> claude --version
Current version
v2.1.294
Published October 8, 2026
Claude Code Changelog: Every Release Explained in Plain English
The Claude Code changelog in plain English: what each release actually changes, why it matters, and whether you should care. Updated with every release.

On this page
Latest version: 2.1.294, published October 8, 2026.
TL;DR: The last few weeks were unusually big. Claude Sonnet 5 became the default model with a 1M-token context window (2.1.197), subagents now run in the background by default (2.1.198), Claude in Chrome went GA (2.1.198),
/doctorbecame a full setup checkup (2.1.205), and Claude Opus 5 became the default Opus model with the same 1M-token context window (2.1.219). Self-hosted environments arrived next (2.1.224), letting Team and Enterprise plans run Claude Code sessions on their own machines instead of Anthropic's hosted infrastructure. Claude Fable 5.1 became the default Fable model, also with a 1M-token context window (2.1.257). Claude Opus 5.5 became the new default Opus model, keeping the 1M-token context window (2.1.280). Claude Sonnet 5.5 took over as the default Sonnet model, also with a 1M-token context window (2.1.284), and most recently Claude Haiku 5.5 became the new default Haiku model, keeping the same 1M-token context window (2.1.293). If your install is older than 2.1.197, update today.
2.1.293 - Claude Haiku 5.5 becomes the default Haiku model, and a nasty post-compaction redo bug gets fixed (October 7, 2026)
- Claude Haiku 5.5 (
claude-haiku-5-5) is now the default Haiku model on the Anthropic API: 1M-token context, $0.10/$0.50 per Mtok (jumping to $0.50/$2.50 once a prompt passes 100K tokens). - Claude used to sometimes treat its own last actions before a context compaction as if they hadn't happened yet, and would redo or retract work that was already finished. Fixed.
- Pressing
←to background a session while it was holding a message you hadn't sent yet used to lose that message outright. It no longer does; if the message can't move with the session,←now stays put and tells you instead. - A memory leak in HTTP MCP connections meant a long session could slowly bloat as it kept every request it had ever sent to that server. Fixed.
- Nudging
/modeleffort to its highest or lowest setting and pressing the arrow one more time used to wrap around, and could silently save Low as that model's default effort. Fixed.
Verdict: Haiku 5.5 is the headline here. Everything else is routine reliability work - update whenever, though the post-compaction redo bug and the lost-message-on-background bug are worth having sooner if you run long sessions or background often. (2.1.294, the next day, closed two hook-enforcement gaps: a prompt or agent hook written as an instruction - "block commands that..." - could be talked around instead of actually blocking, and Stop/SubagentStop instruction hooks were too quick to let Claude stop early. Update today if you rely on hooks to enforce rules.)
2.1.292 - a 92-bullet fix pile, with six quiet sandbox and permission holes closed at once (October 6, 2026)
- Six separate sandbox and permission holes closed in one release: PreToolUse hook approvals and auto mode skipping the prompt for network (UNC) path reads, sandboxed commands able to read staged
/ultrareviewupload copies, a mid-session sandbox read-deny change not revoking access already granted inside it, a symlink swap letting a notebook or PDF read return a file outside what you approved, a tampered settings cache able to switch off the built-in policy plugin, andrm -rfon a Windows short name or alternate drive spelling skipping the "don't nuke the home folder" guard. - Plan mode used to get silently dropped when you picked a session back up with
--resumeor/resume- you'd be out of plan mode without asking to leave it. Fixed. - The saga of vanishing scheduled tasks continues: tasks created right after
/resume,/branchor/clearnow actually fire, and a background session's/loopno longer goes quiet for good when its process restarts. claude plugin installnow takes--marketplace <source>to add and install in one step, and the Agent tool gets aneffortparameter so you can dial a sub-agent's reasoning effort directly instead of inheriting the default.- Grep and Glob used to report "no matches" with no explanation when the path they were given couldn't actually be read. They now retry once or tell you what went wrong.
Verdict: this is a security-heavy fix pile, not a features release - no new default model, no new surface. Update today if you run bypassPermissions, sandboxes, or managed settings (the six permission holes are real, not cosmetic); everyone else can update whenever.
2.1.290 - a 190-bullet fix pile, with scheduled tasks stop vanishing silently and a VS Code startup regression closed (October 5, 2026)
- Scheduled tasks -
/loopwith an interval, and reminders - could vanish instead of coming back: after a conversation got compacted, after you backgrounded a session with ← or/background, or after a cloud session's container lost a pending wakeup to a restart. All three are fixed, and recurring tasks stop firing an extra run on every resume, respawn, or fork. - If Claude Code has felt slow to start since 2.1.285 under an SDK host like the VS Code extension - especially on a Windows drive mounted in WSL - that was managed settings denying reads across a slow filesystem. Fixed.
- Resuming a subagent or teammate mid-run and sending it a message used to throw away its earlier thinking and prompt cache, quietly making the next turn slower and more expensive. Fixed.
- Long sessions with hundreds of images could get permanently stuck on a "Request rejected as unprocessable by the model" error. Fixed, alongside turns that used to end abruptly when the API's content filter interrupted Claude mid-thought - those now get retried once before you see an error.
- WebSearch in interactive sessions no longer hard-stops at 200 calls per session; it now refills at 100 calls an hour instead (
CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOURtunes the rate, 0 turns it off).
Verdict: a reliability release, not a features one - no new default model, no new surface. Update today if you lean on /loop or reminders (the silent-vanishing bug alone is worth it), run the VS Code extension under WSL, or work long multi-image sessions. Everyone else can update whenever. (2.1.291, the next day, was two regression fixes from this release and 2.1.288: cloud sessions dropping answers to permission prompts, and sessions losing their last few messages on quit - both closed within 24 hours.)
2.1.289 - Claude Mods get a stability pass, with four permission gaps closed quietly (October 3, 2026)
- Four separate permission gaps closed at once: a deny or ask rule on part of a compound shell command no longer gets held open by a mod's earlier approval on managed machines,
Readdeny rules now actually block files you @-mention, edit, or select in the IDE through a symlink, and two more holes where a Bash deny or ask rule could be skipped under sandbox auto-allow by putting an expanded environment variable or a bare variable assignment in front of the command. - A user-installed plugin could rewrite the sign-in tool descriptions of an organization-managed MCP server - meaning a plugin could relabel a trusted server's own authentication prompts. Closed.
- Short code blocks packed with unclosed
<script>tags or deeply nested${substitutions could freeze the terminal, and the same trick could freeze or crash a published Artifact page in the reader's browser. Both fixed. - [VSCode] The 2.1.288 change to
claude auth statusthat may have been causing more frequent sign-outs got reverted. - The rest is Claude Mods (the plugin UI that landed in 2.1.287) working through its early bugs: mods not loading in the first session after an upgrade, stale plugin panes and stale
plugin list/eval/updateoutput, and several crashes when a mod's UI threw an error or drew something the terminal couldn't render.
Verdict: update today if you use Claude Mods, sandbox auto-allow, or run MCP servers under an org policy - the four permission gaps and the MCP tool-relabeling fix are real holes, not cosmetic polish. Everyone else can treat this as Mods ironing out its launch bugs and update whenever.
2.1.288 - an 89-bullet fix pile, with a bypassPermissions rm hole closed and the updater stops lying about failed installs (October 2, 2026)
- Security: a dangerous
rmcommand - the kind that could wipe/or your home directory - run inside abash -corsh -cscript used to skip its "always ask" safeguard in bypassPermissions mode or under a shell allow rule. Closed (anthropics/claude-code#96300). - The npm installer could report a successful update even when the real binary failed to download, leaving you running a placeholder
claudestub with no warning. It now tells you the install failed. - A fail-open hook gap closed: PreToolUse and PermissionRequest hooks were being silently skipped - not blocked - whenever Claude Code couldn't match the rule or serialize the tool's input. A skipped check now blocks the call instead of waving it through.
- A cluster of resume and long-session bugs fixed at once: mid-response API timeouts no longer kill a non-interactive turn (it now continues from the partial response), long conversations stop hard-failing with "Prompt is too long" instead of auto-compacting, and
--resumecan no longer lose files or context that a prior compaction had just restored. /loginused to say "Login successful" even when your credentials failed to save to secure storage, so you'd think you were signed in and weren't. It now shows the failure and offers a retry (anthropics/claude-code#73861).
Verdict: update today if you run bypassPermissions or shell allow rules unattended, or if you've had the npm version of Claude Code silently fail to update - both are the kind of bug that fails quietly and bites you later. Everyone else can treat this as a routine reliability release and update whenever.
2.1.287 - Claude Mods let plugins go deeper, and three sneaky security gaps close in the fix pile (October 1, 2026)
- Claude Mods land: plugins can now modify deeper behavior inside Claude Code, not just add commands or tools. The first one Anthropic ships, "You should know," runs a side agent that watches your session and flags things you or Claude might miss - turn it on with
/plugin enable cc-plugin-you-should-know@builtin(first-party sessions with telemetry on only). - Security: a dangerous
rmcommand - the kind that could wipe/or your home directory - used to skip its "always ask" safeguard if the same command also redirected output to a~path or a wildcard. Closed. - Security: a shell write routed through a symlink already committed in your repo could land on a sensitive file or escape your working directory without you noticing. Claude now names exactly where the write lands and waits for you to approve it.
- Security: an MCP tool literally named
__proto__could silently dodge your organization's per-tool permission ceiling. Closed. - Opus 4.7+ and Fable now get the 1M-token context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway, no
[1m]suffix needed (setCLAUDE_CODE_DISABLE_1M_CONTEXT=1if you'd rather stay on 200K).
Verdict: update today if you use Bash a lot, run MCP servers under an org policy, or route through Bedrock, Vertex or Foundry - three real security gaps close here, not cosmetic polish. Everyone else should still grab it soon just to try Claude Mods; "You should know" is worth a look even if you ignore the rest.
2.1.286 - an 88-bullet fix pile, with four credential-leak fixes in logs and three stuck-session bugs closed (September 30, 2026)
- Four separate ways a secret could show up readable in logs, transcripts or error messages are now closed at once: an MCP error message leaking a credential's value when "Bearer" or "Basic" came before its key name, a percent-encoded Bearer token getting only partly masked, a secret whose key name hides an invisible character (like a zero-width space) skipping redaction entirely, and a URL password with punctuation in it - or one that runs past a bracketed host in an ssh URL - surviving redaction. None of these needed anything unusual on your end; normal logging was just leaking the value.
- If the API refused the model your default or a model alias resolves to, every turn used to fail outright. Claude Code now retries once on the previous model in the same tier instead of leaving the session dead.
claude --resumeand--continuecould silently drop every earlier turn after a batch of parallel tool calls, if the original session had crashed or been killed. Fixed - your history should come back intact now.- Cloud sessions with very large histories could get stuck for good if the container was stopped while the transcript was still loading; they just never woke back up. Fixed.
- A tool or hook that returned an object, number or boolean instead of text used to throw a flat API 400 error, even in resumed sessions. Fixed.
(The rest is the usual long tail: a permission-prompt counter when several requests stack up, mouse support for the "N more" rows in fullscreen lists, a verify skill now gets run right before committing when your project defines one, several subagent and Workflow tool fixes (missing task-tracking tools in foreground subagents, worktree-isolated subagents double-loading CLAUDE.md, a stalled Workflow connection restarting from scratch), a redesigned /hooks list and theme/output-style pickers, a Remote Control fix for sessions that should have disconnected under an organization's policy, and the usual round of VSCode, Cloud sessions, and Claude Tag fixes.)
Verdict: update today if you run MCP servers or route through a gateway - the four credential-redaction fixes are real leaks, not cosmetic polish. The model-refusal and --resume data-loss fixes are also worth having if you've hit either. Everyone else can update whenever.
2.1.285 - a 136-bullet fix pile, with three permission gaps and two credential leaks closed at once (September 29, 2026)
- Three separate permission gaps closed at once: the PowerShell tool skipped deny and ask rules - and cached that failure for later checks - whenever its command parser failed to start, such as when the machine was low on memory; fork subagents stopped inheriting their parent's permission mode, so a fork could quietly exit plan mode on its own; and an Artifact tool "don't ask again" allow rule let publishes escape your approved working directory without asking. All three now behave.
- Two credential-leak bugs are fixed: redacted logs and transcripts were showing part of a URL password that contains
@(or all of it when the URL encodes@as%40), and/ultrareviewon macOS and Linux was uploading credential files whose name has a colon before the extension, likeserver:8443.key, straight past its own credential-file check. - Sessions that authenticate with
ANTHROPIC_AUTH_TOKENagainst the Anthropic API were never loading your organization's policy at all, so managed restrictions like model access silently didn't apply. Fixed. - Switching models mid-session with a
set_modelrequest - the Agent SDK'ssetModel, for instance - used to leave the new model stuck on the old model's output-token limit and auto-compact window until you restarted. It now picks up the new model's real limits right away. - A failing API request used to get retried up to 21 times when streaming kept failing, because the non-streaming fallback got a full fresh retry budget of its own instead of sharing the original request's. It now shares that budget, so a bad connection fails fast instead of stalling your turn for minutes.
(The rest is the usual long tail: a batch of new CLI and env-var knobs - claude --desktop, claude plugin configure, per-plugin MCP config at install time, an allowedProviders managed setting - a round of /ultrareview upload fixes on macOS, Linux, WSL and Windows, sandbox and Artifact tool polish, several claude mcp and plugin/marketplace fixes, Bedrock/Vertex/Mantle start-up improvements, a handful of enterprise and gateway settings changes, and the usual pile of VSCode, Cloud sessions, Claude Tag and Code Review fixes.)
Verdict: this one's a security release wearing a fix-pile headline. Update today if you use the PowerShell tool, fork subagents, Artifact tool allow rules, /ultrareview, or sign in with ANTHROPIC_AUTH_TOKEN under an org policy - all five were real gaps, not cosmetic. Everyone else can update whenever.
