Remote Control help text now lists permission modes#
The help text for Remote Control now includes the list of permission modes and checks a feature switch
Unclear It is not clear how the feature switch changes the help text.
You can now stop Claude Code compacting a long conversation while you sit idle by setting idleCompaction to false. The CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS variable sets how large a conversation must be before idle compaction starts. A new --proactivity flag picks how much Claude does on its own when it starts. CLAUDE_CODE_DISABLE_PROACTIVITY turns that choice off. Running claude remote-control with --allow-unattended-tool-calls lets cloud sessions use the current folder for one run. Remote sessions now read the SDK address from CLAUDE_CODE_REMOTE_SDK_URL when --sdk-url is not given.
This release has 7 entries in the build that are not switched on yet. One would let you attach more PDFs as a reference when their page count is known. Another would let an MCP server that needs you to sign in keep its saved tools. Claude Code could also tell the model that you pay per token and what a Bash call costs. Live-update connections could learn to spot a proxy answering in place of the real server. Each of these waits on a switch that is off by default.
Among this release's fixes, a cancel sent from outside the terminal no longer throws away every prompt you had queued. Plugin names that version 2.1.287 changed now match the installed plugins again. Synced skills now keep the text that sits above their main body. A plugin's hook error handler now still runs if the worker running those hooks is replaced mid-event. Stopping a remotely served background command now returns without waiting for it to end.
Written by our agent from the shipped bundle, not by Anthropic.
A new remote-control option lets auto-mode cloud sessions run commands in your folder without asking, sandboxed, with status messages showing what is allowed
Sessions & agentsA new --proactivity <level> option, hidden from help, sets how much Claude does on its own, and a remote session started from Claude Code is sent the same level
New idleCompaction setting can stop idle compaction, and CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS overrides its minimum token threshold
Sessions & agentsA --proactivity flag picks the proactivity level when Claude Code starts, and CLAUDE_CODE_DISABLE_PROACTIVITY turns the selector off
Setting CLAUDE_CODE_REMOVE_PROMPT_STRINGS to a JSON list removes those strings from the prompts Claude Code sends to the model
Sessions & agentsWant the reasoning? Read walks the 61 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →28 more of these are in What probably matters to you, on page 1.
The help text for Remote Control now includes the list of permission modes and checks a feature switch
Unclear It is not clear how the feature switch changes the help text.
When a file could not be sent, the failure line now cleans up the file path and error text before showing them
Unclear It is not clear what the cleanup step removes or changes in the path and error text.
The SDK connection now forwards conversation reset messages only under a condition, and the Remote Control link passes new account memory and pairing details
Unclear It is not clear when conversation resets are now forwarded, or what the other changes do in practice.
When no credential is stored, Claude Code now ignores a saved override of its remotely controlled settings
Unclear It is not clear which setting the override belongs to.
When a session is controlled remotely, a permission answer naming the wrong tool no longer dismisses the prompt that is waiting
Unclear Whether the device identity setting is in use is not clear.
If you change models while Claude Code is preparing a conversation summary ahead of time, that summary is now thrown away
When finding a fleet job's transcript, Claude Code now tries several possible locations instead of only one
Unclear What the possible locations are is not stated.
For MCP tool calls in remote sessions, Claude Code now keeps its own stricter decision over a plugin's looser one
Unclear What the switch controlling this defaults to is not clear.
Sandbox setup now works out the git folder for your working folder and can withhold write access to it when that folder is remote
Unclear The exact condition under which the git folder access is withheld is not clear.
Claude Code gained messages for a message you took back before it reached a cloud session and for one that couldn't be sent
Unclear Which screens or steps show these messages is not settled.
If a PermissionRequest hook approves a web fetch but attaches arguments WebFetch can't check, Claude Code now denies the fetch
Unclear Exactly which hook replies cause a fetch to be denied is not settled.
The review command's help text now lists effort levels from a list in Claude Code rather than fixed low, medium, high and max wording
When a server switch is on, Claude Code loads shell command completion data only when run from source, skipping it in packaged installs
Unclear Which kinds of installation are affected is not settled.
When writing starting settings into a home folder, Claude Code now handles settings files it cannot read whole instead of writing over them blindly
Unclear It is not clear what starts home seeding or whether it is switched on.
