Added a keybindingFlavor setting: set it to "readline" to make Ctrl+W in the prompt delete back to the previous whitespace, as in Bash; the default ("classic") is unchanged
Plugin marketplaces: headersHelper on a url marketplace or a catalog entry runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetches
A catalog entry's headersHelper runs only when you install or update that plugin, after its command is shown; claude plugin install/update ask [y/N] (or pass -y)
Added claude self-hosted-runner --defer-shutdown-max-min <minutes>: on SIGTERM, keep serving attached sessions, park what is left after that many minutes, then exit
Added claude self-hosted-runner --proxy-authorization-command / --proxy-authorization-file for egress proxies that require a freshly issued Proxy-Authorization header on every connection
Fixed unbounded memory growth in long interactive sessions: subagent tool results are now released once they leave the recent display window
Fixed custom, project, and plugin output styles drifting back to the default voice mid-session
Fixed CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true not keeping prompt suggestions on when your account is near, but not over, its usage limit
Fixed worktree-isolation Bash refusals telling you to remove a redirect when the command had none
Fixed self-hosted runners occasionally being removed by the server after a single slow or lost poll request, handing their healthy session to another runner
Fixed MCP elicitation dialogs showing nothing for URLs longer than 4,096 characters, and permission prompts dropping the "don't ask again" option when the project path didn't fit the terminal width
Fixed leftover /tmp/claude-*-cwd files when a Bash command is killed, times out, or is interrupted
Fixed held Backspace being ignored on terminals that send Ctrl+H for Backspace when keystrokes arrive in large bursts (slow SSH/mosh links)
Fixed text-wrapping in permission prompt diffs: lines containing wide multi-code-point characters (such as emoji) or tabs are no longer clipped
Fixed killing a suspended (Ctrl+Z) session sometimes leaving the terminal in bracketed-paste mode with the cursor hidden
Fixed stdio MCP servers receiving a server/discover request before initialize, forcing lazy servers to start their backend on every session open
Fixed a proxy's refusal of a connection being reported as a generic network error instead of naming the proxy
Fixed the /model and /effort cache-miss warning appearing when the prompt cache had already expired
Fixed per-task Stop from the Remote Control tasks panel doing nothing on CLI-hosted sessions
Fixed remote sessions exiting when a client delivered a user message without a valid role
Fixed Remote Control sessions started by claude remote-control inheriting session-scoped environment variables from the launching shell
Fixed a Remote Control session whose process crashed staying unavailable until claude remote-control was restarted; it can now be reused when you next message it
Fixed Remote Control messages sent from the web or Desktop while Claude is mid-turn disappearing from the transcript after the turn finishes
Fixed Remote Control model picks made on a phone or web not updating the model shown in the terminal
Fixed Remote Control disconnecting with "login expired" when a brief network hiccup delays renewing your sign-in; it now retries and stays connected
Fixed Remote Control reporting a failed reconnect on sign-out; signing out now ends the session with a clear message
Fixed ListAgents/SendMessage reporting "Remote Control is not connected" in sessions run by claude remote-control (server mode) or Desktop/IDE hosts; they now list and reach Remote Control peers
Fixed ListAgents and SendMessage exposing the idle worker that the agent view pre-warms for your next background session; it now appears only once a task claims it
Cross-session messaging: sending to a session on this machine that refuses inbound messages (e.g. crossSessionInbound: "refuse") now reports "refused" to the sender instead of a silent success
Cross-session messaging: a session whose inbox drops your messages (rate limit or full queue) now tells your session, instead of the messages vanishing silently
Improved startup: bare claude starts sooner on macOS
Improved Bash tool permission checking for zsh-specific syntax in shell conditionals
Improved Remote Control connection resilience: brief HTTP 403 refusals from a network edge, VPN, or proxy are now tolerated for up to 3 minutes, with the refusing party named when a block persists
Improved startup responsiveness: the automatic update check now runs about 10 seconds after launch instead of competing with startup for CPU
Updated the bundled claude-api skill for the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes
Changed Ctrl+L and Cmd+K in fullscreen to always just repaint — the double-press /clear shortcut was removed, and 1-row nvim terminals no longer trigger automatic /clear loops
Changed claude mcp list and claude mcp get to show disabled servers as ⊘ Disabled instead of connecting to them for a health check
MCP headersHelper in a project .mcp.json, and inline MCP servers in project or --add-dir agent files, now require that folder's trust dialog to have been accepted (also under claude -p)
MCP headersHelper from a project .mcp.json, plugin, or agent file runs without inherited credential env vars; user, managed and claude.ai-scope helpers now run from the Claude config dir
Added an optional spellcheck setting that underlines misspelled words in the prompt input as you type, using your installed aspell, hunspell, or ispell
Fixed whole-prompt-cache invalidation when a language server disconnected or reconnected mid-session
Fixed nested markdown list items misaligning at depth 3+ and added a hanging indent to wrapped list items in the terminal UI
Fixed prompt input highlights (slash commands, keywords, mentions) appearing shifted by one or more characters in some multi-line prompts
Fixed Shift+Tab inside the permission prompt's comment field approving the edit and granting session-wide edit permission instead of closing the field
Fixed the Agent tool advertising a general-purpose default in sessions where that agent is unavailable: an omitted subagent_type there now gets a clear error listing the available agents
Fixed notebook cell delete/replace approval dialogs silently omitting the existing cell content when the notebook or cell could not be read; the dialog now says why
Fixed slash commands run while Claude is responding showing HTML entities instead of the actual characters
Fixed the prompt footer not showing the "Update installed" restart notice after a background auto-update
Fixed the expanded task list (ctrl+t) always starting collapsed when resuming or relaunching into a session that still has open tasks
Improved memory and CPU usage while cloud sessions such as /ultrareview or /autofix-pr run in the background — their event streams are no longer re-scanned and re-rendered on every update
Improved permission dialogs: display text and "don't ask again" options now always match what a grant would cover, and "don't ask again" is withheld when contents cannot be fully displayed
Improved the embedded grep in native macOS/Linux builds: pathological patterns now fail fast instead of exhausting memory, and -m N with -A/-C prints correct context
Improved the context-limit error to say when auto-compact is off and point to /config to re-enable it
Vim mode: NORMAL mode and cursor position are now preserved when toggling the detailed transcript (ctrl+o) or closing a panel
Dialogs: arrow keys and Enter pressed in quick succession now select the option you navigated to instead of the previously highlighted one
SendMessage now refuses messages too large for cross-session delivery up front instead of silently dropping them
Remote Control: claude rc now applies the same enterprise-gateway availability check as interactive startup
[VSCode] Fixed focus jumping between open Claude tabs on its own when a window with several Claude panels is restored or reloaded
Added the optional CLAUDE_CODE_PROJECT_DIR_NAME environment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directory
Added the selection:clear keybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view
Added a GitLab merge request badge to the footer and statusline: repos with a GitLab remote and an authenticated glab CLI show MR !N with draft/pending/green states
Claude Code now continues your session automatically when a claude.ai usage limit resets; turn it off in /config ("Continue automatically at usage limit")
Claude is now told to use your account email only to identify you, and not to send it to unrelated services unless you ask
Security: remote file reads, session restore, CLAUDE.md includes, workflow scripts and file uploads now reject Windows NT-namespace (\??\) paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vector
Fixed auto mode in very long sessions repeatedly re-checking and denying sandboxed commands' network access after the conversation had been compacted
Fixed session-scoped permission answers (including denies) being dropped when answering background subagent tool permission prompts
Fixed a crash when an API response on the non-streaming fallback path (typically via third-party gateways) contained a thinking block missing its thinking field or a text block missing its text field
Fixed markdown rendering becoming extremely slow for some messages containing unusual Unicode sequences
Fixed SendMessage rejecting a recipient copied from ListAgents when the session name is at the 200-character cap or emoji-heavy
Fixed repository detection mis-reading the host of git remotes with unusual userinfo, producing links and repo-specific behavior for the wrong host
Fixed MCP diagnostics printing resolved secrets: scope-conflict warnings now show the configured ${VAR} form, and connection-failure details show only the server origin
Fixed strictKnownMarketplaces allowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to
Fixed modal text such as the /login OAuth URL losing characters when copied in fullscreen
Fixed a --- horizontal rule in rendered markdown running into the line after it
Fixed consecutive shell commands splitting into multiple "Ran 1 shell command" rows when todo/task updates were interleaved between them
Fixed dialogs like /permissions opened while a ! shell command was running being dismissed when the command finished
Fixed a queued ! shell command being sent to the model as plain text after pressing up-arrow to edit the queued input
Fixed queued messages reappearing in the prompt history while still queued, Esc while selecting a queued message no longer interrupts the turn, and ! mode no longer sticks after a mid-turn submit
Fixed accepting the "Try the new fullscreen renderer?" prompt restarting the session without its permission mode (e.g. --dangerously-skip-permissions), tool allow/deny rules, model or effort flags
Fixed /tui dropping launch --allowed-tools/--disallowed-tools rules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can't carry over
Fixed trust prompts omitting the repository-wide scope warning when the directory was first seen before the repository existed there
Fixed a case where an IDE diff tab closing during a permission re-prompt could answer the new prompt with the previous input
Fixed: files sent to the user during Remote Control sessions hosted by Claude Code Desktop or VS Code now upload, so they open on phone and web instead of showing an empty card
Fixed: after /login while CLAUDE_CODE_OAUTH_TOKEN is set, the stale-token reminder no longer leaks into Claude's automatically resumed turn — it now appears only to you
Fixed: permission previews now relay only to channel servers admitted by the inbound trust gate, and a server's explicit permission-capability opt-out is honored
Fixed: credential masking on relayed permission previews can no longer hide commands, paths, or destinations from the approver; oversized private-key blocks now redact under full-strength redaction
Fixed: provider API tokens that mask on permission previews now mask even when directly followed by shell delimiters
Fixed Claude Desktop inter-session messages being silently dropped by the recipient session when cross-session messaging read as disabled, which left the sender's query "thinking" for many minutes
Remote Control: signing this computer in to a different claude.ai account or organization now stops the running session within seconds and says why, instead of a misleading HTTP 404 hours later
Remote Control sessions started from Claude Code Desktop or VS Code now keep phones and claude.ai/code updated on the session's permission mode (and claude.ai/code on the model) as they change
Remote Control: effort picks made on a phone or on claude.ai/code now apply to terminal- and Desktop/VS Code-hosted sessions, and the session publishes its effort level to connected clients
SendMessage and ListAgents now say when your account's session list was too long to check completely, instead of treating unseen sessions as absent
Expired Anthropic profile credential now points you at /login when a claude.ai login would take precedence
Improved the transcript: your own prompts now render markdown (highlighted code blocks, inline code, lists) the same way replies do
Improved the "API returned an empty or malformed response" error to say what came back (content type, body kind, size, request ID) and why the original streaming request failed
Improved auto-generated session titles to read as short, specific names (e.g. "Login button bug") rather than sentences restating your request (e.g. "Fix the login button on mobile")
Reduced the context cost of loading the built-in claude-api skill from ~200k+ tokens to ~25k by loading reference docs on demand
/permissions can now be opened while Claude is working — rule changes apply to the rest of the current turn
/add-dir <path> can now be used while Claude is working; /add-dir, /autocompact, /theme, /help, /config and /advisor dialogs open mid-turn in the fullscreen TUI
/goal now clears itself with a notice when a turn dies on an unrecoverable error (e.g. revoked auth, an exhausted credit balance, or a context overflow) instead of staying armed
/goal: when background tasks keep a goal waiting for 30+ minutes, Claude now checks in on them instead of waiting indefinitely (set CLAUDE_CODE_GOAL_CHECKIN_MINUTES=0 to opt out)
claude setup-token now rejects unexpected extra arguments instead of silently ignoring them
Changed Esc in fullscreen mode to no longer clear a mouse text selection: it interrupts or dismisses as usual and the selection stays highlighted
Removed the redundant "Allowed by auto mode classifier" line that auto mode showed under every Agent tool call
Removed the "Default teammate model" setting from /config; agent-team teammates now use the leader's model unless the spawn names one
Dimmed the elapsed-time counter on the running tool header so it no longer competes with the bold counts
Background task notifications delivered between turns are now sent to the model inside <system-reminder> tags, matching mid-turn delivery
Mantle: skip the admin-pin availability probe at startup when a main-loop model is already picked
Windows: startup no longer stalls on repeated rename retries when ~/.claude.json is read-only
Added GitLab merge request URL support to the --worktree flag and the claude agents view (where MRs display as !N)
Added an opt-in forward_user_identity apps gateway setting on Anthropic upstreams that sends the signed-in user's identity as headers, so a proxy behind the gateway can attribute spend per user
Added opt-in memory cgroup support for Bash tool commands on Linux (CLAUDE_CODE_TOOL_MEMORY_LIMIT) so a runaway build can't stall the session
Added CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS environment variable to configure the WebFetch session URL cache TTL (default unchanged: 15 minutes)
Fixed cloud sessions occasionally being marked as lost when the environment shut down while Claude was waiting on a permission prompt
Fixed MCP v2 connections endlessly reopening the subscriptions/listen stream against servers that terminate long-held streams on a fixed timeout (e.g. serverless hosts)
Fixed Notification hooks not firing for permission prompts when running under Claude Desktop or VS Code
Fixed idle sessions on Linux sometimes keeping one CPU core at 100% when sandboxing is enabled
Fixed bundled skill aliases like /checkup and /review reporting "Unknown command" in -p mode or with plugins/MCP loaded when a user or project skill shadows the bundled skill
Fixed skill/command argument substitution to prevent argument values from being re-expanded as template markers
Fixed Windows paths spelled with the NT \??\ device prefix bypassing UNC path validation, closing an NTLM credential-leak vector
Improved claude self-hosted-runner session start time: the session branch is now created without rewriting the working tree, and two server round trips no longer block the agent's launch
Improved apps gateway error forwarding: 400/413 errors from Vertex, Foundry, and Claude Platform on AWS upstreams now carry the upstream's own message; fixes a bug with auto-compact on apps gateway
Improved claude plugin validate to check a bare .claude/skills directory, reporting SKILL.md files whose frontmatter fails to parse
Improved screen reader mode: the /effort selector renders as a numbered list with a typed-number prompt, and hint and dialog text is no longer clipped
Improved print mode diagnostics: a [claude-code:unrecognized_model] line is written to stderr when a request goes out for a model ID Claude Code doesn't recognize; map it with modelOverrides to silence
Changed the GitHub app setup tip to no longer appear in repositories whose origin remote is on gitlab.com or bitbucket.org; the enterprise marketplace tip now covers non-GitHub internal git hosts
Todo/task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) are no longer available on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; set CLAUDE_CODE_ENABLE_TODO_TOOLS=1 to bring them back
Windows: fixed auto mode repeatedly stopping for manual approval on ordinary cd <dir> && <command> > file Bash commands (a 2.1.232 regression)
Reverted the 2.1.232 Bash permission changes for Cygwin-style symlinks on Windows and for input redirections (< file); a narrower version will return in a later release
Subagent forking is now on by default: a subagent_type: "fork" subagent inherits the full conversation and prompt cache, and non-teammate agent spawns in interactive sessions now run in the background by default
Type @ in the prompt to mention another Claude session by name; Claude then uses SendMessage to reach that session directly
SendMessage now delivers to a bare name that exactly matches one live session, instead of asking to confirm with a ref first
Interactive sessions on one machine now keep unique names: starting or renaming a session to a name another live session already uses gives it a name-word-word variant and tells you
Added /config rows for "Dialog expiry" and "Messages from your other sessions" (cross-session inbound accept/hold/refuse)
Added secret redaction for GitLab token families (glrt-, gloas-, glptt-, glagent-, glimt-, glsoat-, glcbt-, glft-, glffct-) and full redaction of routable glpat-/gldt- tokens; the glab CLI config store gets the same sandbox and credential-path protection as gh
Added GitLab support to plugin marketplaces: bare gitlab.com repo URLs (including nested subgroups) now clone like github.com URLs, and clone auth-failure hints name your actual git host
Settings: additionalMarketplaces and allowedMarketplaces are now accepted as friendlier aliases for extraKnownMarketplaces and strictKnownMarketplaces
Enterprise policy: a url-typed blockedMarketplaces entry for a bare repo URL keeps blocking that URL when the CLI classifies it as a git clone
Gateway: the desktop: overlay now accepts every released Desktop setting (was 11 hand-listed keys), validated at boot against Desktop's own schema; unknown or invalid keys fail boot
Gateway: empty managed.policies[].match.groups/admin.admin_groups entries and malformed email_domain values (empty, or containing @, whitespace, or commas) now fail at boot instead of silently matching no one or granting admin access
Fable 5 is offered as an advisor in /advisor again for organizations with Fable access, with usage-credits consent set up through /model fable
Fixed a PowerShell permission bypass where variable-writing parameters could silently overwrite $PSDefaultParameterValues and redirect later commands' file access
Fixed a Windows permission bypass where Git Bash followed Cygwin-style symlinks that path validation saw as regular files; writes through them now require permission approval
Fixed nested git repositories inheriting trust from a parent directory; each repository now requires its own trust confirmation
Fixed MCP connections hanging for the full 30-second connect timeout when a server fails to answer or sends a malformed reply to the protocol-version probe
Fixed Remote Control sessions hosted by a bridge inside a cloud session inheriting that session's transcript or credentials
Fixed Remote Control sessions started from Claude Desktop or an IDE appearing as a new claude.ai session each time the local session was resumed; they now reattach to the existing one
Fixed Remote Control sessions appearing unreachable to newly attached clients while idle
Fixed Remote Control bridge sessions not restoring conversation history when the session worker restarts
Remote Control: resuming a conversation whose session was deleted from claude.ai or the app now starts a replacement instead of failing with a message about your login (regressed in v2.1.227)
Fixed Cloud gateway /login exiting silently or leaving an unresponsive terminal after "Press Enter to continue" when managed settings failed to load; the reason is now shown
Fixed voice mode on native builds getting stuck on "listening…" when the voice service rejected the connection; the rejection is now shown immediately
Fixed mTLS client certificate rotation requiring a restart; Claude Code now reloads the rotated cert and key automatically on connection errors
Fixed malformed AWS or Vertex region values being used to build request URLs; they now fall back to the default region
Fixed stream idle timeout errors failing the request instead of recovering on Bedrock, Vertex, and gateway deployments
Fixed content-sized overlays containing truncated text rendering one column too wide, and start-truncated text collapsing to an ellipsis
Fixed a stray garbled character where a long shell-command or agent-description preview was cut off mid-emoji
Fixed a startup race that could silently unregister a plugin marketplace due to concurrent writes to known_marketplaces.json
Fixed /update and /tui refusing to restart while work that survives the relaunch was running
Fixed usage-limit guidance suggesting unavailable slash commands in SDK and remote sessions
Fixed the consent message for interactive --advisor fable launches, which told you to run /model fable in an interactive session that had just exited
Improved fullscreen streaming: long sessions stay responsive because the whole conversation is no longer re-normalized on every update
Improved the managed settings approval dialog: shows endpoint URLs, uses clearer wording for telemetry-only changes, skips routine OpenTelemetry options, and requires approval for server-managed sandbox binary overrides (sandbox.bwrapPath, sandbox.socatPath, sandbox.ripgrep)
/feedback and /bug now open immediately when invoked while Claude is responding, instead of waiting for the turn to finish
/plugin install plugin@marketplace now refreshes the marketplace first, so newly published plugins install without a manual marketplace update
/code-review at high, xhigh, and max effort now runs in a background agent like the other levels
Pasted and clipboard images are read without blocking the event loop
Remote Control now keeps reconnecting for about 30 minutes after a network blip and no longer drops after a few blips spread across an hour
Remote Control: resuming a conversation no longer silently takes Remote Control away from another Claude Code on the same machine that still has it; run /remote-control there to move it
Updated agent panel: completed subagents hide immediately with a /tasks footer hint, and the "↓ N more" overflow indicator moved left for visibility
Remote Control: the terminal now says whether a session was taken over by another device, ended from another app, or deleted, and stops suggesting a reconnect that would undo it
Bash input redirections (< file) are now permission-checked like their argument spellings on all platforms
Shortened the message shown when resuming a completed background agent
Cowork sessions no longer inline external @-imports from user-scope memory files
Hardened the auto-generated cross-session messaging socket directory on shared /tmp: a pre-planted symlink or another user's directory is now refused instead of used
Hardened the Linux filesystem sandbox against a protected-path bypass
Changed sandbox.ripgrep to be honored only from user, managed, and --settings settings; project settings can no longer override the sandbox's ripgrep binary
Removed the startup tip suggesting you create custom subagents, and the matching nudge in the /powerup tour
Fixed interactive sessions that could stop redrawing entirely, while the process kept running, after a rare internal layout error
Fixed git / Git Bash not being found on Windows when Claude Code is launched from a parent folder of the git installation
Fixed /tui reverting the session to an earlier model when /model had been changed since the last response
Fixed cross-session messaging sometimes starting without an inbox in the first session after install or upgrade
Fixed Remote Control /resume while connected leaking the resumed conversation's title or history into the connected session
Fixed claude self-hosted-runner sessions failing on every fresh runner when the checkout hook fails for a repository the session doesn't push to; that repository is now skipped with a warning
Fixed self-hosted runners ending sessions in the gap between a background task finishing and the follow-up turn starting
Fixed session cleanup deleting contents inside a project's memory folder
Fixed background plugin-cache cleanup deleting a plugin's cache when its only version is a symlinked development checkout
Fixed a settings-merge issue where a marketplace entry redefined in a higher-precedence settings tier could inherit another tier's custom headers; marketplace entries now merge as whole entries
Fixed the deferred-tools reminder occasionally being sent to the model twice after a skill invocation
Hardened skills synced from claude.ai: they no longer shadow local commands or MCP prompts, their descriptions are sanitized and labeled, and on your machine their bodies don't run ! commands or expand @ files
Improved cross-session messages: the sender and body now display inline instead of a collapsed line, and messages to Remote Control sessions on other machines show your Remote Control session name as the sender
Improved Vertex AI credential handling: expired or missing Google Cloud credentials now fail within seconds instead of retrying for minutes
Improved compaction progress: the retry countdown and stall hint now appear during compaction instead of only a progress bar
Updated terminal title busy-spinner glyphs to reduce tab-bar jitter on some terminals
Changed the Write tool so newer models can overwrite an existing file they haven't read this session, matching the Edit tool's rules; older models still require the read first
Removed the outdated note about auto mode sessions costing slightly more from the first-use notice for Pro, Max, and Team plans
Fixed feature flags being evaluated without the user's subscription tier when a session started with an expired login token, which could wrongly prompt Max plan users to enable usage credits for Fable
Fixed every Bash command failing under claude-code-action with allowed_non_write_users on GitHub-hosted runners
Fixed /tui bringing back a conversation that had been rewound to before its first message
Improved slash-command menu: blue now marks only the selected row, matched characters are bolded instead of recolored, and emoji or accented names keep their glyphs
Improved performance: fewer event-loop stalls on file-not-found suggestions and at-mention size checks
Added self-hosted environments: claude self-hosted-runner turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans
Added archive plugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning
Added a cancel-and-confirm step when removing an unavailable paste changes a command's text
Added ANTHROPIC_BEDROCK_REGION_PREFIX env var for Bedrock to prefer a specific cross-region inference profile over the AWS_REGION-derived one
Added crossSessionInbound and dialogExpiry settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver
Added sandbox credential-masking options: extract and onExtractNoMatch for structured env values, decode: "jwt" with maskClaims for JWT-aware masking, and awsPairs/sigv4 for AWS SigV4 re-signing; these need network.tlsTerminate and are honored only from user, managed, or --settings settings
Added cross-session SendMessage: Claude Code sessions can now message each other, on any of your machines, with ListAgents to discover them (macOS and Linux)
Fixed long (>200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list, rename, fork, delete and /resume no longer cross projects
Fixed SendMessage reporting "Message sent" when the write to a teammate's inbox had actually failed; failed deliveries are now reported as errors
Fixed sandbox filesystem deny entries written with a trailing slash (e.g. denyRead: "~/.aws/") being silently bypassable on Linux and macOS
Fixed sandbox violation details never appearing in Bash tool results; Claude now sees which file or network access was denied and why
Fixed MCP tools that connect mid-turn being deferred for tool search without their names announced to the model
Fixed plugin install records being silently corrupted when the same plugin is installed in multiple projects
Fixed recalled or restored paste content occasionally attaching wrong data or silently losing text when the paste had aged out or placeholder numbers collided
Fixed copy-on-select on Wayland sometimes not reaching the clipboard; the two selection writes no longer race
Fixed the feedback survey's transcript share silently failing on long sessions; a failed share now shows an error instead of a success message
Fixed Remote Control auto-start intermittently failing with "Remote credentials fetch failed" on a cold start with a stale login token
Fixed Remote Control and SDK clients showing a blank "(no content)" message after /clear and other output-less commands
Fixed a Remote Control session recreated after its server session expired uploading prior local conversation history into the new session
Improved fullscreen mode to keep the full pre-compaction history in scrollback across repeated compactions, instead of only the most recent interval
Improved Remote Control: attached web and mobile clients now see compaction progress and the post-compaction boundary instead of a silent pause; /clear resets now propagate to attached clients
Improved Remote Control: connection failures now show a persistent failure indicator with details and a reconnect shortcut, instead of only an 8-second toast
Removed the 200-subagent-per-session spawn cap; long-running sessions no longer refuse new agents (concurrency and depth limits still apply)
Changed managed settings: the approval prompt no longer re-appears after re-login or org switching when the organization's settings are unchanged
Changed the feedback-survey transcript share: with your consent it now also uploads the last request's model settings — the system prompt (which includes your CLAUDE.md instructions), tool definitions, and model parameters. Secrets are redacted as before, and these fields are dropped first if the share is too large
Changed the Bash tool description to always note that command output is displayed to the model, not reliably to the user
Changed recalled paste placeholder numbers to renumber when accepted into the input
Changed Remote Control to archive the stale server session instead of leaving a dead one listed when a fresh session is minted after compaction or /resume
[VSCode] Fixed the extension showing Remote Control as connected after the connection failed
Fixed a session resume silently reconnecting Remote Control after the user turned it off (--resume, SDK hosts, and the VS Code extension)
[VSCode] Fixed sessions not honoring remoteControlAtStartup when explicitly enabled
Added owner wildcard entries ("owner/*") to the strictKnownMarketplaces and blockedMarketplaces managed settings for allowing or blocking all marketplace repos under a GitHub org
Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead
Added a /teleport hint in cloud sessions showing how to continue locally with claude --teleport <session id>
Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks
Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog
Fixed workflow scripts being able to use dynamic import() to run code outside the workflow sandbox
Fixed a permission gap where an agent definition's bypassPermissions mode ignored the org bypass-permissions disable policy
Fixed resuming a session after a mid-session /cd coming back empty
Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as vertex_ai/claude-* or bedrock/anthropic.claude-*
Fixed modelOverrides keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented
Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local managed-settings.json or MDM profile; admin env now merges per key
Fixed sandboxed commands failing to start on Linux when sandbox.filesystem.denyWrite covers the working directory
Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume
Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment
Fixed a rare hang when parsing unusual git push output
Changed CLAUDE_CODE_DISABLE_1M_CONTEXT to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K
Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 to restore the previous behavior
Changed /review to be an alias of /code-review, which reviews the current diff or a PR (/code-review <level> <pr#>); use /code-review ultra for a deep cloud review
Changed /code-review with no effort level to reuse the level you typed last; type a level like /code-review high to change it
Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type
Fixed /usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one
Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message
Fixed "Connection closed mid-response" errors being reported on responses that had actually completed
Fixed /usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it
Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API
Fixed org-restricted model: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family
Fixed stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire
Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a /login hint instead
Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed
Fixed SendMessage rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit
Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own effort: setting
Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown
Fixed screen readers re-reading the whole input line on every backspace in --ax-screen-reader mode — end-of-line deletions now echo just the deleted characters
Fixed host model-selection keys not taking precedence over a stale on-disk managed-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set
Improved auto mode safety: messages sent to other agent sessions via SendMessage are now evaluated by the permission classifier before dispatch
Improved the refusal when Claude tries to invoke a skill with disable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow
Improved the /diff view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv
Changed Remote Control auto-start so repo-local settings (.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config
[VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with Ctrl+Alt+F or the "Claude Code: Toggle Focus view" command
Added mode: "mask" for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an extract regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to deny
Added warnings to claude plugin validate when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync
Added a prompt-audit subcommand to the claude-api skill for auditing prompts and tool descriptions for patterns written for older models
Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in [[ ]] regex conditionals; affected commands now prompt for permission
Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval
Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts
Fixed MCP servers from --mcp-config not being connected before the first turn in print mode (-p), which made the model emit tool calls as literal text
Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it
Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as constructor
Fixed WebSearch failing with a 400 error at effort xhigh/max when thinking is disabled
Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy
Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit
Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray HOME environment variable
Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0 not disabling interrupted-turn auto-resume; falsy values are now honored
Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication
Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized
Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. /help, /feedback) being un-invocable in non-interactive sessions
Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing
Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied
Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view
Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models
Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result
Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions
Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write
Improved /ultrareview error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest git fetch --unshallow on clones that are already complete
Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate powershell.exe no longer prompt
Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives
Changed /plugin install to refresh a stale marketplace catalog and retry before reporting a plugin not found
Changed plugins installed from /plugin to activate immediately when safe, instead of always requiring /reload-plugins
Changed plugins to accept "." as a skills path, and the root-level SKILL.md validation error now suggests using the plugin root
Changed /status to show the session kind: interactive, or a background job that is attached or unattended
Changed emoji autocomplete to accept common alternate shortcodes like :thumbsup:, :thumbsdown:, and :love:
Changed sessions forked with /fork to create a new worktree of their own instead of working in the original session's checkout
Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them
Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently
Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"
Changed the Gateway model field validation: non-string values are rejected with a 400 instead of being forwarded
Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts
Added Claude Opus 5 (claude-opus-5), now the default Opus model — 1M context, fast mode at $10/$50 per Mtok
Added sandbox.network.strictAllowlist setting to deny non-allowlisted hosts for sandboxed commands without prompting
Added DirectoryAdded hook that fires after /add-dir or the SDK register_repo_root control request registers a new working directory mid-session
Added mcp_server_errors to the headless stream-json init event, listing --mcp-config entries skipped by config validation; terminal runs print a startup warning
Added the workflowSizeGuideline settings key so the advisory Dynamic workflow size guideline can be set from any settings file; the /config row is hidden while one does
Added nested subagent forwarding in stream-json: subagents spawned at depth-2+ now appear when --forward-subagent-text is set, keyed by their spawning Agent tool_use id
Fixed claude -p text output dropping the answer already produced when a turn dies on a mid-stream API error
Added HTTP status and error text to claude mcp list and /mcp when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace
Fixed the Fable model row showing "Requires usage credits" for plans that include it, when a stale cache had baked the label in
Fixed the /model picker showing the merged Opus row as plain "Opus" instead of "Opus (1M context)"
Fixed copy-on-select inside GNU screen printing base64 into the terminal instead of copying the selection
Fixed Remote Control clients keeping a stale fast-mode status after a model switch, reconnect, or failed org check
Fixed CLAUDE_CODE_GIT_BASH_PATH on Windows exiting or being used as bash when the path isn't a bash/sh binary; it's now ignored with a warning
Fixed Vim mode: pressing ← on an empty prompt now returns to the agent view from NORMAL mode, not just INSERT
Fixed screen-reader mode rewriting the entire input line on every keystroke instead of echoing only the typed character
Improved the "Remote Control is only available via api.anthropic.com" error to name the specific setting that caused it
Improved claude --teleport to show which repo your current checkout points at when it doesn't match the session's repo
Changed dynamic workflows to default to a medium size guideline (aim for fewer than 15 agents); pick another size or unrestricted with Dynamic workflow size in /config
Changed managed MCP allowlist/denylist ${VAR} entries to resolve from the startup environment and managed-settings env instead of settings-file env
Changed the /model picker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list
Added the current default workflow size to the running-workflow status line, with a pointer to /config for changing it
Removed Opus 4.7 from fast mode; /fast now applies to Opus 5 and Opus 4.8
Updated the claude-api skill to default to Claude Opus 5, with a migration path from Opus 4.8
Subagents can now spawn nested subagents up to depth 3 by default (was 1); set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=1 to disable nesting
Changed /code-review to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target
Added screen-reader announcements of deleted text for word and line deletions (Option+Delete, Ctrl+W, Cmd+Backspace, Ctrl+U, Ctrl+K) in --ax-screen-reader mode
Fixed Windows paths with \u-prefixed segments (like C:\Users\unicorn) being corrupted into CJK characters in tool inputs, which made those files inaccessible
Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded
Fixed multi-line paste collapsing into one line with j in place of newlines in terminals that encode pasted newlines as Ctrl+J
Fixed /context reporting stale pre-compact token usage after compacting from the message picker
Fixed /ultrareview failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings
Fixed /code-review ultra silently running a local review in non-interactive sessions — it now launches the cloud review
Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates
Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped
Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected
Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired tool_use block left in the transcript when a tool aborted mid-response
Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in --ax-screen-reader mode
Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation
Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees
Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR
Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks
Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock
Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai
Fixed prompt history entries being dropped or duplicated when history writes raced or failed
Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; Ctrl+B backgrounding now applies the same background-shell caps as other paths
Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust
Fixed fork-session lineage being lost after compaction in headless and SDK sessions
Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment
Improved /ultrareview error feedback so Claude can correct an invalid argument instead of retrying it unchanged
Improved auto mode: the dangerous-rm, background-&, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead
Improved sandbox command restrictions for IDE interactions
Improved trust dialogs to name the repository root the grant covers
Changed /deep-research to start only when invoked manually; Claude no longer launches it on its own
Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead
Added an announcement when fast mode changes as a result of switching models via /config model=<x> or Remote Control
Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt
Changed agent markdown files to reject agent names containing :, which is reserved for plugin namespacing
Changed skills with context: fork to run in the background by default; opt out per skill with background: false
Added yes/no/on/off/1/0 (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside true/false
Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever
Added emoji shortcode autocomplete in the prompt input: type :heart: to insert ❤️, or :hea for suggestions — disable with the emojiCompletionEnabled setting
Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently
Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session
Fixed Windows auto-update failures that could leave claude.exe missing; failed updates now restore the preserved executable automatically
Fixed background session isolation not canonicalizing symlinked working directories, which could let sessions escape their workspace folder
Fixed auto-compact never triggering for Claude Opus 4.8 on Bedrock and /compact failing once over the limit
Fixed corporate mTLS, TLS-verify, OAuth scope, and proxy settings being ignored in Claude Desktop sessions
Fixed screen reader mode's startup announcement being cut off by the first prompt render, and the thinking status row re-rendering every few seconds to update elapsed time and token counts
Fixed managed settings that set OTEL_EXPORTER_OTLP_ENDPOINT not governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint
Fixed --resume/--continue and /resume failing with a TypeError when a transcript has a malformed attachment entry
Fixed Remote Control sessions not showing a pending permission prompt or dialog to viewers that connected after it appeared
Fixed background shells sometimes becoming impossible to stop after a session is sent to the background (/background or ←) or when the session exits on a heavily loaded machine, most visible on Windows
Fixed a CLAUDE.md or SKILL.md paths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-bounded
Fixed the transcript preview sitting flush against the input area when attaching to a starting background session; it now leaves the same one-line gap as the live layout, so the transcript no longer shifts when the session takes over
Improved footer PR badge links to be clickable hyperlinks even when terminal support can't be detected (e.g. over ssh/tmux); set FORCE_HYPERLINK=0 to opt out
Changed the login-expiry warning to appear 3 days before expiry instead of 5
Capped the frontend-design plugin suggestion tip at 3 lifetime impressions instead of repeating indefinitely
Added a cap on concurrently-running subagents (default 20, override with CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS) so one message can't fan out unbounded background agents
Changed subagents to no longer spawn nested subagents by default; set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH to allow deeper nesting
Fixed --max-budget-usd not stopping background subagents: once the cap is reached, new spawns are denied and running background agents are halted
Fixed single-segment dir/** allow rules like Edit(src/**) auto-approving writes to nested dir/ directories anywhere in the tree instead of only <cwd>/dir
Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer
Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically
Fixed Bash permission checks treating zsh variable subscripts and modifiers in [[ ]] comparisons as inert text — these commands now prompt for approval
Fixed Bash permission checks to no longer auto-approve certain help and man commands that could run unsafe options, command substitutions, or backslash paths
Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog
Added a periodic progress heartbeat for long-running tool calls that previously went silent
Added an ISO modified timestamp to memory file frontmatter
Added message.uuid, client_request_id, and tool_source attributes to OpenTelemetry log events for message-level correlation and tool provenance
Added CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH to configure the 60 KB truncation limit on OpenTelemetry content attributes
Added reasoning effort to the subagentStatusLine payload, so custom agent rows can render model and effort
Added permission prompts for docker commands (including the Podman docker shim) carrying daemon-redirect flags (--url, --connection, --identity, and Podman's remote mode) that previously ran without one
Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags
Fixed Bash tool killing the Claude session when a pkill -f pattern accidentally matched the CLI's own process (Linux)
Fixed unbounded memory growth when --settings points at a device file or multi-GB file; oversized (>2 MiB) settings files now fail at startup with a clear error
Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows
Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap
Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task
Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)
Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)
Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)
Fixed the PowerShell tool reporting where.exe, fc.exe, and diff.exe as errors when they return a valid negative answer (Windows)
Fixed > and >> under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8
Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon
Fixed background sessions parked with ← or /background and left idle keeping the background daemon and a worker process alive indefinitely
Fixed completed background sessions being impossible to remove via claude rm or the agent view once the background service had gone idle
Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view
Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store
Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled
Fixed /install-github-app and the /mcp settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached
Fixed plugins enabled via the --settings CLI flag not loading (regression since v2.1.181)
Fixed feature flags going stale in long-running sessions after the OAuth token rotates
Fixed /ultrareview refusing to run in repos with no merge base — it now offers to review all tracked files
Fixed claude update and claude doctor hanging silently, and the /status System diagnostics section going blank, when a shell-config path is a directory
Fixed memory frontmatter values being silently truncated at an inline # when memory files are saved
Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative message_delta frames
Fixed a spurious "check your network" warning that appeared while the advisor was thinking
Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation
Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context
Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources
Improved the claude rc workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory
Changed single-segment dir/** hook if: conditions to match only <cwd>/dir; write **/dir/** for any-depth matching. deny/ask permission rules keep their any-depth match.
Changed file commands using -m/--magic-file or -f/--files-from to require permission instead of being auto-allowed as read-only
Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket
Changed SessionStart hooks to report source "fork" when a session begins as a fork instead of "resume"
/fork now copies your conversation into a new background session (its own row in claude agents) while you keep working; the in-session subagent it used to launch is now /subtask
Added claude auto-mode reset to restore the default auto-mode configuration, with a confirmation prompt (pass --yes to skip)
Added a session-wide limit on WebSearch tool calls (default 200, tunable via CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION) to stop runaway search loops
Added a per-session cap on subagent spawns (default 200, override with CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION) to stop runaway delegation loops; /clear resets the budget
MCP tool calls running longer than 2 minutes now move to the background automatically so the session stays usable; configure the threshold or disable with CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS
Typing /resume in the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background session
Fixed plan mode auto-running file-modifying Bash commands (e.g. touch, rm) without a permission prompt or SDK canUseTool callback
Fixed worktree creation following a repository-committed symlink at .claude/worktrees, which could create files outside the repository
Fixed a continue:false hook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections
Fixed SIGTERM during a running Bash tool orphaning the command's process tree in print/SDK mode; the CLI now aborts the turn, kills the tree, and exits 143
Fixed /background and claude --bg failing with "EUNKNOWN: unknown error, uv_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7
Fixed shell mode (!) not executing commands containing file paths while the path autocomplete popup was open
Fixed auto-mode denial notifications rendering broken characters when a long denial reason was truncated mid-emoji
Fixed Ctrl+J not inserting a newline in the agent view dispatch input on terminals with extended key reporting, and surfaced the newline shortcut in the ? help overlay
Fixed /ultrareview rejecting PR references like #123, PR 123, and pasted PR URLs; error hints now name the command you actually typed
Fixed /ultrareview <branch> not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos
Fixed /ultrareview skipping the billing confirmation in a new conversation after /clear
Fixed /ultrareview's "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commands
Fixed hosted (host-managed) sessions failing at startup when repository settings configured mTLS certs, extra CA bundles, or OAuth scopes; these transport settings are now ignored with a warning
Fixed a spurious "File has not been read yet" error when editing a file that had been read with offset/limit before resuming a session
Fixed ExitWorktree failing with "no active EnterWorktree session" after resuming a session with --continue/--resume in print/SDK mode
Fixed the workflow agent grid staying empty for Remote Control clients that join a session mid-run
Fixed streaming-mode control requests being marked complete before their handler finished, which could lose the request on session restart
Fixed background sessions created with /fork losing their live-parent protection after a state write failure
Fixed reopening a stopped background session from the agent view failing silently — it now resumes the session, or shows why it can't and lets you force a restart
Fixed agent teams: a stopping teammate could send the leader duplicate idle notifications when team initialization re-ran within a session
Fixed the plan-approval dialog footer splitting "ctrl+g to edit in " apart when the file path is long
Fixed the welcome banner keeping its old panel widths after a combined width+height terminal resize in fullscreen mode
Fixed diff previews losing their line numbers and +/- markers in narrow layouts
Fixed @-mentions attaching nothing after a partial file read, plugin uninstall targeting the wrong marketplace, and false "Command timed out" on exit code 143
Fixed OpenTelemetry HTTP exports being rejected with 411/400 by Azure Monitor and other endpoints that don't accept chunked transfer encoding
Fixed OTLP event log records missing trace_id/span_id when TRACEPARENT is set in SDK/headless mode
Fixed conversations with many images incorrectly failing with "Request too large" errors, and improved the error message to explain the actual cause
Fixed web search and web fetch returning "API Error" text as search results or page content when the API was overloaded
Improved web search and web fetch reliability by retrying 529 errors and rate-limited requests with bounded backoff
Improved prompt caching: the mid-conversation system block now works behind LLM gateways and custom base URLs (Bedrock, Vertex, 1P)
Improved background agent attach: cold-attaching now instantly shows the formatted transcript while the session boots, instead of a blank wait
Reduced token usage in inter-agent messaging: SendMessage bodies are no longer duplicated into replayed history and tool results
Changed /fork to name the copy after your prompt when the session has no title, so the row is recognizable in the agent view
Changed bare /btw to reopen the side-question panel on your most recent exchange so you can browse earlier answers
Changed the ← footer hint to pulse N done for a moment when a background agent finishes while nothing needs your input
Deprecated the Task tool's mode parameter (now ignored); subagents inherit the parent session's permission mode by default
Changed Enterprise forceLoginMethod to be enforced for VS Code extension, SDK, setup-token, and install-github-app logins, not just the terminal
Changed session transcripts to record the reasoning effort level on each assistant message
Changed headless/SDK sessions to apply a set_model control request mid-turn; the next model round-trip uses the new model instead of waiting for the next turn
Changed agent view / claude agents --json: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working"
Updated the auth status panel title from "Cloud authentication" to "Authentication"
Corrected an earlier release note (2.1.200): tmux through the 3.6 series lacks synchronized output; newer tmux with support is detected automatically
Added --forward-subagent-text flag and CLAUDE_CODE_FORWARD_SUBAGENT_TEXT environment variable to include subagent text and thinking in stream-json output
Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote characters, so tool inputs cannot visually alter the approval message
Fixed auto mode overriding a PreToolUse hook's ask decision for unsandboxed Bash — a hook ask now floors the decision at a prompt
Fixed parallel Claude Code sessions all logging out simultaneously after wake-from-sleep when many sessions share one credential store
Fixed plugin MCP servers not reconnecting after an idle web session woke, leaving MCP calls failing until the next message
Fixed Claude Code on Vertex and Bedrock attempting the default Opus model at startup and printing a spurious fallback notice when a model is explicitly configured
Fixed subagents spawned with an explicit model override reverting to the parent's model when resumed or sent a follow-up message
Fixed nested .claude/rules/*.md files loading even when setting sources exclude project settings
Fixed file upload validation: filenames ending in a DOS device suffix (.prn) or trailing dot are now accepted, and files with multiple hard links are refused
Fixed file uploads to Claude in Chrome from remote and CLI sessions
Fixed edits that leave the input as "?" being silently swallowed and toggling the shortcuts panel
Fixed a startup hang when the Claude in Chrome extension is enabled but Chrome is not running
Fixed a 300ms delay revealing async content (Settings tabs, Stats, diff views, and other loading states)
Fixed reopening a just-stopped background session from the agents view starting a blank conversation under the same session id
Fixed /loop hiding the session from /resume after a single use
Fixed screen reader users losing the audible terminal bell after /terminal-setup or onboarding terminal setup
Fixed background jobs on LLM gateway auth (ANTHROPIC_AUTH_TOKEN + ANTHROPIC_BASE_URL) coming back "Not logged in" after the daemon respawns them
Fixed claude agents jobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing
Fixed /clear not resetting the session cost counter — the statusline's cost now starts at $0 after /clear
Fixed Claude in Chrome setup pages failing to open in the browser on Windows
Fixed headless print-mode sessions on Windows crashing or silently exiting when stdin is unreadable
Fixed background session titles in the agents view showing the naming model's refusal text when the prompt contains a link
Fixed background agents killed by the user auto-respawning, and revived agents re-running stale prompts from old sessions
Fixed routines with no schedule reporting a next run time in the year 1
Hardened synced skill/plugin directory naming on Windows and kept CCR web fetch/search proxies working after /clear
Improved terminal layout and rendering performance
Improved background agent result reporting — Claude now reports the status of still-running agents and waits for the real completion instead of fabricating results
Improved the memory index over-limit warning to measure only loaded content, excluding frontmatter and HTML comments
Updated integer environment variables (timeouts, token budgets, retry counts) to accept scientific notation and digit-separator spellings like 1e6 and 64_000
Updated documentation links to the current docs sites
Changed "always allow" permission rules to save at the repository root, so approvals granted in a git worktree persist across sessions and worktrees
Changed /usage-credits to ask for confirmation before sending a request to organization admins
Changed Vim mode s and S (substitute char/line) to work in NORMAL mode, matching vim behavior
[VSCode] Updated the Remote Control banner to describe what it does
Claude in Chrome: hardened file-upload path validation
Claude in Chrome: save_to_disk on screenshot actions now writes the image to disk and returns the path; previously it did nothing
Fixed a prompt-caching regression on Bedrock, Vertex, Mantle, and Foundry that billed the trailing system context block as fresh input tokens on every request.
Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck
Added a startup warning for Write(path), NotebookEdit(path), and Glob(path) permission rules — use Edit(path) or Read(path) instead
Fixed isolation: 'worktree' subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree
Fixed the ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments
Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element
Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text
Fixed claude attach sometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes
Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element
Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait
Fixed Claude assuming a cd took effect after its command was moved to the background; the tool result now states the working directory is unchanged
Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session
Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot
Fixed /doctor skipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in
Fixed Grep content mode claiming "No matches found" when paginating past the end of results
Fixed unmatched $1/$2 positional placeholders in skills and commands being silently stripped; they are now preserved verbatim
Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems
Fixed background workers crash-looping when a client resets its connection to the background service
Fixed claude agents --effort ultracode not reaching dispatched sessions; the value was silently dropped
Fixed pressing ← to open the agents view dropping the task tracker when returning to the session
Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted
Fixed killed background sessions leaving a permanent git worktree lock behind; the periodic sweep now releases locks whose owning process is gone
Fixed SDK MCP servers registered via an initialize control request waiting until the next turn to start connecting
Fixed returning to the agents view from a session leaving overlapping ghost frames with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1
Fixed late-appearing .claude/* symlinks not being reconciled into the sandbox deny-write list
Hardened the Agent tool against indirect prompt injection via content a subagent read
Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request
Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session
Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds
Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation
Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab
The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes
Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection
Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed
Auto mode is now available without CLAUDE_CODE_ENABLE_AUTO_MODE opt-in on Bedrock, Vertex AI, and Foundry; disable via disableAutoMode in settings
Fixed the terminal freezing and keystrokes lagging while streaming responses containing very long lists, tables, paragraphs, or code blocks
Fixed remote managed settings from a non-interactive run (claude -p, the SDK) being permanently recorded as consented without ever showing the security consent dialog
Fixed spurious prompt-injection warnings triggered by benign system-generated conversation updates
Fixed the auto-updater overwriting a custom launcher script or symlink at ~/.local/bin/claude on every release; /doctor now reports an externally managed launcher
Fixed compound commands with cd prompting for permission when the only output redirect was to /dev/null
Fixed the transcript jumping above the start of the answer when a response finishes streaming
Fixed extensions.worktreeConfig being left in the repo's .git/config (breaking go-git tools like tea) after the last worktree.sparsePaths worktree was removed
Fixed malformed bracket patterns in rules globs, skill paths, .ignore, and .worktreeinclude breaking file reads, file suggestions, and worktree creation
Fixed a crash loop in agent teams where a malformed teammate mailbox message caused repeated errors every second until the mailbox file was manually deleted
Fixed background sessions auto-named by accepting a plan not showing that name on their agent-view row
Fixed background sessions that entered a git worktree resuming blank after a cold reopen from the agent list
Fixed Remote Control task status updates being lost when the connection recovered from a network interruption or credential refresh
Fixed Remote Control sessions hosted by the desktop app not showing background agent and workflow progress on mobile and web
Fixed Deep research runs labeling every Fetch-phase agent "unknown" — chips now show the source hostname
Fixed Bedrock repeatedly requesting fresh AWS SSO credentials from IAM Identity Center on every API request
Improved agent view: pasting the same text again now expands the collapsed [Pasted text #N] placeholder instead of adding a second one
Improved agent view: blocked session peeks now lead with the question and show a worded staleness clock (waiting 3m) instead of the same timestamp twice
Changed Bedrock, Vertex, and Claude Platform on AWS to default to Claude Opus 4.8
Changed auto mode to no longer read autoMode from .claude/settings.local.json (repo-resident); use ~/.claude/settings.json instead
Fixed an indefinite hang on Windows when AWS credential resolution stalls (e.g. a stuck credential_process): the 60-second stall guard now fires instead of waiting forever.
Plugin hooks/monitors/MCP headersHelper: ${user_config.*} in shell-form commands is now rejected (shell-injection fix). Hooks: use exec form (args array) or $CLAUDE_PLUGIN_OPTION_<KEY>; monitors and headersHelper: read the value inside the script (config file or the server's env block).
Plugin option values (pluginConfigs) are no longer read from project-level .claude/settings.json; only user, --settings, and managed settings are honored
Fixed /usage-credits amount inputs silently stripping malformed values (e.g. a pasted timestamp) to digits; malformed amounts are now rejected with an error, and amounts over $1,000 require a typed confirmation
Added directory path suggestions to /cd, matching /add-dir behavior
Added a /doctor check that proposes trimming checked-in CLAUDE.md files by cutting content Claude could derive from the codebase
/commit-push-pr now auto-allows git push to the repo's configured push remote (remote.pushDefault, or the sole remote when only one is configured) in addition to origin
Gateway: /login now supports Anthropic-operated public gateway endpoints
EnterWorktree now asks for confirmation before entering a git worktree outside the project's .claude/worktrees/ directory
Background agents now upgrade to a new version in the background right after a Claude Code update, instead of paying a slow stale-session upgrade when you attach
Fixed an expired login failing every model with a misleading "There's an issue with the selected model" error instead of prompting to run /login
Fixed claude --resume and --continue not responding to keyboard input on startup
Fixed MCP servers configured via --mcp-config or .mcp.json ignoring a per-server request_timeout_ms, which caused long-running MCP tool calls to time out at the 60s default in fresh sessions
Fixed CLAUDE_CODE_EXTRA_BODY being silently ignored by claude agents / --bg background workers; the shell-exported override now follows the dispatching session
Fixed OAuth MCP servers requiring manual re-authentication after a single failed token refresh
Fixed --permission-prompt-tool pointing at an MCP server crashing with "MCP tool not found" on cold start before the server finishes connecting
Fixed /model picker rows printing a price for a different model than the row named, and stopped quoting first-party list prices on providers that don't bill them
Fixed server-provided model rows being misplaced in the /model picker when an entitlement or allowlist restriction drops the row they were positioned against
Fixed desktop sessions getting stuck showing "running" after a slash command was sent mid-turn
Fixed keyboard input being ignored in the agents view when a setup prompt appeared before a bare claude --resume on Windows
Fixed claude rm leaving the removed job in the daemon roster, causing the row to reappear in claude agents
Fixed /remote-control showing "Unknown command" when logged out — it now explains how to sign in
Fixed left arrow not stepping back out of a phase or agent in the workflow detail view
Fixed /status listing the same broken-install warning twice
Fixed false "disused plugin" tips and skewed disuse telemetry for LSP plugins
Fixed /doctor's update check to compare Homebrew installs against their cask's channel instead of the settings channel
Fixed the fullscreen jump-to-bottom pill suggesting Ctrl+End on macOS, not showing rebound chords, and wrapping over the transcript
Bedrock: fixed a multi-minute startup hang when using an awsCredentialExport helper on networks with restricted egress
Improved /code-review findings quality on claude-opus-4-8 across all effort levels
Improved agents view: status column now uses full terminal width instead of truncating at 64 characters
Changed agents view: Ctrl+X now permanently removes a completed session, and sessions no longer render twice; deleted background jobs stay deleted
Added a "Dynamic workflow size" setting in /config for controlling how large Claude generally makes dynamic workflows (small/medium/large agent counts) — an advisory guideline, not an enforced cap
Added workflow.run_id and workflow.name OpenTelemetry attributes to telemetry emitted by workflow-spawned agents, so a workflow run's activity can be reconstructed from OTel data
Fixed a crash in the inline Ctrl+R history search when accepting or cancelling while the search was still scanning the history file
Fixed /rename on background sessions being reverted when the job restarts, which broke addressing the session by its new name
Fixed transient mTLS handshake failures when settings were re-applied during an in-place client certificate rotation
Fixed commands sent from Remote Control (mobile/web) into an interactive session failing with "Unknown command"
Fixed images and files sent from the Remote Control mobile or web app without a caption being silently dropped
Fixed the sign-in URL printed by claude auth login and claude mcp login --no-browser not being reliably clickable when it wraps over SSH — it is now emitted as a single hyperlink
Fixed opening a chat from claude agents sometimes failing with "currently running as a background agent" followed by a worker crash/respawn loop
Fixed workflow scripts with unicode quote escapes in strings being corrupted before parsing; workflow parse errors now show the offending line instead of always blaming TypeScript
Fixed voice dictation retrying in an unbounded loop when the microphone or audio recorder fails — repeated capture failures now pause voice input
Fixed /remote-control sessions showing the wrong permission mode in the mobile and web apps
Fixed resuming a session by name, or opening the resume picker, taking minutes and using a large amount of memory in repositories with many git worktrees
Fixed installer and updater downloads failing immediately with "aborted" when a proxy or network drops the connection mid-download — transient connection drops now retry
Fixed re-invoking an already-loaded skill appending a duplicate copy of its instructions to context
Improved /workflows agent list layout: wider titles, a dedicated time column, shorter model names, and no per-row tool-call counts
Improved MCP error messages: clearer error when a server config has url but no type, suggesting "type": "http" instead of the misleading "command: expected string"
Changed /review <pr> back to a fast single-pass review; use /code-review <level> <pr#> for the multi-agent review at a chosen effort level
Stacked slash-skill invocations like /skill-a /skill-b do XYZ now load all leading skills (up to 5), not just the first
Fixed SSL certificate errors (TLS-inspecting proxies, missing NODE_EXTRA_CA_CERTS, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hint
Fixed streaming responses being discarded when the API emits a mid-stream overloaded/server error after partial output — the partial is now kept with an incomplete-response notice
Fixed subagents cut off by a rate limit or server error silently failing instead of returning their partial work to the parent
Fixed subagents reporting API errors (e.g. usage limit reached) as successful results — the error is now reported to the parent agent
Fixed the background-agent daemon on Linux killing itself and every running agent every ~50 seconds after an unclean shutdown left a corrupted worker record
Fixed background agents failing to cold-start over SSH on macOS with "Could not switch to audit session" (regression in 2.1.196)
Fixed claude stop being silently undone when it raced a background-agent respawn — the respawn now honors the stop
Fixed background job progress indicators stalling for minutes while the job ran long commands
Fixed background sessions on memory-starved machines showing a generic error — they now indicate low memory and suggest freeing resources
Fixed remote sessions briefly flapping between Working and Idle in the agent view when a background agent completes
Fixed idle subagents vanishing from the agent panel while other subagents were still working; surplus idle agents now collapse into an expandable summary row
Fixed typing /model or /fast while viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the lead
Fixed SessionStart, Setup, and SubagentStart hooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcript
Fixed claude --dangerously-skip-permissions daemon <subcommand> being treated as a chat prompt instead of running the subcommand
Fixed SendMessage silently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget
Fixed opening or resuming a session with no new messages needlessly growing the transcript file
Fixed backgrounding a session with ← or /background dropping its /color from the agent view row
Fixed resetting a corrupted config file from the startup recovery dialog destroying it unrecoverably — it now backs up the file first
Fixed Claude in Chrome repeatedly opening the reconnect page when sessions run from different builds or config directories
Fixed plan mode not prompting for state-changing browser tool calls; read-only browser_batch calls are now correctly auto-allowed
Transient server rate-limit errors (429s unrelated to your usage limit) are now retried automatically with backoff for subscribers instead of failing the turn
CLAUDE_CODE_RETRY_WATCHDOG now raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 on CLAUDE_CODE_MAX_RETRIES
claude agents session rows now show pull-request links as bare #N without the redundant "PR" label
Subagents now run in the background by default, so Claude keeps working while they run and is notified when they finish (previously a gradual rollout)
Claude in Chrome is now generally available
Added background agent notifications in claude agents — sessions that need input or finish now fire the Notification hook (agent_needs_input / agent_completed)
Added /dataviz skill for chart and dashboard design guidance with a runnable color-palette validator
Gateway: added Claude Platform on AWS (anthropicAws) as an upstream provider; model-not-found responses now advance the failover chain
Background agents launched from claude agents now commit, push, and open a draft PR when they finish code work in a worktree, instead of stopping to ask
The built-in Explore agent now inherits the main session's model (capped at opus) instead of running on haiku
Subagents and context compaction now inherit the session's extended thinking configuration, improving output quality on delegated tasks
Fixed brief network drops mid-response aborting the turn — transient errors like ECONNRESET now retry with backoff instead of failing
Fixed excessive background classifier requests when sandboxed processes repeatedly accessed the same network host
Fixed background tasks in web, desktop, and VS Code task panels getting stuck on "Running" after they finish or after resuming a session
Fixed agent teams: a teammate that dies on an API error now reports "failed" to the lead, and messaging a stuck teammate wakes it to retry immediately
Fixed the /diff panel not refreshing when you switch branches or commit outside the session
Fixed markdown tables overflowing and wrapping their right border when rendered in fullscreen mode
Fixed Claude Platform on AWS and Mantle sessions dead-ending with "Please run /login" when the STS token expires — awsAuthRefresh now runs automatically
Fixed "no route to host" for local-network hosts in macOS background agent sessions by declaring Local Network entitlements
Fixed /desktop failing with "Cannot determine working directory" after entering and exiting a worktree
Fixed background agents repeatedly showing "Reconnecting…" every ~52 seconds on macOS while the agents view was open
Fixed pressing ← inside claude attach <id> exiting to the shell instead of opening the agent view
Fixed claude --bg silently creating an unattachable session when combined with --print/-p; the conflicting flags are now rejected up front
Fixed the workflow progress view dropping the earliest agents from the list while the phase counter stayed correct in SDK and desktop-app sessions
Fixed .claude/rules/ conditional rules not loading when the target file is reached via a symlinked path
Fixed Cmd+click not opening URLs in fullscreen mode in Warp on macOS
Fixed double-click word selection in fullscreen mode to select the entire URL including the scheme
Fixed plan mode not auto-allowing read-only tool calls when a session starts in plan mode
Fixed /branch deriving its default fork name from the compaction summary instead of the first real prompt
Improved focus mode: subagents launched in a turn now appear in its activity summary, and completed background notifications fold into a single count
Improved syntax highlighting accuracy in code blocks, diffs, and file previews by upgrading to highlight.js 11
Keyboard shortcut hints now show opt/cmd instead of alt/super when connected from a Mac over SSH
Improved API retry UX: the error reason is now shown after the second attempt, and a status page link replaces the spinner tip when the API is overloaded
/login now opens the sign-in dialog from the claude agents view instead of saying it isn't available
Subagents now treat messages from the agent that launched them as normal task direction; an agent's message is still never treated as the user's approval
Removed the /agents wizard; ask Claude to create or manage subagents, or edit .claude/agents/ directly
Introducing Claude Sonnet 5: now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2/$10 per Mtok through August 31. Update to version 2.1.197 for access. https://www.anthropic.com/news/claude-sonnet-5
Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in /model when you haven't picked one yourself
Added readable default names for sessions at start, making them easier to identify and message
Added clickable file attachments in chat — Cmd/Ctrl-click reveals the file in Finder/Explorer
Security: claude mcp list/get no longer spawn .mcp.json servers that a repo self-approved via a committed .claude/settings.json; untrusted workspaces show ⏸ Pending approval
Fixed waking a background job permanently deleting its conversation and re-running the original prompt when the transcript probe misread a real transcript; the file is now set aside, never deleted
Fixed the rate-limit warning flickering off and rate-limit telemetry being over-counted when multiple parallel requests were in flight at the moment a usage limit was hit
Fixed duplicate recap lines after a background session's turn: a schema-rejected StructuredOutput attempt no longer renders alongside its retry
Fixed PowerShell git diff/git grep, egrep/fgrep, and quoted search patterns containing | being reported as failures when they exit 1, matching Bash behavior
Fixed multiple claude agents side panel issues: keyboard focus getting stuck when opening an agent, background jobs losing their subagent types on every open, and sessions showing incorrect status while actively running
Fixed claude agents --dangerously-skip-permissions silently falling back to auto mode instead of showing the bypass disclaimer and applying bypass mode to spawned agents
Fixed mid-turn crash recovery for Remote sessions — sessions interrupted by a server restart now auto-resume on the next worker
Fixed sessions moved with /cd reappearing in the old directory's resume list after a non-graceful exit when the old path contained special characters
Fixed claude plugin validate skipping local plugins whose source is "." and stopping after the first error class
Fixed Esc Esc at an idle prompt not opening the rewind menu (regression); use Ctrl+C or Ctrl+X Ctrl+K to stop background agents
Fixed MCP OAuth requesting the authorization server's full scopes_supported catalog when no scope is specified, causing invalid_scope failures on GitLab self-hosted and other enterprise IdPs
Fixed /context showing 0 tokens for all tool groups on Bedrock
Fixed /deep-research misreporting verifier failures as "all claims refuted" instead of unverified
Fixed plugin dependency version pins not being honored when the marketplace was added as a local folder path backed by a git repo
Fixed claude agents session status: completed rows no longer flip between "Done" and "Needs your input", stalled agents are now labeled "Needs attention", and results that mention a PR show a clickable link
Fixed voice dictation swallowing spaces and spuriously starting a recording during very fast typing when voice mode is enabled
Improved background session reliability: long-running commands and workflows now survive the session's process being stopped, restarted, or updated — including on Windows, where background shells are handed off instead of being killed
Improved background agents: workers killed by a daemon restart are now automatically resumed from where they left off the next time the agents view opens
Improved /code-review workflow: merged five cleanup finders into one, cutting token usage by roughly 25%
Reduced per-frame rendering work in the terminal UI by skipping no-op subtree walks during streaming
The streaming idle watchdog is now on by default for all providers — it aborts and retries when a response stream produces no events for 5 minutes. Set CLAUDE_ENABLE_STREAM_WATCHDOG=0 to disable.
