Clearer wording when a settings file is skipped for cloud sessions#
The reason shown for skipping a settings file now says the cloud session may change it
You can now stop Claude Code compacting a long conversation while you sit idle by setting idleCompaction to false. The CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS variable sets how large a conversation must be before idle compaction starts. A new --proactivity flag picks how much Claude does on its own when it starts. CLAUDE_CODE_DISABLE_PROACTIVITY turns that choice off. Running claude remote-control with --allow-unattended-tool-calls lets cloud sessions use the current folder for one run. Remote sessions now read the SDK address from CLAUDE_CODE_REMOTE_SDK_URL when --sdk-url is not given.
This release has 7 entries in the build that are not switched on yet. One would let you attach more PDFs as a reference when their page count is known. Another would let an MCP server that needs you to sign in keep its saved tools. Claude Code could also tell the model that you pay per token and what a Bash call costs. Live-update connections could learn to spot a proxy answering in place of the real server. Each of these waits on a switch that is off by default.
Among this release's fixes, a cancel sent from outside the terminal no longer throws away every prompt you had queued. Plugin names that version 2.1.287 changed now match the installed plugins again. Synced skills now keep the text that sits above their main body. A plugin's hook error handler now still runs if the worker running those hooks is replaced mid-event. Stopping a remotely served background command now returns without waiting for it to end.
Written by our agent from the shipped bundle, not by Anthropic.
A new remote-control option lets auto-mode cloud sessions run commands in your folder without asking, sandboxed, with status messages showing what is allowed
Sessions & agentsA new --proactivity <level> option, hidden from help, sets how much Claude does on its own, and a remote session started from Claude Code is sent the same level
New idleCompaction setting can stop idle compaction, and CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS overrides its minimum token threshold
Sessions & agentsA --proactivity flag picks the proactivity level when Claude Code starts, and CLAUDE_CODE_DISABLE_PROACTIVITY turns the selector off
Setting CLAUDE_CODE_REMOVE_PROMPT_STRINGS to a JSON list removes those strings from the prompts Claude Code sends to the model
Sessions & agentsWant the reasoning? Read walks the 61 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →28 more of these are in What probably matters to you, on page 1.
The reason shown for skipping a settings file now says the cloud session may change it
Errors about attachment paths now show a tidied version of the path instead of exactly what was typed
Unclear It is not clear what tidying is applied to the path.
Claude Code now asks git for all of a file's attributes and marks files that git converts on checkout
Unclear It is not clear what Claude Code does differently with a file marked as converted.
awk and find commands now ask for permission first#Claude Code now asks before running awk or find commands that trip an extra wildcard check, not only ones with unquoted wildcards
Unclear What the second wildcard check looks for is not clear.
git step are no longer presented as Claude's edits#Claude Code now notes that a git step in a shell command may have changed files, so those changes may not be edits
Unclear Where this note appears is not stated.
When a deny rule overrides a PreToolUse hook, the debug log shows the deny's reason type and a second permission check can apply
Unclear What the fallback permission check looks at is not clear.
Before running git, Claude Code now clears a wider fixed set of git environment variables, not just GIT_CONFIG and GIT_ATTR_SOURCE
Unclear Which additional variables are removed is not known.
The shell command reader now splits words at non-ASCII characters, checks folder changes differently and drops some entries from its blocked-read list
Unclear The overall effect on which commands are asked about or allowed is not clear.
The skill that suggests permission rules to cut down prompts is now told never to allow pyright, since it starts Python in your folder
Unclear Whether Claude Code's own command checker still lets some pyright commands through automatically is not settled.
When cleaning up an agent's worktree fails, Claude Code now says whether its own deletion failed or git refused, and keeps the worktree
Adding a GitHub plugin marketplace now runs an extra check against names already registered, and the name-taken error can show the name you asked for
Unclear Exactly which names the new registered-name check rejects is not clear.
The bridge that streams a session's events now tracks queued internal events and sends updates more slowly when no viewer is present
Unclear Whether this is switched on for users, and whether any of it is visible to them, is not clear.
If an MCP server is removed, changed, disabled or refused while Claude Code connects to it, the connection is now marked failed with a reason
GitLab token patterns gain a display setting, and new helpers detect Windows drives under WSL and run git against other folders
Unclear What the new display setting on GitLab token detectors actually controls is not known.
