An internal check became a simple remote on/off switch#
An internal check that used to be looked up on the fly is now a plain remote switch that falls back to off
Unclear It is unclear what parts of Claude Code depend on this check.
You can now hold project settings changes made from a cloud session until you approve them, by running claude apply-project-settings in that folder. This applies when your computer serves the cloud session. Admins can force unattended serving off through managed settings with unattended_serving_off. Resumed sessions no longer keep the prompt cache warm unless the new resumeTouches setting is on. Claude Code's own stand-in for gh, added last release, can now reach any GitHub Enterprise host when ghesHosts is set to "any". Host apps can block file writes in chosen folders, except inside one declared worktree.
A /restart command that keeps your session is in this build but not switched on yet. It also answers to /update and offers newer versions. A shortcut that answers some artifact edit requests with direct file edits is also off for now. Cloud sessions can hand finished file writes to the next turn's worker, but only once that is switched on remotely. A setup guide feature is wired into the prompt box but does nothing yet.
An oversized reply from an MCP server over HTTP now fails only that request and keeps the connection open. Language server requests now time out instead of waiting forever. Reads and rewrites of a session transcript now wait for each other, so compaction and resume cannot clash. Resumed teammates no longer bring back an agent type that a rule or plugin now blocks. The Read tool instructions no longer include the guidance on PDF page ranges.
Written by our agent from the shipped bundle, not by Anthropic.
claude mcp serve lists agent types and blocks background agents in restricted modeclaude mcp serve now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
When your computer serves a cloud session, changed project settings are held back until claude apply-project-settings, and user settings can only tighten
Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
ElsewherePlugins get a new ui.selection operation, and http.fetch and URL audio playback now use a plugin storage id, with $.audio.play refusing URLs without one
ExtensionsCLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns off structured outputsSetting CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS stops Claude Code from asking the model for replies in a fixed format
Want the reasoning? Read walks the 31 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →2 more of these are in What probably matters to you, on page 1.
An internal check that used to be looked up on the fly is now a plain remote switch that falls back to off
Unclear It is unclear what parts of Claude Code depend on this check.
One check now reads its remote switch under a fixed name and still falls back to on when the server sends nothing
Unclear Whether the switch read before was the same one is not known.
Claude Code now keeps a separate set of network connections per key instead of one shared set that any caller could replace
Unclear What the key is and which parts of Claude Code pass one is not known.
Claude Code can now label each approval of a tool call as coming from a person, a classifier, a mode or a hook
Unclear What the related flag actually controls is not known.
When a tool call fails, Claude Code can pass its input and error text to a new handling step, and tool calls now record their permission
Unclear What the new handling step does with the error text, and what condition switches it on, are not established.
The folder trust check for the checkout a session starts from now tests that checkout's root folder and sends which parts it covers
Unclear What this check is for and whether anything holds it back are not stated.
Claude Code's matching of permission rules against shell command patterns changes and may affect commands joined together
Unclear It is not clear which permission checks use the new matching or whether any rule now matches differently.
The Anthropic SDK bundled in Claude Code can now add or remove tools mid-run and tells the model when the tool list changes
Unclear It is not clear whether Claude Code itself uses the new add and remove methods.
Messages from the SDK can now include an optional tag that marks lines a host app may treat specially; hosts ignore tags they do not know
Unclear It is not known which tag values Claude Code actually sends.
A handful of small additions appear, among them a message ID shown in a send tool's result and a new color in the theme
Unclear What reads these new values, and whether any of them is switched off behind a setting, is not known.
When a program restarts a session through the SDK, the check deciding whether to turn on prompt suggestions now runs through a shared helper
Unclear It is not known whether the helper still reads the same remote setting or what it falls back to.
Claude Code now records more detail about how it prepares a compaction, plus a new report when one part of it overflows
Unclear What makes the compaction classifier overflow is not shown.
When resuming an old session, Claude Code now checks a ready-made summary against the last message it covers
Unclear How the prepared summary's record of what it covers has changed is not known.
The Code display element no longer requires its content to be a diff, and compaction gains five more specific reasons for falling back
Unclear What the added compaction reasons are used for is not stated.
When you send a message, Claude Code now gathers a set of facts about the model and passes them into that turn
Unclear It is not clear what facts about the model are gathered, or what the new marking of start-of-turn messages does.
Claude Code now keeps a list of the older Claude 3 models and a check for whether the current model is outside it
Unclear What part of Claude Code uses this check, and so whether anything behaves differently on these models, is not stated.
When the API says a model is not found or not available for your account, the model check now marks it as refused by the server
Unclear It is not clear what Claude Code does differently once a model is marked as refused.
