[{"data":1,"prerenderedAt":837},["ShallowReactive",2],{"tool-claude-code-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":14,"about":23,"sources":33,"cover":67,"og":68,"expertise":69,"locales":70,"lang":71,"title":74,"description":75,"coverAlt":76,"url":77,"pricing":78,"kind":79,"metaTitle":80,"takeaways":81,"faq":87,"toc":100,"blocks":128,"others":606},"claude-code","2026-08-31",10,"agents",[9,10,11,12,13],"Terminal agent","Hooks","Subagents","MCP","Sandbox",[15,16,17,18,19,20,21,22],"claude code","claude code pricing","claude code hooks","claude code vs cursor","claude code sandbox","claude code subagents","claude code context window","coding agent comparison",[24,27,30],{"name":25,"url":26},"Claude (language model)","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FClaude_(language_model)",{"name":28,"url":29},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",{"name":31,"url":32},"Software carpentry","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSoftware_carpentry",[34,37,40,43,46,49,52,55,58,61,64],{"title":35,"url":36},"Claude Code documentation: overview","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Foverview",{"title":38,"url":39},"Claude Code documentation: how Claude Code works","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhow-claude-code-works",{"title":41,"url":42},"Claude Code documentation: extend Claude Code","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Ffeatures-overview",{"title":44,"url":45},"Claude Code documentation: hooks reference","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhooks",{"title":47,"url":48},"Claude Code documentation: configure permissions","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fpermissions",{"title":50,"url":51},"Claude Code documentation: sandboxing","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsandboxing",{"title":53,"url":54},"Claude Code documentation: manage costs effectively","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fcosts",{"title":56,"url":57},"Claude Code documentation: explore the context window","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fcontext-window",{"title":59,"url":60},"Claude Code changelog","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fchangelog",{"title":62,"url":63},"Claude Platform pricing: model list prices and prompt caching","https:\u002F\u002Fplatform.claude.com\u002Fdocs\u002Fen\u002Fabout-claude\u002Fpricing",{"title":65,"url":66},"Anthropic pricing: Claude Free, Pro, Max, Team and Enterprise","https:\u002F\u002Fwww.anthropic.com\u002Fpricing","\u002Fimages\u002Fblog\u002Fclaude-code\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fclaude-code\u002Fog.jpg","ai-engineer",[71,72,73],"en","de","hu","Claude Code: the terminal coding agent, reviewed","An engineering review of Claude Code: the extension surface, the real cost per developer, and the exact boundary of the Bash sandbox.","Cover art for the Claude Code review: a terminal session feeding a permission gate, a context window and a sandbox boundary","https:\u002F\u002Fclaude.com\u002Fproduct\u002Fclaude-code","Free · pay per API token","Coding agent","Claude Code review: an agent in the terminal · Balázs Csorba",[82,83,84,85,86],"Version 2.1.292 shipped on 6 October 2026 and the changelog lists releases almost daily, so pinning a version for CI is standing work rather than a one-off.","Six mechanisms extend the loop — CLAUDE.md, skills, subagents, MCP, hooks and plugins — and using the wrong one is the most common configuration mistake.","Permission rules are enforced by the client, not the model, which makes a PreToolUse hook the only guard that still holds in bypassPermissions.","The Bash sandbox covers Bash, PowerShell and Monitor commands only; file tools, MCP servers, hooks and language servers all run outside it.","Anthropic's own cost documentation puts average enterprise spend at about $13 per developer per active day, with 90% of users below $30.",[88,91,94,97],{"q":89,"a":90},"How much does Claude Code cost per month?","The client is free to install, but Claude Code is not part of the Free plan. Access comes through Claude Pro at $20 a month ($17 billed annually), Max from $100 a month, a Team or Enterprise seat, or the Anthropic API billed per token with no minimum. Anthropic's cost documentation puts average enterprise spend at about $13 per developer per active day and $150 to $250 per month.",{"q":92,"a":93},"Can Claude Code run unattended in CI?","Yes, with the -p flag in non-interactive mode and the dontAsk permission mode, which denies every tool call that would otherwise prompt. The documentation is explicit that any session started with --dangerously-skip-permissions belongs inside a container, virtual machine or the sandbox runtime, running as a non-root user.",{"q":95,"a":96},"What does a PreToolUse hook actually enforce?","It runs before the tool call, in every permission mode including dontAsk and bypassPermissions, and can return permissionDecision deny to block it. A deny from a hook still blocks the call