MCP sign-in messages now give advice that fits where you are running#
MCP not-connected, sign-in-again and extra-permission messages now come from shared text that points to /mcp or claude.ai connector settings
You can now name backup models in the new accessFallbackModels setting, for use when the main model can't be used. A new per-server disableAutoBackground option stops Claude Code from moving that MCP server's tool calls to the background. In remote sessions, CLAUDE_CODE_HOST_SKILL_CATALOG can list which skills are allowed to load. Setting CLAUDE_CODE_ARTIFACT_PREVIEW to false now turns artifact preview off. A new Publish plugin tool sends a plugin to your organization's library after you confirm. Organisations under the HIPAA policy are blocked from publishing plugins this way.
Several features are in the build but not switched on yet. An option for screen-reader users to move through suggestions with the arrow keys is built but held behind a remote switch that is off. WebFetch can ask about blocked URLs one prompt at a time, but only once a server switch is turned on. An emulator engine for artifact previews in remote sessions is built but cannot be selected yet. Plugin rating now also needs a server switch, and that switch defaults to off. Pressing Enter on a slash-command suggestion can run only the one you picked with the arrow keys, once that behaviour is switched on.
Composed characters and IME typing are no longer dropped from the prompt. In vim mode, h and l now stop at the start and end of a line. The vim f, t, F and T searches now stay on the current line. The ; and , keys now repeat the last vim search even when the character was not found. Web search in remote sessions no longer skips the proxy when web fetch is disabled. A slow-starting local MCP server is no longer wrongly remembered as an older server after a timeout.
Written by our agent from the shipped bundle, not by Anthropic.
A new CLAUDE_CODE_HOST_SKILL_CATALOG variable lets a remote session's host name which skills to load, from a new host catalog at /mnt/skills/public
SDK results gain a safety_stops count, interrupts gain an internal worker_epoch, and turn handoffs can carry server-side safeguard verdicts
Sessions now reject every poll event unless the host set CLAUDE_CODE_POLL_EVENTS, and own-events-only remote sessions stop advertising session notices
The CLAUDE_CODE_REPO_CHECKOUTS lookup moves into a new accessor, and the workspace diff scan now returns which repo root it uses and whether it follows the shell
Sessions & agentsA new accessFallbackModels setting lists models Claude Code may fall back to when the main model can't be used
Sessions & agentsWant the reasoning? Read walks the 51 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →8 more of these are in What probably matters to you, on page 1.
MCP not-connected, sign-in-again and extra-permission messages now come from shared text that points to /mcp or claude.ai connector settings
Compaction now stops or accepts its last response when compactionApiAttemptsLeft reaches zero, and lists a new compact_larger_model reason
Subagents now follow the parent's abort through a detachable relay, record launchedWithDefaults, and report runId and usage-limit denials
A stdio MCP server that answers the protocol probe late is no longer remembered as old-protocol, and stdio servers now get a hashed identity
The notice for an expired message sent between sessions drops the line saying the desktop app and non-interactive sessions can't ask for approval
The notice shown when safeguards flag a message now uses the same learn-more link in both versions and drops a sentence for some models
After you buy usage credits, Claude Code now passes on the message saying how many credits were added
Claude Code's safety check for Bash commands that begin by setting environment variables now depends on extra conditions, including a remote switch
Unclear Which commands this applies to, and whether it approves more or fewer of them, is not stated.
A write that would push a project over its size limit now fails with the code write_would_exceed_project_size_limit instead of a sentence
The footer's artifacts hint reads "open in browser" when there is exactly one, and "view artifacts" otherwise
Unclear It is not clear whether this hint only appears when the remotely controlled setting is on.
The Theme row now says '(disabled in safe mode)' when safe mode overrides a saved custom theme, and the theme setting rejects names that are not themes
Headless sessions that take no more input now mark background commands as ending with the final response, so no completion notice follows
In the task list, a finished local agent can now show a 'waiting' status, and is not counted as completed
Unclear It is not clear what condition makes a finished agent show as waiting.
If a stdio MCP server remembered as old-style fails to start, Claude Code forgets that and restarts it once with the newer handshake
Task start, update and background-task list events now carry a run ID and a parent task ID
Choosing a theme now shows "Couldn't save Theme" with the error if saving fails, instead of failing silently
When a cloud session cannot confirm the organization's artifact settings, Claude is told not to retry and that it isn't a network problem
The hooks module now skips a hook that would run again inside its own plugin, and limits hooks that asked to catch errors to answering
SDK task notifications gain runId, and the background tasks changed event now includes parent_task_id
Feedback from a stop hook now has protected text redacted and a trailing < escaped before it is queued for Claude
On Linux, Claude Code now refuses a file read if the system cannot say where the opened file really is
In vim mode, commands like d followed by j or k are now handled by a new set of whole-line motions
Unclear Whether combinations like dj and dk now behave differently, and how, is not clear.
