Cancelled requests no longer retry with your sign-in#
A request you cancel now stops at once instead of being retried with your session sign-in after an access error
You can now name backup models in the new accessFallbackModels setting, for use when the main model can't be used. A new per-server disableAutoBackground option stops Claude Code from moving that MCP server's tool calls to the background. In remote sessions, CLAUDE_CODE_HOST_SKILL_CATALOG can list which skills are allowed to load. Setting CLAUDE_CODE_ARTIFACT_PREVIEW to false now turns artifact preview off. A new Publish plugin tool sends a plugin to your organization's library after you confirm. Organisations under the HIPAA policy are blocked from publishing plugins this way.
Several features are in the build but not switched on yet. An option for screen-reader users to move through suggestions with the arrow keys is built but held behind a remote switch that is off. WebFetch can ask about blocked URLs one prompt at a time, but only once a server switch is turned on. An emulator engine for artifact previews in remote sessions is built but cannot be selected yet. Plugin rating now also needs a server switch, and that switch defaults to off. Pressing Enter on a slash-command suggestion can run only the one you picked with the arrow keys, once that behaviour is switched on.
Composed characters and IME typing are no longer dropped from the prompt. In vim mode, h and l now stop at the start and end of a line. The vim f, t, F and T searches now stay on the current line. The ; and , keys now repeat the last vim search even when the character was not found. Web search in remote sessions no longer skips the proxy when web fetch is disabled. A slow-starting local MCP server is no longer wrongly remembered as an older server after a timeout.
Written by our agent from the shipped bundle, not by Anthropic.
A new CLAUDE_CODE_HOST_SKILL_CATALOG variable lets a remote session's host name which skills to load, from a new host catalog at /mnt/skills/public
SDK results gain a safety_stops count, interrupts gain an internal worker_epoch, and turn handoffs can carry server-side safeguard verdicts
Sessions now reject every poll event unless the host set CLAUDE_CODE_POLL_EVENTS, and own-events-only remote sessions stop advertising session notices
The CLAUDE_CODE_REPO_CHECKOUTS lookup moves into a new accessor, and the workspace diff scan now returns which repo root it uses and whether it follows the shell
Sessions & agentsA new accessFallbackModels setting lists models Claude Code may fall back to when the main model can't be used
Sessions & agentsWant the reasoning? Read walks the 51 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →A request you cancel now stops at once instead of being retried with your session sign-in after an access error
A tool input of command "create" is now dropped, vim insert commands can be repeated, and skills record two invocation settings
6 more of these are in What probably matters to you, on page 1.
The check that makes Claude Code wait out a usage limit now also covers WebFetch reading a fetched page, under a remote switch that is off by default
Unclear What a WebFetch page read does differently once it is held at a usage limit is not stated.
A remotely controlled switch can stop Claude Code from fetching managed settings early at startup, and a message covers approvals it cannot ask for
Unclear What the switch changes about startup, beyond skipping the early fetch of managed settings, is not stated.
A token limit set to a fraction of the context window, by default one sixth, is built in and stays off unless switched on remotely
Unclear It is not clear what this token budget limits once it is switched on.
Claude Code can now reuse a policy-limits result fetched in advance, and CLAUDE_CODE_MANAGED_CONFIG_PREFETCH controls a hedge option on the fetch
Unclear It is not clear what values CLAUDE_CODE_MANAGED_CONFIG_PREFETCH takes or what the hedge does.
Notifications Claude reads now carry arrived_at and read_at timestamps, with arrival time recorded for queued remote notifications
The check that decides which tools skip the auto mode classifier now looks at the full tool instead of just its name
Unclear Which tools now skip the classifier check, compared with before, is not stated.
Claude Code's internal hook machinery now accepts a second kind of hook, labelled "told", that only wires up error handling
New instructions teach a status classifier that a message opening with a request means work is blocked, behind a switch that defaults off
Unclear What this classifier labels and where its result shows up is not clear.
13 more of these are in What probably matters to you, on page 1.
Artifact publish calls can now be relay-only, stopping with 'Nothing was published' instead of falling back when the cloud session gateway cannot carry them
Unclear It is not clear when Claude Code uses the relay-only mode, or whether any build turns it on.
Teammate spawn and plan approval now pass autoPickedByLevel, so a teammate's permission mode can depend on whether the leader's mode was auto-picked by level
Unclear What difference this makes to the permission mode a teammate actually ends up with is not clear.
In remote sessions, some stored rows are now re-sent after a compaction event, and the bridge treats non-slash messages without a verified Slack human turn differently
Unclear It is not stated what the extra step does to messages that are not marked as verified Slack human turns.