in bypassPermissions mode, but an allow from a hook cannot override a deny rule that already exists in settings.",{"q":98,"a":99},"Does the sandbox cover MCP servers and hooks?","No. The Bash sandbox applies to Bash, PowerShell and Monitor commands and their child processes on macOS, Linux and WSL2. Read, Edit, WebFetch, MCP servers, command hooks, plugin monitors and language servers all run outside that boundary, and native Windows runs unsandboxed.",[101,104,107,110,113,116,119,122,125],{"id":102,"title":103},"what-it-is","What it actually is",{"id":105,"title":106},"how-it-works","How it works: one context window",{"id":108,"title":109},"the-extension-surface","The extension surface",{"id":111,"title":112},"getting-started","Getting started properly",{"id":114,"title":115},"cost","What it costs",{"id":117,"title":118},"security","Security and isolation",{"id":120,"title":121},"where-it-weakens","Where it weakens",{"id":123,"title":124},"verdict","Verdict",{"id":126,"title":127},"sources","Sources",[129,133,136,139,142,198,199,202,211,214,215,218,282,293,300,301,304,306,331,341,342,345,414,417,422,423,433,436,464,477,478,481,497,541,544,545,548,565,569,570],{"type":130,"content":131},"paragraph",[132],"Claude Code is Anthropic's terminal-first coding agent: a CLI that reads a repository, edits files, runs commands and iterates on the result, with the Claude models behind it. On the evidence of the documentation it is the most complete agent harness on the market, and the reason is not the model but the six extension mechanisms wrapped around the loop. The cost of that completeness is a configuration surface large enough to get wrong, and a release cadence — 2.1.292 landed on 6 October 2026 — that turns version pinning into standing maintenance. Worth adopting, provided the security section below is read before the first unattended run.",{"type":130,"content":134},[135],"It competes with Cursor's editor-native agent, GitHub Copilot's agent mode and the Codex CLI, and it is the only one of the four where the agent is the application rather than a feature of an editor. That matters on a large repository, where the agent gets the whole working tree, the shell and the git history rather than whatever happens to be open in a tab. The trade is the interface: a terminal is a poor place to read a diff, which is why the VS Code and JetBrains extensions exist at all.",{"type":137,"level":138,"id":102,"text":103},"heading",2,{"type":130,"content":140},[141],"The agentic loop is the product. A task moves through gather context, take action, verify results, over and over, with the model choosing the next tool call and the harness supplying the tools: file operations, search, shell execution, web search, and code intelligence through language-server plugins. Everything below the loop — settings files, skills, subagents, hooks — exists to make that loop cheaper, safer or broader.",{"type":143,"ordered":144,"items":145},"list",false,[146,148,150,152,177,179,181],[147],"Version 2.1.292, published 6 October 2026; the changelog lists releases up to that point almost daily.",[149],"Runs in the terminal, as VS Code and JetBrains extensions, on the desktop, in the browser, and on Amazon Bedrock and Google Cloud.",[151],"Built-in tools cover file operations, search, shell, web search and code intelligence; the terminal CLI, VS Code and JetBrains also accept third-party providers.",[153,154,158,159,162,163,162,166,162,169,172,173,176],"Permission modes are ",{"tag":155,"children":156},"code",[157],"default"," (labelled manual), ",{"tag":155,"children":160},[161],"acceptEdits",", ",{"tag":155,"children":164},[165],"plan",{"tag":155,"children":167},[168],"auto",{"tag":155,"children":170},[171],"dontAsk"," and ",{"tag":155,"children":174},[175],"bypassPermissions",".",[178],"Auto mode is the built-in starting mode for interactive terminal and VS Code sessions on Pro, Max and Team: a separate classifier model reviews each action instead of a human.",[180],"The Bash sandbox uses operating-system primitives — Seatbelt on macOS, bubblewrap on Linux — and applies to Bash, PowerShell and Monitor commands only.",[182,183,162,186,162,189,162,192,172,195,176],"Bundled skills ship in the box, including ",{"tag":155,"children":184},[185],"\u002Fdoctor",{"tag":155,"children":187},[188],"\u002Fcode-review",{"tag":155,"children":190},[191],"\u002Fbatch",{"tag":155,"children":193},[194],"\u002Fdebug",{"tag":155,"children":196},[197],"\u002Floop",{"type":137,"level":138,"id":105,"text":106},{"type":130,"content":200},[201],"Everything the model knows about a session lives in a single context window: CLAUDE.md and any AGENTS.md, auto memory, MCP tool names, skill descriptions, every file read, every tool result and the transcript itself. Path-scoped rules load when their trigger file is read. When the window fills, the session compacts — the conversation is replaced with a structured summary, the root CLAUDE.md and unscoped rules are re-injected from disk, up to five recently modified files are re-read, and