Remote Control is now disabled when ANTHROPIC_BASE_URL points at a non-Anthropic host, matching the existing behavior under CLAUDE_CODE_USE_BEDROCK/_VERTEX/_FOUNDRY
Changed opening the agents view from a foreground session to require a single ← press instead of two, matching the behavior in background sessions
Added CLAUDE_CODE_DISABLE_MOUSE_CLICKS to disable mouse click/drag/hover in fullscreen mode while keeping wheel scroll
Fixed hook matchers with hyphenated identifiers (e.g. code-reviewer, mcp__brave-search) accidentally substring-matching — they now exact-match. Use mcp__brave-search__.* to match all tools from a hyphenated MCP server.
Fixed voice dictation on macOS capturing silence in long-running sessions after the default input device changes
Fixed voice dictation auto-submit never firing for languages written without spaces (Japanese, Chinese, Thai)
Fixed external plugins enabled only by project .claude/settings.json not requiring explicit install consent on every loader path
Fixed /plugin Enable/Disable not working when a plugin's plugin.jsonname differs from its marketplace entry name
Fixed background jobs disappearing from claude agents or losing data when written by a newer Claude Code version
Fixed reopening a crashed background task showing a blank screen for up to 5 seconds instead of its restart
Fixed background agent daemons running unreachable when the control socket fails to start, blocking restarts
Improved voice mode on Linux: now distinguishes "no microphone" from "SoX not installed" when SoX is present but no audio capture device exists
Improved claude agents completed list to fill available vertical space; on short terminals the header compacts so live sessions stay visible
Improved Remote session startup with a provisioning checklist while the container starts
Added autoMode.classifyAllShell setting to route all Bash/PowerShell commands through the auto-mode classifier instead of only arbitrary-code-execution patterns
Added auto-mode denial reasons to the transcript, the denial toast, and /permissions recent denials
Added claude_code.assistant_response OpenTelemetry log event containing the model's response text. Redacted unless OTEL_LOG_ASSISTANT_RESPONSES=1; when that var is unset it follows OTEL_LOG_USER_PROMPTS, so deployments that already log prompt content will start receiving response content on upgrade — set OTEL_LOG_ASSISTANT_RESPONSES=0 to keep prompts-only.
Added live file path autocomplete to bash mode (!)
Added a startup notice when MCP servers need authentication, pointing at /mcp
Added automatic memory-pressure reaping for idle background shell commands (disable with CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP=1)
Fixed /model and other client-data-gated UI showing stale/empty state immediately after /login
Fixed backgrounding (←←) spuriously cancelling with "N background tasks would be abandoned" when all running tasks carry over to the new session
Fixed pinned background agents being re-prompted to "Continue from where you left off" after every auto-update
Fixed backgrounding the main turn spawning a phantom "general-purpose (resumed)" subagent that re-ran the main conversation
Fixed agent panel hiding sibling agents when viewing a subagent
Improved background agents: the launch result no longer instructs Claude to "end your response" — it keeps working on other tasks while the agent runs
Improved MCP headersHelper auth: the helper now re-runs and reconnects automatically when a tool call returns 401/403
Improved plugin auto-rename: marketplace renames maps are now followed automatically, updating your settings to the new name
Improved /add-dir message when the directory is already a working directory
The stream-stall hint now reads "Waiting for API response · will retry in …" instead of "No response from API · Retrying in …", and triggers after 20s of silence instead of 10s
Fixed mid-stream connection drops: partial responses are now preserved instead of showing a raw error, and the spinner no longer gets stuck at "running tool"
Fixed mouse-wheel scrolling in WSL2 under Windows Terminal and VS Code (regression in 2.1.172)
Fixed a sandbox denyRead/allowRead glob over a large directory tree making the Bash tool description enormous and the session unusable on Linux
Fixed the feedback survey capturing a single-digit reply as a session rating immediately after a turn completes
Fixed the welcome screen stacking multiple promotional banners — at most one promo now shows per session
Fixed Ctrl+O not showing the subagent's transcript when viewing a subagent
Fixed clicking the prompt input not returning focus from the subagent/footer panel
Fixed remote session background tasks appearing stuck as "still running" between turns
Improved plugin loading performance in remote sessions
Added enforceAvailableModels managed setting — when enabled, the availableModels allowlist also constrains the Default model (a Default that would resolve to a disallowed model now falls back to the first allowed model), and user or project settings can no longer widen a managed availableModels list
Sub-agents can now spawn their own sub-agents (up to 5 levels deep)
Amazon Bedrock now reads the AWS region from ~/.aws config files when AWS_REGION isn't set, matching AWS SDK precedence; /status shows where the region came from
Added a search bar when browsing a marketplace's plugins in /plugin
Added model attribute to the claude_code.lines_of_code.count OTEL metric
Fixed sessions using 1M context without usage credits getting permanently stuck — the session now automatically compacts back under the standard context limit
Fixed a repeating "an image in the conversation could not be processed and was removed" error when the conversation contained multiple images
Fixed the agents view keeping a session under Working with a busy spinner for up to 30 seconds after the worker replied
Fixed background agents potentially reading another directory's project settings (.mcp.json approvals, trust) when dispatched onto a pre-warmed worker
Fixed background-session attach failing with EAUTH for sessions started on an older version after the daemon auto-updated
Fixed a background sub-agent staying stuck as "active" in the agent panel after a nested agent it spawned was stopped
Fixed /model suggestions in the claude agents dispatch input rendering with a misleading slash prefix and showing models disabled for your org
Fixed availableModels restrictions not being applied to subagent model overrides, the agent dispatch model picker, and the advisor model
Fixed availableModels allowlists hiding the /model picker's Opus and Sonnet 1M rows when entries use version-specific IDs like claude-opus-4-8
Fixed the /model picker on Bedrock offering models the provider doesn't serve — selecting one silently switched the session model and lit the selection marker on multiple rows
Fixed model IDs getting a doubled 1M-context suffix (e.g. [1M][1m]) when ANTHROPIC_DEFAULT_OPUS_MODEL already includes one
Fixed opusplan model setting not shipping with 1M context in plan mode for entitled users; the opusplan[1m] workaround now also correctly switches to Opus in plan mode
Fixed WebFetch(domain:*.example.com) wildcard domain rules never matching subdomains in allow, deny, and ask position, and file permission rules with mid-pattern wildcards (e.g. Read(secrets-*/config.json)) being rejected at startup
Fixed up-arrow prompt history showing the main agent's prompts while a subagent's chat tab is open
Fixed memory recall not finding mounted team memory stores (CLAUDE_MEMORY_STORES) in remote sessions
Disable mouse tracking on Windows consoles that don't fully support it
Fixed the /plugin marketplace list losing its cursor after backing out of a long plugin list, and Esc from the plugin browser returning to the wrong tab
Improved performance in long conversations by removing redundant message normalization and avoiding full message-history transforms when streaming tool-use state is unchanged
Reduced idle CPU usage: /goal status chip no longer re-renders the terminal at 5 Hz while idle, and fewer UI re-renders while subagents run in parallel
Improved Claude in Chrome tool loading: browser tools now load in a single batched call instead of one per tool
Improved the non-interactive Usage Policy refusal message to suggest starting a new session or changing your model
/code-review now keeps the ultra option visible when you're not signed in to claude.ai, with an explanation that the cloud review requires a claude.ai account
Shortened the Remote Control footer indicator to "/rc active" and hid it on narrow terminals
Stopped promoting /loop in remote sessions, where pending loops don't keep the container alive
[VSCode] Fixed PowerShell tool calls rendering as raw JSON instead of a proper command display and permission dialog, and stripped ANSI escape codes from displayed shell output
OTEL_RESOURCE_ATTRIBUTES values are now included as labels on metric datapoints, so you can slice usage metrics by custom dimensions like team or repo
claude agents rows now show done/total before the detail when work is fanned out; peek shows the longest-running item
/mcp now collapses claude.ai connectors you've never signed in to behind a "Show unused connectors" row
Parallel tool calls: a failed Bash command no longer cancels other calls in the same batch — each tool returns its own result independently
Fullscreen mode: clipboard now uses wl-copy/xclip/xsel on Linux when available, copies to both the clipboard and PRIMARY selection for middle-click paste, and the "hold {key} for native selection" hint now shows the correct key per terminal
Fixed the /effort dialog, workflow animations, and prompt keyword shimmer not honoring the "Reduce motion" setting
Fixed forceLoginOrgUUID/forceLoginMethod managed-settings policies blocking third-party provider sessions (Bedrock, Vertex, Foundry, Mantle) alongside the org pin (regression in 2.1.146)
Fixed background subagent output corrupting claude -p stdout when using --output-format text or json
Fixed /usage-credits starting a re-login for Team and Enterprise admins instead of pointing to the organization's usage settings page
Fixed /autofix-pr reporting "cannot run on the default branch" when the session is inside a git worktree or another repository
Fixed --resume picker not showing sessions from the current directory when it isn't a git worktree (e.g., jj workspaces)
Fixed Windows hooks that invoke bash explicitly (e.g., /usr/bin/bash script.sh) failing with "command not found" or "cannot execute binary file"
Fixed OpenTelemetry log events (user_prompt, api_request, tool_result, tool_decision) being silently dropped when emitted before telemetry initialization completed
Fixed claude mcp list/get/add printing secrets to the terminal: ${VAR} references are no longer expanded, and credential headers and URL secrets are redacted
Fixed Workflow agents spawned with isolation: "worktree" in background sessions being blocked from editing files inside their own worktree
Fixed background sessions dispatched from claude agents booting on a stale model from the daemon's environment instead of the model in settings.json
Fixed a potential crash when rendering Write tool results after resuming a session
Fixed completed subagents getting stuck showing as running when an error occurs while finalizing their result
Fixed EADDRINUSE errors from tools that bind Unix sockets under $TMPDIR when CLAUDE_CODE_TMPDIR is set to a deep path
Improved terminal rendering performance by stabilizing the layout engine's JIT compilation profile
Improved rendering performance for large file writes
[VSCode] Added a tip suggesting disabling terminal GPU acceleration (or running /terminal-setup) to fix garbled glyphs
Opus 4.8 is here! Now defaults to high effort · /effort xhigh for your hardest tasks
Introducing dynamic workflows: ask Claude to create a workflow and it orchestrates work across tens to hundreds of agents in the background, so you can take on larger, more complex tasks. Run /workflows to view your runs
Fast mode on Opus 4.8 is now available at a fraction of its previous cost: 2x the standard rate for 2.5x the speed
The lean system prompt is now the default for all models except Haiku, Sonnet, and Opus 4.7 and earlier
Claude now reserves the multiple-choice question prompt for decisions it genuinely cannot make itself, instead of asking when it already has enough context to proceed
/simplify now runs a cleanup-only review (reuse, simplification, efficiency, altitude) and applies the fixes, instead of running the full /code-review --fix bug-hunting review
Renamed the /effort slider labels from "Speed"/"Intelligence" to "Faster"/"Smarter" for clarity
claude agents: type ! <command> to run a shell command as a background session you can attach to and detach from. Also available as claude --bg --exec '<command>'
claude agents: /logout now signs you out instead of being sent to a background session
←← to open the agents view now works on Bedrock, Vertex, Foundry, and with telemetry disabled
Claude in Chrome: pick which connected browser to use via /chrome → "Select browser…", or in-chat when a browser action runs with multiple connected
Plugins can now declare defaultEnabled: false in plugin.json or a marketplace entry; enable them with /plugin or claude plugin enable. Dependencies of enabled plugins are still enabled automatically
The /plugin Discover tab now pins plugins whose relevance signals match the current directory with a "suggested for this directory" annotation
Streaming tool execution is now always enabled, including when telemetry is disabled or on Bedrock/Vertex/Foundry (previously behind a feature flag)
Stdio MCP server subprocesses now receive CLAUDE_CODE_SESSION_ID and CLAUDECODE=1 in their environment
claude mcp list/get now show unapproved .mcp.json servers as ⏸ Pending approval instead of auto-approving and connecting when output is piped
/remote-control autocomplete now shows "Disconnect Remote Control" when Remote Control is already active
Added Claude Opus 4.8 support and 4.7 → 4.8 migration guidance to the /claude-api skill
Deprecated CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE (will be removed on 06/01). To use fast mode on Opus 4.6, switch with /model claude-opus-4-6[1m] and then /fast on
Improved the auto-mode classifier's detection of data exfiltration, particularly bulk transfers of repository contents
Fixed rm -rf $HOME not being blocked as a dangerous path when HOME has a trailing slash
Fixed $TMPDIR resolving to different directories in sandboxed vs unsandboxed Bash commands within the same session
Fixed unreadable highlighted-row text in claude agents when the Claude Code theme doesn't match the terminal background
Fixed background-agent completion notifications triggering premature "out of context" behavior on some 1M-context models
Fixed background-session classifier losing the user's goal when a scheduled /command fires
Fixed pinned background sessions respawning every minute after a Claude Code update, causing repeated agent-start notifications and process churn at idle
Fixed background sessions stuck at "blocked", "running", or "working" not retiring after the idle grace period
Fixed subagents in background sessions bypassing the worktree-isolation guard and writing to the shared checkout
Fixed orphaned claude --bg-pty-host processes spinning at 100% CPU after the daemon exits on macOS
Fixed number key shortcuts not working for options shown below the divider in option dialogs
Fixed worktree.baseRef: "head" resolving to the main checkout's HEAD instead of the current worktree's HEAD when spawning subagents or calling EnterWorktree from inside a linked worktree
Fixed a stray leading space on wrapped lines when the previous line ended exactly at the terminal width
Fixed intermittent terminal rendering corruption in VS Code by capping the number of distinct colors the thinking spinner produces
Fixed plan file names including [Image #N] / [Pasted text #N] placeholders when a plan-mode prompt starts with pasted images or text
Fixed a phantom expand/click affordance on colored tool output: short ANSI-colored lines that fit on screen no longer show a "ctrl+o to expand" hint
Fixed a single invalid allowedMcpServers/deniedMcpServers entry in managed settings discarding all managed-settings policy; the bad entry is now dropped with a claude doctor warning
Fixed API 400 errors on models that don't support the effort parameter when CLAUDE_CODE_ALWAYS_ENABLE_EFFORT is set
Windows: Fixed update failures caused by claude.exe being in use showing a generic error instead of telling you to close other sessions and retry
Removed the stale "& for background" hint from the shortcuts help panel
[VSCode] Auto mode no longer requires the bypass-permissions setting to appear in the mode picker, and a dismissable notice on the new-session screen explains auto mode the first time it's active
Fixed the task panel below the prompt showing a stray unselectable "main" row when only a workflow is running
Fixed /mcp tools list and tool detail rendering when MCP servers have long or multi-line tool names or long descriptions
Fixed the /model picker not showing fast mode pricing on the Default option for API (pay-as-you-go) users when fast mode is on
Fixed auto mode incorrectly blocking actions with "could not evaluate this action" when the safety classifier ran out of output tokens while reasoning
/code-review --fix now applies review findings to your working tree after the review, surfacing reuse, simplification, and efficiency suggestions; /simplify now invokes /code-review --fix
Skills and slash commands can now set disallowed-tools in frontmatter to remove tools from the model while the skill is active
Added /reload-skills command to re-scan skill directories without restarting the session
SessionStart hooks can now return reloadSkills: true to re-scan skill directories, making skills installed by the hook available in the same session
SessionStart hooks can now set the session title via hookSpecificOutput.sessionTitle on startup and resume
Added a MessageDisplay hook event that lets hooks transform or hide assistant message text as it is displayed
Added pluginSuggestionMarketplaces managed setting: admins can allowlist org marketplaces whose plugins may be suggested via context-aware tips
claude plugin marketplace remove now accepts --scope user|project|local for symmetry with marketplace add, install, and uninstall
Claude Code now switches to your configured --fallback-model for the rest of the session when the primary model is not found, instead of failing every request
Auto mode no longer requires opt-in consent
Vim mode: / in NORMAL mode now opens reverse history search (like Ctrl+R), matching bash/zsh vi-mode
The /usage breakdown now includes large session files; files are scanned with a streaming read so memory usage stays flat
Thinking summaries in the collapsed group now stay readable for at least 3 seconds, render as markdown, and cap at 10 lines (Ctrl+O shows the full thinking)
In fullscreen mode, the "Thinking for Ns" indicator now counts up live while the model is thinking, and keeps its value if you interrupt mid-thought
Simplified the Workflow tool's inline progress display — live agent counts now show only in the persistent workflow status row below the prompt
The post-response timer now shows "Waiting for N background agents/workflows to finish" when backgrounded agents or workflows are still running, and reports the cumulative time once their results are processed
Added the session entrypoint as an OpenTelemetry metric attribute (app.entrypoint, opt-in via OTEL_METRICS_INCLUDE_ENTRYPOINT=true)
Fixed terminal styling degrading in very long sessions by recycling the renderer's style pool
Fixed the sandbox-enabled warning not appearing in condensed startup mode — it now shows in every layout
Fixed the loading spinner showing "still thinking"/"almost done thinking" while a tool is running, and reset the thinking status to "thinking" after each tool
Fixed focus mode showing a spurious "N messages hidden" count on turns with no hidden activity
Fixed clicking a link inside an expanded tool result collapsing the section instead of opening the link
Fixed markdown table cell borders inheriting the color of inline code, wrapped continuation lines losing their style, and empty header cells showing a label in the narrow-terminal stacked layout
Fixed plugin MCP servers with the same command but different environment variables being incorrectly deduplicated
Fixed /doctor reporting "marketplace not found" or "plugin not found" for stale enabledPlugins entries referencing removed marketplaces or dropped plugins
Fixed plugins that track a git branch silently no longer receiving updates after the plugin registry was rebuilt
Fixed remote MCP servers failing to connect in Claude Code Remote sessions when the egress proxy is enabled
Fixed the effort-change confirmation dialog appearing when the conversation has no messages or when switching between effort levels that resolve to the same underlying value
Fixed the Agent tool description referencing an agent list that is never delivered when running with --bare or with attachments disabled
Fixed a background worker crash in claude agents when accepting a stale permission prompt after a subagent was cancelled
Fixed cache_creation_input_tokens reporting as 0 in transcript and result usage when the API reports cache writes only via the nested cache_creation breakdown
Fixed the PushNotification tool incorrectly reporting "Mobile push not sent (Remote Control inactive)" in SDK-hosted sessions when Remote Control is enabled
Fixed sessions getting stuck after a model or login switch left stale thinking-block signatures in history; now stripped proactively with a retry safety-net
Added claude agents --json to list live Claude sessions as JSON for scripting (tmux-resurrect, status bars, session pickers)
Added agent_id and parent_agent_id attributes to claude_code.tool OTEL spans, and fixed trace parenting so background subagent spans nest under the dispatching Agent tool span
Status line JSON input now includes GitHub repo and PR information when detected
/plugin Discover and Browse screens now show a plugin's commands, agents, skills, hooks, and MCP/LSP servers before installation
claude agents terminal tab title now shows the awaiting-input count so an alt-tabbed window tells you when an agent needs attention
Slash command and @-mention suggestion list now supports mouse hover and click in fullscreen mode
Stop and SubagentStop hook input now includes background_tasks and session_crons fields
Fixed a permission-prompt bypass where bare variable assignments to non-allowlisted environment variables in Bash commands were auto-approved
Fixed MCP prompt slash commands showing raw server validation errors when a required argument is omitted — the error now names the missing argument and shows expected usage
Fixed the spinner and elapsed-time display freezing until a keypress after the terminal was resized or refocused
Fixed the cross-project resume hint failing in default Windows PowerShell 5.1 — Windows now uses ; as the command separator
Fixed voice push-to-talk not working in the agent view's reply pane
Fixed task lists rendering in random order when several tasks are created at once
Fixed stale "Failed to install Anthropic marketplace" banner showing when the marketplace is already installed
Fixed the PR badge in the footer not updating immediately after gh pr create and other PR-state-changing commands run in-session
Fixed Agent Teams teammates with non-ASCII names failing every API call due to invalid header encoding
Fixed /review using a deprecated projectCards GraphQL query that errored on repos with Classic Projects
Fixed claude plugin validate not flagging skills: entries that point at a file instead of a directory — the error now suggests the parent directory
Fixed an infinite loop where a skill using context: fork could repeatedly re-invoke itself instead of running
Improved the Read tool to return a truncated first page with a "PARTIAL view" notice instead of a hard error when a whole-file read exceeds the token limit
Added plugin dependency enforcement: claude plugin disable now refuses when another enabled plugin depends on the target (with a copy-pasteable disable-chain hint), and claude plugin enable force-enables transitive dependencies
Added projected context cost (per-turn and per-invocation token estimates) to the /plugin marketplace browse pane
Added worktree.bgIsolation: "none" setting to let background sessions edit the working copy directly without EnterWorktree, for repos where worktrees are impractical
PowerShell tool now passes -ExecutionPolicy Bypass. Opt out with CLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY=1
Background sessions now preserve the model and effort level you set after waking from idle
Shift+Tab in attached agent sessions now includes auto mode in the cycle
Fixed a corrupt .credentials.json with a non-array scopes value hanging the CLI on startup or silently aborting OAuth token refresh
Fixed right-click paste in claude agents on Windows Terminal and WSL
Fixed stop hooks that block repeatedly looping forever — the turn now ends with a warning after 8 consecutive blocks (override via CLAUDE_CODE_STOP_HOOK_BLOCK_CAP)
Fixed Esc/Ctrl+C not cancelling a pending /loop wakeup while Claude is idle between iterations
Fixed /goal evaluator firing while background shells or delegated subagents are still running
Fixed NO_COLOR/FORCE_COLOR in settings.json env stripping Claude Code's own UI colors — they now apply to subprocesses only
Fixed agent view spawning repeated PowerShell processes on Windows when listing sessions
Fixed /bg without a prompt sending "continue" to the forked session — the fork now waits for input
Fixed --agent <name> not finding plugin-contributed agents without the plugin: prefix
Fixed deleting a session from agent view not removing its transcript file
Fixed stale-fragment rendering when scrolling in attached background sessions on Windows Terminal
Fixed background agents false-positive worker-stall detection storm after host sleep or macOS App Nap
Fixed 5xx error messages pointing at status.claude.com instead of naming the configured gateway or cloud provider
The PowerShell tool is now enabled by default on Windows for Bedrock, Vertex, and Foundry users. Opt out with CLAUDE_CODE_USE_POWERSHELL_TOOL=0.
claude agents now accepts --add-dir, --settings, --mcp-config, and --plugin-dir and applies them to the dashboard and to background sessions dispatched from it
claude agents accepts --permission-mode, --model, --effort, and --dangerously-skip-permissions to set defaults for sessions dispatched from the view
claude --bg --dangerously-skip-permissions now persists across retire→wake
Fixed background sessions silently capturing IDE file references into the warm spare's input, which caused the reference to be prepended to the next prompt dispatched from claude agents
Worktree cleanup no longer falls back to rm -rf when git worktree remove fails, preventing loss of gitignored or in-progress files
Fixed background-job sessions on macOS getting "Operation not permitted" errors when reading files under ~/Documents, ~/Desktop, or ~/Downloads, even with Full Disk Access granted.
/bg now preserves --mcp-config, --settings, --add-dir, --plugin-dir, and --strict-mcp-config, so backgrounded sessions keep their MCP servers and settings across respawn.
Background sessions launched from claude agents now honor permissions.defaultMode from settings.json (was previously overridden to auto mode)
Fixed: on Windows, pressing ← in claude agents while a response was streaming could leave the agents list unresponsive to all input
/bg and ←-detach now preserve --fallback-model, so backgrounded workers degrade to the fallback model on overload instead of hard-failing.
/bg and ←-detach now preserve --allow-dangerously-skip-permissions, so the forked worker keeps bypass-permissions available in its Shift+Tab cycle.
Fixed: background daemon spawn now falls back to the running binary when the ~/.local/bin/claude launcher is missing or non-executable
Fixed claude agents --allow-dangerously-skip-permissions defaulting dispatched sessions to bypass mode instead of making it available in the permission cycle
Added terminalSequence field to hook JSON output so hooks can emit desktop notifications, window titles, and bells without a controlling terminal
Added CLAUDE_CODE_PLUGIN_PREFER_HTTPS to clone GitHub plugin sources over HTTPS instead of SSH, for environments without a GitHub SSH key
Added ANTHROPIC_WORKSPACE_ID environment variable for workload identity federation — scopes the minted token to a specific workspace when the federation rule covers more than one
Added claude agents --cwd <path> to scope the session list to a directory
/feedback can now include recent sessions (last 24 hours or 7 days) for issues spanning more than the current session
Rewind menu: added "Summarize up to here" to compress earlier context while keeping recent turns intact
Auto mode permission dialog now explains when a permissions.ask rule caused the prompt
Restored the "view diff in your IDE" option on file-edit permission prompts when an IDE is connected
Background agents launched via /bg or ←← now preserve the current permission mode instead of reverting to default
claude agents: agents that finish work but leave a background shell running now move to Completed instead of staying under Working
Improved spinner feedback during long thinking periods — the spinner now warms to amber after 10 seconds to signal Claude is still working
Improved plugin menu navigation: →/Tab switch tabs, ↑ moves to the tab strip, and tab headers and search box are clickable in fullscreen mode
Fixed background side-queries sending an unavailable Haiku model ID on Bedrock/Vertex/Foundry/gateway when no ANTHROPIC_SMALL_FAST_MODEL override is set — now falls back to the main-loop model
Fixed claude daemon status and /doctor on Windows throwing when the daemon pipe key file is locked or unreadable — now shows the underlying error instead of an opaque failure
Fixed claude agents showing the agent-type list instead of the dashboard when launched through a wrapper that adds flags
Fixed claude agents opening a crashed session firing redundant dispatches when the working directory was deleted
Fixed background jobs on a custom ANTHROPIC_BASE_URL gateway not getting auto-named — the namer now uses the main model when no Haiku model is configured
Fixed /model in one session silently changing the autocompact threshold in other concurrent sessions
Fixed switching permission mode while a tool-permission prompt is open not auto-dismissing the prompt when the new setting permits the tool
Fixed pressing Enter while a permission/dialog prompt is open also submitting text in the input box
Fixed hooks receiving a non-existent transcript_path after EnterWorktree switches the working directory
Fixed markdown tables with cell wrapping falling back to the vertical key-value layout instead of rendering as a bordered grid (regression in 2.1.136)
Fixed cancelled prompts being removed from Up-arrow history when auto-restored into the input box, avoiding duplicate entries
Fixed prompts cancelled with Ctrl+C/Esc before any response being dropped from Up-arrow history
Fixed Ctrl+C not interrupting a running turn while in vim INSERT/VISUAL mode
Fixed alternative chat:submit keybindings (e.g. meta+enter, ctrl+enter) not working when enter is rebound to chat:newline
Fixed prompt suggestions being silently disabled when an output style was configured
Fixed spinnerVerbs setting not being honored in turn-completion messages
Fixed AskUserQuestion popup hiding the last line of preceding chat content
Fixed Web Search status showing "Did 0 searches" when searches returned errors
Fixed multi-line statusline output dropping or corrupting rows when any line exceeds terminal width
Fixed light-ansi theme using invisible white for diff context lines on light backgrounds — now uses black
Fixed error overlay dumping minified bundle source that hid the original error message
Fixed pressing Enter after typing a feedback survey rating digit submitting it as a chat message instead of the rating
Fixed pressing x on a selected subagent in the agent panel typing into the prompt instead of stopping the agent
Fixed session title being derived from plugin monitor notifications before the user's first prompt
Fixed "Allowed by PermissionRequest hook" repeating once per tool call under a collapsed read/search group
Fixed /tui silently dropping running background shells and subagents — now refuses and asks to wait for them to finish
Fixed welcome banner showing "API Usage Billing" on Bedrock, Vertex, Foundry, and other third-party providers — now shows the provider name
Fixed /mcp server list not keeping the focused server visible in short terminals in fullscreen mode
Fixed redaction in /feedback bundles producing invalid JSON for quoted values like session IDs
Fixed desktop and third-party provider sessions incorrectly inheriting apiKeyHelper/ANTHROPIC_AUTH_TOKEN from host managed-settings
Fixed early analytics events being silently dropped when fired before logger initialization
Fixed claude plugin install failing for plugins whose marketplace ref no longer exists upstream when a sha is also pinned
Fixed plugin details pane showing 0 MCP servers for plugins that declare them via .mcp.json
Fixed plugin MCP servers with unset config variables showing a generic connection failure instead of a "config issue" message with a fix-it hint; malformed .mcp.json entries no longer drop other MCP servers
Fixed MCP server configs using POSIX shell parameter expansions (e.g. ${var%pattern}) being incorrectly flagged as missing environment variables
Fixed MCP HTTP/SSE servers returning 403 on connect showing as "failed" instead of "needs auth"
Fixed remote MCP servers disconnecting unnecessarily when the optional server-events stream failed to reconnect — tool calls continue over POST
Fixed Remote Control MCP connectors all failing with 401 when the worker session token rotated mid-session
Fixed Remote Control automatically re-enrolling a trusted device when the server rejects a stale token, instead of looping through /login
Fixed a race where early OTel spans could be silently dropped in SDK/headless mode with beta tracing enabled
Fixed custom voice:pushToTalk keybindings and "space": null unbinds being silently ignored
Fixed Windows Alt+V image paste reporting "no image found" when the clipboard contains a screenshot
Fixed SDK "Claude Code native binary not found" on Linux when both glibc and musl platform packages are installed
Bedrock: awsCredentialExport now always runs when configured instead of being skipped when ambient AWS credentials resolve, fixing auth for cross-account access
[VSCode] Fixed in-chat mic showing no feedback when the microphone produced only silence — now shows "No audio detected"
[VSCode] Voice mode: the WSL error now suggests installing sox libsox-fmt-pulse for WSLg users
claude agents: launching a session no longer fails when the pre-warmed background worker is unhealthy — now falls back to a fresh launch
claude agents no longer shows empty placeholder sessions left over from backgrounding a fresh REPL, and shows onboarding text when entered via ← with no other agents
Empty idle background sessions left over from ← are now automatically retired by the daemon after 5 minutes
Improved Agent tool subagent_type matching to accept case- and separator-insensitive values (e.g. "Code Reviewer" resolves to code-reviewer)
Updated agent color palette
Fixed /goal silently hanging when disableAllHooks or allowManagedHooksOnly is set — now shows a clear message instead of an indicator that never resolves
Fixed a regression in settings hot-reload where symlinked settings files caused misattributed change events and spurious ConfigChange hooks
Fixed claude --bg failing with "connection dropped mid-request" when the background service was about to idle-exit
Fixed background service startup failing on machines with enterprise endpoint security by allowing more time
Fixed remote managed settings not retrying on 401 — now retries once with a force-refreshed token
Fixed managed extraKnownMarketplaces auto-update policy not being persisted to known_marketplaces.json
Fixed /loop scheduling redundant wakeups to poll for background tasks that already notify on completion
Fixed a recurring event-loop stall on Windows when a missing executable (e.g. gh) triggered synchronous where.exe re-spawns on every check
Fixed Read tool calls failing validation when offset is passed as a whitespace-padded or +-prefixed string
Fixed native terminal cursor not staying at the input caret when the terminal loses focus
Plugins now warn when a default component folder (e.g. commands/) is silently ignored because plugin.json sets the matching key. Shown in /doctor, claude plugin list, and /plugin.
Added worktree.baseRef setting (fresh | head) to choose whether --worktree, EnterWorktree, and agent-isolation worktrees branch from origin/<default> or local HEAD. Note: the default fresh changes EnterWorktree's base back to origin/<default> (it has been local HEAD since 2.1.128) — set worktree.baseRef: "head" to keep unpushed commits in new worktrees
Added sandbox.bwrapPath and sandbox.socatPath managed settings (Linux/WSL) to specify custom bubblewrap and socat binary locations
Added parentSettingsBehavior admin-tier key ('first-wins' | 'merge') to let admins opt SDK managedSettings (parent tier) into the policy merge
Hooks now receive the active effort level via the effort.level JSON input field and the $CLAUDE_EFFORT environment variable, and Bash tool commands can read $CLAUDE_EFFORT
Improved focus mode behavior
Improved memory usage by releasing warm-spare background workers under memory pressure
Fixed parallel sessions all dead-ending at 401 after a refresh-token race wiped shared credentials
Fixed Edit/Write allow rules scoped to a drive root (C:\) or POSIX / matching incorrectly and always prompting
Fixed an unhandled rejection (ECOMPROMISED) when a history or session-log file lock is compromised by clock skew or slow disk
Fixed pressing Esc during conversation compaction showing a spurious "Error compacting conversation" notification
Fixed HTTP(S)_PROXY / NO_PROXY / mTLS not being respected for the full MCP OAuth flow including discovery, dynamic client registration, token exchange, and token refresh
Fixed Read/Write/Edit being denied on mapped network drives passed via --add-dir / SDK additionalDirectories
Fixed Remote Control stop/interrupt from claude.ai not fully canceling the CLI session the same way local Esc does, causing queued messages to never advance after interrupting a stuck tool or prompt
Fixed /effort in one session unexpectedly changing the effort level of other concurrent sessions, and a related issue where an IDE effort change could be silently dropped
Fixed subagents not discovering project, user, or plugin skills via the Skill tool
claude --help now lists --remote-control alongside --remote-control-session-name-prefix
[VSCode] Fixed claudeCode.claudeProcessWrapper failing with "Unsupported platform" when the extension build doesn't bundle a Claude binary
Bare /color (no args) now picks a random session color
/mcp now shows the tool count for connected servers and flags servers that connected with 0 tools
--plugin-dir now accepts .zip plugin archives in addition to directories
--channels now works with console (API key) authentication — console orgs with managed settings must set channelsEnabled: true to enable
Updated /model picker: collapsed duplicate Opus 4.7 entries, and current Opus now shows as "Opus" instead of "Opus 4.7"
Subprocesses (Bash, hooks, MCP, LSP) no longer inherit OTEL_* environment variables, so OTEL-instrumented apps run via the Bash tool no longer pick up the CLI's own OTLP endpoint
MCP: workspace is now a reserved server name — existing servers with that name will be skipped with a warning
Reconnecting MCP servers no longer flood the conversation with full tool-name lists on every reconnect — re-announced tools are summarized by server prefix
SDK hosts now receive a persistent localSettings suggestion for Bash permission prompts, so "Always allow" writes to .claude/settings.local.json
EnterWorktree now creates the new branch from local HEAD as documented, instead of origin/<default-branch> — unpushed commits are no longer dropped
Auto mode: when the classifier can't evaluate an action, the error now includes a hint (retry, /compact, or run with --debug)
Fixed focus mode briefly dimming the previous response when submitting a new prompt
Fixed stray "4;0;" desktop notification on every /exit in Kitty and other terminals that interpret OSC 9 as a notification
Fixed Remote Control showing an empty "Opening your options…" message on rate limit instead of actionable upsell options
Fixed drag-and-drop image upload hanging on "Pasting text…" when the image read fails
Fixed crash loop when piping very large input (>10 MB) to claude -p via stdin
Fixed long URLs not being individually clickable on every wrapped row in fullscreen mode
Fixed /plugin Components panel showing "Marketplace 'inline' not found" for plugins loaded via --plugin-dir
Fixed MCP tool results dropping images when the server returns both structured content and content blocks
Fixed fenced code blocks inside list items carrying leading whitespace into the clipboard on copy-paste
Fixed tab navigation in /config stranding focus — the tab header now stays focused so arrows and Esc keep working
Fixed markdown link labels being lost on terminals without OSC 8 hyperlink support — links now render as label (url) instead of just the URL
Fixed sessions on 1M-context models with a smaller autocompact window being falsely blocked with "Prompt is too long" before reaching the actual API limit
Fixed parallel shell tool calls: a failing read-only command (grep, git diff, ls) no longer cancels sibling calls
Fixed banner showing "with X effort" on models that don't support effort
Fixed /fast on 3P providers fuzzy-matching to an unrelated skill instead of showing "not available"
Fixed Bedrock default model resolving to global.* instead of the region-appropriate prefix
Fixed vim mode: Space in NORMAL mode now moves the cursor right, matching standard vi/vim behavior
Fixed terminal progress indicator (OSC 9;4) flickering off between tool calls — stays visible across the full turn
Fixed /rename without args failing on resumed sessions whose last entry is a compact boundary
Fixed stale "remote-control is active" status lines from prior sessions appearing after --resume/--continue
Fixed stale installed_plugins.json entries pointing at deleted cache directories polluting PATH
Fixed MCP stdio servers receiving corrupted arguments when CLAUDE_CODE_SHELL_PREFIX is set and an argument contains spaces or shell metacharacters
Added alwaysLoad option to MCP server config — when true, all tools from that server skip tool-search deferral and are always available
Added claude plugin prune to remove orphaned auto-installed plugin dependencies; plugin uninstall --prune cascades
Added a type-to-filter search box to /skills so you can find a skill in long lists without scrolling
PostToolUse hooks can now replace tool output for all tools via hookSpecificOutput.updatedToolOutput (previously MCP-only)
Fullscreen mode: typing into the prompt no longer jumps scroll back to the bottom after you've scrolled up to read earlier output
Dialogs that overflow the terminal are now scrollable with arrow keys, PgUp/PgDn, home/end, and mouse wheel in both fullscreen and non-fullscreen modes
Clicking any line of a long URL that wraps across rows in fullscreen mode now opens the full URL
SDK and claude -p: CLAUDE_CODE_FORK_SUBAGENT=1 now works in non-interactive sessions
--dangerously-skip-permissions no longer prompts for writes to .claude/skills/, .claude/agents/, and .claude/commands/
/terminal-setup now enables iTerm2's "Applications in terminal may access clipboard" setting so /copy works, including from tmux
MCP servers that hit a transient error during startup now auto-retry up to 3 times instead of staying disconnected
The terminal tab session title is now generated in your configured language setting
Claude.ai connectors with the same upstream URL are now deduplicated instead of appearing as duplicates
Vertex AI: support X.509 certificate-based Workload Identity Federation (mTLS ADC)
Faster startup after upgrading: removed the Recent Activity panel from the release-notes splash
LSP diagnostic summaries now expand on click/ctrl+o and show the expand hint
SDK: mcp_authenticate now supports redirectUri for custom scheme completion and claude.ai connectors
OpenTelemetry: added stop_reason, gen_ai.response.finish_reasons, and user_system_prompt (gated behind OTEL_LOG_USER_PROMPTS) to LLM request spans
[VSCode] Voice dictation now respects the accessibility.voice.speechLanguage setting when no Claude Code language is configured
[VSCode] /context now opens a native token usage dialog
Fixed unbounded memory growth (multi-GB RSS) when processing many images in a session
Fixed /usage leaking up to ~2GB of memory on machines with large transcript histories
Fixed memory leak when long-running tools fail to emit a clear progress event
Fixed Bash tool becoming permanently unusable when the directory Claude was started in is deleted or moved mid-session
Fixed --resume crashing on startup in external builds
Fixed --resume failing on large sessions when a transcript line was corrupted by an unclean shutdown — the corrupt line is now skipped
Fixed thinking.type.enabled is not supported error when using Bedrock application inference profile ARNs
Fixed Microsoft 365 MCP OAuth failing with duplicate or unsupported prompt parameter
Fixed scrollback duplication when pressing Ctrl+L or triggering a redraw in non-fullscreen mode on tmux, GNOME Terminal, Windows Terminal, and Konsole
Fixed claude.ai MCP connectors silently disappearing when the connector-list fetch hits a transient auth error at startup
Fixed "Always allow" rules for built-in tools in remote sessions not surviving worker restarts
Fixed NO_PROXY not being respected for all HTTP clients when set via managed-settings.json under the native build
Fixed managed settings approval prompt exiting the session even when accepted — now applies settings and continues
Fixed /usage returning "rate limited" after a stale OAuth token — now refreshes automatically
Fixed invalid legacy enum values in settings.json invalidating the entire settings file
Fixed /usage dialog content being clipped when no-flicker mode is off
Fixed /focus showing "Unknown command" when the fullscreen renderer is off — now explains how to enable it
Fixed embedded grep/find/rg shell wrappers failing when the running binary is deleted mid-session — now falls back to installed tools
Reduced peak file descriptor usage during find in the Bash tool on large directory trees
/config settings (theme, editor mode, verbose, etc.) now persist to ~/.claude/settings.json and participate in project/local/policy override precedence
Added prUrlTemplate setting to point the footer PR badge at a custom code-review URL instead of github.com
Added CLAUDE_CODE_HIDE_CWD environment variable to hide the working directory in the startup logo
--from-pr now accepts GitLab merge-request, Bitbucket pull-request, and GitHub Enterprise PR URLs
--print mode now honors the agent's tools: and disallowedTools: frontmatter, matching interactive-mode behavior
--agent <name> now honors the agent definition's permissionMode for built-in agents
PowerShell tool commands can now be auto-approved in permission mode, matching Bash behavior
Hooks: PostToolUse and PostToolUseFailure hook inputs now include duration_ms (tool execution time, excluding permission prompts and PreToolUse hooks)
Subagent and SDK MCP server reconfiguration now connects servers in parallel instead of serially
Plugins pinned by another plugin's version constraint now auto-update to the highest satisfying git tag
Vim mode: Esc in INSERT no longer pulls a queued message back into the input; press Esc again to interrupt
Slash command suggestions now highlight the characters that matched your query
Slash command picker now wraps long descriptions onto a second line instead of truncating
owner/repo#N shorthand links in output now use your git remote's host instead of always pointing at github.com
Security: blockedMarketplaces now correctly enforces hostPattern and pathPattern entries
OpenTelemetry: tool_result and tool_decision events now include tool_use_id; tool_result also includes tool_input_size_bytes
Status line: stdin JSON now includes effort.level and thinking.enabled
Fixed pasting CRLF content (Windows clipboards, Xcode console) inserting an extra blank line between every line
Fixed multi-line paste losing newlines in terminals using kitty keyboard protocol sequences inside bracketed paste
Fixed Glob and Grep tools disappearing on native macOS/Linux builds when the Bash tool is denied via permissions
Fixed scrolling up in fullscreen mode snapping back to the bottom every time a tool finishes
Fixed MCP HTTP connections failing with "Invalid OAuth error response" when servers returned non-JSON bodies for OAuth discovery requests
Fixed Rewind overlay showing "(no prompt)" for messages with image attachments
Fixed auto mode overriding plan mode with conflicting "Execute immediately" instructions
Fixed async PostToolUse hooks that emit no response payload writing empty entries to the session transcript
Fixed spinner staying on when a subagent task notification is orphaned in the queue
Tool search is now disabled by default on Vertex AI to avoid an unsupported beta header error (opt in with ENABLE_TOOL_SEARCH)
Fixed @-file Tab completion replacing the entire prompt when used inside a slash command with an absolute path
Fixed a stray p character appearing at the prompt on startup in macOS Terminal.app via Docker or SSH
Fixed ${ENV_VAR} placeholders in headers for HTTP/SSE/WebSocket MCP servers not being substituted before requests
Fixed MCP OAuth client secret stored via --client-secret not being sent during token exchange for servers requiring client_secret_post
Fixed /skills Enter key closing the dialog instead of pre-filling /<skill-name> in the prompt
Fixed /agents detail view mislabeling built-in tools unavailable to subagents as "Unrecognized"
Fixed MCP servers from plugins not spawning on Windows when the plugin cache was incomplete
Fixed /export showing the current default model instead of the model the conversation actually used
Fixed verbose output setting not persisting after restart
Fixed /usage progress bars overlapping with their "Resets …" labels
Fixed plugin MCP servers failing when ${user_config.*} references an optional field left blank
Fixed list items containing a sentence-final number wrapping the number onto its own line
Fixed /plan and /plan open not acting on the existing plan when entering plan mode
Fixed skills invoked before auto-compaction being re-executed against the next user message
Fixed /reload-plugins and /doctor reporting load errors for disabled plugins
Fixed Agent tool with isolation: "worktree" reusing stale worktrees from prior sessions
Fixed disabled MCP servers appearing as "failed" in /status
Fixed TaskList returning tasks in arbitrary filesystem order instead of sorted by ID
Fixed spurious "GitHub API rate limit exceeded" hints when gh output contained PR titles mentioning "rate limit"
Fixed SDK/bridge read_file not correctly enforcing size cap on growing files
Fixed PR not linked to session when working in a git worktree
Fixed /doctor warning about MCP server entries overridden by a higher-precedence scope
Added focus view toggle (Ctrl+O) in NO_FLICKER mode showing prompt, one-line tool summary with edit diffstats, and final response
Added refreshInterval status line setting to re-run the status line command every N seconds
Added workspace.git_worktree to the status line JSON input, set when the current directory is inside a linked git worktree
Added ● N running indicator in /agents next to agent types with live subagent instances
Added syntax highlighting for Cedar policy files (.cedar, .cedarpolicy)
Fixed --dangerously-skip-permissions being silently downgraded to accept-edits mode after approving a write to a protected path
Fixed and hardened Bash tool permissions, tightening checks around env-var prefixes and network redirects, and reducing false prompts on common commands
Fixed permission rules with names matching JavaScript prototype properties (e.g. toString) causing settings.json to be silently ignored
Fixed managed-settings allow rules remaining active after an admin removed them until process restart
Fixed permissions.additionalDirectories changes in settings not applying mid-session
Fixed removing a directory from settings.permissions.additionalDirectories revoking access to the same directory passed via --add-dir
Fixed MCP HTTP/SSE connections accumulating ~50 MB/hr of unreleased buffers when servers reconnect
Fixed MCP OAuth oauth.authServerMetadataUrl not being honored on token refresh after restart, fixing ADFS and similar IdPs
Fixed 429 retries burning all attempts in ~13 seconds when the server returns a small Retry-After — exponential backoff now applies as a minimum
Fixed rate-limit upgrade options disappearing after context compaction
Fixed several /resume picker issues: --resume <name> opening uneditable, Ctrl+A reload wiping search, empty list swallowing navigation, task-status text replacing conversation summary, and cross-project staleness
Fixed file-edit diffs disappearing on --resume when the edited file was larger than 10KB
Fixed --resume cache misses and lost mid-turn input from attachment messages not being saved to the transcript
Fixed messages typed while Claude is working not being persisted to the transcript
Fixed prompt-type Stop/SubagentStop hooks failing on long sessions, and hook evaluator API errors displaying "JSON validation failed" instead of the actual message
Fixed subagents with worktree isolation or cwd: override leaking their working directory back to the parent session's Bash tool
Fixed claude plugin update reporting "already at the latest version" for git-based marketplace plugins when the remote had newer commits
Fixed slash command picker breaking when a plugin's frontmatter name is a YAML boolean keyword
Fixed copying wrapped URLs in NO_FLICKER mode inserting spaces at line breaks
Fixed scroll rendering artifacts in NO_FLICKER mode when running inside zellij
Fixed a crash in NO_FLICKER mode when hovering over MCP tool results
Fixed a NO_FLICKER mode memory leak where API retries left stale streaming state
Fixed slow mouse-wheel scrolling in NO_FLICKER mode on Windows Terminal
Fixed custom status line not displaying in NO_FLICKER mode on terminals shorter than 24 rows
Fixed Shift+Enter and Alt/Cmd+arrow shortcuts not working in Warp with NO_FLICKER mode
Fixed Korean/Japanese/Unicode text becoming garbled when copied in no-flicker mode on Windows
Fixed Bedrock SigV4 authentication failing when AWS_BEARER_TOKEN_BEDROCK or ANTHROPIC_BEDROCK_BASE_URL are set to empty strings (as GitHub Actions does for unset inputs)
Improved Accept Edits mode to auto-approve filesystem commands prefixed with safe env vars or process wrappers (e.g. LANG=C rm foo, timeout 5 mkdir out)
Improved auto mode and bypass-permissions mode to auto-approve sandbox network access prompts
Improved sandbox: sandbox.network.allowMachLookup now takes effect on macOS
Improved image handling: pasted and attached images are now compressed to the same token budget as images read via the Read tool
Improved slash command and @-mention completion to trigger after CJK sentence punctuation, so Japanese/Chinese input no longer requires a space before / or @
Improved Bridge sessions to show the local git repo, branch, and working directory on the claude.ai session card
Improved footer layout: indicators (Focus, notifications) now stay on the mode-indicator row instead of wrapping below
Improved context-low warning to show as a transient footer notification instead of a persistent row
Improved markdown blockquotes to show a continuous left bar across wrapped lines
Improved session transcript size by skipping empty hook entries and capping stored pre-edit file copies
Improved transcript accuracy: per-block entries now carry the final token usage instead of the streaming placeholder
Improved Bash tool OTEL tracing: subprocesses now inherit a W3C TRACEPARENT env var when tracing is enabled
Updated /claude-api skill to cover Managed Agents alongside the Claude API
Added forceRemoteSettingsRefresh policy setting: when set, the CLI blocks startup until remote managed settings are freshly fetched, and exits if the fetch fails (fail-closed)
Added interactive Bedrock setup wizard accessible from the login screen when selecting "3rd-party platform" — guides you through AWS authentication, region configuration, credential verification, and model pinning
Added per-model and cache-hit breakdown to /cost for subscription users
/release-notes is now an interactive version picker
Remote Control session names now use your hostname as the default prefix (e.g. myhost-graceful-unicorn), overridable with --remote-control-session-name-prefix
Pro users now see a footer hint when returning to a session after the prompt cache has expired, showing roughly how many tokens the next turn will send uncached
Fixed subagent spawning permanently failing with "Could not determine pane count" after tmux windows are killed or renumbered during a long-running session
Fixed prompt-type Stop hooks incorrectly failing when the small fast model returns ok:false, and restored preventContinuation:true semantics for non-Stop prompt-type hooks
Fixed tool input validation failures when streaming emits array/object fields as JSON-encoded strings
Fixed an API 400 error that could occur when extended thinking produced a whitespace-only text block alongside real content
Fixed accidental feedback survey submissions from auto-pilot keypresses and consecutive-prompt digit collisions
Fixed misleading "esc to interrupt" hint appearing alongside "esc to clear" when a text selection exists in fullscreen mode during processing
Fixed Homebrew install update prompts to use the cask's release channel (claude-code → stable, claude-code@latest → latest)
Fixed ctrl+e jumping to the end of the next line when already at end of line in multiline prompts
Fixed an issue where the same message could appear at two positions when scrolling up in fullscreen mode (iTerm2, Ghostty, and other terminals with DEC 2026 support)
Fixed idle-return "/clear to save X tokens" hint showing cumulative session tokens instead of current context size
Fixed plugin MCP servers stuck "connecting" on session start when they duplicate a claude.ai connector that is unauthenticated
Improved Write tool diff computation speed for large files (60% faster on files with tabs/&/$)
Removed /tag command
Removed /vim command (toggle vim mode via /config → Editor mode)
Linux sandbox now ships the apply-seccomp helper in both npm and native builds, restoring unix-socket blocking for sandboxed commands
Added /powerup — interactive lessons teaching Claude Code features with animated demos
Added CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE env var to keep the existing marketplace cache when git pull fails, useful in offline environments
Added .husky to protected directories (acceptEdits mode)
Fixed an infinite loop where the rate-limit options dialog would repeatedly auto-open after hitting your usage limit, eventually crashing the session
Fixed --resume causing a full prompt-cache miss on the first request for users with deferred tools, MCP servers, or custom agents (regression since v2.1.69)
Fixed Edit/Write failing with "File content has changed" when a PostToolUse format-on-save hook rewrites the file between consecutive edits
Fixed PreToolUse hooks that emit JSON to stdout and exit with code 2 not correctly blocking the tool call
Fixed collapsed search/read summary badge appearing multiple times in fullscreen scrollback when a CLAUDE.md file auto-loads during a tool call
Fixed auto mode not respecting explicit user boundaries ("don't push", "wait for X before Y") even when the action would otherwise be allowed
Fixed click-to-expand hover text being nearly invisible on light terminal themes
Fixed UI crash when malformed tool input reached the permission dialog
Fixed headers disappearing when scrolling /model, /config, and other selection screens
Added "defer" permission decision to PreToolUse hooks — headless sessions can pause at a tool call and resume with -p --resume to have the hook re-evaluate
Added CLAUDE_CODE_NO_FLICKER=1 environment variable to opt into flicker-free alt-screen rendering with virtualized scrollback
Added PermissionDenied hook that fires after auto mode classifier denials — return {retry: true} to tell the model it can retry
Added named subagents to @ mention typeahead suggestions
Added MCP_CONNECTION_NONBLOCKING=true for -p mode to skip the MCP connection wait entirely, and bounded --mcp-config server connections at 5s instead of blocking on the slowest server
Auto mode: denied commands now show a notification and appear in /permissions → Recent tab where you can retry with r
Fixed Edit(//path/**) and Read(//path/**) allow rules to check the resolved symlink target, not just the requested path
Fixed voice push-to-talk not activating for some modifier-combo bindings, and voice mode on Windows failing with "WebSocket upgrade rejected with HTTP 101"
Fixed Edit/Write tools doubling CRLF on Windows and stripping Markdown hard line breaks (two trailing spaces)
Fixed StructuredOutput schema cache bug causing ~50% failure rate when using multiple schemas
Fixed memory leak where large JSON inputs were retained as LRU cache keys in long-running sessions
Fixed a crash when removing a message from very large session files (over 50MB)
Fixed LSP server zombie state after crash — server now restarts on next request instead of failing until session restart
Fixed prompt history entries containing CJK or emoji being silently dropped when they fall on a 4KB boundary in ~/.claude/history.jsonl
Fixed /stats undercounting tokens by excluding subagent usage, and losing historical data beyond 30 days when the stats cache format changes
Fixed -p --resume hangs when the deferred tool input exceeds 64KB or no deferred marker exists, and -p --continue not resuming deferred tools
Fixed claude-cli:// deep links not opening on macOS
Fixed MCP tool errors truncating to only the first content block when the server returns multi-element error content
Fixed skill reminders and other system context being dropped when sending messages with images via the SDK
Fixed PreToolUse/PostToolUse hooks to receive file_path as an absolute path for Write/Edit/Read tools, matching the documented behavior
Fixed autocompact thrash loop — now detects when context refills to the limit immediately after compacting three times in a row and stops with an actionable error instead of burning API calls
Fixed prompt cache misses in long sessions caused by tool schema bytes changing mid-session
Fixed nested CLAUDE.md files being re-injected dozens of times in long sessions that read many files
Fixed --resume crash when transcript contains a tool result from an older CLI version or interrupted write
Fixed misleading "Rate limit reached" message when the API returned an entitlement error — now shows the actual error with actionable hints
Fixed hooks if condition filtering not matching compound commands (ls && git push) or commands with env-var prefixes (FOO=bar git push)
Fixed collapsed search/read group badges duplicating in terminal scrollback during heavy parallel tool use
Fixed notification invalidates not clearing the currently-displayed notification immediately
Fixed prompt briefly disappearing after submit when background messages arrived during processing
Fixed Devanagari and other combining-mark text being truncated in assistant output
Fixed rendering artifacts on main-screen terminals after layout shifts
Fixed voice mode failing to request microphone permission on macOS Apple Silicon
Fixed Shift+Enter submitting instead of inserting a newline on Windows Terminal Preview 1.25
Fixed periodic UI jitter during streaming in iTerm2 when running inside tmux
Fixed PowerShell tool incorrectly reporting failures when commands like git push wrote progress to stderr on Windows PowerShell 5.1
Fixed a potential out-of-memory crash when the Edit tool was used on very large files (>1 GiB)
Improved collapsed tool summary to show "Listed N directories" for ls/tree/du instead of "Read N files"
Improved Bash tool to warn when a formatter/linter command modifies files you have previously read, preventing stale-edit errors
Improved @-mention typeahead to rank source files above MCP resources with similar names
Improved PowerShell tool prompt with version-appropriate syntax guidance (5.1 vs 7+)
Changed Edit to work on files viewed via Bash with sed -n or cat, without requiring a separate Read call first
Changed hook output over 10,000 characters to be saved to disk with a file path + a 2,000-character preview instead of being injected directly into context
Changed cleanupPeriodDays: 0 in settings.json to be rejected with a validation error — it previously silently disabled transcript persistence
Changed thinking summaries to no longer be generated by default in interactive sessions — set showThinkingSummaries: true in settings.json to restore
Documented TaskCreated hook event and its blocking behavior
Preserved task notifications when backgrounding a running command with Ctrl+B
PowerShell tool on Windows: external-command arguments containing both a double-quote and whitespace now prompt instead of auto-allowing (PS 5.1 argument-splitting hardening)
/env now applies to PowerShell tool commands (previously only affected Bash)
/usage now hides redundant "Current week (Sonnet only)" bar for Pro and Enterprise plans
Image paste no longer inserts a trailing space
Pasting !command into an empty prompt now enters bash mode, matching typed ! behavior
/buddy is here for April 1st — hatch a small creature that watches you code
Added ANTHROPIC_DEFAULT_{OPUS,SONNET,HAIKU}_MODEL_SUPPORTS env vars to override effort/thinking capability detection for pinned default models for 3p (Bedrock, Vertex, Foundry), and _MODEL_NAME/_DESCRIPTION to customize the /model picker label
Added CLAUDE_STREAM_IDLE_TIMEOUT_MS env var to configure the streaming idle watchdog threshold (default 90s)
Added TaskCreated hook that fires when a task is created via TaskCreate
Added WorktreeCreate hook support for type: "http" — return the created worktree path via hookSpecificOutput.worktreePath in the response JSON
Added allowedChannelPlugins managed setting for team/enterprise admins to define a channel plugin allowlist
Added x-client-request-id header to API requests for debugging timeouts
Added idle-return prompt that nudges users returning after 75+ minutes to /clear, reducing unnecessary token re-caching on stale sessions
Deep links (claude-cli://) now open in your preferred terminal instead of whichever terminal happens to be first in the detection list
Rules and skills paths: frontmatter now accepts a YAML list of globs
MCP tool descriptions and server instructions are now capped at 2KB to prevent OpenAPI-generated servers from bloating context
MCP servers configured both locally and via claude.ai connectors are now deduplicated — the local config wins
Background bash tasks that appear stuck on an interactive prompt now surface a notification after ~45 seconds
Token counts ≥1M now display as "1.5m" instead of "1512.6k"
Global system-prompt caching now works when ToolSearch is enabled, including for users with MCP tools configured
Fixed voice push-to-talk: holding the voice key no longer leaks characters into the text input, and transcripts now insert at the correct position
Fixed up/down arrow keys being unresponsive when a footer item is focused
Fixed Ctrl+U (kill-to-line-start) being a no-op at line boundaries in multiline input, so repeated Ctrl+U now clears across lines
Fixed null-unbinding a default chord binding (e.g. "ctrl+x ctrl+k": null) still entering chord-wait mode instead of freeing the prefix key
Fixed mouse events inserting literal "mouse" text into transcript search input
Fixed workflow subagents failing with API 400 when the outer session uses --json-schema and the subagent also specifies a schema
Fixed missing background color behind certain emoji in user message bubbles on some terminals
Fixed the "allow Claude to edit its own settings for this session" permission option not sticking for users with Edit(.claude) allow rules
Fixed a hang when generating attachment snippets for large edited files
Fixed MCP tool/resource cache leak on server reconnect
Fixed a startup performance issue where partial clone repositories (Scalar/GVFS) triggered mass blob downloads
Fixed native terminal cursor not tracking the text input caret, so IME composition (CJK input) now renders inline and screen readers can follow the input position
Fixed spurious "Not logged in" errors on macOS caused by transient keychain read failures
Fixed cold-start race where core tools could be deferred without their bypass active, causing Edit/Write to fail with InputValidationError on typed parameters
Improved detection for dangerous removals of Windows drive roots (C:\, C:\Windows, etc.)
