●
v2.1.272 Sep 15, 2026
v2.1.272
What's changed
- Bug fixes and reliability improvements
Every Claude Code release. Bolted straight to the record.
/fast typed in the session applies where your organization allows it/config panel in fullscreen mode: the wheel scrolls the settings list, a click on a setting's value changes it, and the row under the pointer is highlightedclaude self-hosted-runner --drain-marker-file <path>: when that file exists at a SIGTERM drain, the runner reports its exit to the server as a host drain (telemetry only)allowed_domains to Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refusedomitClaudeMd to agent frontmatter and --agents JSON, letting custom and plugin subagents run without user, project and local CLAUDE.md files; managed policy files still load--accept-command <sha256> to claude plugin install and claude plugin update to accept exactly the command a previous --json run displayed, instead of -ymultiplier above 1, up to 10, in the modelPricing managed setting and the Claude apps gateway pricing block, for marked-up internal chargeback rates/desktop, which offers to download the appmanaged-mcp.json that can't be read or parsed being ignored: it now keeps exclusive MCP control (user, project and plugin servers don't load) and warns at startupANTHROPIC_UNIX_SOCKET; they are again treated like other custom gateways, including for Remote Control/fast off answering "Fast mode unavailable" instead of turning fast mode off when the organization has fast mode disabledCLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK re-sending fast requests every turn after the API rejected fast mode; the rejection now stands and its reason is shownCLAUDE_CODE_RETRY_WATCHDOG failing the turn on a usage-credits limit, or retrying an overload at fast speed, instead of falling back to standard speedfmt, column and similar commands read when it follows an option the checker doesn't recognizegrep -v dir/* file)cd+git chain skipping the prompt under permissions.blockReadsOutsideWorkingDirectories in bypass and auto mode.git/config.lock breaking git checkout -b, git push -u and git config for the rest of a session after a sandboxed command failed to start (Linux)claude -p sessions whose tools all come from MCP servers failing with "At least one tool must have defer_loading=false"text/plainlist_changed notifications in a tight loopmcp__server__tool name/mcp sent from Remote Control failing while the transcript view is openSendMessage results no longer imply it was read/model warning about losing the conversation cache when switching back to the model the conversation actually ran on/reload-skills reporting a skill count that disagreed with the slash menu after /cd/resume and /continue showing only 1-2 sessions in fullscreen mode on short terminals/resume and /teleport keeping the previous conversation's file-read tracking, so Claude could edit files the resumed conversation had never read--resume dropping the 1M context window ([1m]) when the resumed session's model family differs from the configured default model/artifacts disappearing from the session after --resumeclaude --bg, claude agents) not watching the artifacts they publish for republishes made elsewhere--host-config-snapshot disk|memorycleanupPeriodDays now move to the recoverable trash at the next launch/add-dir path input: the left and right arrow keys now move the cursor, and Enter adds only the typed path instead of also adding the highlighted completion! to the end of what you typed (!foo came out as foo!)/hooks menu crashing when a hook matcher is named after an inherited object property such as __proto__ or constructor^[[?1;2c) appearing at the shell prompt or in an editor when Claude Code exits, is suspended, or opens an editor right after startingclaude mcp serve: a running tool call now sends a progress update every 30 seconds, so clients show it is still running and idle timeouts don't abort a long command that prints nothingalwaysLoad MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip/mobile to show a single QR code for claude.ai/mobile, which opens the right app store for your phone! shell commands follow default-mode permission rules instead of the classifier; a command no rule decides runs as a reviewed tool call-p runs) and notify Claude to re-arm, replacing the no-timeout persistent option[⧉ …] pill that wraps with the text instead of squeezing multi-line prompts; delete it with Backspace to leave the selection outclaude-api skill to enable eager_input_streaming on streaming custom tools, and to start deliverable-shaped Managed Agents work with user.define_outcomeCLAUDE_CONFIG_DIR changed in the environmentVariables settingclaude plugin eval: run a plugin's eval suite against Claude Code and get scored, reproducible results (JSON + HTML report); see claude plugin eval --help/output-style [name] to list and switch output styles, including over Remote Control and in cloud and other headless sessionsbashEditDiffEnabled)OTEL_METRICS_INCLUDE_REPOSITORY to tag OpenTelemetry metrics and events with vcs.* repository attributes; commit events get vcs.ref.head.* with OTEL_LOG_TOOL_DETAILSCLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MS to extend the LLM gateway /v1/models discovery timeout (default 3s)/focus for a view with just your prompt, a one-line work summary, and the responseCLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS (1–256) to raise the Workflow tool's per-run concurrent agent limit for inference-bound fan-outsCLAUDE_CODE_BG_TASKS_REPORT_RUNNING=0 to restore the old behavior)^[[?1;2c) appearing as stray text at startup in some terminals! applying beyond the settings source that wrote it; such a rule now applies only within its own source, and a bare ! negation is ignoredheadersHelper consent prompts showing a URL path that could be misread as a different host[redacted URL] in place of a relative Windows path with a folder name that starts with @/fork receipt, each under a second apart, never backgrounding the session right away while it waited for the current tool to finishshutdown params (e.g. rust-analyzer) being left running at session end; exit is now sent even if shutdown failspermission_denials in --output-format stream-json results omitting Read, Edit and Write calls blocked by a path-scoped deny rule/insights failing on Bedrock, Vertex, Foundry, and gateway deployments whose account can't reach the default Opus model by using the session model there instead/goal runs silently stalling after API errors, network drops, or token limits: the goal now retries with backoff, or pauses and says why, including until a usage limit resets/btw answers that contained made-up tool calls and output: the side question is now told not to write them, and any that appear are flagged as not executedCLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had failed with an API error over 6 hours earlier, or longer ago than CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS when setEdit() deny rules and the write-path check not applying to the file a Bash tee command writes; a Bash(tee:*) allow rule no longer covers destinations outside the working directories22c, or a terminal's color or version reply, being typed into the prompt at startup over slow connections (ssh, browser terminals)/diff panel to open fully rendered in one step instead of showing a loading state firstalwaysLoad MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip/ultrareview --post to post the PR comment directly when the findings arrive and print the comment link, instead of starting a second cloud session to post itanthropic-skills:<name>, matching Claude Desktop; the bare name still works when nothing else uses itCLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting/model default in a cloud session leaving every later message failing in organizations that restrict which models Claude Code can use@Claude !restart at the top level of a channel where Claude isn't active starting an unrelated conversation; it now privately says there is nothing to restartpricing: set in gateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so /cost and telemetry match the spend meteraccess_control.allow_cidrs is empty, and a one-time warning the first time a request arrives from a public addressgatewayInternalNetworks managed setting, letting administrators allow /login to a Claude apps gateway on their organization's own public IPv4 blockclaude self-hosted-runner --remove-session-state (default off): delete each session's per-session directories under <base-dir>/_sessions/ when the session endsconfigDirectory to the output of claude auth status --json--json to claude plugin install, uninstall, update, enable and disable, and errorDetails/noteDetails to each row of claude plugin list --jsonANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints rejectCLAUDE_CODE_WEBFETCH_DEADLINE_MS to override the deadline (0 turns it off)/etc, /tmp, /var on macOS; /bin on Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spellingenv -C, eval or similar command the permission checker cannot analyze was on the same line/mcp and /plugin server details, claude mcp list/get, and MCP login errors showing secrets resolved from ${VAR} placeholders in MCP configsexcludeDynamicSections: the first message is no longer re-rendered each request401 … jti reused/compact and auto-compact mangling text that contained $ sequences/compact: its restored-file notes now load in the same order on every resume/rename sending the conversation from before a compaction@ file and / command suggestions not appearing after recalling a previous prompt with the up arrow and editing itclaude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a secondclaude agents session delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway/bug and /feedback description field showing no cursor when the terminal's native cursor is enabledclaude remote-control showing a generated name instead of their session title in ListAgentsclaude plugin validate rejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts--print mode-p) runs/resume listing a /fork background session under its parent's name instead of its own ⑂ fork name/remote-control and other claude.ai-gated commands to suggest /login when signed out instead of showing a Claude for Enterprise migration messageCLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS not extending SessionEnd hooks that have no per-hook timeout (they were still cancelled after 1.5 seconds)/autofix-pr and other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to /web-setup or the web connect page/teleport and /remote-env to explain when an organization policy turns them off, instead of answering "Unknown command"--continue / --resume: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript.claude/workflows/ scripts: listing them no longer parses each script/diff selection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer/plugin: installing, enabling or disabling a plugin now takes effect when you close the menu; /reload-plugins is no longer needed afterwardsCLAUDE_CODE_ENABLE_TODO_TOOLS=1 elsewhereWebFetch deny and ask rules to no longer apply to Artifact tool reads and updates; use an Artifact rule (or WebFetch(domain:claude.ai)) to block or gate themCLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting~/.claude/settings.jsonclaudeCode.preferredLocation: "sidebar" (it always opened a panel), and programmatic opens resetting that setting to "panel"CLAUDE_CONFIG_DIR is set through settings@Claude !restart in a thread with its own session sometimes also posting a contradictory "this thread is handled by the channel session" noticemaxEffortLevel setting (top-level or per model under modelSettings): caps the effort level on every provider, including Bedrock, Vertex and Foundry; users can still pick a lower level--system-prompt-snapshot off to render the system prompt fresh on every request instead of reusing the conversation's recorded prompt (for iterating on prompt text)/context and other local command output rendering blank on mobile clientsagent() calls with large output schemas being refused in auto mode instead of being checked by the safety classifier/compact or another slash command ran via -p --resume: a spurious "Continue from where you left off." turn is no longer insertedallowedHttpHookUrls, httpHookAllowedEnvVars and allowedChannelPlugins to admit nothing, not everything, when unreadable/login on machines whose managed settings require Claude apps gateway sign-in: Esc now closes the dialog instead of doing nothingeffort: frontmatter on custom commands, skills, and subagents being ignored on models whose default effort is still pinned (Opus 4.7, Opus 4.8, Fable 5)claude agents @ directory menu not listing repositories created after the session startedclaude remote-control exiting and dropping every attached session when its server credential expires (about 30 days after start); the host now re-registers and keeps going-p) conversation is resumed interactively: the system prompt prefix no longer changes/diff panel: it no longer flashes "0 files changed" and a spinner before settling, and its empty state is centered in the panel/copy when clipboard commands such as pbcopy fail inside the sandbox--resume first-render time for sessions with many Bash tool calls--system-prompt or --append-system-prompt now record the system prompt and tool definitions once instead of re-rendering them--use-anthropic-git-proxy to be reported to the server at registration and to print a warning for each session that still clones through the legacy git proxyforward_user_identity upstreams to return a 429 as-is to a developer whose email was forwarded, instead of failing over to the next upstream, so the proxy's per-user limits holdgh and GitHub API calls failing in organizations without the Claude GitHub App; they now use your connected GitHub account and say so when none is connectedCLAUDE_CODE_USE_GATEWAY environment variable, previously ignored unless ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN were both set, began forcing Cloud-gateway sign-in on its own in 2.1.265, so configurations that set it alongside an API key, apiKeyHelper, or custom auth headers failed every request with "Not signed in to the Cloud gateway". The variable on its own is ignored again; no configuration change is neededuser.email and user.groups to the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions--plugin-dir at a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up/model opusplan[1m] being rejected with "Model not found"?, Erlang $, or Perl $ sigil--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout/add-dir <subdirectory> refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are lockedcontext: fork) not streaming their kickoff prompt and, with --forward-subagent-text, their