New CLAUDE_CODE_AUTOUPDATER_DISABLED_BY_HOST lets a host stop plugin auto-updates#
A host program can set CLAUDE_CODE_AUTOUPDATER_DISABLED_BY_HOST so plugin auto-updates stay off under the host's version pin
Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG now stops your own skills, agents and hooks from widening permissions. In that mode, errors in your user settings file block every prompt and tool call until you fix them. You can set transcriptCacheTtl to 5m to ask for 5-minute prompt caching instead of the default 1 hour. claude mcp serve has a new --session-tunnel mode that connects through a relay. Idle conversations are now compacted shortly before their prompt cache runs out. Plugins can now send notifications through your terminal.
Several features are in this build but not switched on yet. Print mode can show each turn's text result as soon as that turn ends. MCP servers that failed with a retryable error can be retried at the start of the next turn. Images can be re-encoded as smaller WebP files when that saves space. Work on cloud sessions continues, with remote tool requests now pausing while the host computer sleeps. The fleet view can group and pin cloud sessions.
Tool search no longer freezes Claude Code when you have very many tools. A queued message that gets dropped is now handed back to you instead of being discarded. Prompts typed during a left-arrow hand-off to background agents are no longer lost. If a model rejects the 1M-token context option, Claude Code now leaves it out instead of failing every request. Plugin sync from claude.ai no longer removes plugin files that another running session is using. The end-of-turn message no longer includes token budget figures.
Written by our agent from the shipped bundle, not by Anthropic.
In cloud-remote sessions only, claude mcp serve can run over HTTP, dial a session tunnel, read tokens from a descriptor and return tool output objects
ExtensionsA host program can set CLAUDE_CODE_AUTOUPDATER_DISABLED_BY_HOST so plugin auto-updates stay off under the host's version pin
ExtensionsPlugin UI adds a ui.notify operation and Button text from children, and the Grep search now passes a searchOtherAppsData flag
Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG stops your own skills, agents and hooks from widening permissions, and makes key hooks required
Settings & configCLAUDE_CODE_RESTRICT_PERSONAL_CONFIG mode restricts your own Claude Code filesSetting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG starts a session that restricts your own Claude Code files, alongside the other restricted modes
Want the reasoning? Read walks the 43 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →Anything you can use today, anything that visibly changes, and anything worth poking at. One line each, open for detail.
A host program can set CLAUDE_CODE_AUTOUPDATER_DISABLED_BY_HOST so plugin auto-updates stay off under the host's version pin
Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG stops your own skills, agents and hooks from widening permissions, and makes key hooks required
CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG mode restricts your own Claude Code files#Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG starts a session that restricts your own Claude Code files, alongside the other restricted modes
Unclear Which of your own files and settings this mode actually stops from loading is not settled.
A new SELF_HOSTED_RUNNER_SERVER_AUTO_MODE_LISTS setting lets self-hosted runner operators limit which server-supplied auto mode lists sessions follow
Unclear Which of the three values the runner uses when the variable is not set is not stated.
The summary of plugin and marketplace settings now includes a seat section with its own plugin and marketplace values
The gateway's timeouts.upstream_ttfb_ms now covers non-Anthropic upstreams when you set it, upstreams take a models list, and Bedrock can count tokens
Unclear What the per-upstream models list does is not stated.
With CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG set, errors in your user settings file block every prompt and tool call until they are fixed
Command and http hooks accept a new onFailure field, and setting it to "block" makes a failing hook block the action
A new hook option set to block makes a hook that fails, times out or returns bad output stop the action it guards
Unclear The name of the key to put in a hook's configuration for this setting is not known.
CLAUDE_RUNNER_FETCH_SERVER_PROGRESS_CAP_MS sets a time cap on server-side progress when a runner fetches a repository
Unclear It is not stated what happens when the cap is reached, or what the default cap is.
With CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG set, your own agents' MCP servers are skipped and launching an agent in the cloud is refused
HTTP hooks gain an onFailure setting, and icons, stylesheets, scripts, fonts and similar files now get their own file extensions
Unclear What the new onFailure setting does and which values it accepts is not stated.
The gatewayUrl setting is now honoured from your user settings on a machine with no managed settings, not only from admin-managed ones
Unclear Only the setting's description is confirmed to have changed, not the code that applies it.
x-should-retry: false with a 501 not supported response#The bundled gateway guide now says a 501 not supported response should send x-should-retry: false, or Claude Code retries once first
What would fix it?
