claudekit / updates / claude-code-2-1-281
[ PATCH · ]

Claude Code 2.1.281

`"attribution": false` in `settings.json` hides all commit and PR attribution, MCP servers on 2026-07-28 protocol connections can open a browser-based flow through URL-mode elicitation, and `claude plugin validate` now checks MCP servers. A recursive `rm` whose target is only command-substitution output, such as `rm -rf "$(pwd)"`, no longer runs unprompted in auto mode. Fixes focus on resumed sessions re-sending earlier turns in a changed form, and responses cut short or tool calls run twice behind a proxy or gateway.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.281 shipped on September 23, 2026. New features cover hiding attribution, browser-based MCP flows, stricter plugin validation, and more Claude apps gateway settings for admins. Most of the fixes are about reliability: resumed sessions that lost prior reasoning or the prompt cache, and responses that were cut short, lost, or duplicated behind a proxy or gateway. On the permissions side, handling of dangerous rm commands is stricter.

New features

  • "attribution": false

    Hiding commit and PR attribution took the object form of the setting. Now "attribution": false in settings.json hides all of it. Older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions.

  • MCP URL-mode elicitation

    On 2026-07-28 protocol connections, MCP servers can ask Claude Code to open a browser-based flow. No waiting dialog is left on screen when the server has no way to confirm completion.

  • MCP server checks in claude plugin validate

    Broken .mcp.json entries in a plugin used to be dropped silently at load. The validator now reports entries that would be silently dropped, undeclared ${user_config.*} references, and insecure URLs. It also warns when a shell-form hook leaves ${CLAUDE_PLUGIN_ROOT} unquoted, which breaks on plugin paths with spaces.

  • Auto mode recommendation in /insights

    Estimates how many permission prompts auto mode could have handled in your recent sessions.

  • Claude apps gateway settings

    • Support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode
    • assume_role on Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developer
    • guardrail: {id, version} on Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)
    • telemetry.resource_attributes to put fixed labels on the telemetry of Claude Desktop and /login sessions
  • Scrollbars in fullscreen lists

    The /skills, /mcp and /plugin Installed lists get a scrollbar like the one in /workflows. It appears while the mouse is over the list and can be clicked or dragged.

  • [Claude Code on the web] Fast mode switch

    The composer’s model menu in cloud sessions gets a Fast mode switch, shown when your plan includes fast mode and the selected model supports it.

Key improvements

Resume & startup

  • Interactive startup time

    Git reads, startup telemetry and the Bedrock/Vertex model-upgrade checks no longer run before the first frame. Managed settings and policy fetches no longer retry requests that can never succeed.

  • Resuming long sessions

    Long sessions that read many files, and very long sessions that have been compacted, resume faster, most noticeably through the Agent SDK and Claude Desktop. The restored file cache now matches the files as they were read.

  • “Prompt is too long” recovery

    In sessions dominated by one very large first prompt, that prompt was left out of the summary. It is now summarized on its own.

Auto mode & permissions

  • Auto mode denial message

    Claude now treats a denial as covering the outcome, not only the exact command.

  • Wider dangerous-rm check

    Also flags a removal at a shell variable followed by a top-level directory name, at a variable derived from the working directory, or at a backslash-only target.

  • Classifier cache after resume

    After resuming a session in a new process, the permission classifier reuses its earlier prompt cache instead of rewriting it.

  • Sandbox guidance on macOS

    When a local dev server can’t bind a port, Claude points to sandbox.network.allowLocalBinding.

Commands & tools

  • --agents accepts a file path

    With -p, --agents accepts the path to a JSON file as well as inline JSON, and allows an empty prompt.

  • /batch with a WorktreeCreate hook

    /batch now runs where a WorktreeCreate hook provides the agent worktrees, not only inside a git repository.

  • Short names for claude.ai skills

    The / menu, /skills, /context and the /plugin Installed list show skills synced from claude.ai by their short name when no other command uses it, not anthropic-skills:<name>.

  • Large CLAUDE.md startup notice

    Now counts instruction files together, so many mid-sized files and @-imports are caught.

  • Plugin hook-failure errors

    Errors now name the offending plugin.

  • Artifact publishing

    Large page uploads are sent compressed on slow connections, and the bundled artifact-design skill asks Claude for plain, direct prose.

Lists & dialogs

  • Consistent keyboard navigation

    In tabbed dialogs such as /permissions and /usage, ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus. The /workflows and /mcp lists page with PgUp/PgDn and Home/End and take j/k and the mouse. /install-github-app, /desktop and the /plugin prompts use the standard dialog frame, and Ctrl+C or Ctrl+D cancels them on the second press.

  • List layout

    /plugin Installed rows line up in columns (status, name, type, details). /skills rows lead with the skill’s name, with ✔ or ◯ showing on or off. /diff gets a scrollbar for long lists of changed files, and /hooks says what kind of hook it is and where to change it.

  • Background workflow row

    The row below the prompt shows the name, a progress bar, the agent count on wide terminals, elapsed time, total tokens, and the large-workflow warning.

