What changed
Claude Code 2.1.281 shipped on September 23, 2026. New features cover hiding attribution, browser-based MCP flows, stricter plugin validation, and more Claude apps gateway settings for admins. Most of the fixes are about reliability: resumed sessions that lost prior reasoning or the prompt cache, and responses that were cut short, lost, or duplicated behind a proxy or gateway. On the permissions side, handling of dangerous rm commands is stricter.
New features
-
"attribution": falseHiding commit and PR attribution took the object form of the setting. Now
"attribution": falseinsettings.jsonhides all of it. Older CLI versions skip a settings file that holds it, so keep the object form in files shared across versions. -
MCP URL-mode elicitation
On 2026-07-28 protocol connections, MCP servers can ask Claude Code to open a browser-based flow. No waiting dialog is left on screen when the server has no way to confirm completion.
-
MCP server checks in
claude plugin validateBroken
.mcp.jsonentries in a plugin used to be dropped silently at load. The validator now reports entries that would be silently dropped, undeclared${user_config.*}references, and insecure URLs. It also warns when a shell-form hook leaves${CLAUDE_PLUGIN_ROOT}unquoted, which breaks on plugin paths with spaces. -
Auto mode recommendation in
/insightsEstimates how many permission prompts auto mode could have handled in your recent sessions.
-
Claude apps gateway settings
- Support for newer Claude Desktop keys in
desktoppolicy blocks, includingblockReadsOutsideWorkingDirectoriesanddisableBypassPermissionsMode assume_roleon Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, optionally one session per developerguardrail: {id, version}on Bedrock upstreams to apply an Amazon Bedrock guardrail to every request sent through them (set it on all Bedrock upstreams or none)telemetry.resource_attributesto put fixed labels on the telemetry of Claude Desktop and/loginsessions
- Support for newer Claude Desktop keys in
-
Scrollbars in fullscreen lists
The
/skills,/mcpand/pluginInstalled lists get a scrollbar like the one in/workflows. It appears while the mouse is over the list and can be clicked or dragged. -
[Claude Code on the web] Fast mode switch
The composer’s model menu in cloud sessions gets a Fast mode switch, shown when your plan includes fast mode and the selected model supports it.
Key improvements
Resume & startup
-
Interactive startup time
Git reads, startup telemetry and the Bedrock/Vertex model-upgrade checks no longer run before the first frame. Managed settings and policy fetches no longer retry requests that can never succeed.
-
Resuming long sessions
Long sessions that read many files, and very long sessions that have been compacted, resume faster, most noticeably through the Agent SDK and Claude Desktop. The restored file cache now matches the files as they were read.
-
“Prompt is too long” recovery
In sessions dominated by one very large first prompt, that prompt was left out of the summary. It is now summarized on its own.
Auto mode & permissions
-
Auto mode denial message
Claude now treats a denial as covering the outcome, not only the exact command.
-
Wider dangerous-rm check
Also flags a removal at a shell variable followed by a top-level directory name, at a variable derived from the working directory, or at a backslash-only target.
-
Classifier cache after resume
After resuming a session in a new process, the permission classifier reuses its earlier prompt cache instead of rewriting it.
-
Sandbox guidance on macOS
When a local dev server can’t bind a port, Claude points to
sandbox.network.allowLocalBinding.
Commands & tools
-
--agentsaccepts a file pathWith
-p,--agentsaccepts the path to a JSON file as well as inline JSON, and allows an emptyprompt. -
/batchwith a WorktreeCreate hook/batchnow runs where a WorktreeCreate hook provides the agent worktrees, not only inside a git repository. -
Short names for claude.ai skills
The
/menu,/skills,/contextand the/pluginInstalled list show skills synced from claude.ai by their short name when no other command uses it, notanthropic-skills:<name>. -
Large CLAUDE.md startup notice
Now counts instruction files together, so many mid-sized files and @-imports are caught.
-
Plugin hook-failure errors
Errors now name the offending plugin.
