Section 38 of 45 5 min read

Claude and Claude Code

Claude and Claude Code on the same five questions: configuration surface, caching model, pricing, delegation and tools, and controls worth setting.

Objective

Cover Anthropic’s surfaces at the level of detail needed to configure them well.

38.1 Configuration Surface #

MechanismLocationLoads
Project instructionsCLAUDE.md (repo root, nested supported)Every turn
User instructions~/.claude/CLAUDE.mdEvery turn
Imports@path/to/file.md inside CLAUDE.mdEvery turn, inlined
Skills.claude/skills/<name>/SKILL.mdMetadata always; body on demand
Subagents.claude/agents/<name>.md (frontmatter: name, description, tools, model, optional isolation)On delegation
Hooks.claude/settings.json → hooksOn matching event
MCP servers.mcp.json or settingsSchemas every turn, or on discovery with defer_loading
PluginsSettings; versioned bundlesPer bundle contents

The @import mechanism is the distinctive piece, and it is what makes AGENTS.md interoperation clean:

<!-- CLAUDE.md -->
@AGENTS.md
@docs/architecture-constraints.md

<!-- Claude Code specific below -->
- Prefer `rg` over `grep`. It is installed.

Imports are inlined at load time, so an imported file is prefix on every turn exactly as if it were pasted in. The token discipline in §15.5 applies to the transitive closure, not just the root file.

38.2 Caching Model #

This is the richest explicit control of any provider, and the mechanics are covered in full in Sections 22 and 23. The Claude-specific summary:

  • Two modes. Automatic—a single top-level cache_control field, breakpoint moves forward as the conversation grows, best for multi-turn. Explicit—cache_control on individual blocks, for sections that change at different rates.12
  • Up to four breakpoints. Automatic caching consumes one slot.
  • 5-minute TTL by default, refreshed free on every hit; 1-hour available at 2× write.
  • Reads at 0.1× base input, with two documented exceptions: 0.025× on Fable 5.1 and Mythos 5.1, and 0.05× on Opus 5.5, where $0.20 per million reads against $4 base input is the rate the pricing table gives. 5-minute writes at 1.25×; 1-hour writes at 2×.12
  • Minimum cacheable prefix is model-dependent: 512 tokens on Opus 5 and Fable 5.1, 1,024 on Sonnet 5 and Opus 4.8, 4,096 on Haiku 4.5 and Opus 4.6.12
  • Pre-warming via max_tokens: 0 (§22.6).
  • Cache diagnostics beta reports exactly where two consecutive prefixes diverged.

Claude Code places breakpoints on your behalf. The developer’s job is therefore not to configure caching but to avoid breaking it.

A Claude-specific mid-conversation escape hatch: on Fable 5.1, Mythos 5.1, Fable 5, Mythos 5, Opus 4.8, and Opus 5, you can append a {"role": "system"} message inside messages to add an instruction partway through a conversation without invalidating the system or message caches, instead of editing the top-level system field, which does invalidate.12 This is not available on Sonnet 5.

38.3 Pricing #

Verified September 8, 2026:12,26

ModelBase input5m write1h writeCache readOutput
Claude Fable 5.1$10.00$12.50$20.00$0.25$50.00
Claude Opus 5$5.00$6.25$10.00$0.50$25.00
Claude Sonnet 5$2.00$2.50$4.00$0.20$10.00
Claude Sonnet 4.6$3.00$3.75$6.00$0.30$15.00
Claude Haiku 4.5$1.00$1.25$2.00$0.10$5.00

Per million tokens. Batch API applies a 50 percent discount and stacks with caching. No context-length surcharge on the current generation, including at 1M context—a real differentiator against providers with a threshold cliff (§21.3).

38.4 Delegation and Tools #

Subagents get their own context window and only the final message returns—fresh and empty by default, or inheriting the parent conversation and its warm cache when forked (§18.2). The tools frontmatter key is the actual permission boundary and omitting it grants everything (§18.5).

For MCP, defer_loading on a toolset keeps schemas out of the cached prefix until needed:

tools = [{"type": "mcp_toolset", "mcp_server_name": "github",
          "default_config": {"defer_loading": True}}]

Place cache_control on the mcp_toolset entry itself rather than on an individual tool—you do not control tool order within a toolset, and the API applies the breakpoint to the final expanded tool.70

38.5 The Control Surface #

  • Hooks in .claude/settings.json—the deterministic layer (§19).
  • Permission modes—plan mode for read-only exploration is the cheapest safety measure available.
  • Sandboxing—the runtime is open-sourced, which makes the isolation claims verifiable rather than asserted.
  • Enterprise managed settings—the policy floor, with one qualification to settle before you rely on it as an absolute. Settings merge across five layers, from user through project, project-local, and CLI flags, with the managed enterprise file last, and for scalar values and deny rules a lower layer cannot relax it.48 List-valued keys are the exception: Claude Code merges lists across scopes so that each file can add entries, which means an allow-list or exclusion array—sandbox allowed domains and paths, excludedCommands, permissions.allow—takes additions from lower scopes rather than being capped by the managed value. That widens access without overriding anything, and where it matters, allowManagedPermissionRulesOnly is the documented control that closes it for permission rules. This is still where a hook belongs if it must survive contact with a repository an agent can edit (§19.3).
  • Checkout isolation for subagents—isolation: "worktree" spawns a delegated agent inside its own git worktree, and Claude Code then refuses edits targeting the main checkout, commands whose working directory resolves there, git redirected there via -C, --git-dir, GIT_DIR/GIT_WORK_TREE or a cd, and commands whose text it cannot verify stay inside the worktree.48 Read that as what it is, and note the tool scope: the working-directory check covers Bash, PowerShell and Monitor commands, while the git-redirect and command-shape checks are documented for Bash and Monitor—PowerShell gets the working-directory check alone.48 Within that scope, parallel sessions are kept out of each other’s way in the main checkout. It is not an OS filesystem sandbox—writes elsewhere on disk are not its subject, and the worktree still shares the repository’s .git directory. Sandboxing and the permission system are the separate controls for confinement, and they compose with this rather than being replaced by it.

