Hover highlights clear when the terminal window loses focus#
Claude Code now clears hover highlights when you switch away from its window, instead of leaving them on screen
MCP tools that take file inputs can now accept local file paths. Claude Code uploads the file and passes the tool a reference instead. The Read tool's new allow_large option lets Claude read an oversized text file when there is room left in the conversation. Hook commands now take an on_failure setting of continue or block. You can set CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL to choose the model subagents use during a workflow run. Administrators can switch off messaging beyond a user's own agents with the managed setting messagingBeyondOwnAgentsDisabled.
This build holds 11 features that are not switched on yet. Claude can ask a subagent for lower or higher effort than its own, but the option is off by default. A session moved to the cloud from auto mode is being prepared to stay in auto mode. Remote sessions gain a check that probes a stream after about 8 seconds of quiet. That check is controlled remotely and is not on yet. A new restriction could limit an agent to messaging only its own agents.
Messages you typed ahead are no longer lost when a turn is cancelled. They go back into the input box or to the front of the queue. A PreToolUse hook that blocks a tool now shows its full reason in the error. Workspace diffs now follow renamed files and show deleted files as removed. On Windows, MCP servers now get a chance to shut down cleanly before being force-closed. Resumed sessions no longer restore saved MCP tasks from the 2025-11-25 tasks protocol.
Written by our agent from the shipped bundle, not by Anthropic.
allowedProviders can now set ANTHROPIC_BASE_URL automaticallySettings & configCLAUDE_CODE_AGENT_PROGRESS_SUMMARIES, CLAUDE_CODE_SLEEP_COMPACT_AFTER_MS and CLAUDE_CODE_RESUME_SESSIONSTART_HOOKS_WAIT_MS are new and are read by Claude Code
SDK set_model requests can swap the system prompt only if a named model is running, failing with model_not_current otherwise; Remote Control refuses it
Sessions & agentsA managed setting, messagingBeyondOwnAgentsDisabled, now turns this feature off and overrides CLAUDE_CODE_HARBOR_KITE
Gateway policies can use a code block for Claude Desktop's Code tab, cannot mix it with cli or settings, and get clearer warnings about serve_to_desktop
Platform & internalsModel catalog entries can set min_claude_code_version, and older clients see the model as unavailable with a message naming the version to update to
Extensions.mcp.json files can now be skipped when loading MCP serversExtensionsWant the reasoning? Read walks the 38 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →Claude Code now clears hover highlights when you switch away from its window, instead of leaving them on screen
When trimming a final line break, Claude Code now removes a whole Windows-style line ending instead of leaving a stray character
When ending a stopped turn for a connected client fails, the log now records the error that actually happened
When a plugin path cannot be found, Claude Code now checks the right error, so the missing-path skip and its /mnt/ retry apply
Unclear It is not settled whether this changes behaviour at all or only how the program was built.
5 more of these are in What probably matters to you, on page 1.
Remote sessions can send still-here pings and probe a stream that has gone quiet for about 8 seconds, behind tengu_violin_pernambuco
The text Claude gets after a conversation is compacted can now include extra guidance on resuming, depending on an experiment
Creating a session with --remote can now pass a built-in tool restriction, though in this version no restriction is ever sent
Claude Code's remote session code now defines a server-controlled switch named for turning off inherited approvals
Unclear What this switch controls, and whether it affects any session, is not known.
5 more of these are in What probably matters to you, on page 1.
Managed settings entries can now set underCode, which builds the desktop session's settings from the CLI settings without needing serve_to_desktop
short_v2 mode for conversation summaries#The list of summary modes gains short_v2, which keeps the record of what you asked for and rewrites only the account of the work
Worker registration can now return worker_capabilities, and managed cloud workers declare that they do not hydrate carried lines
Unclear What carried-over lines are and what a cloud worker session loses by not restoring them is not stated.
Claude Code can now skip compacting a session transcript when little space would be reclaimed, through a store flag that starts out on
New managed-settings plumbing can detect a gateway serving /managed/settings and verify signed documents saying no settings exist, with an expiry
Unclear Nothing was seen using this check, so whether it runs at all in this version is not known.