When reading a resource from an MCP server, Claude Code now tries another handler first and only asks the server if that handler does not answer
Unclear It is not stated what the other handler is or which resource reads it answers.
Headless sessions can handle file read requests from a host, and wait up to 30 seconds for pending ones before shutting down
Unclear It is not clear what sends these file read requests, or whether they are switched on for everyone.
Activity digests now wrap their content in tags carrying a one-off code, and overly long digests are cut down with earlier items left out
The classifier that labels background agents' work can now add extra instructions, including a variant for project recaps
Claude Code now keeps a set of feature flags out of its on-disk flag cache, both when saving and when reading, so they fall back to defaults
Remote file reads accept an anchor (workspace_root, diff_root or a repo) so clients can read files without absolute paths
Claude Code can start fetching your organization's policy limits ahead of time, and retries the fetch when it fails
/loop wake-ups record when the chain started and what triggered them#Scheduling the next /loop wake-up now records when the loop chain started, whether a keepalive triggered it, and which tool call scheduled it
Teleport handoffs now record specific reasons when the handoff marker is not used, and report a crash during startup as a boot failure
Workflow agents now pass an admission step before starting, follow model changes mid-run, and report the model on rate-limit errors
Unclear What the new admission step checks before a workflow agent starts is not known.
Plugin hook modules now report when their answer was only partly applied, and pass cancellation on to the work they do for a caller
The compaction result now stores keptRows with its after_summary marker, and rewinding to a summary reports that count
The internal-events uploader sets gatherTick, so events queued close together are sent in one batch instead of one at a time
The check that decides which folders count as covered now tells apart folders it has looked through, folders it has not, and vouched-for folders
Unclear Which feature uses this check, and so which paths a reader would see treated differently, is not clear.
Under some condition, picking a theme during setup now saves it a different way and shows any error
Unclear What decides whether the new theme-saving path is used is not known.
A list Claude Code fetches from its remote configuration is now read under a different name, so values set under the old name no longer apply
Unclear It is not stated what this list controls in Claude Code.
Agent @-mentions are now recognised using a shared list of characters allowed before the @, instead of a fixed one
Unclear Whether the shared list differs from the old fixed one, and so whether any mention behaves differently, is not clear.
The /feedback dialog now hands sending to a shared sender that tracks each report's progress, and failures return you to the input screen
When Claude Code creates a Remote Control session, it can now pass along a repository URL and report whether connecting worked
Extra background requests to the model can now remove prompt-caching markers when the model has caching turned off, and log that they did
Claude Code no longer reads VOICE_STREAM_BASE_URL directly for voice streaming; it uses a separate lookup and falls back to the API address
Unclear Whether VOICE_STREAM_BASE_URL is still honoured, or the override has moved to another setting, is not stated.
The scheduler for file-based scheduled tasks can now give up its lock, rewatches files when they change, and recognises a session's own tasks
The footer's task rows are now left empty when a certain condition holds, instead of always being shown
Unclear Which condition empties the footer's task list is not stated.
Claude Code gains a "resend it in two" batch error, an upload size-limit field, and a message about a session's desktop taking calls only via its tools
The coordinator task inside the observer's instructions now carries a one-off code, and the instructions tell the model about it
The model's browser guidance now names Claude in Chrome first and the Claude desktop app's built-in browser second, the reverse of before
Unclear Whether this wording replaces the old one everywhere or is one of two versions chosen by where Claude Code runs is not shown.
If Claude Code's check for changed files is interrupted, the next check now starts with the files it skipped instead of starting over
The check for problems in a project's Git folder now also counts entries in its objects and refs folders
The tip suggesting /focus now reads its text from a stored value instead of a sentence written into the tip itself
Claude Code can now give ripgrep, the program it uses to search files, an extra communication channel when starting it
PowerShell commands run in the background from the main conversation can now get the same background marking as ones run by agents
A check that finds which file path an open file points to now uses a different method, and a failed lookup counts as no result
A log message about the prompt-cache relay has new wording, and two internal command labels were added or annotated
Claude Code's account profile lookup can now give up on an expired sign-in token instead of always refreshing it
The inventory a worker reports now includes its tools, not only its skills and plugins, and updates when any of them change
A check for remote sessions now passes only when CLAUDE_CODE_ENVIRONMENT_KIND is unset and the session is not a child session
Unclear What this check controls is not known, so its effect on remote sessions is unclear.
Files in the handoff folder can now be refreshed by name, replaced only when the local copy has not changed
Unclear Whether this refresh runs for a reader or sits behind a server-controlled setting is not stated.
When remote connections close, Claude Code now switches off its handling for riding out refusals from the model-call proxy
The slowdown on remote session uploads when no viewer is present now applies only to some events instead of to all of them
After a file is placed, Claude Code now makes a follow-up call with its id and name, and failed file list requests report their HTTP status
Unclear What the follow-up call after placing a file does is not stated.