invoked skill bodies come back capped at 5,000 tokens each and 25,000 in total.",{"type":203,"attrs":204,"inner":208,"caption":209},"diagram",{"viewBox":205,"role":206,"aria-labelledby":207},"0 0 720 412","img","d-cc-t d-cc-d","\u003Ctitle id=\"d-cc-t\">Where a session's tokens go, and what compaction keeps\u003C\u002Ftitle>\u003Cdesc id=\"d-cc-d\">Four columns. Startup: CLAUDE.md, unscoped rules, auto memory and skill names, re-injected from disk after compaction. Reads: file contents, tool output and web results, kept only as part of the summary. History: the transcript and its thinking, replaced by a structured summary. Output: the final text, the diffs and the summaries returned by subagents, which are not summarised away. A band below: after compaction the project CLAUDE.md, unscoped rules, auto memory, the git status snapshot and the plan are re-injected from disk, while up to five recently modified files, path-scoped rules and nested CLAUDE.md files are rebuilt on demand. Invoked skill bodies return capped at 5,000 tokens each and 25,000 in total.\u003C\u002Fdesc>\u003Ctext x=\"20\" y=\"26\" class=\"d-title\">Where a session’s tokens go\u003C\u002Ftext>\u003Ctext x=\"700\" y=\"26\" text-anchor=\"end\" class=\"d-label\">and what compaction keeps\u003C\u002Ftext>\u003Crect x=\"20\" y=\"44\" width=\"160\" height=\"56\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"100\" y=\"72\" text-anchor=\"middle\" class=\"d-text\">Startup\u003C\u002Ftext>\u003Ctext x=\"100\" y=\"92\" text-anchor=\"middle\" class=\"d-small\">loaded before you type\u003C\u002Ftext>\u003Cpath d=\"M100 100 V112\" class=\"d-line\" \u002F>\u003Crect x=\"20\" y=\"112\" width=\"160\" height=\"120\" rx=\"10\" class=\"d-box d-dash\" \u002F>\u003Ctext x=\"100\" y=\"140\" text-anchor=\"middle\" class=\"d-small\">CLAUDE.md\u003C\u002Ftext>\u003Ctext x=\"100\" y=\"162\" text-anchor=\"middle\" class=\"d-small\">unscoped rules\u003C\u002Ftext>\u003Ctext x=\"100\" y=\"184\" text-anchor=\"middle\" class=\"d-small\">auto memory\u003C\u002Ftext>\u003Ctext x=\"100\" y=\"206\" text-anchor=\"middle\" class=\"d-small\">skill names\u003C\u002Ftext>\u003Crect x=\"193\" y=\"44\" width=\"160\" height=\"56\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"273\" y=\"72\" text-anchor=\"middle\" class=\"d-text\">Reads\u003C\u002Ftext>\u003Ctext x=\"273\" y=\"92\" text-anchor=\"middle\" class=\"d-small\">grows with the task\u003C\u002Ftext>\u003Cpath d=\"M273 100 V112\" class=\"d-line\" \u002F>\u003Crect x=\"193\" y=\"112\" width=\"160\" height=\"120\" rx=\"10\" class=\"d-box d-dash\" \u002F>\u003Ctext x=\"273\" y=\"140\" text-anchor=\"middle\" class=\"d-small\">file contents\u003C\u002Ftext>\u003Ctext x=\"273\" y=\"162\" text-anchor=\"middle\" class=\"d-small\">tool output\u003C\u002Ftext>\u003Ctext x=\"273\" y=\"184\" text-anchor=\"middle\" class=\"d-small\">web results\u003C\u002Ftext>\u003Ctext x=\"273\" y=\"206\" text-anchor=\"middle\" class=\"d-small\">search hits\u003C\u002Ftext>\u003Crect x=\"366\" y=\"44\" width=\"160\" height=\"56\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"446\" y=\"72\" text-anchor=\"middle\" class=\"d-text\">History\u003C\u002Ftext>\u003Ctext x=\"446\" y=\"92\" text-anchor=\"middle\" class=\"d-small\">grows every turn\u003C\u002Ftext>\u003Cpath d=\"M446 100 V112\" class=\"d-line\" \u002F>\u003Crect x=\"366\" y=\"112\" width=\"160\" height=\"120\" rx=\"10\" class=\"d-box d-dash\" \u002F>\u003Ctext x=\"446\" y=\"140\" text-anchor=\"middle\" class=\"d-small\">transcript\u003C\u002Ftext>\u003Ctext x=\"446\" y=\"162\" text-anchor=\"middle\" class=\"d-small\">thinking blocks\u003C\u002Ftext>\u003Ctext x=\"446\" y=\"184\" text-anchor=\"middle\" class=\"d-small\">tool call results\u003C\u002Ftext>\u003Ctext x=\"446\" y=\"206\" text-anchor=\"middle\" class=\"d-small\">re-sent each turn\u003C\u002Ftext>\u003Crect x=\"539\" y=\"44\" width=\"160\" height=\"56\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"619\" y=\"72\" text-anchor=\"middle\" class=\"d-text\">Output\u003C\u002Ftext>\u003Ctext x=\"619\" y=\"92\" text-anchor=\"middle\" class=\"d-small\">what comes back\u003C\u002Ftext>\u003Cpath d=\"M619 100 V112\" class=\"d-line\" \u002F>\u003Crect x=\"539\" y=\"112\" width=\"160\" height=\"120\" rx=\"10\" class=\"d-box d-dash\" \u002F>\u003Ctext x=\"619\" y=\"140\" text-anchor=\"middle\" class=\"d-small\">final text\u003C\u002Ftext>\u003Ctext x=\"619\" y=\"162\" text-anchor=\"middle\" class=\"d-small\">diffs\u003C\u002Ftext>\u003Ctext x=\"619\" y=\"184\" text-anchor=\"middle\" class=\"d-small\">subagent summaries\u003C\u002Ftext>\u003Ctext x=\"619\" y=\"206\" text-anchor=\"middle\" class=\"d-small\">not summarised\u003C\u002Ftext>\u003Crect x=\"20\" y=\"256\" width=\"679\" height=\"116\" rx=\"10\" class=\"d-box d-dash\" \u002F>\u003Ctext x=\"40\" y=\"284\" class=\"d-text\">When the window fills: compaction\u003C\u002Ftext>\u003Ctext x=\"40\" y=\"312\" class=\"d-small\">Re-injected from disk: project CLAUDE.md, unscoped\u003C\u002Ftext>\u003Ctext x=\"40\" y=\"334\" class=\"d-small\">rules, auto