Improved interactive startup by ~30ms by running setup() in parallel with slash command and agent loading
Improved startup for claude "prompt" with MCP servers — the REPL now renders immediately instead of blocking until all servers connect
Improved Remote Control to show a specific reason when blocked instead of a generic "not yet enabled" message
Improved p90 prompt cache rate
Reduced scroll-to-top resets in long sessions by making the message window immune to compaction and grouping changes
Reduced terminal flickering when animated tool progress scrolls above the viewport
Changed issue/PR references to only become clickable links when written as owner/repo#123 — bare #123 is no longer auto-linked
Slash commands unavailable for the current auth setup (/voice, /mobile, /chrome, /upgrade, etc.) are now hidden instead of shown
[VSCode] Added rate limit warning banner with usage percentage and reset time
Stats screenshot (Ctrl+S in /stats) now works in all builds and is 16× faster
Added --bare flag for scripted -p calls — skips hooks, LSP, plugin sync, and skill directory walks; requires ANTHROPIC_API_KEY or an apiKeyHelper via --settings (OAuth and keychain auth disabled); auto-memory fully disabled
Added --channels permission relay — channel servers that declare the permission capability can forward tool approval prompts to your phone
Fixed multiple concurrent Claude Code sessions requiring repeated re-authentication when one session refreshes its OAuth token
Fixed voice mode silently swallowing retry failures and showing a misleading "check your network" message instead of the actual error
Fixed voice mode audio not recovering when the server silently drops the WebSocket connection
Fixed CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS not suppressing the structured-outputs beta header, causing 400 errors on proxy gateways forwarding to Vertex/Bedrock
Fixed --channels bypass for Team/Enterprise orgs with no other managed settings configured
Fixed a crash on Node.js 18
Fixed unnecessary permission prompts for Bash commands containing dashes in strings
Fixed plugin hooks blocking prompt submission when the plugin directory is deleted mid-session
Fixed a race condition where background agent task output could hang indefinitely when the task completed between polling intervals
Resuming a session that was in a worktree now switches back to that worktree
Fixed /btw not including pasted text when used during an active response
Fixed a race where fast Cmd+Tab followed by paste could beat the clipboard copy under tmux
Fixed terminal tab title not updating with an auto-generated session description
Fixed invisible hook attachments inflating the message count in transcript mode
Fixed Remote Control sessions showing a generic title instead of deriving from the first prompt
Fixed /rename not syncing the title for Remote Control sessions
Fixed Remote Control /exit not reliably archiving the session
Improved MCP read/search tool calls to collapse into a single "Queried {server}" line (expand with Ctrl+O)
Improved ! bash mode discoverability — Claude now suggests it when you need to run an interactive command
Improved plugin freshness — ref-tracked plugins now re-clone on every load to pick up upstream changes
Improved Remote Control session titles to refresh after your third message
Updated MCP OAuth to support Client ID Metadata Document (CIMD / SEP-991) for servers without Dynamic Client Registration
Changed plan mode to hide the "clear context" option by default (restore with "showClearContextOnPlanAccept": true)
Disabled line-by-line response streaming on Windows (including WSL in Windows Terminal) due to rendering issues
[VSCode] Fixed Windows PATH inheritance for Bash tool when using Git Bash (regression in v2.1.78)
Added CLI tool usage detection to plugin tips, in addition to file pattern matching
Added effort frontmatter support for skills and slash commands to override the model effort level when invoked
Added --channels (research preview) — allow MCP servers to push messages into your session
Fixed --resume dropping parallel tool results — sessions with parallel tool calls now restore all tool_use/tool_result pairs instead of showing [Tool result missing] placeholders
Fixed voice mode WebSocket failures caused by Cloudflare bot detection on non-browser TLS fingerprints
Fixed 400 errors when using fine-grained tool streaming through API proxies, Bedrock, or Vertex
Fixed /remote-control appearing for gateway and third-party provider deployments where it cannot function
Fixed /sandbox tab switching not responding to Tab or arrow keys
Improved responsiveness of @ file autocomplete in large git repositories
Improved /effort to show what auto currently resolves to, matching the status bar indicator
Improved /permissions — Tab and arrow keys now switch tabs from within a list
Improved background tasks panel — left arrow now closes from the list view
Simplified plugin install tips to use a single /plugin install command instead of a two-step flow
Reduced memory usage on startup in large repositories (~80 MB saved on 250k-file repos)
Fixed managed settings (enabledPlugins, permissions.defaultMode, policy-set env vars) not being applied at startup when remote-settings.json was cached from a prior session
Increased default maximum output token limits for Claude Opus 4.6 to 64k tokens, and the upper bound for Opus 4.6 and Sonnet 4.6 models to 128k tokens
Added allowRead sandbox filesystem setting to re-allow read access within denyRead regions
/copy now accepts an optional index: /copy N copies the Nth-latest assistant response
Fixed "Always Allow" on compound bash commands (e.g. cd src && npm test) saving a single rule for the full string instead of per-subcommand, leading to dead rules and repeated permission prompts
Fixed auto-updater starting overlapping binary downloads when the slash-command overlay repeatedly opened and closed, accumulating tens of gigabytes of memory
Fixed --resume silently truncating recent conversation history due to a race between memory-extraction writes and the main transcript
Added MCP elicitation support — MCP servers can now request structured input mid-task via an interactive dialog (form fields or browser URL)
Added new Elicitation and ElicitationResult hooks to intercept and override responses before they're sent back
Added -n / --name <name> CLI flag to set a display name for the session at startup
Added worktree.sparsePaths setting for claude --worktree in large monorepos to check out only the directories you need via git sparse-checkout
Added PostCompact hook that fires after compaction completes
Added /effort slash command to set model effort level
Added session quality survey — enterprise admins can configure the sample rate via the feedbackSurveyRate setting
Fixed deferred tools (loaded via ToolSearch) losing their input schemas after conversation compaction, causing array and number parameters to be rejected with type errors
Fixed slash commands showing "Unknown skill"
Fixed plan mode asking for re-approval after the plan was already accepted
Fixed voice mode swallowing keypresses while a permission dialog or plan editor was open
Fixed /voice not working on Windows when installed via npm
Fixed spurious "Context limit reached" when invoking a skill with model: frontmatter on a 1M-context session
Fixed "adaptive thinking is not supported on this model" error when using non-standard model strings
Fixed Bash(cmd:*) permission rules not matching when a quoted argument contains #
Fixed "don't ask again" in the Bash permission dialog showing the full raw command for pipes and compound commands
Fixed auto-compaction retrying indefinitely after consecutive failures — a circuit breaker now stops after 3 attempts
Fixed MCP reconnect spinner persisting after successful reconnection
Fixed LSP plugins not registering servers when the LSP Manager initialized before marketplaces were reconciled
Fixed clipboard copying in tmux over SSH — now attempts both direct terminal write and tmux clipboard integration
Fixed /export showing only the filename instead of the full file path in the success message
Fixed transcript not auto-scrolling to new messages after selecting text
Fixed Escape key not working to exit the login method selection screen
Fixed several Remote Control issues: sessions silently dying when the server reaps an idle environment, rapid messages being queued one-at-a-time instead of batched, and stale work items causing redelivery after JWT refresh
Fixed bridge sessions failing to recover after extended WebSocket disconnects
Fixed slash commands not found when typing the exact name of a soft-hidden command
Improved --worktree startup performance by reading git refs directly and skipping redundant git fetch when the remote branch is already available locally
Improved background agent behavior — killing a background agent now preserves its partial results in the conversation context
Improved model fallback notifications — now always visible instead of hidden behind verbose mode, with human-friendly model names
Improved blockquote readability on dark terminal themes — text is now italic with a left bar instead of dim
Improved stale worktree cleanup — worktrees left behind after an interrupted parallel run are now automatically cleaned up
Improved Remote Control session titles — now derived from your first prompt instead of showing "Interactive session"
Improved /voice to show your dictation language on enable and warn when your language setting isn't supported for voice input
Updated --plugin-dir to only accept one path to support subcommands — use repeated --plugin-dir for multiple directories
[VSCode] Fixed gitignore patterns containing commas silently excluding entire filetypes from the @-mention file picker
Added actionable suggestions to /context command — identifies context-heavy tools, memory bloat, and capacity warnings with specific optimization tips
Added autoMemoryDirectory setting to configure a custom directory for auto-memory storage
Fixed memory leak where streaming API response buffers were not released when the generator was terminated early, causing unbounded RSS growth on the Node.js/npm code path
Fixed managed policy ask rules being bypassed by user allow rules or skill allowed-tools
Fixed full model IDs (e.g., claude-opus-4-5) being silently ignored in agent frontmatter model: field and --agents JSON config — agents now accept the same model values as --model
Fixed MCP OAuth authentication hanging when the callback port is already in use
Fixed MCP OAuth refresh never prompting for re-auth after the refresh token expires, for OAuth servers that return errors with HTTP 200 (e.g. Slack)
Fixed voice mode silently failing on the macOS native binary for users whose terminal had never been granted microphone permission — the binary now includes the audio-input entitlement so macOS prompts correctly
Fixed SessionEnd hooks being killed after 1.5 s on exit regardless of hook.timeout — now configurable via CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS
Fixed /plugin install failing inside the REPL for marketplace plugins with local sources
Fixed marketplace update not syncing git submodules — plugin sources in submodules no longer break after update
Fixed unknown slash commands with arguments silently dropping input — now shows your input as a warning
Fixed Hebrew, Arabic, and other RTL text not rendering correctly in Windows Terminal, conhost, and VS Code integrated terminal
Fixed LSP servers not working on Windows due to malformed file URIs
Changed --plugin-dir so local dev copies now override installed marketplace plugins with the same name (unless that plugin is force-enabled by managed settings)
[VSCode] Fixed delete button not working for Untitled sessions
[VSCode] Improved scroll wheel responsiveness in the integrated terminal with terminal-aware acceleration
Fixed API 400 errors when using ANTHROPIC_BASE_URL with a third-party gateway — tool search now correctly detects proxy endpoints and disables tool_reference blocks
Fixed API Error: 400 This model does not support the effort parameter when using custom Bedrock inference profiles or other model identifiers not matching standard Claude naming patterns
Fixed empty model responses immediately after ToolSearch — the server renders tool schemas with system-prompt-style tags at the prompt tail, which could confuse models into stopping early
Fixed prompt-cache bust when an MCP server with instructions connects after the first turn
Fixed Enter inserting a newline instead of submitting when typing over a slow SSH connection
Fixed clipboard corrupting non-ASCII text (CJK, emoji) on Windows/WSL by using PowerShell Set-Clipboard
Fixed extra VS Code windows opening at startup on Windows when running from the VS Code integrated terminal
Fixed voice mode failing on Windows native binary with "native audio module could not be loaded"
Fixed push-to-talk not activating on session start when voiceEnabled: true was set in settings
Fixed markdown links containing #NNN references incorrectly pointing to the current repository instead of the linked URL
Fixed repeated "Model updated to Opus 4.6" notification when a project's .claude/settings.json has a legacy Opus model string pinned
Fixed plugins showing as inaccurately installed in /plugin
Fixed plugins showing "not found in marketplace" errors on fresh startup by auto-refreshing after marketplace installation
Fixed /security-review command failing with unknown option merge-base on older git versions
Fixed /color command having no way to reset back to the default color — /color default, /color gray, /color reset, and /color none now restore the default
Fixed a performance regression in the AskUserQuestion preview dialog that re-ran markdown rendering on every keystroke in the notes input
Fixed feature flags read during early startup never refreshing their disk cache, causing stale values to persist across sessions
Fixed permissions.defaultMode settings values other than acceptEdits or plan being applied in Claude Code Remote environments — they are now ignored
Fixed skill listing being re-injected on every --resume (~600 tokens saved per resume)
Fixed teleport marker not rendering in VS Code teleported sessions
Improved error message when microphone captures silence to distinguish from "no speech detected"
Improved compaction to preserve images in the summarizer request, allowing prompt cache reuse for faster and cheaper compaction
Improved /rename to work while Claude is processing, instead of being silently queued
Reduced prompt input re-renders during turns by ~74%
Reduced startup memory by ~426KB for users without custom CA certificates
Reduced Remote Control /poll rate to once per 10 minutes while connected (was 1–2s), cutting server load ~300×. Reconnection is unaffected — transport loss immediately wakes fast polling.
[VSCode] Added spark icon in VS Code activity bar that lists all Claude Code sessions, with sessions opening as full editors
[VSCode] Added full markdown document view for plans in VS Code, with support for adding comments to provide feedback
[VSCode] Added native MCP server management dialog — use /mcp in the chat panel to enable/disable servers, reconnect, and manage OAuth authentication without switching to the terminal
Claude automatically saves useful context to auto-memory. Manage with /memory
Added /copy command to show an interactive picker when code blocks are present, allowing selection of individual code blocks or the full response.
Improved "always allow" prefix suggestions for compound bash commands (e.g. cd /tmp && git fetch && git push) to compute smarter per-subcommand prefixes instead of treating the whole command as one
Improved ordering of short task lists
Improved memory usage in multi-agent sessions by releasing completed subagent task state
Fixed MCP OAuth token refresh race condition when running multiple Claude Code instances simultaneously
Fixed shell commands not showing a clear error message when the working directory has been deleted
Fixed config file corruption that could wipe authentication when multiple Claude Code instances ran simultaneously
Added support for startupTimeout configuration for LSP servers
Added WorktreeCreate and WorktreeRemove hook events, enabling custom VCS setup and teardown when agent worktree isolation creates or removes worktrees.
Fixed a bug where resumed sessions could be invisible when the working directory involved symlinks, because the session storage path was resolved at different times during startup. Also fixed session data loss on SSH disconnect by flushing session data before hooks and analytics in the graceful shutdown sequence.
Linux: Fixed native modules not loading on systems with glibc older than 2.30 (e.g., RHEL 8)
Fixed memory leak in agent teams where completed teammate tasks were never garbage collected from session state
Fixed CLAUDE_CODE_SIMPLE to fully strip down skills, session memory, custom agents, and CLAUDE.md token counting
Fixed /mcp reconnect freezing the CLI when given a server name that doesn't exist
Fixed memory leak where completed task state objects were never removed from AppState
Added support for isolation: worktree in agent definitions, allowing agents to declaratively run in isolated git worktrees.
CLAUDE_CODE_SIMPLE mode now also disables MCP tools, attachments, hooks, and CLAUDE.md file loading for a fully minimal experience.
Fixed bug where MCP tools were not discovered when tool search is enabled and a prompt is passed in as a launch argument
Improved memory usage during long sessions by clearing internal caches after compaction
Added claude agents CLI command to list all configured agents
Improved memory usage during long sessions by clearing large tool results after they have been processed
Fixed a memory leak where LSP diagnostic data was never cleaned up after delivery, causing unbounded memory growth in long sessions
Fixed a memory leak where completed task output was not freed from memory, reducing memory usage in long sessions with many tasks
Improved startup performance for headless mode (-p flag) by deferring Yoga WASM and UI component imports
Fixed prompt suggestion cache regression that reduced cache hit rates
Fixed unbounded memory growth in long sessions by capping file history snapshots
Added CLAUDE_CODE_DISABLE_1M_CONTEXT environment variable to disable 1M context window support
Opus 4.6 (fast mode) now includes the full 1M context window
VSCode: Added /extra-usage command support in VS Code sessions
Fixed memory leak where TaskOutput retained recent lines after cleanup
Fixed memory leak in CircularBuffer where cleared items were retained in the backing array
Fixed memory leak in shell command execution where ChildProcess and AbortController references were retained after cleanup
Fixed a crash when agent teams setting changed between renders
Fixed a bug where commands excluded from sandboxing (via sandbox.excludedCommands or dangerouslyDisableSandbox) could bypass the Bash ask permission rule when autoAllowBashIfSandboxed was enabled
Added managedMcpServers managed setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as .mcp.json); entries that name a command to run are skipped
Added --permission-prompts none for unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps deciding
Added recognition of glab mr create/merge/close/reopen/note/update so GitLab merge requests show as MR !N in the collapsed tool summary and refresh the footer MR badge
Added --json to claude plugin validate for a machine-readable validation report
Fixed concurrent sessions silently reverting each other's ~/.claude.json changes — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at once
Fixed a conversation whose thinking was rejected once being rejected again on every later turn
Fixed Bash Read() deny rules not covering files given as option values (--ignore-revs-file=.env, -f.env, @file), git diff/git grep file operands, or cd DIR && cat FILE compounds; grep -r/cp -r over a directory holding a denied file now asks
Fixed the prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled
Fixed fullscreen mode showing a blank conversation after a long turn with hundreds of tool calls
Fixed auto mode running a turn on a model it doesn't support when a command or skill's frontmatter model: named one; the turn now keeps the session model
Fixed CLAUDE_CODE_MAX_CONTEXT_TOKENS being ignored for Vertex-style model IDs (@YYYYMMDD suffix) of model versions Claude Code doesn't recognize
Fixed the live output preview of a running shell command hiding its newest lines when an earlier line wrapped
Fixed a background GitHub connection check that ran on every launch for claude.ai users; the result is now remembered across launches
Fixed --resume failing (and --continue opening an empty conversation) when a saved session contains an attachment entry with no payload
Fixed frontmatter model: on custom commands and skills being ignored in interactive sessions
Fixed Artifact publishing failing once with an "unexpected parameter note" error in conversations continued from an older version
Fixed managed forceRemoteSettingsRefresh being ignored at startup when a policy helper configured by MDM or the managed settings file had already run
Fixed worktree isolation refusing hook-created worktrees on machines where git rev-parse fails with a message other than "not a git repository"
Fixed OpenTelemetry metrics and events from cloud sessions missing the user.email, organization.id, and user.account_uuid attributes
Fixed MCP servers that disconnect while their tools are being listed at startup showing as connected with no tools instead of reporting the error
Fixed the file edit permission dialog sometimes showing a changed line cut short with no indication
Fixed repository detection dropping a known repo identity after a transient git probe failure
Fixed managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value cannot be parsed: Claude Code now refuses to start and names the source
Fixed Stop not actually stopping background agents and workflows in remote-control sessions: killed tasks now stay visible and re-stoppable until their processes exit
Fixed resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents
Fixed marketplace repo URLs on github.com with a trailing slash or dangling ?/# producing an unusable .git clone URL
Fixed blocking Stop hooks causing the turn after a block to lose the model's reasoning from that turn and, on some models, miss the prompt cache
Fixed remote (claude.ai) sessions taking 60 seconds to start a turn after a browser-hosted MCP server's page had gone away
Fixed worktree-isolated sessions refusing common Bash loops, xargs pipelines and launcher-wrapped commands that cannot reach the main checkout
Improved terminal resize and first-render performance for long responses by reusing text measurements
Improved /workflows agent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle
Improved headless/SDK session start: the first turn begins up to 50 ms sooner when MCP servers finish connecting
Improved /install-github-app to explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repository
Improved nested background subagent results to be saved in the parent subagent's transcript, so resumed subagents keep them and shared transcripts show the delivery
Changed allowedMcpServers to govern only servers users add: a literal managed-mcp.json server your allowlist used to filter out now loads on upgrade; use deniedMcpServers to keep it off
[VSCode] Added an Active quick filter and a status filter menu (Needs input, Working, Completed) to the session list sidebar
Fixed remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused
Stacked slash-skill invocations like /skill-a /skill-b do XYZ now load all leading skills (up to 5), not just the first
Fixed SSL certificate errors (TLS-inspecting proxies, missing NODE_EXTRA_CA_CERTS, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hint
Fixed streaming responses being discarded when the API emits a mid-stream overloaded/server error after partial output — the partial is now kept with an incomplete-response notice
Fixed subagents cut off by a rate limit or server error silently failing instead of returning their partial work to the parent
Fixed subagents reporting API errors (e.g. usage limit reached) as successful results — the error is now reported to the parent agent
Fixed the background-agent daemon on Linux killing itself and every running agent every ~50 seconds after an unclean shutdown left a corrupted worker record
Fixed background agents failing to cold-start over SSH on macOS with "Could not switch to audit session" (regression in 2.1.196)
Fixed claude stop being silently undone when it raced a background-agent respawn — the respawn now honors the stop
Fixed background job progress indicators stalling for minutes while the job ran long commands
Fixed background sessions on memory-starved machines showing a generic error — they now indicate low memory and suggest freeing resources
Fixed remote sessions briefly flapping between Working and Idle in the agent view when a background agent completes
Fixed idle subagents vanishing from the agent panel while other subagents were still working; surplus idle agents now collapse into an expandable summary row
Fixed typing /model or /fast while viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the lead
Fixed SessionStart, Setup, and SubagentStart hooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcript
Fixed claude --dangerously-skip-permissions daemon <subcommand> being treated as a chat prompt instead of running the subcommand
Fixed SendMessage silently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget
Fixed opening or resuming a session with no new messages needlessly growing the transcript file
Fixed backgrounding a session with ← or /background dropping its /color from the agent view row
Fixed resetting a corrupted config file from the startup recovery dialog destroying it unrecoverably — it now backs up the file first
Fixed Claude in Chrome repeatedly opening the reconnect page when sessions run from different builds or config directories
Fixed plan mode not prompting for state-changing browser tool calls; read-only browser_batch calls are now correctly auto-allowed
Transient server rate-limit errors (429s unrelated to your usage limit) are now retried automatically with backoff for subscribers instead of failing the turn
CLAUDE_CODE_RETRY_WATCHDOG now raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 on CLAUDE_CODE_MAX_RETRIES
claude agents session rows now show pull-request links as bare #N without the redundant "PR" label
Fixed mid-stream connection drops: partial responses are now preserved instead of showing a raw error, and the spinner no longer gets stuck at "running tool"
Fixed mouse-wheel scrolling in WSL2 under Windows Terminal and VS Code (regression in 2.1.172)
Fixed a sandbox denyRead/allowRead glob over a large directory tree making the Bash tool description enormous and the session unusable on Linux
Fixed the feedback survey capturing a single-digit reply as a session rating immediately after a turn completes
Fixed the welcome screen stacking multiple promotional banners — at most one promo now shows per session
Fixed Ctrl+O not showing the subagent's transcript when viewing a subagent
Fixed clicking the prompt input not returning focus from the subagent/footer panel
Fixed remote session background tasks appearing stuck as "still running" between turns
Improved plugin loading performance in remote sessions
Added --plugin-url <url> flag to fetch a plugin .zip archive from a URL for the current session
Added CLAUDE_CODE_FORCE_SYNC_OUTPUT=1 env var to force-enable synchronized output on terminals that auto-detection misses (e.g. Emacs eat)
Added CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE: when set on Homebrew or WinGet installations, Claude Code runs the upgrade command in the background and prompts to restart
Plugin manifests: themes and monitors should now be declared under "experimental": { ... }. Top-level declarations still work but claude plugin validate will warn
Gateway /v1/models discovery for the /model picker is now opt-in via CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1 (was automatic in 2.1.126–2.1.128)
Ctrl+R history picker now defaults to searching all prompts across all projects, matching pre-2.1.124 behavior. Press Ctrl+S to narrow to the current project or session
Third-party deployments (Bedrock, Vertex, Foundry, or ANTHROPIC_BASE_URL gateway) no longer see spinner tips pointing at first-party Anthropic surfaces
skillOverrides setting now works: off hides from model and /, user-invocable-only hides from model only, name-only collapses description
The claude_code.pull_request.count OTel metric now counts PRs/MRs created via MCP tools, not just shell commands
Policy refusal error messages now include the API Request ID for easier support debugging
Fixed API errors with unrecognized 400 status codes showing raw JSON instead of the underlying error message
Fixed /clear not resetting the terminal tab title after a conversation
Fixed session title chip from /rename disappearing while a permission or other dialog is active
Fixed agent panel below the prompt being hidden when subagents are running (regression in 2.1.122)
Fixed external-editor handoff (Ctrl+G) blanking the conversation history above the prompt
Fixed /context dumping its rendered ASCII visualization grid into the conversation, wasting ~1.6k tokens per call
Fixed /agents Library list arrow-key navigation: the highlighted agent now stays visible when the list exceeds the viewport
Fixed /branch success message not including the new branch's session id for /resume
Fixed bold headers with keycap/ZWJ/skin-tone emoji losing trailing characters in fullscreen mode
Fixed server-managed settings policy not applying for enterprise/team users whose stored OAuth credentials lacked the user:inference scope
Fixed OAuth refresh race after wake-from-sleep that could log out all running sessions
Fixed 1-hour prompt cache TTL being silently downgraded to 5 minutes
Fixed cache-miss warning appearing spuriously after /clear or compaction when changing /effort or /model
Fixed Bash(mkdir *), Bash(touch *) and similar allow rules not being honored for in-project paths
Fixed deniedMcpServers patterns with a *:// scheme wildcard not matching mixed-case hostnames
Fixed harmless WebSocket warning being logged as an error in --debug during voice mode
[VSCode] Fixed /clear not clearing the conversation context and displayed transcript
Added interactive Google Vertex AI setup wizard accessible from the login screen when selecting "3rd-party platform", guiding you through GCP authentication, project and region configuration, credential verification, and model pinning
Added CLAUDE_CODE_PERFORCE_MODE env var: when set, Edit/Write/NotebookEdit fail on read-only files with a p4 edit hint instead of silently overwriting them
Added Monitor tool for streaming events from background scripts
Added subprocess sandboxing with PID namespace isolation on Linux when CLAUDE_CODE_SUBPROCESS_ENV_SCRUB is set, and CLAUDE_CODE_SCRIPT_CAPS env var to limit per-session script invocations
Added --exclude-dynamic-system-prompt-sections flag to print mode for improved cross-user prompt caching
Added workspace.git_worktree to the status line JSON input, set whenever the current directory is inside a linked git worktree
Added W3C TRACEPARENT env var to Bash tool subprocesses when OTEL tracing is enabled, so child-process spans correctly parent to Claude Code's trace tree
LSP: Claude Code now identifies itself to language servers via clientInfo in the initialize request
Fixed a Bash tool permission bypass where a backslash-escaped flag could be auto-allowed as read-only and lead to arbitrary code execution
Fixed compound Bash commands bypassing forced permission prompts for safety checks and explicit ask rules in auto and bypass-permissions modes
Fixed read-only commands with env-var prefixes not prompting unless the var is known-safe (LANG, TZ, NO_COLOR, etc.)
Fixed redirects to /dev/tcp/... or /dev/udp/... not prompting instead of auto-allowing
Fixed stalled streaming responses timing out instead of falling back to non-streaming mode
Fixed 429 retries burning all attempts in ~13s when the server returns a small Retry-After — exponential backoff now applies as a minimum
Fixed MCP OAuth oauth.authServerMetadataUrl config override not being honored on token refresh after restart, affecting ADFS and similar IdPs
Fixed capital letters being dropped to lowercase on xterm and VS Code integrated terminal when the kitty keyboard protocol is active
Fixed macOS text replacements deleting the trigger word instead of inserting the substitution
Fixed --dangerously-skip-permissions being silently downgraded to accept-edits mode after approving a write to a protected path via Bash
Fixed managed-settings allow rules remaining active after an admin removed them, until process restart
Fixed permissions.additionalDirectories changes not applying mid-session — removed directories lose access immediately and added ones work without restart
Fixed removing a directory from additionalDirectories revoking access to the same directory passed via --add-dir
Fixed Bash(cmd:*) and Bash(git commit *) wildcard permission rules failing to match commands with extra spaces or tabs
Fixed Bash(...) deny rules being downgraded to a prompt for piped commands that mix cd with other segments
Fixed permission rules with names matching JavaScript prototype properties (e.g. toString) causing settings.json to be silently ignored
Fixed agent team members not inheriting the leader's permission mode when using --dangerously-skip-permissions
Fixed a crash in fullscreen mode when hovering over MCP tool results
Fixed copying wrapped URLs in fullscreen mode inserting spaces at line breaks
Fixed file-edit diffs disappearing from the UI on --resume when the edited file was larger than 10KB
Fixed several /resume picker issues: --resume <name> opening uneditable, filter reload wiping search state, empty list swallowing arrow keys, cross-project staleness, and transient task-status text replacing conversation summaries
Fixed /export not honoring absolute paths and ~, and silently rewriting user-supplied extensions to .txt
Fixed /effort max being denied for unknown or future model IDs
Fixed slash command picker breaking when a plugin's frontmatter name is a YAML boolean keyword
Fixed rate-limit upsell text being hidden after message remounts
Fixed MCP tools with _meta["anthropic/maxResultSizeChars"] not bypassing the token-based persist layer
Fixed voice mode leaking dozens of space characters into the input when re-holding the push-to-talk key while the previous transcript is still processing
Fixed DISABLE_AUTOUPDATER not fully suppressing the npm registry version check and symlink modification on npm-based installs
Fixed a memory leak where Remote Control permission handler entries were retained for the lifetime of the session
Fixed background subagents that fail with an error not reporting partial progress to the parent agent
Fixed prompt-type Stop/SubagentStop hooks failing on long sessions, and hook evaluator API errors showing "JSON validation failed" instead of the real message
Fixed feedback survey rendering when dismissed
Fixed Bash grep -f FILE / rg -f FILE not prompting when reading a pattern file outside the working directory
Fixed stale subagent worktree cleanup removing worktrees that contain untracked files
Fixed sandbox.network.allowMachLookup not taking effect on macOS
Improved /resume filter hint labels and added project/worktree/branch names in the filter indicator
Improved footer indicators (Focus, notifications) to stay on the mode-indicator row instead of wrapping at narrow terminal widths
Improved /agents with a tabbed layout: a Running tab shows live subagents, and the Library tab adds Run agent and View running instance actions
Improved /reload-plugins to pick up plugin-provided skills without requiring a restart
Improved Accept Edits mode to auto-approve filesystem commands prefixed with safe env vars or process wrappers
Improved Vim mode: j/k in NORMAL mode now navigate history and select the footer pill at the input boundary
Improved hook errors in the transcript to include the first line of stderr for self-diagnosis without --debug
Improved OTEL tracing: interaction spans now correctly wrap full turns under concurrent SDK calls, and headless turns end spans per-turn
Improved transcript entries to carry final token usage instead of streaming placeholders
Updated the /claude-api skill to cover Managed Agents alongside Claude API
[VSCode] Fixed false-positive "requires git-bash" error on Windows when CLAUDE_CODE_GIT_BASH_PATH is set or Git is installed at a default location
Fixed CLAUDE_CODE_MAX_CONTEXT_TOKENS to honor DISABLE_COMPACT when it is set.
Dropped /compact hints when DISABLE_COMPACT is set.
Added the /claude-api skill for building applications with the Claude API and Anthropic SDK
Added Ctrl+U on an empty bash prompt (!) to exit bash mode, matching escape and backspace
Added numeric keypad support for selecting options in Claude's interview questions (previously only the number row above QWERTY worked)
Added optional name argument to /remote-control and claude remote-control (/remote-control My Project or --name "My Project") to set a custom session title visible in claude.ai/code
Added Voice STT support for 10 new languages (20 total) — Russian, Polish, Turkish, Dutch, Ukrainian, Greek, Czech, Danish, Swedish, Norwegian
Added effort level display (e.g., "with low effort") to the logo and spinner, making it easier to see which effort setting is active
Added agent name display in terminal title when using claude --agent
Added sandbox.enableWeakerNetworkIsolation setting (macOS only) to allow Go programs like gh, gcloud, and terraform to verify TLS certificates when using a custom MITM proxy with httpProxyPort
Added includeGitInstructions setting (and CLAUDE_CODE_DISABLE_GIT_INSTRUCTIONS env var) to remove built-in commit and PR workflow instructions from Claude's system prompt
Added /reload-plugins command to activate pending plugin changes without restarting
Added a one-time startup prompt suggesting Claude Code Desktop on macOS and Windows (max 3 showings, dismissible)
Added ${CLAUDE_SKILL_DIR} variable for skills to reference their own directory in SKILL.md content
Added InstructionsLoaded hook event that fires when CLAUDE.md or .claude/rules/*.md files are loaded into context
Added agent_id (for subagents) and agent_type (for subagents and --agent) to hook events
Added worktree field to status line hook commands with name, path, branch, and original repo directory when running in a --worktree session
Added pluginTrustMessage in managed settings to append organization-specific context to the plugin trust warning shown before installation
Added policy limit fetching (e.g., remote control restrictions) for Team plan OAuth users, not just Enterprise
Added pathPattern to strictKnownMarketplaces for regex-matching file/directory marketplace sources alongside hostPattern restrictions
Added plugin source type git-subdir to point to a subdirectory within a git repo
Added oauth.authServerMetadataUrl config option for MCP servers to specify a custom OAuth metadata discovery URL when standard discovery fails
Fixed a security issue where nested skill discovery could load skills from gitignored directories like node_modules
Fixed trust dialog silently enabling all .mcp.json servers on first run. You'll now see the per-server approval dialog as expected
Fixed claude remote-control crashing immediately on npm installs with "bad option: --sdk-url" (#28334)
Fixed --model claude-opus-4-0 and --model claude-opus-4-1 resolving to deprecated Opus versions instead of current
Fixed macOS keychain corruption when using multiple OAuth MCP servers. Large OAuth metadata blobs could overflow the security -i stdin buffer, silently leaving stale credentials behind and causing repeated /login prompts.
Fixed .credentials.json losing subscriptionType (showing "Claude API" instead of "Claude Pro"/"Claude Max") when the profile endpoint transiently fails during token refresh (#30185)
Fixed ghost dotfiles (.bashrc, HEAD, etc.) appearing as untracked files in the working directory after sandboxed Bash commands on Linux
Fixed Shift+Enter printing [27;2;13~ instead of inserting a newline in Ghostty over SSH
Fixed stash (Ctrl+S) being cleared when submitting a message while Claude is working
Fixed ctrl+o (transcript toggle) freezing for many seconds in long sessions with lots of file edits
Fixed plan mode feedback input not supporting multi-line text entry (backslash+Enter and Shift+Enter now insert newlines)
Fixed cursor not moving down into blank lines at the top of the input box
Fixed /stats crash when transcript files contain entries with missing or malformed timestamps
Fixed a brief hang after a streaming error on long sessions (the transcript was being fully rewritten to drop one line; it is now truncated in place)
Fixed --setting-sources user not blocking dynamically discovered project skills
Fixed duplicate CLAUDE.md, slash commands, agents, and rules when running from a worktree nested inside its main repo (e.g. claude -w)
Fixed plugin Stop/SessionEnd/etc hooks not firing after any /plugin operation
Fixed plugin hooks being silently dropped when two plugins use the same ${CLAUDE_PLUGIN_ROOT}/... command template
Fixed memory leak in long-running SDK/CCR sessions where conversation messages were retained unnecessarily
Fixed API 400 errors in forked agents (autocompact, summarization) when resuming sessions that were interrupted mid-tool-batch
Fixed "unexpected tool_use_id found in tool_result blocks" error when resuming conversations that start with an orphaned tool result
Fixed teammates accidentally spawning nested teammates via the Agent tool's name parameter
Fixed CLAUDE_CODE_MAX_OUTPUT_TOKENS being ignored during conversation compaction
Fixed /compact summary rendering as a user bubble in SDK consumers (Claude Code Remote web UI, VSCode extension)
Fixed voice space bar getting stuck after a failed voice activation (module loading race, cold GrowthBook)
Fixed worktree file copy on Windows
Fixed global .claude folder detection on Windows
Fixed symlink bypass where writing new files through a symlinked parent directory could escape the working directory in acceptEdits mode
Fixed sandbox prompting users to approve non-allowed domains when allowManagedDomainsOnly is enabled in managed settings — non-allowed domains are now blocked automatically with no bypass
Fixed interactive tools (e.g., AskUserQuestion) being silently auto-allowed when listed in a skill's allowed-tools, bypassing the permission prompt and running with empty answers
Fixed multi-GB memory spike when committing with large untracked binary files in the working tree
Fixed Escape not interrupting a running turn when the input box has draft text. Use Up arrow to pull queued messages back for editing, or Ctrl+U to clear the input line.
Fixed Android app crash when running local slash commands (/voice, /cost) in Remote Control sessions
Fixed a memory leak where old message array versions accumulated in React Compiler memoCache over long sessions
Fixed a memory leak where REPL render scopes accumulated over long sessions (~35MB over 1000 turns)
Fixed memory retention in in-process teammates where the parent's full conversation history was pinned for the teammate's lifetime, preventing GC after /clear or auto-compact
Fixed a memory leak in interactive mode where hook events could accumulate unboundedly during long sessions
Fixed hang when --mcp-config points to a corrupted file
Fixed slow startup when many skills/plugins are installed
Fixed cd <outside-dir> && <cmd> permission prompt to surface the chained command instead of only showing "Yes, allow reading from /"
Fixed conditional .claude/rules/*.md files (with paths: frontmatter) and nested CLAUDE.md files not loading in print mode (claude -p)
Fixed /clear not fully clearing all session caches, reducing memory retention in long sessions
Fixed terminal flicker caused by animated elements at the scrollback boundary
Fixed UI frame drops on macOS when using MCP servers with OAuth (regression from 2.1.x)
Fixed occasional frame stalls during typing caused by synchronous debug log flushes
Fixed TeammateIdle and TaskCompleted hooks to support {"continue": false, "stopReason": "..."} to stop the teammate, matching Stop hook behavior
Fixed WorktreeCreate and WorktreeRemove plugin hooks being silently ignored
Fixed skill descriptions with colons (e.g., "Triggers include: X, Y, Z") failing to load from SKILL.md frontmatter
Fixed project skills without a description: frontmatter field not appearing in Claude's available skills list
Fixed /context showing identical token counts for all MCP tools from a server
Fixed literal nul file creation on Windows when the model uses CMD-style 2>nul redirection in Git Bash
Fixed extra blank lines appearing below each tool call in the expanded subagent transcript view (Ctrl+O)
Fixed Tab/arrow keys not cycling Settings tabs when /config search box is focused but empty
Fixed service key OAuth sessions (CCR containers) spamming [ERROR] logs with 403s from profile-scoped endpoints
Fixed inconsistent color for "Remote Control active" status indicator
Fixed Voice waveform cursor covering the first suffix letter when dictating mid-input
Fixed Voice input showing all 5 spaces during warmup instead of capping at ~2 (aligning with the "keep holding…" hint)
Improved spinner performance by isolating the 50ms animation loop from the surrounding shell, reducing render and CPU overhead during turns
Improved UI rendering performance in native binaries with React Compiler
Improved --worktree startup by eliminating a git subprocess on the startup path
Improved macOS startup by eliminating redundant settings-file reloads when managed settings resolve
Improved macOS startup for Claude.ai enterprise/team users by skipping an unnecessary keychain lookup
Improved MCP -p startup by pipelining claude.ai config fetch with local connections and using a concurrency pool instead of sequential batching
Improved voice startup by removing imperceptible warmup pulse animations that were causing re-render stutter
Improved MCP binary content handling: tools returning PDFs, Office documents, or audio now save decoded bytes to disk with the correct file extension instead of dumping raw base64 into the conversation context. WebFetch also saves binary responses alongside its summary.
Improved memory usage in long sessions by stabilizing onSubmit across message updates
Improved LSP tool rendering and memory context building to no longer read entire files
Improved session upload and memory sync to avoid reading large files into memory before size/binary checks
Improved file operation performance by avoiding reading file contents for existence checks (6 sites)
Improved documentation to clarify that --append-system-prompt-file and --system-prompt-file work in interactive mode (the docs previously said print mode only)
Reduced baseline memory by ~16MB by deferring Yoga WASM preloading
Reduced memory footprint for SDK and CCR sessions using stream-json output
Reduced memory usage when resuming large sessions (including compacted history)
Reduced token usage on multi-agent tasks with more concise subagent final reports
Changed Sonnet 4.5 users on Pro/Max/Team Premium to be automatically migrated to Sonnet 4.6
Changed the /resume picker to show your most recent prompt instead of the first one. This also resolves some titles appearing as (session).
Changed claude.ai MCP connector failures to show a notification instead of silently disappearing from the tool list
Changed example command suggestions to be generated deterministically instead of calling Haiku
Changed resuming after compaction to no longer produce a preamble recap before continuing
[SDK] Changed task creation to no longer require the activeForm field — the spinner falls back to the task subject
[VSCode] Added compaction display as a collapsible "Compacted chat" card with the summary inside
[VSCode] The permission mode picker now respects permissions.disableBypassPermissionsMode from your effective Claude Code settings (including managed/policy settings) — when set to disable, bypass permissions mode is hidden from the picker
[VSCode] Fixed RTL text (Arabic, Hebrew, Persian) rendering reversed in the chat panel (regression in v2.1.63)
Claude automatically saves useful context to auto-memory. Manage with /memory
Added /copy command to show an interactive picker when code blocks are present, allowing selection of individual code blocks or the full response.
Improved "always allow" prefix suggestions for compound bash commands (e.g. cd /tmp && git fetch && git push) to compute smarter per-subcommand prefixes instead of treating the whole command as one
Improved ordering of short task lists
Improved memory usage in multi-agent sessions by releasing completed subagent task state
Fixed MCP OAuth token refresh race condition when running multiple Claude Code instances simultaneously
Fixed shell commands not showing a clear error message when the working directory has been deleted
Fixed config file corruption that could wipe authentication when multiple Claude Code instances ran simultaneously
Added Claude Sonnet 5.5 (claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads
Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones
Added dollar amounts to the Claude apps gateway spend limit in /usage and the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line's rate_limits.spend_limit also gains used_usd, limit_usd and period
Added effortSlider:decreaseEffort, increaseEffort and toggleUltracode keybinding actions, so the /effort slider's arrow and Tab keys can be rebound in keybindings.json
Added /rate-limit-options to /help and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find
Added /mcp reconnect all in the interactive terminal to retry every MCP server that failed to connect or needs authentication at once
Added Claude apps gateway startup warnings when a managed policy's availableModels is empty, or leaves out the model Claude Code starts on without setting model or enforceAvailableModels
Added auth: { google: {} } for Claude apps gateway telemetry.forward_to destinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials
Added certificate client authentication (private_key_jwt) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets
Fixed a damaged response stream showing raw errors such as "JSON Parse error" or "undefined is not an object", or writing the word "undefined" into an answer, instead of being retried or reported as an interrupted response
Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried
Fixed "Prompt is too long" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation
Fixed a session whose model is unavailable, with no fallback model left, showing a bare "is currently unavailable" message (or "Something went wrong" in cloud sessions) instead of the model-unavailable notice and its Learn more link
Fixed Agent SDK sessions crashing when a user message contains an image with a malformed source, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note
Fixed MCP tool calls in a resumed session failing with "No such tool available" while their server was still connecting; the call now waits up to 10 seconds for the server
Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login: /usage, /extra-usage and IDE usage views now back off instead of re-asking
Fixed claude mcp add reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads
Fixed the /plugin configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs
Fixed ANTHROPIC_FOUNDRY_RESOURCE being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused
Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically
Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt
Fixed Bash tool failing on Windows with many plugins enabled: plugin bin/ directories that don't exist are no longer added to PATH, and inherited entries aren't added twice
Fixed sparsePaths plugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present"
Fixed fullscreen rendering erasing the terminal output above the session when [ in transcript mode writes the conversation to scrollback (macOS and Linux)
Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up
Fixed tab bars in dialogs such as /config and /plugin breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole
Fixed the /model picker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows
Fixed /keybindings writing Backspace and Delete bindings for a footer action that does nothing into the generated keybindings.json
Fixed a rebound agent panel close key (footer:close) typing "x" instead of itself on the row of the agent you're viewing
Fixed vim mode . not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as cw then Esc)
Fixed vim mode leaving the cursor on an image placeholder's opening bracket after dd on the last line or yy at the end of the prompt, where r or x would break or delete the image
Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted
Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory
Fixed rules symlinked into .claude/rules from outside the project being skipped without ever showing the external-imports approval prompt; a .claude directory symlinked from outside the project now asks for the same approval
Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval
Fixed a failed first claude plugin install leaving the plugin enabled and recorded when a dependency's version range could not be met
Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code
Fixed {"decision":"block"} returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does
Fixed sessions launched without the SendMessage tool (such as by Claude Desktop) still being told to message other sessions with it
Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption
Fixed typing a message during an automatic usage-limit wait taking the wait out of the "Continue automatically at usage limit" setting's control when that turn hit the limit again
Fixed usage-limit warnings suggesting /upgrade to users already on the highest Max plan; the warnings and /upgrade itself now point at /usage-credits when it is available
Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model
Fixed /loop status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text
Fixed /ultrareview failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux
Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory
Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private data/users/ subtree, and added a "view" level to as_level
Fixed the Claude apps gateway answering 431 Request Header Fields Too Large to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB
Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown
Improved the "No such tool available" error for Claude in Chrome tools called without their prefix: it now names the tool to call
Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged "Waiting for N … to finish" line after every event
Improved Workflow tool sandbox hardening for errors thrown by async script hooks
Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use
Improved /claude-api: hillclimb no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside report.html is built as one local file that loads nothing from the network
Improved lists such as /tasks, /copy and /hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edge
Improved claude plugin marketplace add to say when it replaces a marketplace already added under the same name from a different source, and how to undo it
Improved the startup refusal when managed settings require a sign-in (forceLoginMethod or forceLoginOrgUUID) and an API key, token or apiKeyHelper is configured: it now names the credential in use, where it is set, and how to remove it
Improved auto-memory loading: invisible characters and tags that imitate Claude Code's own markup are neutralized in MEMORY.md and recalled memory notes before they reach Claude
Improved claude remote-control: in a folder you haven't trusted yet, it now asks for workspace trust on the terminal instead of exiting
Improved artifact pages: Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title
Improved the Artifact tool so that when Claude is given a claude.ai chat or project link, an artifact from a chat, or an artifact id on its own, it asks for the right link or the content instead of stopping
Changed interactive terminal and VS Code sessions to start in auto mode when no permission mode is configured, on every plan and provider; permissions.defaultMode still overrides it
Changed Ultracode into its own toggle in /effort (Tab, or /effort ultracode [on|off]): it no longer forces xhigh effort and stays on at any effort level
Changed retries after a dropped connection mid-response to share one budget with the rest of the request's retries, so a failing request gives up sooner
Changed the notice shown when a Sonnet model's safeguards flag a message to explain why it happened and to offer editing and retrying
Changed safety-related model switches in sessions that pin an Opus model with ANTHROPIC_DEFAULT_OPUS_MODEL or modelOverrides: on the Anthropic API, the API now picks the model to switch to for each kind of flag, not the pinned model
Changed the non-interactive first turn to still wait up to 2s for connecting MCP servers named by --allowedTools or an mcp_tool hook, even when CLAUDE_CODE_MCP_STARTUP_WAIT_MS is 0
Changed /recap to decline with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook; typed in the terminal, the Claude apps, Remote Control, -p or an SDK host, it runs as before
Changed /artifacts to show its filter tabs beside the title with one-word labels (All, Mine, Shared), using the same tab bar as /config and /plugin
Changed artifact publishing to refuse a file on a network share (a \\host\share path or a /net automount) unless it is on a mapped network drive added with --add-dir
[VSCode] Added an optional time above each prompt and response, with a date line where the day changes (Claude Code: Show Message Timestamps setting, off by default)
[VSCode] Added plugin load errors and notes to the Manage plugins rows, with a popup to disable, uninstall or copy the error
[VSCode] Added an Ultracode on/off switch under the Effort slider, replacing the slider's Ultracode stop; the model pill shows "· Ultracode" at any effort level
[VSCode] Fixed Reload Claude from the Memory dialog restarting before an edited file was saved
[VSCode] Fixed a restored tab opening a conversation another Claude process still has open; it now asks first
[VSCode] Fixed Focus view sections you expanded closing on their own while a sub-agent is working or when the section's first step is trimmed from view
[VSCode] Fixed typing /model and Enter printing usage text into the chat instead of opening the model selector
[VSCode] Fixed /feedback on Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does
[VSCode] Fixed sign-in waiting up to a minute for the Python extension after a window reload
[VSCode] Fixed Claude Code tabs that stopped responding after Restart Extensions: they now reopen on their conversation
[VSCode] Fixed a message from another agent with no recorded sender showing as raw XML in the chat
[VSCode] Fixed messages from other agents, sessions or channels disappearing after a reload
[VSCode] Fixed a user's own /mcp, /config or /settings command being shadowed by the extension's dialog
[VSCode] Fixed Escape stopping every background agent when no turn was running
[VSCode] Fixed plugin install links replacing a marketplace you already have that uses the same name
[VSCode] Fixed "Prompt is too long" errors after compaction when a large text file is attached to a message
[VSCode] Fixed chat links to files with non-ASCII characters, spaces or brackets in their path not opening
[VSCode] Changed CLAUDE_CONFIG_DIR in the claudeCode.environmentVariables setting to apply only when it is an absolute path, and passed it to terminals that continue the chat
[Cloud sessions] Fixed a routine's Edit and Duplicate controls saying the routine was still loading while you were offline; they now tell you you're offline
[Claude Tag] Added model family choices such as "Opus (latest)" for a thread, a channel default or your DM, so the choice follows the newest model in that family
[Claude Tag] Added the spend that counts toward your organization-wide limit to the analytics spend projection chart, with how much of the limit is used
[Claude Tag] Fixed the earlier Claude in Slack app's progress card and link previews omitting the repository and Create PR button when a GitHub Enterprise host name contains an underscore
[Claude Tag] Fixed Claude staying silent in a channel whose environment declines to start it; it now posts one notice asking you to contact an admin, and retries when @-mentioned
[Claude Tag] Changed Claude to post its private sign-in notice at every @mention from someone who hasn't connected their Claude account, instead of going quiet after the first
[Claude Tag] Improved "Notify members now" in admin settings: one press reaches every workspace your organization claimed in an Enterprise Grid, and more members in large workspaces
[Claude Tag] Improved Claude's wait notice on self-hosted environments with on-demand runners: it now says whether a runner is starting, a start will be retried, or no runner will start
[Claude Tag] Improved the error shown when adding a channel manager fails because the channel's Slack workspace can't be confirmed as connected to your organization
[Claude Tag] Improved a channel's access lists in admin settings to show the connectors, repositories and plugins an auto-join pattern attaches, and where each comes from
[Claude Tag] Improved adding repositories as a channel manager: when your GitHub sign-in can't confirm you're a repository admin, the page asks you to sign in with GitHub
[Code Review] Fixed Code Review giving up without posting a finished review when an unsubmitted review under its GitHub App was open on the pull request; it now retries the post first
Added Claude in Chrome (Beta) feature that works with the Chrome extension (https://claude.ai/chrome) to let you control your browser directly from Claude Code
Reduced terminal flickering
Added scannable QR code to mobile app tip for quick app downloads
Added loading indicator when resuming conversations for better feedback
Fixed /context command not respecting custom system prompts in non-interactive mode
Fixed order of consecutive Ctrl+K lines when pasting with Ctrl+Y
Thinking mode is now enabled by default for Opus 4.5
Thinking mode configuration has moved to /config
Added search functionality to /permissions command with / keyboard shortcut for filtering rules by tool name
Show reason why autoupdater is disabled in /doctor
Fixed false "Another process is currently updating Claude" error when running claude update while another instance is already on the latest version
Fixed MCP servers from .mcp.json being stuck in pending state when running in non-interactive mode (-p flag or piped input)
Fixed scroll position resetting after deleting a permission rule in /permissions
Fixed word deletion (opt+delete) and word navigation (opt+arrow) not working correctly with non-Latin text such as Cyrillic, Greek, Arabic, Hebrew, Thai, and Chinese
Fixed claude install --force not bypassing stale lock files
Fixed consecutive @~/ file references in CLAUDE.md being incorrectly parsed due to markdown strikethrough interference
Windows: Fixed plugin MCP servers failing due to colons in log directory paths
Pro users now have access to Opus 4.5 as part of their subscription!
Fixed timer duration showing "11m 60s" instead of "12m 0s"
Windows: Managed settings now prefer C:\Program Files\ClaudeCode if it exists. Support for C:\ProgramData\ClaudeCode will be removed in a future version.
Added setting to enable/disable terminal progress bar (OSC 9;4)
VSCode Extension: Added support for VS Code's secondary sidebar (VS Code 1.97+), allowing Claude Code to be displayed in the right sidebar while keeping the file explorer on the left. Requires setting sidebar as Preferred Location in the config.
Fixed proxy DNS resolution being forced on by default. Now opt-in via CLAUDE_CODE_PROXY_RESOLVES_HOSTS=true environment variable
Fixed keyboard navigation becoming unresponsive when holding down arrow keys in memory location selector
Improved AskUserQuestion tool to auto-submit single-select questions on the last question, eliminating the extra review screen for simple question flows
Improved fuzzy matching for @ file suggestions with faster, more accurate results
Improve fuzzy search results when searching commands
Improved VS Code extension to respect chat.fontSize and chat.fontFamily settings throughout the entire UI, and apply font changes immediately without requiring reload
Added CLAUDE_CODE_EXIT_AFTER_STOP_DELAY environment variable to automatically exit SDK mode after a specified idle duration, useful for automated workflows and scripts
Migrated ignorePatterns from project config to deny permissions in the localSettings.
