claudekit / updates / claude-code-2-1-246
[ PATCH · ]

Claude Code 2.1.246

`/permissions` gains an Auto mode tab for viewing and editing auto mode classifier rules, and Bash allow rules with a wildcard before the subcommand (e.g. `Bash(git * main)`) now raise a startup warning, since they also match options inserted before the subcommand. After `/cd`, the new directory's project settings, hooks, `.mcp.json` servers, skills, and agents take effect right away instead of on `--resume`, and non-interactive sessions automatically continue a response cut off mid-stream. Fixes land for background sessions failing to open after 45 seconds when the starting directory had been deleted or the machine had slept, severe transcript slowdown when a diff contained a very long single line, and telemetry requests to Anthropic carrying the API key configured for a third-party gateway.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.246 shipped on August 25, 2026. Most of the release goes to problems that surface in long-lived sessions: fullscreen transcript rendering and memory, background session startup, and plugin install paths. A handful of permission and credential behaviors also change, so environments that manage their own rules should re-check them after upgrading.

New features

  • Auto mode tab in /permissions

    There was no way to see which rules auto mode uses to approve tool calls. /permissions now has an Auto mode tab for viewing and editing auto mode classifier rules.

  • Startup warning for wildcard-before-subcommand Bash allow rules

    Bash allow rules with a wildcard before the subcommand (e.g. Bash(git * main)) also match options inserted before the subcommand, so they approve more than intended. Claude Code now warns about them at startup.

  • Turn completion time on the end-of-turn line

    The end-of-turn line showed how long a turn took but not when it finished. The turn’s completion time is now appended, e.g. ✻ Sautéed for 23s · done 6:05 PM.

Key improvements

  • /cd applies the new directory’s configuration immediately

    After /cd, the new directory’s project settings, hooks, .mcp.json servers, skills, and agents only took effect on --resume. They now take effect right after the move, with .mcp.json servers still behind the usual approval prompt.

  • Non-interactive sessions continue a cut-off response

    In -p, SDK, and cloud sessions, a response cut off mid-stream by a server error, connection loss, or stall ended the run with an error. Those sessions now automatically continue the response instead.

  • Subagent results marked partial at maxTurns

    A subagent that stopped at its maxTurns limit looked finished, so there was no sign its output was incomplete. It now returns its output marked as partial, with a hint to continue it via SendMessage.

  • Lower Bash tool latency

    Replaying snapshot functions on bash shells spawned a base64 subshell per function. That per-function subshell is gone, cutting tool latency.

  • Claude can start /code-review in more environments

    Claude could not start /code-review on its own on Bedrock, Vertex AI, and Foundry, through the Claude apps gateway, or when telemetry or non-essential traffic is disabled. It can now start it in all of those.

  • /goal check-in cap

    Idle check-ins on long-running background work kept waking the session. Idle sessions now start at most three check-ins per goal; your next message allows three more.

  • claude install and claude update defer the consent prompt

    A pending managed-settings consent prompt interrupted the command mid-run. It is now deferred to the next interactive session.

  • Better usage telemetry attribution

    Usage telemetry was not attributed to the right organization for workload identity federation sessions, for events sent while apiKeyHelper runs at startup, and after a login token expired while idle. All three paths now attribute correctly.

  • Corrected OpenTelemetry plugin events for claude.ai-synced plugins

    plugin_id_hash did not reflect the plugin’s real marketplace, and admin-installed plugins were indistinguishable by install path. plugin_id_hash now reflects the real marketplace, and enabled_via is admin-install for admin-installed plugins.

Bug fixes

Fullscreen & transcript rendering

  • Fullscreen mode showing a blank transcript after resizing the terminal, and jumping to the bottom until the next keypress — fixed.
  • Severe transcript slowdown when a diff contained a very long single line (e.g. a base64 string) — such lines now render truncated with a marker.
  • Erratic fullscreen scrolling when positioned at an earlier message, including jump-to-bottom getting stuck mid-transcript — fixed.
  • Memory growing with session length in the fullscreen and Ctrl+O transcript views — each rendered message row no longer retains a full copy of the transcript-wide tool lookups.
  • Fullscreen mode moving keyboard focus onto the control under the pointer when you clicked the terminal window only to bring it back into focus — fixed.
  • Markdown rendering being disabled for a whole message when its first 500 characters contained no markdown — fixed, along with +/N) lists and setext headings.

Background sessions & agents

  • Background sessions failing to open after 45 seconds when Claude Code’s starting directory had been deleted, the machine had slept, or the host is slow to start processes — fixed.
  • Background sessions failing to open with “Couldn’t start the background service … EACCES” when another Claude Code process was re-installing the npm package at that moment — fixed.
  • Opening a just-started session in claude agents while its worker was still booting (common on Windows) stopping it with “was stopped while the respawn was in flight” — fixed.
  • claude agents listing a backgrounded named session twice — backgrounding the same conversation again now numbers the new row (e.g. my-session (2)).
  • The background retention sweep removing git worktrees under .claude/worktrees/ that you created yourself when an old background-session record pointed at them — fixed.
  • Pressing ← or running /background during a dynamic workflow restarting its finished subagents — it now asks first and says how many subagents would restart.
  • /fork from an already-forked or backgrounded session starting the new session with an empty conversation — fixed.