Claude Code now sorts some control messages as interface requests and better explains when a button press was not handled
Unclear How these messages are reached and whether anything uses them yet is not known.
Claude Code can now check each code block in displayed content, drop its formatting if refused and report the problem
Unclear It is unclear where this check is used and whether it is active.
Claude Code gains messages noting that a code block is shown as plain code because it is not in a diff format
Unclear It is not clear where these messages are shown.
A remote switch can make Claude Code wait a short, limited time for some data before each model request
Unclear What data Claude Code waits for is not shown.
Before sending a conversation to Claude, Claude Code can now fold some text together and can send poll events as plain text
Unclear What turns on sending poll events as text, and what poll events are here, is not known.
Messages passed between agents can now be wrapped in a different way when they are marked as a whole message
Unclear It is unclear what the different wrapping does and when it is used.
When Claude Code starts a teammate agent, it now uses the definition sent with the request instead of looking it up by type
Unclear It is not clear where the definition sent with the request comes from.
The review prompt's cap on how many findings to report is now worked out from a value instead of being fixed at four
Unclear What sets the new limit, and what values it can take, is not shown.
The review prompt can now include a stated cap on the number of findings, and usage data records whether a cap was set and its value
Unclear It is not clear how you state the limit or where Claude Code reads it from.
Whether the Read tool's description mentions PDFs now depends on a check made for each request, though the captured text is unchanged
Unclear It is unclear what the new check looks at to decide whether the PDF sentence is shown.
Claude Code now uses a different method to treat Windows line endings when it computes a file's fingerprint
Unclear It has not been confirmed that the new method always gives exactly the same fingerprint.
When a subagent is stopped, killed or fails, Claude Code now clears its waiting items and records why they were removed
Unclear What Claude Code does with the reason it records is not established.
The text telling Claude where to find the list of agent types was reorganised internally, and the captured Agent description reads the same
When Claude searches for tools, Claude Code can now read tool names from full tool definitions as well as from tool references
Unclear What produces these full tool definition entries is not known.
If the main conversation has already asked for deferred tools, Claude Code now waits for that request instead of dropping the pending list
Unclear It is not clear what difference this timing change makes to what a user sees.
Claude Code no longer has its separate step that ran ConfigChange hooks and then reloaded a changed settings file
Unclear It is not clear whether another path now does this reapplying.
The instructions Claude gets for opening files dropped the paragraph about reading PDFs and asking for page ranges on large ones
Unclear The prompt ledger records the longest Read description as unchanged in this release, so it is unclear which model's instructions lost the paragraph.
Published verbatim by Anthropic for v2.1.288. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 89 bullets, 18 name something an entry on this page also names, 29 name something no entry here does, and 42 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
$.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
No entry names this gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
Probably built-in-gh-agent-proxy-now-supports-any-github-enterprise, gh-shim-refusal-message-is-now-more-explicit, built-in-gh-api-client-prompt-text-added-with-no-in-bundle --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
Probably review-arg-parser-adds-max-findings --resume sometimes dropping files and other context that a compaction had just restored
No entry names this --resume showed the prompt unanswered
No entry names this CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off
Probably new-env-var-claude-code-disable-structured-outputs-turns-off sonnet subagent
Nothing to match on Code element held a diff that does not parse; it now draws as plain code
Probably signed-cache-cert-check-reports-hours-left-instead-of-days, updater-status-text-and-failure-hints ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults
Probably plugin-user-config-substitution-can-leave-unset-keys-li, plugin-lsp-config-expands-variables-inside-initializationopt #95801[BUG] Plugin userConfig template ${user_config.X} not substituted in lspServers initializationOptions Open
tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree
No entry names this #92533Any function-hook tool.call on Bash breaks Agent isolation: "worktree" — every Bash call refused with "isolation context for this agent was lost" Open
git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)
No entry names this #98629[BUG] Plugin install fails for git-subdir sources since 2.1.274: "git checkout after sparse-checkout failed … index.lock: File exists" Open
--plugin-dir not showing "Configure options" in /plugin
Probably plugin-user-config-substitution-can-leave-unset-keys-li, cloud-hooks-dialog-gets-plugin-hook-note-and-consent-summary python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references
Probably new-guard-prompts-on-rm-hidden-inside-sh-c-scripts-wit BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently
No entry names this claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals
No entry names this -p or on an interrupted turn, emitting no tool_decision event
No entry names this /compact even though its history was still saved