text turns as progress events in stream-json/plugin with the error code/plugin Discover/Browse and claude plugin list --json --available showing no description or display name for marketplace plugins whose metadata lives only in their plugin.json/login showing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings/model claiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why/clear from Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing/config dialog changing height when switching between its tabsclaude-api skill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403-p with stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; a cd now persists across turnshttp that only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes--worktree startup on large repositories: the new worktree is now checked out in parallel (git 2.32+)/workflows agent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results.claude folder permission option to say what it actually allows: editing files in the project's .claude folder (or ~/.claude) for the sessionforceLoginGatewayUrl in managed settings to be Claude apps gateway sessions from startup, like forceLoginMethod: "gateway"; a leftover claude.ai login or API key is not usedplugin.json on the Installed tab and claude plugin details, filling gaps from plugin.jsonOTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relay/status and claude doctor that says why your organization's policy could not be loaded, such as a proxy not passing the endpoint throughbashOutputMaxChars and taskOutputMaxChars settings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters--append-subagent-system-prompt-file to read the subagent system prompt from a file, for prompts too large to pass on the command line/skill-doctor to show which loaded skills go unused and what they cost in context, so you can prune them/add-dir <subdirectory> printing a false "couldn't be resolved" error when the working directory is on a /net automountenabledPlugins, then falling back to a marketplace clone that could fail[Image #N] chip in the prompt input/clear/teleport into the connected session, which appeared appended to the original on phone and webgcpAuthRefresh opening a browser at startup when the Google credential check was slow, even though the credential was still valid/usage and the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startupclaude -p --resume <file> adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID insteadX-Forwarded-For; with an access list set, an unreadable entry now gets 403file_upload failing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop appSendMessage to an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects<claude-code-hint> tag no longer leaks into the conversation/model picker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes itGOOGLE_APPLICATION_CREDENTIALS is set: API client creation no longer re-runs Google Cloud project discovery or spawns extra gcloud processesrm safety prompt to also catch rm -rf on positional parameters and inside double-quoted sh -c scriptsAPI_TIMEOUT_MS (10 minutes by default) instead of another 3 minutes, and the messages say what to change/login) to say Claude Code may not be enabled for the organization, instead of advising a new sign-inforceLoginMethod: "gateway" to ignore a leftover API key or claude.ai login and ask for /login; Bedrock, Vertex AI, and Foundry sessions are unaffectedkeybindingFlavor no longer has any effect/context token counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests/btw side-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors/diff/cost and the status line's prompt_cache field/reload-plugins to headless sessions, so it appears in the Claude Code Desktop and SDK command lists/advisor (/advisor, /advisor <model>, /advisor off) for the desktop app, Remote Control, and other headless (-p/Agent SDK) sessionsoidc.scope_on_refresh to the Claude apps gateway for IdPs that return an id_token on refresh only when asked for openid againdesktop policy blocks, including userPluginMarketplacesEnabled and userPluginUploadsEnabledEdit/Write/Read permission rules whose path contains parentheses being dropped as invalid or ignored by the Bash sandbox, which left "read-only" folders writable[) making every file edit fail with Invalid regular expression; such a deny rule now guards the literal path it spellspermissions.blockReadsOutsideWorkingDirectories on macOS hiding the user's git config from sandboxed git and hiding a worktree-isolated sub-agent's own checkout/login/status listing a signed-in claude.ai account and a configured API key as if both were in effect; the credential not in use is now markedskillOverrides entries keyed on a bundled skill's alias (e.g. checkup for /doctor) not applying, and Skill(name) deny rules not covering a nested skill listed as <dir>:namemodel: fable agents ignoring the [1m] tag on an ANTHROPIC_DEFAULT_FABLE_MODEL pin and silently running with a 200K context window/model picker not showing Fable 5.1 for organizations that can use it, which was only accepted when typed as /model claude-fable-5-1…)/rewind and --rewind-files reporting success when checkpoint backup files were missing and nothing was actually restored/rewind leaving stale file-read tracking from the rewound-away turns, which caused "File unchanged since last read" stubs and full-file re-injection after external edits-p --resume/--continue (as used by the desktop app) failing on every retry once a session's worktree directory lost its git metadata; it now fails once, then resumes without the worktreeCLAUDE_CODE_RETRY_WATCHDOG) as retry notices evicted real messagesgitlab.com/group/subgroup/project)owner/repo#123 issue references in rendered output linking to github.com when working in a GitLab repository; they now link to the gitlab.com issueRead() deny rules to Bash arguments; it denied npm run build under a Read(./**/build/**) rule in every mode and made cd … && grep prompt even in auto modeagent({schema}) rejects a JSON Schema that can never be satisfied up front, and retry-cap errors now include the last validation failure-p / SDK) sessionsbedrock:CountTokens) instead of a one-token requestEdit(C:\dir\(name)\**), where \( is read as an escaped parenthesis rather than a path separator, to suggest an unambiguous spelling/ultrareview and claude ultrareview to wait up to 45 minutes (previously 30) for long-running cloud reviews/effort on Claude Fable 5.1 so changing effort mid-session no longer invalidates the prompt cacheclaude-api skill so its Go, Java, and C# samples use current-generation model IDs, and clarified that cheaper worker or sub-agent models should be current-generation tooctrl+l / cmd+k in fullscreen mode to clear the transcript view like a terminal clear; scroll up to see earlier messagesBash(ls) x), which never matched anything, to be reported as invalid settings instead of being silently ignoredclaudeMd) no longer triggers the security approval dialog; hooks, shell-command, sandbox, and unsafe env settings still require approval--chrome, /chrome and the browser tools are unavailableorgPluginSettings in the list form read by Claude Desktop 1.15200.0 and later; older desktops ignore itdesktop policy misspells a field in a nested object of a managedMcpServers or orgPluginSettings entry! bash-mode prompt to run outside the sandbox even when strict sandbox mode (sandbox.allowUnsandboxedCommands: false) is on, like typing into your own terminal--kill-session-after-min to release a session that is only waiting on its user (paused, resumable on the next message) instead of killing it and reporting a failuremanagedMcpServers managed setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as .mcp.json); entries that name a command to run are skipped--permission-prompts none for unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps decidingglab mr create/merge/close/reopen/note/update so GitLab merge requests show as MR !N in the collapsed tool summary and refresh the footer MR badge--json to claude plugin validate for a machine-readable validation report~/.claude.json changes — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at onceRead() deny rules not covering files given as option values (--ignore-revs-file=.env, -f.env, @file), git diff/git grep file operands, or cd DIR && cat FILE compounds; grep -r/cp -r over a directory holding a denied file now asksmodel: named one; the turn now keeps the session modelCLAUDE_CODE_MAX_CONTEXT_TOKENS being ignored for Vertex-style model IDs (@YYYYMMDD suffix) of model versions Claude Code doesn't recognize--resume failing (and --continue opening an empty conversation) when a saved session contains an attachment entry with no payloadmodel: on custom commands and skills being ignored in interactive sessionsnote" error in conversations continued from an older versionforceRemoteSettingsRefresh being ignored at startup when a policy helper configured by MDM or the managed settings file had already rungit rev-parse fails with a message other than "not a git repository"user.email, organization.id, and user.account_uuid attributes?/# producing an unusable .git clone URL/workflows agent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle/install-github-app to explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repositoryallowedMcpServers to govern only servers users add: a literal managed-mcp.json server your allowlist used to filter out now loads on upgrade; use deniedMcpServers to keep it offclaude-fable-5-1), now the default Fable model — 1M context, $10/$50 per Mtok with $0.25/Mtok cache readstimeFormat) and timeZone settings: 12-hour, 24-hour, 24-hour UTC, or a strftime pattern for the turn-end clock and transcript-view timestampsCLAUDE_CODE_SUBAGENT_MODEL_FORCE to apply CLAUDE_CODE_SUBAGENT_MODEL (or the main model) to every subagent, ignoring per-spawn and agent-definition model overridess in /effort to change effort for the current session only, matching /model/doctor warning for stale sandbox mask files left by a killed sessionpermissions.blockReadsOutsideWorkingDirectories)description on discovered /model picker entries (CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY); entries without one still read "From gateway".claude/ folder created after startup not being picked up until restart← always starting in the original session's permission mode, overriding the target directory's defaultMode and the agent's permissionModekeybindings.json rebinds of Ctrl+G being ignored in claude agents; its Ctrl+S / Ctrl+T are now rebindable via the new Agents contextstate.json detail repeating its own dispatch prompt after a scheduled wake-upclaude agents keeping a background session you re-prompted buried in Completed after it finished again; Completed now orders by the latest finishclaude --bg from a directory that was just deleted reporting "backgrounded" and leaving a crashed session row; it now prints the reason and exits 1Authorization header overriding the configured credential on Bedrock, Mantle, Vertex, and WIF, and the Vertex setup wizard picking up a leftover Anthropic profile from ~/.config/anthropicAuthorization or profile headers to Foundry, Vertex, and Bedrock, and Foundry Entra ID upstreams not starting when ANTHROPIC_FOUNDRY_API_KEY is set/schedule routines whose prompt was saved without a message role and then ran with nothing to doclaude agents not saying that a background session is waiting for you to approve a message from another session, or who sent itpolicyHelper timeoutMs and refreshIntervalMs values above the timer maximum (2147483647) causing failures or re-runs every millisecond; they are now clampedexample.com.): a deniedDomains entry didn't block the host inside the sandbox, and "don't ask again" for such a host kept promptingn at claude remote-control) counting as consent, so the next request connected without asking/mcp reconnect and enable still connecting a settings-file MCP server that a managed MCP allow/deny list or strictPluginOnlyCustomization loaded after startup should blockclaude mcp remove leaving a remote server's stored OAuth credentials behind when strictPluginOnlyCustomization locks MCP to plugin-only serversclaude remote-control) sessions started from the Claude app ignoring the selected model and running on the machine's default instead--disallowedTools and session deny rules being dropped after the first settings reload when allowManagedPermissionRulesOnly is enabled--resume listing a backgrounded conversation twice and --continue reopening its stalled pre-background copy; --continue now also opens finished background sessions! shell command output to expand itclaude agents --json briefly switching the terminal to raw mode and undoing another program's terminal settings on exit← doing nothing in the /btw panel inside a claude agents session: it now returns to the agents list (even mid-answer), and the panel comes back when you reopen the session/recap, prompt suggestions) and re-sending the full conversation uncached each timeclaude -p exiting about 5 seconds after its final result while a Monitor the model armed was still running; it now waits for the watch to fire or time outpermissions.ask rule being skipped in auto mode when the matching command ran inside a compound command or subshell, letting it run without the confirmation prompt/add-dir rejecting a directory inside the current working directory; it now loads that directory's skills, commands, and agents like --add-dir does at startup/feedbackclaude mcp add/remove hanging or exhausting memory when the project's .mcp.json is a FIFO or a device-file symlink; it now fails fast with an actionable messageclaude -p --input-format stream-json; it now fails fast with a clear error← or Ctrl+B) while a subagent or other tool was running occasionally making the background session treat that tool as rejected instead of re-running itRead()/Edit() deny rules not applying to < file redirects and reader commands like tac and egrep; a deny rule on any argument or redirect target now refuses the command$VAR reads, "$(…)" and heredocs that never touch git as "too complex to verify that it stays inside the worktree"/model and /effort showing a prompt-cache warning after rewinding a conversation back to emptytimeout or setsid) surviving a task stop or Claude Code exit.git directory after cd into a subdirectory/login instead of reporting a network errorcc-daemon-* folders in the system temp directory after an interrupted background daemon start; the cleanupPeriodDays retention sweep now removes them[[ ]] conditionals that zsh parses differently from bash; these commands now prompt for approval/status not showing the Organization for that sign-in/status, declining the managed-settings dialog prints why Claude Code exited, and helper timeouts are reported as