The /login hint to enroll this computer now depends on one check#
The hint to run /login to enroll this computer now shows whenever Claude Code decides this computer would enroll, replacing three checks
MCP tools that take file inputs can now accept local file paths. Claude Code uploads the file and passes the tool a reference instead. The Read tool's new allow_large option lets Claude read an oversized text file when there is room left in the conversation. Hook commands now take an on_failure setting of continue or block. You can set CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL to choose the model subagents use during a workflow run. Administrators can switch off messaging beyond a user's own agents with the managed setting messagingBeyondOwnAgentsDisabled.
This build holds 11 features that are not switched on yet. Claude can ask a subagent for lower or higher effort than its own, but the option is off by default. A session moved to the cloud from auto mode is being prepared to stay in auto mode. Remote sessions gain a check that probes a stream after about 8 seconds of quiet. That check is controlled remotely and is not on yet. A new restriction could limit an agent to messaging only its own agents.
Messages you typed ahead are no longer lost when a turn is cancelled. They go back into the input box or to the front of the queue. A PreToolUse hook that blocks a tool now shows its full reason in the error. Workspace diffs now follow renamed files and show deleted files as removed. On Windows, MCP servers now get a chance to shut down cleanly before being force-closed. Resumed sessions no longer restore saved MCP tasks from the 2025-11-25 tasks protocol.
Written by our agent from the shipped bundle, not by Anthropic.
allowedProviders can now set ANTHROPIC_BASE_URL automaticallySettings & configCLAUDE_CODE_AGENT_PROGRESS_SUMMARIES, CLAUDE_CODE_SLEEP_COMPACT_AFTER_MS and CLAUDE_CODE_RESUME_SESSIONSTART_HOOKS_WAIT_MS are new and are read by Claude Code
SDK set_model requests can swap the system prompt only if a named model is running, failing with model_not_current otherwise; Remote Control refuses it
Sessions & agentsA managed setting, messagingBeyondOwnAgentsDisabled, now turns this feature off and overrides CLAUDE_CODE_HARBOR_KITE
Gateway policies can use a code block for Claude Desktop's Code tab, cannot mix it with cli or settings, and get clearer warnings about serve_to_desktop
Platform & internalsModel catalog entries can set min_claude_code_version, and older clients see the model as unavailable with a message naming the version to update to
Extensions.mcp.json files can now be skipped when loading MCP serversExtensionsWant the reasoning? Read walks the 38 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →12 more of these are in What probably matters to you, on page 1.
The hint to run /login to enroll this computer now shows whenever Claude Code decides this computer would enroll, replacing three checks
Tool results can now be marked as blocked by a denial check, and a new "model not current" denial reason was added
Unclear What the new model_not_current reason is used for is not known.
In the fullscreen view, Claude Code now tracks which link is hovered and recalculates it on every redraw
Unclear How a link becomes hovered, and what the hovered state or the windowed table option changes on screen, is not stated.
When loading a saved conversation, Claude Code now counts and logs lines it could not read instead of skipping them silently
Claude Code now refuses a workflow script that contains control characters an approval prompt cannot display, such as escape bytes
Resuming an agent now checks its transcript and fails with a specific message for each problem instead of a generic error
Unclear It is not clear which sessions count as diskless for the saved-settings check.
Claude Code now limits how many JSON keys and how much nesting it reads from a background hook's output
Unclear It is not clear when this limit applies, since an unidentified check decides whether the old unlimited reading is used instead.
Claude Code now sends PowerShell commands to its parser as plain input and checks the parser saw exactly the command it was sent
When auto mode's check gives no usable answer, the skipped action now shows a dim "Not run" line saying so instead of a generic error
A message sent with send-now can now cut into a running turn, but only when that turn is ending and a remote switch allows it
Unclear It is not stated what the remote setting falls back to when the server sends no value, so whether the new case applies without a server change is unknown.
The notice for files too large to read now suggests reading in portions, or reading the whole file if it still fits
Prompt hooks now use their own configured model or the default small model, without a gateway special case
Unclear It is not settled whether gateway setups without ANTHROPIC_DEFAULT_HAIKU_MODEL or ANTHROPIC_SMALL_FAST_MODEL still get the main model for prompt hooks by another route.
