What changed
Claude Code 2.1.248 shipped on August 27, 2026. It adds --restricted, a mode that strips the tools which execute anything and refuses to let settings files widen that back out, and it tracks down the hourly prompt-cache miss that had been quietly costing long sessions their extended-thinking context. The agent view and claude agents get a round of fixes — resurrected sessions, duplicate processes, refused deletes — and credential-file copies stop leaving your machine with cloud sessions.
New features
-
--restrictedmodeNarrowing what Claude Code can do meant assembling permission rules yourself, and a settings file could widen them again.
--restricted(orCLAUDE_CODE_RESTRICTED=1) removes the built-in tools that run commands or code andWebFetch(unless named in--tools), keeps file tools inside the working directory, refusesbypassPermissions, and ignores user, project and local settings files. -
experimental.cacheTtlin agent frontmatterPrompt cache TTL for subagents could only be set globally. Agent frontmatter now takes
experimental.cacheTtl("5m"or"1h"), used as a per-agent prompt cache TTL when no subagent TTL setting is configured. -
Server-managed settings diagnostics
When server-managed settings didn’t apply, nothing said so. There is now a startup warning when the settings fail to load, plus a
/doctorand/statusline explaining a load failure or why they weren’t fetched (Bedrock/Vertex/third-party provider, customANTHROPIC_BASE_URL). -
Cross-session messaging on Bedrock, Vertex, and Foundry
Messaging another session on the same machine wasn’t available in some setups.
SendMessageandListAgentsnow work between sessions on the same machine on Bedrock, Vertex, and Foundry, and when telemetry is disabled. -
/usage-creditsfor more Enterprise organizationsMembers of Enterprise organizations billed through AWS Marketplace, self-serve Enterprise, and Enterprise trials had no path to ask for more headroom.
/usage-creditsnow works for them, so they can request a higher usage limit from their admin. -
A label for self-hosted runners
A self-hosted runner registered under its hostname, which made several of them hard to tell apart.
claude self-hosted-runner --client-label <label>(orSELF_HOSTED_RUNNER_CLIENT_LABEL) overrides the label the runner registers with. -
GitHub token scope warning in
/web-setupPushes to very large repositories can be rejected when the GitHub CLI token lacks the
workflowscope, and setup gave no hint of it./web-setupnow warns about the missing scope.
Key improvements
-
A smaller prompt footprint for the Workflow tool
The Workflow tool’s description took about 5.7k tokens in every session, used or not. It is now about 1k tokens, with the script-writing reference moved into a bundled
workflow-authoringskill. -
/ultrareview <PR#>checks access before launchA repository access problem only surfaced after the cloud session had started. It now checks before launch that the GitHub account connected to your Claude account can access the repository, and explains how to fix it.
-
Fewer PR badge checks
The prompt-footer PR badge checked GitHub often even while the pull request was unchanged. It now checks less often in that case; a push or a
gh prcommand still refreshes it right away. -
Fewer managed settings approval prompts
Client-side timeout, MCP startup-mode, and stream-watchdog env vars triggered the settings-approval prompt. They no longer do.
-
A fallback directory for cross-session messaging
Cross-session messaging failed outright when the default directory couldn’t be used. It now falls back to a private per-user
/tmpdirectory, and the notice and/statusname the directory to fix. -
Agent view dispatch input keys match the prompt
shift+enter behaved differently in the agent view dispatch input than in the prompt. shift+enter now inserts a newline, and ctrl+enter dispatches and attaches.
-
/loopis always availableSelf-paced dynamic mode and the no-prompt autonomous default were limited in some setups. Both are now always available, including on Bedrock, Vertex, and Foundry.
-
Telemetry export failures are labeled clearly
Anthropic telemetry export failures logged as
[3P telemetry] OTEL diag error, which read like your own OTel collector failing. They now log at debug level as[Anthropic telemetry]. -
SendMessagefrom a subagent says where the reply goesA subagent messaging another session had no way to know where a reply would land. The result now notes that any reply is delivered to the parent session’s conversation, not to the subagent.
Bug fixes
Prompt cache & session continuity
- A prompt-cache miss (and lost extended-thinking context) roughly once an hour in long sessions — fixed; tool definitions were being re-rendered after an OAuth token refresh.
- The
ScheduleWakeuptool definition changing between a session and its--resumewhen the account had entered usage overage, causing a full prompt-cache miss on the resumed session’s first turn — fixed. - Claude Desktop and Cowork sessions disappearing after 30 days — transcript cleanup now keeps desktop-written sessions while they are in the app (unless org policy manages retention), and the new
desktopSessionCleanupPeriodDayssetting caps the exemption. - Being sent to the login screen when another Claude Code process held the token refresh lock while the session token had expired — the request now fails with a retryable error instead.
