The permission prompt arrives mid-session and the honest answer is: by default, only you. What publishing actually does, when a link becomes public, and where Anthropic's own pages disagree — on which plans have it, and on whether a public link needs a Claude sign-in. Checked against their docs on 12 September 2026, sign-in rechecked 19 September 2026.
You're in the middle of a session. Claude Code has built something worth looking at — an annotated diff, a dashboard, a timeline that has been filling in while a long task runs — and a prompt appears asking to publish it as an artifact.
The hesitation is reasonable, and it comes from a real place: in the chat-artifact world, "publish" has meant "put this behind a link anyone can open." If that were true here, publishing a page built from your codebase would be an alarming thing to click past.
It isn't true here. Worth knowing before the next prompt.
Anthropic's Claude Code documentation is explicit: a new artifact is visible only to you. To share it, you open the artifact in your browser and use the Share control in the page header.
So the prompt in your terminal is asking permission to create a page at a URL on claude.ai that you can open. Nobody else gets it by default. The decision that actually exposes the page to another human happens later, deliberately, in a different place.
That also means the prompt is a smaller decision than it feels like — though not a zero one, which is the next section.
From Anthropic's documentation, read on 12 September 2026:
| Within your organisation | Publicly | |
|---|---|---|
| Pro / Max | not available | the only sharing route |
| Team / Enterprise | specific people, or everyone in the org — viewers sign in to claude.ai | off until an organisation Owner enables it |
An organisation link needs a sign-in — viewers sign in as members of your organisation. Whether a public link does is the one place the two Anthropic pages now split, covered below.
The row worth pausing on is the first one. On Pro and Max there is no middle setting: the page is yours alone, or it is on the open internet. If what you wanted was "just this one client, nobody else," that option isn't on this surface.
Anthropic's docs describe how attribution behaves, and it is worth reading before you send a public link to a client.
On an artifact shared within your organisation, your name is in the title menu. On a public artifact, your name is in the page header — but only for signed-in viewers who are in your organisation. Someone who opens that public link without signing in, or from outside your organisation, sees this instead:
Content is user-generated and unverified.
Which is the correct and responsible thing for a platform to show about an arbitrary user-generated page. It is also, from a client's side, the opposite of what you wanted a deliverable to say.
For the client-facing case: drop the HTML somewhere the page is yours — an unguessable link, an optional password, an expiry, and your own name on it rather than an unverified-content label. Free to try, no signup.
Being straight about this rather than picking the one that reads better:
/login."Both read on 12 September 2026. We are not going to guess which one is current or which supersedes which — it's their product and their documentation, and either page could be the one that's been updated. Open the feature in your own account and see. That takes a minute and gives you an answer that is true for you, which neither page can.
Rechecked on 19 September 2026, the two pages give opposite answers:
This one matters more for a client than the plan list does, because if the second page is right, your client lands on a sign-up screen. The tiebreaker is quick: copy the public link, open it in a private browser window where you are not signed in, and see what loads.
This is a good general habit with any fast-moving product: when two of the vendor's own pages disagree, your account is the tiebreaker, not the internet.
The question underneath is what the page is for.
It's for you or your team. Let it publish. That is what artifacts are built for, and the part that makes them genuinely good — the page updates in place as the session continues, so a long-running investigation has somewhere to accumulate instead of scrolling past in the terminal. Nothing leaves your account until you share it.
It's a deliverable for someone outside your organisation. Think for a second longer. On Pro and Max the only way out is a fully public link, and that link presents to your client as unattributed user-generated content. Neither of those is wrong — they're just not what a client deliverable usually wants.
For that second case, a lot of people would rather hand over something they control: a link that isn't guessable and isn't indexed, with a password if it's sensitive and an expiry if it shouldn't outlive the project. Same page, different set of promises attached to it.
If you're weighing this more broadly, where to put HTML that Claude Code generated covers the wider set of options, and what happens when the sandbox goes away covers the failure mode that catches people who leave the output where the agent made it.
You sent a client the public link to a Claude Code artifact and asked them to mark up what to change. There's nowhere to comment. That's by design. Here's the rule, which plans it leaves without a comment option for outside viewers, and how to collect pinned notes anyway. Checked against Anthropic's docs on 15 September 2026.
A disabled Publish button isn't one bug — it's four different situations wearing the same grey. Two of them are permanent, two clear in a minute. Here's how to tell which one you're looking at, and how to get the page to the person waiting for it either way.
You sent a Claude Slides deck with 'anyone with the link' and your client got a sign-up screen. Why that happens, what Docs, Slides and Design actually export, and how to get the work in front of someone who will never make a Claude account.
miinideck turns a single HTML file into an unguessable link with optional password and expiry. Default-private, never indexed.