https://github.com/anthropics/claude-code/blob/main/CHANGELOG.mdClaude Code ChangelogRelease notes for Claude CodeAnthropic2026-09-25T21:49:55Zhttps://github.com/anthropics/claude-code/releases/tag/v2.1.283Claude Code v2.1.2832026-09-25T21:49:55Z<p>• Added x-claude-code-prompt-id to the gateway hint headers so LLM gateways can group the requests that serve one user prompt; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1</p>
<p>• Added availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed</p>
<p>• Added deniedModels managed setting to block specific models, even when availableModels allows them</p>
<p>• Added MCP tool, WebFetch and WebSearch outputs to the tool.output OpenTelemetry span event when OTEL_LOG_TOOL_CONTENT=1</p>
<p>• Added /doctor prompt-audit (also /checkup prompt-audit) to audit your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models</p>
<p>• Added click-to-expand for truncated messages from your other sessions in fullscreen mode</p>
<p>• Added path to --plugin-dir load-failure entries in the stream-json system/init plugin_errors, naming the directory that did not load</p>
<p>• Added an opt-in load_test_mode block to the Claude apps gateway config: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested</p>
<p>• Added a mantle upstream provider to the Claude apps gateway for Amazon Bedrock's Mantle endpoint</p>
<p>• Fixed SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback's result.usage</p>
<p>• Fixed MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress</p>
<p>• Fixed stdio MCP servers being left running when the session ended while they were still starting</p>
<p>• Fixed a brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected</p>
<p>• Fixed MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers</p>
<p>• Fixed the weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled</p>
<p>• Fixed /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused</p>
<p>• Fixed /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model</p>
<p>• Fixed dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model</p>
<p>• Fixed DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session's main model</p>
<p>• Fixed claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation</p>
<p>• Fixed claude plugin validate passing plugins whose outputStyles, themes, monitors, or lspServers paths are missing or point outside the plugin directory</p>
<p>• Fixed claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json</p>
<p>• Fixed claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them</p>
<p>• Fixed claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope</p>
<p>• Fixed plugins that declare no version being silently restored at their source's newest commit, not the installed one, when their cached files were missing</p>
<p>• Fixed user-installed plugins and marketplaces failing to load with "cache-miss" after the home or config directory was moved, for example in bind-mounted devcontainers</p>
<p>• Fixed installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again</p>
<p>• Fixed installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover</p>
<p>• Fixed permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog's own text</p>
<p>• Fixed /context not counting MCP server instructions: they now appear as their own row and count toward the total</p>
<p>• Fixed markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks</p>
<p>• Fixed claude mcp add, add-json, and remove reporting success when the user or local config file could not be written, for example inside a sandbox</p>
<p>• Fixed the first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them</p>
<p>• Fixed Claude's built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send</p>
<p>• Fixed keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix</p>
<p>• Fixed footer hints still saying "Enter to view" after footer:openSelected was rebound or unbound in keybindings.json</p>
<p>• Fixed keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state</p>
<p>• Fixed worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs</p>
<p>• Fixed sandboxed git asking credential helpers to store the sandbox proxy's login, which printed "failed to store"</p>
<p>• Fixed managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies</p>
<p>• Fixed Claude's edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository</p>
<p>• Fixed Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK</p>
<p>• Fixed the /remote-control menu cutting its QR-code hint mid-word in narrow terminals</p>
<p>• Fixed vim mode . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line</p>
<p>• Fixed vim mode cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank</p>
<p>• Fixed vim mode J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does</p>
<p>• Windows: Fixed the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses</p>
<p>• Improved the /mcp tool list: it shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon</p>
<p>• Improved MCP tool results: images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them</p>
<p>• Improved /tasks: rows show a status icon, the name and whole facts, the title and key hints stay on screen with many tasks, and the list gains paging keys, the mouse wheel and clicks</p>
<p>• Improved lists in /help, /hooks, /copy, /chrome, /memory, /ide, /release-notes, /rewind, /diff, /remote-env, /plugin and other pickers with page keys, mouse wheel and clicks</p>
<p>• Improved lists beside a search box, such as /skills and /artifacts, to draw their pointer dim while the search box has the keys, so only one pointer is highlighted</p>
<p>• Improved the compaction spinner: its timer now starts when compaction begins and it counts the summary's tokens as they stream, replacing the percentage bar</p>
<p>• Improved the browser page shown after signing in to an MCP server: centered layout, dark mode, and new artwork</p>
<p>• Improved the Skill tool's reply when a skill belongs to a plugin that failed to load, so Claude tells you the plugin could not be loaded instead of calling the skill uninstalled</p>
<p>• Improved prompt-audit on Claude Code configuration: stale paths, stale commands and contradicting instruction files now lead the report, and thinking keywords that Claude Code documents are kept</p>
<p>• Improved recovery from an installed_plugins.json that cannot be read at all: its contents are kept in a file beside it before it is rebuilt, and claude plugin list names that file</p>
<p>• Improved artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest</p>
<p>• Improved first-reply latency: a pattern-compile step that ran at the end of a session's first reply now runs while the reply streams in</p>
<p>• Improved first-request latency by reusing the preconnected API connection</p>
<p>• Improved startup: claude -p and Claude Code Remote no longer load the interactive UI, and the auto-mode classifier's rules and the Artifact tool load on first use instead of at launch</p>
<p>• Improved startup for claude.ai accounts whose Artifact tool features aren't known yet, as on a first run: the prompt no longer waits up to 1.5 s to check them; the first message waits if needed</p>
<p>• Changed interactive sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured; permissions.defaultMode still overrides it</p>
<p>• Changed the /ultrareview launch dialog to say that reviewing a local branch may upload uncommitted changes to tracked files</p>
<p>• Changed the /model picker's Opus row and the Default model's name to drop "(1M context)" where Opus already has a 1M context window; the window is unchanged</p>
<p>• Changed prompt suggestions in the terminal to appear less often after 20 in a row go unused; using one brings them back</p>
<p>• Changed --system-prompt and --append-system-prompt to accept their text and -file forms together; the file's text comes first</p>
<p>• Changed Skill(anthropic-skills:<name>) deny rules to also block that skill when Claude Desktop delivers it as a plugin, and Skill(skill:<name>) denies to match the skill's alias and display name</p>
<p>• Changed /rewind and /diff lists to move on the same keybinding actions as every other list (select:*); messageSelector:*/diff:* rebinds still work</p>
<p>• Changed the /workflows run list to size itself like other lists: half the terminal inline, and it keeps its title on screen when the prompt shows below</p>
<p>• Changed claude plugin eval to require git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version</p>
<p>• Changed artifact watching: a watch that was armed automatically (not one you asked for) now ends after 3.5 hours with no activity; publishing or watching the artifact again re-arms it</p>
<p>• Self-hosted runner: Changed lifecycle hooks' git to skip a repository's Git LFS pre-push hook, ignore a writable system core.hooksPath, and not sign commits without --configure-git</p>
<p>• Self-hosted runner: Changed GIT_SSL_CAINFO and GIT_SSL_NO_VERIFY under Anthropic-managed git: the runner's own git always verifies Anthropic's git route, and warning lines say what applies where</p>
<p>• Reverted the 2.1.282 reservation of the claude-ai name: skills, commands, workflows and MCP servers' skills and prompts so named load again, and Skill(claude-ai:*) rules are ordinary prefix rules</p>
<p>• [VSCode] Fixed the permission mode indicator showing Default while the session kept running in auto or bypass mode after an automatic switch out of it failed; the switch is now retried until it lands</p>
<p>• [VSCode] Fixed a session teleported from the web dropping the messages sent while Claude was working</p>
<p>• [VSCode] Fixed a Web session staying hidden from the session list, and an empty chat opening in its place, when an older version had saved an empty local copy of it</p>
<p>• [VSCode] Fixed a reopened session splitting a turn at a message Claude received mid-turn, such as an automatic continuation</p>
<p>• [VSCode] Fixed a reloaded session showing a rewound-away turn, or only the rows before a compaction</p>
<p>• [VSCode] Fixed the footer's agents pill drawing its icon off-center, with the status dot against the edge, in narrow panels</p>
<p>• [VSCode] Fixed the chat input showing its text slightly below the cursor and selection after pasting lines that end with a line break into a long prompt</p>
<p>• [Cloud sessions] Improved adding a repository to a running cloud session: a private repository your GitHub account can read but not push to now attaches for reading</p>
<p>• [Cloud sessions] Fixed cloud sessions occasionally redoing an already-finished step, such as posting a duplicate comment or push, after recovering from a server-side restart</p>
<p>• [Cloud sessions] Changed new routine schedules to default to a few minutes past the hour, with a note that routines set exactly on the hour can start several minutes late</p>
<p>• [Claude Tag] Added a "Channels Claude can search" admin setting that limits Claude's Slack search to public channels it has been added to, set per organization, workspace or channel</p>
<p>• [Claude Tag] Added a Back to Slack button on the page shown after connecting your Claude account, returning you to the thread you started from</p>
<p>• [Claude Tag] Fixed a channel's configure page listing no connectors or plugins when the channel gets its access bundle through an attach rule; rule-attached bundles are now shown</p>
<p>• [Claude Tag] Fixed access-bundle repository search missing repositories on GitHub App installs that are limited to a large list of selected repositories</p>
<p>• [Claude Tag] Fixed Claude occasionally posting the same reply twice when a new message interrupted it mid-reply</p>
<p>• [Claude Tag] Fixed channel routines that stopped running in older private channels whose Slack channel ID changed, for example after a Slack Connect share</p>
<p>• [Claude Tag] Fixed conversations in a channel set to "Channel only" all ending when a non-guest member joined and Slack was slow to confirm their membership</p>
<p>• [Code Review] Fixed "@claude review" requests going silent when GitHub failed to return the pull request: the request is retried once, and a comment explains if it still fails</p>
<p>• [Code Review] Fixed billing for a review that stopped at its time limit with nothing verified: it now shows as incomplete, isn't charged, and is retried once</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.282Claude Code v2.1.2822026-09-24T18:37:48Z<p>• Added a maxProseWidth setting that caps the width of Claude's prose in wide terminals while tables and code blocks keep the full width</p>
<p>• Added a startup notice, and /status and claude doctor entries, listing telemetry variables in a project's settings files that were ignored or that turned telemetry off</p>
<p>• Added the allowClaudeInChromeWithManagedMcp managed setting to let claude --chrome run alongside an exclusive managed-mcp.json; the error shown when Chrome is blocked now names it</p>
<p>• Added store.readiness_grace_seconds to the Claude apps gateway so /readyz can stay ready through a short Postgres outage such as a database failover</p>
<p>• Added a scrollbar to the /feedback drafts list in fullscreen mode; it appears while the mouse is over the list</p>
<p>• Fixed every request failing with a 400 error in conversations whose history holds web search results the API cannot decrypt (for example, from a turn answered through a third-party gateway)</p>
<p>• Fixed more cases of continued or resumed sessions (--continue, --resume) re-sending earlier messages in a changed form, which could make the API drop Claude's earlier reasoning</p>
<p>• Fixed earlier extended thinking being dropped when /model, /rename, /artifacts or another immediate slash command was used while Claude was working</p>
<p>• Fixed continued or resumed conversations losing earlier extended thinking when relaunched with a --tools list that leaves out a built-in tool offered earlier in the conversation</p>
<p>• Fixed sessions failing on every turn with an "Invalid data in redacted_thinking block" API error; Claude Code now drops the conversation's thinking blocks and retries once</p>
<p>• Fixed compaction failing when the summarization request is refused; it now retries on a fallback model</p>
<p>• Fixed a failed turn ("Effort 'xhigh' isn't available with thinking turned off") after a safety-related model switch in sessions with thinking off and effort above high</p>
<p>• Fixed an unanswered Fable usage-credits prompt switching models in SDK-hosted sessions such as Claude Desktop; the turn now ends instead, and Remote Control clients now see the model-switch notice</p>
<p>• Fixed /model with a full Fable model id stopping at an API error instead of opening the usage-credits prompt when the plan needs usage credits that aren't turned on yet</p>
<p>• Fixed requests failing for up to a minute with an "another Claude Code process is refreshing it" login error after that other process was closed or killed mid-refresh</p>
<p>• Fixed sessions started while another Claude Code window was refreshing the sign-in (common with several VS Code windows) not retrying their organization policy fetch</p>
<p>• Fixed CLAUDE.md and rules being read at startup through a repository symlink reaching macOS's /Network via .. or a /.vol-style kernel path, or a rules link to macOS's /home being listed</p>
<p>• Fixed Bash permission rules with a mid-pattern :* being skipped in settings files while --allowedTools honored them; they now work from every source, with a startup warning on how they match</p>
<p>• Fixed a command approved on a restored permission prompt running twice when a remote session's worker restarted</p>
<p>• Fixed managed settings ignoring a mistyped value for boolean lock keys such as disableClaudeAiConnectors or allowManagedPermissionRulesOnly; the lock now applies and startup names the key</p>
<p>• Fixed managed permissions, autoMode, worktree and attribution settings being ignored entirely when one nested value was invalid; the rest of the block now still applies</p>
<p>• Fixed repository, user and --add-dir skills, commands and skills-directory plugin manifests pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly</p>
<p>• Fixed safeguard block messages on Amazon Bedrock and Bedrock Mantle not showing a request ID; block messages now also show the message ID</p>
<p>• Vertex AI: Fixed web search not being offered for models Claude Code doesn't recognize yet, such as newly released ones</p>
<p>• Fixed Bash and PowerShell hiding a full disk quota behind "Exit code 1" and leaving large output files in temp</p>
<p>• Fixed tool input validation errors naming only an unknown, missing or mistyped parameter when other parameters in the same call were also invalid; those are now listed too</p>
<p>• Fixed pasted multi-line text being submitted line by line after the terminal's bracketed paste mode was reset mid-session</p>
<p>• Fixed the prompt's example text flashing and disappearing at startup in projects with a SessionStart hook</p>
<p>• Fixed a blank screen flashing before the first frame when starting in fullscreen mode</p>
<p>• Fixed garbled, misplaced rows in the non-fullscreen renderer after the screen got shorter while still taller than the terminal, e.g. deleting a prompt line while a shell command streams output</p>
<p>• Fixed a stale character left in the last column of a diff when a redrawn line's CJK character or emoji wrapped to the next row</p>
<p>• Fixed the cursor landing before the end of a prompt recalled from history when the prompt contains a tab</p>
<p>• Fixed the send-now hint showing ctrl+enter on terminals that send it as a newline (Windows Terminal before 1.25); it now shows ctrl+x ctrl+s there</p>
<p>• Fixed claude remote-control --debug failing with "Unknown argument: --debug", although Remote Control's own eligibility error says to run with --debug</p>
<p>• Fixed /install-github-app saying "cancelled" and then still pushing the branch and saving the API key secret; leaving now stops the remaining steps and reports what was already done</p>
<p>• Fixed /feedback, /bug and /share on Bedrock, Vertex and other third-party providers still saving the report file after you cancelled during the save</p>
<p>• Fixed plugin uninstall reporting success and deleting the plugin's saved options when its settings file still enabled it or could not be read; it now stops and names the file</p>
<p>• Fixed plugin uninstall deleting a plugin's saved options and secrets when the list of installed plugins could not be read after the removal; they are now kept and the uninstall says so</p>
<p>• Fixed a key typed right after / in /skills moving the skill list instead of reaching the search box</p>
<p>• Fixed the terminal cursor jumping from the /skills search box to the skill list while typing, which could hide the caret and put IME input in the wrong place</p>
<p>• Fixed lists with a scrollbar, such as /skills and /mcp, being two columns narrower outside fullscreen mode, where the scrollbar can never appear</p>
<p>• Fixed the agent panel footer wrapping onto two lines with long rebound keys, and its "Esc to collapse" hint ignoring a rebound collapse key</p>
<p>• Fixed a doubled · separator in the /tasks dialog footer when the stop-all-agents shortcut is unbound in keybindings.json</p>
<p>• Fixed artifact publishes failing when Claude gave the version a label longer than 60 characters; the label is now shortened</p>
<p>• Fixed screen-reader mode, quoted lists and very long lists dropping the blank lines at the top of a code block that opens a list item, directly or inside a quote</p>
<p>• Fixed PDF page-read error messages: paths with accented or non-Latin characters now appear readably, and a folder named like "password" or "invalid" can no longer make the error name the wrong cause</p>
<p>• Fixed vim mode >> indenting empty lines, r with a count longer than the line changing text, 2J joining one line too many, and a count on the last line (2dd, 2>>) shifting or deleting it</p>
<p>• Fixed vim mode cursor placement: after dd, dj, dG or a whole-line p/P it lands on the first non-blank, yy no longer moves it, and Esc after an emoji no longer leaves it inside the emoji</p>
<p>• Fixed vim mode ignoring a count typed before . when repeating x, s, p, d or c, and whole-line p/P, o, O, J, >> and << acting on the wrong line when a line above wraps</p>
<p>• Fixed vim mode leaving the cursor past the end of a prompt recalled from history or pulled back from the queue in normal mode, so x did nothing</p>
<p>• Improved the time to resume very large sessions, including ones that were never compacted</p>
<p>• Improved the error shown on Windows when a session can't be resumed because its transcript file could not be read (EBADF): it now names possible causes and what to try</p>
<p>• Improved the Claude Desktop unknown-model error to suggest switching to a different model</p>
<p>• Improved rendering of unusual Unicode in permission prompts</p>
<p>• Improved /artifacts: titles line up in one column, details are dropped whole instead of cut mid-word, and the list supports PgUp/PgDn, Home/End, the mouse wheel and clicks</p>
<p>• Updated the claude-api skill: pre-output refusal billing now links to the How refusals are billed docs, mid-stream refusals bill at normal rates, and pre-output refusals count against rate limits</p>
<p>• Updated the claude-api skill to recommend ant apply for keeping Managed Agents resources as version-controlled files</p>
<p>• Changed auto mode to use the server-side classifier by default on a direct Anthropic API connection when telemetry is off (CLAUDE_CODE_AUTO_MODE_SERVER=0 opts out)</p>
<p>• Changed sandbox.excludedCommands to ignore project and local settings entries when managed settings or --settings set allowUnsandboxedCommands: false, or managed allowManagedDomainsOnly: true</p>
<p>• Changed project and local settings to ignore OpenTelemetry variables that turn on export, set its endpoint, or capture content, like CLAUDE_CODE_ENABLE_TELEMETRY and OTEL_LOG_*</p>
<p>• Changed Windows/WSL managed settings so an admin policy that is present but invalid or unreadable (HKLM, managed-settings.json) keeps user-writable HKCU and WSL /etc/claude-code from applying</p>
<p>• Changed Skill(anthropic-skills:*) and Skill(claude-ai:*) allow rules to cover only skills synced from claude.ai, not plugins or other skills that merely use such a name</p>
<p>• Changed skill folders, command files and workflow commands in the anthropic-skills or claude-ai namespace to no longer load; a plugin so named still loads but yields name ties to synced skills</p>
<p>• Changed MCP servers configured under the name anthropic-skills or claude-ai to list no skills or prompts (their tools still work); rename the server in your MCP configuration to list them again</p>
<p>• Changed the ultracode visuals in /effort and the prompt input to plain styling (no ripple, border flourish or keyword glimmer) and removed the dynamic-workflows spinner tip</p>
<p>• Changed the Clawd mascot's feet in the start-up banner to sit under the corners of his body</p>
<p>• [VSCode] Fixed long replies falling behind the stream: the panel no longer re-parses the whole reply on every update</p>
<p>• [VSCode] Fixed the dictation mic button covering the message input's scrollbar when the input is tall enough to scroll</p>
<p>• [VSCode] Fixed Remote Control sessions started on this computer not opening from their Web entry in the session list; they now open the local conversation unless it's running elsewhere</p>
<p>• [VSCode] Fixed an editor tab's sign-in screen hanging silently after the extension host restarts; it now shows the "stopped responding" notice too</p>
<p>• [Cloud sessions] Added Claude GitHub App status to Settings › Connectors › GitHub: whether the app is installed and reachable for your account, plus steps to connect, install or reconnect</p>
<p>• [Cloud sessions] Added "Open repository" and "Open compare page" links to the repository menu of a cloud session whose repository is hosted on a Git server other than GitHub</p>
<p>• [Cloud sessions] Added attaching a repository from a different GitHub owner, such as a fork's upstream, to a running cloud session that already has one, including sessions started from Slack</p>
<p>• [Cloud sessions] Fixed the next run time shown for an hourly routine being 30 minutes off for people in half-hour-offset time zones such as India</p>
<p>• [Cloud sessions] Improved how quickly the Routines page and the sidebar's Scheduled list load for accounts whose past sessions scheduled many check-in reminders</p>
<p>• [Claude Tag] Fixed auto-join channel patterns saved for one workspace in Claude Tag admin settings being ignored on an Enterprise Grid org-wide install; Claude now joins matching new channels</p>
<p>• [Claude Tag] Fixed Claude not responding in an Enterprise Grid channel shared between two workspaces of one organization when the channel's Claude Tag version was saved from the other workspace</p>
