What changed
Claude Code 2.1.273 shipped on September 15, 2026. The clearest theme is error messages rewritten to name the cause. Blocked GitHub access, an expired sign-in, or a corporate proxy used to surface as “admin permissions required” or “run /login”, which said nothing about what to fix; they now name an IP allow list, a suspended app installation, SAML single sign-on, or an untrusted corporate CA, and say what to do. Fixes lead with 35, and the permission-checker ones matter most: Bash commands the permission checker cannot fully analyze were skipping the prompt under permissions.blockReadsOutsideWorkingDirectories, and a subshell could hide a dangerous rm in bypass mode. Two behavior changes to watch: auto mode on Bedrock, Vertex and Foundry uses the local classifier by default for now, and the 2.1.268 deny-rule change on unanalyzable Bash lines is reverted.
New features
-
Request hint headers for LLM gateways
Gateways could not see a request’s class, the agent type behind it, how long the previous tool calls took, or whether the context had been compacted. Claude Code can now send
x-claude-code-request-class,x-claude-code-agent-type,x-claude-code-prev-tool-durations,x-claude-code-compactionandx-claude-code-context-compacted. They are off by default; opt in withCLAUDE_CODE_GATEWAY_HINT_HEADERS=1. -
A notification when an MCP server disconnects mid-session
When a server dropped and automatic reconnection gave up, its tools quietly went missing while the session carried on. A notification now appears at that point, pointing at
/mcp. -
Forking a Remote Control session
A session started with
claude --remote-controlor/remote-controlcould not be branched from the Claude app to try a different direction. It can now be forked there; the fork runs as a background session on your computer. -
[Claude Code on the web] A “Discard unsaved changes?” confirmation
Closing the New routine page or the Edit routine dialog threw away a routine name, prompt or edit you had typed. It now asks first.
Key improvements
Errors that name the cause
-
Blocked GitHub access in cloud sessions
A refusal showed a generic install hint whatever the cause. It now shows the cause: an IP allow list, a suspended app installation, or SAML single sign-on.
/install-github-appalso no longer reports a SAML single sign-on block as “admin permissions required”. -
/autofix-prfailuresWhen
gh pr viewfailed, a generic exit-code line hid whether it was sign-in, SAML or a rate limit. gh’s own error is now shown. When GitHub webhook delivery can’t be set up for the PR, the reason is named too — for example, no linked GitHub account. -
/web-setuperrorsA refused GitHub token now lists the likely reasons and the fix, and a connection failure names a configured proxy or a TLS certificate problem.
-
In-session SSL certificate and proxy connection errors
They now name the error code and what to fix, such as
NODE_EXTRA_CA_CERTSfor an untrusted corporate CA. -
Expired sign-ins
A cloud session that can’t be created because your Claude login expired or was revoked now tells you to run
/login. An MCP server whose sign-in expires mid-session now says how to re-authenticate (/mcp). -
401/403 on Bedrock, Vertex and Foundry
These errors, and Claude apps gateway 403s, told you to run
/login— wrong advice for sessions that don’t use a claude.ai login. The message now names the credential to refresh or points to your gateway administrator.
Responsiveness & display
-
Responsiveness in long sessions
Hook progress and sub-agent activity re-processed the whole conversation on every update. They no longer do.
-
The spinner on compaction status lines
Compaction status lines such as “Running PreCompact hooks…” showed a doubled ellipsis (”……”). Fixed.
-
A false-positive spinner tip
Reading or publishing Artifacts suggested the frontend-design plugin. Fixed.
Artifacts
-
The Artifact tool’s error on an unserved file type
A publish including a file type artifacts don’t serve was hard to act on. Claude is now told which types are served and what to do instead, and the terminal shows one plain line.
-
The Artifact tool’s page read
It now states the capabilities and database rules the artifact service holds for the page, for anyone who can publish to it.
-
Artifact database writes
Removing one value meant rewriting the whole document. An update can now remove a single field.
