SDK result messages can now report a breakdown of time before the first model request#
Successful SDK results gain timing fields that break down the delay before the first model request, under the same conditions as startup timing
You can now use claude-sonnet-5 with high effort and automatic thinking switched on by default. The high effort option is now labelled Recommended instead of Default. Admins can use the new managed setting allowedProviders to limit which API providers Claude Code may run on. Setting CLAUDE_CODE_DISABLE_WEB_FETCH turns off WebFetch, the tool Claude uses to download web pages. Claude Code can now load relevant memories saved to your account before a turn. The new claude plugin configure command shows a plugin's options and can save values piped in as JSON.
Seven changes are in the build but not switched on yet. A new plugin test command runs a mod's tests and is marked as early access. Waking and retrying background MCP tasks now sits behind a remote switch that is off by default. A report-delivering tool can end the agent's turn, but only when a server switch allows it. The precomputeCompactionEnabled setting still stays hidden unless a server switch turns it on.
Directory sync for cloud sessions is now fully removed. The CLAUDE_CODE_DIR_SYNC_* variables and CLAUDE_CODE_DISABLE_DIR_SYNC no longer do anything. Launching with --cloud no longer offers to sync your folder, and bundle upload still works. On macOS and Linux, CLAUDE_CODE_LEGACY_BUNDLE is now ignored with a warning. Passing unrestrictedPaths to the agent toolset now throws an error. An @-mentioned audio file no longer gets turned into a transcript for Claude.
Written by our agent from the shipped bundle, not by Anthropic.
New ui_* messages let desktop, mobile and VS Code surfaces attach to a session and draw plugin UI, and a gated list_directory request is added
ExtensionsNew claude plugin configure, plugin install --config reaching bundled MCP server settings, and plugin list --data-size for scripts
claude --desktop opens a session in the Claude Desktop appThe new --desktop flag opens Claude Desktop instead of the terminal, and can pick a session with --continue or --resume <id>
ElsewhereThe new managed setting allowedProviders lists the API providers allowed, and Claude Code refuses to run on any other
Claude Code now handles an mcp.connect request that takes the name of an MCP server
plugin test command runs a mod's testsExtensionsWant the reasoning? Read walks the 34 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →10 more of these are in What probably matters to you, on page 1.
Successful SDK results gain timing fields that break down the delay before the first model request, under the same conditions as startup timing
On Bedrock and Vertex AI, Claude Code now remembers per-model access results with expiry and rechecks a model live before using it
Unclear How long each remembered result lasts, and exactly what you will see differently, is not stated.
The SDK's result message now includes api_error when present, alongside api_error_status and api_error_code
Unclear When api_error is actually filled in is not stated.
Claude in Chrome now allows, blocks or asks about navigation and batched browser actions based on the web address and your domain rules
Unclear It is unclear whether this check replaces an earlier permission path for these actions or runs alongside it.
A forked subagent that tries to leave plan mode is now refused, because that belongs to the session that started it
Unclear Exactly which built-in subagent this check applies to is not clear.
On WSL, a malformed /proc/self/mounts line now blocks cloud sessions until fixed, and the unreadable-mounts error is reworded
claude ssh now reports when the machine's credentials changed while your organization's policy was loading, and handles it like a timeout
Claude Code now refuses to read some unsafe git remote addresses, such as ones that look like command options
Unclear Exactly which address forms are now rejected is not clear.
When auto mode blocks an action, the message and log now read the block reason from a different value, possibly fixing the reason shown
Unclear It is unclear whether the reason you actually see is any different after this change.
If the browser sends the sign-in reply again after the code arrived, it gets a plain page saying sign-in is finishing
<<- split across lines are now rejected#Claude Code's shell parser now refuses a heredoc - that only sits next to << because two lines were joined
Creating a worktree now runs git with a hardened set of settings, including limits on network protocols and no interactive SSH prompts
Unclear The full set of git commands covered by these settings is not clear.