<p>• [Claude Tag] Fixed the earlier Claude in Slack app's progress card for sessions on a GitHub Enterprise Server repository: it now names the repository and offers a working Create PR button</p>
<p>• [Claude Tag] Fixed Slack threads whose model has been retired falling back to another model on every reply, slower and with a fallback note each time; the thread now moves to a working model</p>
<p>• [Claude Tag] Fixed files Claude uploads to Slack not being able to carry a caption containing a table; captions now render with the same formatting as replies</p>
<p>• [Claude Tag] Fixed Claude's threads in Slack's Agents & tools view sometimes being listed under their first message instead of their name; later renames now update the list too</p>
<p>• [Claude Tag] Fixed removing a GitHub organization's grant from an access bundle's Repositories tab in Claude Tag admin settings failing to save after that GitHub organization was disconnected</p>
<p>• [Claude Tag] Fixed Claude always replying "Couldn't check this channel just now" in a channel shared with a Grid workspace it isn't added to; the notice now says which workspace needs the app</p>
<p>• [Claude Tag] Fixed the cost and token totals in Claude's reply footer reading many times too high after the session's cloud worker restarted</p>
<p>• [Claude Tag] Changed the bordered cards Claude uses in Slack replies for plans, tables and details to render wide by default instead of a narrow width</p>
<p>• [Claude Tag] Changed newly connected Slack workspaces to follow the current default model instead of keeping whichever model was the default when they were connected</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.281Claude Code v2.1.2812026-09-23T19:18:57Z<p>• Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode</p>
<p>• Added assume_role on Claude apps gateway Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer</p>
<p>• Added guardrail: {id, version} on Claude apps gateway Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)</p>
<p>• Added telemetry.resource_attributes to the Claude apps gateway config, to put fixed labels on the telemetry of Claude Desktop and /login sessions</p>
<p>• Added "attribution": false in settings.json to hide all commit and PR attribution; older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions</p>
<p>• Added MCP URL-mode elicitation on 2026-07-28 protocol connections, so servers can ask Claude Code to open a browser-based flow; no waiting dialog is left on screen when the server has no way to confirm completion</p>
<p>• Added MCP server checks to claude plugin validate: it reports .mcp.json entries that would be silently dropped at load, undeclared ${user_config.*} references, and insecure URLs</p>
<p>• Added an auto mode recommendation to /insights that estimates how many permission prompts auto mode could have handled in your recent sessions</p>
<p>• Added a scrollbar to the /skills, /mcp and /plugin Installed lists in fullscreen mode, like the one /workflows now has: it appears while the mouse is over the list and can be clicked or dragged</p>
<p>• Fixed a crash ("unrecoverable interface error") that could end a session while an API request was being retried</p>
<p>• Fixed a turn that could retry indefinitely, ignoring --max-turns, when the model alternated unparseable tool calls and output-limit truncation</p>
<p>• Fixed resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call's input or a tool-search result while its server was still reconnecting, or a tool-search result whose loading turn was interrupted), which could make the API drop the conversation's prior reasoning</p>
<p>• Fixed resuming a very large session sometimes restoring only its last few messages</p>
<p>• Fixed a session resumed after a restart during a pending permission prompt sending a different history than before, which broke the prompt cache from that point</p>
<p>• Fixed resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden "Continue" message</p>
<p>• Fixed sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once</p>
<p>• Fixed the prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway)</p>
<p>• Fixed responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events</p>
<p>• Fixed responses failing with "Content block not found" when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived</p>
<p>• Fixed an empty completed response being requested twice when the connection dropped before the stream's final event</p>
<p>• Fixed the stop reason being lost when a proxy sends a trailing usage-only frame</p>
<p>• Fixed CLAUDE_CODE_RETRY_WATCHDOG sessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a long Retry-After from a 5xx</p>
<p>• Fixed fast mode retrying rate-limited requests back to back when the server sent Retry-After: 0</p>
<p>• Fixed a tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message</p>
<p>• Fixed conversations getting permanently stuck on "tool_use.name: String should have at most 200 characters" after the model called a tool by an overlong name</p>
<p>• Fixed tool calls failing with "Failed to get memory usage", or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors</p>
<p>• Fixed --input-format stream-json sessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn with an error when an earlier assistant message had plain-string content</p>
<p>• Fixed non-interactive sessions (-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session</p>
<p>• Fixed headless sessions with host-side (SDK) MCP servers stalling on the first message when the host stops responding mid-handshake; remote sessions now wait a few seconds at most</p>
<p>• Fixed interactive startup waiting on the managed-settings network request (about 80 ms, 17+ seconds when the network is unreachable) when no MCP servers or plugins are configured</p>
<p>• Fixed a delay of up to two minutes before responding when reading or @-mentioning a PDF larger than 3 MB</p>
<p>• Fixed an interrupted Read of specific PDF pages leaving its page render running for up to two minutes</p>
<p>• Fixed permission dialogs and attachment checks reading a path under macOS's /.vol, /.nofollow or /.resolve (which can reach a network mount) before approval</p>
<p>• Fixed a recursive rm whose target is only command-substitution output, such as rm -rf "$(pwd)", running unprompted in auto and --dangerously-skip-permissions mode; it now asks even with a Bash allow rule, unless run with CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1</p>
<p>• Fixed a permission rule containing a NUL byte being expanded into a wildcard match; such a rule now matches nothing</p>
<p>• Fixed sandbox excludedCommands entries not matching git rev-parse --git-dir, programs named like shell builtins, and commit messages containing [WIP] or # lines</p>
<p>• Fixed sandboxed Bash commands being unable to write to $TMPDIR when CLAUDE_CODE_TMPDIR is set</p>
<p>• Fixed claude --bg starting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively</p>
<p>• Fixed --setting-sources (and SDK settingSources) not being forwarded to spawned sessions: teammates, /bg, claude agents sessions and --worktree --tmux now start with the parent's restriction</p>
<p>• Fixed Read, Write, Edit and NotebookEdit: a file path containing a null byte now fails that tool call with a clear error instead of ending the whole turn</p>
<p>• Fixed Write refusing a call that gives the file path or content twice under two parameter names with identical values</p>
<p>• Fixed CLAUDE.md and rules files from an --add-dir directory inside the working directory being sent to the model twice in headless and SDK sessions</p>
<p>• Fixed remote sessions staying on "needs approval" with a stale prompt after a permission prompt and a sandbox network-access prompt overlapped and both were answered</p>
<p>• Fixed cloud sessions not telling Claude about background agents that finished just before a worker restart</p>
<p>• Fixed scheduled routine and notification turns in remote sessions not receiving turn-start notices (newly available tools, MCP changes, date, todos) until after the first tool call</p>
<p>• Fixed scheduled tasks and /loop wakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turn</p>
<p>• Fixed Remote Control reporting "disabled by your organization's policy" when the org policy simply hadn't loaded yet; it now retries the fetch and says it couldn't verify</p>
<p>• Fixed the Artifact tool missing from Remote Control sessions that claude remote-control starts for you to open from Claude Desktop, claude.ai or the mobile app</p>
<p>• Fixed macOS credential writes dropping stored MCP OAuth tokens or deleting the keychain entry when the login keychain was locked (e.g. right after wake)</p>
<p>• Fixed gcpAuthRefresh/awsAuthRefresh login processes being left running (and holding their localhost callback port on Windows) when Claude Code exits or the refresh times out</p>
<p>• Fixed the "Not logged in · Run /login" footer and missing claude.ai connectors persisting in a session after logging in from another Claude Code process</p>
<p>• Fixed mcp_tool hooks on blocking events (PreToolUse and similar) being skipped while their MCP server was still connecting; they now wait for it, up to the MCP connect timeout</p>
<p>• Fixed the same MCP server being connected twice when a plugin or claude.ai connector and a configured server spell its URL differently (host letter case, default port, trailing slash)</p>
<p>• Fixed MCP_CONNECTION_NONBLOCKING=0 giving up on claude.ai connectors after 1s instead of honoring MCP_CONNECT_TIMEOUT_MS</p>
<p>• Fixed --channels plugin entries being checked against the installed plugin's marketplace alone; the installed plugin's name must now match the entry as well</p>
<p>• Fixed --plugin-dir on a folder of plugins that also has a .claude-plugin/marketplace.json loading one empty plugin instead of the plugins in it</p>
<p>• Fixed claude plugin uninstall refusing to remove a project-scope plugin that isn't enabled, saying it is "enabled at project scope" while claude plugin disable says it is already disabled</p>
<p>• Fixed claude plugin update failing for project-scoped plugins when --scope is omitted — it now resolves the scope the plugin is installed at instead of assuming user</p>
<p>• Fixed claude plugin validate reporting privacyPolicyUrl, supportUrl and other listing metadata keys in plugin.json as unknown fields</p>
<p>• Fixed known_marketplaces.json recording a marketplace as refreshed when its remote could not be reached and CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE kept the existing clone</p>
<p>• Fixed the /plugin Errors tab showing no confirmation after its last error is resolved</p>
<p>• Fixed /plugin starting a second uninstall or update of the same plugin when Enter was pressed again while the first was still running</p>
<p>• Fixed a y held while /plugin checks a marketplace source adding the marketplace the instant the "Add marketplace?" question appears, before it can be read</p>
<p>• Fixed 1 answering Yes in /permissions' delete and remove-directory confirms while the pointer is on No, which let a held 1 remove one workspace directory after another</p>
<p>• Fixed Alt+T and /config offering to turn thinking off on models that can't; thinking now stays on there, with a one-line reason in place of the switch</p>
<p>• Fixed /context total leaving out messages added since the last response; it now matches its categories and can read higher than the status line</p>
<p>• Fixed /model showing the raw API error JSON and request ID when the API refuses the picked model; it now shows the server's message and says the model was not changed</p>
<p>• Fixed API errors from an HTML error page (such as a proxy's 429 or 502 page) printing the page's raw markup or leaving out the HTTP status, and error messages breaking onto a second line when the server's error text ended in a newline</p>
<p>• Fixed /feedback, /bug and /share still sending your report after you cancelled it while it was being sent</p>
<p>• Fixed /feedback, /bug and /share failing every send with "Couldn't send feedback" after a Remote Control Stop arrived while the dialog was open</p>
<p>• Fixed /ide showing "No available IDEs detected" while also listing a running IDE</p>
<p>• Fixed the terminal being left in a broken state (crash or garbled input) when /setup-bedrock or /setup-vertex restarts Claude Code to apply new settings</p>
<p>• Fixed /config exiting when respectGitignore or copyFullResponse in ~/.claude.json holds null</p>
<p>• Fixed the session name from /rename disappearing while Claude asks a multiple-choice question, so side-by-side sessions stay identifiable</p>
<p>• Fixed one-line pastes showing on their own lines in the sent message for prompts from VS Code or Remote Control and for expanded paste placeholders</p>
<p>• Fixed a message queued while Claude is working losing or changing the IDE selection it was written with, and queued messages not showing their selection</p>
<p>• Fixed pressing Shift+Tab twice quickly landing on the wrong permission mode</p>
<p>• Fixed Ctrl+C or Ctrl+D pressed twice quitting Claude Code instead of closing the dialog in the remaining dialogs and pickers, such as /memory, /hooks, /mcp (including a server's sign-in screen), /export, /copy, /theme, and /teleport's uncommitted-changes and login prompts (where Esc also quit)</p>
<p>• Fixed keys that arrive in one burst of input (e.g. over Remote Control), such as an arrow key followed by Enter, x or s, acting on the previous selection: a stale effort level in /effort and the model picker, and the previously highlighted row in /skills, the background task rows under the prompt, MCP server prompts and /install-github-app</p>
<p>• Fixed /install-github-app updating the workflow after "Skip workflow update" was chosen, running setup twice on a repeated Enter, and ↑ on the repository step blocking a typed repository name when no repository was detected</p>
<p>• Fixed vim mode: dj/dk/dG/dgg and their c/y forms acting on part of a line; 1G going to the last line; d0/c0/y0 doing nothing; the cursor being off by one after . repeats an insert; and o/p on a !-prefixed line switching to shell mode</p>
<p>• Fixed vim mode cw on a space, an empty line, a word's last letter or a one-letter word also changing the next word; word motions stopping inside words in Hindi, Bengali and other scripts; and ., p or P that inserts text starting with ! switching to shell mode, losing text or editing the wrong character</p>
<p>• Fixed the prompt cursor moving one character too far after an accent typed as its own key</p>
<p>• Fixed an extra blank line above a list item whose text starts on the line after its bullet, in screen-reader mode, quoted lists and long lists</p>
<p>• Fixed bulleted lists of plain numbers (like - 316.) showing as letters, roman numerals or the wrong numbers</p>
<p>• Fixed the agent panel's footer hint ignoring keys rebound in keybindings.json, and showing a stray · when the stop-all-agents shortcut is unbound</p>
<p>• Fixed the agent panel footer offering "Enter to view" and "x to stop" on the agent you are already viewing (where x types into its input), and "Enter to view" on the main row when main is already shown</p>
<p>• Fixed a mouse click on an agent-panel row leaving the keyboard cursor on the previously selected row</p>
<p>• Fixed Esc interrupting the running turn instead of deselecting the selected agent-panel row</p>
<p>• Fixed PgUp and PgDn doing nothing in a dialog's list (for example /skills) in fullscreen mode</p>
<p>• Fixed /heapdump summary saying most memory is native when it is in the JS heap snapshot</p>
<p>• Fixed Bash edit-diff snapshot directories piling up in the temp folder: abandoned ones are now deleted right away and the rest when Claude Code exits</p>
<p>• Fixed /workflows moving the pointer to a different run, and x stopping it, when a new run started while the list was open</p>
<p>• Fixed the selected tab in tabbed dialogs (/config, /plugin, /permissions) showing no highlight while the tab bar has focus when color is off (NO_COLOR)</p>
<p>• Fixed the mouse wheel over the /plugin Installed list scrolling the pane behind it instead of the list</p>
<p>• Fixed the hover highlight lingering on a list row in fullscreen mode after scrolling or filtering moved it away from the mouse</p>
<p>• Fixed long list rows, such as in the /remote-control menu, wrapping onto a second line in narrow terminals; they're now cut with …</p>
<p>• Fixed /hooks and /mcp detail views printing a long value over the row below it in narrow terminals</p>
<p>• Fixed lists such as a skill's state options in /plugin not being answerable by typing a number in screen-reader mode</p>
<p>• Windows: Fixed Bash commands that write to $TMPDIR/… failing with "Permission denied"</p>
<p>• Windows: Fixed a race in which Claude Code sessions updating at the same moment could delete each other's claude.exe backup, which could leave no claude.exe behind</p>
<p>• Improved Claude Desktop sign-in and usage-limit error messages to point at the app instead of terminal commands</p>
<p>• Improved startup: managed settings and policy fetches no longer retry requests that can never succeed</p>
<p>• Improved interactive startup time: git reads, startup telemetry and the Bedrock/Vertex model-upgrade checks no longer run before the first frame</p>
<p>• Improved the time to resume long sessions that read many files; the restored file cache now matches the files as they were read</p>
<p>• Improved the time to resume very long sessions that have been compacted, most noticeably through the Agent SDK and Claude Desktop</p>
<p>• Improved "Prompt is too long" recovery in sessions dominated by one very large first prompt: that prompt is now summarized on its own instead of being left out of the summary</p>
<p>• Improved auto mode after resuming a session in a new process: the permission classifier can now reuse its earlier prompt cache instead of rewriting it</p>
<p>• Improved the auto mode denial message so Claude treats a denial as covering the outcome, not only the exact command</p>
<p>• Improved the dangerous-rm check to also flag a removal at a shell variable followed by a top-level directory name, at a variable derived from the working directory, or at a backslash-only target</p>
<p>• Improved sandbox guidance on macOS: when a local dev server can't bind a port, Claude now points to sandbox.network.allowLocalBinding</p>
<p>• Improved --agents to accept the path to a JSON file (with -p) as well as inline JSON, and to allow an empty prompt</p>
<p>• Improved /batch to run where a WorktreeCreate hook provides the agent worktrees, not only inside a git repository</p>
<p>• Improved plugin hook-failure errors to name the offending plugin, and added a claude plugin validate warning when a shell-form hook leaves ${CLAUDE_PLUGIN_ROOT} unquoted (it breaks on plugin paths with spaces)</p>
<p>• Improved the / menu, /skills, /context and the /plugin Installed list to show skills synced from claude.ai by their short name when no other command uses it, not anthropic-skills:<name></p>
<p>• Improved /deep-research reliability on long research briefs by removing unused required fields from the scope step's output</p>
<p>• Improved the writing in published artifact pages: the bundled artifact-design skill now asks Claude for plain, direct prose</p>
<p>• Improved artifact publishing on slow connections: large page uploads are now sent compressed</p>
<p>• Improved the large CLAUDE.md startup notice to also count instruction files together, so many mid-sized files and @-imports are caught</p>
<p>• Improved debug logs to name settings env variables ignored because the session's launch environment already sets them</p>
<p>• Improved keyboard navigation in tabbed dialogs such as /permissions and /usage: ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus</p>
<p>• Improved /help and /sandbox: ←/→ and Tab switch tabs from inside a tab's list, and ↓ on an empty Custom commands tab in /help no longer leaves the keys stuck until Esc</p>
<p>• Improved /install-github-app, /desktop, the /permissions auto mode environment prompts, and the /plugin "Add marketplace?" and "Run this command?" prompts: they now use the standard dialog frame with key hints, and Ctrl+C or Ctrl+D cancels them on the second press like other dialogs</p>
<p>• Improved the /workflows and /mcp lists: they page (PgUp/PgDn, Home/End) and take j/k and the mouse like other lists, their arrows follow select:previous/select:next rebinds, and x in /workflows stops the run the pointer is on</p>
<p>• Improved the /plugin plugin and marketplace details menus and the /remote-control already-connected menu: they now support Home/End and clicking a row</p>
<p>• Improved the background workflow row below the prompt: it now shows the name, a progress bar, the agent count on wide terminals, elapsed time, total tokens, and the large-workflow warning</p>
<p>• Improved the /plugin Installed list: rows now line up in columns (status, name, type, details) across every section</p>
<p>• Improved /skills: each row now leads with the skill's name, with ✔ or ◯ alone showing on or off, and stays on one line in narrow terminals</p>
<p>• Improved narrow list rows (/skills, /workflows, /feedback): a name keeps 20 columns beside its first detail, and details are shown whole or not at all</p>
<p>• Improved /diff: a scrollbar shows where you are in a long list of changed files, and long paths no longer wrap their rows</p>
<p>• Improved /hooks: a hook's detail screen now says what kind of hook it is and where to change it, instead of always pointing at settings.json, and the hooks-disabled, safe mode and managed-hooks-only notices each say what is happening in one plain sentence</p>
<p>• Improved screen-reader output in /mcp: a disabled server is read as "off" instead of "pending"</p>
<p>• Improved the Remote Control confirmation: its options are briefly inactive again after the terminal window regains focus, so a key pressed while switching back cannot answer it</p>
<p>• Changed send now (ctrl+enter or ctrl+x ctrl+s) to move running tools to the background instead of cancelling the turn</p>
<p>• Changed auto mode so that, where its classifier review runs server-side, read-only and sandboxed shell commands also wait for that review and are blocked when it flags them</p>
<p>• Changed CLAUDE_CODE_AUTO_MODE_SERVER to also apply on a direct Anthropic API connection: 0 opts out of the server-side auto mode classifier (the local classifier then counts toward usage), 1 opts in</p>
<p>• Changed the dangerous rm prompt in --dangerously-skip-permissions and auto mode to wait 2 minutes for an answer, then deny the command with a rewrite hint so unattended sessions keep going (CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1 turns this off)</p>
<p>• Changed AGENTS.md support to also work on Amazon Bedrock, Google Vertex AI, Microsoft Foundry, LLM gateways, and sessions with telemetry disabled</p>
<p>• Changed Claude apps gateway to refuse to start when a managedMcpServers entry's envHelper path starts with \??\ or /??/, a path form current Claude Desktop refuses to run</p>
<p>• Changed self-hosted runners to pass system prompts to Claude Code as private files instead of command-line text, so large prompts no longer fail the launch; a wrapper or command hook that appends --system-prompt or --append-system-prompt must switch to --system-prompt-file or --append-system-prompt-file</p>
<p>• Changed queued messages to show in the conversation above the spinner instead of under it</p>
<p>• Changed the session artifact links under the prompt into one footer pill (⧉ name or ⧉ N) that opens /artifacts, which now lists this session's artifacts first</p>
<p>• Changed the Artifact tool to let Claude load scripts from unpkg.com in artifact pages</p>
<p>• Changed hovering a list row in fullscreen mode, including in /config, to tint the row instead of drawing a second ❯ pointer beside the focused row's</p>
<p>• Changed /mcp: each server's row now starts with its status icon and name, says its state once, and in a narrow terminal drops trailing facts like "managed" before shortening the name</p>
<p>• Changed /workflows: each run's row leads with its status icon and elapsed time, and a narrow terminal keeps the run's name and time, dropping the agent and token counts first</p>
<p>• Changed Remote Control attachment downloads to reuse connections and to skip files already downloaded in the session</p>
<p>• Changed MCP resource lists (the resource list tool and @-mention suggestions) to skip MCP Apps UI resources; reading one by URI still works</p>
<p>• Changed claude plugin uninstall --json and the /plugin dialog to say a plugin's data was kept when its folder stays because another installed plugin uses it or install records cannot be read</p>
<p>• Changed the background tasks list (/tasks): pressing x on a running /ultrareview now asks for confirmation before stopping the review</p>
<p>• Removed the leftover "(removed)" /agents entry from the command menu and /help; typing /agents still explains where the wizard went</p>