-
Artifact publishing over a dropped connection
A publish whose connection drops after reaching claude.ai is now re-sent safely instead of failing or creating a duplicate version.
Changed behavior
-
The 2.1.268 deny-rule change (reverted)
2.1.268 checked Read and Edit deny rules on Bash lines the permission checker can’t analyze (
eval,env -C), which denied ordinary commands liketime -p make build. That change is reverted; such commands prompt again instead of being denied. -
Auto mode on Bedrock, Vertex and Foundry (changed)
These platforms use the local classifier by default for now. Set
CLAUDE_CODE_AUTO_MODE_SERVER=1to use the platform’s server-side classifier. -
OTEL_LOG_TOOL_DETAILS=1(changed)Cost and token metrics now also include real agent, skill, plugin and MCP server names.
-
Sign-in with a Claude account (changed)
It now also requests access to your claude.ai plugins.
-
/bugand/feedbackreports (changed)They now include only model-behavior params (model, system prompt, tools) from the last API request, omitting request metadata and
CLAUDE_CODE_EXTRA_BODYfields.
[VSCode] & Windows
-
[VSCode] Organizations with product feedback disabled
“Report a problem” still appeared and
/bug//feedbackopened a report form. Fixed. -
[VSCode] A red banner on Windows
“Claude Code process exited with code 4294967295” appeared after completed turns. Fixed.
-
Windows: The network-path permission check for UNC paths
Improved when a mapped network drive was added with
--add-dir.
[Claude Code on the web], [Claude Tag] & [Code Review]
-
[Claude Code on the web] The routine detail page
The menu and rename move into the breadcrumb, the on/off switch and Run now sit at the top, and run history sits beside the routine’s settings.
-
[Claude Code on the web] The desktop-app download screen (removed)
New users without a cloud environment saw a full-page download screen on Mac and Windows. It is gone; they now go straight to setup.
-
[Claude Code on the web] The “Share cloud sessions” admin setting (changed)
It now lives under Data and privacy instead of the Claude Code page, where Data and privacy admins can also manage it.
-
[Claude Tag] AWS connection failures
When a request can’t be signed — such as a hostname with no region — Claude is now told why and how to fix it instead of getting a bare error.
-
[Claude Tag] Watching related public channels (changed)
Claude only looked at other channels when asked. It now starts watching related public channels on its own, such as an incident channel a conversation depends on.
-
[Code Review] Suggested fixes
When other code depends on the behavior being changed, a suggested fix now says what it must keep working.
-
[Code Review] Comments pointing to a second affected location
They stated that location’s issue as a cut-off stub. It is now a full sentence.
Bug fixes
Permission checks & security
- Bash commands the permission checker cannot fully analyze skipping the prompt under
permissions.blockReadsOutsideWorkingDirectories, and a subshell hiding a dangerousrmin bypass mode. permissions.blockReadsOutsideWorkingDirectoriesnot covering a memory directory chosen by a repository’s settings; it is no longer loaded into the prompt, recalled, indexed, or used by memory extraction.- Skills synced from claude.ai staying available after your organization turns Skills off; they now move to the recoverable trash.
allowManagedMcpServersOnly,deniedMcpServersanddisableClaudeAiConnectorsset via MDM ormanaged-settings.jsonbeing ignored when server-managed settings are also present.
Sessions & context
/login,/upgrade, and/extra-usagediscarding earlier thinking from the conversation, which forced a full prompt-cache rewrite on the next request.- The context meter and auto-compact counting advisor-tool turns at roughly twice their real context size, which made auto-compact fire at about half the real window.
- A long-running session recreating a stub
.git/info/excludeafter the repository’s.gitdirectory was removed or moved away. - Saved scheduled tasks running in the wrong session after
.claude/scheduled_tasks.jsonwas copied into another folder, such as a new worktree. /tuirefusing to restart because of an agent-team teammate that had already finished its work and was no longer shown in the agents panel.
Agents & SDK
- Sub-agents and background agents being reported as failed, with their result never delivered, when the final streamed reply omitted token usage or carried no model id.