-
Artifact publishing
Large page uploads are sent compressed on slow connections, and the bundled artifact-design skill asks Claude for plain, direct prose.
Lists & dialogs
-
Consistent keyboard navigation
In tabbed dialogs such as
/permissionsand/usage, ↑/↓ move focus between the tab row and the content, and a list responds to keys only while it has focus. The/workflowsand/mcplists page with PgUp/PgDn and Home/End and take j/k and the mouse./install-github-app,/desktopand the/pluginprompts use the standard dialog frame, and Ctrl+C or Ctrl+D cancels them on the second press. -
List layout
/pluginInstalled rows line up in columns (status, name, type, details)./skillsrows lead with the skill’s name, with ✔ or ◯ showing on or off./diffgets a scrollbar for long lists of changed files, and/hookssays what kind of hook it is and where to change it. -
Background workflow row
The row below the prompt shows the name, a progress bar, the agent count on wide terminals, elapsed time, total tokens, and the large-workflow warning.
Changed behavior
-
Send now (changed)
Send now (ctrl+enter or ctrl+x ctrl+s) moves running tools to the background instead of cancelling the turn.
-
Server-side auto mode review (changed)
Where the classifier review runs server-side, read-only and sandboxed shell commands also wait for that review and are blocked when it flags them.
-
CLAUDE_CODE_AUTO_MODE_SERVER(changed)Now also applies on a direct Anthropic API connection:
0opts out of the server-side auto mode classifier (the local classifier then counts toward usage),1opts in. -
Dangerous
rmprompt timeout (changed)In
--dangerously-skip-permissionsand auto mode, the prompt waits 2 minutes for an answer, then denies the command with a rewrite hint so unattended sessions keep going.CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1turns this off. -
Self-hosted runner system prompts (changed)
Runners pass system prompts as private files instead of command-line text, so large prompts no longer fail the launch. A wrapper or
commandhook that appends--system-promptor--append-system-promptmust switch to--system-prompt-fileor--append-system-prompt-file. -
Artifact links (changed)
Session artifact links under the prompt become one footer pill (
⧉ nameor⧉ N) that opens/artifacts, which lists this session’s artifacts first. The Artifact tool can load scripts from unpkg.com in artifact pages. -
Queued messages (changed)
Shown in the conversation above the spinner instead of under it.
-
Claude apps gateway
envHelperpaths (changed)The gateway refuses to start when a
managedMcpServersentry’senvHelperpath starts with\??\or/??/, a path form current Claude Desktop refuses to run. -
Stopping
/ultrareviewfrom/tasks(changed)Pressing
xon a running/ultrareviewasks for confirmation first. -
[VSCode] Continue/Stop prompt for billed classifier requests (added)
The VS Code and JetBrains panels show a Continue/Stop prompt when auto mode falls back to billed classifier requests, replacing the unanswerable warning line.
Bug fixes
Permissions & security
- A recursive
rmwhose target is only command-substitution output, such asrm -rf "$(pwd)", running unprompted in auto and--dangerously-skip-permissionsmode; it now asks even with a Bash allow rule, unless run withCLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1. - A permission rule containing a NUL byte being expanded into a wildcard match; such a rule now matches nothing.
claude --bgstarting a background session, and running its project hooks, in a directory that had not passed the workspace trust prompt; it now asks for trust first, or exits when not run interactively.--setting-sources(and SDKsettingSources) not being forwarded to spawned sessions: teammates,/bg,claude agentssessions and--worktree --tmuxnow start with the parent’s restriction.- Permission dialogs and attachment checks reading a path under macOS’s
/.vol,/.nofollowor/.resolve(which can reach a network mount) before approval. - Sandbox
excludedCommandsentries not matchinggit rev-parse --git-dir, programs named like shell builtins, and commit messages containing[WIP]or#lines, and sandboxed Bash commands being unable to write to$TMPDIRwhenCLAUDE_CODE_TMPDIRis set.