Smaller changes and internals, grouped as the pipeline found them. Nothing is dropped, it is only further down.
19 more of these are in What probably matters to you, above.
Self-hosted runners can now write server-supplied autoMode allow, environment and soft-deny lists into sessions, with allow lists withheld by default
When an environment keeps its own settings, only deny and ask rules from your machine are applied, and the notice now explains what was skipped
Seeding of home settings now also runs for runner child sessions that declare an absolute CLAUDE_CONFIG_DIR, not only managed cloud workers
Unclear How a session comes to be treated as a runner child is not stated.
In a certain session mode, Claude Code now skips skills from project folders and synced user skills, and also skips some git and config lookups
Unclear Which session mode causes project and synced skills to be skipped is not settled.
When finding autoMemoryDirectory, Claude Code now skips settings sources that fail a new check, so they cannot move the memory folder
Unclear It is not stated which settings sources fail the new check, so it is unclear whether a project-level autoMemoryDirectory is still honored.
When Claude Code runs inside a claude-code-server setup, it now sends no first-party usage events unless it was given a grant to do so
In a new personal mode, hooks from your own files can no longer change a tool call's input or certain tool results, and Claude Code says so
Unclear It is not stated when Claude Code runs in this personal mode, so it is unclear which sessions get these limits.
With CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG set, launching a cloud agent is refused and you are told to use worktree isolation
disableAllHooks is set#With disableAllHooks set, Claude Code can now still run hooks from your own settings under certain conditions
Unclear The internal condition that lets your own hooks keep running is not stated, so it is unclear when this applies to you.
With a gateway provider, the model list no longer requires a name containing opus, sonnet or haiku
Unclear The further check a gateway model must pass to appear is not stated.
On Amazon Bedrock in a region outside the US and Canada, Claude Code now sends a changed model ID
Unclear It is not stated how the model ID is changed for those regions.
On Bedrock gateways, count_tokens now calls AWS CountTokens with a 10-minute retry backoff, and the built-in gateway guide says the same
When a list grows past its length limit, Claude Code now trims unmanaged entries first and keeps trimming until the list fits
Unclear It is not stated which list this is or what its entries hold, so it is unclear where a reader would notice the change.
When the gateway's Postgres database cannot be written to, the gateway now logs a warning naming the cause and how to fix it
Self-hosted runners can now force a refresh that skips the usual wait and re-runs right after one already in progress
Warnings about upstream model lists in proxy settings now apply to every provider, accept wildcards, and flag entries that match no usable model
Unknown keys in the gateway's Claude Desktop settings are now passed on with a warning, with hints for typos and mis-indented keys
Claude Code no longer reconnects to a saved Cloud gateway when your organization's settings name another gateway or none
When policy limits cannot be fetched and none are saved, Claude Code now needs one more condition before running without restrictions
Unclear It is not stated what the new check tests, so it is unclear which sessions still run without restrictions.
Claude Code may now skip setting up log export to your own telemetry system under an extra condition
Unclear It is not stated what condition now stops the log exporter being created.
With a gateway provider and no Haiku-class model set, hooks use the main model and failed side requests retry on the default
The gateway sign-in screen can now say its address came from your settings file, and Esc now leads to other ways to log in
Self-hosted runner help now says session state stays on disk when cleanup is off, and marks warn as the default confinement mode
When Bedrock rejects a model for on-demand use, the gateway now logs that it needs an inference profile and suggests mapping to one
Trimmed session transcripts are now marked as trimmed, and self-hosted runners can create git repositories without a template
When gateway model discovery is skipped, the message now says the base URL is asserted to be the Anthropic API rather than naming a variable
Unclear Which settings besides _CLAUDE_CODE_ASSUME_FIRST_PARTY_BASE_URL can now cause discovery to be skipped is not stated.
Claude Code now rejects an empty models list on an upstream and says to remove the key to send every model
Unclear Which configuration file or feature this upstream models list belongs to is not stated.
Detailed beta tracing now also requires that the session is not diskless, so it stops in sessions that avoid writing to disk
Unclear What makes a session diskless is not stated.
Claude Code no longer recreates a missing enterprise gateway entry when saving a refresh token, and keeps a stored one that differs
If workload identity credentials are reset while Claude Code is fetching them, it now throws away the result and fetches again
1 more of these is in What probably matters to you, above.
Under a certain condition, Claude Code now sets CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG to 1 for the sessions it starts
The Bedrock Mantle provider entry no longer supplies a list of models, keeping only its login-refresh handling
Unclear Whether this changes which models are available through Mantle is not known.
