Follow Discord

Claude Code v2.1.292

392 entries read Grouped into 331 v2.1.291 → v2.1.292 Mods API: +7 added · 0 removed · 4 changed · 12 docs only Markdown JSON Follow Unofficial

You can now name backup models in the new accessFallbackModels setting, for use when the main model can't be used. A new per-server disableAutoBackground option stops Claude Code from moving that MCP server's tool calls to the background. In remote sessions, CLAUDE_CODE_HOST_SKILL_CATALOG can list which skills are allowed to load. Setting CLAUDE_CODE_ARTIFACT_PREVIEW to false now turns artifact preview off. A new Publish plugin tool sends a plugin to your organization's library after you confirm. Organisations under the HIPAA policy are blocked from publishing plugins this way.

Several features are in the build but not switched on yet. An option for screen-reader users to move through suggestions with the arrow keys is built but held behind a remote switch that is off. WebFetch can ask about blocked URLs one prompt at a time, but only once a server switch is turned on. An emulator engine for artifact previews in remote sessions is built but cannot be selected yet. Plugin rating now also needs a server switch, and that switch defaults to off. Pressing Enter on a slash-command suggestion can run only the one you picked with the arrow keys, once that behaviour is switched on.

Composed characters and IME typing are no longer dropped from the prompt. In vim mode, h and l now stop at the start and end of a line. The vim f, t, F and T searches now stay on the current line. The ; and , keys now repeat the last vim search even when the character was not found. Web search in remote sessions no longer skips the proxy when web fetch is disabled. A slow-starting local MCP server is no longer wrongly remembered as an older server after a timeout.

Written by our agent from the shipped bundle, not by Anthropic.

Five to try today

Picked from 19 you can use now
  1. Remote sessions can load skills from a host skill catalog via CLAUDE_CODE_HOST_SKILL_CATALOG

    A new CLAUDE_CODE_HOST_SKILL_CATALOG variable lets a remote session's host name which skills to load, from a new host catalog at /mnt/skills/public

    Extensions
  2. Protocol adds safety_stops counts, worker_epoch on interrupts and safeguard verdicts on turn handoffs

    SDK results gain a safety_stops count, interrupts gain an internal worker_epoch, and turn handoffs can carry server-side safeguard verdicts

    Extensions
  3. Poll events now require the host to set CLAUDE_CODE_POLL_EVENTS

    Sessions now reject every poll event unless the host set CLAUDE_CODE_POLL_EVENTS, and own-events-only remote sessions stop advertising session notices

    Extensions
  4. Repository checkout map is built through a new helper, and the workspace diff reports followsShell

    The CLAUDE_CODE_REPO_CHECKOUTS lookup moves into a new accessor, and the workspace diff scan now returns which repo root it uses and whether it follows the shell

    Sessions & agents
  5. Backup model list for when the main model is unavailable

    A new accessFallbackModels setting lists models Claude Code may fall back to when the main model can't be used

    Sessions & agents

Want the reasoning? Read walks the 51 entries that probably matter to you, each one opening to what changed and why.

Read this release → Every row →
Reading as
Show only
Who it's for
Tier
Flag state
Names
Pick an entry · j / k steps through · rest on a row to peek
121 entries

Internal Changesopen

Continued from page 3

13 more of these are in What probably matters to you, on page 1.

4 entriesModels · none marked notable
4 entriesSDK · none marked notable
·Internal
Under the hood
Useful1 Signal2
SDK unclear

Rewind requests are now timestamped, and a prompt autocomplete operation appears#

Rewind requests now get a creation time like turn handoffs, teammate messages can record what kind of recipient they are for, and a prompt autocomplete operation exists

Unclear What the new prompt autocomplete operation does, and whether anything can use it yet, is not stated.

Details 0 0 Feedback
·Internal
Under the hood
Useful1 Signal1
SDK unclear

SDK session setup and account calls read from a different stored value#

In the SDK, the calls that return session setup results, account information and turn count now read from a different stored value

Unclear It is not stated whether the account details or setup results that SDK programs receive are actually different now.

Details 0 0 Feedback
3 entriesAgent Peers · none marked notable
·Internal
Under the hood
Useful1 Signal1
Agent Peers unclear

A peers tool returns its list directly#

A tool that lists peers now returns the list itself instead of wrapping it in a listing field

Unclear It is not clear which tool this is.

Details 0 0 Feedback
·Internal
Under the hood
Useful1 Signal1
Agent Peers unclear

Agent listing results now come in a structured layout#

A listing of reachable agents now returns a formatted list plus optional sections of rows with name, ref, id, type and status, and notes

Unclear It is not stated which tool or command produces this agent listing.