Claude Code can request an MCP server's tool list while still connecting and reuse that first page, for servers chosen by tengu_tender_truffle
A model with a 1M-token context window and 128000 output tokens now uses a pricing tier that sets a separate cache-read rate
Unclear Which model this pricing change applies to is not named.
When a check passes, one specific tool is now sent to the API with citations switched on
Unclear Neither which tool this applies to nor the condition that switches it on is known.
A new built-in message asks the model to continue briefly when a reply reached the output limit with no visible output
In VS Code, two server-controlled settings are now refreshed only when the product feedback setting changes
This build is 2.1.296, has an updated model list, and now passes PowerShell commands to its checker through standard input
citations joins strict, eager_input_streaming and defer_loading as an optional tool field that is removed before sending when unsupported
When a skill brings hooks or grants tools, Claude Code now bundles them into one scope instead of registering hooks directly for the session
Unclear It is not clear what the new step does with the skill's hooks and tool grants, so the practical effect on skill permissions is unknown.
Records of whether another agent is present can now include when it last said it was still there
Certain queued poll events can now be folded into the start of Claude's next turn instead of being treated like a typed prompt
Unclear It is not clear what folding an event into the start of a turn does to what Claude sees.
Usage events recorded while Claude Code's event logger is starting, being replaced or shutting down are now queued and sent instead of lost
Under some condition, Claude Code now asks the server not to compress a response and stops unpacking it itself
Unclear When this condition applies is not known.
The PowerShell tool has a new InputMismatch error, alongside its timeout, empty output and invalid JSON errors
In headless sessions, Claude Code now records when the host program's system prompt replaces its saved prompt, and whether that step failed
The record Claude Code keeps when it picks up remote tool calls after a restart now also counts calls that were served but never sent
Claude Code's check for approved project settings now notes whether approval came from settings, bypass or a non-interactive run
The conditions for running without policy limits when none can be fetched are unchanged, and only internal names moved
Claude Code adds diagnostic categories for unreadable transcript lines, cloud built-in tools and MCP task registration
Permission records for MCP tools now carry a reason code when the server's highest allowed permission is ask
Usage records for rejected tool uses now say whether the automatic permission classifier was active
The signed-cache check no longer sends a separate identity report and its usage data gains two new fields
A usage report for denials now includes session_archived when the session had been archived
A new usage measurement counts queued prompts by kind at the moment a turn is interrupted
Metrics counting lines added and removed now label the model with a normalised name instead of the raw value
Unclear It is not clear how the model name is normalised, so the new label values are unknown.
Resume timing data now includes how long Claude Code spends scanning the saved conversation
An error value in usage data is dropped unless it is a short code of lowercase letters, digits and underscores
Once per session, Claude Code reports how many project .mcp.json servers were approved by settings, by bypass or without asking
Claude Code's diagnostics now take the unresponsive-host interval from a different source and time how long resuming waits on SessionStart hooks
When a session resumes, Claude Code's diagnostics now record how much of the saved conversation was scanned and kept
The usage details Claude Code records when an agent starts are now built in one place: type, built-in, skill fork and how it was launched
Claude Code no longer includes the cost of shell command calls in one of its lists of diagnostic fields
Claude Code's startup timing no longer overwrites the hooks setup time after it has stopped waiting for hooks to be ready
Claude Code gains a check for which kind of remote environment it is in, plus addresses for an artifacts service
Unclear Nothing shows these addresses or the environment check being used by any feature yet.
Remote sessions now report that they are waiting on the user through a new step that tracks uploading of turn prompts
The part of Claude Code that writes a session's transcript no longer sets up a separate session log when it starts
Unclear It is not clear what the session log recorded, so whether any log you can see stops being written is unknown.
When a session is handed off during a transcript copy, each wait now has its own time limit and a lagging copy is recorded
Claude Code can now limit how much of a session's internal event record it reads, and stops at oversized or encoded pages
Claude Code can now stop waiting on unfinished work when a session is shutting down
Claude Code now picks a session's project folder from the working copy root, then the git root, then the project root, through one shared step
When copying a session transcript, Claude Code now starts catching up on recent events before waiting, using a read made for catch-up
Claude Code now sets the Chrome classifier floor option when it starts, as part of the rules that decide which actions are allowed
Unclear What decides the value of chromeClassifierFloorEnabled at startup, and whether it is on by default, is not known.