When an MCP tool's highest permission is ask, Claude Code now passes that limit along with the tool's other permission details
Unclear What sets a tool's maximum permission to ask, and whether anything does yet, is not clear.
Serving tools to a cloud client now stops background commands when its check fails, and reports failures, recoveries and mid-session switch-offs
Unclear Which account setting controls serving, and what it defaults to, is not known.
Over-long plugin text is now shortened with an ellipsis and a notice, and long tool descriptions are cut instead of rejected
Unclear The character limits are not stated.
A call that gives one of the app's own MCP tools a name containing a slash is now checked before it runs, with its own explanation
Unclear It is not clear whether this check runs in every case or only under certain conditions.
Whether the Chrome setup offer appears now depends on the app hosting Claude Code, not on SSH-related environment variables
Unclear It is not clear which apps declare that they show the offer themselves.
Background workers reload saved session details first and may stop with a message, and restarted workers get a count of recent stops
Unclear It is not clear what makes a worker stop at startup or what the worker does with the count.
Bash and PowerShell permission prompts can show a hint about where a request came from and truncate the footer
Unclear The wording of the hint is not known.
The remote serving off switch now says no new command is accepted, and path checks reject special /proc and /dev/fd links
Unclear It is not clear whether commands already running are still cancelled, or which systems the new path checks apply to.
Session-binding notices can now appear as pop-ups, including a warning when tool serving is on but the link to the tool host is not working
Unclear What turns tool serving on, and what these notices say, is not shown.
Claude Code's list of trusted documentation hosts now includes claude.dev and Anthropic's experimental and raw GitHub locations
Unclear It is not clear what uses this list, including whether it lets Claude fetch these pages without asking permission.
Queued messages and deferred slash commands are refused in remote mode as well as when sending is disabled, and each refusal is now recorded
Unclear It is not settled whether held turns in remote mode ever reached this point before, so the practical difference in remote mode is unclear.
Messaging between sessions no longer starts in a restricted session, or when an explicit messaging socket path is given
Unclear What makes a session count as restricted is not settled.
A panel opened in the terminal can now be set so that prompts you queued keep running while it is open
Unclear It is not shown which panels, if any, use this setting.
When a command runs on another machine, the permission prompt now shows the folder as spelled rather than the host's working directory
Unclear How the spelled folder is worked out is not established.
Background agents get a new stop reason for when the program serving them could not check whether it still serves the session
Unclear When this new stop reason is raised is not established.
Loading the plugin directory now gives up if no page answers in time, and treats caches with repeated listings, as 2.1.287 wrote, as out of date
Unclear The length of the first-answer time limit is not stated.
Paths you block from reading in the sandbox can now start with ~ or be relative, and Claude Code turns them into full paths
Unclear The full effect of the new path resolution steps is not clear.
Choosing a Chrome browser now handles browsers missing from the list and explains when the chosen browser is not connected
Claude Code now checks the shell commands inside a skill first, and runs none of them if one is invalid
If an MCP connection drops after the server took a call, the call now fails instead of being sent again
Claude Code can now spot the error the API gives when a request has too many or oversized images, or unsupported parameters
Unclear Where Claude Code uses this check, and what it does when the error is found, is not known.
Claude Code now caps the total size of a streamed response and pauses briefly when reading it has taken more than 8 milliseconds
Unclear What the total size limit is set to is not known.
Calls from tools other than search tools can now collapse into a group, labelled with the name of the MCP server they came from
Unclear It is not clear whether this produces a visible change in the display.
Environment variables from your settings are now added before Claude Code filters the environment it passes to programs it starts
Unclear Exactly which settings variables now reach child programs that did not before, or the reverse, is not settled.
Claude Code refuses to install a plugin marketplace whose name looks like Anthropic's own, and marks such names in the marketplace list
Unclear How Claude Code decides that a name looks like Anthropic's is not stated.
The auth status display marks the credential not in use, and gateway credential restore explains when the file is refused
Unclear How the auth status output looks beyond the not-in-use marker is not settled.
Skills with over-long display names are not loaded, and MCP commands with over-long names or aliases are not listed
Unclear The character limit itself is not known.
Debug log messages are now capped in length and rate, and streamed server responses are capped in total size
Unclear The exact limit values are not known.
MCP tool results that carry structured data now go through a new conversion step first, with the old handling kept as a fallback
Unclear What the new first conversion step does differently from the old handling is not clear.
