Skip to content

Releases: anthropics/claude-code

v2.1.293

Choose a tag to compare

@ashwin-ant ashwin-ant released this 07 Oct 18:10
Immutable release. Only release title and notes can be modified.

What's changed

  • Added Claude Haiku 5.5 (claude-haiku-5-5), now the default Haiku model on the Anthropic API — 1M context, $0.10/$0.50 per Mtok ($0.50/$2.50 for prompts over 100K)
  • Added agentType to the subagentStatusLine payload, so scripts can tell custom subagent types apart
  • Added isDeferred to $.tool.register for mods: false lists the tool's schema in the prompt from the start instead of behind tool search
  • Fixed Claude sometimes treating its own last actions before a context compaction as done after it, and retracting or redoing finished work
  • Fixed a memory leak where an HTTP MCP connection kept every request it had sent until it closed
  • Fixed a message sent while Claude was working being lost when ← moved the session to the background; if a queued message can't move, ← now stays put and says so
  • Fixed /model effort ←/→ wrapping past the highest or lowest level, which could accidentally save Low as a model's default effort
  • Fixed /tui disconnecting Claude in Chrome in a session started with --chrome, and ignoring --no-chrome
  • Fixed Claude being told to continue or message subagents with SendMessage in sessions, including resumed ones, where a host, a permission rule or a --tools list removed that tool
  • Fixed subagents and --agent sessions being told a built-in tool was disabled for the whole session when only their own tool list left it out
  • Fixed a claude.ai-synced skill's edited description sometimes not reaching the model until a new conversation or /clear
  • Fixed claude logs, stop, kill, rm and claude daemon status, stop, uninstall sometimes signing you out when your login had expired or was about to
  • Fixed the footer's agents count disappearing after a momentary failure to read the sessions folder (for example, too many open files)
  • Fixed a custom agent named worker being shown as "Agent" when it starts, and the agent detail dialog's title losing the agent type once the agent finishes
  • Fixed the Artifact tool's transcript row briefly reading Artifact("(unprintable path)") while a publish call was still streaming in
  • Fixed the /ultrareview upload on Linux wrongly refusing some repositories, such as one inside another checkout, over a settings file that "could not be parsed" while a sandboxed command was running
  • Fixed the /ultrareview upload's refusal over split-index files advising a git command that could leave git unable to read its index
  • Fixed replies in very long Remote Control and cloud sessions that could still appear a block at a time instead of streaming in
  • Fixed Remote Control uploading a session's starting history again after every credential recovery
  • Fixed PushNotification reporting "Remote Control inactive" in sessions started with claude remote-control
  • Fixed a mod's hooks on classic.* events being skipped while the plugin hooks worker restarts, which left settings hooks to answer without them
  • Fixed claude plugin test failing for mods that call $.session.append; tests can read the appended rows back with the new mock.session
  • Fixed claude plugin eval refusing every Bash-granting run on Macs with Docker Desktop (links under ~/.docker/bin); the refusal now names which part of a credential store held the link
  • Fixed the Claude apps gateway refusing to start when a desktop policy sets Claude Desktop's built-in browser keys, such as builtinBrowserEnabled
  • Fixed claude agents offering bypass permissions that background sessions then ignored when consent was saved only in .claude/settings.local.json or a --settings file; it now asks for consent first, and a session that ignores bypass shows a short notice that stays
  • Fixed ← backgrounding a session after 10 seconds while the prompt held unsent text (it now cancels the move) or a question was waiting for your answer
  • Fixed Esc, or No without feedback, on a permission prompt not stopping the turn when ← had just been pressed to move the session to the background
  • Fixed the agents view briefly replacing the session list with placeholder rows when the sessions folder could not be read (for example, too many open files)
  • Fixed path-scoped rules and nested CLAUDE.md files not loading when Claude views a file with a single-file cat, head, tail, sed -n or grep command in the Bash tool instead of the Read tool
  • Fixed pasted text that begins and ends with the same words sometimes being sent to Claude as if it had been typed
  • Fixed a skill name in pasted text being treated as typed when an accent typed or pasted right after the paste merged into its last letter
  • Fixed /feedback returning to the drafts list after Ctrl+O or Ctrl+Z while a report was sending, leaving the send impossible to cancel
  • Fixed claude purge stopping silently (exit 0, or a hang in a terminal) when a file or folder could not be deleted; it now deletes the rest, lists what it could not delete, and exits 1
  • Fixed keybindings.json checks: a lone " " (space key) is no longer reported as an error, and keys like "ctrl+ k" now get a warning
  • Fixed vim mode >> and << on a line of only spaces leaving the cursor past the end of the line, where a following x deleted nothing
  • Fixed vim mode: after deleting whole lines in Visual mode (V then d) the cursor lands on the first non-blank, and . after it acts on the cursor's line
  • Windows: Fixed stopping a status line, hook, or shell command sometimes terminating an unrelated process that had been given the same process ID
  • Reverted the auto mode denial message change from 2.1.281 that told Claude a denial covers the outcome, not only the exact command
  • Reverted the 2.1.290 fix for cloud sessions staying asleep after a container restart lost a pending /loop wakeup or scheduled task; Claude is no longer told, and the session stays asleep
  • Improved startup for Team and Enterprise organizations: policy and managed settings are fetched earlier, and a stalled request is retried after 3 seconds
  • Improved Claude in Chrome: fewer page actions are refused when the browser is slow to report its tabs
  • Improved the Claude in Chrome message in cloud sessions when the browser can't be reached: if you belong to more than one organization, it now says the extension must be signed in to the same one, and how to change that
  • Improved the Bash edit diff note to say the listed files changed while the command ran, which can include writes by other processes
  • Improved artifacts: Claude pins libraries to exact versions two weeks old or older
  • Changed claude.ai skill syncing to check for changes about every 40 minutes, instead of every 10, while no session is in use
  • Changed the order of agent lists and of MCP servers announced to the model: names with non-ASCII characters now sort after ASCII names
  • Changed OpenTelemetry claude_code.at_mention logging to emit at most 100 agent and 100 MCP-resource events each time a prompt is read
  • Self-hosted runner: Changed the orchestrator to sleep 4 to 6 seconds between polls instead of a constant 5, so several replicas for one environment stop polling at the same moment
  • [Claude Tag] Fixed Claude in Slack saying a workspace isn't set up in Enterprise Grid channels shared across workspaces when Slack labels a message with a workspace that isn't connected
  • [Claude Tag] Fixed Claude in Slack stopping mid-task in a channel when an admin changed the channel's connectors, plugins, skills or rules; the change now applies once Claude finishes
  • [Claude Tag] Fixed asking Claude in Slack to run a thread's routine now with extra notes starting a separate run that couldn't post back; the run now continues in that thread
  • [Claude Tag] Fixed an access bundle's Add a connector dialog in Claude Tag admin settings showing every Google connector as connected after one Google sign-in
  • [Claude Tag] Improved Claude Tag admin settings to list an Enterprise Grid that isn't connected yet, with a Connect button
  • [Claude Tag] Changed Claude in Slack to join announcement channels, where only admins can post, without posting its intro
  • [Claude Tag] Changed the limit on channel rules in Claude Tag admin settings from 20 to 50 for each workspace and for the organization-wide Slack page
  • [Code Review] Improved Code Review's Add a repository dialog to list each repository that couldn't be added and why, such as missing GitHub write access

