Stored permission choice gains a host-side check#
Claude Code's stored permission choice now also records whether the host allows it
Unclear What the host check looks at and which feature uses it are unclear.
You can now stop Claude Code compacting a long conversation while you sit idle by setting idleCompaction to false. The CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS variable sets how large a conversation must be before idle compaction starts. A new --proactivity flag picks how much Claude does on its own when it starts. CLAUDE_CODE_DISABLE_PROACTIVITY turns that choice off. Running claude remote-control with --allow-unattended-tool-calls lets cloud sessions use the current folder for one run. Remote sessions now read the SDK address from CLAUDE_CODE_REMOTE_SDK_URL when --sdk-url is not given.
This release has 7 entries in the build that are not switched on yet. One would let you attach more PDFs as a reference when their page count is known. Another would let an MCP server that needs you to sign in keep its saved tools. Claude Code could also tell the model that you pay per token and what a Bash call costs. Live-update connections could learn to spot a proxy answering in place of the real server. Each of these waits on a switch that is off by default.
Among this release's fixes, a cancel sent from outside the terminal no longer throws away every prompt you had queued. Plugin names that version 2.1.287 changed now match the installed plugins again. Synced skills now keep the text that sits above their main body. A plugin's hook error handler now still runs if the worker running those hooks is replaced mid-event. Stopping a remotely served background command now returns without waiting for it to end.
Written by our agent from the shipped bundle, not by Anthropic.
A new remote-control option lets auto-mode cloud sessions run commands in your folder without asking, sandboxed, with status messages showing what is allowed
Sessions & agentsA new --proactivity <level> option, hidden from help, sets how much Claude does on its own, and a remote session started from Claude Code is sent the same level
New idleCompaction setting can stop idle compaction, and CLAUDE_CODE_IDLE_COMPACT_MIN_TOKENS overrides its minimum token threshold
Sessions & agentsA --proactivity flag picks the proactivity level when Claude Code starts, and CLAUDE_CODE_DISABLE_PROACTIVITY turns the selector off
Setting CLAUDE_CODE_REMOVE_PROMPT_STRINGS to a JSON list removes those strings from the prompts Claude Code sends to the model
Sessions & agentsWant the reasoning? Read walks the 61 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →8 more of these are in What probably matters to you, on page 1.
Claude Code's stored permission choice now also records whether the host allows it
Unclear What the host check looks at and which feature uses it are unclear.
A check on shell commands that run commands held in variables now gives three answers, with possible when it cannot work everything out
Unclear What this check decides beyond permission handling is not clear.
Claude Code now keeps deny and ask read rules from your user settings separate and removes duplicates
Unclear Whether this changes which files are blocked is not known.
When part of a tool's input is set aside, its permission check is now marked incomplete instead of being allowed outright
Unclear What input gets set aside and what the extra check does are not clear.
Claude Code's shell command analysis now marks declaration commands where its quote tracking may go out of step
Unclear It is not clear where this new marker is used or what it changes about prompts.
The check that lets read-only commands run without asking now receives extra information besides the command itself
Unclear It is not clear what the extra information is or whether it changes which commands are approved automatically.
Claude Code gained internal tracking of the claude.ai connector list, a new safeguards option and a shorter keyboard hint style
Unclear What the tool result safeguards option turns on is not settled.
Calls to MCP tools that are moved to the background now carry account memory server details along
Unclear What difference this makes for a user is unclear.
Claude Code can now single out its device tools for special handling, under a server flag that is off unless switched on
Unclear What Claude Code does differently with a tool once this check passes is not settled.
Reconnecting or enabling an MCP server now notes whether its settings came from your own configuration and clears its tools and commands on swap
Unclear It is not clear what the new "asked" flag does, or whether it changes when you are asked to approve a server.
Claude Code now ranks MCP tools using the plugin source stored on each tool instead of looking up the plugin's record
Unclear It is not clear whether any tool actually ends up in a different tier.
Tools that come from an MCP server now carry information about that server inside Claude Code
Unclear It is not clear which parts of Claude Code read this server information or whether anything visible changes because of it.
Claude Code can now scan the current git checkout for tracked files that were replaced, using git diff-index and git ls-files
Unclear Where Claude Code uses this check and what turns it on is not settled.
Looking up a repository's origin now logs when the git config cannot be read instead of silently using the default
Unclear What Claude Code does after the lookup returns the marker is not known.
A git file-listing failure now logs only its exit code, and cloud worktree setup and its error messages were reworked
Unclear What the reworked worktree step does differently is not known.
The git information Claude Code gathers now includes a lookup of the repository's visibility and whether it is the first in the process
Unclear Where this git information is sent is not clear.
Claude Code builds an environment with npm_config_ignore_scripts set to true for a process it starts, now in a changed way
Unclear Which process is started this way is not known.
