# Changelog ## 2.1.295 - Added `onFailure: "block"` for command and HTTP hooks: a hook that can't start, times out, or exits with an unexpected code blocks the action instead of letting it through - Added Program Status Protocol (OSC 7501) support: terminals that implement it can show whether Claude Code is working, waiting on you, or done - Added quoted text to the `/copy` picker, so a drafted message copies without its `>` markers - Added a warning to `claude plugin install`, `enable`, `disable` and `marketplace add` when the settings file they write to does not load - Added a line on stderr, when it is a terminal, that says what a `claude -p` run is waiting for when it stays open after its last turn - Added support for `timeouts.upstream_ttfb_ms` on the Claude apps gateway's Bedrock, Vertex, Foundry and other cloud upstreams: a value you set now limits how long a stream may take to start there, after which it fails over or gets a 502 - Added a "Backgrounding cancelled" message when you stop the turn while `←` is waiting for the current tool to finish - Added an optional `models` list to every Claude apps gateway upstream: only the listed models are sent there, on failover too, and one `*` in an entry is a wildcard - Added support for `forceLoginMethod: "gateway"` and `forceLoginGatewayUrl` in your own user settings on machines with no managed settings, so `/login` opens on that Claude apps gateway - Added advice to `claude plugin validate` when a plugin's README has no install line: it prints the line to paste and never changes the exit code, even with `--strict` - Added `upstream_request_id` to the Claude apps gateway's `inference` audit event: the request ID from Amazon Bedrock, the Anthropic API or another upstream, for support cases - Added `$.ui.notify` for mods: raises a native notification through your own notification setting and says which channel sent it - Added children to a mod's `Button`: strings and `Text`, so a row of a list is one pressable with a chip or a dim detail inside - Added `CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS` to limit how long unattended retry mode (`CLAUDE_CODE_RETRY_WATCHDOG`) waits out 429 and 529 errors - Added a `request-id` header to the Claude apps gateway's successful inference responses, so `request_id` in Claude Code telemetry matches the gateway's audit log - Fixed every request failing on a `[1m]` model when a gateway, Bedrock, Vertex or Foundry refuses the context-1m beta; Claude Code now resends without it - Fixed `claude -p` text output dropping earlier responses when background work started another turn; each turn's response now prints when the turn ends - Fixed remote MCP servers in headless and SDK sessions staying disconnected after an outage longer than 15 seconds, or reconnecting in a tight loop to a server that drops each connection right after it connects; repeated drops now back off, up to 30s - Fixed remote MCP connections being dropped when a server's error reply happened to contain a network error name - Fixed MCP servers that repeat a pagination cursor being asked for the same page up to 20 times at every connect - Fixed CSS, JavaScript and XML files returned by MCP tools being saved as .bin, which the Read tool refuses; font and icon files now get their own extension too - Fixed Bash tool calls failing when the model passes `command_description` instead of `description` - Fixed Claude in Chrome not applying a site deny rule written with port 80 (`host:80`) to plain `http://` pages on that host - Fixed `/plugin`'s Errors tab removing a marketplace that failed to load, and uninstalling its plugins, on Enter without asking first - Fixed `claude plugin marketplace add` reporting success for a marketplace whose name no plugin can be installed under; such an add is now refused - Fixed `CLAUDE_AUTO_BACKGROUND_TASKS` moving a subagent to the background while an edit or shell command waited behind it, which started that call before the subagent finished - Fixed PushNotification saying a push was not sent in `claude remote-control` sessions right after a phone message, without the `/config` toggle, or when started from inside Claude Code - Fixed files sent from remote sessions being refused as "could not be vouched for" when more than 256 were sent at once - Fixed a rare failure to load managed settings at startup right after a login refresh - Fixed `/tui` exiting without a message, or with a raw system error, when Claude Code could not be started again - Fixed a link address shown as text being hidden by a colour or conceal style a reply left on, including where it wraps in a table or a question preview - Fixed Fable models listed in `availableModels` not appearing in the `/model` picker for sessions signed in to a Claude apps gateway; such a model now shows its built-in row in place of a `modelPicker` row added for the same model - Fixed the Claude apps gateway's admin spend view showing a developer's old groups and group cap after their session stopped carrying groups - Fixed `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` hiding the Claude apps gateway spend limit in `/usage` and the status line. The spend limit request goes to the gateway the session is signed in to - Fixed subagents in their own linked worktree being shown the parent session's git branch, status and recent commits - Fixed Claude stopping at the end of the current tool when text typed in the prompt cancelled backgrounding with `←`; Claude now keeps working in the foreground - Fixed `--tools` and `--restricted` not applying to built-in tools that register after launch, and deprecated tool names reaching tools outside the caller's tool set - Fixed an interrupt not ending the turn until a timeout while Claude waited for an MCP server's resource list - Fixed a mod's hook being handed a deeply nested tool input cut short with no error, so a guard could pass content it never saw - Fixed Esc not stopping a self-paced `/loop` that was moved to the background with `←`; cancelling a pending wakeup now shows a notice - Fixed commands and hooks in background sessions inheriting `FORCE_COLOR=3`, which put color escape codes into the output Claude reads - Fixed `claude agents` starting a new background service as it exited when both were stopped with a session open (for example at a reboot), which could delay shutdown and restart an interrupted session - Fixed a custom agent named `worker` being shown as "Agent" in auto-mode denial notices and in the activity lists of task detail views - Fixed Bash permission checks for for-loops over glob patterns, improving permission-check accuracy - Fixed forked skills invoked from Workflow subagents delivering their results to the main conversation instead of the invoking agent - Fixed in-process agent teammates failing their first SendMessage call until they loaded the tool through tool search - Fixed Claude being told on resume that an unfinished background workflow may have been stopped by `TaskStop`, which can never be the cause - Fixed Claude not being told when you stop a long-running MCP tool call from the tasks panel or a connected client - Fixed a background session's `/loop` stopping without notice when its next wakeup came due while the session's process was down; the session now says so and Claude is told - Fixed raw terminal hyperlink bytes in a reply or a teammate's message being drawn as a clickable link with a hidden address - Fixed plugin marketplaces whose repository has large git submodules failing to add or refresh: only the submodules that hold plugin files are now