memory, a fresh git status, the plan\u003C\u002Ftext>\u003Ctext x=\"380\" y=\"312\" class=\"d-small\">Rebuilt on demand: up to five recently modified\u003C\u002Ftext>\u003Ctext x=\"380\" y=\"334\" class=\"d-small\">files, path-scoped rules, nested CLAUDE.md\u003C\u002Ftext>\u003Ctext x=\"40\" y=\"392\" class=\"d-label\">skill bodies return capped at 5,000 tokens each and 25,000 in total\u003C\u002Ftext>",[210],"Context is the scarce resource: everything the model knows about a session is re-sent on every turn, and compaction is the mechanism that throws part of it away.",{"type":130,"content":212},[213],"The consequence for a bill is that re-sent history dominates, not the answer. A real session screen reports hundreds of thousands of cached input tokens against a few thousand output tokens, and cache reads are billed at a tenth of the input rate on current models. Anyone trying to reduce spend is really deciding what enters the window, which is why the documentation pushes MCP Tool Search, subagents and skills over simply asking the model to be brief.",{"type":137,"level":138,"id":108,"text":109},{"type":130,"content":216},[217],"Six mechanisms extend the loop, and the documentation is unusually clear that they are not interchangeable. CLAUDE.md is always-on context. A skill is knowledge or a workflow loaded on demand, following the Agent Skills open standard. A subagent is an isolated context that returns a summary instead of its transcript. MCP connects external services. A hook is a shell command, HTTP request, MCP tool call, single-turn prompt or agent that fires on a lifecycle event. Plugins bundle the lot for distribution across a team.",{"type":219,"head":220,"rows":229},"table",[221,223,225,227],[222],"Mechanism",[224],"What it is",[226],"Context cost",[228],"Deterministic?",[230,239,248,256,264,273],[231,233,235,237],[232],"CLAUDE.md",[234],"Always-on project instructions",[236],"Injected at session start",[238],"No, the model decides to follow it",[240,242,244,246],[241],"Skill",[243],"Markdown knowledge or workflow",[245],"Description at start, body on use",[247],"No",[249,251,253,255],[250],"Subagent",[252],"Isolated loop returning a summary",[254],"Only the summary returns",[247],[257,259,261,263],[258],"MCP server",[260],"External tools and data",[262],"Names at start, schemas on use",[247],[265,267,269,271],[266],"Hook",[268],"Script or model call on an event",[270],"Zero unless it returns output",[272],"Yes, the event always fires",[274,276,278,280],[275],"Plugin",[277],"Bundle of skills, hooks, agents, MCP",[279],"Whatever the bundle contains",[281],"Depends on contents",{"type":130,"content":283},[284,285,288,289,292],"One sentence from the permissions documentation decides the whole design: permission rules are enforced by Claude Code, not by the model. An instruction like ",{"tag":155,"children":286},[287],"never edit .env"," in CLAUDE.md is a request; a ",{"tag":155,"children":290},[291],"PreToolUse"," hook that denies the edit is enforcement. Any team treating the first as a control has misread the threat model.",{"type":294,"variant":295,"title":296,"body":297},"callout","warn","Auto mode is a classifier, not a boundary",[298],[299],"Auto mode removes the human from the loop and replaces it with a second model that reviews each action before it runs. That is a per-action control, not an isolation boundary. A container, a virtual machine or the sandbox runtime is what stops a bad action from reaching the filesystem, and the documentation recommends keeping both.",{"type":137,"level":138,"id":111,"text":112},{"type":130,"content":302},[303],"Installation is a shell script and a login; there is no project to set up. The part of a first session worth getting right is the settings file, because that is where a team converts prompt instructions into enforced rules. This project-level configuration allowlists the commands it trusts, blocks a git push, formats every edit and switches on the Bash sandbox:",{"type":155,"code":305},"{\n  \"permissions\": {\n    \"allow\": [\n      \"Bash(npm run *)\",\n      \"Bash(git commit *)\",\n      \"Read\",\n      \"Edit(src\u002F**)\"\n    ],\n    \"deny\": [\n      \"Bash(git push *)\",\n      \"Read(.env)\"\n    ]\n  },\n  \"sandbox\": {\n    \"enabled\": true,\n    \"allowWrite\": [\"src\"],\n    \"allowedDomains\": [\"registry.npmjs.org\"]\n  },\n  \"hooks\": {\n    \"PostToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          { \"type\": \"command\", \"command\": \"jq -r '.tool_input.file_path' | xargs npx prettier --write\" }\n        ]\n      }\n    ]\n  }\n}\n",{"type":130,"content":307},[308,309,312,313,316,317,320,321,324,325,327,328,330],"Two details in that file are easy to get wrong. ",{"tag":155,"children":310},[311],"Bash(git commit *)"," matches ",{"tag":155,"children":314},[315],"git commit -m 'x'"," but not ",{"tag":155,"children":318},[319],"git -C . commit -m 'x'",", because the wildcard stands in for whatever text sits in its place. And a hook that exits 0 with no output