claudekit / updates / claude-code-2-1-285
[ PATCH · ]

Claude Code 2.1.285

Adds `claude --desktop`, `claude plugin configure`, the `allowedProviders` managed setting and the `CLAUDE_CODE_DISABLE_WEB_FETCH` environment variable. Background Bash and PowerShell commands now stop after a time limit (default 30 min), and sessions behind a custom `ANTHROPIC_BASE_URL` use the 1M context window. Fixes focus on the Artifact tool, `/ultrareview` uploads, plugin installs, subagent permission modes and Remote Control.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.285 shipped on September 29, 2026. New commands and settings include claude --desktop to open the Claude desktop app on the current directory, claude plugin configure to show and set a plugin’s options from the command line, and the allowedProviders managed setting to limit which API providers a machine may use. Behavior changes include a time limit for background commands, the 1M context window behind a custom ANTHROPIC_BASE_URL, and auto mode as the default for claude -p and the Python Agent SDK on third-party providers. Fixes cluster around Artifact tool publish conflicts and overwrites, /ultrareview uploads, plugin install paths, permission handling for fork and background subagents, and Remote Control message delivery.

New features

  • CLAUDE_CODE_DISABLE_WEB_FETCH environment variable

    Turns off the WebFetch tool.

  • claude --desktop

    Opens the Claude desktop app on the current directory, or on a session with --continue / --resume <id>, so you can move from the terminal to the app without finding the folder or session again.

  • claude plugin configure <plugin>

    Shows a plugin’s options and which are unset, or saves new values read from stdin with --values-stdin, without opening /plugin.

  • <server>.<key>=<value> in claude plugin install --config

    A bundled .mcpb MCP server’s own settings can be set at install time, so it starts without visiting /plugin → Configure.

  • allowedProviders managed setting

    Limits which API providers a machine may use: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway.

  • CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable

    Caps re-sends of a non-streaming fallback request that timed out.

  • [VSCode] additions

    • A note under a restored tab’s last message when a window reload interrupted it and no reply will follow.
    • A plugin options form in Manage plugins: installing a plugin that has options asks for the unset ones, and a gear on its row changes them later.
    • An on-demand diagnostics tool, so Claude in the panel can read the Problems panel’s current errors and warnings at any time, not only right after it edits a file.
  • [Claude Tag] Direct messages for Standard and Usage-Based Chat seats

    Members on an Enterprise plan Standard or Usage-Based Chat seat who also have Cowork can now DM Claude; a seat that includes Claude Code is no longer required.

Key improvements

  • Bedrock and Vertex AI fallback when the default model is removed

    When an admin removes access to the default model, sessions now switch to an older available model of the same tier instead of failing, and session titles and summaries fall back with it.

  • Bedrock and Vertex start-up model checks

    Models your account cannot use are remembered for up to a day instead of being re-checked on every launch. Bedrock, Vertex and Mantle start-up checks now send the same User-Agent, x-app and session ID headers as regular requests.

  • /resume and claude --resume on a background session

    They now open a session that is running in the background instead of refusing, and a prompt given with claude --resume <id> "prompt" is sent to it as its next turn.

  • Subagents in auto mode

    A subagent’s run now ends as soon as it hands its report back to its caller, instead of taking extra turns that reach no one.

  • Claude in Chrome computer names

    The native host now reports your computer’s name, so connected browsers can be labeled by computer instead of “Browser 1” / “Browser 2”.

  • Artifact tool results

    • Results now suggest publishing in the same step as writing or editing the page, which can save a round trip.
    • Publish results use fewer tokens: the note on updating an artifact is shorter, and where to find your artifacts is no longer repeated after every publish.
  • Git URL validation for plugins

    Plugin marketplace errors now name why a git address is refused instead of citing enterprise policy, and validation of git URLs for plugins, marketplaces and the current repository’s remote is improved.

  • Other improvements

    • Pictures Claude sends as BMP, HEIC, HEIF, AVIF or TIFF files now show a preview in the Claude apps where Claude Code can convert them.
    • Over Remote Control, a /btw side question asked of a session hosted by an app such as Claude Desktop now sees the turn in progress, not only the last finished one.
    • During a non-streaming fallback request with partial messages on, the SDK now gets a ping stream event every 30 seconds on the Anthropic API, Claude Platform on AWS and gateways.
    • Better per-turn performance when many permission deny rules and MCP tools are configured.
    • Faster exit from the ctrl+o transcript view in long sessions when fullscreen rendering is off.
    • [VSCode] A failed plugin action in Manage plugins now opens a popup that explains it and, where there is one, offers the fix.
    • [Code Review] The check run now says when your repository’s REVIEW.md wasn’t applied, for example on a very large pull request or when REVIEW.md is a symbolic link.