Details 0 0 Feedback
3 entriesInternals · none marked notable
·Internal
Under the hood
Useful1 Signal2
Internals unclear

Unnamed server switch that is on unless turned off#

Claude Code reads a server-controlled switch whose built-in value is on; what it controls is not known

Unclear What this switch controls is not known.

Details 0 0 Feedback
·Internal
Under the hood
Useful1 Signal1
Internals unclear

A server-controlled check now also fails when a step did not run#

A check that runs only when a server value is set now also returns false for a result whose reason is that it did not run

Unclear It is not clear what Claude Code does differently when this check returns true or false.

Details 0 0 Feedback
3 entriesMemory · none marked notable
3 entriesPlugins · none marked notable
3 entriesSubagents · none marked notable
·Internal
Under the hood
Useful3 Signal3
Subagents unclear

Subagents can be started on a chosen model#

Starting a subagent can now take a model, which the subagent runs on and which is added to its permission rules

Unclear What causes a subagent to be started with its own model is not stated.

Details 0 0 Feedback
·Internal
Under the hood
Useful1 Signal1
Subagents unclear

Running subagents are listed with a name, reference and ID#

The list of subagents now shows each one by name, reference and ID, with its type and status as separate fields

Unclear Where in Claude Code this list is shown is not stated.

Details 0 0 Feedback
2 entriesAttachments · none marked notable
2 entriesManaged Settings · none marked notable
·Internal
Under the hood
Useful1 Signal1
Managed Settings unclear

Loading organization settings at startup can reuse an earlier fetch#

Organization-managed settings can now come from a result fetched ahead of time, with login refreshed first so only one refresh runs at a time

Unclear It is not clear whether the early fetch is ever made by default, so the speed-up may not apply to everyone.

Details 0 0 Feedback
2 entriesPDF Reading · none marked notable
·Internal
Under the hood
Useful1 Signal0
PDF Reading

PDF page reading no longer reopens the file#

Claude Code now passes the already-open PDF to pdfinfo and pdftoppm instead of opening the file path again

Details 0 0 Feedback
2 entriesSandbox · none marked notable
·Internal
Under the hood
Useful2 Signal3
Sandbox unclear

Sandbox marks blocked credential locations as masked#

When the sandbox masks credential files, the locations it blocks reading from are now flagged as masked, and a list of trusted blocked locations is added

Unclear It is not clear what turns on mask mode or what this changes for someone using the sandbox.

Details 0 0 Feedback
2 entriesWebFetch · none marked notable
Verbatim
Official · Anthropic

Anthropic’s official release notes

Published verbatim by Anthropic for v2.1.292. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.

Of these 92 bullets, 14 name something an entry on this page also names, 25 name something no entry here does, and 53 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.