The maximum timeout for a plugin command is no longer written as 600 seconds, and the default is still 60
Unclear Whether the maximum is still 600 seconds is not clear.
--replace hint#The hint that suggests --replace when a plugin comes from another marketplace reads exactly as before
Unclear The marketplace list --claudeai output is also part of this change, but nothing describes how it differs.
When Claude Code caches plugin marketplace information from settings, it now also passes along where that marketplace comes from
Unclear Whether this changes how the cache is keyed or checked is not shown.
The consent check for unattended calls now also looks up consent for each call or target, not only one global setting
Unclear What the new per-call lookup checks, and which feature uses this path, is not known.
The device bridge now checks whether it is enabled through a cloud connection, and more of its stages are recorded in usage data
Unclear It is not clear what the device bridge does for a user or whether this changes anything they would notice.
Claude Code can now read a stored remote-control state in an older or newer format and sort it into one of several states
Unclear What uses this new reading, and whether it is switched on, is not clear.
Tool calls now name the tool host interface, and the refusal for tools that do not accept consent covers MCP information tools
An internal step that fetches memory context at the end of each turn no longer returns reason codes
Unclear What difference this makes to users is not known.
The release notes bundled with Claude Code now start at version 2.1.287
On Windows, Claude Code now sets a file's timestamps through the native NtSetInformationFile call
Unclear How file times were set on Windows before this change is not shown.
Auto mode's check of a GitHub repository's visibility now shares lookups already in progress and records how long it takes
Requests to the remote classifier used by auto mode now include a field derived from the current working directory
Unclear How the classifier uses the directory value is not known.
Claude Code adds seven environment variable names for background sessions and terminal hosts to a list it keeps of such names
Unclear It is not clear what this list is used for or whether the feature behind these names is in use.
Claude Code no longer sends a tasks/cancel request when a task stops for one particular reason
Unclear Which stop reason skips the cancel is not known.
Several small internal changes touch compaction, effort level, remote sessions and how agent task status is shown
Unclear It is not clear what each change does for a user or whether any of them is switched on.
The text reminding Claude not to call tools while compacting the conversation is gone from where it was kept
Unclear It is not clear whether the reminder was dropped from the compaction prompt or only moved elsewhere.
Claude Code can now pick out hook commands that run a python, perl, sh, bash or dash script from a plugin, project or home folder
Unclear It is not clear what Claude Code does with a hook command once it matches this pattern.
Claude Code can now check whether a registered hook is marked as caught and whether its matcher applies
Unclear It is not clear what a caught hook does or what part of Claude Code checks for one.
When a model switch is rejected with a certain kind of 400 error, Claude Code now records it as a refusal tied to the session's mode
Unclear It is not clear which 400 errors count as a mode-based refusal.
When you switch models, Claude Code now runs a different routine to prepare work ahead of time
Unclear What the replacement routine does differently is not known.
The reset of permission settings when a skill runs can now be triggered by a separate check as well as by its server-controlled switch
Unclear What the separate check looks at is not known.
Matching skill and command names, stripping accent marks and cleaning text now share one Unicode normalization routine
Unclear It is not clear whether the shared routine produces different output from the inline calls it replaced.
The check on starting Claude Code from a home folder now also reports a drive mounted twice and a mount source it could not read
Unclear It is not known whether these new conditions change when a launch is refused or are only reported.
When startup timing is on, Claude Code now measures each step of setting up its local message inbox
Subagent notes are now wrapped when the subagent's instructions are built, and the agent-proxy search reports failures separately from timeouts
Unclear What the extra wrapping does to the subagent's notes is not clear.
Background subagents and workflow agents now carry a marker saying the stop-agents action can stop them
Unclear It is not clear what reads this marker or what it changes when you stop agents.
One more part of Claude Code now reads the idle-notification delay from messageIdleNotifThresholdMs
Unclear It is not certain this part of Claude Code is related to idle notifications at all.
The part of Claude Code that shows a shell command's output now receives the command that was run and its time limit
Unclear It is not clear whether the command or the time limit is actually shown in the output yet.
The tengu_calm_bear check now always returns false, so the server can no longer turn on whatever it controlled
Unclear What feature this switch controlled is not shown.
Claude Code stops passing a "threaded continue" option with its requests; the option to skip message cache markers stays
Unclear The option may have moved somewhere else rather than being removed.
The script that saves a snapshot of your shell environment no longer defines the _cc_builtins and _cc_copy helpers
Unclear It is not clear whether the copy helper's job moved somewhere else or was dropped.
