Idle compaction is now timed to run just before the prompt cache expires#
A timer now compacts an idle conversation shortly before its prompt cache runs out, if it is large enough and rate limits allow
Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG now stops your own skills, agents and hooks from widening permissions. In that mode, errors in your user settings file block every prompt and tool call until you fix them. You can set transcriptCacheTtl to 5m to ask for 5-minute prompt caching instead of the default 1 hour. claude mcp serve has a new --session-tunnel mode that connects through a relay. Idle conversations are now compacted shortly before their prompt cache runs out. Plugins can now send notifications through your terminal.
Several features are in this build but not switched on yet. Print mode can show each turn's text result as soon as that turn ends. MCP servers that failed with a retryable error can be retried at the start of the next turn. Images can be re-encoded as smaller WebP files when that saves space. Work on cloud sessions continues, with remote tool requests now pausing while the host computer sleeps. The fleet view can group and pin cloud sessions.
Tool search no longer freezes Claude Code when you have very many tools. A queued message that gets dropped is now handed back to you instead of being discarded. Prompts typed during a left-arrow hand-off to background agents are no longer lost. If a model rejects the 1M-token context option, Claude Code now leaves it out instead of failing every request. Plugin sync from claude.ai no longer removes plugin files that another running session is using. The end-of-turn message no longer includes token budget figures.
Written by our agent from the shipped bundle, not by Anthropic.
In cloud-remote sessions only, claude mcp serve can run over HTTP, dial a session tunnel, read tokens from a descriptor and return tool output objects
ExtensionsA host program can set CLAUDE_CODE_AUTOUPDATER_DISABLED_BY_HOST so plugin auto-updates stay off under the host's version pin
ExtensionsPlugin UI adds a ui.notify operation and Button text from children, and the Grep search now passes a searchOtherAppsData flag
Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG stops your own skills, agents and hooks from widening permissions, and makes key hooks required
Settings & configCLAUDE_CODE_RESTRICT_PERSONAL_CONFIG mode restricts your own Claude Code filesSetting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG starts a session that restricts your own Claude Code files, alongside the other restricted modes
Want the reasoning? Read walks the 43 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →Anything you can use today, anything that visibly changes, and anything worth poking at. One line each, open for detail.
A timer now compacts an idle conversation shortly before its prompt cache runs out, if it is large enough and rate limits allow
What would fix it?
Smaller changes and internals, grouped as the pipeline found them. Nothing is dropped, it is only further down.
19 more of these are in What probably matters to you, above.
Self-hosted runners can now write server-supplied autoMode allow, environment and soft-deny lists into sessions, with allow lists withheld by default
When an environment keeps its own settings, only deny and ask rules from your machine are applied, and the notice now explains what was skipped
Claude's guidance on starting other agents now warns that they cost more than they look and can lose detail or confirm a guess
Unclear Claude Code's standard Agent tool text is recorded as unchanged in this release, so it is not clear which setups receive the rewritten guidance.
When finding autoMemoryDirectory, Claude Code now skips settings sources that fail a new check, so they cannot move the memory folder
Unclear It is not stated which settings sources fail the new check, so it is unclear whether a project-level autoMemoryDirectory is still honored.
When a ClaudeInChromeDomain deny rule covers a site, a claude.ai-proxied connector call that needs approval now fails instead of showing an approval card
Unclear It is not clear whether the new deny-rule check sits behind the same remote switch as the approval retry.
After a rewind, Claude Code keeps track of the host it runs on and cancels pending work when no carried-over prompt is waiting
Unclear What exactly is cancelled after a rewind is not stated.
disableAllHooks is set#With disableAllHooks set, Claude Code can now still run hooks from your own settings under certain conditions
Unclear The internal condition that lets your own hooks keep running is not stated, so it is unclear when this applies to you.
On Amazon Bedrock in a region outside the US and Canada, Claude Code now sends a changed model ID
Unclear It is not stated how the model ID is changed for those regions.
MCP servers reached through claude.ai connectors now agree a protocol version automatically unless the server explicitly turns this off
--tools are now withheld unless a deny rule names them#A tool missing from the session's --tools list and named by no deny rule is now withheld, with a warning
Unclear Which tools were previously still offered despite being left out of --tools is not stated.
For certain MCP servers Claude Code no longer accepts requests to prompt you for input, and cancels any such request it receives
Unclear Which MCP servers are affected is not stated.
