claudekit / updates / claude-code-2-1-274
[ PATCH · ]

Claude Code 2.1.274

A visible warning now appears when memory usage is critical, and `CLAUDE_CODE_MCP_STARTUP_WAIT_MS` bounds how long the first non-interactive turn waits for connecting MCP servers. In VS Code, a step interrupted by a window reload now continues, and the Customize menu gains Memory and Instructions entries. Bedrock, Vertex, Foundry and telemetry-disabled installs now use the v2 MCP client by default, and `"type": "sdk"` MCP entries are skipped with a warning. Fixes include sessions stuck endlessly retrying "unexpected tool_use_id" 400 errors, Streamable HTTP MCP tool calls timing out after about 5 minutes despite a longer per-server `timeout`, an active `/goal` lost when resuming a compacted session, and Bash commands that loop over or assign certain special shell variables not asking for permission.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.274 shipped on September 17, 2026. Most of this release is about sessions that got stuck or dropped. A corrupted transcript no longer traps a session in an endless “unexpected tool_use_id” 400 retry loop — it self-heals where possible, or ends with a clear error and a /rewind hint — and MCP connections get a batch of fixes covering legacy HTTP+SSE servers, a 5-minute cap on tool calls, and 403 insufficient_scope errors. Memory handling changes too: a warning appears when memory usage is critical, and background commands are no longer stopped under mild memory pressure. The Claude apps gateway gets work on its Postgres connection, shutdown, and spend-limit checks. Two behavior changes to watch: Bedrock, Vertex, Foundry and telemetry-disabled installs now use the v2 MCP client by default, and /code-review uses leaner inline review prompts instead of spawning many review subagents on models without tuned settings.

New features

  • A warning when memory usage is critical

    Running out of memory gave no visible signal, so a session that slowed down or stalled left you guessing. A visible warning now appears, with steps to free memory or restart safely.

  • CLAUDE_CODE_MCP_STARTUP_WAIT_MS

    The first non-interactive turn could be held up waiting for connecting MCP servers. This variable bounds that wait; 0 means don’t wait.

  • OpenTelemetry additions

    The claude_code.llm_request trace span now carries an effort attribute, matching the api_request event. A new claude_code.managed_settings_resolved event reports managed-settings sources and policy helper state; with OTEL_LOG_MANAGED_SETTINGS=1 it also includes redacted settings and digests.

  • Claude apps gateway settings and warnings

    The Postgres connect timeout was fixed at 5 seconds. store.connect_timeout_seconds in the gateway config now lengthens it, and the boot error when the database is unreachable points to store.postgres_url and the configured timeout. The telemetry Claude Desktop and Cowork send through the gateway now includes enduser.sub, the IdP subject. The gateway also warns when a replica has more requests open than the 256 it sends upstream at once, and logs that limit at startup.

  • Click-to-expand for collapsed messages

    Collapsed teammate and agent messages in fullscreen mode can now be expanded with a click.

  • [VSCode] Continue after reload

    A window reload used to cut off the step in progress. That step now continues, labeled in the chat, and the Claude Code: Continue After Reload setting turns this off.

  • [VSCode] Memory and Instructions in the Customize menu

    Memory shows the auto-memory toggles, the saved memories and the memory folders; Instructions edits the CLAUDE.md files.

  • [VSCode] claudeCode.lockEditorGroups

    Claude always locked the editor groups it opened in. This setting stops it.

  • [Claude Code on the web] A “Compare against” branch picker

    A cloud session’s diff view could only compare against the base branch. It can now diff the session’s changes against any branch.

  • [Claude Tag] A Guests setting when adding channels and workspaces

    The Add channel and Add workspace forms in Claude Tag admin settings now include Guests, so owners can pick Inherit, Allow, Channel only or Restrict up front.

Key improvements

Startup & notifications

  • First turn in --input-format stream-json sessions

    The first turn waited up to 2s for still-connecting MCP servers whose tools tool search defers. It no longer waits; those tools arrive on a later turn.

  • Monitor tool notifications

    A script’s final output and its exit came in as two notifications. They now arrive as one, saving a model turn.

  • Removing an agent worktree

    Safety checks are improved before removing an agent worktree that contains submodule checkouts.

