-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Expand file tree
/
Copy pathfeed.xml
More file actions
1792 lines (1792 loc) · 288 KB
/
Copy pathfeed.xml
File metadata and controls
1792 lines (1792 loc) · 288 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<id>https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md</id>
<title>Claude Code Changelog</title>
<subtitle>Release notes for Claude Code</subtitle>
<author><name>Anthropic</name></author>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md"/>
<link rel="self" type="application/atom+xml" href="https://raw.githubusercontent.com/anthropics/claude-code/main/feed.xml"/>
<updated>2026-10-05T23:32:55Z</updated>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.290</id>
<title>Claude Code v2.1.290</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.290"/>
<updated>2026-10-05T23:32:55Z</updated>
<content type="html"><p>• Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end</p>
<p>• Added agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's</p>
<p>• Added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool</p>
<p>• Added ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name</p>
<p>• Added to claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)</p>
<p>• Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds</p>
<p>• Added claude attach &lt;name&gt; and claude logs &lt;name&gt;: part of a session name works in place of the id</p>
<p>• Added /claude-api managed-agents-onboard &lt;url&gt; to set up the Managed Agents pattern a page describes as ant apply files</p>
<p>• Added /claude-api managed-agents-onboard &lt;quickstart-name&gt; to build a Console quickstart template, such as deep-researcher, with the ant CLI</p>
<p>• Added a warning when a managed settings file is a link to a file outside the managed settings folder</p>
<p>• Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains</p>
<p>• Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta</p>
<p>• Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors</p>
<p>• Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown</p>
<p>• Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run</p>
<p>• Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an offset to read on</p>
<p>• Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep</p>
<p>• Fixed /rewind not listing a prompt sent while Claude was still working</p>
<p>• Fixed scheduled tasks (/loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on</p>
<p>• Fixed scheduled tasks set in the foreground never firing after a ← or /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork</p>
<p>• Fixed headless --json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered</p>
<p>• Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy</p>
<p>• Fixed a project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule</p>
<p>• Fixed URL allow and deny patterns with a wildcard inside an xn-- host label matching differently from one process to the next</p>
<p>• Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions</p>
<p>• Fixed /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved</p>
<p>• Fixed the plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux</p>
<p>• Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in</p>
<p>• Fixed the background daemon's log passing terminal control characters to the screen under claude daemon run and claude daemon logs; they now show as \uXXXX escapes</p>
<p>• Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds</p>
<p>• Fixed a plugin hook with a .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call</p>
<p>• Fixed a mod's turn.step result listing a tool call that a mid-response model fallback had discarded</p>
<p>• Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file</p>
<p>• Fixed claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions</p>
<p>• Fixed /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration</p>
<p>• Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings</p>
<p>• Windows: Fixed multi-line ! shell blocks in skills and commands failing when the file is saved with CRLF line endings</p>
<p>• Fixed Claude Code hanging until killed when a /permissions tab was clicked while searching in fullscreen mode</p>
<p>• Fixed conversation compaction sometimes failing with a "null is not an object" error</p>
<p>• Fixed plugin hooks reading an empty answer on turn.complete for a subagent that hands its report back in auto mode</p>
<p>• Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded</p>
<p>• Fixed a mod's prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name</p>
<p>• Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing</p>
<p>• Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read</p>
<p>• Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded</p>
<p>• Fixed disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents</p>
<p>• Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing</p>
<p>• Fixed an @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed mid-read</p>
<p>• Fixed Esc in the agents view confirming "Press enter again to restart this session — it isn't responding"; Esc now just reopens the session</p>
<p>• Fixed agent view losing a background session's /loop run count, countdown and live status line after the session enters a worktree that it creates</p>
<p>• Fixed claude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt</p>
<p>• Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on declare, typeset, export or readonly</p>
<p>• Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder</p>
<p>• Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded</p>
<p>• Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters</p>
<p>• Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted</p>
<p>• Fixed You should know writing its notes in English regardless of the language setting</p>
<p>• Fixed a freeze after sending some very long messages</p>
<p>• Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing</p>
<p>• Fixed claude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation</p>
<p>• Fixed Esc after an n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section</p>
<p>• Fixed claude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted</p>
<p>• Fixed /ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver</p>
<p>• Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore</p>
<p>• Fixed claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why</p>
<p>• Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt</p>
<p>• Fixed agent view's /loop run count freezing and its countdown disappearing after /clear; the count now restarts with the new conversation</p>
<p>• Fixed --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt</p>
<p>• Fixed /chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135)</p>
<p>• Fixed mods staying off for people who reach Claude through a gateway (ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account</p>
<p>• Fixed replies sent from claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts</p>
<p>• Fixed slash commands and answers to a multiple-choice question that claude agents could not deliver to a running session being saved and sent by themselves the next time it was restarted</p>
<p>• Fixed sandboxed commands that pipe a heredoc into another command (cat &lt;&lt;EOF | python3) asking for approval on every run</p>
<p>• Fixed claude agents failing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one)</p>
<p>• Fixed agent view's "restart this session fresh" re-sending an earlier message from the session instead of starting with an empty conversation</p>
<p>• Fixed Bash permission checks auto-approving some read-only commands (such as rg or git grep) whose arguments the shell would still expand as wildcards; these now prompt for approval</p>
<p>• Fixed claude plugin test refusing to run after an upgrade because of an out-of-date saved setting</p>
<p>• Fixed Bash permission checks auto-approving certain commands whose variable names zsh reads differently from bash; these now prompt for approval</p>
<p>• Fixed a short form of a git clone option keeping the sandbox exemption from a git pattern such as git * in sandbox.excludedCommands; it is now treated like the long form</p>
<p>• Fixed the first feature-flag request of a session ignoring a proxy or API endpoint set in a project's settings</p>
<p>• Fixed /ultrareview of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside .git (git 2.54+); it now refuses with an explanation</p>
<p>• Fixed cloud sessions staying asleep after a container restart lost a pending /loop wakeup or scheduled task; Claude is now told and can schedule it again</p>
<p>• Fixed the Claude apps gateway's retention sweep deleting a returning developer's identity row refreshed at the same moment, on PostgreSQL versions without the November 2025 fixes</p>
<p>• Fixed sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules</p>
<p>• Fixed the Claude apps gateway failing to start when the certificate it presents to the identity provider has an empty subject</p>
<p>• Fixed the Claude apps gateway exiting with a bare "Invalid URL" when store.postgres_url can't be parsed; the error now names the setting and says what the URL may hold</p>
<p>• Fixed background agents failing with "Agent stalled" and Workflow tool subagents restarting from their prompt when a Mac woke from sleep</p>
<p>• Fixed slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL)</p>
<p>• Fixed a response interrupted by computer sleep being treated as a stalled stream on Bedrock, Vertex, Foundry, and custom gateways</p>
<p>• Fixed a freeze before the first request and in the /sandbox Config tab on Linux and WSL when a sandbox read rule such as ~/**/.env covers a large folder</p>
<p>• Fixed skills not being found when asked for by the name in SKILL.md when their folder has a different name (for example a non-English name): the skill listing now shows both names</p>
<p>• Fixed a plan written in plan mode being lost when a cloud session's container restarted before the plan was presented</p>
<p>• Fixed the Bash tool occasionally losing shell aliases, functions and plugin PATH entries for a whole session when its first command ran seconds after startup on a new config directory</p>
<p>• Fixed unbounded memory use when an HTTP MCP server sends a very large response</p>
<p>• Fixed artifact operations failing in a Claude Code run started from inside a cloud session (for example claude -p run from the Bash tool)</p>
<p>• Fixed files sent from remote sessions sometimes being refused as "not the one approved" when four or more were sent at once</p>
<p>• Fixed plan mode not being restored when resuming a session with --continue or --resume &lt;session-id&gt; in the terminal</p>
<p>• Fixed a marketplace named after another GitHub marketplace's download folder stopping that marketplace from downloading</p>
<p>• Fixed automatic compaction giving up with "Prompt is too long" when a Mac went to sleep while it was running</p>
<p>• Fixed the rewind menu (Esc Esc / /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file</p>
<p>• Fixed a subdirectory's AGENTS.md not being attached when a file under it is @-mentioned</p>
<p>• Fixed self-hosted runner sessions resumed after a stopped runner failing with "missing but already registered worktree" when the sessions folder is a relative symlink</p>
<p>• Fixed a freeze when the secret scan or a permission prompt met long token-like text</p>
<p>• Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands</p>
<p>• Fixed CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to dialogExpiry</p>
<p>• Fixed a stall when an MCP server's tool listing contains very long runs of combining characters</p>
<p>• Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block</p>
<p>• Fixed Claude in Chrome's browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog's list going stale after a switch</p>
<p>• Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree</p>
<p>• Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login</p>
<p>• Fixed --restricted (and CLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket</p>
<p>• Fixed sessions moved to the background while idle reopening as "no saved transcript" after a restart or idle cleanup; they now resume their conversation</p>
<p>• Fixed background workers honoring --allow-dangerously-skip-permissions on respawn without the bypass-permissions disclaimer having been accepted</p>
<p>• Fixed Claude replying in an endless loop when a plugin's async Stop hook passes an unquoted script path under a folder with a space, such as Application Support</p>
<p>• Fixed a freeze of several seconds when secret masking met very long unbroken text</p>
<p>• Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input</p>
<p>• Fixed first launch asking to pick a login method again after claude auth login or with a credentials file already in the config directory</p>
<p>• Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts</p>
<p>• Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do</p>
<p>• Fixed macOS /login reporting success when the keychain refused the new login and kept an old one it could not remove</p>
<p>• Fixed SDK hosts using --include-partial-messages seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming</p>
<p>• Fixed sandboxed Bash commands on Linux running ConfigChange hooks and reloading settings mid-command when .claude/settings.json or .claude/settings.local.json does not exist</p>
<p>• Fixed errors reading "Premature close" instead of naming the missing program when a tool Claude Code runs, such as git or gh, is not installed (macOS, Linux)</p>
<p>• Fixed /loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after .claude/scheduled_tasks.json was deleted</p>
<p>• Fixed edits to the file a symlinked settings file points at running without the settings-file permission question</p>
<p>• Improved MCP startup behind a network proxy: a server the proxy blocks (HTTP 403) is no longer retried three times</p>
<p>• Improved permission prompts from background agents to show the Ctrl+X Ctrl+K shortcut that stops all background agents</p>
<p>• Improved the built-in plugin-authoring skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section</p>
<p>• Improved the reply to /plugin in the desktop app's Code tab: it now says where to install and manage plugins there</p>
<p>• Improved the Bash changed-files view: when a chained command includes git merge, pull or checkout, it lists the files without full diffs</p>
<p>• Improved the Claude apps gateway's log when an upstream's cloud credentials or connection fail: the warning now ends with the underlying cause</p>
<p>• Improved the error shown when a cloud session is started without a claude.ai sign-in: it now names claude auth login and /login and no longer blames API-key authentication</p>
<p>• Improved the Read tool's message for binary files: it now points Claude to a skill or a shell command that can read the format</p>
<p>• Improved the error shown when a git config file stops the /ultrareview upload: it is about half as long and says what kind of file is the problem</p>
<p>• Improved the errors shown when the /ultrareview upload refuses a checkout: each known cause now has its own message, with a way to fix it</p>
<p>• Improved the Claude apps gateway to log a warning during the last 30 days before the certificate it presents to the identity provider expires</p>
<p>• Improved Claude in Chrome: a browser_batch call now gets 90 seconds, up from 60, before it is reported as timed out</p>
<p>• Improved the Claude apps gateway's browser sign-in pages: brand fonts, centered layout, and dark mode</p>
<p>• Improved responsiveness while resuming large sessions: timers, input and rendering keep running while the transcript loads</p>
