Streaming connection diagnostics now tell a first connect from a reconnect#
Diagnostic messages about Claude Code's streaming connection now carry a code saying whether it is a first connect or a recovery after a drop
The haiku model name now picks Claude Haiku 5.5 on Anthropic's own API. Bedrock, Vertex and other providers stay on Haiku 4.5. Haiku 5.5 has a 1M-token context window and its own pricing. Desktop admins can now start Claude Code through a corporate launcher with the claudeCodeProcessWrapperEnabled setting. New inferenceIdpOidc and inferenceIdpAuthFlow settings extend company sign-in to more setups, including Bedrock proxies. Admins can also set a Microsoft Foundry base URL for Claude Code sessions from the desktop app.
Four features are in the build but not switched on yet. One is a startup check for team and enterprise users. It would block startup if organization policy or settings fail to load. Another would tell Claude which of its settings files a shell command changed. New keyboard actions for moving between tabs are listed but do nothing yet.
Waiting permission requests no longer time out while you are answering an input prompt. Large repositories stall less when starting a cloud session. MCP servers no longer show an old error after their tool list refreshes successfully. Remote Control now shows the session as running again after it reconnects mid-turn. Sessions that Claude Code starts on its own now keep your Chrome on or off choice. Away and back signals from people viewing a remote session are no longer passed on.
Written by our agent from the shipped bundle, not by Anthropic.
The MCP clientSecretHelper must now print a JSON object, managed config adds OIDC sign-in and session retention, and Workspace becomes Capabilities
Settings & configisDeferred$.tool.register accepts an isDeferred true or false option, so plugin tools can load only when found through tool search
/claude-testClaude Test gains sign-in-dependent access and messages for when it is still loading or its browser helper failed to load
ElsewhereWith CLAUDE_CODE_PEWTER_OWL_TOOL set, the affected tool path now reports whether the turn ends and what to tell you, not a response ID
New inferenceIdpOidc and inferenceIdpAuthFlow settings extend company sign-in to more setups, including Bedrock proxies
Want the reasoning? Read walks the 42 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →8 more of these are in What probably matters to you, on page 1.
Diagnostic messages about Claude Code's streaming connection now carry a code saying whether it is a first connect or a recovery after a drop
When Claude Code reconnects to a remote session after the clock jumps, as after sleep and wake, it now marks that reconnect
Diagnostic reports from remote sessions now carry a reason code, and two new steps run on user messages and file-staging requests
Unclear What the two new steps for user messages and file-staging requests actually do is not shown.
Tracking of reads for remote notifications now also counts how many reads were dropped
Unclear It is not clear whether the dropped count changes anything you can see.
When creating a session fails after a retry, the error reason is now marked as having happened after the retry
Two remote session setup failures are now marked permanent so they are not retried, and a broken credential check is fixed
Background tasks in the task list now store their subagent type, and keep it when the task starts
When a remote worker becomes idle, it no longer resets its record of whether readable reply text has begun this turn
Unclear It is not clear whether the marker is now reset somewhere else, so any visible effect on remote replies is unknown.
Requests that send batches of logged events are now cleaned of sensitive content first, and refused if their contents cannot be read as events
Unclear It is not clear what decides when this check applies, so it may not cover every way Claude Code sends analytics.
The list of services Claude Code connects to over the network now includes a 'Performance timing' entry beside 'Analytics events'
Unclear It is not clear whether Claude Code actually sends performance timing data in this version or only lists it.
Error reports now note when a session mode was refused, and connection diagnostics gain expired-token and missing-sign-in reasons
/api/v2/rum path on Anthropic's host#The essential telemetry endpoints now include an /api/v2/rum path on Anthropic's host alongside the Datadog hosts
Three new event names were added to the list of analytics events Claude Code may send, including ones about header tabs and remote sessions
Claude Code now reports only the first few @-mentions in a message one by one, and sends one count for the rest
Claude Code's usage reporting gains events for remote shell settings and a session list, and drops two project-setup events
Several internal diagnostic messages now carry reason codes, such as for a session that could not be found or a missing set of project files
Claude Code's reporting on possibly duplicated messages now notes whether the message was queued, should be sent, is synthetic or has priority
Claude Code's startup timing records no longer include the detailed breakdown of how long building the system prompt took
Claude Code now defers a trigger-fire event only when an extra piece of information comes with it, so fewer are put off
Unclear What a trigger-fire event is for a user, and what extra information decides whether it waits, is not stated.
An account-eligibility check now treats the enterprise plan as eligible only when a second condition is false
Unclear It is not clear which feature this check controls.
