Local settings file is now described as this folder's, not this checkout's#
Messages about the local settings file now say "this folder's settings.local.json" instead of "this checkout's settings.local.json"
You can now hold project settings changes made from a cloud session until you approve them, by running claude apply-project-settings in that folder. This applies when your computer serves the cloud session. Admins can force unattended serving off through managed settings with unattended_serving_off. Resumed sessions no longer keep the prompt cache warm unless the new resumeTouches setting is on. Claude Code's own stand-in for gh, added last release, can now reach any GitHub Enterprise host when ghesHosts is set to "any". Host apps can block file writes in chosen folders, except inside one declared worktree.
A /restart command that keeps your session is in this build but not switched on yet. It also answers to /update and offers newer versions. A shortcut that answers some artifact edit requests with direct file edits is also off for now. Cloud sessions can hand finished file writes to the next turn's worker, but only once that is switched on remotely. A setup guide feature is wired into the prompt box but does nothing yet.
An oversized reply from an MCP server over HTTP now fails only that request and keeps the connection open. Language server requests now time out instead of waiting forever. Reads and rewrites of a session transcript now wait for each other, so compaction and resume cannot clash. Resumed teammates no longer bring back an agent type that a rule or plugin now blocks. The Read tool instructions no longer include the guidance on PDF page ranges.
Written by our agent from the shipped bundle, not by Anthropic.
An rm hidden in a bash -c script with a run-time target now needs explicit approval, with CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT to turn it off
When your computer serves a cloud session, changed project settings are held back until claude apply-project-settings, and user settings can only tighten
Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
Tools & outputclaude mcp serve lists agent types and blocks background agents in restricted modeclaude mcp serve now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
The agents fleet view adds find and jump-between-groups actions, and its keys, including rename and set group, can now be rebound
Sessions & agentsWant the reasoning? Read walks the 53 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →16 more of these are in What probably matters to you, on page 1.
Messages about the local settings file now say "this folder's settings.local.json" instead of "this checkout's settings.local.json"
Messages about combining two options that both pick a remote backend no longer start with "Error: " in their text
Unclear It is not clear whether "Error: " is now added elsewhere, so the message you see may look the same.
The reason Claude Code gives for not treating an awk command as safe is shorter and no longer mentions an option hiding its program
Unclear What Claude Code does with the new record of whether a command contains a loop is not known.
When a hook errors without blocking, Claude Code now says it "gave no verdict" instead of "could not render a verdict"
The Interrupted message now leaves off its trailing hint when a particular internal condition holds
Unclear It is not clear what condition decides whether the hint is shown.
2 more of these are in What probably matters to you, on page 1.
An MCP server response that is too large now fails only that request, and malformed messages after a login challenge get their own close reason
Unclear It is not clear whether the legacy SSE fallback switch plays any part in these changes.
On resume, a teammate's custom agent type is not restored if a rule or plugin now excludes it, and it gets only basic tools
Claude Code now makes reads and rewrites of a session transcript wait for each other, so compaction and resume can't clash
If the message you gave on the command line fails to send to a cloud session, its text is now put back into the input box
Claude Code now loads a plugin's agent definition before starting it as a teammate or subagent, and gives a clear error if it cannot
Claude Code now waits for one save of the conversation history to finish before the next, so overlapping saves can't split it
Unclear What a split history looked like to someone using Claude Code is not known.
In print/SDK sessions, a launch model the server refuses is now discarded if no turn has been sent yet, and the drop is recorded
Unclear It is not clear which model the session uses instead once the refused one is dropped.
When processes share login credentials, a refresh lock held by a live process no longer counts as stale after a fixed 60 seconds
Unclear The exact waiting time used when the holder is not proven to be running is not stated.
If settings that affect plugins change while Claude Code is loading them, it now reads the plugins again before choosing which hooks to run
Unclear It is not clear how often the extra read happens in practice or whether you would notice it.
When Claude Code can't work out which hooks match an event, it now logs the failure instead of quietly running no hooks
Unclear It is not clear what the stand-in path for plugin hooks is for.
Plugin hooks are now loaded again if the state they were first read under has changed, instead of always reusing the first load
Unclear It is not clear what state the record represents.
Claude Code now politely ignores language-server requests to register or unregister features, instead of failing on them
When scheduled tasks are switched from off to on during a session, the parts of Claude Code waiting on that change are now told
If a sync's saved state does not record that its files were on disk, it ignores pending deletions and downloads missing files again
Unclear It is not stated which data this sync covers.