<p>• [VSCode] Added a Continue/Stop prompt in the VS Code and JetBrains panels when auto mode falls back to billed classifier requests, replacing the unanswerable warning line</p>
<p>• [VSCode] Fixed opening a Web session with no messages saving an empty local copy that could not be resumed; an error now says where to continue it</p>
<p>• [VSCode] Fixed a claude.ai/code session opening empty or with only part of its conversation, with no error, when the server failed to return its history, part of it failed to load, or a network sign-in page answered in its place; it now shows an error and can be opened again</p>
<p>• [VSCode] Fixed conversations in editor tabs hanging silently after the extension host restarts; the tab now tells you to reopen it from the session list</p>
<p>• [VSCode] Fixed Claude attaching option previews to multiple-choice questions in the chat panel, where the question card never shows them</p>
<p>• [VSCode] Fixed the session manager's cost and usage block wrapping mid-text on a narrow side bar, and showing totals from a previous login after an account switch</p>
<p>• [Claude Code on the web] Added a Fast mode switch to the composer's model menu in cloud sessions, shown when your plan includes fast mode and the selected model supports it</p>
<p>• [Claude Code on the web] Added a settings shortcut on the GitHub setup tip and a "Troubleshoot GitHub connection" link in the repository pickers, both opening your GitHub connection page</p>
<p>• [Claude Code on the web] Fixed routines with a GitHub trigger for a pull request being converted to draft never firing; they now start a run when the pull request is converted</p>
<p>• [Claude Code on the web] Fixed cloud sessions on a repository that isn't hosted on GitHub showing a Create PR button that could never work; the button is now hidden there</p>
<p>• [Claude Code on the web] Fixed the GitHub setup tip on claude.ai/code covering the repository picker's search box and rows while the picker is open; it now steps aside until the picker closes</p>
<p>• [Claude Code on the web] Improved the file card shown when a cloud session can't open a file: it now says whether the file no longer exists or the session's permission settings block reading it</p>
<p>• [Claude Tag] Added a short line in the Slack thread after someone presses Stop, naming who stopped Claude's response and saying to mention @Claude to continue</p>
<p>• [Claude Tag] Fixed Slack channels where Claude could permanently stop responding to replies inside threads; affected channels now recover on their own with the next new message to Claude</p>
<p>• [Claude Tag] Fixed Claude resuming a stopped request after you press Stop in Slack, for example when a check-in fired or a background task ended; messages sent mid-response are now read</p>
<p>• [Claude Tag] Fixed Slack replies arriving many minutes late, or never, after Claude's session crashed mid-task, such as on a failed setup script; it now restarts on its own within minutes</p>
<p>• [Claude Tag] Fixed Claude in Slack promising an automatic restart, then failing generically, when a session's configuration is too large to start; the thread now says why and how to retry</p>
<p>• [Claude Tag] Fixed very long Slack threads: Claude could silently withhold a reply after judging it against weeks-old messages, and a restart deep into the thread could lose recent context</p>
<p>• [Claude Tag] Fixed Claude answering every mention with "Couldn't check this channel just now" in a Slack channel moved from Enterprise Grid org-wide sharing into a single workspace</p>
<p>• [Claude Tag] Fixed very large Enterprise Grid workspaces reached mostly through channels shared across workspaces getting "Couldn't check this channel" again after a quiet hour</p>
<p>• [Claude Tag] Fixed a Slack request blocked by your organization's inference hook showing a generic retry notice; the thread now shows the hook's deny message and Claude doesn't retry</p>
<p>• [Claude Tag] Fixed Claude in Slack offering to switch to models your organization can't use; it now lists and offers only models the switch will actually accept</p>
<p>• [Claude Tag] Fixed requests to DynamoDB and Kinesis account-based endpoints failing to authenticate when sent through an AWS connection in Claude Tag</p>
<p>• [Claude Tag] Fixed the Plugins sections in Claude Tag admin settings failing to load for organization admins and listing attached plugins as raw IDs; they now load and show each plugin's name</p>
<p>• [Claude Tag] Changed the routine list Claude gives when asked in a Slack thread to show that thread's own scheduled tasks by default instead of every routine in the channel</p>
<p>• [Code Review] Fixed a pull request getting no review when its reviewed commit was force-pushed away while a failed review was being retried in a repository not set to review every push</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.280Claude Code v2.1.2802026-09-22T16:37:53Z<p>• Added Claude Opus 5.5 (claude-opus-5-5), now the default Opus model — 1M context, $4/$20 per Mtok with $0.20/Mtok cache reads</p>
<p>• Added mouse support to more lists in fullscreen mode: the wheel scrolls the /skills list, and a skill's state options in /plugin can be clicked</p>
<p>• Added CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH to change the 2,048-character cap on MCP tool descriptions and server instructions for every MCP server in the session</p>
<p>• Added hook output sizes and the number of oversized outputs saved to a file to the hook_execution_complete OpenTelemetry event</p>
<p>• Fixed writes through a symlinked path being judged by their in-tree spelling: the prompt names where the write lands, and acceptEdits, allow rules and auto mode no longer approve one landing outside</p>
<p>• Fixed auto mode retrying an action over and over when a safety check declined to review it; the action is now denied once, noting that retrying won't help</p>
<p>• Fixed auto mode denying actions over and over without pause when a safety check gave no answer; retries now back off, and the turn stops with a message after ten in a row</p>
<p>• Fixed Write calls failing validation when a model sends path, file_text, file_content or a stray description instead of file_path and content</p>
<p>• Fixed Ctrl+C or Ctrl+D pressed twice in most dialogs (/model, /effort, /config, /status, /usage, /plugin, /sandbox, /permissions, /artifacts, /mobile, /login, /upgrade, /usage-credits, /install-github-app, /setup-bedrock, /setup-vertex) quitting Claude Code instead of closing the dialog</p>
<p>• Fixed a click that only brought the terminal window to the front also triggering the item under the pointer — in search pickers, tab bars, agent/workflow rows, slash-command links and suggestion dropdowns</p>
<p>• Fixed a stray n closing dialogs and a stray y confirming them; Enter and Esc accept and cancel (bind y/n to confirm:yes/confirm:no in keybindings.json to restore)</p>
<p>• Fixed text fields in dialogs losing a typed letter, digit or Space to a keybinding on that key</p>
<p>• Fixed the prompt line staying scrambled on Windows terminals after invisible characters were removed on Enter; the screen is now repainted so you review the exact text that will be sent</p>
<p>• Fixed the invisible-character cleanup removing the zero-width non-joiner that Persian and Arabic text uses to attach a suffix to a Latin word or number, such as the plural of "PDF"</p>
<p>• Fixed voice dictation not stopping on Ctrl+C (the prompt cleared but the microphone kept recording), Esc not cancelling while a transcript was processing, and held Space starting dictation from the transcript view and vim NORMAL mode</p>
<p>• Fixed a model switch made from a host app (Claude Desktop, VS Code, SDK) while Claude is working causing a prompt-cache miss on the next prompt</p>
<p>• Fixed resumed fork subagents rebuilding their tool list instead of re-sending the one they first used, which broke prompt caching for that agent</p>
<p>• Fixed subagent hand-back messages showing an internal provenance preamble when expanded outside verbose mode</p>
<p>• Fixed installed_plugins.json keeping the install-time commit after updating a plugin from a GitHub repository or git URL that tracks a branch or tag</p>
<p>• Fixed skills in ~/.claude/skills/ being moved to ~/.claude/skills/.trash/ when a manifest.json in that folder listed their names</p>
<p>• Fixed the session feedback survey showing no hover highlight on light and ANSI themes</p>
<p>• Fixed /workflows briefly showing a one-row list before opening the only run</p>
<p>• Fixed the mouse wheel not scrolling selection lists with hidden options (such as /model and /permissions) in fullscreen mode</p>
<p>• Fixed a skill you switched off showing the same red ✘ as a plugin that failed to load in /plugin and /skills; off now shows a dim ◯</p>
<p>• Fixed multi-select option descriptions being indented under the option number instead of under the label</p>
<p>• Fixed the search box in /plugin, /skills and /mcp losing its right border in fullscreen mode</p>
<p>• Fixed /mcp showing △ in the server list but ⚠ in the detail view for the same server; the list, detail views and /plugin now all show ⚠</p>
<p>• Fixed Home and End doing nothing in the /config settings list and in selection lists such as /model, /memory and permission prompts</p>
<p>• Fixed PgUp/PgDn in the /skills menu wrapping past the first or last skill instead of stopping there</p>
<p>• Fixed Tab silently changing the selected setting's value in the /config list; it now does nothing there</p>
<p>• Fixed conversations failing on every turn with a "role 'system' must precede an 'assistant' message" API error</p>
<p>• Fixed conversations with the advisor on failing every turn with API Error 400 "Input tag 'advisor_20260301'" behind a proxy or gateway that doesn't support it; the request now retries without it</p>
<p>• Fixed a session failing on every turn and /compact when its saved history held a malformed notice about MCP tools that could not be loaded</p>
<p>• Fixed a crash when resuming a session whose saved transcript holds a malformed system message or a memory-saved notice without its file list</p>
<p>• Fixed one cause of long-running fullscreen sessions exiting with "Claude Code exited after an unrecoverable interface error": a damaged cached message list is now rebuilt</p>
<p>• Fixed Claude Code hanging when a settings file, or a file it re-reads after an edit, is replaced by a named pipe mid-read</p>
<p>• Fixed /config crashing and some on/off preferences being misread when a preference that has moved to settings.json still holds a value like null or "false" in ~/.claude.json</p>
<p>• Fixed resuming a session with unfinished background agents, shells or workflows starting a model turn on its own before you typed anything</p>
<p>• Fixed messages sent to a background subagent being silently lost in headless and SDK sessions when the subagent was finishing its turn</p>
<p>• Fixed a finished subagent's report being lost when the conversation that launched it was compacted before the report was read</p>
<p>• Fixed background subagents being unable to use the LSP tool when an LSP plugin is active</p>
<p>• Fixed background shell tasks reporting benign non-zero exits (e.g. grep with no matches) as failures</p>
<p>• Fixed background sessions (claude --bg) being unable to run git, hooks, plugins and other helper programs when an environment variable handed to the session contained a NUL character</p>
<p>• Fixed Ctrl+C needing three or four presses to exit while background subagents are running; two presses now exit</p>
<p>• Fixed IDE selection being dropped when a sent prompt comes back into the input, such as pressing Esc to edit it, rewinding to it, or pressing Esc while startup hooks run</p>
<p>• Fixed a ! shell-mode prompt stashed with Ctrl+S coming back as a plain prompt when restored, and / listing file paths right after stashing one</p>
<p>• Fixed claude agents showing a blank, unresponsive screen instead of an error when the temp directory is full, not writable or owned by another user</p>
<p>• Fixed an MCP server re-added under the same name after claude mcp remove still showing as needing authentication instead of reconnecting</p>
<p>• Fixed background plugin marketplace auto-update ignoring git credential helpers, so private-repo marketplaces were re-cloned every run or never updated</p>
<p>• Fixed claude plugin update clearing a plugin's recorded commit and moving it to version "unknown" when the official marketplace's snapshot file is a link or too large</p>
<p>• Fixed the Artifact tool silently disappearing when your organization's policy can't be loaded (for example behind a web proxy); Claude now says what's blocking it</p>
<p>• Fixed artifact republishes silently resetting stored database access rules or dropping the viewer profile scope when that capability was re-sent without them; they are now refused</p>
<p>• Fixed /ultrareview reporting a stopped cloud review as completed or as an error to retry, and waiting out the full timeout when its session was deleted or the signed-in account changed</p>
<p>• Fixed the Claude app showing a missing or stale context usage figure for Remote Control and cloud sessions right after /compact or /clear</p>
<p>• Fixed the Claude app's diff view for Remote Control and cloud sessions dropping a branch's committed files whenever there are also uncommitted changes</p>
<p>• Fixed cloud and self-hosted runner sessions failing with "Authentication failed" after waiting out a long overload during which the session's access token was rotated</p>
<p>• Fixed memory write conflicts in Cowork sessions showing Claude only the start and end of a memory file over about 10,800 characters, so the retried write dropped the middle</p>
<p>• Self-hosted runner: Fixed lifecycle-hook commits failing to sign under --configure-git</p>
<p>• Windows: Fixed background cleanup deleting a directory symlink or junction used to relocate ~/.claude/session-env, image-cache or another cleaned-up folder</p>
<p>• Self-hosted runner: Fixed a turn that ended right at a --retire-at release losing its finished signal; the runner now briefly waits for the turn to be reported before stopping the session</p>
<p>• Reverted ctrl+l / cmd+k in fullscreen mode clearing the transcript view (added in 2.1.260); they redraw the screen again</p>
<p>• Improved /permissions: focus returns to the rule list after viewing, adding or deleting a rule, and the delete-rule and remove-directory confirmations now default to No</p>
<p>• Improved /permissions tab navigation: ←/→ and Tab pressed in a rule list now switch tabs without moving focus to the tab bar</p>
<p>• Improved /cost cache-miss causes to name thinking mode and thinking display changes</p>
<p>• Improved the Artifact tool so that when Claude cannot read an artifact link it was given, it tells the user before continuing</p>
<p>• Improved /install-github-app: the GitHub CLI check and repository selection steps now show "Esc to cancel"</p>
<p>• Improved the /artifacts and /workflows lists: a scrollbar at the right edge shows how much of a long list is hidden and where you are in it</p>
<p>• Improved the workflow progress tree: running agents and phases now show a dim dot instead of ⟳</p>
<p>• Improved /plugin's Add Marketplace form in fullscreen: it no longer draws a box inside the pane, and its text and key hints line up with the rest of /plugin</p>
<p>• Improved the /workflows detail view in fullscreen: it no longer draws a second horizontal rule under the pane's divider</p>
<p>• Improved code blocks that don't name a language: they are now colored like inline code, so commands stand out from the surrounding text</p>
<p>• Improved /btw asked while a tool is still running: the side question now knows that call is in progress instead of reading it as a failed one</p>
<p>• Improved the UserPromptSubmit hook timeout notice and the debug log to name which hook command timed out</p>
<p>• Improved @ file suggestions: a file whose name contains the query now ranks above one that only matches across its folder names</p>
<p>• Improved artifact pages: no Print buttons, confirm dialogs or device features the viewer blocks, email and phone details shown as text, and dark mode that reaches form controls and scrollbars</p>
<p>• Improved /ultrareview uploads: renamed copies of key files, such as id_rsa copy or kubeconfig (1).yaml, now also stay on your machine</p>
<p>• Improved the cross-session messaging startup warning to explain that --debug-file writes a debug log to a path you choose</p>
<p>• Changed the default model on Pro and Team Standard plans from Sonnet to Opus, matching Max, Team Premium, and Enterprise</p>
<p>• Changed an effort level saved before /effort became per-model to no longer apply to newly released models such as Opus 5.5; they start at their default until you pick a level</p>
<p>• Changed Opus 4.7, Opus 4.8 and Fable 5 to stop holding their launch-default effort over /effort in -p or the Agent SDK, a project, managed or --settings effortLevel, or a per-model level</p>
<p>• Changed /autocompact's footer hint to name ←/→, the keys that adjust other ordered values</p>
<p>• Changed /fast's footer to name Space as the toggle key</p>
<p>• Self-hosted runner: Changed git in lifecycle hooks to ignore hook folders and programs named in the runner's shared git files; local-path and git:// remotes there now need GIT_ALLOW_PROTOCOL</p>
<p>• Changed plugin marketplaces whose name imitates a reserved marketplace name to be refused when added, and to stop loading if one was already added</p>
<p>• Changed PermissionRequest hooks: an agent-type hook no longer runs there, since its answer could never allow or deny the request; it now shows an error pointing to command or http hooks</p>
<p>• [VSCode] Added a Status dialog, with a typed /status, showing the session's version, account, model and server details</p>
<p>• [VSCode] Added a Sandbox dialog for the sandbox mode, the unsandboxed fallback and excluded commands, opened from the panel menu or by typing /sandbox</p>
<p>• [VSCode] Added a Claude in Chrome dialog (extension status, the install, reconnect and permissions pages, the enabled-by-default setting), opened from the panel menu or by typing /chrome</p>
<p>• [VSCode] Added Export conversation, with a typed /export, to copy or save the conversation as plain text</p>
<p>• [VSCode] Added each skill's source, token estimate and on/off state to the Slash commands dialog, with a click to change the state, and a typed /skills that opens it</p>
<p>• [VSCode] Added a typed /plan that switches to plan mode, sends a first planning prompt, or shows the session's plan</p>
<p>• [VSCode] Improved pasted-text handling in the chat box: a paste over 800 characters or over 2 line breaks is now marked so Claude can tell it from what you typed</p>
<p>• [VSCode] Improved prompt handling in the chat box: invisible Unicode formatting and tag characters are removed from pasted text with a notice, and from anything else before it is sent</p>
<p>• [VSCode] Changed "Open in New Tab" to open Claude beside the editor group you are working in rather than after the last group</p>
<p>• [VSCode] Fixed the effort chip showing a stale saved effort level instead of the level the session runs at</p>
<p>• [VSCode] Fixed Claude Code never starting when the Python extension hangs while activating; it now starts after 60 seconds without the Python environment</p>
<p>• [VSCode] Fixed the plan approval card never offering auto mode: when auto mode is available, its first option is now "Yes, and use auto mode", as in the terminal</p>
<p>• [VSCode] Fixed arrow-key navigation in the session list stopping after archiving or unarchiving a session from the keyboard</p>
<p>• [VSCode] Fixed paste marker lines showing in your own messages after reopening a session</p>
<p>• [Claude Code on the web] Changed the admin Routines on/off setting to live under Admin settings → Capabilities → Remote sessions; the Claude Code admin page now links to it</p>
<p>• [Claude Code on the web] Fixed gh and GitHub API calls inside a cloud session on a GitHub Enterprise Server repository failing after about eight hours; the token now renews automatically</p>
<p>• [Claude Code on the web] Fixed a routine that resumes an existing session running with its old prompt and name when it was edited moments before the scheduled run started</p>
<p>• [Claude Code on the web] Fixed file links in a cloud session transcript that point outside the session's working directory opening a file card that never loads; they're now disabled and say why</p>
<p>• [Claude Code on the web] Fixed auto mode refusing to retry a tool call because an approval prompt that expired unanswered, or was superseded by a newer message, had been recorded as your rejection</p>
<p>• [Claude Code on the web] Improved cloud sessions viewed in the Claude app: Claude now saves files meant for you where the app can open them</p>
<p>• [Claude Code on the web] Removed the empty repository picker shown when starting a session on a self-hosted environment in an organization where an admin has turned GitHub off</p>
<p>• [Claude Tag] Added Slack's native Working indicator, Stop button and thread title to Claude's threads in channels; the indicator stays up until Claude finishes, and Stop interrupts the task</p>
<p>• [Claude Tag] Added a short notice in the Slack channel when a guest joining, or the last guest leaving, changes how Claude responds there under a Restrict or Channel only guest setting</p>
<p>• [Claude Tag] Fixed scheduled routines silently failing to run in Slack workspaces that were connected to Claude before the workspace joined its Enterprise Grid</p>
<p>• [Claude Tag] Fixed Claude asking you to re-upload a Slack file when a brief file-scanning outage, not the file, was the problem; it now retries the scan and is told when the scanner is down</p>
<p>• [Claude Tag] Fixed a bullet in Claude's Slack reply whose text starts with +, - or * rendering as an empty bullet with a stray nested item; it now shows as one bullet with the character kept</p>
<p>• [Claude Tag] Fixed the Slack notice for a failed cloud environment setup script sometimes being a generic "mention me to retry"; it now names the setup script and says to fix it first</p>
<p>• [Claude Tag] Improved the GitHub banner in Claude Tag admin settings to say why GitHub isn't connected: not signed in, app not linked or not installed, sign-in expired, or SSO not authorized</p>
<p>• [Code Review] Improved the Code Review check run to say when REVIEW.md instructions were cut or left out of a review for exceeding a size limit, naming the file and the limit</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.278Claude Code v2.1.2782026-09-19T03:10:24Z<p>• Changed auto mode for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry and gateways, to default to the server-side classifier, which does not charge for classifier overhead (CLAUDE_CODE_AUTO_MODE_SERVER=0 opts out on Bedrock, Vertex, Foundry and gateways); warns on billed fallback. See https://code.claude.com/docs/en/auto-mode-classifier-billing</p>
<p>• Added an Auto mode server row to /status showing whether this session's auto mode classifier runs on the server</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.277Claude Code v2.1.2772026-09-18T18:06:17Z<p>• Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under "Project instructions" in /config</p>
<p>• Added CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1 for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally</p>
<p>• Added an optional headers: map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider</p>
<p>• Added a line saying a background task's update is waiting when it finishes while a panel such as /tasks is open</p>
<p>• Fixed claude -p and Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1</p>
<p>• Fixed conversations failing every request with "text content blocks must be non-empty" when an earlier assistant turn held an empty text block beside other content, including after --resume</p>
<p>• Fixed being unexpectedly logged out when an older Claude Code build (for example an IDE extension's bundled CLI) runs on the same machine as the current one</p>
<p>• Fixed interactive start-up hanging or showing an error for ANTHROPIC_API_KEY users when ~/.claude.json holds a malformed customApiKeyResponses value</p>
<p>• Fixed update checks erroring every 30 minutes, and claude update hanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformed minimumVersion is now ignored</p>
<p>• Fixed claude update on winget- or apk-managed installs reporting "up to date" when the version lookup failed</p>
<p>• Fixed claude plugin install sometimes failing and breaking the installed copy when reinstalling a plugin version that a session or another program was using; an unchanged copy is now left alone</p>
<p>• Fixed Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so</p>