When a download fails because the server says the file is not there, such as a 404, Claude Code now records the cause as not found
A store of file contents Claude Code has read can now be set to always keep its reference copy, whatever the general rule says
One startup step in Claude Code's daemon now runs only for some of its subcommands
Unclear Which subcommands skip the step, and what the step does, is not shown.
When attaching a file fails because the server could not find it, Claude Code now reports that as its own reason
When the server rejects an upload as too large, Claude Code now records it as a too-large failure instead of a general one
Unclear It is not clear which uploads this covers or what you see when one is too large.
Claude Code now sorts web fetch errors such as bad URLs, blocked sites and rate limits into named reasons for its reporting
The log line written when a session's sign-in headers finally arrive now carries a reason code
Claude Code can now find blocks of text wrapped in certain tags and replace each one with a placeholder
Unclear It is not clear which tags are covered or where this replacement is applied.
Several internal fields were added around continuing agents, compact summaries and capabilities, and one context field was removed
Unclear It is not clear what any of these fields changes for you.
When Claude Code repairs doubly escaped text, it now removes keys that could tamper with internal objects and counts them
A saved record can now mark an entry as tried, and a new filter removes values and keys that match a sensitive pattern, counting what it held back
Unclear What the filter treats as sensitive, and where either addition is used, is not known.
An internal hashing helper now throws a type error when given something other than text or bytes, instead of hashing it anyway
Claude Code's internal load tracking now marks only the most recent typed load, and can note that it may still start
Unclear What feature this tracking belongs to and whether it changes anything you see.
Claude Code's check for when to retry after a period of idle time has been rewritten to use a single shared helper
Unclear Whether the timing of the idle retry actually changed or the rewrite keeps it the same.
Lists such as agent types and attachment names are now sorted with one shared comparison instead of a language-aware one
Requests with a time limit now combine your cancel and the timeout into one signal, instead of forwarding the cancel by hand
Subagents running in the background now receive a value saying whether whatever started them can continue agents
Unclear It is not clear what this value changes about how background subagents behave.
Each subagent now records whether the agent that owns it has the tools to continue agents
Status updates about background agents now tell Claude whether that agent can be continued, based on the tools available
The text for the tool that starts subagents now receives a flag, worked out from the available tools, saying whether continuing is available
Unclear What the Agent tool's text says differently when continuing is available is not known.
A subagent's result can now note that the calling agent cannot continue it, because the caller has no tool for sending it messages
The conditions that decide whether Claude can start a subagent are now combined into one shared check that also sees allowed agent types
Unclear It is not clear whether this changes when subagents can be started or only reorganises the same checks.
Moving a session to the cloud now tells the caller when it moved, may have moved or was refused, and treats server errors as possibly moved
When Claude Code copies your files into a cloud session, it now counts files refused because they look like credentials
Unclear It is not settled whether refusing credential-like files is new in this release or only the counting of them, nor which files count as credentials.
Claude Code now recognises a result meaning there were no project files, and handles it as a case where nothing needs doing
Unclear It is not clear which feature this belongs to or whether it is in use.
When Claude Code fails to read a stage file, the failure now also says whether the error is permanent
A debug message about permission rules that stay on your machine now refers to the settings prepared when the cloud session was created
Messages about permission prompts now pass on a decision reason type and code when Claude Code has them
Each tool result now carries a record of the permission decision behind it: the decision, where it came from, and sometimes a reason type
Tool results now carry a permission_decision field giving the decision, where it came from, and optionally the kind of reason
In headless mode, permission answers that arrive after their turn now carry extra context, and closing one without running its tool is recorded
Unclear It is not clear what the extra context changes for you when a late permission answer arrives.
When Claude Code writes deny and ask permission rules into settings, a restore case now uses its own merge and another case skips writing
Claude Code now separates tool results that carry a message for the user, and marks interrupted turns that end on an unanswered tool call
Unclear What difference this makes to what a user sees is not shown.
The rules for dropping tools from what Claude is offered now also check aliases, and Claude Code tracks skills that were replaced
Unclear It is not clear which extra conditions now cause a tool to be dropped.
Claude Code now builds each tool result through a shared step that also carries the ID of the tool call it answers
Unclear It is not clear whether this changes what gets stored or saved with tool results.
Tool filter statistics now count entries dropped for carrying credentials, and include them in the total number dropped
When a tool's input arrives as JSON text, Claude Code now removes some content from it after turning it back into structured data
Unclear What is removed from the repaired input is not stated.