<p>• Improved the / and @ suggestion lists: the selected row now starts with a ❯ pointer, so you can see it without color</p>
<p>• Changed CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC to also skip the startup connection warm-up</p>
<p>• Changed Claude in Chrome so that a project's settings files can no longer turn it on; use --chrome, /chrome or your user settings</p>
<p>• Changed the Bash tool to ask for permission before running pyright, which is no longer treated as a read-only command</p>
<p>• Changed what a mod's $.process.spawn rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result</p>
<p>• Changed the background daemon's log to write a multi-line message as one JSON-quoted line</p>
<p>• Changed skills and custom commands to refuse a ! shell command that contains raw control characters other than tab and newline, with a message that shows where they are</p>
<p>• Changed /artifacts: opening an artifact in your browser now closes the list</p>
<p>• Changed Bash permission checks so that more forms of the ps command ask for approval instead of running without asking</p>
<p>• Changed plugin hooks so long text is clipped and logged instead of being refused or dropped silently</p>
<p>• Changed background sessions whose scheduled task is gone: they now move to Completed about 20 seconds later and can be updated or shut down when idle</p>
<p>• Changed the "Press ← again" confirm on a just-cleared prompt: a second ← no longer has to wait a second before it switches, and holding ← down now switches too</p>
<p>• Changed the errors shown when the /ultrareview upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text</p>
<p>• Changed /code-review at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5</p>
<p>• Changed an in-process teammate's agent_id in Agent results to its agent ID (its name@team address stays in teammate_id); TeammateIdle hooks no longer fire from its subagents or forks</p>
<p>• Changed background sessions waiting on a scheduled wakeup (/loop): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup</p>
<p>• Changed /model, /effort and /rename sent from claude agents to a busy background session to apply right away, without a confirmation, instead of when the turn ends</p>
<p>• Changed the Claude apps gateway's minimum supported PostgreSQL version from 14 to 11</p>
<p>• Changed the interactive session's WebSearch budget to refill over time (100 calls/hour; CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR sets the rate, 0 turns it off) instead of ending after 200 calls</p>
<p>• Changed CLAUDE_CODE_DISABLE_ATTACHMENTS so a repository's .claude/settings.json or .claude/settings.local.json can no longer set it; shell, user and managed settings still can</p>
<p>• Changed claude plugin update on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins</p>
<p>• Changed the built-in gh api in cloud sessions: a host other than github.com set in GH_HOST or GH_REPO is now refused (use --hostname or a full URL), and stderr notes requests to other hosts</p>
<p>• Changed the claude-api skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the auto permission policy</p>
<p>• Self-hosted runners: Changed claude --environment &lt;id&gt; to create its session through the current Sessions API; printed and JSON session ids keep their session_… form</p>
<p>• [VSCode] Added a screen reader announcement, "Message queued.", when you send a message while Claude is working</p>
<p>• [VSCode] Added a way to review and run a plugin marketplace's install or update command from the Manage plugins dialog</p>
<p>• [VSCode] Fixed a blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place</p>
<p>• [VSCode] Fixed settings dialogs blaming a timeout when Claude Code stopped unexpectedly during a save</p>
<p>• [VSCode] Fixed the branch switch dialog offering to switch when it could not check for uncommitted changes</p>
<p>• [VSCode] Fixed a permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it</p>
<p>• [VSCode] Fixed sign-in and new sessions giving no clear reason when Claude Code cannot find or start its program</p>
<p>• [VSCode] Fixed the agent map showing a nested sub-agent with "Tool calls (0)" and placing the agents it starts under the main agent</p>
<p>• [VSCode] Improved Continue After Reload: tabs reopened after VS Code restarts its extensions now also finish a step the restart interrupted</p>
<p>• [VSCode] Improved file pills in messages: hovering one now shows the file's path from the project folder, so same-named files can be told apart</p>
<p>• [VSCode] Changed message timestamps to show by default (turn them off with the Claude Code: Show Message Timestamps setting)</p>
<p>• [Cloud sessions] Fixed turning off prompt suggestions through a cloud environment's environment variables having no effect in new cloud sessions</p>
<p>• [Cloud sessions] Fixed the working indicator in a cloud session spinning on for several seconds after Claude's reply had finished; it now stops with the reply</p>
<p>• [Cloud sessions] Fixed History on a never-run routine's page still saying "No runs yet" after you pressed Run now; it now shows the new run</p>
<p>• [Cloud sessions] Fixed an unarchived cloud session looking as if Claude were still working until you sent another message</p>
<p>• [Remote Control] Fixed a computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds</p>
<p>• [Claude Tag] Added fast mode in Slack: mention Claude with !fast to switch a thread to fast mode, moving it to Opus if needed, and !fast off to switch back; replies show (fast) while it's on</p>
<p>• [Claude Tag] Added the optional Path prefixes field when creating a custom connection in an access bundle, so its allow rule can cover only those paths instead of the whole host</p>
<p>• [Claude Tag] Fixed members with the Claude Tag Admin permission getting "Couldn't load memory files" on the Activity page's Memory tab; they can now read workspace and channel memory</p>
<p>• [Claude Tag] Fixed a workspace guest's Confirm on a Claude settings card in Slack removing its buttons for everyone; only the guest sees the refusal, and members can still confirm or cancel</p>
<p>• [Claude Tag] Fixed scheduled routines in Slack channels running on a model other than the channel's default; each run that starts a new session now uses the current default model</p>
<p>• [Claude Tag] Fixed GitHub repositories in an access bundle attached by a channel-name rule being refused in the channels the rule covers; Claude can now add, list and clone them there</p>
<p>• [Claude Tag] Improved Claude's notice in your direct messages when your own Claude plan's usage limit is reached: it shows within seconds and says when the limit resets</p>
<p>• [Claude Tag] Improved the earlier Claude in Slack app's reply when it can't start a session: it now says what failed and who can fix it, in full only once per thread</p>
<p>• [Claude Tag] Changed the channel instructions limit to 8,192 characters instead of bytes, so non-English text gets the same room, and added a character count beside Save on the Configure page</p>
<p>• [Code Review] Fixed blocking review comments sometimes opening with a "nit" label that contradicted their severity</p>
<p>• [Code Review] Fixed tips to comment "@claude review" being posted on fork and Manual-mode pull requests in organizations that have turned Code Review off</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.289</id>
<title>Claude Code v2.1.289</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.289"/>
<updated>2026-10-03T23:06:56Z</updated>
<content type="html"><p>• Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines</p>
<p>• Fixed the terminal freezing on short code blocks with many unclosed &lt;script&gt; tags or deeply nested ${ substitutions</p>
<p>• Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink</p>
<p>• [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent</p>
<p>• Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width</p>
<p>• Fixed plugin list, plugin eval and plugin update showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir</p>
<p>• Fixed installed mods not loading in the first session after an upgrade</p>
<p>• Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen</p>
<p>• Fixed plugin panes drawing nothing when a link used a localhost address, an @ in its path, an uppercase host or a file: path</p>
<p>• Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools</p>
<p>• Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know</p>
<p>• Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously</p>
<p>• Fixed sessions ending with an interface error when a plugin region with no height kept growing</p>
<p>• Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands</p>
<p>• Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command</p>
<p>• Fixed claude plugin validate skipping the plugin when the folder also holds a marketplace manifest</p>
<p>• Added agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list()</p>
<p>• Fixed sessions ending with "unrecoverable interface error" when a value a mod's ui.render hook wrote made a row throw while drawn; the engine now draws its own row instead</p>
<p>• Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it</p>
<p>• Fixed right-aligned content in a mod's pane or band drawing under the close mark or [-], which now also keep one column in from the terminal's edge</p>
<p>• Fixed a mod's Client that fails while drawn taking down everything the mod drew around it; it now fails alone and raises ui.fault</p>
<p>• Fixed claude plugin validate failing an Anthropic marketplace's own plugin and listing a clean plugin.json in --json</p>
<p>• Fixed a mod's band that fails to draw briefly telling the cards under it to step aside</p>
<p>• Fixed a failed plugin component showing Error or nothing as its reason when the failure carried no message</p>
<p>• Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn</p>
<p>• Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed &lt;script&gt; tags</p>
<p>• Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.288</id>
<title>Claude Code v2.1.288</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.288"/>
<updated>2026-10-02T20:19:38Z</updated>
<content type="html"><p>• Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row</p>
<p>• Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal</p>
<p>• Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images</p>
<p>• Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call</p>
<p>• Added --max-findings &lt;n&gt;|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default</p>
<p>• Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json</p>
<p>• Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab</p>
<p>• Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried</p>
<p>• Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage</p>
<p>• Fixed --resume sometimes dropping files and other context that a compaction had just restored</p>
<p>• Fixed a resumed session sometimes not saving the last response of a turn, so that the next --resume showed the prompt unanswered</p>
<p>• Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load</p>
<p>• Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking</p>
<p>• Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off</p>
<p>• Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash</p>
<p>• Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent</p>
<p>• Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it</p>
<p>• Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes</p>
<p>• Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device</p>
<p>• Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted</p>
<p>• Fixed a plugin's pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code</p>
<p>• Fixed plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults</p>
<p>• Fixed a plugin's tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree</p>
<p>• Fixed git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)</p>
<p>• Fixed plugins loaded with --plugin-dir not showing "Configure options" in /plugin</p>
<p>• Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running</p>
<p>• Fixed sandboxed heredocs with an unquoted delimiter (python3 &lt;&lt;EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references</p>
<p>• Fixed Bash tool permission check to prompt before a BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently</p>
<p>• Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt</p>
<p>• Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn</p>
<p>• Fixed OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals</p>
<p>• Fixed permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event</p>
<p>• Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved</p>
<p>• Fixed unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts</p>
<p>• Fixed /login reporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (anthropics/claude-code#73861)</p>
<p>• Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request</p>
<p>• Fixed a second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in</p>
<p>• Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults</p>
<p>• Fixed headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it</p>
<p>• Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses</p>
<p>• Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed</p>
<p>• Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named memory</p>
<p>• Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with disableAutoMode or an older model); typing, navigation and JavaScript still ask</p>
<p>• Fixed claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice</p>
<p>• Fixed sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on</p>
<p>• Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings</p>
<p>• Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, /tui)</p>
<p>• Fixed a stall when launching an agent whose tools: lists very many Agent(...) entries</p>
<p>• Fixed sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation</p>
<p>• Fixed the npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder claude stub was installed</p>
<p>• Fixed Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process</p>
<p>• Fixed owner/repo plugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top</p>
<p>• Fixed path-scoped .claude/rules and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)</p>
<p>• Fixed a dangerous rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule (anthropics/claude-code#96300)</p>
<p>• Fixed LSP tool calls hanging indefinitely when a language server uses dynamic capability registration or stops responding; requests now time out after 60s (per-server requestTimeout)</p>
<p>• Fixed idle_prompt notification hooks firing while background agents are still running (anthropics/claude-code#93672)</p>
<p>• Fixed PreToolUse and PermissionRequest hooks being skipped when matching them failed or the tool's input could not be serialized to JSON; the call is now blocked</p>
<p>• Fixed the first request in a fresh environment or after a model switch using the built-in output limit and auto-compact window, not the server's; that request may now wait up to 1.5 seconds</p>
<p>• Fixed the "What should Claude do instead?" hint showing on the Interrupted row after sending queued messages with ctrl+enter</p>
<p>• Fixed /login in a --bare session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work</p>
<p>• Fixed the InstructionsLoaded hook omitting agent_id and agent_type when a subagent's file access loads a rule or nested CLAUDE.md; rules and nested CLAUDE.md files loaded on file access now also report effort</p>