fetched - Fixed the `/advisor` dialog showing a checkmark on a saved advisor model that is no longer available; it now opens on "No advisor" - Fixed the notification for an MCP tool call that moved to the background showing a shortened task id - Fixed vim mode's `~` moving the cursor past the last character of a line, so `x` after it did nothing, and `3~` running on into the next line - Fixed the cursor landing one character too far after pasting accented text copied from macOS (such as a file name) into the middle of the prompt - Fixed the terminal freezing, with ctrl+c ignored, when a response ran to tens of thousands of lines - Fixed calls a mod makes while it reloads during a plugin hooks worker restart getting past another mod's guard hook that has a `.catch`; such calls are now refused - Fixed plugins whose hooks module nests code thousands of levels deep failing to load or validate with a bare stack-overflow message - Fixed `claude plugin test` passing a `session.append` hook that removes tool call, tool result or thinking blocks that a real session keeps - Fixed Claude not being told it can resume background subagents with SendMessage after a session was killed and resumed a second time - Fixed a file being treated as already read after a Bash command such as `cat` ran without printing it - Fixed plugin options named `constructor` or `prototype` always reading as their default and never reloading the plugin when edited - Fixed a mod's hot reload missing a save made while `/reload-plugins` or session start was reading the mod's files - Fixed the mod hot-reloading question being asked again every turn for the whole session when it is approved without picking an answer - Fixed `/model`, `/fast` and `/output-style` saving their setting without asking a plugin's `config.set` hook - Fixed bold text being drawn faint in piped output when it directly follows dim text - Fixed replies whose quotes nest deeper every few lines freezing the terminal for seconds and using gigabytes of memory - Fixed a mod's hot reload missing a save made within a few milliseconds of its last reload, which left the mod on its old version until the next save - Fixed `claude mcp serve` background Bash results not naming the output file, and its tool description promising a notification that never arrives - Fixed an async SessionStart hook's unchanged context being added to the conversation again on every resume - Fixed variables a SessionStart hook writes to `CLAUDE_ENV_FILE` not reaching the Bash tool after an in-app `/resume` or `/branch` - Fixed a skill's `allowed-tools` and `effort` being dropped when the Skill tool finished before the response stream ended, which denied the skill's Bash commands in `-p` runs - Fixed a tampered cache of server-managed settings making a person's own plugin count as organization-managed on machines whose managed settings list or enable plugins - Fixed Claude 3 Opus and Claude 3.x Sonnet sessions being offered tool search, which those models reject, where feature flags are unavailable - Fixed generated type files being written into a `--plugin-dir` plugin's folder in `-p` and SDK sessions; they are now written only where a mod is being developed - Fixed text with tabs or bidirectional control characters losing its end at the edge of the screen or drawing over nearby rows - Fixed `/model` saying a Max effort pick was saved as your default for new sessions; Max applies to the current session only - Fixed an async hook's JSON output being ignored when it is printed over several lines - Fixed the Read tool rejecting calls with an empty `pages` parameter instead of treating it as omitted - Fixed project-scope plugins not loading in VS Code on Windows due to drive-letter casing (anthropics/claude-code#74612) - Fixed `plugin install` and `uninstall` at project or local scope on Windows missing the install record, or adding a second one, when only the drive letter's case differs - Fixed a queued message being lost when pulled back into the prompt with `↑` or `Esc` just after `←`: prompt history now keeps it - Fixed mod hot-reloading turning off for the whole session when an SDK host closed its enable question before anyone answered; the question is now asked up to three times - Fixed a prompt that a mod's `prompt.submit` hook rewrote or dropped still being saved as typed to prompt history and to the transcript's queued-prompt records - Fixed non-interactive sessions telling you about MCP servers that need authentication when your request doesn't use them - Fixed the `claude_code.auth` OpenTelemetry login event not being emitted on Claude apps gateway sign-in. The event is exported when OpenTelemetry is configured on the machine or the session is already signed in to the gateway - Fixed a plugin that adds very large interfaces getting another plugin unloaded when the plugin hooks worker stalls - Fixed Edit treating a file as fully read when its contents changed without its modification time advancing - Fixed short command output with Windows line endings (CRLF) being drawn on a single line - Fixed a stopped scheduled task coming back on resume after a rewind, and a scheduled task being lost on resume after Esc or a rewind following a compaction - Fixed the terminal freezing for seconds or minutes while syntax highlighting code with very long lines, long runs of blank lines, or unclosed strings and heredocs - Fixed temporary files left under `~/.claude/seed-admin` by an interrupted `/ultrareview` upload never being removed by the retention cleanup - Fixed Desktop and SDK sessions refusing to switch back to auto mode until restart after `disableAutoMode` was removed from settings - Fixed claude.ai-synced plugin hooks failing with "Plugin directory does not exist" in long-running sessions after another session synced a plugin update - Fixed the prompt sent after a `/rewind` being lost, and the removed turns coming back, when the session was moved to the background or resumed after being killed - Fixed cloud sessions hanging when a mod's `session.receive` hook asked for permission before passing a message on - Fixed macOS background sessions that restart together after an update sometimes running outside the stable app wrapper, so folder-access prompts could reappear - Fixed an MCP sign-in or reconnect that finishes late in headless and SDK sessions relisting a server set with `setMcpServers()` as your own - Fixed changing the auto-update channel in `/config` saving before a plugin's `config.set` hook was asked - macOS: Fixed a file count at session start that could reach other apps' data and raise the "access data from other apps" prompt when a session starts in the home folder or above it - Improved token counts behind a Claude apps gateway on Amazon Bedrock, which `/context` and large file reads use: the gateway now gets them from AWS's CountTokens API instead of a one-token model request. Grant `bedrock:CountTokens` to use it - Improved the Claude apps gateway to log a warning every 30 seconds while its PostgreSQL database is read-only, saying what fails and how to recover - Improved the status shown in Remote Control, claude.ai and the desktop app for a session waiting on a permission prompt to name an MCP tool by its server and readable name instead of its `mcp__server__tool` identifier - Improved background requests behind a Claude apps gateway to use Haiku 4.5 instead of the session's model, falling back to the session's model where the gateway does not serve Haiku 4.5 - Improved how the Claude apps gateway handles models not listed under `models:` in Amazon