- SDK and
--output-format stream-jsonoutput dropping a subagent’s remaining messages and final report after it is moved to the background mid-run (e.g. byCLAUDE_AUTO_BACKGROUND_TASKS). - Auto mode stopping for approval when the Artifact tool uploads a file you attached to the chat in a cloud or Remote Control session.
- Remote Control clients attached to a Claude Desktop, VS Code or JetBrains session being refused when they ask for the session’s context window usage.
Input & file reads
- The main prompt dropping a
!typed at the start while already in shell mode, so negated commands like! grep …can be typed. - Read on macOS refusing a dragged-in screenshot, or any file the system reports under a second path, with “symlink resolution changed after permission was checked”.
[Claude Code on the web]
- Routines losing access to an organization connector, and still calling the old one, after an admin removed and re-added that connector.
- Creating a self-hosted environment from organization settings occasionally failing with a server error and leaving a half-created environment behind.
[Claude Tag]
- Claude going silent minutes after reinstalling the app when an Enterprise Grid was disconnected but one of its workspaces stayed connected.
- Scheduled tasks set up in an organization-shared private Slack channel silently never posting; they now keep running in the thread they were created in.
- Replying in an older Slack thread while Claude is mid-task sometimes restarting it from scratch and losing work it had not pushed yet.
- Claude occasionally dropping a message with an incorrect “couldn’t find a Claude Code environment” notice right after your account token refreshed.
- AWS connections refusing region-less endpoints such as Budgets, Savings Plans, WAF Classic and Import/Export; Global Accelerator requests now sign correctly.
- OAuth client-credentials and JWT-bearer connections failing with providers that return a lowercase token type; requests now send the standard Bearer scheme.
- Adding a channel manager being refused on Enterprise Grid shared channels, on channels where Claude hasn’t been used yet, and on legacy private channels.
- The admin Memory page not listing Slack channels Claude set up on its own even when they had saved memory; admins can now open, edit and delete that memory.
[Code Review]
- Merging the base branch into a PR whose earlier review listed “Additional findings” triggering a full re-review; these pushes now get the lighter follow-up review.
- A whole REVIEW.md being ignored because of an @-mention, a code span wrapped across lines, or a backticked HTML tag; only lines linking to changed files are withheld.
/ultrareview --postposting the findings comment never or twice on a retry after a GitHub error; it now posts exactly once, and the comment names the reviewed commit.- Empty or content-identical pushes being re-reviewed on GitHub repositories whose owner or name contains a capital letter; these pushes are now skipped.
Notes
- Commands like
time -p make buildprompt again — the 2.1.268 change that checked Read and Edit deny rules on unanalyzable Bash lines (eval,env -C) is reverted. If you adjusted rules around that behavior, re-check them. - Auto mode on Bedrock, Vertex and Foundry uses the local classifier for now — set
CLAUDE_CODE_AUTO_MODE_SERVER=1to go back to the platform’s server-side classifier. OTEL_LOG_TOOL_DETAILS=1now emits real names — cost and token metrics carry real agent, skill, plugin and MCP server names, so review both what you collect and the added metric-label cardinality.- Signing in requests more access — sign-in with a Claude account now also requests access to your claude.ai plugins.
/bugand/feedbacksend less — only model-behavior params (model, system prompt, tools) from the last API request; request metadata andCLAUDE_CODE_EXTRA_BODYfields are omitted.- Turning Skills off now removes synced skills — copies synced from claude.ai move to the recoverable trash instead of staying available.
- A memory directory chosen by a repository’s settings is not used under
permissions.blockReadsOutsideWorkingDirectories— such a directory is not loaded into the prompt, recalled, indexed, or used by memory extraction. - Gateway hint headers are opt-in — the five headers are off by default; gateway operators enable them with
CLAUDE_CODE_GATEWAY_HINT_HEADERS=1. - [Claude Tag] Claude watches related public channels on its own — such as an incident channel a conversation depends on, without being asked.