v2.1.292

Choose a tag to compare

@ashwin-ant ashwin-ant released this 06 Oct 18:59
Immutable release. Only release title and notes can be modified.

What's changed

  • Added --marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
  • Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
  • Added CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
  • Added prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
  • Added prompt caching to $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
  • Added workflow agents to the agent.spawn mod hook, with their run and index, so a mod can refuse them
  • Fixed subagent definitions with permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
  • Fixed sandboxed commands being able to read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin
  • Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers
  • Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
  • Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed
  • Fixed rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
  • Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths
  • Fixed a skill's or slash command's allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
  • Fixed NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
  • Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it
  • Fixed claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
  • Fixed one-shot claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
  • Fixed plan mode not being restored when resuming a session from the claude --resume session picker or with /resume
  • Fixed saved scheduled tasks created after /resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
  • Fixed a background session's /loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
  • Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you
  • Fixed the Read tool returning only the first entry, with no error, when a PDF's pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
  • Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file's size and to read it in portions
  • Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation
  • Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE
  • Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse
  • Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued
  • Fixed /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
  • Fixed /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
  • Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt
  • Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
  • Fixed /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
  • Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and ! leaving the row selected
  • Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2's scrollback with stale pages
  • Fixed a spurious "could not be examined" note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink
  • Fixed "instruction file not loaded" lines going stale or missing after /cd or a permission change, and added a transcript line when a nested one isn't loaded
  • Fixed a compaction summary that repeated /name letting Claude invoke a skill that is reserved for the user
  • Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason
  • Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished
  • Fixed cloud sessions with a large transcript sometimes asking for a permission again after it was approved
  • Fixed scheduled tasks and other queued notifications being lost in cloud sessions when a message was retried or edited while Claude was reading them
  • Fixed cloud sessions forgetting the thinking setting chosen in the client when the session's container restarted
  • Fixed Cowork cloud sessions saying a proxy blocked artifacts when Anthropic couldn't confirm the organization's settings
  • Fixed plugins whose hooks module makes many $.state calls through one const taking minutes to load or validate
  • Fixed claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere
  • Fixed claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused
  • Fixed a plugin's served $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end
  • Fixed plugin interface calls made while the plugin hooks worker restarts running without the hooks other plugins put on them
  • Fixed a mod's config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name
  • Fixed /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked
  • Fixed a plugin's tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog
  • Fixed a mod's start-up prompt, command or subagent being queued a second time when the hooks worker was replaced
  • Fixed a mod's hook that called next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected
  • Fixed a plugin's prompt drop or setting deny being ignored when its reason was longer than 4,096 characters
  • Fixed an organization's plugin being unloaded on its own reload, or after another plugin crashed, when it returned a $ name that a user-installed mod had added; the mod is now unloaded instead
  • Fixed tool calls made while the plugin hooks worker restarts being answered without the plugins' permission hooks
  • Fixed plugin tool.call hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with
  • Fixed a mod's guard hook with a .catch being skipped silently for calls another mod's hook makes beneath the guard's own $ call; its .catch is now asked
  • Improved startup of claude -p and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer resources/list
  • Improved rendering speed of long bulleted or numbered replies: they stream, resize and re-open in the transcript (ctrl+o) much faster
  • Improved Ctrl+C draft recovery: a cleared prompt now stays reachable with Up after a slash command or a sent message
  • Improved hook output handling: <system-reminder> tags written in a hook's output are escaped before they reach Claude
  • Improved tool input handling: Grep accepts file_path for path, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call
  • Improved the steps shown when a marketplace declared in a settings file has a name that looks like an official Anthropic marketplace
  • Improved sandbox auto-allow: with strict sandbox mode set in user, managed or --settings settings, an interpreter command with an env var prefix like FOO=bar python3 app.py runs unprompted
  • Improved the Artifact tool's listing: Claude now sees how many published artifacts you have and can list up to 200 at once instead of 50
  • Improved cloud sessions after a restart: Claude is now told which stopped background agents it can resume by id
  • Improved the Claude in Chrome message in claude.ai cloud sessions when the browser can't be reached: Claude is now told it may continu...
Read more

v2.1.291

Choose a tag to compare

@ashwin-ant ashwin-ant released this 06 Oct 03:55
Immutable release. Only release title and notes can be modified.