When preparing files for upload, Claude Code now refuses symlinks that lead outside their folder and reports links that have moved
Failing to fetch code sessions now reports the HTTP status code, and session titles are cleaned and squeezed onto one line
Unclear Exactly which characters the title cleanup removes is not stated.
A 403 on an expired Remote Control session now fails as expired straight away, while other 403s note when a poll-sessions permission is missing
Unclear How the poll-sessions marker is used once it has been passed on is not known.
Claude Code now shows a service's error text only if it is a single plain line of at most 1,024 characters
Unclear Which errors go through this check is not known.
Claude Code's shell command parser can now spot wildcard patterns, and its error for deeply nested command substitutions is reworded
Unclear How the new wildcard check is used in permission decisions is not known.
Claude Code's Bash command checker now treats text after a heredoc, {fd}> redirects and variables set before export differently
Unclear Exactly which commands are newly approved or newly sent to a prompt is not settled.
Before its first sandboxed command, Claude Code re-checks where blocked and credential paths point and rebuilds the sandbox if they moved
Unclear What triggers the re-check, and whether it only happens when sandboxing is turned on, is not settled.
Claude Code's scrubbing of MCP server details from error text now has limits and fails with an error when text is too long or too deeply encoded
Unclear The actual limits, and whether these new errors can appear on your screen, are not settled.
When a cloud session refuses a request because its repository is not trusted, the message now says to ask Claude to reconnect the computer
A hint about commands running in the background remotely now says their output file shows what printed, not whether they are still running
MCP servers still connecting during a short hold are left out of the pending-tools notice Claude receives, and nothing is sent if nothing is left
Wildcard web address rules now protect punycode host names, and a rule with the wildcard inside part of a host name is refused
Unclear It is not clear whether every rule with a wildcard inside a host name part is refused, or only ones involving punycode.
gh fails#If finding the gh command times out or fails during setup, Claude Code skips its gh stand-in and carries on, except in hosted runs
When settings were refused but permission rules exist, a status line now says only the deny and ask rules could be applied
Unclear It is not clear which feature or situation shows this status line.
The check deciding if a shell command is read-only or allowed now has one more test that can rule it out
Unclear It is not clear what kind of command the new test catches.
Uploading your repository for a cloud session now checks how far ahead of the remote your branch is and gives clearer errors
Unclear How Claude Code decides a branch is ahead of the remote before counting is not clear.
Files staged for a cloud upload are now re-checked after reading so a swapped or linked file is caught
Unclear Any effect you would notice is not known.
Cleanup of old job worktrees now skips recently changed ones and checks their age again right before removing them
When placing a file for a cloud session, Claude Code now rejects folder names with backslashes and destinations outside the staging folder
Unclear It is not clear when these checks run or what the settings helper is used for.
A repeat of a message Claude Code is still waiting to process is now marked as a withheld echo, and repeats get new timing diagnostics
Unclear What the skipped release step does, and so what you would notice, is not clear.
Claude Code recognises more ways of handing a shell an inline script, including PowerShell options like -EncodedCommand, in any capitalisation
Unclear Whether this check is used for permission decisions was not confirmed.
Claude Code now refuses to read a file as text when it contains a NUL byte, a zero character typical of binary files
Unclear Which feature reads files through this helper is not identified.
The error shown when a cloud session started here could not be bound to this machine has changed
Unclear Which command produces this error is not known.
For background commands on a remote host, Claude is now told the host reports whether a command is still running, not its output file
Subscribers whose sign-in token has expired get a dedicated error when Claude Code times out waiting to refresh it
Unclear It is not clear whether this behaves any differently from the previous build.
$$ now ask for permission#Shell commands using patterns like $$[ are now treated as too complex to judge and prompt for permission
Unclear The exact commands that now prompt when they did not before are not fully stated.
The mode indicator below the prompt is now one piece, with a second piece shown after the hint text in some cases
Unclear It is not clear what condition decides when the second piece appears after the hint.
When an isolated session tries to write into another worktree, Claude Code now says so instead of calling it the shared checkout
Unclear It is not clear whether there are other conditions that turn the guard on or off.
