What changed
Claude Code 2.1.271 shipped on September 14, 2026. Fixes lead with 59, and organization policy and permission checks stand out among them. A cached organization policy being reused after switching accounts, organizations, or API keys, and an enterprise managed-mcp.json that can’t be read or parsed being ignored, are both closed off; Bash permission checks no longer miss what a command touches because of a wildcard, an unrecognized option, or a shell variable declaration flag. Several fast mode fixes land alongside fast mode support in Claude Code Remote sessions. One behavior change to watch: Monitor watches now always have a deadline, replacing the no-timeout persistent option.
New features
-
Fast mode in Claude Code Remote sessions
Remote sessions on cloud and self-hosted runners had no fast mode. The host’s fast-mode setting, or
/fasttyped in the session, now applies where your organization allows it. -
Per-command
allowed_domainsin auto mode with sandboxingThere was no way to review and limit the hosts a sandboxed command reaches on a per-command basis. Bash, PowerShell and Monitor now take
allowed_domainsin auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refused. -
omitClaudeMdin agent frontmatterCustom and plugin subagents always loaded user, project and local CLAUDE.md files, mixing unrelated instructions into focused agents. Setting
omitClaudeMdin agent frontmatter or--agentsJSON runs them without those files; managed policy files still load. -
Mouse support in the
/configpanel (fullscreen mode)The settings panel was keyboard-only. In fullscreen mode, the wheel now scrolls the settings list, a click on a setting’s value changes it, and the row under the pointer is highlighted.
-
--accept-command <sha256>forclaude plugin installandclaude plugin updateApproving non-interactively meant
-y, which accepts whatever runs. The new flag accepts exactly the command a previous--jsonrun displayed. -
claude self-hosted-runner --drain-marker-file <path>The server could not tell a SIGTERM exit caused by a host drain from any other. When the marker file exists at a SIGTERM drain, the runner now reports its exit to the server as a host drain (telemetry only).
-
A
multiplierabove 1 inmodelPricingThe
modelPricingmanaged setting and the Claude apps gatewaypricingblock could not express marked-up internal chargeback rates. Amultiplierabove 1, up to 10, is now supported. -
Desktop app spinner tips
Bedrock, Vertex AI, Foundry and LLM gateway users got no pointer to the Claude desktop app. A spinner tip now points them to it, and the claude.ai desktop app tip suggests
/desktop, which offers to download the app. -
[VSCode] An Attach Open File setting
The open file was always added to messages. Turning this setting off stops that; selected text is still attached.
-
[Claude Code on the web] Custom network access in the Cloud environments editor
The Cloud environments editor in admin settings had no allowed-domains list. A Custom network access option now offers the same allowed-domains list as the environment dialog on claude.ai/code.
Key improvements
Rendering & responsiveness
-
Terminal rendering performance
Large diffs and long transcripts produced slow frames. They now render faster, with fewer slow frames.
-
Startup time
Every launch re-validated built-in model data. Skipping that redundant validation improves startup time slightly.
-
Hook feedback
It was unclear what Claude was waiting on while a hook ran. While a SessionStart, UserPromptSubmit, PreToolUse or SessionEnd hook runs, the spinner now says so with elapsed time, and Esc cancels a prompt waiting on a SessionStart hook.
-
Spinner status during long thinking
Long thinking looked the same throughout. The spinner now reads “deep in thought” after 45s, and shows “picking the thought back up” while recovering from the output-token limit.
-
The IDE selection indicator (changed)
The indicator squeezed multi-line prompts. It is now a
[⧉ …]pill that wraps with the text; delete it with Backspace to leave the selection out. -
/mobileIt now shows a single QR code for claude.ai/mobile, which opens the right app store for your phone.
Workflows & agents
-
Dynamic workflows at your usage limit
Hitting the usage limit dropped the affected agents. Dynamic workflows now pause and continue automatically when the limit resets.