2.1.284 - a 100-bullet fix pile, with Sonnet 5.5 becoming the default Sonnet model (September 28, 2026)
- Claude Sonnet 5.5 (
claude-sonnet-5-5) is now the default Sonnet model on the Anthropic API: same 1M-token context window as the last few default swaps, at $2/$10 per Mtok with $0.20/Mtok cache reads. - Interactive terminal and VS Code sessions now start in auto mode by default when you haven't set a permission mode, on every plan and provider. If you were relying on the old ask-every-time default, set
permissions.defaultModeto get it back. - The recurring "Prompt is too long" error that stuck around even after compacting is fixed: when the compacted request is still too long, Claude Code now compacts a second time and keeps less of the recent conversation instead of giving up.
- Garbled response streams - raw "JSON Parse error" or "undefined is not an object" text, or the literal word "undefined" appearing in an answer - are now retried or reported as an interrupted response instead of leaking through.
- MCP tool calls in a resumed session no longer fail with "No such tool available" just because their server hadn't finished reconnecting; the call now waits up to 10 seconds for it.
(The rest is the usual long tail: enterprise/gateway additions - dollar amounts in /usage and the status line's spend limit, telemetry export straight to Google Cloud, certificate-based auth to identity providers - Ultracode becoming its own /effort toggle instead of forcing max effort, /mcp reconnect all and /rate-limit-options, a batch of dialog and keyboard fixes (fullscreen scrollback, tab bars, vim mode, the model picker), a couple of permission-hardening fixes around symlinked rules and plugin tool pre-approval, and the usual round of VSCode, Cloud sessions, Claude Tag and Code Review fixes.)
Verdict: Sonnet 5.5 becoming the default is the headline here, same territory as the Opus 5.5 and Sonnet 5 default swaps above - worth knowing even if you don't act on it immediately. The one thing that can actually surprise you: interactive terminal and VS Code sessions now default to auto mode instead of asking permission for every action. If you've been relying on the old ask-every-time default, set permissions.defaultMode explicitly before you update. Everyone else can update whenever - this is otherwise a reliability-fix release.
2.1.283 - a 94-bullet fix pile, with a Windows delete bypass closed and /doctor learning to audit your prompts (September 25, 2026)
- A real security gap closed on Windows: the PowerShell tool let
cmd /c rd,rmdir,delorerasedelete drive roots, your home folder and other folders thatRemove-Itemnormally refuses. If you're on Windows, this was a hole in a safety net you were probably relying on. /doctor prompt-audit(also/checkup prompt-audit) is new: it audits your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models, and leads with stale paths, stale commands and contradicting instruction files. Worth a run if your instructions have accumulated across model generations.- A handful of ways a session could quietly lose work are fixed: SDK sessions dropping a tool call or its result when a turn ended early, stdio MCP servers left running after a session ended mid-startup, and a stateless remote MCP server's brief 404 (say, a proxy mid-redeploy) taking that server offline for the rest of the session even though it still showed as connected.
/contextnow counts MCP server instructions as their own row instead of silently leaving them out of your total - worth a look if you've ever been surprised by how fast you fill up.- New settings for teams running managed model policy:
deniedModelsblocks specific models outright, andavailableModelsMatch: "exact"locks anavailableModelsentry to the exact version named, so a new release doesn't quietly become available until you add it.
(The rest is the usual long tail: gateway and OpenTelemetry additions for LLM gateway operators, a mantle Bedrock upstream provider, a round of claude plugin validation and recovery fixes, several MCP list and connection fixes, vim mode cursor fixes, screen-reader and keybindings fixes, and the usual batch of VSCode, Cloud sessions, Claude Tag and Code Review fixes.)
Verdict: update today if you're on Windows or you manage model policy for a team - both are real gaps, not cosmetic. Everyone else can update whenever; run /doctor prompt-audit once you're on this version if your CLAUDE.md has been around a while.
2.1.282 - an 86-bullet fix pile, with a Bash permission gap closed and three more session-killing bugs fixed (September 24, 2026)
- A permission gap closed: Bash allow/deny rules with a
:*in the middle of the pattern (not just at the end) were being silently skipped in settings files, even though--allowedToolshonored the same rule. If you lean on mid-pattern:*rules to block or allow specific commands, they weren't actually being enforced - they are now, and startup warns about how they match. - Three more ways a session could get stuck failing every turn are fixed: a 400 error on any conversation whose history holds web search results the API can't decrypt (common behind a third-party gateway), an "Invalid data in redacted_thinking block" API error (Claude Code now drops the thinking blocks and retries once), and resumed or continued sessions re-sending earlier messages in a changed form that could drop Claude's prior reasoning.
- Added
maxProseWidth, a setting that caps how wide Claude's replies stretch on a big terminal, while tables and code blocks still use the full width. - Claude Code now warns at startup, and in
/statusand/doctor, about telemetry environment variables in your project's settings files that were being silently ignored or that turned telemetry off - worth a look if your telemetry data has ever gone quiet for no reason.
(The rest is the usual long tail: a macOS symlink fix for CLAUDE.md and rules being read through paths that could escape the repo, a fix for compaction retrying on a fallback model when the summarization request is refused, several managed-settings fixes for teams running MDM policies, a Bash/PowerShell fix for disk-quota errors that used to just say "Exit code 1", a round of vim mode cursor and count fixes, and the usual batch of VSCode, Cloud sessions, and Claude Tag fixes.)
Verdict: update whenever for most people - none of this is urgent unless you've actually hit a stuck-every-turn error. If your team relies on mid-pattern :* Bash permission rules to block commands, treat that one as more than cosmetic and update sooner.
2.1.281 - a 176-bullet fix pile, with a silent rm security hole closed and resumed sessions finally surviving proxies and restarts (September 23, 2026)
- A real security gap closed:
rm -rf "$(pwd)"and similar recursive deletes whose target only appears after command substitution ran unprompted in auto mode and--dangerously-skip-permissions, dodging the dangerous-rm check entirely. It now asks even with a Bash allow rule in place. - A cluster of resume and proxy bugs that could quietly break a conversation all got fixed at once: resuming could re-send earlier turns in a changed form and drop your prior reasoning, a very large session could restore only its last few messages, and the prompt cache was getting wiped whenever an MCP server disconnected mid-conversation or a proxy cut a stream cleanly with no warning. If resuming has felt unreliable behind a proxy or gateway, this is why.
- The dangerous-rm confirmation in skip-permissions and auto mode now waits 2 minutes for an answer, then denies the command with a rewrite hint instead of hanging an unattended session forever (
CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1turns this off). - Send now (ctrl+enter or ctrl+x ctrl+s) changed behavior: it now moves running tools to the background instead of cancelling the turn outright, so sending a follow-up no longer throws away in-flight work.
- Breaking change for self-hosted runners: system prompts are now passed to Claude Code as private files instead of command-line text (so large prompts stop failing the launch). Any wrapper or hook that appends
--system-promptor--append-system-promptneeds to switch to the-filevariants.
(The rest is the usual long tail: Claude apps gateway additions for Bedrock upstreams (assume_role, guardrail) and Claude Desktop policy keys, an "attribution": false settings.json option, MCP URL-mode elicitation for browser-based server flows, a claude plugin eval-adjacent batch of claude plugin validate checks, dozens of dialog and keyboard-handling fixes (/plugin, /permissions, vim mode, the agent panel), several MCP connection and OAuth fixes, and the usual round of VSCode, Claude Code on the web, Claude Tag, and Code Review fixes.)
Verdict: update today if you run auto mode or --dangerously-skip-permissions unattended, or if you've had resumed sessions behind a proxy or gateway lose context - both are genuine reliability and security fixes, not cosmetic. Self-hosted runner operators should check their launch wrapper before updating; everyone else can update whenever.
2.1.280 - a 114-bullet fix pile, with Opus 5.5 becoming the default Opus model and two conversation-killing bugs fixed (September 22, 2026)
- Claude Opus 5.5 (
claude-opus-5-5) is now the default Opus model: a 1M-token context window at $4/$20 per Mtok, with cache reads at $0.20/Mtok. - Two separate bugs could make a session fail on every single turn: one threw a "role 'system' must precede an 'assistant' message" API error, the other hit conversations with the advisor on with a 400 "Input tag 'advisor_20260301'" error behind a proxy or gateway that didn't support it. Both fixed - if you were stuck on either, you're not anymore.
- Auto mode's retry logic got saner: an action a safety check declined is now denied once instead of retried forever, and if a safety check gives no answer at all, auto mode backs off instead of hammering it, stopping the turn with a message after ten failed attempts in a row.
- A real security gap closed: writes through a symlinked path were approved or denied based on where the path looked like it pointed, not where it actually landed - so
acceptEdits, allow rules, and auto mode could all wave through a write that landed outside the directory you'd approved. - Two ways to silently lose subagent work got fixed: messages sent to a background subagent while it was finishing its turn could vanish in headless and SDK sessions, and a finished subagent's report could be lost for good if the conversation that launched it got compacted before you read it.
(The rest is the usual long tail: several dialog keyboard-handling fixes - Ctrl+C/Ctrl+D quitting instead of closing a dialog, stray y/n keys triggering actions, dropped keystrokes in text fields - a stuck-conversation fix for malformed saved MCP-tool notices, prompt-cache fixes around model switches and resumed fork subagents, three new VSCode dialogs (Status, Sandbox, Claude in Chrome), and the usual round of Claude Code on the web, Claude Tag, and Code Review fixes.)
Verdict: update today if you've hit either of the every-turn API errors, run auto mode, or lean on write permissions as a security boundary - all three were genuine problems, not cosmetic bugs. Opus 5.5 becoming the default is the headline here: same territory as the Sonnet 5 and Fable 5.1 defaults above, worth knowing about even if you don't act on it immediately.
2.1.278 - auto mode's classifier overhead stops billing by default (September 19, 2026)
- If you use auto mode on the Claude API, Enterprise, Bedrock, Vertex, Foundry, or through a gateway, the classifier that picks your model now runs server-side by default - so you stop paying for the classifier's own overhead.
CLAUDE_CODE_AUTO_MODE_SERVER=0opts back out on Bedrock, Vertex, Foundry and gateways, and you get a warning if a request falls back to the old billed path. A new "Auto mode server" row in/statusshows which path your session is on.
Verdict: a pure cost win if you run auto mode outside claude.ai's Pro/Max plans - nothing to configure, just cheaper. Nothing here for Pro/Max subscribers to act on.
2.1.277 - an 87-bullet fix pile, with AGENTS.md support landing and a conversation-killing crash fixed (September 18, 2026)
- Claude Code now reads
AGENTS.mdin a project that has noCLAUDE.md(switch which file it reads under "Project instructions" in/config). Handy if you already maintain anAGENTS.mdfor another tool and don't want a second, duplicate instructions file. Not yet available on Bedrock, Vertex, or Foundry. - Fixed a bug where a conversation could fail every single request with "text content blocks must be non-empty" - triggered whenever an earlier assistant turn held an empty text block, including after
--resume. If you'd hit this, your session was stuck for good; now it isn't. - Fixed
claude -pand Agent SDK sessions that could hang forever with no result after an internal error - they now report the error and exit with code 1 instead of leaving you waiting. - Fixed getting logged out unexpectedly just because an older Claude Code build (for example an IDE extension's bundled CLI) happened to run on the same machine as your current one.
- Subagent results now arrive back at the main agent under a header that marks them as subagent output, so text a subagent returns can no longer be mistaken for the session's own instructions - a real prompt-injection hardening fix, not just a fix bullet.
(The rest is the usual long tail: update-check reliability fixes for malformed version settings, several claude plugin install//plugin crash and bookkeeping fixes, Grep/Glob/Write/Edit tool error-reporting fixes, the deprecated TaskOutput tool removed in favor of reading a background task's output file with Read, and the usual round of VSCode, Claude Code on the web, and Claude Tag fixes.)
Verdict: update today if you've ever hit the "text content blocks must be non-empty" error or a claude -p/SDK hang with no result - both were genuinely stuck states, not cosmetic bugs. AGENTS.md support is worth knowing about if you already keep one for another tool. Everyone else can update whenever.
2.1.275 - your claude.ai skills and plugins now follow you into the terminal, and npm plugins lose their install scripts (September 17, 2026)
- Skills and plugins enabled on your claude.ai account now sync automatically into terminal sessions signed in with that account. If you don't want that, set
syncClaudeAiSkills: falseorsyncClaudeAiPlugins: false. - Plugins installed from an npm source are now fetched with
npm pack --ignore-scriptsand integrity-checked, so a malicious package can no longer run code just by being installed. - New send-now key: ctrl+enter (or ctrl+x ctrl+s) interrupts whatever Claude is doing and sends every queued message at once, instead of waiting for your turn.
- Sandboxed Bash commands on Linux running under zsh were reporting exit code 0 even when the command had actually failed, silently hiding errors from anything that checked the exit code. Fixed.
- A pile of crash-on-resume bugs closed at once: malformed transcript entries, task-reminder or @-file attachments, and bad message content blocks could each crash or block
--resume, the resume picker, or background agents. Sessions with corrupted history should resume cleanly now.
(The rest is the usual long tail: gateway sign-in now confirms the account before saving a credential, /plugin install --marketplace adds the marketplace for you, prompt-cache improvements for custom system prompts and restored memory files, several Artifact tool reliability fixes, a /update-config permission-rule bug, and a long batch of VSCode, Claude Code on the web, Claude Tag, and Code Review fixes.)
Verdict: update today if you install plugins from npm or lean on the account-level skill/plugin sync - both are meaningful security and workflow changes. One thing to know: this release briefly broke every request for anyone behind a proxy or LLM gateway with a 400 ... Input tag 'advisor_20260301' error; that regression was fixed the very next day in 2.1.276, so make sure you're on 2.1.276 or newer before you update in a gated environment.