Claude Code now drops error types and messages from a remote proxy if they look malformed or are too long
Plugins that declare a restricted MCP server type are now told which rule applies, and marketplace-name refusals give fix steps
Unclear It is not clear what condition decides when the reworded marketplace-name refusal is shown.
Output from a SessionStart hook that arrives late is now held until any open tool call finishes, instead of being added at once
When Claude Code saves its plugin marketplace list, a new check now leaves out some entries
Unclear It is not clear which entries the new check leaves out.
Refusing a reserved plugin marketplace name can now say the name looks like one of Anthropic's own marketplaces and that reloading won't help
Unclear It is not clear what decides which of the two wordings you see.
When fetching environments fails, the error now shows only the HTTP status code, for example "HTTP 500"
Claude Code stops reusing saved MCP server details when the server's settings changed, and reloads claude.ai connectors after a policy change
Unclear It is not clear exactly when each of these checks runs.
The check that rejected button labels over a character limit is gone; labels with control characters are still rejected
Unclear It is not clear whether label length is still limited somewhere else.
Claude Code now reports a permission denial to SDK programs based on the final decision, after any overrides
Unclear It is not clear which denials are left out of the report.
When a permission prompt tool answers a permission request, Claude Code now labels who approved it as "user" rather than "person"
Unclear Where this label is read or shown is not stated.
Claude Code now waits for a transcript file to finish loading before rewriting it, and gives up with a warning if loading stalls
Unclear When Claude Code rewrites a transcript is not stated.
Claude Code's shell command parser now accepts characters outside plain ASCII, such as accented letters, at the start of a word
Unclear The exact effect on how such commands are parsed and approved is not shown.
Remote control gains an "off in this window" label, inbox fetch errors show the server's detail, and helper agents get a token-budget note
Unclear It is not clear what triggers each of these messages to appear.
Plugin validation now reports hooks that can block an event, whether they handle errors with .catch, and warns about late refusals
Unclear It is not clear whether this validation output is shown to ordinary users or only to plugin authors.
Claude Code now refuses to load or refresh a saved marketplace whose name fails its look-alike check, even if it was added earlier
Unclear Exactly which names the look-alike check refuses is not stated.
Claude Code's shell permission checks changed for sudo shell flags, += variable prefixes, command -v and backslashes
Unclear The overall effect on any particular command is not clear.
Claude Code now marks any file git converts through its attributes as unsupported, not only those with a filter or encoding set
Unclear It is not clear what Claude Code does with a file marked unsupported, or how often the no-attributes case occurs.
The background service's idle hint now mentions cloud session clients, and one error now names /proc/self/mountinfo
Unclear The condition that makes the token read stop early is not settled.
claude auth login#The error for cloud sessions without a claude.ai sign-in is shorter and names the claude auth login command
If a permission request ID comes up twice in one session, replies to it from a channel are ignored and you are asked to answer in the terminal
The warning about forwarding hooks to a cloud session is shorter, and {owner}/{repo} endpoints now fail for project paths with more than two parts
Uploading a partial clone with missing files is refused, and the message says to use a full clone or run git fsck --name-objects
Unclear It is not clear which upload feature shows this error.
When a Git worktree's link does not point back to its repository, Claude Code now treats it as unregistered without guessing from the error text
Unclear What a user sees differently after this change is not shown.
Shell commands in prompts are read differently, skill use is recorded by the skill's name, and a pull request skill no longer takes a proactivity level
Unclear None of these was followed through, so their effect for users is not known.
MCP reconnects now restore earlier state if the older HTTP+SSE fallback fails, and a refused sign-in step-up fails with adopt_refused
Unclear Whether the legacy HTTP+SSE fallback path is switched on for any account is not known.
Cloud session errors give reworded advice, and a notice warns when uncommitted files stay local because the launch folder can't be reached
Unclear What changed in the rules for which files are read into the cloud bundle is not described.
On Linux and macOS, Claude Code can list folders through the system library so unusual file names come back exactly as stored
Unclear It is not clear whether this listing is used anywhere besides removing worktrees.
rc instead of /rc#The Remote Control label now begins with rc rather than /rc, and its short form is rc
Unclear Where in the interface this label appears is not established.