Bedrock regions outside AWS's US geography. AWS always refused those requests; the gateway now tries the model in your own region, and a refusal names the model to add - Improved headless `rate_limit_event` usage-limit warnings to say whether the account has extra usage turned on - Improved the built-in `plugin-authoring` skill: it no longer tells a session with no terminal to run terminal commands, and explains sharing a mod only when asked - Improved Grep input handling: a search sent with grep's `-l`, `-c` or `-r` flag now runs instead of failing the call - Improved `claude plugin validate` and plugin loading: when a hooks module is refused over a rebound top-level `var`, the error now names the line that rebinds it, the cause, and a fix - Improved the Workflow tool's `scriptPath` refusal: it now says to pass the script inline via `script`, the route that works in sessions without a Read tool - Improved what Claude is told when a large file it sends fails to upload with no reason given, so it reports the failure instead of shrinking the file - Changed MCP tool descriptions the model loads through tool search to be cut at 16,384 characters instead of 2,048 - Changed subagents to preload at most 32 skills from the `skills` field, each once; a subagent with the Skill tool can still invoke the rest - Changed Ctrl+C at the idle prompt of an attached background session to leave a pending `/loop` wakeup alone, so pressing it twice detaches and the loop keeps running; press Esc to stop it - Changed `claude agents` stopped with its background service (macOS, or Linux without the service installed): running sessions now stop in about a minute unless it is run again, and a notice says so - Changed claude.ai connectors to negotiate MCP protocol version 2026-07-28 by default on installs that fetch no flags; `MCP_PROTOCOL_NEGOTIATION=legacy` opts out - Changed Artifact pages with no background of their own to show on white instead of off-white - Changed what Claude and you read when a mod denies a tool call after the tool ran: it now says the tool ran and a plugin withheld its result - Changed tab stops to count from where a text starts instead of from the screen's left edge: an answer indented by 2 has its first stop 8 cells in, where it was 6 - Changed the Artifact tool's permission prompts with telemetry disabled to the same five questions other installs get, instead of asking before each read of someone else's artifact and each data edit - Changed scheduled and Run now routine runs in installs with telemetry disabled to publish new private artifacts, and update your own, without asking, as in other installs - Changed toasts from your organization's mods to show ahead of other mods' toasts instead of waiting behind them - Changed the Claude apps gateway to start with a warning and serve a `desktop` policy key its bundled Claude Desktop schema doesn't know, so new Desktop settings need no gateway upgrade - Changed WebSocket (`ws`) MCP servers: a message over 16 MiB is no longer parsed and closes the connection, the limit the other transports already have - [VSCode] Added a chat row for files Claude sends you: click a file's name to open it in the editor; Claude's caption shows underneath, and the row stays visible in Focus view - [VSCode] Fixed "Fork conversation from here" and Rewind's conversation restore failing with "Message not found in session" after a background agent's activity or one of the panel's own status lines - [VSCode] Fixed Ctrl+Shift+Tab, Cmd+Shift+Tab and Alt+Shift+Tab in the chat input also switching the permission mode, and Ctrl+Tab accepting the suggested prompt - [VSCode] Fixed keyboard focus bouncing between two Claude views visible at once, which could send typed text to the wrong conversation - Self-hosted runner: Changed the runner to stop passing `CCR_AUTO_MODE_ALLOW`, `CCR_AUTO_MODE_ENVIRONMENT` and `CCR_AUTO_MODE_SOFT_DENY` into a session's environment - Self-hosted runner: Fixed git fetches being cut off while the git server was still reporting progress on a large repository; `CLAUDE_RUNNER_FETCH_SERVER_PROGRESS_CAP_MS` tunes or turns off the wait - [Cloud sessions] Fixed a message sent right after unarchiving a cloud session sometimes getting no reply because no container could start for it - [Cloud sessions] Fixed some older routines starting their runs without ever giving Claude their saved prompt; those routines now run their prompt again - [Cloud sessions] Improved how quickly a cloud session catches up after its connection drops: activity you missed now appears all at once instead of row by row - [Cloud sessions] Improved the setup script box in the cloud environment form: it starts taller, grows with your script, and can be resized by dragging - [Claude Tag] Changed the settings confirmation cards Claude posts in a Slack channel to stay open for 30 minutes instead of 10 - [Claude Tag] Changed Claude's notice that a channel shared across Enterprise Grid workspaces uses organization defaults to post only when someone mentions Claude, at most once a month - [Claude Tag] Fixed channel links and @-mentions in a forked thread's "Continued from" card showing as raw Slack codes - [Claude Tag] Fixed Slack's Working status spinning on under a thread after `@Claude !restart` had already confirmed the restart - [Claude Tag] Fixed another app's or bot's @Claude going unanswered in a busy channel where Claude had stopped reading untagged messages - [Claude Tag] Added a confirmation in Claude Tag admin settings before adding a channel manager moves that member to Custom roles, which can remove their other access - [Code Review] Fixed Code Review re-reviews saying no issues were found while earlier findings were still open; the comment now says how many remain open - [Code Review] Fixed Code Review still skipping a large CLAUDE.md's rules when the pull request edits that file - Fixed web searches and `agent` hook evaluations taking much longer at `xhigh` and `max` effort ## 2.1.294 - Fixed `prompt` and `agent` hooks written as instructions (such as "Block commands that...") allowing what they should block - Improved how `prompt` hooks on Stop and SubagentStop written as instructions (such as "Carry on if the build is broken") are judged, so Claude is less likely to stop early ## 2.1.293 - Added Claude Haiku 5.5 (`claude-haiku-5-5`), now the default Haiku model on the Anthropic API — 1M context, $0.10/$0.50 per Mtok ($0.50/$2.50 for prompts over 100K) - Added `agentType` to the `subagentStatusLine` payload, so scripts can tell custom subagent types apart - Added `isDeferred` to `$.tool.register` for mods: `false` lists the tool's schema in the prompt from the start instead of behind tool search - Fixed Claude sometimes treating its own last actions before a context compaction as done after it, and retracting or redoing finished work - Fixed a memory leak where an HTTP MCP connection kept every request it had sent until it closed - Fixed a message sent while Claude was working being lost when `←` moved the session to the background; if a queued message can't move, `←` now stays put and says so - Fixed `/model` effort ←/→ wrapping past the highest or lowest level, which could accidentally save Low as a model's default effort - Fixed `/tui` disconnecting Claude in Chrome in a session started with `--chrome`, and ignoring `--no-chrome` - Fixed Claude being told to continue or message subagents with `SendMessage` in sessions, including resumed ones, where a host, a permission rule or a `--tools` list removed that tool - Fixed subagents and `--agent` sessions