claudekit / updates / claude-code-2-1-257
[ PATCH · ]

Claude Code 2.1.257

Claude Fable 5.1 (`claude-fable-5-1`) is now the default Fable model — 1M context, $10/$50 per Mtok with $0.25/Mtok cache reads. New settings arrive for the turn-end clock and transcript timestamps (`timeFormat`, `timeZone`), for forcing one model across every subagent (`CLAUDE_CODE_SUBAGENT_MODEL_FORCE`), and a Containment Escape rule that stops auto mode from auto-approving cloud metadata-credential fetches, egress evasion, and cross-tenant reach. Rendering performance and prompt input responsiveness improved, `defaultMode: "bypassPermissions"` in project settings is now ignored, and `/btw` history browsing moved to `Shift+←`/`Shift+→`. Roughly 60 bug fixes span background sessions, subagents, prompt caching, and gateway authentication.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.257 shipped on September 1, 2026. Claude Fable 5.1 lands as the new default Fable model, and several things that previously had no knob — clock format, forcing a single subagent model — now have settings. Auto mode gains a rule for actions it should never auto-approve and a first-time prompt before reading outside the working directories. On top of that: rendering work per turn is down in long conversations, and a large batch of fixes covers background sessions, subagents, prompt caching, and gateway authentication.

New features

  • Claude Fable 5.1 (claude-fable-5-1)

    A new Fable model, now the default Fable model. It offers 1M context at $10/$50 per Mtok, with cache reads at $0.25/Mtok.

  • “Time format” (timeFormat) and timeZone settings

    The turn-end clock and transcript-view timestamps had a fixed presentation with no way to change it. You can now pick 12-hour, 24-hour, or 24-hour UTC, or supply a strftime pattern, and set the zone those timestamps are rendered in with timeZone.

  • Containment Escape rule in auto mode

    Actions that reach outside the session’s environment could be auto-approved in auto mode along with everything else. Cloud metadata-credential fetches, egress evasion, and cross-tenant reach are no longer auto-approved unless your environment marks them expected.

  • One-time prompt before the first read outside the working directories

    Auto mode read files outside the working directories without asking. It now prompts once before the first such read, with the option to block them outright; permissions.blockReadsOutsideWorkingDirectories sets that behavior directly.

  • CLAUDE_CODE_SUBAGENT_MODEL_FORCE

    2.1.251 turned CLAUDE_CODE_SUBAGENT_MODEL into a default rather than an override, which left setups that pinned every subagent to one model without a way to do it. Setting this variable applies CLAUDE_CODE_SUBAGENT_MODEL (or the main model) to every subagent, ignoring per-spawn and agent-definition model overrides.

  • s in /effort for the current session only

    Changing the effort level persisted it, so a one-off change had to be reverted later. /effort now accepts s to apply the change to the current session only, matching /model.

  • /doctor warning for stale sandbox mask files

    A killed session can leave sandbox mask files behind with nothing to surface them. /doctor now warns when it finds them.

  • Gateway-supplied description on /model picker entries

    Models found through gateway model discovery (CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY) were hard to tell apart in the picker. Entries now show the description the gateway supplies; entries without one still read “From gateway”.

  • [VSCode] Account and usage in the session list panel

    The session list had no view of your account or usage. Collapsible ACCOUNT & USAGE and SESSION MANAGER section headers now carry the account email, the usage meter, and a View details link that opens the usage dialog. The Ungrouped section also gained a collapse toggle.

  • [VSCode] Model pill in the input footer

    Checking or switching the current model meant leaving the input area. A model pill in the input footer now shows the current model and opens the model picker, with an Effort row and a “More models” page.

  • [VSCode] Output style selection in the command menu

    Output styles could not be picked from the command menu. They now appear there, including custom styles.

Key improvements

  • Rendering performance and prompt input responsiveness

    Long conversations did more re-render work each turn, streaming slowed down as the reply grew, and every background-agent update re-rendered the whole screen. Per-turn re-render work is down, streaming no longer slows as the reply grows, background-agent updates no longer re-render the whole screen, and per-keystroke rendering work is reduced so the prompt input responds faster.