In Remote Control sessions, queued subagent updates are now capped, and the oldest are dropped when too many pile up
/fork can send a repository address when no git address is found#When forking a session finds no git repository address, Claude Code now falls back to another repository address
Unclear Whether /fork now works from a folder that is not a git checkout is not stated.
Claude Code can now register an MCP server's tools and commands before fetching its resources, and a later resource failure no longer marks it failed
Unclear It is not clear what turns on the early-registration path or when it applies.
An agent definition file whose name is longer than the maximum allowed is now skipped and an error is logged
Unclear The maximum allowed name length is not stated.
When an attachment over 30 MiB fails with a server gateway error, the error now says it may be a passing fault or your account's upload limit
When a search cannot read the place it was asked to search, Claude is told the search failed rather than that it found nothing
When an uploaded copy of your repository for a teleport session fails or is discarded, Claude Code now tries to delete it
When Claude lists artifacts, the result can now say 'Showing N of M' and explain how to reach artifacts beyond the first page
Claude Code now tries to repair invalid tool input whenever a tool has a repair step, and keeps the original input alongside the fix
Resuming a skill that runs as its own agent is refused when your organization's Skills setting turns it off; slash names must match exactly one command
Unclear Which commands the new check leaves out of the skill list is not stated.
A skill, agent or command whose name is longer than 256 characters is now rejected with an error
Text from a hook's systemMessage and additionalContext now goes through an extra processing step before the model sees it
Unclear What the extra processing step does to hook text is not stated.
Prompt history can now include drafts cleared in this session, and the artifact list reports a total count
Unclear It is not clear where, if anywhere, cleared drafts are offered back to you.
$ stays at the end of the line#In vim mode, after $ the cursor now stays at the end of each line as you move up and down, as it does in vim
MCP servers defined through the SDK now pass their whole settings object to Claude Code, not only a timeout
Unclear Which settings besides the timeout can be included is not stated.
Most claude plugin commands now wait for remote managed settings to load and do not run if those settings are not approved
Unclear It is not clear in which situations Claude Code waits, so it is unknown whether every reader is affected.
When you @-mention a file too large to attach, Claude is told its size and to read it in portions
Background agent notices now include a run id, finished agents report handback fields, and model-not-found errors carry quota limits
tool.check and ui.scroll hooks now wait for pending work#The tool.check and ui.scroll plugin hooks now wait for pending work to finish before running
Once too many MCP tasks have moved to the background since you last wrote, new ones are cancelled and Claude is told no result will follow
Unclear The size of the limit and whether this behaviour is switched on for everyone are not known.
Negotiating the protocol version with local stdio MCP servers now falls back to on, and a broken record of past probes is ignored rather than trusted
A subagent whose permissionMode is auto now keeps the main session's permission mode, with a warning, when auto mode is not available
A name in a skill or agent file's frontmatter longer than a set limit is now rejected or ignored with a warning
Unclear The maximum name length is not shown.
Claude Code now refuses to resume a skill agent whose skill your organization's Skills setting turns off, not only synced ones
When a host program replaces the MCP server list, Claude Code now always connects those servers at once instead of sometimes deferring
Uninstalling a plugin now checks settings files are readable first, skips network paths, and says clearly whether anything was changed
Claude Code's sensitive-file check now also matches files such as deploy_key, .vault-token, .dockercfg, .tfstate, .kdbx and *.ovpn
Unclear It is not clear whether matching files are blocked from reading, blocked from writing, or only flagged.
A blocked read can now explain that a Read deny rule could not be checked because there was no working directory
Error messages shown as "error (code)" now get their code from a shared step instead of reading only the error_code field
The warning before removing a plugin marketplace now says it deletes the plugins' data, options and secrets, and the hint names what to remove
The error for a key shortcut with non-modifier keys before "+" now lists only a few keys, then a count of the rest
The conflict message for a publish now says when the automatic retry could not go through the cloud session's gateway or was cancelled
When a marketplace from a settings file is refused for an Anthropic-like name, the message now explains how to rename it
After a restart, Claude Code's notice about lost background work now has a case for work that can be partly recovered
MCP prompt commands now split trimmed text into arguments and run a check that can stop the command before the prompt is fetched
Unclear What the new check tests before the prompt is fetched is not known.