Dropping or pasting an image file path now runs a permission check, and a refused path is passed on as plain text instead of read
Unclear The exact rule that decides whether the image may be read is not clear.
The display of files changed by a shell command now recognises git commands such as checkout, pull and reset, and shows a shorter diff
Unclear What exactly the condensed display shows, and what triggers it beyond these commands, is not clear.
A command that is cancelled but keeps running is now killed after a timeout, and failed launches report the code and command
Unclear The exact condition that starts the kill timer is not clear.
Claude Code no longer rejects a tool's input schema for being too long and only checks that it is JSON data
Unclear A size limit may still be enforced somewhere else.
Marketplace refresh skips names that fail a look-alike check, and plugin download and integrity failures now give distinct messages
Starting a cloud session now explains when it starts empty or when local commits and uncommitted changes were left out
Unclear It is not clear exactly when each message is shown.
IDE status now shows connecting and reconnecting, and a remote edit with no diff says it completed on that host
Unclear It is not clear where the new permission field and number option are used.
On Linux and WSL, Claude Code now checks a settings file has really changed before reloading it, and notices when a watched folder is removed
Unclear Exactly what the new project-scoped tracking and file-detail check are for is not clear.
Claude Code now draws very long text only up to a set number of characters and marks how much was left out
Unclear It is not clear which parts of the interface or which tools pass through this limit.
Rewind can now locate its target through a summary written after compaction or a turn started by a background-task notification
Unclear What difference this makes to someone using rewind is not clear.
If an MCP tool call's response ends before any answer arrives, Claude is told the outcome is unknown and to check before retrying
Claude Code now caps MCP HTTP response sizes, unpacks gzip and deflate itself, and refuses responses compressed with br or zstd
Unclear The size limits are not known, and it is not settled in which cases Claude Code does the unpacking itself.
After a plugin install, Claude Code now warns if the marketplace's listing will not keep its dependencies loading, so the plugin will not load
Unclear An additional condition decides whether the warning is shown, and it is not clear what that condition is.
When the background process that runs plugin hooks crashes, Claude Code can now unload the crashed environment and replace the process
Unclear What a user sees during this recovery, and whether anything switches it on or off, is unclear.
If Claude Code can't start its background process mid Homebrew upgrade, it now waits for the upgrade and tries again
Messages sent to a starting background session are no longer queued if they are slash commands, and replies may return a new code
Unclear How ENOREPLY is shown to the user is unclear.
When two commands share a short name, the command list can now label one as the name followed by extra text in parentheses
Unclear It is not clear what goes in the parentheses, what the clash rule checks, or where the labelled name appears.
The background tasks dialog for cloud sessions now warns when the cloud worker is gone and blocks the stop key in that state
Unclear It is not clear what marks the worker as gone or whether this applies to every cloud session.
disableClaudeAiMcp now also blocks claude.ai servers you add yourself#With disableClaudeAiMcp set, a claude.ai proxy server passed by --mcp-config or the SDK mcpServers option no longer connects either
Unclear Only the setting's description is known to have changed; the code that enforces it was not examined.
Claude Code's saved shell setup now takes its PATH from a new source, falling back to your own, and always adds a guard on pkill
Unclear It is not clear what the new PATH value contains or when it differs from your own.
Notifications can now be queued or suppressed depending on screen-reader mode and context, and some no longer interrupt
Unclear It is not clear which notifications are suppressed in which situations.
Claude Code's reading of @-mentions changed: path:line forms and mentions next to CJK punctuation are handled, and trailing repeats trimmed
Unclear The exact differences in which mentions are recognized are not spelled out.
A handoff the session service held for too long is now rejected and its calls are not run
Unclear The time limit and which feature these handoffs belong to are not settled.
Claude Code no longer removes a worktree folder that holds git's internal files or could not be checked, and its error text hides unsafe paths
Claude Code now hides bracketed and percent-encoded login details in URLs, and its pattern for hiding JWT tokens was replaced
Unclear It is not clear in which places Claude Code applies this hiding.
Bash permission checks drop an old table about bare shell launchers and add specific refusal reasons for deep wrapping, env -P and wrappers with no command
Unclear Whether these commands are blocked outright or you are asked to approve them, and whether this is switched on everywhere, is not clear.