Fixed menu navigation getting stuck on items with empty string or other falsy values (e.g., in the /hooks menu)
Added helpful hint to run security unlock-keychain when encountering API key errors on macOS with locked keychain
Added allowUnsandboxedCommands sandbox setting to disable the dangerouslyDisableSandbox escape hatch at policy level
Added disallowedTools field to custom agent definitions for explicit tool blocking
Added prompt-based stop hooks
VSCode: Added respectGitIgnore configuration to include .gitignored files in file searches (defaults to true)
Enabled SSE MCP servers on native build
Deprecated output styles. Review options in /output-style and use --system-prompt-file, --system-prompt, --append-system-prompt, CLAUDE.md, or plugins instead
Removed support for custom ripgrep configuration, resolving an issue where Search returns no results and config discovery fails
Update Bedrock default Sonnet model to global.anthropic.claude-sonnet-4-5-20250929-v1:0
IDE: Add drag-and-drop support for files and folders in chat
/context: Fix counting for thinking blocks
Improve message rendering for users with light themes on dark terminals
Remove deprecated .claude.json allowedTools, ignorePatterns, env, and todoFeatureEnabled config options (instead, configure these in your settings.json)
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [claude-code](https://github.com/anthropics/claude-code) | major | `0.2.122` → `2.1.245` |
---
### Release Notes
<details>
<summary>anthropics/claude-code (claude-code)</summary>
### [`v2.1.245`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21245)
- Fixed a crash on startup on Linux distributions that ship glibc 2.44 (for example Arch Linux, CachyOS and Fedora Rawhide)
### [`v2.1.238`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21238)
- Added a `keybindingFlavor` setting: set it to `"readline"` to make Ctrl+W in the prompt delete back to the previous whitespace, as in Bash; the default (`"classic"`) is unchanged
- Plugin marketplaces: `headersHelper` on a url marketplace or a catalog entry runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetches
- A catalog entry's `headersHelper` runs only when you install or update that plugin, after its command is shown; `claude plugin install/update` ask `[y/N]` (or pass `-y`)
- Added `claude self-hosted-runner --defer-shutdown-max-min <minutes>`: on SIGTERM, keep serving attached sessions, park what is left after that many minutes, then exit
- Added `claude self-hosted-runner --proxy-authorization-command` / `--proxy-authorization-file` for egress proxies that require a freshly issued `Proxy-Authorization` header on every connection
- Fixed unbounded memory growth in long interactive sessions: subagent tool results are now released once they leave the recent display window
- Fixed custom, project, and plugin output styles drifting back to the default voice mid-session
- Fixed `CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true` not keeping prompt suggestions on when your account is near, but not over, its usage limit
- Fixed worktree-isolation Bash refusals telling you to remove a redirect when the command had none
- Fixed self-hosted runners occasionally being removed by the server after a single slow or lost poll request, handing their healthy session to another runner
- Fixed MCP elicitation dialogs showing nothing for URLs longer than 4,096 characters, and permission prompts dropping the "don't ask again" option when the project path didn't fit the terminal width
- Fixed leftover `/tmp/claude-*-cwd` files when a Bash command is killed, times out, or is interrupted
- Fixed held Backspace being ignored on terminals that send Ctrl+H for Backspace when keystrokes arrive in large bursts (slow SSH/mosh links)
- Fixed text-wrapping in permission prompt diffs: lines containing wide multi-code-point characters (such as emoji) or tabs are no longer clipped
- Fixed killing a suspended (Ctrl+Z) session sometimes leaving the terminal in bracketed-paste mode with the cursor hidden
- Fixed stdio MCP servers receiving a `server/discover` request before `initialize`, forcing lazy servers to start their backend on every session open
- Fixed a proxy's refusal of a connection being reported as a generic network error instead of naming the proxy
- Fixed the `/model` and `/effort` cache-miss warning appearing when the prompt cache had already expired
- Fixed per-task Stop from the Remote Control tasks panel doing nothing on CLI-hosted sessions
- Fixed remote sessions exiting when a client delivered a user message without a valid role
- Fixed Remote Control sessions started by `claude remote-control` inheriting session-scoped environment variables from the launching shell
- Fixed a Remote Control session whose process crashed staying unavailable until `claude remote-control` was restarted; it can now be reused when you next message it
- Fixed Remote Control messages sent from the web or Desktop while Claude is mid-turn disappearing from the transcript after the turn finishes
- Fixed Remote Control model picks made on a phone or web not updating the model shown in the terminal
- Fixed Remote Control disconnecting with "login expired" when a brief network hiccup delays renewing your sign-in; it now retries and stays connected
- Fixed Remote Control reporting a failed reconnect on sign-out; signing out now ends the session with a clear message
- Fixed `ListAgents`/`SendMessage` reporting "Remote Control is not connected" in sessions run by `claude remote-control` (server mode) or Desktop/IDE hosts; they now list and reach Remote Control peers
- Fixed `ListAgents` and `SendMessage` exposing the idle worker that the agent view pre-warms for your next background session; it now appears only once a task claims it
- Cross-session messaging: sending to a session on this machine that refuses inbound messages (e.g. `crossSessionInbound: "refuse"`) now reports "refused" to the sender instead of a silent success
- Cross-session messaging: a session whose inbox drops your messages (rate limit or full queue) now tells your session, instead of the messages vanishing silently
- Improved startup: bare `claude` starts sooner on macOS
- Improved Bash tool permission checking for zsh-specific syntax in shell conditionals
- Improved Remote Control connection resilience: brief HTTP 403 refusals from a network edge, VPN, or proxy are now tolerated for up to 3 minutes, with the refusing party named when a block persists
- Improved startup responsiveness: the automatic update check now runs about 10 seconds after launch instead of competing with startup for CPU
- Updated the bundled `claude-api` skill for the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes
- Changed Ctrl+L and Cmd+K in fullscreen to always just repaint — the double-press `/clear` shortcut was removed, and 1-row nvim terminals no longer trigger automatic `/clear` loops
- Changed `claude mcp list` and `claude mcp get` to show disabled servers as `⊘ Disabled` instead of connecting to them for a health check
- MCP `headersHelper` in a project `.mcp.json`, and inline MCP servers in project or `--add-dir` agent files, now require that folder's trust dialog to have been accepted (also under `claude -p`)
- MCP `headersHelper` from a project `.mcp.json`, plugin, or agent file runs without inherited credential env vars; user, managed and claude.ai-scope helpers now run from the Claude config dir
### [`v2.1.235`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21235)
- Added an optional `spellcheck` setting that underlines misspelled words in the prompt input as you type, using your installed `aspell`, `hunspell`, or `ispell`
- Fixed whole-prompt-cache invalidation when a language server disconnected or reconnected mid-session
- Fixed nested markdown list items misaligning at depth 3+ and added a hanging indent to wrapped list items in the terminal UI
- Fixed prompt input highlights (slash commands, keywords, mentions) appearing shifted by one or more characters in some multi-line prompts
- Fixed Shift+Tab inside the permission prompt's comment field approving the edit and granting session-wide edit permission instead of closing the field
- Fixed the Agent tool advertising a general-purpose default in sessions where that agent is unavailable: an omitted `subagent_type` there now gets a clear error listing the available agents
- Fixed notebook cell delete/replace approval dialogs silently omitting the existing cell content when the notebook or cell could not be read; the dialog now says why
- Fixed slash commands run while Claude is responding showing HTML entities instead of the actual characters
- Fixed the prompt footer not showing the "Update installed" restart notice after a background auto-update
- Fixed the expanded task list (`ctrl+t`) always starting collapsed when resuming or relaunching into a session that still has open tasks
- Improved memory and CPU usage while cloud sessions such as `/ultrareview` or `/autofix-pr` run in the background — their event streams are no longer re-scanned and re-rendered on every update
- Improved permission dialogs: display text and "don't ask again" options now always match what a grant would cover, and "don't ask again" is withheld when contents cannot be fully displayed
- Improved the embedded `grep` in native macOS/Linux builds: pathological patterns now fail fast instead of exhausting memory, and `-m N` with `-A/-C` prints correct context
- Improved the context-limit error to say when auto-compact is off and point to `/config` to re-enable it
- Vim mode: NORMAL mode and cursor position are now preserved when toggling the detailed transcript (ctrl+o) or closing a panel
- Dialogs: arrow keys and Enter pressed in quick succession now select the option you navigated to instead of the previously highlighted one
- `SendMessage` now refuses messages too large for cross-session delivery up front instead of silently dropping them
- Remote Control: `claude rc` now applies the same enterprise-gateway availability check as interactive startup
- \[VSCode] Fixed focus jumping between open Claude tabs on its own when a window with several Claude panels is restored or reloaded
### [`v2.1.234`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21234)
- Added the optional `CLAUDE_CODE_PROJECT_DIR_NAME` environment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directory
- Added the `selection:clear` keybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view
- Added a GitLab merge request badge to the footer and statusline: repos with a GitLab remote and an authenticated glab CLI show MR !N with draft/pending/green states
- Claude Code now continues your session automatically when a claude.ai usage limit resets; turn it off in `/config` ("Continue automatically at usage limit")
- Claude is now told to use your account email only to identify you, and not to send it to unrelated services unless you ask
- Security: remote file reads, session restore, CLAUDE.md includes, workflow scripts and file uploads now reject Windows NT-namespace (`\??\`) paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vector
- Fixed auto mode in very long sessions repeatedly re-checking and denying sandboxed commands' network access after the conversation had been compacted
- Fixed session-scoped permission answers (including denies) being dropped when answering background subagent tool permission prompts
- Fixed a crash when an API response on the non-streaming fallback path (typically via third-party gateways) contained a thinking block missing its thinking field or a text block missing its text field
- Fixed markdown rendering becoming extremely slow for some messages containing unusual Unicode sequences
- Fixed `SendMessage` rejecting a recipient copied from `ListAgents` when the session name is at the 200-character cap or emoji-heavy
- Fixed repository detection mis-reading the host of git remotes with unusual userinfo, producing links and repo-specific behavior for the wrong host
- Fixed MCP diagnostics printing resolved secrets: scope-conflict warnings now show the configured `${VAR}` form, and connection-failure details show only the server origin
- Fixed `strictKnownMarketplaces` allowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to
- Fixed modal text such as the `/login` OAuth URL losing characters when copied in fullscreen
- Fixed a `---` horizontal rule in rendered markdown running into the line after it
- Fixed consecutive shell commands splitting into multiple "Ran 1 shell command" rows when todo/task updates were interleaved between them
- Fixed dialogs like `/permissions` opened while a `!` shell command was running being dismissed when the command finished
- Fixed a queued `!` shell command being sent to the model as plain text after pressing up-arrow to edit the queued input
- Fixed queued messages reappearing in the prompt history while still queued, Esc while selecting a queued message no longer interrupts the turn, and `!` mode no longer sticks after a mid-turn submit
- Fixed accepting the "Try the new fullscreen renderer?" prompt restarting the session without its permission mode (e.g. `--dangerously-skip-permissions`), tool allow/deny rules, model or effort flags
- Fixed `/tui` dropping launch `--allowed-tools`/`--disallowed-tools` rules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can't carry over
- Fixed trust prompts omitting the repository-wide scope warning when the directory was first seen before the repository existed there
- Fixed a case where an IDE diff tab closing during a permission re-prompt could answer the new prompt with the previous input
- Fixed: files sent to the user during Remote Control sessions hosted by Claude Code Desktop or VS Code now upload, so they open on phone and web instead of showing an empty card
- Fixed: after `/login` while `CLAUDE_CODE_OAUTH_TOKEN` is set, the stale-token reminder no longer leaks into Claude's automatically resumed turn — it now appears only to you
- Fixed: permission previews now relay only to channel servers admitted by the inbound trust gate, and a server's explicit permission-capability opt-out is honored
- Fixed: credential masking on relayed permission previews can no longer hide commands, paths, or destinations from the approver; oversized private-key blocks now redact under full-strength redaction
- Fixed: provider API tokens that mask on permission previews now mask even when directly followed by shell delimiters
- Fixed Claude Desktop inter-session messages being silently dropped by the recipient session when cross-session messaging read as disabled, which left the sender's query "thinking" for many minutes
- Remote Control: signing this computer in to a different claude.ai account or organization now stops the running session within seconds and says why, instead of a misleading HTTP 404 hours later
- Remote Control sessions started from Claude Code Desktop or VS Code now keep phones and claude.ai/code updated on the session's permission mode (and claude.ai/code on the model) as they change
- Remote Control: effort picks made on a phone or on claude.ai/code now apply to terminal- and Desktop/VS Code-hosted sessions, and the session publishes its effort level to connected clients
- `SendMessage` and `ListAgents` now say when your account's session list was too long to check completely, instead of treating unseen sessions as absent
- Expired Anthropic profile credential now points you at `/login` when a claude.ai login would take precedence
- Improved the transcript: your own prompts now render markdown (highlighted code blocks, inline code, lists) the same way replies do
- Improved the "API returned an empty or malformed response" error to say what came back (content type, body kind, size, request ID) and why the original streaming request failed
- Improved auto-generated session titles to read as short, specific names (e.g. "Login button bug") rather than sentences restating your request (e.g. "Fix the login button on mobile")
- Reduced the context cost of loading the built-in `claude-api` skill from \~200k+ tokens to \~25k by loading reference docs on demand
- `/permissions` can now be opened while Claude is working — rule changes apply to the rest of the current turn
- `/add-dir <path>` can now be used while Claude is working; `/add-dir`, `/autocompact`, `/theme`, `/help`, `/config` and `/advisor` dialogs open mid-turn in the fullscreen TUI
- `/goal` now clears itself with a notice when a turn dies on an unrecoverable error (e.g. revoked auth, an exhausted credit balance, or a context overflow) instead of staying armed
- `/goal`: when background tasks keep a goal waiting for 30+ minutes, Claude now checks in on them instead of waiting indefinitely (set `CLAUDE_CODE_GOAL_CHECKIN_MINUTES=0` to opt out)
- `claude setup-token` now rejects unexpected extra arguments instead of silently ignoring them
- Changed Esc in fullscreen mode to no longer clear a mouse text selection: it interrupts or dismisses as usual and the selection stays highlighted
- Removed the redundant "Allowed by auto mode classifier" line that auto mode showed under every Agent tool call
- Removed the "Default teammate model" setting from `/config`; agent-team teammates now use the leader's model unless the spawn names one
- Dimmed the elapsed-time counter on the running tool header so it no longer competes with the bold counts
- Background task notifications delivered between turns are now sent to the model inside `<system-reminder>` tags, matching mid-turn delivery
- Mantle: skip the admin-pin availability probe at startup when a main-loop model is already picked
- Windows: startup no longer stalls on repeated rename retries when `~/.claude.json` is read-only
### [`v2.1.233`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21233)
- Added GitLab merge request URL support to the `--worktree` flag and the `claude agents` view (where MRs display as `!N`)
- Added an opt-in `forward_user_identity` apps gateway setting on Anthropic upstreams that sends the signed-in user's identity as headers, so a proxy behind the gateway can attribute spend per user
- Added opt-in memory cgroup support for Bash tool commands on Linux (`CLAUDE_CODE_TOOL_MEMORY_LIMIT`) so a runaway build can't stall the session
- Added `CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS` environment variable to configure the WebFetch session URL cache TTL (default unchanged: 15 minutes)
- Fixed cloud sessions occasionally being marked as lost when the environment shut down while Claude was waiting on a permission prompt
- Fixed MCP v2 connections endlessly reopening the subscriptions/listen stream against servers that terminate long-held streams on a fixed timeout (e.g. serverless hosts)
- Fixed Notification hooks not firing for permission prompts when running under Claude Desktop or VS Code
- Fixed idle sessions on Linux sometimes keeping one CPU core at 100% when sandboxing is enabled
- Fixed bundled skill aliases like `/checkup` and `/review` reporting "Unknown command" in `-p` mode or with plugins/MCP loaded when a user or project skill shadows the bundled skill
- Fixed skill/command argument substitution to prevent argument values from being re-expanded as template markers
- Fixed Windows paths spelled with the NT `\??\` device prefix bypassing UNC path validation, closing an NTLM credential-leak vector
- Improved `claude self-hosted-runner` session start time: the session branch is now created without rewriting the working tree, and two server round trips no longer block the agent's launch
- Improved apps gateway error forwarding: 400/413 errors from Vertex, Foundry, and Claude Platform on AWS upstreams now carry the upstream's own message; fixes a bug with auto-compact on apps gateway
- Improved `claude plugin validate` to check a bare `.claude/skills` directory, reporting SKILL.md files whose frontmatter fails to parse
- Improved screen reader mode: the `/effort` selector renders as a numbered list with a typed-number prompt, and hint and dialog text is no longer clipped
- Improved print mode diagnostics: a `[claude-code:unrecognized_model]` line is written to stderr when a request goes out for a model ID Claude Code doesn't recognize; map it with `modelOverrides` to silence
- Changed the GitHub app setup tip to no longer appear in repositories whose origin remote is on gitlab.com or bitbucket.org; the enterprise marketplace tip now covers non-GitHub internal git hosts
- Todo/task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) are no longer available on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; set `CLAUDE_CODE_ENABLE_TODO_TOOLS=1` to bring them back
- Windows: fixed auto mode repeatedly stopping for manual approval on ordinary `cd <dir> && <command> > file` Bash commands (a 2.1.232 regression)
- Reverted the 2.1.232 Bash permission changes for Cygwin-style symlinks on Windows and for input redirections (`< file`); a narrower version will return in a later release
### [`v2.1.232`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21232)
- Subagent forking is now on by default: a `subagent_type: "fork"` subagent inherits the full conversation and prompt cache, and non-teammate agent spawns in interactive sessions now run in the background by default
- Type `@` in the prompt to mention another Claude session by name; Claude then uses `SendMessage` to reach that session directly
- `SendMessage` now delivers to a bare name that exactly matches one live session, instead of asking to confirm with a ref first
- Interactive sessions on one machine now keep unique names: starting or renaming a session to a name another live session already uses gives it a `name-word-word` variant and tells you
- Added `/config` rows for "Dialog expiry" and "Messages from your other sessions" (cross-session inbound accept/hold/refuse)
- Added secret redaction for GitLab token families (`glrt-`, `gloas-`, `glptt-`, `glagent-`, `glimt-`, `glsoat-`, `glcbt-`, `glft-`, `glffct-`) and full redaction of routable `glpat-`/`gldt-` tokens; the `glab` CLI config store gets the same sandbox and credential-path protection as `gh`
- Added GitLab support to plugin marketplaces: bare `gitlab.com` repo URLs (including nested subgroups) now clone like `github.com` URLs, and clone auth-failure hints name your actual git host
- Settings: `additionalMarketplaces` and `allowedMarketplaces` are now accepted as friendlier aliases for `extraKnownMarketplaces` and `strictKnownMarketplaces`
- Enterprise policy: a url-typed `blockedMarketplaces` entry for a bare repo URL keeps blocking that URL when the CLI classifies it as a git clone
- Gateway: the `desktop:` overlay now accepts every released Desktop setting (was 11 hand-listed keys), validated at boot against Desktop's own schema; unknown or invalid keys fail boot
- Gateway: empty `managed.policies[].match.groups`/`admin.admin_groups` entries and malformed `email_domain` values (empty, or containing `@`, whitespace, or commas) now fail at boot instead of silently matching no one or granting admin access
- Fable 5 is offered as an advisor in `/advisor` again for organizations with Fable access, with usage-credits consent set up through `/model fable`
- Fixed a PowerShell permission bypass where variable-writing parameters could silently overwrite `$PSDefaultParameterValues` and redirect later commands' file access
- Fixed a Windows permission bypass where Git Bash followed Cygwin-style symlinks that path validation saw as regular files; writes through them now require permission approval
- Fixed nested git repositories inheriting trust from a parent directory; each repository now requires its own trust confirmation
- Fixed MCP connections hanging for the full 30-second connect timeout when a server fails to answer or sends a malformed reply to the protocol-version probe
- Fixed Remote Control sessions hosted by a bridge inside a cloud session inheriting that session's transcript or credentials
- Fixed Remote Control sessions started from Claude Desktop or an IDE appearing as a new claude.ai session each time the local session was resumed; they now reattach to the existing one
- Fixed Remote Control sessions appearing unreachable to newly attached clients while idle
- Fixed Remote Control bridge sessions not restoring conversation history when the session worker restarts
- Remote Control: resuming a conversation whose session was deleted from claude.ai or the app now starts a replacement instead of failing with a message about your login (regressed in v2.1.227)
- Fixed Cloud gateway `/login` exiting silently or leaving an unresponsive terminal after "Press Enter to continue" when managed settings failed to load; the reason is now shown
- Fixed voice mode on native builds getting stuck on "listening…" when the voice service rejected the connection; the rejection is now shown immediately
- Fixed mTLS client certificate rotation requiring a restart; Claude Code now reloads the rotated cert and key automatically on connection errors
- Fixed malformed AWS or Vertex region values being used to build request URLs; they now fall back to the default region
- Fixed stream idle timeout errors failing the request instead of recovering on Bedrock, Vertex, and gateway deployments
- Fixed content-sized overlays containing truncated text rendering one column too wide, and start-truncated text collapsing to an ellipsis
- Fixed a stray garbled character where a long shell-command or agent-description preview was cut off mid-emoji
- Fixed a startup race that could silently unregister a plugin marketplace due to concurrent writes to `known_marketplaces.json`
- Fixed `/update` and `/tui` refusing to restart while work that survives the relaunch was running
- Fixed usage-limit guidance suggesting unavailable slash commands in SDK and remote sessions
- Fixed the consent message for interactive `--advisor fable` launches, which told you to run `/model fable` in an interactive session that had just exited
- Improved fullscreen streaming: long sessions stay responsive because the whole conversation is no longer re-normalized on every update
- Improved the managed settings approval dialog: shows endpoint URLs, uses clearer wording for telemetry-only changes, skips routine OpenTelemetry options, and requires approval for server-managed sandbox binary overrides (`sandbox.bwrapPath`, `sandbox.socatPath`, `sandbox.ripgrep`)
- `/feedback` and `/bug` now open immediately when invoked while Claude is responding, instead of waiting for the turn to finish
- `/plugin install plugin@marketplace` now refreshes the marketplace first, so newly published plugins install without a manual marketplace update
- `/code-review` at high, xhigh, and max effort now runs in a background agent like the other levels
- Pasted and clipboard images are read without blocking the event loop
- Remote Control now keeps reconnecting for about 30 minutes after a network blip and no longer drops after a few blips spread across an hour
- Remote Control: resuming a conversation no longer silently takes Remote Control away from another Claude Code on the same machine that still has it; run `/remote-control` there to move it
- Updated agent panel: completed subagents hide immediately with a `/tasks` footer hint, and the "↓ N more" overflow indicator moved left for visibility
- Remote Control: the terminal now says whether a session was taken over by another device, ended from another app, or deleted, and stops suggesting a reconnect that would undo it
- Bash input redirections (`< file`) are now permission-checked like their argument spellings on all platforms
- Shortened the message shown when resuming a completed background agent
- Cowork sessions no longer inline external @​-imports from user-scope memory files
- Hardened the auto-generated cross-session messaging socket directory on shared `/tmp`: a pre-planted symlink or another user's directory is now refused instead of used
- Hardened the Linux filesystem sandbox against a protected-path bypass
- Changed `sandbox.ripgrep` to be honored only from user, managed, and `--settings` settings; project settings can no longer override the sandbox's ripgrep binary
- Removed the startup tip suggesting you create custom subagents, and the matching nudge in the `/powerup` tour
### [`v2.1.228`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21228)
- Fixed interactive sessions that could stop redrawing entirely, while the process kept running, after a rare internal layout error
- Fixed `git` / Git Bash not being found on Windows when Claude Code is launched from a parent folder of the git installation
- Fixed `/tui` reverting the session to an earlier model when `/model` had been changed since the last response
- Fixed cross-session messaging sometimes starting without an inbox in the first session after install or upgrade
- Fixed Remote Control `/resume` while connected leaking the resumed conversation's title or history into the connected session
- Fixed `claude self-hosted-runner` sessions failing on every fresh runner when the `checkout` hook fails for a repository the session doesn't push to; that repository is now skipped with a warning
- Fixed self-hosted runners ending sessions in the gap between a background task finishing and the follow-up turn starting
- Fixed session cleanup deleting contents inside a project's memory folder
- Fixed background plugin-cache cleanup deleting a plugin's cache when its only version is a symlinked development checkout
- Fixed a settings-merge issue where a marketplace entry redefined in a higher-precedence settings tier could inherit another tier's custom headers; marketplace entries now merge as whole entries
- Fixed the deferred-tools reminder occasionally being sent to the model twice after a skill invocation
- Hardened skills synced from claude.ai: they no longer shadow local commands or MCP prompts, their descriptions are sanitized and labeled, and on your machine their bodies don't run `!` commands or expand `@` files
- Improved cross-session messages: the sender and body now display inline instead of a collapsed line, and messages to Remote Control sessions on other machines show your Remote Control session name as the sender
- Improved Vertex AI credential handling: expired or missing Google Cloud credentials now fail within seconds instead of retrying for minutes
- Improved compaction progress: the retry countdown and stall hint now appear during compaction instead of only a progress bar
- Updated terminal title busy-spinner glyphs to reduce tab-bar jitter on some terminals
- Changed the Write tool so newer models can overwrite an existing file they haven't read this session, matching the Edit tool's rules; older models still require the read first
- Removed the outdated note about auto mode sessions costing slightly more from the first-use notice for Pro, Max, and Team plans
### [`v2.1.227`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21227)
- Fixed feature flags being evaluated without the user's subscription tier when a session started with an expired login token, which could wrongly prompt Max plan users to enable usage credits for Fable
- Fixed every Bash command failing under `claude-code-action` with `allowed_non_write_users` on GitHub-hosted runners
- Fixed `/tui` bringing back a conversation that had been rewound to before its first message
- Improved slash-command menu: blue now marks only the selected row, matched characters are bolded instead of recolored, and emoji or accented names keep their glyphs
- Improved performance: fewer event-loop stalls on file-not-found suggestions and at-mention size checks
### [`v2.1.226`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21226)
- Bug fixes and reliability improvements
### [`v2.1.224`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21224)
- Added self-hosted environments: `claude self-hosted-runner` turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans
- Added `archive` plugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning
- Added a cancel-and-confirm step when removing an unavailable paste changes a command's text
- Added `ANTHROPIC_BEDROCK_REGION_PREFIX` env var for Bedrock to prefer a specific cross-region inference profile over the `AWS_REGION`-derived one
- Added `crossSessionInbound` and `dialogExpiry` settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver
- Added sandbox credential-masking options: `extract` and `onExtractNoMatch` for structured env values, `decode: "jwt"` with `maskClaims` for JWT-aware masking, and `awsPairs`/`sigv4` for AWS SigV4 re-signing; these need `network.tlsTerminate` and are honored only from user, managed, or `--settings` settings
- Added cross-session `SendMessage`: Claude Code sessions can now message each other, on any of your machines, with `ListAgents` to discover them (macOS and Linux)
- Fixed long (>200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list, rename, fork, delete and `/resume` no longer cross projects
- Fixed `SendMessage` reporting "Message sent" when the write to a teammate's inbox had actually failed; failed deliveries are now reported as errors
- Fixed sandbox filesystem deny entries written with a trailing slash (e.g. `denyRead: "~/.aws/"`) being silently bypassable on Linux and macOS
- Fixed sandbox violation details never appearing in Bash tool results; Claude now sees which file or network access was denied and why
- Fixed MCP tools that connect mid-turn being deferred for tool search without their names announced to the model
- Fixed plugin install records being silently corrupted when the same plugin is installed in multiple projects
- Fixed recalled or restored paste content occasionally attaching wrong data or silently losing text when the paste had aged out or placeholder numbers collided
- Fixed copy-on-select on Wayland sometimes not reaching the clipboard; the two selection writes no longer race
- Fixed the feedback survey's transcript share silently failing on long sessions; a failed share now shows an error instead of a success message
- Fixed Remote Control auto-start intermittently failing with "Remote credentials fetch failed" on a cold start with a stale login token
- Fixed Remote Control and SDK clients showing a blank "(no content)" message after `/clear` and other output-less commands
- Fixed a Remote Control session recreated after its server session expired uploading prior local conversation history into the new session
- Improved fullscreen mode to keep the full pre-compaction history in scrollback across repeated compactions, instead of only the most recent interval
- Improved Remote Control: attached web and mobile clients now see compaction progress and the post-compaction boundary instead of a silent pause; `/clear` resets now propagate to attached clients
- Improved Remote Control: connection failures now show a persistent failure indicator with details and a reconnect shortcut, instead of only an 8-second toast
- Removed the 200-subagent-per-session spawn cap; long-running sessions no longer refuse new agents (concurrency and depth limits still apply)
- Changed managed settings: the approval prompt no longer re-appears after re-login or org switching when the organization's settings are unchanged
- Changed the feedback-survey transcript share: with your consent it now also uploads the last request's model settings — the system prompt (which includes your `CLAUDE.md` instructions), tool definitions, and model parameters. Secrets are redacted as before, and these fields are dropped first if the share is too large
- Changed the Bash tool description to always note that command output is displayed to the model, not reliably to the user
- Changed recalled paste placeholder numbers to renumber when accepted into the input
- Changed Remote Control to archive the stale server session instead of leaving a dead one listed when a fresh session is minted after compaction or `/resume`
- \[VSCode] Fixed the extension showing Remote Control as connected after the connection failed
- Fixed a session resume silently reconnecting Remote Control after the user turned it off (`--resume`, SDK hosts, and the VS Code extension)
- \[VSCode] Fixed sessions not honoring `remoteControlAtStartup` when explicitly enabled
### [`v2.1.223`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21223)
- Added owner wildcard entries (`"owner/*"`) to the `strictKnownMarketplaces` and `blockedMarketplaces` managed settings for allowing or blocking all marketplace repos under a GitHub org
- Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead
- Added a `/teleport` hint in cloud sessions showing how to continue locally with `claude --teleport <session id>`
- Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks
- Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog
- Fixed workflow scripts being able to use dynamic `import()` to run code outside the workflow sandbox
- Fixed a permission gap where an agent definition's `bypassPermissions` mode ignored the org bypass-permissions disable policy
- Fixed resuming a session after a mid-session `/cd` coming back empty
- Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as `vertex_ai/claude-*` or `bedrock/anthropic.claude-*`
- Fixed `modelOverrides` keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented
- Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local `managed-settings.json` or MDM profile; admin env now merges per key
- Fixed sandboxed commands failing to start on Linux when `sandbox.filesystem.denyWrite` covers the working directory
- Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume
- Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment
- Fixed a rare hang when parsing unusual `git push` output
- Changed `CLAUDE_CODE_DISABLE_1M_CONTEXT` to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K
- Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set `CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1` to restore the previous behavior
- Changed `/review` to be an alias of `/code-review`, which reviews the current diff or a PR (`/code-review <level> <pr#>`); use `/code-review ultra` for a deep cloud review
- Changed `/code-review` with no effort level to reuse the level you typed last; type a level like `/code-review high` to change it
### [`v2.1.222`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21222)
- Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type
- Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames)
- Fixed `/usage-credits` on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one
- Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message
- Fixed "Connection closed mid-response" errors being reported on responses that had actually completed
- Fixed `/usage` overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it
- Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API
- Fixed org-restricted `model: opus`-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family
- Fixed stream idle timeout firing on custom `ANTHROPIC_BASE_URL` gateways despite server keep-alive pings arriving on the wire
- Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a `/login` hint instead
- Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed
- Fixed `SendMessage` rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit
- Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own `effort:` setting
- Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown
- Fixed screen readers re-reading the whole input line on every backspace in `--ax-screen-reader` mode — end-of-line deletions now echo just the deleted characters
- Fixed host model-selection keys not taking precedence over a stale on-disk `managed-settings.json` when `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` is set
- Improved auto mode safety: messages sent to other agent sessions via `SendMessage` are now evaluated by the permission classifier before dispatch
- Improved the refusal when Claude tries to invoke a skill with `disable-model-invocation`: Claude is now told to ask you to run the skill instead of replicating its workflow
- Improved the `/diff` view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv
- Changed Remote Control auto-start so repo-local settings (`.claude/settings.json` or `.claude/settings.local.json`) can no longer turn it on (they can still turn it off); enable it at user scope via `/config`
- Removed ultraplan feature
### [`v2.1.221`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21221)
- \[VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with `Ctrl+Alt+F` or the "Claude Code: Toggle Focus view" command
- Added `mode: "mask"` for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an `extract` regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to `deny`
- Added warnings to `claude plugin validate` when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync
- Added a `prompt-audit` subcommand to the `claude-api` skill for auditing prompts and tool descriptions for patterns written for older models
- Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in `[[ ]]` regex conditionals; affected commands now prompt for permission
- Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval
- Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts
- Fixed MCP servers from `--mcp-config` not being connected before the first turn in print mode (`-p`), which made the model emit tool calls as literal text
- Fixed @​-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it
- Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as `constructor`
- Fixed WebSearch failing with a 400 error at effort `xhigh`/`max` when thinking is disabled
- Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy
- Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit
- Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray `HOME` environment variable
- Fixed `CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0` not disabling interrupted-turn auto-resume; falsy values are now honored
- Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication
- Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized
- Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. `/help`, `/feedback`) being un-invocable in non-interactive sessions
- Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing
- Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied
- Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view
- Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models
- Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result
- Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions
- Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write
- Improved `/ultrareview` error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest `git fetch --unshallow` on clones that are already complete
- Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate `powershell.exe` no longer prompt
- Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives
- Changed `/plugin install` to refresh a stale marketplace catalog and retry before reporting a plugin not found
- Changed plugins installed from `/plugin` to activate immediately when safe, instead of always requiring `/reload-plugins`
- Changed plugins to accept `"."` as a `skills` path, and the root-level `SKILL.md` validation error now suggests using the plugin root
- Changed `/status` to show the session kind: `interactive`, or a background job that is `attached` or `unattended`
- Changed emoji autocomplete to accept common alternate shortcodes like `:thumbsup:`, `:thumbsdown:`, and `:love:`
- Changed sessions forked with `/fork` to create a new worktree of their own instead of working in the original session's checkout
- Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them
- Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently
- Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"
- Changed the Gateway `model` field validation: non-string values are rejected with a 400 instead of being forwarded
- Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts
### [`v2.1.220`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21220)
- Bug fixes and reliability improvements
### [`v2.1.219`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21219)
- Added Claude Opus 5 (`claude-opus-5`), now the default Opus model — 1M context, fast mode at $10/$50 per Mtok
- Added `sandbox.network.strictAllowlist` setting to deny non-allowlisted hosts for sandboxed commands without prompting
- Added `DirectoryAdded` hook that fires after `/add-dir` or the SDK `register_repo_root` control request registers a new working directory mid-session
- Added `mcp_server_errors` to the headless stream-json init event, listing `--mcp-config` entries skipped by config validation; terminal runs print a startup warning
- Added the `workflowSizeGuideline` settings key so the advisory Dynamic workflow size guideline can be set from any settings file; the `/config` row is hidden while one does
- Added nested subagent forwarding in stream-json: subagents spawned at depth-2+ now appear when `--forward-subagent-text` is set, keyed by their spawning Agent `tool_use` id
- Fixed `claude -p` text output dropping the answer already produced when a turn dies on a mid-stream API error
- Added HTTP status and error text to `claude mcp list` and `/mcp` when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace
- Fixed the Fable model row showing "Requires usage credits" for plans that include it, when a stale cache had baked the label in
- Fixed the `/model` picker showing the merged Opus row as plain "Opus" instead of "Opus (1M context)"
- Fixed copy-on-select inside GNU screen printing base64 into the terminal instead of copying the selection
- Fixed Remote Control clients keeping a stale fast-mode status after a model switch, reconnect, or failed org check
- Fixed `CLAUDE_CODE_GIT_BASH_PATH` on Windows exiting or being used as bash when the path isn't a bash/sh binary; it's now ignored with a warning
- Fixed Vim mode: pressing ← on an empty prompt now returns to the agent view from NORMAL mode, not just INSERT
- Fixed screen-reader mode rewriting the entire input line on every keystroke instead of echoing only the typed character
- Improved the "Remote Control is only available via api.anthropic.com" error to name the specific setting that caused it
- Improved `claude --teleport` to show which repo your current checkout points at when it doesn't match the session's repo
- Changed dynamic workflows to default to a medium size guideline (aim for fewer than 15 agents); pick another size or unrestricted with Dynamic workflow size in `/config`
- Changed managed MCP allowlist/denylist `${VAR}` entries to resolve from the startup environment and managed-settings env instead of settings-file env
- Changed the `/model` picker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list
- Added the current default workflow size to the running-workflow status line, with a pointer to `/config` for changing it
- Removed Opus 4.7 from fast mode; `/fast` now applies to Opus 5 and Opus 4.8
- Updated the claude-api skill to default to Claude Opus 5, with a migration path from Opus 4.8
- Subagents can now spawn nested subagents up to depth 3 by default (was 1); set CLAUDE\_CODE\_MAX\_SUBAGENT\_SPAWN\_DEPTH=1 to disable nesting
### [`v2.1.218`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21218)
- Changed `/code-review` to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target
- Added screen-reader announcements of deleted text for word and line deletions (`Option+Delete`, `Ctrl+W`, `Cmd+Backspace`, `Ctrl+U`, `Ctrl+K`) in `--ax-screen-reader` mode
- Fixed Windows paths with `\u`-prefixed segments (like `C:\Users\unicorn`) being corrupted into CJK characters in tool inputs, which made those files inaccessible
- Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded
- Fixed multi-line paste collapsing into one line with `j` in place of newlines in terminals that encode pasted newlines as Ctrl+J
- Fixed `/context` reporting stale pre-compact token usage after compacting from the message picker
- Fixed `/ultrareview` failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings
- Fixed `/code-review ultra` silently running a local review in non-interactive sessions — it now launches the cloud review
- Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates
- Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped
- Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected
- Fixed spurious "\[Request interrupted by user]" messages after interrupted tool calls, and an unpaired `tool_use` block left in the transcript when a tool aborted mid-response
- Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in `--ax-screen-reader` mode
- Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation
- Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees
- Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR
- Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks
- Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock
- Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai
- Fixed prompt history entries being dropped or duplicated when history writes raced or failed
- Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; `Ctrl+B` backgrounding now applies the same background-shell caps as other paths
- Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust
- Fixed fork-session lineage being lost after compaction in headless and SDK sessions
- Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment
- Improved `/ultrareview` error feedback so Claude can correct an invalid argument instead of retrying it unchanged
- Improved auto mode: the dangerous-rm, background-`&`, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead
- Improved sandbox command restrictions for IDE interactions
- Improved trust dialogs to name the repository root the grant covers
- Changed `/deep-research` to start only when invoked manually; Claude no longer launches it on its own
- Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead
- Added an announcement when fast mode changes as a result of switching models via `/config model=<x>` or Remote Control
- Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt
- Changed agent markdown files to reject agent names containing `:`, which is reserved for plugin namespacing
- Changed skills with `context: fork` to run in the background by default; opt out per skill with `background: false`
- Added `yes`/`no`/`on`/`off`/`1`/`0` (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside `true`/`false`
- Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever
### [`v2.1.217`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21217)
- Added emoji shortcode autocomplete in the prompt input: type `:heart:` to insert ❤️, or `:hea` for suggestions — disable with the `emojiCompletionEnabled` setting
- Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently
- Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session
- Fixed Windows auto-update failures that could leave `claude.exe` missing; failed updates now restore the preserved executable automatically
- Fixed background session isolation not canonicalizing symlinked working directories, which could let sessions escape their workspace folder
- Fixed auto-compact never triggering for Claude Opus 4.8 on Bedrock and `/compact` failing once over the limit
- Fixed corporate mTLS, TLS-verify, OAuth scope, and proxy settings being ignored in Claude Desktop sessions
- Fixed screen reader mode's startup announcement being cut off by the first prompt render, and the thinking status row re-rendering every few seconds to update elapsed time and token counts
- Fixed managed settings that set `OTEL_EXPORTER_OTLP_ENDPOINT` not governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint
- Fixed `--resume`/`--continue` and `/resume` failing with a TypeError when a transcript has a malformed attachment entry
- Fixed Remote Control sessions not showing a pending permission prompt or dialog to viewers that connected after it appeared
- Fixed background shells sometimes becoming impossible to stop after a session is sent to the background (`/background` or `←`) or when the session exits on a heavily loaded machine, most visible on Windows
- Fixed a `CLAUDE.md` or `SKILL.md` paths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-bounded
- Fixed the transcript preview sitting flush against the input area when attaching to a starting background session; it now leaves the same one-line gap as the live layout, so the transcript no longer shifts when the session takes over
- Improved footer PR badge links to be clickable hyperlinks even when terminal support can't be detected (e.g. over ssh/tmux); set `FORCE_HYPERLINK=0` to opt out
- Changed the login-expiry warning to appear 3 days before expiry instead of 5
- Capped the frontend-design plugin suggestion tip at 3 lifetime impressions instead of repeating indefinitely
- Added a cap on concurrently-running subagents (default 20, override with `CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS`) so one message can't fan out unbounded background agents
- Changed subagents to no longer spawn nested subagents by default; set `CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH` to allow deeper nesting
- Fixed `--max-budget-usd` not stopping background subagents: once the cap is reached, new spawns are denied and running background agents are halted
### [`v2.1.214`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21214)
- Fixed single-segment `dir/**` allow rules like `Edit(src/**)` auto-approving writes to nested `dir/` directories anywhere in the tree instead of only `<cwd>/dir`
- Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
- Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer
- Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically
- Fixed Bash permission checks treating zsh variable subscripts and modifiers in `[[ ]]` comparisons as inert text — these commands now prompt for approval
- Fixed Bash permission checks to no longer auto-approve certain `help` and `man` commands that could run unsafe options, command substitutions, or backslash paths
- Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog
- Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see <https://www.anthropic.com/research/end-subset-conversations>
- Added a periodic progress heartbeat for long-running tool calls that previously went silent
- Added an ISO `modified` timestamp to memory file frontmatter
- Added `message.uuid`, `client_request_id`, and `tool_source` attributes to OpenTelemetry log events for message-level correlation and tool provenance
- Added `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH` to configure the 60 KB truncation limit on OpenTelemetry content attributes
- Added reasoning effort to the `subagentStatusLine` payload, so custom agent rows can render model and effort
- Added permission prompts for `docker` commands (including the Podman `docker` shim) carrying daemon-redirect flags (`--url`, `--connection`, `--identity`, and Podman's remote mode) that previously ran without one
- Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags
- Fixed Bash tool killing the Claude session when a `pkill -f` pattern accidentally matched the CLI's own process (Linux)
- Fixed unbounded memory growth when `--settings` points at a device file or multi-GB file; oversized (>2 MiB) settings files now fail at startup with a clear error
- Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows
- Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap
- Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task
- Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)
- Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)
- Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)
- Fixed the PowerShell tool reporting `where.exe`, `fc.exe`, and `diff.exe` as errors when they return a valid negative answer (Windows)
- Fixed `>` and `>>` under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8
- Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon
- Fixed background sessions parked with `←` or `/background` and left idle keeping the background daemon and a worker process alive indefinitely
- Fixed completed background sessions being impossible to remove via `claude rm` or the agent view once the background service had gone idle
- Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view
- Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store
- Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled
- Fixed `/install-github-app` and the `/mcp` settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached
- Fixed plugins enabled via the `--settings` CLI flag not loading (regression since v2.1.181)
- Fixed feature flags going stale in long-running sessions after the OAuth token rotates
- Fixed `/ultrareview` refusing to run in repos with no merge base — it now offers to review all tracked files
- Fixed `claude update` and `claude doctor` hanging silently, and the `/status` System diagnostics section going blank, when a shell-config path is a directory
- Fixed memory frontmatter values being silently truncated at an inline `#` when memory files are saved
- Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative `message_delta` frames
- Fixed a spurious "check your network" warning that appeared while the advisor was thinking
- Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation
- Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context
- Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources
- Improved the `claude rc` workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory
- Changed single-segment `dir/**` hook `if:` conditions to match only `<cwd>/dir`; write `**/dir/**` for any-depth matching. `deny`/`ask` permission rules keep their any-depth match.
- Changed `file` commands using `-m`/`--magic-file` or `-f`/`--files-from` to require permission instead of being auto-allowed as read-only
- Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket
- Changed SessionStart hooks to report source `"fork"` when a session begins as a fork instead of `"resume"`
### [`v2.1.212`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21212)
- `/fork` now copies your conversation into a new background session (its own row in `claude agents`) while you keep working; the in-session subagent it used to launch is now `/subtask`
- Added `claude auto-mode reset` to restore the default auto-mode configuration, with a confirmation prompt (pass `--yes` to skip)
- Added a session-wide limit on WebSearch tool calls (default 200, tunable via `CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION`) to stop runaway search loops
- Added a per-session cap on subagent spawns (default 200, override with `CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION`) to stop runaway delegation loops; `/clear` resets the budget
- MCP tool calls running longer than 2 minutes now move to the background automatically so the session stays usable; configure the threshold or disable with `CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS`
- Typing `/resume` in the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background session
- Fixed plan mode auto-running file-modifying Bash commands (e.g. `touch`, `rm`) without a permission prompt or SDK `canUseTool` callback
- Fixed worktree creation following a repository-committed symlink at `.claude/worktrees`, which could create files outside the repository
- Fixed a `continue:false` hook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections
- Fixed SIGTERM during a running Bash tool orphaning the command's process tree in print/SDK mode; the CLI now aborts the turn, kills the tree, and exits 143
- Fixed `/background` and `claude --bg` failing with "EUNKNOWN: unknown error, uv\_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7
- Fixed shell mode (`!`) not executing commands containing file paths while the path autocomplete popup was open
- Fixed auto-mode denial notifications rendering broken characters when a long denial reason was truncated mid-emoji
- Fixed Ctrl+J not inserting a newline in the agent view dispatch input on terminals with extended key reporting, and surfaced the newline shortcut in the `?` help overlay
- Fixed `/ultrareview` rejecting PR references like `#123`, `PR 123`, and pasted PR URLs; error hints now name the command you actually typed
- Fixed `/ultrareview <branch>` not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos
- Fixed `/ultrareview` skipping the billing confirmation in a new conversation after `/clear`
- Fixed `/ultrareview`'s "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commands
- Fixed hosted (host-managed) sessions failing at startup when repository settings configured mTLS certs, extra CA bundles, or OAuth scopes; these transport settings are now ignored with a warning
- Fixed a spurious "File has not been read yet" error when editing a file that had been read with offset/limit before resuming a session
- Fixed `ExitWorktree` failing with "no active EnterWorktree session" after resuming a session with `--continue`/`--resume` in print/SDK mode
- Fixed the workflow agent grid staying empty for Remote Control clients that join a session mid-run
- Fixed streaming-mode control requests being marked complete before their handler finished, which could lose the request on session restart
- Fixed background sessions created with `/fork` losing their live-parent protection after a state write failure
- Fixed reopening a stopped background session from the agent view failing silently — it now resumes the session, or shows why it can't and lets you force a restart
- Fixed agent teams: a stopping teammate could send the leader duplicate idle notifications when team initialization re-ran within a session
- Fixed the plan-approval dialog footer splitting "ctrl+g to edit in <editor>" apart when the file path is long
- Fixed the welcome banner keeping its old panel widths after a combined width+height terminal resize in fullscreen mode
- Fixed diff previews losing their line numbers and +/- markers in narrow layouts
- Fixed @​-mentions attaching nothing after a partial file read, plugin uninstall targeting the wrong marketplace, and false "Command timed out" on exit code 143
- Fixed OpenTelemetry HTTP exports being rejected with 411/400 by Azure Monitor and other endpoints that don't accept chunked transfer encoding
- Fixed OTLP event log records missing `trace_id`/`span_id` when `TRACEPARENT` is set in SDK/headless mode
- Fixed conversations with many images incorrectly failing with "Request too large" errors, and improved the error message to explain the actual cause
- Fixed web search and web fetch returning "API Error" text as search results or page content when the API was overloaded
- Improved web search and web fetch reliability by retrying 529 errors and rate-limited requests with bounded backoff
- Improved prompt caching: the mid-conversation system block now works behind LLM gateways and custom base URLs (Bedrock, Vertex, 1P)
- Improved background agent attach: cold-attaching now instantly shows the formatted transcript while the session boots, instead of a blank wait
- Reduced token usage in inter-agent messaging: `SendMessage` bodies are no longer duplicated into replayed history and tool results
- Changed `/fork` to name the copy after your prompt when the session has no title, so the row is recognizable in the agent view
- Changed bare `/btw` to reopen the side-question panel on your most recent exchange so you can browse earlier answers
- Changed the `←` footer hint to pulse `N done` for a moment when a background agent finishes while nothing needs your input
- Deprecated the Task tool's `mode` parameter (now ignored); subagents inherit the parent session's permission mode by default
- Changed Enterprise `forceLoginMethod` to be enforced for VS Code extension, SDK, `setup-token`, and `install-github-app` logins, not just the terminal
- Changed session transcripts to record the reasoning effort level on each assistant message
- Changed headless/SDK sessions to apply a `set_model` control request mid-turn; the next model round-trip uses the new model instead of waiting for the next turn
- Changed agent view / `claude agents --json`: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working"
- Updated the auth status panel title from "Cloud authentication" to "Authentication"
- Corrected an earlier release note (2.1.200): tmux through the 3.6 series lacks synchronized output; newer tmux with support is detected automatically
### [`v2.1.211`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21211)
- Added `--forward-subagent-text` flag and `CLAUDE_CODE_FORWARD_SUBAGENT_TEXT` environment variable to include subagent text and thinking in stream-json output
- Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote characters, so tool inputs cannot visually alter the approval message
- Fixed auto mode overriding a PreToolUse hook's `ask` decision for unsandboxed Bash — a hook `ask` now floors the decision at a prompt
- Fixed parallel Claude Code sessions all logging out simultaneously after wake-from-sleep when many sessions share one credential store
- Fixed plugin MCP servers not reconnecting after an idle web session woke, leaving MCP calls failing until the next message
- Fixed Claude Code on Vertex and Bedrock attempting the default Opus model at startup and printing a spurious fallback notice when a model is explicitly configured
- Fixed subagents spawned with an explicit model override reverting to the parent's model when resumed or sent a follow-up message
- Fixed nested `.claude/rules/*.md` files loading even when setting sources exclude project settings
- Fixed file upload validation: filenames ending in a DOS device suffix (`.prn`) or trailing dot are now accepted, and files with multiple hard links are refused
- Fixed file uploads to Claude in Chrome from remote and CLI sessions
- Fixed edits that leave the input as "?" being silently swallowed and toggling the shortcuts panel
- Fixed a startup hang when the Claude in Chrome extension is enabled but Chrome is not running
- Fixed a 300ms delay revealing async content (Settings tabs, Stats, diff views, and other loading states)
- Fixed reopening a just-stopped background session from the agents view starting a blank conversation under the same session id
- Fixed `/loop` hiding the session from `/resume` after a single use
- Fixed screen reader users losing the audible terminal bell after `/terminal-setup` or onboarding terminal setup
- Fixed background jobs on LLM gateway auth (`ANTHROPIC_AUTH_TOKEN` + `ANTHROPIC_BASE_URL`) coming back "Not logged in" after the daemon respawns them
- Fixed `claude agents` jobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing
- Fixed `/clear` not resetting the session cost counter — the statusline's cost now starts at $0 after `/clear`
- Fixed Claude in Chrome setup pages failing to open in the browser on Windows
- Fixed headless print-mode sessions on Windows crashing or silently exiting when stdin is unreadable
- Fixed background session titles in the agents view showing the naming model's refusal text when the prompt contains a link
- Fixed background agents killed by the user auto-respawning, and revived agents re-running stale prompts from old sessions
- Fixed routines with no schedule reporting a next run time in the year 1
- Hardened synced skill/plugin directory naming on Windows and kept CCR web fetch/search proxies working after `/clear`
- Improved terminal layout and rendering performance
- Improved background agent result reporting — Claude now reports the status of still-running agents and waits for the real completion instead of fabricating results
- Improved the memory index over-limit warning to measure only loaded content, excluding frontmatter and HTML comments
- Updated integer environment variables (timeouts, token budgets, retry counts) to accept scientific notation and digit-separator spellings like `1e6` and `64_000`
- Updated documentation links to the current docs sites
- Changed "always allow" permission rules to save at the repository root, so approvals granted in a git worktree persist across sessions and worktrees
- Changed `/usage-credits` to ask for confirmation before sending a request to organization admins
- Changed Vim mode `s` and `S` (substitute char/line) to work in NORMAL mode, matching vim behavior
- \[VSCode] Updated the Remote Control banner to describe what it does
- Claude in Chrome: hardened file-upload path validation
- Claude in Chrome: `save_to_disk` on screenshot actions now writes the image to disk and returns the path; previously it did nothing
- Fixed a prompt-caching regression on Bedrock, Vertex, Mantle, and Foundry that billed the trailing system context block as fresh input tokens on every request.
### [`v2.1.210`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21210)
- Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck
- Added a startup warning for `Write(path)`, `NotebookEdit(path)`, and `Glob(path)` permission rules — use `Edit(path)` or `Read(path)` instead
- Fixed `isolation: 'worktree'` subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree
- Fixed the `ultracode` keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments
- Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element
- Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text
- Fixed `claude attach` sometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes
- Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element
- Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait
- Fixed Claude assuming a `cd` took effect after its command was moved to the background; the tool result now states the working directory is unchanged
- Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session
- Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot
- Fixed `/doctor` skipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in
- Fixed Grep content mode claiming "No matches found" when paginating past the end of results
- Fixed unmatched `$1`/`$2` positional placeholders in skills and commands being silently stripped; they are now preserved verbatim
- Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems
- Fixed background workers crash-looping when a client resets its connection to the background service
- Fixed `claude agents --effort ultracode` not reaching dispatched sessions; the value was silently dropped
- Fixed pressing ← to open the agents view dropping the task tracker when returning to the session
- Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted
- Fixed killed background sessions leaving a permanent `git worktree lock` behind; the periodic sweep now releases locks whose owning process is gone
- Fixed SDK MCP servers registered via an `initialize` control request waiting until the next turn to start connecting
- Fixed returning to the agents view from a session leaving overlapping ghost frames with `CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1`
- Fixed late-appearing `.claude/*` symlinks not being reconciled into the sandbox deny-write list
- Hardened the Agent tool against indirect prompt injection via content a subagent read
- Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request
- Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session
- Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds
- Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation
- Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab
- The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes
- Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection
- Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed
### [`v2.1.209`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21209)
- Fixed /model and other dialogs being blocked in `claude agents` background sessions (reverts an overly broad guard)
### [`v2.1.207`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21207)
- Auto mode is now available without `CLAUDE_CODE_ENABLE_AUTO_MODE` opt-in on Bedrock, Vertex AI, and Foundry; disable via `disableAutoMode` in settings
- Fixed the terminal freezing and keystrokes lagging while streaming responses containing very long lists, tables, paragraphs, or code blocks
- Fixed remote managed settings from a non-interactive run (`claude -p`, the SDK) being permanently recorded as consented without ever showing the security consent dialog
- Fixed spurious prompt-injection warnings triggered by benign system-generated conversation updates
- Fixed the auto-updater overwriting a custom launcher script or symlink at `~/.local/bin/claude` on every release; `/doctor` now reports an externally managed launcher
- Fixed compound commands with `cd` prompting for permission when the only output redirect was to `/dev/null`
- Fixed the transcript jumping above the start of the answer when a response finishes streaming
- Fixed `extensions.worktreeConfig` being left in the repo's `.git/config` (breaking go-git tools like `tea`) after the last `worktree.sparsePaths` worktree was removed
- Fixed malformed bracket patterns in rules globs, skill paths, `.ignore`, and `.worktreeinclude` breaking file reads, file suggestions, and worktree creation
- Fixed a crash loop in agent teams where a malformed teammate mailbox message caused repeated errors every second until the mailbox file was manually deleted
- Fixed background sessions auto-named by accepting a plan not showing that name on their agent-view row
- Fixed background sessions that entered a git worktree resuming blank after a cold reopen from the agent list
- Fixed Remote Control task status updates being lost when the connection recovered from a network interruption or credential refresh
- Fixed Remote Control sessions hosted by the desktop app not showing background agent and workflow progress on mobile and web
- Fixed Deep research runs labeling every Fetch-phase agent "unknown" — chips now show the source hostname
- Fixed Bedrock repeatedly requesting fresh AWS SSO credentials from IAM Identity Center on every API request
- Improved agent view: pasting the same text again now expands the collapsed `[Pasted text #N]` placeholder instead of adding a second one
- Improved agent view: blocked session peeks now lead with the question and show a worded staleness clock (`waiting 3m`) instead of the same timestamp twice
- Changed Bedrock, Vertex, and Claude Platform on AWS to default to Claude Opus 4.8
- Changed auto mode to no longer read `autoMode` from `.claude/settings.local.json` (repo-resident); use `~/.claude/settings.json` instead
- Fixed an indefinite hang on Windows when AWS credential resolution stalls (e.g. a stuck `credential_process`): the 60-second stall guard now fires instead of waiting forever.
- Plugin hooks/monitors/MCP headersHelper: `${user_config.*}` in shell-form commands is now rejected (shell-injection fix). Hooks: use exec form (`args` array) or `$CLAUDE_PLUGIN_OPTION_<KEY>`; monitors and headersHelper: read the value inside the script (config file or the server's `env` block).
- Plugin option values (`pluginConfigs`) are no longer read from project-level `.claude/settings.json`; only user, `--settings`, and managed settings are honored
- Fixed `/usage-credits` amount inputs silently stripping malformed values (e.g. a pasted timestamp) to digits; malformed amounts are now rejected with an error, and amounts over $1,000 require a typed confirmation
### [`v2.1.206`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21206)
- Added directory path suggestions to `/cd`, matching `/add-dir` behavior
- Added a `/doctor` check that proposes trimming checked-in `CLAUDE.md` files by cutting content Claude could derive from the codebase
- `/commit-push-pr` now auto-allows `git push` to the repo's configured push remote (`remote.pushDefault`, or the sole remote when only one is configured) in addition to `origin`
- Gateway: `/login` now supports Anthropic-operated public gateway endpoints
- `EnterWorktree` now asks for confirmation before entering a git worktree outside the project's `.claude/worktrees/` directory
- Background agents now upgrade to a new version in the background right after a Claude Code update, instead of paying a slow stale-session upgrade when you attach
- Fixed an expired login failing every model with a misleading "There's an issue with the selected model" error instead of prompting to run `/login`
- Fixed `claude --resume` and `--continue` not responding to keyboard input on startup
- Fixed MCP servers configured via `--mcp-config` or `.mcp.json` ignoring a per-server `request_timeout_ms`, which caused long-running MCP tool calls to time out at the 60s default in fresh sessions
- Fixed `CLAUDE_CODE_EXTRA_BODY` being silently ignored by `claude agents` / `--bg` background workers; the shell-exported override now follows the dispatching session
- Fixed OAuth MCP servers requiring manual re-authentication after a single failed token refresh
- Fixed `--permission-prompt-tool` pointing at an MCP server crashing with "MCP tool not found" on cold start before the server finishes connecting
- Fixed `/model` picker rows printing a price for a different model than the row named, and stopped quoting first-party list prices on providers that don't bill them
- Fixed server-provided model rows being misplaced in the `/model` picker when an entitlement or allowlist restriction drops the row they were positioned against
- Fixed desktop sessions getting stuck showing "running" after a slash command was sent mid-turn
- Fixed keyboard input being ignored in the agents view when a setup prompt appeared before a bare `claude --resume` on Windows
- Fixed `claude rm` leaving the removed job in the daemon roster, causing the row to reappear in `claude agents`
- Fixed `/remote-control` showing "Unknown command" when logged out — it now explains how to sign in
- Fixed left arrow not stepping back out of a phase or agent in the workflow detail view
- Fixed `/status` listing the same broken-install warning twice
- Fixed false "disused plugin" tips and skewed disuse telemetry for LSP plugins
- Fixed `/doctor`'s update check to compare Homebrew installs against their cask's channel instead of the settings channel
- Fixed the fullscreen jump-to-bottom pill suggesting Ctrl+End on macOS, not showing rebound chords, and wrapping over the transcript
- Bedrock: fixed a multi-minute startup hang when using an `awsCredentialExport` helper on networks with restricted egress
- Improved `/code-review` findings quality on claude-opus-4-8 across all effort levels
- Improved agents view: status column now uses full terminal width instead of truncating at 64 characters
- Changed agents view: Ctrl+X now permanently removes a completed session, and sessions no longer render twice; deleted background jobs stay deleted
### [`v2.1.204`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21204)
- Fixed hook events not streaming during SessionStart hooks in headless sessions, which could cause remote workers to be idle-reaped mid-hook
### [`v2.1.202`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21202)
- Added a "Dynamic workflow size" setting in `/config` for controlling how large Claude generally makes dynamic workflows (small/medium/large agent counts) — an advisory guideline, not an enforced cap
- Added `workflow.run_id` and `workflow.name` OpenTelemetry attributes to telemetry emitted by workflow-spawned agents, so a workflow run's activity can be reconstructed from OTel data
- Fixed a crash in the inline Ctrl+R history search when accepting or cancelling while the search was still scanning the history file
- Fixed `/rename` on background sessions being reverted when the job restarts, which broke addressing the session by its new name
- Fixed transient mTLS handshake failures when settings were re-applied during an in-place client certificate rotation
- Fixed commands sent from Remote Control (mobile/web) into an interactive session failing with "Unknown command"
- Fixed images and files sent from the Remote Control mobile or web app without a caption being silently dropped
- Fixed the sign-in URL printed by `claude auth login` and `claude mcp login --no-browser` not being reliably clickable when it wraps over SSH — it is now emitted as a single hyperlink
- Fixed opening a chat from `claude agents` sometimes failing with "currently running as a background agent" followed by a worker crash/respawn loop
- Fixed workflow scripts with unicode quote escapes in strings being corrupted before parsing; workflow parse errors now show the offending line instead of always blaming TypeScript
- Fixed voice dictation retrying in an unbounded loop when the microphone or audio recorder fails — repeated capture failures now pause voice input
- Fixed `/remote-control` sessions showing the wrong permission mode in the mobile and web apps
- Fixed resuming a session by name, or opening the resume picker, taking minutes and using a large amount of memory in repositories with many git worktrees
- Fixed installer and updater downloads failing immediately with "aborted" when a proxy or network drops the connection mid-download — transient connection drops now retry
- Fixed re-invoking an already-loaded skill appending a duplicate copy of its instructions to context
- Improved `/workflows` agent list layout: wider titles, a dedicated time column, shorter model names, and no per-row tool-call counts
- Improved MCP error messages: clearer error when a server config has `url` but no `type`, suggesting `"type": "http"` instead of the misleading "command: expected string"
- Changed `/review <pr>` back to a fast single-pass review; use `/code-review <level> <pr#>` for the multi-agent review at a chosen effort level
### [`v2.1.201`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21201)
- Claude Sonnet 5 sessions no longer use the mid-conversation system role for harness reminders
### [`v2.1.199`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21199)
- Stacked slash-skill invocations like `/skill-a /skill-b do XYZ` now load all leading skills (up to 5), not just the first
- Fixed SSL certificate errors (TLS-inspecting proxies, missing `NODE_EXTRA_CA_CERTS`, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hint
- Fixed streaming responses being discarded when the API emits a mid-stream overloaded/server error after partial output — the partial is now kept with an incomplete-response notice
- Fixed subagents cut off by a rate limit or server error silently failing instead of returning their partial work to the parent
- Fixed subagents reporting API errors (e.g. usage limit reached) as successful results — the error is now reported to the parent agent
- Fixed the background-agent daemon on Linux killing itself and every running agent every \~50 seconds after an unclean shutdown left a corrupted worker record
- Fixed background agents failing to cold-start over SSH on macOS with "Could not switch to audit session" (regression in 2.1.196)
- Fixed `claude stop` being silently undone when it raced a background-agent respawn — the respawn now honors the stop
- Fixed background job progress indicators stalling for minutes while the job ran long commands
- Fixed background sessions on memory-starved machines showing a generic error — they now indicate low memory and suggest freeing resources
- Fixed remote sessions briefly flapping between Working and Idle in the agent view when a background agent completes
- Fixed idle subagents vanishing from the agent panel while other subagents were still working; surplus idle agents now collapse into an expandable summary row
- Fixed typing `/model` or `/fast` while viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the lead
- Fixed `SessionStart`, `Setup`, and `SubagentStart` hooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcript
- Fixed `claude --dangerously-skip-permissions daemon <subcommand>` being treated as a chat prompt instead of running the subcommand
- Fixed `SendMessage` silently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget
- Fixed opening or resuming a session with no new messages needlessly growing the transcript file
- Fixed backgrounding a session with `←` or `/background` dropping its `/color` from the agent view row
- Fixed resetting a corrupted config file from the startup recovery dialog destroying it unrecoverably — it now backs up the file first
- Fixed Claude in Chrome repeatedly opening the reconnect page when sessions run from different builds or config directories
- Fixed plan mode not prompting for state-changing browser tool calls; read-only `browser_batch` calls are now correctly auto-allowed
- Transient server rate-limit errors (429s unrelated to your usage limit) are now retried automatically with backoff for subscribers instead of failing the turn
- `CLAUDE_CODE_RETRY_WATCHDOG` now raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 on `CLAUDE_CODE_MAX_RETRIES`
- `claude agents` session rows now show pull-request links as bare `#N` without the redundant "PR" label
### [`v2.1.198`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21198)
- Subagents now run in the background by default, so Claude keeps working while they run and is notified when they finish (previously a gradual rollout)
- Claude in Chrome is now generally available
- Added background agent notifications in `claude agents` — sessions that need input or finish now fire the `Notification` hook (`agent_needs_input` / `agent_completed`)
- Added `/dataviz` skill for chart and dashboard design guidance with a runnable color-palette validator
- Gateway: added Claude Platform on AWS (anthropicAws) as an upstream provider; model-not-found responses now advance the failover chain
- Background agents launched from `claude agents` now commit, push, and open a draft PR when they finish code work in a worktree, instead of stopping to ask
- The built-in Explore agent now inherits the main session's model (capped at opus) instead of running on haiku
- Subagents and context compaction now inherit the session's extended thinking configuration, improving output quality on delegated tasks
- Fixed brief network drops mid-response aborting the turn — transient errors like ECONNRESET now retry with backoff instead of failing
- Fixed excessive background classifier requests when sandboxed processes repeatedly accessed the same network host
- Fixed background tasks in web, desktop, and VS Code task panels getting stuck on "Running" after they finish or after resuming a session
- Fixed agent teams: a teammate that dies on an API error now reports "failed" to the lead, and messaging a stuck teammate wakes it to retry immediately
- Fixed the `/diff` panel not refreshing when you switch branches or commit outside the session
- Fixed markdown tables overflowing and wrapping their right border when rendered in fullscreen mode
- Fixed Claude Platform on AWS and Mantle sessions dead-ending with "Please run /login" when the STS token expires — `awsAuthRefresh` now runs automatically
- Fixed "no route to host" for local-network hosts in macOS background agent sessions by declaring Local Network entitlements
- Fixed `/desktop` failing with "Cannot determine working directory" after entering and exiting a worktree
- Fixed background agents repeatedly showing "Reconnecting…" every \~52 seconds on macOS while the agents view was open
- Fixed pressing `←` inside `claude attach <id>` exiting to the shell instead of opening the agent view
- Fixed `claude --bg` silently creating an unattachable session when combined with `--print`/`-p`; the conflicting flags are now rejected up front
- Fixed the workflow progress view dropping the earliest agents from the list while the phase counter stayed correct in SDK and desktop-app sessions
- Fixed `.claude/rules/` conditional rules not loading when the target file is reached via a symlinked path
- Fixed Cmd+click not opening URLs in fullscreen mode in Warp on macOS
- Fixed double-click word selection in fullscreen mode to select the entire URL including the scheme
- Fixed plan mode not auto-allowing read-only tool calls when a session starts in plan mode
- Fixed `/branch` deriving its default fork name from the compaction summary instead of the first real prompt
- Improved focus mode: subagents launched in a turn now appear in its activity summary, and completed background notifications fold into a single count
- Improved syntax highlighting accuracy in code blocks, diffs, and file previews by upgrading to highlight.js 11
- Keyboard shortcut hints now show opt/cmd instead of alt/super when connected from a Mac over SSH
- Improved API retry UX: the error reason is now shown after the second attempt, and a status page link replaces the spinner tip when the API is overloaded
- `/login` now opens the sign-in dialog from the `claude agents` view instead of saying it isn't available
- Subagents now treat messages from the agent that launched them as normal task direction; an agent's message is still never treated as the user's approval
- Removed the `/agents` wizard; ask Claude to create or manage subagents, or edit `.claude/agents/` directly
### [`v2.1.197`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21197)
- Introducing Claude Sonnet 5: now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2/$10 per Mtok through August 31. Update to version 2.1.197 for access. <https://www.anthropic.com/news/claude-sonnet-5>
### [`v2.1.196`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21196)
- Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in `/model` when you haven't picked one yourself
- Added readable default names for sessions at start, making them easier to identify and message
- Added clickable file attachments in chat — Cmd/Ctrl-click reveals the file in Finder/Explorer
- Security: `claude mcp list`/`get` no longer spawn `.mcp.json` servers that a repo self-approved via a committed `.claude/settings.json`; untrusted workspaces show `⏸ Pending approval`
- Fixed waking a background job permanently deleting its conversation and re-running the original prompt when the transcript probe misread a real transcript; the file is now set aside, never deleted
- Fixed the rate-limit warning flickering off and rate-limit telemetry being over-counted when multiple parallel requests were in flight at the moment a usage limit was hit
- Fixed duplicate recap lines after a background session's turn: a schema-rejected StructuredOutput attempt no longer renders alongside its retry
- Fixed PowerShell `git diff`/`git grep`, `egrep`/`fgrep`, and quoted search patterns containing `|` being reported as failures when they exit 1, matching Bash behavior
- Fixed multiple `claude agents` side panel issues: keyboard focus getting stuck when opening an agent, background jobs losing their subagent types on every open, and sessions showing incorrect status while actively running
- Fixed `claude agents --dangerously-skip-permissions` silently falling back to auto mode instead of showing the bypass disclaimer and applying bypass mode to spawned agents
- Fixed mid-turn crash recovery for Remote sessions — sessions interrupted by a server restart now auto-resume on the next worker
- Fixed sessions moved with `/cd` reappearing in the old directory's resume list after a non-graceful exit when the old path contained special characters
- Fixed `claude plugin validate` skipping local plugins whose source is "." and stopping after the first error class
- Fixed Esc Esc at an idle prompt not opening the rewind menu (regression); use Ctrl+C or Ctrl+X Ctrl+K to stop background agents
- Fixed MCP OAuth requesting the authorization server's full `scopes_supported` catalog when no scope is specified, causing `invalid_scope` failures on GitLab self-hosted and other enterprise IdPs
- Fixed `/context` showing 0 tokens for all tool groups on Bedrock
- Fixed `/deep-research` misreporting verifier failures as "all claims refuted" instead of `unverified`
- Fixed plugin dependency version pins not being honored when the marketplace was added as a local folder path backed by a git repo
- Fixed `claude agents` session status: completed rows no longer flip between "Done" and "Needs your input", stalled agents are now labeled "Needs attention", and results that mention a PR show a clickable link
- Fixed voice dictation swallowing spaces and spuriously starting a recording during very fast typing when voice mode is enabled
- Improved background session reliability: long-running commands and workflows now survive the session's process being stopped, restarted, or updated — including on Windows, where background shells are handed off instead of being killed
- Improved background agents: workers killed by a daemon restart are now automatically resumed from where they left off the next time the agents view opens
- Improved `/code-review` workflow: merged five cleanup finders into one, cutting token usage by roughly 25%
- Reduced per-frame rendering work in the terminal UI by skipping no-op subtree walks during streaming
- The streaming idle watchdog is now on by default for all providers — it aborts and retries when a response stream produces no events for 5 minutes. Set `CLAUDE_ENABLE_STREAM_WATCHDOG=0` to disable.