has not approved anything — it has declined to decide, and the call continues through the normal permission flow. What does hold everywhere is a ",{"tag":155,"children":322},[323],"deny"," returned by a ",{"tag":155,"children":326},[291]," hook: it still blocks the tool in ",{"tag":155,"children":329},[175]," mode, which is the one guarantee that survives a developer who has switched their own prompts off.",{"type":294,"variant":332,"title":333,"body":334},"note","Commit the settings file",[335],[336,337,340],"Put that file at ",{"tag":155,"children":338},[339],".claude\u002Fsettings.json"," and check it into the repository. Enterprise enforcement has to start from managed settings delivered by an MDM or from the server, because no user setting, project setting or command-line flag can override them — a project file only binds the teams that agree to it.",{"type":137,"level":138,"id":114,"text":115},{"type":130,"content":343},[344],"The client is free to install and Claude Code is not part of the Free plan. Model access comes from a Claude subscription, a Team or Enterprise seat, or the Anthropic API billed per token. What makes the bill hard to predict is that subscriptions meter against rolling usage windows rather than publishing a token allowance.",{"type":219,"head":346,"rows":355},[347,349,351,353],[348],"Route",[350],"Price",[352],"Claude Code",[354],"Shape",[356,365,374,382,390,398,406],[357,359,361,363],[358],"Free",[360],"$0",[362],"Not included",[364],"Chat only, no terminal agent",[366,368,370,372],[367],"Pro",[369],"$20 a month, $17 billed annually",[371],"Yes",[373],"Rolling session and weekly limits",[375,377,379,380],[376],"Max",[378],"From $100 a month",[371],[381],"5x or 20x Pro usage",[383,385,387,388],[384],"Team standard seat",[386],"$20 a seat annually, $25 monthly",[371],[389],"Mix and match with premium seats",[391,393,395,396],[392],"Team premium seat",[394],"$100 a seat annually, $125 monthly",[371],[397],"Five times the standard seat usage",[399,401,403,404],[400],"Enterprise",[402],"$20 a seat annually plus usage at API rates",[371],[405],"SSO, SCIM, audit logs, spend limits",[407,409,411,412],[408],"Anthropic API",[410],"Per token, no minimum",[371],[413],"Hard ceiling, billed directly",{"type":130,"content":415},[416],"On the per-token route the current list prices are $4 per million input tokens and $20 per million output tokens for Opus 5.5, $2 and $10 for Sonnet 5.5, and $1 and $5 for Haiku 4.5, with cache reads at $0.20, $0.20 and $0.10. The cheapest lever is therefore the model: the same task on Sonnet 5.5 instead of Opus 5.5 halves the bill at list price, and Haiku 4.5 is a quarter of it. The documentation pushes the same point from the other end — moving long instructions out of CLAUDE.md and into skills, keeping MCP servers few, and pushing verbose work into subagents so their transcripts never enter the main window.",{"type":294,"variant":295,"title":418,"body":419},"Two numbers matter more than the plan table",[420],[421],"Claude 4.7 and later use a newer tokenizer that produces approximately 30% more tokens for the same text, so the cost of a given task rose without the model name changing. And Anthropic's own documentation puts average enterprise spend at about $13 per developer per active day and $150 to $250 per month, with 90% of users under $30 a day. A seat price predicts none of that.",{"type":137,"level":138,"id":117,"text":118},{"type":130,"content":424},[425,426,428,429,432],"The security model is the strongest part of the design and the easiest to misuse. Rules are matched by Claude Code rather than by the model, precedence puts a deny at any scope above an allow at any other, and managed settings outrank user settings, project settings and command-line flags. Deny rules hold in ",{"tag":155,"children":427},[175],", and a removal such as ",{"tag":155,"children":430},[431],"rm -rf \u002F"," is refused even when an allow rule or a hook permits it. That is the behaviour you want from a circuit breaker.",{"type":130,"content":434},[435],"The sandbox is the second layer, and its scope is narrower than the name suggests:",{"type":143,"ordered":144,"items":437},[438,440,446,448,458],[439],"Bash, PowerShell and Monitor commands and their child processes, on macOS, Linux and WSL2 — native Windows runs unsandboxed.",[441,442,445],"File tools such as Read, Edit, Write and WebFetch, which follow permission rules instead; a sandbox ",{"tag":155,"children":443},[444],"denyRead"," entry does not stop Read.",[447],"MCP servers, command hooks, plugin monitors, language servers and helper commands, all of which run with the session's full access.",[449,450,453,454,457],"Commands that fail inside the sandbox can be retried unsandboxed through ",{"tag":155,"children":451},[452],"dangerouslyDisableSandbox","; setting ",{"tag":155,"children":455},[456],"allowUnsandboxedCommands"," to false removes the escape hatch.",[459,460,463],"Trust is per directory and lasts one session: a project-level subagent's frontmatter hooks do not run until