After a message with attachments, files that have no checksum can now be refreshed by name, and a new file mode treats PDFs as binary files
Unclear What switches the by-name refresh on, and how the on_with_pdfs mode is chosen, is not known.
Remote sessions record adopted cloud artifacts and pass along their tools, and workflow agents record quota refusals
Unclear It is not clear whether any of these changes alter what a user sees.
A handoff that asks Claude Code to run calls must now start with a non-empty user message, and memory snapshots are applied in more history requests
Before uploading subagent transcripts it missed, Claude Code now reads what the server already holds and skips those entries
When an internal message queue is full while gathering messages, Claude Code now empties it instead of waiting
Requests to read a file now pass an extra anchor value along with the path, size limit and encoding
Unclear What the anchor value changes about a file read is not known.
At shutdown, the remote-session client can log how many events went undelivered, as a warning if any did
When Claude Code trims tool results before saving a conversation, it now processes messages marked as virtual instead of skipping them
Usage data about background tasks now records details of how a local subagent was started
Claude Code now skips reporting the effort level as session information when its text is over a length limit
When a batch of events is refused with a particular error, Claude Code can split it in two and resend the halves
Usage data for each Bash command now notes zsh 'no matches found' errors, and main-session background commands can be flagged like subagent ones
Unclear What the flag on a main-session background command changes, and when it applies, is not known.
Claude Code now records yes or no for whether a remote session ID or container ID is set
The usage report sent when the prompt cache breaks now records whether it came from a subagent or a resumed session, plus an outline of the messages
Claude Code now works out a turn's origin using its run id too, and passes along a marker for text that was not typed
When an upload of internal events is refused, Claude Code can now split the batch in two and resend it instead of dropping it
Claude Code's memory sampling around tools now skips the measurement when a certain condition is met
Unclear It is not clear what condition makes the sampler skip the measurement.
__proto__#When Claude Code repairs JSON with doubly escaped characters, its usage report now counts how many keys are named __proto__
Claude Code can now write the current time with its offset in the session's time zone, falling back to the computer's zone
Display-only tools are set up differently in thin clients, and a remotely verified admin level is now remembered
Unclear What either change does for someone using Claude Code is not known.
Claude Code gains a helper that sends a second request after 3 seconds, a remote composer autocomplete path and a rewind expiry check
The effort level from a request is now copied into session state when unset, and a lock or state file is written readable only by you
Claude Code now runs an empty placeholder step from two places, with no visible effect
A helper that removes a byte order mark from the start of text now just returns the text and no longer parses it as JSON
Claude Code's internal web request helper now passes a cancel signal through when one is given, so those requests can be stopped
A routine that copies data key by key now skips any key named __proto__, which closes off a known kind of attack
Claude Code's skill loader can take a catalog and then load only the skill folders it lists that contain a SKILL.md file
Unclear It is not clear how a catalog is supplied, so whether a reader can use this is unknown.
The permission reset when a skill runs no longer has a server switch and now depends only on the session being a remote cowork one
When a skill is held back by the host's skill catalog, Claude Code now records that reason separately; you still see 'Unknown skill'
Unclear Which skills the host catalog holds back is not known.
The skill list can now leave out certain skills, and the slash-command suggestion list can let a handler take over the Enter key
Unclear What turns the skill filter on, and which skills it leaves out, is not known.
Skills sync can now use a skills zip file already mounted from the host, and falls back to downloading it if that fails
The skill review card's refusal to update built-in or plugin skills now includes an extra check, and its message names the skill by its short name
When the search for markdown files times out, fails or is cancelled, Claude Code now counts it instead of giving up silently
The name field in a skill's or plugin command's header is now passed through a check instead of being taken as plain text
Unclear What the check accepts and what happens to a name that fails it is not clear.
Claude Code now records when a routine first publishes an artifact without being asked, and can mark that run as tainted
Unclear What marking a routine run as tainted changes for the user is not stated.
Claude Code's decision about when to wind a session down can now hold off while background shell commands are still running
Unclear Whether this waiting is switched on, and in which kinds of session, is not known.
How Claude Code shows, counts and clears background agent tasks now depends on a new switch
Unclear What this switch is, what it falls back to, and whether it is on for anyone is not known.
Notifications about background tasks can now include a run identifier when they did not already have one
A background task with a timeout now records its deadline, so the time left can be shown
The log line for stopping an exiting agent's leftover shell tasks now names the task, and one extra cleanup step was removed
When fetching an artifact's assets or files, Claude Code now tries the artifact service first when it has a token
Reading an artifact can now ask for a specific version, and two new preview settings appear
Unclear Whether version reading and the two new settings are available to users is not stated.