When a managed settings file or folder cannot be read, the error now includes the system's error code where there is one
After publishing an artifact, Claude is no longer told about the gallery, /artifacts or ctrl+], so it is less likely to pass those tips on
Setting allowUnsandboxedCommands to false is now also read through a second settings lookup
Unclear It is not clear which settings source the additional lookup reads.
When a plugin marketplace's git URL is rejected, the error now says what is wrong with it
claude mcp get processes each output line before printing#claude mcp get now passes each line of its output through an extra step and detects local servers differently
Unclear It is not clear what the extra step does to each line, including whether it hides secrets.
Force-deleting an agent's worktree now refuses when the path goes through a link or no longer matches, and cleans up only stale git records
Claude Code now refuses git addresses with certain odd characters when installing plugins or adding marketplaces, and explains which forms work
Logs now mask usernames and passwords in URLs as :@ and also strip any extra @-separated parts that follow
A newly installed plugin that still needs configuration is now treated as activated and reported as needing configuration, not as needing a reload
/context rewritten#The auto-compact window line in /context is built a different way, so its wording may differ slightly
Unclear The exact new wording of the labels is not known.
A file download helper now has a time limit for the server's first reply and returns a failure instead of raising an error when it cannot build the address
Unclear Which downloads in Claude Code use this helper is not stated.
The tool a subagent uses to hand back its final report now tells it the call ends its run, so it must come last
Claude Code now passes more Windows environment variables through, including ALLUSERSPROFILE, SYSTEMDRIVE and the COMMONPROGRAMFILES ones
Unclear Which pass-through list this is, and so which programs receive these variables, is not stated.
Git addresses using git:// are now rejected because they are not encrypted, and the error lists the supported address forms
Unclear It is not clear which features check git addresses this way.
Git remote URLs with bracketed hosts, encoded null characters or ambiguous hosts are now rejected when Claude Code matches repositories
Unclear Which Claude Code features rely on this repository matching is not stated.
Removing a stale git worktree record now checks its paths first, refuses links and odd paths, and respects locked worktrees
Unclear Which command triggers this cleanup is not stated.
The note on a hidden session stats breakdown now says your organization's policy hides it, instead of naming HIPAA
Unclear Whether the situations that hide the breakdown also widened, or only the message changed, is not clear.
Claude Code can now recognize PowerShell parse errors and errors from Invoke-Expression in command output
Unclear How Claude Code uses these recognized errors is not stated.
A list of package registry hosts now covers npm, JSR, PyPI, crates.io and the Go module proxy
Unclear Which feature uses this list, such as the sandbox, is not stated.
When Claude reads an artifact, the result now includes the page title when it is known
A git config file that Claude Code generates now sets longpaths = true, so git can handle very long file paths
Unclear Which git config file this is, and when Claude Code generates it, is not clear.
The built-in skill that answers questions about Claude Code now has web fetching approved only for code.claude.com and platform.claude.com
Unclear Whether pages from other sites can still be fetched after you approve a permission prompt is not clear.
When Claude reads an artifact's files, the result now includes the page title, and files fixed by the artifact's type are no longer listed
Unclear It is not clear whether the Artifact tool is available to everyone or only when switched on.
Subagents are now told that sending their report ends their run, so it should be their last step
Unclear It is not clear which kinds of subagent receive this instruction.
When a cloud session from an uploaded copy of your folder is refused, the message now cites your organization's policy instead of HIPAA
Unclear It is not clear what triggers the refusal or whether it now applies to more organizations than before.
A GitHub conditional access refusal is now retried with a pause like IP allowlist, suspended app and SAML SSO errors
Git commands run by Claude Code now take their allowed network protocols from a shared value and set GIT_NO_LAZY_FETCH and GIT_TERMINAL_PROMPT
Unclear The new value of GIT_ALLOW_PROTOCOL is not known.
When you add a plugin marketplace from a git URL, Claude Code now validates the URL first and stops with an error if it fails
Unclear What kinds of git address the new check rejects is not settled.
Sandbox allowRead and allowWrite paths re-pointed by a link after setup are now checked again and dropped if unsafe or pointing into a denied path
Unclear How often this situation can arise in normal use is not settled.