<p>• Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error</p>
<p>• Fixed the Edit tool treating an escaped backslash followed by uXXXX text as a \uXXXX escape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead</p>
<p>• Fixed the Edit tool reporting "Invalid regular expression: regular expression too large" instead of "String not found in file" when a very large edit containing non-ASCII text did not match the file</p>
<p>• Fixed a turn ending early with "Path contains null bytes" when a tool call's file path contained \u0000 written as an escape sequence; escaped control characters now stay as literal text</p>
<p>• Fixed background sessions (claude --bg) exiting when a plugin's LSP server exited or closed its stdin</p>
<p>• Fixed a crash ("Type error") when opening /mcp or /plugin manage with a malformed claudeAiMcpEverConnected value in ~/.claude.json</p>
<p>• Fixed a crash at launch when ~/.claude.json holds a malformed theme value</p>
<p>• Fixed a crash ("unrecoverable interface error") when the prompt held text containing terminal color codes, for example a prompt recalled from history or text loaded from the external editor</p>
<p>• Fixed a crash when resuming a session whose saved history holds an assistant message stored as a plain string</p>
<p>• Fixed sessions on slow or heavily loaded machines sometimes exiting with "Claude Code exited after an unrecoverable interface error" when the first spinner appeared</p>
<p>• Fixed a rare case where the screen could stop updating for the rest of the session after an internal rendering error</p>
<p>• Fixed a rare case on Windows where a turn could stop with an error such as "Out of memory" right after Claude replied, so that reply's tool calls never ran</p>
<p>• Fixed sessions continued after /clear (restart, --continue, --resume) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss</p>
<p>• Fixed messages from other agents (such as a subagent's SendMessage) that arrived mid-turn showing up below the "Ran N shell commands" row instead of where they arrived</p>
<p>• Fixed the "copied" notice not appearing after drag-selecting text in the fullscreen /resume picker and other panels that cover the prompt area</p>
<p>• Fixed $TMPDIR expanding empty in Bash commands that run outside the sandbox while sandboxing is enabled</p>
<p>• Fixed WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy</p>
<p>• Fixed the Claude apps gateway's telemetry relay ignoring a collector hostname or domain listed in NO_PROXY when a proxy is set</p>
<p>• Fixed one malformed strictKnownMarketplaces or blockedMarketplaces entry silently disabling the whole enterprise marketplace policy</p>
<p>• Fixed failed auto-updates leaving large staged downloads behind in ~/.cache/claude/staging</p>
<p>• Fixed /plugin not stripping terminal control characters from messages on the Installed tab, such as the error of a failed plugin update</p>
<p>• Fixed /plugin → Installed and /skills crashing when a skill or legacy command is named like a built-in Object property such as constructor or toString</p>
<p>• Fixed /plugin closing with no message when every install in a multi-select failed</p>
<p>• Fixed uninstalled plugins reappearing as "failed to load" rows in /plugin Installed, and Remove not clearing such a row</p>
<p>• Fixed plugins from the official marketplace being recorded without their commit in installed_plugins.json, and installed_plugins.json keeping the old commit after updating a pinned-commit plugin</p>
<p>• Fixed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached --plugin-url archive a reload falls back to when its download fails</p>
<p>• Fixed Remote Control session bookkeeping failing when ~/.claude.json holds a malformed placeholder record</p>
<p>• Fixed the error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with /login</p>
<p>• Fixed typed or pasted text occasionally coming out scrambled in the claude agents dispatch input during key repeat or very fast input</p>
<p>• Fixed a crash ("unrecoverable interface error") when resuming a session whose saved transcript contains a stop hook summary without a well-formed hook list</p>
<p>• Fixed Enter on a selected agent panel row doing nothing when keybindings.json rebinds Enter in the Chat context, for example to chat:queueSubmit</p>
<p>• Fixed PDF page reads on Windows failing when the working folder's path is long (about 120 characters or more)</p>
<p>• Fixed a headless resume (claude -p --resume, the SDK, a VS Code extension window reload) starting the session's cost and usage totals at zero; headless sessions now save their totals at exit</p>
<p>• Fixed project skills from the main repository not loading in --worktree sessions when .claude/skills is untracked</p>
<p>• Fixed a sandbox.excludedCommands glob exempting an entire compound Bash command from the sandbox when only one part matched; every part must now match</p>
<p>• Fixed resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, which broke prompt caching for that agent</p>
<p>• Fixed rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again</p>
<p>• Fixed attachments recorded earlier in a conversation being re-rendered after a resume or relaunch, which dropped extended thinking and missed the prompt cache</p>
<p>• Fixed Console sign-in showing only "Request failed with status code 400" when the server refuses to create an API key; it now shows the server's message</p>
<p>• Fixed messages typed while Claude is still working sometimes being ignored by the model</p>
<p>• Improved session start-up for SDK and headless (-p) use: the first turn no longer waits on the per-directory CLAUDE.md lookup</p>
<p>• Improved the Claude apps gateway's loopback error messages to name CLAUDE_GATEWAY_ALLOW_LOOPBACK</p>
<p>• Improved /plugin Installed: an MCP server listed apart from its plugin now shows which plugin it belongs to</p>
<p>• Improved claude plugin install on an already-installed plugin: it now says when the marketplace offers a newer version and names the claude plugin update command</p>
<p>• Improved the startup notice overflow line under the logo: it now reads "N more notices hidden" instead of "+N more · /status"</p>
<p>• Improved prompt handling: invisible Unicode formatting and tag characters in a prompt are removed and the cleaned prompt is shown for review before it is sent</p>
<p>• Improved /ultrareview when there's nothing to review: messages say which case you're in, offer a command that reviews your latest commit, and a new repository's first commit is reviewed in full</p>
<p>• Improved artifact link handling so Claude reads claude.ai artifact links with the Artifact tool instead of WebFetch when that tool is available</p>
<p>• Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a ${VAR:?} guard, so headless runs can recover</p>
<p>• Improved the Artifact tool's permission prompts: shorter sentences, pages and artifacts named by title or file name, and links listed after the text</p>
<p>• Changed Fable to always appear in /model on the Anthropic API; it is greyed out only when your organization's settings disable it</p>
<p>• Changed the Bash sandbox instructions on Bedrock, Vertex and Foundry to the first-party wording, which frames the sandbox as the boundary of what the task was given</p>
<p>• Changed /ultrareview in non-interactive sessions to refuse when the repository has no base branch or shared history</p>
<p>• Changed subagent results to reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions</p>
<p>• Changed workflow scripts' computed agent() prompts on Bedrock, Vertex and Foundry to reach the subagent framed as script-authored text, so the safety classifier does not read them as the user</p>
<p>• Removed the background Haiku auto-title request from claude -p runs launched outside an SDK or IDE</p>
<p>• Removed the deprecated TaskOutput tool; Claude reads a background task's output file with Read instead, and the taskOutputMaxChars setting and TASK_MAX_OUTPUT_LENGTH no longer have any effect</p>
<p>• [VSCode] Added a Sign out row to the panel menu, with /logout in the typed command menu</p>
<p>• [VSCode] Added background shells and other running tasks to the agent map, each with a Stop, and a typed /tasks that opens it</p>
<p>• [VSCode] Added a Copy response button on responses and a typed /copy</p>
<p>• [VSCode] Added a one-time notice when inactive sessions are archived automatically, and an "Unarchive all" action on the Archived sessions group</p>
<p>• [VSCode] Added the session's cost and token usage to the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key)</p>
<p>• [VSCode] Fixed the "General config" menu row showing /config usage text instead of opening settings, and made typed /mcp, /hooks, /memory, /rewind and similar commands open their dialogs</p>
<p>• [VSCode] Fixed the effort slider's level not persisting into later sessions on a model that already had a level saved with /effort</p>
<p>• [VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as "Sonnet"</p>
<p>• [VSCode] Fixed /fast not saving fast mode as the default, so it was lost when the extension relaunched Claude Code</p>
<p>• [Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization</p>
<p>• [Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings → Cloud environments</p>
<p>• [Claude Code on the web] Fixed a cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain</p>
<p>• [Claude Code on the web] Changed the admin Claude Code setting labeled "Web" to "Cloud sessions" and removed the redundant read-only Mobile row beneath it</p>
<p>• [Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran</p>
<p>• [Claude Tag] Fixed the "Learn more" links on credential presets in Claude Tag access bundles to open each vendor's credential-setup page instead of a generic API reference</p>
<p>• [Claude Tag] Changed the Pylon credential preset in Claude Tag access bundles so admins can point it at Pylon's EU host</p>
<p>• [Claude Tag] Fixed Google Cloud credential forms in Claude Tag access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key</p>
<p>• [Claude Tag] Fixed the network events log in Claude Tag admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.276Claude Code v2.1.2762026-09-18T02:12:04Z<p>• Fixed every request failing with 400 … Input tag 'advisor_20260301' when ANTHROPIC_BASE_URL points at a proxy or gateway (2.1.275 regression)</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.275Claude Code v2.1.2752026-09-17T22:32:56Z<p>• Added the signed-in account to Claude apps gateway sign-in: when the gateway names it, you confirm it before the credential is saved, and /status shows it</p>
<p>• Added a send-now key (ctrl+enter, or ctrl+x ctrl+s) that interrupts the current turn and sends all queued messages at once; sent and queued messages show in gray until the model receives them</p>
<p>• Added a startup warning when a configured otelHeadersHelper fails, so sessions that silently export no telemetry are noticed</p>
<p>• Added syncing of the skills and plugins enabled on your claude.ai account to terminal sessions signed in with it; opt out with syncClaudeAiSkills: false or syncClaudeAiPlugins: false</p>
<p>• Added /plugin install <plugin> --marketplace <source>, which offers to add the marketplace before installing the plugin</p>
<p>• Fixed a restored memory file's age note changing between requests after a compaction or resume, which caused prompt cache misses</p>
<p>• Fixed --forward-subagent-text stream-json and SDK output dropping the messages of subagents spawned by a context: fork skill, and of forked skills invoked by a subagent or another forked skill</p>
<p>• Fixed @-mention file suggestions being buried below MCP resources when using a custom fileSuggestion command or typing @./@./</p>
<p>• Fixed fullscreen mode placing background-task completion notices beneath a long turn's collapsed tool row instead of where they arrived; each notice now closes the open row</p>
<p>• Fixed claude plugin marketplace update deleting a GitHub marketplace's local copy when the fetch failed and the marketplace was named after its repository</p>
<p>• Fixed plugin and marketplace messages, logs and claude plugin marketplace list showing a password or token stored in a git, ssh or marketplace URL</p>
<p>• Fixed a resumed cloud session leaving an unanswered question open in the transcript after a queued message superseded it</p>
<p>• Fixed vim mode placing the cursor one character right after a dot-repeated "!" or a fast-typed "i!" switched a non-empty prompt into shell mode</p>
<p>• Fixed fullscreen mode freezing or blanking for several seconds when scrolling up past a large file diff</p>
<p>• Fixed a stray </ccmemory>-style closing tag occasionally appearing in responses</p>
<p>• Fixed plugin messages, logs and the VS Code plugin dialog showing the wrong server for some git addresses</p>
<p>• Fixed a terminal API Error: 400 on every turn for users behind a network gateway that rewrites API error responses when a beta request header is rejected</p>
<p>• Fixed sandboxed Bash commands on Linux reporting exit code 0 for failed commands when the shell is zsh</p>
<p>• Fixed the Read tool hanging instead of reporting an error when part of a large file could not be decoded under memory pressure</p>
<p>• Fixed --resume, the resume picker preview, resumed background agents and the transcript view failing on a session whose saved history contains a malformed task-reminder or @-file attachment entry</p>
<p>• Fixed a crash when resuming a conversation whose transcript contains a malformed message entry, and a fullscreen crash when such a conversation received new messages while scrolled up</p>
<p>• Fixed sessions failing to resume or start when their saved transcript contains a malformed message content block</p>
<p>• Fixed Grep, Glob and @-file suggestions hanging or running out of memory on searches over the 20MB output cap, and system ripgrep reporting "no matches" instead of an error after a flood of warnings</p>
<p>• Fixed /rewind in a forked or background session restoring a zero-filled or truncated file when the session's file-history backups could not be fully copied</p>
<p>• Fixed fullscreen sessions sometimes exiting with "Claude Code exited after an unrecoverable interface error" when typing fast or holding a key with the slash-command dropdown open</p>
<p>• Fixed background sessions crashing and restarting their worker when a command fed through stdin ran on a machine that had run out of file descriptors</p>
<p>• Fixed a crash at launch when ~/.claude.json holds a malformed mcpNeedsAuthNoticed value</p>
<p>• Fixed --resume and --continue dropping a conversation's earlier thinking when a built-in tool it started with has since been switched off by a server-side flag</p>
<p>• Fixed text selected with the mouse in the fullscreen claude --resume session picker never reaching the clipboard</p>
<p>• Fixed plugin reload previews replacing a running session's extracted plugin files when the plugin was loaded from a --plugin-dir or --plugin-url archive</p>
<p>• Fixed self-hosted runners with --drain-wait-sec losing the final result of a turn that finished during a SIGTERM drain; the runner now waits briefly for the turn to be reported</p>
<p>• Fixed SubagentStop hooks with a specific matcher firing for every stopping subagent whose agent type was empty</p>
<p>• Fixed sandboxed Bash commands being unable to write to project directories named hooks/ or config/</p>
<p>• Fixed Artifact updates failing with "File not found" after a session resumes on another machine or its scratchpad is cleared: the page's last published version is restored</p>
<p>• Fixed /update-config writing Write(path) permission rules, which file permission checks don't match, instead of Edit(path) rules</p>
<p>• Fixed four dead documentation URLs (Pricing, Computer Use, Skills, CLI) in the bundled claude-api skill's live-sources table</p>
<p>• Improved prompt caching for a --system-prompt that contains a __SYSTEM_PROMPT_DYNAMIC_BOUNDARY__ line: the text above it is now cached globally, as the SDK's array form already is</p>
<p>• Improved the /desktop error when Claude Desktop does not open: it now says why and what to do next</p>
<p>• Improved the Artifact tool's publish and read results: they now say who can open the page and what the owner's Share menu offers</p>
<p>• Improved artifact publish results: they name the tab icon sent, warn when the page contains a NUL byte, and retry a flaky fetch of the newer page to merge after a stale publish</p>
<p>• Improved pasted and attached images: they are now saved where Claude can open them as files without a permission prompt, including in Desktop and VS Code</p>
<p>• Improved the Artifact tool's guidance so Claude updates a shared artifact in place when you were given edit access to it, instead of publishing a separate copy</p>
<p>• Improved plan-usage reads: editor windows and non-interactive sessions on one machine now share a read made in the last minute instead of each calling the usage endpoint</p>
<p>• Improved the ListPlugins tool description so Claude knows it lists plugins enabled on your claude.ai account, not plugins installed locally with /plugin</p>
<p>• Improved responsiveness when the terminal is slow or paused: output no longer falls further behind while the terminal catches up</p>
<p>• Improved Write and Edit results for files in the synced account-skills folder: they now say the change is not saved to your account and how to save it</p>
<p>• Updated /logout for Claude apps gateway sign-ins to also end the session on gateways that advertise token revocation</p>
<p>• Changed hosted sessions to keep an unanswered permission prompt up after a container restart, instead of asking again</p>
<p>• Changed the Artifact tool to ask for a one-word tab icon on a first publish instead of an emoji favicon</p>
<p>• Changed Claude in Chrome in auto mode to skip the extension's per-site check for classifier-approved calls, as bypass mode does, fixing browser_batch "Permission denied" after a redirect</p>
<p>• Changed plugins installed from an npm source to be fetched with npm pack --ignore-scripts and integrity-verified, so a package's install scripts no longer run</p>
<p>• Changed scheduled and Run now routine runs to save data to, and republish the page of, an artifact you can edit without asking; public artifacts, first publishes and deletes still ask</p>
<p>• Removed the startup notice that told you a one-off scheduled routine had run since your last session</p>
<p>• [VSCode] Added viewing, editing and deleting a saved memory inside the Memory dialog</p>
<p>• [VSCode] Added sending an attached image without typing any text</p>
<p>• [VSCode] Added a Retry link to the MCP servers dialog when the server list fails to load</p>
<p>• [VSCode] Added accept and reject buttons under each change in the proposed-change diff tab, so an edit can be reviewed change by change</p>
<p>• [VSCode] Fixed the transcript creeping toward the bottom in small steps while a permission card waits and content keeps arriving</p>
<p>• [VSCode] Fixed rewound and forked conversations not keeping the permission mode you had picked for the original conversation</p>
<p>• [VSCode] Fixed an empty CLAUDE_CONFIG_DIR entry in the environmentVariables setting making Claude Code keep its files in the workspace</p>
<p>• [VSCode] Fixed plugin install links opening the Manage plugins dialog for plugin names and marketplace addresses that can't be used in a link</p>
<p>• [VSCode] Fixed Remote Control staying shown as connected after a turn-off that Claude Code reported as failed; it now shows as off</p>
<p>• [VSCode] Fixed the scroll to the bottom on send stopping short of the reply when the reply starts arriving during the scroll</p>
<p>• [VSCode] Fixed the agent map showing agents a crash left unfinished as stopped instead of failed once the session is reopened</p>
<p>• [VSCode] Fixed the "Continuing the step" notice not appearing, and the continue limit resetting, after a reload that follows a crash with background tasks still running</p>
<p>• [VSCode] Fixed the session list showing when a session was last reopened, such as after a window reload, instead of when its last message was sent</p>
<p>• [VSCode] Fixed "Fork conversation from here" failing on the message right after one sent while Claude was working</p>
<p>• [VSCode] Fixed the prompt cache clock showing too few minutes after reopening a session with a message sent while Claude was working</p>
<p>• [VSCode] Fixed a background agent that finished while Claude was running a tool losing its completion notice, and its result on the agent map, after a window reload</p>
<p>• [VSCode] Fixed a rare case where text selected in a git-ignored file could be sent to Claude after the extension was unresponsive for several seconds</p>
<p>• [VSCode] Fixed renaming a running session reverting to the generated name (regression in 2.1.269)</p>
<p>• [VSCode] Fixed slash commands typed while Claude is responding being sent to the model as text instead of running once the response finishes</p>
<p>• [VSCode] Fixed unreadable code in the plan preview and the Hooks and Permission rules dialogs with the High Contrast Light theme</p>
<p>• [VSCode] Fixed /remote-control being ignored while Remote Control is still connecting: running it again now turns Remote Control off immediately</p>
<p>• [VSCode] Fixed the conversation pulling you back to the bottom while a reply streams after you scroll up, and added a claudeCode.scrollToBottomOnSend setting to turn off the jump on send</p>
<p>• [VSCode] Fixed the Manage plugins dialog showing a password or token that was typed into a marketplace URL</p>
<p>• [VSCode] Improved the agent map: the pill counts running agents and turns red after a failure, the main agent stays in view while the map scrolls, and agents sort by state then end time</p>
<p>• [VSCode] Changed New session in a Claude editor tab to open in the sidebar when Preferred Location is set to Sidebar, instead of always opening another tab</p>
<p>• [VSCode] Changed a message sent while Claude is working to wait at the bottom of the conversation until Claude starts on it</p>
<p>• [Claude Code on the web] Added a "New routine" button to the page shown when a routine link no longer resolves, next to the link back to your routines list</p>
<p>• [Claude Code on the web] Fixed routine "paused" and "on hold" notifications being cut off mid-sentence; the paused-subscription notice now says to turn the routine back on yourself</p>
<p>• [Claude Code on the web] Fixed cloud environments with a very long allowed-domains list saving fine and then failing every session start; saving now fails up front and says how much to trim</p>
<p>• [Claude Code on the web] Fixed Claude's guidance when a cloud session on a personal account is denied GitHub access: it now links to claude.ai/connect-github instead of an admin settings page</p>
<p>• [Claude Code on the web] Improved what Claude tells you when asked to edit, delete or run a routine it didn't create: it now links to the routine's page so you can do it yourself</p>
<p>• [Claude Tag] Added attach conditions for access bundles in Claude Tag settings: an Owner can let a bundle also apply in channels with guests or Slack Connect channels, not just member-only</p>
<p>• [Claude Tag] Added Amazon CloudWatch, CloudWatch Logs, Amazon SNS, Google Cloud Monitoring and Cloud Logging presets to an access bundle's Credentials tab in Claude Tag admin settings</p>
<p>• [Claude Tag] Added Datadog presets for the US3, AP1, AP2 and US1-FED sites; new Datadog connections are now limited to Datadog's read and query API routes</p>
<p>• [Claude Tag] Fixed S3 uploads from recent AWS CLI and SDK versions failing with a 502 error when sent through an AWS connection</p>
<p>• [Claude Tag] Fixed Claude treating a channel as inactive, and skipping untagged messages there, while it was still posting in that channel from a routine or a thread</p>
<p>• [Claude Tag] Fixed a thread's "Claude [task]" display name reverting to plain "Claude" after the session behind that thread was refreshed or restarted</p>
<p>• [Claude Tag] Fixed the model you switched to in a Slack thread silently reverting to the channel's default after that thread's session was restarted or refreshed</p>
<p>• [Claude Tag] Fixed Claude sometimes replying twice when another app or bot @mentioned it in a top-level channel message</p>
<p>• [Claude Tag] Improved Claude's notices in Enterprise Grid channels shared across workspaces: they now say when no workspace is set up yet, or why only organization defaults apply</p>
<p>• [Code Review] Fixed reviews occasionally dropping part of their analysis when one of the reviewing agents returned its findings in an unexpected format</p>
<p>• [Code Review] Fixed pull requests with more than 100 Claude reviews getting a full re-review on every clean merge from the base branch instead of the lighter merge-focused review</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.274Claude Code v2.1.2742026-09-17T00:11:54Z<p>• Added a visible warning when memory usage is critical, with steps to free memory or restart safely</p>
