Folder trust is checked more strictly for linked git worktrees#
For linked git worktrees, Claude Code now checks the trust record comes from the right folder and fails the check if it does not match
The haiku model name now picks Claude Haiku 5.5 on Anthropic's own API. Bedrock, Vertex and other providers stay on Haiku 4.5. Haiku 5.5 has a 1M-token context window and its own pricing. Desktop admins can now start Claude Code through a corporate launcher with the claudeCodeProcessWrapperEnabled setting. New inferenceIdpOidc and inferenceIdpAuthFlow settings extend company sign-in to more setups, including Bedrock proxies. Admins can also set a Microsoft Foundry base URL for Claude Code sessions from the desktop app.
Four features are in the build but not switched on yet. One is a startup check for team and enterprise users. It would block startup if organization policy or settings fail to load. Another would tell Claude which of its settings files a shell command changed. New keyboard actions for moving between tabs are listed but do nothing yet.
Waiting permission requests no longer time out while you are answering an input prompt. Large repositories stall less when starting a cloud session. MCP servers no longer show an old error after their tool list refreshes successfully. Remote Control now shows the session as running again after it reconnects mid-turn. Sessions that Claude Code starts on its own now keep your Chrome on or off choice. Away and back signals from people viewing a remote session are no longer passed on.
Written by our agent from the shipped bundle, not by Anthropic.
The MCP clientSecretHelper must now print a JSON object, managed config adds OIDC sign-in and session retention, and Workspace becomes Capabilities
Settings & configisDeferred$.tool.register accepts an isDeferred true or false option, so plugin tools can load only when found through tool search
/claude-testClaude Test gains sign-in-dependent access and messages for when it is still loading or its browser helper failed to load
ElsewhereWith CLAUDE_CODE_PEWTER_OWL_TOOL set, the affected tool path now reports whether the turn ends and what to tell you, not a response ID
New inferenceIdpOidc and inferenceIdpAuthFlow settings extend company sign-in to more setups, including Bedrock proxies
Want the reasoning? Read walks the 42 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →10 more of these are in What probably matters to you, on page 1.
For linked git worktrees, Claude Code now checks the trust record comes from the right folder and fails the check if it does not match
When an agent that cannot send messages lists other agents, it gets a notice instead of being told peer messaging is available
The question about rewinding after a refusal now tracks whether a rewind point exists and notes when it disappears while you wait
Unclear It is not clear whether this rewind question appears for every account or only behind a setting switched on remotely.
Uploads now fail with a dedicated message when Claude Code cannot locate the folder holding the worktree's trust and settings
When settings are copied to a cloud session, the messages now say which deny or ask rules and files were left out as likely credentials
If your settings were not sent to a remote session, the warning now says your deny and ask rules are not in force there
Transcripts sent with feedback or bug reports can now replace conversation summaries with a placeholder, as they may include account memory
Unclear Which places Claude Code runs in turn this removal on is not stated.
The message about whether project files reach cloud sessions now considers a second input and has two new outcomes
Unclear It is not clear what supplies the second input or where these messages are shown.
When a cloud environment is recreated, the notice can now say your forwarded settings are not in force and lists rules dropped for looking like credentials
A failed SessionEnd hook that ran on another machine no longer writes its failure output locally, and a new message marks such hooks
When purge cannot delete something it now records why and says the rest is still on disk; an interrupted purge says it stopped and suggests --dry-run
Managed tool policy patterns for MCP tools from plugins now match regardless of case, and two policy sets can be merged keeping the strictest
Unclear Whether these policy changes apply to the Claude Code command-line tool or only to the desktop app.
