Claude Code Updates & Release Notes
464 updates curated from 27 sources by the Releasebot Team. Last updated: Oct 6, 2026
- October 2026
- No date parsed from source.
- First seen by Releasebot:Oct 6, 2026
2.1.291
Claude Code fixes regressions that could drop permission prompt answers and lose the last session messages on quit.
Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts
Fixed a regression in 2.1.288 where the last messages of a session could be lost when quitting
- October 2026
- No date parsed from source.
- First seen by Releasebot:Oct 6, 2026
2.1.290
Claude Code adds managed agents onboarding, richer plugin and hook metadata, new session and logs shortcuts, and VS Code workflow upgrades. This release also strengthens permissions, gateways, and auto mode while delivering a large wave of stability and bug fixes across sessions, sandboxing, and cloud use.
Release Notes
- Added
serverToolUsesto the result of a mod'sturn.stephook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end - Added
agentIdto thetool.checkevent of plugin hooks, so a hook can tell a subagent's permission check from the main session's - Added
ceilingto the question and verdict a mod'stool.checkhook reads, naming the approval an organization requires for a tool - Added
ThemeKeyandColortypes to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name - Added to
claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a.catch(gatingHooksunder--json) - Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds
- Added
claude attach <name>andclaude logs <name>: part of a session name works in place of the id - Added
/claude-api managed-agents-onboard <url>to set up the Managed Agents pattern a page describes asant applyfiles - Added
/claude-api managed-agents-onboard <quickstart-name>to build a Console quickstart template, such asdeep-researcher, with theantCLI - Added a warning when a managed settings file is a link to a file outside the managed settings folder
- Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains
- Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta
- Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors
- Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown
- Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run
- Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an
offsetto read on - Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep
- Fixed
/rewindnot listing a prompt sent while Claude was still working - Fixed scheduled tasks (
/loopwith an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on - Fixed scheduled tasks set in the foreground never firing after a ← or
/backgroundhand-off, and recurring ones firing an extra run on every resume, respawn or fork - Fixed headless
--json-schemaruns exiting non-zero withis_error: trueon asuccessresult when the connection dropped after the structured output was already delivered - Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy
- Fixed a project
CLAUDE.md, rule orAGENTS.mdsymlinked outside the working directories loading underpermissions.blockReadsOutsideWorkingDirectoriesor aReaddeny rule - Fixed URL allow and deny patterns with a wildcard inside an
xn--host label matching differently from one process to the next - Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions
- Fixed
/ultrareviewdropping uncommitted changes without a warning on Windows whengit stash createfailed, and refusing them after agit add -Nfile was deleted or moved - Fixed the
plansDirectorysetting's project-root check for paths that contain a backslash on macOS and Linux - Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in
- Fixed the background daemon's log passing terminal control characters to the screen under
claude daemon runandclaude daemon logs; they now show as\uXXXXescapes - Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds
- Fixed a plugin hook with a
.catchbeing unloaded, and its.catchskipped, when the hook kept the hooks worker busy on a prompt or tool call - Fixed a mod's
turn.stepresult listing a tool call that a mid-response model fallback had discarded - Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file
- Fixed
claude plugin validateand plugin loading refusing a hooks module that destructures an option named like one of its top-level functions - Fixed
/ultrareviewfailing to upload uncommitted changes whencore.safecrlf=trueis set in git's configuration - Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings
- Windows: Fixed multi-line
!shell blocks in skills and commands failing when the file is saved with CRLF line endings - Fixed Claude Code hanging until killed when a
/permissionstab was clicked while searching in fullscreen mode - Fixed conversation compaction sometimes failing with a "null is not an object" error
- Fixed plugin hooks reading an empty
answeronturn.completefor a subagent that hands its report back in auto mode - Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded
- Fixed a mod's
prompt.submithook that drops a prompt after callingnext(e)being ignored silently: the hook is now reported as failed, by name - Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing
- Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
- Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded
- Fixed
disableClaudeAiConnectorsandallowedMcpServersURL rules not being applied to some MCP entries declared in.mcp.json, plugins or agents - Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing
- Fixed an
@-mention under the read block or--restrictedbeing able to read a file outside the working directories through a link changed mid-read - Fixed Esc in the agents view confirming "Press enter again to restart this session — it isn't responding"; Esc now just reopens the session
- Fixed agent view losing a background session's
/looprun count, countdown and live status line after the session enters a worktree that it creates - Fixed
claude agentssessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt - Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on
declare,typeset,exportorreadonly - Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder
- Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded
- Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters
- Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted
- Fixed You should know writing its notes in English regardless of the
languagesetting - Fixed a freeze after sending some very long messages
- Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing
- Fixed
claude respawnre-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation - Fixed Esc after an
n:or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section - Fixed
claude agentssaving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted - Fixed
/ultrareviewuploading uncommitted changes unfiltered for files under a git filter driver namedunsetorunspecified; the upload now stops and asks you to rename the driver - Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore
- Fixed
claude --teleportand/teleportdeleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why - Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt
- Fixed agent view's
/looprun count freezing and its countdown disappearing after/clear; the count now restarts with the new conversation - Fixed
--channelspermission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt - Fixed
/chrome"Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135) - Fixed mods staying off for people who reach Claude through a gateway (
ANTHROPIC_BASE_URLwithANTHROPIC_AUTH_TOKEN) and have no Anthropic account - Fixed replies sent from
claude agentsjust after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts - Fixed slash commands and answers to a multiple-choice question that
claude agentscould not deliver to a running session being saved and sent by themselves the next time it was restarted - Fixed sandboxed commands that pipe a heredoc into another command (
cat <<EOF | python3) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple$VARreferences - Fixed
claude agentsfailing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one) - Fixed agent view's "restart this session fresh" re-sending an earlier message from the session instead of starting with an empty conversation
- Fixed Bash permission checks auto-approving some read-only commands (such as
rgorgit grep) whose arguments the shell would still expand as wildcards; these now prompt for approval - Fixed
claude plugin testrefusing to run after an upgrade because of an out-of-date saved setting - Fixed a short form of a
git cloneoption keeping the sandbox exemption from a git pattern such asgit *insandbox.excludedCommands; it is now treated like the long form - Fixed the first feature-flag request of a session ignoring a proxy or API endpoint set in a project's settings
- Fixed
/ultrareviewof a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside.git(git 2.54+); it now refuses with an explanation - Fixed cloud sessions staying asleep after a container restart lost a pending
/loopwakeup or scheduled task; Claude is now told and can schedule it again - Fixed the Claude apps gateway's retention sweep deleting a returning developer's identity row refreshed at the same moment, on PostgreSQL versions without the November 2025 fixes
- Fixed sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules
- Fixed the Claude apps gateway failing to start when the certificate it presents to the identity provider has an empty subject
- Fixed the Claude apps gateway exiting with a bare "Invalid URL" when
store.postgres_urlcan't be parsed; the error now names the setting and says what the URL may hold - Fixed background agents failing with "Agent stalled" and Workflow tool subagents restarting from their prompt when a Mac woke from sleep
- Fixed slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL)
- Fixed a response interrupted by computer sleep being treated as a stalled stream on Bedrock, Vertex, Foundry, and custom gateways
- Fixed a freeze before the first request and in the
/sandboxConfig tab on Linux and WSL when a sandbox read rule such as~/**/.envcovers a large folder - Fixed skills not being found when asked for by the name in SKILL.md when their folder has a different name (for example a non-English name): the skill listing now shows both names
- Fixed a plan written in plan mode being lost when a cloud session's container restarted before the plan was presented
- Fixed the Bash tool occasionally losing shell aliases, functions and plugin PATH entries for a whole session when its first command ran seconds after startup on a new config directory
- Fixed unbounded memory use when an HTTP MCP server sends a very large response
- Fixed artifact operations failing in a Claude Code run started from inside a cloud session (for example
claude -prun from the Bash tool) - Fixed files sent from remote sessions sometimes being refused as "not the one approved" when four or more were sent at once
- Fixed plan mode not being restored when resuming a session with
--continueor--resume <session-id>in the terminal - Fixed a marketplace named after another GitHub marketplace's download folder stopping that marketplace from downloading
- Fixed automatic compaction giving up with "Prompt is too long" when a Mac went to sleep while it was running
- Fixed the rewind menu (Esc Esc /
/rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file - Fixed a subdirectory's AGENTS.md not being attached when a file under it is @-mentioned
- Fixed self-hosted runner sessions resumed after a stopped runner failing with "missing but already registered worktree" when the sessions folder is a relative symlink
- Fixed a freeze when the secret scan or a permission prompt met long token-like text
- Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands
- Fixed
CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5mbeing read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back todialogExpiry - Fixed a stall when an MCP server's tool listing contains very long runs of combining characters
- Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block
- Fixed Claude in Chrome's browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog's list going stale after a switch
- Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree
- Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login
- Fixed
--restricted(andCLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket - Fixed sessions moved to the background while idle reopening as "no saved transcript" after a restart or idle cleanup; they now resume their conversation
- Fixed background workers honoring
--allow-dangerously-skip-permissionson respawn without the bypass-permissions disclaimer having been accepted - Fixed Claude replying in an endless loop when a plugin's async Stop hook passes an unquoted script path under a folder with a space, such as Application Support
- Fixed a freeze of several seconds when secret masking met very long unbroken text
- Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input
- Fixed first launch asking to pick a login method again after
claude auth loginor with a credentials file already in the config directory - Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts
- Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do
- Fixed macOS
/loginreporting success when the keychain refused the new login and kept an old one it could not remove - Fixed SDK hosts using
--include-partial-messagesseeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming - Fixed
/permissionsin screen reader mode: typing a rule's number now picks it instead of opening the search box - Improved auto mode: when a conversation grows too long for the client-side safety classifier to review, it is now compacted instead of prompting for, or failing, every tool call
- Improved screen reader mode: short announcements, such as a deleted word, now stay on screen until your next key press or until something above them on screen changes
- Improved screen reader mode: answered questions in question dialogs now say "answered" beside their box
- Improved the
/usage-creditsmessage shown to Team and Enterprise members whose organization has turned off usage credit requests - Improved cloud sessions: a new conversation's first turn no longer waits for a stdio MCP server whose config sets
alwaysLoad: false - Improved the error shown when a cloud session can't be created because your Claude login expired or was revoked: it now tells you to run
/login - Improved the error shown when an MCP server's sign-in expires mid-session to say how to re-authenticate (
/mcp) - Changed auto mode on Bedrock, Vertex and Foundry to use the local classifier by default for now; set
CLAUDE_CODE_AUTO_MODE_SERVER=1to use the platform's server-side classifier - Changed
OTEL_METRICS_INCLUDE_REPOSITORYto tag OpenTelemetry metrics and events withvcs.*repository attributes; commit events getvcs.ref.head.*withOTEL_LOG_TOOL_DETAILS - Changed
/ultrareview --postto post the PR comment directly when the findings arrive and print the comment link, instead of starting a second cloud session to post it - Changed artifact database reads that save into the session scratchpad so they no longer stop for working-folder approval
- Changed skills synced from claude.ai in cloud sessions to be named
anthropic-skills:<name>, matching Claude Desktop; the bare name still works when nothing else uses it - [VSCode] Added an agent map: an "N agents" footer pill opens a map of the session's sub-agents with per-agent cards, Stop agent, and read-only transcripts
- [VSCode] Added a Hooks dialog to the command menu for viewing hooks and adding, editing, or removing them in user, project, and local settings; managed, plugin, and session hooks stay read-only
- [VSCode] Added live progress rows for running subagents under the tool-call groups in Focus view
- [VSCode] Added a Permission rules dialog that lists permission rules and adds or removes them in user, project, and local settings; startup-option, session-only, and managed rules stay read-only
- [VSCode] Added a Cancel button to the Switch account screen that returns to your session as the current account
- [VSCode] Fixed Focus view showing a turn started by a delivered plain-text prompt, such as a scheduled task's, as part of the previous turn
- [VSCode] Fixed the footer's prompt cache clock hiding its minutes when the panel is narrow
- [VSCode] Fixed the session list keeping sessions from the default folder when
CLAUDE_CONFIG_DIRis set in a settings file or theenvironmentVariablessetting - [VSCode] Fixed a plan preview that finished loading late sometimes hiding its comment box or showing an older plan
- [VSCode] Fixed a plan preview accepting comments that went nowhere after its Claude tab closed
- [VSCode] Fixed the prompt cache clock and reopen notice for a session compacted after its last reply and then closed, which now reads as cold when reopened
- [VSCode] Fixed a session renamed in the extension while Remote Control is on keeping its old name on claude.ai/code
- [VSCode] Fixed the footer's model pill and Remote Control pill waiting for the new tab's Claude process to start when another tab in the window is already up
- [VSCode] Fixed a second Claude process running through its full startup when a session tab's launch arrived more than half a second after its config read
- [VSCode] Fixed resuming a session from the session list ignoring
claudeCode.preferredLocation: "sidebar"(it always opened a panel), and programmatic opens resetting that setting to "panel" - [VSCode] Fixed Windows issues: the WSL install prompt no longer appears on machines without WSL installed, and IDE diagnostics are now returned correctly for Windows files when WSL is installed
- [VSCode] Fixed the custom style builder saving a User level style in a folder the CLI does not read when
CLAUDE_CONFIG_DIRis set through settings - [VSCode] Fixed pressing Esc to dismiss a CJK IME candidate window canceling the running Claude task
- [VSCode] Fixed the session tab's Rename box opening empty for a tab restored with the window; it now starts with the current name
- [VSCode] Fixed collapsed sections in the session list panel briefly showing expanded each time the panel loaded
- [VSCode] Fixed Focus view showing a tool call as still running after Claude had moved on, such as while a question waited for your answer
- [VSCode] Fixed the session list's active-row highlight going stale when an unfocused Claude tab's session ID is corrected
- [VSCode] Fixed Cmd/Ctrl+Shift+T reopen and deep-link opens placing the Claude tab outside the Claude editor group when a Claude tab has focus
- [VSCode] Fixed the session tab's "Add to group" putting a session opened from Claude Code on the Web in two groups; it now moves the entry the session list shows
- [VSCode] Fixed the model picker showing models an organization has since disabled until the window was reloaded twice
- [VSCode] Fixed a tab opened from the session list jumping back to that session, and a tab opened from a Web session restarting its teleport or staying empty, after VS Code reloads the tab's view
- [VSCode] Fixed
/btwside-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors - [VSCode] Fixed the pending question card not reappearing after the Claude panel reloads when signed in with a Claude.ai or Console account
- [VSCode] Fixed claude.ai-only features staying visible in a window's other Claude panels after one panel picked up a third-party provider from a settings file
- [VSCode] Fixed the sign-in screen appearing despite the Disable Login Prompt setting when Claude Code reports no login or a request fails for lack of one
- [VSCode] Fixed the next queued permission prompt keeping text typed on the previous prompt and accepting an immediate second click
- [VSCode] Fixed install-plugin links opening the Claude sidebar without the install dialog in a window where only the session list had been shown
- [VSCode] Fixed the sidebar usage meter staying empty on a new window until the Account & usage dialog was opened, and a 0% usage limit being left out of the meter
- [VSCode] Fixed "Start new session in this group" losing the group after New conversation, and a missing unread dot for a session that finished before the sidebar's unread list loaded
- [VSCode] Fixed the editor tab badge showing unread during a running turn or missing on a tab opened from the session list, and "Add Session Tab to Group" doing nothing for an archived session
- [VSCode] Fixed "Enable Remote Control for all sessions" so flipping it also applies to sessions that are already open, not only to new ones
- [VSCode] Fixed the session list's Open filter for sessions continued from claude.ai whose tab was still recorded under the web session, and labeled the filter menu's sections for screen readers
- [VSCode] Changed the model picker to one flat list of every model, with rows kept for older model spellings listed last
All of your release notes in one feed
Join Releasebot and get updates from Anthropic and hundreds of other software products.
- October 2026
- No date parsed from source.
- First seen by Releasebot:Oct 4, 2026
2.1.289
Claude Code fixes a wide range of plugin, terminal, and shell-command safety issues, improves large file rendering, and adds agent.spawn plus new agent state support.
- Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
- Fixed the terminal freezing on short code blocks with many unclosed
<script>tags or deeply nested${substitutions - Fixed
Readdeny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink - [VSCode] Reverted a 2.1.288 change to
claude auth statusthat may have made sign-outs more frequent - Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
- Fixed
plugin list,plugin evalandplugin updateshowing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked--plugin-dir - Fixed installed mods not loading in the first session after an upgrade
- Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
- Fixed plugin panes drawing nothing when a link used a localhost address, an
@in its path, an uppercase host or afile:path - Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
- Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
- Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
- Fixed sessions ending with an interface error when a plugin region with no height kept growing
- Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g.