timeouts/code-review --comment to post findings on GitLab merge requests via glab mr note instead of reporting the target as unsupportedclaude self-hosted-runner --configure-git to also enable git push negotiation, so the first push of a new branch from a stale clone uploads only the new commits instead of the whole treeCLAUDE_STREAM_IDLE_TIMEOUT_MS are not mistaken for a hung session/fork to keep the original conversation's prompt cache in the new background session: its worktree briefing now arrives as a message instead of a system-prompt change:satisfied:, :telephone:, :collision:, …)--effort to lift a new model's default-effort hold for that session only rather than permanently; an effort picked on claude.ai for a Remote Control session now applies during the holdpolicyHelper in MDM or managed-settings.json shadowed at launch by cached server-managed settings to run (or exit) as soon as the fetch reports them removed, not at the next launchmanagedSourcesBehavior: "merge" to take sandbox.credentials.awsPairs and sandbox.ripgrep whole from the highest managed source that sets them instead of combining the sources' valuesCLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1) to run even when CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC is set, since it only queries your gatewayclaude --resume <session-id> --bg to continue that session under its own ID when nothing is running it, instead of silently starting a copy; a copy is now announced/btw history browsing from ←/→ to Shift+←/Shift+→ (or [/]), stepping through your recent side questions and back to the live answerdefaultMode: "bypassPermissions" in .claude/settings.json or .claude/settings.local.json to be ignored, like "auto"; set it in user or managed settings, or pass --permission-modefable and best in Claude apps gateway sessions to keep resolving to Fable 5 for now, since gateways not yet configured for Fable 5.1 reject it; pick Fable 5.1 in /model to use it--add-dir, /add-dir, and additionalDirectories to refuse network paths (UNC shares, /net/<host> automounts) with a message before touching them; on Windows use a mapped drive letterPreModelSwitch and PostModelSwitch hook events (block, confirm, or annotate a model switch); SessionStart resume hooks now receive session staleness and the estimated re-cache cost/usage and a rate_limits.spend_limit status line field for developers behind a Claude apps gateway with spend limits/cost (hit ratio, misses, tokens re-cached, warm/cold) and a matching prompt_cache object for status line scriptsattach, logs, stop, respawn, and rm to claude --help; the --resume message for a running background session now names the exact claude attach <id> commandscriptPath outside what the session may read before the permission check ranRead(...) deny rules to files reached through a symlinked search pathhigh in that caseSendMessage to that session id now delivers through Claude Desktop instead of failing with "not reachable"from was the agent type, which is not an address)disableAutoMode arriving mid-session not moving an already-running auto-mode session back to default mode/status and retrying gateway 401s with it, though requests never use it/mcp reconnect on Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session--input-format stream-json: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessionsgit worktree add/usage-credits for Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached--worktree --tmux with a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly/dev/tty, such as emacs -nw and microadditionalDirectories entry containing a null byte crashing startup, or breaking /add-dir and later settings updates when it came from an SDK host, IDE, or hook; it is now skippedscreen terminal typeclaude mcp add --header and claude mcp add-json help text naming the wrong transportsclaude ultrareview and /ultrareview waiting the full 30 minutes when the cloud session fails to start; they now stop early and report the reasonOPTIND=1/0, RANDOM=2+2); these now prompt for approval←, /background, --bg) losing a Vertex/Bedrock gateway (ANTHROPIC_*_BASE_URL + CLAUDE_CODE_SKIP_*_AUTH) exported in the shell, so every request failedclaude --bg --model fable on Max plans stopping to ask for usage credits while the interactive session on the same account still had Fable allowance/bug and /share reporting that /feedback was disabled; tips, /help, and refusal messages no longer suggest /feedback when an org policy or env var turns it off/schedule to explain that MCP servers configured in Claude Code can't be attached to cloud routines, instead of a bare "No MCP connectors" message/tasksCLAUDE_CODE_PROVIDER_MANAGED_BY_HOST (e.g. Claude Desktop): a session given a Bedrock model ID or ARN no longer waits for inference-profile discovery/radio to be available on Bedrock, Vertex AI, Foundry, and Claude Platform on AWS, and when telemetry is disabledCLAUDE_CODE_SUBAGENT_MODEL to set the default subagent model rather than override everything: an agent definition's model: and an explicit per-spawn model now take precedence over itCo-Authored-By: Claude Code when the active model isn't a recognized Claude model (e.g. third-party models behind a custom ANTHROPIC_BASE_URL)/effort to save your default effort level per model, so each model keeps its own setting when you switchDISABLE_TELEMETRYgh auth token, GH_TOKEN, or GITHUB_TOKEN) instead of gh pr viewANTHROPIC_CUSTOM_HEADERS from managed or project settings to require approval when it sets a credential, org/tenant, routing, or API-behavior header (e.g. Authorization, Host).claude/settings.json env to no longer set CLAUDE_CONFIG_DIR, CLAUDE_CODE_TMPDIR, or TMPDIR/TMP/TEMP; set them in your shell, user, or managed settings instead/remote-control--restricted (or CLAUDE_CODE_RESTRICTED=1): removes the built-in tools that run commands or code and WebFetch (unless named in --tools), keeps file tools inside the working directory, refuses bypassPermissions, and ignores user, project and local settings filesexperimental.cacheTtl ("5m" or "1h") to agent frontmatter: a per-agent prompt cache TTL used when no subagent TTL setting is configuredclaude self-hosted-runner --client-label <label> (or SELF_HOSTED_RUNNER_CLIENT_LABEL) to override the label the runner registers with (default: hostname)/doctor and /status line explaining a load failure or why they weren't fetched (Bedrock/Vertex/third-party provider, custom ANTHROPIC_BASE_URL)/web-setup when the GitHub CLI token lacks the workflow scope, since pushes to very large repositories can be rejected without it/usage-credits for Enterprise organizations billed through AWS Marketplace, self-serve Enterprise, and Enterprise trials, so members can request a higher usage limit from their adminSendMessage / ListAgents) between sessions on the same machine on Bedrock, Vertex, and Foundry, and when telemetry is disabledScheduleWakeup tool definition changing between a session and its --resume when the account had entered usage overage, causing a full prompt-cache miss on the resumed session's first turndesktopSessionCleanupPeriodDays setting caps the exemptionclaude agents list not responding to the keyboard after detaching from a session, or when launched in a terminal tab left in win32-input-mode/login failing with an OAuth error before showing a sign-in URL on machines where it can't be used (for example when ANTHROPIC_API_KEY or an API key helper is set); it