  • /fork keeps the original conversation’s prompt cache

    The new background session received its worktree briefing as a system-prompt change, which invalidated the cache it inherited. The briefing now arrives as a message, so the original conversation’s prompt cache carries over.

  • Policy helper diagnostics

    When the policy helper failed, there was little to go on. Refresh failures now show in /status, declining the managed-settings dialog prints why Claude Code exited, and helper timeouts are reported as timeouts.

  • /code-review --comment on GitLab merge requests

    GitLab merge requests were reported as an unsupported target, so findings could not be posted. Findings are now posted via glab mr note.

  • claude self-hosted-runner --configure-git enables push negotiation

    The first push of a new branch from a stale clone uploaded the whole tree. The command now also enables git push negotiation, so only the new commits go up.

  • Liveness reporting to SDK hosts

    A response held open by gateway keep-alives could look like a hung session to an SDK host, particularly under a raised CLAUDE_STREAM_IDLE_TIMEOUT_MS. Liveness is now reported through those waits.

  • Redaction in MCP connection and OAuth logs

    Credentials carried in a server’s URL or request headers appeared in debug and error logs. They are now redacted.

  • Notification timing for queued asks

    An MCP elicitation or permission ask queued under another dialog sent its idle desktop notification later than a visible ask. It now sends at the same delay.

  • Async hook completion notices on one line

    When several hooks finished together, verbose and transcript output printed one line per hook. Notices that arrive together now appear on one line.

  • Emoji autocomplete aliases

    Some GitHub/Slack shortcodes were missing from autocomplete. The remaining aliases (:satisfied:, :telephone:, :collision:, …) are now accepted.

  • --effort lifts the default-effort hold for the session only

    Using --effort to lift a new model’s default-effort hold applied permanently. It now applies to that session only, and an effort picked on claude.ai for a Remote Control session applies during the hold.

  • policyHelper reacts as soon as server-managed settings are removed

    A policyHelper in MDM or managed-settings.json shadowed at launch by cached server-managed settings stayed shadowed until the next launch. It now runs (or exits) as soon as the fetch reports those settings removed.

  • managedSourcesBehavior: "merge" takes some keys whole

    Combining sandbox.credentials.awsPairs and sandbox.ripgrep across managed sources could produce unintended combinations. Both keys are now taken whole from the highest managed source that sets them.

  • Gateway model discovery runs under CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC

    Setting that variable also disabled gateway model discovery. Since discovery (CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1) only queries your own gateway, it now runs regardless.

  • claude --resume <session-id> --bg continues the session itself

    The command silently started a copy, leaving it unclear which session was the original. When nothing is running that session, it now continues under its own ID; a copy is announced when one is made.

  • [VSCode] Filterable slash command and MCP server dialogs

    Slash commands were listed inline in the action menu, which made them hard to scan. They now open in a filterable “Slash commands” dialog and run when picked; the MCP servers dialog gained the same filter box.

  • [VSCode] “Delete session” is now “Archive session”

    Clearing a session from the list meant deleting it for good. Archived sessions move to a collapsible “Archived sessions” group at the bottom of the list, with an Unarchive action.

Bug fixes

Security & permissions

  • A permissions.ask rule being skipped in auto mode when the matching command ran inside a compound command or subshell, letting it run without the confirmation prompt.
  • Plugins reading files outside their own directory through a declared command, agent, skill, hooks or other component path that is a symlink; such paths are now refused with an error.
  • Bash Read()/Edit() deny rules not applying to < file redirects and reader commands like tac and egrep; a deny rule on any argument or redirect target now refuses the command.
  • --disallowedTools and session deny rules being dropped after the first settings reload when allowManagedPermissionRulesOnly is enabled.
  • Bash permission checks auto-approving certain [[ ]] conditionals that zsh parses differently from bash; these commands now prompt for approval.
  • Sandbox network hosts written with a trailing dot (example.com.): a deniedDomains entry didn’t block the host inside the sandbox, and “don’t ask again” for such a host kept prompting.
  • Dismissing the Remote Control consent prompt (Esc, or n at claude remote-control) counting as consent, so the next request connected without asking.
  • /mcp reconnect and enable still connecting a settings-file MCP server that a managed MCP allow/deny list or strictPluginOnlyCustomization loaded after startup should block.
  • claude mcp remove leaving a remote server’s stored OAuth credentials behind when strictPluginOnlyCustomization locks MCP to plugin-only servers.
  • The managed-settings approval prompt showing the generic warning instead of its telemetry wording when the settings also turn detailed tracing or raw API body logging off, or trace export on.