2.1.274 - a 108-bullet fix pile, with tool_use_id retry loops finally healed and two more Bash permission holes closed (September 16, 2026)
- Sessions could get stuck endlessly retrying "unexpected tool_use_id" 400 errors with no way out. Corrupted transcripts now self-heal where possible, and when they can't, you get a clear error with a
/rewindhint instead of an infinite loop. - Two more Bash permission-check gaps closed: commands that loop over or assign certain special shell variables now correctly ask for permission, and worktree-isolated sessions can no longer sneak a command past the checker using certain nested shell expansions. Worth knowing if you lean on Bash permission rules as a security boundary.
- Self-hosted runner sessions could fail every single turn with a 401 after a few failed token refreshes, stuck until the next scheduled refresh came around. The runner now keeps retrying and fetches a fresh token as soon as one fails.
/goalgot more resilient: a hook-driven session no longer hits a dead-end "Prompt is too long" error instead of compacting when context overflows again, and resuming a compacted session no longer silently drops an active/goal.- MCP tool calls that fail with a 403 insufficient_scope error used to be reported as an expired sign-in, sending you to
/loginfor nothing. The error now names the missing permissions and points you to/mcpto re-authenticate.
(The rest is the usual long tail: a warning before you run out of memory with steps to recover safely, several MCP connection fixes - legacy HTTP+SSE servers rejecting the first request, Streamable HTTP calls timing out at 5 minutes regardless of a longer configured timeout, list-changed notifications not refreshing prompts and resources - Bedrock/Vertex/Foundry and telemetry-disabled installs switching to the v2 MCP client by default, a "Compare against" branch picker in Claude Code on the web's diff view, a VSCode banner that resumes the step a window reload interrupted plus new Memory and Instructions menus, and the usual round of Claude apps gateway, Claude Tag, and Code Review fixes.)
Verdict: update today if you've ever hit a session wedged on tool_use_id errors, run self-hosted runners, or write custom Bash permission rules - all three were genuine gaps, not edge cases. Everyone else can update whenever; the /goal and MCP error-message fixes are good quality-of-life wins but nothing urgent.
2.1.273 - three MDM/permission policy holes close, and auto-compact stops firing at half your real context window (September 15, 2026)
- Three separate policy gaps closed. A Bash command the permission checker couldn't fully analyze could skip the deny/ask prompt under
permissions.blockReadsOutsideWorkingDirectories, and a subshell could hide a dangerousrmeven in bypass mode. Skills synced from claude.ai kept working after your organization turned Skills off - they now move to the recoverable trash instead. AndallowManagedMcpServersOnly,deniedMcpServers, anddisableClaudeAiConnectorsset via MDM ormanaged-settings.jsonwere silently ignored whenever server-managed settings were also present - meaning an admin's MCP/connector lockdown could just not apply. - The context meter and auto-compact were counting advisor-tool turns at roughly twice their real size, so auto-compact was firing at about half your actual context window. If compaction has felt like it kicks in too early lately, this is why.
- Sub-agents and background agents that finished without token-usage data or a model id in their final streamed reply were reported as failed, with their result never delivered at all - silently losing real work.
- 401/403 errors on Bedrock, Vertex, Foundry, and the Claude apps gateway now name the credential to refresh or point at your gateway administrator, instead of a bare "run
/login". - A memory directory a repository's settings pointed at was still being loaded into the prompt, recalled, indexed, and used for memory extraction even under
permissions.blockReadsOutsideWorkingDirectories- now blocked like it should have been.
(The rest is the usual long tail: new request headers for LLM gateways behind CLAUDE_CODE_GATEWAY_HINT_HEADERS=1, a notification when an MCP server disconnects and gives up reconnecting, forking a Remote Control session from the Claude app so it runs in the background on your computer, a !-at-start-of-line fix in shell mode, a macOS Read fix for dragged-in screenshots, and the usual round of VSCode, Claude Code on the web, Claude Tag, and Code Review fixes.)
Verdict: update today if you rely on MDM-managed MCP/connector policy or Bash permission rules as a real security boundary - both had genuine gaps. Everyone else can update whenever, though the auto-compact fix alone is worth having if you've been hitting compaction earlier than expected.
2.1.271 - three Bash permission-check holes close, and a stale org policy stops leaking across account switches (September 14, 2026)
- Three separate Bash permission-check holes closed: commands like
fmtorcolumncould dodge a deny/ask rule on the file they read when it followed an option the checker didn't recognize, a wildcard buried inside a command's pattern or option value (thinkgrep -v dir/* file) let matching files slip past the check entirely, and a shell variable-declaration flag could misrepresent which command was actually running. If you lean on Bash permission rules to keep commands out of certain files, these were real gaps. - Switching accounts, organizations, or API keys mid-session used to leave you running under the previous organization's cached policy until the next hourly refresh. It now applies right away.
/resumeand/teleportwere carrying over the previous conversation's file-read tracking, so a resumed session could edit files it had never actually read in that conversation. Fixed.- Cloud sessions running a Workflow, or with an agent approval applied, could start rejecting every subagent tool call with a schema-validation error once the session's worker restarted - breaking the whole run. Fixed.
- A stale
.git/config.lockleft behind by a sandboxed command that failed to start used to breakgit checkout -b,git push -u, andgit configfor the rest of the session on Linux. Fixed.
(The rest is the usual long tail: fast mode now works in Remote Control cloud and self-hosted-runner sessions, per-command allowed_domains lets auto-mode sandboxing open just the hosts a Bash/PowerShell/Monitor command needs instead of all-or-nothing, omitClaudeMd lets a subagent run without CLAUDE.md files, several MCP OAuth client-registration bugs closed, an enterprise managed-mcp.json that fails to parse now warns instead of silently dropping MCP control, mouse support in the /config panel, and the usual round of VSCode, Claude Code on the web, Claude Tag, and Code Review fixes. 2.1.272, later the same day, was a single reliability and bug-fix release with no user-visible specifics worth calling out.)
Verdict: update today if you write custom Bash permission rules or work across multiple organizations or accounts in the same session - both were real gaps with security implications. Everyone else can update whenever; the resumed-session file-tracking fix is good to have but narrow in practice.
2.1.269 - a 98-bullet fix pile, with claude plugin eval landing and stuck sessions finally unstuck (September 11, 2026)
- New
claude plugin evalcommand runs a plugin's eval suite against Claude Code and hands back scored, reproducible results as JSON or an HTML report - useful if you build or maintain plugins and want confidence before shipping an update. - Sessions with a very large prompt - mostly Agent SDK sessions - could get permanently stuck on "Prompt is too long" when auto-compaction had no complete earlier exchange to summarize. Fixed.
- A permission rule using
!to negate part of a deny or ask rule was leaking beyond the settings file that wrote it; a!rule now applies only within its own source, and a bare!on its own is ignored. Worth a look if you write custom permission rules. - Several separate prompt-cache invalidation bugs closed at once: a response cut off at the output limit and auto-resumed, interrupting Claude mid-thought and resuming later, and cloud sessions racing server configuration on the first request were all quietly blowing away your cached prefix.
- A CLAUDE.md or memory rule telling Claude not to add commit or pull request attribution was being silently overridden by the built-in attribution reminder. Your rule wins now - lines set by managed settings still apply.
(The rest is the usual long tail: plugin archives extracted for a session were readable by other local users and could keep world-writable bits from the archive, now fixed; a CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS setting for raising the Workflow tool's concurrency cap; an OpenTelemetry option to tag metrics with repository info; a handful of kitty-protocol and other terminal keyboard-handling fixes; a VS Code agent map for browsing a session's subagents; and the usual round of Claude Tag and Claude Code on the web fixes.)
Verdict: update whenever - nothing here is urgent, but if you write custom permission rules with ! negation or rely on a CLAUDE.md rule to suppress attribution lines, both were real bugs worth having fixed. (2.1.270, the next day, was a single fix for a regression this release introduced: read-only git commands in Bash could quietly start asking for permission again after a session had been running for a while.)
- Added
/output-style [name]to list and switch output styles, including over Remote Control and in cloud and other headless sessions - Added a diff of the files a Bash command changed to the Bash tool result when the Bash tool handles file edits (setting
bashEditDiffEnabled) - Added
OTEL_METRICS_INCLUDE_REPOSITORYto tag OpenTelemetry metrics and events withvcs.*repository attributes; commit events getvcs.ref.head.*withOTEL_LOG_TOOL_DETAILS - Added
CLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MSto extend the LLM gateway/v1/modelsdiscovery timeout (default 3s) - Added a spinner tip suggesting
/focusfor a view with just your prompt, a one-line work summary, and the response - Added
CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS(1–256) to raise the Workflow tool's per-run concurrent agent limit for inference-bound fan-outs - Fixed the prompt cache being partially invalidated on the turn after a response was cut off at the output-token limit and automatically resumed
- Fixed a case where resuming a session after interrupting Claude mid-thought could change how earlier context was re-sent, hurting prompt-cache reuse
- Fixed F1/F2/F4 not working in kitty-protocol terminals and Delete in st, Alt+arrows acting as Escape in rxvt-unicode, and Shift+punctuation typing the unshifted key in WezTerm (regression in 2.1.247)
- Fixed remote and headless sessions reporting "waiting for your input" while background agents were still running (set
CLAUDE_CODE_BG_TASKS_REPORT_RUNNING=0to restore the old behavior) - Fixed the terminal's replies to capability queries (
^[[?1;2c) appearing as stray text at startup in some terminals - Fixed rows at the top or bottom of the transcript going blank in fullscreen after resizing the terminal
- Fixed a deny or ask permission rule starting with
!applying beyond the settings source that wrote it; such a rule now applies only within its own source, and a bare!negation is ignored - Fixed the git status Claude is told after a compaction: it is now the current status, not the one from the start of the session
- Fixed synced plugin MCP servers not connecting when a remote session resumes
- Fixed resumed headless sessions losing a turn's replies when the model was switched or a request was retried mid-turn
- Fixed terminal escape codes, line breaks and oversized text from a background task's on-disk record reaching the task list and task notifications when work is resumed
- Fixed CMYK JPEG images failing to attach with "cannot decode"; they are now converted and resized like other JPEGs
- Fixed the managed settings approval dialog not naming the collector for a gRPC telemetry endpoint set without a scheme
- Fixed plugin
headersHelperconsent prompts showing a URL path that could be misread as a different host - Fixed plugin errors showing
[redacted URL]in place of a relative Windows path with a folder name that starts with@ - Fixed missing cursor in the permission-rule, auto-mode-rule, add-directory, session-rename and feedback-review text fields when the terminal's native cursor is enabled
- Fixed repeated clicks on a
/forkreceipt, each under a second apart, never backgrounding the session right away while it waited for the current tool to finish - Fixed plugin LSP servers that reject
shutdownparams (e.g. rust-analyzer) being left running at session end;exitis now sent even ifshutdownfails - Fixed the attribution reminder overriding a CLAUDE.md or memory rule against commit and pull request attribution; lines set by managed settings still apply
- Fixed prompt suggestions being dropped for text in Japanese, Chinese, Thai and other languages written without spaces between words
- Fixed synchronized output being assumed from the terminal's name in GNOME Terminal and Konsole versions that do not support it
- Fixed
permission_denialsin--output-format stream-jsonresults omitting Read, Edit and Write calls blocked by a path-scoped deny rule - Fixed sessions run through the SDK or the desktop app showing an unknown status in other sessions' agent list
- Fixed
/insightsfailing on Bedrock, Vertex, Foundry, and gateway deployments whose account can't reach the default Opus model by using the session model there instead - Fixed organization policy limits not loading for the session when another Claude Code process refreshed the login at the same moment
- Fixed Claude Desktop sessions using Bedrock, Vertex, or a gateway not getting the contextual "what Claude needs" turn-end notification text
- Fixed MCP servers reconnecting when an updated config only changed the order of the server URL's query parameters
- Fixed the prompt box's top border splitting into extra lines when viewing a background agent whose name or description has line breaks or is wider than the terminal
- Fixed sessions getting permanently stuck on "Prompt is too long" when auto-compaction had no complete earlier exchange to summarize (mostly Agent SDK sessions with very large prompts)
- Fixed
/goalruns silently stalling after API errors, network drops, or token limits: the goal now retries with backoff, or pauses and says why, including until a usage limit resets - Fixed prompt cache misses in cloud sessions by waiting briefly for server configuration before the first request
- Fixed
/btwanswers that contained made-up tool calls and output: the side question is now told not to write them, and any that appear are flagged as not executed - Fixed
CLAUDE_CODE_RESUME_INTERRUPTED_TURNre-running a turn that had failed with an API error over 6 hours earlier, or longer ago thanCLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MSwhen set - Fixed organization plugins enabled through managed settings not loading in headless sessions and on Claude Desktop (once Desktop bundles this CLI version); they load from the next session
- Fixed plugin archives extracted for a session being readable by other local users, extracted files keeping world-writable bits from the archive, and stale files surviving re-extraction
- Fixed
Edit()deny rules and the write-path check not applying to the file a Bashteecommand writes; aBash(tee:*)allow rule no longer covers destinations outside the working directories - Fixed stray characters like
22c, or a terminal's color or version reply, being typed into the prompt at startup over slow connections (ssh, browser terminals) - Fixed the terminal's block cursor showing under the interface in rxvt-unicode after leaving or re-entering fullscreen
- Fixed the cursor block staying visible after returning from an external editor in fullscreen mode on rxvt-unicode
- Fixed the interface being drawn twice after returning from an external editor (Ctrl+G) outside fullscreen mode
- Fixed the interface being drawn twice in Konsole after returning from an external editor
- Windows: Fixed PowerShell tool commands sent to the background stopping when Claude Code exits
- Improved the
/diffpanel to open fully rendered in one step instead of showing a loading state first - Improved prompt suggestion filtering for Japanese, Chinese and Korean text: mixed-script and single-word suggestions are kept, and meta or evaluative text is dropped as it is for English
- Improved the Skill tool's "Unknown skill" error to name the plugin skill's full name when a bare name matches exactly one plugin skill