Managed settings now check that an organization ID is a valid UUID, and documentation links appear only for settings the desktop app reads
When bypass permissions mode is requested at launch but ignored, a pinned warning now says to set skipDangerousModePermissionPrompt to true
rewind_conversation accepts refuse_missing_target_if_usage_limited, and wrongly refuses fewer rewinds over later turns
Pressing right on the highest effort level now stays there instead of jumping back to the lowest
Claude Code caps a cache of MCP tool entries by total size and per-tool count, strips __proto__ keys, and sometimes skips some environment lookups
Unclear It is not clear under what condition Claude Code skips the process and git lookups.
Rows in the remote session list now take their status from the whole session and show a reason in place of the title when there is one
An admin setting that offers a prompt import now says it is off unless set, and that show needs enabled or a sign-in import
When Claude calls a tool that is not available, the error now says whether it is disabled or simply not offered here, with special advice for Agent
A 'not found' answer when fetching a skill file now carries the server's error details, and one wait loop treats 'not found' as finished
Unclear Which waiting step treats 'not found' as finished is not known, so it is unclear what a user might notice.
The error for an MCP tool call that got no answer now says only that the server never answered, and drops the line about the answer stream ending
Switching tabs in the fleet view now resets a second piece of selection state as well as the first
Unclear It is not clear whether this changes what happens on a tab switch or only renames existing code.
When the caller cannot message a subagent, the turn-limit note now drops the hint to send that agent a message
Some permission prompts now get a note line added at the top, instead of having their whole message rewritten
Unclear It is not clear what the added note says or which permission prompts receive it.
In remote sessions, a stream update that is too large is now dropped outright, with no trimmed retry as before
The background task picker now shows a task's subagent type when it differs from the default agent type
The label on the list of files changed during a shell command now says another process may have changed them too
Syncing settings from your machine now shows a warning when credential files or credential restrictions are left out
When deciding how to resume an interrupted turn, Claude Code now notices if Claude's last finished reply was never shown to you
Unclear Whether this makes Claude Code resume more or fewer interrupted turns in practice is not settled.
The note Claude receives after a long conversation is compacted has new wording and drops the line saying recent messages are preserved verbatim
When a git shared index is too large to upload at session start, Claude Code now warns not to delete files by hand
The notice about unreadable Read rules or sandbox settings now says uncommitted files are left out of the upload to the cloud session
If a session moves to the cloud but Remote Control in your terminal fails to update, Claude Code reports it as a partial failure
When a background agent cannot be continued, Claude is now told to relaunch it or check its output instead of sending it a message
When sending to a cloud session fails, Claude Code now says if the message may have arrived anyway and to resend if Claude doesn't reply
When a rewind target is missing and was asked for, Claude Code now reports that the target was not found
Unclear It is not clear which rewind action a reader takes that leads to this new not-found result, or what they see when it happens.
Claude Code now strips a turn-limit partial-result marker and two other known markers from the text of subagent results
The badge showing your default permission mode is now hidden in an extra case, not only when the mode is the default
Unclear Which condition now hides the badge is not known.
The logs, stop, kill and rm commands for background sessions no longer fetch remote feature settings before they start
Hook output with an unknown permission decision or the wrong event name now raises an error that states which of the two went wrong
Unclear It is not clear whether this reason is shown to you or only recorded in Claude Code's usage reporting.
Records for finished subagent tasks now include the subagent's type, and one synced-skill check applies only to skills from the synced folder
After a restart, notices about a background agent that cannot be continued now suggest relaunching it or getting its report instead
Cloud sessions now give a separate notice when forwarded settings are lost after the environment is recreated, and list rules left out for looking like credentials
The spacing of the footer on the /help screen now adjusts, and an internal cache for tool instructions tracks one more setting
The error for a gateway host Claude Code cannot resolve now says to connect to your organization's network, without mentioning a VPN
A keybinding such as 'ctrl + x' now produces an error telling you to remove the spaces next to '+', instead of being misread
Two gateway connection errors now say to connect to your organization's network, dropping the "(or VPN)" wording
If loading the fleet view's session list fails briefly, the sessions already shown stay listed instead of the list going empty
Claude Code's check of a repository bundle now pauses regularly instead of blocking, so large repositories stall less when starting a cloud session
Sessions that Claude Code starts on its own now pass along --chrome or --no-chrome when the Chrome setting was set either way
Purging history and folders now goes through a shared step, and purging a project stops cleanly when an error occurs
When Remote Control reconnects while Claude is working, the session now shows as running again
When an MCP server's tool list refreshes successfully, stale discovery and sign-in errors are now cleared
A waiting permission request now restarts its timer instead of timing out while an input prompt is still waiting for your answer
If listing sessions fails, the fleet nudge keeps its last counts of sessions waiting for input instead of resetting them to zero
When a tool call to an HTTP MCP server fails with certain errors, Claude Code now marks it as answered instead of still waiting
Unclear Which errors, apart from an expired session, count as an answer is not known.
