What changed
Claude Code 2.1.259 shipped on September 2, 2026. Both headline additions target deployments where many people share one configuration: a managed setting that hands out MCP servers organization-wide, and a flag for hosts where nobody is present to answer a permission prompt. The rest is mostly fixes — concurrent sessions reverting each other’s ~/.claude.json, managed settings going unenforced when they cannot be parsed, and worktree-isolated sessions refusing ordinary shell commands.
New features
-
managedMcpServersmanaged settingGiving everyone in an organization the same MCP servers meant having each user configure them or building a separate rollout. Organizations can now list servers under
managedMcpServersin managed settings and they are provided to every user. Entries use the same shape as.mcp.json; entries that name a command to run are skipped, so this covers HTTP/SSE servers. -
--permission-prompts noneOn an unattended headless host, anything that raised a permission prompt stalled the session with nobody there to answer. With this flag, anything that would prompt is denied automatically, while the active permission mode — including auto mode — keeps deciding.
-
Recognition of
glab mrcommandsWorking a GitLab merge request through
glab mr create/merge/close/reopen/note/updateleft the raw command in the tool summary and the footer MR badge stale. These commands are now recognized, so merge requests show asMR !Nin the collapsed tool summary and refresh the footer MR badge. -
--jsonforclaude plugin validateValidation output was human-readable only, so a CI check had to parse printed text.
--jsonnow produces a machine-readable validation report. -
[VSCode] Active quick filter and status filter menu in the session list
Once sessions piled up, finding the one that needed attention meant scanning the whole list. The session list sidebar now has an Active quick filter and a status filter menu (Needs input, Working, Completed).
Key improvements
-
Terminal resize and first-render performance for long responses
Resizing the terminal or rendering the first frame of a long response re-measured the same text every time. Text measurements are now reused, so both are faster.
-
/workflowsagent detailA JSON outcome arrived as one run-together line, and a long outcome filled the view. JSON outcomes are now pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle.
-
Headless/SDK session start
There was unnecessary waiting between MCP servers finishing their connections and the first turn. The first turn now begins up to 50 ms sooner.
-
/install-github-appinside a GitLab repositoryRunning it in a GitLab repo gave little indication of why it did not apply. It now explains that it is GitHub-only and points to the GitLab CI/CD docs.
-
Nested background subagent results kept in the transcript
A background subagent spawned by another subagent had its result dropped from the parent subagent’s transcript, so a resumed subagent lost it. Results are now saved in the parent subagent’s transcript, so resumed subagents keep them and shared transcripts show the delivery.
Bug fixes
Managed settings & permissions
- Managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value cannot be parsed; Claude Code now refuses to start and names the source.
- Bash
Read()deny rules not covering files given as option values (--ignore-revs-file=.env,-f.env,@file),git diff/git grepfile operands, orcd DIR && cat FILEcompounds;grep -r/cp -rover a directory holding a denied file now asks. - Managed
forceRemoteSettingsRefreshbeing ignored at startup when a policy helper configured by MDM or the managed settings file had already run.
Settings & startup
- Concurrent sessions silently reverting each other’s
~/.claude.jsonchanges: workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at once. CLAUDE_CODE_MAX_CONTEXT_TOKENSbeing ignored for Vertex-style model IDs (@YYYYMMDDsuffix) of model versions Claude Code doesn’t recognize.- A background GitHub connection check running on every launch for claude.ai users; the result is now remembered across launches.
- Repository detection dropping a known repo identity after a transient git probe failure.
Models & resuming conversations
- Frontmatter
model:on custom commands and skills being ignored in interactive sessions. - Auto mode running a turn on a model it doesn’t support when a command or skill’s frontmatter
model:named one; the turn now keeps the session model. - A conversation whose thinking was rejected once being rejected again on every later turn.
--resumefailing (and--continueopening an empty conversation) when a saved session contains an attachment entry with no payload.- The prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled.
- Blocking Stop hooks causing the turn after a block to lose the model’s reasoning from that turn and, on some models, miss the prompt cache.
Agents & workflows
- Stop not actually stopping background agents and workflows in remote-control sessions: killed tasks now stay visible and re-stoppable until their processes exit.
- Resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents.
- Remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused.
Worktrees & MCP
- Worktree isolation refusing hook-created worktrees on machines where
git rev-parsefails with a message other than “not a git repository”. - Worktree-isolated sessions refusing common Bash loops, xargs pipelines and launcher-wrapped commands that cannot reach the main checkout.
- MCP servers that disconnect while their tools are being listed at startup showing as connected with no tools instead of reporting the error.
- Remote (claude.ai) sessions taking 60 seconds to start a turn after a browser-hosted MCP server’s page had gone away.
- Marketplace repo URLs on github.com with a trailing slash or dangling
?/#producing an unusable.gitclone URL.
Terminal & UI
- Fullscreen mode showing a blank conversation after a long turn with hundreds of tool calls.
- The live output preview of a running shell command hiding its newest lines when an earlier line wrapped.
- The file edit permission dialog sometimes showing a changed line cut short with no indication.
- Artifact publishing failing once with an “unexpected parameter
note” error in conversations continued from an older version. - OpenTelemetry metrics and events from cloud sessions missing the
user.email,organization.id, anduser.account_uuidattributes.
Notes
allowedMcpServersnow governs only servers users add — a literalmanaged-mcp.jsonserver your allowlist used to filter out loads again on upgrade. UsedeniedMcpServersto keep it off.- Managed settings that cannot be parsed stop Claude Code from starting — if the managed-settings file, a drop-in, the MDM plist, or the HKLM value is malformed, startup is refused and the source is named. Validate them before rolling out.
--permission-prompts nonedoes not replace the permission mode — the active mode, including auto mode, keeps deciding; only the actions that would have prompted are denied.managedMcpServerscovers HTTP/SSE servers — entries that name a command to run are skipped.