Changed behavior

  • Time limit for background Bash and PowerShell commands (changed)

    Commands run with run_in_background now stop after their timeout (default 30 min, max 2 h), and Claude is notified when one is stopped.

  • 1M context behind a custom ANTHROPIC_BASE_URL (changed)

    Sessions behind a custom ANTHROPIC_BASE_URL use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable). Run /autocompact 200k if your gateway stops at 200K.

  • Auto mode for claude -p and the Python Agent SDK (changed)

    On third-party providers or with telemetry off, they start in auto mode when no permission mode is configured, like interactive sessions; --permission-mode still overrides it. The one-time offer to make auto mode your default also shows in these setups when your user settings default to another mode.

  • WebFetch withheld until the organization policy loads (changed)

    Team and Enterprise sessions, and sessions whose sign-in plan Claude Code can’t determine, withhold WebFetch until the organization policy loads if it couldn’t be loaded at startup.

  • Code Review and /ultrareview with disableWorkflows (changed)

    Code Review’s pull request reviews and /ultrareview now run when disableWorkflows is on, unless the machine running the review has it set by its own administrator (MDM or the managed-settings file).

  • Admin-required sandbox protections (changed)

    Project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies.

  • MCP tool alwaysLoad precedence (changed)

    A tool that sets its own _meta['anthropic/alwaysLoad'] to false stays deferred when its --mcp-config, Agent SDK or plugin server is set to alwaysLoad.

  • widgets MCP server name reserved (changed)

    In cloud sessions and on self-hosted runners, your own server named widgets, or a close spelling such as widgets_, no longer loads, so rename it.

  • Auto-memory in /memory (changed)

    Auto-memory can no longer be turned on from a background session or from a session one of Claude Code’s own tools started; turning it off there still works.

  • claude mcp get for plugin stdio servers (changed)

    Hides the command, arguments, and environment values of stdio MCP servers provided by plugins; variable names are still shown.

  • SigV4 Host header on Bedrock, Mantle and Claude Platform on AWS (changed)

    Requests to a base URL with a non-default port include the port in the SigV4-signed Host header. Bedrock, Vertex and Mantle start-up model checks now identify themselves as Claude Code, like other Claude Code requests.

  • /ultrareview uploads on macOS and Linux (changed)

    • Uploading a local repository requires git 2.31 or newer; checkouts made with --separate-git-dir are refused instead of being uploaded with an older method.
    • On git 2.31 or newer, a partial clone is sent as a working-tree snapshot. On older git versions, a partial clone missing some of its working tree’s files is refused instead of fetched; a clone made without --filter uploads.
    • Symbolic refs are left out when uploading a local checkout, and a checkout whose current branch is a symbolic ref is refused with an explanation.
  • Windows project settings env (changed)

    Project and local settings env no longer set ALLUSERSPROFILE, SystemDrive, or the CommonProgramFiles variables; set them in user or managed settings instead.

  • Other changes

    • /tasks folds background work Claude Code runs for itself under one “System tasks” row; press Enter on it to show those tasks.
    • /config chrome=true directs you to the /config panel instead of enabling Claude in Chrome by default; /config chrome=false still turns it off when it was on.
    • /claude-api can no longer be run from Remote Control clients.
    • [VSCode] Manage plugins asks before removing a marketplace or turning off a plugin that your project’s shared .claude/settings.json turns on.
    • [Cloud sessions] MCP_DISCOVERY_CACHE=1, when set in your cloud environment’s variables rather than a settings file, reuses your connectors’ tool lists after a session restart; other MCP servers are no longer cached and connect at startup.