TZ="$HOME" rm -rf build) when the sandbox auto-allows commands - Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
- Fixed
claude plugin validateskipping the plugin when the folder also holds a marketplace manifest - Added
agent.spawnfor teammates, one agent id across plugin hook events, and idle and waiting states in$.agent.list() - Fixed sessions ending with "unrecoverable interface error" when a value a mod's
ui.renderhook wrote made a row throw while drawn; the engine now draws its own row instead - Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
- Fixed right-aligned content in a mod's pane or band drawing under the close mark or
[-], which now also keep one column in from the terminal's edge - Fixed a mod's
Clientthat fails while drawn taking down everything the mod drew around it; it now fails alone and raisesui.fault - Fixed
claude plugin validatefailing an Anthropic marketplace's own plugin and listing a cleanplugin.jsonin--json - Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
- Fixed a failed plugin component showing
Erroror nothing as its reason when the failure carried no message - Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
- Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed
<script>tags - Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it
- October 2026
- No date parsed from source.
- First seen by Releasebot:Oct 2, 2026
2.1.288
Claude Code releases a broad reliability and UX update with smarter resume and recovery flows, stronger plugin and MCP handling, improved permission and auto mode behavior, and many fixes for cloud, SDK, screen reader, and terminal sessions.
Added
- Added
$.ui.selection()for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row - Added a built-in
gh apito cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal - Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images
- Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call
- Added
--max-findings <n>|allto /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass--max-findings default - Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json
- Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab
- Added an announcement when fast mode changes as a result of switching models via
/config model=<x>or Remote Control - Added
yes/no/on/off/1/0(case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongsidetrue/false
Fixed
- Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried
- Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage
- Fixed
--resumesometimes dropping files and other context that a compaction had just restored - Fixed a resumed session sometimes not saving the last response of a turn, so that the next
--resumeshowed the prompt unanswered - Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load
- Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking
- Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added
CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTSto turn structured outputs off - Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash
- Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a
sonnetsubagent - Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it
- Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes
- Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device
- Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted
- Fixed a plugin's pane showing nothing when one
Codeelement held a diff that does not parse; it now draws as plain code - Fixed plugin LSP servers receiving literal
${user_config.*}and${CLAUDE_PLUGIN_ROOT}placeholders ininitializationOptionsandsettingsinstead of substituted values or manifest defaults - Fixed a plugin's
tool.callhook making Bash fail and file searches read the wrong folder in subagents that run in a worktree - Fixed
git-subdirplugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34) - Fixed plugins loaded with
--plugin-dirnot showing "Configure options" in/plugin - Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running
- Fixed sandboxed heredocs with an unquoted delimiter (
python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple$VARreferences - Fixed Bash tool permission check to prompt before a
BASHPIDassignment whose value the shell would evaluate as arithmetic, instead of allowing it silently - Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt
- Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn
- Fixed OpenTelemetry
claude_code.tool.blocked_on_userspans reportingunknownsource or decision in-pand SDK sessions and for PreToolUse hook approvals - Fixed permission asks that ended unanswered, in
-por on an interrupted turn, emitting notool_decisionevent - Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before
/compacteven though its history was still saved - Fixed unattended sessions (
CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts - Fixed
/loginreporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (anthropics/claude-code#73861) - Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request
- Fixed a second
gcpAuthRefresh/awsAuthRefreshbrowser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in - Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults
- Fixed headless (
-p/ SDK) sessions occasionally ignoring SIGTERM when a supervisor such astimeoutor systemd sends SIGCONT alongside it - Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses
- Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed
- Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named
memory - Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with
disableAutoModeor an older model); typing, navigation and JavaScript still ask - Fixed
claude plugin installfailing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice - Fixed
sandbox.credentials.filesentries on git config files not taking effect whilepermissions.blockReadsOutsideWorkingDirectoriesis on - Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings
- Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to Claude apps gateway, provider setup,
/tui) - Fixed a stall when launching an agent whose
tools:lists very manyAgent(...)entries - Fixed sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation
- Fixed the npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder
claudestub was installed - Fixed Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process
- Fixed
owner/repoplugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top - Fixed path-scoped
.claude/rulesand nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them) - Fixed a dangerous
rm(such as one on/or the home directory) inside abash -corsh -cscript running without a prompt in bypassPermissions mode or under a shell allow rule (anthropics/claude-code#96300) - Fixed LSP tool calls hanging indefinitely when a language server uses dynamic capability registration or stops responding; requests now time out after 60s (per-server
requestTimeout) - Fixed
idle_promptnotification hooks firing while background agents are still running (anthropics/claude-code#93672) - Fixed PreToolUse and PermissionRequest hooks being skipped when matching them failed or the tool's input could not be serialized to JSON; the call is now blocked
- Fixed the first request in a fresh environment or after a model switch using the built-in output limit and auto-compact window, not the server's; that request may now wait up to 1.5 seconds
- Fixed the "What should Claude do instead?" hint showing on the Interrupted row after sending queued messages with ctrl+enter
- Fixed
/loginin a--baresession running a sign-in the session never reads, which could replace your saved login; it now says which credentials work - Fixed the InstructionsLoaded hook omitting agent_id and agent_type when a subagent's file access loads a rule or nested CLAUDE.md; rules and nested CLAUDE.md files loaded on file access now also report effort
- Fixed the Agent tool in
claude mcp servealways reporting no available agents and rejecting every subagent_type - Fixed the terminal cursor not following the typed text in the fullscreen transcript viewer's search and in
/theme's custom color search - Fixed
/permissionsin screen reader mode: typing a rule's number now picks it instead of opening the search box - Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional
- Fixed screen reader mode showing a "Tab to amend" hint on approval prompts, where Tab does nothing
- Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying "Select with numbers" in empty menus or while a search box has the keys
- Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs
- Fixed screen reader mode sending the
claude --teleportprogress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame - Fixed
CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETASnot removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject - Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window
- Fixed lists such as
/tasks,/copyand/hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edge - Fixed the overflow rows of lists to read "↑ N more" / "↓ N more" instead of "N more above" / "N more below"
- Fixed
/hooksto open on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three - Fixed the model fallback notice and the autocompact-thrashing error to say when a fallback dropped the context window from 1M to 200K tokens
- Fixed the prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway)
- Fixed responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events
- Fixed responses failing with "Content block not found" when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived
- Fixed an empty completed response being requested twice when the connection dropped before the stream's final event
- Fixed the stop reason being lost when a proxy sends a trailing usage-only frame
- Fixed
CLAUDE_CODE_RETRY_WATCHDOGsessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a longRetry-Afterfrom a 5xx - Fixed fast mode retrying rate-limited requests back to back when the server sent
Retry-After: 0 - Fixed a tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message
- Fixed conversations getting permanently stuck on "tool_use.name: String should have at most 200 characters" after the model called a tool by an overlong name
- Fixed tool calls failing with "Failed to get memory usage", or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors
- Fixed
--input-format stream-jsonsessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn with an error when an earlier assistant message had plain-string content - Fixed non-interactive sessions (
-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session - Fixed a background daemon auto-upgrade failure silently killing all running background sessions
- Fixed
TaskStopandTaskOutputfailing to find background agents spawned by another agent — errors now list running agents by id and description - Fixed the
claude agentscomposer discarding your typed message when a slash command isn't available there - Fixed the agent list crashing when opening a stopped session whose conversation was already open in another session
- Fixed background tasks in the web and mobile Remote Control panels showing stale "Running" status by forwarding full task state on every membership change
- Fixed
/pluginInstalled showing a "more above" indicator when already scrolled to the top - Fixed
~~strikethrough~~showing literal tildes in assistant messages instead of rendering as strikethrough - Fixed
--toolsallowing feature-gated tools to slip through before flags loaded on a cold first launch - Fixed background job status in
claude agentsshowing a stale "needs input" message after replying - Fixed a dark-theme flash when opening a background session from
claude agentson a light terminal - Fixed mouse-selected text staying highlighted after deleting it in
claude agents - Fixed session cost not showing for usage-based Enterprise and Team subscribers
- Fixed agent teams: teammates spawned via tmux/pane backends now inherit the leader's
--effortlevel - Fixed Workflow
agent({schema})subagents looping forever on repeated schema validation failures instead of aborting after 5 attempts - Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever
Changed
- Changed
/deep-researchto start only when invoked manually; Claude no longer launches it on its own - Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead
- Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt
- Changed agent markdown files to reject agent names containing
:, which is reserved for plugin namespacing - Changed skills with
context: forkto run in the background by default; opt out per skill withbackground: false
- October 2026
- No date parsed from source.
- First seen by Releasebot:Oct 1, 2026
2.1.287
Claude Code ships a broad update with Claude Mods, stronger plugin and MCP behavior, better model and session handling, major accessibility and Windows fixes, plus improved cloud, Remote Control, Bedrock, Vertex, and VSCode workflows.
- Added Claude Mods: plugins may now modify deeper behavior
- Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with
/plugin enable cc-plugin-you-should-know@builtin(for first-party sessions with telemetry on) - Added an
n:<text>filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match - Added
prompt_textto the OpenTelemetryuser_promptevent, a copy ofpromptfor backends that nest dotted keys; drop or mask it wherever you drop or maskprompt(anthropics/claude-code#70763) - Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry
- Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool
- Self-hosted runner: Added a built-in
gh api(REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed - Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it
- Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries
- Fixed hooks configured with
asyncRewakewaking Claude over and over with "found issues" notifications when the hook's script file is missing; the broken hook is now reported once - Fixed tool heartbeats not reaching SDK hosts while the model's response stream was stalled with no data arriving
- Fixed Bedrock and Vertex startup model checks ignoring an enforced
availableModelslist, which could collapse/modelto one Opus row - Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached
- Fixed picking Fable in
/modelon a claude.ai login saving the current version's id, so your saved default now follows the newest Fable like Opus and Sonnet do - Fixed switching between Opus 5.5 and Sonnet 5.5 (
/model,opusplan) rewriting earlier MCP tool announcements, which could drop earlier extended thinking - Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail's message when the reply began with thinking
- Fixed a dangerous
rm(such as one on/or the home directory) losing its always-ask safeguard when the same command also redirected output to a~or wildcard path - Fixed
claude -pand SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running - Fixed a folder's CLAUDE.md being attached a second time after resuming a session or after a compaction
- Fixed background sessions that could not be reopened from
claude agentsafter the agent exited and removed the worktree the session was started in - Fixed
/advisorpairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped - Fixed Bash permission prompts showing internal parser names such as "Contains simple_expansion" instead of a plain explanation
- Fixed a cause of fullscreen sessions on slow or busy machines exiting with "Claude Code exited after an unrecoverable interface error" while a scroll key was held in a long conversation
- Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named
__proto__ - Fixed Claude being told to page large MCP results saved as JSON with Read's offset and limit, which cannot split one long line
- Fixed the commit attribution reminder being delivered inside a tool result after a compaction
- Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields
- Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional
- Fixed screen reader mode showing a "Tab to amend" hint on approval prompts, where Tab does nothing
- Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying "Select with numbers" in empty menus or while a search box has the keys
- Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs
- Fixed screen reader mode sending the
claude --teleportprogress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame - Fixed
CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETASnot removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject - Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window
- Fixed
--include-partial-messagessending a cut-short reply'smessage_stoplate or never, so apps could show the reply as still in progress - Fixed
claude agentssometimes not showing the permission prompt a background session is waiting on - Fixed
/ultrareviewgiving advice about.git/info/attributeswhen the upload stops on a committed.gitattributesit cannot read, such as one saved as UTF-16 - Fixed
claude remote-controlfailing to register behind an HTTP proxy with a misleading "Check your organization permissions" error (anthropics/claude-code#97352) - Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable
- Fixed the running-tool dot and three spinners still moving with the "Reduce motion" setting on, and /rewind's confirm screen updating its "ago" time while you type a note
- Fixed times in
claude agentschanging every second in screen reader mode; they now change at most every 10 seconds - Fixed a revoked claude.ai login showing a generic
API Error: 401instead of "OAuth token revoked"; in-pmode the error now starts with "Failed to authenticate" - Fixed
/ultrareviewupload refusals advising you to copy a variable named by a repository's settings file into your own user settings - Fixed
--output-format stream-jsonand the SDK not streaming the turns of acontext: forkskill run by typing/<skill>as the prompt, as they do for the Skill tool's fork - Fixed /feedback and /bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report
- Fixed
claude plugin marketplace add --sparseandgit-subdirplugin installs failing with "transport 'http' not allowed" when the repository is served over plain http - Fixed cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted
- Fixed a plugin reload that overlapped the startup
--plugin-urldownload corrupting the session's cached copy of the plugin archive - Fixed
/desktopquoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause - Fixed an MCP connector tool call occasionally running twice, or the connector's calls failing until restart, when its server changed which MCP protocol version it supports
- Fixed SessionStart hooks from synced plugins not running in new cloud sessions
- Fixed the transcript's "N hooks ran" summary and the verbose debug log's matched-hooks count including Claude Code's internal callbacks, so one configured hook no longer shows as two
- Fixed files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds
- Fixed repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory
- Fixed PNG, JPEG and WebP images over 8,000 pixels on a side failing to send from a remote session; Claude now sends a scaled-down copy
- Fixed messages sent from the Claude apps with 17 to 20 attached files delivering only the first 16
- Fixed headless sessions reporting an MCP server as needing authentication after one refused call, even though later calls succeed
- macOS: Fixed Remote Control sessions started with
claude remote-controlstopping mid-turn when the Mac went to idle sleep - Windows: Fixed interactive
claudehanging or crashing with "Raw mode is not supported" when its input is piped or redirected; it now says why and exits (use-pfor piped input) - Bedrock, Vertex, Mantle: Fixed model availability checks under
CLAUDE_CODE_SKIP_*_AUTHsending a differentAuthorizationheader than real requests whenANTHROPIC_CUSTOM_HEADERSrepeats it - Improved
/config: settings that cycle show ‹ › and step both ways with ←/→, narrow terminals stack each value under its label, and PgUp/PgDn page the list - Improved plugin marketplace errors to say in plain words why a marketplace was ignored or refused, and what to do
- Improved plugin listings to note when a plugin's dependencies were not installed, and updating a plugin now retries an install that did not finish
- Improved the Claude apps gateway's error when Amazon Bedrock rejects a model ID: developers now see which model is unavailable, and the gateway log names the ID that was sent
- Improved SDK sessions so a message sent with priority "now" no longer cancels a running web fetch or web search; it keeps loading in the background
- Improved
/memory: the left and right arrow keys now flip its on/off settings, such as Auto-memory - Improved
/skillnames typed mid-message: Claude is now told they are skills, includingdisable-model-invocationones - Improved the contrast of the prompt input border in light themes and of the ❯ before your earlier messages
- Improved delivery of files Claude sends from cloud sessions and Remote Control: an upload that fails on a timeout, a network error or a 502, 503 or 504 is now retried once
- Improved what Claude says when a file cannot be sent for a reason that may be temporary: it now mentions that you can ask for the file again in a few minutes
- Improved the prompt for a held message from another session to show the message between dashed lines, matching other permission prompts
- Improved MCP and other tool permission prompts to show the tool call between dashed lines, matching file edit prompts
- Improved MCP startup in headless mode: a remote server whose first connect fails transiently is now retried without waiting for the slowest server to finish connecting
- Improved files Claude sends from a remote session: large files now stream from disk instead of being read into memory, and a file over the size limit is refused with the server's limit named
- Improved the explanation Claude gives when the server refuses a file it sends from a Remote Control or cloud session, such as an oversized image
- Improved handling of large MCP tool results: less memory, smaller session files, and no extra upload to count tokens for results far over the limit
- Windows: Improved Bash tool speed by removing a subshell that ran before every command
- Changed a shell write through a repo-committed symlink onto a sensitive file or out of the working tree to name where it lands and wait for a person, on lines with a
~target too - Changed Opus 4.7+ and Fable to use a 1M context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway, with no
[1m]suffix (CLAUDE_CODE_DISABLE_1M_CONTEXT=1keeps 200K) - Changed replies from
claude agentsto arrive as queued messages; slash commands other than/stopsent while a turn is running now run when it ends - Changed whole-tool
Bashallow rules and allowing hooks to prompt for, not run, shell writes to files Claude Code's file tools refuse outright (the Anthropic profile store, the host credentials file) - Changed right-click paste on Windows and Linux, and middle-click paste on Linux, to happen when the button is released; moving the pointer away before releasing cancels it
- Changed MCP server
alwaysLoad: falseto defer all of that server's tools behind tool search - Changed screen reader mode to write new or changed lines without first pausing with the cursor at the start of the line; set
CLAUDE_AX_PREPARK_MS=50to restore the pause - Changed automatic model switches after a flagged message to keep your current effort level instead of the new model's default
- Changed waiting permission prompts to show oldest first, so a new prompt no longer covers the one you're reading (prompts with a countdown still open on top)
- [VSCode] Added "Run in background" to a running command or sub-agent, to move it to the background and keep working
- [VSCode] Added the output of background shells and Monitors to their cards in the agent map
- [VSCode] Fixed settings dialogs blaming a timeout when Claude Code's reply was too large to confirm a save
- [VSCode] Fixed reopening a cloud session that the side bar already brought to this machine opening it again in a new tab; the side bar is shown instead
- [VSCode] Fixed the side bar's Web tab not listing cloud sessions started after the window loaded; a failed load now says "Remote server is not connected" instead of "No web sessions yet"
- [VSCode] Fixed a tab restored after a reload starting a second Claude process on a conversation the side bar already has open; it now shows the "still open somewhere else" notice
- [VSCode] Fixed tool-row file links, session-list links and two hints showing in plain text
- [VSCode] Fixed a background agent's still-running command showing as failed once the main turn ended
- [VSCode] Fixed a user's own
/usageor/contextcommand opening the extension's dialog instead of running when picked from the command menu - [VSCode] Fixed file links in the plan preview tab doing nothing when clicked; they now open the file like links in chat replies
- [VSCode] Fixed opening a tool's input or output in an editor tab failing with "Timeout waiting after 1000ms" on remote hosts such as WSL when the tab is slow to appear
- [VSCode] Improved the Manage plugins dialog: a failed plugin action now opens a popup that explains it and, where there is one, offers the fix
- [VSCode] Changed the Manage plugins dialog to ask before removing a marketplace or turning off a plugin that your project's shared
.claude/settings.jsonturns on - [Cloud sessions] Fixed Run now on a routine showing internal error text when the run is refused before it starts; it now shows the same explanation as the routine's failure notification
- [Cloud sessions] Changed
MCP_DISCOVERY_CACHE=1, when set in your cloud environment's variables rather than a settings file, to reuse your connectors' tool lists after a session restart; other MCP servers are no longer cached and connect at startup - [Claude Tag] Added direct messages with Claude for members on an Enterprise plan Standard or Usage-Based Chat seat who also have Cowork; a seat that includes Claude Code is no longer required
- [Claude Tag] Fixed the Default model setting in admin settings and a channel's Configure page offering models your organization can't use, which made saves or new sessions fail
- [Claude Tag] Fixed the note under Claude's Slack messages saying it answered on a fallback model, and why, disappearing when Claude later edited that message
- [Code Review] Fixed the organization menu in Code Review's "Add a repository" dialog showing only a few of your GitHub organizations; it now loads more as you scroll
- [Code Review] Improved the Code Review check run to say when your repository's REVIEW.md wasn't applied, for example on a very large pull request or when REVIEW.md is a symbolic link
Similar to Claude Code with recent updates:
- Claude updates151 release notes · Latest Oct 1, 2026
- Anthropic updates65 release notes · Latest Oct 2, 2026
- Claude Developer Platform updates166 release notes · Latest Oct 1, 2026
- ChatGPT updates230 release notes · Latest Oct 2, 2026
- OpenAI updates240 release notes · Latest Oct 5, 2026
- Codex updates243 release notes · Latest Oct 6, 2026
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 30, 2026
2.1.286
Claude Code adds permission prompt counts, smoother list navigation, and major reliability fixes across login, sessions, MCP, subagents, plugins, cloud, and VS Code, while improving prompts, commit guidance, and background agent workflows.