now falls back to the API-key sign-in/model and fast-mode switch notices to render as code, so suffixes like [1m] display literally instead of as a linkclaude agents skipping the workspace trust prompt when the CI environment variable is setclaude agents crashing on launch when the PR-status cache held a malformed entryclaude agents: opening a stopped session that you already resumed in another terminal no longer starts a second process on that conversation; the row now says it is open in a terminalclaude agents and claude rm refusing to delete a session ("has commits that are not pushed anywhere") when its worktree branch was already merged into your checked-out default branch (e.g. local main) but not yet pushedPermissionRequest or PreToolUse hook prints an invalid answer: the claude agents row now names the hook and the schema error{…} object that isn't valid JSON as plain text; it's now reported as a hook error with the parse message/mcp listing a project .mcp.json entry that declares the claude.ai connector type under the trusted "claude.ai" heading; it now appears under its real scopeheadersHelper supplies the Authorization header falling into OAuth discovery on a 401 instead of re-running the helper and retrying the call as documented/login to a Claude apps gateway hanging when the managed-settings security approval dialog was requiredCLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY) never running when apiKeyHelper is the only credentialclaude logs leaving mouse tracking, bracketed paste and the alternate screen switched on in the terminal it was run from/ultrareview and locally seeded cloud sessions uploading uncommitted edits to prod.env-style and *.tfvars files, or to editor swap, temp, and backup copies of credential files (e.g. key.pem.tmp, id_rsa.swo); they now stay on your machineclaude remote-control rejecting its own flags (e.g. --spawn, --name) when a global flag or a wrapper-injected option precedes the subcommandgit worktree remove leave it alonecrossSessionInbound value being silently ignored: it now warns and holds cross-session messages (user settings) or refuses them (managed settings) until fixed/usage-credits when that command isn't available for your organization (e.g. hidden with DISABLE_EXTRA_USAGE_COMMAND)workflow-authoring skillgh pr command still refreshes it right away/ultrareview <PR#> to check before launch that the GitHub account connected to your Claude account can access the repository, and to explain how to fix it, instead of failing after the cloud session starts/tmp directory when the default one can't be used, and the notice and /status name the directory to fix/loop: self-paced dynamic mode and the no-prompt autonomous default are now always available, including on Bedrock/Vertex/Foundry[Anthropic telemetry] instead of [3P telemetry] OTEL diag error, so they are not mistaken for your OTel collector failingSendMessage from a subagent to another session: the result now notes that any reply is delivered to the parent session's conversation, not to the subagentSendFeedback tool: when something goes wrong in a session, Claude can draft a feedback report for you to review and send from /feedback (turn off with the feedbackDrafts setting){id, text, cooldownSessions, priority} entries, tipsFile, and label to spinnerTipsOverride, so organizations can rotate their own tips alongside the built-in ones/claude-api cost-optimize to profile an existing project's Claude API spend and work through cost levers (caching, token hygiene, batch, effort, model choice) one measured change at a time/claude-api skill with Admin API coverage (organization members, invites, workspaces, API keys, rate limit reports, workload identity federation, CMEK)/config, /mcp, /skills, background tasks, and /model<35;150;7M being inserted into the prompt when a mouse report arrived split across reads right after the escape prefix~/.claude/settings.json symlink (nix/home-manager, stow) when it is repointed outside the sandbox's writable area/terminal-setup overwriting your entire Zed keymap.json instead of merging in its keybinding/rename silently confirming when the session registry could not be updated; it now says other sessions may still show the old name/compact and "Summarize from here" in sessions started with --agent summarizing under the default system prompt instead of the conversation's ownclaude agents after its terminal host process died; the row now fails within seconds with the reason, and Enter restarts it/install-github-app over SSH: the copy shortcut now says how the sign-in URL was copied instead of always claiming success, and the URL appears immediately when no browser can open[exited with code -1] line when they finish in background sessions/remote-control not reporting the working-tree diff to connected clientsrunning before Claude Code had started, which could trigger a premature "Claude is waiting for your input" notification from the Claude desktop app/plugin and claude plugin output is escape-safeMessage from @<sender>: <first line> preview; Ctrl+O expands the full bodysurface=claude_code device-authorization parameter and a claude-code/<version> User-Agent)Bash(git * main)), since they also match options inserted before the subcommand/permissions for viewing and editing auto mode classifier rules✻ Sautéed for 23s · done 6:05 PM+/N) lists and setext headings{}), instead of their real type/background during a dynamic workflow restarting its finished subagents; it now asks first and says how many subagents would restartclaude agents while its worker was still booting (common on Windows) stopping it with "was stopped while the respawn was in flight"claude agents listing a backgrounded named session twice; backgrounding the same conversation again now numbers the new row (e.g. my-session (2)).claude/worktrees/ that you created yourself when an old background-session record pointed at themname already includes the <plugin>: prefix showing it doubled in the slash menu (e.g. /plugin:plugin:skill)claude plugin update failing for an installed plugin given its bare name (only the fully-qualified name worked)plugin.json was saved with a UTF-8 byte-order mark (BOM)/reload-plugins reporting 0 skills for plugins that define skills under skills/*/SKILL.md${CLAUDE_PLUGIN_ROOT} instead of the resolved plugin path/rename replacing the theme's prompt border color (including a custom theme's promptBorder) with the default cyan; the border now keeps your theme's color unless you pick one with /colordiffAdded/diffRemoved and their dimmed variants) being ignored in diffs and the /theme previewkeybindings.json binding with an unknown action name silently deadening that key; it is now skipped so the default binding keeps working, and a warning is logged under --debug/stats activity heatmap showing each day's activity one cell off (Sunday's count under Monday) in timezones east of UTC/fork from an already-forked or backgrounded session starting the new session with an empty conversation/-- (e.g. Lean doc comments) being rejected as an unknown slash command instead of being sent to Claude@ file picker staying open after the typed text stopped matching a real path~/.claude/sessions left by sessions that exited uncleanlyANTHROPIC_BASE_URL) streams a tool_use block without an idclaude plugin install <name> exiting silently (or hanging in a terminal) instead of reporting an error when ~/.claude/plugins/known_marketplaces.json