: user, managed, --settings only)env_... or ccpool_... IDAnthropic-hosted, else first non-bridge environmentDefault for claude --cloud. --environment overrides. See Cloud environments
agentPushNotifEnabledAnyBooleanfalseClaude may push a phone notification when it judges one worthwhile
inputNeededNotifEnabledAnyBooleanfalsePush notification when a prompt is waiting, while Remote Control is connected
preferredNotifChannelAny"auto", "terminal_bell", "iterm2", "iterm2_with_bell", "kitty", "ghostty", "notifications_disabled""auto"Task-complete alerts. See Terminal configuration
awaySummaryEnabledAnyBooleanOnThe recap shown when you return. CLAUDE_CODE_ENABLE_AWAY_SUMMARY overrides
enableArtifactAnyBooleanAccount availabilityOnly false matters, and no file can undo it. See Artifacts
disableArtifactAnyBooleanUnsetDeprecated; true turns the tool off, false is ignored
disableDeepLinkRegistrationAny"disable"UnsetStops registering the claude-cli:// handler
disableDesktopLocalSessionsManagedtrueUnsetDesktop app offers only SSH and cloud sessions
sshConfigsUser/managedArray of { id, name, sshHost, sshPort?, sshIdentityFile? }UnsetPre-filled SSH connections in the desktop app
sshHostAllowlistManagedArray of hostname patternsAny hostLimits desktop SSH targets

Authentication and providers

KeyWhereAcceptsDefaultNotes
apiKeyHelperAnyShell commandUnsetPrints the API credential. See Authentication
awsAuthRefreshAnyShell commandUnsetRefreshes Bedrock credentials in .aws
awsCredentialExportAnyShell command printing JSON credentialsAmbient AWS chainFor Bedrock
gcpAuthRefreshAnyShell commandUnsetRefreshes Google Cloud credentials
otelHeadersHelperAnyExecutable or shell commandUnsetRotating OpenTelemetry headers
forceLoginMethodAny ("gateway" from device managed sources only)"claudeai", "console", "gateway"User choosesRestrict sign-in route
forceLoginOrgUUIDAny (enforced only when managed)One UUID or an arrayAny organisationElsewhere it only pre-selects the organisation
forceLoginGatewayUrlManaged (device sources)Full URLUnsetGateway the login screen uses. See Claude apps gateway
gatewayInternalNetworksManaged (device sources)Up to four non-overlapping public IPv4 CIDRs, /8 to /32Private ranges onlyLets /login reach a gateway on public address space you use internally
allowedProvidersManagedArray of "anthropic", "bedrock", "vertex", "foundry", "anthropicAws", "mantle", "customEndpoint", "gateway"Any providerA server-managed list can narrow, never widen, a device list

Updates and versions

KeyWhereAcceptsDefaultNotes
autoUpdatesChannelAny"latest" or "stable" (about a week old, skips regressions)"latest"See Setup
minimumVersionAnyVersion string such as "2.1.200"UnsetAuto-update never installs below this. A managed value cannot be lowered
requiredMinimumVersionManagedVersion stringUnsetRefuse to start on older builds
requiredMaximumVersionManagedVersion stringUnsetRefuse to start on newer builds

Desktop tools

KeyWhereAcceptsDefaultNotes
browserExternalPageToolsManaged"disabled" (desktop also accepts "disable")Tools allowedKeeps Claude's tools off external pages in the desktop Browser pane
disableBrowserExternalNavigationManagedtrueUnsetBrowser pane limited to localhost
disableMobileSimulatorToolsManagedtruePer-user toggleBlocks Claude's iOS Simulator tools

Privacy and retention

KeyWhereAcceptsDefaultNotes
cleanupPeriodDaysAnyWhole number, minimum 130Transcript retention. See Data usage
desktopSessionCleanupPeriodDaysUser/managedWhole number, minimum 00 (no limit)Desktop and Cowork transcripts
feedbackDraftsUser/managed"notify", "quiet", "off""notify""off" removes the feedback drafting tool. CLAUDE_CODE_SEND_FEEDBACK=0 overrides
feedbackSurveyRateAnyNumber from 0 to 1Remote rate (0.005 on Bedrock, Vertex, Foundry)CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY=1 turns it off
skipWebFetchPreflightAnyBooleanUnset (check runs)Skip the WebFetch hostname safety check, for networks that cannot reach Anthropic

Managed-only control keys

These shape how managed policy itself is delivered and combined. They only make sense in managed settings or server-managed settings.

