What changed
Claude Code 2.1.277 shipped on September 18, 2026. The headline addition is AGENTS.md support: a project that keeps its instructions in AGENTS.md and has no CLAUDE.md now gets them loaded without a second file. Several changes tighten how text enters the conversation — subagent results and computed workflow agent() prompts are now framed so they cannot pass as the session’s own instructions or the user, and invisible Unicode formatting and tag characters are stripped from prompts. The fixes are broad: headless runs and resumes, crashes from malformed values in ~/.claude.json, update checks, and plugin install and management.
New features
-
AGENTS.md support
A project whose instructions lived only in AGENTS.md had to duplicate them into CLAUDE.md. In a project with no CLAUDE.md, Claude Code now reads AGENTS.md instead; change it under “Project instructions” in
/config. Not yet on Bedrock, Vertex or Foundry. -
CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1For Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally.
-
An optional
headers:map on gateway upstreamsClaude apps gateway upstreams can now send static headers to a proxy you run in front of a provider.
-
A notice for waiting background-task updates
When a background task finishes while a panel such as
/tasksis open, a line now says its update is waiting. -
[VSCode] Additions
A Sign out row in the panel menu, with
/logoutin the typed command menu. Background shells and other running tasks appear in the agent map, each with a Stop, and a typed/tasksopens it. A Copy response button on responses and a typed/copy. A one-time notice when inactive sessions are archived automatically, and an “Unarchive all” action on the Archived sessions group. The session’s cost and token usage in the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key). -
[Claude Code on the web] Personal and Organization environments
On Team and Enterprise plans, the environment picker has Personal and Organization sections, and admins can share a personal environment with the organization.
Key improvements
Start-up & messages
-
Faster start-up for SDK and headless (
-p) useThe first turn no longer waits on the per-directory CLAUDE.md lookup.
-
claude plugin installon an already-installed pluginIt now says when the marketplace offers a newer version and names the
claude plugin updatecommand. -
The dangerous-rm permission prompt
It now names the flagged rm command and suggests a
${VAR:?}guard, so headless runs can recover. -
/ultrareviewwhen there’s nothing to reviewMessages say which case you’re in, offer a command that reviews your latest commit, and a new repository’s first commit is reviewed in full.
-
Other messages
The Claude apps gateway’s loopback error messages name
CLAUDE_GATEWAY_ALLOW_LOOPBACK. In/pluginInstalled, an MCP server listed apart from its plugin shows which plugin it belongs to. The startup notice overflow line under the logo reads “N more notices hidden” instead of “+N more · /status”.
Prompts & artifacts
-
Invisible characters in prompts
Invisible Unicode formatting and tag characters in a prompt are removed, and the cleaned prompt is shown for review before it is sent.
-
claude.ai artifact links
Claude reads them with the Artifact tool instead of WebFetch when that tool is available. The Artifact tool’s permission prompts use shorter sentences, name pages and artifacts by title or file name, and list links after the text.
Changed behavior
-
TaskOutput tool removed (changed)
The deprecated TaskOutput tool is gone; Claude reads a background task’s output file with Read instead. The
taskOutputMaxCharssetting andTASK_MAX_OUTPUT_LENGTHno longer have any effect. -
Subagent results (changed)
Subagent results reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent’s result cannot pass as the session’s own instructions. On Bedrock, Vertex and Foundry, workflow scripts’ computed
agent()prompts reach the subagent framed as script-authored text, so the safety classifier does not read them as the user. -
Bash sandbox instructions on Bedrock, Vertex and Foundry (changed)
They now use the first-party wording, which frames the sandbox as the boundary of what the task was given.
-
Fable in
/model(changed)Fable always appears in
/modelon the Anthropic API; it is greyed out only when your organization’s settings disable it. -
Non-interactive
/ultrareview(changed)It refuses when the repository has no base branch or shared history.
-
Auto-title request removed from
claude -p(changed)claude -pruns launched outside an SDK or IDE no longer send the background Haiku auto-title request. -
[Claude Code on the web] Organization environments and admin settings (changed)
On Team and Enterprise plans, organization environments open as a read-only summary from the Code tab, with editing under Admin settings → Cloud environments. The admin Claude Code setting labeled “Web” is now “Cloud sessions”, and the redundant read-only Mobile row beneath it is removed.
-
[Claude Tag] Pylon credential preset (changed)
Admins can point it at Pylon’s EU host.
Bug fixes
Headless & resume
claude -pand Agent SDK sessions hanging with no result after an internal error; they now report the error and exit with code 1.- Conversations failing every request with “text content blocks must be non-empty” when an earlier assistant turn held an empty text block beside other content, including after
--resume. - A headless resume (
claude -p --resume, the SDK, a VS Code extension window reload) starting cost and usage totals at zero; headless sessions now save their totals at exit. - Crashes when resuming a session whose saved history holds an assistant message stored as a plain string, or whose transcript contains a stop hook summary without a well-formed hook list.
- Sessions continued after
/clear(restart,--continue,--resume) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss. - Prompt cache misses on resume: resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, and earlier attachments being re-rendered after a resume or relaunch, which also dropped extended thinking.