- Remote Control is now disabled when `ANTHROPIC_BASE_URL` points at a non-Anthropic host, matching the existing behavior under `CLAUDE_CODE_USE_BEDROCK`/`_VERTEX`/`_FOUNDRY`
- Changed opening the agents view from a foreground session to require a single `←` press instead of two, matching the behavior in background sessions
### [`v2.1.195`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21195)
- Added `CLAUDE_CODE_DISABLE_MOUSE_CLICKS` to disable mouse click/drag/hover in fullscreen mode while keeping wheel scroll
- Fixed hook matchers with hyphenated identifiers (e.g. `code-reviewer`, `mcp__brave-search`) accidentally substring-matching — they now exact-match. Use `mcp__brave-search__.*` to match all tools from a hyphenated MCP server.
- Fixed voice dictation on macOS capturing silence in long-running sessions after the default input device changes
- Fixed voice dictation auto-submit never firing for languages written without spaces (Japanese, Chinese, Thai)
- Fixed external plugins enabled only by project `.claude/settings.json` not requiring explicit install consent on every loader path
- Fixed `/plugin` Enable/Disable not working when a plugin's `plugin.json` `name` differs from its marketplace entry name
- Fixed background jobs disappearing from `claude agents` or losing data when written by a newer Claude Code version
- Fixed reopening a crashed background task showing a blank screen for up to 5 seconds instead of its restart
- Fixed background agent daemons running unreachable when the control socket fails to start, blocking restarts
- Improved voice mode on Linux: now distinguishes "no microphone" from "SoX not installed" when SoX is present but no audio capture device exists
- Improved `claude agents` completed list to fill available vertical space; on short terminals the header compacts so live sessions stay visible
- Improved Remote session startup with a provisioning checklist while the container starts
### [`v2.1.193`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21193)
- Added `autoMode.classifyAllShell` setting to route all Bash/PowerShell commands through the auto-mode classifier instead of only arbitrary-code-execution patterns
- Added auto-mode denial reasons to the transcript, the denial toast, and `/permissions` recent denials
- Added `claude_code.assistant_response` OpenTelemetry log event containing the model's response text. Redacted unless `OTEL_LOG_ASSISTANT_RESPONSES=1`; when that var is unset it follows `OTEL_LOG_USER_PROMPTS`, so deployments that already log prompt content will start receiving response content on upgrade — set `OTEL_LOG_ASSISTANT_RESPONSES=0` to keep prompts-only.
- Added live file path autocomplete to bash mode (`!`)
- Added a startup notice when MCP servers need authentication, pointing at `/mcp`
- Added automatic memory-pressure reaping for idle background shell commands (disable with `CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP=1`)
- Fixed `/model` and other client-data-gated UI showing stale/empty state immediately after `/login`
- Fixed backgrounding (←←) spuriously cancelling with "N background tasks would be abandoned" when all running tasks carry over to the new session
- Fixed pinned background agents being re-prompted to "Continue from where you left off" after every auto-update
- Fixed backgrounding the main turn spawning a phantom "general-purpose (resumed)" subagent that re-ran the main conversation
- Fixed agent panel hiding sibling agents when viewing a subagent
- Improved background agents: the launch result no longer instructs Claude to "end your response" — it keeps working on other tasks while the agent runs
- Improved MCP `headersHelper` auth: the helper now re-runs and reconnects automatically when a tool call returns 401/403
- Improved plugin auto-rename: marketplace `renames` maps are now followed automatically, updating your settings to the new name
- Improved `/add-dir` message when the directory is already a working directory
### [`v2.1.185`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21185)
- The stream-stall hint now reads "Waiting for API response · will retry in …" instead of "No response from API · Retrying in …", and triggers after 20s of silence instead of 10s
### [`v2.1.179`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21179)
- Fixed mid-stream connection drops: partial responses are now preserved instead of showing a raw error, and the spinner no longer gets stuck at "running tool"
- Fixed mouse-wheel scrolling in WSL2 under Windows Terminal and VS Code (regression in 2.1.172)
- Fixed a sandbox `denyRead`/`allowRead` glob over a large directory tree making the Bash tool description enormous and the session unusable on Linux
- Fixed the feedback survey capturing a single-digit reply as a session rating immediately after a turn completes
- Fixed the welcome screen stacking multiple promotional banners — at most one promo now shows per session
- Fixed Ctrl+O not showing the subagent's transcript when viewing a subagent
- Fixed clicking the prompt input not returning focus from the subagent/footer panel
- Fixed remote session background tasks appearing stuck as "still running" between turns
- Improved plugin loading performance in remote sessions
### [`v2.1.175`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21175)
- Added `enforceAvailableModels` managed setting — when enabled, the `availableModels` allowlist also constrains the Default model (a Default that would resolve to a disallowed model now falls back to the first allowed model), and user or project settings can no longer widen a managed `availableModels` list
### [`v2.1.172`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21172)
- Sub-agents can now spawn their own sub-agents (up to 5 levels deep)
- Amazon Bedrock now reads the AWS region from `~/.aws` config files when `AWS_REGION` isn't set, matching AWS SDK precedence; `/status` shows where the region came from
- Added a search bar when browsing a marketplace's plugins in `/plugin`
- Added `model` attribute to the `claude_code.lines_of_code.count` OTEL metric
- Fixed sessions using 1M context without usage credits getting permanently stuck — the session now automatically compacts back under the standard context limit
- Fixed a repeating "an image in the conversation could not be processed and was removed" error when the conversation contained multiple images
- Fixed the agents view keeping a session under Working with a busy spinner for up to 30 seconds after the worker replied
- Fixed background agents potentially reading another directory's project settings (`.mcp.json` approvals, trust) when dispatched onto a pre-warmed worker
- Fixed background-session attach failing with EAUTH for sessions started on an older version after the daemon auto-updated
- Fixed a background sub-agent staying stuck as "active" in the agent panel after a nested agent it spawned was stopped
- Fixed `/model` suggestions in the `claude agents` dispatch input rendering with a misleading slash prefix and showing models disabled for your org
- Fixed `availableModels` restrictions not being applied to subagent model overrides, the agent dispatch model picker, and the advisor model
- Fixed `availableModels` allowlists hiding the `/model` picker's Opus and Sonnet 1M rows when entries use version-specific IDs like `claude-opus-4-8`
- Fixed the `/model` picker on Bedrock offering models the provider doesn't serve — selecting one silently switched the session model and lit the selection marker on multiple rows
- Fixed model IDs getting a doubled 1M-context suffix (e.g. `[1M][1m]`) when `ANTHROPIC_DEFAULT_OPUS_MODEL` already includes one
- Fixed `opusplan` model setting not shipping with 1M context in plan mode for entitled users; the `opusplan[1m]` workaround now also correctly switches to Opus in plan mode
- Fixed `WebFetch(domain:*.example.com)` wildcard domain rules never matching subdomains in allow, deny, and ask position, and file permission rules with mid-pattern wildcards (e.g. `Read(secrets-*/config.json)`) being rejected at startup
- Fixed up-arrow prompt history showing the main agent's prompts while a subagent's chat tab is open
- Fixed memory recall not finding mounted team memory stores (`CLAUDE_MEMORY_STORES`) in remote sessions
- Fixed workflow validation rejecting scripts whose prompt strings or comments merely mention `Date.now()`/`Math.random()`
- Disable mouse tracking on Windows consoles that don't fully support it
- Fixed the `/plugin` marketplace list losing its cursor after backing out of a long plugin list, and Esc from the plugin browser returning to the wrong tab
- Improved performance in long conversations by removing redundant message normalization and avoiding full message-history transforms when streaming tool-use state is unchanged
- Reduced idle CPU usage: `/goal` status chip no longer re-renders the terminal at 5 Hz while idle, and fewer UI re-renders while subagents run in parallel
- Improved Claude in Chrome tool loading: browser tools now load in a single batched call instead of one per tool
- Improved the non-interactive Usage Policy refusal message to suggest starting a new session or changing your model
- `/code-review` now keeps the `ultra` option visible when you're not signed in to claude.ai, with an explanation that the cloud review requires a claude.ai account
- Shortened the Remote Control footer indicator to "/rc active" and hid it on narrow terminals
- Stopped promoting `/loop` in remote sessions, where pending loops don't keep the container alive
- \[VSCode] Fixed PowerShell tool calls rendering as raw JSON instead of a proper command display and permission dialog, and stripped ANSI escape codes from displayed shell output
### [`v2.1.161`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21161)
- `OTEL_RESOURCE_ATTRIBUTES` values are now included as labels on metric datapoints, so you can slice usage metrics by custom dimensions like team or repo
- `claude agents` rows now show `done/total` before the detail when work is fanned out; peek shows the longest-running item
- `/mcp` now collapses claude.ai connectors you've never signed in to behind a "Show unused connectors" row
- Parallel tool calls: a failed Bash command no longer cancels other calls in the same batch — each tool returns its own result independently
- Fullscreen mode: clipboard now uses `wl-copy`/`xclip`/`xsel` on Linux when available, copies to both the clipboard and PRIMARY selection for middle-click paste, and the "hold {key} for native selection" hint now shows the correct key per terminal
- Fixed the `/effort` dialog, workflow animations, and prompt keyword shimmer not honoring the "Reduce motion" setting
- Fixed `forceLoginOrgUUID`/`forceLoginMethod` managed-settings policies blocking third-party provider sessions (Bedrock, Vertex, Foundry, Mantle) alongside the org pin (regression in 2.1.146)
- Fixed background subagent output corrupting `claude -p` stdout when using `--output-format text` or `json`
- Fixed `/usage-credits` starting a re-login for Team and Enterprise admins instead of pointing to the organization's usage settings page
- Fixed `/autofix-pr` reporting "cannot run on the default branch" when the session is inside a git worktree or another repository
- Fixed `--resume` picker not showing sessions from the current directory when it isn't a git worktree (e.g., jj workspaces)
- Fixed Windows hooks that invoke bash explicitly (e.g., `/usr/bin/bash script.sh`) failing with "command not found" or "cannot execute binary file"
- Fixed OpenTelemetry log events (`user_prompt`, `api_request`, `tool_result`, `tool_decision`) being silently dropped when emitted before telemetry initialization completed
- Fixed `claude mcp` list/get/add printing secrets to the terminal: `${VAR}` references are no longer expanded, and credential headers and URL secrets are redacted
- Fixed Workflow agents spawned with `isolation: "worktree"` in background sessions being blocked from editing files inside their own worktree
- Fixed background sessions dispatched from `claude agents` booting on a stale model from the daemon's environment instead of the model in `settings.json`
- Fixed a potential crash when rendering Write tool results after resuming a session
- Fixed completed subagents getting stuck showing as running when an error occurs while finalizing their result
- Fixed `EADDRINUSE` errors from tools that bind Unix sockets under `$TMPDIR` when `CLAUDE_CODE_TMPDIR` is set to a deep path
- Improved terminal rendering performance by stabilizing the layout engine's JIT compilation profile
- Improved rendering performance for large file writes
- \[VSCode] Added a tip suggesting disabling terminal GPU acceleration (or running `/terminal-setup`) to fix garbled glyphs
### [`v2.1.158`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21158)
- Auto mode is now available on Bedrock, Vertex, and Foundry for Opus 4.7 and Opus 4.8. Opt in by setting `CLAUDE_CODE_ENABLE_AUTO_MODE=1`
### [`v2.1.154`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21154)
- Opus 4.8 is here! Now defaults to high effort · /effort xhigh for your hardest tasks
- Introducing dynamic workflows: ask Claude to create a workflow and it orchestrates work across tens to hundreds of agents in the background, so you can take on larger, more complex tasks. Run `/workflows` to view your runs
- Fast mode on Opus 4.8 is now available at a fraction of its previous cost: 2x the standard rate for 2.5x the speed
- The lean system prompt is now the default for all models except Haiku, Sonnet, and Opus 4.7 and earlier
- Claude now reserves the multiple-choice question prompt for decisions it genuinely cannot make itself, instead of asking when it already has enough context to proceed
- `/simplify` now runs a cleanup-only review (reuse, simplification, efficiency, altitude) and applies the fixes, instead of running the full `/code-review --fix` bug-hunting review
- Renamed the `/effort` slider labels from "Speed"/"Intelligence" to "Faster"/"Smarter" for clarity
- `claude agents`: type `! <command>` to run a shell command as a background session you can attach to and detach from. Also available as `claude --bg --exec '<command>'`
- `claude agents`: `/logout` now signs you out instead of being sent to a background session
- `←←` to open the agents view now works on Bedrock, Vertex, Foundry, and with telemetry disabled
- Claude in Chrome: pick which connected browser to use via `/chrome` → "Select browser…", or in-chat when a browser action runs with multiple connected
- Plugins can now declare `defaultEnabled: false` in `plugin.json` or a marketplace entry; enable them with `/plugin` or `claude plugin enable`. Dependencies of enabled plugins are still enabled automatically
- The `/plugin` Discover tab now pins plugins whose relevance signals match the current directory with a "suggested for this directory" annotation
- Streaming tool execution is now always enabled, including when telemetry is disabled or on Bedrock/Vertex/Foundry (previously behind a feature flag)
- Stdio MCP server subprocesses now receive `CLAUDE_CODE_SESSION_ID` and `CLAUDECODE=1` in their environment
- `claude mcp list`/`get` now show unapproved `.mcp.json` servers as `⏸ Pending approval` instead of auto-approving and connecting when output is piped
- `/remote-control` autocomplete now shows "Disconnect Remote Control" when Remote Control is already active
- Added Claude Opus 4.8 support and 4.7 → 4.8 migration guidance to the `/claude-api` skill
- Deprecated `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` (will be removed on 06/01). To use fast mode on Opus 4.6, switch with `/model claude-opus-4-6[1m]` and then `/fast on`
- Improved the auto-mode classifier's detection of data exfiltration, particularly bulk transfers of repository contents
- Fixed `rm -rf $HOME` not being blocked as a dangerous path when `HOME` has a trailing slash
- Fixed `$TMPDIR` resolving to different directories in sandboxed vs unsandboxed Bash commands within the same session
- Fixed unreadable highlighted-row text in `claude agents` when the Claude Code theme doesn't match the terminal background
- Fixed background-agent completion notifications triggering premature "out of context" behavior on some 1M-context models
- Fixed background-session classifier losing the user's goal when a scheduled `/command` fires
- Fixed pinned background sessions respawning every minute after a Claude Code update, causing repeated agent-start notifications and process churn at idle
- Fixed background sessions stuck at "blocked", "running", or "working" not retiring after the idle grace period
- Fixed subagents in background sessions bypassing the worktree-isolation guard and writing to the shared checkout
- Fixed orphaned `claude --bg-pty-host` processes spinning at 100% CPU after the daemon exits on macOS
- Fixed number key shortcuts not working for options shown below the divider in option dialogs
- Fixed `worktree.baseRef: "head"` resolving to the main checkout's HEAD instead of the current worktree's HEAD when spawning subagents or calling `EnterWorktree` from inside a linked worktree
- Fixed a stray leading space on wrapped lines when the previous line ended exactly at the terminal width
- Fixed intermittent terminal rendering corruption in VS Code by capping the number of distinct colors the thinking spinner produces
- Fixed plan file names including `[Image #N]` / `[Pasted text #N]` placeholders when a plan-mode prompt starts with pasted images or text
- Fixed a phantom expand/click affordance on colored tool output: short ANSI-colored lines that fit on screen no longer show a "ctrl+o to expand" hint
- Fixed a single invalid `allowedMcpServers`/`deniedMcpServers` entry in managed settings discarding all managed-settings policy; the bad entry is now dropped with a `claude doctor` warning
- Fixed API 400 errors on models that don't support the effort parameter when `CLAUDE_CODE_ALWAYS_ENABLE_EFFORT` is set
- Windows: Fixed update failures caused by `claude.exe` being in use showing a generic error instead of telling you to close other sessions and retry
- Removed the stale "& for background" hint from the shortcuts help panel
- \[VSCode] Auto mode no longer requires the bypass-permissions setting to appear in the mode picker, and a dismissable notice on the new-session screen explains auto mode the first time it's active
- Fixed the task panel below the prompt showing a stray unselectable "main" row when only a workflow is running
- Fixed /mcp tools list and tool detail rendering when MCP servers have long or multi-line tool names or long descriptions
- Fixed the /model picker not showing fast mode pricing on the Default option for API (pay-as-you-go) users when fast mode is on
- Fixed auto mode incorrectly blocking actions with "could not evaluate this action" when the safety classifier ran out of output tokens while reasoning
### [`v2.1.152`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21152)
- `/code-review --fix` now applies review findings to your working tree after the review, surfacing reuse, simplification, and efficiency suggestions; `/simplify` now invokes `/code-review --fix`
- Skills and slash commands can now set `disallowed-tools` in frontmatter to remove tools from the model while the skill is active
- Added `/reload-skills` command to re-scan skill directories without restarting the session
- `SessionStart` hooks can now return `reloadSkills: true` to re-scan skill directories, making skills installed by the hook available in the same session
- `SessionStart` hooks can now set the session title via `hookSpecificOutput.sessionTitle` on startup and resume
- Added a `MessageDisplay` hook event that lets hooks transform or hide assistant message text as it is displayed
- Added `pluginSuggestionMarketplaces` managed setting: admins can allowlist org marketplaces whose plugins may be suggested via context-aware tips
- `claude plugin marketplace remove` now accepts `--scope user|project|local` for symmetry with `marketplace add`, `install`, and `uninstall`
- Claude Code now switches to your configured `--fallback-model` for the rest of the session when the primary model is not found, instead of failing every request
- Auto mode no longer requires opt-in consent
- Vim mode: `/` in NORMAL mode now opens reverse history search (like Ctrl+R), matching bash/zsh vi-mode
- The `/usage` breakdown now includes large session files; files are scanned with a streaming read so memory usage stays flat
- Thinking summaries in the collapsed group now stay readable for at least 3 seconds, render as markdown, and cap at 10 lines (`Ctrl+O` shows the full thinking)
- In fullscreen mode, the "Thinking for Ns" indicator now counts up live while the model is thinking, and keeps its value if you interrupt mid-thought
- Simplified the Workflow tool's inline progress display — live agent counts now show only in the persistent workflow status row below the prompt
- The post-response timer now shows "Waiting for N background agents/workflows to finish" when backgrounded agents or workflows are still running, and reports the cumulative time once their results are processed
- Added the session entrypoint as an OpenTelemetry metric attribute (`app.entrypoint`, opt-in via `OTEL_METRICS_INCLUDE_ENTRYPOINT=true`)
- Fixed terminal styling degrading in very long sessions by recycling the renderer's style pool
- Fixed the sandbox-enabled warning not appearing in condensed startup mode — it now shows in every layout
- Fixed the loading spinner showing "still thinking"/"almost done thinking" while a tool is running, and reset the thinking status to "thinking" after each tool
- Fixed focus mode showing a spurious "N messages hidden" count on turns with no hidden activity
- Fixed clicking a link inside an expanded tool result collapsing the section instead of opening the link
- Fixed markdown table cell borders inheriting the color of inline code, wrapped continuation lines losing their style, and empty header cells showing a label in the narrow-terminal stacked layout
- Fixed plugin MCP servers with the same command but different environment variables being incorrectly deduplicated
- Fixed `/doctor` reporting "marketplace not found" or "plugin not found" for stale `enabledPlugins` entries referencing removed marketplaces or dropped plugins
- Fixed plugins that track a git branch silently no longer receiving updates after the plugin registry was rebuilt
- Fixed remote MCP servers failing to connect in Claude Code Remote sessions when the egress proxy is enabled
- Fixed the effort-change confirmation dialog appearing when the conversation has no messages or when switching between effort levels that resolve to the same underlying value
- Fixed the Agent tool description referencing an agent list that is never delivered when running with `--bare` or with attachments disabled
- Fixed a background worker crash in `claude agents` when accepting a stale permission prompt after a subagent was cancelled
- Fixed `cache_creation_input_tokens` reporting as 0 in transcript and result usage when the API reports cache writes only via the nested `cache_creation` breakdown
- Fixed the PushNotification tool incorrectly reporting "Mobile push not sent (Remote Control inactive)" in SDK-hosted sessions when Remote Control is enabled
- Fixed sessions getting stuck after a model or login switch left stale thinking-block signatures in history; now stripped proactively with a retry safety-net
### [`v2.1.148`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21148)
- Fixed the Bash tool returning exit code 127 on every command for some users (a regression introduced in 2.1.147)
### [`v2.1.146`](https://github.com/anthropics/claude-code/releases/tag/v2.1.146)
#### What's changed
- Renamed `/simplify` to `/code-review` with an optional effort level (e.g. `/code-review high`)
- Auto mode no longer suppresses `AskUserQuestion` when the user or a skill explicitly relies on it
- Fixed Windows PowerShell tool failing with "command line is invalid" when `pwsh` is installed via winget or the Microsoft Store (regression in v2.1.124)
- Fixed MCP `resources/list`, `resources/templates/list`, and `prompts/list` dropping items past page 1 on paginating servers
- Fixed full-screen strobing in attached background sessions on Windows Terminal while Claude is streaming
- Fixed the auto-updater status line not showing your current version when an update fails
- Fixed on Windows, removing a background-job worktree no longer follows NTFS junctions into the main repo
- Fixed `/background` refusing sessions whose only typed input was a skill or custom slash command
- Fixed backgrounded sessions re-prompting for tool permissions you already granted with "don't ask again"
- Fixed `/theme` color editor and "New custom theme" dialogs not responding to Esc
- Fixed an uncaught exception at the end of streaming sessions when running via the Agent SDK
- Fixed `forceLoginOrgUUID` and `forceLoginMethod` managed-settings policies not being enforced against third-party-provider and API-key sessions
- Fixed GNOME Terminal right-click and middle-click paste not inserting text
- Fixed `CLAUDE_CODE_SUBAGENT_MODEL` not being forwarded to child processes in multi-agent sessions
- Improved auto-updater reliability: native version checks and downloads now retry transient network failures instead of failing immediately
- Improved diff rendering performance for large file edits
### [`v2.1.145`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21145)
- Added `claude agents --json` to list live Claude sessions as JSON for scripting (tmux-resurrect, status bars, session pickers)
- Added `agent_id` and `parent_agent_id` attributes to `claude_code.tool` OTEL spans, and fixed trace parenting so background subagent spans nest under the dispatching Agent tool span
- Status line JSON input now includes GitHub repo and PR information when detected
- `/plugin` Discover and Browse screens now show a plugin's commands, agents, skills, hooks, and MCP/LSP servers before installation
- `claude agents` terminal tab title now shows the awaiting-input count so an alt-tabbed window tells you when an agent needs attention
- Slash command and @​-mention suggestion list now supports mouse hover and click in fullscreen mode
- Stop and SubagentStop hook input now includes `background_tasks` and `session_crons` fields
- Fixed a permission-prompt bypass where bare variable assignments to non-allowlisted environment variables in Bash commands were auto-approved
- Fixed MCP prompt slash commands showing raw server validation errors when a required argument is omitted — the error now names the missing argument and shows expected usage
- Fixed the spinner and elapsed-time display freezing until a keypress after the terminal was resized or refocused
- Fixed the cross-project resume hint failing in default Windows PowerShell 5.1 — Windows now uses `;` as the command separator
- Fixed voice push-to-talk not working in the agent view's reply pane
- Fixed task lists rendering in random order when several tasks are created at once
- Fixed stale "Failed to install Anthropic marketplace" banner showing when the marketplace is already installed
- Fixed the PR badge in the footer not updating immediately after `gh pr create` and other PR-state-changing commands run in-session
- Fixed Agent Teams teammates with non-ASCII names failing every API call due to invalid header encoding
- Fixed `/review` using a deprecated `projectCards` GraphQL query that errored on repos with Classic Projects
- Fixed `claude plugin validate` not flagging `skills:` entries that point at a file instead of a directory — the error now suggests the parent directory
- Fixed an infinite loop where a skill using `context: fork` could repeatedly re-invoke itself instead of running
- Improved the Read tool to return a truncated first page with a "PARTIAL view" notice instead of a hard error when a whole-file read exceeds the token limit
### [`v2.1.143`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21143)
- Added plugin dependency enforcement: `claude plugin disable` now refuses when another enabled plugin depends on the target (with a copy-pasteable disable-chain hint), and `claude plugin enable` force-enables transitive dependencies
- Added projected context cost (per-turn and per-invocation token estimates) to the `/plugin` marketplace browse pane
- Added `worktree.bgIsolation: "none"` setting to let background sessions edit the working copy directly without `EnterWorktree`, for repos where worktrees are impractical
- PowerShell tool now passes `-ExecutionPolicy Bypass`. Opt out with `CLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY=1`
- Background sessions now preserve the model and effort level you set after waking from idle
- Shift+Tab in attached agent sessions now includes auto mode in the cycle
- Fixed a corrupt `.credentials.json` with a non-array `scopes` value hanging the CLI on startup or silently aborting OAuth token refresh
- Fixed right-click paste in `claude agents` on Windows Terminal and WSL
- Fixed stop hooks that block repeatedly looping forever — the turn now ends with a warning after 8 consecutive blocks (override via `CLAUDE_CODE_STOP_HOOK_BLOCK_CAP`)
- Fixed Esc/Ctrl+C not cancelling a pending `/loop` wakeup while Claude is idle between iterations
- Fixed `/goal` evaluator firing while background shells or delegated subagents are still running
- Fixed `NO_COLOR`/`FORCE_COLOR` in settings.json `env` stripping Claude Code's own UI colors — they now apply to subprocesses only
- Fixed agent view spawning repeated PowerShell processes on Windows when listing sessions
- Fixed `/bg` without a prompt sending "continue" to the forked session — the fork now waits for input
- Fixed `--agent <name>` not finding plugin-contributed agents without the `plugin:` prefix
- Fixed deleting a session from agent view not removing its transcript file
- Fixed stale-fragment rendering when scrolling in attached background sessions on Windows Terminal
- Fixed background agents false-positive worker-stall detection storm after host sleep or macOS App Nap
- Fixed 5xx error messages pointing at status.claude.com instead of naming the configured gateway or cloud provider
- The PowerShell tool is now enabled by default on Windows for Bedrock, Vertex, and Foundry users. Opt out with `CLAUDE_CODE_USE_POWERSHELL_TOOL=0`.
- `claude agents` now accepts `--add-dir`, `--settings`, `--mcp-config`, and `--plugin-dir` and applies them to the dashboard and to background sessions dispatched from it
- `claude agents` accepts `--permission-mode`, `--model`, `--effort`, and `--dangerously-skip-permissions` to set defaults for sessions dispatched from the view
- `claude --bg --dangerously-skip-permissions` now persists across retire→wake
- Fixed background sessions silently capturing IDE file references into the warm spare's input, which caused the reference to be prepended to the next prompt dispatched from `claude agents`
- Worktree cleanup no longer falls back to `rm -rf` when `git worktree remove` fails, preventing loss of gitignored or in-progress files
- Fixed background-job sessions on macOS getting "Operation not permitted" errors when reading files under `~/Documents`, `~/Desktop`, or `~/Downloads`, even with Full Disk Access granted.
- `/bg` now preserves `--mcp-config`, `--settings`, `--add-dir`, `--plugin-dir`, and `--strict-mcp-config`, so backgrounded sessions keep their MCP servers and settings across respawn.
- Background sessions launched from `claude agents` now honor `permissions.defaultMode` from settings.json (was previously overridden to auto mode)
- Fixed: on Windows, pressing ← in `claude agents` while a response was streaming could leave the agents list unresponsive to all input
- `/bg` and `←`-detach now preserve `--fallback-model`, so backgrounded workers degrade to the fallback model on overload instead of hard-failing.
- `/bg` and `←`-detach now preserve `--allow-dangerously-skip-permissions`, so the forked worker keeps bypass-permissions available in its Shift+Tab cycle.
- Fixed: background daemon spawn now falls back to the running binary when the `~/.local/bin/claude` launcher is missing or non-executable
- Fixed `claude agents --allow-dangerously-skip-permissions` defaulting dispatched sessions to bypass mode instead of making it available in the permission cycle
### [`v2.1.141`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21141)
- Added `terminalSequence` field to hook JSON output so hooks can emit desktop notifications, window titles, and bells without a controlling terminal
- Added `CLAUDE_CODE_PLUGIN_PREFER_HTTPS` to clone GitHub plugin sources over HTTPS instead of SSH, for environments without a GitHub SSH key
- Added `ANTHROPIC_WORKSPACE_ID` environment variable for workload identity federation — scopes the minted token to a specific workspace when the federation rule covers more than one
- Added `claude agents --cwd <path>` to scope the session list to a directory
- `/feedback` can now include recent sessions (last 24 hours or 7 days) for issues spanning more than the current session
- Rewind menu: added "Summarize up to here" to compress earlier context while keeping recent turns intact
- Auto mode permission dialog now explains when a `permissions.ask` rule caused the prompt
- Restored the "view diff in your IDE" option on file-edit permission prompts when an IDE is connected
- Background agents launched via `/bg` or `←←` now preserve the current permission mode instead of reverting to default
- `claude agents`: agents that finish work but leave a background shell running now move to Completed instead of staying under Working
- Improved spinner feedback during long thinking periods — the spinner now warms to amber after 10 seconds to signal Claude is still working
- Improved plugin menu navigation: `→`/Tab switch tabs, `↑` moves to the tab strip, and tab headers and search box are clickable in fullscreen mode
- Fixed background side-queries sending an unavailable Haiku model ID on Bedrock/Vertex/Foundry/gateway when no `ANTHROPIC_SMALL_FAST_MODEL` override is set — now falls back to the main-loop model
- Fixed `claude daemon status` and `/doctor` on Windows throwing when the daemon pipe key file is locked or unreadable — now shows the underlying error instead of an opaque failure
- Fixed `claude agents` showing the agent-type list instead of the dashboard when launched through a wrapper that adds flags
- Fixed `claude agents` opening a crashed session firing redundant dispatches when the working directory was deleted
- Fixed background jobs on a custom `ANTHROPIC_BASE_URL` gateway not getting auto-named — the namer now uses the main model when no Haiku model is configured
- Fixed `/model` in one session silently changing the autocompact threshold in other concurrent sessions
- Fixed switching permission mode while a tool-permission prompt is open not auto-dismissing the prompt when the new setting permits the tool
- Fixed pressing Enter while a permission/dialog prompt is open also submitting text in the input box
- Fixed hooks receiving a non-existent `transcript_path` after `EnterWorktree` switches the working directory
- Fixed markdown tables with cell wrapping falling back to the vertical key-value layout instead of rendering as a bordered grid (regression in 2.1.136)
- Fixed cancelled prompts being removed from Up-arrow history when auto-restored into the input box, avoiding duplicate entries
- Fixed prompts cancelled with Ctrl+C/Esc before any response being dropped from Up-arrow history
- Fixed Ctrl+C not interrupting a running turn while in vim INSERT/VISUAL mode
- Fixed alternative `chat:submit` keybindings (e.g. `meta+enter`, `ctrl+enter`) not working when `enter` is rebound to `chat:newline`
- Fixed prompt suggestions being silently disabled when an output style was configured
- Fixed `spinnerVerbs` setting not being honored in turn-completion messages
- Fixed AskUserQuestion popup hiding the last line of preceding chat content
- Fixed Web Search status showing "Did 0 searches" when searches returned errors
- Fixed multi-line statusline output dropping or corrupting rows when any line exceeds terminal width
- Fixed light-ansi theme using invisible white for diff context lines on light backgrounds — now uses black
- Fixed error overlay dumping minified bundle source that hid the original error message
- Fixed pressing Enter after typing a feedback survey rating digit submitting it as a chat message instead of the rating
- Fixed pressing `x` on a selected subagent in the agent panel typing into the prompt instead of stopping the agent
- Fixed session title being derived from plugin monitor notifications before the user's first prompt
- Fixed "Allowed by PermissionRequest hook" repeating once per tool call under a collapsed read/search group
- Fixed `/tui` silently dropping running background shells and subagents — now refuses and asks to wait for them to finish
- Fixed welcome banner showing "API Usage Billing" on Bedrock, Vertex, Foundry, and other third-party providers — now shows the provider name
- Fixed `/mcp` server list not keeping the focused server visible in short terminals in fullscreen mode
- Fixed redaction in `/feedback` bundles producing invalid JSON for quoted values like session IDs
- Fixed desktop and third-party provider sessions incorrectly inheriting `apiKeyHelper`/`ANTHROPIC_AUTH_TOKEN` from host managed-settings
- Fixed early analytics events being silently dropped when fired before logger initialization
- Fixed `claude plugin install` failing for plugins whose marketplace `ref` no longer exists upstream when a `sha` is also pinned
- Fixed plugin details pane showing 0 MCP servers for plugins that declare them via `.mcp.json`
- Fixed plugin MCP servers with unset config variables showing a generic connection failure instead of a "config issue" message with a fix-it hint; malformed `.mcp.json` entries no longer drop other MCP servers
- Fixed MCP server configs using POSIX shell parameter expansions (e.g. `${var%pattern}`) being incorrectly flagged as missing environment variables
- Fixed MCP HTTP/SSE servers returning 403 on connect showing as "failed" instead of "needs auth"
- Fixed remote MCP servers disconnecting unnecessarily when the optional server-events stream failed to reconnect — tool calls continue over POST
- Fixed Remote Control MCP connectors all failing with 401 when the worker session token rotated mid-session
- Fixed Remote Control automatically re-enrolling a trusted device when the server rejects a stale token, instead of looping through `/login`
- Fixed a race where early OTel spans could be silently dropped in SDK/headless mode with beta tracing enabled
- Fixed custom `voice:pushToTalk` keybindings and `"space": null` unbinds being silently ignored
- Fixed Windows Alt+V image paste reporting "no image found" when the clipboard contains a screenshot
- Fixed SDK "Claude Code native binary not found" on Linux when both glibc and musl platform packages are installed
- Bedrock: `awsCredentialExport` now always runs when configured instead of being skipped when ambient AWS credentials resolve, fixing auth for cross-account access
- \[VSCode] Fixed in-chat mic showing no feedback when the microphone produced only silence — now shows "No audio detected"
- \[VSCode] Voice mode: the WSL error now suggests installing `sox libsox-fmt-pulse` for WSLg users
- `claude agents`: launching a session no longer fails when the pre-warmed background worker is unhealthy — now falls back to a fresh launch
- `claude agents` no longer shows empty placeholder sessions left over from backgrounding a fresh REPL, and shows onboarding text when entered via ← with no other agents
- Empty idle background sessions left over from `←` are now automatically retired by the daemon after 5 minutes
### [`v2.1.140`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21140)
- Improved Agent tool `subagent_type` matching to accept case- and separator-insensitive values (e.g. `"Code Reviewer"` resolves to `code-reviewer`)
- Updated agent color palette
- Fixed `/goal` silently hanging when `disableAllHooks` or `allowManagedHooksOnly` is set — now shows a clear message instead of an indicator that never resolves
- Fixed a regression in settings hot-reload where symlinked settings files caused misattributed change events and spurious `ConfigChange` hooks
- Fixed `claude --bg` failing with "connection dropped mid-request" when the background service was about to idle-exit
- Fixed background service startup failing on machines with enterprise endpoint security by allowing more time
- Fixed remote managed settings not retrying on 401 — now retries once with a force-refreshed token
- Fixed managed `extraKnownMarketplaces` auto-update policy not being persisted to `known_marketplaces.json`
- Fixed `/loop` scheduling redundant wakeups to poll for background tasks that already notify on completion
- Fixed a recurring event-loop stall on Windows when a missing executable (e.g. `gh`) triggered synchronous `where.exe` re-spawns on every check
- Fixed `Read` tool calls failing validation when `offset` is passed as a whitespace-padded or `+`-prefixed string
- Fixed native terminal cursor not staying at the input caret when the terminal loses focus
- Plugins now warn when a default component folder (e.g. `commands/`) is silently ignored because `plugin.json` sets the matching key. Shown in `/doctor`, `claude plugin list`, and `/plugin`.
### [`v2.1.138`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21138)
- Internal fixes
### [`v2.1.137`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21137)
- \[VSCode] Fixed extension failing to activate on Windows
### [`v2.1.133`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21133)
- Added `worktree.baseRef` setting (`fresh` | `head`) to choose whether `--worktree`, `EnterWorktree`, and agent-isolation worktrees branch from `origin/<default>` or local `HEAD`. **Note:** the default `fresh` changes `EnterWorktree`'s base back to `origin/<default>` (it has been local `HEAD` since 2.1.128) — set `worktree.baseRef: "head"` to keep unpushed commits in new worktrees
- Added `sandbox.bwrapPath` and `sandbox.socatPath` managed settings (Linux/WSL) to specify custom bubblewrap and socat binary locations
- Added `parentSettingsBehavior` admin-tier key (`'first-wins' | 'merge'`) to let admins opt SDK `managedSettings` (parent tier) into the policy merge
- Hooks now receive the active effort level via the `effort.level` JSON input field and the `$CLAUDE_EFFORT` environment variable, and Bash tool commands can read `$CLAUDE_EFFORT`
- Improved focus mode behavior
- Improved memory usage by releasing warm-spare background workers under memory pressure
- Fixed parallel sessions all dead-ending at 401 after a refresh-token race wiped shared credentials
- Fixed `Edit`/`Write` allow rules scoped to a drive root (`C:\`) or POSIX `/` matching incorrectly and always prompting
- Fixed an unhandled rejection (`ECOMPROMISED`) when a history or session-log file lock is compromised by clock skew or slow disk
- Fixed pressing Esc during conversation compaction showing a spurious "Error compacting conversation" notification
- Fixed `HTTP(S)_PROXY` / `NO_PROXY` / mTLS not being respected for the full MCP OAuth flow including discovery, dynamic client registration, token exchange, and token refresh
- Fixed Read/Write/Edit being denied on mapped network drives passed via `--add-dir` / SDK `additionalDirectories`
- Fixed Remote Control stop/interrupt from claude.ai not fully canceling the CLI session the same way local Esc does, causing queued messages to never advance after interrupting a stuck tool or prompt
- Fixed `/effort` in one session unexpectedly changing the effort level of other concurrent sessions, and a related issue where an IDE effort change could be silently dropped
- Fixed subagents not discovering project, user, or plugin skills via the Skill tool
- `claude --help` now lists `--remote-control` alongside `--remote-control-session-name-prefix`
- \[VSCode] Fixed `claudeCode.claudeProcessWrapper` failing with "Unsupported platform" when the extension build doesn't bundle a Claude binary
### [`v2.1.128`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21128)
- Bare `/color` (no args) now picks a random session color
- `/mcp` now shows the tool count for connected servers and flags servers that connected with 0 tools
- `--plugin-dir` now accepts `.zip` plugin archives in addition to directories
- `--channels` now works with console (API key) authentication — console orgs with managed settings must set `channelsEnabled: true` to enable
- Updated `/model` picker: collapsed duplicate Opus 4.7 entries, and current Opus now shows as "Opus" instead of "Opus 4.7"
- Subprocesses (Bash, hooks, MCP, LSP) no longer inherit `OTEL_*` environment variables, so OTEL-instrumented apps run via the Bash tool no longer pick up the CLI's own OTLP endpoint
- MCP: `workspace` is now a reserved server name — existing servers with that name will be skipped with a warning
- Reconnecting MCP servers no longer flood the conversation with full tool-name lists on every reconnect — re-announced tools are summarized by server prefix
- SDK hosts now receive a persistent `localSettings` suggestion for Bash permission prompts, so "Always allow" writes to `.claude/settings.local.json`
- `EnterWorktree` now creates the new branch from local HEAD as documented, instead of `origin/<default-branch>` — unpushed commits are no longer dropped
- Auto mode: when the classifier can't evaluate an action, the error now includes a hint (retry, `/compact`, or run with `--debug`)
- Fixed focus mode briefly dimming the previous response when submitting a new prompt
- Fixed stray "4;0;" desktop notification on every `/exit` in Kitty and other terminals that interpret OSC 9 as a notification
- Fixed Remote Control showing an empty "Opening your options…" message on rate limit instead of actionable upsell options
- Fixed drag-and-drop image upload hanging on "Pasting text…" when the image read fails
- Fixed crash loop when piping very large input (>10 MB) to `claude -p` via stdin
- Fixed long URLs not being individually clickable on every wrapped row in fullscreen mode
- Fixed `/plugin` Components panel showing "Marketplace 'inline' not found" for plugins loaded via `--plugin-dir`
- Fixed MCP tool results dropping images when the server returns both structured content and content blocks
- Fixed fenced code blocks inside list items carrying leading whitespace into the clipboard on copy-paste
- Fixed tab navigation in `/config` stranding focus — the tab header now stays focused so arrows and Esc keep working
- Fixed markdown link labels being lost on terminals without OSC 8 hyperlink support — links now render as `label (url)` instead of just the URL
- Fixed sessions on 1M-context models with a smaller autocompact window being falsely blocked with "Prompt is too long" before reaching the actual API limit
- Fixed parallel shell tool calls: a failing read-only command (grep, git diff, ls) no longer cancels sibling calls
- Fixed banner showing "with X effort" on models that don't support effort
- Fixed `/fast` on 3P providers fuzzy-matching to an unrelated skill instead of showing "not available"
- Fixed Bedrock default model resolving to `global.*` instead of the region-appropriate prefix
- Fixed vim mode: `Space` in NORMAL mode now moves the cursor right, matching standard vi/vim behavior
- Fixed terminal progress indicator (OSC 9;4) flickering off between tool calls — stays visible across the full turn
- Fixed `/rename` without args failing on resumed sessions whose last entry is a compact boundary
- Fixed stale "remote-control is active" status lines from prior sessions appearing after `--resume`/`--continue`
- Fixed stale `installed_plugins.json` entries pointing at deleted cache directories polluting PATH
- Fixed MCP stdio servers receiving corrupted arguments when `CLAUDE_CODE_SHELL_PREFIX` is set and an argument contains spaces or shell metacharacters
- Fixed sub-agent progress summaries missing the prompt cache (\~3× `cache_creation` reduction)
- Fixed `/plugin update` never detecting new versions of npm-sourced plugins
- Fixed sub-agent summaries firing repeatedly while a sub-agent's transcript is static, capping worst-case token cost on idle sub-agents
- Headless `--output-format stream-json`: `init.plugin_errors` now includes `--plugin-dir` load failures in addition to dependency demotions
### [`v2.1.123`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21123)
- Fixed OAuth authentication failing with a 401 retry loop when `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS=1` is set
### [`v2.1.121`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21121)
- Added `alwaysLoad` option to MCP server config — when `true`, all tools from that server skip tool-search deferral and are always available
- Added `claude plugin prune` to remove orphaned auto-installed plugin dependencies; `plugin uninstall --prune` cascades
- Added a type-to-filter search box to `/skills` so you can find a skill in long lists without scrolling
- PostToolUse hooks can now replace tool output for all tools via `hookSpecificOutput.updatedToolOutput` (previously MCP-only)
- Fullscreen mode: typing into the prompt no longer jumps scroll back to the bottom after you've scrolled up to read earlier output
- Dialogs that overflow the terminal are now scrollable with arrow keys, PgUp/PgDn, home/end, and mouse wheel in both fullscreen and non-fullscreen modes
- Clicking any line of a long URL that wraps across rows in fullscreen mode now opens the full URL
- SDK and `claude -p`: `CLAUDE_CODE_FORK_SUBAGENT=1` now works in non-interactive sessions
- `--dangerously-skip-permissions` no longer prompts for writes to `.claude/skills/`, `.claude/agents/`, and `.claude/commands/`
- `/terminal-setup` now enables iTerm2's "Applications in terminal may access clipboard" setting so `/copy` works, including from tmux
- MCP servers that hit a transient error during startup now auto-retry up to 3 times instead of staying disconnected
- The terminal tab session title is now generated in your configured `language` setting
- Claude.ai connectors with the same upstream URL are now deduplicated instead of appearing as duplicates
- Vertex AI: support X.509 certificate-based Workload Identity Federation (mTLS ADC)
- Faster startup after upgrading: removed the Recent Activity panel from the release-notes splash
- LSP diagnostic summaries now expand on click/ctrl+o and show the expand hint
- SDK: `mcp_authenticate` now supports `redirectUri` for custom scheme completion and claude.ai connectors
- OpenTelemetry: added `stop_reason`, `gen_ai.response.finish_reasons`, and `user_system_prompt` (gated behind `OTEL_LOG_USER_PROMPTS`) to LLM request spans
- \[VSCode] Voice dictation now respects the `accessibility.voice.speechLanguage` setting when no Claude Code language is configured
- \[VSCode] `/context` now opens a native token usage dialog
- Fixed unbounded memory growth (multi-GB RSS) when processing many images in a session
- Fixed `/usage` leaking up to \~2GB of memory on machines with large transcript histories
- Fixed memory leak when long-running tools fail to emit a clear progress event
- Fixed Bash tool becoming permanently unusable when the directory Claude was started in is deleted or moved mid-session
- Fixed `--resume` crashing on startup in external builds
- Fixed `--resume` failing on large sessions when a transcript line was corrupted by an unclean shutdown — the corrupt line is now skipped
- Fixed `thinking.type.enabled is not supported` error when using Bedrock application inference profile ARNs
- Fixed Microsoft 365 MCP OAuth failing with duplicate or unsupported `prompt` parameter
- Fixed scrollback duplication when pressing Ctrl+L or triggering a redraw in non-fullscreen mode on tmux, GNOME Terminal, Windows Terminal, and Konsole
- Fixed claude.ai MCP connectors silently disappearing when the connector-list fetch hits a transient auth error at startup
- Fixed "Always allow" rules for built-in tools in remote sessions not surviving worker restarts
- Fixed `NO_PROXY` not being respected for all HTTP clients when set via `managed-settings.json` under the native build
- Fixed managed settings approval prompt exiting the session even when accepted — now applies settings and continues
- Fixed `/usage` returning "rate limited" after a stale OAuth token — now refreshes automatically
- Fixed invalid legacy enum values in `settings.json` invalidating the entire settings file
- Fixed `/usage` dialog content being clipped when no-flicker mode is off
- Fixed `/focus` showing "Unknown command" when the fullscreen renderer is off — now explains how to enable it
- Fixed embedded grep/find/rg shell wrappers failing when the running binary is deleted mid-session — now falls back to installed tools
- Reduced peak file descriptor usage during `find` in the Bash tool on large directory trees
### [`v2.1.119`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21119)
- `/config` settings (theme, editor mode, verbose, etc.) now persist to `~/.claude/settings.json` and participate in project/local/policy override precedence
- Added `prUrlTemplate` setting to point the footer PR badge at a custom code-review URL instead of github.com
- Added `CLAUDE_CODE_HIDE_CWD` environment variable to hide the working directory in the startup logo
- `--from-pr` now accepts GitLab merge-request, Bitbucket pull-request, and GitHub Enterprise PR URLs
- `--print` mode now honors the agent's `tools:` and `disallowedTools:` frontmatter, matching interactive-mode behavior
- `--agent <name>` now honors the agent definition's `permissionMode` for built-in agents
- PowerShell tool commands can now be auto-approved in permission mode, matching Bash behavior
- Hooks: `PostToolUse` and `PostToolUseFailure` hook inputs now include `duration_ms` (tool execution time, excluding permission prompts and PreToolUse hooks)
- Subagent and SDK MCP server reconfiguration now connects servers in parallel instead of serially
- Plugins pinned by another plugin's version constraint now auto-update to the highest satisfying git tag
- Vim mode: Esc in INSERT no longer pulls a queued message back into the input; press Esc again to interrupt
- Slash command suggestions now highlight the characters that matched your query
- Slash command picker now wraps long descriptions onto a second line instead of truncating
- `owner/repo#N` shorthand links in output now use your git remote's host instead of always pointing at github.com
- Security: `blockedMarketplaces` now correctly enforces `hostPattern` and `pathPattern` entries
- OpenTelemetry: `tool_result` and `tool_decision` events now include `tool_use_id`; `tool_result` also includes `tool_input_size_bytes`
- Status line: stdin JSON now includes `effort.level` and `thinking.enabled`
- Fixed pasting CRLF content (Windows clipboards, Xcode console) inserting an extra blank line between every line
- Fixed multi-line paste losing newlines in terminals using kitty keyboard protocol sequences inside bracketed paste
- Fixed Glob and Grep tools disappearing on native macOS/Linux builds when the Bash tool is denied via permissions
- Fixed scrolling up in fullscreen mode snapping back to the bottom every time a tool finishes
- Fixed MCP HTTP connections failing with "Invalid OAuth error response" when servers returned non-JSON bodies for OAuth discovery requests
- Fixed Rewind overlay showing "(no prompt)" for messages with image attachments
- Fixed auto mode overriding plan mode with conflicting "Execute immediately" instructions
- Fixed async `PostToolUse` hooks that emit no response payload writing empty entries to the session transcript
- Fixed spinner staying on when a subagent task notification is orphaned in the queue
- Tool search is now disabled by default on Vertex AI to avoid an unsupported beta header error (opt in with `ENABLE_TOOL_SEARCH`)
- Fixed `@`-file Tab completion replacing the entire prompt when used inside a slash command with an absolute path
- Fixed a stray `p` character appearing at the prompt on startup in macOS Terminal.app via Docker or SSH
- Fixed `${ENV_VAR}` placeholders in `headers` for HTTP/SSE/WebSocket MCP servers not being substituted before requests
- Fixed MCP OAuth client secret stored via `--client-secret` not being sent during token exchange for servers requiring `client_secret_post`
- Fixed `/skills` Enter key closing the dialog instead of pre-filling `/<skill-name>` in the prompt
- Fixed `/agents` detail view mislabeling built-in tools unavailable to subagents as "Unrecognized"
- Fixed MCP servers from plugins not spawning on Windows when the plugin cache was incomplete
- Fixed `/export` showing the current default model instead of the model the conversation actually used
- Fixed verbose output setting not persisting after restart
- Fixed `/usage` progress bars overlapping with their "Resets …" labels
- Fixed plugin MCP servers failing when `${user_config.*}` references an optional field left blank
- Fixed list items containing a sentence-final number wrapping the number onto its own line
- Fixed `/plan` and `/plan open` not acting on the existing plan when entering plan mode
- Fixed skills invoked before auto-compaction being re-executed against the next user message
- Fixed `/reload-plugins` and `/doctor` reporting load errors for disabled plugins
- Fixed Agent tool with `isolation: "worktree"` reusing stale worktrees from prior sessions
- Fixed disabled MCP servers appearing as "failed" in `/status`
- Fixed `TaskList` returning tasks in arbitrary filesystem order instead of sorted by ID
- Fixed spurious "GitHub API rate limit exceeded" hints when `gh` output contained PR titles mentioning "rate limit"
- Fixed SDK/bridge `read_file` not correctly enforcing size cap on growing files
- Fixed PR not linked to session when working in a git worktree
- Fixed `/doctor` warning about MCP server entries overridden by a higher-precedence scope
- Windows: removed false-positive "Windows requires 'cmd /c' wrapper" MCP config warning
- \[VSCode] Fixed voice dictation's first recording producing nothing on macOS while the microphone permission prompt is showing
### [`v2.1.112`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21112)
- Fixed "claude-opus-4-7 is temporarily unavailable" for auto mode
### [`v2.1.107`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21107)
- Show thinking hints sooner during long operations
### [`v2.1.97`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2197)
- Added focus view toggle (`Ctrl+O`) in `NO_FLICKER` mode showing prompt, one-line tool summary with edit diffstats, and final response
- Added `refreshInterval` status line setting to re-run the status line command every N seconds
- Added `workspace.git_worktree` to the status line JSON input, set when the current directory is inside a linked git worktree
- Added `● N running` indicator in `/agents` next to agent types with live subagent instances
- Added syntax highlighting for Cedar policy files (`.cedar`, `.cedarpolicy`)
- Fixed `--dangerously-skip-permissions` being silently downgraded to accept-edits mode after approving a write to a protected path
- Fixed and hardened Bash tool permissions, tightening checks around env-var prefixes and network redirects, and reducing false prompts on common commands
- Fixed permission rules with names matching JavaScript prototype properties (e.g. `toString`) causing `settings.json` to be silently ignored
- Fixed managed-settings allow rules remaining active after an admin removed them until process restart
- Fixed `permissions.additionalDirectories` changes in settings not applying mid-session
- Fixed removing a directory from `settings.permissions.additionalDirectories` revoking access to the same directory passed via `--add-dir`
- Fixed MCP HTTP/SSE connections accumulating \~50 MB/hr of unreleased buffers when servers reconnect
- Fixed MCP OAuth `oauth.authServerMetadataUrl` not being honored on token refresh after restart, fixing ADFS and similar IdPs
- Fixed 429 retries burning all attempts in \~13 seconds when the server returns a small `Retry-After` — exponential backoff now applies as a minimum
- Fixed rate-limit upgrade options disappearing after context compaction
- Fixed several `/resume` picker issues: `--resume <name>` opening uneditable, Ctrl+A reload wiping search, empty list swallowing navigation, task-status text replacing conversation summary, and cross-project staleness
- Fixed file-edit diffs disappearing on `--resume` when the edited file was larger than 10KB
- Fixed `--resume` cache misses and lost mid-turn input from attachment messages not being saved to the transcript
- Fixed messages typed while Claude is working not being persisted to the transcript
- Fixed prompt-type `Stop`/`SubagentStop` hooks failing on long sessions, and hook evaluator API errors displaying "JSON validation failed" instead of the actual message
- Fixed subagents with worktree isolation or `cwd:` override leaking their working directory back to the parent session's Bash tool
- Fixed compaction writing duplicate multi-MB subagent transcript files on prompt-too-long retries
- Fixed `claude plugin update` reporting "already at the latest version" for git-based marketplace plugins when the remote had newer commits
- Fixed slash command picker breaking when a plugin's frontmatter `name` is a YAML boolean keyword
- Fixed copying wrapped URLs in `NO_FLICKER` mode inserting spaces at line breaks
- Fixed scroll rendering artifacts in `NO_FLICKER` mode when running inside zellij
- Fixed a crash in `NO_FLICKER` mode when hovering over MCP tool results
- Fixed a `NO_FLICKER` mode memory leak where API retries left stale streaming state
- Fixed slow mouse-wheel scrolling in `NO_FLICKER` mode on Windows Terminal
- Fixed custom status line not displaying in `NO_FLICKER` mode on terminals shorter than 24 rows
- Fixed Shift+Enter and Alt/Cmd+arrow shortcuts not working in Warp with `NO_FLICKER` mode
- Fixed Korean/Japanese/Unicode text becoming garbled when copied in no-flicker mode on Windows
- Fixed Bedrock SigV4 authentication failing when `AWS_BEARER_TOKEN_BEDROCK` or `ANTHROPIC_BEDROCK_BASE_URL` are set to empty strings (as GitHub Actions does for unset inputs)
- Improved Accept Edits mode to auto-approve filesystem commands prefixed with safe env vars or process wrappers (e.g. `LANG=C rm foo`, `timeout 5 mkdir out`)
- Improved auto mode and bypass-permissions mode to auto-approve sandbox network access prompts
- Improved sandbox: `sandbox.network.allowMachLookup` now takes effect on macOS
- Improved image handling: pasted and attached images are now compressed to the same token budget as images read via the Read tool
- Improved slash command and `@`-mention completion to trigger after CJK sentence punctuation, so Japanese/Chinese input no longer requires a space before `/` or `@`
- Improved Bridge sessions to show the local git repo, branch, and working directory on the claude.ai session card
- Improved footer layout: indicators (Focus, notifications) now stay on the mode-indicator row instead of wrapping below
- Improved context-low warning to show as a transient footer notification instead of a persistent row
- Improved markdown blockquotes to show a continuous left bar across wrapped lines
- Improved session transcript size by skipping empty hook entries and capping stored pre-edit file copies
- Improved transcript accuracy: per-block entries now carry the final token usage instead of the streaming placeholder
- Improved Bash tool OTEL tracing: subprocesses now inherit a W3C `TRACEPARENT` env var when tracing is enabled
- Updated `/claude-api` skill to cover Managed Agents alongside the Claude API
### [`v2.1.92`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2192)
- Added `forceRemoteSettingsRefresh` policy setting: when set, the CLI blocks startup until remote managed settings are freshly fetched, and exits if the fetch fails (fail-closed)
- Added interactive Bedrock setup wizard accessible from the login screen when selecting "3rd-party platform" — guides you through AWS authentication, region configuration, credential verification, and model pinning
- Added per-model and cache-hit breakdown to `/cost` for subscription users
- `/release-notes` is now an interactive version picker
- Remote Control session names now use your hostname as the default prefix (e.g. `myhost-graceful-unicorn`), overridable with `--remote-control-session-name-prefix`
- Pro users now see a footer hint when returning to a session after the prompt cache has expired, showing roughly how many tokens the next turn will send uncached
- Fixed subagent spawning permanently failing with "Could not determine pane count" after tmux windows are killed or renumbered during a long-running session
- Fixed prompt-type Stop hooks incorrectly failing when the small fast model returns `ok:false`, and restored `preventContinuation:true` semantics for non-Stop prompt-type hooks
- Fixed tool input validation failures when streaming emits array/object fields as JSON-encoded strings
- Fixed an API 400 error that could occur when extended thinking produced a whitespace-only text block alongside real content
- Fixed accidental feedback survey submissions from auto-pilot keypresses and consecutive-prompt digit collisions
- Fixed misleading "esc to interrupt" hint appearing alongside "esc to clear" when a text selection exists in fullscreen mode during processing
- Fixed Homebrew install update prompts to use the cask's release channel (`claude-code` → stable, `claude-code@latest` → latest)
- Fixed `ctrl+e` jumping to the end of the next line when already at end of line in multiline prompts
- Fixed an issue where the same message could appear at two positions when scrolling up in fullscreen mode (iTerm2, Ghostty, and other terminals with DEC 2026 support)
- Fixed idle-return "/clear to save X tokens" hint showing cumulative session tokens instead of current context size
- Fixed plugin MCP servers stuck "connecting" on session start when they duplicate a claude.ai connector that is unauthenticated
- Improved Write tool diff computation speed for large files (60% faster on files with tabs/`&`/`$`)
- Removed `/tag` command
- Removed `/vim` command (toggle vim mode via `/config` → Editor mode)
- Linux sandbox now ships the `apply-seccomp` helper in both npm and native builds, restoring unix-socket blocking for sandboxed commands
### [`v2.1.90`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2190)
- Added `/powerup` — interactive lessons teaching Claude Code features with animated demos
- Added `CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE` env var to keep the existing marketplace cache when `git pull` fails, useful in offline environments
- Added `.husky` to protected directories (acceptEdits mode)
- Fixed an infinite loop where the rate-limit options dialog would repeatedly auto-open after hitting your usage limit, eventually crashing the session
- Fixed `--resume` causing a full prompt-cache miss on the first request for users with deferred tools, MCP servers, or custom agents (regression since v2.1.69)
- Fixed `Edit`/`Write` failing with "File content has changed" when a PostToolUse format-on-save hook rewrites the file between consecutive edits
- Fixed `PreToolUse` hooks that emit JSON to stdout and exit with code 2 not correctly blocking the tool call
- Fixed collapsed search/read summary badge appearing multiple times in fullscreen scrollback when a CLAUDE.md file auto-loads during a tool call
- Fixed auto mode not respecting explicit user boundaries ("don't push", "wait for X before Y") even when the action would otherwise be allowed
- Fixed click-to-expand hover text being nearly invisible on light terminal themes
- Fixed UI crash when malformed tool input reached the permission dialog
- Fixed headers disappearing when scrolling `/model`, `/config`, and other selection screens
- Hardened PowerShell tool permission checks: fixed trailing `&` background job bypass, `-ErrorAction Break` debugger hang, archive-extraction TOCTOU, and parse-fail fallback deny-rule degradation
- Improved performance: eliminated per-turn JSON.stringify of MCP tool schemas on cache-key lookup
- Improved performance: SSE transport now handles large streamed frames in linear time (was quadratic)
- Improved performance: SDK sessions with long conversations no longer slow down quadratically on transcript writes
- Improved `/resume` all-projects view to load project sessions in parallel, improving load times for users with many projects
- Changed `--resume` picker to no longer show sessions created by `claude -p` or SDK invocations
- Removed `Get-DnsClientCache` and `ipconfig /displaydns` from auto-allow (DNS cache privacy)
### [`v2.1.89`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2189)
- Added `"defer"` permission decision to `PreToolUse` hooks — headless sessions can pause at a tool call and resume with `-p --resume` to have the hook re-evaluate
- Added `CLAUDE_CODE_NO_FLICKER=1` environment variable to opt into flicker-free alt-screen rendering with virtualized scrollback
- Added `PermissionDenied` hook that fires after auto mode classifier denials — return `{retry: true}` to tell the model it can retry
- Added named subagents to `@` mention typeahead suggestions
- Added `MCP_CONNECTION_NONBLOCKING=true` for `-p` mode to skip the MCP connection wait entirely, and bounded `--mcp-config` server connections at 5s instead of blocking on the slowest server
- Auto mode: denied commands now show a notification and appear in `/permissions` → Recent tab where you can retry with `r`
- Fixed `Edit(//path/**)` and `Read(//path/**)` allow rules to check the resolved symlink target, not just the requested path
- Fixed voice push-to-talk not activating for some modifier-combo bindings, and voice mode on Windows failing with "WebSocket upgrade rejected with HTTP 101"
- Fixed Edit/Write tools doubling CRLF on Windows and stripping Markdown hard line breaks (two trailing spaces)
- Fixed `StructuredOutput` schema cache bug causing \~50% failure rate when using multiple schemas
- Fixed memory leak where large JSON inputs were retained as LRU cache keys in long-running sessions
- Fixed a crash when removing a message from very large session files (over 50MB)
- Fixed LSP server zombie state after crash — server now restarts on next request instead of failing until session restart
- Fixed prompt history entries containing CJK or emoji being silently dropped when they fall on a 4KB boundary in `~/.claude/history.jsonl`
- Fixed `/stats` undercounting tokens by excluding subagent usage, and losing historical data beyond 30 days when the stats cache format changes
- Fixed `-p --resume` hangs when the deferred tool input exceeds 64KB or no deferred marker exists, and `-p --continue` not resuming deferred tools
- Fixed `claude-cli://` deep links not opening on macOS
- Fixed MCP tool errors truncating to only the first content block when the server returns multi-element error content
- Fixed skill reminders and other system context being dropped when sending messages with images via the SDK
- Fixed PreToolUse/PostToolUse hooks to receive `file_path` as an absolute path for Write/Edit/Read tools, matching the documented behavior
- Fixed autocompact thrash loop — now detects when context refills to the limit immediately after compacting three times in a row and stops with an actionable error instead of burning API calls
- Fixed prompt cache misses in long sessions caused by tool schema bytes changing mid-session
- Fixed nested CLAUDE.md files being re-injected dozens of times in long sessions that read many files
- Fixed `--resume` crash when transcript contains a tool result from an older CLI version or interrupted write
- Fixed misleading "Rate limit reached" message when the API returned an entitlement error — now shows the actual error with actionable hints
- Fixed hooks `if` condition filtering not matching compound commands (`ls && git push`) or commands with env-var prefixes (`FOO=bar git push`)
- Fixed collapsed search/read group badges duplicating in terminal scrollback during heavy parallel tool use
- Fixed notification `invalidates` not clearing the currently-displayed notification immediately
- Fixed prompt briefly disappearing after submit when background messages arrived during processing
- Fixed Devanagari and other combining-mark text being truncated in assistant output
- Fixed rendering artifacts on main-screen terminals after layout shifts
- Fixed voice mode failing to request microphone permission on macOS Apple Silicon
- Fixed Shift+Enter submitting instead of inserting a newline on Windows Terminal Preview 1.25
- Fixed periodic UI jitter during streaming in iTerm2 when running inside tmux
- Fixed PowerShell tool incorrectly reporting failures when commands like `git push` wrote progress to stderr on Windows PowerShell 5.1
- Fixed a potential out-of-memory crash when the Edit tool was used on very large files (>1 GiB)
- Improved collapsed tool summary to show "Listed N directories" for `ls`/`tree`/`du` instead of "Read N files"
- Improved Bash tool to warn when a formatter/linter command modifies files you have previously read, preventing stale-edit errors
- Improved `@`-mention typeahead to rank source files above MCP resources with similar names
- Improved PowerShell tool prompt with version-appropriate syntax guidance (5.1 vs 7+)
- Changed `Edit` to work on files viewed via `Bash` with `sed -n` or `cat`, without requiring a separate `Read` call first
- Changed hook output over 10,000 characters to be saved to disk with a file path + a 2,000-character preview instead of being injected directly into context
- Changed `cleanupPeriodDays: 0` in settings.json to be rejected with a validation error — it previously silently disabled transcript persistence
- Changed thinking summaries to no longer be generated by default in interactive sessions — set `showThinkingSummaries: true` in settings.json to restore
- Documented `TaskCreated` hook event and its blocking behavior
- Preserved task notifications when backgrounding a running command with Ctrl+B
- PowerShell tool on Windows: external-command arguments containing both a double-quote and whitespace now prompt instead of auto-allowing (PS 5.1 argument-splitting hardening)
- `/env` now applies to PowerShell tool commands (previously only affected Bash)
- `/usage` now hides redundant "Current week (Sonnet only)" bar for Pro and Enterprise plans
- Image paste no longer inserts a trailing space
- Pasting `!command` into an empty prompt now enters bash mode, matching typed `!` behavior
- `/buddy` is here for April 1st — hatch a small creature that watches you code
### [`v2.1.87`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2187)
- Fixed messages in Cowork Dispatch not getting delivered
### [`v2.1.86`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2186)
- Added `X-Claude-Code-Session-Id` header to API requests so proxies can aggregate requests by session without parsing the body
- Added `.jj` and `.sl` to VCS directory exclusion lists so Grep and file autocomplete don't descend into Jujutsu or Sapling metadata
- Fixed `--resume` failing with "tool\_use ids were found without tool\_result blocks" on sessions created before v2.1.85
- Fixed Write/Edit/Read failing on files outside the project root (e.g., `~/.claude/CLAUDE.md`) when conditional skills or rules are configured
- Fixed unnecessary config disk writes on every skill invocation that could cause performance issues and config corruption on Windows
- Fixed potential out-of-memory crash when using `/feedback` on very long sessions with large transcript files
- Fixed `--bare` mode dropping MCP tools in interactive sessions and silently discarding messages enqueued mid-turn
- Fixed the `c` shortcut copying only \~20 characters of the OAuth login URL instead of the full URL
- Fixed masked input (e.g., OAuth code paste) leaking the start of the token when wrapping across multiple lines on narrow terminals
- Fixed official marketplace plugin scripts failing with "Permission denied" on macOS/Linux since v2.1.83
- Fixed statusline showing another session's model when running multiple Claude Code instances and using `/model` in one of them
- Fixed scroll not following new messages after wheel scroll or click-to-select at the bottom of a long conversation
- Fixed `/plugin` uninstall dialog: pressing `n` now correctly uninstalls the plugin while preserving its data directory
- Fixed a regression where pressing Enter after clicking could leave the transcript blank until the response arrived
- Fixed `ultrathink` hint lingering after deleting the keyword
- Fixed memory growth in long sessions from markdown/highlight render caches retaining full content strings
- Reduced startup event-loop stalls when many claude.ai MCP connectors are configured (macOS keychain cache extended from 5s to 30s)
- Reduced token overhead when mentioning files with `@` — raw string content no longer JSON-escaped
- Improved prompt cache hit rate for Bedrock, Vertex, and Foundry users by removing dynamic content from tool descriptions
- Memory filenames in the "Saved N memories" notice now highlight on hover and open on click
- Skill descriptions in the `/skills` listing are now capped at 250 characters to reduce context usage
- Changed `/skills` menu to sort alphabetically for easier scanning
- Auto mode now shows "unavailable for your plan" when disabled by plan restrictions (was "temporarily unavailable")
- \[VSCode] Fixed extension incorrectly showing "Not responding" during long-running operations
- \[VSCode] Fixed extension defaulting Max plan users to Sonnet after the OAuth token refreshes (8 hours after login)
- Read tool now uses compact line-number format and deduplicates unchanged re-reads, reducing token usage
### [`v2.1.84`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2184)
- Added PowerShell tool for Windows as an opt-in preview. Learn more at <https://code.claude.com/docs/en/tools-reference#powershell-tool>
- Added `ANTHROPIC_DEFAULT_{OPUS,SONNET,HAIKU}_MODEL_SUPPORTS` env vars to override effort/thinking capability detection for pinned default models for 3p (Bedrock, Vertex, Foundry), and `_MODEL_NAME`/`_DESCRIPTION` to customize the `/model` picker label
- Added `CLAUDE_STREAM_IDLE_TIMEOUT_MS` env var to configure the streaming idle watchdog threshold (default 90s)
- Added `TaskCreated` hook that fires when a task is created via `TaskCreate`
- Added `WorktreeCreate` hook support for `type: "http"` — return the created worktree path via `hookSpecificOutput.worktreePath` in the response JSON
- Added `allowedChannelPlugins` managed setting for team/enterprise admins to define a channel plugin allowlist
- Added `x-client-request-id` header to API requests for debugging timeouts
- Added idle-return prompt that nudges users returning after 75+ minutes to `/clear`, reducing unnecessary token re-caching on stale sessions
- Deep links (`claude-cli://`) now open in your preferred terminal instead of whichever terminal happens to be first in the detection list
- Rules and skills `paths:` frontmatter now accepts a YAML list of globs
- MCP tool descriptions and server instructions are now capped at 2KB to prevent OpenAPI-generated servers from bloating context
- MCP servers configured both locally and via claude.ai connectors are now deduplicated — the local config wins
- Background bash tasks that appear stuck on an interactive prompt now surface a notification after \~45 seconds
- Token counts ≥1M now display as "1.5m" instead of "1512.6k"
- Global system-prompt caching now works when `ToolSearch` is enabled, including for users with MCP tools configured
- Fixed voice push-to-talk: holding the voice key no longer leaks characters into the text input, and transcripts now insert at the correct position
- Fixed up/down arrow keys being unresponsive when a footer item is focused
- Fixed `Ctrl+U` (kill-to-line-start) being a no-op at line boundaries in multiline input, so repeated `Ctrl+U` now clears across lines
- Fixed null-unbinding a default chord binding (e.g. `"ctrl+x ctrl+k": null`) still entering chord-wait mode instead of freeing the prefix key
- Fixed mouse events inserting literal "mouse" text into transcript search input
- Fixed workflow subagents failing with API 400 when the outer session uses `--json-schema` and the subagent also specifies a schema
- Fixed missing background color behind certain emoji in user message bubbles on some terminals
- Fixed the "allow Claude to edit its own settings for this session" permission option not sticking for users with `Edit(.claude)` allow rules
- Fixed a hang when generating attachment snippets for large edited files
- Fixed MCP tool/resource cache leak on server reconnect
- Fixed a startup performance issue where partial clone repositories (Scalar/GVFS) triggered mass blob downloads
- Fixed native terminal cursor not tracking the text input caret, so IME composition (CJK input) now renders inline and screen readers can follow the input position
- Fixed spurious "Not logged in" errors on macOS caused by transient keychain read failures
- Fixed cold-start race where core tools could be deferred without their bypass active, causing Edit/Write to fail with InputValidationError on typed parameters
- Improved detection for dangerous removals of Windows drive roots (`C:\`, `C:\Windows`, etc.)