- Improved keyboard support over SSH and in unrecognized terminals: terminals that answer the kitty keyboard query (such as foot and Alacritty 0.16+) now get Shift+Enter and Ctrl+Shift shortcuts
- Improved responsiveness in long sessions: transcript updates no longer re-process the whole conversation to build the collapsed tool-use summaries
- Improved first-party sessions with telemetry disabled: an
alwaysLoadMCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip - Changed
/ultrareview --postto post the PR comment directly when the findings arrive and print the comment link, instead of starting a second cloud session to post it - Changed artifact database reads that save into the session scratchpad so they no longer stop for working-folder approval
- Changed skills synced from claude.ai in cloud sessions to be named
anthropic-skills:<name>, matching Claude Desktop; the bare name still works when nothing else uses it - [VSCode] Added an agent map: an "N agents" footer pill opens a map of the session's sub-agents with per-agent cards, Stop agent, and read-only transcripts
- [VSCode] Added a Hooks dialog to the command menu for viewing hooks and adding, editing, or removing them in user, project, and local settings; managed, plugin, and session hooks stay read-only
- [VSCode] Added live progress rows for running subagents under the tool-call groups in Focus view
- [VSCode] Added a Permission rules dialog that lists permission rules and adds or removes them in user, project, and local settings; startup-option, session-only, and managed rules stay read-only
- [VSCode] Added a Cancel button to the Switch account screen that returns to your session as the current account
- [VSCode] Fixed Focus view showing a turn started by a delivered plain-text prompt, such as a scheduled task's, as part of the previous turn
- [VSCode] Fixed the footer's prompt cache clock hiding its minutes when the panel is narrow
- [VSCode] Fixed the session list keeping sessions from the default folder when
CLAUDE_CONFIG_DIRis set in a settings file or theenvironmentVariablessetting - [VSCode] Fixed a plan preview that finished loading late sometimes hiding its comment box or showing an older plan
- [VSCode] Fixed a plan preview accepting comments that went nowhere after its Claude tab closed
- [VSCode] Fixed the prompt cache clock and reopen notice for a session compacted after its last reply and then closed, which now reads as cold when reopened
- [VSCode] Fixed a session renamed in the extension while Remote Control is on keeping its old name on claude.ai/code
- [VSCode] Fixed the "Enable Remote Control for all sessions" toggle keeping its last position after the setting was reset to default from a terminal
- [VSCode] Fixed restored Claude tabs not counting as open in the session list after a window reload until clicked, and their row opening a second tab
- [VSCode] Fixed Switch account making a tab forget its dismissed usage-limit warnings when you sign back in as the same account
- [VSCode] Fixed a session rename being replaced by the generated name after a window reload when the session was renamed during a long turn
- [VSCode] Fixed the sidebar usage meter keeping a stale per-model weekly limit row after the account loses that limit
- [VSCode] Fixed a rare case where an @-mention sent with the keyboard shortcut while a new chat view was still starting could be inserted into the input long after the keystroke
- [VSCode] Fixed the session list jumping down when the Account & usage header appeared a moment after opening the Claude side bar
- [VSCode] Improved documents and messages written for someone other than the user: Claude now writes them for that audience and names it at the top of its reply
- [VSCode] Improved screen reader and keyboard accessibility in the slash-command menu, @-mention menu, output-style picker, Send/Stop button, permission and question cards, and onboarding checklist
- [VSCode] Changed the current-file chip in the message box: an X now removes it, replacing the Hide toggle
- [VSCode] Removed the Claude Code items from a session tab's right-click menu and the editor title bar's "..." menu; they could not act on the tab the menu was opened on
- [Claude Code on the web] Added taking back a queued message in a cloud session before Claude reads it: remove it from the queue, or press Esc or Up, and the text returns to the message box
- [Claude Code on the web] Fixed
/model defaultin a cloud session leaving every later message failing in organizations that restrict which models Claude Code can use - [Claude Code on the web] Fixed one-off scheduled routines occasionally running a second time after a transient server error
- [Claude Code on the web] Fixed routine runs that use subagents sometimes being treated as finished too early, which could skip the retry after a real failure or start a duplicate run
- [Claude Code on the web] Fixed file links in cloud session transcripts opening a GitHub 404 when Claude was working from a subfolder of the repository
- [Claude Code on the web] Changed the Cloud environments admin page to list every environment instead of capping each table at five rows behind a Show more control that could be unreachable
- [Claude Code on the web] Changed claude.ai/code for Free-plan users to open the plans page with a path to upgrade, instead of a "Disabled by org admin" page with no way forward
- [Claude Tag] Added a confirmation dialog before Connect all or Disconnect on a GitHub installation in admin settings, to guard against accidental organization-wide changes
- [Claude Tag] Fixed threads occasionally going silent after a failed turn because the failure notice was dropped when Slack briefly rate-limited it; the notice is now retried
- [Claude Tag] Fixed Claude accepting a switch to a model your organization hasn't enabled and then quietly answering with a fallback model; it now declines and says an admin can enable it
- [Claude Tag] Fixed a table posting as raw pipe text when Claude attached files to the same message; the table now posts as a normal reply and the files follow with a plain caption
- [Claude Tag] Fixed
@Claude !restartat the top level of a channel where Claude isn't active starting an unrelated conversation; it now privately says there is nothing to restart - [Claude Tag] Fixed plugin rows in Slack access settings showing an unlabeled raw ID with no way to turn the plugin off; they now show its name and link to the bundle that manages it
- [Claude Tag] Fixed the shared-session banner and Share dialog on sessions started from Slack claiming the whole organization could open the link; they now name the Slack channel's audience
- [Claude Tag] Improved load time of the admin settings page and its Slack channel picker, most noticeably for organizations with many channels or several connected workspaces
- [Claude Tag] Improved scheduled routines in Slack channels: a routine run can now reply in an existing thread instead of always posting a new top-level channel message
- [Claude Tag] Improved the timestamp on Claude's live progress checklists to show each reader's local time and how long ago it was updated, instead of a fixed UTC time
2.1.268 - a 96-bullet fix pile, with third-party API endpoints working again (September 10, 2026)
- If you route through a third-party Anthropic-compatible endpoint (
ANTHROPIC_BASE_URL), every single turn had been failing outright with an HTTP 400 since 2.1.265 - a regex in the Artifact tool's input schema those endpoints reject. Fixed. - Two permission-check bypasses closed: deny and ask rules on symlinked system directories (
/etc,/tmp,/varon macOS;/binon Linux) stopped applying when a path was given by its real location, and a Read or Edit deny rule could be skipped just by puttingenv -C,eval, or another command the checker can't parse on the same line. - Plugin, marketplace, and MCP error messages could show a token, password, or a secret resolved from an
${VAR}placeholder in your MCP config. Both now get scrubbed before display. - A stale cached model-access entry could make a running session silently switch to your organization's default model when another Claude Code process refreshed it - fixed, along with entitled users wrongly being told a model was restricted after a restart.
- WebFetch could hang indefinitely on a server that keeps the response open without finishing; it now times out after 300 seconds (
CLAUDE_CODE_WEBFETCH_DEADLINE_MSto change that), and a busy loop that pinned a CPU core in long-running idle sessions is gone.
(The rest is the usual long tail: a gatewayInternalNetworks managed setting for locking down Claude apps gateway logins, --json added across claude plugin install/uninstall/update/enable/disable, browser-tab icons for published artifacts, a /compact bug that mangled text containing $ sequences, claude agents navigation and session-delete polish, a batch of VS Code fixes (the model pill blanking after login or logout, session names reverting after a window reload), and the usual round of Claude Tag and Code Review fixes.)
Verdict: update today if you're on a third-party Anthropic-compatible endpoint - that 400 regression has been breaking every turn since 2.1.265. Everyone else can update whenever; the permission-bypass and secret-leak fixes are good to have but narrow in practice.
2.1.267 - a half-dozen ways your prompt cache was quietly breaking, all closed at once (September 9, 2026)
- Switching models with
/model, resuming a-p(print-mode) session interactively, an MCP connector's tools changing between a session and its resume, a tool disappearing mid-conversation when its server disconnects, and a background worker adding a tool mid-session were all separately blowing away your cached prompt prefix. Every one of them is fixed now - if you switch models often or resume sessions a lot, this release alone should noticeably cut your rebuild costs. - New
maxEffortLevelsetting (top-level or per model) caps the effort level across every provider, including Bedrock, Vertex, and Foundry, while still letting people pick something lower. Useful if you're trying to keep a team's spend predictable without banning high-effort work outright. - A marketplace entry path containing a backslash could bypass the containment check for fetched marketplaces on macOS and Linux, letting a plugin reach outside its own directory. Fixed - worth knowing if you install plugins from third-party marketplaces.
- The VS Code extension host could hang at 100% CPU when forking, editing an earlier message, or rewinding a conversation whose saved transcript had a cyclic parent link. Fixed.
- Resuming a session with a transcript over 5 MB used to silently drop parallel tool calls and their hook output from the reloaded conversation - a real correctness bug for anyone with long-running sessions. Fixed.
(The rest is the usual long tail: expired AWS/Google Cloud credentials retrying ten times with a generic error before showing the real re-authenticate prompt, a spurious "Continue from where you left off" turn no longer inserted when resuming after /compact, several VS Code fixes - WSL2 screenshot pasting raw bytes instead of attaching the image, chat diffs always rendering dark instead of following your theme, CRLF files failing to accept edits, @-mentions dropping paths with spaces, the session list failing over Remote-SSH, runaway ripgrep processes - Claude Code on the web refreshing an expired GitHub Enterprise Server token automatically instead of showing "disconnected," and a batch of Claude Tag admin-settings fixes.)
Verdict: update today if you resume sessions often or switch models mid-conversation - the prompt-cache fixes are worth real money over time. Everyone else can update whenever; the marketplace bypass fix is good to have but only matters if you install third-party plugins.
2.1.265 and 2.1.266 - a 51-bullet fix pile, with subagent resume no longer breaking your prompt cache (September 8, 2026)
- Two separate bugs were quietly blowing away your prompt cache: resuming a subagent you'd spawned in the foreground reset its tool list and system prompt, and resumed subagents (plus agent teammates) lost their hook context and preloaded skills from the prompt prefix on later turns. Either one meant paying to rebuild the cache from scratch. Fixed.
- Windows: sessions running inside an AppContainer or a restricted-token sandbox had Read, Write, and Edit refuse every single file with a bogus "symlink resolution changed after permission was checked" error - effectively unusable in those sandboxes until now. Fixed.
- Non-interactive sessions (headless
-p, the Agent SDK, cloud sessions) used to forget yourcdat every new message, resetting the shell's working directory each turn. It persists across turns now, like an interactive session. - MCP servers configured as
httpthat only speak the older HTTP+SSE transport never connected at all. Claude Code falls back to SSE now, as the MCP spec requires. - Hours after shipping 2.1.265, 2.1.266 fixed a regression it had just introduced: setting the undocumented
CLAUDE_CODE_USE_GATEWAYenv var alongside a plain API key,apiKeyHelper, or custom auth headers made every request fail with "Not signed in to the Cloud gateway". Gone again - if you're on an LLM gateway or proxy setup and hit that error on the 8th, it's fixed.
(The rest is the usual long tail: a 1 GB cap on tool results saved to disk with a truncation notice, --plugin-dir now accepting a folder of plugins, two plugin-path security fixes on macOS and Linux, faster resume on sessions that read many files, and a batch of VS Code, Remote Control, and /plugin polish.)
Verdict: update today if you're on Windows in a restricted sandbox or you lean on subagents heavily enough that cache misses cost you real money - both were genuinely broken. Everyone else can update whenever; nothing else here is urgent.
2.1.261 - a 67-bullet fix pile, with resumed sessions no longer losing hook context (September 4, 2026)
- Resuming a session used to lose hook output and other context around parallel tool calls, quietly changing what got sent when you picked the conversation back up. Fixed - this was a real correctness bug if you resume often.
- New
/skill-doctorcommand shows which loaded skills you never actually use and how much context they're costing you, so you can prune the dead weight. bashOutputMaxCharsandtaskOutputMaxCharssettings raise how much command and background-task output Claude reads inline before it gets dumped to a file, up to 128K characters.- SDK and cloud sessions were ignoring a Stop or interrupt sent right after the first prompt, before the turn had actually started - it just ran to completion anyway. It stops now.
- A background agent that couldn't be resumed used to retry its wake-up in a tight loop and burn CPU. Fixed.
(The rest is the usual long tail: a --append-subagent-system-prompt-file flag for subagent prompts too large for the command line, an "Organization policy" line in /status/claude doctor explaining a failed policy load, the dangerous-rm safety prompt now also catching rm -rf on positional parameters and inside quoted sh -c scripts, several Remote Control fixes for stale permission modes and stuck stop spinners, Bedrock/Vertex/gateway auth polish, and a big batch of VS Code session-list and MCP-dialog polish.)
Verdict: update whenever - nothing here is urgent, but the hook-context fix on resume is worth having if you resume sessions a lot, and /skill-doctor is worth a run to see what your skills are actually costing you. (2.1.263, September 6, was a small bug-fix and reliability release with no user-visible specifics worth calling out.)
2.1.260 - permission rules with parentheses in the path finally behave (September 3, 2026)
- A permission rule pointing at a path with parentheses (think
Program Files (x86)) was being silently dropped or ignored by the Bash sandbox, which left folders you'd marked read-only actually writable. Fixed. - One bad file permission rule - an unclosed
[, say - used to break every single edit in the session with an "Invalid regular expression" error. Now a broken rule only guards its own literal path instead of taking everything else down with it. - zsh commands that hid a command substitution inside a
REPORTTIME,REPORTMEMORY, orDIRSTACKSIZEassignment were slipping past auto-approval. They now prompt like any other command. - The 2.1.259 change that made
Read()deny rules apply to Bash arguments has been reverted - it was blocking plainnpm run buildunder aRead(./**/build/**)rule and makingcd … && grepprompt even in auto mode. If you hit that on 2.1.259, it's gone now. - Also new: a
/diffpanel that sits beside the conversation in fullscreen mode and shows your uncommitted changes live as Claude edits, and/cost/the status line now explain why a prompt-cache miss happened instead of just flagging it.
