Developer Tools & APIs

Claude Code mods let developers rewrite the agent from the inside out

Anthropic's new mods system lets developers write TypeScript functions that hook into Claude Code's pipeline, add UI, and replace built-in features.

developer tools apis category

On 1 October 2026, Anthropic shipped mods for Claude Code, a plugin system that lets developers write small TypeScript functions and inject them directly into the agent’s request pipeline. You can rewrite prompts before Claude sees them, intercept tool calls, render custom UI, register new commands, or replace built-in features entirely. The /diff panel now ships as a mod itself, meaning you can disable or swap it out the same way you would any third-party extension.

This landed in Claude Code 2.1.287 and is enabled by default.

What a mod actually is

A mod is a Claude Code plugin whose behaviour lives in a TypeScript or JavaScript module. The folder follows the standard plugin layout, with a .claude-plugin/plugin.json manifest and a hooks/hooks.json file pointing to your module. Inside that module, you export a single register(on, options) function, and inside that you attach handlers to events.

The events you can hook include tool.call, prompt.submit, turn.start, turn.complete, session.start, command.run, and ui.render. Each handler receives the event, a continuation function to pass control to the next hook in the chain, and a $ capability object for side effects such as reading session data, running processes, or drawing UI panels.

When several mods hook the same event, they run in load order. The first mod loaded sees the event first and receives the final result last, which is the same middleware pattern you’d recognise from Express or similar frameworks. That composability is deliberate: you can stack mods from different authors and they work together without coordination.

Each time Claude Code loads a mod, it writes fresh TypeScript type declarations into the mod’s .claude-plugin/types/ folder, so your editor has accurate types for the exact version you’re running.

What you can build

Anthropic published three reference mods that show the range of what’s possible.

Token Weather reads session usage after each turn and renders a status line above the prompt showing context percentage, token count, a 12-turn sparkline, and the delta since the previous turn. The whole thing is around 80 lines of code.

Blast Radius intercepts Bash tool calls, classifies commands like rm -rf and git reset --hard as destructive, runs a dry-run check, then opens a side pane with Proceed and Cancel controls before anything executes.

Replay Theater records every file edit Claude makes in a turn and registers a /replay command that steps through those diffs one at a time in a docked pane.

The community moved quickly after launch. Demos appeared within days covering secret redaction on hover, inline Mermaid diagram rendering, and custom diff panes. You can browse what’s been shared at claudemod.com and the Claude.dev mods showcase.

You can also ask Claude Code to write a mod for you. The tool can author the TypeScript, install the plugin, and hot-reload it in the same session, which is a fast way to prototype something specific to your workflow.

What this means for enterprise teams

For developers, the practical wins are immediate: you get instrumentation, safety gates, and workflow tools that previously required waiting for Anthropic to ship them, or patching around the tool with external scripts.

For teams and organisations, the implications are broader. On Team and Enterprise plans, a built-in mod called sec-default loads first and blocks risky behaviour such as overriding permission-deny rules. Administrators can load their own mods ahead of third-party ones, which gives platform teams a hook for enforcing standards across every developer session. The highest-value enterprise use cases flagged in early analysis are secret redaction from prompts, quality gates on sensitive code paths, and context routing that loads team-specific instructions based on the current directory.

Administrators on managed deployments can also allow or block the public plugin marketplace, which matters for organisations that need to govern what code runs in their developer environments.

The security question you should be asking

Mods are not sandboxed. They run with the same permissions as Claude Code itself, which means the same access to your file system, your shell, and your network. A mod that intercepts prompt.submit can read or modify everything you type before Claude sees it. A mod that hooks tool.call sits between Claude and every action it takes.

Anthropic is clear about this in the documentation: install mods only from sources you trust, the same way you would evaluate any code you run on your machine. The sec-default enterprise mod addresses some of this by letting administrators cap what downstream mods can do. Because every capability flows through the $ object, an admin mod loaded first can remove methods before any subsequent plugin runs.

The security community has noted that this is a new supply-chain surface that enterprise security teams need to get ahead of before developers start pulling from a public directory without review. That is a fair read. The same composability that makes mods powerful also means a compromised or malicious mod in the load chain has significant reach.

How to get started

Mods are available in both the Claude Code CLI and the desktop app from version 2.1.287 onwards. Install a plugin that includes mods from the Claude directory or by running /plugin in the CLI. The official mods overview and reference docs cover the full API. To share a mod, package it as a plugin and submit it to the directory.

If you want to see the design before writing any code, four built-in mods ship in the public Claude Code repository: the AGENTS.md loader, the diff panel, telemetry, and the organisation security mod. Reading those is probably the fastest way to understand how the system fits together.