being told a built-in tool was disabled for the whole session when only their own tool list left it out - Fixed a claude.ai-synced skill's edited description sometimes not reaching the model until a new conversation or `/clear` - Fixed `claude logs`, `stop`, `kill`, `rm` and `claude daemon status`, `stop`, `uninstall` sometimes signing you out when your login had expired or was about to - Fixed the footer's agents count disappearing after a momentary failure to read the sessions folder (for example, too many open files) - Fixed a custom agent named `worker` being shown as "Agent" when it starts, and the agent detail dialog's title losing the agent type once the agent finishes - Fixed the Artifact tool's transcript row briefly reading `Artifact("(unprintable path)")` while a publish call was still streaming in - Fixed the `/ultrareview` upload on Linux wrongly refusing some repositories, such as one inside another checkout, over a settings file that "could not be parsed" while a sandboxed command was running - Fixed the `/ultrareview` upload's refusal over split-index files advising a git command that could leave git unable to read its index - Fixed replies in very long Remote Control and cloud sessions that could still appear a block at a time instead of streaming in - Fixed Remote Control uploading a session's starting history again after every credential recovery - Fixed PushNotification reporting "Remote Control inactive" in sessions started with `claude remote-control` - Fixed a mod's hooks on `classic.*` events being skipped while the plugin hooks worker restarts, which left settings hooks to answer without them - Fixed `claude plugin test` failing for mods that call `$.session.append`; tests can read the appended rows back with the new `mock.session` - Fixed `claude plugin eval` refusing every Bash-granting run on Macs with Docker Desktop (links under `~/.docker/bin`); the refusal now names which part of a credential store held the link - Fixed the Claude apps gateway refusing to start when a `desktop` policy sets Claude Desktop's built-in browser keys, such as `builtinBrowserEnabled` - Fixed `claude agents` offering bypass permissions that background sessions then ignored when consent was saved only in `.claude/settings.local.json` or a `--settings` file; it now asks for consent first, and a session that ignores bypass shows a short notice that stays - Fixed `←` backgrounding a session after 10 seconds while the prompt held unsent text (it now cancels the move) or a question was waiting for your answer - Fixed Esc, or No without feedback, on a permission prompt not stopping the turn when `←` had just been pressed to move the session to the background - Fixed the agents view briefly replacing the session list with placeholder rows when the sessions folder could not be read (for example, too many open files) - Fixed path-scoped rules and nested CLAUDE.md files not loading when Claude views a file with a single-file cat, head, tail, sed -n or grep command in the Bash tool instead of the Read tool - Fixed pasted text that begins and ends with the same words sometimes being sent to Claude as if it had been typed - Fixed a skill name in pasted text being treated as typed when an accent typed or pasted right after the paste merged into its last letter - Fixed `/feedback` returning to the drafts list after Ctrl+O or Ctrl+Z while a report was sending, leaving the send impossible to cancel - Fixed `claude purge` stopping silently (exit 0, or a hang in a terminal) when a file or folder could not be deleted; it now deletes the rest, lists what it could not delete, and exits 1 - Fixed keybindings.json checks: a lone " " (space key) is no longer reported as an error, and keys like "ctrl+ k" now get a warning - Fixed vim mode `>>` and `<<` on a line of only spaces leaving the cursor past the end of the line, where a following `x` deleted nothing - Fixed vim mode: after deleting whole lines in Visual mode (`V` then `d`) the cursor lands on the first non-blank, and `.` after it acts on the cursor's line - Windows: Fixed stopping a status line, hook, or shell command sometimes terminating an unrelated process that had been given the same process ID - Reverted the auto mode denial message change from 2.1.281 that told Claude a denial covers the outcome, not only the exact command - Reverted the 2.1.290 fix for cloud sessions staying asleep after a container restart lost a pending `/loop` wakeup or scheduled task; Claude is no longer told, and the session stays asleep - Improved startup for Team and Enterprise organizations: policy and managed settings are fetched earlier, and a stalled request is retried after 3 seconds - Improved Claude in Chrome: fewer page actions are refused when the browser is slow to report its tabs - Improved the Claude in Chrome message in cloud sessions when the browser can't be reached: if you belong to more than one organization, it now says the extension must be signed in to the same one, and how to change that - Improved the Bash edit diff note to say the listed files changed while the command ran, which can include writes by other processes - Improved artifacts: Claude pins libraries to exact versions two weeks old or older - Changed claude.ai skill syncing to check for changes about every 40 minutes, instead of every 10, while no session is in use - Changed the order of agent lists and of MCP servers announced to the model: names with non-ASCII characters now sort after ASCII names - Changed OpenTelemetry `claude_code.at_mention` logging to emit at most 100 agent and 100 MCP-resource events each time a prompt is read - Self-hosted runner: Changed the orchestrator to sleep 4 to 6 seconds between polls instead of a constant 5, so several replicas for one environment stop polling at the same moment - [Claude Tag] Fixed Claude in Slack saying a workspace isn't set up in Enterprise Grid channels shared across workspaces when Slack labels a message with a workspace that isn't connected - [Claude Tag] Fixed Claude in Slack stopping mid-task in a channel when an admin changed the channel's connectors, plugins, skills or rules; the change now applies once Claude finishes - [Claude Tag] Fixed asking Claude in Slack to run a thread's routine now with extra notes starting a separate run that couldn't post back; the run now continues in that thread - [Claude Tag] Fixed an access bundle's Add a connector dialog in Claude Tag admin settings showing every Google connector as connected after one Google sign-in - [Claude Tag] Improved Claude Tag admin settings to list an Enterprise Grid that isn't connected yet, with a Connect button - [Claude Tag] Changed Claude in Slack to join announcement channels, where only admins can post, without posting its intro - [Claude Tag] Changed the limit on channel rules in Claude Tag admin settings from 20 to 50 for each workspace and for the organization-wide Slack page - [Code Review] Improved Code Review's Add a repository dialog to list each repository that couldn't be added and why, such as missing GitHub write access ## 2.1.292 - Added `--marketplace ` to `claude plugin install`: adds the marketplace if needed, under the same policy checks as `claude plugin marketplace add`, then installs the plugin from it - Added an `effort` parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for - Added `CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS` environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request - Added `prompt.autocomplete`, an event a mod hooks to add its own rows to the prompt box's