Release notes
- Added a count such as "2 of 5" to the permission prompt when several permission requests stack up
- Added mouse support for the "N more" rows of lists in fullscreen mode: click one to jump to that end of the list, with hover and pressed states
- Fixed several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire
- Fixed
claude --resumeand--continuesometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed - Fixed API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions
- Fixed cloud sessions with very large histories never waking up because the container was stopped while the transcript was still loading
- Fixed the Claude apps gateway's spend meter pricing 1-hour prompt cache writes at the cheaper 5-minute rate, and counting only the first model call's input tokens on streamed turns that run a server-side tool such as web search
- Fixed macOS sessions still showing "Not logged in" or "Login expired" after
/loginsucceeds in another Claude Code window when a leftover~/.claude/.credentials.jsonexists - Fixed every turn failing when the Anthropic API refuses the model your default or a model alias resolves to: Claude Code now retries once on the previous model of the same tier
- Fixed Remote Control sessions (including
claude remote-control) staying connected after your organization's policy turns Remote Control off; they now disconnect with a notice - Fixed refusal and
--fallback-modelretries failing when the fallback model can't run fast; they now run at standard speed, with a one-time notice in interactive sessions - Fixed headless sessions repeating the "MCP servers require authentication" reminder after a successful re-authentication when the MCP discovery cache is enabled
- Fixed
claude auth statusreporting a Console sign-in's stored API key asclaude.ai; it now reportsapi_key, and the VS Code extension treats that session as an API key session - Fixed
/statuslisting an Anthropic profile beside an API key as if both were in effect; the profile is now marked as not in use - Fixed Claude not being told when a file attached to a message sent over Remote Control did not arrive, and a file sometimes getting only 10 seconds for its last download try
- Fixed a Remote Control message that arrived while Claude Code was exiting being marked delivered and then never answered; it now stays queued for the session's next run
- Fixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name
- Fixed percent-encoded Bearer tokens being only partly masked in error messages
- Fixed redacted logs and transcripts showing a secret whose key name has an invisible character inside, such as a zero-width space
- Fixed logs and transcripts showing part of a URL password that contains punctuation such as
), quotes,],&or a second@, or that runs past a/to a bracketed host such as[::1]in an ssh URL - Fixed the session transcript in the zip that
/feedbacksaves to disk containing invalid JSON lines after secret redaction - Fixed MCP connectors listing no tools for up to a day after their server dropped the older MCP handshake
- Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working
- Fixed
/usagenot crediting an MCP server for a tool call made while that server was still connecting or had only just connected, such as right after a restart - Fixed plugins enabled on claude.ai occasionally going missing from Claude Code for a session after a transient server error
- Fixed a message typed into a running subagent showing twice in its transcript after the subagent read it
- Fixed subagent hand-back messages showing a raw task id instead of the agent's name when the subagent had no registered name
- Fixed foreground subagents sometimes missing the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions that have them enabled
- Fixed subagents spawned with worktree isolation loading the project CLAUDE.md and its imports a second time from the worktree copy on their first file read
- Fixed Workflow tool subagents being restarted from their original prompt when a connection stalled for a few minutes mid-response
- Fixed
/compact,/clear, and/rewindtyped while viewing a background agent's or teammate's transcript silently acting on the main conversation: a dialog now names the target and asks first - Fixed background jobs showing done while waiting for your approval
- Fixed the commit attribution reminder being re-sent inside tool output when a model fallback lasts only one turn
- Fixed a click on the space between words of a collapsed row (such as "Thought for 4s") highlighting the row without expanding it in fullscreen mode
- Fixed a row with no details, such as an action row with a long name, pushing every other row's details to the right in list screens
- Fixed files with very long names not reaching a cloud session when attached to it
- Fixed plugin errors for a marketplace Claude Code refuses to load: they now say why and how to fix it instead of "not found"
- Fixed
/plugin's Discover tab showing a marketplace name unquoted in its "Checking 00for new plugins" line when its rows already show that name in quotes - Improved commit guidance: when your project or user skills include one named
verify, Claude is now told to run it right before committing, except for docs-only and tests-only commits - Improved send now (ctrl+enter) in a subagent's view: it now moves the subagent's running command to the background so your message is read right away
- Improved replies from background agents to your messages so they no longer open with a separate recap of what you said
- Improved claude.ai artifact link reads: WebFetch now asks the same questions as the Artifact tool's read (no artifact prompt while the session's network access is on, one per artifact while it is off), and an auto-mode yes no longer counts where only you can answer
- Improved fetch, skill, file read, sandbox network, Claude in Chrome, workflow script and notebook edit permission prompts to match the look of file edit prompts
- Improved Bash, PowerShell and Monitor permission prompts to show the command between dashed lines, matching file edit prompts
- Improved list scrollbars in fullscreen mode: in most lists the bar no longer shifts as the "N more" rows come and go, and it now has 11 arrows you can click or hold to scroll
- Improved the external editor (Ctrl+G): editors that take a line number now open on the line your cursor is on in the prompt
- Improved slash command suggestion responsiveness while typing when many skills or plugin commands are installed; command descriptions now match by word prefix
- Improved the output style picker: it now opens on your current style instead of Default, with each style's description on the line under its name; number keys no longer pick a style
- Improved
/hooks: the closing line of a hook's detail screen now says "this hook" instead of "it" - Improved the model fallback notice and the autocompact-thrashing error to say when a fallback dropped the context window from 1M to 200K tokens
- Improved responsiveness of SDK and
-psessions when a host re-sends an MCP server enable for a server that is already connected - Improved the protocol page a Claude apps gateway serves at
/protocol: it now says not to reject unknown input and matches what Claude Code sends today - Changed prompts sent while nothing is running or queued to show in the normal text color right away instead of gray
- Changed how failed API requests are retried: one limit now covers a whole model call, so with the default retry settings a failing call sends at most 14 requests
- Changed
--bareto connect only the MCP servers named on the command line, send the model no system reminders, and start no background tasks; under--bare, a shell command that reaches its timeout now stops instead of moving to the background - Changed the send-now key (ctrl+enter) to move a skill's own shell command to the background instead of ending it
- Changed the WebFetch error for a rate-limited domain safety check to tell Claude not to retry it in a loop
- Changed plugin installs to refuse npm sources that are git repositories or folders, and to install plugin dependencies only from registry packages
- Changed list screens (
/artifacts,/mcp,/skills,/hooksand others) to always line up each row's details in one column after the names - Changed the overflow rows of lists to read "1 N more" / "1 N more" instead of "N more above" / "N more below"
- Changed
/hooksto open on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three - Changed the theme picker to a scrolling list that fits your terminal instead of pushing the preview off screen; number keys no longer pick a theme
- Changed
/exit's Remove worktree to run after Claude Code stops the servers and shells it started there, which on Windows could keep the folder from being deleted - Changed the
claude-apiskill's Managed Agents examples to create environments with limited networking - Removed the browser link from
/ultrareviewandclaude ultrareviewoutput - Windows: Fixed
claude --bgand the agents view refusing a folder thatclaudealready trusts when its trust record was saved with different letter case - [VSCode] Added bookmarks: save Claude's responses and keep them in view in a Bookmarks side panel
- [VSCode] Added the questions Claude asks and your answers to the conversation: after you answer a question card, a Questions row shows each question with your picks
- [VSCode] Added option previews to question cards in the chat panel: the highlighted choice's mockup or snippet shows beside or under the options
- [VSCode] Added rows under a message that open to the terminal output, browser tab, browser instructions and selected code sent with it
- [VSCode] Fixed a second copy of a conversation opening in a tab when it was already open in the side bar; the side bar now switches to it
- [VSCode] Fixed settings dialogs reporting a failed save, without re-checking, when Claude Code printed more than 1 MB of output
- [VSCode] Fixed an endless "Teleporting session00 spinner when the extension stops responding
- [VSCode] Improved the Manage plugins dialog: it says when a turned-off plugin is still on because of other settings, and explains a plugin folder clash
- [VSCode] Changed Stop and Escape to end only the current turn; background agents keep running and can be stopped one by one from the agent map
- [VSCode] Changed the "7 Claude Code" status bar item to show in every window, so you can open Claude when no file is open
- [Cloud sessions] Fixed an answered question card or approved tool call getting no reply when the session had gone idle after Claude sent a message
- [Cloud sessions] Fixed clearing an organization environment's setup script in admin settings leaving new cloud sessions still running the old script
- [Cloud sessions] Fixed the Runner actions menu on the self-hosted environments admin page closing on its own a few seconds after it opened
- [Cloud sessions] Fixed routine runs whose cloud session never started showing as Succeeded in the Runs pane, the routine's page and the sidebar; they now show as Failed
- [Cloud sessions] Fixed clicking an audio or video file in a cloud session's Outputs card opening an empty file search instead of playing the file
- [Cloud sessions] Changed a routine's page to read "Due" with the scheduled time, instead of a next run time in the past, when a scheduled run is late and hasn't started
- [Claude Tag] Added an Add channel button to Claude Tag's spend limits page in admin settings, so a limit can be set on any channel, including a private one, from its channel ID or Slack link
- [Claude Tag] Fixed memory recall finding nothing in organizations that cannot use the default Sonnet model
- [Claude Tag] Fixed a Slack channel losing its Claude settings when an Enterprise Grid admin moves it to another workspace and the first post afterward doesn't mention Claude
- [Claude Tag] Fixed Claude in a Slack thread occasionally starting over on a fresh machine, losing work it hadn't pushed, when your reply answered a question it had just asked
- [Claude Tag] Fixed public channel names on Claude Tag's spend limits page in admin settings showing as raw Slack IDs in larger organizations
- [Claude Tag] Improved the titles of sessions started from Slack as shown on claude.ai: they now read as the words you typed, without Slack user IDs or escape codes
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 29, 2026
2.1.285
Claude Code releases a broad update with new desktop, plugin, MCP, and environment controls, plus improved VSCode and web experiences. It also adds stronger model, task, and artifact workflows while fixing many session, permissions, remote control, and platform issues across desktop, web, Slack, and code review.