the workspace trust dialog is accepted, and a ",{"tag":155,"children":461},[462],"-p"," run does not count as accepting it.",{"type":294,"variant":295,"title":465,"body":466},"The environment variable that changes your invoice",[467],[468,469,472,473,476],"If ",{"tag":155,"children":470},[471],"ANTHROPIC_API_KEY"," is set in the environment, the CLI authenticates with the API key and bills at API rates instead of drawing on the subscription. In CI that is usually intended; on a developer machine it is a silent cost switch. The security documentation also notes that reviewing a project's ",{"tag":155,"children":474},[475],".mcp.json"," does not show every server a session can load, because plugins and user-scope servers sit outside the repository.",{"type":137,"level":138,"id":120,"text":121},{"type":130,"content":479},[480],"The honest weaknesses come before the comparison. Claude Code is fast-moving and configuration-heavy, the model behind it is not yours to tune, and the agent has shell access by design.",{"type":143,"ordered":144,"items":482},[483,489,491,493,495],[484,485,488],"A release a day means behaviour can change under a CI job. ",{"tag":155,"children":486},[487],"--bare"," exists to strip hooks, skills, commands, subagents, plugins, MCP servers, auto memory and CLAUDE.md for reproducible scripted runs, and it is the right default there.",[490],"Context is the scarce resource. Compaction drops the middle of the conversation, only five files are re-read afterwards, and skill bodies are truncated from the start — so the important instruction at the bottom of a long SKILL.md is the one that disappears.",[492],"Descriptions of model-invocable skills load on every request, so vague or overlapping descriptions make the model load the wrong skill or miss the useful one.",[494],"Subscriptions meter in time windows, not dollars. One heavy morning can exhaust the session limit with a week of allowance still unused, and only API billing offers a hard ceiling.",[496],"It is closed. Anthropic's models are the product; only the terminal CLI, VS Code and JetBrains accept a third-party provider, and agent features are not portable to another harness.",{"type":219,"head":498,"rows":506},[499,501,502,504],[500],"Option",[224],[503],"Entry price",[505],"Main trade-off",[507,515,523,532],[508,509,511,513],[352],[510],"Terminal agent, the application itself",[512],"$20 a month on Pro",[514],"Highest ceiling for repository-scale work, largest configuration surface",[516,518,520,521],[517],"Cursor",[519],"Editor fork with an agent mode",[512],[522],"Better diff and inline ergonomics, but the agent lives inside the editor",[524,526,528,530],[525],"GitHub Copilot",[527],"IDE extension, completions plus agent",[529],"$10 a month on Pro",[531],"Cheapest entry point, least autonomy of the four",[533,535,537,539],[534],"Codex CLI",[536],"Terminal agent on OpenAI models",[538],"Bundled with ChatGPT plans",[540],"A different model family, without the Claude-specific harness features",{"type":130,"content":542},[543],"The short version: for long-running, repository-scale work the terminal harness wins on capability; for line-by-line work an editor-native agent on a cheaper seat is the better buy. Running both is a defensible $30 a month, and most teams who end up there describe it as in-editor work for the small changes and the terminal for everything that spans a repository.",{"type":137,"level":138,"id":123,"text":124},{"type":130,"content":546},[547],"Claude Code is worth adopting on one condition: the team writes the guardrails down and puts them in version control. Without a committed settings file, a PreToolUse hook on the protected paths and an explicit decision about unattended runs, the tool is faster than a reviewer and less careful than one.",{"type":143,"ordered":549,"items":550},true,[551,553,555,557,559],[552],"Adopt it when the work is repository-scale: migrations, refactors, multi-file changes that end in a verification step.",[554],"Adopt it when the budget can carry one seat for a heavy user and one for a light user — the windows, not the seats, are the binding constraint.",[556],"Adopt the permission and hook model seriously. It is the only difference between an agent and a supervised agent.",[558],"Do not make it the only tool. Keep an editor-native completion product if most of the day is writing lines rather than changing systems.",[560,561,564],"Do not run it unattended on a machine you care about without a container, and never with ",{"tag":155,"children":562},[563],"--dangerously-skip-permissions"," outside one.",{"type":566,"content":567},"quote",[568],"Permission rules are enforced by Claude Code, not by the model. Instructions in your prompt or CLAUDE.md shape what Claude tries to do, but they do not change what Claude Code