autocomplete list - Added prompt caching to `$.model.complete` for mods: `prompt` and `system` take blocks of text, and `cache: true` on a block caches the request up to it - Added workflow agents to the `agent.spawn` mod hook, with their run and index, so a mod can refuse them - Fixed subagent definitions with `permissionMode: auto` entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it) - Fixed sandboxed commands being able to read the staged file copies of `/ultrareview` uploads under `~/.claude/seed-admin` - Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers - Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read - Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed - Fixed `rm -rf` on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it - Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths - Fixed a skill's or slash command's `allowed-tools` rule coming back in a later turn when you leave auto mode or plan mode partway through that turn - Fixed `NO_PROXY` being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when `HTTPS_PROXY` is set - Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it - Fixed `claude plugin` commands such as `marketplace add` and `install` running before an organization's managed settings had loaded on a first run - Fixed one-shot `claude -p` and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot `claude -p` runs dropping a scheduled wakeup; both are now waited for - Fixed plan mode not being restored when resuming a session from the `claude --resume` session picker or with `/resume` - Fixed saved scheduled tasks created after `/resume`, `/branch` or `/clear` never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart - Fixed a background session's `/loop` silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost - Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you - Fixed the Read tool returning only the first entry, with no error, when a PDF's `pages` was a list such as "6,9,15"; it now returns an error saying to read each page or range separately - Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file's size and to read it in portions - Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation - Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE - Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse - Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued - Fixed `/bug`, `/share` and `/feedback ` starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent - Fixed `/remote-env` replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect - Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt - Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and `f`/`t`/`F`/`T`/`;`/`,` jumping to, or deleting up to, a match on another line of the prompt - Fixed `/add-dir` path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys - Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and `!` leaving the row selected - Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2's scrollback with stale pages - Fixed a spurious "could not be examined" note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink - Fixed "instruction file not loaded" lines going stale or missing after `/cd` or a permission change, and added a transcript line when a nested one isn't loaded - Fixed a compaction summary that repeated `/name` letting Claude invoke a skill that is reserved for the user - Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason - Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished - Fixed cloud sessions with a large transcript sometimes asking for a permission again after it was approved - Fixed scheduled tasks and other queued notifications being lost in cloud sessions when a message was retried or edited while Claude was reading them - Fixed cloud sessions forgetting the thinking setting chosen in the client when the session's container restarted - Fixed Cowork cloud sessions saying a proxy blocked artifacts when Anthropic couldn't confirm the organization's settings - Fixed plugins whose hooks module makes many `$.state` calls through one const taking minutes to load or validate - Fixed `claude plugin validate` listing a matcher or state value for a hooks module that the engine reads from elsewhere - Fixed `claude plugin validate` listing a `$.state` value read through a top-level `var` that was declared again or reassigned; such a module is now refused - Fixed a plugin's served `$` method restarting the hook origin, which could run a guard hook with a `.catch` above it again without end - Fixed plugin interface calls made while the plugin hooks worker restarts running without the hooks other plugins put on them - Fixed a mod's `config.set`, `state.set`, `env.set` or `agent.spawn` hook that denies after calling `next(e)` being answered as a refusal: the hook is now reported as failed, by name - Fixed `/theme`, the `/config` Theme menu and the first-run theme step saving a theme before a plugin's `config.set` hook was asked - Fixed a plugin's `tool.check` hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog - Fixed a mod's start-up prompt, command or subagent being queued a second time when the hooks worker was replaced - Fixed a mod's hook that called `next(e)` and then failed while the turn was interrupted letting the call through; the call is now rejected - Fixed a plugin's prompt drop or setting deny being ignored when its reason was longer than 4,096 characters - Fixed an organization's plugin being unloaded on its own reload, or after another plugin crashed, when it returned a `$` name that a user-installed mod had added; the mod is now unloaded instead - Fixed tool calls made while the plugin hooks worker restarts being answered without the plugins' permission hooks - Fixed plugin `tool.call` hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with - Fixed a mod's guard hook with a `.catch` being skipped silently for calls another mod's hook makes beneath the guard's own `$` call; its `.catch` is now asked - Improved startup of `claude -p` and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer `resources/list` - Improved rendering speed of long bulleted or numbered replies: they stream, resize and re-open in the transcript (ctrl+o) much faster - Improved Ctrl+C draft recovery: a cleared prompt now stays reachable with Up after a slash command or a sent message - Improved hook output handling: `` tags written in a hook's output are escaped before they reach Claude - Improved tool input handling: Grep accepts `file_path` for `path`, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call - Improved the steps shown when a marketplace declared in a settings file has a name that looks like an official Anthropic marketplace - Improved sandbox auto-allow: with strict sandbox mode set in user, managed or --settings settings, an interpreter command with an env var prefix like `FOO=bar python3 app.py` runs unprompted - Improved the Artifact tool's listing: Claude now sees how many published artifacts you have and can list up to 200 at once instead of 50 - Improved cloud sessions after a restart: Claude is now told which stopped background agents it can resume by id - Improved the Claude in Chrome message in claude.ai cloud sessions when the browser can't be reached: Claude is now told it may continue with alternatives if the user prefers - Improved the /focus tip: it now invites you to try focus view mid-turn and shows how to switch back - Improved startup with local (stdio) MCP servers that ignore the newer protocol check: after one slow connect they are remembered for 7 days and connected