Errors for files, paths, folders and artifacts that do not exist, and their suggestions, are now passed through a cleaning step
Unclear It is not clear what the processing step does to the paths.
The suggestion list now sizes its name column to leave room for each item's description
Unclear The exact visual effect has not been checked.
The reasons Claude Code gives for refusing to analyse certain shell launches are now shorter
Unclear Whether the way these shell launches are matched also changed is not settled.
The reasons Claude Code gives for asking you to approve a shell command are shorter, with some explanations in brackets removed
The permission warning for git commands that set core.hooksPath or an include path on the command line is now shorter
Permission prompts now say 'it runs a project tool, such as make or npm' and 'it runs a file by a relative path'
The browser pages shown after signing in to Claude Code now share one template and are allowed to use embedded fonts
Unclear What changed in the pages' styling is not settled.
Marketplace and plugin names in plugin update result lines now go through a formatter instead of being printed as is
Unclear It is not clear what the formatter does to the names or when each formatting is chosen.
When fitting the skills list into its space limit, Claude Code now counts each skill's displayed name instead of its raw name
Unclear How the display name differs from the raw name is not known.
The refusal reason for a command that passes shell code through too many nested shells now reads more simply
MERGE_RR and MERGE_AUTOSTASH join MERGE_HEAD and MERGE_MSG on Claude Code's list of git's internal file names
Unclear It is not clear what Claude Code does with this list, for example whether these files are now protected from edits.
A failed config save now shows: Could not save this to the config file, so nothing changed
Unclear It is not clear where in Claude Code this message is shown.
When a file does not exist, the error Claude Code returns now includes its "Did you mean" suggestion for a similar file
Unclear It is not clear whether the earlier message already contained the suggestion in some form.
When fetching session events fails, the error now reads "Failed to fetch session events: HTTP" followed by the status code
Some reasons Claude Code gives for flagging a shell command are shorter, including the one for risky PHP options
Unclear It is not confirmed whether the restricted-mode handling in the file-reading check was moved elsewhere or removed.
A path ending in white space now gets a clearer refusal, and its error code changed from 2 to 20
Permission prompts for shell commands that run Python now give shorter reasons, such as "it runs python with -i"
The check for delisted plugins now skips one particular marketplace, and translating Gemini commands handles shell blocks correctly
Unclear Which marketplace the delisted-plugin scan skips is not stated.
A cancel sent from outside the terminal now targets specific queued input instead of discarding everything you had queued
Unclear It is not clear what decides which queued commands a cancel is aimed at, or whether this behaviour is switched on for everyone.
A remotely served background command still counts as running while it is being stopped, and the stop result returns without waiting
Unclear What difference this makes to someone using Claude Code is not clear.
If the worker running plugin hooks is replaced mid-event, Claude Code now waits for the new one and lets the plugin's error handler run there
Unclear It is not clear whether plugin hook modules are themselves behind a switch.
Attachments that carry a scheduled task's state no longer stop Claude Code from rewriting a stretch of the conversation, and are kept
Unclear It is not clear where the kept attachments are used afterwards.
Claude Code now repairs plugin listings so they use the names their installed plugins use again, and logs how many it fixed
Unclear When the repair step runs is not known.
Loading a saved conversation now pauses regularly so the interface stays responsive when you resume a large session
If a reply's idle timer goes off because the computer slept, Claude Code now stops that reply and writes a warning to its log
Hooks-module loading now drops only the failing plugin and retries, keeps a plugin loaded after a worker crash, and adds new errors around engine.create
Unclear Exactly when one module pushes out another is not clear.
The agent_id line Claude sees after starting a new agent now holds the agent's ID instead of the teammate ID
Claude Code now decides a device owns a bound tool host only when there is also a valid link to that tool host
Unclear It is not clear what a tool host is or which feature it belongs to.