allows.",{"type":137,"level":138,"id":126,"text":127},{"type":143,"ordered":549,"items":571},[572,576,579,582,585,588,591,594,597,600,603],[573],{"tag":574,"href":36,"children":575},"a",[35],[577],{"tag":574,"href":39,"children":578},[38],[580],{"tag":574,"href":42,"children":581},[41],[583],{"tag":574,"href":45,"children":584},[44],[586],{"tag":574,"href":48,"children":587},[47],[589],{"tag":574,"href":51,"children":590},[50],[592],{"tag":574,"href":54,"children":593},[53],[595],{"tag":574,"href":57,"children":596},[56],[598],{"tag":574,"href":60,"children":599},[59],[601],{"tag":574,"href":63,"children":602},[62],[604],{"tag":574,"href":66,"children":605},[65],[607,669,717,783],{"slug":608,"published":609,"minutes":610,"category":7,"tags":611,"keywords":615,"about":622,"sources":624,"cover":661,"og":662,"expertise":69,"locales":663,"lang":71,"title":664,"description":665,"coverAlt":666,"url":627,"pricing":667,"kind":668},"mcp-reference-servers","2026-09-25",9,[12,612,613,614],"Reference servers","Tool protocol","Server SDKs",[616,617,618,619,620,621],"mcp reference servers","modelcontextprotocol servers github","write an mcp server","mcp server examples","mcp server sdk","mcp server security",[623],{"name":28,"url":29},[625,628,631,634,637,640,643,646,649,652,655,658],{"title":626,"url":627},"MCP reference servers repository","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers",{"title":629,"url":630},"Repository README and server list","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FREADME.md",{"title":632,"url":633},"Security policy","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FSECURITY.md",{"title":635,"url":636},"Release process and trusted publishing","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FRELEASING.md",{"title":638,"url":639},"Filesystem server README","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002Fsrc\u002Ffilesystem\u002FREADME.md",{"title":641,"url":642},"Everything server feature list","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002Fsrc\u002Feverything\u002Fdocs\u002Ffeatures.md",{"title":644,"url":645},"MCP Registry","https:\u002F\u002Fregistry.modelcontextprotocol.io\u002F",{"title":647,"url":648},"Archived reference servers","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers-archived",{"title":650,"url":651},"Model Context Protocol documentation","https:\u002F\u002Fmodelcontextprotocol.io\u002F",{"title":653,"url":654},"TypeScript MCP SDK","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Ftypescript-sdk",{"title":656,"url":657},"Python MCP SDK","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fpython-sdk",{"title":659,"url":660},"FastMCP on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Ffastmcp\u002F","\u002Fimages\u002Fblog\u002Fmcp-reference-servers\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fmcp-reference-servers\u002Fog.jpg",[71,72,73],"MCP reference servers: what they demonstrate and what they omit","A review of modelcontextprotocol\u002Fservers: seven reference servers, what each one teaches, the SDK versions behind them and why none of them should reach production.","Seven reference servers fanning out from a single MCP client over stdio","MIT","Protocol tooling",{"slug":670,"published":671,"minutes":6,"category":7,"tags":672,"keywords":677,"about":685,"sources":692,"cover":709,"og":710,"expertise":69,"locales":711,"lang":71,"title":712,"description":713,"coverAlt":714,"url":715,"pricing":716,"kind":79},"aider","2026-09-23",[79,673,674,675,676],"Terminal","Git workflow","BYO key","Open source",[670,678,679,680,681,682,683,684],"aider vs claude code","aider polyglot benchmark","ai pair programming terminal","aider leaderboard","open source coding agent","aider architect mode","aider install",[686,689],{"name":687,"url":688},"Aider","https:\u002F\u002Faider.chat\u002F",{"name":690,"url":691},"Aider on GitHub","https:\u002F\u002Fgithub.com\u002FAider-AI\u002Faider",[693,695,698,701,704,706],{"title":694,"url":688},"Aider website",{"title":696,"url":697},"Aider LLM leaderboards","https:\u002F\u002Faider.chat\u002Fdocs\u002Fleaderboards\u002F",{"title":699,"url":700},"Aider linting and testing","https:\u002F\u002Faider.chat\u002Fdocs\u002Fusage\u002Flint-test.html",{"title":702,"url":703},"Aider token limits","https:\u002F\u002Faider.chat\u002Fdocs\u002Ftroubleshooting\u002Ftoken-limits.html",{"title":705,"url":691},"Aider repository on GitHub",{"title":707,"url":708},"aider-chat on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Faider-chat\u002F","\u002Fimages\u002Fblog\u002Faider\u002Fcover.webp","\u002Fimages\u002Fblog\u002Faider\u002Fog.jpg",[71,72,73],"Aider review: git-first pair programming in the terminal","A review of Aider 0.86.2, an Apache-2.0 terminal pair programmer whose benchmark ranks models honestly and whose release cadence has stopped.","Cover art for the Aider review: a terminal session turning a single request into a row of git commits","https:\u002F\u002Faider.chat","Free · BYO API key",{"slug":718,"published":719,"minutes":6,"category":7,"tags":720,"keywords":725,"about":734,"sources":744,"cover":775,"og":776,"expertise":69,"locales":777,"lang":71,"title":778,"description":779,"coverAlt":780,"url":747,"pricing":781,"kind":782},"openai-agents-sdk","2026-09-11",[721,722,723,12,724],"Agent