- Added
CLAUDE_CODE_DISABLE_WEB_FETCHenvironment variable to turn off the WebFetch tool - Added
claude --desktopto open the Claude desktop app on the current directory, or on a session with--continue/--resume <id> - Added
claude plugin configure <plugin>to show a plugin's options and which are unset, or save new values read from stdin with--values-stdin - Added
<server>.<key>=<value>toclaude plugin install --config, so a bundled.mcpbMCP server's own settings can be set at install time and it starts without visiting/plugin
Configure
- Added
allowedProvidersmanaged setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway) - Added
CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIESenvironment variable to cap re-sends of a non-streaming fallback request that timed out - Fixed
claude -pwithCLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result - Fixed plugin and marketplace installs and updates over SSH ignoring the ssh program set in
GIT_SSHor in your git config'score.sshCommand - Fixed Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file's policies. Other read errors and unparseable files stop every session
- Fixed cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published
- Fixed
claude plugin disableandenablewith a fullname@marketplaceid changing a settings entry in another letter case instead of the installed plugin's own - Fixed files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice
- Fixed switching models mid-session with a
set_modelrequest (such as the Agent SDK'ssetModel) leaving the new model on the built-in output-token limit and auto-compact window until restart - Fixed redacted logs and transcripts showing part of a URL password that contains
@, or all of it when the URL writes its@as%40 - Fixed SSH passphrase and new-host prompts from worktree and
/teleportfetches taking over the terminal; these fetches now fail fast instead of asking - Fixed switching off an MCP server added mid-session in SDK and
-psessions leaving its tools available - Fixed
claude -p --permission-prompt-tool: a background subagent's permission request now goes to the prompt tool instead of being auto-denied - Fixed
claude mcp listandclaude mcp get, and the not-found error ofclaude mcp remove,loginandlogout, printing line breaks and terminal escape sequences from MCP server names and values - Fixed sandbox auto-allow asking for approval on every run of many inline scripts (
python3 -c,node -e) just because they contain= - Fixed fork subagents not keeping the session's plan mode or
dontAskmode: a fork now runs under its parent's permission mode and cannot exit plan mode - Fixed
claude remote-control --helpsaying--[no-]chromedefaults to the machine's/chromesetting; spawned sessions keep Claude in Chrome off unless--chromeis passed - Fixed background subagents in auto mode prompting a second, redundant reply after each report
- Fixed cloud session creation and
/remote-envreading only the newest 20 of an account's environments - Fixed Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume)
- Fixed installing a plugin with
claude plugin installor/pluginputting it into an installed plugin's cache or data folder when their ids differ only in.,-,@or (macOS, Windows) capitals; the install is now refused - Fixed hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response
- Fixed the first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283
- Fixed sessions that authenticate with
ANTHROPIC_AUTH_TOKENagainst the Anthropic API never loading the organization's policy - Fixed a failed
agent(),parallel()orpipeline()call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session - Fixed synchronous hooks hanging Claude Code while a background process the hook started (for example
some-daemon &) kept its output open; the hook now finishes shortly after its own process exits - Fixed WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block
- Fixed the fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish
- Fixed Amazon Bedrock mid-stream
modelTimeoutExceptionandserviceUnavailableExceptionerrors showing a raw JSON body instead of the error message - Fixed
/autofix-prand/schedulesaying the Claude GitHub App is not installed on a repository whose install status had not been checked yet - Fixed dismissing a row (x) in
/artifactsunlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it - Fixed Artifact tool publishes after a conversation rewind (Esc Esc) overwriting a file's newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file
- Fixed an
Artifactallow rule ("don't ask again") letting the Artifact tool publish a file outside the working directories without asking; add the file's folder with--add-dirfor the rule to cover it - Fixed
/costand SDKmodelUsagereporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected - Fixed the Artifact tool so that publishing a page no longer lets Claude overwrite its source file without re-reading it when Claude's earlier read was cut short or the file had changed since
- Fixed auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else's artifact when you had approved that artifact earlier in another permission mode
- Fixed a misleading "core.worktree is set" error from
/ultrareviewwhen the project folder briefly could not be read - Fixed
/ultrareviewon macOS and Linux failing to upload the working tree from a git worktree whose per-worktree config setscore.longpaths - Fixed the Artifact tool sometimes reporting a publish as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded
- Fixed
/ultrareviewuploads including uncommitted changes to credential files whose name has a colon before the extension, such asserver:8443.key - Fixed a rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time
- Fixed the PowerShell tool's permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory)
- Fixed
/ultrareviewuploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks - Fixed a cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up
- Fixed vim mode: after editing in the external editor (Ctrl+G),
xorrin NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt - Fixed responses blocked by the API's output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter's error right away
- Fixed plugins silently skipping a bundled
.mcpbMCP server that still needs configuration:/plugin, the install message andclaude plugin installnow say so and point to Configure - Fixed compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields
- WSL: Fixed
/ultrareviewrefusing to upload a checkout on a Linux volume when a changed file's name has a colon or ends in a dot or space - Fixed the Artifact tool missing from Remote Control sessions that
claude remote-controlstarts for you to open from Claude Desktop, claude.ai or the mobile app - Fixed macOS credential writes dropping stored MCP OAuth tokens or deleting the keychain entry when the login keychain was locked (e.g. right after wake)
- Fixed
gcpAuthRefresh/awsAuthRefreshlogin processes being left running (and holding their localhost callback port on Windows) when Claude Code exits or the refresh times out - Fixed the "Not logged in Run /login" footer and missing claude.ai connectors persisting in a session after logging in from another Claude Code process
- Fixed
mcp_toolhooks on blocking events (PreToolUse and similar) being skipped while their MCP server was still connecting; they now wait for it, up to the MCP connect timeout - Fixed the same MCP server being connected twice when a plugin or claude.ai connector and a configured server spell its URL differently (host letter case, default port, trailing slash)
- Fixed
MCP_CONNECTION_NONBLOCKING=0giving up on claude.ai connectors after 1s instead of honoringMCP_CONNECT_TIMEOUT_MS - Fixed
--channelsplugin entries being checked against the installed plugin's marketplace alone; the installed plugin's name must now match the entry as well - Fixed
--plugin-diron a folder of plugins that also has a.claude-plugin/marketplace.jsonloading one empty plugin instead of the plugins in it - Fixed
claude plugin uninstallrefusing to remove a project-scope plugin that isn't enabled, saying it is "enabled at project scope" whileclaude plugin disablesays it is already disabled - Fixed
claude plugin updatefailing for project-scoped plugins when--scopeis omitted
Configure
- it now resolves the scope the plugin is installed at instead of assuming user
- Fixed
claude plugin validatereportingprivacyPolicyUrl,supportUrland other listing metadata keys in plugin.json as unknown fields - Fixed
known_marketplaces.jsonrecording a marketplace as refreshed when its remote could not be reached andCLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILUREkept the existing clone - Fixed the
/pluginErrors tab showing no confirmation after its last error is resolved - Fixed
/pluginstarting a second uninstall or update of the same plugin when Enter was pressed again while the first was still running - Fixed a
yheld while/pluginchecks a marketplace source adding the marketplace the instant the "Add marketplace?" question appears, before it can be read - Fixed
1answering Yes in/permissions' delete and remove-directory confirms while the pointer is on No, which let a held1remove one workspace directory after another - Fixed Alt+T and
/configoffering to turn thinking off on models that can't; thinking now stays on there, with a one-line reason in place of the switch - Fixed a rebound agent panel close key (
footer:close) typing "x" instead of itself on the row of the agent you're viewing - Fixed a doubled
separator in the/tasksdialog footer when the stop-all-agents shortcut is unbound inkeybindings.json - Fixed artifact publishes failing when Claude gave the version a label longer than 60 characters; the label is now shortened
- Fixed screen-reader mode, quoted lists and very long lists dropping the blank lines at the top of a code block that opens a list item, directly or inside a quote
- Fixed PDF page-read error messages: paths with accented or non-Latin characters now appear readably, and a folder named like "password" or "invalid" can no longer make the error name the wrong cause
- Fixed vim mode
>>indenting empty lines,rwith a count longer than the line changing text,2Jjoining one line too many, and a count on the last line (2dd,2>>) shifting or deleting it - Fixed vim mode cursor placement: after
dd,dj,dGor a whole-linep/Pit lands on the first non-blank,yyno longer moves it, and Esc after an emoji no longer leaves it inside the emoji - Fixed vim mode ignoring a count typed before
.when repeatingx,s,p,dorc, and whole-linep/P,o,O,J,>>and<<acting on the wrong line when a line above wraps - Fixed vim mode leaving the cursor past the end of a prompt recalled from history or pulled back from the queue in normal mode, so
xdid nothing - Windows: Fixed the PowerShell tool letting
cmd /c rd,rmdir,delorerasedelete drive roots, the home folder and other folders thatRemove-Itemrefuses - Improved the
/mcptool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon - Improved MCP tool results: images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them
- Improved
/tasks: rows show a status icon, the name and whole facts, the title and key hints stay on screen with many tasks, and the list gains paging keys, the mouse wheel and clicks - Improved lists in
/help,/hooks,/copy,/chrome,/memory,/ide,/release-notes,/rewind,/diff,/remote-env,/pluginand other pickers with page keys, mouse wheel and clicks - Improved lists beside a search box, such as
/skillsand/artifacts, to draw their pointer dim while the search box has the keys, so only one pointer is highlighted - Improved artifact pages: Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title
- Improved
/ultrareviewuploads: renamed copies of key files, such asid_rsa copyorkubeconfig (1).yaml, now also stay on your machine - Improved the cross-session messaging startup warning to explain that
--debug-filewrites a debug log to a path you choose - Changed the default model on Pro and Team Standard plans from Sonnet to Opus, matching Max, Team Premium, and Enterprise
- Changed an effort level saved before
/effortbecame per-model to no longer apply to newly released models such as Opus 5.5; they start at their default until you pick a level - Changed Opus 4.7, Opus 4.8 and Fable 5 to stop holding their launch-default effort over
/effortin-por the Agent SDK, a project, managed or--settingseffortLevel, or a per-model level - Changed
/autocompact's footer hint to name 1/1, the keys that adjust other ordered values - Changed
/fast's footer to name Space as the toggle key - Self-hosted runner: Changed git in lifecycle hooks to skip a repository's Git LFS
pre-pushhook, ignore a writable systemcore.hooksPath, and not sign commits without--configure-git - Changed plugin marketplaces whose name imitates a reserved marketplace name to be refused when added, and to stop loading if one was already added
- Changed
PermissionRequesthooks: an agent-type hook no longer runs there, since its answer could never allow or deny the request; it now shows an error pointing to command or http hooks - [VSCode] Added a Status dialog, with a typed
/status, showing the session's version, account, model and server details - [VSCode] Added a Sandbox dialog for the sandbox mode, the unsandboxed fallback and excluded commands, opened from the panel menu or by typing
/sandbox - [VSCode] Added a Claude in Chrome dialog (extension status, the install, reconnect and permissions pages, the enabled-by-default setting), opened from the panel menu or by typing
/chrome - [VSCode] Added Export conversation, with a typed
/export, to copy or save the conversation as plain text - [VSCode] Added each skill's source, token estimate and on/off state to the Slash commands dialog, with a click to change the state, and a typed
/skillsthat opens it - [VSCode] Added a typed
/planthat switches to plan mode, sends a first planning prompt, or shows the session's plan - [VSCode] Improved pasted-text handling in the chat box: a paste over 800 characters or over 2 line breaks is now marked so Claude can tell it from what you typed
- [VSCode] Improved prompt handling in the chat box: invisible Unicode formatting and tag characters are removed from pasted text with a notice, and from anything else before it is sent
- [VSCode] Changed "Open in New Tab" to open Claude beside the editor group you are working in rather than after the last group
- [VSCode] Fixed the effort chip showing a stale saved effort level instead of the level the session runs at
- [VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as "Sonnet"
- [VSCode] Fixed
/fastnot saving fast mode as the default, so it was lost when the extension relaunched Claude Code - [Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization
- [Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings
Cloud environments
- [Claude Code on the web] Fixed cloud environments with a very long allowed-domains list saving fine and then failing every session start; saving now fails up front and says how much to trim
- [Claude Code on the web] Fixed Claude's guidance when a cloud session on a personal account is denied GitHub access: it now links to claude.ai/connect-github instead of an admin settings page
- [Claude Code on the web] Improved what Claude tells you when asked to edit, delete or run a routine it didn't create: it now links to the routine's page so you can do it yourself
- [Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran
- [Claude Tag] Fixed replying in an older Slack thread while Claude is mid-task sometimes restarting it from scratch and losing work it had not pushed yet
- [Claude Tag] Fixed Claude occasionally dropping a message with an incorrect "couldn't find a Claude Code environment" notice right after your account token refreshed
- [Claude Tag] Fixed AWS connections refusing region-less endpoints such as Budgets, Savings Plans, WAF Classic and Import/Export; Global Accelerator requests now sign correctly
- [Claude Tag] Fixed OAuth client-credentials and JWT-bearer connections failing with providers that return a lowercase token type; requests now send the standard Bearer scheme
- [Claude Tag] Fixed adding a channel manager being refused on Enterprise Grid shared channels, on channels where Claude hasn't been used yet, and on legacy private channels
- [Claude Tag] Changed Claude to start watching related public channels on its own, such as an incident channel a conversation depends on, instead of only when asked
- [Claude Tag] Fixed the admin Memory page not listing Slack channels Claude set up on its own even when they had saved memory; admins can now open, edit and delete that memory
- [Code Review] Added a note under the still-open findings list in follow-up reviews: resolving a finding's thread, not just replying to it, stops later reviews from counting it as open
- [Code Review] Fixed reviews sometimes ending as incomplete when one of the agents verifying a finding failed midway; the review now replaces that agent and reaches a verdict
- [Code Review] Fixed a push-triggered review that was queued behind a running review still posting after the pull request had been converted to draft
- [Code Review] Fixed reviews ignoring a directory's CLAUDE.md conventions when the PR edited a root file (e.g. README.md) that only shares a name with a file that CLAUDE.md lists
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 28, 2026
2.1.284
Claude Code adds Claude Sonnet 5.5 as the new default Sonnet model and brings major upgrades across usage, MCP, plugins, dialogs, and performance, while also fixing a wide range of session, terminal, and gateway issues for a smoother experience.