File staging in cloud sessions now marks unrecoverable failures as permanent so they are not retried, fixes the gated-list error text and notes overwrites
When a cloud session starts, Claude Code now records a skip when there are no project settings files and counts credentials it removes
Listing past sessions can now report when the sessions folder can't be read, where before it just returned an empty list
Unclear It is not clear whether or where Claude Code shows this error to you.
The warning about MCP servers blocked by enterprise policy now shows whenever the set of blocked servers changes
Claude Code now forgets it already announced a skill once that skill is replaced mid-session, so the new version can be listed again
After a delete in the prompt input, the cursor is now placed using the line and column left after deletion, not the old position
When stopping a shell command, Claude Code now skips the escalation steps if the process has already exited
Several small fixes cover screen layout positions, vim visual-mode indenting, failed results and allow-list state
The prompt input has a changed check for finding text that ends in combining marks such as accents
Unclear It is not clear what this check does when you type.
As you edit the prompt, Claude Code now matches pasted content using Unicode-normalised text and caches each comparison
Unclear It is not clear what visible problem with pasted content in the prompt this fixes.
2 more of these are in What probably matters to you, on page 1.
A new, switched-off check tells shell commands that only name app identifiers apart from ones that name settings files
Unclear Which shell commands this check applies to is not explained.
Behind a setting that is off by default, Claude Code checks its settings files before and after a shell command and tells Claude which ones changed
Claude Code can mark a round of polled events as declared and hand them to Claude in one message, but only behind a remote switch
Unclear What changes for a user when a round of events is marked as declared is not known.
8 more of these are in What probably matters to you, on page 1.
Claude Code gains a step that waits for transcript uploads before a session is handed off, and records when the wait times out or fails
Syncing settings to a cloud session skips rewriting identical files, keeps files that differ, and reports files that are too large
Unclear Where Claude Code turns this option on is not known, so it is unclear when files are now left alone.
The claude-test plugin drops its explicit edit rules for CLAUDE.md, .claude and .mcp.json and adds rules for .claude-test files
Unclear It is not shown whether the shared lists still cover CLAUDE.md, CLAUDE.local.md, .claude and .mcp.json.
A failed settings restore is now marked as permanent, and restores can end as switched off or settings gone
Unclear It is not clear which settings restore or sync feature this belongs to.
A new entry about container sessions restarting on a version change was added to the list of container-related names
Unclear It is not clear what this list is used for or whether anything turns this behaviour on.
When a remotely served shell command is held on settings, Claude Code now records the cause and notes if settings changed around the command
Queued messages now mark whether they carry monitor output or a notice, and the cap on remembered reads returns a dropped count instead of logging it
Remote permission handling now records when a prompt ended and when a parked answer arrived, including at shutdown
Queued remote notifications gain a readsDroppedThisTurn counter and keep pinned items, alongside several small remote-session tracking changes
/bug reports and feedback drafts now pass a host value, and captured transcripts record it and are cleaned according to it
Unclear It is not stated what the host value is or how it changes where a report goes.