(The rest is the usual long tail: Bedrock certificate and token-counting fixes for corporate root CAs, several Fable 5.1 model-picker and caching fixes, /rewind and background-session reliability patches, and a batch of VS Code and GitLab-repository polish.)
Verdict: update today if you write custom permission rules with parentheses in the path, use zsh, or got bitten by the npm run build regression in 2.1.259 - all three are real, and the last one is Claude Code fixing its own mistake from yesterday. Everyone else can update whenever.
2.1.259 - a 37-bullet fix pile, with concurrent sessions no longer scrambling your config (September 2, 2026)
- Running more than one session at a time could make them silently stomp on each other's
~/.claude.json- workspace trust resetting itself, MCP servers or project state just disappearing mid-work. Fixed. --resumecould fail outright, and--continuecould open an empty conversation, if the saved session held an attachment with no payload. Fixed.- Worktree-isolated sessions were refusing ordinary Bash loops, xargs pipelines, and launcher-wrapped commands just because they couldn't reach the main checkout. They work again.
- Stop wasn't actually stopping background agents and workflows in Remote Control sessions - a killed task now stays visible and re-stoppable until it's really gone.
- Frontmatter
model:on custom commands and skills was being ignored in interactive sessions. It's respected again.
(Also worth a glance if you manage MCP servers centrally: allowedMcpServers now only governs servers users add themselves - a managed-mcp.json server your allowlist used to filter out will load on upgrade unless you add it to deniedMcpServers.)
The rest is the usual long tail: a managedMcpServers setting for organizations to push MCP servers to everyone, --permission-prompts none for unattended headless hosts, GitLab merge requests now showing up in the tool summary and footer badge, two more permission-check bypasses closed (Bash Read() deny rules skipping option-value paths like --ignore-revs-file=.env, and managed settings going silently unenforced when unparseable - Claude Code now refuses to start instead), MCP servers that disconnect mid-startup no longer showing as connected with no tools, and a batch of VS Code, /workflows, and terminal-rendering polish.
Verdict: update today if you routinely run multiple sessions at once or lean on worktree isolation - both of those were real, reproducible papercuts. Everyone else can update whenever; nothing here is urgent.
2.1.257 - Fable 5.1 becomes the default, and auto mode gets a guardrail against credential theft (September 1, 2026)
- Claude Fable 5.1 (
claude-fable-5-1) is the new default Fable model: same pricing as before ($10/$50 per Mtok, $0.25/Mtok for cache reads) with a 1M-token context window. If you're on a third-party gateway,fableandbeststill resolve to Fable 5 until your gateway adds 5.1 support - pick it explicitly in/modelto use it now. - Auto mode gets a new Containment Escape rule: attempts to fetch cloud metadata credentials, evade network egress controls, or reach across tenants are no longer auto-approved unless your environment explicitly expects them. It's paired with a one-time prompt (and an optional hard block via
permissions.blockReadsOutsideWorkingDirectories) the first time auto mode tries to read a file outside your working directories. - A cluster of permission-check bypasses got closed: plugins could read files outside their own directory through a symlinked command, agent, skill, or hook path; Bash
Read()/Edit()deny rules didn't apply to< fileredirects or reader commands liketacandegrep; and--disallowedToolsplus session deny rules could silently vanish after the first settings reload underallowManagedPermissionRulesOnly. All fixed. - Subagents that got cut off mid-response by a dropped connection, a server error, or your computer sleeping now pick back up automatically instead of ending with a broken answer - worth having if you lean on subagents for long-running work.
- New
timeFormat/timeZonesettings control how the turn-end clock and transcript timestamps render (12-hour, 24-hour, 24-hour UTC, or a strftime pattern), andCLAUDE_CODE_SUBAGENT_MODEL_FORCElets you pin every subagent to one model regardless of per-agent overrides.
(2.1.258, also September 1, was two more fixes: Claude Code had stopped launching at all on macOS 12 Monterey, a regression from 2.1.255, and remote or scheduled sessions could crash with "user messages must have non-empty content" after a re-sent permission approval failed to apply. Both fixed.)
The rest is the usual long tail: rendering and prompt-input performance work in long conversations, a /doctor warning for stale sandbox mask files, several Bedrock/Vertex/Foundry credential-header fixes, and a batch of claude agents, Remote Control, and VS Code polish (a model picker pill, collapsible session-list sections, "Archive session" replacing "Delete session").
Verdict: update today. Fable users get a materially better default model for free, and the Containment Escape rule plus the permission-bypass fixes matter if you run Claude Code with plugins, in less-trusted environments, or under an org's managed permission rules.
2.1.252 - a small pile of reliability fixes, nothing urgent (August 31, 2026)
- Bash commands on some Macs were failing outright with a "task output swap refused" error whenever the tasks directory had moved or turned into a symlink. Fixed.
- Clicking "always allow" on a permission prompt silently failed to save in a project that didn't already have a
.claude/settings.local.jsonfile - you'd get asked again next time. Fixed. - Remote Control sessions hosted by Claude Desktop or VS Code could stall for minutes after a tool finished if the connection to claude.ai was degraded, instead of just reporting the result. Fixed.
- A background task that failed with a lot of output (git errors on a full disk, for example) could push the conversation past the API's request size limit and break the turn. Fixed.
Verdict: update whenever. Four narrow bug fixes, none of them a must-have unless you've personally hit one of these.
2.1.251 - five permission-check bypasses get closed in one release (August 28, 2026)
- Five different ways to slip past a permission check got fixed at once: Read, Write, and Edit could be tricked into working outside the approved directory by swapping in a symlink after the check passed; Grep and Glob ignored
Read()deny rules on paths reached through a symlink; a plugin marketplace entry could point its commands outside the plugin directory; the Workflow tool could read ascriptPathoutside what the session was allowed to read; and project settings could quietly turn on raw API body logging or dodge an org-pinned OTLP collector. - New
PreModelSwitchandPostModelSwitchhook events let you block, confirm, or log a mid-session model change before or after it happens. CLAUDE_CODE_SUBAGENT_MODELnow sets the default subagent model instead of overriding everything - an agent's ownmodel:or an explicit per-spawn model wins over it./effortalso now remembers its setting per model instead of one global level for all of them.- Fixed conversations getting permanently stuck on a "text content blocks must be non-empty" error after a turn where the model produced only thinking.
- Fixed Opus 5 requests failing outright when effort was set to xhigh or max with thinking turned off; effort now quietly downgrades to high instead of erroring.
The rest is the usual long tail: live streaming of a foreground subagent's tool calls to Remote Control, a spend-limit bar in /usage for gateway users, a per-session prompt-cache breakdown in /cost, Opus 5 becoming the default for seat-based Enterprise plans, a smaller install (native binary down about 5 MB, plus another 2.5 MB from dropping six rarely used syntax-highlighting languages), and dozens of smaller reliability fixes across background sessions, Remote Control, and the sandbox.
Verdict: update today - the permission-check bypasses matter regardless of how likely you are to hit one, especially if you work with symlinks, install third-party plugins, or run under an org's beta-tracing policy. Everyone else still gets the stuck-conversation fix and the per-model effort setting, which are worth having either way.
2.1.248 and 2.1.250 - a --restricted mode arrives, and uncommitted secrets stop leaking to cloud sessions (August 27, 2026)
- New
--restrictedflag (orCLAUDE_CODE_RESTRICTED=1): strips out the tools that run commands or code andWebFetch, keeps file access inside the working directory, refusesbypassPermissions, and ignores your settings files. A real lockdown mode for running Claude Code somewhere you don't fully trust. /ultrareviewand locally-seeded cloud sessions were uploading uncommitted edits to files likeprod.env,*.tfvars, and editor backups of key files (key.pem.tmp,id_rsa.swo). Fixed - those now stay on your machine.- A prompt-cache miss, with the extended-thinking context that goes with it, was quietly happening about once an hour in long sessions, triggered by an OAuth token refresh re-rendering your tool definitions. Fixed.
- Claude Desktop and Cowork sessions were disappearing after 30 days because cleanup didn't know they were still open in the app. Fixed; a new
desktopSessionCleanupPeriodDayssetting caps how long the exemption lasts. - Cross-session messaging (
SendMessage,ListAgents) now works on Bedrock, Vertex, and Foundry, and with telemetry disabled - closing the same gap 2.1.243 fixed for rootless containers.
(2.1.250, later the same day, was a single line: "Bug fixes and reliability improvements," with nothing to report.)
Verdict: update today if you've ever run Claude Code in a repo with secrets sitting in an untracked .env or backup file, or if you lean on cloud sessions or long-running sessions - the leak fix and the hourly cache miss both matter. Everyone else can update whenever; --restricted is worth knowing about if you ever run Claude Code somewhere you don't fully trust.
2.1.247 - SendFeedback lands, and sessions stop wedging on giant hook output (August 26, 2026)
- New
SendFeedbacktool: when something goes wrong mid-session, Claude can draft a feedback report for you to review and send from/feedback(turn it off with thefeedbackDraftssetting). - A hook or background agent that dumped megabytes of error output could overflow the conversation and wedge the whole session on "Prompt is too long." Fixed.
- Sub-agents that hit a 404 on their first model call used to just die. They now fall back through the session's model chain instead, and the error handed back to the parent includes the type, status, and request id so you can actually debug it.
- Fast arrow-key-then-Enter sequences in history search,
/config,/mcp,/skills, background tasks, and/modelwere acting on the row above the one you'd actually navigated to - the same class of bug 2.1.235 fixed in permission dialogs, just showing up in more menus. - Cloud sessions (web, desktop, mobile) used to go silent if the container restarted mid-turn while a background agent or shell was still running. A resumed session now tells you work was lost instead of leaving you guessing.
Verdict: update today if you lean on hooks or background agents - the giant-output wedge and the sub-agent 404 fallback both matter there - or use cloud sessions from web, desktop, or mobile. Everyone else can update whenever; SendFeedback is a nice touch, but nothing here is urgent.
2.1.246 - a 61-bullet fix pile, with a gateway credential leak closed (August 25, 2026)
- Telemetry and metrics requests could carry the API key configured for a third-party gateway (
ANTHROPIC_BASE_URL) along to Anthropic's own endpoints. Fixed - a credential now only goes to the host it belongs to. - Malformed Bash commands with a dangling
&&or||now always require your approval instead of possibly slipping through the permission check. - Fullscreen mode gets several stability fixes: it could go blank after resizing the terminal, scroll erratically when you weren't at the bottom, and slow to a crawl on a diff with one very long line (like a base64 string) - long lines now render truncated instead.
- Background sessions get two real fixes: they no longer fail to open after 45 seconds when the starting directory was deleted or the machine had slept, and no longer fail with
EACCESwhen another Claude Code process happened to be reinstalling the npm package at the same moment. - The Write tool no longer freezes or reports "Out of memory" after overwriting a large existing file - the write had actually gone through, you just couldn't tell.
(2.1.245, the same day, was a single fix: a startup crash on Linux distributions shipping glibc 2.44, like Arch, CachyOS, and Fedora Rawhide.)
The rest is the usual long tail: a new Auto mode tab in /permissions for viewing and editing classifier rules, a startup warning for Bash allow rules with a wildcard before the subcommand, resumed sessions no longer failing every turn with a 400 on history a third-party proxy wrote badly, memory that no longer grows with session length in the fullscreen and Ctrl+O transcript views, and a batch of plugin, keybinding, and MCP fixes.
Verdict: update today if you route through a third-party gateway - that credential leak is worth closing regardless of how likely it was to matter for you. Everyone else can update whenever; it's a big pile of small reliability wins, not a must-have.
2.1.243 - installs shrink to a quarter of their size, and namespaced containers get SendMessage back (August 24, 2026)
- Native installs and auto-updates now ship zstd-compressed - about 75 MB instead of 340 MB on Linux x64 - and long sessions use noticeably less memory since code loads on demand instead of staying resident.
- Cross-session messaging (
SendMessage,ListAgents) had been silently broken inside user namespaces and rootless containers since 2.1.232's socket hardening. Fixed - it works there again. - Sessions that got no response at all from the API used to sit silently for 10+ minutes. They now time out after about 3 minutes, retry once, and surface a clear
API Error: No response from APIinstead of leaving you guessing. - New
modelPickersetting curates the/modellist with your own ordered, labeled models (any id, including Vertex/Bedrock); newpromptCacheTtl/subagentPromptCacheTtlsettings let API-key and cloud-provider users keep the main conversation on a full 1-hour prompt cache while subagents stay on the cheaper 5-minute one. - Hook
ifconditions likeBash(cat *)could misfire on unrelated commands whenever the command contained$()or backtick substitution followed by more arguments. Fixed.
The rest is the usual long tail: a modelPricing managed setting for organizations with contracted per-model rates, a keyless "sign in with your Console account" option under /login, a Skipped sources line in /status for overridden managed settings, model and effort level now shown per subagent in /tasks, /usage gets a Loops breakdown, sandbox network-violation details no longer get dropped from Bash results that still exit 0, and a batch of MCP, plugin, and VSCode fixes.
Verdict: update today if you run Claude Code inside rootless containers or user namespaces - that SendMessage regression is worth closing. Everyone else can update whenever; the smaller install and lower memory use are nice, but nothing here is urgent.
2.1.240 and 2.1.241 - nothing to see here (August 22, 2026)
Both releases shipped as a single line each: "Bug fixes and reliability improvements," with no bullets underneath. Nothing user-visible to report.
Verdict: update whenever - there's no reason to rush this one.
