New /restart command keeps your session and refuses remote or non-typed use#
A /restart command (alias /update) restarts Claude Code, keeps the session and offers a newer version, but only when typed by you at the prompt
You can now hold project settings changes made from a cloud session until you approve them, by running claude apply-project-settings in that folder. This applies when your computer serves the cloud session. Admins can force unattended serving off through managed settings with unattended_serving_off. Resumed sessions no longer keep the prompt cache warm unless the new resumeTouches setting is on. Claude Code's own stand-in for gh, added last release, can now reach any GitHub Enterprise host when ghesHosts is set to "any". Host apps can block file writes in chosen folders, except inside one declared worktree.
A /restart command that keeps your session is in this build but not switched on yet. It also answers to /update and offers newer versions. A shortcut that answers some artifact edit requests with direct file edits is also off for now. Cloud sessions can hand finished file writes to the next turn's worker, but only once that is switched on remotely. A setup guide feature is wired into the prompt box but does nothing yet.
An oversized reply from an MCP server over HTTP now fails only that request and keeps the connection open. Language server requests now time out instead of waiting forever. Reads and rewrites of a session transcript now wait for each other, so compaction and resume cannot clash. Resumed teammates no longer bring back an agent type that a rule or plugin now blocks. The Read tool instructions no longer include the guidance on PDF page ranges.
Written by our agent from the shipped bundle, not by Anthropic.
An rm hidden in a bash -c script with a run-time target now needs explicit approval, with CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT to turn it off
When your computer serves a cloud session, changed project settings are held back until claude apply-project-settings, and user settings can only tighten
Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
Tools & outputclaude mcp serve lists agent types and blocks background agents in restricted modeclaude mcp serve now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
The agents fleet view adds find and jump-between-groups actions, and its keys, including rename and set group, can now be rebound
Sessions & agentsWant the reasoning? Read walks the 53 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →Anything you can use today, anything that visibly changes, and anything worth poking at. One line each, open for detail.
A /restart command (alias /update) restarts Claude Code, keeps the session and offers a newer version, but only when typed by you at the prompt
Claude Code has a new remotely controlled switch, off unless turned on, with a check for an "arbiter" permission mode beside it
Unclear It is not clear what the switch controls, where the arbiter check is used, or what "arbiter" mode is.
Built but off unless enabled remotely: a shortcut that answers some artifact edit requests with direct file edits instead of a model reply
Unclear It is not clear where in Claude Code this shortcut is wired in.
A turn handoff can now carry answered Write calls to a cloud worker, which writes those files into the home folder before the turn continues
Unclear It is not clear how the new worker learns about and receives the carried writes from end to end.
An rm hidden in a bash -c script with a run-time target now needs explicit approval, with CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT to turn it off
Unclear What this variable controls, and whether any rm prompt for inline shell commands is on by default, is not established.
When your computer serves a cloud session, changed project settings are held back until claude apply-project-settings, and user settings can only tighten
Unclear Where the claude apply-project-settings command itself is defined could not be confirmed, only the messages that point to it.
Hooks for a setup-guide paste and link feature are in place, including a wider pasted-text chip match, but they do nothing in this build
Unclear It is not clear what the missing part is or which build would include it.
Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
Unclear Which host application sets these variables is not shown.
claude mcp serve lists agent types and blocks background agents in restricted mode#claude mcp serve now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
Unclear It is not clear exactly which connection types count as the restricted HTTP mode.
Plugins get a new ui.selection operation, and http.fetch and URL audio playback now use a plugin storage id, with $.audio.play refusing URLs without one
Unclear It is not clear what ui.selection returns, or whether the extra check on signed-in requests is always on.
The agents fleet view adds find and jump-between-groups actions, and its keys, including rename and set group, can now be rebound
Unclear The default key for agents:setGroup is not listed, so it may no longer be ctrl+e.
The description Claude reads about what artifacts can do now mentions the viewer's camera, microphone, location, screen and device motion
Unclear It is not clear whether artifacts are actually given access to these features.
The tool that publishes HTML pages to claude.ai now tells Claude to publish when a page beats text or work is for others, even unasked
Unclear It is not clear whether the publishing tool is available to everyone or switched on only for some accounts.
Claude Code now has a confirmation dialog for writing account memory everywhere, alongside its existing account memory permission prompt
Unclear It is not clear when this dialog appears or whether it is switched off unless enabled remotely.
Claude Code can now edit an HTML artifact you own in one quick request, and hands the job back when the page is shared, too large or would prompt
Unclear It is not clear what starts this quick edit or whether it is switched on for everyone.
The remoteAgentIsolationDisabled setting now turns off remote isolation, alongside the existing CLAUDE_CODE_REMOTE check
Unclear It is not fully settled that this check is the one controlling remote isolation for subagents.