No entry names this CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts
No entry names this /login reporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (anthropics/claude-code#73861)
Probably bare-mode-login-now-refuses-with-explanation, login-shows-a-dedicated-screen-when-credentials-cannot-be-sa #95425/login reports "Login successful" but token is never saved: ENOTDIR rmdir on stale .storage-write.lock file (2.1.277) Open
#89801TUI /login reports success but never persists credentials — Keychain timeout classified as transient skips the file fallback Open
#86616macOS login keychain corrupted twice in 3 days (CSSMERR_CSP_INVALID_DATA); corruption timing matches Claude Code credential writes under ~20 concurrent instances Open
#95386[BUG] macOS: "Keychain is not writable" reported while security add-generic-password succeeds; login never persists (v2.1.276) Open
gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in
No entry names this -p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it
Nothing to match on memory
Nothing to match on #98546Desktop-hosted sessions: subagents receive none of the tools of a user MCP server named `memory` (misclassified as account memory server, since 2.1.284) Open
disableAutoMode or an older model); typing, navigation and JavaScript still ask
Probably auto-mode-off-explanation-text-for-permission-prompts claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice
No entry names this sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on
No entry names this /tui)
No entry names this tools: lists very many Agent(...) entries
No entry names this claude stub was installed
Nothing to match on #95297[BUG] `claude upgrade` reports success but leaves `bin/claude.exe` as the fallback stub — native binary not linked Open
#88105[BUG] Auto-update to 2.1.237 leaves broken stub on Windows: [email protected] missing from npm registry (incomplete release) Open
#96265[Windows] claude update (npm global) reports success but leaves 500-byte placeholder claude.exe: 'not a valid application for this OS platform' Open
#85974[Bug] Auto-update reports success with non-functional stub binary after postinstall link failure Duplicate
#85975[Bug] Auto-update reports success with non-functional stub binary after postinstall link failure Duplicate
owner/repo plugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top
No entry names this #96811Plugin marketplace update/refresh forces HTTPS and fails even when the existing clone works fine over SSH Closed
.claude/rules and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)
No entry names this #96361[BUG] Path-scoped rules and nested CLAUDE.md never load when Write creates a new file Open
#93248[FEATURE] `paths:` frontmatter on rules and skills triggers on reads only, so neither loads when Claude creates a file Open
rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule (anthropics/claude-code#96300)
Probably inline-sh-cbash-c-rm-commands-now-get-a-dangerous-rem, new-guard-prompts-on-rm-hidden-inside-sh-c-scripts-wit #96300Dangerous-rm check does not look inside `sh -c` / `bash -c` Closed
requestTimeout)
Probably lsp-requests-get-a-timeout-and-telemetry-workspace-file-wat, lsp-servers-get-a-configurable-per-request-timeout-default #96044LSP client answers client/registerCapability with -32601, wedging servers that use dynamic registration (and no per-request timeout) Closed
idle_prompt notification hooks firing while background agents are still running (anthropics/claude-code#93672)
No entry names this #98373[BUG] idle_prompt "Claude is waiting for your input" fires while background agents/tasks are still running Open
#93672[BUG] Notification idle_prompt fires while background subagents are still running Closed
/login in a --bare session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work
Probably bare-mode-login-now-refuses-with-explanation, login-shows-a-dedicated-screen-when-credentials-cannot-be-sa claude mcp serve always reporting no available agents and rejecting every subagent_type
Probably mcp-serve-honours-strict-mcp-config, per-agent-type-listing-and-subagent-definitions-in-claude-m /theme's custom color search
No entry names this /permissions in screen reader mode: typing a rule's number now picks it instead of opening the search box
No entry names this /usage-credits message shown to Team and Enterprise members whose organization has turned off usage credit requests
No entry names this alwaysLoad: false
No entry names this gh api: a refused gh command now prints its gh api equivalent, --paginate follows every page of a repository's lists, and a nested claude no longer removes it
Probably built-in-gh-agent-proxy-now-supports-any-github-enterprise, gh-shim-refusal-message-is-now-more-explicit, built-in-gh-api-client-prompt-text-added-with-no-in-bundle -p, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit
Nothing to match on ANTHROPIC_DEFAULT_SONNET_MODEL pin that names Claude Sonnet 5.5 or Opus 5.5 and use Claude Sonnet 5 instead
Probably auto-mode-classifier-ignores-anthropic-default-sonnet-model claude project purge to claude purge; the old name still works and prints a notice
Probably claude-project-purge-moved-to-top-level-claude-purge-ol n: filter (and Ctrl+F search) so Enter opens the session whose name matches best instead of the top row
Nothing to match on /autocompact to save the auto-compact window per model, so each model keeps its own setting when you switch
Probably per-model-autocompactwindow-setting claude plugin test reporting mods as turned off remotely when it had only read an out-of-date saved setting
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
2 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 1 line added, 1 line removed.
Claude Code, interactive mode
2 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
731 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 63 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?