Claude now always gets the same instruction for saving memories: save as whichever type fits best, following the memory type and what-not-to-save rules
Removing a computer on claude.ai now shows a shorter message: cloud sessions started here can no longer use this computer
Unclear It is unclear whether file sync itself was removed or only these messages.
When /update refuses because a session came from another project, the message now names that directory and the current one
Before listing or removing git worktrees, Claude Code now confirms the git directory and does nothing if it cannot
The WebFetch refusal for an organization policy that blocks arbitrary web addresses now comes from a shared template starting "Arbitrary-URL egress"
Unclear The full wording of the new message is not given.
The settings description now says allowedProviders, like the other restriction allowlists, is taken whole from the helper and not merged
When a session has reached its file limit, the message now refers to uploaded files, and one failure reason is gone
CLAUDE_CODE_SKIP_AWS_CRED_CACHE#The gateway's Bedrock connection now always uses the AWS credential lookup, even when CLAUDE_CODE_SKIP_AWS_CRED_CACHE is set
Unclear It is not clear which other places still honour the variable.
When a cloud session skips your plugins because its synced folder holds your Claude settings, you now see the generic could-not-check message
When a tool call times out or is cancelled before anything ran, Claude is no longer told it may have partly run
When your organization's policy blocks something because the provider is not allowed, the refusal now says so instead of using the general reason
Unclear It is not clear which command shows this refusal.
New sandbox text says glob, UNC and automount values are ignored, and values re-pointed into a denied read path are dropped
Unclear It is not clear where this text appears or which setting it describes.
Failed plugin enable or disable results now carry the governing scope, whether to disable first, and related dependencies
Unclear What the new step run before enabling or disabling does is not known.
On WSL, Claude Code's check for risky folders now also looks at how drives are mounted, not only at path names
Unclear What difference this makes for someone using Claude Code on WSL is not known.
One of Claude Code's git version checks now passes with git 2.32 or later, where it used to require git 2.41
Unclear It is not clear which feature this version check controls.
The 'new task? /clear' hint after a long idle spell now counts from the latest completed turn, including one that finished elsewhere
Unclear Nothing was found that reports these other turn completions, so this timing may not have any effect yet.
Problems loading a plugin's MCP servers are now gathered into a separate list of warnings
Unclear It is not clear whether or where these warnings are shown to you.
When Claude Code merges structured data, it now drops any key named __proto__
Messages refusing to upload a working tree to the cloud were reworded and split by cause, and now refuse more git setups
Unclear It is unclear which command performs this upload.
A built-in skill that fetches pages from platform.claude.com can no longer be run from a remote or bridged session
Unclear It is not clear which skill this is.
Claude Code now refuses anything but plain files when unpacking a downloaded skill, and stops if it cannot safely leave an entry out
Remote sessions now re-enrol the device and retry for any refusal reason, not only untrusted_device
Unclear Which refusal reasons other than untrusted_device exist is not known.
A git configuration safety check now reads config.worktree as well as config, and flags includes, core.worktree and unreadable files
Unclear It is not clear where this check runs, what happens when it flags something, or what the shared second name case covers.
When the sessions server refuses Remote Control, Claude Code reads the reason and only re-registers the device if it is untrusted
The ctrl+b background hint can now be hidden, and switching models can refresh account data for some models
Unclear It is not clear when the hint is hidden or which models trigger the refresh.
When feedback is switched off, Claude Code now gives a reason it is unavailable instead of returning nothing
Unclear It is not clear how or where the reason is shown to you.
A plugin's hooks are skipped if they share any of several names with a plugin that loads first, not just its main name
Unclear It is not clear which extra names are now compared.
Claude Code now fetches your remote environments page by page, so long lists are no longer cut short after the first request
Unclear The maximum number of pages is not known.
Loading a plugin now collects warnings for its MCP servers that still need configuration
Unclear Where these warnings are shown to the user is not clear.
The notice that plugins cannot use the network is now put together from a shared policy check instead of a fixed sentence
Unclear What the shared check looks at, and the full wording of the new message, are not clear.