If a plugin directory refresh misses a listing that an installed plugin uses, Claude Code keeps it for a grace period instead of dropping it
Unclear It is not clear what value is sent for the extra option on catalog requests.
Read-deny rules now also catch paths with trailing spaces or a trailing invisible byte order mark character
claude auto-mode defaults and claude auto-mode config finish sending usage data before exiting#The claude auto-mode defaults and config commands now send pending usage data before exiting, and defaults now receives its label filter
Claude Code no longer rejoins an MCP server after re-authentication when its close reason matches a certain check, and stops retrying one new error kind
Unclear It is not clear which close reasons stop the rejoin or which error is no longer retried.
Claude Code now checks ANTHROPIC_GOOGLE_CLOUD_BASE_URL like the Vertex and Mantle providers when deciding if the default endpoint is in use
Unclear It is not clear what Claude Code does differently based on this check, and the accounts of how the previous build handled this case disagree.
If plugin-related settings change while plugins are loading, Claude Code now uses the current settings and skips side effects
If a running tool's regular progress update fails, Claude Code now reports it and stops sending updates
When a model rejects structured outputs, Claude Code now treats it as its own error instead of retrying it as an effort problem
Unclear It is not clear what Claude Code does differently after it recognises this error.
Interrupting while a permission request is waiting now waits for the conversation record to be closed out before the stop completes
Unclear Which cases wait for this cleanup is not known.
/clear to apply#When resuming starts a fresh conversation, Claude Code waits for a queued /clear before linking back to the old one, or reports that it never applied
Unclear When this resume path runs is not stated.
When Claude Code imports a CA certificate with Java's keytool, it no longer passes the -trustcacerts option
Unclear When Claude Code runs this import, and what practical difference dropping the option makes, is not established.
A key: value line in a file's settings header is now read only if the value starts with a non-space character
Unclear It is not certain which files this parser handles, though it is believed to be the one for output styles.
When a tool fails, Claude Code strips the markup around the error text before cutting it down to length
Unclear It is not clear whether the error text Claude itself receives still carries the tags.
7 more of these are in What probably matters to you, on page 1.
Before reusing a summary prepared in advance, auto-compact now checks it still covers the conversation and fits, and refuses it with a named reason if not
Unclear It is not clear whether preparing summaries in advance runs for anyone, since its setting is only shown when a server-side switch allows it.
If a hook cannot check a tool call, Claude Code now blocks the call with an explanation unless the server flag tengu_quiet_hopcroft relaxes it
Unclear Which hook events this blocking applies to, and one further condition it checks, are not established.
Settings for parked and resumed turns now come from saved or served presets, and a new flag tengu_polished_salamander can hold parked messages open
Unclear What a reader actually sees differently, and what applies when the server sends nothing, are not settled.
A new check can skip re-reading a file Claude has seen when its timestamp is newer, and the number actually re-read is recorded
Unclear It is not clear what the new check compares before skipping a file.
The /bridge request can now send expected_epoch and handles epoch conflicts, and worker_epoch is described as sent by every claude-code-server worker
Unclear It is not clear what supplies the expected epoch, so when it is actually sent is unknown.
Two remote switches, off by default, control keeping a file-sending tool's results in subagents and how unanswered tool requests are found
Unclear What either switch changes for a user in practice is not shown.
The "Precompute compaction" and "Show message timestamps" settings still only appear when a server-side switch allows them
A new remote switch, off by default, can stop extended usage requests for workflows set to wait out a usage limit
Unclear What counts as extra usage being turned off for a real reason is not stated.
Claude Code's settings code gained handling for which settings keys come from the folder it was launched in, with no visible effect yet
Unclear Which settings keys are involved, and whether the empty panel field is ever shown, were not traced.
Claude Code now logs that hooks modules are not loaded, that no switch enables them, and that no built-in plugin loads
Unclear It is not clear exactly when this message appears or which hooks it covers.
A new switch, off unless turned on remotely, was added; a local override cannot enable it, and its purpose is not shown
Unclear What this switch controls in Claude Code is not known.
One remotely controlled feature now stays off unless the server turns it on, and stays off on errors, where before it defaulted to on
Unclear It is not clear what feature this setting controls.