Artifact deletions now always go through Claude Code's shared approval step instead of a separate prompt
If a plugin hook on another machine changes a tool call's input, Claude Code now refuses the call instead of running it
Claude Code no longer reconnects to a saved Cloud gateway when your organization's settings name another gateway or none
Oversized updatedPermissions answers from SDK programs are now refused or cut, and a waiting permission ask can resolve on its own
If the plugin hook runner cannot tell where a tool call runs, Claude Code now refuses a hook's rewritten input for that call
Unclear Whether plugin hooks still receive the tool's response in this case is not stated.
Claude in Chrome now matches blocked sites with or without a port, and refuses actions when it cannot tell which site they target
Permission prompts and read checks for artifact tools no longer depend on an earlier condition and now always apply
In headless mode, some sessions now refuse to compile schemas, and content lists over a size cap are rejected as too many items
Unclear It is not clear which sessions refuse to compile schemas.
Sharing, watching or uploading an artifact always uses the approval card, and publish refuses if an earlier edit in the same reply failed
Claude Code now refuses to add a plugin marketplace whose name can't be used in plugin names, and says what to fix
Claude Code now rejects an empty models list on an upstream and says to remove the key to send every model
Unclear Which configuration file or feature this upstream models list belongs to is not stated.
Foreign artifact reads now always need consent, and reading comments always loads and checks the artifact first
The message Claude Code emits at the end of a turn no longer carries the token budget used, the limit or the nudge count
Published verbatim by Anthropic for v2.1.295. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 143 bullets, 35 name something an entry on this page also names, 32 name something no entry here does, and 76 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
onFailure: "block" for command and HTTP hooks: a hook that can't start, times out, or exits with an unexpected code blocks the action instead of letting it through
No entry names this /copy picker, so a drafted message copies without its > markers
Probably copy-picker-now-lists-blockquotes-as-well-as-code-blocks claude plugin install, enable, disable and marketplace add when the settings file they write to does not load
Probably release-notes-bundle-for-21292, marketplace-add-warns-after-success claude -p run is waiting for when it stays open after its last turn
Probably print-mode-text-results-printed-at-each-turn-end timeouts.upstream_ttfb_ms on the Claude apps gateway's Bedrock, Vertex, Foundry and other cloud upstreams: a value you set now limits how long a stream may take to start there, after which it fails over or gets a 502
Probably gateway-upstream-ttfb-timeout-now-only-applies-when-operator, gateway-notes-upstream-ttfb-ms-now-applies-to-non-anthropic ← is waiting for the current tool to finish
No entry names this models list to every Claude apps gateway upstream: only the listed models are sent there, on failover too, and one * in an entry is a wildcard
Nothing to match on forceLoginMethod: "gateway" and forceLoginGatewayUrl in your own user settings on machines with no managed settings, so /login opens on that Claude apps gateway
No entry names this claude plugin validate when a plugin's README has no install line: it prints the line to paste and never changes the exit code, even with --strict
Probably claude-plugin-validate-adds-a-further-check-pass upstream_request_id to the Claude apps gateway's inference audit event: the request ID from Amazon Bedrock, the Anthropic API or another upstream, for support cases
Probably telemetry-additions-api-message-id-text-runs-joined-upstr $.ui.notify for mods: raises a native notification through your own notification setting and says which channel sent it
Probably plugin-uinotify-channel-and-tool-search-aware-description Button: strings and Text, so a row of a list is one pressable with a chip or a dim detail inside
No entry names this CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS to limit how long unattended retry mode (CLAUDE_CODE_RETRY_WATCHDOG) waits out 429 and 529 errors
Probably retry-watchdog-skip-can-be-overridden-by-claude-code-retry-w request-id header to the Claude apps gateway's successful inference responses, so request_id in Claude Code telemetry matches the gateway's audit log
Probably gateway-forwards-upstream-request-id, telemetry-additions-api-message-id-text-runs-joined-upstr [1m] model when a gateway, Bedrock, Vertex or Foundry refuses the context-1m beta; Claude Code now resends without it
No entry names this claude -p text output dropping earlier responses when background work started another turn; each turn's response now prints when the turn ends
Probably print-mode-text-results-printed-at-each-turn-end command_description instead of description
Probably bash-tool-input-command-description-is-accepted-as-descript host:80) to plain http:// pages on that host
No entry names this /plugin's Errors tab removing a marketplace that failed to load, and uninstalling its plugins, on Enter without asking first