What's changed

  • Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts
  • Fixed a regression in 2.1.288 where the last messages of a session could be lost when quitting

v2.1.290

Choose a tag to compare

@ashwin-ant ashwin-ant released this 05 Oct 23:33
Immutable release. Only release title and notes can be modified.

What's changed

  • Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
  • Added agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
  • Added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool
  • Added ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
  • Added to claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)
  • Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds
  • Added claude attach <name> and claude logs <name>: part of a session name works in place of the id
  • Added /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as ant apply files
  • Added /claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as deep-researcher, with the ant CLI
  • Added a warning when a managed settings file is a link to a file outside the managed settings folder
  • Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains
  • Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta
  • Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors
  • Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown
  • Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run
  • Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an offset to read on
  • Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep
  • Fixed /rewind not listing a prompt sent while Claude was still working
  • Fixed scheduled tasks (/loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on
  • Fixed scheduled tasks set in the foreground never firing after a ← or /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork
  • Fixed headless --json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered
  • Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy
  • Fixed a project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule
  • Fixed URL allow and deny patterns with a wildcard inside an xn-- host label matching differently from one process to the next
  • Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions
  • Fixed /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved
  • Fixed the plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux
  • Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in
  • Fixed the background daemon's log passing terminal control characters to the screen under claude daemon run and claude daemon logs; they now show as \uXXXX escapes
  • Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds
  • Fixed a plugin hook with a .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call
  • Fixed a mod's turn.step result listing a tool call that a mid-response model fallback had discarded
  • Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file
  • Fixed claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions
  • Fixed /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration
  • Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings
  • Windows: Fixed multi-line ! shell blocks in skills and commands failing when the file is saved with CRLF line endings
  • Fixed Claude Code hanging until killed when a /permissions tab was clicked while searching in fullscreen mode
  • Fixed conversation compaction sometimes failing with a "null is not an object" error
  • Fixed plugin hooks reading an empty answer on turn.complete for a subagent that hands its report back in auto mode
  • Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded
  • Fixed a mod's prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name
  • Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing
  • Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
  • Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded
  • Fixed disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents
  • Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing
  • Fixed an @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed mid-read
  • Fixed Esc in the agents view confirming "Press enter again to restart this session — it isn't responding"; Esc now just reopens the session
  • Fixed agent view losing a background session's /loop run count, countdown and live status line after the session enters a worktree that it creates
  • Fixed claude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt
  • Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on declare, typeset, export or readonly
  • Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder
  • Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded
  • Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters
  • Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted
  • Fixed You should know writing its notes in English regardless of the language setting
  • Fixed a freeze after sending some very long messages
  • Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing
  • Fixed claude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation
  • Fixed Esc after an n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section
  • Fixed claude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted
  • Fixed /ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver
  • Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore
  • Fixed claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why
  • Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt
  • Fixed agent view's /loop run count freezing and its countdown disappearing after /clear; the count now restarts with the new conversation
  • Fixed --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt
  • Fixed /chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (#98135)
  • Fixed mods staying off for people who reach Claude through a gateway (ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account
  • Fixed replies sent from claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts
  • Fixed slash commands and answers to a multiple-choice question that claude agents could not deliver to a running session being saved and sent by themselves the next time it was restarted
  • Fixed sandboxed c...
Read more

v2.1.289

Choose a tag to compare

@ashwin-ant ashwin-ant released this 03 Oct 23:07
Immutable release. Only release title and notes can be modified.

What's changed

  • Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
  • Fixed the terminal freezing on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions
  • Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink
  • [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent
  • Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
  • Fixed plugin list, plugin eval and plugin update showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir
  • Fixed installed mods not loading in the first session after an upgrade
  • Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
  • Fixed plugin panes drawing nothing when a link used a localhost address, an @ in its path, an uppercase host or a file: path
  • Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
  • Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
  • Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
  • Fixed sessions ending with an interface error when a plugin region with no height kept growing
  • Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands
  • Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
  • Fixed claude plugin validate skipping the plugin when the folder also holds a marketplace manifest
  • Added agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list()
  • Fixed sessions ending with "unrecoverable interface error" when a value a mod's ui.render hook wrote made a row throw while drawn; the engine now draws its own row instead
  • Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
  • Fixed right-aligned content in a mod's pane or band drawing under the close mark or [-], which now also keep one column in from the terminal's edge
  • Fixed a mod's Client that fails while drawn taking down everything the mod drew around it; it now fails alone and raises ui.fault
  • Fixed claude plugin validate failing an Anthropic marketplace's own plugin and listing a clean plugin.json in --json
  • Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
  • Fixed a failed plugin component showing Error or nothing as its reason when the failure carried no message
  • Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
  • Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed <script> tags
  • Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it

v2.1.288

Choose a tag to compare

@ashwin-ant ashwin-ant released this 02 Oct 20:19
Immutable release. Only release title and notes can be modified.