Claude is told to preview an artifact before sharing its link only when the browser in use is a local Chrome
Listing artifacts now signals when more results may exist, and a folder cleanup step now removes more subfolders than before
Reading or listing an artifact's earlier versions is denied with a dedicated message when its permission check cannot complete
Claude Code can now sort a model into a family such as Fable, Haiku, Mythos, Opus or Sonnet, and names it only when a server-side list allows it
Haiku's image limits now include a maximum of 1568 tokens per image, alongside several small internal additions
Published verbatim by Anthropic for v2.1.292. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 92 bullets, 14 name something an entry on this page also names, 25 name something no entry here does, and 53 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
--marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
Probably marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
Nothing to match on CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
No entry names this prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
Probably prompt-cache-relay-message-and-commandrun-annotation, new-ui-prompt-autocomplete-control-request-for-remote-compos, new-plugin-hook-event-promptautocomplete, plugin-hook-table-gains-promptautocomplete-validator-treat, new-promptautocomplete-hook-surface-plugin-supplied-rows-u $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
Probably hooks-modelcomplete-accepts-cached-promptsystem-blocks agent.spawn mod hook, with their run and index, so a mod can refuse them
No entry names this permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
No entry names this /ultrareview uploads under ~/.claude/seed-admin
No entry names this rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
No entry names this #99193[BUG] Windows: sub-agent rm -rf on the 8.3 short-name alias of the home dir wiped ~116 GB; TaskStop left it running ~50 min; agent reported 'looks intact' (related: #92593, #95426, #97660) Open
#99198[CRITICAL] Sub-agent ran `rm -rf` on the user's Windows home directory (via 8.3 short name), no hard guard; delete kept running after the task was stopped Open
allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
No entry names this NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
No entry names this claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
Probably plugin-commands-wait-for-remote-managed-settings-before-runn, plugin-remove-explains-blocked-legacy-local-settings-file, marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
Probably print-mode-can-hold-open-for-background-shells-before-the-ce #86447[BUG] Print mode (-p --output-format stream-json): session ends with result: success while background tasks are running and a ScheduleWakeup is pending — scheduled wakeup can never fire, background tasks are killed Duplicate
claude --resume session picker or with /resume
No entry names this #89463Plan mode indicator vs. enforcement desync when resuming a conversation that was in "edits on" Open
/resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
No entry names this #98219Durable scheduled tasks (CronCreate `durable: true`) never fire after an in-app `/resume` Open
/loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
Probably loop-wakeup-scheduling-tracks-tooluseid-and-chain-start, cronloop-tasks-can-fire-after-input-closes-while-waiting-fo pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
No entry names this /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
Probably feedback-now-tracks-send-state-and-shows-a-submittingdone, safeguard-flagged-message-text-now-drops-a-sentence-for-some /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
No entry names this f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
Nothing to match on /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
No entry names this ! leaving the row selected
Nothing to match on /cd or a permission change, and added a transcript line when a nested one isn't loaded
No entry names this /name letting Claude invoke a skill that is reserved for the user
No entry names this $.state calls through one const taking minutes to load or validate
No entry names this claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere
Probably plugin-commands-wait-for-remote-managed-settings-before-runn claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused
Probably plugin-commands-wait-for-remote-managed-settings-before-runn $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end
Nothing to match on config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name
No entry names this /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked
No entry names this tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog
Probably tool-check-hooks-can-no-longer-override-tools-that-require-t, plugin-toolcheck-and-uiscroll-wait-on-pending-work-first next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected
No entry names this $ name that a user-installed mod had added; the mod is now unloaded instead
Nothing to match on tool.call hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with
No entry names this .catch being skipped silently for calls another mod's hook makes beneath the guard's own $ call; its .catch is now asked
Nothing to match on claude -p and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer resources/list
Probably print-mode-can-hold-open-for-background-shells-before-the-ce <system-reminder> tags written in a hook's output are escaped before they reach Claude
No entry names this file_path for path, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call
Probably search-tool-accepts-file-path-as-an-alias-for-path, artifact-preview-tool-wording-differs-in-emulator-mode FOO=bar python3 app.py runs unprompted
No entry names this MCP_PROTOCOL_NEGOTIATION=legacy opts out
No entry names this claude plugin test: a failed expect inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently
Probably plugin-commands-wait-for-remote-managed-settings-before-runn name longer than that is ignored
Nothing to match on @Claude !status in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again
No entry names this !fork to a card showing where it came from, the request, and who asked, with a link to the original thread
Nothing to match on A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 25 tool schemas changed.
Claude Code, interactive mode
11 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
495 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 59 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?