The message when Monitor is blocked from opening a live connection for compliance reasons now uses a full stop instead of a colon
Claude Code now sets GIT_TRACE2, GIT_TRACE2_PERF and GIT_TRACE2_EVENT to "0" instead of empty when it runs git
The hint for a wildcard skill deny rule now says it denies every skill rather than every skill tool
Unclear It is not clear which exact rule the hint suggests you use.
Hooks now wait for their output to finish after exiting, and fail with an "output incomplete" message if it was cut off
Unclear It is not clear exactly when Claude Code decides a hook's output was cut off.
When loading a saved conversation, Claude Code now finds the point where it was compacted even when that marker sits far into the line
The request for your account roles during sign-in now stops waiting after 10 seconds instead of waiting indefinitely
When a workflow script leaves a failed agent(), parallel(), pipeline() or workflow() call unhandled, Claude Code logs it and keeps running
Unclear Whether the handler also catches unhandled failures from outside workflow scripts is not settled.
If a local MCP server stalls or exits during connection, Claude Code now restarts it once using the older connection method
Asking to enter plan mode from a subagent is now refused up front with "Only the main session can enter plan mode."
Unclear It is not clear whether subagents can still see the EnterPlanMode tool at all.
When a hook's output stream closes early, Claude Code no longer reads it as a verdict or reports the hook's script as missing
When the GitHub app's status is unknown, Claude Code now asks the server to recheck and explains SSO or IP allowlist blocks
In remote sessions, tracked background tasks are now cleared when the remote worker goes away, when catch-up history is cut short, or on disconnect
A version lookup compared the wrong value and never found the best matching version; it now compares the right one
Unclear Which feature, plugins or something else, uses this version lookup is not stated.
dir/ now match the folder itself#Ignore rules written for folders, such as dir/, now match that folder, because Claude Code checks folders with a trailing slash
Unclear It is not clear which feature uses these ignore rules.
/model in a cloud session waits for the session to be ready#In a cloud session, /model now waits for the cloud session to start before loading models, instead of timing out or falling back
On resume, a turn that stopped at the max-turns limit now counts as complete and is not re-run as if it had been interrupted
Unclear It is not clear exactly what a reader sees differently on resume.
Attaching an artifact that was already attached but dismissed now restores it and reports that it is listed again
Unclear It is not stated what an artifact is here or where the attach action is reached.
A small check that used to read the cloud worker generation number now reads CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL instead
Unclear The variable may already have been read elsewhere in the previous version, so how much this changes in practice is unclear.
When you paste an MCP server's login code manually, Claude Code now records that the code arrived before using it
Unclear Where the received flag is checked, and so whether it prevents failed logins, is not confirmed.
During browser sign-in, Claude Code now records that it received the sign-in code and checks this first when a later reply comes in
Unclear It is not clear what else in Claude Code uses the record that a code was received.
Claude Code now clears its record of what the mouse is over when the pointer moves to a different spot
Unclear Which parts of the interface use hover highlighting is not known.
If starting a monitor is interrupted, Claude Code now cleans up and says the call was interrupted and nothing is running
An error now counts as blocked by the content filter only if the API returned status 400 or no status, not whenever the text appears
A PowerShell hook cancelled while Claude Code looks for PowerShell now ends as cancelled instead of a not-found error
Unclear What pinning project hooks does is not explained.
When Claude Code exits, OpenTelemetry shutdown now flushes and closes one more data source, and a broken reference is fixed
Unclear It is not clear which data source is the one now flushed at shutdown.
