claudekit / updates / claude-code-2-1-284
[ PATCH · ]

Claude Code 2.1.284

Claude Sonnet 5.5 (`claude-sonnet-5-5`) is added and is now the default Sonnet model on the Anthropic API. Interactive terminal and VS Code sessions start in auto mode when no permission mode is configured, on every plan and provider, and Ultracode becomes its own toggle in `/effort`. Fixes focus on damaged response streams, "Prompt is too long" after compacting, MCP connections and plugin permissions.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.284 shipped on September 28, 2026. The headline addition is Claude Sonnet 5.5, now the default Sonnet model on the Anthropic API. Interactive terminal and VS Code sessions now start in auto mode when no permission mode is configured, on every plan and provider, and Ultracode is split out of the effort levels into its own toggle that stays on at any effort level. Fixes cluster around damaged response streams, “Prompt is too long” errors that persisted after compacting, MCP server connections, and plugin tool pre-approval under managed settings.

New features

  • Claude Sonnet 5.5 (claude-sonnet-5-5)

    Now the default Sonnet model on the Anthropic API, with 1M context at $2/$10 per Mtok and $0.20/Mtok cache reads.

  • “Yes, but ask again next time” in auto mode

    A new answer to auto mode’s prompt before a read outside the working directories: allow that one read and still be asked about later ones.

  • /mcp reconnect all

    In the interactive terminal, retries every MCP server that failed to connect or needs authentication at once.

  • Rebindable /effort slider keys

    New effortSlider:decreaseEffort, increaseEffort and toggleUltracode keybinding actions let you rebind the slider’s arrow and Tab keys in keybindings.json.

  • /rate-limit-options in /help and the command menu

    For claude.ai subscribers, so the usage-limit notices that mention it point to a command you can find.

  • Claude apps gateway additions

    • Dollar amounts for the spend limit in /usage and the status line (for example “$271.40 / $500.00 spent this month”) when the gateway runs this version or later. The status line’s rate_limits.spend_limit gains used_usd, limit_usd and period.
    • Startup warnings when a managed policy’s availableModels is empty, or leaves out the model Claude Code starts on without setting model or enforceAvailableModels.
    • auth: { google: {} } for telemetry.forward_to destinations, exporting telemetry straight to Google Cloud’s OTLP endpoint using the gateway’s Google Cloud credentials.
    • Certificate client authentication (private_key_jwt) between the gateway and its identity provider, for identity providers that issue certificate credentials instead of client secrets.
  • [VSCode] additions

    • An optional time above each prompt and response, with a date line where the day changes (Claude Code: Show Message Timestamps setting, off by default).
    • Plugin load errors and notes on the Manage plugins rows, with a popup to disable, uninstall or copy the error.
    • An Ultracode on/off switch under the Effort slider, replacing the slider’s Ultracode stop; the model pill shows ”· Ultracode” at any effort level.
  • [Claude Tag] additions

    • Model family choices such as “Opus (latest)” for a thread, a channel default or your DM, so the choice follows the newest model in that family.
    • The spend that counts toward your organization-wide limit in the analytics spend projection chart, with how much of the limit is used.

Key improvements

  • Usage-limit wait

    The limit’s state and the countdown with the usage-credits option now show as one block under the prompt, and limit messages no longer repeat the countdown.

  • Startup time and memory use

    Only the parts of the settings schema that your settings files actually use are built.

  • Auto-memory loading

    Invisible characters and tags that imitate Claude Code’s own markup are neutralized in MEMORY.md and recalled memory notes before they reach Claude.

  • Startup refusal under managed sign-in

    When managed settings require a sign-in (forceLoginMethod or forceLoginOrgUUID) and an API key, token or apiKeyHelper is configured, the refusal now names the credential in use, where it is set, and how to remove it.

  • claude remote-control workspace trust

    In a folder you haven’t trusted yet, it now asks for workspace trust on the terminal instead of exiting.