- Improved interactive startup by \~30ms by running `setup()` in parallel with slash command and agent loading
- Improved startup for `claude "prompt"` with MCP servers — the REPL now renders immediately instead of blocking until all servers connect
- Improved Remote Control to show a specific reason when blocked instead of a generic "not yet enabled" message
- Improved p90 prompt cache rate
- Reduced scroll-to-top resets in long sessions by making the message window immune to compaction and grouping changes
- Reduced terminal flickering when animated tool progress scrolls above the viewport
- Changed issue/PR references to only become clickable links when written as `owner/repo#123` — bare `#123` is no longer auto-linked
- Slash commands unavailable for the current auth setup (`/voice`, `/mobile`, `/chrome`, `/upgrade`, etc.) are now hidden instead of shown
- \[VSCode] Added rate limit warning banner with usage percentage and reset time
- Stats screenshot (Ctrl+S in /stats) now works in all builds and is 16× faster
### [`v2.1.81`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2181)
- Added `--bare` flag for scripted `-p` calls — skips hooks, LSP, plugin sync, and skill directory walks; requires `ANTHROPIC_API_KEY` or an `apiKeyHelper` via `--settings` (OAuth and keychain auth disabled); auto-memory fully disabled
- Added `--channels` permission relay — channel servers that declare the permission capability can forward tool approval prompts to your phone
- Fixed multiple concurrent Claude Code sessions requiring repeated re-authentication when one session refreshes its OAuth token
- Fixed voice mode silently swallowing retry failures and showing a misleading "check your network" message instead of the actual error
- Fixed voice mode audio not recovering when the server silently drops the WebSocket connection
- Fixed `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` not suppressing the structured-outputs beta header, causing 400 errors on proxy gateways forwarding to Vertex/Bedrock
- Fixed `--channels` bypass for Team/Enterprise orgs with no other managed settings configured
- Fixed a crash on Node.js 18
- Fixed unnecessary permission prompts for Bash commands containing dashes in strings
- Fixed plugin hooks blocking prompt submission when the plugin directory is deleted mid-session
- Fixed a race condition where background agent task output could hang indefinitely when the task completed between polling intervals
- Resuming a session that was in a worktree now switches back to that worktree
- Fixed `/btw` not including pasted text when used during an active response
- Fixed a race where fast Cmd+Tab followed by paste could beat the clipboard copy under tmux
- Fixed terminal tab title not updating with an auto-generated session description
- Fixed invisible hook attachments inflating the message count in transcript mode
- Fixed Remote Control sessions showing a generic title instead of deriving from the first prompt
- Fixed `/rename` not syncing the title for Remote Control sessions
- Fixed Remote Control `/exit` not reliably archiving the session
- Improved MCP read/search tool calls to collapse into a single "Queried {server}" line (expand with Ctrl+O)
- Improved `!` bash mode discoverability — Claude now suggests it when you need to run an interactive command
- Improved plugin freshness — ref-tracked plugins now re-clone on every load to pick up upstream changes
- Improved Remote Control session titles to refresh after your third message
- Updated MCP OAuth to support Client ID Metadata Document (CIMD / SEP-991) for servers without Dynamic Client Registration
- Changed plan mode to hide the "clear context" option by default (restore with `"showClearContextOnPlanAccept": true`)
- Disabled line-by-line response streaming on Windows (including WSL in Windows Terminal) due to rendering issues
- \[VSCode] Fixed Windows PATH inheritance for Bash tool when using Git Bash (regression in v2.1.78)
### [`v2.1.80`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2180)
- Added `rate_limits` field to statusline scripts for displaying Claude.ai rate limit usage (5-hour and 7-day windows with `used_percentage` and `resets_at`)
- Added `source: 'settings'` plugin marketplace source — declare plugin entries inline in settings.json
- Added CLI tool usage detection to plugin tips, in addition to file pattern matching
- Added `effort` frontmatter support for skills and slash commands to override the model effort level when invoked
- Added `--channels` (research preview) — allow MCP servers to push messages into your session
- Fixed `--resume` dropping parallel tool results — sessions with parallel tool calls now restore all tool\_use/tool\_result pairs instead of showing `[Tool result missing]` placeholders
- Fixed voice mode WebSocket failures caused by Cloudflare bot detection on non-browser TLS fingerprints
- Fixed 400 errors when using fine-grained tool streaming through API proxies, Bedrock, or Vertex
- Fixed `/remote-control` appearing for gateway and third-party provider deployments where it cannot function
- Fixed `/sandbox` tab switching not responding to Tab or arrow keys
- Improved responsiveness of `@` file autocomplete in large git repositories
- Improved `/effort` to show what auto currently resolves to, matching the status bar indicator
- Improved `/permissions` — Tab and arrow keys now switch tabs from within a list
- Improved background tasks panel — left arrow now closes from the list view
- Simplified plugin install tips to use a single `/plugin install` command instead of a two-step flow
- Reduced memory usage on startup in large repositories (\~80 MB saved on 250k-file repos)
- Fixed managed settings (`enabledPlugins`, `permissions.defaultMode`, policy-set env vars) not being applied at startup when `remote-settings.json` was cached from a prior session
### [`v2.1.77`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2177)
- Increased default maximum output token limits for Claude Opus 4.6 to 64k tokens, and the upper bound for Opus 4.6 and Sonnet 4.6 models to 128k tokens
- Added `allowRead` sandbox filesystem setting to re-allow read access within `denyRead` regions
- `/copy` now accepts an optional index: `/copy N` copies the Nth-latest assistant response
- Fixed "Always Allow" on compound bash commands (e.g. `cd src && npm test`) saving a single rule for the full string instead of per-subcommand, leading to dead rules and repeated permission prompts
- Fixed auto-updater starting overlapping binary downloads when the slash-command overlay repeatedly opened and closed, accumulating tens of gigabytes of memory
- Fixed `--resume` silently truncating recent conversation history due to a race between memory-extraction writes and the main transcript
- Fixed PreToolUse hooks returning `"allow"` bypassing `deny` permission rules, including enterprise managed settings
- Fixed Write tool silently converting line endings when overwriting CRLF files or creating files in CRLF directories
- Fixed memory growth in long-running sessions from progress messages surviving compaction
- Fixed cost and token usage not being tracked when the API falls back to non-streaming mode
- Fixed `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` not stripping beta tool-schema fields, causing proxy gateways to reject requests
- Fixed Bash tool reporting errors for successful commands when the system temp directory path contains spaces
- Fixed paste being lost when typing immediately after pasting
- Fixed Ctrl+D in `/feedback` text input deleting forward instead of the second press exiting the session
- Fixed API error when dragging a 0-byte image file into the prompt
- Fixed Claude Desktop sessions incorrectly using the terminal CLI's configured API key instead of OAuth
- Fixed `git-subdir` plugins at different subdirectories of the same monorepo commit colliding in the plugin cache
- Fixed ordered list numbers not rendering in terminal UI
- Fixed a race condition where stale-worktree cleanup could delete an agent worktree just resumed from a previous crash
- Fixed input deadlock when opening `/mcp` or similar dialogs while the agent is running
- Fixed Backspace and Delete keys not working in vim NORMAL mode
- Fixed status line not updating when vim mode is toggled on or off
- Fixed hyperlinks opening twice on Cmd+click in VS Code, Cursor, and other xterm.js-based terminals
- Fixed background colors rendering as terminal-default inside tmux with default configuration
- Fixed iTerm2 session crash when selecting text inside tmux over SSH
- Fixed clipboard copy silently failing in tmux sessions; copy toast now indicates whether to paste with `⌘V` or tmux `prefix+]`
- Fixed `←`/`→` accidentally switching tabs in settings, permissions, and sandbox dialogs while navigating lists
- Fixed IDE integration not auto-connecting when Claude Code is launched inside tmux or screen
- Fixed CJK characters visually bleeding into adjacent UI elements when clipped at the right edge
- Fixed teammate panes not closing when the leader exits
- Fixed iTerm2 auto mode not detecting iTerm2 for native split-pane teammates
- Faster startup on macOS (\~60ms) by reading keychain credentials in parallel with module loading
- Faster `--resume` on fork-heavy and very large sessions — up to 45% faster loading and \~100-150MB less peak memory
- Improved Esc to abort in-flight non-streaming API requests
- Improved `claude plugin validate` to check skill, agent, and command frontmatter plus `hooks/hooks.json`, catching YAML parse errors and schema violations
- Background bash tasks are now killed if output exceeds 5GB, preventing runaway processes from filling disk
- Sessions are now auto-named from plan content when you accept a plan
- Improved headless mode plugin installation to compose correctly with `CLAUDE_CODE_PLUGIN_SEED_DIR`
- Show a notice when `apiKeyHelper` takes longer than 10s, preventing it from blocking the main loop
- The Agent tool no longer accepts a `resume` parameter — use `SendMessage({to: agentId})` to continue a previously spawned agent
- `SendMessage` now auto-resumes stopped agents in the background instead of returning an error
- Renamed `/fork` to `/branch` (`/fork` still works as an alias)
- \[VSCode] Improved plan preview tab titles to use the plan's heading instead of "Claude's Plan"
- \[VSCode] When option+click doesn't trigger native selection on macOS, the footer now points to the `macOptionClickForcesSelection` setting
### [`v2.1.76`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2176)
- Added MCP elicitation support — MCP servers can now request structured input mid-task via an interactive dialog (form fields or browser URL)
- Added new `Elicitation` and `ElicitationResult` hooks to intercept and override responses before they're sent back
- Added `-n` / `--name <name>` CLI flag to set a display name for the session at startup
- Added `worktree.sparsePaths` setting for `claude --worktree` in large monorepos to check out only the directories you need via git sparse-checkout
- Added `PostCompact` hook that fires after compaction completes
- Added `/effort` slash command to set model effort level
- Added session quality survey — enterprise admins can configure the sample rate via the `feedbackSurveyRate` setting
- Fixed deferred tools (loaded via `ToolSearch`) losing their input schemas after conversation compaction, causing array and number parameters to be rejected with type errors
- Fixed slash commands showing "Unknown skill"
- Fixed plan mode asking for re-approval after the plan was already accepted
- Fixed voice mode swallowing keypresses while a permission dialog or plan editor was open
- Fixed `/voice` not working on Windows when installed via npm
- Fixed spurious "Context limit reached" when invoking a skill with `model:` frontmatter on a 1M-context session
- Fixed "adaptive thinking is not supported on this model" error when using non-standard model strings
- Fixed `Bash(cmd:*)` permission rules not matching when a quoted argument contains `#`
- Fixed "don't ask again" in the Bash permission dialog showing the full raw command for pipes and compound commands
- Fixed auto-compaction retrying indefinitely after consecutive failures — a circuit breaker now stops after 3 attempts
- Fixed MCP reconnect spinner persisting after successful reconnection
- Fixed LSP plugins not registering servers when the LSP Manager initialized before marketplaces were reconciled
- Fixed clipboard copying in tmux over SSH — now attempts both direct terminal write and tmux clipboard integration
- Fixed `/export` showing only the filename instead of the full file path in the success message
- Fixed transcript not auto-scrolling to new messages after selecting text
- Fixed Escape key not working to exit the login method selection screen
- Fixed several Remote Control issues: sessions silently dying when the server reaps an idle environment, rapid messages being queued one-at-a-time instead of batched, and stale work items causing redelivery after JWT refresh
- Fixed bridge sessions failing to recover after extended WebSocket disconnects
- Fixed slash commands not found when typing the exact name of a soft-hidden command
- Improved `--worktree` startup performance by reading git refs directly and skipping redundant `git fetch` when the remote branch is already available locally
- Improved background agent behavior — killing a background agent now preserves its partial results in the conversation context
- Improved model fallback notifications — now always visible instead of hidden behind verbose mode, with human-friendly model names
- Improved blockquote readability on dark terminal themes — text is now italic with a left bar instead of dim
- Improved stale worktree cleanup — worktrees left behind after an interrupted parallel run are now automatically cleaned up
- Improved Remote Control session titles — now derived from your first prompt instead of showing "Interactive session"
- Improved `/voice` to show your dictation language on enable and warn when your `language` setting isn't supported for voice input
- Updated `--plugin-dir` to only accept one path to support subcommands — use repeated `--plugin-dir` for multiple directories
- \[VSCode] Fixed gitignore patterns containing commas silently excluding entire filetypes from the @​-mention file picker
### [`v2.1.74`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2174)
- Added actionable suggestions to `/context` command — identifies context-heavy tools, memory bloat, and capacity warnings with specific optimization tips
- Added `autoMemoryDirectory` setting to configure a custom directory for auto-memory storage
- Fixed memory leak where streaming API response buffers were not released when the generator was terminated early, causing unbounded RSS growth on the Node.js/npm code path
- Fixed managed policy `ask` rules being bypassed by user `allow` rules or skill `allowed-tools`
- Fixed full model IDs (e.g., `claude-opus-4-5`) being silently ignored in agent frontmatter `model:` field and `--agents` JSON config — agents now accept the same model values as `--model`
- Fixed MCP OAuth authentication hanging when the callback port is already in use
- Fixed MCP OAuth refresh never prompting for re-auth after the refresh token expires, for OAuth servers that return errors with HTTP 200 (e.g. Slack)
- Fixed voice mode silently failing on the macOS native binary for users whose terminal had never been granted microphone permission — the binary now includes the `audio-input` entitlement so macOS prompts correctly
- Fixed `SessionEnd` hooks being killed after 1.5 s on exit regardless of `hook.timeout` — now configurable via `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS`
- Fixed `/plugin install` failing inside the REPL for marketplace plugins with local sources
- Fixed marketplace update not syncing git submodules — plugin sources in submodules no longer break after update
- Fixed unknown slash commands with arguments silently dropping input — now shows your input as a warning
- Fixed Hebrew, Arabic, and other RTL text not rendering correctly in Windows Terminal, conhost, and VS Code integrated terminal
- Fixed LSP servers not working on Windows due to malformed file URIs
- Changed `--plugin-dir` so local dev copies now override installed marketplace plugins with the same name (unless that plugin is force-enabled by managed settings)
- \[VSCode] Fixed delete button not working for Untitled sessions
- \[VSCode] Improved scroll wheel responsiveness in the integrated terminal with terminal-aware acceleration
### [`v2.1.70`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2170)
- Fixed API 400 errors when using `ANTHROPIC_BASE_URL` with a third-party gateway — tool search now correctly detects proxy endpoints and disables `tool_reference` blocks
- Fixed `API Error: 400 This model does not support the effort parameter` when using custom Bedrock inference profiles or other model identifiers not matching standard Claude naming patterns
- Fixed empty model responses immediately after `ToolSearch` — the server renders tool schemas with system-prompt-style tags at the prompt tail, which could confuse models into stopping early
- Fixed prompt-cache bust when an MCP server with `instructions` connects after the first turn
- Fixed Enter inserting a newline instead of submitting when typing over a slow SSH connection
- Fixed clipboard corrupting non-ASCII text (CJK, emoji) on Windows/WSL by using PowerShell `Set-Clipboard`
- Fixed extra VS Code windows opening at startup on Windows when running from the VS Code integrated terminal
- Fixed voice mode failing on Windows native binary with "native audio module could not be loaded"
- Fixed push-to-talk not activating on session start when `voiceEnabled: true` was set in settings
- Fixed markdown links containing `#NNN` references incorrectly pointing to the current repository instead of the linked URL
- Fixed repeated "Model updated to Opus 4.6" notification when a project's `.claude/settings.json` has a legacy Opus model string pinned
- Fixed plugins showing as inaccurately installed in `/plugin`
- Fixed plugins showing "not found in marketplace" errors on fresh startup by auto-refreshing after marketplace installation
- Fixed `/security-review` command failing with `unknown option merge-base` on older git versions
- Fixed `/color` command having no way to reset back to the default color — `/color default`, `/color gray`, `/color reset`, and `/color none` now restore the default
- Fixed a performance regression in the `AskUserQuestion` preview dialog that re-ran markdown rendering on every keystroke in the notes input
- Fixed feature flags read during early startup never refreshing their disk cache, causing stale values to persist across sessions
- Fixed `permissions.defaultMode` settings values other than `acceptEdits` or `plan` being applied in Claude Code Remote environments — they are now ignored
- Fixed skill listing being re-injected on every `--resume` (\~600 tokens saved per resume)
- Fixed teleport marker not rendering in VS Code teleported sessions
- Improved error message when microphone captures silence to distinguish from "no speech detected"
- Improved compaction to preserve images in the summarizer request, allowing prompt cache reuse for faster and cheaper compaction
- Improved `/rename` to work while Claude is processing, instead of being silently queued
- Reduced prompt input re-renders during turns by \~74%
- Reduced startup memory by \~426KB for users without custom CA certificates
- Reduced Remote Control `/poll` rate to once per 10 minutes while connected (was 1–2s), cutting server load \~300×. Reconnection is unaffected — transport loss immediately wakes fast polling.
- \[VSCode] Added spark icon in VS Code activity bar that lists all Claude Code sessions, with sessions opening as full editors
- \[VSCode] Added full markdown document view for plans in VS Code, with support for adding comments to provide feedback
- \[VSCode] Added native MCP server management dialog — use `/mcp` in the chat panel to enable/disable servers, reconnect, and manage OAuth authentication without switching to the terminal
### [`v2.1.66`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2166)
- Reduced spurious error logging
### [`v2.1.59`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2159)
- Claude automatically saves useful context to auto-memory. Manage with /memory
- Added `/copy` command to show an interactive picker when code blocks are present, allowing selection of individual code blocks or the full response.
- Improved "always allow" prefix suggestions for compound bash commands (e.g. `cd /tmp && git fetch && git push`) to compute smarter per-subcommand prefixes instead of treating the whole command as one
- Improved ordering of short task lists
- Improved memory usage in multi-agent sessions by releasing completed subagent task state
- Fixed MCP OAuth token refresh race condition when running multiple Claude Code instances simultaneously
- Fixed shell commands not showing a clear error message when the working directory has been deleted
- Fixed config file corruption that could wipe authentication when multiple Claude Code instances ran simultaneously
### [`v2.1.50`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2150)
- Added support for `startupTimeout` configuration for LSP servers
- Added `WorktreeCreate` and `WorktreeRemove` hook events, enabling custom VCS setup and teardown when agent worktree isolation creates or removes worktrees.
- Fixed a bug where resumed sessions could be invisible when the working directory involved symlinks, because the session storage path was resolved at different times during startup. Also fixed session data loss on SSH disconnect by flushing session data before hooks and analytics in the graceful shutdown sequence.
- Linux: Fixed native modules not loading on systems with glibc older than 2.30 (e.g., RHEL 8)
- Fixed memory leak in agent teams where completed teammate tasks were never garbage collected from session state
- Fixed `CLAUDE_CODE_SIMPLE` to fully strip down skills, session memory, custom agents, and CLAUDE.md token counting
- Fixed `/mcp reconnect` freezing the CLI when given a server name that doesn't exist
- Fixed memory leak where completed task state objects were never removed from AppState
- Added support for `isolation: worktree` in agent definitions, allowing agents to declaratively run in isolated git worktrees.
- `CLAUDE_CODE_SIMPLE` mode now also disables MCP tools, attachments, hooks, and CLAUDE.md file loading for a fully minimal experience.
- Fixed bug where MCP tools were not discovered when tool search is enabled and a prompt is passed in as a launch argument
- Improved memory usage during long sessions by clearing internal caches after compaction
- Added `claude agents` CLI command to list all configured agents
- Improved memory usage during long sessions by clearing large tool results after they have been processed
- Fixed a memory leak where LSP diagnostic data was never cleaned up after delivery, causing unbounded memory growth in long sessions
- Fixed a memory leak where completed task output was not freed from memory, reducing memory usage in long sessions with many tasks
- Improved startup performance for headless mode (`-p` flag) by deferring Yoga WASM and UI component imports
- Fixed prompt suggestion cache regression that reduced cache hit rates
- Fixed unbounded memory growth in long sessions by capping file history snapshots
- Added `CLAUDE_CODE_DISABLE_1M_CONTEXT` environment variable to disable 1M context window support
- Opus 4.6 (fast mode) now includes the full 1M context window
- VSCode: Added `/extra-usage` command support in VS Code sessions
- Fixed memory leak where TaskOutput retained recent lines after cleanup
- Fixed memory leak in CircularBuffer where cleared items were retained in the backing array
- Fixed memory leak in shell command execution where ChildProcess and AbortController references were retained after cleanup
### [`v2.1.39`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2139)
- Improved terminal rendering performance
- Fixed fatal errors being swallowed instead of displayed
- Fixed process hanging after session close
- Fixed character loss at terminal screen boundary
- Fixed blank lines in verbose transcript view
### [`v2.1.37`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2137)
- Fixed an issue where /fast was not immediately available after enabling /extra-usage
### [`v2.1.34`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2134)
- Fixed a crash when agent teams setting changed between renders
- Fixed a bug where commands excluded from sandboxing (via `sandbox.excludedCommands` or `dangerouslyDisableSandbox`) could bypass the Bash ask permission rule when `autoAllowBashIfSandboxed` was enabled
### [`v2.1.25`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21259)
- Added `managedMcpServers` managed setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as `.mcp.json`); entries that name a command to run are skipped
- Added `--permission-prompts none` for unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps deciding
- Added recognition of `glab mr create/merge/close/reopen/note/update` so GitLab merge requests show as `MR !N` in the collapsed tool summary and refresh the footer MR badge
- Added `--json` to `claude plugin validate` for a machine-readable validation report
- Fixed concurrent sessions silently reverting each other's `~/.claude.json` changes — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at once
- Fixed a conversation whose thinking was rejected once being rejected again on every later turn
- Fixed Bash `Read()` deny rules not covering files given as option values (`--ignore-revs-file=.env`, `-f.env`, `@file`), `git diff`/`git grep` file operands, or `cd DIR && cat FILE` compounds; `grep -r`/`cp -r` over a directory holding a denied file now asks
- Fixed the prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled
- Fixed fullscreen mode showing a blank conversation after a long turn with hundreds of tool calls
- Fixed auto mode running a turn on a model it doesn't support when a command or skill's frontmatter `model:` named one; the turn now keeps the session model
- Fixed `CLAUDE_CODE_MAX_CONTEXT_TOKENS` being ignored for Vertex-style model IDs (`@YYYYMMDD` suffix) of model versions Claude Code doesn't recognize
- Fixed the live output preview of a running shell command hiding its newest lines when an earlier line wrapped
- Fixed a background GitHub connection check that ran on every launch for claude.ai users; the result is now remembered across launches
- Fixed `--resume` failing (and `--continue` opening an empty conversation) when a saved session contains an attachment entry with no payload
- Fixed frontmatter `model:` on custom commands and skills being ignored in interactive sessions
- Fixed Artifact publishing failing once with an "unexpected parameter `note`" error in conversations continued from an older version
- Fixed managed `forceRemoteSettingsRefresh` being ignored at startup when a policy helper configured by MDM or the managed settings file had already run
- Fixed worktree isolation refusing hook-created worktrees on machines where `git rev-parse` fails with a message other than "not a git repository"
- Fixed OpenTelemetry metrics and events from cloud sessions missing the `user.email`, `organization.id`, and `user.account_uuid` attributes
- Fixed MCP servers that disconnect while their tools are being listed at startup showing as connected with no tools instead of reporting the error
- Fixed the file edit permission dialog sometimes showing a changed line cut short with no indication
- Fixed repository detection dropping a known repo identity after a transient git probe failure
- Fixed managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value cannot be parsed: Claude Code now refuses to start and names the source
- Fixed Stop not actually stopping background agents and workflows in remote-control sessions: killed tasks now stay visible and re-stoppable until their processes exit
- Fixed resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents
- Fixed marketplace repo URLs on github.com with a trailing slash or dangling `?`/`#` producing an unusable `.git` clone URL
- Fixed blocking Stop hooks causing the turn after a block to lose the model's reasoning from that turn and, on some models, miss the prompt cache
- Fixed remote (claude.ai) sessions taking 60 seconds to start a turn after a browser-hosted MCP server's page had gone away
- Fixed worktree-isolated sessions refusing common Bash loops, xargs pipelines and launcher-wrapped commands that cannot reach the main checkout
- Improved terminal resize and first-render performance for long responses by reusing text measurements
- Improved `/workflows` agent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle
- Improved headless/SDK session start: the first turn begins up to 50 ms sooner when MCP servers finish connecting
- Improved `/install-github-app` to explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repository
- Improved nested background subagent results to be saved in the parent subagent's transcript, so resumed subagents keep them and shared transcripts show the delivery
- Changed `allowedMcpServers` to govern only servers users add: a literal `managed-mcp.json` server your allowlist used to filter out now loads on upgrade; use `deniedMcpServers` to keep it off
- \[VSCode] Added an Active quick filter and a status filter menu (Needs input, Working, Completed) to the session list sidebar
- Fixed remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused
### [`v2.1.20`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21209)
- Fixed /model and other dialogs being blocked in `claude agents` background sessions (reverts an overly broad guard)
### [`v2.1.19`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21199)
- Stacked slash-skill invocations like `/skill-a /skill-b do XYZ` now load all leading skills (up to 5), not just the first
- Fixed SSL certificate errors (TLS-inspecting proxies, missing `NODE_EXTRA_CA_CERTS`, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hint
- Fixed streaming responses being discarded when the API emits a mid-stream overloaded/server error after partial output — the partial is now kept with an incomplete-response notice
- Fixed subagents cut off by a rate limit or server error silently failing instead of returning their partial work to the parent
- Fixed subagents reporting API errors (e.g. usage limit reached) as successful results — the error is now reported to the parent agent
- Fixed the background-agent daemon on Linux killing itself and every running agent every \~50 seconds after an unclean shutdown left a corrupted worker record
- Fixed background agents failing to cold-start over SSH on macOS with "Could not switch to audit session" (regression in 2.1.196)
- Fixed `claude stop` being silently undone when it raced a background-agent respawn — the respawn now honors the stop
- Fixed background job progress indicators stalling for minutes while the job ran long commands
- Fixed background sessions on memory-starved machines showing a generic error — they now indicate low memory and suggest freeing resources
- Fixed remote sessions briefly flapping between Working and Idle in the agent view when a background agent completes
- Fixed idle subagents vanishing from the agent panel while other subagents were still working; surplus idle agents now collapse into an expandable summary row
- Fixed typing `/model` or `/fast` while viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the lead
- Fixed `SessionStart`, `Setup`, and `SubagentStart` hooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcript
- Fixed `claude --dangerously-skip-permissions daemon <subcommand>` being treated as a chat prompt instead of running the subcommand
- Fixed `SendMessage` silently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget
- Fixed opening or resuming a session with no new messages needlessly growing the transcript file
- Fixed backgrounding a session with `←` or `/background` dropping its `/color` from the agent view row
- Fixed resetting a corrupted config file from the startup recovery dialog destroying it unrecoverably — it now backs up the file first
- Fixed Claude in Chrome repeatedly opening the reconnect page when sessions run from different builds or config directories
- Fixed plan mode not prompting for state-changing browser tool calls; read-only `browser_batch` calls are now correctly auto-allowed
- Transient server rate-limit errors (429s unrelated to your usage limit) are now retried automatically with backoff for subscribers instead of failing the turn
- `CLAUDE_CODE_RETRY_WATCHDOG` now raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 on `CLAUDE_CODE_MAX_RETRIES`
- `claude agents` session rows now show pull-request links as bare `#N` without the redundant "PR" label
### [`v2.1.17`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21179)
- Fixed mid-stream connection drops: partial responses are now preserved instead of showing a raw error, and the spinner no longer gets stuck at "running tool"
- Fixed mouse-wheel scrolling in WSL2 under Windows Terminal and VS Code (regression in 2.1.172)
- Fixed a sandbox `denyRead`/`allowRead` glob over a large directory tree making the Bash tool description enormous and the session unusable on Linux
- Fixed the feedback survey capturing a single-digit reply as a session rating immediately after a turn completes
- Fixed the welcome screen stacking multiple promotional banners — at most one promo now shows per session
- Fixed Ctrl+O not showing the subagent's transcript when viewing a subagent
- Fixed clicking the prompt input not returning focus from the subagent/footer panel
- Fixed remote session background tasks appearing stuck as "still running" between turns
- Improved plugin loading performance in remote sessions
### [`v2.1.15`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21159)
- Internal infrastructure improvements (no user-facing changes)
### [`v2.1.12`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21129)
- Added `--plugin-url <url>` flag to fetch a plugin `.zip` archive from a URL for the current session
- Added `CLAUDE_CODE_FORCE_SYNC_OUTPUT=1` env var to force-enable synchronized output on terminals that auto-detection misses (e.g. Emacs `eat`)
- Added `CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE`: when set on Homebrew or WinGet installations, Claude Code runs the upgrade command in the background and prompts to restart
- Plugin manifests: `themes` and `monitors` should now be declared under `"experimental": { ... }`. Top-level declarations still work but `claude plugin validate` will warn
- Gateway `/v1/models` discovery for the `/model` picker is now opt-in via `CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1` (was automatic in 2.1.126–2.1.128)
- Ctrl+R history picker now defaults to searching all prompts across all projects, matching pre-2.1.124 behavior. Press Ctrl+S to narrow to the current project or session
- Third-party deployments (Bedrock, Vertex, Foundry, or `ANTHROPIC_BASE_URL` gateway) no longer see spinner tips pointing at first-party Anthropic surfaces
- `skillOverrides` setting now works: `off` hides from model and `/`, `user-invocable-only` hides from model only, `name-only` collapses description
- The `claude_code.pull_request.count` OTel metric now counts PRs/MRs created via MCP tools, not just shell commands
- Policy refusal error messages now include the API Request ID for easier support debugging
- Fixed API errors with unrecognized 400 status codes showing raw JSON instead of the underlying error message
- Fixed `/clear` not resetting the terminal tab title after a conversation
- Fixed session title chip from `/rename` disappearing while a permission or other dialog is active
- Fixed agent panel below the prompt being hidden when subagents are running (regression in 2.1.122)
- Fixed external-editor handoff (Ctrl+G) blanking the conversation history above the prompt
- Fixed `/context` dumping its rendered ASCII visualization grid into the conversation, wasting \~1.6k tokens per call
- Fixed `/agents` Library list arrow-key navigation: the highlighted agent now stays visible when the list exceeds the viewport
- Fixed `/branch` success message not including the new branch's session id for `/resume`
- Fixed bold headers with keycap/ZWJ/skin-tone emoji losing trailing characters in fullscreen mode
- Fixed server-managed settings policy not applying for enterprise/team users whose stored OAuth credentials lacked the `user:inference` scope
- Fixed OAuth refresh race after wake-from-sleep that could log out all running sessions
- Fixed 1-hour prompt cache TTL being silently downgraded to 5 minutes
- Fixed cache-miss warning appearing spuriously after `/clear` or compaction when changing `/effort` or `/model`
- Fixed `Bash(mkdir *)`, `Bash(touch *)` and similar allow rules not being honored for in-project paths
- Fixed `deniedMcpServers` patterns with a `*://` scheme wildcard not matching mixed-case hostnames
- Fixed harmless WebSocket warning being logged as an error in `--debug` during voice mode
- \[VSCode] Fixed `/clear` not clearing the conversation context and displayed transcript
### [`v2.1.9`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2198)
- Added interactive Google Vertex AI setup wizard accessible from the login screen when selecting "3rd-party platform", guiding you through GCP authentication, project and region configuration, credential verification, and model pinning
- Added `CLAUDE_CODE_PERFORCE_MODE` env var: when set, Edit/Write/NotebookEdit fail on read-only files with a `p4 edit` hint instead of silently overwriting them
- Added Monitor tool for streaming events from background scripts
- Added subprocess sandboxing with PID namespace isolation on Linux when `CLAUDE_CODE_SUBPROCESS_ENV_SCRUB` is set, and `CLAUDE_CODE_SCRIPT_CAPS` env var to limit per-session script invocations
- Added `--exclude-dynamic-system-prompt-sections` flag to print mode for improved cross-user prompt caching
- Added `workspace.git_worktree` to the status line JSON input, set whenever the current directory is inside a linked git worktree
- Added W3C `TRACEPARENT` env var to Bash tool subprocesses when OTEL tracing is enabled, so child-process spans correctly parent to Claude Code's trace tree
- LSP: Claude Code now identifies itself to language servers via `clientInfo` in the initialize request
- Fixed a Bash tool permission bypass where a backslash-escaped flag could be auto-allowed as read-only and lead to arbitrary code execution
- Fixed compound Bash commands bypassing forced permission prompts for safety checks and explicit ask rules in auto and bypass-permissions modes
- Fixed read-only commands with env-var prefixes not prompting unless the var is known-safe (`LANG`, `TZ`, `NO_COLOR`, etc.)
- Fixed redirects to `/dev/tcp/...` or `/dev/udp/...` not prompting instead of auto-allowing
- Fixed stalled streaming responses timing out instead of falling back to non-streaming mode
- Fixed 429 retries burning all attempts in \~13s when the server returns a small `Retry-After` — exponential backoff now applies as a minimum
- Fixed MCP OAuth `oauth.authServerMetadataUrl` config override not being honored on token refresh after restart, affecting ADFS and similar IdPs
- Fixed capital letters being dropped to lowercase on xterm and VS Code integrated terminal when the kitty keyboard protocol is active
- Fixed macOS text replacements deleting the trigger word instead of inserting the substitution
- Fixed `--dangerously-skip-permissions` being silently downgraded to accept-edits mode after approving a write to a protected path via Bash
- Fixed managed-settings allow rules remaining active after an admin removed them, until process restart
- Fixed `permissions.additionalDirectories` changes not applying mid-session — removed directories lose access immediately and added ones work without restart
- Fixed removing a directory from `additionalDirectories` revoking access to the same directory passed via `--add-dir`
- Fixed `Bash(cmd:*)` and `Bash(git commit *)` wildcard permission rules failing to match commands with extra spaces or tabs
- Fixed `Bash(...)` deny rules being downgraded to a prompt for piped commands that mix `cd` with other segments
- Fixed false Bash permission prompts for `cut -d /`, `paste -d /`, `column -s /`, `awk '{print $1}' file`, and filenames containing `%`
- Fixed permission rules with names matching JavaScript prototype properties (e.g. `toString`) causing `settings.json` to be silently ignored
- Fixed agent team members not inheriting the leader's permission mode when using `--dangerously-skip-permissions`
- Fixed a crash in fullscreen mode when hovering over MCP tool results
- Fixed copying wrapped URLs in fullscreen mode inserting spaces at line breaks
- Fixed file-edit diffs disappearing from the UI on `--resume` when the edited file was larger than 10KB
- Fixed several `/resume` picker issues: `--resume <name>` opening uneditable, filter reload wiping search state, empty list swallowing arrow keys, cross-project staleness, and transient task-status text replacing conversation summaries
- Fixed `/export` not honoring absolute paths and `~`, and silently rewriting user-supplied extensions to `.txt`
- Fixed `/effort max` being denied for unknown or future model IDs
- Fixed slash command picker breaking when a plugin's frontmatter `name` is a YAML boolean keyword
- Fixed rate-limit upsell text being hidden after message remounts
- Fixed MCP tools with `_meta["anthropic/maxResultSizeChars"]` not bypassing the token-based persist layer
- Fixed voice mode leaking dozens of space characters into the input when re-holding the push-to-talk key while the previous transcript is still processing
- Fixed `DISABLE_AUTOUPDATER` not fully suppressing the npm registry version check and symlink modification on npm-based installs
- Fixed a memory leak where Remote Control permission handler entries were retained for the lifetime of the session
- Fixed background subagents that fail with an error not reporting partial progress to the parent agent
- Fixed prompt-type Stop/SubagentStop hooks failing on long sessions, and hook evaluator API errors showing "JSON validation failed" instead of the real message
- Fixed feedback survey rendering when dismissed
- Fixed Bash `grep -f FILE` / `rg -f FILE` not prompting when reading a pattern file outside the working directory
- Fixed stale subagent worktree cleanup removing worktrees that contain untracked files
- Fixed `sandbox.network.allowMachLookup` not taking effect on macOS
- Improved `/resume` filter hint labels and added project/worktree/branch names in the filter indicator
- Improved footer indicators (Focus, notifications) to stay on the mode-indicator row instead of wrapping at narrow terminal widths
- Improved `/agents` with a tabbed layout: a Running tab shows live subagents, and the Library tab adds Run agent and View running instance actions
- Improved `/reload-plugins` to pick up plugin-provided skills without requiring a restart
- Improved Accept Edits mode to auto-approve filesystem commands prefixed with safe env vars or process wrappers
- Improved Vim mode: `j`/`k` in NORMAL mode now navigate history and select the footer pill at the input boundary
- Improved hook errors in the transcript to include the first line of stderr for self-diagnosis without `--debug`
- Improved OTEL tracing: interaction spans now correctly wrap full turns under concurrent SDK calls, and headless turns end spans per-turn
- Improved transcript entries to carry final token usage instead of streaming placeholders
- Updated the `/claude-api` skill to cover Managed Agents alongside Claude API
- \[VSCode] Fixed false-positive "requires git-bash" error on Windows when `CLAUDE_CODE_GIT_BASH_PATH` is set or Git is installed at a default location
- Fixed `CLAUDE_CODE_MAX_CONTEXT_TOKENS` to honor `DISABLE_COMPACT` when it is set.
- Dropped `/compact` hints when `DISABLE_COMPACT` is set.
### [`v2.1.7`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2179)
- Added `--console` flag to `claude auth login` for Anthropic Console (API billing) authentication
- Added "Show turn duration" toggle to the `/config` menu
- Fixed `claude -p` hanging when spawned as a subprocess without explicit stdin (e.g. Python `subprocess.run`)
- Fixed Ctrl+C not working in `-p` (print) mode
- Fixed `/btw` returning the main agent's output instead of answering the side question when triggered during streaming
- Fixed voice mode not activating correctly on startup when `voiceEnabled: true` is set
- Fixed left/right arrow tab navigation in `/permissions`
- Fixed `CLAUDE_CODE_DISABLE_TERMINAL_TITLE` not preventing terminal title from being set on startup
- Fixed custom status line showing nothing when workspace trust is blocking it
- Fixed enterprise users being unable to retry on rate limit (429) errors
- Fixed `SessionEnd` hooks not firing when using interactive `/resume` to switch sessions
- Improved startup memory usage by \~18MB across all scenarios
- Improved non-streaming API fallback with a 2-minute per-attempt timeout, preventing sessions from hanging indefinitely
- `CLAUDE_CODE_PLUGIN_SEED_DIR` now supports multiple seed directories separated by the platform path delimiter (`:` on Unix, `;` on Windows)
- \[VSCode] Added `/remote-control` — bridge your session to claude.ai/code to continue from a browser or phone
- \[VSCode] Session tabs now get AI-generated titles based on your first message
- \[VSCode] Fixed the thinking pill showing "Thinking" instead of "Thought for Ns" after a response completes
- \[VSCode] Fixed missing session diff button when opening sessions from the left sidebar
### [`v2.1.6`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2169)
- Added the `/claude-api` skill for building applications with the Claude API and Anthropic SDK
- Added Ctrl+U on an empty bash prompt (`!`) to exit bash mode, matching `escape` and `backspace`
- Added numeric keypad support for selecting options in Claude's interview questions (previously only the number row above QWERTY worked)
- Added optional name argument to `/remote-control` and `claude remote-control` (`/remote-control My Project` or `--name "My Project"`) to set a custom session title visible in claude.ai/code
- Added Voice STT support for 10 new languages (20 total) — Russian, Polish, Turkish, Dutch, Ukrainian, Greek, Czech, Danish, Swedish, Norwegian
- Added effort level display (e.g., "with low effort") to the logo and spinner, making it easier to see which effort setting is active
- Added agent name display in terminal title when using `claude --agent`
- Added `sandbox.enableWeakerNetworkIsolation` setting (macOS only) to allow Go programs like `gh`, `gcloud`, and `terraform` to verify TLS certificates when using a custom MITM proxy with `httpProxyPort`
- Added `includeGitInstructions` setting (and `CLAUDE_CODE_DISABLE_GIT_INSTRUCTIONS` env var) to remove built-in commit and PR workflow instructions from Claude's system prompt
- Added `/reload-plugins` command to activate pending plugin changes without restarting
- Added a one-time startup prompt suggesting Claude Code Desktop on macOS and Windows (max 3 showings, dismissible)
- Added `${CLAUDE_SKILL_DIR}` variable for skills to reference their own directory in SKILL.md content
- Added `InstructionsLoaded` hook event that fires when CLAUDE.md or `.claude/rules/*.md` files are loaded into context
- Added `agent_id` (for subagents) and `agent_type` (for subagents and `--agent`) to hook events
- Added `worktree` field to status line hook commands with name, path, branch, and original repo directory when running in a `--worktree` session
- Added `pluginTrustMessage` in managed settings to append organization-specific context to the plugin trust warning shown before installation
- Added policy limit fetching (e.g., remote control restrictions) for Team plan OAuth users, not just Enterprise
- Added `pathPattern` to `strictKnownMarketplaces` for regex-matching file/directory marketplace sources alongside `hostPattern` restrictions
- Added plugin source type `git-subdir` to point to a subdirectory within a git repo
- Added `oauth.authServerMetadataUrl` config option for MCP servers to specify a custom OAuth metadata discovery URL when standard discovery fails
- Fixed a security issue where nested skill discovery could load skills from gitignored directories like `node_modules`
- Fixed trust dialog silently enabling all `.mcp.json` servers on first run. You'll now see the per-server approval dialog as expected
- Fixed `claude remote-control` crashing immediately on npm installs with "bad option: --sdk-url" ([#​28334](https://github.com/anthropics/claude-code/issues/28334))
- Fixed `--model claude-opus-4-0` and `--model claude-opus-4-1` resolving to deprecated Opus versions instead of current
- Fixed macOS keychain corruption when using multiple OAuth MCP servers. Large OAuth metadata blobs could overflow the `security -i` stdin buffer, silently leaving stale credentials behind and causing repeated `/login` prompts.
- Fixed `.credentials.json` losing `subscriptionType` (showing "Claude API" instead of "Claude Pro"/"Claude Max") when the profile endpoint transiently fails during token refresh ([#​30185](https://github.com/anthropics/claude-code/issues/30185))
- Fixed ghost dotfiles (`.bashrc`, `HEAD`, etc.) appearing as untracked files in the working directory after sandboxed Bash commands on Linux
- Fixed Shift+Enter printing `[27;2;13~` instead of inserting a newline in Ghostty over SSH
- Fixed stash (Ctrl+S) being cleared when submitting a message while Claude is working
- Fixed ctrl+o (transcript toggle) freezing for many seconds in long sessions with lots of file edits
- Fixed plan mode feedback input not supporting multi-line text entry (backslash+Enter and Shift+Enter now insert newlines)
- Fixed cursor not moving down into blank lines at the top of the input box
- Fixed `/stats` crash when transcript files contain entries with missing or malformed timestamps
- Fixed a brief hang after a streaming error on long sessions (the transcript was being fully rewritten to drop one line; it is now truncated in place)
- Fixed `--setting-sources user` not blocking dynamically discovered project skills
- Fixed duplicate CLAUDE.md, slash commands, agents, and rules when running from a worktree nested inside its main repo (e.g. `claude -w`)
- Fixed plugin Stop/SessionEnd/etc hooks not firing after any `/plugin` operation
- Fixed plugin hooks being silently dropped when two plugins use the same `${CLAUDE_PLUGIN_ROOT}/...` command template
- Fixed memory leak in long-running SDK/CCR sessions where conversation messages were retained unnecessarily
- Fixed API 400 errors in forked agents (autocompact, summarization) when resuming sessions that were interrupted mid-tool-batch
- Fixed "unexpected tool\_use\_id found in tool\_result blocks" error when resuming conversations that start with an orphaned tool result
- Fixed teammates accidentally spawning nested teammates via the Agent tool's `name` parameter
- Fixed `CLAUDE_CODE_MAX_OUTPUT_TOKENS` being ignored during conversation compaction
- Fixed `/compact` summary rendering as a user bubble in SDK consumers (Claude Code Remote web UI, VSCode extension)
- Fixed voice space bar getting stuck after a failed voice activation (module loading race, cold GrowthBook)
- Fixed worktree file copy on Windows
- Fixed global `.claude` folder detection on Windows
- Fixed symlink bypass where writing new files through a symlinked parent directory could escape the working directory in `acceptEdits` mode
- Fixed sandbox prompting users to approve non-allowed domains when `allowManagedDomainsOnly` is enabled in managed settings — non-allowed domains are now blocked automatically with no bypass
- Fixed interactive tools (e.g., `AskUserQuestion`) being silently auto-allowed when listed in a skill's allowed-tools, bypassing the permission prompt and running with empty answers
- Fixed multi-GB memory spike when committing with large untracked binary files in the working tree
- Fixed Escape not interrupting a running turn when the input box has draft text. Use Up arrow to pull queued messages back for editing, or Ctrl+U to clear the input line.
- Fixed Android app crash when running local slash commands (`/voice`, `/cost`) in Remote Control sessions
- Fixed a memory leak where old message array versions accumulated in React Compiler `memoCache` over long sessions
- Fixed a memory leak where REPL render scopes accumulated over long sessions (\~35MB over 1000 turns)
- Fixed memory retention in in-process teammates where the parent's full conversation history was pinned for the teammate's lifetime, preventing GC after `/clear` or auto-compact
- Fixed a memory leak in interactive mode where hook events could accumulate unboundedly during long sessions
- Fixed hang when `--mcp-config` points to a corrupted file
- Fixed slow startup when many skills/plugins are installed
- Fixed `cd <outside-dir> && <cmd>` permission prompt to surface the chained command instead of only showing "Yes, allow reading from <dir>/"
- Fixed conditional `.claude/rules/*.md` files (with `paths:` frontmatter) and nested CLAUDE.md files not loading in print mode (`claude -p`)
- Fixed `/clear` not fully clearing all session caches, reducing memory retention in long sessions
- Fixed terminal flicker caused by animated elements at the scrollback boundary
- Fixed UI frame drops on macOS when using MCP servers with OAuth (regression from 2.1.x)
- Fixed occasional frame stalls during typing caused by synchronous debug log flushes
- Fixed `TeammateIdle` and `TaskCompleted` hooks to support `{"continue": false, "stopReason": "..."}` to stop the teammate, matching `Stop` hook behavior
- Fixed `WorktreeCreate` and `WorktreeRemove` plugin hooks being silently ignored
- Fixed skill descriptions with colons (e.g., "Triggers include: X, Y, Z") failing to load from SKILL.md frontmatter
- Fixed project skills without a `description:` frontmatter field not appearing in Claude's available skills list
- Fixed `/context` showing identical token counts for all MCP tools from a server
- Fixed literal `nul` file creation on Windows when the model uses CMD-style `2>nul` redirection in Git Bash
- Fixed extra blank lines appearing below each tool call in the expanded subagent transcript view (Ctrl+O)
- Fixed Tab/arrow keys not cycling Settings tabs when `/config` search box is focused but empty
- Fixed service key OAuth sessions (CCR containers) spamming `[ERROR]` logs with 403s from profile-scoped endpoints
- Fixed inconsistent color for "Remote Control active" status indicator
- Fixed Voice waveform cursor covering the first suffix letter when dictating mid-input
- Fixed Voice input showing all 5 spaces during warmup instead of capping at \~2 (aligning with the "keep holding…" hint)
- Improved spinner performance by isolating the 50ms animation loop from the surrounding shell, reducing render and CPU overhead during turns
- Improved UI rendering performance in native binaries with React Compiler
- Improved `--worktree` startup by eliminating a git subprocess on the startup path
- Improved macOS startup by eliminating redundant settings-file reloads when managed settings resolve
- Improved macOS startup for Claude.ai enterprise/team users by skipping an unnecessary keychain lookup
- Improved MCP `-p` startup by pipelining claude.ai config fetch with local connections and using a concurrency pool instead of sequential batching
- Improved voice startup by removing imperceptible warmup pulse animations that were causing re-render stutter
- Improved MCP binary content handling: tools returning PDFs, Office documents, or audio now save decoded bytes to disk with the correct file extension instead of dumping raw base64 into the conversation context. WebFetch also saves binary responses alongside its summary.
- Improved memory usage in long sessions by stabilizing `onSubmit` across message updates
- Improved LSP tool rendering and memory context building to no longer read entire files
- Improved session upload and memory sync to avoid reading large files into memory before size/binary checks
- Improved file operation performance by avoiding reading file contents for existence checks (6 sites)
- Improved documentation to clarify that `--append-system-prompt-file` and `--system-prompt-file` work in interactive mode (the docs previously said print mode only)
- Reduced baseline memory by \~16MB by deferring Yoga WASM preloading
- Reduced memory footprint for SDK and CCR sessions using stream-json output
- Reduced memory usage when resuming large sessions (including compacted history)
- Reduced token usage on multi-agent tasks with more concise subagent final reports
- Changed Sonnet 4.5 users on Pro/Max/Team Premium to be automatically migrated to Sonnet 4.6
- Changed the `/resume` picker to show your most recent prompt instead of the first one. This also resolves some titles appearing as `(session)`.
- Changed claude.ai MCP connector failures to show a notification instead of silently disappearing from the tool list
- Changed example command suggestions to be generated deterministically instead of calling Haiku
- Changed resuming after compaction to no longer produce a preamble recap before continuing
- \[SDK] Changed task creation to no longer require the `activeForm` field — the spinner falls back to the task subject
- \[VSCode] Added compaction display as a collapsible "Compacted chat" card with the summary inside
- \[VSCode] The permission mode picker now respects `permissions.disableBypassPermissionsMode` from your effective Claude Code settings (including managed/policy settings) — when set to `disable`, bypass permissions mode is hidden from the picker
- \[VSCode] Fixed RTL text (Arabic, Hebrew, Persian) rendering reversed in the chat panel (regression in v2.1.63)
### [`v2.1.5`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2159)
- Claude automatically saves useful context to auto-memory. Manage with /memory
- Added `/copy` command to show an interactive picker when code blocks are present, allowing selection of individual code blocks or the full response.