Claude Code now checks plugin-related settings that come from settings files users cannot write to
Unclear What Claude Code does with the result of this check is not stated.
In a certain restricted mode, usage data no longer includes your email and reports a fixed terminal type
Unclear The condition that switches on the restricted mode is not stated, so it is unclear who gets this behaviour.
Under an organisation's telemetry rules, usage data still waiting to be sent at shutdown is now recorded as dropped
A startup check on whether project settings can be claimed is now skipped in some cases, and settings sync handles files from elsewhere
Unclear What condition makes the project-settings check get skipped is not known.
The screen where you pick how to log in takes a new internal option related to gateways, with no visible effect stated
Unclear What this option changes on the login screen is not stated.
The gateway now reads an upstream request ID header, returns it as the request ID on successful replies, and passes on a response timeout
Published verbatim by Anthropic for v2.1.295. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 143 bullets, 35 name something an entry on this page also names, 32 name something no entry here does, and 76 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
onFailure: "block" for command and HTTP hooks: a hook that can't start, times out, or exits with an unexpected code blocks the action instead of letting it through
No entry names this /copy picker, so a drafted message copies without its > markers
Probably copy-picker-now-lists-blockquotes-as-well-as-code-blocks claude plugin install, enable, disable and marketplace add when the settings file they write to does not load
Probably release-notes-bundle-for-21292, marketplace-add-warns-after-success claude -p run is waiting for when it stays open after its last turn
Probably print-mode-text-results-printed-at-each-turn-end timeouts.upstream_ttfb_ms on the Claude apps gateway's Bedrock, Vertex, Foundry and other cloud upstreams: a value you set now limits how long a stream may take to start there, after which it fails over or gets a 502
Probably gateway-upstream-ttfb-timeout-now-only-applies-when-operator, gateway-notes-upstream-ttfb-ms-now-applies-to-non-anthropic ← is waiting for the current tool to finish
No entry names this models list to every Claude apps gateway upstream: only the listed models are sent there, on failover too, and one * in an entry is a wildcard
Nothing to match on forceLoginMethod: "gateway" and forceLoginGatewayUrl in your own user settings on machines with no managed settings, so /login opens on that Claude apps gateway
No entry names this claude plugin validate when a plugin's README has no install line: it prints the line to paste and never changes the exit code, even with --strict
Probably claude-plugin-validate-adds-a-further-check-pass upstream_request_id to the Claude apps gateway's inference audit event: the request ID from Amazon Bedrock, the Anthropic API or another upstream, for support cases
Probably telemetry-additions-api-message-id-text-runs-joined-upstr $.ui.notify for mods: raises a native notification through your own notification setting and says which channel sent it
Probably plugin-uinotify-channel-and-tool-search-aware-description Button: strings and Text, so a row of a list is one pressable with a chip or a dim detail inside
No entry names this CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS to limit how long unattended retry mode (CLAUDE_CODE_RETRY_WATCHDOG) waits out 429 and 529 errors
Probably retry-watchdog-skip-can-be-overridden-by-claude-code-retry-w request-id header to the Claude apps gateway's successful inference responses, so request_id in Claude Code telemetry matches the gateway's audit log
Probably gateway-forwards-upstream-request-id, telemetry-additions-api-message-id-text-runs-joined-upstr [1m] model when a gateway, Bedrock, Vertex or Foundry refuses the context-1m beta; Claude Code now resends without it
No entry names this claude -p text output dropping earlier responses when background work started another turn; each turn's response now prints when the turn ends
Probably print-mode-text-results-printed-at-each-turn-end command_description instead of description
Probably bash-tool-input-command-description-is-accepted-as-descript host:80) to plain http:// pages on that host
No entry names this /plugin's Errors tab removing a marketplace that failed to load, and uninstalling its plugins, on Enter without asking first
Probably plugin-name-read-from-pluginjson-marketplace-clone-gains-p, plugin-errors-view-asks-for-confirmation-before-removing-mar, plugin-addressed-mcp-requestresponse-metadata-gated-behind claude plugin marketplace add reporting success for a marketplace whose name no plugin can be installed under; such an add is now refused
No entry names this CLAUDE_AUTO_BACKGROUND_TASKS moving a subagent to the background while an edit or shell command waited behind it, which started that call before the subagent finished
