Follow Discord

Claude Code v2.1.290

620 entries read Grouped into 548 v2.1.289 → v2.1.290 Mods API: +8 added · 0 removed · 11 changed · 29 docs only Markdown JSON Follow Unofficial

You can now stop Claude Code compacting a long conversation while you sit idle by setting idleCompaction to false. The CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS variable sets how large a conversation must be before idle compaction starts. A new --proactivity flag picks how much Claude does on its own when it starts. CLAUDE_CODE_DISABLE_PROACTIVITY turns that choice off. Running claude remote-control with --allow-unattended-tool-calls lets cloud sessions use the current folder for one run. Remote sessions now read the SDK address from CLAUDE_CODE_REMOTE_SDK_URL when --sdk-url is not given.

This release has 7 entries in the build that are not switched on yet. One would let you attach more PDFs as a reference when their page count is known. Another would let an MCP server that needs you to sign in keep its saved tools. Claude Code could also tell the model that you pay per token and what a Bash call costs. Live-update connections could learn to spot a proxy answering in place of the real server. Each of these waits on a switch that is off by default.

Among this release's fixes, a cancel sent from outside the terminal no longer throws away every prompt you had queued. Plugin names that version 2.1.287 changed now match the installed plugins again. Synced skills now keep the text that sits above their main body. A plugin's hook error handler now still runs if the worker running those hooks is replaced mid-event. Stopping a remotely served background command now returns without waiting for it to end.

Written by our agent from the shipped bundle, not by Anthropic.

Five to try today

Picked from 36 you can use now
  1. claude remote-control gains --allow-unattended-tool-calls

    A new remote-control option lets auto-mode cloud sessions run commands in your folder without asking, sandboxed, with status messages showing what is allowed

    Sessions & agents
  2. A hidden --proactivity option and a matching session control request

    A new --proactivity <level> option, hidden from help, sets how much Claude does on its own, and a remote session started from Claude Code is sent the same level

    Elsewhere
  3. Idle compaction gets an idleCompaction off switch and a minimum-token override

    New idleCompaction setting can stop idle compaction, and CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS overrides its minimum token threshold

    Sessions & agents
  4. New --proactivity flag sets how much Claude does on its own at startup

    A --proactivity flag picks the proactivity level when Claude Code starts, and CLAUDE_CODE_DISABLE_PROACTIVITY turns the selector off

    Elsewhere
  5. Strings can be removed from prompts with an environment variable

    Setting CLAUDE_CODE_REMOVE_PROMPT_STRINGS to a JSON list removes those strings from the prompts Claude Code sends to the model

    Sessions & agents

Want the reasoning? Read walks the 61 entries that probably matter to you, each one opening to what changed and why.

Read this release → Every row →
72 of 548 shownClear
Reading as
Show only
Who it's for
Tier
Flag state
Names
Pick an entry · j / k steps through · rest on a row to peek
5 entries here

What probably matters to you

Anything you can use today, anything that visibly changes, and anything worth poking at. One line each, open for detail.

↑Improved
Use it now
Useful3 Signal2
Network Proxy no docs found unclear

Proxy auth helper runs under new rules for personal and policy sources#

With sources set to personAndPolicy, the proxy auth helper is skipped under folder trust or else runs from another folder

Unclear What sets the sources value, and which folder the helper now runs from, are not settled.

Details 0 0 Feedback
proxyAuthHelperConfig.sources
Were these the right ones to put at the top? 0 answered
Below the fold

Everything else

Smaller changes and internals, grouped as the pipeline found them. Nothing is dropped, it is only further down.

67 entries here

Improvementsopen

28 more of these are in What probably matters to you, above.

↑Improved
You'll notice
Useful3 Signal3
Group of 2 Chrome & Browser unclear

Fewer settings can now turn on Claude in Chrome at startup#

Remote and Cowork sessions ignore Claude in Chrome's enabled-by-default setting, and project settings can no longer turn it on

Unclear How Claude Code decides that a session counts as remote or Cowork is not shown.