- Added Claude Sonnet 5.5 (
claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads - Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones
- Added dollar amounts to the Claude apps gateway spend limit in
/usageand the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line'srate_limits.spend_limitalso gainsused_usd,limit_usdandperiod - Added
effortSlider:decreaseEffort,increaseEffortandtoggleUltracodekeybinding actions, so the/effortslider's arrow and Tab keys can be rebound inkeybindings.json - Added
/rate-limit-optionsto/helpand the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find - Added
/mcp reconnect allin the interactive terminal to retry every MCP server that failed to connect or needs authentication at once - Added Claude apps gateway startup warnings when a managed policy's
availableModelsis empty, or leaves out the model Claude Code starts on without settingmodelorenforceAvailableModels - Added
auth: { google: {} }for Claude apps gatewaytelemetry.forward_todestinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials - Added certificate client authentication (
private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets - Fixed a damaged response stream showing raw errors such as "JSON Parse error" or "undefined is not an object", or writing the word "undefined" into an answer, instead of being retried or reported as an interrupted response
- Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried
- Fixed "Prompt is too long" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation
- Fixed a session whose model is unavailable, with no fallback model left, showing a bare "is currently unavailable" message (or "Something went wrong" in cloud sessions) instead of the model-unavailable notice and its Learn more link
- Fixed Agent SDK sessions crashing when a user message contains an image with a malformed
source, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note - Fixed MCP tool calls in a resumed session failing with "No such tool available" while their server was still connecting; the call now waits up to 10 seconds for the server
- Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login:
/usage,/extra-usageand IDE usage views now back off instead of re-asking - Fixed
claude mcp addreporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads - Fixed the
/pluginconfigure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs - Fixed
ANTHROPIC_FOUNDRY_RESOURCEbeing interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused - Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically
- Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt
- Fixed Bash tool failing on Windows with many plugins enabled: plugin
bin/directories that don't exist are no longer added to PATH, and inherited entries aren't added twice - Fixed
sparsePathsplugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present" - Fixed fullscreen rendering erasing the terminal output above the session when
[in transcript mode writes the conversation to scrollback (macOS and Linux) - Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up
- Fixed tab bars in dialogs such as
/configand/pluginbreaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole - Fixed the
/modelpicker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows - Fixed
/keybindingswriting Backspace and Delete bindings for a footer action that does nothing into the generatedkeybindings.json - Fixed a rebound agent panel close key (
footer:close) typing "x" instead of itself on the row of the agent you're viewing - Fixed vim mode
.not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such ascwthen Esc) - Fixed vim mode leaving the cursor on an image placeholder's opening bracket after
ddon the last line oryyat the end of the prompt, whererorxwould break or delete the image - Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted
- Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory
- Fixed rules symlinked into
.claude/rulesfrom outside the project being skipped without ever showing the external-imports approval prompt; a.claudedirectory symlinked from outside the project now asks for the same approval - Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via
allowed-toolsunder managedallowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval - Fixed a failed first
claude plugin installleaving the plugin enabled and recorded when a dependency's version range could not be met - Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code
- Fixed
{"decision":"block"}returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does - Fixed sessions launched without the
SendMessagetool (such as by Claude Desktop) still being told to message other sessions with it - Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption
- Fixed typing a message during an automatic usage-limit wait taking the wait out of the "Continue automatically at usage limit" setting's control when that turn hit the limit again
- Fixed usage-limit warnings suggesting
/upgradeto users already on the highest Max plan; the warnings and/upgradeitself now point at/usage-creditswhen it is available - Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model
- Fixed
/loopstatus updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text - Fixed
/ultrareviewfailing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux - Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory
- Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private
data/users/subtree, and added a "view" level toas_level - Fixed the Claude apps gateway answering
431 Request Header Fields Too Largeto every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB - Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown
- Improved the "No such tool available" error for Claude in Chrome tools called without their prefix: it now names the tool to call
- Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged "Waiting for N … to finish" line after every event
- Improved Workflow tool sandbox hardening for errors thrown by async script hooks
- Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use
- Improved
/claude-api:hillclimbno longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for besidereport.htmlis built as one local file that loads nothing from the network - Improved lists such as
/tasks,/copyand/hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edge - Improved lists beside a search box, such as
/skillsand/artifacts, to draw their pointer dim while the search box has the keys, so only one pointer is highlighted - Improved the compaction spinner: its timer now starts when compaction begins and it counts the summary's tokens as they stream, replacing the percentage bar
- Improved the browser page shown after signing in to an MCP server: centered layout, dark mode, and new artwork
- Improved the Skill tool's reply when a skill belongs to a plugin that failed to load, so Claude tells you the plugin could not be loaded instead of calling the skill uninstalled
- Improved
prompt-auditon Claude Code configuration: stale paths, stale commands and contradicting instruction files now lead the report, and thinking keywords that Claude Code documents are kept - Improved recovery from an
installed_plugins.jsonthat cannot be read at all: its contents are kept in a file beside it before it is rebuilt, andclaude plugin listnames that file - Improved artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest
- Improved first-reply latency: a pattern-compile step that ran at the end of a session's first reply now runs while the reply streams in
- Improved first-request latency by reusing the preconnected API connection
- Improved startup:
claude -pand Claude Code Remote no longer load the interactive UI, and the auto-mode classifier's rules and the Artifact tool load on first use instead of at launch - Improved startup for claude.ai accounts whose Artifact tool features aren't known yet, as on a first run: the prompt no longer waits up to 1.5 s to check them; the first message waits if needed
- Changed interactive sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured;
permissions.defaultModestill overrides it - Changed
/ultrareviewlaunch dialog to say that reviewing a local branch may upload uncommitted changes to tracked files - Changed the
/modelpicker's Opus row and the Default model's name to drop "(1M context)" where Opus already has a 1M context window; the window is unchanged - Changed prompt suggestions in the terminal to appear less often after 20 in a row go unused; using one brings them back
- Changed
--system-promptand--append-system-promptto accept their text and-fileforms together; the file's text comes first - Changed
Skill(anthropic-skills:<name>)deny rules to also block that skill when Claude Desktop delivers it as a plugin, andSkill(skill:<name>)denies to match the skill's alias and display name - Changed
/rewindand/difflists to move on the same keybinding actions as every other list (select:*);messageSelector:*/diff:*rebinds still work - Changed the
/workflowsrun list to size itself like other lists: half the terminal inline, and it keeps its title on screen when the prompt shows below - Changed
claude plugin evalto require git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version - Changed artifact watching: a watch that was armed automatically (not one you asked for) now ends after 3.5 hours with no activity; publishing or watching the artifact again re-arms it
- Changed the large CLAUDE.md startup notice to also count instruction files together, so many mid-sized files and @-imports are caught
- Changed debug logs to name settings
envvariables ignored because the session's launch environment already sets them - Changed keyboard navigation in tabbed dialogs such as
/permissionsand/usage: ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus - Changed
/helpand/sandbox: ←/→ and Tab switch tabs from inside a tab's list, and ↓ on an empty Custom commands tab in/helpno longer leaves the keys stuck until Esc - Changed
/install-github-app,/desktop, the/permissionsauto mode environment prompts, and the/plugin"Add marketplace?" and "Run this command?" prompts: they now use the standard dialog frame with key hints, and Ctrl+C or Ctrl+D cancels them on the second press like other dialogs - Changed the
/workflowsand/mcplists: they page (PgUp/PgDn, Home/End) and take j/k and the mouse like other lists, their arrows followselect:previous/select:nextrebinds, andxin/workflowsstops the run the pointer is on - Changed the background workflow row below the prompt: it now shows the name, a progress bar, the agent count on wide terminals, elapsed time, total tokens, and the large-workflow warning
- Changed the /plugin Installed list: rows now line up in columns (status, name, type, details) across every section
- Changed
/skills: each row now leads with the skill's name, with ✔ or ◯ alone showing on or off, and stays on one line in narrow terminals - Changed narrow list rows (
/skills,/workflows,/feedback): a name keeps 20 columns beside its first detail, and details are shown whole or not at all - Changed
/diff: a scrollbar shows where you are in a long list of changed files, and long paths no longer wrap their rows - Changed
/hooks: a hook's detail screen now says what kind of hook it is and where to change it, instead of always pointing at settings.json, and the hooks-disabled, safe mode and managed-hooks-only notices each say what is happening in one plain sentence - Changed the terminal cursor jumping from the
/skillssearch box to the skill list while typing, which could hide the caret and put IME input in the wrong place - Changed
/pluginstarting a second uninstall or update of the same plugin when Enter was pressed again while the first was still running - Changed a
yheld while/pluginchecks a marketplace source adding the marketplace the instant the "Add marketplace?" question appears, before it can be read - Changed Alt+T and
/configoffering to turn thinking off on models that can't; thinking now stays on there, with a one-line reason in place of the switch - Changed
/contexttotal leaving out messages added since the last response; it now matches its categories and can read higher than the status line - Changed
/modelshowing the raw API error JSON and request ID when the API refuses the picked model; it now shows the server's message and says the model was not changed - Changed API errors from an HTML error page (such as a proxy's 429 or 502 page) printing the page's raw markup or leaving out the HTTP status, and error messages breaking onto a second line when the server's error text ended in a newline
- Changed
/feedback,/bugand/sharestill sending your report after you cancelled it while it was being sent - Changed
/feedback,/bugand/sharefailing every send with "Couldn't send feedback" after a Remote Control Stop arrived while the dialog was open - Changed
/ideshowing "No available IDEs detected" while also listing a running IDE - Changed the terminal being left in a broken state (crash or garbled input) when
/setup-bedrockor/setup-vertexrestarts Claude Code to apply new settings - Changed
/configexiting whenrespectGitignoreorcopyFullResponsein~/.claude.jsonholdsnull - Changed the session name from /rename disappearing while Claude asks a multiple-choice question, so side-by-side sessions stay identifiable
- Changed one-line pastes showing on their own lines in the sent message for prompts from VS Code or Remote Control and for expanded paste placeholders
- Changed
/pluginInstalled and/skillscrashing when a skill or legacy command is named like a built-in Object property such asconstructorortoString - Changed
/pluginclosing with no message when every install in a multi-select failed - Changed uninstalled plugins reappearing as "failed to load" rows in
/pluginInstalled, and Remove not clearing such a row - Changed plugins from the official marketplace being recorded without their commit in
installed_plugins.json, andinstalled_plugins.jsonkeeping the old commit after updating a pinned-commit plugin - Changed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached
--plugin-urlarchive a reload falls back to when its download fails - Changed Remote Control attachment downloads to reuse connections and to skip files already downloaded in the session
- Changed MCP resource lists (the resource list tool and @-mention suggestions) to skip MCP Apps UI resources; reading one by URI still works
- Changed
claude plugin uninstall --jsonand the /plugin dialog to say a plugin's data was kept when its folder stays because another installed plugin uses it or install records cannot be read - Changed the background tasks list (
/tasks): pressingxon a running/ultrareviewnow asks for confirmation before stopping the review - Changed the leftover "(removed)"
/agentsentry from the command menu and/help; typing/agentsstill explains where the wizard went - [VSCode] Added a Continue/Stop prompt in the VS Code and JetBrains panels when auto mode falls back to billed classifier requests, replacing the unanswerable warning line
- [VSCode] Fixed opening a Web session with no messages saving an empty local copy that could not be resumed; an error now says where to continue it
- [VSCode] Fixed conversations in editor tabs hanging silently after the extension host restarts; the tab now tells you to reopen it from the session list
- [VSCode] Fixed Claude attaching option previews to multiple-choice questions in the chat panel, where the question card never shows them
- [VSCode] Fixed the session manager's cost and usage block wrapping mid-text on a narrow side bar, and showing totals from a previous login after an account switch
- [Claude Code on the web] Added a Continue/Stop prompt in the chat panel when auto mode falls back to billed classifier requests
- [Claude Code on the web] Added a "New routine" button to the page shown when a routine link no longer resolves, next to the link back to your routines list
- [Claude Code on the web] Fixed cloud sessions running longer than about six hours silently losing files saved to persisted session folders; saves now persist for up to a day
- [Claude Code on the web] Fixed "Invalid effort level" errors when a routine resumes a session, or a session starts with no set effort, in orgs where an admin caps a model's effort
- [Claude Code on the web] Improved routine creation from a conversation: when the new routine has no connectors, Claude now says so and how to add them instead of only confirming it
- [Claude Tag] Added a confirmation dialog before Connect all or Disconnect on a GitHub installation in admin settings, to guard against accidental organization-wide changes
- [Claude Tag] Fixed threads occasionally going silent after a failed turn because the failure notice was dropped when Slack briefly rate-limited it; the notice is now retried
- [Claude Tag] Fixed Claude accepting a switch to a model your organization hasn't enabled and then quietly answering with a fallback model; it now declines and says an admin can enable it
- [Claude Tag] Fixed a table posting as raw pipe text when Claude attached files to the same message; the table now posts as a normal reply and the files follow with a plain caption
- [Claude Tag] Fixed
@Claude !restartat the top level of a channel where Claude isn't active starting an unrelated conversation; it now privately says there is nothing to restart - [Claude Tag] Fixed plugin rows in Slack access settings showing an unlabeled raw ID with no way to turn the plugin off; they now show its name and link to the bundle that manages it
- [Claude Tag] Fixed the shared-session banner and Share dialog on sessions started from Slack claiming the whole organization could open the link; they now name the Slack channel's audience
- [Claude Tag] Improved load time of the admin settings page and its Slack channel picker, most noticeably for organizations with many channels or several connected workspaces
- [Claude Tag] Improved scheduled routines in Slack channels: a routine run can now reply in an existing thread instead of always posting a new top-level channel message
- [Claude Tag] Improved the timestamp on Claude's live progress checklists to show each reader's local time and how long ago it was updated, instead of a fixed UTC time
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 25, 2026
2.1.283
Claude Code adds broader gateway, MCP, plugin, workflow, and /doctor audit controls, plus faster startup and latency improvements, richer list and terminal navigation, and many fixes across sessions, models, sandboxing, Windows, VS Code, cloud, and Claude Tag.
Changes
- Added
x-claude-code-prompt-idto the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in withCLAUDE_CODE_GATEWAY_HINT_HEADERS=1 - Added
availableModelsMatchmanaged setting: with"exact", anavailableModelsentry allows only the model version it names, so new releases stay blocked until listed - Added
deniedModelsmanaged setting to block specific models, even whenavailableModelsallows them - Added MCP tool, WebFetch and WebSearch outputs to the
tool.outputOpenTelemetry span event whenOTEL_LOG_TOOL_CONTENT=1 - Added
/doctor prompt-audit(also/checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models - Added click-to-expand for truncated messages from your other sessions in fullscreen mode
- Added
pathto--plugin-dirload-failure entries in the stream-jsonsystem/initplugin_errors, naming the directory that did not load - Added an opt-in
load_test_modeblock to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested - Added a
mantleupstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint - Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's
result.usage - Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress
- Fixed stdio MCP servers being left running when the session ended while they were still starting
- Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected
- Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error;
/mcpno longer offers Authenticate for such servers - Fixed the weekly Fable limit not appearing in
/usageand the VS Code usage meters when telemetry is disabled - Fixed
/modelaccepting Sonnet 4.6 or Sonnet 5 with[1m]when the id carried a date or-v1:0suffix, in the cases where the plain id was refused - Fixed
/modelpicker showing a hardcoded Haiku version and price whenANTHROPIC_DEFAULT_HAIKU_MODELpins a different model - Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model
- Fixed
DISABLE_PROMPT_CACHING_HAIKUhaving no effect when Haiku is the session's main model - Fixed
claude plugin validatesaying Claude Code accepts a plugin or marketplace name it cannot install; such names inmarketplace.jsonnow fail validation - Fixed
claude plugin validatepassing plugins whoseoutputStyles,themes,monitors, orlspServerspaths are missing or point outside the plugin directory - Fixed
claude plugin detailsshowing 0 MCP servers for plugins that declare their servers inplugin.json - Fixed
claude plugin marketplace removenot saying which installed plugins it uninstalled with the marketplace; it now lists them - Fixed
claude plugin uninstallremoving the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had noenabledPluginsentry at that scope - Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing
- Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers
- Fixed
installed_plugins.jsonshowing no plugins when it holds a record under an invalid plugin id; such a file loads again - Fixed
installed_plugins.jsonbeing rewritten, losing records, when it holds a record this version cannot read;claude plugincommands now name the record and say how to recover - Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text
- Fixed
/contextnot counting MCP server instructions: they now appear as their own row and count toward the total - Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks
- Fixed
claude mcp add,add-json, andremovereporting success when the user or local config file could not be written, for example inside a sandbox - Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them
- Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling
cmdan alias ofmeta, which could producecmd+shortcuts most terminals never send - Fixed
keybindings.jsonsilently accepting a misspelled modifier such asctl+k; it now warns in the debug log and suggests the fix - Fixed footer hints still saying "Enter to view" after
footer:openSelectedwas rebound or unbound inkeybindings.json - Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state
- Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as
GIT_CONFIG_COUNTenvironment pairs - Fixed sandboxed
gitasking credential helpers to store the sandbox proxy's login, which printed "failed to store" - Fixed managed
sandboxsettings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies - Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository
- Fixed Remote Control being unavailable on paid plans when telemetry is turned off with
DISABLE_TELEMETRYorDO_NOT_TRACK - Fixed the
/remote-controlmenu cutting its QR-code hint mid-word in narrow terminals - Fixed vim mode
.dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after3Jor Visual-modeJon the last line - Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and
Vthenpnow lands on the first non-blank - Fixed vim mode
Jjoining lines with different spacing than Vim (such as a space before)or after a tab), and3Jor Visual-modeJon the last line not moving the cursor as Vim does - Windows: Fixed the PowerShell tool letting
cmd /c rd,rmdir,delorerasedelete drive roots, the home folder and other folders thatRemove-Itemrefuses - Improved the
/mcptool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon - Improved MCP tool results: images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them
- Improved
/tasks: rows show a status icon, the name and whole facts, the title and key hints stay on screen with many tasks, and the list gains paging keys, the mouse wheel and clicks - Improved lists in
/help,/hooks,/copy,/chrome,/memory,/ide,/release-notes,/rewind,/diff,/remote-env,/pluginand other pickers with page keys, mouse wheel and clicks - Improved lists beside a search box, such as
/skillsand/artifacts, to draw their pointer dim while the search box has the keys, so only one pointer is highlighted - Improved the compaction spinner: its timer now starts when compaction begins and it counts the summary's tokens as they stream, replacing the percentage bar
- Improved the browser page shown after signing in to an MCP server: centered layout, dark mode, and new artwork
- Improved the Skill tool's reply when a skill belongs to a plugin that failed to load, so Claude tells you the plugin could not be loaded instead of calling the skill uninstalled
- Improved
prompt-auditon Claude Code configuration: stale paths, stale commands and contradicting instruction files now lead the report, and thinking keywords that Claude Code documents are kept - Improved recovery from an
installed_plugins.jsonthat cannot be read at all: its contents are kept in a file beside it before it is rebuilt, andclaude plugin listnames that file - Improved artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest
- Improved first-reply latency: a pattern-compile step that ran at the end of a session's first reply now runs while the reply streams in
- Improved first-request latency by reusing the preconnected API connection
- Improved startup:
claude -pand Claude Code Remote no longer load the interactive UI, and the auto-mode classifier's rules and the Artifact tool load on first use instead of at launch - Improved startup for claude.ai accounts whose Artifact tool features aren't known yet, as on a first run: the prompt no longer waits up to 1.5 s to check them; the first message waits if needed
- Changed interactive sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured;
permissions.defaultModestill overrides it - Changed the
/ultrareviewlaunch dialog to say that reviewing a local branch may upload uncommitted changes to tracked files - Changed the
/modelpicker's Opus row and the Default model's name to drop "(1M context)" where Opus already has a 1M context window; the window is unchanged - Changed prompt suggestions in the terminal to appear less often after 20 in a row go unused; using one brings them back
- Changed
--system-promptand--append-system-promptto accept their text and-fileforms together; the file's text comes first - Changed
Skill(anthropic-skills:<name>)deny rules to also block that skill when Claude Desktop delivers it as a plugin, andSkill(skill:<name>)denies to match the skill's alias and display name - Changed
/rewindand/difflists to move on the same keybinding actions as every other list (select:*);messageSelector:*/diff:*rebinds still work - Changed the
/workflowsrun list to size itself like other lists: half the terminal inline, and it keeps its title on screen when the prompt shows below - Changed
claude plugin evalto require git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version - Changed artifact watching: a watch that was armed automatically (not one you asked for) now ends after 3.5 hours with no activity; publishing or watching the artifact again re-arms it
- Changed the error shown on Windows when a session can't be resumed because its transcript file could not be read (EBADF): it now names possible causes and what to try
- Improved the Claude Desktop unknown-model error to suggest switching to a different model
- Improved rendering of unusual Unicode in permission prompts
- Improved
/artifacts: titles line up in one column, details are dropped whole instead of cut mid-word, and the list supports PgUp/PgDn, Home/End, the mouse wheel and clicks - Improved the
claude-apiskill: pre-output refusal billing now links to the How refusals are billed docs, mid-stream refusals bill at normal rates, and pre-output refusals count against rate limits - Updated the
claude-apiskill to recommendant applyfor keeping Managed Agents resources as version-controlled files - Changed auto mode to use the server-side classifier by default on a direct Anthropic API connection when telemetry is off (
CLAUDE_CODE_AUTO_MODE_SERVER=0opts out) - Changed
sandbox.excludedCommandsto ignore project and local settings entries when managed settings or--settingssetallowUnsandboxedCommands: false, or managedallowManagedDomainsOnly: true - Changed project and local settings to ignore OpenTelemetry variables that turn on export, set its endpoint, or capture content, like
CLAUDE_CODE_ENABLE_TELEMETRYandOTEL_LOG_* - Changed Windows/WSL managed settings so an admin policy that is present but invalid or unreadable (HKLM,
managed-settings.json) keeps user-writable HKCU and WSL/etc/claude-codefrom applying - Changed
Skill(anthropic-skills:*)andSkill(claude-ai:*)allow rules to cover only skills synced from claude.ai, not plugins or other skills that merely use such a name - Changed skill folders, command files and workflow commands in the
anthropic-skillsorclaude-ainamespace to no longer load; a plugin so named still loads but yields name ties to synced skills - Changed MCP servers configured under the name
anthropic-skillsorclaude-aito list no skills or prompts (their tools still work); rename the server in your MCP configuration to list them again - Changed the
ultracodevisuals in/effortand the prompt input to plain styling (no ripple, border flourish or keyword glimmer) and removed the dynamic-workflows spinner tip - Changed the Clawd mascot's feet in the start-up banner to sit under the corners of his body
- [VSCode] Fixed long replies falling behind the stream: the panel no longer re-parses the whole reply on every update
- [VSCode] Fixed the dictation mic button covering the message input's scrollbar when the input is tall enough to scroll
- [VSCode] Fixed Remote Control sessions started on this computer not opening from their Web entry in the session list; they now open the local conversation unless it's running elsewhere
- [VSCode] Fixed an editor tab's sign-in screen hanging silently after the extension host restarts; it now shows the "stopped responding" notice too
- [Cloud sessions] Improved adding a repository to a running cloud session: a private repository your GitHub account can read but not push to now attaches for reading
- [Cloud sessions] Fixed cloud sessions occasionally redoing an already-finished step, such as posting a duplicate comment or push, after recovering from a server-side restart
- [Cloud sessions] Changed new routine schedules to default to a few minutes past the hour, with a note that routines set exactly on the hour can start several minutes late
- [Claude Tag] Added a "Channels Claude can search" admin setting that limits Claude's Slack search to public channels it has been added to, set per organization, workspace or channel
- [Claude Tag] Added a Back to Slack button on the page shown after connecting your Claude account, returning you to the thread you started from
- [Claude Tag] Fixed a channel's configure page listing no connectors or plugins when the channel gets its access bundle through an attach rule; rule-attached bundles are now shown
- [Claude Tag] Fixed access-bundle repository search missing repositories on GitHub App installs that are limited to a large list of selected repositories
- [Claude Tag] Fixed Claude occasionally posting the same reply twice when a new message interrupted it mid-reply
- [Claude Tag] Fixed channel routines that stopped running in older private channels whose Slack channel ID changed, for example after a Slack Connect share
- [Claude Tag] Fixed conversations in a channel set to "Channel only" all ending when a non-guest member joined and Slack was slow to confirm their membership
- [Code Review] Fixed "@claude review" requests going silent when GitHub failed to return the pull request: the request is retried once, and a comment explains if it still fails
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 25, 2026
2.1.282
Claude Code ships a broad release with new terminal and policy controls, faster startup and session resume, stronger reliability across conversations, plugins, MCP, background agents and remote control, plus many UI and Windows fixes.