If writing a temporary git reference fails, the error now says something git did not create may be in the way at .git/refs/seed
For one tool, the option to save an "always allow" rule is now held back when the mode is "ask"
Unclear Which tool this applies to, and what the "ask" mode refers to, is not known.
When a write would push a project over its maximum size, Claude Code refuses it and tells Claude not to delete documents to make room
The warning about a plugin marketplace with an official-looking name now says to remove a refused entry in /plugin under Marketplaces
When Claude Code redraws its full-screen view, it may now clear old content a different way, except when CLAUDE_BG_BACKEND is daemon
Unclear Apart from CLAUDE_BG_BACKEND, the condition that picks the new clearing method is not known.
A 403 response with a plain-text body can now be reported as a proxy denial instead of going unclassified
Claude can no longer propose a skill whose SKILL.md file has no instructions, and is told to resend the complete file
Claude is now told that a background task's result reaches it only if the task finishes before Claude gives its final response
An @-mentioned file that is too big now shows "not read: too large" with its size, and a PDF still downloading shows "queued before download"
Cloud sessions now explain that artifacts are unavailable because Anthropic couldn't confirm the organization's settings, not because of your network
claude plugin remove now explains why .claude/settings.local.json was skipped: a link to another machine, an unreadable path, or a mid-read change
Warnings about instruction files that cannot be read now list each file with its reason and collapse into a 'more' summary when the list is long
The "Browser extension is not connected" error messages can now end with extra text, always for remote cases and sometimes for the local one
Unclear What the added text says, and the condition that adds it to the local message, are not clear.
The list of teammates is now cut off past a limit with a "more not shown" line, and shows each teammate's type and status as separate fields
Claude Code's check for risky places to write now flags Windows network admin shares, device paths, WSL mounts, /.vol on macOS and root folders
The "exceeds the upload limit" message now formats the limit with a shared size formatter instead of always writing it in MiB
When plugin removal cannot read settings from an --add-dir folder, the message now suggests replacing a link to another machine with a real folder
Claude Code's date formatting can now include the year, and only removes a comma when it comes before a time
The error for a bad pages value when reading a file now says to give one page or one range and read several separately
file_path is now read as path#When the model passes file_path where a tool expects path, Claude Code now reads it as path and tells the model it did so
Whether web search goes through the remote-session proxy no longer depends on web fetch being disabled
Unclear It is not clear whether the new host check still keeps sessions with web fetch disabled away from the proxy.
The prompt now accepts keystrokes that produce more than one character, such as composed or IME input, instead of ignoring them
In vim normal mode, x, p, P, D and u now reset the column the cursor tries to keep when moving up and down
In vim mode, the f, t, F and T character searches now stop at the edge of the current line instead of searching the whole input
When a forked agent finishes, Claude Code now stops the shell commands it started and clears any messages still queued for it
In vim mode, f and t searches are now remembered properly, so ; and , repeat the last search even when the character was not found
A local MCP server that answered the protocol check late is no longer remembered as an older server after a connection timeout
In Vim normal mode, h and l no longer move the cursor onto the previous or next line
Unclear Which key the new left-movement action is bound to is not known.
Scheduled loop wakeups can now fire after input has closed if the run is still waiting for agents, so the session stays open instead of exiting
Unclear It is not known whether the scheduler that does this is switched on for a given account.
Resuming a session restores a pending scheduled wakeup, and if the background process that runs hooks dies, Claude Code restarts it and retries once
LSP, Write, Read and notebook edit errors no longer collapse into a generic line when a permission rule blocked the call
A deny response keyed on a tool call's id now settles a pending can_use_tool request whose prompt was blanked, instead of being dropped as unknown
Cancelling every scheduled loop wake-up now also clears the leftover waiting state once no loop tasks remain
When an MCP tool is stopped for going idle too long, the message now shows the same idle time and timeout that actually triggered it
After a paste, the cursor position is now calculated from where it was and the new text, instead of being set to where the paste began
Unclear Where exactly the cursor now lands after a paste is not known.
Resuming a subagent now loads its agent type from its plugin first, and stops with a clear error if that load fails
In vim mode, a text-object selection ending at a line break now treats surrounding spaces differently
Unclear Which vim text-object command is affected is not stated.
Claude Code now removes an unexpected description field from tool input, alongside renaming length to limit
A request you cancel now stops at once instead of being retried with your session sign-in after an access error
A tool input of command "create" is now dropped, vim insert commands can be repeated, and skills record two invocation settings
6 more of these are in What probably matters to you, on page 1.