Details 0 0 Feedback
claudeInChromeDefaultEnabled
↑Improved
You'll notice
Useful3 Signal3
Chrome & Browser unclear

Some Claude in Chrome actions can now ask for permission#

Some Claude in Chrome tools now ask for your permission rather than running at once, even with a whole-tool allow rule

Unclear Which Chrome tools are on the list that asks for permission is not stated.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal3
Sessions unclear

Remote sessions now refuse some interface requests from less trusted clients#

Remote sessions refuse interface requests from clients below a trust level, or when the policy or the list of who may write is unreadable or stale

Unclear Whether these checks always apply or only under a policy is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal3
Remote Control unclear

Remote Control no longer receives account memory prompts#

Account memory prompts now stay in the terminal instead of going to Remote Control, and outgoing events pass through a redaction step

Unclear It is not clear what the redaction step removes.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal3
Artifacts unclear

Stricter checks before automatic replies to artifact comments#

Before replying to an artifact comment unattended, Claude Code now does a fuller check when a quick rules check allows it

Unclear It is not clear what controls this behaviour or what a user sees differently.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal3
Channels unclear

Channel messages can now be ignored when a check fails#

Incoming channel notifications are now dropped unless a check passes, where before they were always queued

Unclear What the check tests is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Group of 2 Cloud Sessions unclear

Turn handoffs now track their age and expire after 30 minutes#

A turn handoff held over 30 minutes now fails as expired, the handler now gets the handoff's age, and handoff validation was reworked

Unclear Only the description of the error was seen, not the code that enforces the 30-minute limit.

Details 0 0 Feedback
↑Improved
You'll notice
Useful3 Signal2
Plugins unclear

Plugin installs fall back to the official marketplace's copy if a fetch fails#

If a plugin named without a marketplace cannot be fetched, Claude Code installs the official marketplace's copy instead of failing

Unclear Which marketplaces count as official, and exactly when the fallback applies, is not stated.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Permissions unclear

Allow rules no longer approve shell commands that redirect output elsewhere#

A command allowed only once its output redirection is removed is now rechecked as written, and refused if the full form is not allowed

Unclear It is unclear whether the redirection recheck always applies or depends on a switch that could not be identified.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Git unclear

Claude Code now ignores git config files that fail a safety check#

When Claude Code reads a repository's git config file, it now returns nothing if the content fails a check, instead of always using it

Unclear It is not clear what content the check rejects.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Permissions unclear

Remote tool calls now obey the session's read-deny rules#

Tool calls served to a remote session are now refused when a read-deny rule matches the path, or when the rules cannot be checked

Unclear Exactly which tools these checks cover is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Permissions unclear

Stricter checks when Claude Code runs tools for a remote host#

Remotely hosted tool calls now refuse over-long paths and settings-file edits, deny on a rule-check crash, and use up approvals that arrive too late

Unclear It is not clear which of these checks apply in every setup and which depend on a setting or remote switch.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Remote Control unclear

Remote Control no longer shows your account memory to remote clients#

Remote Control now replaces or drops account memory content before sending session events and history to remote clients

Unclear Whether the filter is controlled by a remote setting, and what decides when it is switched off, is not known.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Permissions unclear

Wildcards in permission rules are matched differently#

Permission rules with wildcards are now checked against a tool's name and its other names, replacing the old ** handling

Unclear Exactly which rules now match differently than before is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
MCP unclear

MCP allowlists now apply more strictly to claude.ai connectors#

An organisation's MCP allowlist now refuses claude.ai connectors it cannot find or does not admit, and matches them by their real name

Unclear What makes a connector count as admitted is not settled.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal2
Hooks unclear

PreToolUse hooks can be matched against more than one tool name#

Claude Code's check for PreToolUse hooks now matches against a wider list of names worked out from an extra tool name, not just one

Unclear It is not clear what the extra names are or what bypassCapabilityNotification does.

Details 0 0 Feedback
PreToolUse
↑Improved
You'll notice
Useful3 Signal1
Web Search unclear

Web search limit now refills over time and can apply per turn#

The web search cap is now a budget that refills each hour, and in some modes it counts per turn instead of per session

Unclear What decides whether the limit counts per turn or per session is not settled.