A /login you start Claude Code with is now cleared after setup only if you did not skip sign-in
Published verbatim by Anthropic for v2.1.290. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 190 bullets, 30 name something an entry on this page also names, 67 name something no entry here does, and 93 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
No entry names this agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
No entry names this ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool
No entry names this ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
No entry names this claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)
No entry names this claude attach <name> and claude logs <name>: part of a session name works in place of the id
No entry names this /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as ant apply files
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts /claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as deep-researcher, with the ant CLI
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts offset to read on
Nothing to match on #95127[BUG] WebFetch truncation is invisible to the model — absent from the tool description, unmarked in the result, and the web-fetch subagent can neither detect nor recover from it Open
/rewind not listing a prompt sent while Claude was still working
No entry names this /loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on
No entry names this /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork
No entry names this #96531[BUG] /loop scheduled task stops firing on its own after the session is backgrounded — fires only right after a user turn Open
--json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered
No entry names this CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule
Probably instruction-file-loading-de-duplicated-via-a-held-set-and, edit-tool-results-carry-gitdiffread-flag-sealed-path-case, sandbox-read-blocking-and-wsl-mount-parsing-rework, withheld-memory-files-now-shown-as-a-startup-warning, instruction-files-claudemd-rules-held-outside-the-workin, plan-exit-dialog-hides-clear-context-option-for-ask-proactiv, startupresume-telemetry-adds-store-confirm-and-system-promp, home-settings-seeded-to-cloud-sessions-ccr, hooks-module-fsancestors-reads-agentsmd-with-a-held-outs xn-- host label matching differently from one process to the next
Probably url-permission-patterns-reject-punycode-wildcard-hosts /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved
No entry names this plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux
Probably plansdirectory-rejects-backslashes-off-windows claude daemon run and claude daemon logs; they now show as \uXXXX escapes
No entry names this .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call
Nothing to match on turn.step result listing a tool call that a mid-response model fallback had discarded
No entry names this claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions
No entry names this /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration
No entry names this ! shell blocks in skills and commands failing when the file is saved with CRLF line endings
Nothing to match on /permissions tab was clicked while searching in fullscreen mode
No entry names this answer on turn.complete for a subagent that hands its report back in auto mode
No entry names this prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name
No entry names this disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents
No entry names this @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed mid-read
Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check /loop run count, countdown and live status line after the session enters a worktree that it creates
No entry names this claude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt
No entry names this declare, typeset, export or readonly
Nothing to match on language setting
Nothing to match on #99232[FEATURE] "You should know" mod: respect the `language` setting instead of always writing in English Open
claude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation
No entry names this n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section
Nothing to match on claude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted
No entry names this /ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver
No entry names this claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why
No entry names this /loop run count freezing and its countdown disappearing after /clear; the count now restarts with the new conversation
Probably bridge-remote-control-peers-can-run-effort-model-rena --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt
Probably channels-banner-shows-a-waiting-for-your-organizations-pol /chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135)
Probably project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act #98135/chrome Reconnect never registers claude-in-chrome MCP tools when a session starts with the bridge down (survives --resume) Closed
ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account
No entry names this claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts
No entry names this claude agents could not deliver to a running session being saved and sent by themselves the next time it was restarted
No entry names this cat <<EOF | python3) asking for approval on every run
No entry names this claude agents failing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one)
No entry names this #84827Daemon self-respawn after a Homebrew cask upgrade targets the purged versioned path (ENOENT), killing every background session Open
rg or git grep) whose arguments the shell would still expand as wildcards; these now prompt for approval
No entry names this claude plugin test refusing to run after an upgrade because of an out-of-date saved setting
Probably claude-plugin-test-rollout-flag-hold-and-file-form git clone option keeping the sandbox exemption from a git pattern such as git * in sandbox.excludedCommands; it is now treated like the long form
No entry names this /ultrareview of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside .git (git 2.54+); it now refuses with an explanation
No entry names this /loop wakeup or scheduled task; Claude is now told and can schedule it again
No entry names this store.postgres_url can't be parsed; the error now names the setting and says what the URL may hold
