# Claude Code v2.1.296

> Claude Code v2.1.296, released 9 Oct 2026 (2026-10-09). 304 entries read out of the shipped bundle. Unofficial, and not affiliated with Anthropic.

[Web version](https://changelogs.core-directive.com/v/2.1.296)

MCP tools that take file inputs can now accept local file paths. Claude Code uploads the file and passes the tool a reference instead. The Read tool's new `allow_large` option lets Claude read an oversized text file when there is room left in the conversation. Hook commands now take an `on_failure` setting of continue or block. You can set `CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL` to choose the model subagents use during a workflow run. Administrators can switch off messaging beyond a user's own agents with the managed setting `messagingBeyondOwnAgentsDisabled`.

This build holds 11 features that are not switched on yet. Claude can ask a subagent for lower or higher effort than its own, but the option is off by default. A session moved to the cloud from auto mode is being prepared to stay in auto mode. Remote sessions gain a check that probes a stream after about 8 seconds of quiet. That check is controlled remotely and is not on yet. A new restriction could limit an agent to messaging only its own agents.

Messages you typed ahead are no longer lost when a turn is cancelled. They go back into the input box or to the front of the queue. A `PreToolUse` hook that blocks a tool now shows its full reason in the error. Workspace diffs now follow renamed files and show deleted files as removed. On Windows, MCP servers now get a chance to shut down cleanly before being force-closed. Resumed sessions no longer restore saved MCP tasks from the 2025-11-25 tasks protocol.

## Sections

Each section is its own markdown document of whole entries, in pages of about 40 KB. The whole release in one document is [full.md](https://changelogs.core-directive.com/v/2.1.296/full.md).

- [What probably matters to you](https://changelogs.core-directive.com/v/2.1.296/what-probably-matters-to-you.md): 38 entries, 2 pages
- [Improvements](https://changelogs.core-directive.com/v/2.1.296/improvements.md): 133 entries, 4 pages
- [Bug Fixes](https://changelogs.core-directive.com/v/2.1.296/bug-fixes.md): 33 entries
- [In Development](https://changelogs.core-directive.com/v/2.1.296/in-development.md): 4 entries
- [Internal Changes](https://changelogs.core-directive.com/v/2.1.296/internal-changes.md): 90 entries, 2 pages
- [Removed](https://changelogs.core-directive.com/v/2.1.296/removed.md): 6 entries

## What probably matters to you

The first 10 of 38, one line each. The section's own pages have every one in full.

- [Subagents can be given a relative effort of lower or higher](https://changelogs.core-directive.com/v/2.1.296/e/relative-subagent-effort-lowerhigher-built-but-gated.json): The Agent tool can take effort "lower" or "higher" to step a subagent's reasoning effort one level, behind a helper check and tengu_snappy_pelican
- [Three new environment variables for progress summaries, sleep-compact timing and the resume hook wait](https://changelogs.core-directive.com/v/2.1.296/e/three-new-claude-code-env-vars-registered-and-read-agent.json): `CLAUDE_CODE_AGENT_PROGRESS_SUMMARIES`, `CLAUDE_CODE_SLEEP_COMPACT_AFTER_MS` and `CLAUDE_CODE_RESUME_SESSIONSTART_HOOKS_WAIT_MS` are new and are read by Claude Code
- [set_model gains an only_if_model_is_current guard for swapping the system prompt](https://changelogs.core-directive.com/v/2.1.296/e/set-model-gains-only-if-model-is-current-guard.json): SDK set_model requests can swap the system prompt only if a named model is running, failing with model_not_current otherwise; Remote Control refuses it
- [New controls over moving agents to the background and over agent messaging](https://changelogs.core-directive.com/v/2.1.296/e/policy-getters-for-agent-messaging-and-foreground-to-backgro.json): A `backgroundLaunchRule` can now veto moving a foreground agent to the background, and new policy getters cover agent moves and cross-agent messaging
- [Administrators can now switch off messaging beyond a user's own agents](https://changelogs.core-directive.com/v/2.1.296/e/harbor-kite-messaging-is-now-disabled-by-a-managed-policy-sw.json): A managed setting, `messagingBeyondOwnAgentsDisabled`, now turns this feature off and overrides `CLAUDE_CODE_HARBOR_KITE`
- [MCP tools can receive files uploaded from your computer](https://changelogs.core-directive.com/v/2.1.296/e/mcp-tools-can-upload-local-files-via-file-input-arguments-t.json): MCP tools that declare file inputs can now take local file paths, which Claude Code uploads and replaces with references
- [Gateway policy files gain a code block for Claude Desktop's Code tab](https://changelogs.core-directive.com/v/2.1.296/e/gateway-policy-files-new-code-block-and-clisettings-conf.json): Gateway policies can use a code block for Claude Desktop's Code tab, cannot mix it with cli or settings, and get clearer warnings about serve_to_desktop
- [Models can now require a minimum Claude Code version](https://changelogs.core-directive.com/v/2.1.296/e/plugin-schema-gains-min-claude-code-version.json): Model catalog entries can set min_claude_code_version, and older clients see the model as unavailable with a message naming the version to update to
- [A resumed session can honour an answer given to a permission prompt before the restart](https://changelogs.core-directive.com/v/2.1.296/e/remote-control-sdk-listturnprompts-and-inheritedansweroff.json): When a resumed session adopts a parked permission prompt, it can now use a saved matching answer instead of asking again, with `inheritedAnswerOff` to disable it
- [Forked skill and slash command results can pass through a formatter; async agent failures carry a cause](https://changelogs.core-directive.com/v/2.1.296/e/skills-accept-formatforegroundforkresult.json): Skills can supply a formatForegroundForkResult hook to reshape foreground forked results, and failed background agents now record a cause