Details 0 0 Feedback
CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION
↑Improved
You'll notice
Useful3 Signal1
Plan Mode unclear

Resuming a session can put it back into plan mode#

When a resumed session was still in plan mode, Claude Code can now switch plan mode back on

Unclear It is not clear what switches this on or whether it applies only to remote sessions.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal2
Plugins unclear

Plugin install can now refuse some plugins as not found#

Installing a plugin can now stop with the not_found failure code when a check on that plugin matches

Unclear What the check looks up, and which plugins it matches, is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal2
Permissions unclear

Some rm commands with variables set in front now ask first#

Claude Code now rechecks rm commands with variables set before a declaration, and asks you when it cannot check them all

Unclear Which part of the new checking each of the two server flags controls is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Plugins unclear

Plugin marketplaces with names that imitate Anthropic's are refused#

Claude Code refuses to install a plugin marketplace whose name looks like Anthropic's own, and marks such names in the marketplace list

Unclear How Claude Code decides that a name looks like Anthropic's is not stated.

Details 0 0 Feedback
/plugin
↑Improved
You'll notice
Useful2 Signal1
MCP unclear

MCP servers over HTTP get response size limits and a clear error for br or zstd#

Claude Code now caps MCP HTTP response sizes, unpacks gzip and deflate itself, and refuses responses compressed with br or zstd

Unclear The size limits are not known, and it is not settled in which cases Claude Code does the unpacking itself.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Sessions unclear

Background sessions no longer queue slash commands while starting#

Messages sent to a starting background session are no longer queued if they are slash commands, and replies may return a new code

Unclear How ENOREPLY is shown to the user is unclear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Shell unclear

Bash commands now get their PATH from a new source#

Claude Code's saved shell setup now takes its PATH from a new source, falling back to your own, and always adds a guard on pkill

Unclear It is not clear what the new PATH value contains or when it differs from your own.

Details 0 0 Feedback
↑Improved
You'll notice
Useful2 Signal1
Cloud Sessions unclear

Handed-off calls that waited too long are now rejected#

A handoff the session service held for too long is now rejected and its calls are not run

Unclear The time limit and which feature these handoffs belong to are not settled.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

More awk and find commands now ask for permission first#

Claude Code now asks before running awk or find commands that trip an extra wildcard check, not only ones with unquoted wildcards

Unclear What the second wildcard check looks for is not clear.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

Better detection of scripts passed directly to shells, including PowerShell#

Claude Code recognises more ways of handing a shell an inline script, including PowerShell options like -EncodedCommand, in any capitalisation

Unclear Whether this check is used for permission decisions was not confirmed.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

More shell commands using $$ now ask for permission#

Shell commands using patterns like $$[ are now treated as too complex to judge and prompt for permission

Unclear The exact commands that now prompt when they did not before are not fully stated.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Plugins unclear

Saved plugin marketplaces with look-alike names are now refused#

Claude Code now refuses to load or refresh a saved marketplace whose name fails its look-alike check, even if it was added earlier

Unclear Exactly which names the look-alike check refuses is not stated.

Details 0 0 Feedback
↑Improved
You'll notice
Useful1 Signal1
Permissions unclear

Shell command permission checks were tightened in several places#

Claude Code's shell permission checks changed for sudo shell flags, += variable prefixes, command -v and backslashes

Unclear The overall effect on any particular command is not clear.

Details 0 0 Feedback
Verbatim
Official · Anthropic

Anthropic’s official release notes

Published verbatim by Anthropic for v2.1.290. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.

Of these 190 bullets, 30 name something an entry on this page also names, 67 name something no entry here does, and 93 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.

  • Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end No entry names this
  • Added agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's No entry names this
  • Added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool No entry names this
  • Added ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name No entry names this
  • Added to claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json) No entry names this
  • Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds Nothing to match on
  • Added claude attach <name> and claude logs <name>: part of a session name works in place of the id No entry names this
  • Added /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as ant apply files Probably bundled-claude-api-skill-adds-managed-agents-quickstarts
  • Added /claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as deep-researcher, with the ant CLI Probably bundled-claude-api-skill-adds-managed-agents-quickstarts
  • Added a warning when a managed settings file is a link to a file outside the managed settings folder Nothing to match on
  • Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains Probably cloud-session-auth-error-reworded-to-point-at-claude-auth-l
  • Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta Nothing to match on
  • Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors No entry names this
  • Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown Nothing to match on
  • Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run Nothing to match on #94728[BUG] Resuming a background subagent misses its prompt cache: messages_changed, no thinking blocks Open
  • Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an offset to read on Nothing to match on #95127[BUG] WebFetch truncation is invisible to the model — absent from the tool description, unmarked in the result, and the web-fetch subagent can neither detect nor recover from it Open
  • Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep No entry names this
  • Fixed /rewind not listing a prompt sent while Claude was still working No entry names this
  • Fixed scheduled tasks (/loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on No entry names this
  • Fixed scheduled tasks set in the foreground never firing after a ← or /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork No entry names this #96531[BUG] /loop scheduled task stops firing on its own after the session is backgrounded — fires only right after a user turn Open
  • Fixed headless --json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered No entry names this
  • Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy Nothing to match on
  • Fixed a project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule Probably instruction-file-loading-de-duplicated-via-a-held-set-and, edit-tool-results-carry-gitdiffread-flag-sealed-path-case, sandbox-read-blocking-and-wsl-mount-parsing-rework, withheld-memory-files-now-shown-as-a-startup-warning, instruction-files-claudemd-rules-held-outside-the-workin, plan-exit-dialog-hides-clear-context-option-for-ask-proactiv, startupresume-telemetry-adds-store-confirm-and-system-promp, home-settings-seeded-to-cloud-sessions-ccr, hooks-module-fsancestors-reads-agentsmd-with-a-held-outs
  • Fixed URL allow and deny patterns with a wildcard inside an xn-- host label matching differently from one process to the next Probably url-permission-patterns-reject-punycode-wildcard-hosts
  • Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions Nothing to match on
  • Fixed /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved No entry names this
  • Fixed the plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux Probably plansdirectory-rejects-backslashes-off-windows
  • Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in Nothing to match on
  • Fixed the background daemon's log passing terminal control characters to the screen under claude daemon run and claude daemon logs; they now show as \uXXXX escapes No entry names this
  • Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds Nothing to match on
  • Fixed a plugin hook with a .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call Nothing to match on
  • Fixed a mod's turn.step result listing a tool call that a mid-response model fallback had discarded No entry names this
  • Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file Nothing to match on
  • Fixed claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions No entry names this
  • Fixed /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration No entry names this
  • Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings Nothing to match on #96228[BUG] Refusal-fallback credited retry changes output_config.effort (high to xhigh), gets HTTP 400, then retries without the credit token Open
  • Windows: Fixed multi-line ! shell blocks in skills and commands failing when the file is saved with CRLF line endings Nothing to match on
  • Fixed Claude Code hanging until killed when a /permissions tab was clicked while searching in fullscreen mode No entry names this
  • Fixed conversation compaction sometimes failing with a "null is not an object" error No entry names this
  • Fixed plugin hooks reading an empty answer on turn.complete for a subagent that hands its report back in auto mode No entry names this
  • Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded Nothing to match on
  • Fixed a mod's prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name No entry names this
  • Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing Nothing to match on
  • Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read Nothing to match on
  • Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded Nothing to match on
  • Fixed disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents No entry names this
  • Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing Nothing to match on
