claudekit / updates / claude-code-2-1-273
[ PATCH · ]

Claude Code 2.1.273

Five request headers for LLM gateways are available behind `CLAUDE_CODE_GATEWAY_HINT_HEADERS=1`, a notification now points at `/mcp` when automatic reconnection to an MCP server gives up, and a session started with `claude --remote-control` can be forked from the Claude app. 17 improvements and 6 changes mostly rewrite errors to name the cause: a GitHub IP allow list, SAML single sign-on, an untrusted corporate CA, or a gateway administrator to contact. Long sessions are more responsive because hook progress and sub-agent activity no longer re-process the whole conversation on every update. 35 fixes include Bash commands the permission checker cannot fully analyze skipping the prompt, skills synced from claude.ai staying available after an organization turns Skills off, and advisor-tool turns being counted at roughly twice their real context size.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.273 shipped on September 15, 2026. The clearest theme is error messages rewritten to name the cause. Blocked GitHub access, an expired sign-in, or a corporate proxy used to surface as “admin permissions required” or “run /login”, which said nothing about what to fix; they now name an IP allow list, a suspended app installation, SAML single sign-on, or an untrusted corporate CA, and say what to do. Fixes lead with 35, and the permission-checker ones matter most: Bash commands the permission checker cannot fully analyze were skipping the prompt under permissions.blockReadsOutsideWorkingDirectories, and a subshell could hide a dangerous rm in bypass mode. Two behavior changes to watch: auto mode on Bedrock, Vertex and Foundry uses the local classifier by default for now, and the 2.1.268 deny-rule change on unanalyzable Bash lines is reverted.

New features

  • Request hint headers for LLM gateways

    Gateways could not see a request’s class, the agent type behind it, how long the previous tool calls took, or whether the context had been compacted. Claude Code can now send x-claude-code-request-class, x-claude-code-agent-type, x-claude-code-prev-tool-durations, x-claude-code-compaction and x-claude-code-context-compacted. They are off by default; opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1.

  • A notification when an MCP server disconnects mid-session

    When a server dropped and automatic reconnection gave up, its tools quietly went missing while the session carried on. A notification now appears at that point, pointing at /mcp.

  • Forking a Remote Control session

    A session started with claude --remote-control or /remote-control could not be branched from the Claude app to try a different direction. It can now be forked there; the fork runs as a background session on your computer.

  • [Claude Code on the web] A “Discard unsaved changes?” confirmation

    Closing the New routine page or the Edit routine dialog threw away a routine name, prompt or edit you had typed. It now asks first.

Key improvements

Errors that name the cause

  • Blocked GitHub access in cloud sessions

    A refusal showed a generic install hint whatever the cause. It now shows the cause: an IP allow list, a suspended app installation, or SAML single sign-on. /install-github-app also no longer reports a SAML single sign-on block as “admin permissions required”.

  • /autofix-pr failures

    When gh pr view failed, a generic exit-code line hid whether it was sign-in, SAML or a rate limit. gh’s own error is now shown. When GitHub webhook delivery can’t be set up for the PR, the reason is named too — for example, no linked GitHub account.

  • /web-setup errors

    A refused GitHub token now lists the likely reasons and the fix, and a connection failure names a configured proxy or a TLS certificate problem.

  • In-session SSL certificate and proxy connection errors

    They now name the error code and what to fix, such as NODE_EXTRA_CA_CERTS for an untrusted corporate CA.

  • Expired sign-ins

    A cloud session that can’t be created because your Claude login expired or was revoked now tells you to run /login. An MCP server whose sign-in expires mid-session now says how to re-authenticate (/mcp).

  • 401/403 on Bedrock, Vertex and Foundry

    These errors, and Claude apps gateway 403s, told you to run /login — wrong advice for sessions that don’t use a claude.ai login. The message now names the credential to refresh or points to your gateway administrator.

Responsiveness & display

  • Responsiveness in long sessions

    Hook progress and sub-agent activity re-processed the whole conversation on every update. They no longer do.

  • The spinner on compaction status lines

    Compaction status lines such as “Running PreCompact hooks…” showed a doubled ellipsis (”……”). Fixed.

  • A false-positive spinner tip

    Reading or publishing Artifacts suggested the frontend-design plugin. Fixed.

