A Claude Code mod is a small piece of code that runs inside Claude Code and gets a say every time something happens: Claude is about to run a tool, you send a prompt, the screen is drawn. It can watch, change, or stop that thing. You do not have to write it yourself: you can ask Claude to make one in plain words. Here is what that means in practice, what people use mods for, and the simplest one you can build today.
A mod in one sentence
A mod is a plugin with a few functions that Claude Code calls when an event happens, and each function can let the event pass, change it, or answer it itself.1
Anthropic added mods in Claude Code v2.1.287 on October 1, 2026, and they are on by default.6 During early access the same thing was called function hooks. You will see both names online.
Think of Claude Code as a road and a mod as a checkpoint you put on it. Every tool call, every prompt, every redraw of the screen drives past your checkpoint. Most of the time the checkpoint waves it through. Sometimes it adds a note, changes the cargo, or says no.
What it looks like in practice
On disk, a mod is a folder with three small files: a plugin.json with its name, a hooks/hooks.json that points at your code, and the code file itself, called the hooks module.1 Claude Code loads .js and .ts files directly, so there is no build step and no Node.js setup.2
Inside the code file you write one function, register, and in it you say which events you care about. Every handler gets three things: $, the toolbox for doing things in Claude Code (draw, show a message, run a command); e, the event itself, such as the tool name and its arguments; and next, which means "carry on as usual".2
That is the whole model. Call next(e) and nothing changes. Call next with a changed event and you rewrite what happens. Return your own answer without calling next and the normal behavior never runs.3
Anthropic's own first example is a good picture of how small this can be: about twenty lines that count Claude's tool calls and show the count next to the spinner, as in "Thinking · tool calls: 3".1
What you can do with one
Real examples, all from Anthropic's docs and sample mods:
- Stop a risky command and say why. A mod can refuse a
git push --forceand give Claude a sentence it reads instead, such as "push to a new branch instead".3 - Ask you before something risky runs. The sample mod
blast-radiusholds a command likerm -rfor a force push, shows what it would change, and gives you buttons to proceed or cancel.7 - Draw something new on screen. The sample
token-weatherdraws a forecast of your context window above the prompt.7 Mods can open a pane next to the transcript, with tabs, buttons and text fields.1 - Add a command that runs instantly. The sample
replay-theateradds/replay, which steps through the file edits Claude made in the last turn.7 A mod command runs your code at once, with no Claude turn, even while Claude is busy.1 - Add context Claude reads. A mod can add a line only Claude sees, such as the current git branch whenever your prompt mentions a pull request.3
- Tell you when Claude is done, and what it did. A mod sees when a turn ends, including Claude's final answer, so a notification can say what happened instead of just "done".3 Ours is open source: session-pings on GitHub.
Some of Claude Code itself is now built as mods. /diff is a built-in mod, and so is AGENTS.md support. There is also an optional built-in called cc-plugin-you-should-know, which runs a side agent that watches longer tasks and shows a note above the prompt when it spots something you might miss.1
Mods vs CLAUDE.md, plugins, skills, hooks and MCP
Claude Code now has a lot of ways to customize it, and they overlap. In plain words:
| Thing | What it is | Use it when |
|---|---|---|
| Prompt or CLAUDE.md | Text Claude reads as instructions. Guidance, not a lock. | You want to tell Claude how you like things done |
| Skill | A SKILL.md file of instructions Claude loads when relevant | You keep pasting the same instructions into chat |
| MCP server | An outside program or service that gives Claude new tools | Claude needs to reach an outside system, like your logs or database |
| Settings hook | A script in settings.json that runs on an event. It can block a tool call with a reason or change its arguments. | You want to block, allow or log something with a script you already have |
| Mod | Functions that run inside Claude Code on every event | You want a pane, a band, an instant command, memory across calls, or to rewrite an event |
| Plugin | The package. One plugin can hold skills, MCP servers, settings hooks and a mod. | You want to share any of the above |
Two notes to keep this fair. First, settings hooks are not weak: a PreToolUse hook can already refuse a tool call and give Claude the reason, and it can change the call's input.4 If you have one that works, keep it. What a mod adds is that it runs inside Claude Code: it can draw, keep data from one call to the next, call a model, add instant commands, and change what Claude Code shows.1 Second, a mod is not a replacement for a skill or an MCP server. A plugin can ship all three together.1
The difference that matters most is between the first row and the mod row. A rule in CLAUDE.md is something Claude reads and usually follows. A rule in a mod is code that every tool call passes through, so Claude cannot skip it.
The simplest mod: ask Claude for it
The easiest way to make a mod is to describe it. Claude Code ships a built-in skill called plugin-authoring that tells Claude where to write a mod and which events your version has. Claude can load it on its own when you ask for a mod, or you can run /plugin-authoring yourself.2
Here is what happens, step by step:2
- Claude writes the mod into a folder for this session:
~/.claude/dev-mods/plus the session ID, plus the mod's name. In the default permission mode you approve each file, because~/.claudeis a protected path. - When the first file is saved, Claude Code asks: "Enable hot reloading for this session?" Pick Enable for this session.
- The mod loads when Claude's turn ends. Run
/pluginand check the Installed tab to see it. - Try it. If it is not right, say what to change. It reloads at the end of each turn that edits it.
A mod written this way lives only in that session, and its folder is cleaned up later. To keep it, copy the folder somewhere of your own, such as ~/mods/protect-env, and start Claude Code with claude --plugin-dir ~/mods/protect-env.2
And here is the whole mod from the prompt above. It is one rule: Claude may not edit or write a .env file. When it tries, the edit does not happen, and Claude reads a short instruction instead, so it can carry on and tell you what to change.