When Claude Code sets up its connection to the API, it now fetches extra headers and adds them to every kind of connection it makes
Unclear Which headers the new source actually adds is not stated.
Requests Claude Code builds for Amazon Bedrock now also pass along the model you configured
Unclear What passing the configured model to Bedrock changes, and what the new switch controls, is not stated.
An internal version list gains two new entries, named for reading large files and editing the original file
Claude Code now uses a line-by-line scan to remove claude-code-hint lines, and it handles Unicode line breaks and extra spaces
Claude Code now records when each regular check-in signal fires and stops clearing a cache early once it is small enough
Two low-confidence secret-scanner rules now load prebuilt search patterns instead of building them in place
Unclear It is not clear whether the patterns themselves changed, so whether these rules now flag different text is unknown.
A cloud worker that rebuilt the conversation from the saved transcript can now say it accepts a turn handoff request sent again
builtinTools option now carries through to the session#A builtinTools option is now passed on to the session along with the allowed and disallowed tool lists
Unclear It is not clear whether builtinTools is an option you can set yourself, or where it is set.
A loop that sends hints for starting new agents now waits, up to a set window, for its hooks to finish before polling again
Unclear The length of the window and whether this loop can run at all are not known.
The error shown when a flag tries to change an existing cloud session's tool deny list is now built in one shared place
When Claude Code runs some tool calls, it now tells the tool the session's version and whether a subagent made the call
Unclear Whether any tool actually behaves differently for subagents or by session version yet is not shown.
Once an agent's event read reports it is over its size bound, Claude Code stops reading that agent's events
Claude's guidance on briefing subagents now calls a good brief its first lever on cost, rather than its one lever
Claude's instructions for handing work to a subagent now call the brief its "first" lever on cost instead of its "one" lever
Claude Code now lists project and plugin MCP servers separately and gains an internal way to close a project's MCP servers
When an MCP server needs configuration, Claude Code now finds the required values through a lookup step instead of reading them directly
Unclear Whether this stops values with dots in their names being wrongly reported as missing is not stated.
MCP connection diagnostics now note the time an MCP server successfully answered the start-up notification
Agents that plugins register while Claude Code is running now record the folder of the plugin that registered them
Claude Code changed how it looks up plugin options and which saved plugin secrets it keeps when it tidies them up
Unclear It is not clear whether this changes which saved plugin secrets are removed or whether the two changes cancel each other out.
Plugin updates and marketplace handling now find a marketplace's entry through a lookup step instead of reading it by its exact name
Unclear Whether marketplace names now match regardless of letter case, or through other names, is not established.
Claude Code now refreshes the task list display when only a task's ambient status changes
Claude Code records three more pieces of information: a shared marker, an ambient flag on task notices, and a resume scan record
Unclear It is not clear whether any of these fields changes anything a user sees.
Updating the extra details on a task now uses a shared routine instead of code written in place
Unclear Whether setting a task detail to null still removes it is not confirmed.
Workflow script text read from a file now passes through a processing step before Claude Code uses it
Workflow scripts from plugins and folders now pass through an extra preparation step before their header information is checked
Unclear What the new preparation step does, and so whether any script now loads or is skipped differently, is not known.
Workflow script files are now read up to the number of bytes actually read, and their text passes through a processing step before use
Unclear It is not clear what the new processing step does to a workflow script's text.
When two user messages sit next to each other, Claude Code now combines them in a new way that can change where tool results appear
The internal log of API requests now fingerprints each message once and records caching marks only on messages that have them
The remotely switched instruction text used for shell commands now records which tool it is for, so the same text could serve other tools
BASH_ARGV0 joins Claude Code's list of special bash variables, alongside BASH_ARGC and BASH_LINENO
Unclear What this list of variables controls, such as how commands are checked before they run, is not stated.
The prompts Claude Code uses to summarize a long conversation now include short and short_v2 versions, and short_v2 adds advice on finishing work
When Claude Code checks a conversation handoff, it can now reject messages that were appended to it and give a reason
When Claude Code re-reads a file before writing to it, it now also notes whether the file's text could be read without loss
Unclear What Claude Code does when a file could not be read cleanly is not stated.