What's changed

  • Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
  • Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
  • Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images
  • Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call
  • Added --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
  • Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json
  • Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab
  • Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried
  • Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage
  • Fixed --resume sometimes dropping files and other context that a compaction had just restored
  • Fixed a resumed session sometimes not saving the last response of a turn, so that the next --resume showed the prompt unanswered
  • Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load
  • Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking
  • Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off
  • Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash
  • Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent
  • Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it
  • Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes
  • Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device
  • Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted
  • Fixed a plugin's pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code
  • Fixed plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults
  • Fixed a plugin's tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree
  • Fixed git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)
  • Fixed plugins loaded with --plugin-dir not showing "Configure options" in /plugin
  • Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running
  • Fixed sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references
  • Fixed Bash tool permission check to prompt before a BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently
  • Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt
  • Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn
  • Fixed OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals
  • Fixed permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event
  • Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved
  • Fixed unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts
  • Fixed /login reporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (#73861)
  • Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request
  • Fixed a second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in
  • Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults
  • Fixed headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it
  • Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses
  • Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed
  • Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named memory
  • Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with disableAutoMode or an older model); typing, navigation and JavaScript still ask
  • Fixed claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice
  • Fixed sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on
  • Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings
  • Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, /tui)
  • Fixed a stall when launching an agent whose tools: lists very many Agent(...) entries
  • Fixed sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation
  • Fixed the npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder claude stub was installed
  • Fixed Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process
  • Fixed owner/repo plugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top
  • Fixed path-scoped .claude/rules and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)
  • Fixed a dangerous rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule (#96300)
  • Fixed LSP tool calls hanging indefinitely when a language server uses dynamic capability registration or stops responding; requests now time out after 60s (per-server requestTimeout)
  • Fixed idle_prompt notification hooks firing while background agents are still running (#93672)
  • Fixed PreToolUse and PermissionRequest hooks being skipped when matching them failed or the tool's input could not be serialized to JSON; the call is now blocked
  • Fixed the first request in a fresh environment or after a model switch using the built-in output limit and auto-compact window, not the server's; that request may now wait up to 1.5 seconds
  • Fixed the "What should Claude do instead?" hint showing on the Interrupted row after sending queued messages with ctrl+enter
  • Fixed /login in a --bare session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work
  • Fixed the InstructionsLoaded hook omitting agent_id and agent_type when a subagent's file access loads a rule or nested CLAUDE.md; rules and nested CLAUDE.md files loaded on file access now also report effort
  • Fixed the Agent tool in claude mcp serve always reporting no available agents and rejecting every subagent_type
  • Fixed the terminal cursor not following the typed text in the fullscreen transcript viewer's search and in /theme's custom color search
  • Fixed /permissions in screen reader mode: typing a rule's number now picks it instead of opening the search box
  • Improved auto mode: when a conversation grows too long for the client-side safety classifier to review, it is now compacted instead of prompting for, or failing, every tool call
  • Improved screen reader mode: short announcements, such as a deleted word, now stay on screen until your next key press or until something above them on screen changes
  • Improved screen reader mode: answered questions in question dialogs now say "answered" beside their box
  • Improved the /usage-credits message shown to Team and Enter...
Read more

v2.1.287

Choose a tag to compare

@ashwin-ant ashwin-ant released this 01 Oct 18:00
Immutable release. Only release title and notes can be modified.

