claudekit / updates / claude-code-2-1-238
[ PATCH · ]

Claude Code 2.1.238

A new `keybindingFlavor` setting makes Ctrl+W in the prompt delete back to the previous whitespace, as in Bash, when set to `"readline"`. Plugin marketplaces gain `headersHelper`, a command that mints HTTP headers such as a short-lived token for catalog and same-origin archive fetches, with the command shown and confirmed before it runs on install or update. Self-hosted runners gain `--defer-shutdown-max-min` for graceful SIGTERM handling and `--proxy-authorization-command` / `--proxy-authorization-file` for egress proxies that require a freshly issued `Proxy-Authorization` header on every connection. More than 30 fixes and improvements land alongside, including unbounded memory growth in long interactive sessions, output styles drifting back to the default voice mid-session, and a large cluster of Remote Control connection and messaging fixes.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.238 shipped on August 20, 2026. The theme is authenticated, locked-down environments: plugin marketplaces and MCP can now mint fresh headers per fetch, and self-hosted runners gain flags for graceful shutdown and proxy authorization. The rest is more than 30 fixes and improvements clustered around memory use in long sessions, terminal input and rendering, and Remote Control connectivity.

New features

  • keybindingFlavor setting

    Ctrl+W in the prompt didn’t delete the same span it does in a Bash shell, so shell muscle memory removed the wrong amount of text. Setting keybindingFlavor to "readline" now makes Ctrl+W delete back to the previous whitespace, as in Bash. The default ("classic") is unchanged.

  • headersHelper for plugin marketplaces

    An authenticated marketplace needs a valid token on every request, and a static value in a config file can’t carry a short-lived one. headersHelper on a url marketplace or a catalog entry now runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetches. A catalog entry’s headersHelper runs only when you install or update that plugin, after its command is shown; claude plugin install/update ask [y/N] (or pass -y).

  • claude self-hosted-runner --defer-shutdown-max-min <minutes>

    A SIGTERM tore down the runner along with the sessions attached to it, cutting work short during a deploy or restart. On SIGTERM the runner now keeps serving attached sessions, parks what is left after that many minutes, then exits.

  • claude self-hosted-runner --proxy-authorization-command / --proxy-authorization-file

    Runners couldn’t connect behind egress proxies that require a freshly issued Proxy-Authorization header on every connection. Both flags source that header per connection — from a command’s output or from a file.

Key improvements

  • Project-scope headersHelper and inline MCP servers require folder trust

    A headersHelper in a project .mcp.json, and inline MCP servers in project or --add-dir agent files, could run without the folder’s trust dialog. They now require that folder’s trust dialog to have been accepted, including under claude -p.

  • headersHelper runs without inherited credential env vars

    A headersHelper from a project .mcp.json, plugin, or agent file now runs without inherited credential env vars. User, managed and claude.ai-scope helpers now run from the Claude config dir.

  • Ctrl+L and Cmd+K in fullscreen always just repaint

    A double press triggered /clear, and 1-row nvim terminals could fall into automatic /clear loops. Both keys now always just repaint, and the double-press /clear shortcut was removed.

  • claude mcp list and claude mcp get no longer connect to disabled servers

    Both commands connected to disabled servers for a health check. They now show them as ⊘ Disabled instead.

  • Remote Control connection resilience

    A brief HTTP 403 refusal from a network edge, VPN, or proxy dropped the connection outright. Such refusals are now tolerated for up to 3 minutes, with the refusing party named when a block persists.

  • Bash tool permission checking for zsh-specific syntax

    Permission checking mishandled zsh-specific syntax in shell conditionals. Its handling of those conditionals is improved.

  • Startup

    Bare claude starts sooner on macOS, and the automatic update check now runs about 10 seconds after launch instead of competing with startup for CPU.

  • Updated bundled claude-api skill

    The bundled skill now reflects the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes.