  • Added --marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it Probably marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun
  • Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for Nothing to match on
  • Added CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request No entry names this
  • Added prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list Probably prompt-cache-relay-message-and-commandrun-annotation, new-ui-prompt-autocomplete-control-request-for-remote-compos, new-plugin-hook-event-promptautocomplete, plugin-hook-table-gains-promptautocomplete-validator-treat, new-promptautocomplete-hook-surface-plugin-supplied-rows-u
  • Added prompt caching to $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it Probably hooks-modelcomplete-accepts-cached-promptsystem-blocks
  • Added workflow agents to the agent.spawn mod hook, with their run and index, so a mod can refuse them No entry names this
  • Fixed subagent definitions with permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it) No entry names this
  • Fixed sandboxed commands being able to read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin No entry names this
  • Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers Nothing to match on
  • Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read Nothing to match on
  • Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed Nothing to match on
  • Fixed rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it No entry names this #99193[BUG] Windows: sub-agent rm -rf on the 8.3 short-name alias of the home dir wiped ~116 GB; TaskStop left it running ~50 min; agent reported 'looks intact' (related: #92593, #95426, #97660) Open #99198[CRITICAL] Sub-agent ran `rm -rf` on the user's Windows home directory (via 8.3 short name), no hard guard; delete kept running after the task was stopped Open
  • Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths Nothing to match on
  • Fixed a skill's or slash command's allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn No entry names this
  • Fixed NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set No entry names this
  • Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it Nothing to match on #96152[Bug] Anthropic API Error: Tool name exceeds 128 character limit Open
  • Fixed claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run Probably plugin-commands-wait-for-remote-managed-settings-before-runn, plugin-remove-explains-blocked-legacy-local-settings-file, marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun
  • Fixed one-shot claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for Probably print-mode-can-hold-open-for-background-shells-before-the-ce #86447[BUG] Print mode (-p --output-format stream-json): session ends with result: success while background tasks are running and a ScheduleWakeup is pending — scheduled wakeup can never fire, background tasks are killed Duplicate
  • Fixed plan mode not being restored when resuming a session from the claude --resume session picker or with /resume No entry names this #89463Plan mode indicator vs. enforcement desync when resuming a conversation that was in "edits on" Open
  • Fixed saved scheduled tasks created after /resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart No entry names this #98219Durable scheduled tasks (CronCreate `durable: true`) never fire after an in-app `/resume` Open
  • Fixed a background session's /loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost Probably loop-wakeup-scheduling-tracks-tooluseid-and-chain-start, cronloop-tasks-can-fire-after-input-closes-while-waiting-fo
  • Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you Nothing to match on
  • Fixed the Read tool returning only the first entry, with no error, when a PDF's pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately No entry names this
  • Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file's size and to read it in portions Nothing to match on
  • Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation Nothing to match on
  • Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE Nothing to match on
  • Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse Nothing to match on
  • Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued Nothing to match on
  • Fixed /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent Probably feedback-now-tracks-send-state-and-shows-a-submittingdone, safeguard-flagged-message-text-now-drops-a-sentence-for-some
  • Fixed /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect No entry names this
  • Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt Nothing to match on
  • Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt Nothing to match on
  • Fixed /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys No entry names this
  • Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and ! leaving the row selected Nothing to match on
  • Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2's scrollback with stale pages Nothing to match on
  • Fixed a spurious "could not be examined" note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink No entry names this
  • Fixed "instruction file not loaded" lines going stale or missing after /cd or a permission change, and added a transcript line when a nested one isn't loaded No entry names this
  • Fixed a compaction summary that repeated /name letting Claude invoke a skill that is reserved for the user No entry names this
  • Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason Nothing to match on
  • Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished Nothing to match on
  • Fixed cloud sessions with a large transcript sometimes asking for a permission again after it was approved Nothing to match on
  • Fixed scheduled tasks and other queued notifications being lost in cloud sessions when a message was retried or edited while Claude was reading them Nothing to match on
  • Fixed cloud sessions forgetting the thinking setting chosen in the client when the session's container restarted Nothing to match on
  • Fixed Cowork cloud sessions saying a proxy blocked artifacts when Anthropic couldn't confirm the organization's settings Nothing to match on
  • Fixed plugins whose hooks module makes many $.state calls through one const taking minutes to load or validate No entry names this
  • Fixed claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere Probably plugin-commands-wait-for-remote-managed-settings-before-runn
  • Fixed claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused Probably plugin-commands-wait-for-remote-managed-settings-before-runn
  • Fixed a plugin's served $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end Nothing to match on
  • Fixed plugin interface calls made while the plugin hooks worker restarts running without the hooks other plugins put on them Nothing to match on
  • Fixed a mod's config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name No entry names this
  • Fixed /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked No entry names this
  • Fixed a plugin's tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog Probably tool-check-hooks-can-no-longer-override-tools-that-require-t, plugin-toolcheck-and-uiscroll-wait-on-pending-work-first