<p>• Added CLAUDE_CODE_MCP_STARTUP_WAIT_MS to bound how long the first non-interactive turn waits for connecting MCP servers (0 = don't wait)</p>
<p>• Added effort attribute to the claude_code.llm_request OpenTelemetry trace span, matching the api_request event</p>
<p>• Added claude_code.managed_settings_resolved OTel event: managed-settings sources and policy helper state; redacted settings and digests with OTEL_LOG_MANAGED_SETTINGS=1</p>
<p>• Added store.connect_timeout_seconds to the Claude apps gateway config to lengthen the Postgres connect timeout (default 5 seconds), and improved the boot error when the database is unreachable to point to store.postgres_url and the configured timeout</p>
<p>• Added enduser.sub, the IdP subject, to the telemetry Claude Desktop and Cowork send through a Claude apps gateway</p>
<p>• Added a Claude apps gateway warning when a replica has more requests open than the 256 it sends upstream at once, and a startup log line showing that limit</p>
<p>• Added click-to-expand for collapsed teammate and agent messages in fullscreen mode</p>
<p>• Fixed sessions getting stuck endlessly retrying "unexpected tool_use_id" 400 errors: corrupted transcripts now self-heal where possible, and otherwise a clear error (with a /rewind hint) ends the loop</p>
<p>• Fixed MCP servers configured as http that only speak legacy HTTP+SSE failing to connect when they answer the first request with 422 or another 4xx error</p>
<p>• Fixed Streamable HTTP MCP tool calls timing out after about 5 minutes even when a longer per-server timeout was set</p>
<p>• Fixed MCP prompts and resources not refreshing when a server sends list-changed notifications without declaring listChanged</p>
<p>• Fixed MCP tool calls refused with 403 insufficient_scope being reported as an expired sign-in: the error now names the missing permissions and points to /mcp re-authentication</p>
<p>• Fixed hook-driven sessions (such as an active /goal) ending with "Prompt is too long" instead of compacting when the context overflowed again after a reactive compaction</p>
<p>• Fixed an active /goal being lost when resuming (--continue / --resume) a session that had compacted</p>
<p>• Fixed claude agents losing --model, --effort, --permission-mode, --allow-dangerously-skip-permissions and --agent after an auto-update relaunch</p>
<p>• Fixed a per-turn slowdown when a language server publishes project-wide diagnostics for thousands of files</p>
<p>• Fixed subagents with model: "opus" on Bedrock, Vertex or Foundry leaving the session's model when its id has no recognizable model family (unless ANTHROPIC_DEFAULT_OPUS_MODEL is set)</p>
<p>• Fixed self-hosted runner sessions failing every turn with a 401 after a few failed token refreshes, until the next scheduled refresh; the runner now keeps retrying, and fetches a new token after a 401</p>
<p>• Fixed clickable links to local file paths doing nothing in VS Code and other terminals that require a file:// URI</p>
<p>• Fixed the transcript renumbering ordered lists in your own messages (typing "3. 2. 1." displayed "3. 4. 5."); numbers and "N)" markers now show as typed</p>
<p>• Fixed AskUserQuestion preview notes being attached to a previously chosen option instead of the highlighted one</p>
<p>• Fixed AskUserQuestion preview mode dropping the highlighted option when submitting a note with Enter</p>
<p>• Fixed a resumed background agent keeping half of an interrupted tool batch when one of its calls was approved with a message</p>
<p>• Fixed a local claude -p --resume started with CLAUDE_CODE_RESUME_INTERRUPTED_TURN not reporting background tasks the previous process left unfinished</p>
<p>• Fixed the first turn of a cloud session sometimes starting without the tools of an SDK-hosted MCP server that was still connecting</p>
<p>• Fixed background agent notifications claiming the agent had no live background work when it was still waiting on its own background task and would resume</p>
<p>• Fixed error hints in Claude Desktop sessions to suggest slash commands like /usage-credits instead of CLI flags that cannot be used there</p>
<p>• Fixed /schedule saving a routine's prompt without its message role when Claude writes the routine in the shape that listing routines returns</p>
<p>• Fixed /status not showing the apiKeyHelper failure that its own error banner told you to check</p>
<p>• Fixed /fast on in non-interactive sessions reporting on and then turning off under an organization's managed fast mode policy; it now says the organization has disabled it</p>
<p>• Fixed the Artifact tool asking you to approve an update to an artifact that it then refused because the session had not read the latest version</p>
<p>• Fixed Cowork and claude.ai cloud sessions with network access on treating reads of a teammate's artifact as if network access were off</p>
<p>• Fixed a plugin or marketplace directory with no git repository of its own taking its version from an enclosing git repository, such as a git-managed ~/.claude</p>
<p>• Fixed --strict-mcp-config with an empty --mcp-config holding the first non-interactive turn for up to MCP_TIMEOUT on incidental MCP servers</p>
<p>• Fixed Stop prompt hooks re-sending their whole prompt on every block in a conversation; repeat blocks now name the condition with a 500-character label</p>
<p>• Fixed extra empty editor windows opening at startup on Linux under Wayland when running inside the Cursor or VS Code terminal</p>
<p>• Fixed an unhandled promise rejection in the Claude apps gateway when Postgres drops a connection during a spend check</p>
<p>• Fixed Claude apps gateway cutting every open stream on SIGTERM: it now lets in-flight requests finish for up to 25 seconds before exiting (CLAUDE_GATEWAY_DRAIN_TIMEOUT_MS)</p>
<p>• Fixed installed_plugins.json being rewritten on nearly every start-up when plugin policy comes from remote managed settings, which made Claude Desktop reload every open session's plugins</p>
<p>• Fixed headless and SDK sessions making a separate model call for every background task that finished; completions already queued are now answered by one call</p>
<p>• Fixed the Bash tool re-sourcing the shell profile (a multi-second stall on the next command) after every plugin reload; it now does so only when the plugins' bin/ directories changed</p>
<p>• Fixed plugins with a top-level $schema in hooks/hooks.json showing an "unknown key" notice</p>
<p>• Fixed MCP connection errors and the MCP login tool's description showing secrets resolved from ${VAR} placeholders in MCP configs</p>
<p>• Fixed Bash permission checks for commands that loop over or assign certain special shell variables; these commands now ask for permission</p>
<p>• Fixed worktree-isolated sessions accepting Bash commands with certain nested shell expansions; these are now refused</p>
<p>• Fixed the Edit permission prompt preview sometimes showing a different location than the approved edit in files with multi-byte characters</p>
<p>• Fixed background commands being stopped after 30 idle minutes on machines under mild memory pressure; they're now stopped only when memory is critically low, and the debug log says why</p>
<p>• Fixed a message a subagent sends to the main session disappearing from the Claude Desktop transcript after a relaunch</p>
<p>• Fixed a plugin loaded from a .zip being served from a stale extraction after several overlapping reloads</p>
<p>• Fixed a sub-agent's progress summary being replaced by a runaway multi-paragraph reply</p>
<p>• Improved startup in --input-format stream-json sessions: the first turn no longer waits up to 2s for still-connecting MCP servers whose tools tool search defers; they arrive on a later turn</p>
<p>• Improved Monitor tool notifications: a script's final output and its exit now arrive as one notification instead of two, saving a model turn</p>
<p>• Improved Artifact tool errors: when you are not signed in to claude.ai the terminal now says so on the first attempt, and Claude is told to stop retrying a rejected call sooner</p>
<p>• Improved artifact publishing: a publish built on an older version is stopped before it is sent, with the newer page to merge</p>
<p>• Improved safety checks before removing an agent worktree that contains submodule checkouts</p>
<p>• Improved OTEL_LOG_RAW_API_BODIES=file:<dir> output: a new index.jsonl and request_body_id / message.id event attributes link each response to its request file and transcript message</p>
<p>• Improved Claude apps gateway boot: it now tries the first Postgres connection up to three times before exiting, so a database that is reachable a few seconds late no longer fails the boot</p>
<p>• Improved the Claude apps gateway's spend-limit check under load: it now takes one database round trip instead of four, so fewer checks time out on a busy gateway</p>
<p>• Improved Claude apps gateway sign-in rate limit errors: /login now explains the refusal, and the gateway log says which limit was hit and which setting to change</p>
<p>• Changed Bedrock, Vertex, Foundry and telemetry-disabled installs to use the v2 MCP client and MCP 2026-07-28 negotiation with direct HTTP servers by default, as other installs already do (opt out: MCP_SDK_GENERATION=v1 or MCP_PROTOCOL_NEGOTIATION=legacy)</p>
<p>• Changed /code-review to use leaner inline review prompts for every model that has no tuned settings of its own, instead of spawning many review subagents</p>
<p>• Changed "type": "sdk" MCP entries in .mcp.json, settings, plugins and agent files to be skipped with a warning: only an SDK host application can register in-process servers</p>
<p>• Changed artifact watching in local sessions: a new version published elsewhere no longer starts a turn; Claude learns of it from a later Artifact tool result</p>
<p>• Changed plugin and marketplace clones to leave Git LFS files as pointers instead of downloading them; git lfs pull in the checkout fetches them</p>
<p>• Changed self-hosted runners to skip a read-only repository the git host refuses at the access check instead of failing the session start</p>
<p>• Changed the /status GitHub line to read "Cloud sessions", and /web-setup, /ultrareview, and teleport messages to say "cloud session" instead of "Claude Code on the web"</p>
<p>• [VSCode] Added continuation of the step a window reload interrupted, labeled in the chat, with a Claude Code: Continue After Reload setting to turn it off</p>
<p>• [VSCode] Added Memory and Instructions entries to the Customize menu: Memory shows the auto-memory toggles, the saved memories and the memory folders, and Instructions edits the CLAUDE.md files</p>
<p>• [VSCode] Added a claudeCode.lockEditorGroups setting to stop Claude from locking the editor groups it opens in</p>
<p>• [VSCode] Fixed a /btw side question asked in a new conversation's first seconds occasionally showing another session's side-question history</p>
<p>• [VSCode] Fixed a brief freeze when the extension first looks up your global gitignore file</p>
<p>• [VSCode] Fixed a message sent while Claude was running a tool disappearing from the conversation after a window reload</p>
<p>• [VSCode] Fixed the Manage Plugins enable toggle and MCP servers dialog rows being unreachable from the keyboard</p>
<p>• [VSCode] Fixed sign-ins and sign-outs made in a terminal not showing until a reload after CLAUDE_CONFIG_DIR changed in the Environment Variables setting</p>
<p>• [VSCode] Fixed Edit diffs in the chat being cut off at the bottom at some panel widths and for long wrapped lines; diff boxes now fit the rows shown</p>
<p>• [VSCode] Fixed overlapping settings writes from the extension leaving ~/.claude/settings.json unparseable or dropping a setting</p>
<p>• [VSCode] Fixed Open in New Tab (Ctrl/Cmd+Shift+Esc) sometimes leaving the new tab's message box unfocused, so typing went nowhere until you clicked it</p>
<p>• [VSCode] Fixed reopening a closed Claude tab splitting the editor layout when its locked group still holds another Claude tab and a file</p>
<p>• [VSCode] Fixed New session opening another locked editor group whenever a file tab shared the group with your Claude tab</p>
<p>• [VSCode] Fixed session names shifting sideways in the session picker while typing a search query</p>
<p>• [VSCode] Fixed the plan review card cutting off its Send feedback button and reason field when a plan has several comments; the comment list now scrolls</p>
<p>• [VSCode] Fixed inline code and code blocks in chat replies being unreadable under the High Contrast themes</p>
<p>• [VSCode] Improved screen reader navigation of the conversation: each message is announced as "You" or "Claude", with the tool name for tool steps</p>
<p>• [VSCode] Changed the default global gitignore file to $XDG_CONFIG_HOME/git/ignore when XDG_CONFIG_HOME is an absolute path</p>
<p>• [Claude Code on the web] Added a "Compare against" branch picker to a cloud session's diff view, so you can diff its changes against any branch instead of only the base branch</p>
<p>• [Claude Code on the web] Fixed git operations in cloud sessions failing with "service unavailable" when GitHub's token renewal briefly errors</p>
<p>• [Claude Code on the web] Fixed editing a routine occasionally making it fire twice or re-enabling a routine that had just been paused</p>
<p>• [Claude Code on the web] Fixed commits in cloud sessions occasionally failing with a signing error for a few minutes after the session's credentials refreshed</p>
<p>• [Claude Code on the web] Fixed the toast after saving a routine whose GitHub trigger couldn't be linked to show the reason, such as a per-repository trigger limit, instead of only "edit to retry"</p>
<p>• [Claude Code on the web] Fixed sessions sometimes flipping back to unread right after you mark them read</p>
<p>• [Claude Code on the web] Changed routines to skip a run and retry for up to 72 hours when the owner's GitHub connection is missing, instead of switching the routine off at the first failed check</p>
<p>• [Claude Code on the web] Changed a routine's on-hold notice: when your subscription is paused it now tells you to turn the routine back on yourself instead of promising an automatic resume</p>
<p>• [Claude Tag] Added a Guests setting to the Add channel and Add workspace forms in Claude Tag admin settings, so owners can pick Inherit, Allow, Channel only or Restrict up front</p>
<p>• [Claude Tag] Fixed Claude not answering when another Slack app or bot @mentions it; the tag now gets a reply and wakes Claude in a channel it had stopped following after days of inactivity</p>
<p>• [Claude Tag] Fixed Claude missing another app's message that tagged @Claude right after a new Slack channel was created; it's now delivered once Claude has joined</p>
<p>• [Claude Tag] Fixed Claude folding a follow-up sent minutes after its last Slack message into it as a silent edit; late updates such as blockers now post as a new reply that notifies</p>
<p>• [Claude Tag] Fixed Claude's Slack search failing with an error whenever it searched within a single channel; it now returns that channel's matching messages</p>
<p>• [Claude Tag] Fixed a safety-filter stop silently resetting a Slack thread's context when nobody was waiting; Claude now always says so and no longer cancels background work still running</p>
<p>• [Claude Tag] Fixed email addresses in Claude's Slack replies rendering with a visible mailto: prefix; they now show as the plain, clickable address</p>
<p>• [Claude Tag] Fixed Claude refusing to watch an Enterprise Grid channel shared with the whole organization when asked from another workspace in the grid</p>
<p>• [Claude Tag] Fixed the Environment picker in Claude Tag admin settings showing a raw environment ID instead of the environment's name for archived or app-created environments</p>
<p>• [Claude Tag] Improved Claude's live progress checklist in Slack: capped at 2,000 characters, reposted at most every 15 minutes in busy threads, with older "Latest task list" links updated</p>
<p>• [Claude Tag] Removed the repeated guest-attribution note Claude appended to a Slack canvas each time it edited one in a channel using the "Channel only" guest setting</p>
<p>• [Code Review] Fixed re-reviews occasionally leaving a fixed finding's thread open when the new review also filed a lower-severity note under it</p>
<p>• [Code Review] Fixed rare reviews ending with "Code review encountered an error" when GitHub or an internal service failed transiently at launch; they now wait and retry</p>
<p>• [Code Review] Improved how Code Review words each posted finding: short plain sentences that say who is affected, where the code goes wrong, and the fix up front</p>
<p>• [Code Review] Improved the check-run card and PR comment when a review is skipped because of an organization limit: each cause now links the admin page that fixes it</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.273Claude Code v2.1.2732026-09-15T20:22:55Z<p>• Added x-claude-code-request-class, x-claude-code-agent-type, x-claude-code-prev-tool-durations, x-claude-code-compaction and x-claude-code-context-compacted request headers for LLM gateways; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1</p>
<p>• Added a notification when an MCP server disconnects mid-session and automatic reconnection gives up, pointing at /mcp</p>
<p>• Added forking a session started with claude --remote-control or /remote-control from the Claude app; the fork runs as a background session on your computer</p>
<p>• Fixed Bash commands the permission checker cannot fully analyze skipping the prompt under permissions.blockReadsOutsideWorkingDirectories, and a subshell hiding a dangerous rm in bypass mode</p>
<p>• Fixed skills synced from claude.ai staying available after your organization turns Skills off; they now move to the recoverable trash</p>
<p>• Fixed allowManagedMcpServersOnly, deniedMcpServers and disableClaudeAiConnectors set via MDM or managed-settings.json being ignored when server-managed settings are also present</p>
<p>• Fixed 401/403 errors on Bedrock, Vertex and Foundry, and Claude apps gateway 403s, telling you to run /login; the message now names the credential to refresh or points to your gateway administrator</p>
<p>• Fixed /login, /upgrade, and /extra-usage discarding earlier thinking from the conversation, which forced a full prompt-cache rewrite on the next request</p>
<p>• Fixed auto mode stopping for approval when the Artifact tool uploads a file you attached to the chat in a cloud or Remote Control session</p>
<p>• Fixed a long-running session recreating a stub .git/info/exclude after the repository's .git directory was removed or moved away</p>
<p>• Fixed the main prompt dropping a ! typed at the start while already in shell mode, so negated commands like ! grep … can be typed</p>
<p>• Fixed Read on macOS refusing a dragged-in screenshot, or any file the system reports under a second path, with "symlink resolution changed after permission was checked"</p>
<p>• Fixed permissions.blockReadsOutsideWorkingDirectories: a memory directory chosen by a repository's settings is no longer loaded into the prompt, recalled, indexed, or used by memory extraction</p>
<p>• Fixed sub-agents and background agents being reported as failed, with their result never delivered, when the final streamed reply omitted token usage or carried no model id</p>
<p>• Fixed the context meter and auto-compact counting advisor-tool turns at roughly twice their real context size, which made auto-compact fire at about half the real window</p>
<p>• Fixed /tui refusing to restart because of an agent-team teammate that had already finished its work and was no longer shown in the agents panel</p>
<p>• Fixed saved scheduled tasks running in the wrong session after .claude/scheduled_tasks.json was copied into another folder, such as a new worktree</p>
<p>• Fixed SDK and --output-format stream-json output dropping a subagent's remaining messages and final report after it is moved to the background mid-run (e.g. by CLAUDE_AUTO_BACKGROUND_TASKS)</p>
<p>• Fixed /install-github-app reporting a SAML single sign-on block as "admin permissions required"</p>
<p>• Fixed Remote Control clients attached to a Claude Desktop, VS Code or JetBrains session being refused when they ask for the session's context window usage</p>
<p>• Fixed the spinner showing a doubled ellipsis ("……") on compaction status lines such as "Running PreCompact hooks…"</p>
<p>• Fixed a false-positive spinner tip suggesting the frontend-design plugin after reading or publishing Artifacts</p>
<p>• Reverted a 2.1.268 change that checked Read and Edit deny rules on Bash lines the permission checker can't analyze (eval, env -C); commands like time -p make build prompt again instead of being denied</p>
<p>• Improved responsiveness in long sessions: hook progress and sub-agent activity no longer re-process the whole conversation on every update</p>
<p>• Improved the Artifact tool's error when a publish includes a file type artifacts don't serve: Claude is told which types are served and what to do instead, and the terminal shows one plain line</p>
<p>• Improved the Artifact tool's page read to state the capabilities and database rules the artifact service holds for the page, for anyone who can publish to it</p>
<p>• Improved artifact database writes: an update can now remove a single field instead of rewriting the whole document</p>
<p>• Improved artifact publishing: a publish whose connection drops after reaching claude.ai is now re-sent safely instead of failing or creating a duplicate version</p>
<p>• Improved the cloud-session GitHub error for an IP allow list, a suspended app installation or SAML single sign-on to show the cause instead of a generic install hint</p>
<p>• Improved /autofix-pr: when gh pr view fails it now shows gh's own error (sign-in, SAML, rate limit) instead of a generic exit-code line</p>
<p>• Improved /autofix-pr to say why GitHub webhook delivery couldn't be set up for the PR (for example, no linked GitHub account) instead of a generic warning</p>
<p>• Improved /web-setup errors: a refused GitHub token now lists the likely reasons and the fix, and a connection failure names a configured proxy or TLS certificate problem</p>
<p>• Improved the in-session SSL certificate and proxy connection errors to name the error code and what to fix, such as NODE_EXTRA_CA_CERTS for an untrusted corporate CA</p>
<p>• Improved the error when a cloud session can't be created because your Claude login expired or was revoked: it now tells you to run /login</p>
<p>• Improved the error shown when an MCP server's sign-in expires mid-session to say how to re-authenticate (/mcp)</p>
<p>• Changed auto mode on Bedrock, Vertex and Foundry to use the local classifier by default for now; set CLAUDE_CODE_AUTO_MODE_SERVER=1 to use the platform's server-side classifier</p>
<p>• Changed OTEL_LOG_TOOL_DETAILS=1 to also include real agent, skill, plugin and MCP server names on cost and token metrics</p>
<p>• Changed sign-in with a Claude account to also request access to your claude.ai plugins</p>
<p>• Changed /bug and /feedback reports to include only model-behavior params (model, system prompt, tools) from the last API request, omitting request metadata and CLAUDE_CODE_EXTRA_BODY fields</p>
<p>• [VSCode] Fixed "Report a problem" still appearing, and /bug / /feedback opening a report form, for organizations that have product feedback disabled</p>
<p>• [VSCode] Fixed a red "Claude Code process exited with code 4294967295" banner appearing after completed turns on Windows</p>
<p>• Windows: Improved the network-path permission check for UNC paths when a mapped network drive was added with --add-dir</p>
<p>• [Claude Code on the web] Fixed routines losing access to an organization connector, and still calling the old one, after an admin removed and re-added that connector</p>
<p>• [Claude Code on the web] Fixed creating a self-hosted environment from organization settings occasionally failing with a server error and leaving a half-created environment behind</p>
<p>• [Claude Code on the web] Changed the admin "Share cloud sessions" setting to live under Data and privacy instead of the Claude Code page, where Data and privacy admins can also manage it</p>
<p>• [Claude Code on the web] Added a "Discard unsaved changes?" confirmation before the New routine page or the Edit routine dialog throws away a routine name, prompt or edit you typed</p>
<p>• [Claude Code on the web] Removed the full-page desktop-app download screen that new users without a cloud environment saw on Mac and Windows; they now go straight to setup</p>
<p>• [Claude Code on the web] Improved the routine detail page: menu and rename in the breadcrumb, the on/off switch and Run now at the top, and run history beside the routine's settings</p>
<p>• [Claude Tag] Fixed Claude going silent minutes after reinstalling the app when an Enterprise Grid was disconnected but one of its workspaces stayed connected</p>