We built this exact folder and ran Claude Code's own checks on it. claude plugin validate reads the code the way Claude Code will and lists what it hooks and what it calls. claude plugin test runs a small test with no session at all. Both passed on v2.1.287 (the warning is only that the manifest has no author field).
The pattern is the same as the force push example in Anthropic's docs: return { deny } with a sentence Claude can act on, and call next(e) for everything else.3 Note what this mod does not catch: a shell command like echo X > .env goes through Bash, not Edit or Write. A guard only sees what you point it at.
Turning mods on and off, and the one safety note
Mods need Claude Code v2.1.287 or later. Run claude --version to check.1 To turn them off, pick how much:1
- One mod: disable or uninstall its plugin in
/plugin, on the Installed tab. - All installed mods, for one session: start with
claude --safe-mode. - All installed mods, everywhere: set
"disableAllHooks": truein~/.claude/settings.json. This also stops your settings hooks and custom status line.
If your company manages Claude Code, an admin can also allow only the company's own mods with a setting called allowManagedModsOnly.5
The safety note: mods are not sandboxed. A mod runs with your permissions. It can read and write your files, start programs, make network requests, read your environment variables and API keys, see every prompt and tool call, and spend your usage on model calls.1 So install mods only from people you trust, and before you install one, run claude plugin validate on its folder. The hooks: and calls: lines tell you what it listens to and what it can do.1
Why bother: rules that always hold
Panes and games are fun, and that is where most early mods are. But the most useful thing a mod gives you is simpler: a rule that holds every time.
Today, most people's rules live in CLAUDE.md: "never touch production", "don't edit .env", "ask before you delete". Claude follows them most of the time. Most of the time is the problem. A mod turns the rule into code that every tool call passes through. And a good guard does not end the session. It blocks the one action and tells Claude why, so Claude finds another way to get you the result.
It is an extra layer, not a guarantee. It sits on top of Claude Code's own permission system, it only sees what passes through the events you hook, pattern matching can miss things, and --safe-mode turns it off. But for "this must never happen" rules, it is a much better place than a sentence in a prompt. We go deeper in rules Claude Code cannot ignore.
Next reads
- Guardrails as a mod: rules Claude cannot ignore, and why a prompt rule is not enough
- Notifications as a mod: your hook pings you, a mod tells you why
- Redact sensitive data: keep secrets and personal data out of the session
- Database guard: stop destructive database actions and keep Claude read-only on production
One more thing a session cannot see on its own is what your app is doing in production. Fixter is monitoring for teams that build with coding agents: you send your logs and traces over standard OpenTelemetry, and Fixter finds the issues and bugs in your system and tells you what broke and why. You pull them straight into Claude Code over MCP and fix them there.
Key takeaways
- A mod is a plugin with functions that run inside Claude Code on each event and can pass, change or answer it
- Mods shipped in v2.1.287 on October 1, 2026, and are on by default
- You can ask Claude to write one; approve hot reloading and it loads when the turn ends
- Mods are not sandboxed: install only what you trust, and check it with claude plugin validate
- The best everyday use is a rule that must always hold, enforced in code instead of a prompt
Frequently asked questions
What is a Claude Code mod?
A mod is a small plugin with a few JavaScript or TypeScript functions that run inside Claude Code. Claude Code calls them when something happens, such as Claude being about to use a tool, you sending a prompt, or part of the screen being drawn. Each function can watch the event, change it, or answer it itself. Mods arrived in Claude Code v2.1.287 on October 1, 2026, and are on by default.
Do I need to know how to code to make a mod?
Not really. You can describe the mod in a normal Claude Code session, for example "make a mod that stops you from editing .env files", and Claude writes it with its built-in plugin-authoring skill. Claude Code then asks whether to enable hot reloading for the session, and once you say yes the mod loads. Reading the short code it writes is still a good idea, because a mod runs with your permissions.
What is the difference between a mod and a settings hook?
A settings hook is a script you list in settings.json that runs on an event, such as PreToolUse or Stop. It can already block a tool call with a reason, change a tool call's arguments, and add context. A mod is a function that runs inside Claude Code, so it can also draw panes and bands, add slash commands that run instantly, keep data between calls, call a model, and change what Claude Code itself draws.
Are Claude Code mods safe?
A mod is not sandboxed. It runs with your permissions, so it can read and write your files, start programs, make network requests, read environment variables, and see every prompt and tool call. Install mods only from authors you trust. Before you install one, run claude plugin validate on its folder to list which events it handles and what it calls.
How do I turn mods off?
To stop one mod, disable or uninstall its plugin from the Installed tab in /plugin. To run one session without any installed mods, start Claude Code with --safe-mode. To stop every mod you installed in every session, set disableAllHooks to true in ~/.claude/settings.json, which also stops your settings hooks and custom status line.
Sources
- Claude Code docs, Mods overview (what a mod is, what it can reach, built-in mods, turning mods off, comparison with settings hooks, skills and MCP)
- Claude Code docs, Create a mod (asking Claude, the dev-mods folder, hot reloading, --plugin-dir, validate and test)
- Claude Code docs, React to events with a mod (observe, rewrite or answer; deny a tool call; prompts and turns)
- Claude Code docs, Hooks reference (PreToolUse can deny a tool call with a reason and update its input)
- Claude Code docs, Manage mods for your organization (allowManagedModsOnly and the built-in guard)
- Claude Code release v2.1.287, October 1, 2026 (adds Claude Mods)
- Anthropic, sample mods in claude-code-playground (token-weather, blast-radius, replay-theater)