Probably plugin-name-read-from-pluginjson-marketplace-clone-gains-p, plugin-errors-view-asks-for-confirmation-before-removing-mar, plugin-addressed-mcp-requestresponse-metadata-gated-behind claude plugin marketplace add reporting success for a marketplace whose name no plugin can be installed under; such an add is now refused
No entry names this CLAUDE_AUTO_BACKGROUND_TASKS moving a subagent to the background while an edit or shell command waited behind it, which started that call before the subagent finished
No entry names this claude remote-control sessions right after a phone message, without the /config toggle, or when started from inside Claude Code
Probably settings-panel-auto-update-channel-and-notification-changes, config-rows-commit-through-a-shared-writer-output-style-an #92661PushNotification reports "Remote Control inactive" (no_transport) in sessions served by `claude remote-control` Open
#99781PushNotification reports "Remote Control inactive" in sessions started with claude rc Closed
/tui exiting without a message, or with a raw system error, when Claude Code could not be started again
No entry names this availableModels not appearing in the /model picker for sessions signed in to a Claude apps gateway; such a model now shows its built-in row in place of a modelPicker row added for the same model
Probably remote-model-now-checks-whether-the-default-save-failed, model-pick-now-goes-through-a-saved-model-row-commit-with-s CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC hiding the Claude apps gateway spend limit in /usage and the status line. The spend limit request goes to the gateway the session is signed in to
Probably spend-limit-and-upsell-hint-text-refactored-into-a-lookup-ta, claude-mcp-serve-gains-an-http-transport-port-and-ses ←; Claude now keeps working in the foreground
Nothing to match on --tools and --restricted not applying to built-in tools that register after launch, and deprecated tool names reaching tools outside the caller's tool set
Probably sdk-spawns-cli-with-flagvalue-form-and-guards-values-st, tools-launch-list-now-withholds-unlisted-tools, new-claude-code-restrict-personal-config-env-var-recognized /loop that was moved to the background with ←; cancelling a pending wakeup now shows a notice
Probably resume-restores-a-pending-loop-wakeup-or-reports-it-as-mis FORCE_COLOR=3, which put color escape codes into the output Claude reads
No entry names this claude agents starting a new background service as it exited when both were stopped with a session open (for example at a reboot), which could delay shutdown and restart an interrupted session
Probably background-attach-prints-exit-notice-about-sessions-stopping #99369Agent view restarts the background daemon during system shutdown; the new daemon holds the shutdown for 90 s Open
worker being shown as "Agent" in auto-mode denial notices and in the activity lists of task detail views
No entry names this TaskStop, which can never be the cause
No entry names this /loop stopping without notice when its next wakeup came due while the session's process was down; the session now says so and Claude is told
Probably resume-restores-a-pending-loop-wakeup-or-reports-it-as-mis /advisor dialog showing a checkmark on a saved advisor model that is no longer available; it now opens on "No advisor"
No entry names this ~ moving the cursor past the last character of a line, so x after it did nothing, and 3~ running on into the next line
Nothing to match on .catch; such calls are now refused
Nothing to match on claude plugin test passing a session.append hook that removes tool call, tool result or thinking blocks that a real session keeps
No entry names this cat ran without printing it
Nothing to match on constructor or prototype always reading as their default and never reloading the plugin when edited
Nothing to match on /reload-plugins or session start was reading the mod's files
No entry names this /model, /fast and /output-style saving their setting without asking a plugin's config.set hook
Probably fast-mode-toggle-wrapped-for-remote-sessions-with-pre-switch, remote-model-now-checks-whether-the-default-save-failed, model-pick-now-goes-through-a-saved-model-row-commit-with-s claude mcp serve background Bash results not naming the output file, and its tool description promising a notification that never arrives
Probably mcp-tool-server-registers-extra-capabilities-when-serving-in, claude-mcp-serve-gains-an-http-transport-port-and-ses, mcp-serve-session-tunnel-and-tool-output-protocol #99934[BUG] `claude mcp serve`: Bash run_in_background output is unreachable since TaskOutput was removed (2.1.277) Open
CLAUDE_ENV_FILE not reaching the Bash tool after an in-app /resume or /branch
Probably restart-failure-messages #98933[BUG] CLAUDE_ENV_FILE env lost after in-app /resume — hook writes to startup session dir, Bash reads resumed dir (still on 2.1.287; #40391, #24775 auto-closed) Open
allowed-tools and effort being dropped when the Skill tool finished before the response stream ended, which denied the skill's Bash commands in -p runs
Probably new-claude-code-restrict-personal-config-mode-limits-what-a #99353[BUG] Skill allowed-tools rule is dropped when the Skill tool finishes before the response stream ends (2.1.289) Open