-
Dynamic workflow sizes (changed)
The default dynamic workflow size is now small on Pro plans, and the medium size guideline is lowered from 15 to 10 agents.
-
Monitor watch deadlines (changed)
The
persistentoption let a watch run with no timeout. Monitor watches now always have a deadline (at most 30 minutes; 10 in single-prompt-pruns) and notify Claude to re-arm, replacingpersistent. -
Subagent hand-back in auto mode (changed)
A subagent’s last message was reviewed by the safety classifier after the fact. A subagent now reports back to its caller through a dedicated hand-back call that the classifier reviews.
-
Inline
!shell commands in skills and slash commands in auto mode (changed)These were decided by the classifier. They now follow default-mode permission rules; a command no rule decides runs as a reviewed tool call.
MCP, artifacts & remote sessions
-
claude mcp serveprogress updatesA long command that printed nothing could look stalled and hit client idle timeouts. A running tool call now sends a progress update every 30 seconds.
-
alwaysLoadMCP servers on Foundry and Claude Platform on AWSAn
alwaysLoadMCP server that finished connecting mid-conversation was not usable right away. It is now usable on the next turn without a tool-search round trip. -
Markdown files published as artifacts
They now render as styled document pages (title header, document typography, syntax-highlighted code).
-
Artifact tool errors
Publish and contract errors were hard to act on. A publish with no file now says to write the page to a file first, an unsupported file type is reported before a missing favicon, and a page declaring a capability its contract version lacks gets a list of every supported capability, noting when a newer contract version has it.
-
Artifact watching
A session can now watch up to 10 published artifacts at once for republishes made elsewhere, up from 5.
-
Remote Control on a flaky network
Failed setup left empty sessions on claude.ai. Fewer are left behind now.
-
Claude in Chrome in cloud sessions
When the browser can’t be reached, the message now says the computer may be asleep before it suggests an install.
-
Leftover claude.ai logins (changed)
Claude apps gateway, Bedrock, Vertex AI, and Foundry sessions no longer refresh a leftover claude.ai login that the session does not use.
-
PDF @-mentions
When pdfinfo cannot count the pages, they now say “page count unknown” instead of a page count guessed from the file size.
-
The bundled
claude-apiskillUpdated to enable
eager_input_streamingon streaming custom tools, and to start deliverable-shaped Managed Agents work withuser.define_outcome.
[VSCode]
-
The Hooks dialog on refused saves
A save refused because of the settings file itself now opens a popup with an “Open settings file” button and the reason behind “Copy error”.
-
Toggle switches (changed)
The on state changed from Claude orange to the editor theme’s button color.
[Claude Code on the web] & [Claude Tag]
-
The Routines page (changed)
The Routines page on claude.ai/code has a new layout with Yours and Templates tabs and two-column routine cards that show run status; the calendar view is removed.
-
The Cloud environments admin page
It now shows the default environment for Claude Tag and Claude Code, with a link to change it, and marks the recommended kind to create.
-
The Claude Tag Environment picker
Options are now labeled Anthropic-hosted or self-hosted, with links to edit that environment or create one.
Bug fixes
Organization policy & managed settings
- A cached organization policy being reused after switching accounts, organizations, or API keys, and the policy not refreshing until the hourly check when the credential changes mid-session.
- The tool and command lists not updating when the organization policy finishes loading after startup or changes mid-session.
- An enterprise
managed-mcp.jsonthat can’t be read or parsed being ignored; it now keeps exclusive MCP control (user, project and plugin servers don’t load) and warns at startup. - Org policy being fetched through, and rejected by, third-party local proxies set via
ANTHROPIC_UNIX_SOCKET; they are again treated like other custom gateways, including for Remote Control.
Permission checks & auto mode
- Bash permission checks missing the file that
fmt,columnand similar commands read when it follows an option the checker doesn’t recognize. - Bash permission checks skipping files a wildcard expands to when the wildcard sits in a command’s pattern or option value (for example
grep -v dir/* file). - Shell variable declaration flags being able to misrepresent the command being run in Bash permission checks.