  • OTEL_LOG_RAW_API_BODIES=file:<dir> output

    Responses were hard to tie back to their requests. A new index.jsonl and request_body_id / message.id event attributes link each response to its request file and transcript message.

Artifacts

  • Artifact tool errors when signed out of claude.ai

    The terminal now says you are not signed in on the first attempt, and Claude is told to stop retrying a rejected call sooner.

  • Publishing on top of an older version

    A publish built on an older version is now stopped before it is sent, with the newer page to merge.

Claude apps gateway

  • Boot with a slow database

    The gateway now tries the first Postgres connection up to three times before exiting, so a database that is reachable a few seconds late no longer fails the boot.

  • Spend-limit checks under load

    A check now takes one database round trip instead of four, so fewer checks time out on a busy gateway.

  • Sign-in rate limit errors

    /login now explains the refusal, and the gateway log says which limit was hit and which setting to change.

Changed behavior

  • v2 MCP client by default on more installs (changed)

    Bedrock, Vertex, Foundry and telemetry-disabled installs now use the v2 MCP client and MCP 2026-07-28 negotiation with direct HTTP servers by default, as other installs already do. Opt out with MCP_SDK_GENERATION=v1 or MCP_PROTOCOL_NEGOTIATION=legacy.

  • /code-review (changed)

    For every model that has no tuned settings of its own, it uses leaner inline review prompts instead of spawning many review subagents.

  • "type": "sdk" MCP entries (changed)

    Entries in .mcp.json, settings, plugins and agent files are skipped with a warning: only an SDK host application can register in-process servers.

  • Artifact watching in local sessions (changed)

    A new version published elsewhere no longer starts a turn; Claude learns of it from a later Artifact tool result.

  • Git LFS in plugin and marketplace clones (changed)

    LFS files are left as pointers instead of downloaded. Run git lfs pull in the checkout to fetch them.

  • Self-hosted runners and read-only repositories (changed)

    A read-only repository the git host refuses at the access check is skipped instead of failing the session start.

  • “Cloud session” wording (changed)

    The /status GitHub line reads “Cloud sessions”, and /web-setup, /ultrareview and teleport messages say “cloud session” instead of “Claude Code on the web”.

  • [VSCode] Default global gitignore file (changed)

    It is now $XDG_CONFIG_HOME/git/ignore when XDG_CONFIG_HOME is an absolute path.

  • [Claude Code on the web] Routines without a GitHub connection (changed)

    A routine used to be switched off at the first failed check when the owner’s GitHub connection was missing. It now skips the run and retries for up to 72 hours. When your subscription is paused, the on-hold notice tells you to turn the routine back on yourself instead of promising an automatic resume.

[VSCode], [Claude Tag] & [Code Review]

  • [VSCode] Screen reader navigation

    Each message is announced as “You” or “Claude”, with the tool name for tool steps.

  • [Claude Tag] The live progress checklist in Slack

    It is capped at 2,000 characters, reposted at most every 15 minutes in busy threads, and older “Latest task list” links are updated. The repeated guest-attribution note Claude appended to a Slack canvas in “Channel only” guest channels is removed.

  • [Code Review] Finding wording

    Each posted finding now uses short plain sentences that say who is affected, where the code goes wrong, and the fix up front.

  • [Code Review] Reviews skipped by an organization limit

    The check-run card and PR comment now link each cause to the admin page that fixes it.

Bug fixes

Sessions & context

  • Sessions getting stuck endlessly retrying “unexpected tool_use_id” 400 errors; corrupted transcripts now self-heal where possible, and otherwise a clear error (with a /rewind hint) ends the loop.
  • Hook-driven sessions (such as an active /goal) ending with “Prompt is too long” instead of compacting when the context overflowed again after a reactive compaction.
  • An active /goal being lost when resuming (--continue / --resume) a session that had compacted.
  • claude agents losing --model, --effort, --permission-mode, --allow-dangerously-skip-permissions and --agent after an auto-update relaunch.
  • A per-turn slowdown when a language server publishes project-wide diagnostics for thousands of files.
  • Subagents with model: "opus" on Bedrock, Vertex or Foundry leaving the session’s model when its id has no recognizable model family (unless ANTHROPIC_DEFAULT_OPUS_MODEL is set).
  • Background commands being stopped after 30 idle minutes under mild memory pressure; they’re now stopped only when memory is critically low, and the debug log says why.