What's changed

  • Added Claude Mods: plugins may now modify deeper behavior
  • Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin (for first-party sessions with telemetry on)
  • Added an n:<text> filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match
  • Added prompt_text to the OpenTelemetry user_prompt event, a copy of prompt for backends that nest dotted keys; drop or mask it wherever you drop or mask prompt (#70763)
  • Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry
  • Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool
  • Self-hosted runner: Added a built-in gh api (REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed
  • Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it
  • Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries
  • Fixed hooks configured with asyncRewake waking Claude over and over with "found issues" notifications when the hook's script file is missing; the broken hook is now reported once
  • Fixed tool heartbeats not reaching SDK hosts while the model's response stream was stalled with no data arriving
  • Fixed Bedrock and Vertex startup model checks ignoring an enforced availableModels list, which could collapse /model to one Opus row
  • Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached
  • Fixed picking Fable in /model on a claude.ai login saving the current version's id, so your saved default now follows the newest Fable like Opus and Sonnet do
  • Fixed switching between Opus 5.5 and Sonnet 5.5 (/model, opusplan) rewriting earlier MCP tool announcements, which could drop earlier extended thinking
  • Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail's message when the reply began with thinking
  • Fixed a dangerous rm (such as one on / or the home directory) losing its always-ask safeguard when the same command also redirected output to a ~ or wildcard path
  • Fixed claude -p and SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running
  • Fixed a folder's CLAUDE.md being attached a second time after resuming a session or after a compaction
  • Fixed background sessions that could not be reopened from claude agents after the agent exited and removed the worktree the session was started in
  • Fixed /advisor pairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped
  • Fixed Bash permission prompts showing internal parser names such as "Contains simple_expansion" instead of a plain explanation
  • Fixed a cause of fullscreen sessions on slow or busy machines exiting with "Claude Code exited after an unrecoverable interface error" while a scroll key was held in a long conversation
  • Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named __proto__
  • Fixed Claude being told to page large MCP results saved as JSON with Read's offset and limit, which cannot split one long line
  • Fixed the commit attribution reminder being delivered inside a tool result after a compaction
  • Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields
  • Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional
  • Fixed screen reader mode showing a "Tab to amend" hint on approval prompts, where Tab does nothing
  • Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying "Select with numbers" in empty menus or while a search box has the keys
  • Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs
  • Fixed screen reader mode sending the claude --teleport progress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame
  • Fixed CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS not removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject
  • Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window
  • Fixed --include-partial-messages sending a cut-short reply's message_stop late or never, so apps could show the reply as still in progress
  • Fixed claude agents sometimes not showing the permission prompt a background session is waiting on
  • Fixed /ultrareview giving advice about .git/info/attributes when the upload stops on a committed .gitattributes it cannot read, such as one saved as UTF-16
  • Fixed claude remote-control failing to register behind an HTTP proxy with a misleading "Check your organization permissions" error (#97352)
  • Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable
  • Fixed the running-tool dot and three spinners still moving with the "Reduce motion" setting on, and /rewind's confirm screen updating its "ago" time while you type a note
  • Fixed times in claude agents changing every second in screen reader mode; they now change at most every 10 seconds
  • Fixed a revoked claude.ai login showing a generic API Error: 401 instead of "OAuth token revoked"; in -p mode the error now starts with "Failed to authenticate"
  • Fixed /ultrareview upload refusals advising you to copy a variable named by a repository's settings file into your own user settings
  • Fixed --output-format stream-json and the SDK not streaming the turns of a context: fork skill run by typing /<skill> as the prompt, as they do for the Skill tool's fork
  • Fixed /feedback and /bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report
  • Fixed claude plugin marketplace add --sparse and git-subdir plugin installs failing with "transport 'http' not allowed" when the repository is served over plain http
  • Fixed cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted
  • Fixed a plugin reload that overlapped the startup --plugin-url download corrupting the session's cached copy of the plugin archive
  • Fixed /desktop quoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause
  • Fixed an MCP connector tool call occasionally running twice, or the connector's calls failing until restart, when its server changed which MCP protocol version it supports
  • Fixed SessionStart hooks from synced plugins not running in new cloud sessions
  • Fixed the transcript's "N hooks ran" summary and the verbose debug log's matched-hooks count including Claude Code's internal callbacks, so one configured hook no longer shows as two
  • Fixed files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds
  • Fixed repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory
  • Fixed PNG, JPEG and WebP images over 8,000 pixels on a side failing to send from a remote session; Claude now sends a scaled-down copy
  • Fixed messages sent from the Claude apps with 17 to 20 attached files delivering only the first 16
  • Fixed headless sessions reporting an MCP server as needing authentication after one refused call, even though later calls succeed
  • macOS: Fixed Remote Control sessions started with claude remote-control stopping mid-turn when the Mac went to idle sleep
  • Windows: Fixed interactive claude hanging or crashing with "Raw mode is not supported" when its input is piped or redirected; it now says why and exits (use -p for piped input)
  • Bedrock, Vertex, Mantle: Fixed model availability checks under CLAUDE_CODE_SKIP_*_AUTH sending a different Authorization header than real requests when ANTHROPIC_CUSTOM_HEADERS repeats it
  • Improved /config: settings that cycle show ‹ › and step both ways with ←/→, narrow terminals stack each value under its label, and PgUp/PgDn page the list
  • Improved plugin marketplace errors to say in plain words why a marketplace was ignored or refused, and what to do
  • Improved plugin listings to note when a plugin's dependencies were not installed, and updating a plugin now retries an install that did not finish
  • Improved the Claude apps gateway's error when Amazon Bedrock rejects a model ID: developers now see which model is unavailable, and the gateway log names the ID that was sent
  • Improved SDK sessions so a message sent with priority "now" no longer cancels a running web fetch or web search; it keeps loading in the background
  • Improved /memory: the left and right arrow keys now flip its on/off settings, such as Auto-memory
  • Improved /skill names typed mid-message: Claude is now told they are skills, including disable-model-invocation ones
  • Improved the contrast of the prompt input border in light themes and of the ❯ before your earlier messages
  • Improved delivery of files Claude...
Read more

v2.1.286

Choose a tag to compare

@ashwin-ant ashwin-ant released this 30 Sep 19:10
Immutable release. Only release title and notes can be modified.