Claude Code now handles an "MCP tool listing" content block alongside MCP tool calls and results
Unclear It is not clear whether the model sends this block type yet.
Plugins that use function hooks gain a new request type, called ui_surface, that Claude Code forwards on
Unclear What this request shows, and whether it is switched on, is not established.
Setting CLAUDE_CODE_GROWTHBOOK_KICK_ON_WARM_CACHE makes non-interactive runs refresh feature flags early even with a saved copy
Unclear It is not clear exactly what the early refresh changes later in the run.
Two environment variables control holding screen-reader announcements, for up to 10 seconds, and rewriting held ones, which is off by default
Unclear Where these announcements are held, and whether another setting must also be on, is not shown.
The built-in gh used in proxied and cloud sessions now handles any GitHub Enterprise host, suggests gh api equivalents and gives clearer errors and help
Unclear Which sessions use the built-in gh, and how the any-host mode is turned on, is not shown.
Claude's environment details gain a githubCli entry, the model is told when built-in gh goes away, and the gh stand-in can reach any GitHub host
Unclear It is not clear what sets ghesHosts to "any".
Resumed sessions can keep the 1-hour prompt cache warm on a timer, but only when server config sets resumeTouches
Unclear It is not clear where resumeTouches is set or whether you can change it yourself.
New cloud sessions now get their permission mode from --permission-mode, may start in auto mode by default, and weigh your carried mode when deciding
Unclear Only the message wording changed in what was seen, so it is not confirmed that cloud sessions now apply the mode from the flag.
A remote switch can add guidance on files and folders on your computer to the browser and computer-use tool descriptions
Unclear It is not certain that the device-files guidance switch is new in this release.
Claude Code now sorts some control messages as interface requests and better explains when a button press was not handled
Unclear How these messages are reached and whether anything uses them yet is not known.
Claude Code recognises a new mcp_tasks_changed message that only the service may send to cloud agents; programs hosting Claude Code are refused
Unclear What Claude Code does on receiving this message, and who sends it, were not established.
autoCompactWindow can now hold a different value for each model, and /autocompact and /config show and save it for the current model
Unclear It is not shown whether the top-level setting was already read in the same way before.
requestTimeout#Requests to LSP language servers now give up after 60000 ms by default, which an LSP server's requestTimeout setting can change
Unclear Whether requests already waited 60000 milliseconds before this change, so that the default is unchanged, is not established.
Managed settings can now force unattended serving off with unattended_serving_off, and auto_mode_off reports it as turned off by settings
Unclear Where these settings keys are defined, and exactly what unattended serving covers, is not confirmed.
The activity keep-alive settings now include a resumeTouches option, which is off unless set otherwise
Unclear It is not clear what turning this option on does or where it is set.
Plugins gain a way to fetch a URL, and Claude Code refuses to restart itself unless you type /restart
Unclear Whether either change is switched on or limited by a setting is not clear.
A session can now take on a starting permission mode it was handed even when it is not a remote session, if an option asks for it
Unclear It is not clear what sets this option or whether a reader can set it.
When a conversation is too long for auto mode's safety check, Claude Code can now compact it and tell Claude to retry the action afterwards
Unclear What decides whether Claude Code asks for compaction, rather than only blocking, is not settled.
CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns off structured outputs#Setting CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS stops Claude Code from asking the model for replies in a fixed format
Unclear It is not clear which models the new support check excludes.
The code review command accepts --max-findings <n>, all or default, and remembers your choice for later reviews
Unclear It does not say which review command, by name, gains this option.
Two new keyboard shortcut actions, chat:increaseEffort and chat:decreaseEffort, step the effort level up or down
Unclear It is not clear whether these actions have keys assigned by default or are held back behind a switch.
On Linux, setting CLAUDE_CODE_CONFIG_WATCH_EVENTS makes Claude Code spot config file changes through system change events
A new error says no hooks module loads in a claude-code-server tenant, because that process serves many people
Unclear It is not clear when the new error is shown, or whether moving the deny-rule check changed how blocked tools are handled.
Remote sessions have new named setup steps for repository agents, skills, root registration, switches and flag prefetching
Unclear What uses these step names and what they do for a session is not established.
In remote sessions using the agent proxy, certificate checks accept swapped order and the gh stand-in now lives in each session's own folder
Unclear What CCR_AGENT_PROXY_CA_WATCH_ENABLED turns on is not shown.
Log batches sent to Datadog can now be gzip-compressed, falling back to uncompressed if Datadog refuses one
Unclear Whether compression is on by default when the environment variable is not set is not established.
Clearing the prompt box with Ctrl+C now keeps the text, and pressing Up while the box is empty restores it
Unclear The exact situations in which Ctrl+C keeps the text, and how long it is kept, are not known.
The rule for turning on fleet view's simple mode is unchanged, but the way that code looks up keyboard shortcuts changed
Unclear It is not clear what the new keyboard shortcut lookup returns or whether shortcuts behave differently.