Added
- Added a
maxProseWidthsetting that caps the width of Claude's prose in wide terminals while tables and code blocks keep the full width - Added a startup notice, and
/statusandclaude doctorentries, listing telemetry variables in a project's settings files that were ignored or that turned telemetry off - Added the
allowClaudeInChromeWithManagedMcpmanaged setting to letclaude --chromerun alongside an exclusivemanaged-mcp.json; the error shown when Chrome is blocked now names it - Added
store.readiness_grace_secondsto the Claude apps gateway so/readyzcan stay ready through a short Postgres outage such as a database failover - Added a scrollbar to the
/feedbackdrafts list in fullscreen mode; it appears while the mouse is over the list
Fixed
- Fixed every request failing with a 400 error in conversations whose history holds web search results the API cannot decrypt (for example, from a turn answered through a third-party gateway)
- Fixed more cases of continued or resumed sessions (
--continue,--resume) re-sending earlier messages in a changed form, which could make the API drop Claude's earlier reasoning - Fixed earlier extended thinking being dropped when
/model,/rename,/artifactsor another immediate slash command was used while Claude was working - Fixed continued or resumed conversations losing earlier extended thinking when relaunched with a
--toolslist that leaves out a built-in tool offered earlier in the conversation - Fixed sessions failing on every turn with an "Invalid
datainredacted_thinkingblock" API error; Claude Code now drops the conversation's thinking blocks and retries once - Fixed compaction failing when the summarization request is refused; it now retries on a fallback model
- Fixed a failed turn ("Effort 'xhigh' isn't available with thinking turned off") after a safety-related model switch in sessions with thinking off and effort above high
- Fixed an unanswered Fable usage-credits prompt switching models in SDK-hosted sessions such as Claude Desktop; the turn now ends instead, and Remote Control clients now see the model-switch notice
- Fixed
/modelwith a full Fable model id stopping at an API error instead of opening the usage-credits prompt when the plan needs usage credits that aren't turned on yet - Fixed requests failing for up to a minute with an "another Claude Code process is refreshing it" login error after that other process was closed or killed mid-refresh
- Fixed sessions started while another Claude Code window was refreshing the sign-in (common with several VS Code windows) not retrying their organization policy fetch
- Fixed CLAUDE.md and rules being read at startup through a repository symlink reaching macOS's
/Networkvia..or a/.vol-style kernel path, or a rules link to macOS's/homebeing listed - Fixed Bash permission rules with a mid-pattern
:*being skipped in settings files while--allowedToolshonored them; they now work from every source, with a startup warning on how they match - Fixed a command approved on a restored permission prompt running twice when a remote session's worker restarted
- Fixed managed settings ignoring a mistyped value for boolean lock keys such as
disableClaudeAiConnectorsorallowManagedPermissionRulesOnly; the lock now applies and startup names the key - Fixed managed
permissions,autoMode,worktreeandattributionsettings being ignored entirely when one nested value was invalid; the rest of the block now still applies - Fixed repository, user and
--add-dirskills, commands and skills-directory plugin manifests pre-approving their own tools viaallowed-toolsunder managedallowManagedPermissionRulesOnly - Fixed safeguard block messages on Amazon Bedrock and Bedrock Mantle not showing a request ID; block messages now also show the message ID
- Vertex AI: Fixed web search not being offered for models Claude Code doesn't recognize yet, such as newly released ones
- Fixed Bash and PowerShell hiding a full disk quota behind "Exit code 1" and leaving large output files in temp
- Fixed tool input validation errors naming only an unknown, missing or mistyped parameter when other parameters in the same call were also invalid; those are now listed too
- Fixed pasted multi-line text being submitted line by line after the terminal's bracketed paste mode was reset mid-session
- Fixed the prompt's example text flashing and disappearing at startup in projects with a
SessionStarthook - Fixed a blank screen flashing before the first frame when starting in fullscreen mode
- Fixed garbled, misplaced rows in the non-fullscreen renderer after the screen got shorter while still taller than the terminal, e.g. deleting a prompt line while a shell command streams output
- Fixed a stale character left in the last column of a diff when a redrawn line's CJK character or emoji wrapped to the next row
- Fixed the cursor landing before the end of a prompt recalled from history when the prompt contains a tab
- Fixed the send-now hint showing ctrl+enter on terminals that send it as a newline (Windows Terminal before 1.25); it now shows ctrl+x ctrl+s there
- Fixed
claude remote-control --debugfailing with "Unknown argument: --debug", although Remote Control's own eligibility error says to run with--debug - Fixed
/install-github-appsaying "cancelled" and then still pushing the branch and saving the API key secret; leaving now stops the remaining steps and reports what was already done - Fixed /feedback, /bug and /share on Bedrock, Vertex and other third-party providers still saving the report file after you cancelled during the save
- Fixed plugin uninstall reporting success and deleting the plugin's saved options when its settings file still enabled it or could not be read; it now stops and names the file
- Fixed plugin uninstall deleting a plugin's saved options and secrets when the list of installed plugins could not be read after the removal; they are now kept and the uninstall says so
- Fixed a key typed right after
/in/skillsmoving the skill list instead of reaching the search box - Fixed the terminal cursor jumping from the
/skillssearch box to the skill list while typing, which could hide the caret and put IME input in the wrong place - Fixed lists with a scrollbar, such as
/skillsand/mcp, being two columns narrower outside fullscreen mode, where the scrollbar can never appear - Fixed the agent panel footer wrapping onto two lines with long rebound keys, and its "Esc to collapse" hint ignoring a rebound collapse key
- Fixed a doubled
·separator in the/tasksdialog footer when the stop-all-agents shortcut is unbound inkeybindings.json - Fixed the agent panel footer offering "Enter to view" and "x to stop" on the agent you are already viewing (where x types into its input), and "Enter to view" on the main row when main is already shown
- Fixed a mouse click on an agent-panel row leaving the keyboard cursor on the previously selected row
- Fixed Esc interrupting the running turn instead of deselecting the selected agent-panel row
- Fixed PgUp and PgDn doing nothing in a dialog's list (for example
/skills) in fullscreen mode - Fixed
/heapdumpsummary saying most memory is native when it is in the JS heap snapshot - Fixed Bash edit-diff snapshot directories piling up in the temp folder: abandoned ones are now deleted right away and the rest when Claude Code exits
- Fixed /workflows moving the pointer to a different run, and
xstopping it, when a new run started while the list was open - Fixed the selected tab in tabbed dialogs (
/config,/plugin,/permissions) showing no highlight while the tab bar has focus when color is off (NO_COLOR) - Fixed the mouse wheel over the
/pluginInstalled list scrolling the pane behind it instead of the list - Fixed the hover highlight lingering on a list row in fullscreen mode after scrolling or filtering moved it away from the mouse
- Fixed long list rows, such as in the /remote-control menu, wrapping onto a second line in narrow terminals; they're now cut with …
- Fixed
/hooksand/mcpdetail views printing a long value over the row below it in narrow terminals - Fixed lists such as a skill's state options in
/pluginnot being answerable by typing a number in screen-reader mode - Windows: Fixed Bash commands that write to
$TMPDIR/…failing with "Permission denied" - Windows: Fixed a race in which Claude Code sessions updating at the same moment could delete each other's
claude.exebackup, which could leave noclaude.exebehind
Improved
- Improved Claude Desktop sign-in and usage-limit error messages to point at the app instead of terminal commands
- Improved startup: managed settings and policy fetches no longer retry requests that can never succeed
- Improved interactive startup time: git reads, startup telemetry and the Bedrock/Vertex model-upgrade checks no longer run before the first frame
- Improved the time to resume long sessions that read many files; the restored file cache now matches the files as they were read
- Improved the time to resume very long sessions that have been compacted, most noticeably through the Agent SDK and Claude Desktop
- Improved "Prompt is too long" recovery in sessions dominated by one very large first prompt: that prompt is now summarized on its own instead of being left out of the summary
- Improved auto mode after resuming a session in a new process: the permission classifier can now reuse its earlier prompt cache instead of rewriting it
- Improved the auto mode denial message so Claude treats a denial as covering the outcome, not only the exact command
- Improved the dangerous-rm check to also flag a removal at a shell variable followed by a top-level directory name, at a variable derived from the working directory, or at a backslash-only target
- Improved sandbox guidance on macOS: when a local dev server can't bind a port, Claude now points to
sandbox.network.allowLocalBinding - Improved
--agentsto accept the path to a JSON file (with-p) as well as inline JSON, and to allow an emptyprompt - Improved
/batchto run where a WorktreeCreate hook provides the agent worktrees, not only inside a git repository - Improved plugin hook-failure errors to name the offending plugin, and added a
claude plugin validatewarning when a shell-form hook leaves${CLAUDE_PLUGIN_ROOT}unquoted (it breaks on plugin paths with spaces) - Improved the
/menu,/skills,/contextand the/pluginInstalled list to show skills synced from claude.ai by their short name when no other command uses it, notanthropic-skills:<name> - Improved
/deep-researchreliability on long research briefs by removing unused required fields from the scope step's output - Improved the writing in published artifact pages: the bundled artifact-design skill now asks Claude for plain, direct prose
- Improved artifact publishing on slow connections: large page uploads are now sent compressed
- Improved the large CLAUDE.md startup notice to also count instruction files together, so many mid-sized files and @-imports are caught
- Improved debug logs to name settings
envvariables ignored because the session's launch environment already sets them - Improved keyboard navigation in tabbed dialogs such as
/permissionsand/usage: ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus - Improved
/helpand/sandbox: ←/→ and Tab switch tabs from inside a tab's list, and ↓ on an empty Custom commands tab in/helpno longer leaves the keys stuck until Esc - Improved
/install-github-app,/desktop, the/permissionsauto mode environment prompts, and the/plugin"Add marketplace?" and "Run this command?" prompts: they now use the standard dialog frame with key hints, and Ctrl+C or Ctrl+D cancels them on the second press like other dialogs - Improved
/workflowsand/mcplists: they page (PgUp/PgDn, Home/End) and take j/k and the mouse like other lists, their arrows followselect:previous/select:nextrebinds, andxin/workflowsstops the run the pointer is on - Improved the
/pluginplugin and marketplace details menus and the/remote-controlalready-connected menu: they now support Home/End and clicking a row - Improved the background workflow row below the prompt: it now shows the name, a progress bar, the agent count on wide terminals, elapsed time, total tokens, and the large-workflow warning
- Improved the /plugin Installed list: rows now line up in columns (status, name, type, details) across every section
- Improved
/skills: each row now leads with the skill's name, with ✔ or ◯ alone showing on or off, and stays on one line in narrow terminals - Improved narrow list rows (
/skills,/workflows,/feedback): a name keeps 20 columns beside its first detail, and details are shown whole or not at all - Improved the search box in
/plugin,/skillsand/mcplosing its right border in fullscreen mode - Improved
/mcpshowing △ in the server list but ⚠ in the detail view for the same server; the list, detail views and/pluginnow all show ⚠ - Improved Home and End doing nothing in the
/configsettings list and in selection lists such as/model,/memoryand permission prompts - Improved PgUp/PgDn in the
/skillsmenu wrapping past the first or last skill instead of stopping there - Improved Tab silently changing the selected setting's value in the
/configlist; it now does nothing there - Improved conversations failing on every turn with a "role 'system' must precede an 'assistant' message" API error
- Improved conversations with the advisor on failing every turn with API Error 400 "Input tag 'advisor_20260301'" behind a proxy or gateway that doesn't support it; the request now retries without it
- Improved a session failing on every turn and
/compactwhen its saved history held a malformed notice about MCP tools that could not be loaded - Improved a crash when resuming a session whose saved transcript holds a malformed system message or a memory-saved notice without its file list
- Improved one cause of long-running fullscreen sessions exiting with "Claude Code exited after an unrecoverable interface error": a damaged cached message list is now rebuilt
- Improved Claude Code hanging when a settings file, or a file it re-reads after an edit, is replaced by a named pipe mid-read
- Improved
/configcrashing and some on/off preferences being misread when a preference that has moved tosettings.jsonstill holds a value likenullor"false"in~/.claude.json - Improved resuming a session with unfinished background agents, shells or workflows starting a model turn on its own before you typed anything
- Improved messages sent to a background subagent being silently lost in headless and SDK sessions when the subagent was finishing its turn
- Improved a finished subagent's report being lost when the conversation that launched it was compacted before the report was read
- Improved background subagents being unable to use the LSP tool when an LSP plugin is active
- Improved background shell tasks reporting benign non-zero exits (e.g. grep with no matches) as failures
- Improved background sessions (
claude --bg) being unable to run git, hooks, plugins and other helper programs when an environment variable handed to the session contained a NUL character - Improved Ctrl+C needing three or four presses to exit while background subagents are running; two presses now exit
- Improved IDE selection being dropped when a sent prompt comes back into the input, such as pressing Esc to edit it, rewinding to it, or pressing Esc while startup hooks run
- Improved a
!shell-mode prompt stashed with Ctrl+S coming back as a plain prompt when restored, and/listing file paths right after stashing one - Improved
claude agentsshowing a blank, unresponsive screen instead of an error when the temp directory is full, not writable or owned by another user - Improved MCP connection errors and the MCP login tool's description showing secrets resolved from
${VAR}placeholders in MCP configs - Improved Bash permission checks for commands that loop over or assign certain special shell variables; these commands now ask for permission
- Improved worktree-isolated sessions accepting Bash commands with certain nested shell expansions; these are now refused
- Improved the Edit permission prompt preview sometimes showing a different location than the approved edit in files with multi-byte characters
- Improved background commands being stopped after 30 idle minutes on machines under mild memory pressure; they're now stopped only when memory is critically low, and the debug log says why
- Improved a message a subagent sends to the main session disappearing from the Claude Desktop transcript after a relaunch
- Improved a plugin loaded from a
.zipbeing served from a stale extraction after several overlapping reloads - Improved a sub-agent's progress summary being replaced by a runaway multi-paragraph reply
- Improved
/ultrareviewandclaude ultrareviewto wait up to 45 minutes (previously 30) for long-running cloud reviews - Improved
/efforton Claude Fable 5.1 so changing effort mid-session no longer invalidates the prompt cache
Updated
- Updated the bundled
claude-apiskill so its Go, Java, and C# samples use current-generation model IDs, and clarified that cheaper worker or sub-agent models should be current-generation too
Changed
- Changed
ctrl+l/cmd+kin fullscreen mode to clear the transcript view like a terminalclear; scroll up to see earlier messages - Changed permission rules with text after the closing parenthesis (e.g.