What's changed

  • Added a count such as "2 of 5" to the permission prompt when several permission requests stack up
  • Added mouse support for the "N more" rows of lists in fullscreen mode: click one to jump to that end of the list, with hover and pressed states
  • Fixed several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire
  • Fixed claude --resume and --continue sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed
  • Fixed API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions
  • Fixed cloud sessions with very large histories never waking up because the container was stopped while the transcript was still loading
  • Fixed the Claude apps gateway's spend meter pricing 1-hour prompt cache writes at the cheaper 5-minute rate, and counting only the first model call's input tokens on streamed turns that run a server-side tool such as web search
  • Fixed macOS sessions still showing "Not logged in" or "Login expired" after /login succeeds in another Claude Code window when a leftover ~/.claude/.credentials.json exists
  • Fixed every turn failing when the Anthropic API refuses the model your default or a model alias resolves to: Claude Code now retries once on the previous model of the same tier
  • Fixed Remote Control sessions (including claude remote-control) staying connected after your organization's policy turns Remote Control off; they now disconnect with a notice
  • Fixed refusal and --fallback-model retries failing when the fallback model can't run fast; they now run at standard speed, with a one-time notice in interactive sessions
  • Fixed headless sessions repeating the "MCP servers require authentication" reminder after a successful re-authentication when the MCP discovery cache is enabled
  • Fixed claude auth status reporting a Console sign-in's stored API key as claude.ai; it now reports api_key, and the VS Code extension treats that session as an API key session
  • Fixed /status listing an Anthropic profile beside an API key as if both were in effect; the profile is now marked as not in use
  • Fixed Claude not being told when a file attached to a message sent over Remote Control did not arrive, and a file sometimes getting only 10 seconds for its last download try
  • Fixed a Remote Control message that arrived while Claude Code was exiting being marked delivered and then never answered; it now stays queued for the session's next run
  • Fixed MCP error messages showing a credential's value when "Bearer" or "Basic" came before its key name
  • Fixed percent-encoded Bearer tokens being only partly masked in error messages
  • Fixed redacted logs and transcripts showing a secret whose key name has an invisible character inside, such as a zero-width space
  • Fixed logs and transcripts showing part of a URL password that contains punctuation such as ), quotes, ], & or a second @, or that runs past a / to a bracketed host such as [::1] in an ssh URL
  • Fixed the session transcript in the zip that /feedback saves to disk containing invalid JSON lines after secret redaction
  • Fixed MCP connectors listing no tools for up to a day after their server dropped the older MCP handshake
  • Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working
  • Fixed /usage not crediting an MCP server for a tool call made while that server was still connecting or had only just connected, such as right after a restart
  • Fixed plugins enabled on claude.ai occasionally going missing from Claude Code for a session after a transient server error
  • Fixed a message typed into a running subagent showing twice in its transcript after the subagent read it
  • Fixed subagent hand-back messages showing a raw task id instead of the agent's name when the subagent had no registered name
  • Fixed foreground subagents sometimes missing the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions that have them enabled
  • Fixed subagents spawned with worktree isolation loading the project CLAUDE.md and its imports a second time from the worktree copy on their first file read
  • Fixed Workflow tool subagents being restarted from their original prompt when a connection stalled for a few minutes mid-response
  • Fixed /compact, /clear, and /rewind typed while viewing a background agent's or teammate's transcript silently acting on the main conversation: a dialog now names the target and asks first
  • Fixed background jobs showing done while waiting for your approval
  • Fixed the commit attribution reminder being re-sent inside tool output when a model fallback lasts only one turn
  • Fixed a click on the space between words of a collapsed row (such as "Thought for 4s") highlighting the row without expanding it in fullscreen mode
  • Fixed a row with no details, such as an action row with a long name, pushing every other row's details to the right in list screens
  • Fixed files with very long names not reaching a cloud session when attached to it
  • Fixed plugin errors for a marketplace Claude Code refuses to load: they now say why and how to fix it instead of "not found"
  • Fixed /plugin's Discover tab showing a marketplace name unquoted in its "Checking … for new plugins" line when its rows already show that name in quotes
  • Improved commit guidance: when your project or user skills include one named verify, Claude is now told to run it right before committing, except for docs-only and tests-only commits
  • Improved send now (ctrl+enter) in a subagent's view: it now moves the subagent's running command to the background so your message is read right away
  • Improved replies from background agents to your messages so they no longer open with a separate recap of what you said
  • Improved claude.ai artifact link reads: WebFetch now asks the same questions as the Artifact tool's read (no artifact prompt while the session's network access is on, one per artifact while it is off), and an auto-mode yes no longer counts where only you can answer
  • Improved fetch, skill, file read, sandbox network, Claude in Chrome, workflow script and notebook edit permission prompts to match the look of file edit prompts
  • Improved Bash, PowerShell and Monitor permission prompts to show the command between dashed lines, matching file edit prompts
  • Improved list scrollbars in fullscreen mode: in most lists the bar no longer shifts as the "N more" rows come and go, and it now has ↑/↓ arrows you can click or hold to scroll
  • Improved the external editor (Ctrl+G): editors that take a line number now open on the line your cursor is on in the prompt
  • Improved slash command suggestion responsiveness while typing when many skills or plugin commands are installed; command descriptions now match by word prefix
  • Improved the output style picker: it now opens on your current style instead of Default, with each style's description on the line under its name; number keys no longer pick a style
  • Improved /hooks: the closing line of a hook's detail screen now says "this hook" instead of "it"
  • Improved the model fallback notice and the autocompact-thrashing error to say when a fallback dropped the context window from 1M to 200K tokens
  • Improved responsiveness of SDK and -p sessions when a host re-sends an MCP server enable for a server that is already connected
  • Improved the protocol page a Claude apps gateway serves at /protocol: it now says not to reject unknown input and matches what Claude Code sends today
  • Changed prompts sent while nothing is running or queued to show in the normal text color right away instead of gray
  • Changed how failed API requests are retried: one limit now covers a whole model call, so with the default retry settings a failing call sends at most 14 requests
  • Changed --bare to connect only the MCP servers named on the command line, send the model no system reminders, and start no background tasks; under --bare, a shell command that reaches its timeout now stops instead of moving to the background
  • Changed the send-now key (ctrl+enter) to move a skill's own shell command to the background instead of ending it
  • Changed the WebFetch error for a rate-limited domain safety check to tell Claude not to retry it in a loop
  • Changed plugin installs to refuse npm sources that are git repositories or folders, and to install plugin dependencies only from registry packages
  • Changed list screens (/artifacts, /mcp, /skills, /hooks and others) to always line up each row's details in one column after the names
  • Changed the overflow rows of lists to read "↑ N more" / "↓ N more" instead of "N more above" / "N more below"
  • Changed /hooks to open on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three
  • Changed the theme picker to a scrolling list that fits your terminal instead of pushing the preview off screen; number keys no longer pick a theme
  • Changed /exit's Remove worktree to run after Claude Code stops the servers and shells it started there, which on Windows could keep the folder from being deleted
  • Changed the claude-api skill's Managed Agents examples to create environments with limited networking
  • Removed the browser link from /ultrareview and claude ultrareview output
  • Windows: Fixed claude --bg and the agents view refusing a folder that claude already trusts when its trust record was saved with different letter case
  • [VSCode] Added bookmarks: save Claude's responses and keep them in view in a Bookmarks side panel
  • [VSCode] Added the questions Claude asks and your answers to the conversation: after you answer a question card, a Questions row shows each question with your picks
  • [VSCode] Added option previews to question cards in the chat panel: the highlighted choice's mockup or ...
Read more

v2.1.285

Choose a tag to compare

@ashwin-ant ashwin-ant released this 29 Sep 19:27
Immutable release. Only release title and notes can be modified.