Claude Code now runs its own git commands with format.pretty=medium so a custom log format cannot break how it reads the output
A shell command cancelled right before it starts is now cleaned up, and the Bash tool now states time limits for background commands
Telemetry records created before a collector is ready are now held and sent later, up to a limit
Published verbatim by Anthropic for v2.1.285. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 136 bullets, 40 name something an entry on this page also names, 29 name something no entry here does, and 67 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
CLAUDE_CODE_DISABLE_WEB_FETCH environment variable to turn off the WebFetch tool
Probably new-host-env-var-claude-code-host-prompt-supersedes-record-a, new-claude-code-disable-web-fetch-env-var-turns-off-the-webf claude --desktop to open the Claude desktop app on the current directory, or on a session with --continue / --resume <id>
Probably wide-ranging-desktop-option-rejects-subcommands-claude, update-refusal-message-names-the-two-directories, resume-of-a-live-session-now-hands-off-with-a-prompt, new-claude-desktop-launcher-for-claude-desktop, new-desktop-cli-option, resume-picker-now-offers-to-open-a-live-background-session, desktop-flag-rejected-when-combined-with-background-or-wor, resuming-a-live-background-session-can-now-attach-to-it-and claude plugin configure <plugin> to show a plugin's options and which are unset, or save new values read from stdin with --values-stdin
Probably new-claude-plugin-configure-cli-command-with-values-stdi <server>.<key>=<value> to claude plugin install --config, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without visiting /plugin → Configure
Probably hint-for-bundled-mcp-servers-that-need-configuration, config-keyvalue-parser, mcp-server-policy-checks-extended-to-plugin-provided-and-url, plugin-install-config-reaches-bundled-mcp-server-config, new-claude-plugin-configure-cli-command-with-values-stdi, config-accepts-bundled-mcpb-server-fields allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)
Probably managed-policy-read-failure-message, login-screen-honours-allowedproviders-managed-setting, wide-ranging-desktop-option-rejects-subcommands-claude, claude-authenticate-joins-an-in-flight-oauth-flow-and-enfo, managed-settings-helper-merge-doc-allowedproviders-is-a-w, settings-validation-for-allowedproviders, provider-not-allowed-startup-refusal, allowedproviders-managed-setting-restricts-which-api-provide, allowedproviders-policy-enforced-on-login-and-setup-token CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable to cap re-sends of a non-streaming fallback request that timed out
No entry names this claude -p with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result
No entry names this GIT_SSH or in your git config's core.sshCommand
Probably plugin-git-clones-now-read-coresshcommand-and-sshvariant, git-ssh-handling-reworked-for-vetted-clones claude plugin disable and enable with a full name@marketplace id changing a settings entry in another letter case instead of the installed plugin's own
No entry names this set_model request (such as the Agent SDK's setModel) leaving the new model on the built-in output-token limit and auto-compact window until restart
No entry names this @, or all of it when the URL writes its @ as %40
No entry names this /teleport fetches taking over the terminal; these fetches now fail fast instead of asking
No entry names this #96858Worktree fetch leaves ssh reading keystrokes from the terminal Open
-p sessions leaving its tools available
Nothing to match on claude -p --permission-prompt-tool: a background subagent's permission request now goes to the prompt tool instead of being auto-denied
No entry names this claude mcp list and claude mcp get, and the not-found error of claude mcp remove, login and logout, printing line breaks and terminal escape sequences from MCP server names and values
Probably mcp-tool-call-stdio-check-and-secret-masking-in-mcp-get python3 -c, node -e) just because they contain =
No entry names this dontAsk mode: a fork now runs under its parent's permission mode and cannot exit plan mode
No entry names this #95155[BUG] Fork subagent performs write actions despite parent session being in plan mode Open
#95154[BUG] Fork subagent performs write actions despite parent session being in plan mode Closed
claude remote-control --help saying --[no-]chrome defaults to the machine's /chrome setting; spawned sessions keep Claude in Chrome off unless --chrome is passed
Probably sandbox-and-gateway-smaller-changes, headless-cli-argument-classification-list /remote-env reading only the newest 20 of an account's environments
No entry names this claude plugin install or /plugin putting it into an installed plugin's cache or data folder when their ids differ only in ., -, @ or (macOS, Windows) capitals; the install is now refused