Published verbatim by Anthropic for v2.1.290. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 190 bullets, 30 name something an entry on this page also names, 67 name something no entry here does, and 93 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
No entry names this agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
No entry names this ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool
No entry names this ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
No entry names this claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)
No entry names this claude attach <name> and claude logs <name>: part of a session name works in place of the id
No entry names this /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as ant apply files
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts /claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as deep-researcher, with the ant CLI
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts offset to read on
Nothing to match on #95127[BUG] WebFetch truncation is invisible to the model — absent from the tool description, unmarked in the result, and the web-fetch subagent can neither detect nor recover from it Open
/rewind not listing a prompt sent while Claude was still working
No entry names this /loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on
No entry names this /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork
No entry names this #96531[BUG] /loop scheduled task stops firing on its own after the session is backgrounded — fires only right after a user turn Open
--json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered
No entry names this CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule
Probably instruction-file-loading-de-duplicated-via-a-held-set-and, edit-tool-results-carry-gitdiffread-flag-sealed-path-case, sandbox-read-blocking-and-wsl-mount-parsing-rework, withheld-memory-files-now-shown-as-a-startup-warning, instruction-files-claudemd-rules-held-outside-the-workin, plan-exit-dialog-hides-clear-context-option-for-ask-proactiv, startupresume-telemetry-adds-store-confirm-and-system-promp, home-settings-seeded-to-cloud-sessions-ccr, hooks-module-fsancestors-reads-agentsmd-with-a-held-outs xn-- host label matching differently from one process to the next
Probably url-permission-patterns-reject-punycode-wildcard-hosts /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved
No entry names this plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux
Probably plansdirectory-rejects-backslashes-off-windows claude daemon run and claude daemon logs; they now show as \uXXXX escapes
No entry names this .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call
Nothing to match on turn.step result listing a tool call that a mid-response model fallback had discarded
No entry names this claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions
No entry names this /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration
No entry names this ! shell blocks in skills and commands failing when the file is saved with CRLF line endings
Nothing to match on /permissions tab was clicked while searching in fullscreen mode
No entry names this answer on turn.complete for a subagent that hands its report back in auto mode
No entry names this prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name
No entry names this disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents
No entry names this @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed mid-read
Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check /loop run count, countdown and live status line after the session enters a worktree that it creates
No entry names this claude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt
No entry names this declare, typeset, export or readonly
Nothing to match on language setting
Nothing to match on #99232[FEATURE] "You should know" mod: respect the `language` setting instead of always writing in English Open
claude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation
No entry names this n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section
Nothing to match on claude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted
No entry names this /ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver
No entry names this claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why
No entry names this /loop run count freezing and its countdown disappearing after /clear; the count now restarts with the new conversation
Probably bridge-remote-control-peers-can-run-effort-model-rena --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt
Probably channels-banner-shows-a-waiting-for-your-organizations-pol /chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135)
Probably project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act #98135/chrome Reconnect never registers claude-in-chrome MCP tools when a session starts with the bridge down (survives --resume) Closed
ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account
No entry names this claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts
No entry names this claude agents could not deliver to a running session being saved and sent by themselves the next time it was restarted
No entry names this cat <<EOF | python3) asking for approval on every run
No entry names this claude agents failing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one)
No entry names this #84827Daemon self-respawn after a Homebrew cask upgrade targets the purged versioned path (ENOENT), killing every background session Open
rg or git grep) whose arguments the shell would still expand as wildcards; these now prompt for approval
No entry names this claude plugin test refusing to run after an upgrade because of an out-of-date saved setting
Probably claude-plugin-test-rollout-flag-hold-and-file-form git clone option keeping the sandbox exemption from a git pattern such as git * in sandbox.excludedCommands; it is now treated like the long form
No entry names this /ultrareview of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside .git (git 2.54+); it now refuses with an explanation
No entry names this /loop wakeup or scheduled task; Claude is now told and can schedule it again
No entry names this store.postgres_url can't be parsed; the error now names the setting and says what the URL may hold
Probably gateway-gives-a-clear-error-for-an-invalid-storepostgres-ur /sandbox Config tab on Linux and WSL when a sandbox read rule such as ~/**/.env covers a large folder