Feature-ok telemetry gets per-feature sampling rates from remote config, and the sampling helper now takes the rate as a number
Monitor watches now emit a close event saying why they stopped, and a fixed MCP app sandbox host was added
Every tool now goes through the read-only check for served shell lines, and a check that fails counts as not read-only
Unclear Whether this lets more tool calls run as read-only in practice is unclear.
When auto mode's action check cannot return a result, Claude Code now records what kind of error it was and the HTTP status code
Unclear It is not clear whether these failure details are shown to the user anywhere or only kept for diagnostics.
The text bundled into Claude Code for onboarding and model migration has changed, with onboarding replaced by a reference file
Unclear What the text now says, compared with before, is not known.
Claude Code's record of a session's requests now keeps your last prompt, plus the model and time of each request, for cache timing
Claude Code now keeps one shared list of effort levels: low, medium, high, xhigh and max
The outbound network address Claude Code lists for a plugin marketplace now comes from a different lookup; GitHub sources still list github.com
When placing a model's deprecation date in Pacific time, Claude Code now works out daylight saving from the US calendar rules
Claude Code's remote sessions handle a new "returned" state and either report a reconnect or announce the return
Unclear It is not clear when a session enters the returned state or what a user sees when it is announced.
Remote session home seeding now logs when a staged file announcement is read, and its on/off check gains an announced-only result
Unclear It is not clear whether the announced-only state can be reached or what it changes for a remote session.
In remote mode the staging folder is marked as coming from chat, and an oversized git shared index is reported as its own case
A callback for viewer sign-ins is gone from the remote connection, and host mount state is now cleared when a connection closes
Claude Code now keeps a record of which tasks started background shells marked as quiet, and clears it on reset
Unclear What a reader actually sees differently, such as fewer or different notifications about background shells.
Remote sessions now save data only when CLAUDE_CODE_REMOTE_SESSION_ID is set and the session came from an allowed remote entry point
Unclear It is not clear what these checks control in practice.
When a remote session's saved settings are gone, Claude Code now rechecks and reports them as not restored
In remote sessions, Claude Code now records for diagnostics whether each prompt queued while it worked was answered, left open or stopped
When Claude Code successfully restarts a background session, it now runs an extra step on that session
Unclear What the new step does after a background session restarts is not known.
When a remote session gives up registering or its live connection times out, Claude Code now tags the diagnostic with a reason code
The connection check for remote sessions now records when the connection was last healthy and uses a different timeout value
Unclear Whether the new timeout for remote sessions is longer or shorter than before is not known.
Published verbatim by Anthropic for v2.1.293. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 56 bullets, 9 name something an entry on this page also names, 15 name something no entry here does, and 32 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
claude-haiku-5-5), now the default Haiku model on the Anthropic API — 1M context, $0.10/$0.50 per Mtok ($0.50/$2.50 for prompts over 100K)
Probably haiku-alias-moves-to-claude-haiku-55, haiku-alias-now-defaults-to-claude-haiku-5-5-with-third-par, claude-haiku-5-5-model-family-recognised, claude-haiku-55-model-added-with-vertex-region-override agentType to the subagentStatusLine payload, so scripts can tell custom subagent types apart
No entry names this isDeferred to $.tool.register for mods: false lists the tool's schema in the prompt from the start instead of behind tool search
Probably mods-can-register-deferred-tools, toolregister-accepts-isdeferred ← moved the session to the background; if a queued message can't move, ← now stays put and says so
Nothing to match on /model effort ←/→ wrapping past the highest or lowest level, which could accidentally save Low as a model's default effort
No entry names this #99212/model picker: pressing Right on the highest effort level wraps to Low and saves it as the default Closed
/tui disconnecting Claude in Chrome in a session started with --chrome, and ignoring --no-chrome