Settings & startup

  • Settings in a .claude/ folder created after startup not being picked up until restart.
  • Sessions dispatched from an agent view opened with ← always starting in the original session’s permission mode, overriding the target directory’s defaultMode and the agent’s permissionMode.
  • /add-dir rejecting a directory inside the current working directory; it now loads that directory’s skills, commands, and agents like --add-dir does at startup.
  • Telemetry (OTEL) settings pushed through server-managed settings being ignored on warm starts, including desktop-app Code sessions.
  • policyHelper timeoutMs and refreshIntervalMs values above the timer maximum (2147483647) causing failures or re-runs every millisecond; they are now clamped.
  • The keyless Console sign-in (“Sign in with your Console account”) not applying your organization’s server-managed settings, and /status not showing the Organization for that sign-in.
  • /schedule routines whose prompt was saved without a message role and then ran with nothing to do.

Agents & background sessions

  • Background sessions failing to start on macOS npm installs during a self-update, and on Windows when a stale daemon lock file pointed at a reused process id.
  • Background sessions failing to open with “Couldn’t start the background service” while another Claude Code process was downloading an npm update; the start now waits for it.
  • A background session’s state.json detail repeating its own dispatch prompt after a scheduled wake-up.
  • claude agents keeping a background session you re-prompted buried in Completed after it finished again; Completed now orders by the latest finish.
  • claude --bg from a directory that was just deleted reporting “backgrounded” and leaving a crashed session row; it now prints the reason and exits 1.
  • claude agents not saying that a background session is waiting for you to approve a message from another session, or who sent it.
  • A prompt stashed with Ctrl+S inside an opened background session being lost when the session went idle or was stopped and then reopened.
  • Subagents stopping when a response was cut off mid-stream by a computer sleep, dropped connection, or server error; they now automatically continue instead of ending with an incomplete response.
  • Backgrounding a turn (← or Ctrl+B) while a subagent or other tool was running occasionally making the background session treat that tool as rejected instead of re-running it.
  • Resuming or messaging a subagent whose transcript had grown past 5 MB (for example after reading many images) failing with “No transcript found”.
  • The main agent not being told when you resume a subagent you had stopped from its transcript view.
  • Stopping a background subagent leaving its monitors running.
  • Claude not being told when you stop a background command from the tasks panel or a connected client.
  • Background commands that detach from their shell (for example under timeout or setsid) surviving a task stop or Claude Code exit.
  • Background sessions left running an older Claude Code binary piling up across auto-updates instead of being retired.
  • Proactive output style sessions busy-looping with filler messages and repeated log reads instead of idling while a background command or Monitor they started is still running.
  • claude -p exiting about 5 seconds after its final result while a Monitor the model armed was still running; it now waits for the watch to fire or time out.
  • --resume listing a backgrounded conversation twice and --continue reopening its stalled pre-background copy; --continue now also opens finished background sessions.
  • A teammate permission request being answered twice when the leader’s mailbox write was briefly locked.
  • Agent-team teammates in tmux/iTerm2 panes sometimes staying open after acknowledging a shutdown request.
  • ← doing nothing in the /btw panel inside a claude agents session: it now returns to the agents list (even mid-answer), and the panel comes back when you reopen the session.
  • keybindings.json rebinds of Ctrl+G being ignored in claude agents; its Ctrl+S / Ctrl+T are now rebindable via the new Agents context.
  • claude agents --json briefly switching the terminal to raw mode and undoing another program’s terminal settings on exit.
  • Leftover cc-daemon-* folders in the system temp directory after an interrupted background daemon start; the cleanupPeriodDays retention sweep now removes them.