<p>• [Claude Tag] Fixed scheduled tasks set up in an organization-shared private Slack channel silently never posting; they now keep running in the thread they were created in</p>
<p>• [Claude Tag] Fixed replying in an older Slack thread while Claude is mid-task sometimes restarting it from scratch and losing work it had not pushed yet</p>
<p>• [Claude Tag] Fixed Claude occasionally dropping a message with an incorrect "couldn't find a Claude Code environment" notice right after your account token refreshed</p>
<p>• [Claude Tag] Fixed AWS connections refusing region-less endpoints such as Budgets, Savings Plans, WAF Classic and Import/Export; Global Accelerator requests now sign correctly</p>
<p>• [Claude Tag] Improved AWS connection failures: when a request can't be signed, such as a hostname with no region, Claude is told why and how to fix it instead of a bare error</p>
<p>• [Claude Tag] Fixed OAuth client-credentials and JWT-bearer connections failing with providers that return a lowercase token type; requests now send the standard Bearer scheme</p>
<p>• [Claude Tag] Fixed adding a channel manager being refused on Enterprise Grid shared channels, on channels where Claude hasn't been used yet, and on legacy private channels</p>
<p>• [Claude Tag] Changed Claude to start watching related public channels on its own, such as an incident channel a conversation depends on, instead of only when asked</p>
<p>• [Claude Tag] Fixed the admin Memory page not listing Slack channels Claude set up on its own even when they had saved memory; admins can now open, edit and delete that memory</p>
<p>• [Code Review] Fixed merging the base branch into a PR whose earlier review listed "Additional findings" triggering a full re-review; these pushes now get the lighter follow-up review</p>
<p>• [Code Review] Fixed a whole REVIEW.md being ignored because of an @-mention, a code span wrapped across lines, or a backticked HTML tag; only lines linking to changed files are withheld</p>
<p>• [Code Review] Improved suggested fixes to say what the fix must keep working when other code depends on the behavior being changed</p>
<p>• [Code Review] Improved review comments that point to a second affected location to state that location's issue in a full sentence instead of a cut-off stub</p>
<p>• [Code Review] Fixed /ultrareview --post so a retry after a GitHub error posts the findings comment exactly once instead of never or twice; the comment now names the reviewed commit</p>
<p>• [Code Review] Fixed empty or content-identical pushes being re-reviewed on GitHub repositories whose owner or name contains a capital letter; these pushes are now skipped</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.272Claude Code v2.1.2722026-09-15T00:42:19Z<p>• Bug fixes and reliability improvements</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.271Claude Code v2.1.2712026-09-14T22:12:48Z<p>• Added fast mode in Claude Code Remote sessions (cloud and self-hosted runners): the host's fast-mode setting or /fast typed in the session applies where your organization allows it</p>
<p>• Added mouse support to the /config panel in fullscreen mode: the wheel scrolls the settings list, a click on a setting's value changes it, and the row under the pointer is highlighted</p>
<p>• Added claude self-hosted-runner --drain-marker-file <path>: when that file exists at a SIGTERM drain, the runner reports its exit to the server as a host drain (telemetry only)</p>
<p>• Added per-command allowed_domains to Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refused</p>
<p>• Added omitClaudeMd to agent frontmatter and --agents JSON, letting custom and plugin subagents run without user, project and local CLAUDE.md files; managed policy files still load</p>
<p>• Added --accept-command <sha256> to claude plugin install and claude plugin update to accept exactly the command a previous --json run displayed, instead of -y</p>
<p>• Added support for a multiplier above 1, up to 10, in the modelPricing managed setting and the Claude apps gateway pricing block, for marked-up internal chargeback rates</p>
<p>• Added a spinner tip pointing Bedrock, Vertex AI, Foundry and LLM gateway users to the Claude desktop app; the claude.ai desktop app tip now suggests /desktop, which offers to download the app</p>
<p>• Fixed a cached organization policy being reused after switching accounts, organizations, or API keys, and the policy not refreshing until the hourly check when the credential changes mid-session</p>
<p>• Fixed the tool and command lists not updating when the organization policy finishes loading after startup or changes mid-session</p>
<p>• Fixed an enterprise managed-mcp.json that can't be read or parsed being ignored: it now keeps exclusive MCP control (user, project and plugin servers don't load) and warns at startup</p>
<p>• Fixed org policy being fetched through, and rejected by, third-party local proxies set via ANTHROPIC_UNIX_SOCKET; they are again treated like other custom gateways, including for Remote Control</p>
<p>• Fixed cloud sessions rejecting every subagent tool call ("updatedInput … failed schema validation") when a workflow or agent approval was applied after the session's worker restarted</p>
<p>• Fixed /fast off answering "Fast mode unavailable" instead of turning fast mode off when the organization has fast mode disabled</p>
<p>• Fixed sessions started with CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK re-sending fast requests every turn after the API rejected fast mode; the rejection now stands and its reason is shown</p>
<p>• Fixed fast mode under CLAUDE_CODE_RETRY_WATCHDOG failing the turn on a usage-credits limit, or retrying an overload at fast speed, instead of falling back to standard speed</p>
<p>• Fixed Bash permission checks missing the file that fmt, column and similar commands read when it follows an option the checker doesn't recognize</p>
<p>• Fixed Bash permission checks skipping files a wildcard expands to when the wildcard sits in a command's pattern or option value (for example grep -v dir/* file)</p>
<p>• Fixed Bash permission checks so that shell variable declaration flags cannot misrepresent the command being run</p>
<p>• Fixed Bash commands with two directory changes, a subshell, or a cd+git chain skipping the prompt under permissions.blockReadsOutsideWorkingDirectories in bypass and auto mode</p>
<p>• Fixed a stale .git/config.lock breaking git checkout -b, git push -u and git config for the rest of a session after a sandboxed command failed to start (Linux)</p>
<p>• Fixed settings file changes made outside the session going unnoticed on macOS machines whose system file-event service is saturated; the watcher now falls back to polling</p>
<p>• Fixed resumed claude -p sessions whose tools all come from MCP servers failing with "At least one tool must have defer_loading=false"</p>
<p>• Fixed turns failing with "API returned an empty or malformed response" when an LLM gateway returns the non-streaming reply as text/plain</p>
<p>• Fixed sustained high CPU usage and repeated tool-list requests when an MCP server sends list_changed notifications in a tight loop</p>
<p>• Fixed MCP OAuth mishandling client registrations: denying consent forced a new one, one for another redirect URI was reused, and a concurrent write could delete a valid one or keep a mismatched one</p>
<p>• Fixed tool search returning no match when Claude selects an MCP tool by its bare name instead of its full mcp__server__tool name</p>
<p>• Fixed Ctrl+O cancelling pending MCP server reconnects, and /mcp sent from Remote Control failing while the transcript view is open</p>
<p>• Fixed the Claude in Chrome prompt telling the model to load tools through ToolSearch when ToolSearch is unavailable</p>
<p>• Fixed cross-session messages held by the receiving session's permission-mode policy leaving no trace: headless senders now get a delivery notice, and SendMessage results no longer imply it was read</p>
<p>• Fixed Claude starting a second copy of a background command (such as a watch task or dev server) that was still running after the conversation was compacted</p>
<p>• Fixed /model warning about losing the conversation cache when switching back to the model the conversation actually ran on</p>
<p>• Fixed /reload-skills reporting a skill count that disagreed with the slash menu after /cd</p>
<p>• Fixed /resume and /continue showing only 1-2 sessions in fullscreen mode on short terminals</p>
<p>• Fixed /resume and /teleport keeping the previous conversation's file-read tracking, so Claude could edit files the resumed conversation had never read</p>
<p>• Fixed --resume dropping the 1M context window ([1m]) when the resumed session's model family differs from the configured default model</p>
<p>• Fixed artifacts attached with /artifacts disappearing from the session after --resume</p>
<p>• Fixed background sessions (claude --bg, claude agents) not watching the artifacts they publish for republishes made elsewhere</p>
<p>• Fixed custom agents, slash commands and output styles beyond the first not loading from a virtual drive that reports inode 0, such as an encrypted vault mounted as a Windows drive</p>
<p>• Fixed self-hosted runner sessions silently losing all host config (settings, skills, plugins, MCP servers) when the host config directory exceeds 64 MiB; added --host-config-snapshot disk|memory</p>
<p>• Fixed skills synced from claude.ai staying on disk indefinitely after signing out; copies not refreshed within cleanupPeriodDays now move to the recoverable trash at the next launch</p>
<p>• Fixed spinner tips suggesting commands that aren't available for your account type or are disabled in your session</p>
<p>• Fixed the /add-dir path input: the left and right arrow keys now move the cursor, and Enter adds only the typed path instead of also adding the highlighted completion</p>
<p>• Fixed text fields outside the main prompt moving a leading ! to the end of what you typed (!foo came out as foo!)</p>
<p>• Fixed the interactive /hooks menu crashing when a hook matcher is named after an inherited object property such as __proto__ or constructor</p>
<p>• Fixed a fullscreen rendering glitch where text kept a stale background color after the box around it lost its background</p>
<p>• Fixed Delete in st and Alt+arrow keys in rxvt-unicode not working in attached background sessions</p>
<p>• Fixed the terminal's replies to capability queries (^[[?1;2c) appearing at the shell prompt or in an editor when Claude Code exits, is suspended, or opens an editor right after starting</p>
<p>• Improved terminal rendering performance: large diffs and long transcripts render faster, with fewer slow frames</p>
<p>• Improved startup time slightly by skipping a redundant validation of built-in model data on every launch</p>
<p>• Improved hook feedback: while a SessionStart, UserPromptSubmit, PreToolUse or SessionEnd hook runs, the spinner says so with elapsed time, and Esc cancels a prompt waiting on a SessionStart hook</p>
<p>• Improved the spinner status during long thinking: it now reads "deep in thought" after 45s, and shows "picking the thought back up" while recovering from the output-token limit</p>
<p>• Improved dynamic workflows to pause when you hit your usage limit and continue automatically when it resets, instead of dropping the affected agents</p>
<p>• Improved Remote Control to leave fewer empty sessions on claude.ai when setup fails on a flaky network</p>
<p>• Improved the Claude in Chrome message in cloud sessions when the browser can't be reached: it now says the computer may be asleep before it suggests an install</p>
<p>• Improved claude mcp serve: a running tool call now sends a progress update every 30 seconds, so clients show it is still running and idle timeouts don't abort a long command that prints nothing</p>
<p>• Improved Foundry and Claude Platform on AWS sessions: an alwaysLoad MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip</p>
<p>• Improved Markdown files published as artifacts: they now render as styled document pages (title header, document typography, syntax-highlighted code)</p>
<p>• Improved Artifact tool publish errors: a publish with no file now says to write the page to a file first, and an unsupported file type is reported before a missing favicon</p>
<p>• Improved the Artifact tool's error when a page declares a capability its contract version lacks: it now lists every supported capability and notes when a newer contract version has it</p>
<p>• Improved artifact watching: a session can now watch up to 10 published artifacts at once for republishes made elsewhere, up from 5</p>
<p>• Improved PDF @-mentions to say "page count unknown" instead of a page count guessed from the file size when pdfinfo cannot count the pages</p>
<p>• Improved /mobile to show a single QR code for claude.ai/mobile, which opens the right app store for your phone</p>
<p>• Changed auto mode so that a skill's or slash command's inline ! shell commands follow default-mode permission rules instead of the classifier; a command no rule decides runs as a reviewed tool call</p>
<p>• Changed auto mode so a subagent reports back to its caller through a dedicated hand-back call that the safety classifier reviews, instead of its last message being reviewed after the fact</p>
<p>• Changed Monitor watches to always have a deadline (at most 30 minutes; 10 in single-prompt -p runs) and notify Claude to re-arm, replacing the no-timeout persistent option</p>
<p>• Changed the IDE selection indicator in the prompt to a [⧉ …] pill that wraps with the text instead of squeezing multi-line prompts; delete it with Backspace to leave the selection out</p>
<p>• Changed the default dynamic workflow size to small on Pro plans and lowered the medium size guideline from 15 to 10 agents</p>
<p>• Changed Claude apps gateway, Bedrock, Vertex AI, and Foundry sessions so that they no longer refresh a leftover claude.ai login that the session does not use</p>
<p>• Updated the bundled claude-api skill to enable eager_input_streaming on streaming custom tools, and to start deliverable-shaped Managed Agents work with user.define_outcome</p>
<p>• [VSCode] Added an Attach Open File setting that, when turned off, stops the open file from being added to messages; selected text is still attached</p>
<p>• [VSCode] Fixed the Hooks and Permission rules dialogs reporting a save that landed as failed, and the Hooks dialog going blank under a plugin-only policy lock or showing color codes in save errors</p>
<p>• [VSCode] Fixed Hooks dialog saves: no duplicate hook on replace, a header name retyped in other capitals keeps its secret, and settings.local.json is gitignored before the save returns</p>
<p>• [VSCode] Fixed session history showing only the current session when the workspace is on a Windows mapped network drive or SUBST drive</p>
<p>• [VSCode] Fixed the session list's Active filter hiding open idle sessions when Open is also checked in the filter menu</p>
<p>• [VSCode] Fixed a new chat switching back to the previous chat when the session list refreshed</p>
<p>• [VSCode] Fixed open tabs and the side bar keeping the old config folder until a window reload after CLAUDE_CONFIG_DIR changed in the environmentVariables setting</p>
<p>• [VSCode] Fixed console windows flashing on Windows when the extension runs background commands such as git, ripgrep, and the sign-in status check</p>
<p>• [VSCode] Fixed the prompt cache clock's hover text appearing only after a delay, and the auto-compact icon showing the browser's own tooltip beside its popup</p>
<p>• [VSCode] Improved the Hooks dialog: a save refused because of the settings file itself now opens a popup with an "Open settings file" button and the reason behind "Copy error"</p>
<p>• [VSCode] Changed the on state of toggle switches from Claude orange to the editor theme's button color</p>
<p>• [Claude Code on the web] Fixed a cloud session sometimes taking about ten minutes to respond after its process exited while the session still looked live; sending a message now restarts it right away</p>
<p>• [Claude Code on the web] Changed the Routines page on claude.ai/code to a new layout with Yours and Templates tabs and two-column routine cards that show run status, and removed its calendar view</p>
<p>• [Claude Code on the web] Added a Custom network access option to the Cloud environments editor in admin settings, with the same allowed-domains list the environment dialog on claude.ai/code offers</p>
<p>• [Claude Code on the web] Improved the Cloud environments admin page: it shows the default environment for Claude Tag and Claude Code, with a link to change it, and marks the recommended kind to create</p>
<p>• [Claude Tag] Fixed Claude in a channel where it stays active losing its working context about once an hour when the conversation is mostly in threads; thread activity now keeps it from being reset</p>
<p>• [Claude Tag] Fixed a thread that asked Claude to watch a pull request no longer hearing about CI failures, comments and reviews after Claude was restarted in that thread</p>
<p>• [Claude Tag] Fixed deleting the first message of a thread Claude had already replied in not ending Claude's work there; it now stops, as it did when a message with no replies was deleted</p>
<p>• [Claude Tag] Fixed Claude holding back a post because of an earlier instruction addressed to a different bot or assistant; only instructions addressed to Claude bind it, and it asks when unsure</p>
<p>• [Claude Tag] Fixed the reply-mode card Claude posts on joining a busy channel saying it "sees a lot of automated posts" when the channel is only chatty or large; the card now names the real reason</p>
<p>• [Claude Tag] Improved the Environment picker in Claude Tag admin settings: options are labeled Anthropic-hosted or self-hosted, with links to edit that environment or create one</p>
<p>• [Code Review] Fixed a pull request in a repository reviewed once per PR sometimes getting no review when a commit arrived while its review was waiting to start; it now reviews the requested commit</p>
<p>• [Code Review] Fixed Code Review occasionally posting the same findings two or three times when GitHub reported an error for a review it had in fact created</p>
<p>• [Code Review] Fixed follow-up reviews re-posting a security finding a person had already resolved when a later push moved the lines it was anchored to</p>
<p>• [Code Review] Fixed reopening a finished /ultrareview cloud session in the Claude app starting the whole review over again unprompted</p>
<p>• Windows: Fixed PowerShell commands failing with "Exit code 1" and no output when the session's temp output path reaches 260 characters</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.270Claude Code v2.1.2702026-09-12T19:45:38Z<p>• Fixed read-only git commands in Bash unexpectedly asking for permission after a session had been running for a while (regression in 2.1.269)</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.269Claude Code v2.1.2692026-09-11T19:17:47Z<p>• Added claude plugin eval: run a plugin's eval suite against Claude Code and get scored, reproducible results (JSON + HTML report); see claude plugin eval --help</p>
<p>• Added /output-style [name] to list and switch output styles, including over Remote Control and in cloud and other headless sessions</p>
<p>• Added a diff of the files a Bash command changed to the Bash tool result when the Bash tool handles file edits (setting bashEditDiffEnabled)</p>
<p>• Added OTEL_METRICS_INCLUDE_REPOSITORY to tag OpenTelemetry metrics and events with vcs.* repository attributes; commit events get vcs.ref.head.* with OTEL_LOG_TOOL_DETAILS</p>
<p>• Added CLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MS to extend the LLM gateway /v1/models discovery timeout (default 3s)</p>
<p>• Added a spinner tip suggesting /focus for a view with just your prompt, a one-line work summary, and the response</p>
<p>• Added CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS (1–256) to raise the Workflow tool's per-run concurrent agent limit for inference-bound fan-outs</p>
<p>• Fixed the prompt cache being partially invalidated on the turn after a response was cut off at the output-token limit and automatically resumed</p>
<p>• Fixed a case where resuming a session after interrupting Claude mid-thought could change how earlier context was re-sent, hurting prompt-cache reuse</p>
<p>• Fixed F1/F2/F4 not working in kitty-protocol terminals and Delete in st, Alt+arrows acting as Escape in rxvt-unicode, and Shift+punctuation typing the unshifted key in WezTerm (regression in 2.1.247)</p>
<p>• Fixed remote and headless sessions reporting "waiting for your input" while background agents were still running (set CLAUDE_CODE_BG_TASKS_REPORT_RUNNING=0 to restore the old behavior)</p>
<p>• Fixed the terminal's replies to capability queries (^[[?1;2c) appearing as stray text at startup in some terminals</p>
<p>• Fixed rows at the top or bottom of the transcript going blank in fullscreen after resizing the terminal</p>
<p>• Fixed a deny or ask permission rule starting with ! applying beyond the settings source that wrote it; such a rule now applies only within its own source, and a bare ! negation is ignored</p>
<p>• Fixed the git status Claude is told after a compaction: it is now the current status, not the one from the start of the session</p>
<p>• Fixed synced plugin MCP servers not connecting when a remote session resumes</p>
<p>• Fixed resumed headless sessions losing a turn's replies when the model was switched or a request was retried mid-turn</p>
<p>• Fixed terminal escape codes, line breaks and oversized text from a background task's on-disk record reaching the task list and task notifications when work is resumed</p>
<p>• Fixed CMYK JPEG images failing to attach with "cannot decode"; they are now converted and resized like other JPEGs</p>
<p>• Fixed the managed settings approval dialog not naming the collector for a gRPC telemetry endpoint set without a scheme</p>
<p>• Fixed plugin headersHelper consent prompts showing a URL path that could be misread as a different host</p>
<p>• Fixed plugin errors showing [redacted URL] in place of a relative Windows path with a folder name that starts with @</p>
<p>• Fixed missing cursor in the permission-rule, auto-mode-rule, add-directory, session-rename and feedback-review text fields when the terminal's native cursor is enabled</p>
<p>• Fixed repeated clicks on a /fork receipt, each under a second apart, never backgrounding the session right away while it waited for the current tool to finish</p>
<p>• Fixed plugin LSP servers that reject shutdown params (e.g. rust-analyzer) being left running at session end; exit is now sent even if shutdown fails</p>
<p>• Fixed the attribution reminder overriding a CLAUDE.md or memory rule against commit and pull request attribution; lines set by managed settings still apply</p>
<p>• Fixed prompt suggestions being dropped for text in Japanese, Chinese, Thai and other languages written without spaces between words</p>
<p>• Fixed synchronized output being assumed from the terminal's name in GNOME Terminal and Konsole versions that do not support it</p>
<p>• Fixed permission_denials in --output-format stream-json results omitting Read, Edit and Write calls blocked by a path-scoped deny rule</p>
<p>• Fixed sessions run through the SDK or the desktop app showing an unknown status in other sessions' agent list</p>
<p>• Fixed /insights failing on Bedrock, Vertex, Foundry, and gateway deployments whose account can't reach the default Opus model by using the session model there instead</p>
<p>• Fixed organization policy limits not loading for the session when another Claude Code process refreshed the login at the same moment</p>
<p>• Fixed Claude Desktop sessions using Bedrock, Vertex, or a gateway not getting the contextual "what Claude needs" turn-end notification text</p>
<p>• Fixed MCP servers reconnecting when an updated config only changed the order of the server URL's query parameters</p>
<p>• Fixed the prompt box's top border splitting into extra lines when viewing a background agent whose name or description has line breaks or is wider than the terminal</p>
<p>• Fixed sessions getting permanently stuck on "Prompt is too long" when auto-compaction had no complete earlier exchange to summarize (mostly Agent SDK sessions with very large prompts)</p>
<p>• Fixed /goal runs silently stalling after API errors, network drops, or token limits: the goal now retries with backoff, or pauses and says why, including until a usage limit resets</p>
<p>• Fixed prompt cache misses in cloud sessions by waiting briefly for server configuration before the first request</p>
<p>• Fixed /btw answers that contained made-up tool calls and output: the side question is now told not to write them, and any that appear are flagged as not executed</p>
<p>• Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had failed with an API error over 6 hours earlier, or longer ago than CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS when set</p>