What's changed

  • Added CLAUDE_CODE_DISABLE_WEB_FETCH environment variable to turn off the WebFetch tool
  • Added claude --desktop to open the Claude desktop app on the current directory, or on a session with --continue / --resume <id>
  • Added claude plugin configure <plugin> to show a plugin's options and which are unset, or save new values read from stdin with --values-stdin
  • Added <server>.<key>=<value> to claude plugin install --config, so a bundled .mcpb MCP server's own settings can be set at install time and it starts without visiting /plugin → Configure
  • Added allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)
  • Added CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable to cap re-sends of a non-streaming fallback request that timed out
  • Fixed claude -p with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result
  • Fixed plugin and marketplace installs and updates over SSH ignoring the ssh program set in GIT_SSH or in your git config's core.sshCommand
  • Fixed Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file's policies. Other read errors and unparseable files stop every session
  • Fixed cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published
  • Fixed claude plugin disable and enable with a full name@marketplace id changing a settings entry in another letter case instead of the installed plugin's own
  • Fixed files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice
  • Fixed switching models mid-session with a set_model request (such as the Agent SDK's setModel) leaving the new model on the built-in output-token limit and auto-compact window until restart
  • Fixed redacted logs and transcripts showing part of a URL password that contains @, or all of it when the URL writes its @ as %40
  • Fixed SSH passphrase and new-host prompts from worktree and /teleport fetches taking over the terminal; these fetches now fail fast instead of asking
  • Fixed switching off an MCP server added mid-session in SDK and -p sessions leaving its tools available
  • Fixed claude -p --permission-prompt-tool: a background subagent's permission request now goes to the prompt tool instead of being auto-denied
  • Fixed claude mcp list and claude mcp get, and the not-found error of claude mcp remove, login and logout, printing line breaks and terminal escape sequences from MCP server names and values
  • Fixed sandbox auto-allow asking for approval on every run of many inline scripts (python3 -c, node -e) just because they contain =
  • Fixed fork subagents not keeping the session's plan mode or dontAsk mode: a fork now runs under its parent's permission mode and cannot exit plan mode
  • Fixed claude remote-control --help saying --[no-]chrome defaults to the machine's /chrome setting; spawned sessions keep Claude in Chrome off unless --chrome is passed
  • Fixed background subagents in auto mode prompting a second, redundant reply after each report
  • Fixed cloud session creation and /remote-env reading only the newest 20 of an account's environments
  • Fixed Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume)
  • Fixed installing a plugin with claude plugin install or /plugin putting it into an installed plugin's cache or data folder when their ids differ only in ., -, @ or (macOS, Windows) capitals; the install is now refused
  • Fixed hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response
  • Fixed the first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283
  • Fixed sessions that authenticate with ANTHROPIC_AUTH_TOKEN against the Anthropic API never loading the organization's policy
  • Fixed a failed agent(), parallel() or pipeline() call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session
  • Fixed synchronous hooks hanging Claude Code while a background process the hook started (for example some-daemon &) kept its output open; the hook now finishes shortly after its own process exits
  • Fixed WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block
  • Fixed the fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish
  • Fixed Amazon Bedrock mid-stream modelTimeoutException and serviceUnavailableException errors showing a raw JSON body instead of the error message
  • Fixed /autofix-pr and /schedule saying the Claude GitHub App is not installed on a repository whose install status had not been checked yet
  • Fixed dismissing a row (x) in /artifacts unlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it
  • Fixed Artifact tool publishes after a conversation rewind (Esc Esc) overwriting a file's newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file
  • Fixed an Artifact allow rule ("don't ask again") letting the Artifact tool publish a file outside the working directories without asking; add the file's folder with --add-dir for the rule to cover it
  • Fixed /cost and SDK modelUsage reporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected
  • Fixed the Artifact tool so that publishing a page no longer lets Claude overwrite its source file without re-reading it when Claude's earlier read was cut short or the file had changed since
  • Fixed auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else's artifact when you had approved that artifact earlier in another permission mode
  • Fixed a misleading "core.worktree is set" error from /ultrareview when the project folder briefly could not be read
  • Fixed /ultrareview on macOS and Linux failing to upload the working tree from a git worktree whose per-worktree config sets core.longpaths
  • Fixed the Artifact tool sometimes reporting a publish as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded
  • Fixed /ultrareview uploads including uncommitted changes to credential files whose name has a colon before the extension, such as server:8443.key
  • Fixed a rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time
  • Fixed the PowerShell tool's permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory)
  • Fixed /ultrareview uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks
  • Fixed a cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up
  • Fixed vim mode: after editing in the external editor (Ctrl+G), x or r in NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt
  • Fixed responses blocked by the API's output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter's error right away
  • Fixed plugins silently skipping a bundled .mcpb MCP server that still needs configuration: /plugin, the install message and claude plugin install now say so and point to Configure
  • Fixed compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields
  • WSL: Fixed /ultrareview refusing to upload a checkout on a Linux volume when a changed file's name has a colon or ends in a dot or space
  • Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had ended at --max-turns
  • Fixed sign-in that could wait forever after the browser showed success
  • Windows: Fixed /ultrareview uploading a linked worktree of a repository rooted at your home folder in some cases
  • Fixed cloud sessions reporting the uploads folder as missing before any file had been uploaded
  • Fixed a reply sent from claude agents to a background session waiting on a permission prompt sometimes approving the pending command
  • Fixed claude attach, logs, stop, respawn and rm starting a new session with the command name as its prompt when options came before it, such as from a shell alias
  • Fixed claude mcp list leaving out WebSocket (ws) MCP servers; each is now listed with its URL and health status
  • Fixed claude mcp get showing no Type, Command, Args, or Environment for stdio servers whose config entry omits the type field
  • Fixed .claude/settings.local.json allow rules being held back outside a git repository when git's trace2 output is configured
  • Fixed the /claude-api eval runner scaffold and report builder writing through a symlink or hard link planted at an output file
  • Fixed the /claude-api eval runner scaffold counting responses cut off at max_tokens in the score averages; they are now marked truncated and counted separately
  • Fixed &nbsp; showing as literal text in the ...
Read more