<p>• Fixed the Agent tool in claude mcp serve always reporting no available agents and rejecting every subagent_type</p>
<p>• Fixed the terminal cursor not following the typed text in the fullscreen transcript viewer's search and in /theme's custom color search</p>
<p>• Fixed /permissions in screen reader mode: typing a rule's number now picks it instead of opening the search box</p>
<p>• Improved auto mode: when a conversation grows too long for the client-side safety classifier to review, it is now compacted instead of prompting for, or failing, every tool call</p>
<p>• Improved screen reader mode: short announcements, such as a deleted word, now stay on screen until your next key press or until something above them on screen changes</p>
<p>• Improved screen reader mode: answered questions in question dialogs now say "answered" beside their box</p>
<p>• Improved the /usage-credits message shown to Team and Enterprise members whose organization has turned off usage credit requests</p>
<p>• Improved cloud sessions: a new conversation's first turn no longer waits for a stdio MCP server whose config sets alwaysLoad: false</p>
<p>• Improved "You should know" notes to say "we", "the main agent" or "you" depending on who was responsible for a decision</p>
<p>• Improved the error for an artifact database write refused at the database's size limit: it now states the limit and what frees space</p>
<p>• Improved Bash permission prompts to give a shorter reason when part of a command can't be checked before it runs</p>
<p>• Self-hosted runner: Improved the built-in gh api: a refused gh command now prints its gh api equivalent, --paginate follows every page of a repository's lists, and a nested claude no longer removes it</p>
<p>• Improved Remote Control's recovery from an expired server credential: sessions stay connected during renewal and are kept if it gives up after a server outage</p>
<p>• Changed the background command time limit to apply only in unattended sessions (-p, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit</p>
<p>• Changed the client-side auto mode classifier to ignore an ANTHROPIC_DEFAULT_SONNET_MODEL pin that names Claude Sonnet 5.5 or Opus 5.5 and use Claude Sonnet 5 instead</p>
<p>• Changed claude project purge to claude purge; the old name still works and prints a notice</p>
<p>• Changed the agents view n: filter (and Ctrl+F search) so Enter opens the session whose name matches best instead of the top row</p>
<p>• Changed /autocompact to save the auto-compact window per model, so each model keeps its own setting when you switch</p>
<p>• Changed MCP URL prompts from servers that can't report when you're done to wait for "I'm done, continue" before the tool call continues, so you can finish in the browser first</p>
<p>• [VSCode] Fixed a claude.ai connector staying on "Needs authentication" after you authorize it: the MCP servers dialog now offers Check connection</p>
<p>• [VSCode] Fixed the opt-in New Conversation shortcut (Cmd/Ctrl+N) starting a conversation in every visible Claude view instead of only the one you are in</p>
<p>• [VSCode] Fixed the chat view resuming the next saved session after you archive the one it shows; it now starts a new conversation instead</p>
<p>• [Cloud sessions] Fixed the Cloud sessions switch in Claude Code admin settings staying locked off while an unrelated security setting was loading or had failed to load</p>
<p>• [Cloud sessions] Fixed pressing Stop while a self-hosted runner was still starting not cancelling the queued message, which could then run once the runner was up</p>
<p>• [Claude Tag] Fixed Claude Tag admin settings offering a "Remove this scope" option, which always failed, on channels whose settings were created automatically</p>
<p>• [Claude Tag] Improved Claude to also follow a related Slack thread in another channel that it only read, so updates there reach the conversation that depends on them</p>
<p>• [Claude Tag] Improved save errors on a channel's Configure page: too-long channel instructions now say to shorten them, and a save refused for lost access no longer says to try again</p>
<p>• Fixed claude plugin test reporting mods as turned off remotely when it had only read an out-of-date saved setting</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.287</id>
<title>Claude Code v2.1.287</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.287"/>
<updated>2026-10-01T17:59:57Z</updated>
<content type="html"><p>• Added Claude Mods: plugins may now modify deeper behavior</p>
<p>• Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin (for first-party sessions with telemetry on)</p>
<p>• Added an n:&lt;text&gt; filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match</p>
<p>• Added prompt_text to the OpenTelemetry user_prompt event, a copy of prompt for backends that nest dotted keys; drop or mask it wherever you drop or mask prompt (anthropics/claude-code#70763)</p>
<p>• Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry</p>
<p>• Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool</p>
<p>• Self-hosted runner: Added a built-in gh api (REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed</p>
<p>• Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it</p>
<p>• Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries</p>
<p>• Fixed hooks configured with asyncRewake waking Claude over and over with "found issues" notifications when the hook's script file is missing; the broken hook is now reported once</p>
<p>• Fixed tool heartbeats not reaching SDK hosts while the model's response stream was stalled with no data arriving</p>
<p>• Fixed Bedrock and Vertex startup model checks ignoring an enforced availableModels list, which could collapse /model to one Opus row</p>
<p>• Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached</p>
<p>• Fixed picking Fable in /model on a claude.ai login saving the current version's id, so your saved default now follows the newest Fable like Opus and Sonnet do</p>
<p>• Fixed switching between Opus 5.5 and Sonnet 5.5 (/model, opusplan) rewriting earlier MCP tool announcements, which could drop earlier extended thinking</p>
<p>• Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail's message when the reply began with thinking</p>
<p>• Fixed a dangerous rm (such as one on / or the home directory) losing its always-ask safeguard when the same command also redirected output to a ~ or wildcard path</p>
<p>• Fixed claude -p and SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running</p>
<p>• Fixed a folder's CLAUDE.md being attached a second time after resuming a session or after a compaction</p>
<p>• Fixed background sessions that could not be reopened from claude agents after the agent exited and removed the worktree the session was started in</p>
<p>• Fixed /advisor pairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped</p>
<p>• Fixed Bash permission prompts showing internal parser names such as "Contains simple_expansion" instead of a plain explanation</p>
<p>• Fixed a cause of fullscreen sessions on slow or busy machines exiting with "Claude Code exited after an unrecoverable interface error" while a scroll key was held in a long conversation</p>
<p>• Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named __proto__</p>
<p>• Fixed Claude being told to page large MCP results saved as JSON with Read's offset and limit, which cannot split one long line</p>
<p>• Fixed the commit attribution reminder being delivered inside a tool result after a compaction</p>
<p>• Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields</p>
<p>• Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional</p>
<p>• Fixed screen reader mode showing a "Tab to amend" hint on approval prompts, where Tab does nothing</p>
<p>• Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying "Select with numbers" in empty menus or while a search box has the keys</p>
<p>• Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs</p>
<p>• Fixed screen reader mode sending the claude --teleport progress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame</p>
<p>• Fixed CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS not removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject</p>
<p>• Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window</p>
<p>• Fixed --include-partial-messages sending a cut-short reply's message_stop late or never, so apps could show the reply as still in progress</p>
<p>• Fixed claude agents sometimes not showing the permission prompt a background session is waiting on</p>
<p>• Fixed /ultrareview giving advice about .git/info/attributes when the upload stops on a committed .gitattributes it cannot read, such as one saved as UTF-16</p>
<p>• Fixed claude remote-control failing to register behind an HTTP proxy with a misleading "Check your organization permissions" error (anthropics/claude-code#97352)</p>
<p>• Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable</p>
<p>• Fixed the running-tool dot and three spinners still moving with the "Reduce motion" setting on, and /rewind's confirm screen updating its "ago" time while you type a note</p>
<p>• Fixed times in claude agents changing every second in screen reader mode; they now change at most every 10 seconds</p>
<p>• Fixed a revoked claude.ai login showing a generic API Error: 401 instead of "OAuth token revoked"; in -p mode the error now starts with "Failed to authenticate"</p>
<p>• Fixed /ultrareview upload refusals advising you to copy a variable named by a repository's settings file into your own user settings</p>
<p>• Fixed --output-format stream-json and the SDK not streaming the turns of a context: fork skill run by typing /&lt;skill&gt; as the prompt, as they do for the Skill tool's fork</p>
<p>• Fixed /feedback and /bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report</p>
<p>• Fixed claude plugin marketplace add --sparse and git-subdir plugin installs failing with "transport 'http' not allowed" when the repository is served over plain http</p>
<p>• Fixed cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted</p>
<p>• Fixed a plugin reload that overlapped the startup --plugin-url download corrupting the session's cached copy of the plugin archive</p>
<p>• Fixed /desktop quoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause</p>
<p>• Fixed an MCP connector tool call occasionally running twice, or the connector's calls failing until restart, when its server changed which MCP protocol version it supports</p>
<p>• Fixed SessionStart hooks from synced plugins not running in new cloud sessions</p>
<p>• Fixed the transcript's "N hooks ran" summary and the verbose debug log's matched-hooks count including Claude Code's internal callbacks, so one configured hook no longer shows as two</p>
<p>• Fixed files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds</p>
<p>• Fixed repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory</p>
<p>• Fixed PNG, JPEG and WebP images over 8,000 pixels on a side failing to send from a remote session; Claude now sends a scaled-down copy</p>
<p>• Fixed messages sent from the Claude apps with 17 to 20 attached files delivering only the first 16</p>
<p>• Fixed headless sessions reporting an MCP server as needing authentication after one refused call, even though later calls succeed</p>
<p>• macOS: Fixed Remote Control sessions started with claude remote-control stopping mid-turn when the Mac went to idle sleep</p>
<p>• Windows: Fixed interactive claude hanging or crashing with "Raw mode is not supported" when its input is piped or redirected; it now says why and exits (use -p for piped input)</p>
<p>• Bedrock, Vertex, Mantle: Fixed model availability checks under CLAUDE_CODE_SKIP_*_AUTH sending a different Authorization header than real requests when ANTHROPIC_CUSTOM_HEADERS repeats it</p>
<p>• Improved /config: settings that cycle show ‹ › and step both ways with ←/→, narrow terminals stack each value under its label, and PgUp/PgDn page the list</p>
<p>• Improved plugin marketplace errors to say in plain words why a marketplace was ignored or refused, and what to do</p>
<p>• Improved plugin listings to note when a plugin's dependencies were not installed, and updating a plugin now retries an install that did not finish</p>
<p>• Improved the Claude apps gateway's error when Amazon Bedrock rejects a model ID: developers now see which model is unavailable, and the gateway log names the ID that was sent</p>
<p>• Improved SDK sessions so a message sent with priority "now" no longer cancels a running web fetch or web search; it keeps loading in the background</p>
<p>• Improved /memory: the left and right arrow keys now flip its on/off settings, such as Auto-memory</p>
<p>• Improved /skill names typed mid-message: Claude is now told they are skills, including disable-model-invocation ones</p>
<p>• Improved the contrast of the prompt input border in light themes and of the ❯ before your earlier messages</p>
<p>• Improved delivery of files Claude sends from cloud sessions and Remote Control: an upload that fails on a timeout, a network error or a 502, 503 or 504 is now retried once</p>
<p>• Improved what Claude says when a file cannot be sent for a reason that may be temporary: it now mentions that you can ask for the file again in a few minutes</p>
<p>• Improved the prompt for a held message from another session to show the message between dashed lines, matching other permission prompts</p>
<p>• Improved MCP and other tool permission prompts to show the tool call between dashed lines, matching file edit prompts</p>
<p>• Improved MCP startup in headless mode: a remote server whose first connect fails transiently is now retried without waiting for the slowest server to finish connecting</p>
<p>• Improved files Claude sends from a remote session: large files now stream from disk instead of being read into memory, and a file over the size limit is refused with the server's limit named</p>
<p>• Improved the explanation Claude gives when the server refuses a file it sends from a Remote Control or cloud session, such as an oversized image</p>
<p>• Improved handling of large MCP tool results: less memory, smaller session files, and no extra upload to count tokens for results far over the limit</p>
<p>• Windows: Improved Bash tool speed by removing a subshell that ran before every command</p>
<p>• Changed a shell write through a repo-committed symlink onto a sensitive file or out of the working tree to name where it lands and wait for a person, on lines with a ~ target too</p>
<p>• Changed Opus 4.7+ and Fable to use a 1M context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway, with no [1m] suffix (CLAUDE_CODE_DISABLE_1M_CONTEXT=1 keeps 200K)</p>
<p>• Changed replies from claude agents to arrive as queued messages; slash commands other than /stop sent while a turn is running now run when it ends</p>
<p>• Changed whole-tool Bash allow rules and allowing hooks to prompt for, not run, shell writes to files Claude Code's file tools refuse outright (the Anthropic profile store, the host credentials file)</p>
<p>• Changed right-click paste on Windows and Linux, and middle-click paste on Linux, to happen when the button is released; moving the pointer away before releasing cancels it</p>
<p>• Changed MCP server alwaysLoad: false to defer all of that server's tools behind tool search</p>
<p>• Changed screen reader mode to write new or changed lines without first pausing with the cursor at the start of the line; set CLAUDE_AX_PREPARK_MS=50 to restore the pause</p>
<p>• Changed automatic model switches after a flagged message to keep your current effort level instead of the new model's default</p>
<p>• Changed waiting permission prompts to show oldest first, so a new prompt no longer covers the one you're reading (prompts with a countdown still open on top)</p>