the older way without the wait - Changed local (stdio) MCP server connections to negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex and Foundry; `MCP_PROTOCOL_NEGOTIATION=legacy` opts out - Changed `claude plugin test`: a failed `expect` inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently - Changed usage limit messages to write claude.ai settings links with https:// so terminals and apps can make them clickable - Changed scheduled and Run now routine runs to publish a new artifact only you can see without asking for approval; artifacts that request connectors or other access still ask - Changed agent names to allow at most 256 characters: a longer one is rejected, and a skill's or a plugin file's `name` longer than that is ignored - [Cloud sessions] Fixed routine runs occasionally staying listed as running for hours after they had finished - [Cloud sessions] Fixed editing or duplicating a routine turning off its push notifications when the routine had no saved notification setting - [Cloud sessions] Fixed SVG, HEIC, TIFF and other less common image files failing to attach; they now attach as regular files - [Cloud sessions] Fixed approval prompts offering "Always allow" for connector tools that an organization set to require approval; the choice had no effect - [Remote Control] Fixed the first message of a new Remote Control session started from claude.ai/code accepting only images; it now accepts PDFs and other files like later messages - [Claude Tag] Added an Edit button to the Allowed domains card on a channel's Configure page, so Enterprise admins can open the access bundle that sets the channel's domains - [Claude Tag] Fixed replies sent in a Slack thread while Claude was still on its first request there being held until that request finished, or missed when sent seconds apart - [Claude Tag] Fixed Slack threads woken only by GitHub pull request activity or a routine staying on their original model after an admin changed the channel or workspace default model - [Claude Tag] Fixed Claude sometimes posting a spend limit notice in Slack when the real cause was that your organization had run out of usage credits - [Claude Tag] Fixed a session hanging until interrupted when a permission prompt that can't be answered from Slack was denied automatically - [Claude Tag] Improved `@Claude !status` in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again - [Claude Tag] Changed the first message of a Slack thread continued with `!fork` to a card showing where it came from, the request, and who asked, with a link to the original thread - [Claude Tag] Changed the organization-wide and default spend limit boxes on Claude Tag's spend limits page in admin settings to save only when you press Save or Enter, not when you click away - [Code Review] Added the period's total with its change from the previous period, and a breakdown by repository, to the PRs reviewed chart in Code Review analytics - [Code Review] Fixed a queued review failing when the pull request moved to a new base branch and the old one was deleted; the commit is now re-queued for review - [Code Review] Fixed reviews ignoring a CLAUDE.md's rules when the pull request edits that file; reviews now use its version from the base branch ## 2.1.291 - Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts - Fixed a regression in 2.1.288 where the last messages of a session could be lost when quitting ## 2.1.290 - Added `serverToolUses` to the result of a mod's `turn.step` hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end - Added `agentId` to the `tool.check` event of plugin hooks, so a hook can tell a subagent's permission check from the main session's - Added `ceiling` to the question and verdict a mod's `tool.check` hook reads, naming the approval an organization requires for a tool - Added `ThemeKey` and `Color` types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name - Added to `claude plugin validate`: each hook a mod registers at a gating site is listed with whether it has a `.catch` (`gatingHooks` under `--json`) - Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds - Added `claude attach ` and `claude logs `: part of a session name works in place of the id - Added `/claude-api managed-agents-onboard ` to set up the Managed Agents pattern a page describes as `ant apply` files - Added `/claude-api managed-agents-onboard ` to build a Console quickstart template, such as `deep-researcher`, with the `ant` CLI - Added a warning when a managed settings file is a link to a file outside the managed settings folder - Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains - Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta - Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors - Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown - Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run - Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an `offset` to read on - Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep - Fixed `/rewind` not listing a prompt sent while Claude was still working - Fixed scheduled tasks (`/loop` with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on - Fixed scheduled tasks set in the foreground never firing after a ← or `/background` hand-off, and recurring ones firing an extra run on every resume, respawn or fork - Fixed headless `--json-schema` runs exiting non-zero with `is_error: true` on a `success` result when the connection dropped after the structured output was already delivered - Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy - Fixed a project `CLAUDE.md`, rule or `AGENTS.md` symlinked outside the working directories loading under `permissions.blockReadsOutsideWorkingDirectories` or a `Read` deny rule - Fixed URL allow and deny patterns with a wildcard inside an `xn--` host label matching differently from one process to the next - Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions - Fixed `/ultrareview` dropping uncommitted changes without a warning on Windows when `git stash create` failed, and refusing them after a `git add -N` file was deleted or moved - Fixed the `plansDirectory` setting's project-root check for paths that contain a backslash on macOS and Linux - Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in - Fixed the background daemon's log passing terminal control characters to the screen under `claude daemon run` and `claude daemon logs`; they now show as `\uXXXX` escapes - Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds - Fixed a plugin hook with a `.catch` being unloaded, and its `.catch` skipped, when the hook kept the hooks worker busy on a prompt or tool call - Fixed a mod's `turn.step` result listing a tool call that a mid-response model fallback had discarded - Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file - Fixed `claude plugin validate` and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions - Fixed `/ultrareview` failing to upload uncommitted changes when `core.safecrlf=true` is set in git's configuration - Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings - Windows: Fixed multi-line `!