38.6 What Is Distinctive #

The explicit cache control goes further than any competitor’s, which is why Claude is the easiest platform on which to build a high-hit-rate agentic system. The import mechanism solves the multi-file instruction problem cleanly. The remaining friction is that which instruction file loads is now conditional rather than fixed: AGENTS.md is read natively from v2.1.277, but only where no CLAUDE.md or CLAUDE.local.md is present at or above the working directory, with a /config setting to change that and a provider restriction that applied before v2.1.281 and no longer does (§15.2).48 The one-line import makes the answer the same everywhere, which is why it stays in the file.

References cited in this section

4 of 81 · numbering matches the PDF

  1. 12Anthropic, "Prompt Caching," Claude Platform documentation verified September 8, 2026. Vendor documentation; cited as product fact for mechanism, pricing multipliers, minimum cacheable lengths, invalidation behavior, the 20-block lookback window, pre-warming, and data retention. The pricing table in this reference is the primary source for all Anthropic rates quoted in this document.platform.claude.com/docs/en/build-with-claude/prompt-caching ↗
  2. 26Anthropic model pricing, published in the pricing table of reference 12 and verified September 8, 2026. Source for all Claude per-model rates: Fable 5.1 $10/$50, Opus 5 $5/$25, Sonnet 5 $2/$10, Sonnet 4.6 $3/$15, Haiku 4.5 $1/$5 per MTok, with cache multipliers of 1.25× (5m write), 2× (1h write), and 0.1× read (0.025× on Fable 5.1 and Mythos 5.1).platform.claude.com/docs/en/about-claude/pricing ↗
  3. 70Anthropic, "Tool use with prompt caching," Claude Platform documentation Vendor documentation; cited as product fact for defer_loading, breakpoint placement on mcp_toolset entries, and the automatic 5-minute breakpoint applied to server tool results.platform.claude.com/docs/en/agents-and-tools/tool-use/tool-use-with-prompt-caching ↗
  4. 48Claude Code documentation (settings, hooks, sub-agents, and skills references), verified September 11, 2026, cross-checked against an independently compiled feature and settings snapshot at https://hidekazu-konishi.com/entry/claude_code_features_settings_reference_2026.html. Vendor documentation plus a third-party catalog that links each row back to the official docs. Cited for the settings precedence tree (user, project, project-local, CLI flags, enterprise managed, in ascending precedence, with the managed layer a floor that CLI flags cannot relax for scalar values and deny rules—list-valued keys such as permissions.allow and the sandbox allow and exclusion arrays merge across scopes instead, so lower scopes can add entries and widen access, which allowManagedPermissionRulesOnly exists to prevent for permission rules), the hook event catalog including PostCompact and its auto/manual matcher, the hook exit-code semantics, subagent frontmatter fields and isolation: "worktree", and the documented routing of subagent permission prompts—foreground subagents pass prompts through to the user, background subagents surface them in the main session naming the asking subagent, and auto-denial is a permission-mode behavior rather than a property of delegation. An earlier revision of this entry asserted that subagents cannot raise interactive prompts at all, so approval-required calls always resolve as denials; that was wrong, and §18.5 was corrected before this entry was. The same revision compressed the exit-code semantics to "0 allow, 1 allow with warning, 2 deny," which conflates the handler's process status with the event's decision, and the hook printed in §19.2 is the counterexample: it emits a permissionDecision of deny and exits 0. Exit 0 means the handler succeeded and Claude Code reads the decision from stdout JSON—silence is not approval, it is merely no decision, and the call continues through the normal permission flow. Exit 1 is a non-blocking error that Claude Code proceeds past, not a warning-flavored allow. Exit 2 blocks, but which events can block is event-specific: PreToolUse and UserPromptSubmit block, while PermissionRequest, PostToolUse, Notification, SessionStart and others do not honor it. Read the per-event table rather than a three-value mapping. Also cited, against the memory page and the v2.1.277 release notes of September 18, 2026, for native AGENTS.md loading and its conditions: by default Claude reads AGENTS.md only where no CLAUDE.md, .claude/CLAUDE.md or CLAUDE.local.md sits in the working directory or above it, while a user-level CLAUDE.md, a managed one and .claude/rules/ files do not count against it; a Project instructions setting in /config selects other modes, including loading both; and nested and subdirectory files load on access. The provider limitation this entry previously recorded as current is now version-scoped: the memory page places it before v2.1.281, published September 23, 2026, and directs affected Bedrock users to update rather than describing an ongoing platform gap. The verification date in this entry was accurate when made; this is a product change after it, not a correction to it. The conditions that remain current are an installation before v2.1.277, a disabled agents-md plugin, and in some cases the first session after an upgrade. An earlier revision of this document said Claude Code simply does not read AGENTS.md and presented the import line as a universal requirement; §15.2, §38.6, §43.1 and Appendix D were corrected together. The third-party snapshot is dated May 2026 and its model-name rows are consequently stale against the lineup in reference 12; the mechanism rows cited here were re-checked against the current official pages.docs.claude.com/en/docs/claude-code ↗
PDF↓