Prompt cache & usage display

  • Remote Control connecting mid-session re-sending the Bash tool definition, causing a prompt-cache miss.
  • Sessions with an advisor model set missing the prompt cache on background requests (compaction, /recap, prompt suggestions) and re-sending the full conversation uncached each time.
  • Prompt-cache misses on every turn in long screenshot-heavy sessions once images exceeded the per-request size cap.
  • /model and /effort showing a prompt-cache warning after rewinding a conversation back to empty.
  • The token counter freezing or crawling after switching to another subagent’s transcript; background subagents’ and teammates’ counters now update live while a response streams.

Providers & gateways

  • A doubly-listed custom Authorization header overriding the configured credential on Bedrock, Mantle, Vertex, and WIF, and the Vertex setup wizard picking up a leftover Anthropic profile from ~/.config/anthropic.
  • Claude apps gateway sending stray host Authorization or profile headers to Foundry, Vertex, and Bedrock, and Foundry Entra ID upstreams not starting when ANTHROPIC_FOUNDRY_API_KEY is set.
  • A leftover Anthropic API key or auth token being sent alongside your Foundry subscription key in API-key mode.
  • Bedrock and Bedrock Mantle requests going silent during long hidden-thinking phases on Opus 4.7 and later, which let idle timeouts cut the connection; the stream now carries progress events.
  • Launching Claude Code after a Claude apps gateway expired or revoked your session reporting a network error; it now says the session ended and offers /login.
  • Remote Control (claude remote-control) sessions started from the Claude app ignoring the selected model and running on the machine’s default instead.
  • Cloud sessions losing git/GitHub credentials for the rest of the session when the session’s network proxy failed to start at launch; it now retries in the background and recovers.

Terminal & UI

  • The working spinner stopping while a response streams behind a slash-command panel.
  • A phantom duplicate slash-command row rendering below the in-flight turn while a command’s auto-continued response streamed.
  • Fullscreen mode not letting you click ! shell command output to expand it.
  • A crash when pasting ANSI-colored text (e.g. a CI log) into dialogs like /feedback.
  • The Edit permission prompt’s diff view rendering emoji and multi-code-point characters with incorrect widths.
  • WebSocket MCP server connection failures being logged as “[object ErrorEvent]” instead of the underlying error.
  • claude mcp add/remove hanging or exhausting memory when the project’s .mcp.json is a FIFO or a device-file symlink; it now fails fast with an actionable message.
  • Unbounded memory growth when non-JSONL data is piped into claude -p --input-format stream-json; it now fails fast with a clear error.
  • Worktree-isolated sessions refusing Bash loops, $VAR reads, "$(…)" and heredocs that never touch git as “too complex to verify that it stays inside the worktree”.
  • Sandboxed git commands in a linked worktree losing write access to the repository’s common .git directory after cd into a subdirectory.
  • [VSCode] Third-party provider deployments (Bedrock, Vertex, and others) still showing claude.ai-only features (remote sessions, dictation, usage) and calling claude.ai with a leftover login.
  • [VSCode] The session list panel’s usage meter staying blank after the panel loads; it now shows the last known usage immediately.
  • [VSCode] The “Enable Remote Control for all sessions” toggle not applying to sessions that are already open, only to new ones.
  • [VSCode] Screen reader announcements: a control character before a fence or heading no longer drops visible lines from speech, and bold markers spanning a heading are no longer mis-paired.

Notes

  • fable and best still resolve to Fable 5 in Claude apps gateway sessions — gateways not yet configured for Fable 5.1 reject it. Pick Fable 5.1 in /model to use it.
  • defaultMode: "bypassPermissions" is now ignored in project settings — setting it in .claude/settings.json or .claude/settings.local.json no longer works, the same as "auto". Set it in user or managed settings, or pass --permission-mode.
  • /btw history browsing moved to Shift+←/Shift+→ — or [/] — stepping through your recent side questions and back to the live answer. ←/→ no longer do this.
  • Network paths are refused as working directories — --add-dir, /add-dir, and additionalDirectories now refuse UNC shares and /net/<host> automounts with a message before touching them. On Windows, use a mapped drive letter.
  • Reading an artifact that isn’t yours always asks first — in Cowork and claude.ai cloud sessions, even in auto mode.
  • The Ctrl+E command explanation was removed from Bash and PowerShell permission prompts.
  • Claude apps gateway sign-in and token refresh verify the gateway’s pinned TLS certificate — the same check the managed settings fetch already does.