No entry names this claude remote-control sessions right after a phone message, without the /config toggle, or when started from inside Claude Code
Probably settings-panel-auto-update-channel-and-notification-changes, config-rows-commit-through-a-shared-writer-output-style-an #92661PushNotification reports "Remote Control inactive" (no_transport) in sessions served by `claude remote-control` Open
#99781PushNotification reports "Remote Control inactive" in sessions started with claude rc Closed
/tui exiting without a message, or with a raw system error, when Claude Code could not be started again
No entry names this availableModels not appearing in the /model picker for sessions signed in to a Claude apps gateway; such a model now shows its built-in row in place of a modelPicker row added for the same model
Probably remote-model-now-checks-whether-the-default-save-failed, model-pick-now-goes-through-a-saved-model-row-commit-with-s CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC hiding the Claude apps gateway spend limit in /usage and the status line. The spend limit request goes to the gateway the session is signed in to
Probably spend-limit-and-upsell-hint-text-refactored-into-a-lookup-ta, claude-mcp-serve-gains-an-http-transport-port-and-ses ←; Claude now keeps working in the foreground
Nothing to match on --tools and --restricted not applying to built-in tools that register after launch, and deprecated tool names reaching tools outside the caller's tool set
Probably sdk-spawns-cli-with-flagvalue-form-and-guards-values-st, tools-launch-list-now-withholds-unlisted-tools, new-claude-code-restrict-personal-config-env-var-recognized /loop that was moved to the background with ←; cancelling a pending wakeup now shows a notice
Probably resume-restores-a-pending-loop-wakeup-or-reports-it-as-mis FORCE_COLOR=3, which put color escape codes into the output Claude reads
No entry names this claude agents starting a new background service as it exited when both were stopped with a session open (for example at a reboot), which could delay shutdown and restart an interrupted session
Probably background-attach-prints-exit-notice-about-sessions-stopping #99369Agent view restarts the background daemon during system shutdown; the new daemon holds the shutdown for 90 s Open
worker being shown as "Agent" in auto-mode denial notices and in the activity lists of task detail views
No entry names this TaskStop, which can never be the cause
No entry names this /loop stopping without notice when its next wakeup came due while the session's process was down; the session now says so and Claude is told
Probably resume-restores-a-pending-loop-wakeup-or-reports-it-as-mis /advisor dialog showing a checkmark on a saved advisor model that is no longer available; it now opens on "No advisor"
No entry names this ~ moving the cursor past the last character of a line, so x after it did nothing, and 3~ running on into the next line
Nothing to match on .catch; such calls are now refused
Nothing to match on claude plugin test passing a session.append hook that removes tool call, tool result or thinking blocks that a real session keeps
No entry names this cat ran without printing it
Nothing to match on constructor or prototype always reading as their default and never reloading the plugin when edited
Nothing to match on /reload-plugins or session start was reading the mod's files
No entry names this /model, /fast and /output-style saving their setting without asking a plugin's config.set hook
Probably fast-mode-toggle-wrapped-for-remote-sessions-with-pre-switch, remote-model-now-checks-whether-the-default-save-failed, model-pick-now-goes-through-a-saved-model-row-commit-with-s claude mcp serve background Bash results not naming the output file, and its tool description promising a notification that never arrives
Probably mcp-tool-server-registers-extra-capabilities-when-serving-in, claude-mcp-serve-gains-an-http-transport-port-and-ses, mcp-serve-session-tunnel-and-tool-output-protocol #99934[BUG] `claude mcp serve`: Bash run_in_background output is unreachable since TaskOutput was removed (2.1.277) Open
CLAUDE_ENV_FILE not reaching the Bash tool after an in-app /resume or /branch
Probably restart-failure-messages #98933[BUG] CLAUDE_ENV_FILE env lost after in-app /resume — hook writes to startup session dir, Bash reads resumed dir (still on 2.1.287; #40391, #24775 auto-closed) Open
allowed-tools and effort being dropped when the Skill tool finished before the response stream ended, which denied the skill's Bash commands in -p runs
Probably new-claude-code-restrict-personal-config-mode-limits-what-a #99353[BUG] Skill allowed-tools rule is dropped when the Skill tool finishes before the response stream ends (2.1.289) Open
--plugin-dir plugin's folder in -p and SDK sessions; they are now written only where a mod is being developed
No entry names this /model saying a Max effort pick was saved as your default for new sessions; Max applies to the current session only