- Bash commands with two directory changes, a subshell, or a
cd+gitchain skipping the prompt underpermissions.blockReadsOutsideWorkingDirectoriesin bypass and auto mode. - Cloud sessions rejecting every subagent tool call (“updatedInput … failed schema validation”) when a workflow or agent approval was applied after the session’s worker restarted.
Fast mode
/fast offanswering “Fast mode unavailable” instead of turning fast mode off when the organization has fast mode disabled.- Sessions started with
CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECKre-sending fast requests every turn after the API rejected fast mode; the rejection now stands and its reason is shown. - Fast mode under
CLAUDE_CODE_RETRY_WATCHDOGfailing the turn on a usage-credits limit, or retrying an overload at fast speed, instead of falling back to standard speed.
MCP & tools
- Sustained high CPU usage and repeated tool-list requests when an MCP server sends
list_changednotifications in a tight loop. - MCP OAuth mishandling client registrations: denying consent forced a new one, one for another redirect URI was reused, and a concurrent write could delete a valid one or keep a mismatched one.
- Tool search returning no match when Claude selects an MCP tool by its bare name instead of its full
mcp__server__toolname. - Resumed
claude -psessions whose tools all come from MCP servers failing with “At least one tool must have defer_loading=false”. - Ctrl+O cancelling pending MCP server reconnects, and
/mcpsent from Remote Control failing while the transcript view is open. - Turns failing with “API returned an empty or malformed response” when an LLM gateway returns the non-streaming reply as
text/plain. - The Claude in Chrome prompt telling the model to load tools through ToolSearch when ToolSearch is unavailable.
Resuming & background work
/resumeand/teleportkeeping the previous conversation’s file-read tracking, so Claude could edit files the resumed conversation had never read.--resumedropping the 1M context window ([1m]) when the resumed session’s model family differs from the configured default model.- Artifacts attached with
/artifactsdisappearing from the session after--resume. - Background sessions (
claude --bg,claude agents) not watching the artifacts they publish for republishes made elsewhere. - Claude starting a second copy of a background command (such as a watch task or dev server) that was still running after the conversation was compacted.
- Cross-session messages held by the receiving session’s permission-mode policy leaving no trace; headless senders now get a delivery notice, and
SendMessageresults no longer imply it was read. /modelwarning about losing the conversation cache when switching back to the model the conversation actually ran on.
Settings, self-hosted runners & file systems
- Self-hosted runner sessions silently losing all host config (settings, skills, plugins, MCP servers) when the host config directory exceeds 64 MiB;
--host-config-snapshot disk|memoryis added. - A stale
.git/config.lockbreakinggit checkout -b,git push -uandgit configfor the rest of a session after a sandboxed command failed to start (Linux). - Settings file changes made outside the session going unnoticed on macOS machines whose system file-event service is saturated; the watcher now falls back to polling.
- Custom agents, slash commands and output styles beyond the first not loading from a virtual drive that reports inode 0, such as an encrypted vault mounted as a Windows drive.
- Skills synced from claude.ai staying on disk indefinitely after signing out; copies not refreshed within
cleanupPeriodDaysnow move to the recoverable trash at the next launch. - Windows: PowerShell commands failing with “Exit code 1” and no output when the session’s temp output path reaches 260 characters.
Commands & input
/reload-skillsreporting a skill count that disagreed with the slash menu after/cd./resumeand/continueshowing only 1-2 sessions in fullscreen mode on short terminals.- The
/add-dirpath input: the left and right arrow keys now move the cursor, and Enter adds only the typed path instead of also adding the highlighted completion. - Text fields outside the main prompt moving a leading
!to the end of what you typed (!foocame out asfoo!). - The interactive
/hooksmenu crashing when a hook matcher is named after an inherited object property such as__proto__orconstructor. - Spinner tips suggesting commands that aren’t available for your account type or are disabled in your session.