<p>• [VSCode] Added "Run in background" to a running command or sub-agent, to move it to the background and keep working</p>
<p>• [VSCode] Added the output of background shells and Monitors to their cards in the agent map</p>
<p>• [VSCode] Fixed settings dialogs blaming a timeout when Claude Code's reply was too large to confirm a save</p>
<p>• [VSCode] Fixed reopening a cloud session that the side bar already brought to this machine opening it again in a new tab; the side bar is shown instead</p>
<p>• [VSCode] Fixed the side bar's Web tab not listing cloud sessions started after the window loaded; a failed load now says "Remote server is not connected" instead of "No web sessions yet"</p>
<p>• [VSCode] Fixed a tab restored after a reload starting a second Claude process on a conversation the side bar already has open; it now shows the "still open somewhere else" notice</p>
<p>• [VSCode] Fixed tool-row file links, session-list links and two hints showing in plain text</p>
<p>• [VSCode] Fixed a background agent's still-running command showing as failed once the main turn ended</p>
<p>• [VSCode] Fixed a user's own /usage or /context command opening the extension's dialog instead of running when picked from the command menu</p>
<p>• [VSCode] Fixed file links in the plan preview tab doing nothing when clicked; they now open the file like links in chat replies</p>
<p>• [VSCode] Fixed opening a tool's input or output in an editor tab failing with "Timeout waiting after 1000ms" on remote hosts such as WSL when the tab is slow to appear</p>
<p>• [VSCode] Improved the Manage plugins dialog: a failed marketplace add, remove or refresh now says what went wrong</p>
<p>• [VSCode] Changed the Claude in Chrome "Enabled by default" switch to also connect the editor's own sessions, which still ask before browser actions</p>
<p>• [Cloud sessions] Fixed occasional failures to fetch from or push to GitHub when GitHub briefly refused a newly issued access token</p>
<p>• [Claude Tag] Fixed Claude posting a failure warning, such as a spend limit notice, in a Slack thread when a background event like GitHub activity woke it and nobody was waiting on a reply</p>
<p>• [Claude Tag] Fixed Claude Tag's spend limits page in admin settings leaving out recently created and private channels in organizations with many channels</p>
<p>• [Claude Tag] Improved Claude's task list in long Slack threads: background work no longer reposts it as a new message on its own, so people following the thread aren't notified</p>
<p>• [Code Review] Fixed finding comments and their "Why this was flagged" text stopping mid-sentence; they now end on a complete sentence</p>
<p>• [Code Review] Fixed Code Review skipping a pull request after a new push when its review had failed twice on the previous commit; it now reviews the latest commit</p>
<p>• [Code Review] Improved the failed-review card on a pull request whose conversation is locked: it now says the lock blocked the review and that nothing was posted or charged</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.286</id>
<title>Claude Code v2.1.286</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.286"/>
<updated>2026-09-30T19:09:53Z</updated>
<content type="html"><p>• Added a count such as "2 of 5" to the permission prompt when several permission requests stack up</p>
<p>• Added mouse support for the "N more" rows of lists in fullscreen mode: click one to jump to that end of the list, with hover and pressed states</p>
<p>• Fixed several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire</p>
<p>• Fixed claude --resume and --continue sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed</p>
<p>• Fixed API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions</p>
<p>• Fixed cloud sessions with very large histories never waking up because the container was stopped while the transcript was still loading</p>
<p>• Fixed the Claude apps gateway's spend meter pricing 1-hour prompt cache writes at the cheaper 5-minute rate, and counting only the first model call's input tokens on streamed turns that run a server-side tool such as web search</p>
<p>• Fixed macOS sessions still showing "Not logged in" or "Login expired" after /login succeeds in another Claude Code window when a leftover ~/.claude/.credentials.json exists</p>
<p>• Fixed every turn failing when the Anthropic API refuses the model your default or a model alias resolves to: Claude Code now retries once on the previous model of the same tier</p>
<p>• Fixed Remote Control sessions (including claude remote-control) staying connected after your organization's policy turns Remote Control off; they now disconnect with a notice</p>
<p>• Fixed refusal and --fallback-model retries failing when the fallback model can't run fast; they now run at standard speed, with a one-time notice in interactive sessions</p>
<p>• Fixed headless sessions repeating the "MCP servers require authentication" reminder after a successful re-authentication when the MCP discovery cache is enabled</p>
<p>• Fixed claude auth status reporting a Console sign-in's stored API key as claude.ai; it now reports api_key, and the VS Code extension treats that session as an API key session</p>
<p>• Fixed /status listing an Anthropic profile beside an API key as if both were in effect; the profile is now marked as not in use</p>
<p>• Fixed Claude not being told when a file attached to a message sent over Remote Control did not arrive, and a file sometimes getting only 10 seconds for its last download try</p>
<p>• Fixed a Remote Control message that arrived while Claude Code was exiting being marked delivered and then never answered; it now stays queued for the session's next run</p>
<p>• Fixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name</p>
<p>• Fixed percent-encoded Bearer tokens being only partly masked in error messages</p>
<p>• Fixed redacted logs and transcripts showing a secret whose key name has an invisible character inside, such as a zero-width space</p>
<p>• Fixed logs and transcripts showing part of a URL password that contains punctuation such as ), quotes, ], &amp; or a second @, or that runs past a / to a bracketed host such as [::1] in an ssh URL</p>
<p>• Fixed the session transcript in the zip that /feedback saves to disk containing invalid JSON lines after secret redaction</p>
<p>• Fixed MCP connectors listing no tools for up to a day after their server dropped the older MCP handshake</p>
<p>• Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working</p>
<p>• Fixed /usage not crediting an MCP server for a tool call made while that server was still connecting or had only just connected, such as right after a restart</p>
<p>• Fixed plugins enabled on claude.ai occasionally going missing from Claude Code for a session after a transient server error</p>
<p>• Fixed a message typed into a running subagent showing twice in its transcript after the subagent read it</p>
<p>• Fixed subagent hand-back messages showing a raw task id instead of the agent's name when the subagent had no registered name</p>
<p>• Fixed foreground subagents sometimes missing the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions that have them enabled</p>
<p>• Fixed subagents spawned with worktree isolation loading the project CLAUDE.md and its imports a second time from the worktree copy on their first file read</p>
<p>• Fixed Workflow tool subagents being restarted from their original prompt when a connection stalled for a few minutes mid-response</p>
<p>• Fixed /compact, /clear, and /rewind typed while viewing a background agent's or teammate's transcript silently acting on the main conversation: a dialog now names the target and asks first</p>
<p>• Fixed background jobs showing done while waiting for your approval</p>
<p>• Fixed the commit attribution reminder being re-sent inside tool output when a model fallback lasts only one turn</p>
<p>• Fixed a click on the space between words of a collapsed row (such as "Thought for 4s") highlighting the row without expanding it in fullscreen mode</p>
<p>• Fixed a row with no details, such as an action row with a long name, pushing every other row's details to the right in list screens</p>
<p>• Fixed files with very long names not reaching a cloud session when attached to it</p>
<p>• Fixed plugin errors for a marketplace Claude Code refuses to load: they now say why and how to fix it instead of "not found"</p>
<p>• Fixed /plugin's Discover tab showing a marketplace name unquoted in its "Checking … for new plugins" line when its rows already show that name in quotes</p>
<p>• Improved commit guidance: when your project or user skills include one named verify, Claude is now told to run it right before committing, except for docs-only and tests-only commits</p>
<p>• Improved send now (ctrl+enter) in a subagent's view: it now moves the subagent's running command to the background so your message is read right away</p>
<p>• Improved replies from background agents to your messages so they no longer open with a separate recap of what you said</p>
<p>• Improved claude.ai artifact link reads: WebFetch now asks the same questions as the Artifact tool's read (no artifact prompt while the session's network access is on, one per artifact while it is off), and an auto-mode yes no longer counts where only you can answer</p>
<p>• Improved fetch, skill, file read, sandbox network, Claude in Chrome, workflow script and notebook edit permission prompts to match the look of file edit prompts</p>
<p>• Improved Bash, PowerShell and Monitor permission prompts to show the command between dashed lines, matching file edit prompts</p>
<p>• Improved list scrollbars in fullscreen mode: in most lists the bar no longer shifts as the "N more" rows come and go, and it now has ↑/↓ arrows you can click or hold to scroll</p>
<p>• Improved the external editor (Ctrl+G): editors that take a line number now open on the line your cursor is on in the prompt</p>
<p>• Improved slash command suggestion responsiveness while typing when many skills or plugin commands are installed; command descriptions now match by word prefix</p>
<p>• Improved the output style picker: it now opens on your current style instead of Default, with each style's description on the line under its name; number keys no longer pick a style</p>
<p>• Improved /hooks: the closing line of a hook's detail screen now says "this hook" instead of "it"</p>
<p>• Improved the model fallback notice and the autocompact-thrashing error to say when a fallback dropped the context window from 1M to 200K tokens</p>
<p>• Improved responsiveness of SDK and -p sessions when a host re-sends an MCP server enable for a server that is already connected</p>
<p>• Improved the protocol page a Claude apps gateway serves at /protocol: it now says not to reject unknown input and matches what Claude Code sends today</p>
<p>• Changed prompts sent while nothing is running or queued to show in the normal text color right away instead of gray</p>
<p>• Changed how failed API requests are retried: one limit now covers a whole model call, so with the default retry settings a failing call sends at most 14 requests</p>
<p>• Changed --bare to connect only the MCP servers named on the command line, send the model no system reminders, and start no background tasks; under --bare, a shell command that reaches its timeout now stops instead of moving to the background</p>
<p>• Changed the send-now key (ctrl+enter) to move a skill's own shell command to the background instead of ending it</p>
<p>• Changed the WebFetch error for a rate-limited domain safety check to tell Claude not to retry it in a loop</p>
<p>• Changed plugin installs to refuse npm sources that are git repositories or folders, and to install plugin dependencies only from registry packages</p>
<p>• Changed list screens (/artifacts, /mcp, /skills, /hooks and others) to always line up each row's details in one column after the names</p>
<p>• Changed the overflow rows of lists to read "↑ N more" / "↓ N more" instead of "N more above" / "N more below"</p>
<p>• Changed /hooks to open on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three</p>
<p>• Changed the theme picker to a scrolling list that fits your terminal instead of pushing the preview off screen; number keys no longer pick a theme</p>
<p>• Changed /exit's Remove worktree to run after Claude Code stops the servers and shells it started there, which on Windows could keep the folder from being deleted</p>
<p>• Changed the claude-api skill's Managed Agents examples to create environments with limited networking</p>
<p>• Removed the browser link from /ultrareview and claude ultrareview output</p>
<p>• Windows: Fixed claude --bg and the agents view refusing a folder that claude already trusts when its trust record was saved with different letter case</p>
<p>• [VSCode] Added bookmarks: save Claude's responses and keep them in view in a Bookmarks side panel</p>
<p>• [VSCode] Added the questions Claude asks and your answers to the conversation: after you answer a question card, a Questions row shows each question with your picks</p>
<p>• [VSCode] Added option previews to question cards in the chat panel: the highlighted choice's mockup or snippet shows beside or under the options</p>
<p>• [VSCode] Added rows under a message that open to the terminal output, browser tab, browser instructions and selected code sent with it</p>
<p>• [VSCode] Fixed a second copy of a conversation opening in a tab when it was already open in the side bar; the side bar now switches to it</p>
<p>• [VSCode] Fixed settings dialogs reporting a failed save, without re-checking, when Claude Code printed more than 1 MB of output</p>
<p>• [VSCode] Fixed an endless "Teleporting session…" spinner when the extension stops responding</p>
<p>• [VSCode] Improved the Manage plugins dialog: it says when a turned-off plugin is still on because of other settings, and explains a plugin folder clash</p>
<p>• [VSCode] Changed Stop and Escape to end only the current turn; background agents keep running and can be stopped one by one from the agent map</p>
<p>• [VSCode] Changed the "✻ Claude Code" status bar item to show in every window, so you can open Claude when no file is open</p>
<p>• [Cloud sessions] Fixed an answered question card or approved tool call getting no reply when the session had gone idle after Claude sent a message</p>
<p>• [Cloud sessions] Fixed clearing an organization environment's setup script in admin settings leaving new cloud sessions still running the old script</p>
<p>• [Cloud sessions] Fixed the Runner actions menu on the self-hosted environments admin page closing on its own a few seconds after it opened</p>
<p>• [Cloud sessions] Fixed routine runs whose cloud session never started showing as Succeeded in the Runs pane, the routine's page and the sidebar; they now show as Failed</p>
<p>• [Cloud sessions] Fixed clicking an audio or video file in a cloud session's Outputs card opening an empty file search instead of playing the file</p>
<p>• [Cloud sessions] Changed a routine's page to read "Due" with the scheduled time, instead of a next run time in the past, when a scheduled run is late and hasn't started</p>
<p>• [Claude Tag] Added an Add channel button to Claude Tag's spend limits page in admin settings, so a limit can be set on any channel, including a private one, from its channel ID or Slack link</p>
<p>• [Claude Tag] Fixed memory recall finding nothing in organizations that cannot use the default Sonnet model</p>
<p>• [Claude Tag] Fixed a Slack channel losing its Claude settings when an Enterprise Grid admin moves it to another workspace and the first post afterward doesn't mention Claude</p>