2.1.239 - a 59-bullet fix pile, with a Bedrock billing bug closed (August 21, 2026)
- Bedrock users behind a proxy that strips the response
Content-Typeheader were being silently double-billed: streaming quietly fell back to non-streaming and reran every turn from scratch. Fixed. - A race with queued prompts: pressing Esc while a prompt was queued could let the next turn finish early and leave the session sitting idle while Claude was actually still working, and resubmitting the queued prompt afterward could repeat actions Claude had already taken. Fixed.
- Fullscreen mode gets a cluster of fixes: mouse movement no longer inserts stray text like
"35;150;7M"into the prompt, clicking the terminal just to refocus it no longer answers a permission prompt or presses a button, and panels like/configand/workflowsno longer cover the latest messages or overflow off-screen. - WebFetch was holding expired page content in memory for the whole session instead of releasing it after the intended 15 minutes. Fixed.
- Windows catches up to macOS and Linux: cross-session messaging now works, so Claude Code sessions on your machines can message each other with
SendMessageand find each other withListAgents.
The rest is the usual long tail: a hang at startup behind an HTTPS proxy on Bedrock with SSO, remote MCP servers staying marked failed after a transient 5xx, custom session titles disappearing from /resume on long conversations, claude -c picking up the wrong session when directory names differed only by punctuation, a JetBrains pause on Edit/Write calls, /goal check-ins that now back off over time instead of repeating every 30 minutes, and a batch of keybinding and clipboard fixes.
Verdict: update today if you run Bedrock behind a proxy - that billing bug was real money. Everyone else can update whenever; nothing here changes your day-to-day beyond fewer rough edges in fullscreen mode.
2.1.238 - a memory leak fix, and a Remote Control reliability pass (August 20, 2026)
- Long interactive sessions could grow memory without bound as subagent tool results piled up. Fixed - results are now released once they scroll out of the recent display window.
- Custom, project, and plugin output styles used to drift back to Claude's default voice partway through a session. Fixed - your chosen style now sticks.
- MCP
headersHelper(which runs a command to mint auth headers) on a project's.mcp.jsonor an inline agent-file server now requires that folder's trust dialog to have been accepted first, instead of running unprompted. - Remote Control gets a real reliability pass: messages sent from web or Desktop mid-turn no longer vanish from the transcript, model picks made on a phone sync back to the terminal, sign-out no longer reports a fake failed-reconnect error, and
ListAgents/SendMessagefinally work from server-mode and Desktop/IDE-hosted sessions instead of claiming Remote Control isn't connected. - New
keybindingFlavor: "readline"setting makes Ctrl+W in the prompt delete back to the previous whitespace, Bash-style, instead of the whole word.
The rest is the usual long tail: two new self-hosted-runner flags for graceful shutdown and proxy re-authentication, a fix for self-hosted runners getting evicted after one slow poll, MCP elicitation dialogs going blank on very long URLs, leftover /tmp/claude-*-cwd files after a killed Bash command, held Backspace being dropped on slow SSH links, wide-character clipping in permission-prompt diffs, a bracketed-paste glitch after killing a suspended session, faster macOS startup, and a claude-api skill update for the Aug 19 Managed Agents release.
Verdict: update today if you run long sessions (the memory leak was real) or lean on Remote Control from a phone or web browser - both get meaningfully better here. The MCP headersHelper trust requirement is worth knowing if you use plugin marketplaces with one. Everyone else can update whenever.
2.1.237 - a Concise output style, and a caching fix for gateway users (August 19, 2026)
- New "Concise" output style: Claude leads with results and skips the preamble and narration, doing the same work with less chatter around it. Turn it on under Output style in
/config. - Fixed prompt caching breaking for sessions that go through an LLM gateway or a custom base URL - caching now works there again.
Verdict: try Concise if Claude's running commentary gets in your way. Everyone routing through a gateway or a custom base URL should update to get caching back; otherwise update whenever.
2.1.236 - a default-model env var, and a directory-deletion bug closed (August 19, 2026)
- New
ANTHROPIC_DEFAULT_MODELenvironment variable sets which model new sessions start on. Unlike the olderANTHROPIC_MODEL, a/modelpick still overrides it and sticks across restarts. - If you'd
cd'd into a directory during a session and then deleted it, clipboard copy, background housekeeping, background sessions, and local MCP logs could all quietly stop working. Fixed - this had been broken since 2.1.229. - macOS sandbox: wildcard read-deny rules like
**/.envnow actually hold inside allowed read regions, cover everything inside a matched directory, and can't be dodged by renaming the file they're supposed to block. - Cross-session
SendMessagegetsnotify_when_idle: ask another local Claude Code session to ping you once, the next time it goes idle, instead of polling it yourself. - [VSCode] Screen reader support lands for the transcript - live announcements for replies, permission requests, and errors, plus per-turn heading navigation.
The rest is the usual long tail: the fullscreen renderer no longer breaks permanently after one failed start, the /model picker no longer overflows a short terminal, a SendMessage bug with malformed closing tags, a subprocess-crash regression from 2.1.234, several auto mode refinements (Monitor commands now reviewed like Bash, parity on Bedrock/Vertex/Foundry, a git-status spoofing fix), a /usage credits row for Team and Enterprise, faster Remote Control offline detection, and a batch of terminal-rendering and UI polish.
Verdict: update today if you use directories you delete mid-session (that bug touched more than it looked like) or rely on macOS sandbox read-deny rules. The ANTHROPIC_DEFAULT_MODEL env var and VSCode screen reader support are worth knowing about either way; everyone else can update whenever.
2.1.235 - two permission-prompt bugs could grant or pick the wrong thing (August 18, 2026)
- A stray Shift+Tab inside the permission prompt's comment field was approving the edit and granting session-wide edit permission instead of just closing the field. Fixed - that keystroke now does what it looks like it does.
- Dialogs in general had a similar problem: navigating with arrow keys and hitting Enter in quick succession could select the option you'd just moved to instead of whatever was highlighted a moment before. Matters most in a permission prompt, where the wrong selection means the wrong grant.
- Permission dialogs are also more honest now - what they display and offer as "don't ask again" always matches what the grant would actually cover, and "don't ask again" is withheld whenever the dialog can't show everything it applies to.
- Background cloud sessions like
/ultrareviewor/autofix-pruse noticeably less memory and CPU: their event streams stopped being re-scanned and re-rendered on every single update. - New: an opt-in
spellchecksetting underlines misspelled words in the prompt input as you type, using whateveraspell,hunspell, orispellyou already have installed.
Verdict: update today if you spend real time answering permission prompts - the Shift+Tab and dialog-selection bugs could both hand out a grant you didn't mean to give. Everyone else can update whenever; nothing else here is urgent.
2.1.234 - sessions auto-continue after usage limits reset, and permission answers stop vanishing (August 17, 2026)
- Claude Code now auto-continues your session as soon as a claude.ai usage limit resets, instead of leaving you stalled until you notice and nudge it yourself. Turn it off in
/config("Continue automatically at usage limit") if you'd rather it just stop. - Fixed auto mode in very long, already-compacted sessions repeatedly re-checking and denying sandboxed commands' network access - it kept forgetting approvals it had already granted earlier in the conversation.
- Fixed session-scoped permission answers, including denies, getting silently dropped when you answered a background subagent's tool permission prompt. Your answer wasn't actually being remembered.
- The built-in
claude-apiskill used to cost roughly 200k+ tokens of context just to load. It now loads reference docs on demand and costs about 25k - a real difference in sessions that touch the Claude API. - Security: Windows NT-namespace paths (the
\??\device prefix) are now blocked everywhere a file gets pre-approved - remote file reads, session restore, CLAUDE.md includes, workflow scripts, uploads - closing the rest of the credential-leak vector 2.1.233 started patching.
Verdict: update today if you're on Windows (this finishes the NT-namespace fix from 2.1.233) or you run long auto-mode sessions that got stuck re-approving network access. Everyone else can update whenever - the usage-limit auto-continue and the much cheaper claude-api skill are welcome, but nothing here is urgent.
2.1.233 - TodoWrite quietly disappears on newer models, and Windows closes a credential-leak bypass (August 14, 2026)
- Security: a Windows path spelled with the NT
\??\device prefix could slip past UNC path validation, opening an NTLM credential-leak vector. Closed - no action needed beyond updating. - TodoWrite and the task-tracking tools (TaskCreate/Get/Update/List) are now off by default on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models. If your workflow depends on visible todo lists, set
CLAUDE_CODE_ENABLE_TODO_TOOLS=1to get them back. - Two Windows regressions from yesterday's 2.1.232 are fixed: auto mode no longer stops for manual approval on ordinary
cd dir && command > fileBash commands, and the Cygwin-symlink and input-redirection permission changes from that release are reverted until a narrower fix ships. - Cloud sessions were sometimes marked as lost if the environment shut down while Claude was waiting on a permission prompt. Fixed.
- MCP v2 connections could get stuck endlessly reopening the subscriptions stream against servers that close long-held connections on a fixed timeout - common on serverless hosts. Fixed.
Verdict: update today if you're on Windows - the credential-leak fix and the two 2.1.232 regressions all land here. Also check your workflow if you're on Sonnet 5, Opus 4.8, Fable 5, or Mythos 5 and rely on TodoWrite: it's now opt-in. Everyone else can update whenever.
2.1.232 - three more permission bypasses close, and sessions get easier to talk to (August 13, 2026)
- Security: three separate holes close at once - a PowerShell trick that could silently overwrite
$PSDefaultParameterValuesto redirect where later commands write, a Windows Git Bash bug where Cygwin-style symlinks slipped past the permission check, and nested git repositories that were silently inheriting trust from a parent folder instead of asking for their own. None of these needed you to do anything wrong to be exposed. - Cross-session messaging gets easier to actually use: type
@in your prompt to mention another named Claude session and Claude reaches it withSendMessagedirectly, delivery to a name that matches one live session no longer stops to ask you to confirm first, and two sessions on the same machine can no longer collide on the same name. - GitLab is now a first-class citizen alongside GitHub: secret redaction covers the full family of GitLab token types, the
glabCLI gets the same sandbox and credential protectionsghalready had, and plugin marketplaces can point at agitlab.comrepo URL the same way they point at a GitHub one. - Fixed: MCP connections used to hang for the full 30 seconds when a server failed to answer or sent back a malformed reply during setup. They now fail fast instead of stalling your session.
- Remote Control got a real reliability pass: sessions no longer show up as a duplicate claude.ai conversation every time you resume from Desktop or an IDE, bridge sessions restore their history after a worker restart instead of losing it, and reconnecting no longer silently yanks Remote Control away from another device that was using it.
(2.1.231, also August 13, was a single fix: MCP OAuth sign-in was failing with a redirect URI mismatch for servers that use a pre-registered OAuth client, like Slack.)
Verdict: update today if you use PowerShell, Git Bash on Windows, or work across nested git repositories - all three permission bypasses are closed here. Everyone else can update whenever; the session-naming, GitLab, and Remote Control fixes are welcome but nothing here is urgent for a single-session GitHub user.
2.1.229 - two more ways to crash on resume close, and VSCode gets session groups (August 12, 2026)
- Resuming a session could throw you straight to the error screen two different ways: if any turn in its history had a tool call with a bad (non-string) file path, glob, or command value, or if your terminal window was narrow enough to trigger a rendering crash in a progress bar or markdown table. Both are fixed, so
--resumeand--continueare safe to rely on again. - Long streamed responses could visibly glitch - part of the text disappearing mid-print, then the whole response printing twice. Fixed.
- The GitHub Action that
/install-github-appsets up could finish reviewing a pull request without ever posting the review, so it looked like nothing had run. Fixed. - VSCode gets session groups in the sidebar: right-click to create, rename, or delete one, and Cmd/Ctrl- or Shift-click to move several sessions into it at once.
Verdict: update today if --resume or --continue has crashed on you lately - both crash paths are closed here. Everyone else can update whenever; the streaming glitch and the silent PR-review miss are minor annoyances, not blockers.
2.1.228 - session cleanup stops eating your memory files (August 11, 2026)
- A session-cleanup bug could delete the contents of your project's memory folder outright. Fixed - if files there have gone missing lately, this was why.
- Interactive sessions could freeze completely - no redraws, but the process kept running underneath - after a rare internal layout error. You had to kill and restart to get input back; that dead end is closed.
- Skills synced in from claude.ai are hardened: they can no longer shadow your local commands or MCP prompts, their descriptions are sanitized before display, and their bodies can no longer run
!shell commands or expand@-file references on your machine. - Remote Control's
/resumewhile connected could leak the resumed conversation's title or history into the session you were already connected to. Fixed. - The Write tool now lets newer models overwrite a file they haven't read yet this session, matching what the Edit tool already allowed - a small safety-rule loosening if you were relying on the stricter behavior. Older models still need the read first.
Verdict: update today if you use claude.ai-synced skills or Remote Control - both had real trust gaps closed here. Everyone else should still update soon: the memory-folder deletion and frozen-session bugs are the kind that cost you work before you notice.
2.1.227 - claude-code-action's Bash commands work again (August 10, 2026)
claude-code-actionon GitHub-hosted runners: every Bash command was failing outright whenallowed_non_write_userswas set. Fixed - if your CI workflow uses that option, this was breaking every run.- A session that started with an expired login token could evaluate your feature flags without checking your subscription tier, which was wrongly telling Max plan users to enable usage credits for Fable. Fixed.
/tuiused to resurrect a conversation after you had rewound it past its first message. It stays gone now.- Slash-command menu cleanup: blue now marks only the selected row instead of bleeding onto others, matched characters are bolded instead of recolored, and emoji or accented command names keep their glyphs.
- Fewer event-loop stalls on file-not-found suggestions and at-mention size checks - snappier autocomplete while typing.
Verdict: update today if you run claude-code-action with allowed_non_write_users on GitHub-hosted runners - that combination was completely broken. Everyone else can update whenever; the rest is minor polish.