No entry names this #98023[BUG] 2.1.284 freezes on first Enter: new sandbox glob expander synchronously walks all of ~ for "~/**/…" denyRead patterns (follows symlinks, unbounded memory); 2.1.280 fine Open
claude -p run from the Bash tool)
No entry names this --continue or --resume <session-id> in the terminal
Probably cloud-sessions-print-a-claude-cloud-resume-hint, resume-with-resume-print-drop-turn-guard-adds-an-attach, background-job-respawn-can-fork-a-resume, remote-control-gains-allow-unattended-tool-calls-and-a-for /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file
No entry names this CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to dialogExpiry
Probably chrome-permission-env-defaults-and-remote-tools-unattended-h --restricted (and CLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket
Probably attachment-paths-are-displayed-in-a-normalized-form-in-error, safe-mode-is-now-evaluated-lazily-and-uses-the-same-check --allow-dangerously-skip-permissions on respawn without the bypass-permissions disclaimer having been accepted
Probably background-sessions-ignore-allow-dangerously-skip-permissi, new-proactivity-startup-level-gated-by-tengu-proactivity, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no claude auth login or with a credentials file already in the config directory
Probably cloud-session-auth-error-reworded-to-point-at-claude-auth-l /login reporting success when the keychain refused the new login and kept an old one it could not remove
Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act --include-partial-messages seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming
No entry names this ConfigChange hooks and reloading settings mid-command when .claude/settings.json or .claude/settings.local.json does not exist
Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with /loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after .claude/scheduled_tasks.json was deleted
No entry names this plugin-authoring skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section
No entry names this /plugin in the desktop app's Code tab: it now says where to install and manage plugins there
Probably plugin-marketplace-names-that-imitate-anthropics-are-refuse, plugin-in-desktop-app-returns-guidance-text claude auth login and /login and no longer blames API-key authentication
Probably onboarding-sign-in-skip-tracked-login-prompt-kept, trusted-device-error-text-reworded, cloud-session-auth-error-reworded-to-point-at-claude-auth-l, chrome-menu-reports-live-connection-state-and-reconnect-act /ultrareview upload: it is about half as long and says what kind of file is the problem
No entry names this /ultrareview upload refuses a checkout: each known cause now has its own message, with a way to fix it
No entry names this browser_batch call now gets 90 seconds, up from 60, before it is reported as timed out
Probably browser-batch-gets-its-own-tool-call-timeout CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC to also skip the startup connection warm-up
No entry names this --chrome, /chrome or your user settings
Probably claude-in-chrome-enabled-by-default-is-ignored-in-remote-a, project-settings-can-no-longer-turn-on-claude-in-chrome-a-w, chrome-disabled-session-notice-tells-the-model-not-to-use-br, chrome-menu-reports-live-connection-state-and-reconnect-act pyright, which is no longer treated as a read-only command
Nothing to match on $.process.spawn rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result
No entry names this ! shell command that contains raw control characters other than tab and newline, with a message that shows where they are
Nothing to match on /artifacts: opening an artifact in your browser now closes the list
No entry names this ps command ask for approval instead of running without asking
Nothing to match on /ultrareview upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text
No entry names this /code-review at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5
Probably medium-and-high-effort-now-map-to-a-different-measured-profi agent_id in Agent results to its agent ID (its name@team address stays in teammate_id); TeammateIdle hooks no longer fire from its subagents or forks
Probably teammate-agent-id-now-uses-resumable-id, teammate-ambiguity-message-wording, agent-spawn-result-reports-agent-id, taskstop-description-now-covers-background-agents-spawned-wi /loop): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup
No entry names this /model, /effort and /rename sent from claude agents to a busy background session to apply right away, without a confirmation, instead of when the turn ends
Probably effort-commands-log-from-level-and-route, medium-and-high-effort-now-map-to-a-different-measured-profi, bridge-remote-control-peers-can-run-effort-model-rena CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR sets the rate, 0 turns it off) instead of ending after 200 calls
Probably websearch-gets-a-refilling-token-bucket-budget CLAUDE_CODE_DISABLE_ATTACHMENTS so a repository's .claude/settings.json or .claude/settings.local.json can no longer set it; shell, user and managed settings still can
Probably background-worker-bypass-permission-mode-requires-consent-in, background-sessions-ignore-allow-dangerously-skip-permissi, cloud-session-settings-review-now-covers-user-settings-with, new-proactivity-startup-level-gated-by-tengu-proactivity, proactivity-opt-in-restored-across-worker-epochs, new-relaunchproactivity-env-vars-added-to-a-scrub-list-no claude plugin update on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins
No entry names this gh api in cloud sessions: a host other than github.com set in GH_HOST or GH_REPO is now refused (use --hostname or a full URL), and stderr notes requests to other hosts
Probably gh-api-hostname-help-text-varies, new-gh-host-gh-repo-guidance-when-the-host-differs, gh-style-endpoint-repo-resolution-tightened, gh-tool-description-gh-host-and-gh-repo-host-text claude-api skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the auto permission policy
Probably bundled-claude-api-skill-adds-managed-agents-quickstarts claude --environment <id> to create its session through the current Sessions API; printed and JSON session ids keep their session_… form
No entry names this !fast to switch a thread to fast mode, moving it to Opus if needed, and !fast off to switch back; replies show (fast) while it's on
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 2 lines added, 1 line removed.
Claude Code, interactive mode
15 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
334 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 70 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?