` shell blocks in skills and commands failing when the file is saved with CRLF line endings - Fixed Claude Code hanging until killed when a `/permissions` tab was clicked while searching in fullscreen mode - Fixed conversation compaction sometimes failing with a "null is not an object" error - Fixed plugin hooks reading an empty `answer` on `turn.complete` for a subagent that hands its report back in auto mode - Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded - Fixed a mod's `prompt.submit` hook that drops a prompt after calling `next(e)` being ignored silently: the hook is now reported as failed, by name - Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing - Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read - Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded - Fixed `disableClaudeAiConnectors` and `allowedMcpServers` URL rules not being applied to some MCP entries declared in `.mcp.json`, plugins or agents - Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing - Fixed an `@`-mention under the read block or `--restricted` being able to read a file outside the working directories through a link changed mid-read - Fixed Esc in the agents view confirming "Press enter again to restart this session — it isn't responding"; Esc now just reopens the session - Fixed agent view losing a background session's `/loop` run count, countdown and live status line after the session enters a worktree that it creates - Fixed `claude agents` sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt - Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on `declare`, `typeset`, `export` or `readonly` - Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder - Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded - Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters - Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted - Fixed You should know writing its notes in English regardless of the `language` setting - Fixed a freeze after sending some very long messages - Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing - Fixed `claude respawn` re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation - Fixed Esc after an `n:` or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section - Fixed `claude agents` saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted - Fixed `/ultrareview` uploading uncommitted changes unfiltered for files under a git filter driver named `unset` or `unspecified`; the upload now stops and asks you to rename the driver - Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore - Fixed `claude --teleport` and `/teleport` deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why - Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt - Fixed agent view's `/loop` run count freezing and its countdown disappearing after `/clear`; the count now restarts with the new conversation - Fixed `--channels` permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt - Fixed `/chrome` "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135) - Fixed mods staying off for people who reach Claude through a gateway (`ANTHROPIC_BASE_URL` with `ANTHROPIC_AUTH_TOKEN`) and have no Anthropic account - Fixed replies sent from `claude agents` just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts - Fixed slash commands and answers to a multiple-choice question that `claude agents` could not deliver to a running session being saved and sent by themselves the next time it was restarted - Fixed sandboxed commands that pipe a heredoc into another command (`cat <` in the terminal - Fixed a marketplace named after another GitHub marketplace's download folder stopping that marketplace from downloading - Fixed automatic compaction giving up with "Prompt is too long" when a Mac went to sleep while it was running - Fixed the rewind menu (Esc Esc / `/rewind`) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file - Fixed a subdirectory's AGENTS.md not being attached when a file under it is @-mentioned - Fixed self-hosted runner sessions resumed after a stopped runner failing with "missing but already registered worktree" when the sessions folder is a relative symlink - Fixed a freeze when the secret scan or a permission prompt met long token-like text - Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands - Fixed `CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m` being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to `dialogExpiry` - Fixed a stall when an MCP server's tool listing contains very long runs of combining characters - Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block - Fixed Claude in Chrome's browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog's list going stale after a switch - Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree - Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login - Fixed `--restricted` (and `CLAUDE_CODE_RESTRICTED=1`) sessions opening the cross-session messaging socket - Fixed sessions moved to the background while idle reopening as "no saved transcript" after a restart or idle cleanup; they now resume their conversation - Fixed background workers honoring `--allow-dangerously-skip-permissions` on respawn without the bypass-permissions disclaimer having been accepted - Fixed Claude replying in an endless loop when a plugin's async Stop hook passes an unquoted script path under a folder with a space, such as Application Support - Fixed a freeze of several seconds when secret masking met very long unbroken text - Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input - Fixed first launch asking to pick a login method again after `claude auth login` or with a credentials file already in the config directory - Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts - Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do - Fixed macOS `/login` reporting success when the keychain refused the new login and kept an old one it could not remove - Fixed SDK hosts using `--include-partial-messages` seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming - Fixed sandboxed Bash commands on Linux running `ConfigChange` hooks and reloading settings mid-command when `.claude/settings.json` or `.claude/settings.local.json` does not exist - Fixed errors reading "Premature close" instead of naming the missing program when a tool Claude Code runs, such as git or gh, is not installed (macOS, Linux) - Fixed `/loop` and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after `.claude/scheduled_tasks.json` was deleted - Fixed edits to the file a symlinked settings file points at running without the settings-file permission question - Improved MCP startup behind a network proxy: a server the proxy blocks (HTTP 403) is no longer retried three times - Improved permission prompts from background agents to show the Ctrl+X Ctrl+K shortcut that stops all background agents - Improved the built-in `plugin-authoring` skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section - Improved the reply to `/plugin` in the desktop app's Code tab: it now says where to install and manage plugins there - Improved the Bash changed-files view: when a chained command includes git merge, pull or checkout, it lists the files without full diffs - Improved the Claude apps gateway's log when an upstream's cloud credentials or connection fail: the warning now ends with the underlying cause - Improved the error shown when a cloud session is started without a claude.ai sign-in: it now names `claude auth login` and /login and no longer blames API-key authentication - Improved the Read tool's message for binary files: it now points Claude to a skill or a shell command that can read the format - Improved the error shown when a git config file stops the `/ultrareview` upload: it is about half as long and says what kind of file is the problem - Improved the errors shown when the `/ultrareview` upload refuses a checkout: each known cause now has its own message, with a way to fix it - Improved the Claude apps gateway to log a warning during the last 30 days before the certificate it presents to the identity provider expires - Improved Claude in Chrome: a `browser_batch` call now gets 90 seconds, up from 60, before it is reported as timed out - Improved the Claude apps gateway's browser sign-in pages: brand fonts, centered layout, and dark mode - Improved responsiveness while resuming large sessions: timers, input and rendering keep running while the transcript loads - Improved the / and @ suggestion lists: the selected row now starts with a ❯ pointer, so you can see it without color - Changed `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` to also skip the startup connection warm-up - Changed Claude in Chrome so that a project's settings files can no longer turn it on; use `--chrome`, `/chrome` or your user settings - Changed the Bash tool to ask for permission before running `pyright`, which is no longer treated as a read-only command - Changed what a mod's `$.process.spawn` rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result - Changed the background daemon's log to write a multi-line message as one JSON-quoted line - Changed skills and custom commands to refuse a `!