  • claude plugin marketplace add

    Now says when it replaces a marketplace already added under the same name from a different source, and how to undo it.

  • /claude-api

    hillclimb no longer spends rounds on prompt rewordings too small for the eval to measure, and an extra page you ask for beside report.html is built as one local file that loads nothing from the network.

  • Artifacts

    • Claude writes its design plan into the page instead of the reply, and uses the name you already gave something as the page title.
    • Given a claude.ai chat or project link, an artifact from a chat, or an artifact id on its own, the Artifact tool asks for the right link or the content instead of stopping.
  • Other improvements

    • The “No such tool available” error for Claude in Chrome tools called without their prefix now names the tool to call.
    • Monitor event rows show what each event printed instead of repeating the description, and an unchanged “Waiting for N … to finish” line no longer repeats after every event.
    • Lists such as /tasks, /copy and /hooks line up the details after each name in one column when they fit, and otherwise place them at the right edge.
    • Workflow tool sandbox hardening for errors thrown by async script hooks.
    • [Claude Tag] “Notify members now” in admin settings reaches every workspace your organization claimed in an Enterprise Grid, and more members in large workspaces.
    • [Claude Tag] The wait notice on self-hosted environments with on-demand runners says whether a runner is starting, a start will be retried, or no runner will start.
    • [Claude Tag] A clearer error when adding a channel manager fails because the channel’s Slack workspace can’t be confirmed as connected to your organization.
    • [Claude Tag] A channel’s access lists show the connectors, repositories and plugins an auto-join pattern attaches, and where each comes from.
    • [Claude Tag] When your GitHub sign-in can’t confirm you’re a repository admin, the page asks you to sign in with GitHub.

Changed behavior

  • Auto mode by default on every plan and provider (changed)

    Interactive terminal and VS Code sessions start in auto mode when no permission mode is configured. 2.1.283 applied this to third-party providers and telemetry-off sessions; it now covers every plan and provider. permissions.defaultMode still overrides it.

  • Ultracode as its own toggle in /effort (changed)

    Toggle it with Tab or /effort ultracode [on|off]. It no longer forces xhigh effort and stays on at any effort level.

  • Retries after a dropped connection (changed)

    Retries after a dropped connection mid-response now share one budget with the rest of the request’s retries, so a failing request gives up sooner.

  • Sonnet safeguards notice (changed)

    When a Sonnet model’s safeguards flag a message, the notice explains why it happened and offers editing and retrying.

  • Safety-related model switches with a pinned Opus model (changed)

    In sessions that pin an Opus model with ANTHROPIC_DEFAULT_OPUS_MODEL or modelOverrides, on the Anthropic API the API now picks the model to switch to for each kind of flag, not the pinned model.

  • MCP wait on the non-interactive first turn (changed)

    The first turn still waits up to 2s for connecting MCP servers named by --allowedTools or an mcp_tool hook, even when CLAUDE_CODE_MCP_STARTUP_WAIT_MS is 0.

  • Relayed /recap (changed)

    /recap declines with a short notice when it arrives relayed from a chat thread (your own included) or from a routine or webhook. Typed in the terminal, the Claude apps, Remote Control, -p or an SDK host, it runs as before.

  • /artifacts filter tabs (changed)

    Shown beside the title with one-word labels (All, Mine, Shared), using the same tab bar as /config and /plugin.

  • Artifact publishing from network shares (changed)

    A file on a network share (a \\host\share path or a /net automount) is refused unless it is on a mapped network drive added with --add-dir.

  • [VSCode] CLAUDE_CONFIG_DIR (changed)

    In the claudeCode.environmentVariables setting, it applies only when it is an absolute path, and is passed to terminals that continue the chat.

  • [Claude Tag] Sign-in notice (changed)

    Claude posts its private sign-in notice at every @mention from someone who hasn’t connected their Claude account, instead of going quiet after the first.