/artifacts, and usage-limit notices can mention a paused workflow#Choosing the frame item in the footer now runs /artifacts, and usage-limit notices have room for a paused-workflow message
Unclear It is not clear what the paused-workflow entry says, or how the footer's handling of /artifacts differs from before.
claude project purge is now claude purge#The purge command moved from claude project purge to claude purge; the old name still works but prints a deprecation notice
/teleport in a cloud session now tells you how to continue locally#Typing /teleport or /tp in a cloud session now shows the claude --teleport command to run on your own machine
The menu for a single plugin now lists Update now and a red Uninstall option, so you can manage the plugin from there
Unclear Some kinds of plugin may not show these options.
Variables in a plugin language server's initializationOptions and settings are now filled in, and an empty command gets a clear error
OpenTelemetry logging of raw API bodies can now record that a body was withheld instead of logging it, and filters bodies through an account memory step
Unclear It is not clear what causes a body to be withheld, or what the account memory step does to the logged bodies.
claude mcp serve now takes --strict-mcp-config into account#Running claude mcp serve now passes the --strict-mcp-config option along before the server starts
Unclear How the recorded value is used afterwards was not checked.
With CLAUDE_CODE_ACCESSIBILITY set, announcement lines are held for a while across redraws and placed after the main content
Unclear How long announcements are held is not known.
With claude --cloud, notices about hooks held back are shorter and give a cause, with a warning when a changed guard hook blocks tool calls
Unclear It is not known whether this applies to every user of claude --cloud.
What would fix it?
Smaller changes and internals, grouped as the pipeline found them. Nothing is dropped, it is only further down.
16 more of these are in What probably matters to you, above.
Idle background subagents now wake for more queued items, can wake only to deliver results, and are dropped after repeated failed resumes
Unclear Part of the new wake-up path may not run yet, and it is not clear what decides the extra cases that trigger a check.
When this computer serves a cloud session with no one at the terminal, the launch folder's local settings and hooks are skipped and you are told why
Unclear What puts Claude Code into this served-session mode is not shown.
Stopping or rewinding a remote session turn now properly ends the turn and clears a message that was being held back, instead of leaving it stuck
Unclear What sets a session up to retire parked requests on stop is not established.
A pasted team setup guide now appears as a short placeholder, the same way long pasted text does
Unclear Whether the team setup guide feature is available yet, and what triggers it, is not clear.
Login now warns when your credentials could not be saved instead of claiming success, names the storage used, and can let you continue without logging in
Unclear It is not clear where this message appears.
Plugin installs and marketplace clones now retry over the other git transport, HTTPS or SSH, when the first fails, and report both errors
Unclear It is not clear what the gitHubHttpsFallback option does when installing a plugin.
The code review prompt can now keep every finding with no limit, or have results reported through a tool call
Unclear It is not clear what decides which version or which limit a review uses.
ScheduleWakeup is loaded up front and steered toward self-paced /loop#The ScheduleWakeup tool is no longer deferred, so Claude has it from the start, and it gains guidance for /loop runs with no interval
Unclear The tool may be switched on or off elsewhere, so it is not settled that every session has it.
Headless sessions can skip waiting for MCP servers the conversation doesn't need, and no longer defer servers added after the first request
Unclear It is not clear which mode or setting turns this skipping on.
Results from the database write tool now report warnings and embedded data after the usage figures, for single and batch writes
Unclear It is not clear what the embedded part contains, or whether the change is available to everyone.
In remote sessions, a project hook that changed after you approved it is now held until you give permission again
Unclear The exact wording you see when asked again, and whether this is switched on for everyone, is not clear.
When the API refuses an image or PDF, Claude Code now drops it from later requests and reports a media_removed error that explains why
Served sessions gain a mode where a project hook that changed since attaching is set aside or run as recorded, not always held
Unclear What switches this mode on is not known.
Claude Code can warn you when the combined size of your CLAUDE.md instruction files goes over the limit, showing the size and the limit
Unclear What the further environment check looks at is not known.
Claude Code can decide to reuse an earlier compaction summary, and refuses when, for example, the result would not fit
Unclear What triggers this reuse, and whether it is switched on, is not stated.
The auto-update notice can now show restart wording such as "/restart to apply" or "Restart to update", fetched from a remote configuration
Unclear It is not clear whether /restart exists as a command you can run, or what condition chooses between the two wordings.
In a diskless session, Claude Code now refuses to attach or upload local files and reports an error instead
Unclear It is not clear which sessions count as diskless.
When a too-large artifact document contains encoded file data, Claude is now told to upload the file instead
Tool calls served to a remote session are cancelled when that session is no longer served, and broken project hooks are tracked
Unclear It is not clear what switches this behaviour on or what its defaults are.