<p>• Fixed organization plugins enabled through managed settings not loading in headless sessions and on Claude Desktop (once Desktop bundles this CLI version); they load from the next session</p>
<p>• Fixed plugin archives extracted for a session being readable by other local users, extracted files keeping world-writable bits from the archive, and stale files surviving re-extraction</p>
<p>• Fixed Edit() deny rules and the write-path check not applying to the file a Bash tee command writes; a Bash(tee:*) allow rule no longer covers destinations outside the working directories</p>
<p>• Fixed stray characters like 22c, or a terminal's color or version reply, being typed into the prompt at startup over slow connections (ssh, browser terminals)</p>
<p>• Fixed the terminal's block cursor showing under the interface in rxvt-unicode after leaving or re-entering fullscreen</p>
<p>• Fixed the cursor block staying visible after returning from an external editor in fullscreen mode on rxvt-unicode</p>
<p>• Fixed the interface being drawn twice after returning from an external editor (Ctrl+G) outside fullscreen mode</p>
<p>• Fixed the interface being drawn twice in Konsole after returning from an external editor</p>
<p>• Windows: Fixed PowerShell tool commands sent to the background stopping when Claude Code exits</p>
<p>• Improved the /diff panel to open fully rendered in one step instead of showing a loading state first</p>
<p>• Improved prompt suggestion filtering for Japanese, Chinese and Korean text: mixed-script and single-word suggestions are kept, and meta or evaluative text is dropped as it is for English</p>
<p>• Improved the Skill tool's "Unknown skill" error to name the plugin skill's full name when a bare name matches exactly one plugin skill</p>
<p>• Improved keyboard support over SSH and in unrecognized terminals: terminals that answer the kitty keyboard query (such as foot and Alacritty 0.16+) now get Shift+Enter and Ctrl+Shift shortcuts</p>
<p>• Improved responsiveness in long sessions: transcript updates no longer re-process the whole conversation to build the collapsed tool-use summaries</p>
<p>• Improved first-party sessions with telemetry disabled: an alwaysLoad MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip</p>
<p>• Changed /ultrareview --post to post the PR comment directly when the findings arrive and print the comment link, instead of starting a second cloud session to post it</p>
<p>• Changed artifact database reads that save into the session scratchpad so they no longer stop for working-folder approval</p>
<p>• Changed skills synced from claude.ai in cloud sessions to be named anthropic-skills:<name>, matching Claude Desktop; the bare name still works when nothing else uses it</p>
<p>• [VSCode] Added an agent map: an "N agents" footer pill opens a map of the session's sub-agents with per-agent cards, Stop agent, and read-only transcripts</p>
<p>• [VSCode] Added a Hooks dialog to the command menu for viewing hooks and adding, editing, or removing them in user, project, and local settings; managed, plugin, and session hooks stay read-only</p>
<p>• [VSCode] Added live progress rows for running subagents under the tool-call groups in Focus view</p>
<p>• [VSCode] Added a Permission rules dialog that lists permission rules and adds or removes them in user, project, and local settings; startup-option, session-only, and managed rules stay read-only</p>
<p>• [VSCode] Added a Cancel button to the Switch account screen that returns to your session as the current account</p>
<p>• [VSCode] Fixed Focus view showing a turn started by a delivered plain-text prompt, such as a scheduled task's, as part of the previous turn</p>
<p>• [VSCode] Fixed the footer's prompt cache clock hiding its minutes when the panel is narrow</p>
<p>• [VSCode] Fixed the session list keeping sessions from the default folder when CLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting</p>
<p>• [VSCode] Fixed a plan preview that finished loading late sometimes hiding its comment box or showing an older plan</p>
<p>• [VSCode] Fixed a plan preview accepting comments that went nowhere after its Claude tab closed</p>
<p>• [VSCode] Fixed the prompt cache clock and reopen notice for a session compacted after its last reply and then closed, which now reads as cold when reopened</p>
<p>• [VSCode] Fixed a session renamed in the extension while Remote Control is on keeping its old name on claude.ai/code</p>
<p>• [VSCode] Fixed the "Enable Remote Control for all sessions" toggle keeping its last position after the setting was reset to default from a terminal</p>
<p>• [VSCode] Fixed restored Claude tabs not counting as open in the session list after a window reload until clicked, and their row opening a second tab</p>
<p>• [VSCode] Fixed Switch account making a tab forget its dismissed usage-limit warnings when you sign back in as the same account</p>
<p>• [VSCode] Fixed a session rename being replaced by the generated name after a window reload when the session was renamed during a long turn</p>
<p>• [VSCode] Fixed the sidebar usage meter keeping a stale per-model weekly limit row after the account loses that limit</p>
<p>• [VSCode] Fixed a rare case where an @-mention sent with the keyboard shortcut while a new chat view was still starting could be inserted into the input long after the keystroke</p>
<p>• [VSCode] Fixed the session list jumping down when the Account & usage header appeared a moment after opening the Claude side bar</p>
<p>• [VSCode] Improved documents and messages written for someone other than the user: Claude now writes them for that audience and names it at the top of its reply</p>
<p>• [VSCode] Improved screen reader and keyboard accessibility in the slash-command menu, @-mention menu, output-style picker, Send/Stop button, permission and question cards, and onboarding checklist</p>
<p>• [VSCode] Changed the current-file chip in the message box: an X now removes it, replacing the Hide toggle</p>
<p>• [VSCode] Removed the Claude Code items from a session tab's right-click menu and the editor title bar's "..." menu; they could not act on the tab the menu was opened on</p>
<p>• [Claude Code on the web] Added taking back a queued message in a cloud session before Claude reads it: remove it from the queue, or press Esc or Up, and the text returns to the message box</p>
<p>• [Claude Code on the web] Fixed /model default in a cloud session leaving every later message failing in organizations that restrict which models Claude Code can use</p>
<p>• [Claude Code on the web] Fixed one-off scheduled routines occasionally running a second time after a transient server error</p>
<p>• [Claude Code on the web] Fixed routine runs that use subagents sometimes being treated as finished too early, which could skip the retry after a real failure or start a duplicate run</p>
<p>• [Claude Code on the web] Fixed file links in cloud session transcripts opening a GitHub 404 when Claude was working from a subfolder of the repository</p>
<p>• [Claude Code on the web] Changed the Cloud environments admin page to list every environment instead of capping each table at five rows behind a Show more control that could be unreachable</p>
<p>• [Claude Code on the web] Changed claude.ai/code for Free-plan users to open the plans page with a path to upgrade, instead of a "Disabled by org admin" page with no way forward</p>
<p>• [Claude Tag] Added a confirmation dialog before Connect all or Disconnect on a GitHub installation in admin settings, to guard against accidental organization-wide changes</p>
<p>• [Claude Tag] Fixed threads occasionally going silent after a failed turn because the failure notice was dropped when Slack briefly rate-limited it; the notice is now retried</p>
<p>• [Claude Tag] Fixed Claude accepting a switch to a model your organization hasn't enabled and then quietly answering with a fallback model; it now declines and says an admin can enable it</p>
<p>• [Claude Tag] Fixed a table posting as raw pipe text when Claude attached files to the same message; the table now posts as a normal reply and the files follow with a plain caption</p>
<p>• [Claude Tag] Fixed @Claude !restart at the top level of a channel where Claude isn't active starting an unrelated conversation; it now privately says there is nothing to restart</p>
<p>• [Claude Tag] Fixed plugin rows in Slack access settings showing an unlabeled raw ID with no way to turn the plugin off; they now show its name and link to the bundle that manages it</p>
<p>• [Claude Tag] Fixed the shared-session banner and Share dialog on sessions started from Slack claiming the whole organization could open the link; they now name the Slack channel's audience</p>
<p>• [Claude Tag] Improved load time of the admin settings page and its Slack channel picker, most noticeably for organizations with many channels or several connected workspaces</p>
<p>• [Claude Tag] Improved scheduled routines in Slack channels: a routine run can now reply in an existing thread instead of always posting a new top-level channel message</p>
<p>• [Claude Tag] Improved the timestamp on Claude's live progress checklists to show each reader's local time and how long ago it was updated, instead of a fixed UTC time</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.268Claude Code v2.1.2682026-09-10T20:30:46Z<p>• Added to the Claude apps gateway: with pricing: set in gateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so /cost and telemetry match the spend meter</p>
<p>• Added a startup warning for gateways when access_control.allow_cidrs is empty, and a one-time warning the first time a request arrives from a public address</p>
<p>• Added the gatewayInternalNetworks managed setting, letting administrators allow /login to a Claude apps gateway on their organization's own public IPv4 block</p>
<p>• Added claude self-hosted-runner --remove-session-state (default off): delete each session's per-session directories under <base-dir>/_sessions/ when the session ends</p>
<p>• Added configDirectory to the output of claude auth status --json</p>
<p>• Added --json to claude plugin install, uninstall, update, enable and disable, and errorDetails/noteDetails to each row of claude plugin list --json</p>
<p>• Added browser-tab icons for published artifacts, chosen by Claude to match each page</p>
<p>• Fixed every turn failing with HTTP 400 on third-party Anthropic-compatible endpoints (ANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints reject</p>
<p>• Fixed WebFetch hanging indefinitely on a server that keeps the response open without finishing; a fetch now fails after 300 seconds. Set CLAUDE_CODE_WEBFETCH_DEADLINE_MS to override the deadline (0 turns it off)</p>
<p>• Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted</p>
<p>• Fixed sustained high CPU usage: a busy loop in long-running idle sessions no longer pins a CPU core, and rapid terminal focus reports during a session recap no longer keep the CPU high</p>
<p>• Fixed Claude sometimes replying "your message came through empty" after an MCP tool call</p>
<p>• Fixed deny and ask permission rules on symlinked directories (/etc, /tmp, /var on macOS; /bin on Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spelling</p>
<p>• Fixed a case where a Read or Edit deny rule did not apply when an env -C, eval or similar command the permission checker cannot analyze was on the same line</p>
<p>• Fixed plugin and marketplace errors showing a token or password from a git source URL</p>
<p>• Fixed /mcp and /plugin server details, claude mcp list/get, and MCP login errors showing secrets resolved from ${VAR} placeholders in MCP configs</p>
<p>• Fixed prompt caching and extended thinking breaking mid-session for SDK sessions using excludeDynamicSections: the first message is no longer re-rendered each request</p>
<p>• Fixed entitled users being told a model is restricted after restart or in the Desktop Code tab when a cached model-access denial was stale</p>
<p>• Fixed a running session silently switching to the organization's default model when another Claude Code process refreshed a stale model-access entry</p>
<p>• Fixed long-context 429s on Fable models showing the usage-credits consent prompt instead of the 1M-context message on Pro and Team plans</p>
<p>• Fixed workload identity federation via a profile (as claude-code-action configures it): processes sharing the profile could fail mid-run with 401 … jti reused</p>
<p>• Fixed MCP server OAuth sign-in failing with "No available ports for OAuth redirect" when the local callback port range can't be bound</p>
<p>• Fixed the conversation summary produced by /compact and auto-compact mangling text that contained $ sequences</p>
<p>• Fixed resuming a conversation that ended with /compact: its restored-file notes now load in the same order on every resume</p>
<p>• Fixed SDK prompt suggestions, side questions and /rename sending the conversation from before a compaction</p>
<p>• Fixed @ file and / command suggestions not appearing after recalling a previous prompt with the up arrow and editing it</p>
<p>• Fixed claude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a second</p>
<p>• Fixed claude agents session delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway</p>
<p>• Fixed background agent and workflow rows in the agents panel expanding to many lines when their text contained line breaks</p>
<p>• Fixed Claude in Slack sessions losing their Slack tools when org managed settings set an MCP allowlist</p>
<p>• Fixed Claude in Chrome asking to allow the host "https" when a navigation URL had a scheme but a host that could not be parsed</p>
<p>• Fixed the spinner wrapping onto several lines when the current task's label is long; the label and the "Next:" task line now stay within one terminal row</p>
<p>• Fixed the /bug and /feedback description field showing no cursor when the terminal's native cursor is enabled</p>
<p>• Fixed Remote Control sessions served by claude remote-control showing a generated name instead of their session title in ListAgents</p>
<p>• Fixed claude plugin validate rejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts</p>
<p>• Fixed plugins silently skipping a default monitors file or root SKILL.md that could not be checked</p>
<p>• Fixed WebFetch's error for localhost and other dotless hostnames to explain why the URL is refused and suggest curl</p>
<p>• Fixed PermissionRequest hooks not firing in --print mode</p>
<p>• Fixed policy-helper warnings not printing on headless (-p) runs</p>
<p>• Fixed /resume listing a /fork background session under its parent's name instead of its own ⑂ fork name</p>
<p>• Fixed /remote-control and other claude.ai-gated commands to suggest /login when signed out instead of showing a Claude for Enterprise migration message</p>
<p>• Fixed CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS not extending SessionEnd hooks that have no per-hook timeout (they were still cancelled after 1.5 seconds)</p>
<p>• Fixed /autofix-pr and other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to /web-setup or the web connect page</p>
<p>• Fixed cloud-session commands such as /teleport and /remote-env to explain when an organization policy turns them off, instead of answering "Unknown command"</p>
<p>• Fixed Bash sandbox instructions over-stating confinement: no unenforced path lists when filesystem isolation is off, and strict mode no longer claims commands can never run unsandboxed</p>
<p>• Improved fullscreen mode: adding or removing a prompt line (Shift+Enter) now repaints as fast as typing a character instead of re-rendering the visible transcript</p>
<p>• Improved --continue / --resume: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript</p>
<p>• Improved responsiveness during tool-heavy turns by no longer redrawing the transcript for a hidden per-tool-batch reminder</p>
<p>• Improved startup time in projects with .claude/workflows/ scripts: listing them no longer parses each script</p>
<p>• Improved auto mode denials: the message Claude receives now names the rule that blocked the action and asks Claude to try a safer method and finish unrelated work before stopping to ask you</p>
<p>• Improved Claude in Chrome: long page reads now stay inline instead of being saved to a file and read back</p>
<p>• Improved the MEMORY.md truncation warning to say how many lines were cut and where the cut starts</p>
<p>• Improved the terminal permission prompt for artifacts: it now leads with the ask's question</p>
<p>• Improved the prompt footer: an editor or /diff selection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer</p>
<p>• Improved the "Usage credits required for 1M context" message to say that usage credits turned on mid-session take effect after restarting Claude Code</p>
<p>• Improved /plugin: installing, enabling or disabling a plugin now takes effect when you close the menu; /reload-plugins is no longer needed afterwards</p>
<p>• Changed the system prompt on Bedrock, Vertex and Foundry to deliver environment, model and settings details as attachments, matching first-party sessions</p>
<p>• Changed Bedrock, Vertex and Foundry sessions to keep the tool list byte-stable across a conversation (late-connecting tools load deferred instead of rewriting it), matching first-party sessions</p>
<p>• Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be offered only on Claude 3.x, Opus 4.0–4.7, Sonnet 4.0–4.6, Haiku 4.5; set CLAUDE_CODE_ENABLE_TODO_TOOLS=1 elsewhere</p>
<p>• Changed the artifact data-edit permission prompt in the terminal to a card that shows the document count and who can open the artifact</p>
<p>• Changed local Cowork sessions set to skip all approvals: the Artifact tool now refuses a local file outside the session's folders, or behind a symlink, instead of reading it without asking</p>
<p>• Changed plain WebFetch deny and ask rules to no longer apply to Artifact tool reads and updates; use an Artifact rule (or WebFetch(domain:claude.ai)) to block or gate them</p>
<p>• Changed the "N MCP servers need authentication" startup notice to announce each server once instead of at every launch</p>
<p>• [VSCode] Fixed the session list, settings toggles, and chat tabs when CLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting</p>
<p>• [VSCode] Fixed the model pill, model picker and command menu going blank in open tabs for a few seconds after a login, logout or account switch</p>
<p>• [VSCode] Fixed Auto disappearing from the mode picker in new-tab or just-reloaded conversations when a project or local setting overrides the model named in ~/.claude/settings.json</p>
<p>• [VSCode] Fixed session names reverting to the last prompt after a window reload when a SessionStart hook is configured</p>
<p>• [VSCode] Fixed the footer's model pill and Remote Control pill waiting for the new tab's Claude process to start when another tab in the window is already up</p>
<p>• [VSCode] Fixed a second Claude process running through its full startup when a session tab's launch arrived more than half a second after its config read</p>
<p>• [VSCode] Fixed resuming a session from the session list ignoring claudeCode.preferredLocation: "sidebar" (it always opened a panel), and programmatic opens resetting that setting to "panel"</p>
<p>• [VSCode] Fixed Windows issues: the WSL install prompt no longer appears on machines without WSL installed, and IDE diagnostics are now returned correctly for Windows files when WSL is installed</p>
<p>• [VSCode] Fixed the custom style builder saving a User level style in a folder the CLI does not read when CLAUDE_CONFIG_DIR is set through settings</p>
<p>• [VSCode] Added Left and Right arrow keys to change where an always-allow permission rule is saved, for keyboard and screen reader users</p>
<p>• [VSCode] Added a "Claude Code: Focus last message" command that moves keyboard focus to the newest message in the conversation, for keyboard and screen reader users</p>
<p>• [VSCode] Changed the Manage plugins dialog to apply installs, enables, disables and uninstalls to open sessions without a restart</p>
<p>• [VSCode] Changed some artifact permission prompts to omit the "don't ask again" choice, matching the terminal</p>
<p>• [Claude Code on the web] Fixed cloud sessions running longer than about six hours silently losing files saved to persisted session folders; saves now persist for up to a day</p>
<p>• [Claude Code on the web] Fixed "Invalid effort level" errors when a routine resumes a session, or a session starts with no set effort, in orgs where an admin caps a model's effort</p>
<p>• [Claude Code on the web] Improved routine creation from a conversation: when the new routine has no connectors, Claude now says so and how to add them instead of only confirming it</p>
<p>• [Claude Tag] Fixed the admin settings page hanging on a loading skeleton or going blank after a transient load failure; a section that fails to load now shows a Retry button</p>
<p>• [Claude Tag] Added a link from a Slack channel's configure page back to the organization's Claude in Slack admin settings</p>
<p>• [Claude Tag] Fixed a Slack Enterprise Grid channel losing its Claude settings (repository, environment, access) after a Slack admin moved it to another workspace</p>
<p>• [Claude Tag] Improved how Claude explains a blocked action: it now says whether a permission check, its own decision to confirm first, or missing access stopped it</p>
<p>• [Claude Tag] Improved reply speed: Claude now runs several read-only lookups (searching Slack, reading a thread, finding people) at once instead of one after another</p>
<p>• [Claude Tag] Improved formatting of comparisons: sentence-length comparisons now come as lists instead of wide tables that scroll sideways, and long table cells wrap</p>
<p>• [Claude Tag] Fixed @Claude !restart in a thread with its own session sometimes also posting a contradictory "this thread is handled by the channel session" notice</p>
<p>• [Claude Tag] Improved the message shown when your Claude account is in a different organization than the Slack workspace: it now explains how to connect the workspace to your org</p>
<p>• [Claude Tag] Fixed Markdown links whose URL is wrapped in angle brackets showing as literal bracket text in Slack instead of a clickable link</p>
<p>• [Claude Tag] Fixed a workspace guest's top-level @mention in a channel where guests may use Claude sometimes getting a "your Slack account isn't connected" reply instead of an answer</p>
<p>• [Claude Tag] Fixed a channel's long-running session being replaced with a fresh one mid-conversation; the scheduled refresh now waits until the channel and its threads are quiet</p>
<p>• [Claude Tag] Fixed channel-settings cards clicked more than once telling the proposing session the change was refused after it had already applied; the outcome is now sent once</p>
<p>• [Claude Tag] Changed memory in public channels: each channel now keeps its own notes, and Claude no longer recalls notes it saved in other public channels; workspace notes stay shared</p>
<p>• [Code Review] Added a note under the still-open findings list in follow-up reviews: resolving a finding's thread, not just replying to it, stops later reviews from counting it as open</p>
<p>• [Code Review] Fixed reviews sometimes ending as incomplete when one of the agents verifying a finding failed midway; the review now replaces that agent and reaches a verdict</p>
<p>• [Code Review] Fixed a push-triggered review that was queued behind a running review still posting after the pull request had been converted to draft</p>
<p>• [Code Review] Fixed reviews ignoring a directory's CLAUDE.md conventions when the PR edited a root file (e.g. README.md) that only shares a name with a file that CLAUDE.md lists</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.267Claude Code v2.1.2672026-09-09T19:58:08Z<p>• Added maxEffortLevel setting (top-level or per model under modelSettings): caps the effort level on every provider, including Bedrock, Vertex and Foundry; users can still pick a lower level</p>
<p>• Added --system-prompt-snapshot off to render the system prompt fresh on every request instead of reusing the conversation's recorded prompt (for iterating on prompt text)</p>
<p>• Fixed Cowork scheduled tasks in the cloud failing at startup for organizations whose managed settings require sandboxing</p>
<p>• Fixed /context and other local command output rendering blank on mobile clients</p>
<p>• Fixed shift+enter and option+backspace not working after reconnecting to a tmux or ssh session inside an agent view</p>
<p>• Fixed the dim last-prompt header not appearing at the top of the conversation when scrolling up in fullscreen mode</p>
<p>• Fixed Workflow agent() calls with large output schemas being refused in auto mode instead of being checked by the safety classifier</p>
<p>• Fixed a case where a marketplace entry path containing a backslash could bypass the containment check for fetched marketplaces on macOS and Linux</p>