Bug fixes

Response streams & retries

  • A damaged response stream showing raw errors such as “JSON Parse error” or “undefined is not an object”, or writing the word “undefined” into an answer, instead of being retried or reported as an interrupted response.
  • An overloaded or server error arriving right after a thinking block ending the turn with an error instead of being retried.
  • “Prompt is too long” errors that persisted after compacting; when the compacted request is still too long, Claude Code now compacts once more, keeping less of the recent conversation.
  • A session whose model is unavailable, with no fallback model left, showing a bare “is currently unavailable” message (or “Something went wrong” in cloud sessions) instead of the model-unavailable notice and its Learn more link.
  • Agent SDK sessions crashing on an image with a malformed source, and failing on every later turn after a malformed document block; a malformed image is now replaced with an explanatory note.

MCP servers

  • MCP tool calls in a resumed session failing with “No such tool available” while their server was still connecting; the call now waits up to 10 seconds for the server.
  • claude mcp add reporting success when managed settings restrict MCP servers to plugins; it now refuses and says what to do, instead of saving a server that never loads.
  • {"decision":"block"} returned by Elicitation and ElicitationResult hooks being ignored; it now declines the MCP elicitation, as exit code 2 does.

Plugins & marketplaces

  • Plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed allowManagedPermissionRulesOnly; only plugins from an official Anthropic source or a source that managed settings vouch for keep that pre-approval.
  • A failed first claude plugin install leaving the plugin enabled and recorded when a dependency’s version range could not be met.
  • The /plugin configure screen: boolean options are now a true/false choice instead of free text, number options refuse invalid input, and ←/→ change an options field instead of switching tabs.
  • sparsePaths plugin marketplaces cloning empty on older git (before 2.39) and replacing a working local copy, which failed every refresh with “marketplace.json file is no longer present”.
  • Bash tool failing on Windows with many plugins enabled; plugin bin/ directories that don’t exist are no longer added to PATH, and inherited entries aren’t added twice.

Usage & models

  • Repeated calls to the plan-usage endpoint after it rate-limits or rejects your login; /usage, /extra-usage and IDE usage views now back off instead of re-asking.
  • Typing a message during an automatic usage-limit wait taking the wait out of the “Continue automatically at usage limit” setting’s control when that turn hit the limit again.
  • Usage-limit warnings suggesting /upgrade to users already on the highest Max plan; the warnings and /upgrade itself now point at /usage-credits when it is available.
  • The Explore subagent switching to Opus on the Claude API when the session runs a model ID Claude Code doesn’t recognize, such as a custom model behind a proxy; Explore now inherits that model.

Security & permissions

  • ANTHROPIC_FOUNDRY_RESOURCE being interpolated into the Foundry endpoint host unvalidated; a value that is not a plain resource name is now refused.
  • Rules symlinked into .claude/rules from outside the project being skipped without ever showing the external-imports approval prompt; a .claude directory symlinked from outside the project now asks for the same approval.
  • The workspace trust dialog appearing a second time after switching renderers or updating when Claude Code was started in the home directory.
  • Sandboxed Bash commands failing to start on Linux when the working directory is write-denied and contains a read-denied directory.
  • Artifact database write results telling Claude that every viewer sees a write to a viewer’s private data/users/ subtree; a “view” level is also added to as_level.

Display & input

  • Fullscreen rendering erasing the terminal output above the session when [ in transcript mode writes the conversation to scrollback (macOS and Linux).
  • Fullscreen scroll position jumping to the previous message or to the bottom when a reply finished streaming while scrolled up.
  • Tab bars in dialogs such as /config and /plugin breaking the title and tab labels mid-word in a narrow terminal; a tab that doesn’t fit now moves to the next line whole.
  • The /model picker showing “+1 model” below the list after scrolling to the last model.
  • ↓ in shell mode selecting a hidden background-tasks pill, which stopped Backspace and Ctrl+U from editing the prompt.
  • /keybindings writing Backspace and Delete bindings for a footer action that does nothing into the generated keybindings.json.
  • A rebound agent panel close key (footer:close) typing “x” instead of itself on the row of the agent you’re viewing.
  • A key pressed the instant the terminal regained focus answering the Remote Control enable prompt before its short safety delay restarted.