  • Fixed an @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed mid-read Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check
  • Fixed Esc in the agents view confirming "Press enter again to restart this session — it isn't responding"; Esc now just reopens the session Nothing to match on
  • Fixed agent view losing a background session's /loop run count, countdown and live status line after the session enters a worktree that it creates No entry names this
  • Fixed claude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt No entry names this
  • Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on declare, typeset, export or readonly Nothing to match on
  • Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder Nothing to match on
  • Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded Nothing to match on
  • Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters Nothing to match on
  • Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted Nothing to match on
  • Fixed You should know writing its notes in English regardless of the language setting Nothing to match on #99232[FEATURE] "You should know" mod: respect the `language` setting instead of always writing in English Open
  • Fixed a freeze after sending some very long messages Nothing to match on
  • Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing Nothing to match on
  • Fixed claude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation No entry names this
  • Fixed Esc after an n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section Nothing to match on
  • Fixed claude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted No entry names this
  • Fixed /ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver No entry names this
  • Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore Nothing to match on #95842Claude in Chrome form_input denied by the auto-mode classifier in bypassPermissions (2.1.272): the "add a Bash permission rule" hint is still wrong, and a documented autoMode.allow rule is labelled [Auto-Mode Bypass] Open
  • Fixed claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why No entry names this
  • Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt No entry names this
  • Fixed agent view's /loop run count freezing and its countdown disappearing after /clear; the count now restarts with the new conversation Probably bridge-remote-control-peers-can-run-effort-model-rena
  • Fixed --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt Probably channels-banner-shows-a-waiting-for-your-organizations-pol
  • Fixed /chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135) Probably project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act #98135/chrome Reconnect never registers claude-in-chrome MCP tools when a session starts with the bridge down (survives --resume) Closed
  • Fixed mods staying off for people who reach Claude through a gateway (ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account No entry names this
  • Fixed replies sent from claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts No entry names this
  • Fixed slash commands and answers to a multiple-choice question that claude agents could not deliver to a running session being saved and sent by themselves the next time it was restarted No entry names this
  • Fixed sandboxed commands that pipe a heredoc into another command (cat <<EOF | python3) asking for approval on every run No entry names this
  • Fixed claude agents failing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one) No entry names this #84827Daemon self-respawn after a Homebrew cask upgrade targets the purged versioned path (ENOENT), killing every background session Open
  • Fixed agent view's "restart this session fresh" re-sending an earlier message from the session instead of starting with an empty conversation No entry names this
  • Fixed Bash permission checks auto-approving some read-only commands (such as rg or git grep) whose arguments the shell would still expand as wildcards; these now prompt for approval No entry names this
  • Fixed claude plugin test refusing to run after an upgrade because of an out-of-date saved setting Probably claude-plugin-test-rollout-flag-hold-and-file-form
  • Fixed Bash permission checks auto-approving certain commands whose variable names zsh reads differently from bash; these now prompt for approval Nothing to match on
  • Fixed a short form of a git clone option keeping the sandbox exemption from a git pattern such as git * in sandbox.excludedCommands; it is now treated like the long form No entry names this
  • Fixed the first feature-flag request of a session ignoring a proxy or API endpoint set in a project's settings Nothing to match on
  • Fixed /ultrareview of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside .git (git 2.54+); it now refuses with an explanation No entry names this
  • Fixed cloud sessions staying asleep after a container restart lost a pending /loop wakeup or scheduled task; Claude is now told and can schedule it again No entry names this
  • Fixed the Claude apps gateway's retention sweep deleting a returning developer's identity row refreshed at the same moment, on PostgreSQL versions without the November 2025 fixes Nothing to match on
  • Fixed sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules Nothing to match on
  • Fixed the Claude apps gateway failing to start when the certificate it presents to the identity provider has an empty subject Nothing to match on
  • Fixed the Claude apps gateway exiting with a bare "Invalid URL" when store.postgres_url can't be parsed; the error now names the setting and says what the URL may hold Probably gateway-gives-a-clear-error-for-an-invalid-storepostgres-ur
  • Fixed background agents failing with "Agent stalled" and Workflow tool subagents restarting from their prompt when a Mac woke from sleep No entry names this
  • Fixed slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL) Nothing to match on
