What changed
Claude Code 2.1.283 shipped on September 25, 2026. The headline additions are model controls for admins: an availableModels entry can now allow only the exact version it names, and deniedModels blocks specific models outright. A new /doctor prompt-audit checks your configuration for prompting patterns written for older models. Fixes cluster around MCP servers, installed_plugins.json and vim mode, and many lists and pickers gain page keys, mouse wheel and clicks. The claude-ai name reservation introduced in 2.1.282 is reverted.
New features
-
availableModelsMatchmanaged settingWith
"exact", anavailableModelsentry allows only the model version it names, so new releases stay blocked until listed. -
deniedModelsmanaged settingBlocks specific models, even when
availableModelsallows them. -
/doctor prompt-auditAlso available as
/checkup prompt-audit. Audits your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models. Stale paths, stale commands and contradicting instruction files lead the report, and thinking keywords that Claude Code documents are kept. -
x-claude-code-prompt-idgateway hint headerLets LLM gateways group the requests that serve one user prompt. Opt in with
CLAUDE_CODE_GATEWAY_HINT_HEADERS=1. -
MCP tool, WebFetch and WebSearch outputs in OpenTelemetry
These outputs are now added to the
tool.outputspan event whenOTEL_LOG_TOOL_CONTENT=1. -
Click-to-expand for messages from other sessions
In fullscreen mode, truncated messages from your other sessions can be expanded with a click.
-
pathinplugin_errors--plugin-dirload-failure entries in the stream-jsonsystem/initplugin_errorsnow includepath, naming the directory that did not load. -
Claude apps gateway additions
- An opt-in
load_test_modeblock: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested. - A
mantleupstream provider for Amazon Bedrock’s Mantle endpoint.
- An opt-in
-
[Claude Tag] Slack additions
- A “Channels Claude can search” admin setting that limits Claude’s Slack search to public channels it has been added to, set per organization, workspace or channel.
- A Back to Slack button on the page shown after connecting your Claude account, returning you to the thread you started from.
Key improvements
-
MCP tool images saved to a file
Images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them.
-
/mcptool listShows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon.
-
/tasksand other lists/tasksrows show a status icon, the name and whole facts, and the title and key hints stay on screen with many tasks. Lists in/help,/hooks,/copy,/chrome,/memory,/ide,/release-notes,/rewind,/diff,/remote-env,/pluginand other pickers gain page keys, mouse wheel and clicks. Lists beside a search box, such as/skillsand/artifacts, draw their pointer dim while the search box has the keys, so only one pointer is highlighted. -
Compaction spinner
The timer now starts when compaction begins and counts the summary’s tokens as they stream, replacing the percentage bar.
-
Latency and startup
- First-reply latency: a pattern-compile step that ran at the end of a session’s first reply now runs while the reply streams in.
- First-request latency: the preconnected API connection is reused.
claude -pand Claude Code Remote no longer load the interactive UI, and the auto-mode classifier’s rules and the Artifact tool load on first use instead of at launch.- For claude.ai accounts whose Artifact tool features aren’t known yet, as on a first run, the prompt no longer waits up to 1.5 s to check them; the first message waits if needed.
-
Skills from a plugin that failed to load
The Skill tool’s reply now lets Claude tell you the plugin could not be loaded, instead of calling the skill uninstalled.
-
Recovery from an unreadable
installed_plugins.jsonIts contents are kept in a file beside it before it is rebuilt, and
claude plugin listnames that file. -
Other improvements
- The browser page shown after signing in to an MCP server has a centered layout, dark mode and new artwork.
- Artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest.
- [Cloud sessions] Adding a repository to a running cloud session: a private repository your GitHub account can read but not push to now attaches for reading.
