Restricted models are always attributed to the model allowlist#
When your model choices are restricted, Claude Code now always gives the model allowlist as the reason
You can now name backup models in the new accessFallbackModels setting, for use when the main model can't be used. A new per-server disableAutoBackground option stops Claude Code from moving that MCP server's tool calls to the background. In remote sessions, CLAUDE_CODE_HOST_SKILL_CATALOG can list which skills are allowed to load. Setting CLAUDE_CODE_ARTIFACT_PREVIEW to false now turns artifact preview off. A new Publish plugin tool sends a plugin to your organization's library after you confirm. Organisations under the HIPAA policy are blocked from publishing plugins this way.
Several features are in the build but not switched on yet. An option for screen-reader users to move through suggestions with the arrow keys is built but held behind a remote switch that is off. WebFetch can ask about blocked URLs one prompt at a time, but only once a server switch is turned on. An emulator engine for artifact previews in remote sessions is built but cannot be selected yet. Plugin rating now also needs a server switch, and that switch defaults to off. Pressing Enter on a slash-command suggestion can run only the one you picked with the arrow keys, once that behaviour is switched on.
Composed characters and IME typing are no longer dropped from the prompt. In vim mode, h and l now stop at the start and end of a line. The vim f, t, F and T searches now stay on the current line. The ; and , keys now repeat the last vim search even when the character was not found. Web search in remote sessions no longer skips the proxy when web fetch is disabled. A slow-starting local MCP server is no longer wrongly remembered as an older server after a timeout.
Written by our agent from the shipped bundle, not by Anthropic.
A new CLAUDE_CODE_HOST_SKILL_CATALOG variable lets a remote session's host name which skills to load, from a new host catalog at /mnt/skills/public
SDK results gain a safety_stops count, interrupts gain an internal worker_epoch, and turn handoffs can carry server-side safeguard verdicts
Sessions now reject every poll event unless the host set CLAUDE_CODE_POLL_EVENTS, and own-events-only remote sessions stop advertising session notices
The CLAUDE_CODE_REPO_CHECKOUTS lookup moves into a new accessor, and the workspace diff scan now returns which repo root it uses and whether it follows the shell
Sessions & agentsA new accessFallbackModels setting lists models Claude Code may fall back to when the main model can't be used
Sessions & agentsWant the reasoning? Read walks the 51 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →13 more of these are in What probably matters to you, on page 1.
When your model choices are restricted, Claude Code now always gives the model allowlist as the reason
When a model's setup is replaced, Claude Code can now remove the beta features recorded for it
Restarted workers now restore thinking settings, bad model lists are ignored with a warning, and too-old rewind requests are refused
Rewind requests now get a creation time like turn handoffs, teammate messages can record what kind of recipient they are for, and a prompt autocomplete operation exists
Unclear What the new prompt autocomplete operation does, and whether anything can use it yet, is not stated.
When a control request is settled under a different id than its reply carries, Claude Code now notifies a registered listener
In the SDK, the calls that return session setup results, account information and turn count now read from a different stored value
Unclear It is not stated whether the account details or setup results that SDK programs receive are actually different now.
The list of other agents a session can see is now built as sections plus notes, including a note when messaging is turned off
A tool that lists peers now returns the list itself instead of wrapping it in a listing field
Unclear It is not clear which tool this is.
A listing of reachable agents now returns a formatted list plus optional sections of rows with name, ref, id, type and status, and notes
Unclear It is not stated which tool or command produces this agent listing.
Claude Code reads a server-controlled switch whose built-in value is on; what it controls is not known
Unclear What this switch controls is not known.
Claude Code can now hold back a background consent check because its own feature-flag lookup has not finished
A check that runs only when a server value is set now also returns false for a result whose reason is that it did not run
Unclear It is not clear what Claude Code does differently when this check returns true or false.
When the background memory pass in a remote session is refused permission, the refusal now includes a code saying why; the message is unchanged
When a tool is blocked during auto memory, the debug log and usage data now say why
Claude Code reorganized how it keeps track, during a session, of the memory files it has loaded and moved
New internal names mention plugin policy at startup, hook autocomplete and reading tool output into files; none is shown to be usable yet
A failed sign-in setup with --remote now logs the real error, and a plugin_publish plugin operation name has been added
Unclear Nothing shows a command or screen that uses plugin_publish, so it is unclear whether a reader can publish a plugin.
When working out why plugins are still on, Claude Code now reads the legacy local settings file and added-directory settings through a guarded reader
Starting a subagent can now take a model, which the subagent runs on and which is added to its permission rules
Unclear What causes a subagent to be started with its own model is not stated.
Claude Code adds a handful of internal fields and a new message for when a subagent fails to start after hooks allowed it
The list of subagents now shows each one by name, reference and ID, with its type and status as separate fields
Unclear Where in Claude Code this list is shown is not stated.
Claude Code now reports whether early attachment preparation was off, on, or on including PDFs, controlled by two switches off by default
SendUserFile attachments are now checked once before upload, attachment data can note a suspected size limit, and child sessions get one more setting
Fetching remote managed settings can now be cancelled, and after a 401 error Claude Code forces a login token refresh only once
Organization-managed settings can now come from a result fetched ahead of time, with login refreshed first so only one refresh runs at a time
Unclear It is not clear whether the early fetch is ever made by default, so the speed-up may not apply to everyone.
