At a glance
Claude Corner tip- Claude Code v2.1.285 and later can turn off the WebFetch tool with
CLAUDE_CODE_DISABLE_WEB_FETCH=1, and the WebSearch tool stays available. - The npm
stablechannel already includes that floor, so you do not needlatestjust to drop page fetch from a session. - A domain allow rule and the sibling deadline or cache variables do not remove the tool, and Bash
curlis still a separate network path.
WebFetch is on unless you turn it off. The tools reference describes it as the tool that fetches a URL and, when the server returns HTML, converts the response to Markdown. In Manual and acceptEdits modes it prompts before a fetch unless a WebFetch(domain:...) rule already allows or denies that domain, and preapproved documentation domains can fetch without a prompt. On a compliance machine, a CI runner, or any repo where the session should not pull live pages, that default is the wrong shape.
Why it matters
A domain allow rule does not remove WebFetch. It only decides which hosts a still-present tool may call. The separate kill switch shipped in v2.1.285 on 29 September 2026, and the environment variables page says to set CLAUDE_CODE_DISABLE_WEB_FETCH to 1 to turn the tool off while WebSearch stays available. WebSearch is a different tool: it runs a search and returns titles and URLs, so turning off page fetch does not turn off search. On the morning of 5 October 2026, npm stable was still v2.1.285 while latest and next were v2.1.289, so anything added after v2.1.285 is not on a stable install, but this switch is. You do not need a managed deny rule just to drop the fetch tool from the session.
How to turn WebFetch off
This tip is for the Claude Code CLI. The environment variables page documents CLAUDE_CODE_DISABLE_WEB_FETCH for Claude Code and does not name Claude Desktop. Desktop docs say a settings.json env block can reach Claude sessions on that machine, but they do not name this variable, so do not assume the Desktop app turns WebFetch off the same way.
- Run
claude --versionand confirm it prints v2.1.285 or later. If the line is older, install thestabletag and check again. Installinglatestalso has the variable, but it is not required for this tip. - Put the variable in the user settings
envblock so Claude Code reads it no matter howclaudewas launched. The documented value is1. If the file already has anenvobject, add this key beside the existing keys and do not replace the whole object. For one terminal only, you can insteadexport CLAUDE_CODE_DISABLE_WEB_FETCH=1and runclaudein that shell.
- Quit any session that was already open, then start a new one. The environment variables page says a running session applies new
envvalues when you save the file, except for a feature that reads its variables once at startup. A sibling WebFetch variable,CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS, is documented as read once per launch. The page does not say the kill switch hot-reloads the tool list, so treat a freshclaudeprocess as required. - In the new session, ask Claude to fetch one specific public URL with the WebFetch tool and to say whether that tool is available. It should not be able to call WebFetch. Then ask it to search the web for the same page title. WebSearch should still be available.
- If WebFetch still runs, confirm three things:
claude --versionis v2.1.285 or later, the settings value is the string1, and the session is a new process started after the file was saved. A resumed session from before the variable was set is not the check.
Do not combine this with CLAUDE_CODE_WEBFETCH_DEADLINE_MS or CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS. Those tune a WebFetch that is still on (deadline default 300000 ms, cache default 900000 ms). They do nothing useful once the tool is off. We did not run a signed-in WebFetch or WebSearch check against a live session, so treat step 4 as a test of your own.
Gotchas
- Disabling WebFetch does not stop Claude from reaching the network through Bash, for example
curl, so a compliance machine still needs Bash permission rules if shell fetches are out of bounds. - An organization policy can also withhold WebFetch for Team and Enterprise sessions. This tip does not name that policy key, and it does not replace it.
- VS Code and JetBrains surfaces are not claimed here. Confirm the variable on the CLI first.
Recommended AI prompt
Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever AI you use.
I use Claude Code v2.1.285 or later and want WebFetch off while WebSearch stays on. Explain how to set CLAUDE_CODE_DISABLE_WEB_FETCH to 1 under the env key in ~/.claude/settings.json, or with a one-shell export, without changing other keys and without setting CLAUDE_CODE_WEBFETCH_DEADLINE_MS or CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS. Give me a two-minute restart-and-verify checklist that confirms WebFetch is unavailable and WebSearch still works, note that this is documented for Claude Code rather than Claude Desktop, and remind me that Bash curl is a separate path. Do not invent flags or settings. Ask for the output of claude --version if you are unsure which version I have.
Sources
Go deeper in Grok
Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).
Article: Claude Code v2.1.285 Can Disable WebFetch Without Disabling WebSearch
Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.