  • Fixed a mod's start-up prompt, command or subagent being queued a second time when the hooks worker was replaced Nothing to match on
  • Fixed a mod's hook that called next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected No entry names this
  • Fixed a plugin's prompt drop or setting deny being ignored when its reason was longer than 4,096 characters Nothing to match on
  • Fixed an organization's plugin being unloaded on its own reload, or after another plugin crashed, when it returned a $ name that a user-installed mod had added; the mod is now unloaded instead Nothing to match on
  • Fixed tool calls made while the plugin hooks worker restarts being answered without the plugins' permission hooks Nothing to match on
  • Fixed plugin tool.call hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with No entry names this
  • Fixed a mod's guard hook with a .catch being skipped silently for calls another mod's hook makes beneath the guard's own $ call; its .catch is now asked Nothing to match on
  • Improved startup of claude -p and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer resources/list Probably print-mode-can-hold-open-for-background-shells-before-the-ce
  • Improved rendering speed of long bulleted or numbered replies: they stream, resize and re-open in the transcript (ctrl+o) much faster Nothing to match on
  • Improved Ctrl+C draft recovery: a cleared prompt now stays reachable with Up after a slash command or a sent message Nothing to match on
  • Improved hook output handling: <system-reminder> tags written in a hook's output are escaped before they reach Claude No entry names this
  • Improved tool input handling: Grep accepts file_path for path, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call Probably search-tool-accepts-file-path-as-an-alias-for-path, artifact-preview-tool-wording-differs-in-emulator-mode
  • Improved the steps shown when a marketplace declared in a settings file has a name that looks like an official Anthropic marketplace Nothing to match on
  • Improved sandbox auto-allow: with strict sandbox mode set in user, managed or --settings settings, an interpreter command with an env var prefix like FOO=bar python3 app.py runs unprompted No entry names this
  • Improved the Artifact tool's listing: Claude now sees how many published artifacts you have and can list up to 200 at once instead of 50 Nothing to match on
  • Improved cloud sessions after a restart: Claude is now told which stopped background agents it can resume by id Nothing to match on
  • Improved the Claude in Chrome message in claude.ai cloud sessions when the browser can't be reached: Claude is now told it may continue with alternatives if the user prefers Nothing to match on
  • Improved the /focus tip: it now invites you to try focus view mid-turn and shows how to switch back Probably focus-view-tip-text-moved-into-a-constant
  • Improved startup with local (stdio) MCP servers that ignore the newer protocol check: after one slow connect they are remembered for 7 days and connected the older way without the wait Nothing to match on
  • Changed local (stdio) MCP server connections to negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex and Foundry; MCP_PROTOCOL_NEGOTIATION=legacy opts out No entry names this
  • Changed claude plugin test: a failed expect inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently Probably plugin-commands-wait-for-remote-managed-settings-before-runn
  • Changed usage limit messages to write claude.ai settings links with https:// so terminals and apps can make them clickable Nothing to match on
  • Changed scheduled and Run now routine runs to publish a new artifact only you can see without asking for approval; artifacts that request connectors or other access still ask Nothing to match on
  • Changed agent names to allow at most 256 characters: a longer one is rejected, and a skill's or a plugin file's name longer than that is ignored Nothing to match on
  • [Cloud sessions] Fixed routine runs occasionally staying listed as running for hours after they had finished Nothing to match on
  • [Cloud sessions] Fixed editing or duplicating a routine turning off its push notifications when the routine had no saved notification setting Nothing to match on
  • [Cloud sessions] Fixed SVG, HEIC, TIFF and other less common image files failing to attach; they now attach as regular files Nothing to match on
  • [Cloud sessions] Fixed approval prompts offering "Always allow" for connector tools that an organization set to require approval; the choice had no effect No entry names this
  • [Remote Control] Fixed the first message of a new Remote Control session started from claude.ai/code accepting only images; it now accepts PDFs and other files like later messages Nothing to match on
  • [Claude Tag] Added an Edit button to the Allowed domains card on a channel's Configure page, so Enterprise admins can open the access bundle that sets the channel's domains Nothing to match on
  • [Claude Tag] Fixed replies sent in a Slack thread while Claude was still on its first request there being held until that request finished, or missed when sent seconds apart Nothing to match on
  • [Claude Tag] Fixed Slack threads woken only by GitHub pull request activity or a routine staying on their original model after an admin changed the channel or workspace default model Nothing to match on
  • [Claude Tag] Fixed Claude sometimes posting a spend limit notice in Slack when the real cause was that your organization had run out of usage credits Nothing to match on
  • [Claude Tag] Fixed a session hanging until interrupted when a permission prompt that can't be answered from Slack was denied automatically Nothing to match on
  • [Claude Tag] Improved @Claude !status in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again No entry names this
  • [Claude Tag] Changed the first message of a Slack thread continued with !fork to a card showing where it came from, the request, and who asked, with a link to the original thread Nothing to match on
  • [Claude Tag] Changed the organization-wide and default spend limit boxes on Claude Tag's spend limits page in admin settings to save only when you press Save or Enter, not when you click away Nothing to match on
  • [Code Review] Added the period's total with its change from the previous period, and a breakdown by repository, to the PRs reviewed chart in Code Review analytics Nothing to match on
  • [Code Review] Fixed a queued review failing when the pull request moved to a new base branch and the old one was deleted; the commit is now re-queued for review Nothing to match on
  • [Code Review] Fixed reviews ignoring a CLAUDE.md's rules when the pull request edits that file; reviews now use its version from the base branch Nothing to match on

A model matched these bullets to the GitHub issues they fix, so a link can be wrong.

System prompt

1 of 25 tool schemas changed.

Claude Code, interactive mode

11 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.

Documentation

What the docs did around this release

495 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.

Switches

Every name in this release

The 59 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.

Slash commands

CLI flags

Environment variables

Settings and names in the code

Feedback