Claude's artifact instructions now allow device features such as motion sensors only when you have that capability and the page declares it
Activity passed in from a linked conversation is now labelled as not a new message from a person and never approval for a prompt
Unclear It is not clear which feature links conversations in this way.
When an action is blocked, the hint about adding a permission rule now names the actual tool instead of always saying Bash, and is left out where it does not apply
Unclear The wording of the message that uses this is not shown.
Skills from MCP servers and memory stores, and plugin agents, now have their frontmatter read with limits and are skipped or refused if it can't be read
Unclear It is not clear what reading a header as untrusted changes beyond skipping skills whose header fails.
When an MCP server asks you to finish something in a browser, the dialog now offers Open in browser, I'm done, continue and Decline
Unclear It is not clear which MCP requests use the new layout and which still use the old two-button one.
The Remote Control bridge now records when its environment secret expires and can re-register early to renew it; stop messages are reworked
Unclear What starts an early re-registration, and what sets the separate check-in interval, is not established.
The hosted model catalog can now name a minimum Claude Code version that older builds skip, and failed first cloud messages now give a clearer reason
Unclear Whether any model list currently sets a minimum version is not established.
When a model cannot accept a whole PDF, Claude is now told to read specific pages with the Read tool's pages option instead of retrying
Unclear Which models trigger this message is not stated.
Files on network paths are no longer auto-approved, and served sessions refuse edits to settings files, with clearer reasons in the prompt
Unclear It is not clear when a session counts as served or exactly what you see when an edit is refused.
The dialog an MCP server uses to ask you for input can now be told you will confirm when you are done, and can check whether an answer would be taken
Unclear It is not established whether this dialog is linked to the step-up sign-in setting for MCP servers whose default changed.
The Code tab in Claude Desktop now gets a warning when your CLAUDE.md and rules files together exceed the recommended size
Unclear The recommended size limit itself is not stated.
Auto mode can now decide Claude in Chrome actions from grant rules without its safety check, and allows read-only calls the server skipped
Unclear It is not clear what turns on the option that skips the classifier for Claude in Chrome.
Claude Code now checks each MCP server sign-in response for a missing-permission answer and returns the server's real response
Unclear It is not shown where the step-up dialog switch is read, so the link between this change and that dialog is unconfirmed.
The dialog for MCP servers that ask you to sign in again with extra permissions now falls back to on when the server sends no setting
Unclear It is not clear what the second remote switch, now read where the old one was, controls.
New messages explain that an action is allowed but Claude still asks, because auto mode is unavailable, and say why
Unclear It is not clear when or where these messages appear.
Claude Code now watches for a changed security certificate, updates the system and tool trust stores, and retries installs that do not take
Unclear It is not clear whether some of this certificate handling already existed in an earlier form.
When a hold is on, tools and instructions from an MCP server that is reconnecting are not announced as gone, and are re-announced if they return
Unclear What turns the hold on is not known.
Remote Control now renews this computer's credential before it expires, instead of only after a connection is rejected
Unclear Renewal depends on an expiry time from the server, and what sets it is not known.
The hooks panel now lists this machine's hooks, says whether each runs in the cloud session, and shows your consent status
Unclear It is not clear what setting or condition makes this panel appear.
API timeout errors are now classified as timedOut instead of serverError, and are retried or sent to a fallback model rather than failing
Unclear It is not clear what this handling actually does, for example whether it retries the request or skips a fallback.
When Claude Code can't find a task you ask it to stop, the error may now name the host tool that owns it
Unclear It is not clear when the host-tool lookup is on or what the "needs" part of the message names.
rewind_conversation now waits for a stopping turn to settle and refuses when the messages it would cut are no longer on disk
Unclear What the Send-now interruption mark changes for a user is not known.
For remote background commands, Claude is now told a command is over when its output file ends with an exit or stop line
Unclear It is not confirmed that the remote host actually writes these closing lines.
When a cloud session setting change is not confirmed, Claude Code rereads and retries it, and reports not_stored if it did not stick
Claude Code now keeps track of text you select across full-screen terminal views and notes when a selection is cleared
Unclear It is not clear what this tracking is for or whether readers will see any difference.
Remote sessions can now say a permission request was withdrawn because nobody answered it in time, and a --any-host flag appears
Unclear It is not clear which commands accept --any-host or --gh-standin, or what they do.
Claude Code now defers a second set of tools, keeping their details out until tool search finds them
Unclear It is not clear which tools are on the new list.
With OTEL_LOG_USER_PROMPTS on, logged prompts, outputs and tool data are now scrubbed of account memory text
Unclear Exactly what the cleaning step removes beyond account memory text is not shown.
Anthropic has not published official notes for v2.1.288 yet. This section updates automatically when the entry appears in the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
2 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 1 line added, 1 line removed.
Claude Code, interactive mode
2 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
698 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 67 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?