When skills sync is turned off, hooks from synced skills are now removed and Claude Code records that this happened
When user settings are skipped or hooks are turned off elsewhere, Claude Code now gives the reason instead of saying nothing
Claude Code now checks each prompt an MCP server lists on its own, dropping invalid ones and logging how many were dropped
In remote sessions, Claude now explains that claude.ai connectors are authorised in connector settings and other servers can't be signed into there
Claude Code now cuts off output from programs it runs when it passes a size limit and marks it as cut off
Claude Code's check for whether a command made a git commit reads git's own record of recent changes to find the commit and branch
For large edits, Claude Code can now leave out the original file's contents from what it stores about the edit
Unclear When this applies is not stated, since what switches it on was not identified.
When a file is too large to read, Claude Code can now tell Claude to retry with an override that reads only what still fits
When Claude Code fails to start under --input-format stream-json, it can answer with a "Claude Code didn't start" message and a result
When a background job loads its state.json, Claude Code now lists ignored environment entries with a reason for each
After compaction, Claude Code keeps task metadata when it fits and drops detail one step at a time when it does not
Git change counts now record whether each file was added, removed, renamed, copied or modified, with old and new paths for renames
Claude Code now reads only about the first 16 MB of an MCP listing and returns an error for directory listings that are too large
Claude Code now marks subagent transcripts that are over a size limit and refuses to load them again on demand
Plugin agent files now log a warning for settings Claude Code does not recognize, suggest the likely intended name, and flag more ignored ones
In headless and SDK runs, a turn stopped before its prompt check finished now ends as an error rather than a success
When search results are highlighted, the match you are on is now also underlined
sed edits now handles files that are not UTF-8#When Claude asks to edit a non-UTF-8 file with sed, the permission prompt now says it cannot be previewed instead of showing a garbled diff
On Linux and WSL, when the system clipboard copy works in a VTE terminal such as GNOME Terminal, Claude Code no longer also sends OSC 52
Sandbox options passed in now merge with your sandbox settings, deny lists add up, and failIfUnavailable defaults to true
New messages tell Claude it can read an oversized file by calling Read again with allow_large: true, or read it in parts
Unclear It is not clear whether allow_large is actually available to Claude yet or held back behind a switch.
The log line for an out-of-date auto mode approval now says the request's information was missing or no longer holds, and gives a cause
The error shown when your prompt cannot be sent to a newly created cloud session now begins "The cloud session was created, but"
When a remote message cannot be verified, the error may now suggest trying again or signing in again instead of re-pairing the device
A PreToolUse hook that stops Claude from continuing now produces the same stop note as PostToolUse, and 422 API errors are shown as 400
Loading a large session transcript can now stop scanning early, and records how much it read and kept when it trims the file
The error for an artifact action whose details had gone stale now says the information was missing or out of date, not only that it changed
Claude Code now handles unusual line-break characters in session transcripts and checks file size and change time more precisely
When matching plugin dependencies, Claude Code now also uses the source of the plugin that declares the dependency
Unclear It is not known exactly which dependencies now match differently than before.
Claude Code now refuses to add a plugin marketplace whose name clashes with a built-in name such as constructor or toString
Cloud session status now reads "paused · reply to resume", and a session with no reported worker status shows as working
A path safety check in Claude Code now rejects any path containing a backslash
Unclear Which feature uses this check, and so where a path with a backslash will now be refused, is not known.
The recipient field of SendMessage now explains its allowed values, and the Agent tool gains a step that adjusts its input
Unclear It is not clear what kinds of input the Agent tool's new adjustment step accepts or corrects.
Claude Code's name checks now reject unusual spaces, invisible characters and broken combining-character sequences
Unclear Which names are checked against these rules is not stated.
The message shown when a settings problem blocks tool calls now names your hooks as well as your settings
After syncing skills, Claude Code re-reads its list of skills up to twice and rewrites any downloaded entries that went missing
Claude Code now skips fetching model capabilities when its saved model list is recent enough, and in some environments
The check that blocks dangerous operations on protected paths now tests several values worked out from the command, not just one
When fetching teleport events fails, Claude Code now raises an error instead of quietly returning
Hook matcher patterns are now checked before use, and one kind of failure is raised as an error instead of only being logged
Unclear It is not known which matcher patterns the new check rejects with an error.