- Improved "always allow" prefix suggestions for compound bash commands (e.g. `cd /tmp && git fetch && git push`) to compute smarter per-subcommand prefixes instead of treating the whole command as one
- Improved ordering of short task lists
- Improved memory usage in multi-agent sessions by releasing completed subagent task state
- Fixed MCP OAuth token refresh race condition when running multiple Claude Code instances simultaneously
- Fixed shell commands not showing a clear error message when the working directory has been deleted
- Fixed config file corruption that could wipe authentication when multiple Claude Code instances ran simultaneously
### [`v2.1.2`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#21284)
- Added Claude Sonnet 5.5 (`claude-sonnet-5-5`), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads
- Added a "Yes, but ask again next time" answer to auto mode's prompt before a read outside the working directories, so you can allow that one read and still be asked about later ones
- Added dollar amounts to the Claude apps gateway spend limit in `/usage` and the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line's `rate_limits.spend_limit` also gains `used_usd`, `limit_usd` and `period`
- Added `effortSlider:decreaseEffort`, `increaseEffort` and `toggleUltracode` keybinding actions, so the `/effort` slider's arrow and Tab keys can be rebound in `keybindings.json`
- Added `/rate-limit-options` to `/help` and the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find
- Added `/mcp reconnect all` in the interactive terminal to retry every MCP server that failed to connect or needs authentication at once
- Added Claude apps gateway startup warnings when a managed policy's `availableModels` is empty, or leaves out the model Claude Code starts on without setting `model` or `enforceAvailableModels`
- Added `auth: { google: {} }` for Claude apps gateway `telemetry.forward_to` destinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentials
- Added certificate client authentication (`private_key_jwt`) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets
- Fixed a damaged response stream showing raw errors such as "JSON Parse error" or "undefined is not an object", or writing the word "undefined" into an answer, instead of being retried or reported as an interrupted response
- Fixed an overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried
- Fixed "Prompt is too long" errors that persisted after compacting: when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation
- Fixed a session whose model is unavailable, with no fallback model left, showing a bare "is currently unavailable" message (or "Something went wrong" in cloud sessions) instead of the model-unavailable notice and its Learn more link
- Fixed Agent SDK sessions crashing when a user message contains an image with a malformed `source`, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note
- Fixed MCP tool calls in a resumed session failing with "No such tool available" while their server was still connecting; the call now waits up to 10 seconds for the server
- Fixed repeated calls to the plan-usage endpoint after it rate-limits or rejects your login: `/usage`, `/extra-usage` and IDE usage views now back off instead of re-asking
- Fixed `claude mcp add` reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads
- Fixed the `/plugin` configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs
- Fixed `ANTHROPIC_FOUNDRY_RESOURCE` being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused
- Fixed Claude Desktop behind a Claude apps gateway offering no 1M context option: the gateway now marks each 1M-capable model for Desktop automatically
- Fixed ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt
- Fixed Bash tool failing on Windows with many plugins enabled: plugin `bin/` directories that don't exist are no longer added to PATH, and inherited entries aren't added twice
- Fixed `sparsePaths` plugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present"
- Fixed fullscreen rendering erasing the terminal output above the session when `[` in transcript mode writes the conversation to scrollback (macOS and Linux)
- Fixed fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up
- Fixed tab bars in dialogs such as `/config` and `/plugin` breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole
- Fixed the `/model` picker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows
- Fixed `/keybindings` writing Backspace and Delete bindings for a footer action that does nothing into the generated `keybindings.json`
- Fixed a rebound agent panel close key (`footer:close`) typing "x" instead of itself on the row of the agent you're viewing
- Fixed vim mode `.` not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as `cw` then Esc)
- Fixed vim mode leaving the cursor on an image placeholder's opening bracket after `dd` on the last line or `yy` at the end of the prompt, where `r` or `x` would break or delete the image
- Fixed a key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted
- Fixed the workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory
- Fixed rules symlinked into `.claude/rules` from outside the project being skipped without ever showing the external-imports approval prompt; a `.claude` directory symlinked from outside the project now asks for the same approval
- Fixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via `allowed-tools` under managed `allowManagedPermissionRulesOnly`; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval
- Fixed a failed first `claude plugin install` leaving the plugin enabled and recorded when a dependency's version range could not be met
- Fixed the debug log dropping a failed hook's stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code
- Fixed `{"decision":"block"}` returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does
- Fixed sessions launched without the `SendMessage` tool (such as by Claude Desktop) still being told to message other sessions with it
- Fixed a photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption
- Fixed typing a message during an automatic usage-limit wait taking the wait out of the "Continue automatically at usage limit" setting's control when that turn hit the limit again
- Fixed usage-limit warnings suggesting `/upgrade` to users already on the highest Max plan; the warnings and `/upgrade` itself now point at `/usage-credits` when it is available
- Fixed the Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn't recognize, such as a custom model behind a proxy; Explore now inherits that model
- Fixed `/loop` status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text
- Fixed `/ultrareview` failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux
- Fixed sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory
- Fixed artifact database write results telling Claude that every viewer sees a write to a viewer's private `data/users/` subtree, and added a "view" level to `as_level`
- Fixed the Claude apps gateway answering `431 Request Header Fields Too Large` to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB
- Improved the usage-limit wait: the limit's state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown
- Improved the "No such tool available" error for Claude in Chrome tools called without their prefix: it now names the tool to call
- Improved Monitor event rows to show what each event printed instead of repeating the description, and stopped repeating an unchanged "Waiting for N … to finish" line after every event
- Improved Workflow tool sandbox hardening for errors thrown by async script hooks
- Improved startup time and memory use by building only the parts of the settings schema that your settings files actually use
- Improved `/claude-api`: `hillclimb` no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside `report.html` is built as one local file that loads nothing from the network
- Improved lists such as `/tasks`, `/copy` and `/hooks`: the details after each name now line up in one column when they fit, and otherwise sit at the right edge
- Improved `claude plugin marketplace add` to say when it replaces a marketplace already added under the same name from a different source, and how to undo it
- Improved the startup refusal when managed settings require a sign-in (`forceLoginMethod` or `forceLoginOrgUUID`) and an API key, token or `apiKeyHelper` is configured: it now names the credential in use, where it is set, and how to remove it
- Improved auto-memory loading: invisible characters and tags that imitate Claude Code's own markup are neutralized in `MEMORY.md` and recalled memory notes before they reach Claude
- Improved `claude remote-control`: in a folder you haven't trusted yet, it now asks for workspace trust on the terminal instead of exiting
- Improved artifact pages: Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title
- Improved the Artifact tool so that when Claude is given a claude.ai chat or project link, an artifact from a chat, or an artifact id on its own, it asks for the right link or the content instead of stopping
- Changed interactive terminal and VS Code sessions to start in auto mode when no permission mode is configured, on every plan and provider; `permissions.defaultMode` still overrides it
- Changed Ultracode into its own toggle in `/effort` (Tab, or `/effort ultracode [on|off]`): it no longer forces xhigh effort and stays on at any effort level
- Changed retries after a dropped connection mid-response to share one budget with the rest of the request's retries, so a failing request gives up sooner
- Changed the notice shown when a Sonnet model's safeguards flag a message to explain why it happened and to offer editing and retrying
- Changed safety-related model switches in sessions that pin an Opus model with `ANTHROPIC_DEFAULT_OPUS_MODEL` or `modelOverrides`: on the Anthropic API, the API now picks the model to switch to for each kind of flag, not the pinned model
- Changed the non-interactive first turn to still wait up to 2s for connecting MCP servers named by `--allowedTools` or an `mcp_tool` hook, even when `CLAUDE_CODE_MCP_STARTUP_WAIT_MS` is `0`
- Changed `/recap` to decline with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook; typed in the terminal, the Claude apps, Remote Control, `-p` or an SDK host, it runs as before
- Changed `/artifacts` to show its filter tabs beside the title with one-word labels (All, Mine, Shared), using the same tab bar as `/config` and `/plugin`
- Changed artifact publishing to refuse a file on a network share (a `\\host\share` path or a `/net` automount) unless it is on a mapped network drive added with `--add-dir`
- \[VSCode] Added an optional time above each prompt and response, with a date line where the day changes (Claude Code: Show Message Timestamps setting, off by default)
- \[VSCode] Added plugin load errors and notes to the Manage plugins rows, with a popup to disable, uninstall or copy the error
- \[VSCode] Added an Ultracode on/off switch under the Effort slider, replacing the slider's Ultracode stop; the model pill shows "· Ultracode" at any effort level
- \[VSCode] Fixed Reload Claude from the Memory dialog restarting before an edited file was saved
- \[VSCode] Fixed a restored tab opening a conversation another Claude process still has open; it now asks first
- \[VSCode] Fixed Focus view sections you expanded closing on their own while a sub-agent is working or when the section's first step is trimmed from view
- \[VSCode] Fixed typing `/model` and Enter printing usage text into the chat instead of opening the model selector
- \[VSCode] Fixed `/feedback` on Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does
- \[VSCode] Fixed sign-in waiting up to a minute for the Python extension after a window reload
- \[VSCode] Fixed Claude Code tabs that stopped responding after Restart Extensions: they now reopen on their conversation
- \[VSCode] Fixed a message from another agent with no recorded sender showing as raw XML in the chat
- \[VSCode] Fixed messages from other agents, sessions or channels disappearing after a reload
- \[VSCode] Fixed a user's own `/mcp`, `/config` or `/settings` command being shadowed by the extension's dialog
- \[VSCode] Fixed Escape stopping every background agent when no turn was running
- \[VSCode] Fixed plugin install links replacing a marketplace you already have that uses the same name
- \[VSCode] Fixed "Prompt is too long" errors after compaction when a large text file is attached to a message
- \[VSCode] Fixed chat links to files with non-ASCII characters, spaces or brackets in their path not opening
- \[VSCode] Changed `CLAUDE_CONFIG_DIR` in the `claudeCode.environmentVariables` setting to apply only when it is an absolute path, and passed it to terminals that continue the chat
- \[Cloud sessions] Fixed a routine's Edit and Duplicate controls saying the routine was still loading while you were offline; they now tell you you're offline
- \[Claude Tag] Added model family choices such as "Opus (latest)" for a thread, a channel default or your DM, so the choice follows the newest model in that family
- \[Claude Tag] Added the spend that counts toward your organization-wide limit to the analytics spend projection chart, with how much of the limit is used
- \[Claude Tag] Fixed the earlier Claude in Slack app's progress card and link previews omitting the repository and Create PR button when a GitHub Enterprise host name contains an underscore
- \[Claude Tag] Fixed Claude staying silent in a channel whose environment declines to start it; it now posts one notice asking you to contact an admin, and retries when @​-mentioned
- \[Claude Tag] Changed Claude to post its private sign-in notice at every @​mention from someone who hasn't connected their Claude account, instead of going quiet after the first
- \[Claude Tag] Improved "Notify members now" in admin settings: one press reaches every workspace your organization claimed in an Enterprise Grid, and more members in large workspaces
- \[Claude Tag] Improved Claude's wait notice on self-hosted environments with on-demand runners: it now says whether a runner is starting, a start will be retried, or no runner will start
- \[Claude Tag] Improved the error shown when adding a channel manager fails because the channel's Slack workspace can't be confirmed as connected to your organization
- \[Claude Tag] Improved a channel's access lists in admin settings to show the connectors, repositories and plugins an auto-join pattern attaches, and where each comes from
- \[Claude Tag] Improved adding repositories as a channel manager: when your GitHub sign-in can't confirm you're a repository admin, the page asks you to sign in with GitHub
- \[Code Review] Fixed Code Review giving up without posting a finished review when an unsubmitted review under its GitHub App was open on the pull request; it now retries the post first
### [`v2.0.76`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2076)
- Fixed issue with macOS code-sign warning when using Claude in Chrome integration
### [`v2.0.75`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2075)
- Minor bugfixes
### [`v2.0.74`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2074)
- Added LSP (Language Server Protocol) tool for code intelligence features like go-to-definition, find references, and hover documentation
- Added `/terminal-setup` support for Kitty, Alacritty, Zed, and Warp terminals
- Added ctrl+t shortcut in `/theme` to toggle syntax highlighting on/off
- Added syntax highlighting info to theme picker
- Added guidance for macOS users when Alt shortcuts fail due to terminal configuration
- Fixed skill `allowed-tools` not being applied to tools invoked by the skill
- Fixed Opus 4.5 tip incorrectly showing when user was already using Opus
- Fixed a potential crash when syntax highlighting isn't initialized correctly
- Fixed visual bug in `/plugins discover` where list selection indicator showed while search box was focused
- Fixed macOS keyboard shortcuts to display 'opt' instead of 'alt'
- Improved `/context` command visualization with grouped skills and agents by source, slash commands, and sorted token count
- \[Windows] Fixed issue with improper rendering
- \[VSCode] Added gift tag pictogram for year-end promotion message
### [`v2.0.72`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2072)
- Added Claude in Chrome (Beta) feature that works with the Chrome extension (<https://claude.ai/chrome>) to let you control your browser directly from Claude Code
- Reduced terminal flickering
- Added scannable QR code to mobile app tip for quick app downloads
- Added loading indicator when resuming conversations for better feedback
- Fixed `/context` command not respecting custom system prompts in non-interactive mode
- Fixed order of consecutive Ctrl+K lines when pasting with Ctrl+Y
- Improved @​ mention file suggestion speed (\~3× faster in git repositories)
- Improved file suggestion performance in repos with `.ignore` or `.rgignore` files
- Improved settings validation errors to be more prominent
- Changed thinking toggle from Tab to Alt+T to avoid accidental triggers
### [`v2.0.71`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2071)
- Added /config toggle to enable/disable prompt suggestions
- Added `/settings` as an alias for the `/config` command
- Fixed @​ file reference suggestions incorrectly triggering when cursor is in the middle of a path
- Fixed MCP servers from `.mcp.json` not loading when using `--dangerously-skip-permissions`
- Fixed permission rules incorrectly rejecting valid bash commands containing shell glob patterns (e.g., `ls *.txt`, `for f in *.png`)
- Bedrock: Environment variable `ANTHROPIC_BEDROCK_BASE_URL` is now respected for token counting and inference profile listing
- New syntax highlighting engine for native build
### [`v2.0.70`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2070)
- Added Enter key to accept and submit prompt suggestions immediately (tab still accepts for editing)
- Added wildcard syntax `mcp__server__*` for MCP tool permissions to allow or deny all tools from a server
- Added auto-update toggle for plugin marketplaces, allowing per-marketplace control over automatic updates
- Added `current_usage` field to status line input, enabling accurate context window percentage calculations
- Fixed input being cleared when processing queued commands while the user was typing
- Fixed prompt suggestions replacing typed input when pressing Tab
- Fixed diff view not updating when terminal is resized
- Improved memory usage by 3x for large conversations
- Improved resolution of stats screenshots copied to clipboard (Ctrl+S) for crisper images
- Removed # shortcut for quick memory entry (tell Claude to edit your CLAUDE.md instead)
- Fix thinking mode toggle in /config not persisting correctly
- Improve UI for file creation permission dialog
### [`v2.0.69`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2069)
- Minor bugfixes
### [`v2.0.67`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2067)
- Thinking mode is now enabled by default for Opus 4.5
- Thinking mode configuration has moved to /config
- Added search functionality to `/permissions` command with `/` keyboard shortcut for filtering rules by tool name
- Show reason why autoupdater is disabled in `/doctor`
- Fixed false "Another process is currently updating Claude" error when running `claude update` while another instance is already on the latest version
- Fixed MCP servers from `.mcp.json` being stuck in pending state when running in non-interactive mode (`-p` flag or piped input)
- Fixed scroll position resetting after deleting a permission rule in `/permissions`
- Fixed word deletion (opt+delete) and word navigation (opt+arrow) not working correctly with non-Latin text such as Cyrillic, Greek, Arabic, Hebrew, Thai, and Chinese
- Fixed `claude install --force` not bypassing stale lock files
- Fixed consecutive @​\~/ file references in CLAUDE.md being incorrectly parsed due to markdown strikethrough interference
- Windows: Fixed plugin MCP servers failing due to colons in log directory paths
### [`v2.0.65`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2065)
- Added ability to switch models while writing a prompt using alt+p (linux, windows), option+p (macos).
- Added context window information to status line input
- Added `fileSuggestion` setting for custom `@` file search commands
- Added `CLAUDE_CODE_SHELL` environment variable to override automatic shell detection (useful when login shell differs from actual working shell)
- Fixed prompt not being saved to history when aborting a query with Escape
- Fixed Read tool image handling to identify format from bytes instead of file extension
### [`v2.0.64`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2064)
- Made auto-compacting instant
- Agents and bash commands can run asynchronously and send messages to wake up the main agent
- /stats now provides users with interesting CC stats, such as favorite model, usage graph, usage streak
- Added named session support: use `/rename` to name sessions, `/resume <name>` in REPL or `claude --resume <name>` from the terminal to resume them
- Added support for .claude/rules/\`. See <https://code.claude.com/docs/en/memory> for details.
- Added image dimension metadata when images are resized, enabling accurate coordinate mappings for large images
- Fixed auto-loading .env when using native installer
- Fixed `--system-prompt` being ignored when using `--continue` or `--resume` flags
- Improved `/resume` screen with grouped forked sessions and keyboard shortcuts for preview (P) and rename (R)
- VSCode: Added copy-to-clipboard button on code blocks and bash tool inputs
- VSCode: Fixed extension not working on Windows ARM64 by falling back to x64 binary via emulation
- Bedrock: Improve efficiency of token counting
- Bedrock: Add support for `aws login` AWS Management Console credentials
- Unshipped AgentOutputTool and BashOutputTool, in favor of a new unified TaskOutputTool
### [`v2.0.61`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2061)
- Reverted VSCode support for multiple terminal clients due to responsiveness issues.
### [`v2.0.59`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2059)
- Added --agent CLI flag to override the agent setting for the current session
- Added `agent` setting to configure main thread with a specific agent's system prompt, tool restrictions, and model
- VS Code: Fixed .claude.json config file being read from incorrect location
### [`v2.0.58`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2058)
- Pro users now have access to Opus 4.5 as part of their subscription!
- Fixed timer duration showing "11m 60s" instead of "12m 0s"
- Windows: Managed settings now prefer `C:\Program Files\ClaudeCode` if it exists. Support for `C:\ProgramData\ClaudeCode` will be removed in a future version.
### [`v2.0.57`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2057)
- Added feedback input when rejecting plans, allowing users to tell Claude what to change
- VSCode: Added streaming message support for real-time response display
### [`v2.0.56`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2056)
- Added setting to enable/disable terminal progress bar (OSC 9;4)
- VSCode Extension: Added support for VS Code's secondary sidebar (VS Code 1.97+), allowing Claude Code to be displayed in the right sidebar while keeping the file explorer on the left. Requires setting sidebar as Preferred Location in the config.
### [`v2.0.55`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2055)
- Fixed proxy DNS resolution being forced on by default. Now opt-in via `CLAUDE_CODE_PROXY_RESOLVES_HOSTS=true` environment variable
- Fixed keyboard navigation becoming unresponsive when holding down arrow keys in memory location selector
- Improved AskUserQuestion tool to auto-submit single-select questions on the last question, eliminating the extra review screen for simple question flows
- Improved fuzzy matching for `@` file suggestions with faster, more accurate results
### [`v2.0.54`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2054)
- Hooks: Enable PermissionRequest hooks to process 'always allow' suggestions and apply permission updates
- Fix issue with excessive iTerm notifications
### [`v2.0.50`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2050)
- Fixed bug preventing calling MCP tools that have nested references in their input schemas
- Silenced a noisy but harmless error during upgrades
- Improved ultrathink text display
- Improved clarity of 5-hour session limit warning message
### [`v2.0.49`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2049)
- Added readline-style ctrl-y for pasting deleted text
- Improved clarity of usage limit warning message
- Fixed handling of subagent permissions
### [`v2.0.47`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2047)
- Improved error messages and validation for `claude --teleport`
- Improved error handling in `/usage`
- Fixed race condition with history entry not getting logged at exit
- Fixed Vertex AI configuration not being applied from `settings.json`
### [`v2.0.46`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2046)
- Fixed image files being reported with incorrect media type when format cannot be detected from metadata
### [`v2.0.42`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2042)
- Added `agent_id` and `agent_transcript_path` fields to `SubagentStop` hooks.
### [`v2.0.37`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2037)
- Fixed how idleness is computed for notifications
- Hooks: Added matcher values for Notification hook events
- Output Styles: Added `keep-coding-instructions` option to frontmatter
### [`v2.0.35`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2035)
- Improve fuzzy search results when searching commands
- Improved VS Code extension to respect `chat.fontSize` and `chat.fontFamily` settings throughout the entire UI, and apply font changes immediately without requiring reload
- Added `CLAUDE_CODE_EXIT_AFTER_STOP_DELAY` environment variable to automatically exit SDK mode after a specified idle duration, useful for automated workflows and scripts
- Migrated `ignorePatterns` from project config to deny permissions in the localSettings.
- Fixed menu navigation getting stuck on items with empty string or other falsy values (e.g., in the `/hooks` menu)
### [`v2.0.34`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2034)
- VSCode Extension: Added setting to configure the initial permission mode for new conversations
- Improved file path suggestion performance with native Rust-based fuzzy finder
- Fixed infinite token refresh loop that caused MCP servers with OAuth (e.g., Slack) to hang during connection
- Fixed memory crash when reading or writing large files (especially base64-encoded images)
### [`v2.0.33`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2033)
- Native binary installs now launch quicker.
- Fixed `claude doctor` incorrectly detecting Homebrew vs npm-global installations by properly resolving symlinks
- Fixed `claude mcp serve` exposing tools with incompatible outputSchemas
### [`v2.0.32`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2032)
- Un-deprecate output styles based on community feedback
- Added `companyAnnouncements` setting for displaying announcements on startup
- Fixed hook progress messages not updating correctly during PostToolUse hook execution
### [`v2.0.31`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2031)
- Windows: native installation uses shift+tab as shortcut for mode switching, instead of alt+m
- Vertex: add support for Web Search on supported models
- VSCode: Adding the respectGitIgnore configuration to include .gitignored files in file searches (defaults to true)
- Fixed a bug with subagents and MCP servers related to "Tool names must be unique" error
- Fixed issue causing `/compact` to fail with `prompt_too_long` by making it respect existing compact boundaries
- Fixed plugin uninstall not removing plugins
### [`v2.0.30`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2030)
- Added helpful hint to run `security unlock-keychain` when encountering API key errors on macOS with locked keychain
- Added `allowUnsandboxedCommands` sandbox setting to disable the dangerouslyDisableSandbox escape hatch at policy level
- Added `disallowedTools` field to custom agent definitions for explicit tool blocking
- Added prompt-based stop hooks
- VSCode: Added respectGitIgnore configuration to include .gitignored files in file searches (defaults to true)
- Enabled SSE MCP servers on native build
- Deprecated output styles. Review options in `/output-style` and use --system-prompt-file, --system-prompt, --append-system-prompt, CLAUDE.md, or plugins instead
- Removed support for custom ripgrep configuration, resolving an issue where Search returns no results and config discovery fails
- Fixed Explore agent creating unwanted .md investigation files during codebase exploration
- Fixed a bug where `/context` would sometimes fail with "max\_tokens must be greater than thinking.budget\_tokens" error message
- Fixed `--mcp-config` flag to correctly override file-based MCP configurations
- Fixed bug that saved session permissions to local settings
- Fixed MCP tools not being available to sub-agents
- Fixed hooks and plugins not executing when using --dangerously-skip-permissions flag
- Fixed delay when navigating through typeahead suggestions with arrow keys
- VSCode: Restored selection indicator in input footer showing current file or code selection status
### [`v2.0.28`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2028)
- Plan mode: introduced new Plan subagent
- Subagents: claude can now choose to resume subagents
- Subagents: claude can dynamically choose the model used by its subagents
- SDK: added --max-budget-usd flag
- Discovery of custom slash commands, subagents, and output styles no longer respects .gitignore
- Stop `/terminal-setup` from adding backslash to `Shift + Enter` in VS Code
- Add branch and tag support for git-based plugins and marketplaces using fragment syntax (e.g., `owner/repo#branch`)
- Fixed a bug where macOS permission prompts would show up upon initial launch when launching from home directory
- Various other bug fixes
### [`v2.0.27`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2027)
- New UI for permission prompts
- Added current branch filtering and search to session resume screen for easier navigation
- Fixed directory @​-mention causing "No assistant message found" error
- VSCode Extension: Add config setting to include .gitignored files in file searches
- VSCode Extension: Bug fixes for unrelated 'Warmup' conversations, and configuration/settings occasionally being reset to defaults
### [`v2.0.25`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2025)
- Removed legacy SDK entrypoint. Please migrate to [@​anthropic-ai/claude-agent-sdk](https://github.com/anthropic-ai/claude-agent-sdk) for future SDK updates: <https://platform.claude.com/docs/en/agent-sdk/migration-guide>
### [`v2.0.22`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2022)
- Fixed content layout shift when scrolling through slash commands
- IDE: Add toggle to enable/disable thinking.
- Fix bug causing duplicate permission prompts with parallel tool calls
- Add support for enterprise managed MCP allowlist and denylist
### [`v2.0.17`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2017)
- Added Haiku 4.5 to model selector!
- Haiku 4.5 automatically uses Sonnet in plan mode, and Haiku for execution (i.e. SonnetPlan by default)
- 3P (Bedrock and Vertex) are not automatically upgraded yet. Manual upgrading can be done through setting `ANTHROPIC_DEFAULT_HAIKU_MODEL`
- Introducing the Explore subagent. Powered by Haiku it'll search through your codebase efficiently to save context!
- OTEL: support HTTP\_PROXY and HTTPS\_PROXY
- `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` now disables release notes fetching
### [`v2.0.15`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2015)
- Fixed bug with resuming where previously created files needed to be read again before writing
- Fixed bug with `-p` mode where @​-mentioned files needed to be read again before writing
### [`v2.0.14`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2014)
- Fix @​-mentioning MCP servers to toggle them on/off
- Improve permission checks for bash with inline env vars
- Fix ultrathink + thinking toggle
- Reduce unnecessary logins
- Document --system-prompt
- Several improvements to rendering
- Plugins UI polish
### [`v2.0.11`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2011)
- Reduced system prompt size by 1.4k tokens
- IDE: Fixed keyboard shortcuts and focus issues for smoother interaction
- Fixed Opus fallback rate limit errors appearing incorrectly
- Fixed /add-dir command selecting wrong default tab
### [`v2.0.10`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2010)
- Rewrote terminal renderer for buttery smooth UI
- Enable/disable MCP servers by [@​mentioning](https://github.com/mentioning), or in /mcp
- Added tab completion for shell commands in bash mode
- PreToolUse hooks can now modify tool inputs
- Press Ctrl-G to edit your prompt in your system's configured text editor
- Fixes for bash permission checks with environment variables in the command
### [`v2.0.9`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#209)
- Fix regression where bash backgrounding stopped working
### [`v2.0.8`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#208)
- Update Bedrock default Sonnet model to `global.anthropic.claude-sonnet-4-5-20250929-v1:0`
- IDE: Add drag-and-drop support for files and folders in chat
- /context: Fix counting for thinking blocks
- Improve message rendering for users with light themes on dark terminals
- Remove deprecated .claude.json allowedTools, ignorePatterns, env, and todoFeatureEnabled config options (instead, configure these in your settings.json)
### [`v2.0.5`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2059)
- Added --agent CLI flag to override the agent setting for the current session
- Added `agent` setting to configure main thread with a specific agent's system prompt, tool restrictions, and model
- VS Code: Fixed .claude.json config file being read from incorrect location
### [`v2.0.1`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#2019)
- Auto-background long-running bash commands instead of killing them. Customize with BASH\_DEFAULT\_TIMEOUT\_MS
- Fixed a bug where Haiku was unnecessarily called in print mode
### [`v1.0.126`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#10126)
- Enable /context command for Bedrock and Vertex
- Add mTLS support for HTTP-based OpenTelemetry exporters
### [`v1.0.123`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#10123)
- Bash permission rules now support output redirections when matching (e.g., `Bash(python:*)` matches `python script.py > output.txt`)
- Fixed thinking mode triggering on negation phrases like "don't think"
- Fixed rendering performance degradation during token streaming
- Added SlashCommand tool, which enables Claude to invoke your slash commands. <https://code.claude.com/docs/en/slash-commands#SlashCommand-tool>
- Enhanced BashTool environment snapshot logging
- Fixed a bug where resuming a conversation in headless mode would sometimes enable thinking unnecessarily
- Migrated --debug logging to a file, to enable easy tailing & filtering
### [`v1.0.119`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#10119)
- Fix Windows issue where process visually freezes on entering interactive mode
- Support dynamic headers for MCP servers via headersHelper configuration
- Fix thinking mode not working in headless sessions
- Fix slash commands now properly update allowed tools instead of replacing them
### [`v1.0.117`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#10117)
- Add Ctrl-R history search to recall previous commands like bash/zsh
- Fix input lag while typing, especially on Windows
- Add sed command to auto-allowed commands in acceptEdits mode
- Fix Windows PATH comparison to be case-insensitive for drive letters
- Add permissions management hint to /add-dir output
### [`v1.0.72`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1072)
- Ask permissions: have Claude Code always ask for confirmation to use specific tools with /permissions
### [`v1.0.71`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1071)
- Background commands: (Ctrl-b) to run any Bash command in the background so Claude can keep working (great for dev servers, tailing logs, etc.)
- Customizable status line: add your terminal prompt to Claude Code with /statusline
### [`v1.0.65`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1065)
- IDE: Fixed connection stability issues and error handling for diagnostics
- Windows: Fixed shell environment setup for users without .bashrc files
### [`v1.0.64`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1064)
- Agents: Added model customization support - you can now specify which model an agent should use
- Agents: Fixed unintended access to the recursive agent tool
- Hooks: Added systemMessage field to hook JSON output for displaying warnings and context
- SDK: Fixed user input tracking across multi-turn conversations
- Added hidden files to file search and @​-mention suggestions
### [`v1.0.62`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1062)
- Added @​-mention support with typeahead for custom agents. @​<your-custom-agent> to invoke it
- Hooks: Added SessionStart hook for new session initialization
- /add-dir command now supports typeahead for directory paths
- Improved network connectivity check reliability
### [`v1.0.61`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1061)
- Transcript mode (Ctrl+R): Changed Esc to exit transcript mode rather than interrupt
- Settings: Added `--settings` flag to load settings from a JSON file
- Settings: Fixed resolution of settings files paths that are symlinks
- OTEL: Fixed reporting of wrong organization after authentication changes
- Slash commands: Fixed permissions checking for allowed-tools with Bash
- IDE: Added support for pasting images in VSCode MacOS using ⌘+V
- IDE: Added `CLAUDE_CODE_AUTO_CONNECT_IDE=false` for disabling IDE auto-connection
- Added `CLAUDE_CODE_SHELL_PREFIX` for wrapping Claude and user-provided shell commands run by Claude Code
### [`v1.0.60`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1060)
- You can now create custom subagents for specialized tasks! Run /agents to get started
### [`v1.0.58`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1058)
- Added support for reading PDFs
- MCP: Improved server health status display in 'claude mcp list'
- Hooks: Added CLAUDE\_PROJECT\_DIR env var for hook commands
### [`v1.0.56`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1056)
- Windows: Enabled shift+tab for mode switching on versions of Node.js that support terminal VT mode
- Fixes for WSL IDE detection
- Fix an issue causing awsRefreshHelper changes to .aws directory not to be picked up
### [`v1.0.55`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1055)
- Clarified knowledge cutoff for Opus 4 and Sonnet 4 models
- Windows: fixed Ctrl+Z crash
- SDK: Added ability to capture error logging
- Add --system-prompt-file option to override system prompt in print mode
### [`v1.0.54`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1054)
- Hooks: Added UserPromptSubmit hook and the current working directory to hook inputs
- Custom slash commands: Added argument-hint to frontmatter
- Windows: OAuth uses port 45454 and properly constructs browser URL
- Windows: mode switching now uses alt + m, and plan mode renders properly
- Shell: Switch to in-memory shell snapshot to fix file-related errors
### [`v1.0.51`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1051)
- Added support for native Windows (requires Git for Windows)
- Added support for Bedrock API keys through environment variable AWS\_BEARER\_TOKEN\_BEDROCK
- Settings: /doctor can now help you identify and fix invalid setting files
- `--append-system-prompt` can now be used in interactive mode, not just --print/-p.
- Increased auto-compact warning threshold from 60% to 80%
- Fixed an issue with handling user directories with spaces for shell snapshots
- OTEL resource now includes os.type, os.version, host.arch, and wsl.version (if running on Windows Subsystem for Linux)
- Custom slash commands: Fixed user-level commands in subdirectories
- Plan mode: Fixed issue where rejected plan from sub-task would get discarded
### [`v1.0.48`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1048)
- Fixed a bug in v1.0.45 where the app would sometimes freeze on launch
- Added progress messages to Bash tool based on the last 5 lines of command output
- Added expanding variables support for MCP server configuration
- Moved shell snapshots from /tmp to \~/.claude for more reliable Bash tool calls
- Improved IDE extension path handling when Claude Code runs in WSL
- Hooks: Added a PreCompact hook
- Vim mode: Added c, f/F, t/T
### [`v1.0.44`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1044)
- New /export command lets you quickly export a conversation for sharing
- MCP: resource\_link tool results are now supported
- MCP: tool annotations and tool titles now display in /mcp view
- Changed Ctrl+Z to suspend Claude Code. Resume by running `fg`. Prompt input undo is now Ctrl+U.
### [`v1.0.43`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1043)
- Fixed a bug where the theme selector was saving excessively
- Hooks: Added EPIPE system error handling
### [`v1.0.41`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1041)
- Hooks: Split Stop hook triggering into Stop and SubagentStop
- Hooks: Enabled optional timeout configuration for each command
- Hooks: Added "hook\_event\_name" to hook input
- Fixed a bug where MCP tools would display twice in tool list
- New tool parameters JSON for Bash tool in `tool_decision` event
### [`v1.0.38`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1038)
- Released hooks. Special thanks to community input in [#​712](https://github.com/anthropics/claude-code/issues/712). Docs: <https://code.claude.com/docs/en/hooks>
### [`v1.0.35`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1035)
- Added support for MCP OAuth Authorization Server discovery
### [`v1.0.33`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1033)
- Improved logging functionality with session ID support
- Added prompt input undo functionality (Ctrl+Z and vim 'u' command)
- Improvements to plan mode
### [`v1.0.30`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1030)
- Custom slash commands: Run bash output, @​-mention files, enable thinking with thinking keywords
- Improved file path autocomplete with filename matching
- Added timestamps in Ctrl-r mode and fixed Ctrl-c handling
- Enhanced jq regex support for complex filters with pipes and select
### [`v1.0.29`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1029)
- Improved CJK character support in cursor navigation and rendering
### [`v1.0.24`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1024)
- Improved /mcp output
- Fixed a bug where settings arrays got overwritten instead of merged
### [`v1.0.21`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1021)
- Improved editing of files with tab-based indentation
- Fix for tool\_use without matching tool\_result errors
- Fixed a bug where stdio MCP server processes would linger after quitting Claude Code
### [`v1.0.17`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1017)
- We now emit messages from sub-tasks in -p mode (look for the parent\_tool\_use\_id property)
- Fixed crashes when the VS Code diff tool is invoked multiple times quickly
- MCP server list UI improvements
- Update Claude Code process title to display "claude" instead of "node"
### [`v1.0.11`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#10119)
- Fix Windows issue where process visually freezes on entering interactive mode
- Support dynamic headers for MCP servers via headersHelper configuration
- Fix thinking mode not working in headless sessions
- Fix slash commands now properly update allowed tools instead of replacing them
### [`v1.0.6`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1069)
- Upgraded Opus to version 4.1
### [`v1.0.5`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1059)
- SDK: Added tool confirmation support with canUseTool callback
- SDK: Allow specifying env for spawned process
- Hooks: Exposed PermissionDecision to hooks (including "ask")
- Hooks: UserPromptSubmit now supports additionalContext in advanced JSON output
- Fixed issue where some Max users that specified Opus would still see fallback to Sonnet
### [`v1.0.3`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1039)
- New Active Time metric in OpenTelemetry logging
### [`v1.0.2`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#1029)
- Improved CJK character support in cursor navigation and rendering
### [`v1.0.0`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#100)
- Claude Code is now generally available
- Introducing Sonnet 4 and Opus 4 models
</details>
---
### Configuration
📅 **Schedule**: (in timezone Europe/Oslo)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
danijel.simeunovic
was assigned by gitea_admin2026-09-29 00:13:57 +00:00
gitea_admin
requested review from danijel.simeunovic 2026-09-29 00:14:03 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
0.2.122→2.1.245Release Notes
anthropics/claude-code (claude-code)
v2.1.245v2.1.238keybindingFlavorsetting: set it to"readline"to make Ctrl+W in the prompt delete back to the previous whitespace, as in Bash; the default ("classic") is unchangedheadersHelperon a url marketplace or a catalog entry runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetchesheadersHelperruns only when you install or update that plugin, after its command is shown;claude plugin install/updateask[y/N](or pass-y)claude self-hosted-runner --defer-shutdown-max-min <minutes>: on SIGTERM, keep serving attached sessions, park what is left after that many minutes, then exitclaude self-hosted-runner --proxy-authorization-command/--proxy-authorization-filefor egress proxies that require a freshly issuedProxy-Authorizationheader on every connectionCLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=truenot keeping prompt suggestions on when your account is near, but not over, its usage limit/tmp/claude-*-cwdfiles when a Bash command is killed, times out, or is interruptedserver/discoverrequest beforeinitialize, forcing lazy servers to start their backend on every session open/modeland/effortcache-miss warning appearing when the prompt cache had already expiredclaude remote-controlinheriting session-scoped environment variables from the launching shellclaude remote-controlwas restarted; it can now be reused when you next message itListAgents/SendMessagereporting "Remote Control is not connected" in sessions run byclaude remote-control(server mode) or Desktop/IDE hosts; they now list and reach Remote Control peersListAgentsandSendMessageexposing the idle worker that the agent view pre-warms for your next background session; it now appears only once a task claims itcrossSessionInbound: "refuse") now reports "refused" to the sender instead of a silent successclaudestarts sooner on macOSclaude-apiskill for the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes/clearshortcut was removed, and 1-row nvim terminals no longer trigger automatic/clearloopsclaude mcp listandclaude mcp getto show disabled servers as⊘ Disabledinstead of connecting to them for a health checkheadersHelperin a project.mcp.json, and inline MCP servers in project or--add-diragent files, now require that folder's trust dialog to have been accepted (also underclaude -p)headersHelperfrom a project.mcp.json, plugin, or agent file runs without inherited credential env vars; user, managed and claude.ai-scope helpers now run from the Claude config dirv2.1.235spellchecksetting that underlines misspelled words in the prompt input as you type, using your installedaspell,hunspell, orispellsubagent_typethere now gets a clear error listing the available agentsctrl+t) always starting collapsed when resuming or relaunching into a session that still has open tasks/ultrareviewor/autofix-prrun in the background — their event streams are no longer re-scanned and re-rendered on every updategrepin native macOS/Linux builds: pathological patterns now fail fast instead of exhausting memory, and-m Nwith-A/-Cprints correct context/configto re-enable itSendMessagenow refuses messages too large for cross-session delivery up front instead of silently dropping themclaude rcnow applies the same enterprise-gateway availability check as interactive startupv2.1.234CLAUDE_CODE_PROJECT_DIR_NAMEenvironment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directoryselection:clearkeybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view/config("Continue automatically at usage limit")\??\) paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vectorSendMessagerejecting a recipient copied fromListAgentswhen the session name is at the 200-character cap or emoji-heavy${VAR}form, and connection-failure details show only the server originstrictKnownMarketplacesallowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to/loginOAuth URL losing characters when copied in fullscreen---horizontal rule in rendered markdown running into the line after it/permissionsopened while a!shell command was running being dismissed when the command finished!shell command being sent to the model as plain text after pressing up-arrow to edit the queued input!mode no longer sticks after a mid-turn submit--dangerously-skip-permissions), tool allow/deny rules, model or effort flags/tuidropping launch--allowed-tools/--disallowed-toolsrules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can't carry over/loginwhileCLAUDE_CODE_OAUTH_TOKENis set, the stale-token reminder no longer leaks into Claude's automatically resumed turn — it now appears only to youSendMessageandListAgentsnow say when your account's session list was too long to check completely, instead of treating unseen sessions as absent/loginwhen a claude.ai login would take precedenceclaude-apiskill from ~200k+ tokens to ~25k by loading reference docs on demand/permissionscan now be opened while Claude is working — rule changes apply to the rest of the current turn/add-dir <path>can now be used while Claude is working;/add-dir,/autocompact,/theme,/help,/configand/advisordialogs open mid-turn in the fullscreen TUI/goalnow clears itself with a notice when a turn dies on an unrecoverable error (e.g. revoked auth, an exhausted credit balance, or a context overflow) instead of staying armed/goal: when background tasks keep a goal waiting for 30+ minutes, Claude now checks in on them instead of waiting indefinitely (setCLAUDE_CODE_GOAL_CHECKIN_MINUTES=0to opt out)claude setup-tokennow rejects unexpected extra arguments instead of silently ignoring them/config; agent-team teammates now use the leader's model unless the spawn names one<system-reminder>tags, matching mid-turn delivery~/.claude.jsonis read-onlyv2.1.233--worktreeflag and theclaude agentsview (where MRs display as!N)forward_user_identityapps gateway setting on Anthropic upstreams that sends the signed-in user's identity as headers, so a proxy behind the gateway can attribute spend per userCLAUDE_CODE_TOOL_MEMORY_LIMIT) so a runaway build can't stall the sessionCLAUDE_CODE_WEBFETCH_CACHE_TTL_MSenvironment variable to configure the WebFetch session URL cache TTL (default unchanged: 15 minutes)/checkupand/reviewreporting "Unknown command" in-pmode or with plugins/MCP loaded when a user or project skill shadows the bundled skill\??\device prefix bypassing UNC path validation, closing an NTLM credential-leak vectorclaude self-hosted-runnersession start time: the session branch is now created without rewriting the working tree, and two server round trips no longer block the agent's launchclaude plugin validateto check a bare.claude/skillsdirectory, reporting SKILL.md files whose frontmatter fails to parse/effortselector renders as a numbered list with a typed-number prompt, and hint and dialog text is no longer clipped[claude-code:unrecognized_model]line is written to stderr when a request goes out for a model ID Claude Code doesn't recognize; map it withmodelOverridesto silenceCLAUDE_CODE_ENABLE_TODO_TOOLS=1to bring them backcd <dir> && <command> > fileBash commands (a 2.1.232 regression)< file); a narrower version will return in a later releasev2.1.232subagent_type: "fork"subagent inherits the full conversation and prompt cache, and non-teammate agent spawns in interactive sessions now run in the background by default@in the prompt to mention another Claude session by name; Claude then usesSendMessageto reach that session directlySendMessagenow delivers to a bare name that exactly matches one live session, instead of asking to confirm with a ref firstname-word-wordvariant and tells you/configrows for "Dialog expiry" and "Messages from your other sessions" (cross-session inbound accept/hold/refuse)glrt-,gloas-,glptt-,glagent-,glimt-,glsoat-,glcbt-,glft-,glffct-) and full redaction of routableglpat-/gldt-tokens; theglabCLI config store gets the same sandbox and credential-path protection asghgitlab.comrepo URLs (including nested subgroups) now clone likegithub.comURLs, and clone auth-failure hints name your actual git hostadditionalMarketplacesandallowedMarketplacesare now accepted as friendlier aliases forextraKnownMarketplacesandstrictKnownMarketplacesblockedMarketplacesentry for a bare repo URL keeps blocking that URL when the CLI classifies it as a git clonedesktop:overlay now accepts every released Desktop setting (was 11 hand-listed keys), validated at boot against Desktop's own schema; unknown or invalid keys fail bootmanaged.policies[].match.groups/admin.admin_groupsentries and malformedemail_domainvalues (empty, or containing@, whitespace, or commas) now fail at boot instead of silently matching no one or granting admin access/advisoragain for organizations with Fable access, with usage-credits consent set up through/model fable$PSDefaultParameterValuesand redirect later commands' file access/loginexiting silently or leaving an unresponsive terminal after "Press Enter to continue" when managed settings failed to load; the reason is now shownknown_marketplaces.json/updateand/tuirefusing to restart while work that survives the relaunch was running--advisor fablelaunches, which told you to run/model fablein an interactive session that had just exitedsandbox.bwrapPath,sandbox.socatPath,sandbox.ripgrep)/feedbackand/bugnow open immediately when invoked while Claude is responding, instead of waiting for the turn to finish/plugin install plugin@marketplacenow refreshes the marketplace first, so newly published plugins install without a manual marketplace update/code-reviewat high, xhigh, and max effort now runs in a background agent like the other levels/remote-controlthere to move it/tasksfooter hint, and the "↓ N more" overflow indicator moved left for visibility< file) are now permission-checked like their argument spellings on all platforms/tmp: a pre-planted symlink or another user's directory is now refused instead of usedsandbox.ripgrepto be honored only from user, managed, and--settingssettings; project settings can no longer override the sandbox's ripgrep binary/poweruptourv2.1.228git/ Git Bash not being found on Windows when Claude Code is launched from a parent folder of the git installation/tuireverting the session to an earlier model when/modelhad been changed since the last response/resumewhile connected leaking the resumed conversation's title or history into the connected sessionclaude self-hosted-runnersessions failing on every fresh runner when thecheckouthook fails for a repository the session doesn't push to; that repository is now skipped with a warning!commands or expand@filesv2.1.227claude-code-actionwithallowed_non_write_userson GitHub-hosted runners/tuibringing back a conversation that had been rewound to before its first messagev2.1.226v2.1.224claude self-hosted-runnerturns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plansarchiveplugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinningANTHROPIC_BEDROCK_REGION_PREFIXenv var for Bedrock to prefer a specific cross-region inference profile over theAWS_REGION-derived onecrossSessionInboundanddialogExpirysettings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliverextractandonExtractNoMatchfor structured env values,decode: "jwt"withmaskClaimsfor JWT-aware masking, andawsPairs/sigv4for AWS SigV4 re-signing; these neednetwork.tlsTerminateand are honored only from user, managed, or--settingssettingsSendMessage: Claude Code sessions can now message each other, on any of your machines, withListAgentsto discover them (macOS and Linux)/resumeno longer cross projectsSendMessagereporting "Message sent" when the write to a teammate's inbox had actually failed; failed deliveries are now reported as errorsdenyRead: "~/.aws/") being silently bypassable on Linux and macOS/clearand other output-less commands/clearresets now propagate to attached clientsCLAUDE.mdinstructions), tool definitions, and model parameters. Secrets are redacted as before, and these fields are dropped first if the share is too large/resume--resume, SDK hosts, and the VS Code extension)remoteControlAtStartupwhen explicitly enabledv2.1.223"owner/*") to thestrictKnownMarketplacesandblockedMarketplacesmanaged settings for allowing or blocking all marketplace repos under a GitHub org/teleporthint in cloud sessions showing how to continue locally withclaude --teleport <session id>import()to run code outside the workflow sandboxbypassPermissionsmode ignored the org bypass-permissions disable policy/cdcoming back emptyvertex_ai/claude-*orbedrock/anthropic.claude-*modelOverrideskeys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documentedmanaged-settings.jsonor MDM profile; admin env now merges per keysandbox.filesystem.denyWritecovers the working directorygit pushoutputCLAUDE_CODE_DISABLE_1M_CONTEXTto hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200KCLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1to restore the previous behavior/reviewto be an alias of/code-review, which reviews the current diff or a PR (/code-review <level> <pr#>); use/code-review ultrafor a deep cloud review/code-reviewwith no effort level to reuse the level you typed last; type a level like/code-review highto change itv2.1.222/usage-creditson Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one/usageoverattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to itmodel: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the familyANTHROPIC_BASE_URLgateways despite server keep-alive pings arriving on the wire/loginhint insteadSendMessagerejecting a long summary — it now truncates instead, so sends no longer fail on a character limiteffort:setting--ax-screen-readermode — end-of-line deletions now echo just the deleted charactersmanaged-settings.jsonwhenCLAUDE_CODE_PROVIDER_MANAGED_BY_HOSTis setSendMessageare now evaluated by the permission classifier before dispatchdisable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow/diffview, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv.claude/settings.jsonor.claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via/configv2.1.221Ctrl+Alt+For the "Claude Code: Toggle Focus view" commandmode: "mask"for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by anextractregex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back todenyclaude plugin validatewhen a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace syncprompt-auditsubcommand to theclaude-apiskill for auditing prompts and tool descriptions for patterns written for older models[[ ]]regex conditionals; affected commands now prompt for permission--mcp-confignot being connected before the first turn in print mode (-p), which made the model emit tool calls as literal textconstructorxhigh/maxwhen thinking is disabledHOMEenvironment variableCLAUDE_CODE_RESUME_INTERRUPTED_TURN=0not disabling interrupted-turn auto-resume; falsy values are now honored/help,/feedback) being un-invocable in non-interactive sessions/ultrareviewerror messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggestgit fetch --unshallowon clones that are already completepowershell.exeno longer prompt/plugin installto refresh a stale marketplace catalog and retry before reporting a plugin not found/pluginto activate immediately when safe, instead of always requiring/reload-plugins"."as askillspath, and the root-levelSKILL.mdvalidation error now suggests using the plugin root/statusto show the session kind:interactive, or a background job that isattachedorunattended:thumbsup:,:thumbsdown:, and:love:/forkto create a new worktree of their own instead of working in the original session's checkoutmodelfield validation: non-string values are rejected with a 400 instead of being forwardedv2.1.220v2.1.219claude-opus-5), now the default Opus model — 1M context, fast mode at $10/$50 per Mtoksandbox.network.strictAllowlistsetting to deny non-allowlisted hosts for sandboxed commands without promptingDirectoryAddedhook that fires after/add-diror the SDKregister_repo_rootcontrol request registers a new working directory mid-sessionmcp_server_errorsto the headless stream-json init event, listing--mcp-configentries skipped by config validation; terminal runs print a startup warningworkflowSizeGuidelinesettings key so the advisory Dynamic workflow size guideline can be set from any settings file; the/configrow is hidden while one does--forward-subagent-textis set, keyed by their spawning Agenttool_useidclaude -ptext output dropping the answer already produced when a turn dies on a mid-stream API errorclaude mcp listand/mcpwhen a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace/modelpicker showing the merged Opus row as plain "Opus" instead of "Opus (1M context)"CLAUDE_CODE_GIT_BASH_PATHon Windows exiting or being used as bash when the path isn't a bash/sh binary; it's now ignored with a warningclaude --teleportto show which repo your current checkout points at when it doesn't match the session's repo/config${VAR}entries to resolve from the startup environment and managed-settings env instead of settings-file env/modelpicker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list/configfor changing it/fastnow applies to Opus 5 and Opus 4.8v2.1.218/code-reviewto run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review targetOption+Delete,Ctrl+W,Cmd+Backspace,Ctrl+U,Ctrl+K) in--ax-screen-readermode\u-prefixed segments (likeC:\Users\unicorn) being corrupted into CJK characters in tool inputs, which made those files inaccessiblejin place of newlines in terminals that encode pasted newlines as Ctrl+J/contextreporting stale pre-compact token usage after compacting from the message picker/ultrareviewfailing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings/code-review ultrasilently running a local review in non-interactive sessions — it now launches the cloud reviewtool_useblock left in the transcript when a tool aborted mid-response--ax-screen-readermodeCtrl+Bbackgrounding now applies the same background-shell caps as other paths/ultrareviewerror feedback so Claude can correct an invalid argument instead of retrying it unchanged&, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead/deep-researchto start only when invoked manually; Claude no longer launches it on its own/config model=<x>or Remote Control:, which is reserved for plugin namespacingcontext: forkto run in the background by default; opt out per skill withbackground: falseyes/no/on/off/1/0(case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongsidetrue/falsev2.1.217:heart:to insert ❤️, or:heafor suggestions — disable with theemojiCompletionEnabledsettingclaude.exemissing; failed updates now restore the preserved executable automatically/compactfailing once over the limitOTEL_EXPORTER_OTLP_ENDPOINTnot governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint--resume/--continueand/resumefailing with a TypeError when a transcript has a malformed attachment entry/backgroundor←) or when the session exits on a heavily loaded machine, most visible on WindowsCLAUDE.mdorSKILL.mdpaths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-boundedFORCE_HYPERLINK=0to opt outCLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS) so one message can't fan out unbounded background agentsCLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTHto allow deeper nesting--max-budget-usdnot stopping background subagents: once the cap is reached, new spawns are denied and running background agents are haltedv2.1.214dir/**allow rules likeEdit(src/**)auto-approving writes to nesteddir/directories anywhere in the tree instead of only<cwd>/dir[[ ]]comparisons as inert text — these commands now prompt for approvalhelpandmancommands that could run unsafe options, command substitutions, or backslash pathsmodifiedtimestamp to memory file frontmattermessage.uuid,client_request_id, andtool_sourceattributes to OpenTelemetry log events for message-level correlation and tool provenanceCLAUDE_CODE_OTEL_CONTENT_MAX_LENGTHto configure the 60 KB truncation limit on OpenTelemetry content attributessubagentStatusLinepayload, so custom agent rows can render model and effortdockercommands (including the Podmandockershim) carrying daemon-redirect flags (--url,--connection,--identity, and Podman's remote mode) that previously ran without onepkill -fpattern accidentally matched the CLI's own process (Linux)--settingspoints at a device file or multi-GB file; oversized (>2 MiB) settings files now fail at startup with a clear errorwhere.exe,fc.exe, anddiff.exeas errors when they return a valid negative answer (Windows)>and>>under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8←or/backgroundand left idle keeping the background daemon and a worker process alive indefinitelyclaude rmor the agent view once the background service had gone idle/install-github-appand the/mcpsettings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached--settingsCLI flag not loading (regression since v2.1.181)/ultrareviewrefusing to run in repos with no merge base — it now offers to review all tracked filesclaude updateandclaude doctorhanging silently, and the/statusSystem diagnostics section going blank, when a shell-config path is a directory#when memory files are savedmessage_deltaframesclaude rcworkspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directorydir/**hookif:conditions to match only<cwd>/dir; write**/dir/**for any-depth matching.deny/askpermission rules keep their any-depth match.filecommands using-m/--magic-fileor-f/--files-fromto require permission instead of being auto-allowed as read-only"fork"when a session begins as a fork instead of"resume"v2.1.212/forknow copies your conversation into a new background session (its own row inclaude agents) while you keep working; the in-session subagent it used to launch is now/subtaskclaude auto-mode resetto restore the default auto-mode configuration, with a confirmation prompt (pass--yesto skip)CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION) to stop runaway search loopsCLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION) to stop runaway delegation loops;/clearresets the budgetCLAUDE_CODE_MCP_AUTO_BACKGROUND_MS/resumein the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background sessiontouch,rm) without a permission prompt or SDKcanUseToolcallback.claude/worktrees, which could create files outside the repositorycontinue:falsehook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections/backgroundandclaude --bgfailing with "EUNKNOWN: unknown error, uv_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7!) not executing commands containing file paths while the path autocomplete popup was open?help overlay/ultrareviewrejecting PR references like#123,PR 123, and pasted PR URLs; error hints now name the command you actually typed/ultrareview <branch>not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos/ultrareviewskipping the billing confirmation in a new conversation after/clear/ultrareview's "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commandsExitWorktreefailing with "no active EnterWorktree session" after resuming a session with--continue/--resumein print/SDK mode/forklosing their live-parent protection after a state write failuretrace_id/span_idwhenTRACEPARENTis set in SDK/headless modeSendMessagebodies are no longer duplicated into replayed history and tool results/forkto name the copy after your prompt when the session has no title, so the row is recognizable in the agent view/btwto reopen the side-question panel on your most recent exchange so you can browse earlier answers←footer hint to pulseN donefor a moment when a background agent finishes while nothing needs your inputmodeparameter (now ignored); subagents inherit the parent session's permission mode by defaultforceLoginMethodto be enforced for VS Code extension, SDK,setup-token, andinstall-github-applogins, not just the terminalset_modelcontrol request mid-turn; the next model round-trip uses the new model instead of waiting for the next turnclaude agents --json: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working"v2.1.211--forward-subagent-textflag andCLAUDE_CODE_FORWARD_SUBAGENT_TEXTenvironment variable to include subagent text and thinking in stream-json outputaskdecision for unsandboxed Bash — a hookasknow floors the decision at a prompt.claude/rules/*.mdfiles loading even when setting sources exclude project settings.prn) or trailing dot are now accepted, and files with multiple hard links are refused/loophiding the session from/resumeafter a single use/terminal-setupor onboarding terminal setupANTHROPIC_AUTH_TOKEN+ANTHROPIC_BASE_URL) coming back "Not logged in" after the daemon respawns themclaude agentsjobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing/clearnot resetting the session cost counter — the statusline's cost now starts at $0 after/clear/clear1e6and64_000/usage-creditsto ask for confirmation before sending a request to organization adminssandS(substitute char/line) to work in NORMAL mode, matching vim behaviorsave_to_diskon screenshot actions now writes the image to disk and returns the path; previously it did nothingv2.1.210Write(path),NotebookEdit(path), andGlob(path)permission rules — useEdit(path)orRead(path)insteadisolation: 'worktree'subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktreeultracodekeyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR commentsclaude attachsometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completescdtook effect after its command was moved to the background; the tool result now states the working directory is unchanged/doctorskipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in$1/$2positional placeholders in skills and commands being silently stripped; they are now preserved verbatimclaude agents --effort ultracodenot reaching dispatched sessions; the value was silently droppedgit worktree lockbehind; the periodic sweep now releases locks whose owning process is goneinitializecontrol request waiting until the next turn to start connectingCLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1.claude/*symlinks not being reconciled into the sandbox deny-write listv2.1.209claude agentsbackground sessions (reverts an overly broad guard)v2.1.207CLAUDE_CODE_ENABLE_AUTO_MODEopt-in on Bedrock, Vertex AI, and Foundry; disable viadisableAutoModein settingsclaude -p, the SDK) being permanently recorded as consented without ever showing the security consent dialog~/.local/bin/claudeon every release;/doctornow reports an externally managed launchercdprompting for permission when the only output redirect was to/dev/nullextensions.worktreeConfigbeing left in the repo's.git/config(breaking go-git tools liketea) after the lastworktree.sparsePathsworktree was removed.ignore, and.worktreeincludebreaking file reads, file suggestions, and worktree creation[Pasted text #N]placeholder instead of adding a second onewaiting 3m) instead of the same timestamp twiceautoModefrom.claude/settings.local.json(repo-resident); use~/.claude/settings.jsoninsteadcredential_process): the 60-second stall guard now fires instead of waiting forever.${user_config.