Bash(ls) x), which never matched anything, to be reported as invalid settings instead of being silently ignored - Changed server-managed settings so a managed CLAUDE.md (
claudeMd) no longer triggers the security approval dialog; hooks, shell-command, sandbox, and unsafeenvsettings still require approval - Changed Claude in Chrome to follow your organization's Claude in Chrome admin setting; when an admin turns it off,
--chrome,/chromeand the browser tools are unavailable - Changed Claude apps gateway to send
orgPluginSettingsin the list form read by Claude Desktop 1.15200.0 and later; older desktops ignore it - Changed Claude apps gateway to also refuse to start, naming the field, when a
desktoppolicy misspells a field in a nested object of amanagedMcpServersororgPluginSettingsentry - Changed commands typed at the
!bash-mode prompt to run outside the sandbox even when strict sandbox mode (sandbox.allowUnsandboxedCommands: false) is on, like typing into your own terminal - Changed self-hosted runner
--kill-session-after-minto release a session that is only waiting on its user (paused, resumable on the next message) instead of killing it and reporting a failure
Removed
- Removed the one-hour time limit on background commands started by subagents; they now run until they exit or are stopped, matching the main session
VSCode
- [VSCode] Added the selected effort level to the footer model pill, fixed a stale effort level after switching models, and returned the footer pills to their earlier compact size
- [VSCode] Added Open and Closed to the session list's status filter menu
- [VSCode] Fixed the welcome screen disappearing in a new session when Remote Control turns on automatically
- [VSCode] Fixed the session history picker loading a session a second time when it is already open in another tab; it now switches to that tab
- [VSCode] Fixed the session tab's Rename command silently doing nothing while the tab's view was reloading; it now always applies
- [VSCode] Fixed a half-finished message, an empty tool card or an extra "Thought for" line staying on screen after Claude Code retried a dropped response
- [VSCode] Fixed "Enable Remote Control for all sessions" not applying to a session tab that was still starting when the toggle was flipped
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 22, 2026
2.1.280
Claude Code releases Claude Opus 5.5 as the new default Opus model and brings a broad round of usability, reliability, and terminal fixes, including better fullscreen mouse support, stronger MCP controls, cleaner dialogs, and VS Code session archiving.
- Added Claude Opus 5.5 (
claude-opus-5-5), now the default Opus model — 1M context, $4/$20 per Mtok with $0.20/Mtok cache reads - Added mouse support to more lists in fullscreen mode: the wheel scrolls the
/skillslist, and a skill's state options in/plugincan be clicked - Added
CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTHto change the 2,048-character cap on MCP tool descriptions and server instructions for every MCP server in the session - Added hook output sizes and the number of oversized outputs saved to a file to the
hook_execution_completeOpenTelemetry event - Fixed writes through a symlinked path being judged by their in-tree spelling: the prompt names where the write lands, and
acceptEdits, allow rules and auto mode no longer approve one landing outside - Fixed auto mode retrying an action over and over when a safety check declined to review it; the action is now denied once, noting that retrying won't help
- Fixed auto mode denying actions over and over without pause when a safety check gave no answer; retries now back off, and the turn stops with a message after ten in a row
- Fixed Write calls failing validation when a model sends
path,file_text,file_contentor a straydescriptioninstead offile_pathandcontent - Fixed Ctrl+C or Ctrl+D pressed twice in most dialogs (
/model,/effort,/config,/status,/usage,/plugin,/sandbox,/permissions,/artifacts,/mobile,/login,/upgrade,/usage-credits,/install-github-app,/setup-bedrock,/setup-vertex) quitting Claude Code instead of closing the dialog - Fixed a click that only brought the terminal window to the front also triggering the item under the pointer — in search pickers, tab bars, agent/workflow rows, slash-command links and suggestion dropdowns
- Fixed a stray
nclosing dialogs and a strayyconfirming them; Enter and Esc accept and cancel (bindy/ntoconfirm:yes/confirm:noinkeybindings.jsonto restore) - Fixed text fields in dialogs losing a typed letter, digit or Space to a keybinding on that key
- Fixed the prompt line staying scrambled on Windows terminals after invisible characters were removed on Enter; the screen is now repainted so you review the exact text that will be sent
- Fixed the invisible-character cleanup removing the zero-width non-joiner that Persian and Arabic text uses to attach a suffix to a Latin word or number, such as the plural of "PDF"
- Fixed voice dictation not stopping on Ctrl+C (the prompt cleared but the microphone kept recording), Esc not cancelling while a transcript was processing, and held Space starting dictation from the transcript view and vim NORMAL mode
- Fixed a model switch made from a host app (Claude Desktop, VS Code, SDK) while Claude is working causing a prompt-cache miss on the next prompt
- Fixed resumed fork subagents rebuilding their tool list instead of re-sending the one they first used, which broke prompt caching for that agent
- Fixed subagent hand-back messages showing an internal provenance preamble when expanded outside verbose mode
- Fixed
installed_plugins.jsonkeeping the install-time commit after updating a plugin from a GitHub repository or git URL that tracks a branch or tag - Fixed skills in
~/.claude/skills/being moved to~/.claude/skills/.trash/when amanifest.jsonin that folder listed their names - Fixed the session feedback survey showing no hover highlight on light and ANSI themes
- Fixed
/workflowsbriefly showing a one-row list before opening the only run - Fixed the mouse wheel not scrolling selection lists with hidden options (such as
/modeland/permissions) in fullscreen mode - Fixed a skill you switched off showing the same red ✘ as a plugin that failed to load in
/pluginand/skills; off now shows a dim ◯ - Fixed multi-select option descriptions being indented under the option number instead of under the label
- Fixed the search box in
/plugin,/skillsand/mcplosing its right border in fullscreen mode - Fixed
/mcpshowing △ in the server list but ⚠ in the detail view for the same server; the list, detail views and/pluginnow all show ⚠ - Fixed Home and End doing nothing in the
/configsettings list and in selection lists such as/model,/memoryand permission prompts - Fixed PgUp/PgDn in the
/skillsmenu wrapping past the first or last skill instead of stopping there - Fixed Tab silently changing the selected setting's value in the
/configlist; it now does nothing there - Fixed conversations failing on every turn with a "role 'system' must precede an 'assistant' message" API error
- Fixed conversations with the advisor on failing every turn with API Error 400 "Input tag 'advisor_20260301'" behind a proxy or gateway that doesn't support it; the request now retries without it
- Fixed a session failing on every turn and
/compactwhen its saved history held a malformed notice about MCP tools that could not be loaded - Fixed a crash when resuming a session whose saved transcript holds a malformed system message or a memory-saved notice without its file list
- Fixed one cause of long-running fullscreen sessions exiting with "Claude Code exited after an unrecoverable interface error": a damaged cached message list is now rebuilt
- Fixed Claude Code hanging when a settings file, or a file it re-reads after an edit, is replaced by a named pipe mid-read
- Fixed
/configcrashing and some on/off preferences being misread when a preference that has moved tosettings.jsonstill holds a value likenullor"false"in~/.claude.json - Fixed resuming a session with unfinished background agents, shells or workflows starting a model turn on its own before you typed anything
- Fixed messages sent to a background subagent being silently lost in headless and SDK sessions when the subagent was finishing its turn
- Fixed a finished subagent's report being lost when the conversation that launched it was compacted before the report was read
- Fixed background subagents being unable to use the LSP tool when an LSP plugin is active
- Fixed background shell tasks reporting benign non-zero exits (e.g. grep with no matches) as failures
- Fixed background sessions (
claude --bg) being unable to run git, hooks, plugins and other helper programs when an environment variable handed to the session contained a NUL character - Fixed Ctrl+C needing three or four presses to exit while background subagents are running; two presses now exit
- Fixed IDE selection being dropped when a sent prompt comes back into the input, such as pressing Esc to edit it, rewinding to it, or pressing Esc while startup hooks run
- Fixed a
!shell-mode prompt stashed with Ctrl+S coming back as a plain prompt when restored, and/listing file paths right after stashing one - Fixed
claude agentsshowing a blank, unresponsive screen instead of an error when the temp directory is full, not writable or owned by another user - Fixed an MCP server re-added under the same name after
claude mcp removestill showing as needing authentication instead of reconnecting - Fixed background plugin marketplace auto-update ignoring git credential helpers, so private-repo marketplaces were re-cloned every run or never updated
- Fixed
claude plugin updateclearing a plugin's recorded commit and moving it to version "unknown" when the official marketplace's snapshot file is a link or too large - Fixed the Artifact tool silently disappearing when your organization's policy can't be loaded (for example behind a web proxy); Claude now says what's blocking it
- Fixed artifact republishes silently resetting stored database access rules or dropping the viewer profile scope when that capability was re-sent without them; they are now refused
- Fixed
/ultrareviewreporting a stopped cloud review as completed or as an error to retry, and waiting out the full timeout when its session was deleted or the signed-in account changed - Fixed the Claude app showing a missing or stale context usage figure for Remote Control and cloud sessions right after /compact or /clear
- Fixed the Claude app's diff view for Remote Control and cloud sessions dropping a branch's committed files whenever there are also uncommitted changes
- Fixed cloud and self-hosted runner sessions failing with "Authentication failed" after waiting out a long overload during which the session's access token was rotated
- Fixed memory write conflicts in Cowork sessions showing Claude only the start and end of a memory file over about 10,800 characters, so the retried write dropped the middle
- Self-hosted runner: Fixed lifecycle-hook commits failing to sign under
--configure-git - Windows: Fixed background cleanup deleting a directory symlink or junction used to relocate
~/.claude/session-env,image-cacheor another cleaned-up folder - Self-hosted runner: Fixed a turn that ended right at a
--retire-atrelease losing its finished signal; the runner now briefly waits for the turn to be reported before stopping the session - Reverted
ctrl+l/cmd+kin fullscreen mode clearing the transcript view (added in 2.1.260); they redraw the screen again - Improved
/permissions: focus returns to the rule list after viewing, adding or deleting a rule, and the delete-rule and remove-directory confirmations now default to No - Improved
/permissionstab navigation: ←/→ and Tab pressed in a rule list now switch tabs without moving focus to the tab bar - Improved
/costcache-miss causes to name thinking mode and thinking display changes - Improved the Artifact tool so that when Claude cannot read an artifact link it was given, it tells the user before continuing
- Improved
/install-github-app: the GitHub CLI check and repository selection steps now show "Esc to cancel" - Improved the
/artifactsand/workflowslists: a scrollbar at the right edge shows how much of a long list is hidden and where you are in it - Improved the workflow progress tree: running agents and phases now show a dim dot instead of ⟳
- Improved
/plugin's Add Marketplace form in fullscreen: it no longer draws a box inside the pane, and its text and key hints line up with the rest of/plugin - Improved the
/workflowsdetail view in fullscreen: it no longer draws a second horizontal rule under the pane's divider - Improved code blocks that don't name a language: they are now colored like inline code, so commands stand out from the surrounding text
- Improved
/btwasked while a tool is still running: the side question now knows that call is in progress instead of reading it as a failed one - Improved the UserPromptSubmit hook timeout notice and the debug log to name which hook command timed out
- Improved
@file suggestions: a file whose name contains the query now ranks above one that only matches across its folder names - Improved artifact pages: no Print buttons, confirm dialogs or device features the viewer blocks, email and phone details shown as text, and dark mode that reaches form controls and scrollbars
- Improved
/ultrareviewuploads: renamed copies of key files, such asid_rsa copyorkubeconfig (1).yaml, now also stay on your machine - Improved the cross-session messaging startup warning to explain that
--debug-filewrites a debug log to a path you choose - Changed the bundled
claude-apiskill to enableeager_input_streamingon streaming custom tools, and to start deliverable-shaped Managed Agents work withuser.define_outcome - [VSCode] Added automatic archiving of sessions inactive for a set period (new "Archive inactive sessions" setting, default 14 days)
- [VSCode] Fixed the sidebar chat coming back blank after Reload Window or a restart when the conversation had been open for more than 10 minutes
- [VSCode] Fixed the timeline dot sitting below the text on the "Remote Control is active" message
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 19, 2026
2.1.278
Claude Code changes auto mode to default to server-side classifier billing for API and Enterprise users and adds a new /status row.
Changed auto mode for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry and gateways, to default to the server-side classifier, which does not charge for classifier overhead (
CLAUDE_CODE_AUTO_MODE_SERVER=0opts out on Bedrock, Vertex, Foundry and gateways); warns on billed fallback. See https://code.claude.com/docs/en/auto-mode-classifier-billingAdded an
Auto mode serverrow to/statusshowing whether this session's auto mode classifier runs on the server
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 18, 2026
- Modified by Releasebot:Sep 21, 2026
2.1.277
Claude Code releases a broad stability and workflow update with AGENTS.md support, gateway and proxy improvements, faster headless and SDK startup, richer VS Code and web controls, and many fixes for crashes, update issues, plugin handling, sessions, sandboxing, and review workflows.
- Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under "Project instructions" in
/config(not yet on Bedrock, Vertex or Foundry) - Added
CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally - Added an optional
headers:map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider - Added a line saying a background task's update is waiting when it finishes while a panel such as
/tasksis open - Fixed
claude -pand Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1 - Fixed conversations failing every request with "text content blocks must be non-empty" when an earlier assistant turn held an empty text block beside other content, including after
--resume - Fixed being unexpectedly logged out when an older Claude Code build (for example an IDE extension's bundled CLI) runs on the same machine as the current one
- Fixed interactive start-up hanging or showing an error for
ANTHROPIC_API_KEYusers when~/.claude.jsonholds a malformedcustomApiKeyResponsesvalue - Fixed update checks erroring every 30 minutes, and
claude updatehanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformedminimumVersionis now ignored - Fixed
claude updateon winget- or apk-managed installs reporting "up to date" when the version lookup failed - Fixed
claude plugin installsometimes failing and breaking the installed copy when reinstalling a plugin version that a session or another program was using; an unchanged copy is now left alone - Fixed Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so
- Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error
- Fixed the Edit tool treating an escaped backslash followed by
uXXXXtext as a\uXXXXescape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead - Fixed the Edit tool reporting "Invalid regular expression: regular expression too large" instead of "String not found in file" when a very large edit containing non-ASCII text did not match the file
- Fixed a turn ending early with "Path contains null bytes" when a tool call's file path contained
\u0000written as an escape sequence; escaped control characters now stay as literal text - Fixed background sessions (
claude --bg) exiting when a plugin's LSP server exited or closed its stdin - Fixed a crash ("Type error") when opening
/mcpor/plugin managewith a malformedclaudeAiMcpEverConnectedvalue in~/.claude.json - Fixed a crash at launch when
~/.claude.jsonholds a malformedthemevalue - Fixed a crash ("unrecoverable interface error") when the prompt held text containing terminal color codes, for example a prompt recalled from history or text loaded from the external editor
- Fixed a crash when resuming a session whose saved history holds an assistant message stored as a plain string
- Fixed sessions on slow or heavily loaded machines sometimes exiting with "Claude Code exited after an unrecoverable interface error" when the first spinner appeared
- Fixed a rare case where the screen could stop updating for the rest of the session after an internal rendering error
- Fixed a rare case on Windows where a turn could stop with an error such as "Out of memory" right after Claude replied, so that reply's tool calls never ran
- Fixed sessions continued after
/clear(restart,--continue,--resume) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss - Fixed messages from other agents (such as a subagent's SendMessage) that arrived mid-turn showing up below the "Ran N shell commands" row instead of where they arrived
- Fixed the "copied" notice not appearing after drag-selecting text in the fullscreen
/resumepicker and other panels that cover the prompt area - Fixed
$TMPDIRexpanding empty in Bash commands that run outside the sandbox while sandboxing is enabled - Fixed WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy
- Fixed the Claude apps gateway's telemetry relay ignoring a collector hostname or domain listed in
NO_PROXYwhen a proxy is set - Fixed one malformed
strictKnownMarketplacesorblockedMarketplacesentry silently disabling the whole enterprise marketplace policy - Fixed failed auto-updates leaving large staged downloads behind in
~/.cache/claude/staging - Fixed
/pluginnot stripping terminal control characters from messages on the Installed tab, such as the error of a failed plugin update - Fixed
/plugin→ Installed and/skillscrashing when a skill or legacy command is named like a built-in Object property such asconstructorortoString - Fixed
/pluginclosing with no message when every install in a multi-select failed - Fixed uninstalled plugins reappearing as "failed to load" rows in
/pluginInstalled, and Remove not clearing such a row - Fixed plugins from the official marketplace being recorded without their commit in
installed_plugins.json, andinstalled_plugins.jsonkeeping the old commit after updating a pinned-commit plugin - Fixed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached
--plugin-urlarchive a reload falls back to when its download fails - Fixed Remote Control session bookkeeping failing when
~/.claude.jsonholds a malformed placeholder record - Fixed the error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with
/login - Fixed typed or pasted text occasionally coming out scrambled in the
claude agentsdispatch input during key repeat or very fast input - Fixed a crash ("unrecoverable interface error") when resuming a session whose saved transcript contains a stop hook summary without a well-formed hook list
- Fixed Enter on a selected agent panel row doing nothing when
keybindings.jsonrebinds Enter in the Chat context, for example tochat:queueSubmit - Fixed PDF page reads on Windows failing when the working folder's path is long (about 120 characters or more)
- Fixed a headless resume (
claude -p --resume, the SDK, a VS Code extension window reload) starting the session's cost and usage totals at zero; headless sessions now save their totals at exit - Fixed project skills from the main repository not loading in
--worktreesessions when.claude/skillsis untracked - Fixed a
sandbox.excludedCommandsglob exempting an entire compound Bash command from the sandbox when only one part matched; every part must now match - Fixed resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, which broke prompt caching for that agent
- Fixed rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again
- Fixed attachments recorded earlier in a conversation being re-rendered after a resume or relaunch, which dropped extended thinking and missed the prompt cache
- Fixed Console sign-in showing only "Request failed with status code 400" when the server refuses to create an API key; it now shows the server's message
- Fixed messages typed while Claude is still working sometimes being ignored by the model
- Improved session start-up for SDK and headless (
-p) use: the first turn no longer waits on the per-directory CLAUDE.md lookup - Improved the Claude apps gateway's loopback error messages to name
CLAUDE_GATEWAY_ALLOW_LOOPBACK - Improved
/pluginInstalled: an MCP server listed apart from its plugin now shows which plugin it belongs to - Improved
claude plugin installon an already-installed plugin: it now says when the marketplace offers a newer version and names theclaude plugin updatecommand - Improved the startup notice overflow line under the logo: it now reads "N more notices hidden" instead of "+N more · /status"
- Improved prompt handling: invisible Unicode formatting and tag characters in a prompt are removed and the cleaned prompt is shown for review before it is sent
- Improved
/ultrareviewwhen there's nothing to review: messages say which case you're in, offer a command that reviews your latest commit, and a new repository's first commit is reviewed in full - Improved artifact link handling so Claude reads claude.ai artifact links with the Artifact tool instead of WebFetch when that tool is available
- Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a
${VAR:?}guard, so headless runs can recover - Improved the Artifact tool's permission prompts: shorter sentences, pages and artifacts named by title or file name, and links listed after the text
- Changed Fable to always appear in
/modelon the Anthropic API; it is greyed out only when your organization's settings disable it - Changed the Bash sandbox instructions on Bedrock, Vertex and Foundry to the first-party wording, which frames the sandbox as the boundary of what the task was given
- Changed
/ultrareviewin non-interactive sessions to refuse when the repository has no base branch or shared history - Changed subagent results to reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions
- Changed workflow scripts' computed
agent()prompts on Bedrock, Vertex and Foundry to reach the subagent framed as script-authored text, so the safety classifier does not read them as the user - Removed the background Haiku auto-title request from
claude -pruns launched outside an SDK or IDE - Removed the deprecated TaskOutput tool; Claude reads a background task's output file with Read instead, and the
taskOutputMaxCharssetting andTASK_MAX_OUTPUT_LENGTHno longer have any effect - [VSCode] Added a Sign out row to the panel menu, with
/logoutin the typed command menu - [VSCode] Added background shells and other running tasks to the agent map, each with a Stop, and a typed
/tasksthat opens it - [VSCode] Added a Copy response button on responses and a typed
/copy - [VSCode] Added a one-time notice when inactive sessions are archived automatically, and an "Unarchive all" action on the Archived sessions group
- [VSCode] Added the session's cost and token usage to the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key)
- [VSCode] Fixed the "General config" menu row showing
/configusage text instead of opening settings, and made typed/mcp,/hooks,/memory,/rewindand similar commands open their dialogs - [VSCode] Fixed the effort slider's level not persisting into later sessions on a model that already had a level saved with
/effort - [VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as "Sonnet"
- [VSCode] Fixed
/fastnot saving fast mode as the default, so it was lost when the extension relaunched Claude Code - [Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization
- [Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings 1 Cloud environments
- [Claude Code on the web] Fixed a cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain
- [Claude Code on the web] Changed the admin Claude Code setting labeled "Web" to "Cloud sessions" and removed the redundant read-only Mobile row beneath it
- [Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran
- [Claude Tag] Fixed the "Learn more" links on credential presets in Claude Tag access bundles to open each vendor's credential-setup page instead of a generic API reference
- [Claude Tag] Changed the Pylon credential preset in Claude Tag access bundles so admins can point it at Pylon's EU host
- [Claude Tag] Fixed Google Cloud credential forms in Claude Tag access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key
- [Claude Tag] Fixed the network events log in Claude Tag admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA
- [Claude Tag] Fixed adding a channel manager being refused on Enterprise Grid shared channels, on channels where Claude hasn't been used yet, and on legacy private channels
- [Claude Tag] Changed Claude to start watching related public channels on its own, such as an incident channel a conversation depends on, instead of only when asked
- [Claude Tag] Fixed the admin Memory page not listing Slack channels Claude set up on its own even when they had saved memory; admins can now open, edit and delete that memory
- [Code Review] Fixed re-reviews occasionally leaving a fixed finding's thread open when the new review also filed a lower-severity note under it
- [Code Review] Fixed rare reviews ending with "Code review encountered an error" when GitHub or an internal service failed transiently at launch; they now wait and retry
- [Code Review] Improved how Code Review words each posted finding: short plain sentences that say who is affected, where the code goes wrong, and the fix up front
- [Code Review] Improved the check-run card and PR comment when a review is skipped because of an organization limit: each cause now links the admin page that fixes it
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 18, 2026
2.1.276
Claude Code fixes request failures with proxy or gateway base URLs after a 2.1.275 regression.
- Fixed every request failing with
400 Input tag 'advisor_20260301'whenANTHROPIC_BASE_URLpoints at a proxy or gateway (2.1.275 regression)
- September 2026
- No date parsed from source.
- First seen by Releasebot:Sep 18, 2026
- Modified by Releasebot:Sep 21, 2026
2.1.275
Claude Code adds stronger gateway sign-in, smarter plugin and skill syncing, and faster send-now messaging, while improving model display, startup reliability, and streaming performance. This release also brings broad fixes across sessions, permissions, VS Code, web, and Claude Tag.
- Added the signed-in account to Claude apps gateway sign-in: when the gateway names it, you confirm it before the credential is saved, and
/statusshows it - Added a send-now key (ctrl+enter, or ctrl+x ctrl+s) that interrupts the current turn and sends all queued messages at once; sent and queued messages show in gray until the model receives them
- Added a startup warning when a configured
otelHeadersHelperfails, so sessions that silently export no telemetry are noticed - Added syncing of the skills and plugins enabled on your claude.ai account to terminal sessions signed in with it; opt out with
syncClaudeAiSkills: falseorsyncClaudeAiPlugins: false - Added
/plugin install <plugin> --marketplace <source>, which offers to add the marketplace before installing the plugin - Fixed a restored memory file's age note changing between requests after a compaction or resume, which caused prompt cache misses
- Fixed
--forward-subagent-textstream-json and SDK output dropping the messages of subagents spawned by acontext: forkskill, and of forked skills invoked by a subagent or another forked skill - Fixed @-mention file suggestions being buried below MCP resources when using a custom
fileSuggestioncommand or typing@./@./ - Fixed fullscreen mode placing background-task completion notices beneath a long turn's collapsed tool row instead of where they arrived; each notice now closes the open row
- Fixed
claude plugin marketplace updatedeleting a GitHub marketplace's local copy when the fetch failed and the marketplace was named after its repository - Fixed plugin and marketplace messages, logs and
claude plugin marketplace listshowing a password or token stored in a git, ssh or marketplace URL - Fixed a resumed cloud session leaving an unanswered question open in the transcript after a queued message superseded it
- Fixed vim mode placing the cursor one character right after a dot-repeated "!" or a fast-typed "i!" switched a non-empty prompt into shell mode
- Fixed fullscreen mode freezing or blanking for several seconds when scrolling up past a large file diff
- Fixed a stray
</ccmemory>-style closing tag occasionally appearing in responses - Fixed the Bash tool re-sourcing the shell profile (a multi-second stall on the next command) after every plugin reload; it now does so only when the plugins'
bin/directories changed - Fixed plugins with a top-level
$schemainhooks/hooks.jsonshowing an "unknown key" notice - Fixed MCP connection errors and the MCP login tool's description showing secrets resolved from
${VAR}placeholders in MCP configs - Fixed Bash permission checks for commands that loop over or assign certain special shell variables; these commands now ask for permission
- Fixed worktree-isolated sessions accepting Bash commands with certain nested shell expansions; these are now refused
- Fixed the Edit permission prompt preview sometimes showing a different location than the approved edit in files with multi-byte characters
- Fixed background commands being stopped after 30 idle minutes on machines under mild memory pressure; they're now stopped only when memory is critically low, and the debug log says why
- Fixed a message a subagent sends to the main session disappearing from the Claude Desktop transcript after a relaunch
- Fixed the usage-limit warning flickering on and off during a session when requests for different models or modes report different limit windows
- Fixed
claude -p --resume <file>adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID instead - Fixed the terminal progress indicator (iTerm2, Ghostty, ConEmu) showing the session as finished while a background workflow or agent was still running
- Fixed a rare layout glitch where a box could render with the wrong height after its container switched between row and column direction
- Fixed Claude apps gateway client IP when a trusted proxy appends a port to
X-Forwarded-For; with an access list set, an unreadable entry now gets 403 - Fixed Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected Desktop's data
- Fixed Desktop and web showing a session as busy while it only watches an artifact for updates
- Fixed Claude in Chrome
file_uploadfailing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop app - Fixed
SendMessageto an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects - Fixed plugin install hints from CLIs run in background Bash commands: they are now detected, and the raw
<claude-code-hint>tag no longer leaks into the conversation - Fixed in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn, which changed the request prefix and missed the prompt cache
- Improved the
/modelpicker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes it - Improved startup on Google Vertex AI when
GOOGLE_APPLICATION_CREDENTIALSis set: API client creation no longer re-runs Google Cloud project discovery or spawns extragcloudprocesses - Improved streaming performance: already-rendered blocks are no longer re-checked by layout on each update
- Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a
${VAR:?}guard, so headless runs can recover - Improved the prompt footer: an editor or
/diffselection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer - Improved the "Usage credits required for 1M context" message to say that usage credits turned on mid-session take effect after restarting Claude Code
- Improved
/plugin: installing, enabling or disabling a plugin now takes effect when you close the menu;/reload-pluginsis no longer needed afterwards - Changed the system prompt on Bedrock, Vertex and Foundry to deliver environment, model and settings details as attachments, matching first-party sessions
- Changed Bedrock, Vertex and Foundry sessions to keep the tool list byte-stable across a conversation (late-connecting tools load deferred instead of rewriting it), matching first-party sessions
- Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be offered only on Claude 3.x, Opus 4.04.7, Sonnet 4.04.6, Haiku 4.5; set
CLAUDE_CODE_ENABLE_TODO_TOOLS=1elsewhere - Changed the artifact data-edit permission prompt in the terminal to a card that shows the document count and who can open the artifact
- Changed local Cowork sessions set to skip all approvals: the Artifact tool now refuses a local file outside the session's folders, or behind a symlink, instead of reading it without asking
- Changed plain
WebFetchdeny and ask rules to no longer apply to Artifact tool reads and updates; use anArtifactrule (orWebFetch(domain:claude.ai)) to block or gate them - Changed the "N MCP servers need authentication" startup notice to announce each server once instead of at every launch
- [VSCode] Fixed the session list, settings toggles, and chat tabs when
CLAUDE_CONFIG_DIRis set in a settings file or theenvironmentVariablessetting - [VSCode] Fixed the model pill, model picker and command menu going blank in open tabs for a few seconds after a login, logout or account switch
- [VSCode] Fixed Auto disappearing from the mode picker in new-tab or just-reloaded conversations when a project or local setting overrides the model named in
~/.claude/settings.json - [VSCode] Fixed session names reverting to the last prompt after a window reload when a SessionStart hook is configured
- [VSCode] Fixed the footer's model pill and Remote Control pill waiting for the new tab's Claude process to start when another tab in the window is already up
- [VSCode] Fixed a second Claude process running through its full startup when a session tab's launch arrived more than half a second after its config read
- [VSCode] Fixed resuming a session from the session list ignoring
claudeCode.preferredLocation: "sidebar"(it always opened a panel), and programmatic opens resetting that setting to "panel" - [VSCode] Fixed Windows issues: the WSL install prompt no longer appears on machines without WSL installed, and IDE diagnostics are now returned correctly for Windows files when WSL is installed
- [VSCode] Fixed the custom style builder saving a User level style in a folder the CLI does not read when
CLAUDE_CONFIG_DIRis set through settings - [VSCode] Added Left and Right arrow keys to change where an always-allow permission rule is saved, for keyboard and screen reader users
- [VSCode] Added a "Claude Code: Focus last message" command that moves keyboard focus to the newest message in the conversation, for keyboard and screen reader users
- [VSCode] Changed the Manage plugins dialog to apply installs, enables, disables and uninstalls to open sessions without a restart
- [VSCode] Changed some artifact permission prompts to omit the "don't ask again" choice, matching the terminal
- [Claude Code on the web] Fixed cloud sessions running longer than about six hours silently losing files saved to persisted session folders; saves now persist for up to a day
- [Claude Code on the web] Fixed "Invalid effort level" errors when a routine resumes a session, or a session starts with no set effort, in orgs where an admin caps a model's effort
- [Claude Code on the web] Improved routine creation from a conversation: when the new routine has no connectors, Claude now says so and how to add them instead of only confirming it
- [Claude Tag] Fixed the admin settings page hanging on a loading skeleton or going blank after a transient load failure; a section that fails to load now shows a Retry button
- [Claude Tag] Added a link from a Slack channel's configure page back to the organization's Claude in Slack admin settings
- [Claude Tag] Fixed Claude replying "The API rejected the request as invalid" when the organization has run out of usage credits; the reply now says so and explains how to add more
- [Claude Tag] Fixed thread requests to edit or delete a message Claude posted at the channel's top level being answered with a correction instead of reaching the session that posted it
- [Claude Tag] Fixed Connect on Tool access requests under Admin settings > Review requests failing with "Authorization failed" or showing the requested access bundle as deleted
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.