is empty or corruptedcurl -fsSL https://claude.ai/install.sh | bash failing with "Raw mode is not supported" for some Team/Enterprise users with server-managed settingsclaude -p --continue/--resume with a permission prompt tool, when no permission mode was setNotification hook not firing while the sandbox "Network request outside of sandbox" permission prompt is waiting&& or || operator--strict-mcp-config sessions prompting to approve .mcp.json servers they would never load, which left background sessions waiting at startupANTHROPIC_BASE_URL); a credential is now only sent to its own hostapiKeyHelper returns short-lived JWTs: an expired cached token is now refreshed before sending, and 401/403 auth errors retry quietly/ultrareview runs and cloud sessions launched at the same time from one repository (e.g. from several worktrees) sometimes starting with another launch's uncommitted changes3/5) shown for background cloud sessions such as /autofix-pr occasionally missing a taskrequiresUserInteraction still offering "Yes, and don't ask again" in their permission prompt; the option wrote an allow rule the tool then ignored/cd: the new directory's project settings, hooks, .mcp.json servers (behind the usual approval prompt), skills, and agents now take effect right after the move instead of on --resumemaxTurns limit now returns its output marked as partial, with a hint to continue it via SendMessage, instead of appearing finished-p, SDK, cloud sessions) to automatically continue a response cut off mid-stream by a server error, connection loss, or stall instead of ending with an errorapiKeyHelper runs at startup, and after a login token expired while idle/code-review so Claude can also start it on its own on Bedrock, Vertex AI, and Foundry, through the Claude apps gateway, and when telemetry or non-essential traffic is disabled/goal: Changed idle sessions to start at most three check-ins on long-running background work per goal; your next message allows three moreclaude install and claude update to defer a pending managed-settings consent prompt to the next interactive session instead of prompting mid-commandplugin_id_hash now reflects the plugin's real marketplace, and enabled_via is admin-install for admin-installed plugins--setting-sources/cost, status line, --max-budget-usd) now include the 1.1× US-only-inference premium for data-residency workspaces/claude-api upgrade to migrate Python projects from anthropic 0.x to 1.x, and updated the skill's Python reference for 1.x (timeouts use anthropic.Timeout, not httpx.Timeout)name@synced, work with claude plugin enable/disable <name>@synced, and never override a same-named plugin you installedawsAuthRefresh — the credential pre-check now honors HTTPS_PROXYsetMcpServers()/resume after more than ~64 KB of conversation was written following the renameclaude -c/resume picking up sessions from a different directory whose path differed only by characters like _, -, or ./resume and the agents view showing a session as recently changed (and reordering it) when only its file was touched or it was merely reopened/resume in all-projects mode telling you to cd into a deleted directory (e.g. a removed worktree); such sessions now resume in the current directorydark-ansi theme rendering expanded tool results in fullscreen mode with text the same color as the background.worktreeinclude patterns starting with **/ silently matching nothing when the target lived in a gitignored directory.md file starts with a UTF-8 BOM being silently ignored/insights echoing literal <message> tags in its response on some modelsmetadata.pluginRoot having no effect: bare plugin source names now resolve under it as the docs describe"35;150;7M" into the prompt when a mouse report arrived split across writesPreToolUse hook now resume in the original turn's trace instead of starting a new traceselection:copy keybinding silently dropping a text selection that had been extended with Shift+Arrow keys/voice startup tip still appearing after voice dictation was enabled via the voice.enabled setting!) Tab completion dropping the ./ from a ./script path, which left a command the shell couldn't run/config, /model) in fullscreen mode covering the latest messages; the conversation now stays pinned above the panel/workflows detail dialog overflowing the terminal and losing its header off-screen when opened while Claude is still responding.git/config.worktree unreadable, which broke every sandboxed git command in repos with extensions.worktreeConfig setclaudeMdExcludes not excluding a symlinked .claude/rules file when the pattern names the rules directory or the symlink rather than its target/ being unaddressable by SendMessage and shown as "(untitled)" in ListAgentsdf/dt leaving a broken [Pasted text #N] placeholder when the cursor was inside itSessionStart or Setup hook runs, so the container is not idle-reaped mid-hook/goal: repeat check-ins on long-running background work now back off (30 min, then 1 h, then every 2 h) instead of repeating every 30 minutes/goal: resuming a session from the claude --resume picker now restores its active goalListAgents now tells a session its own name (the one peers use to message it), and SendMessage to your own name says so instead of "no agent named …"ListAgents and /list-agents now list your live teammates (previously only subagents and other sessions appeared, so a reachable teammate looked absent)keybindingFlavor: "readline" now also matches Bash for word keys: Alt+F and Ctrl/Option+→ stop at the end of the word, Alt+D deletes to it (Ctrl+Y pastes it back), and punctuation separates wordsCLAUDE_CODE_RETRY_WATCHDOG) now fails immediately on organization spend-limit and out-of-credits errors instead of waiting indefinitely for a reset/clear now closes the session's Chrome tab group, and empty groups are closed on /resume and when Claude Code exitsclaude doctor wording when Remote Control isn't enabled for your accountSendMessage and find each other with ListAgents, as on macOS and LinuxkeybindingFlavor setting: set it to "readline" to make Ctrl+W in the prompt delete back to the previous whitespace, as in Bash; the default ("classic") is unchangedheadersHelper on a url marketplace or a catalog entry runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetchesheadersHelper runs only when you install or update that plugin, after its command is shown; claude plugin install/update ask [y/N] (or pass -y)claude self-hosted-runner --defer-shutdown-max-min <minutes>: on SIGTERM, keep serving attached sessions, park what is left after that many minutes, then exitclaude self-hosted-runner --proxy-authorization-command / --proxy-authorization-file for egress proxies that require a freshly issued Proxy-Authorization header on every connectionCLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true not keeping prompt suggestions on when your account is near, but not over, its usage limit/tmp/claude-*-cwd files when a Bash command is killed, times out, or is interruptedserver/discover request before initialize, forcing lazy servers to start their backend on every session open/model and /effort cache-miss warning appearing when the prompt cache had already expiredclaude remote-control inheriting session-scoped environment variables from the launching shellclaude remote-control was restarted; it can now be reused when you next message itListAgents/SendMessage reporting "Remote