v2.1.284

Choose a tag to compare

@ashwin-ant ashwin-ant released this 28 Sep 18:02
Immutable release. Only release title and notes can be modified.

What's changed

  • Added Claude Sonnet 5.5 (claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads
  • Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones
  • Added dollar amounts to the Claude apps gateway spend limit in /usage and the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line's rate_limits.spend_limit also gains used_usd, limit_usd and period
  • Added effortSlider:decreaseEffort, increaseEffort and toggleUltracode keybinding actions, so the /effort slider's arrow and Tab keys can be rebound in keybindings.json
  • Added /rate-limit-options to /help and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find
  • Added /mcp reconnect all in the interactive terminal to retry every MCP server that failed to connect or needs authentication at once
  • Added Claude apps gateway startup warnings when a managed policy's availableModels is empty, or leaves out the model Claude Code starts on without setting model or enforceAvailableModels
  • Added auth: { google: {} } for Claude apps gateway telemetry.forward_to destinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials
  • Added certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets
  • Fixed a damaged response stream showing raw errors such as "JSON Parse error" or "undefined is not an object", or writing the word "undefined" into an answer, instead of being retried or reported as an interrupted response
  • Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried
  • Fixed "Prompt is too long" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation
  • Fixed a session whose model is unavailable, with no fallback model left, showing a bare "is currently unavailable" message (or "Something went wrong" in cloud sessions) instead of the model-unavailable notice and its Learn more link
  • Fixed Agent SDK sessions crashing when a user message contains an image with a malformed source, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note
  • Fixed MCP tool calls in a resumed session failing with "No such tool available" while their server was still connecting; the call now waits up to 10 seconds for the server
  • Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login: /usage, /extra-usage and IDE usage views now back off instead of re-asking
  • Fixed claude mcp add reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads
  • Fixed the /plugin configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs
  • Fixed ANTHROPIC_FOUNDRY_RESOURCE being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused
  • Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically
  • Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt
  • Fixed Bash tool failing on Windows with many plugins enabled: plugin bin/ directories that don't exist are no longer added to PATH, and inherited entries aren't added twice
  • Fixed sparsePaths plugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present"
  • Fixed fullscreen rendering erasing the terminal output above the session when [ in transcript mode writes the conversation to scrollback (macOS and Linux)
  • Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up
  • Fixed tab bars in dialogs such as /config and /plugin breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole
  • Fixed the /model picker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows
  • Fixed /keybindings writing Backspace and Delete bindings for a footer action that does nothing into the generated keybindings.json
  • Fixed a rebound agent panel close key (footer:close) typing "x" instead of itself on the row of the agent you're viewing
  • Fixed vim mode . not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as cw then Esc)
  • Fixed vim mode leaving the cursor on an image placeholder's opening bracket after dd on the last line or yy at the end of the prompt, where r or x would break or delete the image
  • Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted
  • Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory
  • Fixed rules symlinked into .claude/rules from outside the project being skipped without ever showing the external-imports approval prompt; a .claude directory symlinked from outside the project now asks for the same approval
  • Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval
  • Fixed a failed first claude plugin install leaving the plugin enabled and recorded when a dependency's version range could not be met
  • Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code
  • Fixed {"decision":"block"} returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does
  • Fixed sessions launched without the SendMessage tool (such as by Claude Desktop) still being told to message other sessions with it
  • Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption
  • Fixed typing a message during an automatic usage-limit wait taking the wait out of the "Continue automatically at usage limit" setting's control when that turn hit the limit again
  • Fixed usage-limit warnings suggesting /upgrade to users already on the highest Max plan; the warnings and /upgrade itself now point at /usage-credits when it is available
  • Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model
  • Fixed /loop status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text
  • Fixed /ultrareview failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux
  • Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory
  • Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private data/users/ subtree, and added a "view" level to as_level
  • Fixed the Claude apps gateway answering 431 Request Header Fields Too Large to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB
  • Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown
  • Improved the "No such tool available" error for Claude in Chrome tools called without their prefix: it now names the tool to call
  • Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged "Waiting for N … to finish" line after every event
  • Improved Workflow tool sandbox hardening for errors thrown by async script hooks
  • Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use
  • Improved /claude-api: hillclimb no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside report.html is built as one local file that loads nothing from the network
  • Improved lists such as /tasks, /copy and /hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edge
  • Improved claude plugin marketplace add to say when it replaces a marketplace already added under the same name from a different source, and how to undo it
  • Improved the startup refusal when managed settings require a sign-in (forceLoginMethod or `forceLogin...
Read more