claudekit / updates / claude-code-2-1-283
[ PATCH · ]

Claude Code 2.1.283

New `availableModelsMatch` and `deniedModels` managed settings let organizations pin allowed models to exact versions and block specific models, and `/doctor prompt-audit` audits CLAUDE.md files, skills, agents and commands for prompting patterns written for older models. Fixes focus on MCP server reliability, `installed_plugins.json` handling and vim mode, and the 2.1.282 reservation of the `claude-ai` name is reverted.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.283 shipped on September 25, 2026. The headline additions are model controls for admins: an availableModels entry can now allow only the exact version it names, and deniedModels blocks specific models outright. A new /doctor prompt-audit checks your configuration for prompting patterns written for older models. Fixes cluster around MCP servers, installed_plugins.json and vim mode, and many lists and pickers gain page keys, mouse wheel and clicks. The claude-ai name reservation introduced in 2.1.282 is reverted.

New features

  • availableModelsMatch managed setting

    With "exact", an availableModels entry allows only the model version it names, so new releases stay blocked until listed.

  • deniedModels managed setting

    Blocks specific models, even when availableModels allows them.

  • /doctor prompt-audit

    Also available as /checkup prompt-audit. Audits your CLAUDE.md files, skills, agents and commands for prompting patterns written for older models. Stale paths, stale commands and contradicting instruction files lead the report, and thinking keywords that Claude Code documents are kept.

  • x-claude-code-prompt-id gateway hint header

    Lets LLM gateways group the requests that serve one user prompt. Opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1.

  • MCP tool, WebFetch and WebSearch outputs in OpenTelemetry

    These outputs are now added to the tool.output span event when OTEL_LOG_TOOL_CONTENT=1.

  • Click-to-expand for messages from other sessions

    In fullscreen mode, truncated messages from your other sessions can be expanded with a click.

  • path in plugin_errors

    --plugin-dir load-failure entries in the stream-json system/init plugin_errors now include path, naming the directory that did not load.

  • Claude apps gateway additions

    • An opt-in load_test_mode block: requests are built and signed but not sent upstream, and clients get a canned reply, so a deployment can be load tested.
    • A mantle upstream provider for Amazon Bedrock’s Mantle endpoint.
  • [Claude Tag] Slack additions

    • A “Channels Claude can search” admin setting that limits Claude’s Slack search to public channels it has been added to, set per organization, workspace or channel.
    • A Back to Slack button on the page shown after connecting your Claude account, returning you to the thread you started from.

Key improvements

  • MCP tool images saved to a file

    Images returned by MCP tools are now also saved to a file, so Bash, Read and other tools can open them.

  • /mcp tool list

    Shows more tools at once, scrolls with the page keys and mouse, and marks tools your organization blocked with a warning icon.

  • /tasks and other lists

    /tasks rows show a status icon, the name and whole facts, and the title and key hints stay on screen with many tasks. Lists in /help, /hooks, /copy, /chrome, /memory, /ide, /release-notes, /rewind, /diff, /remote-env, /plugin and other pickers gain page keys, mouse wheel and clicks. Lists beside a search box, such as /skills and /artifacts, draw their pointer dim while the search box has the keys, so only one pointer is highlighted.

  • Compaction spinner

    The timer now starts when compaction begins and counts the summary’s tokens as they stream, replacing the percentage bar.

  • Latency and startup

    • First-reply latency: a pattern-compile step that ran at the end of a session’s first reply now runs while the reply streams in.
    • First-request latency: the preconnected API connection is reused.
    • claude -p and Claude Code Remote no longer load the interactive UI, and the auto-mode classifier’s rules and the Artifact tool load on first use instead of at launch.
    • For claude.ai accounts whose Artifact tool features aren’t known yet, as on a first run, the prompt no longer waits up to 1.5 s to check them; the first message waits if needed.
  • Skills from a plugin that failed to load

    The Skill tool’s reply now lets Claude tell you the plugin could not be loaded, instead of calling the skill uninstalled.

  • Recovery from an unreadable installed_plugins.json

    Its contents are kept in a file beside it before it is rebuilt, and claude plugin list names that file.

  • Other improvements

    • The browser page shown after signing in to an MCP server has a centered layout, dark mode and new artwork.
    • Artifact database reads: an ordered query that returns a full page now says it is one page and how to read the rest.
    • [Cloud sessions] Adding a repository to a running cloud session: a private repository your GitHub account can read but not push to now attaches for reading.

Changed behavior

  • Auto mode by default on third-party providers or with telemetry off (changed)

    Interactive sessions on third-party providers or with telemetry off start in auto mode when no permission mode is configured. permissions.defaultMode still overrides it.