The hardwareBuddyEnabled setting is now marked as for the desktop app, alongside new repository MCP and session-append entries
Unclear How any of these three additions reaches a Claude Code user is not known.
A check on your settings files now reports the names of environment variables they set, and treats project settings as their own level
An internal check that used to accept project-scoped items now rejects them
Unclear It is not clear what kind of item this check applies to.
Claude Code now stores where your local settings file is and its resolved real location, instead of working out the real location each time
Messages now carry a flag marking a repeated compaction summary, and some message copies keep their permission decision
A command's output can now be marked as repeating the conversation summary made during compaction
Unclear What the new permission-mode check affects is not known.
/compact now notes when its message already shows the summary#The result of /compact now records whether its on-screen message repeats the conversation summary
Hook code can call session.append next to session.send, and file-write checks, the sandbox and hook reporting get small changes
When Claude Code gathers hook output, it now skips results from hooks that ran elsewhere, not only failed, blocked or empty ones
Unclear It is not stated what makes Claude Code treat a hook as having run elsewhere, so it is unclear which setups this affects.
One way of running hooks now marks a backgrounded result as having run elsewhere
Unclear What this mark changes for someone using hooks is not shown.
Some authorized requests Claude Code sends to MCP servers now include a header holding the ID of the tool call that caused them
Unclear The header's name, and which requests pass the check that adds it, are not known.
When a tool call makes Claude Code connect to a cached MCP server, the call's id is now passed into the connection attempt
When connecting to a claude.ai connector that offers tools or prompts, Claude Code now skips one of two listing requests in some cases
When Claude Code saves memories from your conversation through MCP, it now passes along the prompt that led to them
Unclear It is not clear whether the change to the skip check alters when memories are written directly or only renames a value.
Claude Code now hides account-memory content only when memory is in play, and treats it as in play when it cannot tell
Session setup now marks the project as not synced and no longer tracks one memory-index timing step
When Claude Code sets up its connection to the API, it can now pass a request class value that feeds a request header
Claude Code now removes a field called input_transformations from streamed message events before passing them on
Unclear It is not clear whether this changes the streamed output that people reading Claude Code's own output can see.
SDK output now describes a resumed subagent run that the resuming tool call waits on, with its report returned in that call's result
Unclear The name of the new field is not shown, nor whether Claude Code actually sends it yet.
The result field counting safety stops covers refusals, content-filter stops and sometimes safety-monitor blocks, and resets on resume and /clear
Unclear The name of this result field is not known.
When a classification is 'other', or 'design' with a match, Claude Code now records a motion type field
When Claude Code looks up an artifact's declared capabilities, it now also records whether they cover the whole declaration
Unclear It is not clear whether this changes what happens when you publish an artifact.
When Claude Code cannot read a Chrome tab's web address and denies the action, it now records the reason and how long the lookup took
Two of the messages saying the Chrome browser extension is not connected now include an added piece of text
Unclear What the added text says is not shown.
An internal check tied to the sandbox no longer looks at any conditions and always returns false
Unclear What this check controls, and so what changes for a user, is not known.
Claude Code's sandbox has a new way to put a created file in place that refuses to replace a file already there
A step that used to check whether a plan limit period had ended now resets other internal tracking instead
Unclear It is not clear whether this changes when plan limits apply or show up for users.
When loading policy limits at startup fails or is replaced, Claude Code now also clears the stored outcome, HTTP status and server error
Claude Code no longer passes on away or back signals from people viewing a remote session, and records unexpected event types
Unclear It is not clear whether away and back signals are now handled somewhere else or dropped entirely.