` shell command that contains raw control characters other than tab and newline, with a message that shows where they are - Changed `/artifacts`: opening an artifact in your browser now closes the list - Changed Bash permission checks so that more forms of the `ps` command ask for approval instead of running without asking - Changed plugin hooks so long text is clipped and logged instead of being refused or dropped silently - Changed background sessions whose scheduled task is gone: they now move to Completed about 20 seconds later and can be updated or shut down when idle - Changed the "Press ← again" confirm on a just-cleared prompt: a second ← no longer has to wait a second before it switches, and holding ← down now switches too - Changed the errors shown when the `/ultrareview` upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text - Changed `/code-review` at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5 - Changed an in-process teammate's `agent_id` in Agent results to its agent ID (its `name@team` address stays in `teammate_id`); TeammateIdle hooks no longer fire from its subagents or forks - Changed background sessions waiting on a scheduled wakeup (`/loop`): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup - Changed `/model`, `/effort` and `/rename` sent from `claude agents` to a busy background session to apply right away, without a confirmation, instead of when the turn ends - Changed the Claude apps gateway's minimum supported PostgreSQL version from 14 to 11 - Changed the interactive session's WebSearch budget to refill over time (100 calls/hour; `CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR` sets the rate, 0 turns it off) instead of ending after 200 calls - Changed `CLAUDE_CODE_DISABLE_ATTACHMENTS` so a repository's `.claude/settings.json` or `.claude/settings.local.json` can no longer set it; shell, user and managed settings still can - Changed `claude plugin update` on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins - Changed the built-in `gh api` in cloud sessions: a host other than github.com set in `GH_HOST` or `GH_REPO` is now refused (use `--hostname` or a full URL), and stderr notes requests to other hosts - Changed the `claude-api` skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the `auto` permission policy - Self-hosted runners: Changed `claude --environment ` to create its session through the current Sessions API; printed and JSON session ids keep their session_… form - [VSCode] Added a screen reader announcement, "Message queued.", when you send a message while Claude is working - [VSCode] Added a way to review and run a plugin marketplace's install or update command from the Manage plugins dialog - [VSCode] Fixed a blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place - [VSCode] Fixed settings dialogs blaming a timeout when Claude Code stopped unexpectedly during a save - [VSCode] Fixed the branch switch dialog offering to switch when it could not check for uncommitted changes - [VSCode] Fixed a permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it - [VSCode] Fixed sign-in and new sessions giving no clear reason when Claude Code cannot find or start its program - [VSCode] Fixed the agent map showing a nested sub-agent with "Tool calls (0)" and placing the agents it starts under the main agent - [VSCode] Improved Continue After Reload: tabs reopened after VS Code restarts its extensions now also finish a step the restart interrupted - [VSCode] Improved file pills in messages: hovering one now shows the file's path from the project folder, so same-named files can be told apart - [VSCode] Changed message timestamps to show by default (turn them off with the Claude Code: Show Message Timestamps setting) - [Cloud sessions] Fixed turning off prompt suggestions through a cloud environment's environment variables having no effect in new cloud sessions - [Cloud sessions] Fixed the working indicator in a cloud session spinning on for several seconds after Claude's reply had finished; it now stops with the reply - [Cloud sessions] Fixed History on a never-run routine's page still saying "No runs yet" after you pressed Run now; it now shows the new run - [Cloud sessions] Fixed an unarchived cloud session looking as if Claude were still working until you sent another message - [Remote Control] Fixed a computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds - [Claude Tag] Added fast mode in Slack: mention Claude with `!fast` to switch a thread to fast mode, moving it to Opus if needed, and `!fast off` to switch back; replies show (fast) while it's on - [Claude Tag] Added the optional Path prefixes field when creating a custom connection in an access bundle, so its allow rule can cover only those paths instead of the whole host - [Claude Tag] Fixed members with the Claude Tag Admin permission getting "Couldn't load memory files" on the Activity page's Memory tab; they can now read workspace and channel memory - [Claude Tag] Fixed a workspace guest's Confirm on a Claude settings card in Slack removing its buttons for everyone; only the guest sees the refusal, and members can still confirm or cancel - [Claude Tag] Fixed scheduled routines in Slack channels running on a model other than the channel's default; each run that starts a new session now uses the current default model - [Claude Tag] Fixed GitHub repositories in an access bundle attached by a channel-name rule being refused in the channels the rule covers; Claude can now add, list and clone them there - [Claude Tag] Improved Claude's notice in your direct messages when your own Claude plan's usage limit is reached: it shows within seconds and says when the limit resets - [Claude Tag] Improved the earlier Claude in Slack app's reply when it can't start a session: it now says what failed and who can fix it, in full only once per thread - [Claude Tag] Changed the channel instructions limit to 8,192 characters instead of bytes, so non-English text gets the same room, and added a character count beside Save on the Configure page - [Code Review] Fixed blocking review comments sometimes opening with a "nit" label that contradicted their severity - [Code Review] Fixed tips to comment "@claude review" being posted on fork and Manual-mode pull requests in organizations that have turned Code Review off ## 2.1.289 - Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines - Fixed the terminal freezing on short code blocks with many unclosed `