MCP connections

  • MCP servers configured as http that only speak legacy HTTP+SSE failing to connect when they answer the first request with 422 or another 4xx error.
  • Streamable HTTP MCP tool calls timing out after about 5 minutes even when a longer per-server timeout was set.
  • MCP prompts and resources not refreshing when a server sends list-changed notifications without declaring listChanged.
  • MCP tool calls refused with 403 insufficient_scope being reported as an expired sign-in; the error now names the missing permissions and points to /mcp re-authentication.
  • --strict-mcp-config with an empty --mcp-config holding the first non-interactive turn for up to MCP_TIMEOUT on incidental MCP servers.
  • The first turn of a cloud session sometimes starting without the tools of an SDK-hosted MCP server that was still connecting.

Permission checks & security

  • Bash commands that loop over or assign certain special shell variables not asking for permission; they now do.
  • Worktree-isolated sessions accepting Bash commands with certain nested shell expansions; these are now refused.
  • MCP connection errors and the MCP login tool’s description showing secrets resolved from ${VAR} placeholders in MCP configs.
  • The Edit permission prompt preview sometimes showing a different location than the approved edit in files with multi-byte characters.

Agents, hooks & headless

  • A resumed background agent keeping half of an interrupted tool batch when one of its calls was approved with a message.
  • A local claude -p --resume started with CLAUDE_CODE_RESUME_INTERRUPTED_TURN not reporting background tasks the previous process left unfinished.
  • Background agent notifications claiming the agent had no live background work when it was still waiting on its own background task and would resume.
  • Headless and SDK sessions making a separate model call for every background task that finished; completions already queued are now answered by one call.
  • Stop prompt hooks re-sending their whole prompt on every block; repeat blocks now name the condition with a 500-character label.
  • A sub-agent’s progress summary being replaced by a runaway multi-paragraph reply.
  • A message a subagent sends to the main session disappearing from the Claude Desktop transcript after a relaunch.

Plugins

  • A plugin or marketplace directory with no git repository of its own taking its version from an enclosing git repository, such as a git-managed ~/.claude.
  • installed_plugins.json being rewritten on nearly every start-up when plugin policy comes from remote managed settings, which made Claude Desktop reload every open session’s plugins.
  • The Bash tool re-sourcing the shell profile after every plugin reload (a multi-second stall on the next command); it now does so only when the plugins’ bin/ directories changed.
  • Plugins with a top-level $schema in hooks/hooks.json showing an “unknown key” notice.
  • A plugin loaded from a .zip being served from a stale extraction after several overlapping reloads.

Display & input

  • Clickable links to local file paths doing nothing in VS Code and other terminals that require a file:// URI.
  • The transcript renumbering ordered lists in your own messages (typing “3. 2. 1.” displayed “3. 4. 5.”); numbers and “N)” markers now show as typed.
  • AskUserQuestion preview notes being attached to a previously chosen option instead of the highlighted one, and preview mode dropping the highlighted option when submitting a note with Enter.
  • Extra empty editor windows opening at startup on Linux under Wayland when running inside the Cursor or VS Code terminal.

Commands & tools

  • Error hints in Claude Desktop sessions suggesting CLI flags that cannot be used there; they now suggest slash commands like /usage-credits.
  • /schedule saving a routine’s prompt without its message role when Claude writes the routine in the shape that listing routines returns.
  • /status not showing the apiKeyHelper failure that its own error banner told you to check.
  • /fast on in non-interactive sessions reporting on and then turning off under an organization’s managed fast mode policy; it now says the organization has disabled it.
  • The Artifact tool asking you to approve an update to an artifact that it then refused because the session had not read the latest version.
  • Cowork and claude.ai cloud sessions with network access on treating reads of a teammate’s artifact as if network access were off.
  • Self-hosted runner sessions failing every turn with a 401 after a few failed token refreshes, until the next scheduled refresh; the runner now keeps retrying, and fetches a new token after a 401.

Claude apps gateway

  • An unhandled promise rejection when Postgres drops a connection during a spend check.
  • Every open stream being cut on SIGTERM; the gateway now lets in-flight requests finish for up to 25 seconds before exiting (CLAUDE_GATEWAY_DRAIN_TIMEOUT_MS).