Changed behavior
-
Auto mode by default on third-party providers or with telemetry off (changed)
Interactive sessions on third-party providers or with telemetry off start in auto mode when no permission mode is configured.
permissions.defaultModestill overrides it. -
claude-ainame reservation reverted (changed)The 2.1.282 reservation is undone: skills, commands, workflows and MCP servers’ skills and prompts named
claude-aiload again, andSkill(claude-ai:*)rules are ordinary prefix rules. -
Skill(...)deny rules (changed)Skill(anthropic-skills:<name>)deny rules also block that skill when Claude Desktop delivers it as a plugin, andSkill(skill:<name>)denies match the skill’s alias and display name. -
--system-promptand--append-system-prompt(changed)Each accepts its text and
-fileforms together; the file’s text comes first. -
“(1M context)” in the
/modelpicker (changed)The Opus row and the Default model’s name drop “(1M context)” where Opus already has a 1M context window. The window is unchanged.
-
/ultrareviewlaunch dialog (changed)Now says that reviewing a local branch may upload uncommitted changes to tracked files.
-
Prompt suggestions (changed)
Terminal prompt suggestions appear less often after 20 in a row go unused; using one brings them back.
-
List keybindings and sizing (changed)
/rewindand/difflists move on the same keybinding actions as every other list (select:*);messageSelector:*/diff:*rebinds still work. The/workflowsrun list sizes itself like other lists: half the terminal inline, keeping its title on screen when the prompt shows below. -
claude plugin evalgit requirement (changed)Requires git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version.
-
Artifact watching (changed)
A watch that was armed automatically (not one you asked for) ends after 3.5 hours with no activity. Publishing or watching the artifact again re-arms it.
-
Self-hosted runner git (changed)
- Lifecycle hooks’ git skips a repository’s Git LFS
pre-pushhook, ignores a writable systemcore.hooksPath, and does not sign commits without--configure-git. - Under Anthropic-managed git, the runner’s own git always verifies Anthropic’s git route regardless of
GIT_SSL_CAINFOandGIT_SSL_NO_VERIFY, and warning lines say what applies where.
- Lifecycle hooks’ git skips a repository’s Git LFS
-
[Cloud sessions] Default routine schedule (changed)
New routine schedules default to a few minutes past the hour, with a note that routines set exactly on the hour can start several minutes late.
Bug fixes
MCP servers
- MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress.
- stdio MCP servers being left running when the session ended while they were still starting.
- A brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected.
- MCP sign-in for a server with no valid URL failing with an opaque SDK error;
/mcpno longer offers Authenticate for such servers. claude mcp add,add-jsonandremovereporting success when the user or local config file could not be written, for example inside a sandbox./contextnot counting MCP server instructions; they now appear as their own row and count toward the total.
Models & usage
- The weekly Fable limit not appearing in
/usageand the VS Code usage meters when telemetry is disabled. /modelaccepting Sonnet 4.6 or Sonnet 5 with[1m]when the id carried a date or-v1:0suffix, in the cases where the plain id was refused.- The
/modelpicker showing a hardcoded Haiku version and price whenANTHROPIC_DEFAULT_HAIKU_MODELpins a different model. - Dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model.
DISABLE_PROMPT_CACHING_HAIKUhaving no effect when Haiku is the session’s main model.
Plugins
claude plugin validatesaying Claude Code accepts a plugin or marketplace name it cannot install; such names inmarketplace.jsonnow fail validation.claude plugin validatepassing plugins whoseoutputStyles,themes,monitorsorlspServerspaths are missing or point outside the plugin directory.claude plugin detailsshowing 0 MCP servers for plugins that declare their servers inplugin.json.claude plugin marketplace removenot saying which installed plugins it uninstalled with the marketplace; it now lists them.claude plugin uninstallremoving the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had noenabledPluginsentry at that scope.- Plugins that declare no version being silently restored at their source’s newest commit, not the installed one, when their cached files were missing.
- User-installed plugins and marketplaces failing to load with “cache-miss” after the home or config directory was moved, for example in bind-mounted devcontainers.
installed_plugins.jsonshowing no plugins when it holds a record under an invalid plugin id; such a file loads again.installed_plugins.jsonbeing rewritten, losing records, when it holds a record this version cannot read;claude plugincommands now name the record and say how to recover.