Workflow pauses for usage limits gain a check on whether they would wait, plus a new remotely set number with a cap
Unclear It is not clear what the new number controls or what uses the new check.
A server-controlled setting can make some background requests to the model point back to the reply they came from
Unclear It is not clear what the marker does once a request is sent.
The auto-updater display now receives whether you are at the prompt, with no visible effect yet
Unclear How this information is used is not known.
Claude Code gained internal tracking for requests where structured outputs are unsupported, with no visible effect yet
Unclear Nothing calling the new tracking was found, so what it will be used for is unknown.
6 more of these are in What probably matters to you, on page 1.
Claude Code now notes whether a slash command came from the input box, and can store an expanded copy of a prompt with extra text added
Unclear It is not clear what text is added when a prompt is expanded, or when that happens.
Tools whose names start with mcp__claude-device__chrome_ are now treated as Claude in Chrome tools
Unclear Which Claude Code behaviours depend on this list of Chrome prefixes is not established.
Remote and cloud sessions now hold for a pending end-of-turn summary, with a time limit, before taking the next step or reporting idle
Unclear When an end-of-turn summary is pending is not stated.
Claude Code can now mark where a parent prompt ends as a prompt-cache breakpoint, which affects how often cached prompts are reused
Unclear It is not clear which parts of Claude Code turn this marking on.
The tengu_bridge_attestation_enforce flag now falls back to on instead of off when no trusted value is found, and its config has a new source order
Unclear What the switch falls back to when no value is present could not be determined.
Claude Code's early check that your sign-in is still fresh can now be scheduled ahead of time as well as at the start of a turn
Unclear Whether this warm-up is on by default could not be determined.
The sandbox's file-read rules now include user settings passed in directly, allowRead re-opens and credential files resolved across all settings levels
Unclear What part of Claude Code passes these settings in is not known.
The remote switch for bringing named files along on cloud handoffs now reads tengu_hazy_nova instead of tengu_keen_moth
Unclear Which feature this switch controls is not stated.
Claude Code gains a new attachment prefetch request header, two new fields on saved items, and a few small error-handling tweaks
Unclear It is not clear which requests carry the new attachment prefetch header.
In auto mode, Claude Code now records when its automatic check denies an action as blocked
Unclear It is not clear what Claude Code does with the recorded block.
In Remote Control, early downloads of large attachments can now stop once the server reports the file was already delivered
Unclear It is not clear which server reply triggers the stop or what the extra check before it tests.
The Prompt suggestions row in /config still appears only when a server-side switch is on; only the surrounding code changed
Cloud session workers can now accept a server offer to send events over a streaming connection, alongside the usual one-request-per-batch route
Unclear It is not known whether the server currently offers the streaming connection.
The check for whether a remote session is limited to the owner's account is now shared, and a separate check for remote cowork sessions was added
Unclear What the new switch controls in anything you see is not clear.
A remote session's time limit can now come from a value set for its tenant, not only from the CLAUDE_CODE_REMOTE flag setting
Unclear It is not clear what decides whether the limit comes from the tenant or the flag.
Claude Code clears two more pieces of session state on reset and gains internal fields for holding a session open, with nothing yet visible
Unclear It is not clear what will use the hold and park fields.
Messages that update the on-screen interface in a remote session are now checked against the minimum trust level for their sender
Unclear It is unclear what happens to genuine interface messages that arrive without proof of who sent them.
Setting up trust for the agent proxy's certificate no longer checks a server switch there and now catches certificates listed in swapped order
Unclear It is not clear what the remaining use of the setting controls, or whether the trust step still depends on it in some other way.
Creating a remote session now attaches the local checkout you launched from even when your code is sent as a bundle
Unclear It is not clear what difference the 'remote' and 'bundle' markings make to the remote session.
Remote sessions can now upload events by other routes, send events together, and hold some reports until the sender is attached
Unclear It is not clear what turns on the other upload routes or who receives them.
In remote sessions, Claude Code now merges newly announced session details after reconnecting and reports them if they differ
Remote sessions gain logic for epoch conflicts and for denials awaiting cancellation, and close upload paths on shutdown
Unclear Whether this logic is in use yet, and what sets it off, is not known.
gh command#In remote sessions, the stand-in gh command now gets its own folder per session, is skipped in some cases and cleans itself up
Unclear It is not clear what sets the session identifier that selects the per-session setup.