Bug fixes

Subagents & permission modes

  • Fork subagents not keeping the session’s plan mode or dontAsk mode; a fork now runs under its parent’s permission mode and cannot exit plan mode.
  • claude -p with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent’s own Agent call now runs in the foreground, so the subagent gets the child’s result.
  • claude -p --permission-prompt-tool auto-denying a background subagent’s permission request; it now goes to the prompt tool.
  • Background subagents in auto mode prompting a second, redundant reply after each report.
  • A reply sent from claude agents to a background session waiting on a permission prompt sometimes approving the pending command.
  • Hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response.
  • Auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else’s artifact when you had approved that artifact earlier in another permission mode.
  • The PowerShell tool’s permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory).
  • .claude/settings.local.json allow rules being held back outside a git repository when git’s trace2 output is configured.

Plugins & marketplaces

  • Plugin and marketplace installs and updates over SSH ignoring the ssh program set in GIT_SSH or in your git config’s core.sshCommand.
  • Installing a plugin into an installed plugin’s cache or data folder when their ids differ only in ., -, @ or (macOS, Windows) capitals; the install is now refused.
  • claude plugin disable and enable with a full name@marketplace id changing a settings entry in another letter case instead of the installed plugin’s own.
  • Plugins silently skipping a bundled .mcpb MCP server that still needs configuration; /plugin, the install message and claude plugin install now say so and point to Configure.

MCP servers

  • Switching off an MCP server added mid-session in SDK and -p sessions leaving its tools available.
  • claude mcp list leaving out WebSocket (ws) MCP servers; each is now listed with its URL and health status.
  • claude mcp get showing no Type, Command, Args, or Environment for stdio servers whose config entry omits the type field.
  • claude mcp list, claude mcp get, and the not-found error of claude mcp remove, login and logout printing line breaks and terminal escape sequences from MCP server names and values.

API requests & retries

  • A failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request’s retry budget instead of getting a fresh set of retries.
  • Responses blocked by the API’s output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter’s error right away.
  • /cost and SDK modelUsage reporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected.
  • Switching models mid-session with a set_model request (such as the Agent SDK’s setModel) leaving the new model on the built-in output-token limit and auto-compact window until restart.
  • Amazon Bedrock mid-stream modelTimeoutException and serviceUnavailableException errors showing a raw JSON body instead of the error message.
  • Sessions that authenticate with ANTHROPIC_AUTH_TOKEN against the Anthropic API never loading the organization’s policy.
  • WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block.

Artifact tool

  • Publishes after a conversation rewind (Esc Esc) overwriting a file’s newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file.
  • Publishing a page letting Claude overwrite its source file without re-reading it when Claude’s earlier read was cut short or the file had changed since.
  • An Artifact allow rule (“don’t ask again”) letting the Artifact tool publish a file outside the working directories without asking; add the file’s folder with --add-dir for the rule to cover it.
  • A publish reported as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded.
  • Dismissing a row (x) in /artifacts unlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it.
  • Cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published.

/ultrareview

  • Failing to upload the working tree on macOS and Linux from a git worktree whose per-worktree config sets core.longpaths.
  • Uploads including uncommitted changes to credential files whose name has a colon before the extension, such as server:8443.key.
  • Uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks.
  • A misleading “core.worktree is set” error when the project folder briefly could not be read.
  • [WSL] Refusing to upload a checkout on a Linux volume when a changed file’s name has a colon or ends in a dot or space.
  • [Windows] Uploading a linked worktree of a repository rooted at your home folder in some cases.

Remote Control & cloud sessions

  • Files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice.
  • Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume).
  • claude remote-control --help saying --[no-]chrome defaults to the machine’s /chrome setting; spawned sessions keep Claude in Chrome off unless --chrome is passed.
  • Cloud session creation and /remote-env reading only the newest 20 of an account’s environments.
  • The first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283.
  • Cloud sessions reporting the uploads folder as missing before any file had been uploaded.