  • Fixed a response interrupted by computer sleep being treated as a stalled stream on Bedrock, Vertex, Foundry, and custom gateways Nothing to match on
  • Fixed a freeze before the first request and in the /sandbox Config tab on Linux and WSL when a sandbox read rule such as ~/**/.env covers a large folder No entry names this #98023[BUG] 2.1.284 freezes on first Enter: new sandbox glob expander synchronously walks all of ~ for "~/**/…" denyRead patterns (follows symlinks, unbounded memory); 2.1.280 fine Open
  • Fixed skills not being found when asked for by the name in SKILL.md when their folder has a different name (for example a non-English name): the skill listing now shows both names Nothing to match on
  • Fixed a plan written in plan mode being lost when a cloud session's container restarted before the plan was presented Nothing to match on
  • Fixed the Bash tool occasionally losing shell aliases, functions and plugin PATH entries for a whole session when its first command ran seconds after startup on a new config directory Nothing to match on
  • Fixed unbounded memory use when an HTTP MCP server sends a very large response Nothing to match on
  • Fixed artifact operations failing in a Claude Code run started from inside a cloud session (for example claude -p run from the Bash tool) No entry names this
  • Fixed files sent from remote sessions sometimes being refused as "not the one approved" when four or more were sent at once No entry names this
  • Fixed plan mode not being restored when resuming a session with --continue or --resume <session-id> in the terminal Probably cloud-sessions-print-a-claude-cloud-resume-hint, resume-with-resume-print-drop-turn-guard-adds-an-attach, background-job-respawn-can-fork-a-resume, remote-control-gains-allow-unattended-tool-calls-and-a-for
  • Fixed a marketplace named after another GitHub marketplace's download folder stopping that marketplace from downloading Nothing to match on
  • Fixed automatic compaction giving up with "Prompt is too long" when a Mac went to sleep while it was running No entry names this
  • Fixed the rewind menu (Esc Esc / /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file No entry names this
  • Fixed a subdirectory's AGENTS.md not being attached when a file under it is @-mentioned Nothing to match on #98796Nested `AGENTS.md` not loaded when a file in its directory is `@`-mentioned (nested `CLAUDE.md` is) Open
  • Fixed self-hosted runner sessions resumed after a stopped runner failing with "missing but already registered worktree" when the sessions folder is a relative symlink No entry names this
  • Fixed a freeze when the secret scan or a permission prompt met long token-like text Nothing to match on
  • Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands Nothing to match on
  • Fixed CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to dialogExpiry Probably chrome-permission-env-defaults-and-remote-tools-unattended-h
  • Fixed a stall when an MCP server's tool listing contains very long runs of combining characters Nothing to match on
  • Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block Nothing to match on
  • Fixed Claude in Chrome's browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog's list going stale after a switch Nothing to match on
  • Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree Nothing to match on #98307Worktree isolation in a background session blocks subagents' Bash commands, even for other repos Open
  • Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login Nothing to match on
  • Fixed --restricted (and CLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check
  • Fixed sessions moved to the background while idle reopening as "no saved transcript" after a restart or idle cleanup; they now resume their conversation No entry names this
  • Fixed background workers honoring --allow-dangerously-skip-permissions on respawn without the bypass-permissions disclaimer having been accepted Probably background-sessions-ignore-allow-dangerously-skip-permissi, new-proactivity-startup-level-gated-by-tengu-proactivity, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no
  • Fixed Claude replying in an endless loop when a plugin's async Stop hook passes an unquoted script path under a folder with a space, such as Application Support Nothing to match on
  • Fixed a freeze of several seconds when secret masking met very long unbroken text Nothing to match on
  • Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input Nothing to match on
  • Fixed first launch asking to pick a login method again after claude auth login or with a credentials file already in the config directory Probably cloud-session-auth-error-reworded-to-point-at-claude-auth-l
  • Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts Nothing to match on
  • Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do Nothing to match on
  • Fixed macOS /login reporting success when the keychain refused the new login and kept an old one it could not remove Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act
  • Fixed SDK hosts using --include-partial-messages seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming No entry names this
  • Fixed sandboxed Bash commands on Linux running ConfigChange hooks and reloading settings mid-command when .claude/settings.json or .claude/settings.local.json does not exist Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with
  • Fixed errors reading "Premature close" instead of naming the missing program when a tool Claude Code runs, such as git or gh, is not installed (macOS, Linux) No entry names this
  • Fixed /loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after .claude/scheduled_tasks.json was deleted No entry names this
  • Fixed edits to the file a symlinked settings file points at running without the settings-file permission question Nothing to match on