2.1.225 - claude agents finally asks before trusting a new folder (August 7, 2026)
claude agentsnow shows the same workspace-trust prompt asclaudebefore running in an unfamiliar directory - launching an agent used to skip that check entirely.- A stored login's short-lived token could silently replace a long-lived
CLAUDE_CODE_OAUTH_TOKEN, breaking headless sessions with a transient 401 until you restarted. Fixed. - MCP OAuth servers on macOS could fail with a burst of 401s, looking like you'd never authenticated, whenever a keychain read timed out. Fixed.
- Gateway operators can now set a spend limit that Claude Code's usage warning actually names, along with the reset time and the operator's own message, once you hit it.
SendMessagecan now start a conversation with your Remote Control sessions on other machines by name, instead of only replying after they message you first.
(2.1.226, the next day, was bug fixes and reliability improvements only.)
The rest is the usual long tail: cross-session messages no longer sit parked without a notice or expiry in headless sessions, conversation history no longer breaks on Remote Control resume after a very large conversation gets compacted, hovering over another project's session in the agents list no longer changes where your next agent starts, claude self-hosted-runner now exits at startup with a clear error instead of registering and failing every session when its base directory can't be created, and a batch of VSCode Focus view and Remote Control polish.
Verdict: update whenever - nothing here forces your hand, but the workspace-trust prompt for claude agents and the headless-session 401 fix are worth having if you run agents against directories you don't fully trust, or run headless at all.
2.1.224 - self-hosted runners land, and sessions can finally talk to each other (August 7, 2026)
- Self-hosted environments:
claude self-hosted-runnerlets Team and Enterprise plans point web, mobile, and desktop sessions at their own machines or containers instead of Anthropic's hosted infrastructure. - Claude Code sessions can now message each other across your machines -
SendMessageto send,ListAgentsto find them (macOS and Linux). If the target session is running with bypassed permissions, its inbound messages now sit in an approval queue instead of running immediately (newcrossSessionInboundanddialogExpirysettings). - Two silent isolation bugs are fixed: a sandbox deny rule written with a trailing slash (like
denyRead: "~/.aws/") was being ignored on Linux and macOS, and long (200+ character) project paths could collide under a shared sanitized prefix - pointing one project's session list, rename, fork, or/resumeat a different project's sessions. SendMessageused to report "Message sent" even when the write to a teammate's inbox had actually failed; failed deliveries now show as errors. Claude also finally sees why a sandboxed command was denied, instead of just that it was.- The 200-subagent-per-session spawn cap is gone - long-running sessions no longer refuse new agents (the real concurrency and depth limits still apply).
Verdict: update today if you run sandboxed or worktree-isolated sessions - the trailing-slash and long-path bugs were both silently defeating isolation you thought you had. Everyone else can update whenever; self-hosted runners only matter if you're on a Team or Enterprise plan and want Claude Code sessions running on your own infrastructure.
2.1.223 - three permission bypasses close, and /review merges back into /code-review (August 5, 2026)
- Security: a crafted command, or one padded with tabs or invisible Unicode, could hide part of itself from Bash's permission check - so the command you approved was not always the command that ran. Both tricks are closed.
- Security: workflow scripts could use dynamic
import()to run code outside the workflow sandbox. Closed. - Security: an agent definition's
bypassPermissionsmode could override your org's policy disabling bypass permissions entirely. Closed. /reviewis an alias of/code-reviewagain - the fast single-pass mode 2.1.202 split it into is gone./code-review <level> <pr#>reviews a PR directly and now remembers the effort level you last typed instead of resetting every time.
The rest is the usual long tail: a /teleport hint now shows up in cloud sessions for continuing locally, CLAUDE_CODE_DISABLE_1M_CONTEXT auto-compacts every native 1M-context model down to 200K instead of a fixed list, managed settings from your org no longer stomp a machine-local env block, and a batch of gateway model-ID, sandbox, and session-resume fixes.
Verdict: update today. Three separate ways to fool your own permission prompts closing in one release is worth being current for, whether or not you have noticed any of them. If you liked the fast /review, note it is /code-review doing all the work again now.
2.1.222 - two more worktree escapes close, and ultraplan disappears (August 4, 2026)
- Security: worktree-isolated sessions and their subagents could still run destructive git commands against your real checkout - isolation now covers file edits and Bash in every session type, not just some.
- Security: a background agent task (summaries, compaction, renames) could bypass its own tool restrictions through a PreToolUse auto-allow hook. Closed.
- Security: a repo's checked-in
.claude/settings.jsoncould quietly turn Remote Control on for you. It can still turn it off, but turning it on now needs your own user-scope/config. - "Connection closed mid-response" errors that were actually finished responses, and a startup connectivity check that hung behind an HTTPS proxy instead of timing out cleanly - both fixed, so a red error banner now means something actually failed.
- Removed: the ultraplan feature is gone.
The rest is the usual long tail: /usage was overattributing cost to MCP servers for turns that never touched their tool results, sessions weren't always linking to pull requests created after the branch was pushed, claude.ai connectors got falsely flagged as needing re-authorization, /diff and file-edit diffs now use raw git blob content instead of your configured diff driver, and a batch of screen-reader, enterprise model-alias, and custom-gateway fixes.
Verdict: another release where the security fixes matter more than the bullet count suggests. Update today if you run worktree-isolated subagents, background agents, or Remote Control - otherwise whenever. If you were using ultraplan, it's gone as of this update.
2.1.221 - a zsh permission bypass closes, and VSCode gets a Focus view (August 3, 2026)
- Security: zsh could run hidden commands inside
[[ ]]regex conditionals without ever hitting Bash's permission check. Those commands now prompt for approval like everything else. - VSCode gets a Focus view (
Ctrl+Alt+F): it collapses tool activity into an expandable per-turn summary with a live "still working" indicator, so a busy tool run doesn't bury the actual conversation. - Linux and WSL sandboxes can now mask credential files instead of blocking them outright: sandboxed commands see a stand-in value while the sandbox proxy swaps in the real one only as the request leaves. macOS still just blocks access to those files.
- Background sessions now act more like a teammate: they commit and push to save their work, open a draft PR only if the task actually calls for one, follow your CLAUDE.md's git conventions, and always tell you where the work ended up.
- MCP servers passed via
--mcp-configused to connect too late in print mode (-p), so the model's first tool calls came out as plain text instead of running. Fixed.
The rest is the usual long tail: PowerShell paths with quote characters on Windows now prompt for approval instead of skipping the check, /fork sessions get their own worktree instead of sharing the original's, fast mode now tells you on the stream when credits run out instead of failing silently, Vim mode's yank register and undo confirmation stop resetting themselves mid-session, and a batch of Stats panel, Windows startup, and Bedrock/SSO fixes.
Verdict: update today if you use zsh - the permission bypass is a real hole, however narrow. Everyone else can update whenever; the Focus view and credential masking are welcome but nothing here forces your hand.
2.1.219 - Opus 5 becomes the default Opus model (July 24, 2026)
- Claude Opus 5 (
claude-opus-5) is now the default Opus model, with a 1M-token context window and fast-mode pricing at $10/$50 per million tokens. - New
sandbox.network.strictAllowlistsetting denies non-allowlisted hosts outright for sandboxed commands, instead of stopping to ask every time. - Subagents can spawn nested subagents up to depth 3 by default again - 2.1.217 had capped this at 1 (no nesting). Set
CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=1if you were relying on that tighter limit. - Dynamic workflows now default to a "medium" size guideline (aim for fewer than 15 agents) instead of running unrestricted; change it in
/configif you want more. claude -pno longer throws away the answer it already produced when a turn dies mid-stream on an API error.
(2.1.220, same day, was bug fixes and reliability improvements only.)
Verdict: update today if you use Opus at all - the price and context window are a real upgrade. If you were counting on 2.1.217's subagent-depth cap, check your env var before you update; nesting is back on by default.
2.1.218 - /code-review moves to the background, plus a hook-trust hole closed (July 22, 2026)
/code-reviewnow runs as a background subagent, so review output no longer fills up your conversation while it works.- Security: agent frontmatter hooks could run from a folder you'd never actually granted workspace trust to. Hooks now require the agent file's own folder to have been trusted first.
- The left arrow key used to discard your whole conversation with no way to undo it. A press right after an edit now asks you to confirm, and Esc in the agent view returns you to the conversation it backgrounded instead of losing it.
- Windows paths with a
\u-prefixed segment (likeC:\Users\unicorn) were getting corrupted into CJK characters in tool inputs, which made those files inaccessible. Fixed. - Skills marked
context: forknow run in the background by default - opt a specific skill out withbackground: falseif you want it to block like before.
The rest is the usual long tail: Bedrock application-inference-profile spend now meters at the right model's rate instead of overcharging, pull request events no longer get lost when a session exits right after creating one, a retry loop that kept re-sending doomed requests after a context-overflow error is fixed, a resumed session no longer fails every turn or crashes on a malformed transcript, fork-session lineage now survives compaction, and a batch of screen-reader, Bedrock setup-wizard, and prompt-history fixes.
Verdict: update today if you use agent frontmatter hooks at all - the untrusted-folder fix closes a real trust gap. Everyone else can update whenever, though the left-arrow and Windows path fixes are reason enough on their own.
2.1.217 - runaway subagents get reined in (July 21, 2026)
- Subagent spawning gets three guardrails at once: a default cap of 20 concurrently-running subagents (
CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTSto raise it), subagents no longer spawn their own nested subagents by default (CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTHto allow deeper nesting), and--max-budget-usdnow actually halts running background agents once the cap hits instead of just blocking new spawns. Together these stop one message from fanning out into an unbounded, unbudgeted swarm. - Security: background session isolation wasn't canonicalizing symlinked working directories, so an isolated session could escape its workspace folder. Fixed.
- A real memory leak is fixed: truncated MCP tool outputs used to keep the full untruncated result in memory for the rest of the session - long sessions with big tool outputs get that headroom back.
- Corporate mTLS, TLS-verify, OAuth scope, and proxy settings being silently ignored in Claude Desktop sessions is fixed - if your org's network policies weren't applying there, this was why.
- A
CLAUDE.mdorSKILL.mdfrontmatter value with many brace groups could OOM-kill or stall the CLI before it even started. Brace expansion is now budget-bounded.
The rest is the usual long tail: emoji shortcode autocomplete in the prompt input, warnings instead of silent data loss when transcript writes fail, a Windows auto-update fix that could leave claude.exe missing, an Opus-4.8-on-Bedrock auto-compact fix, screen reader and Remote Control polish, an OTEL endpoint override bug, and a --resume crash on malformed transcripts.
Verdict: update today if you run subagents or background agents at any real scale - the concurrency, depth, and budget caps are the kind of thing you want in place before you hit the problem, not after. Everyone else can update whenever.
2.1.216 - a 40-bullet fix pile, with two more worktree escapes closed (July 20, 2026)
- Security: worktree-isolated subagents could still redirect git commands into your real checkout using
git -C,--git-dir, or theGIT_DIR/GIT_WORK_TREEenvironment variables. Closed - the isolation guarantee no longer has this hole. - Security: a symlink placed at
.claudecould redirect workflow saves and scheduled-task writes outside your project folder. Fixed. - Long sessions get noticeably faster: message normalization cost was growing quadratically with turn count, which is why long sessions and resumes could stall for several seconds. Now fixed.
- Resuming a background agent session used to revert it to the default agent, silently dropping its custom prompt and tool restrictions. The agent's actual configuration is now restored on resume.
- Cloud sessions no longer lose your in-flight message if the container restarts mid-turn - the interrupted turn re-runs on resume instead of leaving the session stuck.
The rest is the usual long tail: auto mode no longer denies commands over a stale "HTTP 401" after your OAuth token rotates mid-session, worktree sessions landing in another project's leftover worktree, background sessions with no git repo being undeletable, a stale daemon lockfile that could let claude daemon stop --any kill an unrelated process, AskUserQuestion no longer nudging Claude to continue when your free-text answer asked it to wait, and a batch of Bash-parsing, PowerShell, fullscreen-UI, and Claude-in-Chrome fixes.
Verdict: two more worktree/symlink isolation gaps closed alongside a real background-agent bug. Update today if you run worktree-isolated subagents, background agents, or cloud sessions - otherwise whenever.
2.1.215 - /verify and /code-review stop running themselves (July 19, 2026)
- Claude used to invoke the
/verifyand/code-reviewskills automatically once it finished a change. It no longer does - you now run/verifyor/code-reviewyourself when you want them.
Verdict: a default change, not a bug fix. If you were counting on Claude auto-reviewing its own work, add /verify or /code-review back into your routine - otherwise there is nothing to do here.
2.1.214 - the Bash permission checker gets six holes patched at once (July 18, 2026)
- Security: an allow rule like
Edit(src/**)was meant to cover only thesrc/folder in your working directory, but it was matching asrc/folder anywhere in the repo tree - so a rule you scoped to one place could quietly approve writes somewhere else entirely. Fixed, along with a cluster of adjacent gaps: a Windows PowerShell 5.1 bypass, commands over 10,000 characters skipping the prompt, zsh comparisons and file-descriptor redirects the checker was misreading as harmless, and somehelp/maninvocations that could run unsafe options without asking. - Security: permission prompts on remote sessions could let a command start running before you'd actually confirmed the local dialog - closed, so approval now means what it says.
- Scheduled tasks no longer treat their own configured prompt as untrusted input to refuse. If you run routines like this one, the prompt you set up now gets delivered as the session's real task instead of tripping an injection guard.
- Background sessions get a reliability pass: a crashed daemon could delete the control socket of the healthy replacement that took over for it, sessions parked idle with
/backgroundcould leave daemons and worker processes running forever, and completed or non-git-folder sessions that were impossible to remove viaclaude rmor the agents view now clean up properly. - Windows PowerShell tool: fixes for commands hanging when a child process waits on stdin, crashes on non-UTF-8 input or non-ASCII output,
>/>>writing UTF-16LE files nothing else could read as UTF-8, and raw ANSI escape codes leaking into error text.