Probably hint-for-bundled-mcp-servers-that-need-configuration, mcp-server-policy-checks-extended-to-plugin-provided-and-url, new-claude-plugin-configure-cli-command-with-values-stdi ANTHROPIC_AUTH_TOKEN against the Anthropic API never loading the organization's policy
Probably ssh-placeholder-credential-detection agent(), parallel() or pipeline() call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session
Probably workflow-swallows-unhandled-promise-rejections some-daemon &) kept its output open; the hook now finishes shortly after its own process exits
No entry names this #92934Windows: synchronous command hooks wait for persistent descendants Closed
modelTimeoutException and serviceUnavailableException errors showing a raw JSON body instead of the error message
No entry names this /autofix-pr and /schedule saying the Claude GitHub App is not installed on a repository whose install status had not been checked yet
No entry names this /artifacts unlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it
Probably artifact-publish-tool-prompt-no-longer-lists-artifacts-hint Artifact allow rule ("don't ask again") letting the Artifact tool publish a file outside the working directories without asking; add the file's folder with --add-dir for the rule to cover it
Probably network-permission-dont-ask-again-can-persist-to-user-set /cost and SDK modelUsage reporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected
No entry names this /ultrareview when the project folder briefly could not be read
Probably workflows-disable-setting-description-clarifies-scope /ultrareview on macOS and Linux failing to upload the working tree from a git worktree whose per-worktree config sets core.longpaths
Probably workflows-disable-setting-description-clarifies-scope /ultrareview uploads including uncommitted changes to credential files whose name has a colon before the extension, such as server:8443.key
Probably workflows-disable-setting-description-clarifies-scope /ultrareview uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks
Probably workflows-disable-setting-description-clarifies-scope x or r in NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt
Nothing to match on .mcpb MCP server that still needs configuration: /plugin, the install message and claude plugin install now say so and point to Configure
Probably hint-for-bundled-mcp-servers-that-need-configuration, mcp-server-policy-checks-extended-to-plugin-provided-and-url, new-claude-plugin-configure-cli-command-with-values-stdi #95683[BUG] For marketplace installs the MCP bundle (.mcpb) user_config is never prompted for Open
/ultrareview refusing to upload a checkout on a Linux volume when a changed file's name has a colon or ends in a dot or space
Probably workflows-disable-setting-description-clarifies-scope CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had ended at --max-turns
Probably remote-session-max-turns-is-passed-to-cloud-sessions-and-i, maxturns-validation-for-cloud-sessions-and-attach, headless-resume-of-interrupted-turn-orphaned-task-flush-is, max-turns-reported-as-lost, cloud-session-flag-table-maxturns-no-longer-unsupported-de /ultrareview uploading a linked worktree of a repository rooted at your home folder in some cases
Probably workflows-disable-setting-description-clarifies-scope claude agents to a background session waiting on a permission prompt sometimes approving the pending command
Probably resume-picker-now-offers-to-open-a-live-background-session claude attach, logs, stop, respawn and rm starting a new session with the command name as its prompt when options came before it, such as from a shell alias
Probably resume-picker-now-offers-to-open-a-live-background-session, resuming-a-session-that-is-running-in-the-background-can-ope, resuming-a-live-background-session-can-now-attach-to-it-and claude mcp list leaving out WebSocket (ws) MCP servers; each is now listed with its URL and health status
No entry names this claude mcp get showing no Type, Command, Args, or Environment for stdio servers whose config entry omits the type field
Probably mcp-tool-call-stdio-check-and-secret-masking-in-mcp-get .claude/settings.local.json allow rules being held back outside a git repository when git's trace2 output is configured
No entry names this /claude-api eval runner scaffold and report builder writing through a symlink or hard link planted at an output file
No entry names this /claude-api eval runner scaffold counting responses cut off at max_tokens in the score averages; they are now marked truncated and counted separately
No entry names this showing as literal text in the terminal when a reply uses it to indent text, such as row labels in a markdown table
Nothing to match on /clear or /compact