*}in shell-form commands is now rejected (shell-injection fix). Hooks: use exec form (argsarray) or$CLAUDE_PLUGIN_OPTION_<KEY>; monitors and headersHelper: read the value inside the script (config file or the server'senvblock).pluginConfigs) are no longer read from project-level.claude/settings.json; only user,--settings, and managed settings are honored/usage-creditsamount inputs silently stripping malformed values (e.g. a pasted timestamp) to digits; malformed amounts are now rejected with an error, and amounts over $1,000 require a typed confirmationv2.1.206/cd, matching/add-dirbehavior/doctorcheck that proposes trimming checked-inCLAUDE.mdfiles by cutting content Claude could derive from the codebase/commit-push-prnow auto-allowsgit pushto the repo's configured push remote (remote.pushDefault, or the sole remote when only one is configured) in addition toorigin/loginnow supports Anthropic-operated public gateway endpointsEnterWorktreenow asks for confirmation before entering a git worktree outside the project's.claude/worktrees/directory/loginclaude --resumeand--continuenot responding to keyboard input on startup--mcp-configor.mcp.jsonignoring a per-serverrequest_timeout_ms, which caused long-running MCP tool calls to time out at the 60s default in fresh sessionsCLAUDE_CODE_EXTRA_BODYbeing silently ignored byclaude agents/--bgbackground workers; the shell-exported override now follows the dispatching session--permission-prompt-toolpointing at an MCP server crashing with "MCP tool not found" on cold start before the server finishes connecting/modelpicker rows printing a price for a different model than the row named, and stopped quoting first-party list prices on providers that don't bill them/modelpicker when an entitlement or allowlist restriction drops the row they were positioned againstclaude --resumeon Windowsclaude rmleaving the removed job in the daemon roster, causing the row to reappear inclaude agents/remote-controlshowing "Unknown command" when logged out — it now explains how to sign in/statuslisting the same broken-install warning twice/doctor's update check to compare Homebrew installs against their cask's channel instead of the settings channelawsCredentialExporthelper on networks with restricted egress/code-reviewfindings quality on claude-opus-4-8 across all effort levelsv2.1.204v2.1.202/configfor controlling how large Claude generally makes dynamic workflows (small/medium/large agent counts) — an advisory guideline, not an enforced capworkflow.run_idandworkflow.nameOpenTelemetry attributes to telemetry emitted by workflow-spawned agents, so a workflow run's activity can be reconstructed from OTel data/renameon background sessions being reverted when the job restarts, which broke addressing the session by its new nameclaude auth loginandclaude mcp login --no-browsernot being reliably clickable when it wraps over SSH — it is now emitted as a single hyperlinkclaude agentssometimes failing with "currently running as a background agent" followed by a worker crash/respawn loop/remote-controlsessions showing the wrong permission mode in the mobile and web apps/workflowsagent list layout: wider titles, a dedicated time column, shorter model names, and no per-row tool-call countsurlbut notype, suggesting"type": "http"instead of the misleading "command: expected string"/review <pr>back to a fast single-pass review; use/code-review <level> <pr#>for the multi-agent review at a chosen effort levelv2.1.201v2.1.199/skill-a /skill-b do XYZnow load all leading skills (up to 5), not just the firstNODE_EXTRA_CA_CERTS, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hintclaude stopbeing silently undone when it raced a background-agent respawn — the respawn now honors the stop/modelor/fastwhile viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the leadSessionStart,Setup, andSubagentStarthooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcriptclaude --dangerously-skip-permissions daemon <subcommand>being treated as a chat prompt instead of running the subcommandSendMessagesilently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget←or/backgrounddropping its/colorfrom the agent view rowbrowser_batchcalls are now correctly auto-allowedCLAUDE_CODE_RETRY_WATCHDOGnow raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 onCLAUDE_CODE_MAX_RETRIESclaude agentssession rows now show pull-request links as bare#Nwithout the redundant "PR" labelv2.1.198claude agents— sessions that need input or finish now fire theNotificationhook (agent_needs_input/agent_completed)/datavizskill for chart and dashboard design guidance with a runnable color-palette validatorclaude agentsnow commit, push, and open a draft PR when they finish code work in a worktree, instead of stopping to ask/diffpanel not refreshing when you switch branches or commit outside the sessionawsAuthRefreshnow runs automatically/desktopfailing with "Cannot determine working directory" after entering and exiting a worktree←insideclaude attach <id>exiting to the shell instead of opening the agent viewclaude --bgsilently creating an unattachable session when combined with--print/-p; the conflicting flags are now rejected up front.claude/rules/conditional rules not loading when the target file is reached via a symlinked path/branchderiving its default fork name from the compaction summary instead of the first real prompt/loginnow opens the sign-in dialog from theclaude agentsview instead of saying it isn't available/agentswizard; ask Claude to create or manage subagents, or edit.claude/agents/directlyv2.1.197v2.1.196/modelwhen you haven't picked one yourselfclaude mcp list/getno longer spawn.mcp.jsonservers that a repo self-approved via a committed.claude/settings.json; untrusted workspaces show⏸ Pending approvalgit diff/git grep,egrep/fgrep, and quoted search patterns containing|being reported as failures when they exit 1, matching Bash behaviorclaude agentsside panel issues: keyboard focus getting stuck when opening an agent, background jobs losing their subagent types on every open, and sessions showing incorrect status while actively runningclaude agents --dangerously-skip-permissionssilently falling back to auto mode instead of showing the bypass disclaimer and applying bypass mode to spawned agents/cdreappearing in the old directory's resume list after a non-graceful exit when the old path contained special charactersclaude plugin validateskipping local plugins whose source is "." and stopping after the first error classscopes_supportedcatalog when no scope is specified, causinginvalid_scopefailures on GitLab self-hosted and other enterprise IdPs/contextshowing 0 tokens for all tool groups on Bedrock/deep-researchmisreporting verifier failures as "all claims refuted" instead ofunverifiedclaude agentssession status: completed rows no longer flip between "Done" and "Needs your input", stalled agents are now labeled "Needs attention", and results that mention a PR show a clickable link/code-reviewworkflow: merged five cleanup finders into one, cutting token usage by roughly 25%CLAUDE_ENABLE_STREAM_WATCHDOG=0to disable.ANTHROPIC_BASE_URLpoints at a non-Anthropic host, matching the existing behavior underCLAUDE_CODE_USE_BEDROCK/_VERTEX/_FOUNDRY←press instead of two, matching the behavior in background sessionsv2.1.195CLAUDE_CODE_DISABLE_MOUSE_CLICKSto disable mouse click/drag/hover in fullscreen mode while keeping wheel scrollcode-reviewer,mcp__brave-search) accidentally substring-matching — they now exact-match. Usemcp__brave-search__.*to match all tools from a hyphenated MCP server..claude/settings.jsonnot requiring explicit install consent on every loader path/pluginEnable/Disable not working when a plugin'splugin.jsonnamediffers from its marketplace entry nameclaude agentsor losing data when written by a newer Claude Code versionclaude agentscompleted list to fill available vertical space; on short terminals the header compacts so live sessions stay visiblev2.1.193autoMode.classifyAllShellsetting to route all Bash/PowerShell commands through the auto-mode classifier instead of only arbitrary-code-execution patterns/permissionsrecent denialsclaude_code.assistant_responseOpenTelemetry log event containing the model's response text. Redacted unlessOTEL_LOG_ASSISTANT_RESPONSES=1; when that var is unset it followsOTEL_LOG_USER_PROMPTS, so deployments that already log prompt content will start receiving response content on upgrade — setOTEL_LOG_ASSISTANT_RESPONSES=0to keep prompts-only.!)/mcpCLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP=1)/modeland other client-data-gated UI showing stale/empty state immediately after/loginheadersHelperauth: the helper now re-runs and reconnects automatically when a tool call returns 401/403renamesmaps are now followed automatically, updating your settings to the new name/add-dirmessage when the directory is already a working directoryv2.1.185v2.1.179denyRead/allowReadglob over a large directory tree making the Bash tool description enormous and the session unusable on Linuxv2.1.175enforceAvailableModelsmanaged setting — when enabled, theavailableModelsallowlist also constrains the Default model (a Default that would resolve to a disallowed model now falls back to the first allowed model), and user or project settings can no longer widen a managedavailableModelslistv2.1.172~/.awsconfig files whenAWS_REGIONisn't set, matching AWS SDK precedence;/statusshows where the region came from/pluginmodelattribute to theclaude_code.lines_of_code.countOTEL metric.mcp.jsonapprovals, trust) when dispatched onto a pre-warmed worker/modelsuggestions in theclaude agentsdispatch input rendering with a misleading slash prefix and showing models disabled for your orgavailableModelsrestrictions not being applied to subagent model overrides, the agent dispatch model picker, and the advisor modelavailableModelsallowlists hiding the/modelpicker's Opus and Sonnet 1M rows when entries use version-specific IDs likeclaude-opus-4-8/modelpicker on Bedrock offering models the provider doesn't serve — selecting one silently switched the session model and lit the selection marker on multiple rows[1M][1m]) whenANTHROPIC_DEFAULT_OPUS_MODELalready includes oneopusplanmodel setting not shipping with 1M context in plan mode for entitled users; theopusplan[1m]workaround now also correctly switches to Opus in plan modeWebFetch(domain:*.example.com)wildcard domain rules never matching subdomains in allow, deny, and ask position, and file permission rules with mid-pattern wildcards (e.g.Read(secrets-*/config.json)) being rejected at startupCLAUDE_MEMORY_STORES) in remote sessionsDate.now()/Math.random()/pluginmarketplace list losing its cursor after backing out of a long plugin list, and Esc from the plugin browser returning to the wrong tab/goalstatus chip no longer re-renders the terminal at 5 Hz while idle, and fewer UI re-renders while subagents run in parallel/code-reviewnow keeps theultraoption visible when you're not signed in to claude.ai, with an explanation that the cloud review requires a claude.ai account/loopin remote sessions, where pending loops don't keep the container alivev2.1.161OTEL_RESOURCE_ATTRIBUTESvalues are now included as labels on metric datapoints, so you can slice usage metrics by custom dimensions like team or repoclaude agentsrows now showdone/totalbefore the detail when work is fanned out; peek shows the longest-running item/mcpnow collapses claude.ai connectors you've never signed in to behind a "Show unused connectors" rowwl-copy/xclip/xselon Linux when available, copies to both the clipboard and PRIMARY selection for middle-click paste, and the "hold {key} for native selection" hint now shows the correct key per terminal/effortdialog, workflow animations, and prompt keyword shimmer not honoring the "Reduce motion" settingforceLoginOrgUUID/forceLoginMethodmanaged-settings policies blocking third-party provider sessions (Bedrock, Vertex, Foundry, Mantle) alongside the org pin (regression in 2.1.146)claude -pstdout when using--output-format textorjson/usage-creditsstarting a re-login for Team and Enterprise admins instead of pointing to the organization's usage settings page/autofix-prreporting "cannot run on the default branch" when the session is inside a git worktree or another repository--resumepicker not showing sessions from the current directory when it isn't a git worktree (e.g., jj workspaces)/usr/bin/bash script.sh) failing with "command not found" or "cannot execute binary file"user_prompt,api_request,tool_result,tool_decision) being silently dropped when emitted before telemetry initialization completedclaude mcplist/get/add printing secrets to the terminal:${VAR}references are no longer expanded, and credential headers and URL secrets are redactedisolation: "worktree"in background sessions being blocked from editing files inside their own worktreeclaude agentsbooting on a stale model from the daemon's environment instead of the model insettings.jsonEADDRINUSEerrors from tools that bind Unix sockets under$TMPDIRwhenCLAUDE_CODE_TMPDIRis set to a deep path/terminal-setup) to fix garbled glyphsv2.1.158CLAUDE_CODE_ENABLE_AUTO_MODE=1v2.1.154/workflowsto view your runs/simplifynow runs a cleanup-only review (reuse, simplification, efficiency, altitude) and applies the fixes, instead of running the full/code-review --fixbug-hunting review/effortslider labels from "Speed"/"Intelligence" to "Faster"/"Smarter" for clarityclaude agents: type! <command>to run a shell command as a background session you can attach to and detach from. Also available asclaude --bg --exec '<command>'claude agents:/logoutnow signs you out instead of being sent to a background session←←to open the agents view now works on Bedrock, Vertex, Foundry, and with telemetry disabled/chrome→ "Select browser…", or in-chat when a browser action runs with multiple connecteddefaultEnabled: falseinplugin.jsonor a marketplace entry; enable them with/pluginorclaude plugin enable. Dependencies of enabled plugins are still enabled automatically/pluginDiscover tab now pins plugins whose relevance signals match the current directory with a "suggested for this directory" annotationCLAUDE_CODE_SESSION_IDandCLAUDECODE=1in their environmentclaude mcp list/getnow show unapproved.mcp.jsonservers as⏸ Pending approvalinstead of auto-approving and connecting when output is piped/remote-controlautocomplete now shows "Disconnect Remote Control" when Remote Control is already active/claude-apiskillCLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE(will be removed on 06/01). To use fast mode on Opus 4.6, switch with/model claude-opus-4-6[1m]and then/fast onrm -rf $HOMEnot being blocked as a dangerous path whenHOMEhas a trailing slash$TMPDIRresolving to different directories in sandboxed vs unsandboxed Bash commands within the same sessionclaude agentswhen the Claude Code theme doesn't match the terminal background/commandfiresclaude --bg-pty-hostprocesses spinning at 100% CPU after the daemon exits on macOSworktree.baseRef: "head"resolving to the main checkout's HEAD instead of the current worktree's HEAD when spawning subagents or callingEnterWorktreefrom inside a linked worktree[Image #N]/[Pasted text #N]placeholders when a plan-mode prompt starts with pasted images or textallowedMcpServers/deniedMcpServersentry in managed settings discarding all managed-settings policy; the bad entry is now dropped with aclaude doctorwarningCLAUDE_CODE_ALWAYS_ENABLE_EFFORTis setclaude.exebeing in use showing a generic error instead of telling you to close other sessions and retryv2.1.152/code-review --fixnow applies review findings to your working tree after the review, surfacing reuse, simplification, and efficiency suggestions;/simplifynow invokes/code-review --fixdisallowed-toolsin frontmatter to remove tools from the model while the skill is active/reload-skillscommand to re-scan skill directories without restarting the sessionSessionStarthooks can now returnreloadSkills: trueto re-scan skill directories, making skills installed by the hook available in the same sessionSessionStarthooks can now set the session title viahookSpecificOutput.sessionTitleon startup and resumeMessageDisplayhook event that lets hooks transform or hide assistant message text as it is displayedpluginSuggestionMarketplacesmanaged setting: admins can allowlist org marketplaces whose plugins may be suggested via context-aware tipsclaude plugin marketplace removenow accepts--scope user|project|localfor symmetry withmarketplace add,install, anduninstall--fallback-modelfor the rest of the session when the primary model is not found, instead of failing every request/in NORMAL mode now opens reverse history search (like Ctrl+R), matching bash/zsh vi-mode/usagebreakdown now includes large session files; files are scanned with a streaming read so memory usage stays flatCtrl+Oshows the full thinking)app.entrypoint, opt-in viaOTEL_METRICS_INCLUDE_ENTRYPOINT=true)/doctorreporting "marketplace not found" or "plugin not found" for staleenabledPluginsentries referencing removed marketplaces or dropped plugins--bareor with attachments disabledclaude agentswhen accepting a stale permission prompt after a subagent was cancelledcache_creation_input_tokensreporting as 0 in transcript and result usage when the API reports cache writes only via the nestedcache_creationbreakdownv2.1.148v2.1.146What's changed
/simplifyto/code-reviewwith an optional effort level (e.g./code-review high)AskUserQuestionwhen the user or a skill explicitly relies on itpwshis installed via winget or the Microsoft Store (regression in v2.1.124)resources/list,resources/templates/list, andprompts/listdropping items past page 1 on paginating servers/backgroundrefusing sessions whose only typed input was a skill or custom slash command/themecolor editor and "New custom theme" dialogs not responding to EscforceLoginOrgUUIDandforceLoginMethodmanaged-settings policies not being enforced against third-party-provider and API-key sessionsCLAUDE_CODE_SUBAGENT_MODELnot being forwarded to child processes in multi-agent sessionsv2.1.145claude agents --jsonto list live Claude sessions as JSON for scripting (tmux-resurrect, status bars, session pickers)agent_idandparent_agent_idattributes toclaude_code.toolOTEL spans, and fixed trace parenting so background subagent spans nest under the dispatching Agent tool span/pluginDiscover and Browse screens now show a plugin's commands, agents, skills, hooks, and MCP/LSP servers before installationclaude agentsterminal tab title now shows the awaiting-input count so an alt-tabbed window tells you when an agent needs attentionbackground_tasksandsession_cronsfields;as the command separatorgh pr createand other PR-state-changing commands run in-session/reviewusing a deprecatedprojectCardsGraphQL query that errored on repos with Classic Projectsclaude plugin validatenot flaggingskills:entries that point at a file instead of a directory — the error now suggests the parent directorycontext: forkcould repeatedly re-invoke itself instead of runningv2.1.143claude plugin disablenow refuses when another enabled plugin depends on the target (with a copy-pasteable disable-chain hint), andclaude plugin enableforce-enables transitive dependencies/pluginmarketplace browse paneworktree.bgIsolation: "none"setting to let background sessions edit the working copy directly withoutEnterWorktree, for repos where worktrees are impractical-ExecutionPolicy Bypass. Opt out withCLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY=1.credentials.jsonwith a non-arrayscopesvalue hanging the CLI on startup or silently aborting OAuth token refreshclaude agentson Windows Terminal and WSLCLAUDE_CODE_STOP_HOOK_BLOCK_CAP)/loopwakeup while Claude is idle between iterations/goalevaluator firing while background shells or delegated subagents are still runningNO_COLOR/FORCE_COLORin settings.jsonenvstripping Claude Code's own UI colors — they now apply to subprocesses only/bgwithout a prompt sending "continue" to the forked session — the fork now waits for input--agent <name>not finding plugin-contributed agents without theplugin:prefixCLAUDE_CODE_USE_POWERSHELL_TOOL=0.claude agentsnow accepts--add-dir,--settings,--mcp-config, and--plugin-dirand applies them to the dashboard and to background sessions dispatched from itclaude agentsaccepts--permission-mode,--model,--effort, and--dangerously-skip-permissionsto set defaults for sessions dispatched from the viewclaude --bg --dangerously-skip-permissionsnow persists across retire→wakeclaude agentsrm -rfwhengit worktree removefails, preventing loss of gitignored or in-progress files~/Documents,~/Desktop, or~/Downloads, even with Full Disk Access granted./bgnow preserves--mcp-config,--settings,--add-dir,--plugin-dir, and--strict-mcp-config, so backgrounded sessions keep their MCP servers and settings across respawn.claude agentsnow honorpermissions.defaultModefrom settings.json (was previously overridden to auto mode)claude agentswhile a response was streaming could leave the agents list unresponsive to all input/bgand←-detach now preserve--fallback-model, so backgrounded workers degrade to the fallback model on overload instead of hard-failing./bgand←-detach now preserve--allow-dangerously-skip-permissions, so the forked worker keeps bypass-permissions available in its Shift+Tab cycle.~/.local/bin/claudelauncher is missing or non-executableclaude agents --allow-dangerously-skip-permissionsdefaulting dispatched sessions to bypass mode instead of making it available in the permission cyclev2.1.141terminalSequencefield to hook JSON output so hooks can emit desktop notifications, window titles, and bells without a controlling terminalCLAUDE_CODE_PLUGIN_PREFER_HTTPSto clone GitHub plugin sources over HTTPS instead of SSH, for environments without a GitHub SSH keyANTHROPIC_WORKSPACE_IDenvironment variable for workload identity federation — scopes the minted token to a specific workspace when the federation rule covers more than oneclaude agents --cwd <path>to scope the session list to a directory/feedbackcan now include recent sessions (last 24 hours or 7 days) for issues spanning more than the current sessionpermissions.askrule caused the prompt/bgor←←now preserve the current permission mode instead of reverting to defaultclaude agents: agents that finish work but leave a background shell running now move to Completed instead of staying under Working→/Tab switch tabs,↑moves to the tab strip, and tab headers and search box are clickable in fullscreen modeANTHROPIC_SMALL_FAST_MODELoverride is set — now falls back to the main-loop modelclaude daemon statusand/doctoron Windows throwing when the daemon pipe key file is locked or unreadable — now shows the underlying error instead of an opaque failureclaude agentsshowing the agent-type list instead of the dashboard when launched through a wrapper that adds flagsclaude agentsopening a crashed session firing redundant dispatches when the working directory was deletedANTHROPIC_BASE_URLgateway not getting auto-named — the namer now uses the main model when no Haiku model is configured/modelin one session silently changing the autocompact threshold in other concurrent sessionstranscript_pathafterEnterWorktreeswitches the working directorychat:submitkeybindings (e.g.meta+enter,ctrl+enter) not working whenenteris rebound tochat:newlinespinnerVerbssetting not being honored in turn-completion messagesxon a selected subagent in the agent panel typing into the prompt instead of stopping the agent/tuisilently dropping running background shells and subagents — now refuses and asks to wait for them to finish/mcpserver list not keeping the focused server visible in short terminals in fullscreen mode/feedbackbundles producing invalid JSON for quoted values like session IDsapiKeyHelper/ANTHROPIC_AUTH_TOKENfrom host managed-settingsclaude plugin installfailing for plugins whose marketplacerefno longer exists upstream when ashais also pinned.mcp.json.mcp.jsonentries no longer drop other MCP servers${var%pattern}) being incorrectly flagged as missing environment variables/loginvoice:pushToTalkkeybindings and"space": nullunbinds being silently ignoredawsCredentialExportnow always runs when configured instead of being skipped when ambient AWS credentials resolve, fixing auth for cross-account accesssox libsox-fmt-pulsefor WSLg usersclaude agents: launching a session no longer fails when the pre-warmed background worker is unhealthy — now falls back to a fresh launchclaude agentsno longer shows empty placeholder sessions left over from backgrounding a fresh REPL, and shows onboarding text when entered via ← with no other agents←are now automatically retired by the daemon after 5 minutesv2.1.140subagent_typematching to accept case- and separator-insensitive values (e.g."Code Reviewer"resolves tocode-reviewer)/goalsilently hanging whendisableAllHooksorallowManagedHooksOnlyis set — now shows a clear message instead of an indicator that never resolvesConfigChangehooksclaude --bgfailing with "connection dropped mid-request" when the background service was about to idle-exitextraKnownMarketplacesauto-update policy not being persisted toknown_marketplaces.json/loopscheduling redundant wakeups to poll for background tasks that already notify on completiongh) triggered synchronouswhere.exere-spawns on every checkReadtool calls failing validation whenoffsetis passed as a whitespace-padded or+-prefixed stringcommands/) is silently ignored becauseplugin.jsonsets the matching key. Shown in/doctor,claude plugin list, and/plugin.v2.1.138v2.1.137v2.1.133worktree.baseRefsetting (fresh|head) to choose whether--worktree,EnterWorktree, and agent-isolation worktrees branch fromorigin/<default>or localHEAD. Note: the defaultfreshchangesEnterWorktree's base back toorigin/<default>(it has been localHEADsince 2.1.128) — setworktree.baseRef: "head"to keep unpushed commits in new worktreessandbox.bwrapPathandsandbox.socatPathmanaged settings (Linux/WSL) to specify custom bubblewrap and socat binary locationsparentSettingsBehavioradmin-tier key ('first-wins' | 'merge') to let admins opt SDKmanagedSettings(parent tier) into the policy mergeeffort.levelJSON input field and the$CLAUDE_EFFORTenvironment variable, and Bash tool commands can read$CLAUDE_EFFORTEdit/Writeallow rules scoped to a drive root (C:\) or POSIX/matching incorrectly and always promptingECOMPROMISED) when a history or session-log file lock is compromised by clock skew or slow diskHTTP(S)_PROXY/NO_PROXY/ mTLS not being respected for the full MCP OAuth flow including discovery, dynamic client registration, token exchange, and token refresh--add-dir/ SDKadditionalDirectories/effortin one session unexpectedly changing the effort level of other concurrent sessions, and a related issue where an IDE effort change could be silently droppedclaude --helpnow lists--remote-controlalongside--remote-control-session-name-prefixclaudeCode.claudeProcessWrapperfailing with "Unsupported platform" when the extension build doesn't bundle a Claude binaryv2.1.128/color(no args) now picks a random session color/mcpnow shows the tool count for connected servers and flags servers that connected with 0 tools--plugin-dirnow accepts.zipplugin archives in addition to directories--channelsnow works with console (API key) authentication — console orgs with managed settings must setchannelsEnabled: trueto enable/modelpicker: collapsed duplicate Opus 4.7 entries, and current Opus now shows as "Opus" instead of "Opus 4.7"OTEL_*environment variables, so OTEL-instrumented apps run via the Bash tool no longer pick up the CLI's own OTLP endpointworkspaceis now a reserved server name — existing servers with that name will be skipped with a warninglocalSettingssuggestion for Bash permission prompts, so "Always allow" writes to.claude/settings.local.jsonEnterWorktreenow creates the new branch from local HEAD as documented, instead oforigin/<default-branch>— unpushed commits are no longer dropped/compact, or run with--debug)/exitin Kitty and other terminals that interpret OSC 9 as a notificationclaude -pvia stdin/pluginComponents panel showing "Marketplace 'inline' not found" for plugins loaded via--plugin-dir/configstranding focus — the tab header now stays focused so arrows and Esc keep workinglabel (url)instead of just the URL/faston 3P providers fuzzy-matching to an unrelated skill instead of showing "not available"global.*instead of the region-appropriate prefixSpacein NORMAL mode now moves the cursor right, matching standard vi/vim behavior/renamewithout args failing on resumed sessions whose last entry is a compact boundary--resume/--continueinstalled_plugins.jsonentries pointing at deleted cache directories polluting PATHCLAUDE_CODE_SHELL_PREFIXis set and an argument contains spaces or shell metacharacterscache_creationreduction)/plugin updatenever detecting new versions of npm-sourced plugins--output-format stream-json:init.plugin_errorsnow includes--plugin-dirload failures in addition to dependency demotionsv2.1.123CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS=1is setv2.1.121alwaysLoadoption to MCP server config — whentrue, all tools from that server skip tool-search deferral and are always availableclaude plugin pruneto remove orphaned auto-installed plugin dependencies;plugin uninstall --prunecascades/skillsso you can find a skill in long lists without scrollinghookSpecificOutput.updatedToolOutput(previously MCP-only)claude -p:CLAUDE_CODE_FORK_SUBAGENT=1now works in non-interactive sessions--dangerously-skip-permissionsno longer prompts for writes to.claude/skills/,.claude/agents/, and.claude/commands//terminal-setupnow enables iTerm2's "Applications in terminal may access clipboard" setting so/copyworks, including from tmuxlanguagesettingmcp_authenticatenow supportsredirectUrifor custom scheme completion and claude.ai connectorsstop_reason,gen_ai.response.finish_reasons, anduser_system_prompt(gated behindOTEL_LOG_USER_PROMPTS) to LLM request spansaccessibility.voice.speechLanguagesetting when no Claude Code language is configured/contextnow opens a native token usage dialog/usageleaking up to ~2GB of memory on machines with large transcript histories--resumecrashing on startup in external builds--resumefailing on large sessions when a transcript line was corrupted by an unclean shutdown — the corrupt line is now skippedthinking.type.enabled is not supportederror when using Bedrock application inference profile ARNspromptparameterNO_PROXYnot being respected for all HTTP clients when set viamanaged-settings.jsonunder the native build/usagereturning "rate limited" after a stale OAuth token — now refreshes automaticallysettings.jsoninvalidating the entire settings file/usagedialog content being clipped when no-flicker mode is off/focusshowing "Unknown command" when the fullscreen renderer is off — now explains how to enable itfindin the Bash tool on large directory treesv2.1.119/configsettings (theme, editor mode, verbose, etc.) now persist to~/.claude/settings.jsonand participate in project/local/policy override precedenceprUrlTemplatesetting to point the footer PR badge at a custom code-review URL instead of github.comCLAUDE_CODE_HIDE_CWDenvironment variable to hide the working directory in the startup logo--from-prnow accepts GitLab merge-request, Bitbucket pull-request, and GitHub Enterprise PR URLs--printmode now honors the agent'stools:anddisallowedTools:frontmatter, matching interactive-mode behavior--agent <name>now honors the agent definition'spermissionModefor built-in agentsPostToolUseandPostToolUseFailurehook inputs now includeduration_ms(tool execution time, excluding permission prompts and PreToolUse hooks)owner/repo#Nshorthand links in output now use your git remote's host instead of always pointing at github.comblockedMarketplacesnow correctly enforceshostPatternandpathPatternentriestool_resultandtool_decisionevents now includetool_use_id;tool_resultalso includestool_input_size_byteseffort.levelandthinking.enabledPostToolUsehooks that emit no response payload writing empty entries to the session transcriptENABLE_TOOL_SEARCH)@-file Tab completion replacing the entire prompt when used inside a slash command with an absolute pathpcharacter appearing at the prompt on startup in macOS Terminal.app via Docker or SSH${ENV_VAR}placeholders inheadersfor HTTP/SSE/WebSocket MCP servers not being substituted before requests--client-secretnot being sent during token exchange for servers requiringclient_secret_post/skillsEnter key closing the dialog instead of pre-filling/<skill-name>in the prompt/agentsdetail view mislabeling built-in tools unavailable to subagents as "Unrecognized"/exportshowing the current default model instead of the model the conversation actually used/usageprogress bars overlapping with their "Resets …" labels${user_config.*}references an optional field left blank/planand/plan opennot acting on the existing plan when entering plan mode/reload-pluginsand/doctorreporting load errors for disabled pluginsisolation: "worktree"reusing stale worktrees from prior sessions/statusTaskListreturning tasks in arbitrary filesystem order instead of sorted by IDghoutput contained PR titles mentioning "rate limit"read_filenot correctly enforcing size cap on growing files/doctorwarning about MCP server entries overridden by a higher-precedence scopev2.1.112v2.1.107v2.1.97Ctrl+O) inNO_FLICKERmode showing prompt, one-line tool summary with edit diffstats, and final responserefreshIntervalstatus line setting to re-run the status line command every N secondsworkspace.git_worktreeto the status line JSON input, set when the current directory is inside a linked git worktree● N runningindicator in/agentsnext to agent types with live subagent instances.cedar,.cedarpolicy)--dangerously-skip-permissionsbeing silently downgraded to accept-edits mode after approving a write to a protected pathtoString) causingsettings.jsonto be silently ignoredpermissions.additionalDirectorieschanges in settings not applying mid-sessionsettings.permissions.additionalDirectoriesrevoking access to the same directory passed via--add-diroauth.authServerMetadataUrlnot being honored on token refresh after restart, fixing ADFS and similar IdPsRetry-After— exponential backoff now applies as a minimum/resumepicker issues:--resume <name>opening uneditable, Ctrl+A reload wiping search, empty list swallowing navigation, task-status text replacing conversation summary, and cross-project staleness--resumewhen the edited file was larger than 10KB--resumecache misses and lost mid-turn input from attachment messages not being saved to the transcriptStop/SubagentStophooks failing on long sessions, and hook evaluator API errors displaying "JSON validation failed" instead of the actual messagecwd:override leaking their working directory back to the parent session's Bash toolclaude plugin updatereporting "already at the latest version" for git-based marketplace plugins when the remote had newer commitsnameis a YAML boolean keywordNO_FLICKERmode inserting spaces at line breaksNO_FLICKERmode when running inside zellijNO_FLICKERmode when hovering over MCP tool resultsNO_FLICKERmode memory leak where API retries left stale streaming stateNO_FLICKERmode on Windows TerminalNO_FLICKERmode on terminals shorter than 24 rowsNO_FLICKERmodeAWS_BEARER_TOKEN_BEDROCKorANTHROPIC_BEDROCK_BASE_URLare set to empty strings (as GitHub Actions does for unset inputs)LANG=C rm foo,timeout 5 mkdir out)sandbox.network.allowMachLookupnow takes effect on macOS@-mention completion to trigger after CJK sentence punctuation, so Japanese/Chinese input no longer requires a space before/or@TRACEPARENTenv var when tracing is enabled/claude-apiskill to cover Managed Agents alongside the Claude APIv2.1.92forceRemoteSettingsRefreshpolicy setting: when set, the CLI blocks startup until remote managed settings are freshly fetched, and exits if the fetch fails (fail-closed)/costfor subscription users/release-notesis now an interactive version pickermyhost-graceful-unicorn), overridable with--remote-control-session-name-prefixok:false, and restoredpreventContinuation:truesemantics for non-Stop prompt-type hooksclaude-code→ stable,claude-code@latest→ latest)ctrl+ejumping to the end of the next line when already at end of line in multiline prompts&/$)/tagcommand/vimcommand (toggle vim mode via/config→ Editor mode)apply-seccomphelper in both npm and native builds, restoring unix-socket blocking for sandboxed commandsv2.1.90/powerup— interactive lessons teaching Claude Code features with animated demosCLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILUREenv var to keep the existing marketplace cache whengit pullfails, useful in offline environments.huskyto protected directories (acceptEdits mode)--resumecausing a full prompt-cache miss on the first request for users with deferred tools, MCP servers, or custom agents (regression since v2.1.69)Edit/Writefailing with "File content has changed" when a PostToolUse format-on-save hook rewrites the file between consecutive editsPreToolUsehooks that emit JSON to stdout and exit with code 2 not correctly blocking the tool call/model,/config, and other selection screens&background job bypass,-ErrorAction Breakdebugger hang, archive-extraction TOCTOU, and parse-fail fallback deny-rule degradation/resumeall-projects view to load project sessions in parallel, improving load times for users with many projects--resumepicker to no longer show sessions created byclaude -por SDK invocationsGet-DnsClientCacheandipconfig /displaydnsfrom auto-allow (DNS cache privacy)v2.1.89"defer"permission decision toPreToolUsehooks — headless sessions can pause at a tool call and resume with-p --resumeto have the hook re-evaluateCLAUDE_CODE_NO_FLICKER=1environment variable to opt into flicker-free alt-screen rendering with virtualized scrollbackPermissionDeniedhook that fires after auto mode classifier denials — return{retry: true}to tell the model it can retry@mention typeahead suggestionsMCP_CONNECTION_NONBLOCKING=truefor-pmode to skip the MCP connection wait entirely, and bounded--mcp-configserver connections at 5s instead of blocking on the slowest server/permissions→ Recent tab where you can retry withrEdit(//path/**)andRead(//path/**)allow rules to check the resolved symlink target, not just the requested pathStructuredOutputschema cache bug causing ~50% failure rate when using multiple schemas~/.claude/history.jsonl/statsundercounting tokens by excluding subagent usage, and losing historical data beyond 30 days when the stats cache format changes-p --resumehangs when the deferred tool input exceeds 64KB or no deferred marker exists, and-p --continuenot resuming deferred toolsclaude-cli://deep links not opening on macOSfile_pathas an absolute path for Write/Edit/Read tools, matching the documented behavior--resumecrash when transcript contains a tool result from an older CLI version or interrupted writeifcondition filtering not matching compound commands (ls && git push) or commands with env-var prefixes (FOO=bar git push)invalidatesnot clearing the currently-displayed notification immediatelygit pushwrote progress to stderr on Windows PowerShell 5.1ls/tree/duinstead of "Read N files"@-mention typeahead to rank source files above MCP resources with similar namesEditto work on files viewed viaBashwithsed -norcat, without requiring a separateReadcall firstcleanupPeriodDays: 0in settings.json to be rejected with a validation error — it previously silently disabled transcript persistenceshowThinkingSummaries: truein settings.json to restoreTaskCreatedhook event and its blocking behavior/envnow applies to PowerShell tool commands (previously only affected Bash)/usagenow hides redundant "Current week (Sonnet only)" bar for Pro and Enterprise plans!commandinto an empty prompt now enters bash mode, matching typed!behavior/buddyis here for April 1st — hatch a small creature that watches you codev2.1.87v2.1.86X-Claude-Code-Session-Idheader to API requests so proxies can aggregate requests by session without parsing the body.jjand.slto VCS directory exclusion lists so Grep and file autocomplete don't descend into Jujutsu or Sapling metadata--resumefailing with "tool_use ids were found without tool_result blocks" on sessions created before v2.1.85~/.claude/CLAUDE.md) when conditional skills or rules are configured/feedbackon very long sessions with large transcript files--baremode dropping MCP tools in interactive sessions and silently discarding messages enqueued mid-turncshortcut copying only ~20 characters of the OAuth login URL instead of the full URL/modelin one of them/pluginuninstall dialog: pressingnnow correctly uninstalls the plugin while preserving its data directoryultrathinkhint lingering after deleting the keyword@— raw string content no longer JSON-escaped/skillslisting are now capped at 250 characters to reduce context usage/skillsmenu to sort alphabetically for easier scanningv2.1.84ANTHROPIC_DEFAULT_{OPUS,SONNET,HAIKU}_MODEL_SUPPORTSenv vars to override effort/thinking capability detection for pinned default models for 3p (Bedrock, Vertex, Foundry), and_MODEL_NAME/_DESCRIPTIONto customize the/modelpicker labelCLAUDE_STREAM_IDLE_TIMEOUT_MSenv var to configure the streaming idle watchdog threshold (default 90s)TaskCreatedhook that fires when a task is created viaTaskCreateWorktreeCreatehook support fortype: "http"— return the created worktree path viahookSpecificOutput.worktreePathin the response JSONallowedChannelPluginsmanaged setting for team/enterprise admins to define a channel plugin allowlistx-client-request-idheader to API requests for debugging timeouts/clear, reducing unnecessary token re-caching on stale sessionsclaude-cli://) now open in your preferred terminal instead of whichever terminal happens to be first in the detection listpaths:frontmatter now accepts a YAML list of globsToolSearchis enabled, including for users with MCP tools configuredCtrl+U(kill-to-line-start) being a no-op at line boundaries in multiline input, so repeatedCtrl+Unow clears across lines"ctrl+x ctrl+k": null) still entering chord-wait mode instead of freeing the prefix key--json-schemaand the subagent also specifies a schemaEdit(.claude)allow rulesC:\,C:\Windows, etc.)setup()in parallel with slash command and agent loadingclaude "prompt"with MCP servers — the REPL now renders immediately instead of blocking until all servers connectowner/repo#123— bare#123is no longer auto-linked/voice,/mobile,/chrome,/upgrade, etc.) are now hidden instead of shownv2.1.81--bareflag for scripted-pcalls — skips hooks, LSP, plugin sync, and skill directory walks; requiresANTHROPIC_API_KEYor anapiKeyHelpervia--settings(OAuth and keychain auth disabled); auto-memory fully disabled--channelspermission relay — channel servers that declare the permission capability can forward tool approval prompts to your phoneCLAUDE_CODE_DISABLE_EXPERIMENTAL_BETASnot suppressing the structured-outputs beta header, causing 400 errors on proxy gateways forwarding to Vertex/Bedrock--channelsbypass for Team/Enterprise orgs with no other managed settings configured/btwnot including pasted text when used during an active response/renamenot syncing the title for Remote Control sessions/exitnot reliably archiving the session!bash mode discoverability — Claude now suggests it when you need to run an interactive command"showClearContextOnPlanAccept": true)v2.1.80rate_limitsfield to statusline scripts for displaying Claude.ai rate limit usage (5-hour and 7-day windows withused_percentageandresets_at)source: 'settings'plugin marketplace source — declare plugin entries inline in settings.jsoneffortfrontmatter support for skills and slash commands to override the model effort level when invoked--channels(research preview) — allow MCP servers to push messages into your session--resumedropping parallel tool results — sessions with parallel tool calls now restore all tool_use/tool_result pairs instead of showing[Tool result missing]placeholders/remote-controlappearing for gateway and third-party provider deployments where it cannot function/sandboxtab switching not responding to Tab or arrow keys@file autocomplete in large git repositories/effortto show what auto currently resolves to, matching the status bar indicator/permissions— Tab and arrow keys now switch tabs from within a list/plugin installcommand instead of a two-step flowenabledPlugins,permissions.defaultMode, policy-set env vars) not being applied at startup whenremote-settings.jsonwas cached from a prior sessionv2.1.77allowReadsandbox filesystem setting to re-allow read access withindenyReadregions/copynow accepts an optional index:/copy Ncopies the Nth-latest assistant responsecd src && npm test) saving a single rule for the full string instead of per-subcommand, leading to dead rules and repeated permission prompts--resumesilently truncating recent conversation history due to a race between memory-extraction writes and the main transcript"allow"bypassingdenypermission rules, including enterprise managed settingsCLAUDE_CODE_DISABLE_EXPERIMENTAL_BETASnot stripping beta tool-schema fields, causing proxy gateways to reject requests/feedbacktext input deleting forward instead of the second press exiting the sessiongit-subdirplugins at different subdirectories of the same monorepo commit colliding in the plugin cache/mcpor similar dialogs while the agent is running⌘Vor tmuxprefix+]←/→accidentally switching tabs in settings, permissions, and sandbox dialogs while navigating lists--resumeon fork-heavy and very large sessions — up to 45% faster loading and ~100-150MB less peak memoryclaude plugin validateto check skill, agent, and command frontmatter plushooks/hooks.json, catching YAML parse errors and schema violationsCLAUDE_CODE_PLUGIN_SEED_DIRapiKeyHelpertakes longer than 10s, preventing it from blocking the main loopresumeparameter — useSendMessage({to: agentId})to continue a previously spawned agentSendMessagenow auto-resumes stopped agents in the background instead of returning an error/forkto/branch(/forkstill works as an alias)macOptionClickForcesSelectionsettingv2.1.76ElicitationandElicitationResulthooks to intercept and override responses before they're sent back-n/--name <name>CLI flag to set a display name for the session at startupworktree.sparsePathssetting forclaude --worktreein large monorepos to check out only the directories you need via git sparse-checkoutPostCompacthook that fires after compaction completes/effortslash command to set model effort levelfeedbackSurveyRatesettingToolSearch) losing their input schemas after conversation compaction, causing array and number parameters to be rejected with type errors/voicenot working on Windows when installed via npmmodel:frontmatter on a 1M-context sessionBash(cmd:*)permission rules not matching when a quoted argument contains#/exportshowing only the filename instead of the full file path in the success message--worktreestartup performance by reading git refs directly and skipping redundantgit fetchwhen the remote branch is already available locally/voiceto show your dictation language on enable and warn when yourlanguagesetting isn't supported for voice input--plugin-dirto only accept one path to support subcommands — use repeated--plugin-dirfor multiple directoriesv2.1.74/contextcommand — identifies context-heavy tools, memory bloat, and capacity warnings with specific optimization tipsautoMemoryDirectorysetting to configure a custom directory for auto-memory storageaskrules being bypassed by userallowrules or skillallowed-toolsclaude-opus-4-5) being silently ignored in agent frontmattermodel:field and--agentsJSON config — agents now accept the same model values as--modelaudio-inputentitlement so macOS prompts correctlySessionEndhooks being killed after 1.5 s on exit regardless ofhook.timeout— now configurable viaCLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS/plugin installfailing inside the REPL for marketplace plugins with local sources--plugin-dirso local dev copies now override installed marketplace plugins with the same name (unless that plugin is force-enabled by managed settings)v2.1.70ANTHROPIC_BASE_URLwith a third-party gateway — tool search now correctly detects proxy endpoints and disablestool_referenceblocksAPI Error: 400 This model does not support the effort parameterwhen using custom Bedrock inference profiles or other model identifiers not matching standard Claude naming patternsToolSearch— the server renders tool schemas with system-prompt-style tags at the prompt tail, which could confuse models into stopping earlyinstructionsconnects after the first turnSet-ClipboardvoiceEnabled: truewas set in settings#NNNreferences incorrectly pointing to the current repository instead of the linked URL.claude/settings.jsonhas a legacy Opus model string pinned/plugin/security-reviewcommand failing withunknown option merge-baseon older git versions/colorcommand having no way to reset back to the default color —/color default,/color gray,/color reset, and/color nonenow restore the defaultAskUserQuestionpreview dialog that re-ran markdown rendering on every keystroke in the notes inputpermissions.defaultModesettings values other thanacceptEditsorplanbeing applied in Claude Code Remote environments — they are now ignored--resume(~600 tokens saved per resume)/renameto work while Claude is processing, instead of being silently queued/pollrate to once per 10 minutes while connected (was 1–2s), cutting server load ~300×. Reconnection is unaffected — transport loss immediately wakes fast polling./mcpin the chat panel to enable/disable servers, reconnect, and manage OAuth authentication without switching to the terminalv2.1.66v2.1.59/copycommand to show an interactive picker when code blocks are present, allowing selection of individual code blocks or the full response.cd /tmp && git fetch && git push) to compute smarter per-subcommand prefixes instead of treating the whole command as onev2.1.50startupTimeoutconfiguration for LSP serversWorktreeCreateandWorktreeRemovehook events, enabling custom VCS setup and teardown when agent worktree isolation creates or removes worktrees.CLAUDE_CODE_SIMPLEto fully strip down skills, session memory, custom agents, and CLAUDE.md token counting/mcp reconnectfreezing the CLI when given a server name that doesn't existisolation: worktreein agent definitions, allowing agents to declaratively run in isolated git worktrees.CLAUDE_CODE_SIMPLEmode now also disables MCP tools, attachments, hooks, and CLAUDE.md file loading for a fully minimal experience.claude agentsCLI command to list all configured agents-pflag) by deferring Yoga WASM and UI component importsCLAUDE_CODE_DISABLE_1M_CONTEXTenvironment variable to disable 1M context window support/extra-usagecommand support in VS Code sessionsv2.1.39v2.1.37v2.1.34sandbox.excludedCommandsordangerouslyDisableSandbox) could bypass the Bash ask permission rule whenautoAllowBashIfSandboxedwas enabledv2.1.25managedMcpServersmanaged setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as.mcp.json); entries that name a command to run are skipped--permission-prompts nonefor unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps decidingglab mr create/merge/close/reopen/note/updateso GitLab merge requests show asMR !Nin the collapsed tool summary and refresh the footer MR badge--jsontoclaude plugin validatefor a machine-readable validation report~/.claude.jsonchanges — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at onceRead()deny rules not covering files given as option values (--ignore-revs-file=.env,-f.env,@file),git diff/git grepfile operands, orcd DIR && cat FILEcompounds;grep -r/cp -rover a directory holding a denied file now asksmodel:named one; the turn now keeps the session modelCLAUDE_CODE_MAX_CONTEXT_TOKENSbeing ignored for Vertex-style model IDs (@YYYYMMDDsuffix) of model versions Claude Code doesn't recognize--resumefailing (and--continueopening an empty conversation) when a saved session contains an attachment entry with no payloadmodel:on custom commands and skills being ignored in interactive sessionsnote" error in conversations continued from an older versionforceRemoteSettingsRefreshbeing ignored at startup when a policy helper configured by MDM or the managed settings file had already rungit rev-parsefails with a message other than "not a git repository"user.email,organization.id, anduser.account_uuidattributes?/#producing an unusable.gitclone URL/workflowsagent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle/install-github-appto explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repositoryallowedMcpServersto govern only servers users add: a literalmanaged-mcp.jsonserver your allowlist used to filter out now loads on upgrade; usedeniedMcpServersto keep it offv2.1.20claude agentsbackground sessions (reverts an overly broad guard)v2.1.19/skill-a /skill-b do XYZnow load all leading skills (up to 5), not just the firstNODE_EXTRA_CA_CERTS, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hintclaude stopbeing silently undone when it raced a background-agent respawn — the respawn now honors the stop/modelor/fastwhile viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the leadSessionStart,Setup, andSubagentStarthooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcriptclaude --dangerously-skip-permissions daemon <subcommand>being treated as a chat prompt instead of running the subcommandSendMessagesilently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget←or/backgrounddropping its/colorfrom the agent view rowbrowser_batchcalls are now correctly auto-allowedCLAUDE_CODE_RETRY_WATCHDOGnow raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 onCLAUDE_CODE_MAX_RETRIESclaude agentssession rows now show pull-request links as bare#Nwithout the redundant "PR" labelv2.1.17denyRead/allowReadglob over a large directory tree making the Bash tool description enormous and the session unusable on Linuxv2.1.15v2.1.12--plugin-url <url>flag to fetch a plugin.ziparchive from a URL for the current sessionCLAUDE_CODE_FORCE_SYNC_OUTPUT=1env var to force-enable synchronized output on terminals that auto-detection misses (e.g. Emacseat)CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE: when set on Homebrew or WinGet installations, Claude Code runs the upgrade command in the background and prompts to restartthemesandmonitorsshould now be declared under"experimental": { ... }. Top-level declarations still work butclaude plugin validatewill warn/v1/modelsdiscovery for the/modelpicker is now opt-in viaCLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1(was automatic in 2.1.126–2.1.128)ANTHROPIC_BASE_URLgateway) no longer see spinner tips pointing at first-party Anthropic surfacesskillOverridessetting now works:offhides from model and/,user-invocable-onlyhides from model only,name-onlycollapses descriptionclaude_code.pull_request.countOTel metric now counts PRs/MRs created via MCP tools, not just shell commands/clearnot resetting the terminal tab title after a conversation/renamedisappearing while a permission or other dialog is active/contextdumping its rendered ASCII visualization grid into the conversation, wasting ~1.6k tokens per call/agentsLibrary list arrow-key navigation: the highlighted agent now stays visible when the list exceeds the viewport/branchsuccess message not including the new branch's session id for/resumeuser:inferencescope/clearor compaction when changing/effortor/modelBash(mkdir *),Bash(touch *)and similar allow rules not being honored for in-project pathsdeniedMcpServerspatterns with a*://scheme wildcard not matching mixed-case hostnames--debugduring voice mode/clearnot clearing the conversation context and displayed transcriptv2.1.9CLAUDE_CODE_PERFORCE_MODEenv var: when set, Edit/Write/NotebookEdit fail on read-only files with ap4 edithint instead of silently overwriting themCLAUDE_CODE_SUBPROCESS_ENV_SCRUBis set, andCLAUDE_CODE_SCRIPT_CAPSenv var to limit per-session script invocations--exclude-dynamic-system-prompt-sectionsflag to print mode for improved cross-user prompt cachingworkspace.git_worktreeto the status line JSON input, set whenever the current directory is inside a linked git worktreeTRACEPARENTenv var to Bash tool subprocesses when OTEL tracing is enabled, so child-process spans correctly parent to Claude Code's trace treeclientInfoin the initialize requestLANG,TZ,NO_COLOR, etc.)/dev/tcp/...or/dev/udp/...not prompting instead of auto-allowingRetry-After— exponential backoff now applies as a minimumoauth.authServerMetadataUrlconfig override not being honored on token refresh after restart, affecting ADFS and similar IdPs--dangerously-skip-permissionsbeing silently downgraded to accept-edits mode after approving a write to a protected path via Bashpermissions.additionalDirectorieschanges not applying mid-session — removed directories lose access immediately and added ones work without restartadditionalDirectoriesrevoking access to the same directory passed via--add-dirBash(cmd:*)andBash(git commit *)wildcard permission rules failing to match commands with extra spaces or tabsBash(...)deny rules being downgraded to a prompt for piped commands that mixcdwith other segmentscut -d /,paste -d /,column -s /,awk '{print $1}' file, and filenames containing%toString) causingsettings.jsonto be silently ignored--dangerously-skip-permissions--resumewhen the edited file was larger than 10KB/resumepicker issues:--resume <name>opening uneditable, filter reload wiping search state, empty list swallowing arrow keys, cross-project staleness, and transient task-status text replacing conversation summaries/exportnot honoring absolute paths and~, and silently rewriting user-supplied extensions to.txt/effort maxbeing denied for unknown or future model IDsnameis a YAML boolean keyword_meta["anthropic/maxResultSizeChars"]not bypassing the token-based persist layerDISABLE_AUTOUPDATERnot fully suppressing the npm registry version check and symlink modification on npm-based installsgrep -f FILE/rg -f FILEnot prompting when reading a pattern file outside the working directorysandbox.network.allowMachLookupnot taking effect on macOS/resumefilter hint labels and added project/worktree/branch names in the filter indicator/agentswith a tabbed layout: a Running tab shows live subagents, and the Library tab adds Run agent and View running instance actions/reload-pluginsto pick up plugin-provided skills without requiring a restartj/kin NORMAL mode now navigate history and select the footer pill at the input boundary--debug/claude-apiskill to cover Managed Agents alongside Claude APICLAUDE_CODE_GIT_BASH_PATHis set or Git is installed at a default locationCLAUDE_CODE_MAX_CONTEXT_TOKENSto honorDISABLE_COMPACTwhen it is set./compacthints whenDISABLE_COMPACTis set.v2.1.7--consoleflag toclaude auth loginfor Anthropic Console (API billing) authentication/configmenuclaude -phanging when spawned as a subprocess without explicit stdin (e.g. Pythonsubprocess.run)-p(print) mode/btwreturning the main agent's output instead of answering the side question when triggered during streamingvoiceEnabled: trueis set/permissionsCLAUDE_CODE_DISABLE_TERMINAL_TITLEnot preventing terminal title from being set on startupSessionEndhooks not firing when using interactive/resumeto switch sessionsCLAUDE_CODE_PLUGIN_SEED_DIRnow supports multiple seed directories separated by the platform path delimiter (:on Unix,;on Windows)/remote-control— bridge your session to claude.ai/code to continue from a browser or phonev2.1.6/claude-apiskill for building applications with the Claude API and Anthropic SDK!) to exit bash mode, matchingescapeandbackspace/remote-controlandclaude remote-control(/remote-control My Projector--name "My Project") to set a custom session title visible in claude.ai/codeclaude --agentsandbox.enableWeakerNetworkIsolationsetting (macOS only) to allow Go programs likegh,gcloud, andterraformto verify TLS certificates when using a custom MITM proxy withhttpProxyPortincludeGitInstructionssetting (andCLAUDE_CODE_DISABLE_GIT_INSTRUCTIONSenv var) to remove built-in commit and PR workflow instructions from Claude's system prompt/reload-pluginscommand to activate pending plugin changes without restarting${CLAUDE_SKILL_DIR}variable for skills to reference their own directory in SKILL.md contentInstructionsLoadedhook event that fires when CLAUDE.md or.claude/rules/*.mdfiles are loaded into contextagent_id(for subagents) andagent_type(for subagents and--agent) to hook eventsworktreefield to status line hook commands with name, path, branch, and original repo directory when running in a--worktreesessionpluginTrustMessagein managed settings to append organization-specific context to the plugin trust warning shown before installationpathPatterntostrictKnownMarketplacesfor regex-matching file/directory marketplace sources alongsidehostPatternrestrictionsgit-subdirto point to a subdirectory within a git repooauth.authServerMetadataUrlconfig option for MCP servers to specify a custom OAuth metadata discovery URL when standard discovery failsnode_modules.mcp.jsonservers on first run. You'll now see the per-server approval dialog as expectedclaude remote-controlcrashing immediately on npm installs with "bad option: --sdk-url" (#28334)--model claude-opus-4-0and--model claude-opus-4-1resolving to deprecated Opus versions instead of currentsecurity -istdin buffer, silently leaving stale credentials behind and causing repeated/loginprompts..credentials.jsonlosingsubscriptionType(showing "Claude API" instead of "Claude Pro"/"Claude Max") when the profile endpoint transiently fails during token refresh (#30185).bashrc,HEAD, etc.) appearing as untracked files in the working directory after sandboxed Bash commands on Linux[27;2;13~instead of inserting a newline in Ghostty over SSH/statscrash when transcript files contain entries with missing or malformed timestamps--setting-sources usernot blocking dynamically discovered project skillsclaude -w)/pluginoperation${CLAUDE_PLUGIN_ROOT}/...command templatenameparameterCLAUDE_CODE_MAX_OUTPUT_TOKENSbeing ignored during conversation compaction/compactsummary rendering as a user bubble in SDK consumers (Claude Code Remote web UI, VSCode extension).claudefolder detection on WindowsacceptEditsmodeallowManagedDomainsOnlyis enabled in managed settings — non-allowed domains are now blocked automatically with no bypassAskUserQuestion) being silently auto-allowed when listed in a skill's allowed-tools, bypassing the permission prompt and running with empty answers/voice,/cost) in Remote Control sessionsmemoCacheover long sessions/clearor auto-compact--mcp-configpoints to a corrupted filecd <outside-dir> && <cmd>permission prompt to surface the chained command instead of only showing "Yes, allow reading from /".claude/rules/*.mdfiles (withpaths:frontmatter) and nested CLAUDE.md files not loading in print mode (claude -p)/clearnot fully clearing all session caches, reducing memory retention in long sessionsTeammateIdleandTaskCompletedhooks to support{"continue": false, "stopReason": "..."}to stop the teammate, matchingStophook behaviorWorktreeCreateandWorktreeRemoveplugin hooks being silently ignoreddescription:frontmatter field not appearing in Claude's available skills list/contextshowing identical token counts for all MCP tools from a servernulfile creation on Windows when the model uses CMD-style2>nulredirection in Git Bash/configsearch box is focused but empty[ERROR]logs with 403s from profile-scoped endpoints--worktreestartup by eliminating a git subprocess on the startup path-pstartup by pipelining claude.ai config fetch with local connections and using a concurrency pool instead of sequential batchingonSubmitacross message updates--append-system-prompt-fileand--system-prompt-filework in interactive mode (the docs previously said print mode only)/resumepicker to show your most recent prompt instead of the first one. This also resolves some titles appearing as(session).activeFormfield — the spinner falls back to the task subjectpermissions.disableBypassPermissionsModefrom your effective Claude Code settings (including managed/policy settings) — when set todisable, bypass permissions mode is hidden from the pickerv2.1.5/copycommand to show an interactive picker when code blocks are present, allowing selection of individual code blocks or the full response.cd /tmp && git fetch && git push) to compute smarter per-subcommand prefixes instead of treating the whole command as onev2.1.2claude-sonnet-5-5), now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads/usageand the status line (for example "$271.40 / $500.00 spent this month") when the gateway runs this version or later; the status line'srate_limits.spend_limitalso gainsused_usd,limit_usdandperiodeffortSlider:decreaseEffort,increaseEffortandtoggleUltracodekeybinding actions, so the/effortslider's arrow and Tab keys can be rebound inkeybindings.json/rate-limit-optionsto/helpand the command menu for claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find/mcp reconnect allin the interactive terminal to retry every MCP server that failed to connect or needs authentication at onceavailableModelsis empty, or leaves out the model Claude Code starts on without settingmodelorenforceAvailableModelsauth: { google: {} }for Claude apps gatewaytelemetry.forward_todestinations, so telemetry can be exported straight to Google Cloud's OTLP endpoint using the gateway's Google Cloud credentialsprivate_key_jwt) between the Claude apps gateway and its identity provider, for identity providers that issue certificate credentials instead of client secretssource, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note/usage,/extra-usageand IDE usage views now back off instead of re-askingclaude mcp addreporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads/pluginconfigure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabsANTHROPIC_FOUNDRY_RESOURCEbeing interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refusedbin/directories that don't exist are no longer added to PATH, and inherited entries aren't added twicesparsePathsplugin marketplaces cloning empty and replacing a working local copy on older git (before 2.39), which failed every refresh with "marketplace.json file is no longer present"[in transcript mode writes the conversation to scrollback (macOS and Linux)/configand/pluginbreaking the title and tab labels mid-word in a narrow terminal; a tab that doesn't fit now moves to the next line whole/modelpicker showing "+1 model" below the list after scrolling to the last model; the count now covers only the models below the visible rows/keybindingswriting Backspace and Delete bindings for a footer action that does nothing into the generatedkeybindings.jsonfooter:close) typing "x" instead of itself on the row of the agent you're viewing.not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such ascwthen Esc)ddon the last line oryyat the end of the prompt, whererorxwould break or delete the image.claude/rulesfrom outside the project being skipped without ever showing the external-imports approval prompt; a.claudedirectory symlinked from outside the project now asks for the same approvalallowed-toolsunder managedallowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approvalclaude plugin installleaving the plugin enabled and recorded when a dependency's version range could not be met{"decision":"block"}returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 doesSendMessagetool (such as by Claude Desktop) still being told to message other sessions with it/upgradeto users already on the highest Max plan; the warnings and/upgradeitself now point at/usage-creditswhen it is available/loopstatus updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text/ultrareviewfailing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linuxdata/users/subtree, and added a "view" level toas_level431 Request Header Fields Too Largeto every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB/claude-api:hillclimbno longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for besidereport.htmlis built as one local file that loads nothing from the network/tasks,/copyand/hooks: the details after each name now line up in one column when they fit, and otherwise sit at the right edgeclaude plugin marketplace addto say when it replaces a marketplace already added under the same name from a different source, and how to undo itforceLoginMethodorforceLoginOrgUUID) and an API key, token orapiKeyHelperis configured: it now names the credential in use, where it is set, and how to remove itMEMORY.mdand recalled memory notes before they reach Claudeclaude remote-control: in a folder you haven't trusted yet, it now asks for workspace trust on the terminal instead of exitingpermissions.defaultModestill overrides it/effort(Tab, or/effort ultracode [on|off]): it no longer forces xhigh effort and stays on at any effort levelANTHROPIC_DEFAULT_OPUS_MODELormodelOverrides: on the Anthropic API, the API now picks the model to switch to for each kind of flag, not the pinned model--allowedToolsor anmcp_toolhook, even whenCLAUDE_CODE_MCP_STARTUP_WAIT_MSis0/recapto decline with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook; typed in the terminal, the Claude apps, Remote Control,-por an SDK host, it runs as before/artifactsto show its filter tabs beside the title with one-word labels (All, Mine, Shared), using the same tab bar as/configand/plugin\\host\sharepath or a/netautomount) unless it is on a mapped network drive added with--add-dir/modeland Enter printing usage text into the chat instead of opening the model selector/feedbackon Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does/mcp,/configor/settingscommand being shadowed by the extension's dialogCLAUDE_CONFIG_DIRin theclaudeCode.environmentVariablessetting to apply only when it is an absolute path, and passed it to terminals that continue the chatv2.0.76v2.0.75v2.0.74/terminal-setupsupport for Kitty, Alacritty, Zed, and Warp terminals/themeto toggle syntax highlighting on/offallowed-toolsnot being applied to tools invoked by the skill/plugins discoverwhere list selection indicator showed while search box was focused/contextcommand visualization with grouped skills and agents by source, slash commands, and sorted token countv2.0.72/contextcommand not respecting custom system prompts in non-interactive mode.ignoreor.rgignorefilesv2.0.71/settingsas an alias for the/configcommand.mcp.jsonnot loading when using--dangerously-skip-permissionsls *.txt,for f in *.png)ANTHROPIC_BEDROCK_BASE_URLis now respected for token counting and inference profile listingv2.0.70mcp__server__*for MCP tool permissions to allow or deny all tools from a servercurrent_usagefield to status line input, enabling accurate context window percentage calculationsv2.0.69v2.0.67/permissionscommand with/keyboard shortcut for filtering rules by tool name/doctorclaude updatewhile another instance is already on the latest version.mcp.jsonbeing stuck in pending state when running in non-interactive mode (-pflag or piped input)/permissionsclaude install --forcenot bypassing stale lock filesv2.0.65fileSuggestionsetting for custom@file search commandsCLAUDE_CODE_SHELLenvironment variable to override automatic shell detection (useful when login shell differs from actual working shell)v2.0.64/renameto name sessions,/resume <name>in REPL orclaude --resume <name>from the terminal to resume them--system-promptbeing ignored when using--continueor--resumeflags/resumescreen with grouped forked sessions and keyboard shortcuts for preview (P) and rename (R)aws loginAWS Management Console credentialsv2.0.61v2.0.59agentsetting to configure main thread with a specific agent's system prompt, tool restrictions, and modelv2.0.58C:\Program Files\ClaudeCodeif it exists. Support forC:\ProgramData\ClaudeCodewill be removed in a future version.v2.0.57v2.0.56v2.0.55CLAUDE_CODE_PROXY_RESOLVES_HOSTS=trueenvironment variable@file suggestions with faster, more accurate resultsv2.0.54v2.0.50v2.0.49v2.0.47claude --teleport/usagesettings.jsonv2.0.46v2.0.42agent_idandagent_transcript_pathfields toSubagentStophooks.v2.0.37keep-coding-instructionsoption to frontmatterv2.0.35chat.fontSizeandchat.fontFamilysettings throughout the entire UI, and apply font changes immediately without requiring reloadCLAUDE_CODE_EXIT_AFTER_STOP_DELAYenvironment variable to automatically exit SDK mode after a specified idle duration, useful for automated workflows and scriptsignorePatternsfrom project config to deny permissions in the localSettings./hooksmenu)v2.0.34v2.0.33claude doctorincorrectly detecting Homebrew vs npm-global installations by properly resolving symlinksclaude mcp serveexposing tools with incompatible outputSchemasv2.0.32companyAnnouncementssetting for displaying announcements on startupv2.0.31/compactto fail withprompt_too_longby making it respect existing compact boundariesv2.0.30security unlock-keychainwhen encountering API key errors on macOS with locked keychainallowUnsandboxedCommandssandbox setting to disable the dangerouslyDisableSandbox escape hatch at policy leveldisallowedToolsfield to custom agent definitions for explicit tool blocking/output-styleand use --system-prompt-file, --system-prompt, --append-system-prompt, CLAUDE.md, or plugins instead/contextwould sometimes fail with "max_tokens must be greater than thinking.budget_tokens" error message--mcp-configflag to correctly override file-based MCP configurationsv2.0.28/terminal-setupfrom adding backslash toShift + Enterin VS Codeowner/repo#branch)v2.0.27v2.0.25v2.0.22v2.0.17ANTHROPIC_DEFAULT_HAIKU_MODELCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICnow disables release notes fetchingv2.0.15-pmode where @-mentioned files needed to be read again before writingv2.0.14v2.0.11v2.0.10v2.0.9v2.0.8global.anthropic.claude-sonnet-4-5-20250929-v1:0v2.0.5agentsetting to configure main thread with a specific agent's system prompt, tool restrictions, and modelv2.0.1v1.0.126v1.0.123Bash(python:*)matchespython script.py > output.txt)v1.0.119v1.0.117v1.0.72v1.0.71v1.0.65v1.0.64v1.0.62v1.0.61--settingsflag to load settings from a JSON fileCLAUDE_CODE_AUTO_CONNECT_IDE=falsefor disabling IDE auto-connectionCLAUDE_CODE_SHELL_PREFIXfor wrapping Claude and user-provided shell commands run by Claude Codev1.0.60v1.0.58v1.0.56v1.0.55v1.0.54v1.0.51--append-system-promptcan now be used in interactive mode, not just --print/-p.v1.0.48v1.0.44fg. Prompt input undo is now Ctrl+U.v1.0.43v1.0.41tool_decisioneventv1.0.38v1.0.35v1.0.33v1.0.30v1.0.29v1.0.24v1.0.21v1.0.17v1.0.11v1.0.6v1.0.5v1.0.3v1.0.2v1.0.0Configuration
📅 Schedule: (in timezone Europe/Oslo)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
3b318b9f2ato997e0365e2