When reading a PDF, Claude Code now passes the already open file, its size and a cancel signal into page rendering and page counting
Claude Code now passes the already-open PDF to pdfinfo and pdftoppm instead of opening the file path again
When the sandbox masks credential files, the locations it blocks reading from are now flagged as masked, and a list of trusted blocked locations is added
Unclear It is not clear what turns on mask mode or what this changes for someone using the sandbox.
The sandbox now keeps several pieces of progress state while locating folders that commands are blocked from reading
The web-fetch agent's description now tells Claude that using it to read a page is ordinary tool use, not a decision to spawn a helper agent
Claude Code records one more internal outcome for web page fetches, with no visible change
Published verbatim by Anthropic for v2.1.292. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 92 bullets, 14 name something an entry on this page also names, 25 name something no entry here does, and 53 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
--marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
Probably marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
Nothing to match on CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
No entry names this prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
Probably prompt-cache-relay-message-and-commandrun-annotation, new-ui-prompt-autocomplete-control-request-for-remote-compos, new-plugin-hook-event-promptautocomplete, plugin-hook-table-gains-promptautocomplete-validator-treat, new-promptautocomplete-hook-surface-plugin-supplied-rows-u $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
Probably hooks-modelcomplete-accepts-cached-promptsystem-blocks agent.spawn mod hook, with their run and index, so a mod can refuse them
No entry names this permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
No entry names this /ultrareview uploads under ~/.claude/seed-admin
No entry names this rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
No entry names this #99193[BUG] Windows: sub-agent rm -rf on the 8.3 short-name alias of the home dir wiped ~116 GB; TaskStop left it running ~50 min; agent reported 'looks intact' (related: #92593, #95426, #97660) Open
#99198[CRITICAL] Sub-agent ran `rm -rf` on the user's Windows home directory (via 8.3 short name), no hard guard; delete kept running after the task was stopped Open
allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
No entry names this NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
No entry names this claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
Probably plugin-commands-wait-for-remote-managed-settings-before-runn, plugin-remove-explains-blocked-legacy-local-settings-file, marketplace-argument-validation-for-plugin-install, claude-plugin-install-marketplace-flow-added-only-the-fun claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
Probably print-mode-can-hold-open-for-background-shells-before-the-ce #86447[BUG] Print mode (-p --output-format stream-json): session ends with result: success while background tasks are running and a ScheduleWakeup is pending — scheduled wakeup can never fire, background tasks are killed Duplicate
claude --resume session picker or with /resume
No entry names this #89463Plan mode indicator vs. enforcement desync when resuming a conversation that was in "edits on" Open
/resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
No entry names this #98219Durable scheduled tasks (CronCreate `durable: true`) never fire after an in-app `/resume` Open
/loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
Probably loop-wakeup-scheduling-tracks-tooluseid-and-chain-start, cronloop-tasks-can-fire-after-input-closes-while-waiting-fo pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
No entry names this /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
Probably feedback-now-tracks-send-state-and-shows-a-submittingdone, safeguard-flagged-message-text-now-drops-a-sentence-for-some /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
No entry names this f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
Nothing to match on /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
No entry names this ! leaving the row selected
Nothing to match on /cd or a permission change, and added a transcript line when a nested one isn't loaded
No entry names this /name letting Claude invoke a skill that is reserved for the user
No entry names this $.state calls through one const taking minutes to load or validate
No entry names this claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere
Probably plugin-commands-wait-for-remote-managed-settings-before-runn claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused
Probably plugin-commands-wait-for-remote-managed-settings-before-runn $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end
Nothing to match on config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name
No entry names this /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked
No entry names this tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog
Probably tool-check-hooks-can-no-longer-override-tools-that-require-t, plugin-toolcheck-and-uiscroll-wait-on-pending-work-first next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected
No entry names this $ name that a user-installed mod had added; the mod is now unloaded instead
Nothing to match on tool.call hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with
No entry names this .catch being skipped silently for calls another mod's hook makes beneath the guard's own $ call; its .catch is now asked
Nothing to match on claude -p and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer resources/list
Probably print-mode-can-hold-open-for-background-shells-before-the-ce <system-reminder> tags written in a hook's output are escaped before they reach Claude
No entry names this file_path for path, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call
Probably search-tool-accepts-file-path-as-an-alias-for-path, artifact-preview-tool-wording-differs-in-emulator-mode FOO=bar python3 app.py runs unprompted
No entry names this MCP_PROTOCOL_NEGOTIATION=legacy opts out
No entry names this claude plugin test: a failed expect inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently
Probably plugin-commands-wait-for-remote-managed-settings-before-runn name longer than that is ignored
Nothing to match on @Claude !status in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again
No entry names this !fork to a card showing where it came from, the request, and who asked, with a link to the original thread
Nothing to match on A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 of 25 tool schemas changed.
Claude Code, interactive mode
11 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
495 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 59 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?