--plugin-dir plugin's folder in -p and SDK sessions; they are now written only where a mod is being developed
No entry names this /model saying a Max effort pick was saved as your default for new sessions; Max applies to the current session only
Probably remote-model-now-checks-whether-the-default-save-failed, model-pick-now-goes-through-a-saved-model-row-commit-with-s #99350[BUG] Clarify /model confirmation wording: max effort applies only to the current session Closed
pages parameter instead of treating it as omitted
Nothing to match on #98651[BUG] Read: `pages: ""` on a non-PDF file fails validation, and PreToolUse hooks can't work around it (still on 2.1.286) Closed
plugin install and uninstall at project or local scope on Windows missing the install record, or adding a second one, when only the drive letter's case differs
Probably release-notes-bundle-for-21292, plugin-install-lookup-refactored-into-a-shared-helper, plugin-install-records-matched-across-path-spellings-on-wind #92121Project-scope plugin installs are auto-created, never updated, and unreachable via --scope project (Windows drive-case duplicates) Open
↑ or Esc just after ←: prompt history now keeps it
Probably gateway-login-developer-sourced-url-and-esc-wording prompt.submit hook rewrote or dropped still being saved as typed to prompt history and to the transcript's queued-prompt records
No entry names this claude_code.auth OpenTelemetry login event not being emitted on Claude apps gateway sign-in. The event is exported when OpenTelemetry is configured on the machine or the session is already signed in to the gateway
No entry names this ~/.claude/seed-admin by an interrupted /ultrareview upload never being removed by the retention cleanup
No entry names this disableAutoMode was removed from settings
No entry names this /rewind being lost, and the removed turns coming back, when the session was moved to the background or resumed after being killed
Probably spend-limit-and-upsell-hint-text-refactored-into-a-lookup-ta session.receive hook asked for permission before passing a message on
No entry names this setMcpServers() as your own
No entry names this /config saving before a plugin's config.set hook was asked
Probably settings-panel-auto-update-channel-and-notification-changes, config-rows-commit-through-a-shared-writer-output-style-an /context and large file reads use: the gateway now gets them from AWS's CountTokens API instead of a one-token model request. Grant bedrock:CountTokens to use it
Probably bedrock-count-tokens-now-uses-aws-counttokens-with-backoff mcp__server__tool identifier
Probably auto-mode-resolves-toolaliases-for-mcp-tools-behind-tengu-so models: in Amazon Bedrock regions outside AWS's US geography. AWS always refused those requests; the gateway now tries the model in your own region, and a refusal names the model to add
Nothing to match on rate_limit_event usage-limit warnings to say whether the account has extra usage turned on
No entry names this plugin-authoring skill: it no longer tells a session with no terminal to run terminal commands, and explains sharing a mod only when asked
No entry names this -l, -c or -r flag now runs instead of failing the call
Nothing to match on claude plugin validate and plugin loading: when a hooks module is refused over a rebound top-level var, the error now names the line that rebinds it, the cause, and a fix
Probably claude-plugin-validate-adds-a-further-check-pass scriptPath refusal: it now says to pass the script inline via script, the route that works in sessions without a Read tool
No entry names this skills field, each once; a subagent with the Skill tool can still invoke the rest
Nothing to match on /loop wakeup alone, so pressing it twice detaches and the loop keeps running; press Esc to stop it
Probably resume-restores-a-pending-loop-wakeup-or-reports-it-as-mis claude agents stopped with its background service (macOS, or Linux without the service installed): running sessions now stop in about a minute unless it is run again, and a notice says so
Probably background-attach-prints-exit-notice-about-sessions-stopping MCP_PROTOCOL_NEGOTIATION=legacy opts out
No entry names this desktop policy key its bundled Claude Desktop schema doesn't know, so new Desktop settings need no gateway upgrade
Nothing to match on ws) MCP servers: a message over 16 MiB is no longer parsed and closes the connection, the limit the other transports already have
Nothing to match on CCR_AUTO_MODE_ALLOW, CCR_AUTO_MODE_ENVIRONMENT and CCR_AUTO_MODE_SOFT_DENY into a session's environment
Probably runner-spawns-child-with-ccr-auto-mode-env-vars-cleared CLAUDE_RUNNER_FETCH_SERVER_PROGRESS_CAP_MS tunes or turns off the wait
Probably git-fetch-gets-a-server-progress-stall-cap-env-var @Claude !restart had already confirmed the restart
No entry names this agent hook evaluations taking much longer at xhigh and max effort
Nothing to match on A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
1 added and 1 removed, of 218 lines, about 22 words, in the prompt 14 of 27 arms receive. 4 other prompts also changed. The appended system-reminder blocks moved: 1 line added, 1 line removed.
Claude Code, interactive mode
13 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
568 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 78 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?