SDK & Remote Control
- SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback’s
result.usage. - Remote Control being unavailable on paid plans when telemetry is turned off with
DISABLE_TELEMETRYorDO_NOT_TRACK. - The
/remote-controlmenu cutting its QR-code hint mid-word in narrow terminals.
Sandbox, permissions & safety
- Windows: the PowerShell tool letting
cmd /c rd,rmdir,delorerasedelete drive roots, the home folder and other folders thatRemove-Itemrefuses. - Managed
sandboxsettings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies. - Sandboxed
gitasking credential helpers to store the sandbox proxy’s login, which printed “failed to store”. - Worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as
GIT_CONFIG_COUNTenvironment pairs. - Claude’s edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository.
- Permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog’s own text.
Keybindings & input
- Claude’s built-in keybindings guide saying chords time out after 1 second instead of 3, and calling
cmdan alias ofmeta, which could producecmd+shortcuts most terminals never send. keybindings.jsonsilently accepting a misspelled modifier such asctl+k; it now warns in the debug log and suggests the fix.- Footer hints still saying “Enter to view” after
footer:openSelectedwas rebound or unbound inkeybindings.json. - Keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state.
- Markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks.
- The first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them.
Vim mode
.dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after3Jor Visual-modeJon the last line.- Cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and
Vthenpnow lands on the first non-blank. Jjoining lines with different spacing than Vim (such as a space before)or after a tab), and3Jor Visual-modeJon the last line not moving the cursor as Vim does.
[VSCode]
- The permission mode indicator showing Default while the session kept running in auto or bypass mode after an automatic switch out of it failed; the switch is now retried until it lands.
- A session teleported from the web dropping the messages sent while Claude was working.
- A Web session staying hidden from the session list, and an empty chat opening in its place, when an older version had saved an empty local copy of it.
- A reopened session splitting a turn at a message Claude received mid-turn, such as an automatic continuation, and a reloaded session showing a rewound-away turn, or only the rows before a compaction.
- The footer’s agents pill drawing its icon off-center, with the status dot against the edge, in narrow panels.
- The chat input showing its text slightly below the cursor and selection after pasting lines that end with a line break into a long prompt.
[Cloud sessions]
- Cloud sessions occasionally redoing an already-finished step, such as posting a duplicate comment or push, after recovering from a server-side restart.
[Claude Tag]
- A channel’s configure page listing no connectors or plugins when the channel gets its access bundle through an attach rule; rule-attached bundles are now shown.
- Access-bundle repository search missing repositories on GitHub App installs that are limited to a large list of selected repositories.
- Claude occasionally posting the same reply twice when a new message interrupted it mid-reply.
- Channel routines that stopped running in older private channels whose Slack channel ID changed, for example after a Slack Connect share.
- Conversations in a channel set to “Channel only” all ending when a non-guest member joined and Slack was slow to confirm their membership.
[Code Review]
- “@claude review” requests going silent when GitHub failed to return the pull request; the request is retried once, and a comment explains if it still fails.
- Billing for a review that stopped at its time limit with nothing verified; it now shows as incomplete, isn’t charged, and is retried once.
Notes
- Pin model versions with
availableModelsMatch: "exact"— with it, new model releases stay blocked until you add them toavailableModels. UsedeniedModelsto block a model thatavailableModelswould otherwise allow. - Third-party provider and telemetry-off sessions now start in auto mode when no permission mode is configured — set
permissions.defaultModeto keep a different default. - The
claude-ainame is usable again — the 2.1.282 reservation is reverted, so skills, commands and MCP servers under that name don’t need renaming. This release does not revert theanthropic-skillsrestrictions. - Try
/doctor prompt-auditon your configuration — it flags prompting patterns written for older models, plus stale paths, stale commands and contradicting instruction files. claude plugin evalneeds git 2.31 or later when git is installed.