When Claude Code safely replaces a file, it now changes the owner and permissions in a safer order and reports failures clearly
When Claude Code cannot find a commit ID, it now produces fallback commit details instead of returning nothing
When Claude Code combines per-file change counts, tracked files now lose their old and new path details
Unclear It is not clear whether this changes anything you can see.
Claude Code now stores each hooks module's arguments while it is loaded and discards them when it unloads
On Linux and WSL, Claude Code names the thread that runs hooks and reads its CPU time and sleep state from the system
When auto-dream memory consolidation finishes, the usage report it sends no longer includes how many daily logs it found
The code that reads memory document sections has been rewritten to search the text less often
Malformed updatedPermissions replies from a bridge client are now handled by a shared routine labelled as refusing them
Unclear Whether malformed permission updates from a bridge client are still simply ignored or are now refused in a way the app sees is not stated.
! has been reorganised#Claude Code reorganised how it reads permission rules whose content starts with !, with no behaviour change shown
Unclear Whether this changes how any permission rule is matched is not known.
A coverage check on directories gains a list of folders that are scanned one level deep only
Unclear It is not clear when this shallow list is filled in or what it changes for a reader's sessions.
The check that reports whether Claude Code runs inside a bubblewrap sandbox or a Docker container has changed
On resume, saved MCP tasks that used the 2025-11-25 tasks protocol are dropped, not restored, and are not cancelled on the server
One route for MCP tool calls now always makes a plain call instead of asking the server to run it in the background
Unclear Whether MCP servers still receive background-task tool calls through the remaining mechanism, and under what conditions, is not settled.
Published verbatim by Anthropic for v2.1.296. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 79 bullets, 15 name something an entry on this page also names, 27 name something no entry here does, and 37 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
code key to the Claude apps gateway's managed.policies[]: the same settings as cli, also applied in Claude Desktop's Code tab; beside desktop, it turns on Claude Desktop's gateway mode
No entry names this autoCompactWindow to subagent frontmatter and --agents definitions, so a subagent can auto-compact earlier than the main conversation's window
Probably agent-definitions-can-carry-an-autocompactwindow-passed-to, agent-auto-compact-threshold-now-takes-a-second-window-sourc, plugin-agent-frontmatter-gains-autocompactwindow-passed-thr CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL to run every workflow agent on one model while other subagents keep theirs
Probably new-env-var-claude-code-workflow-subagent-model-overrides-th CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MS environment variable to set a longer maximum delay for the backoff when retrying an overloaded (529) request
No entry names this /plugin on a plugin whose hooks are left out because another enabled plugin has the same name
No entry names this allow_large option to the Read tool so Claude can read a text file past the usual size limits in one call when it needs the whole file and the context has room
Probably read-tool-allow-large-override-messages-added, read-tool-gains-allow-large-option-sized-to-remaining-contex PreToolUse hooks that deny a tool call with "continue": false, and managed prompt hooks that block one, refusing the call but not ending the turn
Probably pretooluse-hook-stop-reason-is-appended-correctly, pretooluse-hook-stop-attachment-helper-and-422-to-400-error updatedMCPToolOutput in some sessions
Probably posttooluse-hooks-can-rewrite-mcp-tool-output-via-updatedmcp .mcp.json or plugin MCP server that was switched off for that folder, after changing directory or reloading plugins
Probably telemetry-for-auto-approved-project-mcp-servers, project-mcp-config-skipped-when-a-flag-checked-helper-is-on allowedProviders with "gateway" locking out laptops that name that gateway in user settings
Probably managed-settings-env-now-injects-a-computed-anthropic-base-u forceLoginMethod to gateway with no forceLoginGatewayUrl (regression in 2.1.295)
Probably gateway-login-method-now-counts-as-gateway-required --teleport opening an empty conversation when the session's history could not be read
No entry names this #95873[BUG] Regression since ~2026-09-12: Remote Control sessions have 0 teleport-events, so opening them from another machine (VS Code Remote tab / --teleport) yields an empty session (worked 2026-08-26 → 09-11) Open
52;c;… escape sequence printed on screen after copying in older VTE-based terminals such as MATE Terminal