Agent view & background sessions
- Agent view resurrecting a weeks-old background session after the machine was off — such a session now shows as stopped at its real end, and opening it asks before resuming its saved conversation.
claude agentsstarting a second process on a conversation you already resumed in another terminal — the row now says it is open in a terminal.- Agent view sometimes opening an older conversation, and dropping the typed prompt, when starting a new session — fixed.
claude agentsandclaude rmrefusing to delete a session (“has commits that are not pushed anywhere”) when its worktree branch was already merged into your checked-out default branch (e.g. localmain) but not yet pushed — fixed.- A backgrounded worktree session losing its checkout — the background session now holds the worktree’s lock while it runs, so cleanup and
git worktree removeleave it alone. - Background sessions waiting silently when a
PermissionRequestorPreToolUsehook prints an invalid answer — theclaude agentsrow now names the hook and the schema error. - Hooks silently treating a stdout
{…}object that isn’t valid JSON as plain text — it’s now reported as a hook error with the parse message. - [Windows] The
claude agentslist not responding to the keyboard after detaching from a session, or when launched in a terminal tab left in win32-input-mode — fixed. claude agentsskipping the workspace trust prompt when theCIenvironment variable is set — fixed.claude agentscrashing on launch when the PR-status cache held a malformed entry — fixed.
Sign-in, MCP & settings
- The recommended Console sign-in in
/loginfailing with an OAuth error before showing a sign-in URL on machines where it can’t be used (for example whenANTHROPIC_API_KEYor an API key helper is set) — it now falls back to the API-key sign-in. /loginto a Claude apps gateway hanging when the managed-settings security approval dialog was required — fixed.- Gateway model discovery (
CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY) never running whenapiKeyHelperis the only credential — fixed. /mcplisting a project.mcp.jsonentry that declares the claude.ai connector type under the trusted “claude.ai” heading — it now appears under its real scope.- MCP servers whose
headersHelpersupplies theAuthorizationheader falling into OAuth discovery on a 401 instead of re-running the helper and retrying the call as documented — fixed. - An invalid
crossSessionInboundvalue being silently ignored — it now warns and holds cross-session messages (user settings) or refuses them (managed settings) until fixed.
Remote & cloud sessions
/ultrareviewand locally seeded cloud sessions uploading uncommitted edits toprod.env-style and*.tfvarsfiles, or to editor swap, temp, and backup copies of credential files (e.g.key.pem.tmp,id_rsa.swo) — they now stay on your machine.- Remote Control sessions occasionally never showing a permission prompt or the latest messages on the connected device after the CLI silently reconnected — fixed.
- Cloud sessions occasionally failing at startup when the container’s session credentials were not yet readable — fixed.
claude remote-controlrejecting its own flags (e.g.--spawn,--name) when a global flag or a wrapper-injected option precedes the subcommand — fixed.
Terminal & display
- @-mentions of other sessions not matching names typed with non-Latin characters (for example Korean entered through an IME) — fixed.
claude logsleaving mouse tracking, bracketed paste and the alternate screen switched on in the terminal it was run from — fixed.- Model names in
/modeland fast-mode switch notices not rendering as code, so suffixes like[1m]displayed as a link — fixed; they display literally. - The trust dialog’s list of repo permission rules showing a garbled character when a long rule was cut off in the middle of an emoji — fixed.
- The permission mode indicator staying hidden behind the “Press Ctrl-C again to exit” hint when you press shift+tab right after ctrl+c — fixed.
- Startup warnings (e.g. “N MCP servers need authentication”) rendering one column right of the rest of the transcript — fixed.
- Rate-limit, usage, and fast-mode messages telling you to run
/usage-creditswhen that command isn’t available for your organization (e.g. hidden withDISABLE_EXTRA_USAGE_COMMAND) — fixed. - [VSCode] A chat tab getting stuck on “No conversation found” when its session was never saved — it now starts a new conversation instead.
Notes
--restrictedignores settings files too — beyond removing execution tools, it skips user, project and local settings files and refusesbypassPermissions, so work that relies on your usual settings behaves differently under it.- Desktop session retention changed — sessions written by Claude Desktop and Cowork are exempt from the 30-day transcript cleanup while they are in the app.
desktopSessionCleanupPeriodDayscaps that exemption, and org policy managing retention takes precedence. - Credential-file copies stay local —
/ultrareviewand locally seeded cloud sessions no longer uploadprod.env-style files,*.tfvars, or editor swap, temp and backup copies such askey.pem.tmpandid_rsa.swo. - shift+enter changed in the agent view — it now inserts a newline; use ctrl+enter to dispatch and attach.
- The Workflow script reference moved — how to write a workflow script now lives in the bundled
workflow-authoringskill rather than in the tool description. - An invalid
crossSessionInboundvalue no longer passes silently — cross-session messages are held (user settings) or refused (managed settings) until the value is fixed.