The rest is the usual long tail: a new EndConversation tool for abusive or jailbreak sessions, a progress heartbeat for long-running tool calls, several OpenTelemetry attribute additions, docker commands with daemon-redirect flags now prompting, a GrowthBook crash fix, and a batch of smaller session, hook, and telemetry cleanups.
Verdict: a security release wearing a fix-pile costume. Update today if you lean on Edit(pattern/**)-style allow rules, use remote or background sessions, or run scheduled automation - otherwise whenever.
2.1.212 - plan mode was letting Bash run without asking (July 16, 2026)
- Security: plan mode was supposed to stop and ask before touching anything, but file-modifying Bash commands like
touchandrmcould slip through with no permission prompt and no SDKcanUseToolcallback. Fixed. - Security: creating a worktree that followed a repo-committed symlink at
.claude/worktreescould write files outside your repository. Fixed. /forksplits into two commands: it now copies your conversation into a new background session with its own row inclaude agents, while you keep working in the original. The old in-session delegate behavior is now/subtask.- New runaway-loop guards: WebSearch calls cap at 200 per session, subagent spawns cap at 200 per session, and MCP tool calls still running after 2 minutes now move to the background automatically instead of blocking your session - all tunable via environment variables.
- Fixed conversations with lots of images wrongly failing with "Request too large," and web search/fetch silently handing back literal "API Error" text as if it were a real result.
The rest is the usual long tail: /resume now shows a picker that includes deleted sessions and reopens your pick as a background session, reopening a stopped background session no longer fails silently, headless/SDK sessions can switch models mid-turn instead of waiting for the next one, and a batch of /ultrareview, OpenTelemetry, and terminal-rendering fixes.
Verdict: two real trust bugs buried in a 48-bullet pile. Update today if you rely on plan mode's permission gate or use worktree-isolated subagents - otherwise whenever.
2.1.211 - your approval prompts can't be faked anymore (July 15, 2026)
- Security: a permission prompt relayed to a chat channel (Slack and similar) could be visually altered with invisible or look-alike characters hidden in the tool input, so what you approved wasn't necessarily what ran. Those characters are now stripped before you see the prompt.
- Security: auto mode could override a hook's
askdecision on unsandboxed Bash commands and run them anyway. A hook that says "ask" is now honored no matter what. - Background agents stopped making things up: Claude used to sometimes report a still-running agent as finished. It now waits for the real result instead of fabricating one.
- If you run Claude Code through Bedrock, Vertex, Mantle, or Foundry, a caching bug was billing your trailing system context as fresh input tokens on every single request. That's fixed - worth checking your last invoice if this applies to you.
- Sessions that share one credential store (common in team or CI setups) no longer all get logged out at once when the machine wakes from sleep.
The rest is the usual long tail: subagents with an explicit model override no longer forget it on resume, plugin MCP servers now reconnect properly after an idle web session wakes, /clear resets the statusline cost counter, and a pile of Claude in Chrome, Windows, and accessibility fixes.
Verdict: two real security fixes and a billing bug dressed up as an ordinary fix pile. Update today if you relay approvals through a chat integration, rely on hooks under auto mode, or run on Bedrock/Vertex/Mantle/Foundry - otherwise whenever.
2.1.210 - subagents actually stay in their worktree now (July 14, 2026)
- Worktree-isolated subagents could run git-mutating commands against your real repo checkout instead of their own isolated copy - the isolation guarantee is fixed for real now, not just for file writes.
- The Agent tool is hardened against indirect prompt injection from content a subagent reads, and the
ultracodekeyword opt-in no longer fires on non-human input like webhook payloads or relayed PR comments - both close paths where content you didn't type could change what a session does. - Plan approvals without edits stopped mislabeling themselves "(edited by user)" and overwriting your plan file with a stale snapshot - a real way to lose planning work, now fixed.
- A hook callback timeout was being reported to the model as a user rejection, which made unattended sessions quietly stop and wait instead of erroring properly - matters if you run headless or background sessions.
- Unmatched
$1/$2placeholders in skills and commands used to get silently stripped. If a skill's arguments looked wrong for no reason, this was why - they're preserved verbatim now.
(2.1.209, same day, reverted an overly broad guard that had been blocking /model and other dialogs inside claude agents background sessions.)
The rest is the usual long tail: claude attach reliability during session transitions, a session crash from a tool result returning a bigint or plain text, memory writes over the MEMORY.md index limit now error instead of truncating silently, stale git worktree lock files from killed background sessions finally get swept automatically, and a batch of agents-view and accessibility polish.
Verdict: a security and reliability release wearing a fix-pile costume. The worktree isolation bug and the prompt-injection hardening are worth updating for even if nothing else here applies to you - update today if you run isolated subagents or unattended sessions, otherwise whenever.
2.1.208 - a 45-bullet fix pile, with a real memory cleanup (July 13, 2026)
- Long sessions get an actual cleanup: MCP server stderr no longer piles up to 64 MB per server, LSP documents now cap at 50 open docs instead of growing forever, and headless/SDK sessions stop ballooning from large tool results.
- Sessions with lots of MCP tools get noticeably snappier - tool-pool assembly is now cached, cutting per-call overhead by up to 7x at high tool counts.
- Session transcripts shrink up to 79x in edit-heavy sessions, and checkpoint disk usage is bounded by pruning old file-history backups instead of keeping every version.
- Added an opt-in screen reader mode (
claude --ax-screen-reader) that renders plain text instead of the usual fullscreen UI. rm -rfand other catastrophic deletes now get caught even when hidden inside$(...), backticks, or<(...)- previously only the plain form triggered a confirmation prompt in auto mode and--dangerously-skip-permissions.
The rest is the usual long tail: background-session daemon and attach fixes, a fast-mode toggle that stopped restoring itself, several tool error-message improvements (Read, Grep, Glob), and a Bedrock SSO regression from 2.1.207.
Verdict: all fixes, no new workflow to learn - but if you run long sessions or lean on lots of MCP servers, the memory and speed cleanup alone makes this worth updating for. Update whenever.
2.1.207 - closing three settings and plugin loopholes (July 10, 2026)
- Security: a non-interactive run (
claude -p, the SDK) could get its managed settings permanently marked as consented without ever showing you the security dialog. Fixed - the dialog now shows, or the settings do not apply. - Security: plugin hooks written with
${user_config.*}inside a shell-form command were vulnerable to shell injection. That interpolation is now rejected; hooks read config values with$CLAUDE_PLUGIN_OPTION_<KEY>or an exec-form command instead. - Security: plugin option values are no longer read from a project's checked-in
.claude/settings.json- only your user settings,--settings, or managed settings count now. A cloned repo can no longer quietly configure plugin behavior for you. - Auto mode got the same fix: it no longer reads
autoModefrom repo-resident.claude/settings.local.json. Set it in~/.claude/settings.jsoninstead. - The terminal freezing and keystrokes lagging during long streamed responses (big lists, tables, code blocks) is fixed - if that was happening to you, it was not your machine.
- If you run Claude Code through Bedrock, Vertex AI, or a Foundry deployment: auto mode no longer needs the
CLAUDE_CODE_ENABLE_AUTO_MODEopt-in, and Bedrock, Vertex, and Claude Platform on AWS now default to Claude Opus 4.8.
The rest is the usual pile: a crash loop in agent teams from a malformed teammate mailbox message, a few Remote Control reliability fixes (task status surviving a reconnect, mobile and web now showing background progress from desktop-hosted sessions), a Bedrock SSO credential-refresh loop, and /usage-credits now rejecting malformed amounts instead of silently truncating them.
Worth doing after this update: if you use plugins or auto mode at all, this release closes real gaps where a cloned repo could influence your settings without asking - update for that alone even if nothing else here applies to you.
2.1.206 - a 28-bullet fix pile (July 9, 2026)
- If your MCP tool calls were dying at exactly 60 seconds no matter what timeout you configured, this is the fix: a per-server
request_timeout_msin.mcp.jsonwas being ignored in fresh sessions. OAuth MCP servers also stop demanding manual re-authentication after a single failed token refresh. - An expired login used to fail every model with a misleading "There's an issue with the selected model" error. Now it just tells you to run
/login. - Background agents upgrade themselves right after a Claude Code update, instead of making you sit through a slow stale-session upgrade when you attach.
/doctorgained a check that suggests trimming checked-in CLAUDE.md files of anything Claude could work out from the codebase on its own.
All fixes, no new workflow. Update whenever - though if you run long MCP tool calls, the timeout fix alone is worth forcing it today.
2.1.205 - /doctor becomes a full checkup (July 8, 2026)
/doctoris now a complete setup checkup that can diagnose and fix issues instead of just listing them./checkupis an alias.- Auto mode got two safety guards: it asks before running
rm -rfon a variable it cannot resolve, and it blocks tampering with session transcript files. - The
claude agentsview got a real upgrade: sessions show a colored state word and a plain-English headline instead of raw tool-call text, and sessions that touch a pull request now link it. - The auto-updater streams downloads to disk instead of buffering them, cutting roughly 400 MB of peak memory during updates.
Worth doing after this update: run /doctor once. It catches config problems you did not know you had. (2.1.204, same day, was a single fix for hook streaming in headless sessions.)
2.1.203 - background sessions stop dying quietly (July 7, 2026)
- You now get a warning before your login expires, so background sessions stop getting interrupted mid-run.
- A batch of background-agent fixes landed: sessions no longer become permanently unresponsive when a session token goes stale, Windows agents no longer inherit a stale
PATH, and a bug that sent API keys to the wrong endpoint (failing with 401) is fixed. - Worktree-isolated subagents sometimes ran shell commands in the parent checkout instead of their own worktree. Fixed - this one could silently write to the wrong working copy.
- Small but nice: a grey pause badge now shows in the footer when you are in manual permission mode.
If you run agents in the background and had ghost failures over the last month, this release and 2.1.199 below are probably why they stop.
2.1.202 - /review is fast again (July 6, 2026)
/review <pr>went back to being a fast single-pass review. The heavy multi-agent version is/code-review <level> <pr#>- two commands, two speeds, pick per situation.- New "Dynamic workflow size" setting in
/configcontrols how many agents Claude spawns in dynamic workflows. - The resume picker no longer takes minutes (and a pile of memory) in repositories with many git worktrees.
- Re-invoking an already-loaded skill no longer appends a duplicate copy of its instructions to context - a quiet token saver if you watch your usage.
2.1.199 and 2.1.200 - the resilience batch (July 2-3, 2026)
- Partial output is now kept when the API errors mid-stream, instead of the whole turn being discarded.
- Transient rate-limit errors (429s that are not your usage limit) retry automatically with backoff instead of failing the turn.
- Subagents that die on a rate limit or server error now return their partial work and report the error, instead of silently failing or - worse - reporting success.
AskUserQuestiondialogs no longer auto-continue by default, and the "default" permission mode is now called "Manual" everywhere, which is what it always was.- Stacked skills:
/skill-a /skill-b do Xnow loads all leading skills (up to 5), not just the first.
2.1.198 - subagents go background by default, Chrome goes GA (July 1, 2026)
The biggest workflow change of this batch:
- Subagents now run in the background by default. Claude keeps working while they run and gets notified when they finish - no more sitting idle waiting for a delegate.
- Claude in Chrome is generally available.
- Background agents launched from
claude agentsnow commit, push, and open a draft PR when they finish code work in a worktree, instead of stopping to ask. - The built-in Explore agent now inherits your session's model instead of always running on a small one - exploration answers got noticeably better.
- New
/datavizskill for chart and dashboard design, with a runnable color-palette validator.
If you use parallel agents at all, this release changes how your sessions feel day to day. My parallel-agents setup tip pairs well with it.
2.1.197 - Claude Sonnet 5 becomes the default (June 30, 2026)
One line in the changelog, the biggest single change of the month: Claude Sonnet 5 is now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2/$10 per million tokens through August 31. You need 2.1.197 or newer to get it - if claude --version shows something older, that alone is the reason to update.
2.1.196 - a security fix worth knowing about (June 29, 2026)
- Security: a cloned repo can no longer self-approve its own
.mcp.jsonservers by committing a.claude/settings.json. Untrusted workspaces now show servers as pending approval. This closes a real attack path where a malicious repo could auto-start MCP servers on your machine the moment you open it. - Org admins can now set organization default models.
- Sessions get readable default names at start, and file attachments in chat became Cmd/Ctrl-clickable.
- Background reliability: long-running commands survive the session process being stopped or updated, and workers killed by a daemon restart auto-resume.
Older releases
This page explains releases from 2.1.196 (June 29, 2026) forward. Everything older is in the official CHANGELOG.md - complete, terse, and undated. If an older release still matters for something current, it gets folded into the explanation above instead of listed separately.
FAQ
How often does Claude Code update? Almost daily, often more than once a day. Most releases are bug fixes; a feature release worth changing your workflow for lands every week or two. This page separates the two so you can skim.
How do I check my Claude Code version?
Run claude --version in your terminal, or /doctor inside a session for a full setup checkup (available since 2.1.205).
How do I update Claude Code?
Claude Code updates itself automatically by default. To force it, run claude update. If you installed via npm, npm install -g @anthropic-ai/claude-code@latest does the same.
Where is the official Claude Code changelog? In the anthropics/claude-code repository on GitHub, in CHANGELOG.md. It is complete but terse - raw bullet points with no dates or context. This page adds the dates, the plain-English explanation, and a judgment call on what matters.
Do I need to update Claude Code to get new models?
Sometimes. New models can require a minimum version - Claude Sonnet 5 needs 2.1.197 or newer. If a model announcement says update to access, check claude --version first.
I read every release the day it ships, because releases change defaults - permission modes get renamed, models get swapped, tools get new flags. That tracking is also what keeps ClockedCode current: the curated setup it installs reflects what the current Claude Code version actually supports, so one paste gets you a configuration that matches today's tool, not January's.