Bug fixes

Sessions & memory

  • Unbounded memory growth in long interactive sessions — subagent tool results are now released once they leave the recent display window.
  • Custom, project, and plugin output styles drifting back to the default voice mid-session — fixed.
  • CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true not keeping prompt suggestions on when your account is near, but not over, its usage limit — fixed.
  • The /model and /effort cache-miss warning appearing when the prompt cache had already expired — fixed.

Terminal & rendering

  • Held Backspace being ignored on terminals that send Ctrl+H for Backspace when keystrokes arrive in large bursts — fixed; this showed up on slow SSH/mosh links.
  • Text-wrapping in permission prompt diffs — lines containing wide multi-code-point characters (such as emoji) or tabs are no longer clipped.
  • Killing a suspended (Ctrl+Z) session sometimes leaving the terminal in bracketed-paste mode with the cursor hidden — fixed.
  • MCP elicitation dialogs showing nothing for URLs longer than 4,096 characters, and permission prompts dropping the “don’t ask again” option when the project path didn’t fit the terminal width — fixed.

Permissions & execution

  • Worktree-isolation Bash refusals telling you to remove a redirect when the command had none — fixed.
  • Leftover /tmp/claude-*-cwd files when a Bash command is killed, times out, or is interrupted — fixed.

MCP, proxies & runners

  • stdio MCP servers receiving a server/discover request before initialize — fixed; this forced lazy servers to start their backend on every session open.
  • A proxy’s refusal of a connection being reported as a generic network error — fixed; the proxy is now named.
  • Self-hosted runners occasionally being removed by the server after a single slow or lost poll request — fixed; this handed their healthy session to another runner.

Remote Control

  • Per-task Stop from the tasks panel doing nothing on CLI-hosted sessions — fixed.
  • Remote sessions exiting when a client delivered a user message without a valid role — fixed.
  • Sessions started by claude remote-control inheriting session-scoped environment variables from the launching shell — fixed.
  • A session whose process crashed staying unavailable until claude remote-control was restarted — fixed; it can now be reused when you next message it.
  • Messages sent from the web or Desktop while Claude is mid-turn disappearing from the transcript after the turn finishes — fixed.
  • Model picks made on a phone or web not updating the model shown in the terminal — fixed.
  • Disconnecting with “login expired” when a brief network hiccup delays renewing your sign-in — fixed; it now retries and stays connected.
  • Reporting a failed reconnect on sign-out — fixed; signing out now ends the session with a clear message.

Cross-session messaging

  • ListAgents/SendMessage reporting “Remote Control is not connected” in sessions run by claude remote-control (server mode) or Desktop/IDE hosts — fixed; they now list and reach Remote Control peers.
  • ListAgents and SendMessage exposing the idle worker that the agent view pre-warms for your next background session — fixed; it now appears only once a task claims it.
  • Sending to a session on this machine that refuses inbound messages (e.g. crossSessionInbound: "refuse") — now reports “refused” to the sender instead of a silent success.
  • A session whose inbox drops your messages (rate limit or full queue) — now tells your session, instead of the messages vanishing silently.

Notes

  • 2.1.237 carried only two items — a fix for prompt caching in sessions using an LLM gateway or custom base URL, and a built-in “Concise” output style where Claude leads with results and skips preamble and narration while doing the work just as thoroughly. Select it under Output style in /config. It is too small to cover as a standalone post.
  • The double-press /clear shortcut is gone — Ctrl+L and Cmd+K in fullscreen now always just repaint, so type /clear to clear the conversation.
  • A catalog entry’s headersHelper is gated behind a confirmation — it runs only on install or update, its command is shown first, and claude plugin install/update ask [y/N] (or pass -y).
  • Project-scope headersHelper needs folder trust — a headersHelper in a project .mcp.json and inline MCP servers require that folder’s trust dialog to have been accepted, including under claude -p. They also run without inherited credential env vars, so helper commands that relied on those need rechecking after the upgrade.
  • keybindingFlavor defaults to "classic" — set it to "readline" for Bash-style Ctrl+W.
  • claude mcp list no longer health-checks disabled servers — they show as ⊘ Disabled without a connection attempt, so enable a server first if you want to verify it is reachable.