Control is not connected" in sessions run by claude remote-control (server mode) or Desktop/IDE hosts; they now list and reach Remote Control peersListAgents and SendMessage exposing the idle worker that the agent view pre-warms for your next background session; it now appears only once a task claims itcrossSessionInbound: "refuse") now reports "refused" to the sender instead of a silent successclaude starts sooner on macOSclaude-api skill for the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes/clear shortcut was removed, and 1-row nvim terminals no longer trigger automatic /clear loopsclaude mcp list and claude mcp get to show disabled servers as ⊘ Disabled instead of connecting to them for a health checkheadersHelper in a project .mcp.json, and inline MCP servers in project or --add-dir agent files, now require that folder's trust dialog to have been accepted (also under claude -p)headersHelper from a project .mcp.json, plugin, or agent file runs without inherited credential env vars; user, managed and claude.ai-scope helpers now run from the Claude config dirANTHROPIC_DEFAULT_MODEL environment variable: sets the model new sessions start on, while a /model pick still overrides it and persists across restarts (unlike ANTHROPIC_MODEL)notify_when_idle to cross-session SendMessage: ask another Claude Code session on this machine to send one notice when it next goes idle — opt-in, one-shot, no polling (macOS and Linux)**/.env) now take precedence inside allowed read regions, cover matched directories' contents, and can't be bypassed by renaming the denied file/model picker rendering taller than the terminal: it now shows only as many models as fit the window, with the rest reachable by scrollingSendMessage calls being rejected when a malformed closing tag left the message text inside the summary fieldpowershell.exe on WSL with Windows interop disabled (regression in 2.1.234)~/.claude.json was malformed/recap) is now capped at 400 characters, cut at a word boundaryMonitor allow rules are now set aside while auto mode is active, so Monitor commands are reviewed the same way Bash commands arestatus.showUntrackedFiles=no setting into reporting a clean tree/model picker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list/goal: an idle session whose goal is parked behind long-running background work now checks in automatically after 30 minutes (then 1h, 2h) instead of waiting for you to return/usage now shows the usage-credits spend row for Team and Enterprise members, and shows a capped row at 0% before anything is spentSendMessage now refuses further messages to a session up front once a rapid burst would exceed what that session's inbox accepts, instead of reporting them sent while they were droppedspellcheck setting that underlines misspelled words in the prompt input as you type, using your installed aspell, hunspell, or ispellsubagent_type there now gets a clear error listing the available agentsctrl+t) always starting collapsed when resuming or relaunching into a session that still has open tasks/ultrareview or /autofix-pr run in the background — their event streams are no longer re-scanned and re-rendered on every updategrep in native macOS/Linux builds: pathological patterns now fail fast instead of exhausting memory, and -m N with -A/-C prints correct context/config to re-enable itSendMessage now refuses messages too large for cross-session delivery up front instead of silently dropping themclaude rc now applies the same enterprise-gateway availability check as interactive startupCLAUDE_CODE_PROJECT_DIR_NAME environment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directoryselection:clear keybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view/config ("Continue automatically at usage limit")\??\) paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vectorSendMessage rejecting a recipient copied from ListAgents when the session name is at the 200-character cap or emoji-heavy${VAR} form, and connection-failure details show only the server originstrictKnownMarketplaces allowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to/login OAuth URL losing characters when copied in fullscreen--- horizontal rule in rendered markdown running into the line after it/permissions opened while a ! shell command was running being dismissed when the command finished! shell command being sent to the model as plain text after pressing up-arrow to edit the queued input! mode no longer sticks after a mid-turn submit--dangerously-skip-permissions), tool allow/deny rules, model or effort flags/tui dropping launch --allowed-tools/--disallowed-tools rules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can't carry over/login while CLAUDE_CODE_OAUTH_TOKEN is set, the stale-token reminder no longer leaks into Claude's automatically resumed turn — it now appears only to youSendMessage and ListAgents now say when your account's session list was too long to check completely, instead of treating unseen sessions as absent/login when a claude.ai login would take precedenceclaude-api skill from ~200k+ tokens to ~25k by loading reference docs on demand/permissions can now be opened while Claude is working — rule changes apply to the rest of the current turn/add-dir <path> can now be used while Claude is working; /add-dir, /autocompact, /theme, /help, /config and /advisor dialogs open mid-turn in the fullscreen TUI/goal now clears itself with a notice when a turn dies on an unrecoverable error (e.g. revoked auth, an exhausted credit balance, or a context overflow) instead of staying armed/goal: when background tasks keep a goal waiting for 30+ minutes, Claude now checks in on them instead of waiting indefinitely (set CLAUDE_CODE_GOAL_CHECKIN_MINUTES=0 to opt out)claude setup-token now rejects unexpected extra arguments instead of silently ignoring them/config; agent-team teammates now use the leader's model unless the spawn names one<system-reminder> tags, matching mid-turn delivery~/.claude.json is read-only--worktree flag and the claude agents view (where MRs display as !N)forward_user_identity apps gateway setting on Anthropic upstreams that sends the signed-in user's identity as headers, so a proxy behind the gateway can attribute spend per userCLAUDE_CODE_TOOL_MEMORY_LIMIT) so a runaway build can't stall the sessionCLAUDE_CODE_WEBFETCH_CACHE_TTL_MS environment variable to configure the WebFetch session URL cache TTL (default unchanged: 15 minutes)/checkup and /review reporting "Unknown command" in -p mode or with plugins/MCP loaded when a user or project skill shadows the bundled skill\??\ device prefix bypassing UNC path validation, closing an NTLM credential-leak vectorclaude self-hosted-runner session start time: the session branch is now created without rewriting the working tree, and two server round trips no longer block the agent's launchclaude plugin validate to check a bare .claude/skills directory, reporting SKILL.md files whose frontmatter fails to parse/effort selector renders as a numbered list with a typed-number prompt, and hint and dialog text is no longer clipped[claude-code:unrecognized_model] line is written to stderr when a request goes out for a model ID Claude Code doesn't recognize; map it with modelOverrides to silenceCLAUDE_CODE_ENABLE_TODO_TOOLS=1 to bring them backcd <dir> && <command> > file Bash commands (a 2.1.232 regression)< file); a narrower version will return in a later release