- Messages typed while Claude is still working sometimes being ignored by the model.
Sign-in & config files
- Unexpected logouts when an older Claude Code build (for example an IDE extension’s bundled CLI) runs on the same machine as the current one.
- Malformed values in
~/.claude.json: interactive start-up hanging or erroring forANTHROPIC_API_KEYusers with a malformedcustomApiKeyResponses, a crash at launch with a malformedtheme, a “Type error” crash opening/mcpor/plugin managewith a malformedclaudeAiMcpEverConnected, and Remote Control session bookkeeping failing on a malformed placeholder record. - The error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with
/login. - Console sign-in showing only “Request failed with status code 400” when the server refuses to create an API key; it now shows the server’s message.
Updates
- Update checks erroring every 30 minutes, and
claude updatehanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformedminimumVersionis now ignored. claude updateon winget- or apk-managed installs reporting “up to date” when the version lookup failed.- Failed auto-updates leaving large staged downloads behind in
~/.cache/claude/staging.
Tools & sandbox
- Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so.
- The Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error.
- The Edit tool treating an escaped backslash followed by
uXXXXtext as a\uXXXXescape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead. - The Edit tool reporting “Invalid regular expression: regular expression too large” instead of “String not found in file” when a very large edit containing non-ASCII text did not match.
- A turn ending early with “Path contains null bytes” when a tool call’s file path contained
�written as an escape sequence; escaped control characters now stay as literal text. $TMPDIRexpanding empty in Bash commands that run outside the sandbox while sandboxing is enabled.- A
sandbox.excludedCommandsglob exempting an entire compound Bash command when only one part matched; every part must now match. - PDF page reads on Windows failing when the working folder’s path is long (about 120 characters or more).
- WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy.
- Rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again.
Rendering & input
- An “unrecoverable interface error” crash when the prompt held text containing terminal color codes, such as a prompt recalled from history or text loaded from the external editor.
- Sessions on slow or heavily loaded machines exiting with “Claude Code exited after an unrecoverable interface error” when the first spinner appeared, and a rare case where the screen stopped updating after an internal rendering error.
- A rare case on Windows where a turn stopped with an error such as “Out of memory” right after Claude replied, so that reply’s tool calls never ran.
- Messages from other agents (such as a subagent’s SendMessage) that arrived mid-turn showing up below the “Ran N shell commands” row instead of where they arrived.
- The “copied” notice not appearing after drag-selecting text in the fullscreen
/resumepicker and other panels that cover the prompt area. - Typed or pasted text coming out scrambled in the
claude agentsdispatch input during key repeat or very fast input. - Enter on a selected agent panel row doing nothing when
keybindings.jsonrebinds Enter in the Chat context, for example tochat:queueSubmit.
Plugins & skills
claude plugin installfailing and breaking the installed copy when reinstalling a plugin version a session or another program was using; an unchanged copy is now left alone.- One malformed
strictKnownMarketplacesorblockedMarketplacesentry silently disabling the whole enterprise marketplace policy. - Official-marketplace plugins recorded without their commit in
installed_plugins.json, and the file keeping the old commit after updating a pinned-commit plugin. /plugin→ Installed and/skillscrashing when a skill or legacy command is named like a built-in Object property such asconstructorortoString./pluginissues: uninstalled plugins reappearing as “failed to load” rows that Remove could not clear, closing with no message when every install in a multi-select failed, and not stripping terminal control characters from Installed tab messages.- Plugin reload previews keeping every previewed archive copy unpacked until exit, and overwriting the cached
--plugin-urlarchive a reload falls back to when its download fails. - Project skills from the main repository not loading in
--worktreesessions when.claude/skillsis untracked. - Background sessions (
claude --bg) exiting when a plugin’s LSP server exited or closed its stdin.
Claude apps gateway
- The telemetry relay ignoring a collector hostname or domain listed in
NO_PROXYwhen a proxy is set.
[VSCode]
- The “General config” menu row showing
/configusage text instead of opening settings; typed/mcp,/hooks,/memory,/rewindand similar commands now open their dialogs. - The effort slider’s level not persisting into later sessions on a model that already had a level saved with
/effort. - Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as “Sonnet”.
/fastnot saving fast mode as the default, so it was lost when the extension relaunched Claude Code.
[Claude Code on the web]
- A cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain.
[Claude Tag]
- Routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran.
- “Learn more” links on credential presets in access bundles now open each vendor’s credential-setup page instead of a generic API reference.
- Google Cloud credential forms in access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key.
- The network events log in admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA.
Notes
- AGENTS.md is read only when there is no CLAUDE.md — change this under “Project instructions” in
/config. Not yet on Bedrock, Vertex or Foundry. - TaskOutput is gone — the
taskOutputMaxCharssetting andTASK_MAX_OUTPUT_LENGTHno longer have any effect. sandbox.excludedCommandsis stricter — every part of a compound Bash command must match for it to be exempted from the sandbox.- Headless failures now exit with code 1 — scripts using
claude -por the Agent SDK can detect an internal error instead of waiting on a hang. - Prompts may be cleaned before sending — invisible Unicode formatting and tag characters are removed, and the cleaned prompt is shown for review.