What changed
Claude Code 2.1.238 shipped on August 20, 2026. The theme is authenticated, locked-down environments: plugin marketplaces and MCP can now mint fresh headers per fetch, and self-hosted runners gain flags for graceful shutdown and proxy authorization. The rest is more than 30 fixes and improvements clustered around memory use in long sessions, terminal input and rendering, and Remote Control connectivity.
New features
-
keybindingFlavorsettingCtrl+W in the prompt didn’t delete the same span it does in a Bash shell, so shell muscle memory removed the wrong amount of text. Setting
keybindingFlavorto"readline"now makes Ctrl+W delete back to the previous whitespace, as in Bash. The default ("classic") is unchanged. -
headersHelperfor plugin marketplacesAn authenticated marketplace needs a valid token on every request, and a static value in a config file can’t carry a short-lived one.
headersHelperon a url marketplace or a catalog entry now runs a command that mints HTTP headers (e.g. a short-lived token) for catalog and same-origin archive fetches. A catalog entry’sheadersHelperruns only when you install or update that plugin, after its command is shown;claude plugin install/updateask[y/N](or pass-y). -
claude self-hosted-runner --defer-shutdown-max-min <minutes>A SIGTERM tore down the runner along with the sessions attached to it, cutting work short during a deploy or restart. On SIGTERM the runner now keeps serving attached sessions, parks what is left after that many minutes, then exits.
-
claude self-hosted-runner --proxy-authorization-command/--proxy-authorization-fileRunners couldn’t connect behind egress proxies that require a freshly issued
Proxy-Authorizationheader on every connection. Both flags source that header per connection — from a command’s output or from a file.
Key improvements
-
Project-scope
headersHelperand inline MCP servers require folder trustA
headersHelperin a project.mcp.json, and inline MCP servers in project or--add-diragent files, could run without the folder’s trust dialog. They now require that folder’s trust dialog to have been accepted, including underclaude -p. -
headersHelperruns without inherited credential env varsA
headersHelperfrom a project.mcp.json, plugin, or agent file now runs without inherited credential env vars. User, managed and claude.ai-scope helpers now run from the Claude config dir. -
Ctrl+L and Cmd+K in fullscreen always just repaint
A double press triggered
/clear, and 1-row nvim terminals could fall into automatic/clearloops. Both keys now always just repaint, and the double-press/clearshortcut was removed. -
claude mcp listandclaude mcp getno longer connect to disabled serversBoth commands connected to disabled servers for a health check. They now show them as
⊘ Disabledinstead. -
Remote Control connection resilience
A brief HTTP 403 refusal from a network edge, VPN, or proxy dropped the connection outright. Such refusals are now tolerated for up to 3 minutes, with the refusing party named when a block persists.
-
Bash tool permission checking for zsh-specific syntax
Permission checking mishandled zsh-specific syntax in shell conditionals. Its handling of those conditionals is improved.
-
Startup
Bare
claudestarts sooner on macOS, and the automatic update check now runs about 10 seconds after launch instead of competing with startup for CPU. -
Updated bundled
claude-apiskillThe bundled skill now reflects the Managed Agents Aug 19 release: web search/fetch domain settings and memory stores on self-hosted sandboxes.
Bug fixes
Sessions & memory
- Unbounded memory growth in long interactive sessions — subagent tool results are now released once they leave the recent display window.
- Custom, project, and plugin output styles drifting back to the default voice mid-session — fixed.
CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=truenot keeping prompt suggestions on when your account is near, but not over, its usage limit — fixed.- The
/modeland/effortcache-miss warning appearing when the prompt cache had already expired — fixed.
Terminal & rendering
- Held Backspace being ignored on terminals that send Ctrl+H for Backspace when keystrokes arrive in large bursts — fixed; this showed up on slow SSH/mosh links.
- Text-wrapping in permission prompt diffs — lines containing wide multi-code-point characters (such as emoji) or tabs are no longer clipped.
- Killing a suspended (Ctrl+Z) session sometimes leaving the terminal in bracketed-paste mode with the cursor hidden — fixed.
- MCP elicitation dialogs showing nothing for URLs longer than 4,096 characters, and permission prompts dropping the “don’t ask again” option when the project path didn’t fit the terminal width — fixed.
Permissions & execution
- Worktree-isolation Bash refusals telling you to remove a redirect when the command had none — fixed.
- Leftover
/tmp/claude-*-cwdfiles when a Bash command is killed, times out, or is interrupted — fixed.
MCP, proxies & runners
- stdio MCP servers receiving a
server/discoverrequest beforeinitialize— fixed; this forced lazy servers to start their backend on every session open. - A proxy’s refusal of a connection being reported as a generic network error — fixed; the proxy is now named.
- Self-hosted runners occasionally being removed by the server after a single slow or lost poll request — fixed; this handed their healthy session to another runner.
Remote Control
- Per-task Stop from the tasks panel doing nothing on CLI-hosted sessions — fixed.
- Remote sessions exiting when a client delivered a user message without a valid role — fixed.
- Sessions started by
claude remote-controlinheriting session-scoped environment variables from the launching shell — fixed. - A session whose process crashed staying unavailable until
claude remote-controlwas restarted — fixed; it can now be reused when you next message it. - Messages sent from the web or Desktop while Claude is mid-turn disappearing from the transcript after the turn finishes — fixed.
- Model picks made on a phone or web not updating the model shown in the terminal — fixed.
- Disconnecting with “login expired” when a brief network hiccup delays renewing your sign-in — fixed; it now retries and stays connected.
- Reporting a failed reconnect on sign-out — fixed; signing out now ends the session with a clear message.
Cross-session messaging
ListAgents/SendMessagereporting “Remote Control is not connected” in sessions run byclaude remote-control(server mode) or Desktop/IDE hosts — fixed; they now list and reach Remote Control peers.ListAgentsandSendMessageexposing the idle worker that the agent view pre-warms for your next background session — fixed; it now appears only once a task claims it.- Sending to a session on this machine that refuses inbound messages (e.g.
crossSessionInbound: "refuse") — now reports “refused” to the sender instead of a silent success. - A session whose inbox drops your messages (rate limit or full queue) — now tells your session, instead of the messages vanishing silently.
Notes
- 2.1.237 carried only two items — a fix for prompt caching in sessions using an LLM gateway or custom base URL, and a built-in “Concise” output style where Claude leads with results and skips preamble and narration while doing the work just as thoroughly. Select it under Output style in
/config. It is too small to cover as a standalone post. - The double-press
/clearshortcut is gone — Ctrl+L and Cmd+K in fullscreen now always just repaint, so type/clearto clear the conversation. - A catalog entry’s
headersHelperis gated behind a confirmation — it runs only on install or update, its command is shown first, andclaude plugin install/updateask[y/N](or pass-y). - Project-scope
headersHelperneeds folder trust — aheadersHelperin a project.mcp.jsonand inline MCP servers require that folder’s trust dialog to have been accepted, including underclaude -p. They also run without inherited credential env vars, so helper commands that relied on those need rechecking after the upgrade. keybindingFlavordefaults to"classic"— set it to"readline"for Bash-style Ctrl+W.claude mcp listno longer health-checks disabled servers — they show as⊘ Disabledwithout a connection attempt, so enable a server first if you want to verify it is reachable.