No entry names this /diff panel or dialog was open
No entry names this #99026[BUG] Built-in /diff pane holds mod toasts, undocumented and contradicted by the screen map Open
UserPromptSubmit hook or a mod's prompt.submit hook ending headless sessions, clearing the typed prompt, or letting the unchecked prompt through
Probably prompt-submit-hook-interrupted-while-checking, input-hooks-interrupted-by-abort-now-return-interrupted-resu, prompt-submit-hook-handling-blocked-prompt-tracking-and-abo, interrupted-while-prompt-checked-handling, userpromptsubmit-hook-cancellation-distinguishes-interrupts claude self-hosted-runner printing misleading errors when registration is refused: it now names the org admin setting, or says a restarted on-demand runner needs a fresh work order
No entry names this --capacity above 1
No entry names this $ methods running in the main session's working directory instead of the calling agent's, and ignoring the turn their calling hook holds
Nothing to match on $.agent.register succeeding from a mod's hook that was still running after the mod was reloaded or removed; the call is now refused
No entry names this $.http.fetch in mods refusing a HEAD request when the response declares a Content-Length over the 4 MiB body limit
Probably custom-headers-check-function-replaced-and-git-subprocess-e, api-client-adds-per-request-extra-headers-and-awaits-a-heade, git-commit-detection-from-reflog, web-fetch-head-requests-skip-the-content-length-size-refusa, new-x-claude-code-wiggly-dove-request-header-off-by-default claude plugin marketplace add, marketplace update and plugin install failing with an internal error for a marketplace named like constructor; add now refuses such names clearly
Probably plugin-install-gets-replace-for-same-repo-duplicates-mcp constructor or prototype being deleted by the next save of that plugin's options
Nothing to match on CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a finished turn after a restart when an MCP tool result had ended that turn
No entry names this BASH_ARGV0 shell variable and then use it; these now prompt for approval
Probably bash-variable-list-adds-bash-argv0 ← being run twice, once unseen in the foreground, when the background service was slow to answer
Nothing to match on ← moved the session to the background; it is still not sent, but ↑ now brings it back
Nothing to match on /clear in headless sessions
No entry names this /mcp or claude mcp when an MCP server needs authentication
Probably auth-needed-prompt-for-remote-sessions-without-oauth, remote-environment-classifier-and-ccr-artifacts-endpoints /code-review ending on a raw JSON array in cloud sessions, the Agent SDK and IDE integrations; the findings now print as a numbered list
No entry names this tool_result events missing git_commit_id after git commit -q or git -C <dir> commit
No entry names this #95934OTel: git_commit_id still silently dropped for `git -C <path> commit` and quiet/redirected commits (2.1.278) — recurrence of #77237 Open
CLAUDE_CODE_TRANSCRIPT_LOCAL_GC dropping a message from the saved transcript when its text held a Unicode line or paragraph separator (U+2028, U+2029)
No entry names this claude purge leaving a prompt in the history file when its text held a Unicode line or paragraph separator (U+2028, U+2029)
No entry names this claude plugin install failing for GitHub owner/repo plugin sources on machines with no GitHub SSH key; the clone is now retried over HTTPS
No entry names this rm -rf /c/Users/<name> in Git Bash not asking in bypass permissions mode
No entry names this code settings, the reason shows as a reply
Nothing to match on --debug output to name unrecognized frontmatter fields in custom agent files, with a hint for likely typos
No entry names this --debug output for hooks: command hooks on tool calls, prompts, SessionStart and Stop now log their command, plugin, outcome and duration when they finish, so a slow hook is identifiable
No entry names this CLAUDE_CODE_TRANSCRIPT_LOCAL_GC: a large transcript file is no longer rewritten when that would free under 10% of it
No entry names this /cost, the status line, --max-budget-usd and the SDK's cost figures to price Sonnet 5.5 cache reads at $0.10 per million tokens (was $0.20)
No entry names this ←: a turn or ! command started while the session moves to the background is now stopped instead of finishing out of sight
Nothing to match on claudeCode.spinnerVerbs missing from the extension's settings, so settings.json now completes and validates it; a malformed value no longer breaks the chat panel
No entry names this @browser, as the terminal does; allowing a site for the session stops repeat asks
No entry names this prefersReducedMotion setting
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
910 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 43 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?