Add a path-specific Read deny rule to the applicable Claude Code settings file to block reads of a project’s root .env through the permission system. The rule is narrow, but Anthropic describes its coverage of other built-in readers as best effort—not an absolute guarantee against every way of accessing the file.
Configure a deny rule for the project’s root .env
In the Claude Code settings JSON that applies to your project, add this entry under permissions.deny:
As an Amazon Associate I earn from qualifying purchases.
{
"permissions": {
"deny": [
"Read(./.env)"
]
}
}
This targets a file named .env at the project root. If the settings file already contains a permissions object or deny array, merge the entry into the existing structure rather than replacing unrelated settings. Anthropic documents permission rules using the form Tool(optional-specifier). Anthropic’s permission rules and settings documentation explains the syntax and matching behavior.
Make sure the pattern matches your project layout
Read and Edit path patterns use gitignore-style matching relative to the directory containing the settings file. That means the same text can target a different location—or fail to target the intended file—if you put the settings in a different directory. Check both where the settings file lives and where the secret file lives.
#1 Best Overall
Read(./.env)is the documented-style project-relative pattern for a root-level.env, when the settings location corresponds to that project.- If your secret is in a subdirectory, or you use a different settings location, adjust the pattern to match that layout. Do not assume a root-level pattern covers every file named
.envelsewhere. - Anthropic also documents home-relative rules and
//as the prefix for an absolute path. Use those forms only when the intended file is outside the settings file’s relevant project-relative location.
Check the effective permissions
- Start Claude Code in the project where the rule should apply.
- Run
/permissionsto inspect and manage the effective tool permission rules. Confirm that theRead(./.env)deny entry appears and that the settings source is the one you intended. - If the rule is missing or not behaving as expected, check the settings file’s location and the path pattern, then inspect the effective rules again.
Claude Code settings can come from multiple layers. Anthropic says deny rules take precedence over allow rules, and enterprise managed settings take precedence over user and project settings. A project-level entry therefore should not be treated as overriding a higher-priority managed configuration. The IAM documentation describes the settings layers and precedence.
Understand what a Read deny rule does—and does not—guarantee
Anthropic says it makes a best effort to apply Read permission rules to built-in file-reading tools, including Grep, Glob, and LS. “Best effort” matters: this is not documented as a guarantee that every possible route to file contents is blocked. The documentation cited here does not establish that a Read rule governs shell commands, external programs, or every third-party integration.
Rank #2
For that reason, treat this as an application permission control, not an operating-system security boundary. If you need to prevent access at the file-system level, use operating-system access controls appropriate to your environment; the Claude Code rule alone is not evidence that such access is impossible.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhen to use –disallowedTools
The CLI reference also documents --disallowedTools, which can disallow tools in addition to settings.json rules. That flag is tool-oriented: it does not replace a path-specific Read deny rule when the goal is to target one file such as .env. See Anthropic’s CLI reference for the flag.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