Artifacts

  • The Artifact tool’s error on an unserved file type

    A publish including a file type artifacts don’t serve was hard to act on. Claude is now told which types are served and what to do instead, and the terminal shows one plain line.

  • The Artifact tool’s page read

    It now states the capabilities and database rules the artifact service holds for the page, for anyone who can publish to it.

  • Artifact database writes

    Removing one value meant rewriting the whole document. An update can now remove a single field.

  • Artifact publishing over a dropped connection

    A publish whose connection drops after reaching claude.ai is now re-sent safely instead of failing or creating a duplicate version.

Changed behavior

  • The 2.1.268 deny-rule change (reverted)

    2.1.268 checked Read and Edit deny rules on Bash lines the permission checker can’t analyze (eval, env -C), which denied ordinary commands like time -p make build. That change is reverted; such commands prompt again instead of being denied.

  • Auto mode on Bedrock, Vertex and Foundry (changed)

    These platforms use the local classifier by default for now. Set CLAUDE_CODE_AUTO_MODE_SERVER=1 to use the platform’s server-side classifier.

  • OTEL_LOG_TOOL_DETAILS=1 (changed)

    Cost and token metrics now also include real agent, skill, plugin and MCP server names.

  • Sign-in with a Claude account (changed)

    It now also requests access to your claude.ai plugins.

  • /bug and /feedback reports (changed)

    They now include only model-behavior params (model, system prompt, tools) from the last API request, omitting request metadata and CLAUDE_CODE_EXTRA_BODY fields.

[VSCode] & Windows

  • [VSCode] Organizations with product feedback disabled

    “Report a problem” still appeared and /bug / /feedback opened a report form. Fixed.

  • [VSCode] A red banner on Windows

    “Claude Code process exited with code 4294967295” appeared after completed turns. Fixed.

  • Windows: The network-path permission check for UNC paths

    Improved when a mapped network drive was added with --add-dir.

[Claude Code on the web], [Claude Tag] & [Code Review]

  • [Claude Code on the web] The routine detail page

    The menu and rename move into the breadcrumb, the on/off switch and Run now sit at the top, and run history sits beside the routine’s settings.

  • [Claude Code on the web] The desktop-app download screen (removed)

    New users without a cloud environment saw a full-page download screen on Mac and Windows. It is gone; they now go straight to setup.

  • [Claude Code on the web] The “Share cloud sessions” admin setting (changed)

    It now lives under Data and privacy instead of the Claude Code page, where Data and privacy admins can also manage it.

  • [Claude Tag] AWS connection failures

    When a request can’t be signed — such as a hostname with no region — Claude is now told why and how to fix it instead of getting a bare error.

  • [Claude Tag] Watching related public channels (changed)

    Claude only looked at other channels when asked. It now starts watching related public channels on its own, such as an incident channel a conversation depends on.

  • [Code Review] Suggested fixes

    When other code depends on the behavior being changed, a suggested fix now says what it must keep working.

  • [Code Review] Comments pointing to a second affected location

    They stated that location’s issue as a cut-off stub. It is now a full sentence.

Bug fixes

Permission checks & security

  • Bash commands the permission checker cannot fully analyze skipping the prompt under permissions.blockReadsOutsideWorkingDirectories, and a subshell hiding a dangerous rm in bypass mode.
  • permissions.blockReadsOutsideWorkingDirectories not covering a memory directory chosen by a repository’s settings; it is no longer loaded into the prompt, recalled, indexed, or used by memory extraction.
  • Skills synced from claude.ai staying available after your organization turns Skills off; they now move to the recoverable trash.
  • allowManagedMcpServersOnly, deniedMcpServers and disableClaudeAiConnectors set via MDM or managed-settings.json being ignored when server-managed settings are also present.

Sessions & context

  • /login, /upgrade, and /extra-usage discarding earlier thinking from the conversation, which forced a full prompt-cache rewrite on the next request.
  • The context meter and auto-compact counting advisor-tool turns at roughly twice their real context size, which made auto-compact fire at about half the real window.
  • A long-running session recreating a stub .git/info/exclude after the repository’s .git directory was removed or moved away.
  • Saved scheduled tasks running in the wrong session after .claude/scheduled_tasks.json was copied into another folder, such as a new worktree.
  • /tui refusing to restart because of an agent-team teammate that had already finished its work and was no longer shown in the agents panel.