When a remote rewind is refused over a turn that is finishing, Claude Code now waits for it and reports the turn as still running if it does not end
Unclear It is not clear what you see differently when you rewind in a remote session.
Interrupting Claude Code while a UserPromptSubmit hook runs now cancels the hook cleanly, and the debug log says which kind of cancel it was
In fullscreen mode Claude Code tracks the link under the pointer and redraws when it changes, likely fixing stale hover highlighting
Unclear It is not confirmed what the redraw shows, such as whether the link is highlighted.
The warning about unknown keys in a plugin's hooks.json no longer cuts the list off with "and N more"
Unclear Whether the new warning lists every unknown key or still shortens the list in another way is not known.
PreToolUse hooks now show their full reason#When a PreToolUse hook blocks a tool, the hook's extra text is now added to the error message instead of being lost
When a turn is cancelled, queued messages that were not yet answered go back into the input box or back to the front of the queue
If you interrupt while a prompt.submit or UserPromptSubmit hook is checking your prompt, a block still stands and the turn ends as interrupted
Claude Code now closes an inherited permission request on interrupt, rewind and shutdown, and the transcript mirror tracks over-bound agents
If a skill download looks claimed by another process for too long, skill sync now gives up waiting instead of staying stuck
The agents view now quits with a message and restores your terminal when you switch tabs and no session remains to open
A tool-list change from an MCP server that arrives before Claude Code is listening now triggers a refresh instead of being ignored
The workspace diff now follows a renamed file from its old path to its new one and shows deleted files as removed
Quitting while Claude Code is attaching to a cloud session no longer shows an attach error; it exits quietly
Fetching a session's history for resume or teleport now shows an error when it fails, instead of returning an empty or partial session
On Windows, Claude Code now closes an MCP server's input and waits before force-closing it, instead of killing it at once
On Windows, the check that decides whether to stay on SSH for GitHub now reads your SSH configuration instead of stopping straight away
Unclear Whether this makes Windows connections to GitHub stay on SSH or switch to HTTPS more often is not clear.
HEAD requests in web fetch are no longer refused when the server reports a large file size
A check that stopped commands in a linked git checkout with no admin folder now lets them through when the environment runs in its own directories
Unclear Which environments are marked as running in their own directories is not stated.
When a hook run is cancelled, Claude Code now records it as cancelled instead of treating the turn as blocked or ended
Claude Code now skips malformed prompts from an MCP server and logs how many it dropped
When estimating how much space a tool's result takes up, Claude Code now counts the content of search result blocks instead of treating them as empty
If a prompt-submit hook blocks your prompt after the session was interrupted, Claude Code now treats it as an interruption instead of a normal block
Unclear It is not clear what you see differently when a prompt-submit hook blocks after an interrupt.
Some errors raised while expanding stacked slash commands now stop the expansion instead of being logged and ignored
Unclear Exactly which kinds of error now stop the expansion is not confirmed.
Requests that count tokens now set the thinking option to suit the model instead of always using one fixed setting
Output lines from asyncRewake hooks must now pass a check before being read as JSON, and their summary is kept correctly
Unclear It is not stated what the new check requires of an output line, so hook authors cannot tell which lines are read.
Claude Code resets its state before each MCP tool-list change notice and refreshes some servers' tool lists as soon as it connects
When reconnecting to a background session in retry-only mode, Claude Code now skips the "stalled" error
Unclear It is not clear when Claude Code reconnects in retry-only mode, so it is not clear when you would stop seeing the stalled error.
When Claude Code cannot read what the server already holds for a session, it now uploads nothing and retries instead of uploading everything again
When Claude Code copies text with the system clipboard, plugin copy calls now report success instead of a false no-clipboard failure
The hooks worker watchdog now checks processor time used, so a worker that was never given CPU time is not blamed for hanging
Unclear How much of the processor-time check is actually active in this build is not clear.
A saved syntax-highlighting result is now reused only when the stored code and its display variant both match the code being shown
When Claude Code cannot turn an error into text, it now shows "a value with no text" instead of failing again
Claude Code now clears hover highlights when you switch away from its window, instead of leaving them on screen
When trimming a final line break, Claude Code now removes a whole Windows-style line ending instead of leaving a stray character
When ending a stopped turn for a connected client fails, the log now records the error that actually happened
When a plugin path cannot be found, Claude Code now checks the right error, so the missing-path skip and its /mnt/ retry apply
Unclear It is not settled whether this changes behaviour at all or only how the program was built.