<p>• Fixed expired AWS or Google Cloud credentials under a host app such as Claude Desktop retrying ten times with a generic "request failed" before the re-authenticate error appeared</p>
<p>• Fixed resuming a session after /compact or another slash command ran via -p --resume: a spurious "Continue from where you left off." turn is no longer inserted</p>
<p>• Fixed resuming a large session (transcript over 5 MB): parallel tool calls and their hook output are no longer dropped from the reloaded conversation</p>
<p>• Fixed managed allowedHttpHookUrls, httpHookAllowedEnvVars and allowedChannelPlugins to admit nothing, not everything, when unreadable</p>
<p>• Fixed /login on machines whose managed settings require Claude apps gateway sign-in: Esc now closes the dialog instead of doing nothing</p>
<p>• Fixed artifact publishes cut off by a dropped connection mid-upload: they now retry once when Claude Code can tell the upload never completed, instead of reporting an unknown outcome</p>
<p>• Fixed effort: frontmatter on custom commands, skills, and subagents being ignored on models whose default effort is still pinned (Opus 4.7, Opus 4.8, Fable 5)</p>
<p>• Fixed artifact publish failing with an unhelpful error when the page file isn't valid UTF-8 or contains a replacement character (U+FFFD); the error now names the line and column to fix</p>
<p>• Fixed claude agents @ directory menu not listing repositories created after the session started</p>
<p>• Fixed Remote Control clients that join a Claude Desktop or VS Code session showing a stale permission mode until it was changed again</p>
<p>• Fixed claude remote-control exiting and dropping every attached session when its server credential expires (about 30 days after start); the host now re-registers and keeps going</p>
<p>• Fixed the usage-limit warning flickering on and off during a session when requests for different models or modes report different limit windows</p>
<p>• Fixed earlier reasoning being dropped when an MCP server re-sends, or a built-in tool re-renders, a tool the model already loaded</p>
<p>• Fixed a tool that disappears mid-conversation, from a disconnected MCP server or an upgrade, rewriting the tool list and discarding earlier thinking</p>
<p>• Fixed a background worker forked from a conversation adding EnterWorktree to the conversation's tool block mid-session, which broke prompt-cache reuse</p>
<p>• Fixed mid-session MCP and plugin tools being added to the tool list in sessions without ToolSearch, which broke prompt-cache reuse; supported models now receive them as deferred definitions</p>
<p>• Fixed switching models with /model re-sending every tool definition (a prompt-cache miss); commit and PR attribution text now arrives as a conversation note that updates on model changes</p>
<p>• Fixed resumed sessions rewriting the inline tool set when an MCP connector reconnects at a different moment than before</p>
<p>• Fixed resumed sessions re-rendering tool descriptions instead of replaying the recorded ones when the first turn ran a tool</p>
<p>• Fixed prompt-cache misses and dropped extended thinking when a claude.ai connector's tools change between a session and its resume</p>
<p>• Fixed resumed sessions rewriting earlier MCP tool announcements (and dropping extended thinking) before their connectors reconnect</p>
<p>• Fixed a prompt-cache break when a print-mode (-p) conversation is resumed interactively: the system prompt prefix no longer changes</p>
<p>• Improved the /diff panel: it no longer flashes "0 files changed" and a spinner before settling, and its empty state is centered in the panel</p>
<p>• Improved the Bash tool's description guidance so Claude describes what a command does in plain words instead of echoing the command</p>
<p>• Improved sandbox guidance so Claude suggests /copy when clipboard commands such as pbcopy fail inside the sandbox</p>
<p>• Improved --resume first-render time for sessions with many Bash tool calls</p>
<p>• Improved prompt input responsiveness: keystrokes no longer occasionally wait a frame behind spinner or streaming repaints</p>
<p>• Improved prompt-cache stability: subagents and sessions started with --system-prompt or --append-system-prompt now record the system prompt and tool definitions once instead of re-rendering them</p>
<p>• Improved Artifact tool publish errors: when a publish is refused, the message now says why and what to do about it</p>
<p>• Self-hosted runner: Changed --use-anthropic-git-proxy to be reported to the server at registration and to print a warning for each session that still clones through the legacy git proxy</p>
<p>• Gateway: Changed forward_user_identity upstreams to return a 429 as-is to a developer whose email was forwarded, instead of failing over to the next upstream, so the proxy's per-user limits hold</p>
<p>• [VSCode] Fixed the extension host hanging at 100% CPU when forking, editing an earlier message, or rewinding in a conversation whose saved transcript contains a cyclic parent link</p>
<p>• [VSCode] Fixed pasting a screenshot on WSL2/WSLg inserting raw image bytes into the chat input; the image is now attached when the clipboard provides it, otherwise the paste is ignored</p>
<p>• [VSCode] Fixed chat diff blocks always rendering with a dark editor theme; they now follow the active VS Code color theme, including high contrast</p>
<p>• [VSCode] Fixed mixed right-to-left and English text rendering in the wrong order while typing in the message input</p>
<p>• [VSCode] Fixed accepting an edit in the diff view on a file with Windows (CRLF) line endings failing with "String not found in file"</p>
<p>• [VSCode] Fixed @-mentions dropping files whose paths contain spaces</p>
<p>• [VSCode] Fixed the sessions list view failing to load in windows connected over Remote-SSH when the workspace folder exists only on the remote host</p>
<p>• [VSCode] Fixed runaway ripgrep processes when viewing files in large or symlink-heavy workspaces</p>
<p>• [Claude Code on the web] Fixed GitHub Enterprise Server sessions showing your GitHub account as disconnected once its token expired; PR and issue operations now refresh it automatically</p>
<p>• [Claude Code on the web] Fixed gh and GitHub API calls failing in organizations without the Claude GitHub App; they now use your connected GitHub account and say so when none is connected</p>
<p>• [Claude Tag] Added a "Use a custom connector" link to the preset connection forms in Claude Tag admin settings, so you can switch to a custom connection without starting over</p>
<p>• [Claude Tag] Fixed Claude replying "The API rejected the request as invalid" when the organization has run out of usage credits; the reply now says so and explains how to add more</p>
<p>• [Claude Tag] Fixed thread requests to edit or delete a message Claude posted at the channel's top level being answered with a correction instead of reaching the session that posted it</p>
<p>• [Claude Tag] Fixed Connect on Tool access requests under Admin settings > Review requests failing with "Authorization failed" or showing the requested access bundle as deleted</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.266Claude Code v2.1.2662026-09-08T23:55:08Z<p>• Fixed a 2.1.265 regression affecting LLM-gateway and proxy setups: the undocumented CLAUDE_CODE_USE_GATEWAY environment variable, previously ignored unless ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN were both set, began forcing Cloud-gateway sign-in on its own in 2.1.265, so configurations that set it alongside an API key, apiKeyHelper, or custom auth headers failed every request with "Not signed in to the Cloud gateway". The variable on its own is ignored again; no configuration change is needed</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.265Claude Code v2.1.2652026-09-08T20:37:23Z<p>• Added user.email and user.groups to the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions</p>
<p>• Added support for pointing --plugin-dir at a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up</p>
<p>• Added a 1 GB cap on tool results saved to disk; the in-conversation preview says when a saved file was truncated</p>
<p>• Fixed resuming a foreground-spawned subagent changing its tool list and system prompt prefix, which broke prompt-cache reuse for that agent</p>
<p>• Fixed agent teammates and resumed subagents moving SubagentStart hook context and preloaded skills out of the prompt prefix on later turns, which broke prompt-cache reuse</p>
<p>• Fixed resume after the previous process died while a tool was running: the last prompt is no longer rewritten, and the interrupted tool call is kept and marked interrupted</p>
<p>• Fixed /model opusplan[1m] being rejected with "Model not found"</p>
<p>• Fixed syntax-highlighted code in permission prompts and messages sometimes omitting a character after a Ruby ?, Erlang $, or Perl $ sigil</p>
<p>• Fixed the fullscreen transcript jumping by one row whenever the slash-command or @-file suggestion list opened or closed</p>
<p>• Fixed a plugin path containing a backslash bypassing the symlink containment check on macOS and Linux</p>
<p>• Fixed plugin directories whose names begin with two dots being wrongly refused as outside the plugin root</p>
<p>• Fixed VS Code and SDK sessions occasionally requiring re-login when a session was closed while refreshing its token</p>
<p>• Fixed Remote Control sessions sending the end-of-turn signal before the reply's last message, which could show a reply as finished in the Claude app before its last part arrived</p>
<p>• Fixed background (--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout</p>
<p>• Fixed Claude Code's own git status and diff probes running clean filters configured by a nested repository inside the working tree</p>
<p>• Fixed the advisor tool and its instructions being re-decided per request from the request's model; the decision is now made once and announced in the conversation when it changes</p>
<p>• Fixed artifact publish accepting connector tool names the connector doesn't expose; the publish is now refused when none of the declared tools exist, and warned when only some don't</p>
<p>• Fixed /add-dir <subdirectory> refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are locked</p>
<p>• Fixed two-key keyboard shortcuts cancelling silently when the second key arrived more than a second later, as happens inside tmux; they now wait 3 seconds and show a notice when they time out</p>
<p>• Fixed forked skills (context: fork) not streaming their kickoff prompt and, with --forward-subagent-text, their text turns as progress events in stream-json</p>
<p>• Fixed a plugin's default component folder that the OS cannot check, such as a symlink loop, being silently skipped; it is now reported in /plugin with the error code</p>
<p>• Fixed the Claude apps gateway's OTLP telemetry relay pausing all forwarding to a collector for 30 seconds after it rejected a few payloads as malformed or too large</p>
<p>• Fixed /plugin Discover/Browse and claude plugin list --json --available showing no description or display name for marketplace plugins whose metadata lives only in their plugin.json</p>
<p>• Fixed /login showing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings</p>
<p>• Fixed /model claiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why</p>
<p>• Fixed /clear from Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing</p>
<p>• Fixed the /config dialog changing height when switching between its tabs</p>
<p>• Fixed resuming a workflow run after its container restarted; a resume whose run journal is missing now fails with a clear error instead of rerunning every agent</p>
<p>• Fixed the claude-api skill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403</p>
<p>• Fixed non-interactive sessions (-p with stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; a cd now persists across turns</p>
<p>• Fixed MCP servers configured as http that only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes</p>
<p>• Fixed some claude.ai connectors in cloud sessions showing as needing authentication even though they are connected in claude.ai (servers that answer an unsupported request with HTTP 401)</p>
<p>• Fixed remote sessions keeping their sandbox container alive while a connector approval or sign-in link waits for you</p>
<p>• Fixed resumed sessions showing long model-facing recovery instructions in "background task didn't finish" notices instead of a short status line</p>
<p>• Windows: Fixed Read, Write and Edit refusing every file ("symlink resolution changed after permission was checked") when running inside an AppContainer or restricted-token sandbox</p>
<p>• Improved --worktree startup on large repositories: the new worktree is now checked out in parallel (git 2.32+)</p>
<p>• Improved /workflows agent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results</p>
<p>• Improved slash commands typed mid-prompt: matches now show in a list (Tab opens it outside fullscreen) instead of a single suggestion, and a plugin skill is now found by its bare name</p>
<p>• Improved remote MCP servers that need sign-in: Claude Code no longer registers an OAuth client with them until you actually authenticate</p>
<p>• Improved the time to resume long sessions that read many files</p>
<p>• Improved the error shown when an image over the size limits cannot be decoded: it now names the cause and how to fix it instead of only citing the limit</p>
<p>• Improved the Artifact tool's read of an artifact someone else wrote: the summary now treats the page as untrusted content and flags embedded instructions rather than relaying them</p>
<p>• Updated the .claude folder permission option to say what it actually allows: editing files in the project's .claude folder (or ~/.claude) for the session</p>
<p>• Changed machines with forceLoginGatewayUrl in managed settings to be Claude apps gateway sessions from startup, like forceLoginMethod: "gateway"; a leftover claude.ai login or API key is not used</p>
<p>• Changed image processing to use the runtime's built-in image support; the CLI no longer extracts a native image module to the temp directory</p>
<p>• Changed plugin display metadata to prefer the marketplace entry over plugin.json on the Installed tab and claude plugin details, filling gaps from plugin.json</p>
<p>• Changed Claude apps gateway sessions to export OpenTelemetry directly to a collector the gateway's managed settings name in OTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relay</p>
<p>• [VSCode] Added automatic archiving of sessions inactive for a set period (new "Archive inactive sessions" setting, default 14 days)</p>
<p>• [VSCode] Fixed the sidebar chat coming back blank after Reload Window or a restart when the conversation had been open for more than 10 minutes</p>
<p>• [VSCode] Fixed the timeline dot sitting below the text on the "Remote Control is active" message</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.263Claude Code v2.1.2632026-09-06T02:54:14Z<p>• Bug fixes and reliability improvements</p>https://github.com/anthropics/claude-code/releases/tag/v2.1.261Claude Code v2.1.2612026-09-04T19:58:03Z<p>• Added an "Organization policy" line to /status and claude doctor that says why your organization's policy could not be loaded, such as a proxy not passing the endpoint through</p>
<p>• Added bashOutputMaxChars and taskOutputMaxChars settings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters</p>
<p>• Added --append-subagent-system-prompt-file to read the subagent system prompt from a file, for prompts too large to pass on the command line</p>
<p>• Added /skill-doctor to show which loaded skills go unused and what they cost in context, so you can prune them</p>
<p>• Fixed typed or pasted characters occasionally landing out of order or being dropped during fast input or key repeat</p>
<p>• Fixed /add-dir <subdirectory> printing a false "couldn't be resolved" error when the working directory is on a /net automount</p>
<p>• Fixed the Bedrock setup wizard hanging when AWS or an AWS credential helper never responds (it now times out with a clear error), and its model checks failing behind a TLS-inspecting proxy</p>
<p>• Fixed cloud sessions discarding a plugin synced from claude.ai when managed settings force-enable it in enabledPlugins, then falling back to a marketplace clone that could fail</p>
<p>• Fixed being unable to delete the character immediately before an inline [Image #N] chip in the prompt input</p>
<p>• Fixed resuming a session losing hook output and other context around parallel tool calls, which changed the resumed request</p>
<p>• Fixed Remote Control showing a stale permission mode when a phone, browser, or claude.ai app attaches to a terminal session or after the mode changes in the terminal</p>
<p>• Fixed Remote Control sessions showing as still working (stuck spinner and Stop button) after stopping a turn from a connected phone or browser, or after a local slash command like /clear</p>
<p>• Fixed SDK and cloud sessions ignoring a Stop or interrupt sent just after the first prompt, before the turn had started; the turn now stops instead of running to completion</p>
<p>• Fixed Remote Control uploading a session pulled with /teleport into the connected session, which appeared appended to the original on phone and web</p>
<p>• Fixed Remote Control's inbound event stream failing behind TLS-inspecting corporate proxies on native Windows</p>
<p>• Fixed Remote Control sessions showing the default effort level on claude.ai when the effort comes from settings</p>
<p>• Fixed gcpAuthRefresh opening a browser at startup when the Google credential check was slow, even though the credential was still valid</p>
<p>• Fixed claude.ai connectors staying absent for the whole session when the startup connector fetch timed out — the CLI now retries in the background</p>
<p>• Fixed sustained high CPU usage when a background agent could not be resumed and its wake-up was retried in a tight loop</p>
<p>• Fixed feature flags gated to a newer version occasionally applying to an older Claude Code version running on the same machine</p>
<p>• Fixed /usage and the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startup</p>
<p>• Fixed claude -p --resume <file> adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID instead</p>
<p>• Fixed the terminal progress indicator (iTerm2, Ghostty, ConEmu) showing the session as finished while a background workflow or agent was still running</p>
<p>• Fixed a rare layout glitch where a box could render with the wrong height after its container switched between row and column direction</p>
<p>• Fixed Claude apps gateway client IP when a trusted proxy appends a port to X-Forwarded-For; with an access list set, an unreadable entry now gets 403</p>
<p>• Fixed Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected Desktop's data</p>
<p>• Fixed Desktop and web showing a session as busy while it only watches an artifact for updates</p>
<p>• Fixed Claude in Chrome file_upload failing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop app</p>
<p>• Fixed SendMessage to an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects</p>
<p>• Fixed plugin install hints from CLIs run in background Bash commands: they are now detected, and the raw <claude-code-hint> tag no longer leaks into the conversation</p>
<p>• Fixed in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn, which changed the request prefix and missed the prompt cache</p>
<p>• Improved the /model picker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes it</p>
<p>• Improved startup on Google Vertex AI when GOOGLE_APPLICATION_CREDENTIALS is set: API client creation no longer re-runs Google Cloud project discovery or spawns extra gcloud processes</p>
<p>• Improved streaming performance: already-rendered blocks are no longer re-checked by layout on each update</p>
<p>• Improved the dangerous-rm safety prompt to also catch rm -rf on positional parameters and inside double-quoted sh -c scripts</p>
<p>• Improved handling when the API sends no response headers: the retry now waits up to API_TIMEOUT_MS (10 minutes by default) instead of another 3 minutes, and the messages say what to change</p>
<p>• Changed a Claude apps gateway 403 on the managed settings load (at startup or after /login) to say Claude Code may not be enabled for the organization, instead of advising a new sign-in</p>
<p>• Changed machines whose managed settings pin forceLoginMethod: "gateway" to ignore a leftover API key or claude.ai login and ask for /login; Bedrock, Vertex AI, and Foundry sessions are unaffected</p>
<p>• Changed auto mode to treat a link that packs content into a public diagram renderer's URL as an upload to that site: no longer auto-approved unless you asked for it</p>
<p>• Changed the prompt's word-editing keys to match Bash: Ctrl+W deletes back to whitespace, Alt+F and Alt+D stop at word end, punctuation separates words; keybindingFlavor no longer has any effect</p>
<p>• Changed /context token counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests</p>
<p>• [VSCode] Added a "Build a custom style" walkthrough to the Output styles menu that writes a custom output style file and lists it right away</p>
<p>• [VSCode] Added an Add server form and a Remove action to the MCP servers dialog, so MCP servers can be added and removed without leaving the IDE</p>
<p>• [VSCode] Added a hollow ring in the session list for sessions open in a terminal, another VS Code window, or Claude Desktop, so they no longer look closed</p>
<p>• [VSCode] Added a fold button to permission and question prompts so the conversation behind them can be read without dismissing them; the space beside the prompt now scrolls the conversation</p>
<p>• [VSCode] Added "Archive session" to the session list's right-click menu and gave Unarchive its own icon</p>
<p>• [VSCode] Fixed a session teleported from Claude Code on the web treating a question that was cut off when the cloud session shut down as declined</p>
<p>• [VSCode] Fixed the session tab's Rename box opening empty for a tab restored with the window; it now starts with the current name</p>
<p>• [VSCode] Fixed collapsed sections in the session list panel briefly showing expanded each time the panel loaded</p>
<p>• [VSCode] Fixed Focus view showing a tool call as still running after Claude had moved on, such as while a question waited for your answer</p>
<p>• [VSCode] Fixed the session list's active-row highlight going stale when an unfocused Claude tab's session ID is corrected</p>
<p>• [VSCode] Fixed Cmd/Ctrl+Shift+T reopen and deep-link opens placing the Claude tab outside the Claude editor group when a Claude tab has focus</p>
<p>• [VSCode] Fixed the session tab's "Add to group" putting a session opened from Claude Code on the Web in two groups; it now moves the entry the session list shows</p>
<p>• [VSCode] Fixed the model picker showing models an organization has since disabled until the window was reloaded twice</p>
<p>• [VSCode] Fixed a tab opened from the session list jumping back to that session, and a tab opened from a Web session restarting its teleport or staying empty, after VS Code reloads the tab's view</p>
<p>• [VSCode] Fixed /btw side-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors</p>
<p>• [VSCode] Fixed the pending question card not reappearing after the Claude panel reloads when signed in with a Claude.ai or Console account</p>
<p>• [VSCode] Fixed claude.ai-only features staying visible in a window's other Claude panels after one panel picked up a third-party provider from a settings file</p>
<p>• [VSCode] Fixed the sign-in screen appearing despite the Disable Login Prompt setting when Claude Code reports no login or a request fails for lack of one</p>
<p>• [VSCode] Fixed the next queued permission prompt keeping text typed on the previous prompt and accepting an immediate second click</p>
<p>• [VSCode] Fixed install-plugin links opening the Claude sidebar without the install dialog in a window where only the session list had been shown</p>
<p>• [VSCode] Fixed the sidebar usage meter staying empty on a new window until the Account & usage dialog was opened, and a 0% usage limit being left out of the meter</p>
<p>• [VSCode] Fixed "Start new session in this group" losing the group after New conversation, and a missing unread dot for a session that finished before the sidebar's unread list loaded</p>
<p>• [VSCode] Fixed the editor tab badge showing unread during a running turn or missing on a tab opened from the session list, and "Add Session Tab to Group" doing nothing for an archived session</p>
<p>• [VSCode] Fixed "Enable Remote Control for all sessions" so flipping it also applies right away to sessions open in other VS Code windows</p>
<p>• [VSCode] Fixed the session list's Open filter for sessions continued from claude.ai whose tab was still recorded under the web session, and labeled the filter menu's sections for screen readers</p>
<p>• [VSCode] Changed the model picker to one flat list of every model, with rows kept for older model spellings listed last</p>