Probably gateway-gives-a-clear-error-for-an-invalid-storepostgres-ur /sandbox Config tab on Linux and WSL when a sandbox read rule such as ~/**/.env covers a large folder
No entry names this #98023[BUG] 2.1.284 freezes on first Enter: new sandbox glob expander synchronously walks all of ~ for "~/**/…" denyRead patterns (follows symlinks, unbounded memory); 2.1.280 fine Open
claude -p run from the Bash tool)
No entry names this --continue or --resume <session-id> in the terminal
Probably cloud-sessions-print-a-claude-cloud-resume-hint, resume-with-resume-print-drop-turn-guard-adds-an-attach, background-job-respawn-can-fork-a-resume, remote-control-gains-allow-unattended-tool-calls-and-a-for /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file
No entry names this CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to dialogExpiry
Probably chrome-permission-env-defaults-and-remote-tools-unattended-h --restricted (and CLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket
Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check --allow-dangerously-skip-permissions on respawn without the bypass-permissions disclaimer having been accepted
Probably background-sessions-ignore-allow-dangerously-skip-permissi, new-proactivity-startup-level-gated-by-tengu-proactivity, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no claude auth login or with a credentials file already in the config directory
Probably cloud-session-auth-error-reworded-to-point-at-claude-auth-l /login reporting success when the keychain refused the new login and kept an old one it could not remove
Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act --include-partial-messages seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming
No entry names this ConfigChange hooks and reloading settings mid-command when .claude/settings.json or .claude/settings.local.json does not exist
Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with /loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after .claude/scheduled_tasks.json was deleted
No entry names this plugin-authoring skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section
No entry names this /plugin in the desktop app's Code tab: it now says where to install and manage plugins there
Probably plugin-marketplace-names-that-imitate-anthropics-are-refuse, plugin-in-desktop-app-returns-guidance-text claude auth login and /login and no longer blames API-key authentication
Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act /ultrareview upload: it is about half as long and says what kind of file is the problem
No entry names this /ultrareview upload refuses a checkout: each known cause now has its own message, with a way to fix it
No entry names this browser_batch call now gets 90 seconds, up from 60, before it is reported as timed out
Probably browser-batch-gets-its-own-tool-call-timeout CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC to also skip the startup connection warm-up
No entry names this --chrome, /chrome or your user settings
Probably claude-in-chrome-enabled-by-default-is-ignored-in-remote-a, project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act pyright, which is no longer treated as a read-only command
Nothing to match on $.process.spawn rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result
No entry names this ! shell command that contains raw control characters other than tab and newline, with a message that shows where they are
Nothing to match on /artifacts: opening an artifact in your browser now closes the list
No entry names this ps command ask for approval instead of running without asking
Nothing to match on /ultrareview upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text
No entry names this /code-review at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5
Probably medium-and-high-effort-now-map-to-a-different-measured-profi agent_id in Agent results to its agent ID (its name@team address stays in teammate_id); TeammateIdle hooks no longer fire from its subagents or forks
Probably teammate-agent-id-now-uses-resumable-id, teammate-ambiguity-message-wording, agent-spawn-result-reports-agent-id, taskstop-description-now-covers-background-agents-spawned-wi /loop): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup
No entry names this /model, /effort and /rename sent from claude agents to a busy background session to apply right away, without a confirmation, instead of when the turn ends
Probably effort-commands-log-from-level-and-route, medium-and-high-effort-now-map-to-a-different-measured-profi, bridge-remote-control-peers-can-run-effort-model-rena CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR sets the rate, 0 turns it off) instead of ending after 200 calls
Probably websearch-gets-a-refilling-token-bucket-budget CLAUDE_CODE_DISABLE_ATTACHMENTS so a repository's .claude/settings.json or .claude/settings.local.json can no longer set it; shell, user and managed settings still can
Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with, new-proactivity-startup-level-gated-by-tengu-proactivity, proactivity-opt-in-restored-across-worker-epochs, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no claude plugin update on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins
No entry names this gh api in cloud sessions: a host other than github.com set in GH_HOST or GH_REPO is now refused (use --hostname or a full URL), and stderr notes requests to other hosts
Probably gh-api-hostname-help-text-varies, new-gh-host-gh-repo-guidance-when-the-host-differs, gh-style-endpoint-repo-resolution-tightened, gh-tool-description-gh-host-and-gh-repo-host-text claude-api skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the auto permission policy
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts claude --environment <id> to create its session through the current Sessions API; printed and JSON session ids keep their session_… form
No entry names this !fast to switch a thread to fast mode, moving it to Opus if needed, and !fast off to switch back; replies show (fast) while it's on
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 2 lines added, 1 line removed.
Claude Code, interactive mode
15 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
334 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 70 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?