<p>• [Claude Tag] Fixed Claude in a Slack thread occasionally starting over on a fresh machine, losing work it hadn't pushed, when your reply answered a question it had just asked</p>
<p>• [Claude Tag] Fixed public channel names on Claude Tag's spend limits page in admin settings showing as raw Slack IDs in larger organizations</p>
<p>• [Claude Tag] Improved the titles of sessions started from Slack as shown on claude.ai: they now read as the words you typed, without Slack user IDs or escape codes</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.285</id>
<title>Claude Code v2.1.285</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.285"/>
<updated>2026-09-29T19:27:09Z</updated>
<content type="html"><p>• Added CLAUDE_CODE_DISABLE_WEB_FETCH environment variable to turn off the WebFetch tool</p>
<p>• Added claude --desktop to open the Claude desktop app on the current directory, or on a session with --continue / --resume &lt;id&gt;</p>
<p>• Added claude plugin configure &lt;plugin&gt; to show a plugin's options and which are unset, or save new values read from stdin with --values-stdin</p>
<p>• Added &lt;server&gt;.&lt;key&gt;=&lt;value&gt; to claude plugin install --config, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without visiting /plugin → Configure</p>
<p>• Added allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)</p>
<p>• Added CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable to cap re-sends of a non-streaming fallback request that timed out</p>
<p>• Fixed claude -p with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result</p>
<p>• Fixed plugin and marketplace installs and updates over SSH ignoring the ssh program set in GIT_SSH or in your git config's core.sshCommand</p>
<p>• Fixed Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file's policies. Other read errors and unparseable files stop every session</p>
<p>• Fixed cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published</p>
<p>• Fixed claude plugin disable and enable with a full name@marketplace id changing a settings entry in another letter case instead of the installed plugin's own</p>
<p>• Fixed files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice</p>
<p>• Fixed switching models mid-session with a set_model request (such as the Agent SDK's setModel) leaving the new model on the built-in output-token limit and auto-compact window until restart</p>
<p>• Fixed redacted logs and transcripts showing part of a URL password that contains @, or all of it when the URL writes its @ as %40</p>
<p>• Fixed SSH passphrase and new-host prompts from worktree and /teleport fetches taking over the terminal; these fetches now fail fast instead of asking</p>
<p>• Fixed switching off an MCP server added mid-session in SDK and -p sessions leaving its tools available</p>
<p>• Fixed claude -p --permission-prompt-tool: a background subagent's permission request now goes to the prompt tool instead of being auto-denied</p>
<p>• Fixed claude mcp list and claude mcp get, and the not-found error of claude mcp remove, login and logout, printing line breaks and terminal escape sequences from MCP server names and values</p>
<p>• Fixed sandbox auto-allow asking for approval on every run of many inline scripts (python3 -c, node -e) just because they contain =</p>
<p>• Fixed fork subagents not keeping the session's plan mode or dontAsk mode: a fork now runs under its parent's permission mode and cannot exit plan mode</p>
<p>• Fixed claude remote-control --help saying --[no-]chrome defaults to the machine's /chrome setting; spawned sessions keep Claude in Chrome off unless --chrome is passed</p>
<p>• Fixed background subagents in auto mode prompting a second, redundant reply after each report</p>
<p>• Fixed cloud session creation and /remote-env reading only the newest 20 of an account's environments</p>
<p>• Fixed Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume)</p>
<p>• Fixed installing a plugin with claude plugin install or /plugin putting it into an installed plugin's cache or data folder when their ids differ only in ., -, @ or (macOS, Windows) capitals; the install is now refused</p>
<p>• Fixed hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response</p>
<p>• Fixed the first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283</p>
<p>• Fixed sessions that authenticate with ANTHROPIC_AUTH_TOKEN against the Anthropic API never loading the organization's policy</p>
<p>• Fixed a failed agent(), parallel() or pipeline() call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session</p>
<p>• Fixed synchronous hooks hanging Claude Code while a background process the hook started (for example some-daemon &amp;) kept its output open; the hook now finishes shortly after its own process exits</p>
<p>• Fixed WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block</p>
<p>• Fixed the fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish</p>
<p>• Fixed Amazon Bedrock mid-stream modelTimeoutException and serviceUnavailableException errors showing a raw JSON body instead of the error message</p>
<p>• Fixed /autofix-pr and /schedule saying the Claude GitHub App is not installed on a repository whose install status had not been checked yet</p>
<p>• Fixed dismissing a row (x) in /artifacts unlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it</p>
<p>• Fixed Artifact tool publishes after a conversation rewind (Esc Esc) overwriting a file's newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file</p>
<p>• Fixed an Artifact allow rule ("don't ask again") letting the Artifact tool publish a file outside the working directories without asking; add the file's folder with --add-dir for the rule to cover it</p>
<p>• Fixed /cost and SDK modelUsage reporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected</p>
<p>• Fixed the Artifact tool so that publishing a page no longer lets Claude overwrite its source file without re-reading it when Claude's earlier read was cut short or the file had changed since</p>
<p>• Fixed auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else's artifact when you had approved that artifact earlier in another permission mode</p>
<p>• Fixed a misleading "core.worktree is set" error from /ultrareview when the project folder briefly could not be read</p>
<p>• Fixed /ultrareview on macOS and Linux failing to upload the working tree from a git worktree whose per-worktree config sets core.longpaths</p>
<p>• Fixed the Artifact tool sometimes reporting a publish as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded</p>
<p>• Fixed /ultrareview uploads including uncommitted changes to credential files whose name has a colon before the extension, such as server:8443.key</p>
<p>• Fixed a rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time</p>
<p>• Fixed the PowerShell tool's permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory)</p>
<p>• Fixed /ultrareview uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks</p>
<p>• Fixed a cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up</p>
<p>• Fixed vim mode: after editing in the external editor (Ctrl+G), x or r in NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt</p>
<p>• Fixed responses blocked by the API's output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter's error right away</p>
<p>• Fixed plugins silently skipping a bundled .mcpb MCP server that still needs configuration: /plugin, the install message and claude plugin install now say so and point to Configure</p>
<p>• Fixed compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields</p>
<p>• WSL: Fixed /ultrareview refusing to upload a checkout on a Linux volume when a changed file's name has a colon or ends in a dot or space</p>
<p>• Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had ended at --max-turns</p>
<p>• Fixed sign-in that could wait forever after the browser showed success</p>
<p>• Windows: Fixed /ultrareview uploading a linked worktree of a repository rooted at your home folder in some cases</p>
<p>• Fixed cloud sessions reporting the uploads folder as missing before any file had been uploaded</p>
<p>• Fixed a reply sent from claude agents to a background session waiting on a permission prompt sometimes approving the pending command</p>
<p>• Fixed claude attach, logs, stop, respawn and rm starting a new session with the command name as its prompt when options came before it, such as from a shell alias</p>
<p>• Fixed claude mcp list leaving out WebSocket (ws) MCP servers; each is now listed with its URL and health status</p>
<p>• Fixed claude mcp get showing no Type, Command, Args, or Environment for stdio servers whose config entry omits the type field</p>
<p>• Fixed .claude/settings.local.json allow rules being held back outside a git repository when git's trace2 output is configured</p>
<p>• Fixed the /claude-api eval runner scaffold and report builder writing through a symlink or hard link planted at an output file</p>
<p>• Fixed the /claude-api eval runner scaffold counting responses cut off at max_tokens in the score averages; they are now marked truncated and counted separately</p>
<p>• Fixed &amp;nbsp; showing as literal text in the terminal when a reply uses it to indent text, such as row labels in a markdown table</p>
<p>• Fixed a brief freeze (up to a second) partway through long sessions outside fullscreen mode, which came back after /clear or /compact</p>
<p>• Fixed an approved Edit never going through when its target is a device, such as a file symlinked to /dev/null, and the approval came from the IDE diff view or changed the edit</p>
<p>• Fixed a failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request's retry budget instead of getting a fresh set of retries</p>
<p>• Improved Claude in Chrome: the native host now reports your computer's name, so connected browsers can be labeled by computer instead of "Browser 1" / "Browser 2"</p>
<p>• Improved Bedrock and Vertex AI sessions to switch to an older available model of the same tier, instead of failing, when an admin removes access to the default model; session titles and summaries now fall back with it</p>
<p>• Improved plugin marketplace errors to name why a git address is refused instead of citing enterprise policy</p>
<p>• Improved validation of git URLs for plugins, marketplaces and the current repository's remote</p>
<p>• Improved Artifact tool results: they now suggest publishing in the same step as writing or editing the page, which can save a round trip</p>
<p>• Improved Remote Control: a /btw side question asked of a session hosted by an app such as Claude Desktop now sees the turn in progress, not only the last finished one</p>
<p>• Improved pictures Claude sends as BMP, HEIC, HEIF, AVIF or TIFF files: the Claude apps now show a preview where Claude Code can convert them</p>
<p>• Improved subagents in auto mode: a subagent's run now ends as soon as it hands its report back to its caller, instead of taking extra turns that reach no one</p>
<p>• Improved Bedrock and Vertex start-up model checks: models your account cannot use are now remembered for up to a day instead of being re-checked on every launch</p>
<p>• Improved Artifact tool publish results to use fewer tokens: the note on updating an artifact is shorter, and where to find your artifacts is no longer repeated after every publish</p>
<p>• Improved SDK liveness during a non-streaming fallback request: with partial messages on, a ping stream event is now sent every 30 seconds on the Anthropic API, Claude Platform on AWS and gateways</p>
<p>• Improved /resume and claude --resume on a session that is running in the background: they now open that session instead of refusing, and a prompt given with claude --resume &lt;id&gt; "prompt" is sent to it as its next turn</p>
<p>• Improved per-turn performance when many permission deny rules and MCP tools are configured</p>
<p>• Improved responsiveness when leaving the ctrl+o transcript view in long sessions when fullscreen rendering is off</p>
<p>• Improved Bedrock, Vertex and Mantle start-up model checks to send the same User-Agent, x-app and session ID headers as regular requests</p>
<p>• Changed MCP tools so a tool that sets its own _meta['anthropic/alwaysLoad'] to false stays deferred when its --mcp-config, Agent SDK or plugin server is set to alwaysLoad</p>
<p>• Changed background Bash and PowerShell commands to stop after a time limit (their timeout with run_in_background, default 30 min, max 2 h); Claude is notified when one is stopped</p>
<p>• Changed Code Review's pull request reviews and /ultrareview to run when disableWorkflows is on, unless the machine running the review has it set by its own administrator (MDM or the managed-settings file)</p>
<p>• Changed sessions behind a custom ANTHROPIC_BASE_URL to use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable); run /autocompact 200k if your gateway stops at 200K</p>
<p>• Changed Team and Enterprise sessions, and sessions whose sign-in plan Claude Code can't determine, to withhold WebFetch until the organization policy loads if it couldn't be loaded at startup</p>
<p>• Changed /memory so that Auto-memory can no longer be turned on from a background session or from a session one of Claude Code's own tools started; turning it off there still works</p>
<p>• Changed the one-time offer to make auto mode your default permission mode to also show on third-party providers and with telemetry off, when your user settings default to another mode</p>
<p>• Changed claude -p and Python Agent SDK sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured, like interactive sessions; --permission-mode still overrides it</p>
<p>• Changed Bedrock, Mantle and Claude Platform on AWS requests to a base URL with a non-default port to include the port in the SigV4-signed Host header</p>
<p>• Changed the MCP server name widgets to be reserved in cloud sessions and on self-hosted runners: your own server under it, or a close spelling such as widgets_, no longer loads, so rename it</p>
<p>• Changed /ultrareview on macOS and Linux to leave symbolic refs out when uploading a local checkout; a checkout whose current branch is a symbolic ref is now refused with an explanation</p>
<p>• Windows: Changed project and local settings env to no longer set ALLUSERSPROFILE, SystemDrive, or the CommonProgramFiles variables; set them in user or managed settings instead</p>
<p>• Changed /tasks to fold background work Claude Code runs for itself under one "System tasks" row; press Enter on it to show those tasks</p>
<p>• Changed /ultrareview on macOS and Linux to require git 2.31 or newer to upload a local repository; checkouts made with --separate-git-dir are now refused instead of being uploaded with an older method</p>
<p>• Changed /ultrareview uploads on macOS and Linux to send a partial clone as a working-tree snapshot on git 2.31 or newer, instead of falling back or refusing when git's version looked too old</p>
<p>• Changed /ultrareview uploads on macOS and Linux to refuse, instead of fetching, a partial clone missing some of its working tree's files on older git versions; a clone made without --filter uploads</p>
<p>• Changed Bedrock, Vertex and Mantle start-up model checks to identify themselves as Claude Code, like other Claude Code requests</p>
<p>• Changed claude mcp get to hide the command, arguments, and environment values of stdio MCP servers provided by plugins; variable names are still shown</p>
<p>• Changed /claude-api so it can no longer be run from Remote Control clients</p>
<p>• Changed /config chrome=true to direct you to the /config panel instead of enabling Claude in Chrome by default; /config chrome=false still turns it off when it was on</p>