The path-safety check now resolves relative file names given to MCP tools, considers mount points, and describes /proc links, overlong paths and unknown home folders
Unclear It is not clear what switches the handling of relative names on, or whether it applies in every session.
The cloud-session create command now prints the session ID, a notice and a not_applied list, and names the agent that requires a repository
Unclear What the session ID formatter changes about the printed ID is not clear.
The warning now says "Couldn't send your first message" instead of the longer cloud session wording
Bash commands with $ followed by non-ASCII text, and some redirect and loop forms, are now too complex to check and prompt you
The check that refuses to run outdated versions now waits for pending server settings before refusing and shutting down
Unclear What causes the settings fetch to be held is not stated.
A path check now rejects entries containing the Unicode replacement character, the � that marks garbled text
Unclear Which feature uses this path check is not known.
Fetched session history is now saved in a private temporary folder and checked for changes before it is read
On Linux and WSL, plugin packages are installed through a held-open handle on the plugin folder, and the install stops if that folder is swapped
Unclear It is not clear which plugin install steps use this new method.
{fd}>file now ask for your approval#Shell redirects that store a file number in a variable, such as {fd}>file, are now treated as too complex to run without asking
The saved-message note now says it will be sent at the next restart, and new notes say when this machine's settings did not reach a cloud session
Unclear It is not clear what triggers each of the new settings notes.
When .git/index or HEAD is a link, the message now says to look at the file and not to run git in that folder
When a session is set to save nothing to disk, Claude Code no longer writes its plugin directory bindings file
The connection status colours now cover connected, pending and disconnected, and a pending connection shows the error colour
Unclear Which part of the screen uses these colours is not clear.
A cloud session refusal about git configuration is reworded, and a message about trimmed search path entries now gives the right count
Unclear Which feature shows these messages to users is not known.
On WSL, Claude Code now finds Windows drives from /proc/self/mountinfo, and the sandbox's read-blocking rules are built differently
Unclear The overall effect on what the sandbox allows or blocks is not clear.
A file write that leads to a Claude Code settings file through a symbolic link now triggers a permission prompt and cannot be auto-approved
Adding a plugin marketplace now fails if its name matches the download folder of a GitHub marketplace you already have
In worktree sessions, git commands are now refused if a word the shell fills in at run time comes before git's subcommand
A set of small changes covering skill proposals, synced file paths, sign-in retries, config file lists, scheduled tasks and telemetry
Unclear What each change does in practice was only briefly checked, so the details may be incomplete.
A plansDirectory setting containing a backslash may now be rejected, and the error message says so
Unclear Whether paths with a backslash are also rejected on Windows is not clear.
Pasted images are now saved in a tmp folder as pasted-<sha12>.<ext>, named from their contents, with retries and a check after writing
Unclear When Claude Code uses the note instead of showing the image is not clear.
Errors from an npm registry override for plugins now say whether the address was invalid or the registry was unencrypted
The too-large repository error now states the size of the git history and the maximum allowed, and no longer points to GitHub setup
Claude Code can now match API errors other than status 400 to the beta options it sent, so its fallback may trigger more often
Unclear It is not clear what kinds of error the new check matches.
When Claude Code starts a subagent, its description can now be generated from the name the subagent is given
Unclear It is not clear which parts of Claude Code use this yet.
Two remote-session error messages now leave out raw server responses and URL details when they are not safe to quote
A git branch-name check no longer limits name length, rejects HEAD or a leading dash, or limits each part's size
Unclear The removed tests may have moved elsewhere, and this may be a different check rather than the old one changed.
Claude Code's list of GitHub-related domains changed, and gitignore patterns starting with / are no longer read as single-segment patterns
Unclear It is not clear what Claude Code uses the GitHub domain list for.
The error hint for messaging a teammate now says teammates are addressed by name
After an MCP sign-in, a connection that can't be taken over is discarded, and tool list refreshes are filtered by each server's config
Unclear It is not clear what the new tool and command filters remove.
When a background subagent asks for permission, the request is now labelled as coming from a subagent
Unclear It is not clear when the label is applied or whether anything on screen shows it yet.