Probably spawned-sessions-now-forward-chrome-no-chrome SendMessage in sessions, including resumed ones, where a host, a permission rule or a --tools list removed that tool
Probably resumed-subagent-run-flag-documented-for-sendmessage-waits, orphaned-background-agent-resume-messages-depend-on-whether, agent-subagent-report-and-messaging-prompt-strings-refactore, restarted-background-agent-notices-adapt-when-the-agent-cann #92183[BUG] Desktop app disallows SendMessage, so subagents cannot be messaged or resumed Closed
--agent sessions being told a built-in tool was disabled for the whole session when only their own tool list left it out
No entry names this /clear
Probably safety-stop-count-field-on-results claude logs, stop, kill, rm and claude daemon status, stop, uninstall sometimes signing you out when your login had expired or was about to
No entry names this worker being shown as "Agent" when it starts, and the agent detail dialog's title losing the agent type once the agent finishes
Probably tool-not-found-errors-tailored-for-the-agent-tool-and-disabl, background-agent-completion-notice-omits-send-it-a-message, subagent-results-now-report-cancontinueagent Artifact("(unprintable path)") while a publish call was still streaming in
No entry names this /ultrareview upload on Linux wrongly refusing some repositories, such as one inside another checkout, over a settings file that "could not be parsed" while a sandboxed command was running
No entry names this /ultrareview upload's refusal over split-index files advising a git command that could leave git unable to read its index
No entry names this claude remote-control
No entry names this #92661PushNotification reports "Remote Control inactive" (no_transport) in sessions served by `claude remote-control` Open
#99781PushNotification reports "Remote Control inactive" in sessions started with claude rc Closed
classic.* events being skipped while the plugin hooks worker restarts, which left settings hooks to answer without them
No entry names this claude plugin test failing for mods that call $.session.append; tests can read the appended rows back with the new mock.session
No entry names this claude plugin eval refusing every Bash-granting run on Macs with Docker Desktop (links under ~/.docker/bin); the refusal now names which part of a credential store held the link
No entry names this #93368`claude plugin eval` refuses every Bash-granting evaluation under Docker Desktop's default `~/.docker` layout; `DOCKER_CONFIG` does not bypass Open
#94308`claude plugin eval` refuses every Bash-granting run on a Mac with Docker Desktop (symlinks in ~/.docker/cli-plugins) Closed
desktop policy sets Claude Desktop's built-in browser keys, such as builtinBrowserEnabled
Probably desktop-3p-config-built-in-browser-policy-keys-added #100016[BUG] Claude gateway rejects builtinBrowserEnabled in policy desktop block Open
claude agents offering bypass permissions that background sessions then ignored when consent was saved only in .claude/settings.local.json or a --settings file; it now asks for consent first, and a session that ignores bypass shows a short notice that stays
No entry names this ← backgrounding a session after 10 seconds while the prompt held unsent text (it now cancels the move) or a question was waiting for your answer
Nothing to match on ← had just been pressed to move the session to the background
Nothing to match on /feedback returning to the drafts list after Ctrl+O or Ctrl+Z while a report was sending, leaving the send impossible to cancel
Probably feedback-transcripts-redact-account-memory-compact-summaries claude purge stopping silently (exit 0, or a hang in a terminal) when a file or folder could not be deleted; it now deletes the rest, lists what it could not delete, and exits 1
No entry names this >> and << on a line of only spaces leaving the cursor past the end of the line, where a following x deleted nothing
Nothing to match on V then d) the cursor lands on the first non-blank, and . after it acts on the cursor's line
Nothing to match on /loop wakeup or scheduled task; Claude is no longer told, and the session stays asleep
Probably org-managed-config-schema-gains-sharing-endpoint-scheduled claude_code.at_mention logging to emit at most 100 agent and 100 MCP-resource events each time a prompt is read
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 added and 1 removed, of 218 lines, about 9 words, in the prompt 14 of 27 arms receive. 3 other prompts also changed. 1 new prompt appeared. The appended system-reminder blocks moved: 1 line added.
Claude Code, interactive mode
No prompt capture for v2.1.293, so this release's prompt surface is unknown.
718 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 37 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?