Sessions, hooks & auth

  • Synchronous hooks hanging Claude Code while a background process the hook started (for example some-daemon &) kept its output open; the hook now finishes shortly after its own process exits.
  • A cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up.
  • A failed agent(), parallel() or pipeline() call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session.
  • Compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields.
  • CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had ended at --max-turns.
  • claude attach, logs, stop, respawn and rm starting a new session with the command name as its prompt when options came before it, such as from a shell alias.
  • Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file’s policies. Other read errors and unparseable files stop every session.
  • SSH passphrase and new-host prompts from worktree and /teleport fetches taking over the terminal; these fetches now fail fast instead of asking.
  • Sign-in that could wait forever after the browser showed success.
  • A rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time.
  • Redacted logs and transcripts showing part of a URL password that contains @, or all of it when the URL writes its @ as %40.
  • Sandbox auto-allow asking for approval on every run of many inline scripts (python3 -c, node -e) just because they contain =.
  • /autofix-pr and /schedule saying the Claude GitHub App is not installed on a repository whose install status had not been checked yet.
  • An approved Edit never going through when its target is a device, such as a file symlinked to /dev/null, and the approval came from the IDE diff view or changed the edit.
  • The /claude-api eval runner scaffold and report builder writing through a symlink or hard link planted at an output file.
  • The /claude-api eval runner scaffold counting responses cut off at max_tokens in the score averages; they are now marked truncated and counted separately.

Display & input

  • The fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish.
  • A brief freeze (up to a second) partway through long sessions outside fullscreen mode, which came back after /clear or /compact.
  • &nbsp; showing as literal text in the terminal when a reply uses it to indent text, such as row labels in a markdown table.
  • Vim mode: after editing in the external editor (Ctrl+G), x or r in NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt.

[VSCode]

  • Pressing Enter after typing a slash command running an unrelated menu item picked by fuzzy match, or doing nothing.
  • Escape stopping the running turn instead of closing the command menu after clicking one of its rows.
  • Every file Read, Write and Edit stalling for ten minutes and then being skipped when the editor stops responding to the extension’s automatic save before the tool runs.
  • Opening a conversation that is already open in another window or app starting a second copy of it without warning; it now asks first.
  • Opening Past conversations replacing a live conversation with its saved copy.
  • A message sent while Claude was working disappearing from the conversation after the session was reopened.
  • Restored tabs re-running an interrupted turn when VS Code was started with CLAUDE_CODE_RESUME_INTERRUPTED_TURN set, even with Continue After Reload off.
  • Tabs stuck on a conversation that can’t be resumed; the error now says so and offers to start a new conversation.
  • A Claude tab reloaded after an extension restart staying blank instead of saying how to recover.
  • A message that quotes a Claude Code or IDE tag losing the rest of its text in the chat.
  • A hook’s reason for blocking or stopping a prompt disappearing after a window reload.
  • An open agent transcript losing the agent’s newer messages during a long session, and the agent map’s transcript view leaving out messages sent to a running agent.
  • The agent map labeling a sub-agent with the session’s model instead of the model it actually ran on (e.g. under CLAUDE_CODE_SUBAGENT_MODEL_FORCE or an agent’s own model).
  • The conversation disappearing from a session when many agents run, and the chat panel stalling when a long session trims its oldest rows.
  • Uninstalling a plugin from the Manage plugins dialog removing the wrong installation or failing for a plugin installed for the project.
  • The session list’s Web tab showing the previous account’s sessions after an account switch.
  • Sign-in staying on the authorization-code step after going back and choosing the same sign-in method again.
  • The editor tab keeping an old name after a session was renamed with /rename, by a SessionStart hook, or on claude.ai.

[Cloud sessions]

  • Run now on a routine showing internal error text when the run is refused before it starts; it now shows the same explanation as the routine’s failure notification.

[Claude Tag]

  • The Default model setting in admin settings and a channel’s Configure page offering models your organization can’t use, which made saves or new sessions fail.
  • The note under Claude’s Slack messages saying it answered on a fallback model, and why, disappearing when Claude later edited that message.

[Code Review]

  • The organization menu in the “Add a repository” dialog showing only a few of your GitHub organizations; it now loads more as you scroll.

Notes

  • Background Bash and PowerShell commands now stop after a time limit (default 30 min, max 2 h) — the limit is the command’s timeout with run_in_background, and Claude is notified when one is stopped.
  • Sessions behind a custom ANTHROPIC_BASE_URL now use the 1M context window — run /autocompact 200k if your gateway stops at 200K.
  • claude -p and the Python Agent SDK on third-party providers or with telemetry off start in auto mode when no permission mode is configured — pass --permission-mode to keep a different mode.
  • The MCP server name widgets is reserved in cloud sessions and on self-hosted runners — rename your own server if it uses that name or a close spelling.
  • /ultrareview on macOS and Linux requires git 2.31 or newer to upload a local repository.
  • On Windows, move ALLUSERSPROFILE, SystemDrive and CommonProgramFiles variables out of project and local settings env into user or managed settings.