Published verbatim by Anthropic for v2.1.290. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 190 bullets, 30 name something an entry on this page also names, 67 name something no entry here does, and 93 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
No entry names this agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
No entry names this ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool
No entry names this ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
No entry names this claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)
No entry names this claude attach <name> and claude logs <name>: part of a session name works in place of the id
No entry names this /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as ant apply files
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts /claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as deep-researcher, with the ant CLI
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts offset to read on
Nothing to match on #95127[BUG] WebFetch truncation is invisible to the model — absent from the tool description, unmarked in the result, and the web-fetch subagent can neither detect nor recover from it Open
/rewind not listing a prompt sent while Claude was still working
No entry names this /loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on
No entry names this /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork
No entry names this #96531[BUG] /loop scheduled task stops firing on its own after the session is backgrounded — fires only right after a user turn Open
--json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered
No entry names this CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule
Probably instruction-file-loading-de-duplicated-via-a-held-set-and, edit-tool-results-carry-gitdiffread-flag-sealed-path-case, sandbox-read-blocking-and-wsl-mount-parsing-rework, withheld-memory-files-now-shown-as-a-startup-warning, instruction-files-claudemd-rules-held-outside-the-workin, plan-exit-dialog-hides-clear-context-option-for-ask-proactiv, startupresume-telemetry-adds-store-confirm-and-system-promp, home-settings-seeded-to-cloud-sessions-ccr, hooks-module-fsancestors-reads-agentsmd-with-a-held-outs xn-- host label matching differently from one process to the next
Probably url-permission-patterns-reject-punycode-wildcard-hosts /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved
No entry names this plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux
Probably plansdirectory-rejects-backslashes-off-windows claude daemon run and claude daemon logs; they now show as \uXXXX escapes
No entry names this .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call
Nothing to match on turn.step result listing a tool call that a mid-response model fallback had discarded
No entry names this claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions
No entry names this /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration
No entry names this ! shell blocks in skills and commands failing when the file is saved with CRLF line endings
Nothing to match on /permissions tab was clicked while searching in fullscreen mode
No entry names this answer on turn.complete for a subagent that hands its report back in auto mode
No entry names this prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name
No entry names this disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents
No entry names this @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed mid-read
Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check /loop run count, countdown and live status line after the session enters a worktree that it creates
No entry names this claude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt
No entry names this declare, typeset, export or readonly
Nothing to match on language setting
Nothing to match on #99232[FEATURE] "You should know" mod: respect the `language` setting instead of always writing in English Open
claude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation
No entry names this n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section
Nothing to match on claude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted
No entry names this /ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver
No entry names this claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why
No entry names this /loop run count freezing and its countdown disappearing after /clear; the count now restarts with the new conversation
Probably bridge-remote-control-peers-can-run-effort-model-rena --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt
Probably channels-banner-shows-a-waiting-for-your-organizations-pol /chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135)
Probably project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act #98135/chrome Reconnect never registers claude-in-chrome MCP tools when a session starts with the bridge down (survives --resume) Closed
ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account
No entry names this claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts
No entry names this claude agents could not deliver to a running session being saved and sent by themselves the next time it was restarted
No entry names this cat <<EOF | python3) asking for approval on every run
No entry names this claude agents failing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one)
No entry names this #84827Daemon self-respawn after a Homebrew cask upgrade targets the purged versioned path (ENOENT), killing every background session Open
rg or git grep) whose arguments the shell would still expand as wildcards; these now prompt for approval
No entry names this claude plugin test refusing to run after an upgrade because of an out-of-date saved setting
Probably claude-plugin-test-rollout-flag-hold-and-file-form git clone option keeping the sandbox exemption from a git pattern such as git * in sandbox.excludedCommands; it is now treated like the long form
No entry names this /ultrareview of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside .git (git 2.54+); it now refuses with an explanation
No entry names this /loop wakeup or scheduled task; Claude is now told and can schedule it again
No entry names this store.postgres_url can't be parsed; the error now names the setting and says what the URL may hold