Resume & prompt cache
- Resumed sessions re-sending earlier turns in a changed form (a parallel tool-call turn, an MCP tool call’s input, or a tool-search result), which could make the API drop the conversation’s prior reasoning.
- Resuming a very large session sometimes restoring only its last few messages.
- A session resumed after a restart during a pending permission prompt sending a different history, which broke the prompt cache from that point.
- Resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and a manual resume no longer adds a hidden “Continue” message.
- Sessions with an earlier advisor result the API could no longer read failing one request every turn and repeatedly losing earlier reasoning; the history is now repaired once.
- The prompt cache being lost when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (for example behind a proxy or gateway).
Proxies, gateways & API responses
- Responses cut short by a proxy or gateway that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events.
- Responses failing with “Content block not found” when a proxy drops a stream event mid-response; the partial response is now kept, and web search keeps results that already arrived.
- An empty completed response being requested twice when the connection dropped before the stream’s final event, and the stop reason being lost when a proxy sends a trailing usage-only frame.
- API errors from an HTML error page (such as a proxy’s 429 or 502 page) printing the page’s raw markup or leaving out the HTTP status.
CLAUDE_CODE_RETRY_WATCHDOGsessions failing on the first 5xx or dropped connection after a run of 429/529 waits, and sleeping uncapped and silently on a longRetry-Afterfrom a 5xx.- Fast mode retrying rate-limited requests back to back when the server sent
Retry-After: 0.
Tool calls & session stability
- A crash (“unrecoverable interface error”) that could end a session while an API request was being retried.
- A turn that could retry indefinitely, ignoring
--max-turns, when the model alternated unparseable tool calls and output-limit truncation. - Conversations getting permanently stuck on “tool_use.name: String should have at most 200 characters” after the model called a tool by an overlong name.
- A tool that returned an oversized image leaving sibling tool calls unanswered and still running, or ending the turn with no final message.
- Tool calls failing with “Failed to get memory usage”, or being reported as failed after they ran, when Claude Code cannot read its own memory usage, for example when it has run out of file descriptors.
- Read, Write, Edit and NotebookEdit ending the whole turn on a file path containing a null byte; that tool call now fails with a clear error.
- A delay of up to two minutes when reading or @-mentioning a PDF larger than 3 MB, and an interrupted Read of specific PDF pages leaving its page render running for up to two minutes.
- Interactive startup waiting on the managed-settings network request (about 80 ms, 17+ seconds when the network is unreachable) when no MCP servers or plugins are configured.
Headless, SDK & remote sessions
--input-format stream-jsonsessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn when an earlier assistant message had plain-string content.- Non-interactive sessions (
-p, Agent SDK) failing on the next turn after the directory they were started in was deleted mid-session. - Headless sessions with host-side (SDK) MCP servers stalling on the first message when the host stops responding mid-handshake; remote sessions now wait a few seconds at most.
- CLAUDE.md and rules files from an
--add-dirdirectory inside the working directory being sent to the model twice in headless and SDK sessions. - Scheduled tasks and
/loopwakeups being fired again every second when their delivery failed, which could make Claude Code exit at the end of a turn. - Remote Control reporting “disabled by your organization’s policy” when the org policy simply hadn’t loaded yet; it now retries the fetch and says it couldn’t verify.
- The Artifact tool missing from Remote Control sessions that
claude remote-controlstarts for you.
Auth & MCP
- macOS credential writes dropping stored MCP OAuth tokens or deleting the keychain entry when the login keychain was locked (e.g. right after wake).
- The “Not logged in” footer and missing claude.ai connectors persisting after logging in from another Claude Code process.
gcpAuthRefresh/awsAuthRefreshlogin processes being left running (and holding their localhost callback port on Windows) when Claude Code exits or the refresh times out.mcp_toolhooks on blocking events (PreToolUse and similar) being skipped while their MCP server was still connecting; they now wait for it, up to the MCP connect timeout.- The same MCP server being connected twice when a plugin or claude.ai connector and a configured server spell its URL differently (host letter case, default port, trailing slash), and
MCP_CONNECTION_NONBLOCKING=0giving up on claude.ai connectors after 1s instead of honoringMCP_CONNECT_TIMEOUT_MS.