5 more of these are in What probably matters to you, on page 1.
Remote sessions can send still-here pings and probe a stream that has gone quiet for about 8 seconds, behind tengu_violin_pernambuco
The text Claude gets after a conversation is compacted can now include extra guidance on resuming, depending on an experiment
Creating a session with --remote can now pass a built-in tool restriction, though in this version no restriction is ever sent
Claude Code's remote session code now defines a server-controlled switch named for turning off inherited approvals
Unclear What this switch controls, and whether it affects any session, is not known.
5 more of these are in What probably matters to you, on page 1.
short_v2 mode for conversation summaries#The list of summary modes gains short_v2, which keeps the record of what you asked for and rewrites only the account of the work
Worker registration can now return worker_capabilities, and managed cloud workers declare that they do not hydrate carried lines
Unclear What carried-over lines are and what a cloud worker session loses by not restoring them is not stated.
Claude Code can now skip compacting a session transcript when little space would be reclaimed, through a store flag that starts out on
Claude Code can request an MCP server's tool list while still connecting and reuse that first page, for servers chosen by tengu_tender_truffle
A model with a 1M-token context window and 128000 output tokens now uses a pricing tier that sets a separate cache-read rate
Unclear Which model this pricing change applies to is not named.
When a check passes, one specific tool is now sent to the API with citations switched on
Unclear Neither which tool this applies to nor the condition that switches it on is known.
A new built-in message asks the model to continue briefly when a reply reached the output limit with no visible output
Published verbatim by Anthropic for v2.1.296. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 79 bullets, 15 name something an entry on this page also names, 27 name something no entry here does, and 37 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
code key to the Claude apps gateway's managed.policies[]: the same settings as cli, also applied in Claude Desktop's Code tab; beside desktop, it turns on Claude Desktop's gateway mode
No entry names this autoCompactWindow to subagent frontmatter and --agents definitions, so a subagent can auto-compact earlier than the main conversation's window
Probably agent-definitions-can-carry-an-autocompactwindow-passed-to, agent-auto-compact-threshold-now-takes-a-second-window-sourc, plugin-agent-frontmatter-gains-autocompactwindow-passed-thr CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL to run every workflow agent on one model while other subagents keep theirs
Probably new-env-var-claude-code-workflow-subagent-model-overrides-th CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MS environment variable to set a longer maximum delay for the backoff when retrying an overloaded (529) request
No entry names this /plugin on a plugin whose hooks are left out because another enabled plugin has the same name
No entry names this allow_large option to the Read tool so Claude can read a text file past the usual size limits in one call when it needs the whole file and the context has room
Probably read-tool-allow-large-override-messages-added, read-tool-gains-allow-large-option-sized-to-remaining-contex PreToolUse hooks that deny a tool call with "continue": false, and managed prompt hooks that block one, refusing the call but not ending the turn
Probably pretooluse-hook-stop-reason-is-appended-correctly, pretooluse-hook-stop-attachment-helper-and-422-to-400-error updatedMCPToolOutput in some sessions
Probably posttooluse-hooks-can-rewrite-mcp-tool-output-via-updatedmcp .mcp.json or plugin MCP server that was switched off for that folder, after changing directory or reloading plugins
Probably telemetry-for-auto-approved-project-mcp-servers, project-mcp-config-skipped-when-a-flag-checked-helper-is-on allowedProviders with "gateway" locking out laptops that name that gateway in user settings
Probably managed-settings-env-now-injects-a-computed-anthropic-base-u forceLoginMethod to gateway with no forceLoginGatewayUrl (regression in 2.1.295)
Probably gateway-login-method-now-counts-as-gateway-required --teleport opening an empty conversation when the session's history could not be read
No entry names this #95873[BUG] Regression since ~2026-09-12: Remote Control sessions have 0 teleport-events, so opening them from another machine (VS Code Remote tab / --teleport) yields an empty session (worked 2026-08-26 → 09-11) Open
52;c;… escape sequence printed on screen after copying in older VTE-based terminals such as MATE Terminal
No entry names this /diff panel or dialog was open