  • claude-ai name reservation reverted (changed)

    The 2.1.282 reservation is undone: skills, commands, workflows and MCP servers’ skills and prompts named claude-ai load again, and Skill(claude-ai:*) rules are ordinary prefix rules.

  • Skill(...) deny rules (changed)

    Skill(anthropic-skills:<name>) deny rules also block that skill when Claude Desktop delivers it as a plugin, and Skill(skill:<name>) denies match the skill’s alias and display name.

  • --system-prompt and --append-system-prompt (changed)

    Each accepts its text and -file forms together; the file’s text comes first.

  • “(1M context)” in the /model picker (changed)

    The Opus row and the Default model’s name drop “(1M context)” where Opus already has a 1M context window. The window is unchanged.

  • /ultrareview launch dialog (changed)

    Now says that reviewing a local branch may upload uncommitted changes to tracked files.

  • Prompt suggestions (changed)

    Terminal prompt suggestions appear less often after 20 in a row go unused; using one brings them back.

  • List keybindings and sizing (changed)

    /rewind and /diff lists move on the same keybinding actions as every other list (select:*); messageSelector:*/diff:* rebinds still work. The /workflows run list sizes itself like other lists: half the terminal inline, keeping its title on screen when the prompt shows below.

  • claude plugin eval git requirement (changed)

    Requires git 2.31 or later when git is installed; a run on an older git is refused with a message naming the version.

  • Artifact watching (changed)

    A watch that was armed automatically (not one you asked for) ends after 3.5 hours with no activity. Publishing or watching the artifact again re-arms it.

  • Self-hosted runner git (changed)

    • Lifecycle hooks’ git skips a repository’s Git LFS pre-push hook, ignores a writable system core.hooksPath, and does not sign commits without --configure-git.
    • Under Anthropic-managed git, the runner’s own git always verifies Anthropic’s git route regardless of GIT_SSL_CAINFO and GIT_SSL_NO_VERIFY, and warning lines say what applies where.
  • [Cloud sessions] Default routine schedule (changed)

    New routine schedules default to a few minutes past the hour, with a note that routines set exactly on the hour can start several minutes late.

Bug fixes

MCP servers

  • MCP progress notifications being discarded once a long-running tool call moved to the background; the background task now shows the latest progress.
  • stdio MCP servers being left running when the session ended while they were still starting.
  • A brief HTTP 404 from a stateless remote MCP server (for example a proxy mid-redeploy) leaving that server unusable for the rest of the session while still shown as connected.
  • MCP sign-in for a server with no valid URL failing with an opaque SDK error; /mcp no longer offers Authenticate for such servers.
  • claude mcp add, add-json and remove reporting success when the user or local config file could not be written, for example inside a sandbox.
  • /context not counting MCP server instructions; they now appear as their own row and count toward the total.

Models & usage

  • The weekly Fable limit not appearing in /usage and the VS Code usage meters when telemetry is disabled.
  • /model accepting Sonnet 4.6 or Sonnet 5 with [1m] when the id carried a date or -v1:0 suffix, in the cases where the plain id was refused.
  • The /model picker showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins a different model.
  • Dynamic workflows started during a model fallback running every agent on the fallback model instead of retrying the configured model.
  • DISABLE_PROMPT_CACHING_HAIKU having no effect when Haiku is the session’s main model.

Plugins

  • claude plugin validate saying Claude Code accepts a plugin or marketplace name it cannot install; such names in marketplace.json now fail validation.
  • claude plugin validate passing plugins whose outputStyles, themes, monitors or lspServers paths are missing or point outside the plugin directory.
  • claude plugin details showing 0 MCP servers for plugins that declare their servers in plugin.json.
  • claude plugin marketplace remove not saying which installed plugins it uninstalled with the marketplace; it now lists them.
  • claude plugin uninstall removing the other of two installed plugins whose ids differ only in case, with its options and secrets, when the one named had no enabledPlugins entry at that scope.
  • Plugins that declare no version being silently restored at their source’s newest commit, not the installed one, when their cached files were missing.
  • User-installed plugins and marketplaces failing to load with “cache-miss” after the home or config directory was moved, for example in bind-mounted devcontainers.
  • installed_plugins.json showing no plugins when it holds a record under an invalid plugin id; such a file loads again.
  • installed_plugins.json being rewritten, losing records, when it holds a record this version cannot read; claude plugin commands now name the record and say how to recover.