runtime","Tracing","Guardrails","Python",[726,727,728,729,730,731,732,733],"openai agents sdk","openai agents sdk vs langgraph","python agent framework comparison","openai agents sdk guardrails","agent run tracing tool calls","openai agents sdk human in the loop","openai-agents pypi","agents sdk vs responses api",[735,738,741],{"name":736,"url":737},"Model context protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_context_protocol",{"name":739,"url":740},"Software framework","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSoftware_framework",{"name":742,"url":743},"Agentic AI","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FAgentic_AI",[745,748,751,754,757,760,763,766,769,772],{"title":746,"url":747},"OpenAI Agents SDK documentation: Intro, and Agents SDK or Responses API","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002F",{"title":749,"url":750},"OpenAI Agents SDK documentation: Running agents","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Frunning_agents\u002F",{"title":752,"url":753},"OpenAI Agents SDK documentation: Guardrails","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fguardrails\u002F",{"title":755,"url":756},"OpenAI Agents SDK documentation: Human-in-the-loop","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fhuman_in_the_loop\u002F",{"title":758,"url":759},"OpenAI Agents SDK documentation: Tracing","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Ftracing\u002F",{"title":761,"url":762},"OpenAI Agents SDK documentation: Configuration","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fconfig\u002F",{"title":764,"url":765},"openai-agents 0.23.1 on PyPI, release history and licence","https:\u002F\u002Fpypi.org\u002Fproject\u002Fopenai-agents\u002F",{"title":767,"url":768},"OpenAI: The next evolution of the Agents SDK (15 April 2026)","https:\u002F\u002Fopenai.com\u002Findex\u002Fthe-next-evolution-of-the-agents-sdk\u002F",{"title":770,"url":771},"OpenAI API documentation: Agents, comparison of the three runtimes","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents",{"title":773,"url":774},"Arize: AI agent frameworks compared (1 October 2026)","https:\u002F\u002Farize.com\u002Fai-agents\u002Fagent-frameworks\u002F","\u002Fimages\u002Fblog\u002Fopenai-agents-sdk\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenai-agents-sdk\u002Fog.jpg",[71,72,73],"OpenAI Agents SDK: a small agent runtime with sharp edges","A review of the OpenAI Agents SDK: the runner loop, tracing, guardrails and approvals, plus what the release churn and the Responses-only features cost.","Diagram of the Agents SDK runner loop: input, agent, model call, final output, guardrails, and tool calls feeding back into the input","MIT · API pay per token","Agent framework",{"slug":784,"published":785,"minutes":610,"category":7,"tags":786,"keywords":791,"about":798,"sources":808,"cover":829,"og":830,"expertise":69,"locales":831,"lang":71,"title":832,"description":833,"coverAlt":834,"url":835,"pricing":836,"kind":79},"openhands","2026-09-09",[79,787,788,789,790],"Sandboxed execution","Automations","Self-hosted","MIT licence",[784,792,793,794,795,796,682,797],"openhands self-host","open hands coding agent","openhands vs claude code","agent canvas","openhands docker sandbox","openhands cloud pricing",[799,802,805],{"name":800,"url":801},"OpenHands","https:\u002F\u002Fwww.openhands.dev",{"name":803,"url":804},"OpenHands on GitHub","https:\u002F\u002Fgithub.com\u002FOpenHands\u002FOpenHands",{"name":806,"url":807},"Intelligent agent","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FIntelligent_agent",[809,811,814,817,820,823,826],{"title":810,"url":804},"OpenHands README",{"title":812,"url":813},"OpenHands licence (MIT)","https:\u002F\u002Fgithub.com\u002FOpenHands\u002FOpenHands\u002Fblob\u002Fmain\u002FLICENSE",{"title":815,"url":816},"Agent Canvas 1.25.0 release notes","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Fagent-canvas\u002Frelease-notes\u002Fv1.25.0.md",{"title":818,"url":819},"OpenHands sandbox overview","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Fsandboxes\u002Foverview.md",{"title":821,"url":822},"OpenHands quick start","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Finstallation",{"title":824,"url":825},"OpenHands pricing","https:\u002F\u002Fwww.openhands.dev\u002Fpricing",{"title":827,"url":828},"Introducing the OpenHands Index","https:\u002F\u002Fwww.openhands.dev\u002Fblog\u002Fintroducing-the-openhands-index","\u002Fimages\u002Fblog\u002Fopenhands\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenhands\u002Fog.jpg",[71,72,73],"OpenHands: the open-source coding agent you operate","OpenHands 1.25.0 is an MIT-licensed coding agent platform with a web canvas, a CLI, sandboxed execution and scheduled automations. A review of where it is strong and where it gets heavy.","Cover artwork for the OpenHands review showing a loop from task to agent to sandboxed run and back","https:\u002F\u002Fgithub.com\u002FAll-Hands-AI\u002FOpenHands","Free · self-host",1791383548782]