What changed
Claude Code 2.1.236 shipped on August 19, 2026. Two additions: an environment variable for the model new sessions start on, and a way to ask another session for one notice when it next goes idle. The rest tightens what auto mode reviews and how, closes a bypass in macOS sandbox read-deny rules, and clears close to 30 fixes clustered around fullscreen rendering and background work.
New features
-
ANTHROPIC_DEFAULT_MODELenvironment variableANTHROPIC_MODELpins the model, so a/modelpick made inside a session did not stick. The newANTHROPIC_DEFAULT_MODELsets only the model new sessions start on: a/modelpick still overrides it, and that pick persists across restarts. -
notify_when_idleon cross-sessionSendMessageFinding out whether another session had finished meant asking it. You can now ask another Claude Code session on this machine to send one notice when it next goes idle — opt-in, one-shot, no polling. Available on macOS and Linux.
Key improvements
-
Wildcard read-deny rules take precedence in the macOS sandbox
A wildcard read-deny rule such as
**/.envcould lose to an allowed read region, and renaming the denied file was enough to get around it. On macOS these rules now take precedence inside allowed read regions, cover matched directories’ contents, and can’t be bypassed by renaming the denied file. -
Auto mode reviews
MonitorcommandsMonitorallow rules still applied under auto mode, so pre-allowed Monitor commands skipped review entirely. Those allow rules are now set aside while auto mode is active, and Monitor commands are reviewed the same way Bash commands are. -
Auto mode on Bedrock, Vertex AI and Foundry
The auto mode classifier behaved differently on Bedrock, Vertex AI and Foundry, and when telemetry is disabled, than it did on the Claude API. It now uses the same defaults in those setups, including severity-scored classification.
-
The auto mode git status check can’t be fooled
A repo’s
status.showUntrackedFiles=nosetting made auto mode’s git status check report a clean tree. That is no longer possible. -
The
/modelpicker highlights only the newest modelThe picker’s highlight covered an arbitrary subset of the list, so it wasn’t clear what it marked. It now highlights only the newest model’s name, so the highlight marks the new release.
-
/goalchecks in on parked workAn idle session whose goal sat behind long-running background work waited for you to come back. It now checks in automatically after 30 minutes, then again at 1h and 2h.
-
/usageshows usage credits for Team and EnterpriseTeam and Enterprise members had no usage-credits spend row in
/usage. It now appears, including a capped row at 0% before anything is spent. -
SIGTERM in print/SDK mode leaves a clean record
Terminating print or SDK mode with SIGTERM recorded an interrupted turn and synthetic tool denials on the way out. It no longer does; running commands are still terminated and the process still exits with code 143.
-
Slash-command typos are reported, not guessed
Pressing Enter on a mistyped slash command, or one unavailable in this session, ran the closest fuzzy match. It now reports the problem instead; prefixes and aliases still run.
-
Remote Control marks sessions offline quickly
A session kept looking alive in Remote Control after the CLI exited or its terminal closed. It is now marked offline within seconds.
-
SendMessagerefuses bursts a session’s inbox can’t takeA rapid burst of messages beyond what the recipient’s inbox accepts was reported as sent while the messages were dropped.
SendMessagenow refuses further messages to that session up front. -
Faster startup
Writing the session counter held up startup. It is now written in the background.
-
Alignment around the prompt
The session title chip on the prompt border sat out of line with the footer’s right edge; they are now aligned. Right-aligned footer items (goal indicator, session state, background agent status) and truncated notices also share a consistent right margin with the rest of the prompt area.
-
[VSCode] Screen reader support for the transcript
The transcript was hard to follow with a screen reader. It now has live announcements for replies, permission requests, errors and status changes, plus per-turn heading navigation.
Bug fixes
Rendering & terminal
- The fullscreen renderer failing permanently after a single failed start — fixed; it now falls back to the classic renderer instead of exiting on every subsequent launch.
- The
/modelpicker rendering taller than the terminal — fixed; it now shows only as many models as fit the window, with the rest reachable by scrolling. - Fullscreen mode sometimes not showing a newly sent message until the next update after the terminal was resized — fixed.
- A blank band remaining above the prompt after clearing a multi-line prompt, and panes not repainting after resizing the terminal away and back, in fullscreen mode — fixed.
- Terminal tab titles jumping in tmux (iTerm tmux integration) — fixed; the title is now written only when its text changes instead of animating every 960ms.
- The Clawd mascot’s eyes and feet rendering unevenly in iTerm2 at some font sizes — fixed.
- Occasional runaway session recaps — fixed; recap text (automatic and
/recap) is now capped at 400 characters, cut at a word boundary.
Sessions & background work
- Clipboard copy, background housekeeping, background sessions and local MCP logs breaking after the directory a session had switched into was removed — fixed; this dated from 2.1.229.
- Unhandled promise rejections when a subprocess fails to start, for example
powershell.exeon WSL with Windows interop disabled — fixed; this was a regression in 2.1.234. - Skills hot-reload in SDK/VS Code sessions raising an error on every skills change after the session’s working directory was deleted — fixed; this affected 2.1.229+.
- Self-hosted runner sessions occasionally resuming on another runner before the post-session hook had finished — fixed; this happened for sessions released on idle, retire or startup timeout.
- Spinner tips never appearing, with a repeated background error, when the cached guest-pass reward in
~/.claude.jsonwas malformed — fixed.
Other fixes
SendMessagecalls being rejected when a malformed closing tag left the message text inside the summary field — fixed.- The managed-settings approval prompt sometimes not appearing at startup while still capturing the first keypress as approval — fixed.
- An unclear error when the cloud environments list came back empty or malformed — fixed.
- The Fable 5 first-time usage-credits prompt auto-selecting the fallback model after 60 seconds with no answer when using Remote Control — fixed.
Notes
ANTHROPIC_DEFAULT_MODELis notANTHROPIC_MODEL— it sets only the model new sessions start on, and a/modelpick still overrides it and persists across restarts.notify_when_idleis opt-in and one-shot — it sends a single notice when the other session next goes idle, on macOS and Linux.Monitorallow rules don’t apply under auto mode — while auto mode is active, Monitor commands go through the same review as Bash commands.- The sandbox read-deny change is macOS — with
**/.env-style rules now taking precedence inside allowed read regions, files that used to be readable may stop being readable. - Recaps are capped at 400 characters — both automatic recaps and
/recapare cut at a word boundary. - Mistyped slash commands no longer run the closest match — if you relied on fuzzy matching, use a prefix or an alias instead.