<p>• Changed sandbox settings so project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies</p>
<p>• [VSCode] Added a note under a restored tab's last message when a window reload interrupted it and no reply will follow</p>
<p>• [VSCode] Added a plugin options form to Manage plugins: installing a plugin that has options asks for the unset ones, and a gear on its row changes them later</p>
<p>• [VSCode] Added an on-demand diagnostics tool so Claude in the panel can read the Problems panel's current errors and warnings at any time, not only right after it edits a file</p>
<p>• [VSCode] Fixed pressing Enter after typing a slash command running an unrelated menu item picked by fuzzy match, or doing nothing</p>
<p>• [VSCode] Fixed an open agent transcript losing the agent's newer messages during a long session</p>
<p>• [VSCode] Fixed a message that quotes a Claude Code or IDE tag losing the rest of its text in the chat</p>
<p>• [VSCode] Fixed a message sent while Claude was working disappearing from the conversation after the session was reopened</p>
<p>• [VSCode] Fixed the session list's Web tab showing the previous account's sessions after an account switch</p>
<p>• [VSCode] Fixed restored tabs re-running an interrupted turn when VS Code was started with CLAUDE_CODE_RESUME_INTERRUPTED_TURN set, even with Continue After Reload off</p>
<p>• [VSCode] Fixed Escape stopping the running turn instead of closing the command menu after clicking one of its rows</p>
<p>• [VSCode] Fixed opening Past conversations replacing a live conversation with its saved copy</p>
<p>• [VSCode] Fixed a Claude tab reloaded after an extension restart staying blank instead of saying how to recover</p>
<p>• [VSCode] Fixed opening a conversation that is already open in another window or app starting a second copy of it without warning; it now asks first</p>
<p>• [VSCode] Fixed a hook's reason for blocking or stopping a prompt disappearing after a window reload</p>
<p>• [VSCode] Fixed tabs stuck on a conversation that can't be resumed: the error now says so and offers to start a new conversation</p>
<p>• [VSCode] Fixed every file Read, Write and Edit stalling for ten minutes and then being skipped when the editor stops responding to the extension's automatic save before the tool runs</p>
<p>• [VSCode] Fixed the agent map labeling a sub-agent with the session's model instead of the model it actually ran on (e.g. under CLAUDE_CODE_SUBAGENT_MODEL_FORCE or an agent's own model)</p>
<p>• [VSCode] Fixed uninstalling a plugin from the Manage plugins dialog, which removed the wrong installation or failed for a plugin installed for the project</p>
<p>• [VSCode] Fixed sign-in staying on the authorization-code step after going back and choosing the same sign-in method again</p>
<p>• [VSCode] Fixed the chat panel stalling when a long session trims its oldest rows</p>
<p>• [VSCode] Fixed the conversation disappearing from a session when many agents run</p>
<p>• [VSCode] Fixed the editor tab keeping an old name after a session was renamed with /rename, by a SessionStart hook, or on claude.ai</p>
<p>• [VSCode] Fixed the agent map's transcript view leaving out messages sent to a running agent</p>
<p>• [VSCode] Improved the Manage plugins dialog: a failed plugin action now opens a popup that explains it and, where there is one, offers the fix</p>
<p>• [VSCode] Changed the Manage plugins dialog to ask before removing a marketplace or turning off a plugin that your project's shared .claude/settings.json turns on</p>
<p>• [Cloud sessions] Fixed Run now on a routine showing internal error text when the run is refused before it starts; it now shows the same explanation as the routine's failure notification</p>
<p>• [Cloud sessions] Changed MCP_DISCOVERY_CACHE=1, when set in your cloud environment's variables rather than a settings file, to reuse your connectors' tool lists after a session restart; other MCP servers are no longer cached and connect at startup</p>
<p>• [Claude Tag] Added direct messages with Claude for members on an Enterprise plan Standard or Usage-Based Chat seat who also have Cowork; a seat that includes Claude Code is no longer required</p>
<p>• [Claude Tag] Fixed the Default model setting in admin settings and a channel's Configure page offering models your organization can't use, which made saves or new sessions fail</p>
<p>• [Claude Tag] Fixed the note under Claude's Slack messages saying it answered on a fallback model, and why, disappearing when Claude later edited that message</p>
<p>• [Code Review] Fixed the organization menu in Code Review's "Add a repository" dialog showing only a few of your GitHub organizations; it now loads more as you scroll</p>
<p>• [Code Review] Improved the Code Review check run to say when your repository's REVIEW.md wasn't applied, for example on a very large pull request or when REVIEW.md is a symbolic link</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.284</id>
<title>Claude Code v2.1.284</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.284"/>
<updated>2026-09-28T18:01:46Z</updated>
<content type="html"><p>• Added Claude Sonnet 5.5 (claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads</p>
<p>• Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones</p>
<p>• Added dollar amounts to the Claude apps gateway spend limit in /usage and the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line's rate_limits.spend_limit also gains used_usd, limit_usd and period</p>
<p>• Added effortSlider:decreaseEffort, increaseEffort and toggleUltracode keybinding actions, so the /effort slider's arrow and Tab keys can be rebound in keybindings.json</p>
<p>• Added /rate-limit-options to /help and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find</p>
<p>• Added /mcp reconnect all in the interactive terminal to retry every MCP server that failed to connect or needs authentication at once</p>
<p>• Added Claude apps gateway startup warnings when a managed policy's availableModels is empty, or leaves out the model Claude Code starts on without setting model or enforceAvailableModels</p>
<p>• Added auth: { google: {} } for Claude apps gateway telemetry.forward_to destinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials</p>
<p>• Added certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets</p>
<p>• Fixed a damaged response stream showing raw errors such as "JSON Parse error" or "undefined is not an object", or writing the word "undefined" into an answer, instead of being retried or reported as an interrupted response</p>
<p>• Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried</p>
<p>• Fixed "Prompt is too long" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation</p>
<p>• Fixed a session whose model is unavailable, with no fallback model left, showing a bare "is currently unavailable" message (or "Something went wrong" in cloud sessions) instead of the model-unavailable notice and its Learn more link</p>
<p>• Fixed Agent SDK sessions crashing when a user message contains an image with a malformed source, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note</p>
<p>• Fixed MCP tool calls in a resumed session failing with "No such tool available" while their server was still connecting; the call now waits up to 10 seconds for the server</p>
<p>• Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login: /usage, /extra-usage and IDE usage views now back off instead of re-asking</p>
<p>• Fixed claude mcp add reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads</p>
<p>• Fixed the /plugin configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs</p>
<p>• Fixed ANTHROPIC_FOUNDRY_RESOURCE being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused</p>
<p>• Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically</p>
<p>• Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt</p>
<p>• Fixed Bash tool failing on Windows with many plugins enabled: plugin bin/ directories that don't exist are no longer added to PATH, and inherited entries aren't added twice</p>
<p>• Fixed sparsePaths plugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present"</p>
<p>• Fixed fullscreen rendering erasing the terminal output above the session when [ in transcript mode writes the conversation to scrollback (macOS and Linux)</p>
<p>• Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up</p>
<p>• Fixed tab bars in dialogs such as /config and /plugin breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole</p>
<p>• Fixed the /model picker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows</p>
<p>• Fixed /keybindings writing Backspace and Delete bindings for a footer action that does nothing into the generated keybindings.json</p>
<p>• Fixed a rebound agent panel close key (footer:close) typing "x" instead of itself on the row of the agent you're viewing</p>
<p>• Fixed vim mode . not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as cw then Esc)</p>
<p>• Fixed vim mode leaving the cursor on an image placeholder's opening bracket after dd on the last line or yy at the end of the prompt, where r or x would break or delete the image</p>
<p>• Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted</p>
<p>• Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory</p>
<p>• Fixed rules symlinked into .claude/rules from outside the project being skipped without ever showing the external-imports approval prompt; a .claude directory symlinked from outside the project now asks for the same approval</p>
<p>• Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval</p>
<p>• Fixed a failed first claude plugin install leaving the plugin enabled and recorded when a dependency's version range could not be met</p>
<p>• Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code</p>
<p>• Fixed {"decision":"block"} returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does</p>
<p>• Fixed sessions launched without the SendMessage tool (such as by Claude Desktop) still being told to message other sessions with it</p>
<p>• Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption</p>
<p>• Fixed typing a message during an automatic usage-limit wait taking the wait out of the "Continue automatically at usage limit" setting's control when that turn hit the limit again</p>
<p>• Fixed usage-limit warnings suggesting /upgrade to users already on the highest Max plan; the warnings and /upgrade itself now point at /usage-credits when it is available</p>
<p>• Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model</p>
<p>• Fixed /loop status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text</p>
<p>• Fixed /ultrareview failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux</p>
<p>• Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory</p>
<p>• Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private data/users/ subtree, and added a "view" level to as_level</p>
<p>• Fixed the Claude apps gateway answering 431 Request Header Fields Too Large to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB</p>
<p>• Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown</p>
<p>• Improved the "No such tool available" error for Claude in Chrome tools called without their prefix: it now names the tool to call</p>
<p>• Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged "Waiting for N … to finish" line after every event</p>
<p>• Improved Workflow tool sandbox hardening for errors thrown by async script hooks</p>
<p>• Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use</p>
<p>• Improved /claude-api: hillclimb no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside report.html is built as one local file that loads nothing from the network</p>
<p>• Improved lists such as /tasks, /copy and /hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edge</p>
<p>• Improved claude plugin marketplace add to say when it replaces a marketplace already added under the same name from a different source, and how to undo it</p>
<p>• Improved the startup refusal when managed settings require a sign-in (forceLoginMethod or forceLoginOrgUUID) and an API key, token or apiKeyHelper is configured: it now names the credential in use, where it is set, and how to remove it</p>
<p>• Improved auto-memory loading: invisible characters and tags that imitate Claude Code's own markup are neutralized in MEMORY.md and recalled memory notes before they reach Claude</p>
<p>• Improved claude remote-control: in a folder you haven't trusted yet, it now asks for workspace trust on the terminal instead of exiting</p>
<p>• Improved artifact pages: Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title</p>
<p>• Improved the Artifact tool so that when Claude is given a claude.ai chat or project link, an artifact from a chat, or an artifact id on its own, it asks for the right link or the content instead of stopping</p>
<p>• Changed interactive terminal and VS Code sessions to start in auto mode when no permission mode is configured, on every plan and provider; permissions.defaultMode still overrides it</p>
<p>• Changed Ultracode into its own toggle in /effort (Tab, or /effort ultracode [on|off]): it no longer forces xhigh effort and stays on at any effort level</p>
<p>• Changed retries after a dropped connection mid-response to share one budget with the rest of the request's retries, so a failing request gives up sooner</p>
<p>• Changed the notice shown when a Sonnet model's safeguards flag a message to explain why it happened and to offer editing and retrying</p>
<p>• Changed safety-related model switches in sessions that pin an Opus model with ANTHROPIC_DEFAULT_OPUS_MODEL or modelOverrides: on the Anthropic API, the API now picks the model to switch to for each kind of flag, not the pinned model</p>
<p>• Changed the non-interactive first turn to still wait up to 2s for connecting MCP servers named by --allowedTools or an mcp_tool hook, even when CLAUDE_CODE_MCP_STARTUP_WAIT_MS is 0</p>
<p>• Changed /recap to decline with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook; typed in the terminal, the Claude apps, Remote Control, -p or an SDK host, it runs as before</p>
<p>• Changed /artifacts to show its filter tabs beside the title with one-word labels (All, Mine, Shared), using the same tab bar as /config and /plugin</p>
<p>• Changed artifact publishing to refuse a file on a network share (a \\host\share path or a /net automount) unless it is on a mapped network drive added with --add-dir</p>
<p>• [VSCode] Added an optional time above each prompt and response, with a date line where the day changes (Claude Code: Show Message Timestamps setting, off by default)</p>
<p>• [VSCode] Added plugin load errors and notes to the Manage plugins rows, with a popup to disable, uninstall or copy the error</p>
<p>• [VSCode] Added an Ultracode on/off switch under the Effort slider, replacing the slider's Ultracode stop; the model pill shows "· Ultracode" at any effort level</p>
<p>• [VSCode] Fixed Reload Claude from the Memory dialog restarting before an edited file was saved</p>
<p>• [VSCode] Fixed a restored tab opening a conversation another Claude process still has open; it now asks first</p>
<p>• [VSCode] Fixed Focus view sections you expanded closing on their own while a sub-agent is working or when the section's first step is trimmed from view</p>
<p>• [VSCode] Fixed typing /model and Enter printing usage text into the chat instead of opening the model selector</p>
<p>• [VSCode] Fixed /feedback on Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does</p>
<p>• [VSCode] Fixed sign-in waiting up to a minute for the Python extension after a window reload</p>
<p>• [VSCode] Fixed Claude Code tabs that stopped responding after Restart Extensions: they now reopen on their conversation</p>
<p>• [VSCode] Fixed a message from another agent with no recorded sender showing as raw XML in the chat</p>