  • Improved MCP startup behind a network proxy: a server the proxy blocks (HTTP 403) is no longer retried three times Nothing to match on
  • Improved permission prompts from background agents to show the Ctrl+X Ctrl+K shortcut that stops all background agents Nothing to match on
  • Improved the built-in plugin-authoring skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section No entry names this
  • Improved the reply to /plugin in the desktop app's Code tab: it now says where to install and manage plugins there Probably plugin-marketplace-names-that-imitate-anthropics-are-refuse, plugin-in-desktop-app-returns-guidance-text
  • Improved the Bash changed-files view: when a chained command includes git merge, pull or checkout, it lists the files without full diffs Nothing to match on
  • Improved the Claude apps gateway's log when an upstream's cloud credentials or connection fail: the warning now ends with the underlying cause Nothing to match on
  • Improved the error shown when a cloud session is started without a claude.ai sign-in: it now names claude auth login and /login and no longer blames API-key authentication Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act
  • Improved the Read tool's message for binary files: it now points Claude to a skill or a shell command that can read the format Nothing to match on
  • Improved the error shown when a git config file stops the /ultrareview upload: it is about half as long and says what kind of file is the problem No entry names this
  • Improved the errors shown when the /ultrareview upload refuses a checkout: each known cause now has its own message, with a way to fix it No entry names this
  • Improved the Claude apps gateway to log a warning during the last 30 days before the certificate it presents to the identity provider expires Nothing to match on
  • Improved Claude in Chrome: a browser_batch call now gets 90 seconds, up from 60, before it is reported as timed out Probably browser-batch-gets-its-own-tool-call-timeout
  • Improved the Claude apps gateway's browser sign-in pages: brand fonts, centered layout, and dark mode Nothing to match on
  • Improved responsiveness while resuming large sessions: timers, input and rendering keep running while the transcript loads Nothing to match on
  • Improved the / and @ suggestion lists: the selected row now starts with a ❯ pointer, so you can see it without color Nothing to match on
  • Changed CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC to also skip the startup connection warm-up No entry names this
  • Changed Claude in Chrome so that a project's settings files can no longer turn it on; use --chrome, /chrome or your user settings Probably claude-in-chrome-enabled-by-default-is-ignored-in-remote-a, project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act
  • Changed the Bash tool to ask for permission before running pyright, which is no longer treated as a read-only command Nothing to match on
  • Changed what a mod's $.process.spawn rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result No entry names this
  • Changed the background daemon's log to write a multi-line message as one JSON-quoted line Nothing to match on
  • Changed skills and custom commands to refuse a ! shell command that contains raw control characters other than tab and newline, with a message that shows where they are Nothing to match on
  • Changed /artifacts: opening an artifact in your browser now closes the list No entry names this
  • Changed Bash permission checks so that more forms of the ps command ask for approval instead of running without asking Nothing to match on
  • Changed plugin hooks so long text is clipped and logged instead of being refused or dropped silently Nothing to match on
  • Changed background sessions whose scheduled task is gone: they now move to Completed about 20 seconds later and can be updated or shut down when idle Nothing to match on
  • Changed the "Press ← again" confirm on a just-cleared prompt: a second ← no longer has to wait a second before it switches, and holding ← down now switches too No entry names this
  • Changed the errors shown when the /ultrareview upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text No entry names this
  • Changed /code-review at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5 Probably medium-and-high-effort-now-map-to-a-different-measured-profi
  • Changed an in-process teammate's agent_id in Agent results to its agent ID (its name@team address stays in teammate_id); TeammateIdle hooks no longer fire from its subagents or forks Probably teammate-agent-id-now-uses-resumable-id, teammate-ambiguity-message-wording, agent-spawn-result-reports-agent-id, taskstop-description-now-covers-background-agents-spawned-wi
  • Changed background sessions waiting on a scheduled wakeup (/loop): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup No entry names this
  • Changed /model, /effort and /rename sent from claude agents to a busy background session to apply right away, without a confirmation, instead of when the turn ends Probably effort-commands-log-from-level-and-route, medium-and-high-effort-now-map-to-a-different-measured-profi, bridge-remote-control-peers-can-run-effort-model-rena
  • Changed the Claude apps gateway's minimum supported PostgreSQL version from 14 to 11 Nothing to match on
  • Changed the interactive session's WebSearch budget to refill over time (100 calls/hour; CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR sets the rate, 0 turns it off) instead of ending after 200 calls Probably websearch-gets-a-refilling-token-bucket-budget
  • Changed CLAUDE_CODE_DISABLE_ATTACHMENTS so a repository's .claude/settings.json or .claude/settings.local.json can no longer set it; shell, user and managed settings still can Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with, new-proactivity-startup-level-gated-by-tengu-proactivity, proactivity-opt-in-restored-across-worker-epochs, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no