Probably gateway-gives-a-clear-error-for-an-invalid-storepostgres-ur /sandbox Config tab on Linux and WSL when a sandbox read rule such as ~/**/.env covers a large folder
No entry names this #98023[BUG] 2.1.284 freezes on first Enter: new sandbox glob expander synchronously walks all of ~ for "~/**/…" denyRead patterns (follows symlinks, unbounded memory); 2.1.280 fine Open
claude -p run from the Bash tool)
No entry names this --continue or --resume <session-id> in the terminal
Probably cloud-sessions-print-a-claude-cloud-resume-hint, resume-with-resume-print-drop-turn-guard-adds-an-attach, background-job-respawn-can-fork-a-resume, remote-control-gains-allow-unattended-tool-calls-and-a-for /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file
No entry names this CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to dialogExpiry
Probably chrome-permission-env-defaults-and-remote-tools-unattended-h --restricted (and CLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket
Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check --allow-dangerously-skip-permissions on respawn without the bypass-permissions disclaimer having been accepted
Probably background-sessions-ignore-allow-dangerously-skip-permissi, new-proactivity-startup-level-gated-by-tengu-proactivity, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no claude auth login or with a credentials file already in the config directory
Probably cloud-session-auth-error-reworded-to-point-at-claude-auth-l /login reporting success when the keychain refused the new login and kept an old one it could not remove
Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act --include-partial-messages seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming
No entry names this ConfigChange hooks and reloading settings mid-command when .claude/settings.json or .claude/settings.local.json does not exist
Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with /loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after .claude/scheduled_tasks.json was deleted
No entry names this plugin-authoring skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section
No entry names this /plugin in the desktop app's Code tab: it now says where to install and manage plugins there
Probably plugin-marketplace-names-that-imitate-anthropics-are-refuse, plugin-in-desktop-app-returns-guidance-text claude auth login and /login and no longer blames API-key authentication
Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act /ultrareview upload: it is about half as long and says what kind of file is the problem
No entry names this /ultrareview upload refuses a checkout: each known cause now has its own message, with a way to fix it
No entry names this browser_batch call now gets 90 seconds, up from 60, before it is reported as timed out
Probably browser-batch-gets-its-own-tool-call-timeout CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC to also skip the startup connection warm-up
No entry names this --chrome, /chrome or your user settings
Probably claude-in-chrome-enabled-by-default-is-ignored-in-remote-a, project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act pyright, which is no longer treated as a read-only command
Nothing to match on $.process.spawn rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result
No entry names this ! shell command that contains raw control characters other than tab and newline, with a message that shows where they are
Nothing to match on /artifacts: opening an artifact in your browser now closes the list
No entry names this ps command ask for approval instead of running without asking
Nothing to match on /ultrareview upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text
No entry names this /code-review at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5
Probably medium-and-high-effort-now-map-to-a-different-measured-profi agent_id in Agent results to its agent ID (its name@team address stays in teammate_id); TeammateIdle hooks no longer fire from its subagents or forks
Probably teammate-agent-id-now-uses-resumable-id, teammate-ambiguity-message-wording, agent-spawn-result-reports-agent-id, taskstop-description-now-covers-background-agents-spawned-wi /loop): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup
No entry names this /model, /effort and /rename sent from claude agents to a busy background session to apply right away, without a confirmation, instead of when the turn ends
Probably effort-commands-log-from-level-and-route, medium-and-high-effort-now-map-to-a-different-measured-profi, bridge-remote-control-peers-can-run-effort-model-rena CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR sets the rate, 0 turns it off) instead of ending after 200 calls
Probably websearch-gets-a-refilling-token-bucket-budget CLAUDE_CODE_DISABLE_ATTACHMENTS so a repository's .claude/settings.json or .claude/settings.local.json can no longer set it; shell, user and managed settings still can
Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with, new-proactivity-startup-level-gated-by-tengu-proactivity, proactivity-opt-in-restored-across-worker-epochs, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no claude plugin update on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins
No entry names this gh api in cloud sessions: a host other than github.com set in GH_HOST or GH_REPO is now refused (use --hostname or a full URL), and stderr notes requests to other hosts
Probably gh-api-hostname-help-text-varies, new-gh-host-gh-repo-guidance-when-the-host-differs, gh-style-endpoint-repo-resolution-tightened, gh-tool-description-gh-host-and-gh-repo-host-text claude-api skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the auto permission policy
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts claude --environment <id> to create its session through the current Sessions API; printed and JSON session ids keep their session_… form
No entry names this !fast to switch a thread to fast mode, moving it to Opus if needed, and !fast off to switch back; replies show (fast) while it's on
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 2 lines added, 1 line removed.
Claude Code, interactive mode
15 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
334 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 70 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?