The check that makes Claude Code wait out a usage limit now also covers WebFetch reading a fetched page, under a remote switch that is off by default
Unclear What a WebFetch page read does differently once it is held at a usage limit is not stated.
A token limit set to a fraction of the context window, by default one sixth, is built in and stays off unless switched on remotely
Unclear It is not clear what this token budget limits once it is switched on.
Notifications Claude reads now carry arrived_at and read_at timestamps, with arrival time recorded for queued remote notifications
Published verbatim by Anthropic for v2.1.292. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 92 bullets, 14 name something an entry on this page also names, 25 name something no entry here does, and 53 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
--marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
Probably marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
Nothing to match on CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
No entry names this prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
Probably prompt-cache-relay-message-and-commandrun-annotation, new-ui-prompt-autocomplete-control-request-for-remote-compos, new-plugin-hook-event-promptautocomplete, plugin-hook-table-gains-promptautocomplete-validator-treat, new-promptautocomplete-hook-surface-plugin-supplied-rows-u $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
Probably hooks-modelcomplete-accepts-cached-promptsystem-blocks agent.spawn mod hook, with their run and index, so a mod can refuse them
No entry names this permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
No entry names this /ultrareview uploads under ~/.claude/seed-admin
No entry names this rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
No entry names this #99193[BUG] Windows: sub-agent rm -rf on the 8.3 short-name alias of the home dir wiped ~116 GB; TaskStop left it running ~50 min; agent reported 'looks intact' (related: #92593, #95426, #97660) Open
#99198[CRITICAL] Sub-agent ran `rm -rf` on the user's Windows home directory (via 8.3 short name), no hard guard; delete kept running after the task was stopped Open
allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
No entry names this NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
No entry names this claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
Probably plugin-commands-wait-for-remote-managed-settings-before-runn, plugin-remove-explains-blocked-legacy-local-settings-file, marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
Probably print-mode-can-hold-open-for-background-shells-before-the-ce #86447[BUG] Print mode (-p --output-format stream-json): session ends with result: success while background tasks are running and a ScheduleWakeup is pending — scheduled wakeup can never fire, background tasks are killed Duplicate
claude --resume session picker or with /resume
No entry names this #89463Plan mode indicator vs. enforcement desync when resuming a conversation that was in "edits on" Open
/resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
No entry names this #98219Durable scheduled tasks (CronCreate `durable: true`) never fire after an in-app `/resume` Open
/loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
Probably loop-wakeup-scheduling-tracks-tooluseid-and-chain-start, cronloop-tasks-can-fire-after-input-closes-while-waiting-fo pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
No entry names this /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
Probably feedback-now-tracks-send-state-and-shows-a-submittingdone, safeguard-flagged-message-text-now-drops-a-sentence-for-some /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
No entry names this f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
Nothing to match on /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
No entry names this ! leaving the row selected
Nothing to match on /cd or a permission change, and added a transcript line when a nested one isn't loaded
No entry names this /name letting Claude invoke a skill that is reserved for the user
No entry names this $.state calls through one const taking minutes to load or validate
No entry names this claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere
Probably plugin-commands-wait-for-remote-managed-settings-before-runn claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused
Probably plugin-commands-wait-for-remote-managed-settings-before-runn $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end
Nothing to match on config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name
No entry names this /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked
No entry names this tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog
Probably tool-check-hooks-can-no-longer-override-tools-that-require-t, plugin-toolcheck-and-uiscroll-wait-on-pending-work-first next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected
No entry names this $ name that a user-installed mod had added; the mod is now unloaded instead
Nothing to match on tool.call hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with
No entry names this .catch being skipped silently for calls another mod's hook makes beneath the guard's own $ call; its .catch is now asked
Nothing to match on claude -p and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer resources/list
Probably print-mode-can-hold-open-for-background-shells-before-the-ce <system-reminder> tags written in a hook's output are escaped before they reach Claude
No entry names this file_path for path, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call
Probably search-tool-accepts-file-path-as-an-alias-for-path, artifact-preview-tool-wording-differs-in-emulator-mode FOO=bar python3 app.py runs unprompted
No entry names this MCP_PROTOCOL_NEGOTIATION=legacy opts out
No entry names this claude plugin test: a failed expect inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently
Probably plugin-commands-wait-for-remote-managed-settings-before-runn name longer than that is ignored
Nothing to match on @Claude !status in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again
No entry names this !fork to a card showing where it came from, the request, and who asked, with a link to the original thread
Nothing to match on A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 25 tool schemas changed.
Claude Code, interactive mode
11 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
495 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 59 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?