When a remote session withdraws a permission request, its Deny answer is now held and sent in one request together with the cancellation
The startup details sent when a hosted session is claimed gained more fields, and file staging dropped one condition
Unclear What, if anything, these changes alter for someone using a hosted session is not known.
In remote mode Claude Code now skips its early git status lookup, avoiding a local git call it would not use
Unclear It is not clear exactly what Claude Code counts as remote mode for this check.
Loading a remote session's transcript and writing subagent transcripts now happen under a lock so only one writer works at a time
Unclear It is not clear how the lock behaves when the file is already locked, such as whether it waits or gives up.
The folder trust check for the checkout a session starts from now tests that checkout's root folder and sends which parts it covers
Unclear What this check is for and whether anything holds it back are not stated.
Claude Code now uses a single marker for the account memory server when refusing writes from spawned agents
Unclear It is not clear whether any writes are now allowed or refused differently.
The signed cache certificate check now trusts one named production issuer instead of a fixed list, and reports time left in hours
Unclear It is not clear whether verification behaves any differently for users.
A prompt waiting in the queue now goes through an extra step with its text before its attachments are prepared
Unclear It is not clear what the new step does with the prompt text.
Claude Code now treats a session as a local agent only when it was started as local-agent or local_agent
Unclear Which other entry points were previously accepted is not known.
The health check of a self-hosted Remote Control runner now polls its token status, including a retire time and whether it is stopping
Unclear What the health check does with the retire time and stopping state is not established.
On Windows, Claude Code can now switch terminal input into raw mode and straight back out
Unclear When this helper runs and what input problem it addresses are not stated.
When packing your repository for teleport, Claude Code now hands the bundling step a working folder if none was supplied
Unclear It is not clear what difference these two changes make to someone using teleport.
Claude Code changed how it decides on and runs the background loading it does when it starts
Unclear What the new step and the wrapper actually do is not clear.
A setup helper now creates its file empty and readable only by your user, and also does so when it hits an error
Unclear Which file this helper creates is not known.
The stall detector can now drop to a slower checking rate after a quiet period and speed back up when work resumes
Unclear Which parts of Claude Code besides remote sessions use the slower idle rate is not established.
The log line and usage data for trusting repositories when a remote session is created now say what the trust covers
Unclear What range of things the trust can cover is not known.
The self-hosted runner's health server now decides who may read /v1/metrics with a shared check instead of a fixed list of local addresses
Unclear It is not clear which callers the new check allows.
In interactive sessions, the detector for program stalls is told to take a resume after suspension into account
Unclear It is not confirmed what accounting for SIGCONT does inside the detector.
Claude Code reports a few more usage events, and failed requests from host apps can now include an error code
Unclear It is not confirmed that a projects or purge-project command exists or can be used.
Claude Code now records more detail about how it prepares a compaction, plus a new report when one part of it overflows
Unclear What makes the compaction classifier overflow is not shown.
Claude Code now reports when it starts fetching settings at startup, and adds diagnostics about background work in cloud sessions
Unclear What triggers these events is not known.
Claude Code now records how often it stops reading attachments ahead of time when loading them for a remote connection
Unclear It is not clear what causes an early read to be stopped.
Claude Code's timing of the start of a turn now records the slowest attachment step, its resource use, and changed files reread
Unclear Where these timings are reported is not known.
Claude Code now records the first successful write of a session's history, and again when a failing writer recovers
Unclear It is not clear whether this event goes to usage reporting or only to a local diagnostics log.
Claude Code now recognises a media_removed error from the API and records four more timing phases at the start of a turn
Unclear It is not clear when the media_removed error is reported or what a user sees when it happens.
Timing data for the start of a turn now includes message_prep, model_config_wait and auto_mode_context_wait
Claude Code's usage data now records whether startup began fetching its remote feature settings early
Two new usage-reporting event names appear, one for language server requests and one for tool progress heartbeats
Unclear Where these events are sent from and whether anything controls them is not established.
Claude Code's usage data now keeps tool_use_id and transport fields, with transport limited to bridge, native or other
Unclear It is not clear which usage events carry these fields or what bridge and native refer to.
Anthropic has not published official notes for v2.1.288 yet. This section updates automatically when the entry appears in the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
2 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 1 line added, 1 line removed.
Claude Code, interactive mode
2 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
698 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 67 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?