<p>• [VSCode] Fixed messages from other agents, sessions or channels disappearing after a reload</p>
<p>• [VSCode] Fixed a user's own /mcp, /config or /settings command being shadowed by the extension's dialog</p>
<p>• [VSCode] Fixed Escape stopping every background agent when no turn was running</p>
<p>• [VSCode] Fixed plugin install links replacing a marketplace you already have that uses the same name</p>
<p>• [VSCode] Fixed "Prompt is too long" errors after compaction when a large text file is attached to a message</p>
<p>• [VSCode] Fixed chat links to files with non-ASCII characters, spaces or brackets in their path not opening</p>
<p>• [VSCode] Changed CLAUDE_CONFIG_DIR in the claudeCode.environmentVariables setting to apply only when it is an absolute path, and passed it to terminals that continue the chat</p>
<p>• [Cloud sessions] Fixed a routine's Edit and Duplicate controls saying the routine was still loading while you were offline; they now tell you you're offline</p>
<p>• [Claude Tag] Added model family choices such as "Opus (latest)" for a thread, a channel default or your DM, so the choice follows the newest model in that family</p>
<p>• [Claude Tag] Added the spend that counts toward your organization-wide limit to the analytics spend projection chart, with how much of the limit is used</p>
<p>• [Claude Tag] Fixed the earlier Claude in Slack app's progress card and link previews omitting the repository and Create PR button when a GitHub Enterprise host name contains an underscore</p>
<p>• [Claude Tag] Fixed Claude staying silent in a channel whose environment declines to start it; it now posts one notice asking you to contact an admin, and retries when @-mentioned</p>
<p>• [Claude Tag] Changed Claude to post its private sign-in notice at every @mention from someone who hasn't connected their Claude account, instead of going quiet after the first</p>
<p>• [Claude Tag] Improved "Notify members now" in admin settings: one press reaches every workspace your organization claimed in an Enterprise Grid, and more members in large workspaces</p>
<p>• [Claude Tag] Improved Claude's wait notice on self-hosted environments with on-demand runners: it now says whether a runner is starting, a start will be retried, or no runner will start</p>
<p>• [Claude Tag] Improved the error shown when adding a channel manager fails because the channel's Slack workspace can't be confirmed as connected to your organization</p>
<p>• [Claude Tag] Improved a channel's access lists in admin settings to show the connectors, repositories and plugins an auto-join pattern attaches, and where each comes from</p>
<p>• [Claude Tag] Improved adding repositories as a channel manager: when your GitHub sign-in can't confirm you're a repository admin, the page asks you to sign in with GitHub</p>
<p>• [Code Review] Fixed Code Review giving up without posting a finished review when an unsubmitted review under its GitHub App was open on the pull request; it now retries the post first</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.283</id>
<title>Claude Code v2.1.283</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.283"/>
<updated>2026-09-25T21:49:55Z</updated>
<content type="html"><p>• Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1</p>
<p>• Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed</p>
<p>• Added deniedModels managed setting to block specific models, even when availableModels allows them</p>
<p>• Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1</p>
<p>• Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models</p>
<p>• Added click-to-expand for truncated messages from your other sessions in fullscreen mode</p>
<p>• Added path to --plugin-dir load-failure entries in the stream-json system/init plugin_errors, naming the directory that did not load</p>
<p>• Added an opt-in load_test_mode block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested</p>
<p>• Added a mantle upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint</p>
<p>• Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's result.usage</p>
<p>• Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress</p>
<p>• Fixed stdio MCP servers being left running when the session ended while they were still starting</p>
<p>• Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected</p>
<p>• Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers</p>
<p>• Fixed the weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled</p>
<p>• Fixed /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused</p>
<p>• Fixed /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model</p>
<p>• Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model</p>
<p>• Fixed DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session's main model</p>
<p>• Fixed claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation</p>
<p>• Fixed claude plugin validate passing plugins whose outputStyles, themes, monitors, or lspServers paths are missing or point outside the plugin directory</p>
<p>• Fixed claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json</p>
<p>• Fixed claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them</p>
<p>• Fixed claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope</p>
<p>• Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing</p>
<p>• Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers</p>
<p>• Fixed installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again</p>
<p>• Fixed installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover</p>
<p>• Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text</p>
<p>• Fixed /context not counting MCP server instructions: they now appear as their own row and count toward the total</p>
<p>• Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks</p>
<p>• Fixed claude mcp add, add-json, and remove reporting success when the user or local config file could not be written, for example inside a sandbox</p>
<p>• Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them</p>
<p>• Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send</p>
<p>• Fixed keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix</p>
<p>• Fixed footer hints still saying "Enter to view" after footer:openSelected was rebound or unbound in keybindings.json</p>
<p>• Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state</p>
<p>• Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs</p>
<p>• Fixed sandboxed git asking credential helpers to store the sandbox proxy's login, which printed "failed to store"</p>
<p>• Fixed managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies</p>
<p>• Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository</p>
<p>• Fixed Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK</p>
<p>• Fixed the /remote-control menu cutting its QR-code hint mid-word in narrow terminals</p>
<p>• Fixed vim mode . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line</p>
<p>• Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank</p>
<p>• Fixed vim mode J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does</p>
<p>• Windows: Fixed the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses</p>
<p>• Improved the /mcp tool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon</p>
<p>• Improved MCP tool results: images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them</p>
<p>• Improved /tasks: rows show a status icon, the name and whole facts, the title and key hints stay on screen with many tasks, and the list gains paging keys, the mouse wheel and clicks</p>
<p>• Improved lists in /help, /hooks, /copy, /chrome, /memory, /ide, /release-notes, /rewind, /diff, /remote-env, /plugin and other pickers with page keys, mouse wheel and clicks</p>
<p>• Improved lists beside a search box, such as /skills and /artifacts, to draw their pointer dim while the search box has the keys, so only one pointer is highlighted</p>
<p>• Improved the compaction spinner: its timer now starts when compaction begins and it counts the summary's tokens as they stream, replacing the percentage bar</p>
<p>• Improved the browser page shown after signing in to an MCP server: centered layout, dark mode, and new artwork</p>
<p>• Improved the Skill tool's reply when a skill belongs to a plugin that failed to load, so Claude tells you the plugin could not be loaded instead of calling the skill uninstalled</p>
<p>• Improved prompt-audit on Claude Code configuration: stale paths, stale commands and contradicting instruction files now lead the report, and thinking keywords that Claude Code documents are kept</p>
<p>• Improved recovery from an installed_plugins.json that cannot be read at all: its contents are kept in a file beside it before it is rebuilt, and claude plugin list names that file</p>
<p>• Improved artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest</p>
<p>• Improved first-reply latency: a pattern-compile step that ran at the end of a session's first reply now runs while the reply streams in</p>
<p>• Improved first-request latency by reusing the preconnected API connection</p>
<p>• Improved startup: claude -p and Claude Code Remote no longer load the interactive UI, and the auto-mode classifier's rules and the Artifact tool load on first use instead of at launch</p>
<p>• Improved startup for claude.ai accounts whose Artifact tool features aren't known yet, as on a first run: the prompt no longer waits up to 1.5 s to check them; the first message waits if needed</p>
<p>• Changed interactive sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured; permissions.defaultMode still overrides it</p>
<p>• Changed the /ultrareview launch dialog to say that reviewing a local branch may upload uncommitted changes to tracked files</p>
<p>• Changed the /model picker's Opus row and the Default model's name to drop "(1M context)" where Opus already has a 1M context window; the window is unchanged</p>
<p>• Changed prompt suggestions in the terminal to appear less often after 20 in a row go unused; using one brings them back</p>
<p>• Changed --system-prompt and --append-system-prompt to accept their text and -file forms together; the file's text comes first</p>
<p>• Changed Skill(anthropic-skills:&lt;name&gt;) deny rules to also block that skill when Claude Desktop delivers it as a plugin, and Skill(skill:&lt;name&gt;) denies to match the skill's alias and display name</p>
<p>• Changed /rewind and /diff lists to move on the same keybinding actions as every other list (select:*); messageSelector:*/diff:* rebinds still work</p>
<p>• Changed the /workflows run list to size itself like other lists: half the terminal inline, and it keeps its title on screen when the prompt shows below</p>
<p>• Changed claude plugin eval to require git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version</p>
<p>• Changed artifact watching: a watch that was armed automatically (not one you asked for) now ends after 3.5 hours with no activity; publishing or watching the artifact again re-arms it</p>
<p>• Self-hosted runner: Changed lifecycle hooks' git to skip a repository's Git LFS pre-push hook, ignore a writable system core.hooksPath, and not sign commits without --configure-git</p>
<p>• Self-hosted runner: Changed GIT_SSL_CAINFO and GIT_SSL_NO_VERIFY under Anthropic-managed git: the runner's own git always verifies Anthropic's git route, and warning lines say what applies where</p>
<p>• Reverted the 2.1.282 reservation of the claude-ai name: skills, commands, workflows and MCP servers' skills and prompts so named load again, and Skill(claude-ai:*) rules are ordinary prefix rules</p>
<p>• [VSCode] Fixed the permission mode indicator showing Default while the session kept running in auto or bypass mode after an automatic switch out of it failed; the switch is now retried until it lands</p>
<p>• [VSCode] Fixed a session teleported from the web dropping the messages sent while Claude was working</p>
<p>• [VSCode] Fixed a Web session staying hidden from the session list, and an empty chat opening in its place, when an older version had saved an empty local copy of it</p>
<p>• [VSCode] Fixed a reopened session splitting a turn at a message Claude received mid-turn, such as an automatic continuation</p>
<p>• [VSCode] Fixed a reloaded session showing a rewound-away turn, or only the rows before a compaction</p>
<p>• [VSCode] Fixed the footer's agents pill drawing its icon off-center, with the status dot against the edge, in narrow panels</p>
<p>• [VSCode] Fixed the chat input showing its text slightly below the cursor and selection after pasting lines that end with a line break into a long prompt</p>
<p>• [Cloud sessions] Improved adding a repository to a running cloud session: a private repository your GitHub account can read but not push to now attaches for reading</p>
<p>• [Cloud sessions] Fixed cloud sessions occasionally redoing an already-finished step, such as posting a duplicate comment or push, after recovering from a server-side restart</p>
<p>• [Cloud sessions] Changed new routine schedules to default to a few minutes past the hour, with a note that routines set exactly on the hour can start several minutes late</p>
<p>• [Claude Tag] Added a "Channels Claude can search" admin setting that limits Claude's Slack search to public channels it has been added to, set per organization, workspace or channel</p>
<p>• [Claude Tag] Added a Back to Slack button on the page shown after connecting your Claude account, returning you to the thread you started from</p>
<p>• [Claude Tag] Fixed a channel's configure page listing no connectors or plugins when the channel gets its access bundle through an attach rule; rule-attached bundles are now shown</p>
<p>• [Claude Tag] Fixed access-bundle repository search missing repositories on GitHub App installs that are limited to a large list of selected repositories</p>
<p>• [Claude Tag] Fixed Claude occasionally posting the same reply twice when a new message interrupted it mid-reply</p>
<p>• [Claude Tag] Fixed channel routines that stopped running in older private channels whose Slack channel ID changed, for example after a Slack Connect share</p>
<p>• [Claude Tag] Fixed conversations in a channel set to "Channel only" all ending when a non-guest member joined and Slack was slow to confirm their membership</p>
<p>• [Code Review] Fixed "@claude review" requests going silent when GitHub failed to return the pull request: the request is retried once, and a comment explains if it still fails</p>
<p>• [Code Review] Fixed billing for a review that stopped at its time limit with nothing verified: it now shows as incomplete, isn't charged, and is retried once</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.282</id>
<title>Claude Code v2.1.282</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.282"/>
<updated>2026-09-24T18:37:48Z</updated>
<content type="html"><p>• Added a maxProseWidth setting that caps the width of Claude's prose in wide terminals while tables and code blocks keep the full width</p>
<p>• Added a startup notice, and /status and claude doctor entries, listing telemetry variables in a project's settings files that were ignored or that turned telemetry off</p>
<p>• Added the allowClaudeInChromeWithManagedMcp managed setting to let claude --chrome run alongside an exclusive managed-mcp.json; the error shown when Chrome is blocked now names it</p>
<p>• Added store.readiness_grace_seconds to the Claude apps gateway so /readyz can stay ready through a short Postgres outage such as a database failover</p>
<p>• Added a scrollbar to the /feedback drafts list in fullscreen mode; it appears while the mouse is over the list</p>
<p>• Fixed every request failing with a 400 error in conversations whose history holds web search results the API cannot decrypt (for example, from a turn answered through a third-party gateway)</p>