Probably remote-model-now-checks-whether-the-default-save-failed, model-pick-now-goes-through-a-saved-model-row-commit-with-s #99350[BUG] Clarify /model confirmation wording: max effort applies only to the current session Closed
pages parameter instead of treating it as omitted
Nothing to match on #98651[BUG] Read: `pages: ""` on a non-PDF file fails validation, and PreToolUse hooks can't work around it (still on 2.1.286) Closed
plugin install and uninstall at project or local scope on Windows missing the install record, or adding a second one, when only the drive letter's case differs
Probably release-notes-bundle-for-21292, plugin-install-lookup-refactored-into-a-shared-helper, plugin-install-records-matched-across-path-spellings-on-wind #92121Project-scope plugin installs are auto-created, never updated, and unreachable via --scope project (Windows drive-case duplicates) Open
↑ or Esc just after ←: prompt history now keeps it
Probably gateway-login-developer-sourced-url-and-esc-wording prompt.submit hook rewrote or dropped still being saved as typed to prompt history and to the transcript's queued-prompt records
No entry names this claude_code.auth OpenTelemetry login event not being emitted on Claude apps gateway sign-in. The event is exported when OpenTelemetry is configured on the machine or the session is already signed in to the gateway
No entry names this ~/.claude/seed-admin by an interrupted /ultrareview upload never being removed by the retention cleanup
No entry names this disableAutoMode was removed from settings
No entry names this /rewind being lost, and the removed turns coming back, when the session was moved to the background or resumed after being killed
Probably spend-limit-and-upsell-hint-text-refactored-into-a-lookup-ta session.receive hook asked for permission before passing a message on
No entry names this setMcpServers() as your own
No entry names this /config saving before a plugin's config.set hook was asked
Probably settings-panel-auto-update-channel-and-notification-changes, config-rows-commit-through-a-shared-writer-output-style-an /context and large file reads use: the gateway now gets them from AWS's CountTokens API instead of a one-token model request. Grant bedrock:CountTokens to use it
Probably bedrock-count-tokens-now-uses-aws-counttokens-with-backoff mcp__server__tool identifier
Probably auto-mode-resolves-toolaliases-for-mcp-tools-behind-tengu-so models: in Amazon Bedrock regions outside AWS's US geography. AWS always refused those requests; the gateway now tries the model in your own region, and a refusal names the model to add
Nothing to match on rate_limit_event usage-limit warnings to say whether the account has extra usage turned on
No entry names this plugin-authoring skill: it no longer tells a session with no terminal to run terminal commands, and explains sharing a mod only when asked
No entry names this -l, -c or -r flag now runs instead of failing the call
Nothing to match on claude plugin validate and plugin loading: when a hooks module is refused over a rebound top-level var, the error now names the line that rebinds it, the cause, and a fix
Probably claude-plugin-validate-adds-a-further-check-pass scriptPath refusal: it now says to pass the script inline via script, the route that works in sessions without a Read tool
No entry names this skills field, each once; a subagent with the Skill tool can still invoke the rest
Nothing to match on /loop wakeup alone, so pressing it twice detaches and the loop keeps running; press Esc to stop it
Probably resume-restores-a-pending-loop-wakeup-or-reports-it-as-mis claude agents stopped with its background service (macOS, or Linux without the service installed): running sessions now stop in about a minute unless it is run again, and a notice says so
Probably background-attach-prints-exit-notice-about-sessions-stopping MCP_PROTOCOL_NEGOTIATION=legacy opts out
No entry names this desktop policy key its bundled Claude Desktop schema doesn't know, so new Desktop settings need no gateway upgrade
Nothing to match on ws) MCP servers: a message over 16 MiB is no longer parsed and closes the connection, the limit the other transports already have
Nothing to match on CCR_AUTO_MODE_ALLOW, CCR_AUTO_MODE_ENVIRONMENT and CCR_AUTO_MODE_SOFT_DENY into a session's environment
Probably runner-spawns-child-with-ccr-auto-mode-env-vars-cleared CLAUDE_RUNNER_FETCH_SERVER_PROGRESS_CAP_MS tunes or turns off the wait
Probably git-fetch-gets-a-server-progress-stall-cap-env-var @Claude !restart had already confirmed the restart
No entry names this agent hook evaluations taking much longer at xhigh and max effort
Nothing to match on A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 added and 1 removed, of 218 lines, about 22 words, in the prompt 14 of 27 arms receive. 4 other prompts also changed. The appended system-reminder blocks moved: 1 line added, 1 line removed.
Claude Code, interactive mode
13 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
568 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 78 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?