Vim mode

  • . not repeating text typed very fast (for example over ssh or in tmux) or pasted without bracketed paste, and leaving the prompt in INSERT mode after repeating a change with nothing typed (such as cw then Esc).
  • The cursor left on an image placeholder’s opening bracket after dd on the last line or yy at the end of the prompt, where r or x would break or delete the image.

Sessions, hooks & Remote Control

  • The debug log dropping a failed hook’s stderr when the hook also wrote to stdout, and logging nothing for a failed hook with no output; failed hooks now also log their status code.
  • Sessions launched without the SendMessage tool (such as by Claude Desktop) still being told to message other sessions with it.
  • A photo sent from the Claude app over Remote Control being lost when its queued message was pulled back into the terminal prompt to edit, and the cursor moving one character for a photo with no caption.
  • /loop status updates in self-paced mode often not being shown because Claude wrote them only in its reasoning; Claude now writes each update, and the outcome when the loop stops, as visible text.
  • /ultrareview failing to upload the working tree when started from a git worktree that the Claude desktop app created on macOS or Linux.
  • Claude Desktop behind a Claude apps gateway offering no 1M context option; the gateway now marks each 1M-capable model for Desktop automatically.
  • The Claude apps gateway answering 431 Request Header Fields Too Large to every request from a sign-in whose identity provider lists many groups; it now accepts request headers up to 256 KiB.

[VSCode]

  • Reload Claude from the Memory dialog restarting before an edited file was saved.
  • A restored tab opening a conversation another Claude process still has open; it now asks first.
  • Focus view sections you expanded closing on their own while a sub-agent is working or when the section’s first step is trimmed from view.
  • Typing /model and Enter printing usage text into the chat instead of opening the model selector.
  • /feedback on Vertex, Bedrock and Foundry being refused after you pressed Send; the report is now saved on this computer, as the terminal does.
  • Sign-in waiting up to a minute for the Python extension after a window reload.
  • Claude Code tabs that stopped responding after Restart Extensions; they now reopen on their conversation.
  • A message from another agent with no recorded sender showing as raw XML, and messages from other agents, sessions or channels disappearing after a reload.
  • A user’s own /mcp, /config or /settings command being shadowed by the extension’s dialog.
  • Escape stopping every background agent when no turn was running.
  • Plugin install links replacing a marketplace you already have that uses the same name.
  • “Prompt is too long” errors after compaction when a large text file is attached to a message.
  • Chat links to files with non-ASCII characters, spaces or brackets in their path not opening.

[Cloud sessions]

  • A routine’s Edit and Duplicate controls saying the routine was still loading while you were offline; they now tell you you’re offline.

[Claude Tag]

  • The earlier Claude in Slack app’s progress card and link previews omitting the repository and Create PR button when a GitHub Enterprise host name contains an underscore.
  • Claude staying silent in a channel whose environment declines to start it; it now posts one notice asking you to contact an admin, and retries when @-mentioned.

[Code Review]

  • Code Review giving up without posting a finished review when an unsubmitted review under its GitHub App was open on the pull request; it now retries the post first.

Notes

  • Sonnet 5.5 is now the default Sonnet model on the Anthropic API — 1M context, $2/$10 per Mtok with $0.20/Mtok cache reads.
  • Interactive terminal and VS Code sessions now start in auto mode on every plan and provider when no permission mode is configured — set permissions.defaultMode to keep a different default.
  • Ultracode no longer forces xhigh effort — turn it on with /effort ultracode on and pick the effort level separately.
  • Organizations using managed allowManagedPermissionRulesOnly see a change in plugin tool approval — allowed-tools pre-approval is kept only for plugins from an official Anthropic source or a source that managed settings vouch for.
  • Use /mcp reconnect all when several MCP servers failed to connect — it retries every server that failed or needs authentication at once.