Plugins
claude plugin uninstallrefusing to remove a project-scope plugin that isn’t enabled, andclaude plugin updatefailing for project-scoped plugins when--scopeis omitted.--plugin-diron a folder of plugins that also has a.claude-plugin/marketplace.jsonloading one empty plugin instead of the plugins in it.--channelsplugin entries being checked against the installed plugin’s marketplace alone; the plugin’s name must now match as well.claude plugin validatereportingprivacyPolicyUrl,supportUrland other listing metadata keys in plugin.json as unknown fields./pluginstarting a second uninstall or update when Enter was pressed again, and a heldyadding a marketplace the instant the “Add marketplace?” question appears.
Dialogs & keys
- Ctrl+C or Ctrl+D pressed twice quitting Claude Code instead of closing the dialog in the remaining dialogs and pickers, such as
/memory,/hooks,/mcp,/export,/copy,/theme, and/teleport’s prompts. 1answering Yes in/permissions’ delete and remove-directory confirms while the pointer is on No, which let a held1remove one workspace directory after another.- Pressing Shift+Tab twice quickly landing on the wrong permission mode.
- Keys that arrive in one burst of input (e.g. over Remote Control) acting on the previous selection.
- Alt+T and
/configoffering to turn thinking off on models that can’t, and/modelshowing the raw API error JSON when the API refuses the picked model. - Vim mode fixes:
dj/dk/dG/dggand theirc/yforms acting on part of a line,1Ggoing to the last line,cwalso changing the next word, and word motions stopping inside words in Hindi, Bengali and other scripts, among others. - /feedback, /bug and /share still sending your report after you cancelled it while it was being sent.
Windows
- Bash commands that write to
$TMPDIR/…failing with “Permission denied”. - A race in which sessions updating at the same moment could delete each other’s
claude.exebackup, which could leave noclaude.exebehind.
[VSCode]
- A claude.ai/code session opening empty or with only part of its conversation, with no error, when its history failed to load; it now shows an error and can be opened again.
- Conversations in editor tabs hanging silently after the extension host restarts; the tab now tells you to reopen it from the session list.
- The session manager’s cost and usage block showing totals from a previous login after an account switch.
[Claude Code on the web]
- Routines with a GitHub trigger for a pull request being converted to draft never firing.
- Cloud sessions on a repository that isn’t hosted on GitHub showing a Create PR button that could never work.
[Claude Tag]
- Slack channels where Claude could permanently stop responding to replies inside threads; affected channels recover with the next new message to Claude.
- Claude resuming a stopped request after you press Stop in Slack, for example when a check-in fired or a background task ended.
- Slack replies arriving many minutes late, or never, after Claude’s session crashed mid-task; it now restarts on its own within minutes.
- A Slack request blocked by your organization’s inference hook showing a generic retry notice; the thread now shows the hook’s deny message and Claude doesn’t retry.
- Claude offering to switch to models your organization can’t use, and “Couldn’t check this channel” answers in some Enterprise Grid setups.
[Code Review]
- A pull request getting no review when its reviewed commit was force-pushed away while a failed review was being retried in a repository not set to review every push.
Notes
"attribution": falseisn’t backward compatible — older CLI versions skip a settings file that holds it, so keep the object form in settings files shared across versions.- Self-hosted runner wrappers and hooks need updating — switch
--system-prompt/--append-system-promptto--system-prompt-file/--append-system-prompt-file. - Send now no longer cancels the turn — ctrl+enter or ctrl+x ctrl+s moves running tools to the background.
- Unattended dangerous
rmprompts are denied after 2 minutes — setCLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1to keep waiting as before. - Command-substitution
rmtargets now always prompt — even with a Bash allow rule;CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT=1turns this off. - Running behind a proxy or gateway? — many fixes in this release address truncated responses, duplicated tool calls, and prompt-cache loss in that setup.