  • Changed claude plugin update on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins No entry names this
  • Changed the built-in gh api in cloud sessions: a host other than github.com set in GH_HOST or GH_REPO is now refused (use --hostname or a full URL), and stderr notes requests to other hosts Probably gh-api-hostname-help-text-varies, new-gh-host-gh-repo-guidance-when-the-host-differs, gh-style-endpoint-repo-resolution-tightened, gh-tool-description-gh-host-and-gh-repo-host-text
  • Changed the claude-api skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the auto permission policy Probably bundled-claude-api-skill-adds-managed-agents-quickstarts
  • Self-hosted runners: Changed claude --environment <id> to create its session through the current Sessions API; printed and JSON session ids keep their session_… form No entry names this
  • [VSCode] Added a screen reader announcement, "Message queued.", when you send a message while Claude is working No entry names this
  • [VSCode] Added a way to review and run a plugin marketplace's install or update command from the Manage plugins dialog Nothing to match on
  • [VSCode] Fixed a blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place Nothing to match on
  • [VSCode] Fixed settings dialogs blaming a timeout when Claude Code stopped unexpectedly during a save Nothing to match on
  • [VSCode] Fixed the branch switch dialog offering to switch when it could not check for uncommitted changes Nothing to match on
  • [VSCode] Fixed a permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it Nothing to match on
  • [VSCode] Fixed sign-in and new sessions giving no clear reason when Claude Code cannot find or start its program Nothing to match on
  • [VSCode] Fixed the agent map showing a nested sub-agent with "Tool calls (0)" and placing the agents it starts under the main agent No entry names this
  • [VSCode] Improved Continue After Reload: tabs reopened after VS Code restarts its extensions now also finish a step the restart interrupted Nothing to match on
  • [VSCode] Improved file pills in messages: hovering one now shows the file's path from the project folder, so same-named files can be told apart Nothing to match on
  • [VSCode] Changed message timestamps to show by default (turn them off with the Claude Code: Show Message Timestamps setting) Nothing to match on
  • [Cloud sessions] Fixed turning off prompt suggestions through a cloud environment's environment variables having no effect in new cloud sessions Nothing to match on
  • [Cloud sessions] Fixed the working indicator in a cloud session spinning on for several seconds after Claude's reply had finished; it now stops with the reply Nothing to match on
  • [Cloud sessions] Fixed History on a never-run routine's page still saying "No runs yet" after you pressed Run now; it now shows the new run No entry names this
  • [Cloud sessions] Fixed an unarchived cloud session looking as if Claude were still working until you sent another message Nothing to match on
  • [Remote Control] Fixed a computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds Nothing to match on
  • [Claude Tag] Added fast mode in Slack: mention Claude with !fast to switch a thread to fast mode, moving it to Opus if needed, and !fast off to switch back; replies show (fast) while it's on No entry names this
  • [Claude Tag] Added the optional Path prefixes field when creating a custom connection in an access bundle, so its allow rule can cover only those paths instead of the whole host Nothing to match on
  • [Claude Tag] Fixed members with the Claude Tag Admin permission getting "Couldn't load memory files" on the Activity page's Memory tab; they can now read workspace and channel memory No entry names this
  • [Claude Tag] Fixed a workspace guest's Confirm on a Claude settings card in Slack removing its buttons for everyone; only the guest sees the refusal, and members can still confirm or cancel Nothing to match on
  • [Claude Tag] Fixed scheduled routines in Slack channels running on a model other than the channel's default; each run that starts a new session now uses the current default model Nothing to match on
  • [Claude Tag] Fixed GitHub repositories in an access bundle attached by a channel-name rule being refused in the channels the rule covers; Claude can now add, list and clone them there Nothing to match on
  • [Claude Tag] Improved Claude's notice in your direct messages when your own Claude plan's usage limit is reached: it shows within seconds and says when the limit resets Nothing to match on
  • [Claude Tag] Improved the earlier Claude in Slack app's reply when it can't start a session: it now says what failed and who can fix it, in full only once per thread Nothing to match on
  • [Claude Tag] Changed the channel instructions limit to 8,192 characters instead of bytes, so non-English text gets the same room, and added a character count beside Save on the Configure page Nothing to match on
  • [Code Review] Fixed blocking review comments sometimes opening with a "nit" label that contradicted their severity Nothing to match on
  • [Code Review] Fixed tips to comment "@claude review" being posted on fork and Manual-mode pull requests in organizations that have turned Code Review off No entry names this

A model matched these bullets to the GitHub issues they fix, so a link can be wrong.

System prompt

1 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 2 lines added, 1 line removed.

Claude Code, interactive mode

15 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.

Documentation

What the docs did around this release

334 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.

Switches

Every name in this release

The 70 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.

Slash commands

CLI flags

Environment variables

Settings and names in the code

Feedback