No entry names this #99026[BUG] Built-in /diff pane holds mod toasts, undocumented and contradicted by the screen map Open
UserPromptSubmit hook or a mod's prompt.submit hook ending headless sessions, clearing the typed prompt, or letting the unchecked prompt through
Probably prompt-submit-hook-interrupted-while-checking, input-hooks-interrupted-by-abort-now-return-interrupted-resu, prompt-submit-hook-handling-blocked-prompt-tracking-and-abo, interrupted-while-prompt-checked-handling, userpromptsubmit-hook-cancellation-distinguishes-interrupts claude self-hosted-runner printing misleading errors when registration is refused: it now names the org admin setting, or says a restarted on-demand runner needs a fresh work order
No entry names this --capacity above 1
No entry names this $ methods running in the main session's working directory instead of the calling agent's, and ignoring the turn their calling hook holds
Nothing to match on $.agent.register succeeding from a mod's hook that was still running after the mod was reloaded or removed; the call is now refused
No entry names this $.http.fetch in mods refusing a HEAD request when the response declares a Content-Length over the 4 MiB body limit
Probably custom-headers-check-function-replaced-and-git-subprocess-e, api-client-adds-per-request-extra-headers-and-awaits-a-heade, git-commit-detection-from-reflog, web-fetch-head-requests-skip-the-content-length-size-refusa, new-x-claude-code-wiggly-dove-request-header-off-by-default claude plugin marketplace add, marketplace update and plugin install failing with an internal error for a marketplace named like constructor; add now refuses such names clearly
Probably plugin-install-gets-replace-for-same-repo-duplicates-mcp constructor or prototype being deleted by the next save of that plugin's options
Nothing to match on CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a finished turn after a restart when an MCP tool result had ended that turn
No entry names this BASH_ARGV0 shell variable and then use it; these now prompt for approval
Probably bash-variable-list-adds-bash-argv0 ← being run twice, once unseen in the foreground, when the background service was slow to answer
Nothing to match on ← moved the session to the background; it is still not sent, but ↑ now brings it back
Nothing to match on /clear in headless sessions
No entry names this /mcp or claude mcp when an MCP server needs authentication
Probably auth-needed-prompt-for-remote-sessions-without-oauth, remote-environment-classifier-and-ccr-artifacts-endpoints /code-review ending on a raw JSON array in cloud sessions, the Agent SDK and IDE integrations; the findings now print as a numbered list
No entry names this tool_result events missing git_commit_id after git commit -q or git -C <dir> commit
No entry names this #95934OTel: git_commit_id still silently dropped for `git -C <path> commit` and quiet/redirected commits (2.1.278) — recurrence of #77237 Open
CLAUDE_CODE_TRANSCRIPT_LOCAL_GC dropping a message from the saved transcript when its text held a Unicode line or paragraph separator (U+2028, U+2029)
No entry names this claude purge leaving a prompt in the history file when its text held a Unicode line or paragraph separator (U+2028, U+2029)
No entry names this claude plugin install failing for GitHub owner/repo plugin sources on machines with no GitHub SSH key; the clone is now retried over HTTPS
No entry names this rm -rf /c/Users/<name> in Git Bash not asking in bypass permissions mode
No entry names this code settings, the reason shows as a reply
Nothing to match on --debug output to name unrecognized frontmatter fields in custom agent files, with a hint for likely typos
No entry names this --debug output for hooks: command hooks on tool calls, prompts, SessionStart and Stop now log their command, plugin, outcome and duration when they finish, so a slow hook is identifiable
No entry names this CLAUDE_CODE_TRANSCRIPT_LOCAL_GC: a large transcript file is no longer rewritten when that would free under 10% of it
No entry names this /cost, the status line, --max-budget-usd and the SDK's cost figures to price Sonnet 5.5 cache reads at $0.10 per million tokens (was $0.20)
No entry names this ←: a turn or ! command started while the session moves to the background is now stopped instead of finishing out of sight
Nothing to match on claudeCode.spinnerVerbs missing from the extension's settings, so settings.json now completes and validates it; a malformed value no longer breaks the chat panel
No entry names this @browser, as the terminal does; allowing a site for the session stops repeat asks
No entry names this prefersReducedMotion setting
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
910 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 43 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?