Managed settings now treat coworkVmWindowsShareFallbackEnabled as retired and read disableMobileSimulatorTools from a new place
Published verbatim by Anthropic for v2.1.293. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 56 bullets, 9 name something an entry on this page also names, 15 name something no entry here does, and 32 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
claude-haiku-5-5), now the default Haiku model on the Anthropic API — 1M context, $0.10/$0.50 per Mtok ($0.50/$2.50 for prompts over 100K)
Probably haiku-alias-moves-to-claude-haiku-55, haiku-alias-now-defaults-to-claude-haiku-5-5-with-third-par, claude-haiku-5-5-model-family-recognised, claude-haiku-55-model-added-with-vertex-region-override agentType to the subagentStatusLine payload, so scripts can tell custom subagent types apart
No entry names this isDeferred to $.tool.register for mods: false lists the tool's schema in the prompt from the start instead of behind tool search
Probably mods-can-register-deferred-tools, toolregister-accepts-isdeferred ← moved the session to the background; if a queued message can't move, ← now stays put and says so
Nothing to match on /model effort ←/→ wrapping past the highest or lowest level, which could accidentally save Low as a model's default effort
No entry names this #99212/model picker: pressing Right on the highest effort level wraps to Low and saves it as the default Closed
/tui disconnecting Claude in Chrome in a session started with --chrome, and ignoring --no-chrome
Probably spawned-sessions-now-forward-chrome-no-chrome SendMessage in sessions, including resumed ones, where a host, a permission rule or a --tools list removed that tool
Probably resumed-subagent-run-flag-documented-for-sendmessage-waits, orphaned-background-agent-resume-messages-depend-on-whether, agent-subagent-report-and-messaging-prompt-strings-refactore, restarted-background-agent-notices-adapt-when-the-agent-cann #92183[BUG] Desktop app disallows SendMessage, so subagents cannot be messaged or resumed Closed
--agent sessions being told a built-in tool was disabled for the whole session when only their own tool list left it out
No entry names this /clear
Probably safety-stop-count-field-on-results claude logs, stop, kill, rm and claude daemon status, stop, uninstall sometimes signing you out when your login had expired or was about to
No entry names this worker being shown as "Agent" when it starts, and the agent detail dialog's title losing the agent type once the agent finishes
Probably tool-not-found-errors-tailored-for-the-agent-tool-and-disabl, background-agent-completion-notice-omits-send-it-a-message, subagent-results-now-report-cancontinueagent Artifact("(unprintable path)") while a publish call was still streaming in
No entry names this /ultrareview upload on Linux wrongly refusing some repositories, such as one inside another checkout, over a settings file that "could not be parsed" while a sandboxed command was running
No entry names this /ultrareview upload's refusal over split-index files advising a git command that could leave git unable to read its index
No entry names this claude remote-control
No entry names this #92661PushNotification reports "Remote Control inactive" (no_transport) in sessions served by `claude remote-control` Open
#99781PushNotification reports "Remote Control inactive" in sessions started with claude rc Closed
classic.* events being skipped while the plugin hooks worker restarts, which left settings hooks to answer without them
No entry names this claude plugin test failing for mods that call $.session.append; tests can read the appended rows back with the new mock.session
No entry names this claude plugin eval refusing every Bash-granting run on Macs with Docker Desktop (links under ~/.docker/bin); the refusal now names which part of a credential store held the link
No entry names this #93368`claude plugin eval` refuses every Bash-granting evaluation under Docker Desktop's default `~/.docker` layout; `DOCKER_CONFIG` does not bypass Open
#94308`claude plugin eval` refuses every Bash-granting run on a Mac with Docker Desktop (symlinks in ~/.docker/cli-plugins) Closed
desktop policy sets Claude Desktop's built-in browser keys, such as builtinBrowserEnabled
Probably desktop-3p-config-built-in-browser-policy-keys-added #100016[BUG] Claude gateway rejects builtinBrowserEnabled in policy desktop block Open
claude agents offering bypass permissions that background sessions then ignored when consent was saved only in .claude/settings.local.json or a --settings file; it now asks for consent first, and a session that ignores bypass shows a short notice that stays
No entry names this ← backgrounding a session after 10 seconds while the prompt held unsent text (it now cancels the move) or a question was waiting for your answer
Nothing to match on ← had just been pressed to move the session to the background
Nothing to match on /feedback returning to the drafts list after Ctrl+O or Ctrl+Z while a report was sending, leaving the send impossible to cancel
Probably feedback-transcripts-redact-account-memory-compact-summaries claude purge stopping silently (exit 0, or a hang in a terminal) when a file or folder could not be deleted; it now deletes the rest, lists what it could not delete, and exits 1
No entry names this >> and << on a line of only spaces leaving the cursor past the end of the line, where a following x deleted nothing
Nothing to match on V then d) the cursor lands on the first non-blank, and . after it acts on the cursor's line
Nothing to match on /loop wakeup or scheduled task; Claude is no longer told, and the session stays asleep
Probably org-managed-config-schema-gains-sharing-endpoint-scheduled claude_code.at_mention logging to emit at most 100 agent and 100 MCP-resource events each time a prompt is read
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 added and 1 removed, of 218 lines, about 9 words, in the prompt 14 of 27 arms receive. 3 other prompts also changed. 1 new prompt appeared. The appended system-reminder blocks moved: 1 line added.
Claude Code, interactive mode
No prompt capture for v2.1.293, so this release's prompt surface is unknown.
718 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 37 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?