Agents & SDK

  • Sub-agents and background agents being reported as failed, with their result never delivered, when the final streamed reply omitted token usage or carried no model id.
  • SDK and --output-format stream-json output dropping a subagent’s remaining messages and final report after it is moved to the background mid-run (e.g. by CLAUDE_AUTO_BACKGROUND_TASKS).
  • Auto mode stopping for approval when the Artifact tool uploads a file you attached to the chat in a cloud or Remote Control session.
  • Remote Control clients attached to a Claude Desktop, VS Code or JetBrains session being refused when they ask for the session’s context window usage.

Input & file reads

  • The main prompt dropping a ! typed at the start while already in shell mode, so negated commands like ! grep … can be typed.
  • Read on macOS refusing a dragged-in screenshot, or any file the system reports under a second path, with “symlink resolution changed after permission was checked”.

[Claude Code on the web]

  • Routines losing access to an organization connector, and still calling the old one, after an admin removed and re-added that connector.
  • Creating a self-hosted environment from organization settings occasionally failing with a server error and leaving a half-created environment behind.

[Claude Tag]

  • Claude going silent minutes after reinstalling the app when an Enterprise Grid was disconnected but one of its workspaces stayed connected.
  • Scheduled tasks set up in an organization-shared private Slack channel silently never posting; they now keep running in the thread they were created in.
  • Replying in an older Slack thread while Claude is mid-task sometimes restarting it from scratch and losing work it had not pushed yet.
  • Claude occasionally dropping a message with an incorrect “couldn’t find a Claude Code environment” notice right after your account token refreshed.
  • AWS connections refusing region-less endpoints such as Budgets, Savings Plans, WAF Classic and Import/Export; Global Accelerator requests now sign correctly.
  • OAuth client-credentials and JWT-bearer connections failing with providers that return a lowercase token type; requests now send the standard Bearer scheme.
  • Adding a channel manager being refused on Enterprise Grid shared channels, on channels where Claude hasn’t been used yet, and on legacy private channels.
  • The admin Memory page not listing Slack channels Claude set up on its own even when they had saved memory; admins can now open, edit and delete that memory.

[Code Review]

  • Merging the base branch into a PR whose earlier review listed “Additional findings” triggering a full re-review; these pushes now get the lighter follow-up review.
  • A whole REVIEW.md being ignored because of an @-mention, a code span wrapped across lines, or a backticked HTML tag; only lines linking to changed files are withheld.
  • /ultrareview --post posting the findings comment never or twice on a retry after a GitHub error; it now posts exactly once, and the comment names the reviewed commit.
  • Empty or content-identical pushes being re-reviewed on GitHub repositories whose owner or name contains a capital letter; these pushes are now skipped.

Notes

  • Commands like time -p make build prompt again — the 2.1.268 change that checked Read and Edit deny rules on unanalyzable Bash lines (eval, env -C) is reverted. If you adjusted rules around that behavior, re-check them.
  • Auto mode on Bedrock, Vertex and Foundry uses the local classifier for now — set CLAUDE_CODE_AUTO_MODE_SERVER=1 to go back to the platform’s server-side classifier.
  • OTEL_LOG_TOOL_DETAILS=1 now emits real names — cost and token metrics carry real agent, skill, plugin and MCP server names, so review both what you collect and the added metric-label cardinality.
  • Signing in requests more access — sign-in with a Claude account now also requests access to your claude.ai plugins.
  • /bug and /feedback send less — only model-behavior params (model, system prompt, tools) from the last API request; request metadata and CLAUDE_CODE_EXTRA_BODY fields are omitted.
  • Turning Skills off now removes synced skills — copies synced from claude.ai move to the recoverable trash instead of staying available.
  • A memory directory chosen by a repository’s settings is not used under permissions.blockReadsOutsideWorkingDirectories — such a directory is not loaded into the prompt, recalled, indexed, or used by memory extraction.
  • Gateway hint headers are opt-in — the five headers are off by default; gateway operators enable them with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1.
  • [Claude Tag] Claude watches related public channels on its own — such as an incident channel a conversation depends on, without being asked.