[VSCode]

  • A /btw side question asked in a new conversation’s first seconds occasionally showing another session’s side-question history.
  • A brief freeze when the extension first looks up your global gitignore file.
  • A message sent while Claude was running a tool disappearing from the conversation after a window reload.
  • The Manage Plugins enable toggle and MCP servers dialog rows being unreachable from the keyboard.
  • Sign-ins and sign-outs made in a terminal not showing until a reload after CLAUDE_CONFIG_DIR changed in the Environment Variables setting.
  • Edit diffs in the chat being cut off at the bottom at some panel widths and for long wrapped lines; diff boxes now fit the rows shown.
  • Overlapping settings writes leaving ~/.claude/settings.json unparseable or dropping a setting.
  • Open in New Tab (Ctrl/Cmd+Shift+Esc) sometimes leaving the new tab’s message box unfocused, so typing went nowhere until you clicked it.
  • Reopening a closed Claude tab splitting the editor layout, and New session opening another locked editor group, when a file tab shared the group with a Claude tab.
  • Session names shifting sideways in the session picker while typing a search query.
  • The plan review card cutting off its Send feedback button and reason field when a plan has several comments; the comment list now scrolls.
  • Inline code and code blocks in chat replies being unreadable under the High Contrast themes.

[Claude Code on the web]

  • Git operations in cloud sessions failing with “service unavailable” when GitHub’s token renewal briefly errors.
  • Editing a routine occasionally making it fire twice or re-enabling a routine that had just been paused.
  • Commits in cloud sessions occasionally failing with a signing error for a few minutes after the session’s credentials refreshed.
  • The toast after saving a routine whose GitHub trigger couldn’t be linked showing only “edit to retry”; it now shows the reason, such as a per-repository trigger limit.
  • Sessions sometimes flipping back to unread right after you mark them read.

[Claude Tag]

  • Claude not answering when another Slack app or bot @mentions it; the tag now gets a reply and wakes Claude in a channel it had stopped following after days of inactivity.
  • Claude missing another app’s message that tagged @claude right after a new Slack channel was created; it’s now delivered once Claude has joined.
  • Claude folding a follow-up sent minutes after its last Slack message into it as a silent edit; late updates such as blockers now post as a new reply that notifies.
  • Slack search failing with an error whenever it searched within a single channel; it now returns that channel’s matching messages.
  • A safety-filter stop silently resetting a Slack thread’s context when nobody was waiting; Claude now always says so and no longer cancels background work still running.
  • Email addresses in Slack replies rendering with a visible mailto: prefix.
  • Claude refusing to watch an Enterprise Grid channel shared with the whole organization when asked from another workspace in the grid.
  • The Environment picker showing a raw environment ID instead of the name for archived or app-created environments.

[Code Review]

  • Re-reviews occasionally leaving a fixed finding’s thread open when the new review also filed a lower-severity note under it.
  • Rare reviews ending with “Code review encountered an error” when GitHub or an internal service failed transiently at launch; they now wait and retry.

Notes

  • The v2 MCP client is now the default on Bedrock, Vertex and Foundry — and on telemetry-disabled installs. If direct HTTP MCP servers misbehave, opt out with MCP_SDK_GENERATION=v1 or MCP_PROTOCOL_NEGOTIATION=legacy.
  • "type": "sdk" MCP entries are skipped — in .mcp.json, settings, plugins and agent files they only produce a warning; in-process servers must be registered by an SDK host application.
  • Plugin clones no longer download Git LFS files — run git lfs pull in the checkout if a plugin depends on LFS-tracked files.
  • The first non-interactive turn’s MCP wait is configurable — CLAUDE_CODE_MCP_STARTUP_WAIT_MS bounds it, and 0 means don’t wait.
  • /code-review may behave differently — on models without tuned settings it uses inline review prompts instead of many review subagents.
  • The Claude apps gateway drains on SIGTERM — in-flight requests get up to 25 seconds to finish before exit (CLAUDE_GATEWAY_DRAIN_TIMEOUT_MS).
  • [Claude Code on the web] Routines aren’t switched off for a missing GitHub connection — runs are skipped and retried for up to 72 hours. A routine on hold because your subscription is paused must be turned back on by you.