MCP & tool calls

  • MCP tool calls interrupted by an incoming message in headless/remote sessions being reported to the model as “completed with no output” — the model now gets an explicit interrupted error.
  • MCP tool arguments being sent as JSON strings when the parameter’s schema is empty ({}), instead of their real type — fixed.
  • A command interrupted mid-run showing as “Ran 1 shell command” with no sign it was cut — fixed.
  • The UI stopping with a render error on the first tool call when a third-party Anthropic-compatible endpoint (ANTHROPIC_BASE_URL) streams a tool_use block without an id — fixed.
  • The Write tool reporting “Out of memory” or freezing for a long time after overwriting a very large existing file, even though the file had been written — fixed.
  • MCP tools marked requiresUserInteraction still offering “Yes, and don’t ask again” in their permission prompt — the option wrote an allow rule the tool then ignored.
  • --strict-mcp-config sessions prompting to approve .mcp.json servers they would never load — fixed; this left background sessions waiting at startup.

Plugins

  • The plugin cache creating duplicate SHA-named directories for the same plugin — fixed.
  • Plugin skills whose frontmatter name already includes the <plugin>: prefix showing it doubled in the slash menu (e.g. /plugin:plugin:skill) — fixed.
  • claude plugin update failing for an installed plugin given its bare name — fixed; only the fully-qualified name worked before.
  • Plugin installation failing when plugin.json was saved with a UTF-8 byte-order mark (BOM) — fixed.
  • /reload-plugins reporting 0 skills for plugins that define skills under skills/*/SKILL.md — fixed.
  • Hook error messages showing a literal ${CLAUDE_PLUGIN_ROOT} instead of the resolved plugin path — fixed.
  • claude plugin install <name> exiting silently (or hanging in a terminal) instead of reporting an error when ~/.claude/plugins/known_marketplaces.json is empty or corrupted — fixed.

Permissions & credentials

  • Auto mode tool calls being denied as “temporarily unavailable” on very large sessions — the safety-check deadline now scales with prompt size.
  • Bash permission checks now always require approval for malformed commands with a dangling && or || operator.
  • Telemetry and metrics requests to Anthropic carrying the API key configured for a third-party gateway (ANTHROPIC_BASE_URL) — a credential is now only sent to its own host.
  • A visible API error on the first prompt after idle when apiKeyHelper returns short-lived JWTs — an expired cached token is now refreshed before sending, and 401/403 auth errors retry quietly.
  • Sessions that ended in plan mode resuming outside plan mode — fixed in the VS Code extension, and in claude -p --continue/--resume with a permission prompt tool when no permission mode was set.
  • The Notification hook not firing while the sandbox “Network request outside of sandbox” permission prompt is waiting — fixed.
  • The command sandbox’s filesystem configuration not respecting --setting-sources — fixed.

Resume & install

  • Resumed sessions failing every turn with a 400 when the saved history contains tool blocks the Anthropic API does not accept — fixed; these are typically written by a third-party API proxy.
  • curl -fsSL https://claude.ai/install.sh | bash failing with “Raw mode is not supported” for some Team/Enterprise users with server-managed settings — fixed.
  • Windows/macOS: headless sessions not cleaning up stale entries in ~/.claude/sessions left by sessions that exited uncleanly — fixed.

Cloud & remote sessions

  • /ultrareview runs and cloud sessions launched at the same time from one repository (e.g. from several worktrees) sometimes starting with another launch’s uncommitted changes — fixed.
  • The task progress count (e.g. 3/5) shown for background cloud sessions such as /autofix-pr occasionally missing a task — fixed.
  • Remote Control sessions keeping their placeholder name in claude.ai and the Claude app until the second prompt — the auto-generated title now appears after the first prompt.
  • The self-hosted runner ending its live sessions or exiting when a work-poll response is malformed (e.g. an intercepting proxy’s HTML page) — it now retries the poll.

Terminal, themes & input

  • /rename replacing the theme’s prompt border color (including a custom theme’s promptBorder) with the default cyan — the border now keeps your theme’s color unless you pick one with /color.
  • Custom theme diff colors (diffAdded/diffRemoved and their dimmed variants) being ignored in diffs and the /theme preview — fixed.
  • A keybindings.json binding with an unknown action name silently deadening that key — it is now skipped so the default binding keeps working, and a warning is logged under --debug.
  • /stats activity heatmap showing each day’s activity one cell off (Sunday’s count under Monday) in timezones east of UTC — fixed.
  • Prompts beginning with /-- (e.g. Lean doc comments) being rejected as an unknown slash command instead of being sent to Claude — fixed.
  • The @ file picker staying open after the typed text stopped matching a real path — fixed.
  • The status line’s cost and duration resetting to zero after navigating to the agents view and back — fixed.
  • Path completion failing when the completion token or working directory contained a null byte — fixed.

Notes

  • 2.1.244 was not published, and 2.1.245 is a single fix — 2.1.244 never appeared on GitHub Releases, and 2.1.245 contains only a fix for a startup crash on Linux distributions that ship glibc 2.44 (Arch Linux, CachyOS, Fedora Rawhide), so neither is covered separately.
  • Audit Bash allow rules with a wildcard before the subcommand — rules like Bash(git * main) now trigger a startup warning. They also match options inserted before the subcommand, so rewrite them if you meant to approve a narrower command.
  • Malformed commands with a dangling && or || always require approval now — scripts that were auto-approved before may start hitting a permission prompt after upgrading.
  • Third-party gateway users get tighter credential scoping — the API key configured for a gateway via ANTHROPIC_BASE_URL was being sent with telemetry and metrics requests to Anthropic. A credential is now only sent to its own host.
  • Worktrees you created under .claude/worktrees/ are no longer swept — if the background retention sweep previously removed a worktree you made yourself, this release fixes it.
  • /goal idle check-ins are capped at three per goal — your next message allows three more.