SDK & Remote Control

  • SDK sessions losing a deferred tool call or finished tool result when a turn ended early, a held approval prompt after a worker restart, and a non-streaming fallback’s result.usage.
  • Remote Control being unavailable on paid plans when telemetry is turned off with DISABLE_TELEMETRY or DO_NOT_TRACK.
  • The /remote-control menu cutting its QR-code hint mid-word in narrow terminals.

Sandbox, permissions & safety

  • Windows: the PowerShell tool letting cmd /c rd, rmdir, del or erase delete drive roots, the home folder and other folders that Remove-Item refuses.
  • Managed sandbox settings being ignored entirely when one nested value was invalid; the invalid value now fails closed and the rest of the block still applies.
  • Sandboxed git asking credential helpers to store the sandbox proxy’s login, which printed “failed to store”.
  • Worktree checkouts failing certificate verification (for example on Git LFS downloads) when the CA certificate is passed to git as GIT_CONFIG_COUNT environment pairs.
  • Claude’s edits to its own auto-memory notes being blocked as sensitive-file writes when Claude Code was started in a subdirectory of a git repository.
  • Permission dialogs in screen-reader mode reading quoted commands and paths as if they were the dialog’s own text.

Keybindings & input

  • Claude’s built-in keybindings guide saying chords time out after 1 second instead of 3, and calling cmd an alias of meta, which could produce cmd+ shortcuts most terminals never send.
  • keybindings.json silently accepting a misspelled modifier such as ctl+k; it now warns in the debug log and suggests the fix.
  • Footer hints still saying “Enter to view” after footer:openSelected was rebound or unbound in keybindings.json.
  • Keys typed quickly together (type-ahead, key repeat, bursts over ssh or tmux) sometimes being handled against stale state.
  • Markdown links in the Warp terminal rendering as plain text instead of clickable hyperlinks.
  • The first words of a reply in a cloud session sometimes appearing late instead of streaming as Claude writes them.

Vim mode

  • . dropping a Shift+Enter newline, leaving the cursor inside an accented letter, and repeating an older change after 3J or Visual-mode J on the last line.
  • Cursor placement: recalling a prompt over 10,000 characters in normal mode no longer leaves the cursor past the end, and V then p now lands on the first non-blank.
  • J joining lines with different spacing than Vim (such as a space before ) or after a tab), and 3J or Visual-mode J on the last line not moving the cursor as Vim does.

[VSCode]

  • The permission mode indicator showing Default while the session kept running in auto or bypass mode after an automatic switch out of it failed; the switch is now retried until it lands.
  • A session teleported from the web dropping the messages sent while Claude was working.
  • A Web session staying hidden from the session list, and an empty chat opening in its place, when an older version had saved an empty local copy of it.
  • A reopened session splitting a turn at a message Claude received mid-turn, such as an automatic continuation, and a reloaded session showing a rewound-away turn, or only the rows before a compaction.
  • The footer’s agents pill drawing its icon off-center, with the status dot against the edge, in narrow panels.
  • The chat input showing its text slightly below the cursor and selection after pasting lines that end with a line break into a long prompt.

[Cloud sessions]

  • Cloud sessions occasionally redoing an already-finished step, such as posting a duplicate comment or push, after recovering from a server-side restart.

[Claude Tag]

  • A channel’s configure page listing no connectors or plugins when the channel gets its access bundle through an attach rule; rule-attached bundles are now shown.
  • Access-bundle repository search missing repositories on GitHub App installs that are limited to a large list of selected repositories.
  • Claude occasionally posting the same reply twice when a new message interrupted it mid-reply.
  • Channel routines that stopped running in older private channels whose Slack channel ID changed, for example after a Slack Connect share.
  • Conversations in a channel set to “Channel only” all ending when a non-guest member joined and Slack was slow to confirm their membership.

[Code Review]

  • “@claude review” requests going silent when GitHub failed to return the pull request; the request is retried once, and a comment explains if it still fails.
  • Billing for a review that stopped at its time limit with nothing verified; it now shows as incomplete, isn’t charged, and is retried once.

Notes

  • Pin model versions with availableModelsMatch: "exact" — with it, new model releases stay blocked until you add them to availableModels. Use deniedModels to block a model that availableModels would otherwise allow.
  • Third-party provider and telemetry-off sessions now start in auto mode when no permission mode is configured — set permissions.defaultMode to keep a different default.
  • The claude-ai name is usable again — the 2.1.282 reservation is reverted, so skills, commands and MCP servers under that name don’t need renaming. This release does not revert the anthropic-skills restrictions.
  • Try /doctor prompt-audit on your configuration — it flags prompting patterns written for older models, plus stale paths, stale commands and contradicting instruction files.
  • claude plugin eval needs git 2.31 or later when git is installed.