KeyAcceptsDefaultNotes
managedSourcesBehavior"first-wins" or "merge""first-wins"Whether to use only the highest-priority admin source or combine them all
parentSettingsBehavior"first-wins" or "merge""first-wins"Whether restrictions passed by an SDK or IDE host are dropped or applied (restrictively) under your managed tier
forceRemoteSettingsRefreshBooleanfalseBlock startup until server-managed settings are freshly fetched; exit on failure
disableSideloadFlagsBooleanfalseReject --plugin-dir, --plugin-url, --agents and --mcp-config
policyHelperObject with path, timeoutMs, refreshIntervalMsUnsetExecutable that computes policy at startup. Read from plist, HKLM or the managed file only
policyHelper.pathAbsolute, normalised path (.exe on Windows)Required
policyHelper.timeoutMsInteger, minimum 100010000
policyHelper.refreshIntervalMs0, or at least 60000Run onceBackground refresh
wslInheritsWindowsSettingsBooleanfalseWSL reads the Windows policy chain, falling back to /etc/claude-code

Under "merge", keys combine by kind:

KindRuleExamples
ListsEntries from every source are combinedpermissions.allow, sandbox.network.allowedDomains
LocksStrictest value from any source winsallowManagedPermissionRulesOnly, permissions.disableBypassPermissionsMode
Restriction allowlistsTaken whole from the highest source that sets oneavailableModels, allowedMcpServers, allowedProviders, strictKnownMarketplaces, allowedChannelPlugins, fallbackModel
Whole valuesTaken whole from the highest source that sets themsandbox.credentials.awsPairs, sandbox.ripgrep
Provided MCP serversNames combined; on a clash the higher source's entry winsmanagedMcpServers
Helpers and login pinsHighest policy-carrying source onlyapiKeyHelper, awsAuthRefresh, gcpAuthRefresh, otelHeadersHelper, forceLoginOrgUUID
envMerged per variable under both modesenv
Everything elseHighest source that sets itmodel, cleanupPeriodDays

Only use "merge" when every lower-ranked source is also under admin control, because lower sources can then add allow rules. Run /status and check the "Setting sources" line to see what combined.

Global config keys (~/.claude.json)

These live in ~/.claude.json and are ignored in any settings file. /config writes most of them.

KeyAcceptsDefaultNotes
autoConnectIdeBooleanfalseConnect to a running VS Code or JetBrains IDE from an external terminal. CLAUDE_CODE_AUTO_CONNECT_IDE overrides
autoInstallIdeExtensionBooleantrueInstall the IDE extension when run from a VS Code terminal. CLAUDE_CODE_IDE_SKIP_AUTO_INSTALL=1 skips
claudeInChromeDefaultEnabledBooleanUnset (off, setup offered)Start interactive sessions with Chrome integration. --chrome and --no-chrome override
copyFullResponseBooleanfalse/copy skips the code-block picker
copyOnSelectBooleantrueMouse selection copies to the clipboard in fullscreen and agent view
defaultToAgentsViewBooleanfalseBare claude opens agent view
leftArrowOpensAgentsBooleantrue← on an empty prompt backgrounds the session and opens agent view
diffTool"auto" or "terminal""auto"Show proposed diffs in the connected IDE or keep them in the terminal
externalEditorContextBooleanfalseCtrl+G editor buffer starts with Claude's last reply as # comments
prStatusFooterEnabledBooleantruePR review status badge in the footer

Older versions also kept theme, verbose, showTurnDuration, terminalProgressBarEnabled, teammateMode, preferredNotifChannel, remoteControlAtStartup, agentPushNotifEnabled, inputNeededNotifEnabled and respectGitignore here. Claude Code still reads those old values when no settings file sets the key.

Deprecated and removed keys

KeyStatus
includeCoAuthoredByDeprecated; use attribution
disableArtifactDeprecated; use enableArtifact: false
keybindingFlavorDeprecated, no effect; word editing always follows readline conventions
taskOutputMaxCharsRemoved in v2.1.277 with the TaskOutput tool
permissionExplainerEnabledRemoved in v2.1.257 with the Ctrl+E command explanation
teammateDefaultModelRemoved in v2.1.234