Changed behavior

  • Send now (changed)

    Send now (ctrl+enter or ctrl+x ctrl+s) moves running tools to the background instead of cancelling the turn.

  • Server-side auto mode review (changed)

    Where the classifier review runs server-side, read-only and sandboxed shell commands also wait for that review and are blocked when it flags them.

  • CLAUDE_CODE_AUTO_MODE_SERVER (changed)

    Now also applies on a direct Anthropic API connection: 0 opts out of the server-side auto mode classifier (the local classifier then counts toward usage), 1 opts in.

  • Dangerous rm prompt timeout (changed)

    In --dangerously-skip-permissions and auto mode, the prompt waits 2 minutes for an answer, then denies the command with a rewrite hint so unattended sessions keep going. CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1 turns this off.

  • Self-hosted runner system prompts (changed)

    Runners pass system prompts as private files instead of command-line text, so large prompts no longer fail the launch. A wrapper or command hook that appends --system-prompt or --append-system-prompt must switch to --system-prompt-file or --append-system-prompt-file.

  • Artifact links (changed)

    Session artifact links under the prompt become one footer pill (⧉ name or ⧉ N) that opens /artifacts, which lists this session’s artifacts first. The Artifact tool can load scripts from unpkg.com in artifact pages.

  • Queued messages (changed)

    Shown in the conversation above the spinner instead of under it.

  • Claude apps gateway envHelper paths (changed)

    The gateway refuses to start when a managedMcpServers entry’s envHelper path starts with \??\ or /??/, a path form current Claude Desktop refuses to run.

  • Stopping /ultrareview from /tasks (changed)

    Pressing x on a running /ultrareview asks for confirmation first.

  • [VSCode] Continue/Stop prompt for billed classifier requests (added)

    The VS Code and JetBrains panels show a Continue/Stop prompt when auto mode falls back to billed classifier requests, replacing the unanswerable warning line.

Bug fixes

Permissions & security

  • A recursive rm whose target is only command-substitution output, such as rm -rf "$(pwd)", running unprompted in auto and --dangerously-skip-permissions mode; it now asks even with a Bash allow rule, unless run with CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1.
  • A permission rule containing a NUL byte being expanded into a wildcard match; such a rule now matches nothing.
  • claude --bg starting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively.
  • --setting-sources (and SDK settingSources) not being forwarded to spawned sessions: teammates, /bg, claude agents sessions and --worktree --tmux now start with the parent’s restriction.
  • Permission dialogs and attachment checks reading a path under macOS’s /.vol, /.nofollow or /.resolve (which can reach a network mount) before approval.
  • Sandbox excludedCommands entries not matching git rev-parse --git-dir, programs named like shell builtins, and commit messages containing [WIP] or # lines, and sandboxed Bash commands being unable to write to $TMPDIR when CLAUDE_CODE_TMPDIR is set.

Resume & prompt cache

  • Resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call’s input, or a tool-search result), which could make the API drop the conversation’s prior reasoning.
  • Resuming a very large session sometimes restoring only its last few messages.
  • A session resumed after a restart during a pending permission prompt sending a different history, which broke the prompt cache from that point.
  • Resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden “Continue” message.
  • Sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once.
  • The prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway).

Proxies, gateways & API responses

  • Responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events.
  • Responses failing with “Content block not found” when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived.
  • An empty completed response being requested twice when the connection dropped before the stream’s final event, and the stop reason being lost when a proxy sends a trailing usage-only frame.
  • API errors from an HTML error page (such as a proxy’s 429 or 502 page) printing the page’s raw markup or leaving out the HTTP status.
  • CLAUDE_CODE_RETRY_WATCHDOG sessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a long Retry-After from a 5xx.
  • Fast mode retrying rate-limited requests back to back when the server sent Retry-After: 0.

Tool calls & session stability

  • A crash (“unrecoverable interface error”) that could end a session while an API request was being retried.
  • A turn that could retry indefinitely, ignoring --max-turns, when the model alternated unparseable tool calls and output-limit truncation.
  • Conversations getting permanently stuck on “tool_use.name: String should have at most 200 characters” after the model called a tool by an overlong name.
  • A tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message.
  • Tool calls failing with “Failed to get memory usage”, or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors.
  • Read, Write, Edit and NotebookEdit ending the whole turn on a file path containing a null byte; that tool call now fails with a clear error.
  • A delay of up to two minutes when reading or @-mentioning a PDF larger than 3 MB, and an interrupted Read of specific PDF pages leaving its page render running for up to two minutes.
  • Interactive startup waiting on the managed-settings network request (about 80 ms, 17+ seconds when the network is unreachable) when no MCP servers or plugins are configured.

Headless, SDK & remote sessions

  • --input-format stream-json sessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn when an earlier assistant message had plain-string content.
  • Non-interactive sessions (-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session.
  • Headless sessions with host-side (SDK) MCP servers stalling on the first message when the host stops responding mid-handshake; remote sessions now wait a few seconds at most.
  • CLAUDE.md and rules files from an --add-dir directory inside the working directory being sent to the model twice in headless and SDK sessions.
  • Scheduled tasks and /loop wakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turn.
  • Remote Control reporting “disabled by your organization’s policy” when the org policy simply hadn’t loaded yet; it now retries the fetch and says it couldn’t verify.
  • The Artifact tool missing from Remote Control sessions that claude remote-control starts for you.