Probably idle-clear-hint-now-counts-from-other-sessions-turns /btw side question asked of a session hosted by an app such as Claude Desktop now sees the turn in progress, not only the last finished one
No entry names this ping stream event is now sent every 30 seconds on the Anthropic API, Claude Platform on AWS and gateways
Nothing to match on /resume and claude --resume on a session that is running in the background: they now open that session instead of refusing, and a prompt given with claude --resume <id> "prompt" is sent to it as its next turn
Probably update-refusal-message-names-the-two-directories, resume-of-a-live-session-now-hands-off-with-a-prompt, new-claude-desktop-launcher-for-claude-desktop, new-desktop-cli-option, resume-picker-now-offers-to-open-a-live-background-session, resuming-a-live-background-session-can-now-attach-to-it-and _meta['anthropic/alwaysLoad'] to false stays deferred when its --mcp-config, Agent SDK or plugin server is set to alwaysLoad
Probably claude-in-chrome-can-be-served-by-the-remote-session-host-ov, alwaysload-mcp-option-server-tools-can-opt-out-per-tool timeout with run_in_background, default 30 min, max 2 h); Claude is notified when one is stopped
Probably the-bash-tool-description-was-rewritten, the-bash-tool-description-in-the-command-security-review-pro, the-bash-tool-description-in-the-command-team-onboarding-pro, background-shell-commands-get-a-stop-deadline /ultrareview to run when disableWorkflows is on, unless the machine running the review has it set by its own administrator (MDM or the managed-settings file)
Probably workflows-disable-setting-description-clarifies-scope, workflows-kill-switch-claude-code-disable-workflows-and-dis ANTHROPIC_BASE_URL to use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable); run /autocompact 200k if your gateway stops at 200K
No entry names this claude -p and Python Agent SDK sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured, like interactive sessions; --permission-mode still overrides it
No entry names this widgets to be reserved in cloud sessions and on self-hosted runners: your own server under it, or a close spelling such as widgets_, no longer loads, so rename it
No entry names this /ultrareview on macOS and Linux to leave symbolic refs out when uploading a local checkout; a checkout whose current branch is a symbolic ref is now refused with an explanation
Probably workflows-disable-setting-description-clarifies-scope env to no longer set ALLUSERSPROFILE, SystemDrive, or the CommonProgramFiles variables; set them in user or managed settings instead
Probably windows-env-passthrough-list-extended, allusersprofile-added-to-an-env-allowlist-opus-4-max-token /tasks to fold background work Claude Code runs for itself under one "System tasks" row; press Enter on it to show those tasks
Probably background-tasks-dialog-collapses-self-managed-tasks-into-on /ultrareview on macOS and Linux to require git 2.31 or newer to upload a local repository; checkouts made with --separate-git-dir are now refused instead of being uploaded with an older method
Probably workflows-disable-setting-description-clarifies-scope /ultrareview uploads on macOS and Linux to send a partial clone as a working-tree snapshot on git 2.31 or newer, instead of falling back or refusing when git's version looked too old
Probably workflows-disable-setting-description-clarifies-scope /ultrareview uploads on macOS and Linux to refuse, instead of fetching, a partial clone missing some of its working tree's files on older git versions; a clone made without --filter uploads
Probably workflows-disable-setting-description-clarifies-scope claude mcp get to hide the command, arguments, and environment values of stdio MCP servers provided by plugins; variable names are still shown
Probably mcp-tool-call-stdio-check-and-secret-masking-in-mcp-get /claude-api so it can no longer be run from Remote Control clients
No entry names this /config chrome=true to direct you to the /config panel instead of enabling Claude in Chrome by default; /config chrome=false still turns it off when it was on
No entry names this CLAUDE_CODE_RESUME_INTERRUPTED_TURN set, even with Continue After Reload off
Probably headless-resume-of-interrupted-turn-orphaned-task-flush-is CLAUDE_CODE_SUBAGENT_MODEL_FORCE or an agent's own model)
No entry names this .claude/settings.json turns on
Probably project-settings-can-no-longer-set-some-keys MCP_DISCOVERY_CACHE=1, when set in your cloud environment's variables rather than a settings file, to reuse your connectors' tool lists after a session restart; other MCP servers are no longer cached and connect at startup
Probably mcp-discovery-cache-for-ccr-dynamic-http-servers A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 1 line added.
Claude Code, interactive mode
442 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 87 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?