<p>• Fixed more cases of continued or resumed sessions (--continue, --resume) re-sending earlier messages in a changed form, which could make the API drop Claude's earlier reasoning</p>
<p>• Fixed earlier extended thinking being dropped when /model, /rename, /artifacts or another immediate slash command was used while Claude was working</p>
<p>• Fixed continued or resumed conversations losing earlier extended thinking when relaunched with a --tools list that leaves out a built-in tool offered earlier in the conversation</p>
<p>• Fixed sessions failing on every turn with an "Invalid data in redacted_thinking block" API error; Claude Code now drops the conversation's thinking blocks and retries once</p>
<p>• Fixed compaction failing when the summarization request is refused; it now retries on a fallback model</p>
<p>• Fixed a failed turn ("Effort 'xhigh' isn't available with thinking turned off") after a safety-related model switch in sessions with thinking off and effort above high</p>
<p>• Fixed an unanswered Fable usage-credits prompt switching models in SDK-hosted sessions such as Claude Desktop; the turn now ends instead, and Remote Control clients now see the model-switch notice</p>
<p>• Fixed /model with a full Fable model id stopping at an API error instead of opening the usage-credits prompt when the plan needs usage credits that aren't turned on yet</p>
<p>• Fixed requests failing for up to a minute with an "another Claude Code process is refreshing it" login error after that other process was closed or killed mid-refresh</p>
<p>• Fixed sessions started while another Claude Code window was refreshing the sign-in (common with several VS Code windows) not retrying their organization policy fetch</p>
<p>• Fixed CLAUDE.md and rules being read at startup through a repository symlink reaching macOS's /Network via .. or a /.vol-style kernel path, or a rules link to macOS's /home being listed</p>
<p>• Fixed Bash permission rules with a mid-pattern :* being skipped in settings files while --allowedTools honored them; they now work from every source, with a startup warning on how they match</p>
<p>• Fixed a command approved on a restored permission prompt running twice when a remote session's worker restarted</p>
<p>• Fixed managed settings ignoring a mistyped value for boolean lock keys such as disableClaudeAiConnectors or allowManagedPermissionRulesOnly; the lock now applies and startup names the key</p>
<p>• Fixed managed permissions, autoMode, worktree and attribution settings being ignored entirely when one nested value was invalid; the rest of the block now still applies</p>
<p>• Fixed repository, user and --add-dir skills, commands and skills-directory plugin manifests pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly</p>
<p>• Fixed safeguard block messages on Amazon Bedrock and Bedrock Mantle not showing a request ID; block messages now also show the message ID</p>
<p>• Vertex AI: Fixed web search not being offered for models Claude Code doesn't recognize yet, such as newly released ones</p>
<p>• Fixed Bash and PowerShell hiding a full disk quota behind "Exit code 1" and leaving large output files in temp</p>
<p>• Fixed tool input validation errors naming only an unknown, missing or mistyped parameter when other parameters in the same call were also invalid; those are now listed too</p>
<p>• Fixed pasted multi-line text being submitted line by line after the terminal's bracketed paste mode was reset mid-session</p>
<p>• Fixed the prompt's example text flashing and disappearing at startup in projects with a SessionStart hook</p>
<p>• Fixed a blank screen flashing before the first frame when starting in fullscreen mode</p>
<p>• Fixed garbled, misplaced rows in the non-fullscreen renderer after the screen got shorter while still taller than the terminal, e.g. deleting a prompt line while a shell command streams output</p>
<p>• Fixed a stale character left in the last column of a diff when a redrawn line's CJK character or emoji wrapped to the next row</p>
<p>• Fixed the cursor landing before the end of a prompt recalled from history when the prompt contains a tab</p>
<p>• Fixed the send-now hint showing ctrl+enter on terminals that send it as a newline (Windows Terminal before 1.25); it now shows ctrl+x ctrl+s there</p>
<p>• Fixed claude remote-control --debug failing with "Unknown argument: --debug", although Remote Control's own eligibility error says to run with --debug</p>
<p>• Fixed /install-github-app saying "cancelled" and then still pushing the branch and saving the API key secret; leaving now stops the remaining steps and reports what was already done</p>
<p>• Fixed /feedback, /bug and /share on Bedrock, Vertex and other third-party providers still saving the report file after you cancelled during the save</p>
<p>• Fixed plugin uninstall reporting success and deleting the plugin's saved options when its settings file still enabled it or could not be read; it now stops and names the file</p>
<p>• Fixed plugin uninstall deleting a plugin's saved options and secrets when the list of installed plugins could not be read after the removal; they are now kept and the uninstall says so</p>
<p>• Fixed a key typed right after / in /skills moving the skill list instead of reaching the search box</p>
<p>• Fixed the terminal cursor jumping from the /skills search box to the skill list while typing, which could hide the caret and put IME input in the wrong place</p>
<p>• Fixed lists with a scrollbar, such as /skills and /mcp, being two columns narrower outside fullscreen mode, where the scrollbar can never appear</p>
<p>• Fixed the agent panel footer wrapping onto two lines with long rebound keys, and its "Esc to collapse" hint ignoring a rebound collapse key</p>
<p>• Fixed a doubled · separator in the /tasks dialog footer when the stop-all-agents shortcut is unbound in keybindings.json</p>
<p>• Fixed artifact publishes failing when Claude gave the version a label longer than 60 characters; the label is now shortened</p>
<p>• Fixed screen-reader mode, quoted lists and very long lists dropping the blank lines at the top of a code block that opens a list item, directly or inside a quote</p>
<p>• Fixed PDF page-read error messages: paths with accented or non-Latin characters now appear readably, and a folder named like "password" or "invalid" can no longer make the error name the wrong cause</p>
<p>• Fixed vim mode &gt;&gt; indenting empty lines, r with a count longer than the line changing text, 2J joining one line too many, and a count on the last line (2dd, 2&gt;&gt;) shifting or deleting it</p>
<p>• Fixed vim mode cursor placement: after dd, dj, dG or a whole-line p/P it lands on the first non-blank, yy no longer moves it, and Esc after an emoji no longer leaves it inside the emoji</p>
<p>• Fixed vim mode ignoring a count typed before . when repeating x, s, p, d or c, and whole-line p/P, o, O, J, &gt;&gt; and &lt;&lt; acting on the wrong line when a line above wraps</p>
<p>• Fixed vim mode leaving the cursor past the end of a prompt recalled from history or pulled back from the queue in normal mode, so x did nothing</p>
<p>• Improved the time to resume very large sessions, including ones that were never compacted</p>
<p>• Improved the error shown on Windows when a session can't be resumed because its transcript file could not be read (EBADF): it now names possible causes and what to try</p>
<p>• Improved the Claude Desktop unknown-model error to suggest switching to a different model</p>
<p>• Improved rendering of unusual Unicode in permission prompts</p>
<p>• Improved /artifacts: titles line up in one column, details are dropped whole instead of cut mid-word, and the list supports PgUp/PgDn, Home/End, the mouse wheel and clicks</p>
<p>• Updated the claude-api skill: pre-output refusal billing now links to the How refusals are billed docs, mid-stream refusals bill at normal rates, and pre-output refusals count against rate limits</p>
<p>• Updated the claude-api skill to recommend ant apply for keeping Managed Agents resources as version-controlled files</p>
<p>• Changed auto mode to use the server-side classifier by default on a direct Anthropic API connection when telemetry is off (CLAUDE_CODE_AUTO_MODE_SERVER=0 opts out)</p>
<p>• Changed sandbox.excludedCommands to ignore project and local settings entries when managed settings or --settings set allowUnsandboxedCommands: false, or managed allowManagedDomainsOnly: true</p>
<p>• Changed project and local settings to ignore OpenTelemetry variables that turn on export, set its endpoint, or capture content, like CLAUDE_CODE_ENABLE_TELEMETRY and OTEL_LOG_*</p>
<p>• Changed Windows/WSL managed settings so an admin policy that is present but invalid or unreadable (HKLM, managed-settings.json) keeps user-writable HKCU and WSL /etc/claude-code from applying</p>
<p>• Changed Skill(anthropic-skills:*) and Skill(claude-ai:*) allow rules to cover only skills synced from claude.ai, not plugins or other skills that merely use such a name</p>
<p>• Changed skill folders, command files and workflow commands in the anthropic-skills or claude-ai namespace to no longer load; a plugin so named still loads but yields name ties to synced skills</p>
<p>• Changed MCP servers configured under the name anthropic-skills or claude-ai to list no skills or prompts (their tools still work); rename the server in your MCP configuration to list them again</p>
<p>• Changed the ultracode visuals in /effort and the prompt input to plain styling (no ripple, border flourish or keyword glimmer) and removed the dynamic-workflows spinner tip</p>
<p>• Changed the Clawd mascot's feet in the start-up banner to sit under the corners of his body</p>
<p>• [VSCode] Fixed long replies falling behind the stream: the panel no longer re-parses the whole reply on every update</p>
<p>• [VSCode] Fixed the dictation mic button covering the message input's scrollbar when the input is tall enough to scroll</p>
<p>• [VSCode] Fixed Remote Control sessions started on this computer not opening from their Web entry in the session list; they now open the local conversation unless it's running elsewhere</p>
<p>• [VSCode] Fixed an editor tab's sign-in screen hanging silently after the extension host restarts; it now shows the "stopped responding" notice too</p>
<p>• [Cloud sessions] Added Claude GitHub App status to Settings › Connectors › GitHub: whether the app is installed and reachable for your account, plus steps to connect, install or reconnect</p>
<p>• [Cloud sessions] Added "Open repository" and "Open compare page" links to the repository menu of a cloud session whose repository is hosted on a Git server other than GitHub</p>
<p>• [Cloud sessions] Added attaching a repository from a different GitHub owner, such as a fork's upstream, to a running cloud session that already has one, including sessions started from Slack</p>
<p>• [Cloud sessions] Fixed the next run time shown for an hourly routine being 30 minutes off for people in half-hour-offset time zones such as India</p>
<p>• [Cloud sessions] Improved how quickly the Routines page and the sidebar's Scheduled list load for accounts whose past sessions scheduled many check-in reminders</p>
<p>• [Claude Tag] Fixed auto-join channel patterns saved for one workspace in Claude Tag admin settings being ignored on an Enterprise Grid org-wide install; Claude now joins matching new channels</p>
<p>• [Claude Tag] Fixed Claude not responding in an Enterprise Grid channel shared between two workspaces of one organization when the channel's Claude Tag version was saved from the other workspace</p>
<p>• [Claude Tag] Fixed the earlier Claude in Slack app's progress card for sessions on a GitHub Enterprise Server repository: it now names the repository and offers a working Create PR button</p>
<p>• [Claude Tag] Fixed Slack threads whose model has been retired falling back to another model on every reply, slower and with a fallback note each time; the thread now moves to a working model</p>
<p>• [Claude Tag] Fixed files Claude uploads to Slack not being able to carry a caption containing a table; captions now render with the same formatting as replies</p>
<p>• [Claude Tag] Fixed Claude's threads in Slack's Agents &amp; tools view sometimes being listed under their first message instead of their name; later renames now update the list too</p>
<p>• [Claude Tag] Fixed removing a GitHub organization's grant from an access bundle's Repositories tab in Claude Tag admin settings failing to save after that GitHub organization was disconnected</p>
<p>• [Claude Tag] Fixed Claude always replying "Couldn't check this channel just now" in a channel shared with a Grid workspace it isn't added to; the notice now says which workspace needs the app</p>
<p>• [Claude Tag] Fixed the cost and token totals in Claude's reply footer reading many times too high after the session's cloud worker restarted</p>
<p>• [Claude Tag] Changed the bordered cards Claude uses in Slack replies for plans, tables and details to render wide by default instead of a narrow width</p>
<p>• [Claude Tag] Changed newly connected Slack workspaces to follow the current default model instead of keeping whichever model was the default when they were connected</p></content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.281</id>
<title>Claude Code v2.1.281</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.281"/>
<updated>2026-09-23T19:18:57Z</updated>
<content type="html"><p>• Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode</p>
<p>• Added assume_role on Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer</p>
<p>• Added guardrail: {id, version} on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)</p>
<p>• Added telemetry.resource_attributes to the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and /login sessions</p>
<p>• Added "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions</p>
<p>• Added MCP URL-mode elicitation on 2026-07-28 protocol connections, so servers can ask Claude Code to open a browser-based flow; no waiting dialog is left on screen when the server has no way to confirm completion</p>
<p>• Added MCP server checks to claude plugin validate: it reports .mcp.json entries that would be silently dropped at load, undeclared ${user_config.*} references, and insecure URLs</p>
<p>• Added an auto mode recommendation to /insights that estimates how many permission prompts auto mode could have handled in your recent sessions</p>
<p>• Added a scrollbar to the /skills, /mcp and /plugin Installed lists in fullscreen mode, like the one /workflows now has: it appears while the mouse is over the list and can be clicked or dragged</p>
<p>• Fixed a crash ("unrecoverable interface error") that could end a session while an API request was being retried</p>
<p>• Fixed a turn that could retry indefinitely, ignoring --max-turns, when the model alternated unparseable tool calls and output-limit truncation</p>
<p>• Fixed resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call's input or a tool-search result while its server was still reconnecting, or a tool-search result whose loading turn was interrupted), which could make the API drop the conversation's prior reasoning</p>
<p>• Fixed resuming a very large session sometimes restoring only its last few messages</p>
<p>• Fixed a session resumed after a restart during a pending permission prompt sending a different history than before, which broke the prompt cache from that point</p>
<p>• Fixed resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden "Continue" message</p>
<p>• Fixed sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once</p>