Auth & MCP

  • macOS credential writes dropping stored MCP OAuth tokens or deleting the keychain entry when the login keychain was locked (e.g. right after wake).
  • The “Not logged in” footer and missing claude.ai connectors persisting after logging in from another Claude Code process.
  • gcpAuthRefresh/awsAuthRefresh login processes being left running (and holding their localhost callback port on Windows) when Claude Code exits or the refresh times out.
  • mcp_tool hooks on blocking events (PreToolUse and similar) being skipped while their MCP server was still connecting; they now wait for it, up to the MCP connect timeout.
  • The same MCP server being connected twice when a plugin or claude.ai connector and a configured server spell its URL differently (host letter case, default port, trailing slash), and MCP_CONNECTION_NONBLOCKING=0 giving up on claude.ai connectors after 1s instead of honoring MCP_CONNECT_TIMEOUT_MS.

Plugins

  • claude plugin uninstall refusing to remove a project-scope plugin that isn’t enabled, and claude plugin update failing for project-scoped plugins when --scope is omitted.
  • --plugin-dir on a folder of plugins that also has a .claude-plugin/marketplace.json loading one empty plugin instead of the plugins in it.
  • --channels plugin entries being checked against the installed plugin’s marketplace alone; the plugin’s name must now match as well.
  • claude plugin validate reporting privacyPolicyUrl, supportUrl and other listing metadata keys in plugin.json as unknown fields.
  • /plugin starting a second uninstall or update when Enter was pressed again, and a held y adding a marketplace the instant the “Add marketplace?” question appears.

Dialogs & keys

  • Ctrl+C or Ctrl+D pressed twice quitting Claude Code instead of closing the dialog in the remaining dialogs and pickers, such as /memory, /hooks, /mcp, /export, /copy, /theme, and /teleport’s prompts.
  • 1 answering Yes in /permissions’ delete and remove-directory confirms while the pointer is on No, which let a held 1 remove one workspace directory after another.
  • Pressing Shift+Tab twice quickly landing on the wrong permission mode.
  • Keys that arrive in one burst of input (e.g. over Remote Control) acting on the previous selection.
  • Alt+T and /config offering to turn thinking off on models that can’t, and /model showing the raw API error JSON when the API refuses the picked model.
  • Vim mode fixes: dj/dk/dG/dgg and their c/y forms acting on part of a line, 1G going to the last line, cw also changing the next word, and word motions stopping inside words in Hindi, Bengali and other scripts, among others.
  • /feedback, /bug and /share still sending your report after you cancelled it while it was being sent.

Windows

  • Bash commands that write to $TMPDIR/… failing with “Permission denied”.
  • A race in which sessions updating at the same moment could delete each other’s claude.exe backup, which could leave no claude.exe behind.

[VSCode]

  • A claude.ai/code session opening empty or with only part of its conversation, with no error, when its history failed to load; it now shows an error and can be opened again.
  • Conversations in editor tabs hanging silently after the extension host restarts; the tab now tells you to reopen it from the session list.
  • The session manager’s cost and usage block showing totals from a previous login after an account switch.

[Claude Code on the web]

  • Routines with a GitHub trigger for a pull request being converted to draft never firing.
  • Cloud sessions on a repository that isn’t hosted on GitHub showing a Create PR button that could never work.

[Claude Tag]

  • Slack channels where Claude could permanently stop responding to replies inside threads; affected channels recover with the next new message to Claude.
  • Claude resuming a stopped request after you press Stop in Slack, for example when a check-in fired or a background task ended.
  • Slack replies arriving many minutes late, or never, after Claude’s session crashed mid-task; it now restarts on its own within minutes.
  • A Slack request blocked by your organization’s inference hook showing a generic retry notice; the thread now shows the hook’s deny message and Claude doesn’t retry.
  • Claude offering to switch to models your organization can’t use, and “Couldn’t check this channel” answers in some Enterprise Grid setups.

[Code Review]

  • A pull request getting no review when its reviewed commit was force-pushed away while a failed review was being retried in a repository not set to review every push.

Notes

  • "attribution": false isn’t backward compatible — older CLI versions skip a settings file that holds it, so keep the object form in settings files shared across versions.
  • Self-hosted runner wrappers and hooks need updating — switch --system-prompt / --append-system-prompt to --system-prompt-file / --append-system-prompt-file.
  • Send now no longer cancels the turn — ctrl+enter or ctrl+x ctrl+s moves running tools to the background.
  • Unattended dangerous rm prompts are denied after 2 minutes — set CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1 to keep waiting as before.
  • Command-substitution rm targets now always prompt — even with a Bash allow rule; CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1 turns this off.
  • Running behind a proxy or gateway? — many fixes in this release address truncated responses, duplicated tool calls, and prompt-cache loss in that setup.