Terminal display
- Text keeping a stale background color in fullscreen after the box around it lost its background.
- Delete in st and Alt+arrow keys in rxvt-unicode not working in attached background sessions.
- The terminal’s replies to capability queries (
^[[?1;2c) appearing at the shell prompt or in an editor when Claude Code exits, is suspended, or opens an editor right after starting.
[VSCode]
- The Hooks and Permission rules dialogs reporting a save that landed as failed, and the Hooks dialog going blank under a plugin-only policy lock or showing color codes in save errors.
- Hooks dialog saves: no duplicate hook on replace, a header name retyped in other capitals keeps its secret, and settings.local.json is gitignored before the save returns.
- Session history showing only the current session when the workspace is on a Windows mapped network drive or SUBST drive.
- The session list’s Active filter hiding open idle sessions when Open is also checked in the filter menu.
- A new chat switching back to the previous chat when the session list refreshed.
- Open tabs and the side bar keeping the old config folder until a window reload after
CLAUDE_CONFIG_DIRchanged in theenvironmentVariablessetting. - Console windows flashing on Windows when the extension runs background commands such as git, ripgrep, and the sign-in status check.
- The prompt cache clock’s hover text appearing only after a delay, and the auto-compact icon showing the browser’s own tooltip beside its popup.
[Claude Code on the web]
- A cloud session sometimes taking about ten minutes to respond after its process exited while the session still looked live; sending a message now restarts it right away.
[Claude Tag]
- Claude in a channel where it stays active losing its working context about once an hour when the conversation is mostly in threads; thread activity now keeps it from being reset.
- A thread that asked Claude to watch a pull request no longer hearing about CI failures, comments and reviews after Claude was restarted in that thread.
- Deleting the first message of a thread Claude had already replied in not ending Claude’s work there; it now stops, as it did when a message with no replies was deleted.
- Claude holding back a post because of an earlier instruction addressed to a different bot or assistant; only instructions addressed to Claude bind it, and it asks when unsure.
- The reply-mode card saying Claude “sees a lot of automated posts” when the channel is only chatty or large; the card now names the real reason.
[Code Review]
- A pull request in a repository reviewed once per PR sometimes getting no review when a commit arrived while its review was waiting to start; it now reviews the requested commit.
- Code Review occasionally posting the same findings two or three times when GitHub reported an error for a review it had in fact created.
- Follow-up reviews re-posting a security finding a person had already resolved when a later push moved the lines it was anchored to.
- Reopening a finished /ultrareview cloud session in the Claude app starting the whole review over again unprompted.
Notes
- Monitor’s
persistentoption is gone — every watch now has a deadline (at most 30 minutes; 10 in single-prompt-pruns) and Claude is notified to re-arm. Check any flow that relied on a no-timeout watch. - An unreadable
managed-mcp.jsonnow blocks other MCP servers — it keeps exclusive MCP control, so user, project and plugin servers don’t load. If you see the startup warning, fix the file. - Expect more Bash permission prompts — tighter checks around wildcards, unrecognized options, shell variable declaration flags, and
permissions.blockReadsOutsideWorkingDirectoriesmay prompt for commands that used to pass. - Inline
!shell commands in skills and slash commands follow permission rules in auto mode — default-mode permission rules apply instead of the classifier; add allow rules where needed. - Dynamic workflow sizes are smaller — the default is small on Pro plans, and the medium size guideline is 10 agents, down from 15.
- Synced claude.ai skills are cleaned up after signing out — copies not refreshed within
cleanupPeriodDaysmove to the recoverable trash at the next launch. - Self-hosted runners with a large host config should check
--host-config-snapshot— host config over 64 MiB no longer disappears silently, and the snapshot can bediskormemory. - Fast mode in Remote sessions follows organization policy — where your organization doesn’t allow it, neither the host setting nor
/fastturns it on.