What changed
Claude Code 2.1.285 shipped on September 29, 2026. New commands and settings include claude --desktop to open the Claude desktop app on the current directory, claude plugin configure to show and set a plugin’s options from the command line, and the allowedProviders managed setting to limit which API providers a machine may use. Behavior changes include a time limit for background commands, the 1M context window behind a custom ANTHROPIC_BASE_URL, and auto mode as the default for claude -p and the Python Agent SDK on third-party providers. Fixes cluster around Artifact tool publish conflicts and overwrites, /ultrareview uploads, plugin install paths, permission handling for fork and background subagents, and Remote Control message delivery.
New features
-
CLAUDE_CODE_DISABLE_WEB_FETCHenvironment variableTurns off the WebFetch tool.
-
claude --desktopOpens the Claude desktop app on the current directory, or on a session with
--continue/--resume <id>, so you can move from the terminal to the app without finding the folder or session again. -
claude plugin configure <plugin>Shows a plugin’s options and which are unset, or saves new values read from stdin with
--values-stdin, without opening/plugin. -
<server>.<key>=<value>inclaude plugin install --configA bundled
.mcpbMCP server’s own settings can be set at install time, so it starts without visiting/plugin→ Configure. -
allowedProvidersmanaged settingLimits which API providers a machine may use: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway.
-
CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIESenvironment variableCaps re-sends of a non-streaming fallback request that timed out.
-
[VSCode] additions
- A note under a restored tab’s last message when a window reload interrupted it and no reply will follow.
- A plugin options form in Manage plugins: installing a plugin that has options asks for the unset ones, and a gear on its row changes them later.
- An on-demand diagnostics tool, so Claude in the panel can read the Problems panel’s current errors and warnings at any time, not only right after it edits a file.
-
[Claude Tag] Direct messages for Standard and Usage-Based Chat seats
Members on an Enterprise plan Standard or Usage-Based Chat seat who also have Cowork can now DM Claude; a seat that includes Claude Code is no longer required.
Key improvements
-
Bedrock and Vertex AI fallback when the default model is removed
When an admin removes access to the default model, sessions now switch to an older available model of the same tier instead of failing, and session titles and summaries fall back with it.
-
Bedrock and Vertex start-up model checks
Models your account cannot use are remembered for up to a day instead of being re-checked on every launch. Bedrock, Vertex and Mantle start-up checks now send the same User-Agent, x-app and session ID headers as regular requests.
-
/resumeandclaude --resumeon a background sessionThey now open a session that is running in the background instead of refusing, and a prompt given with
claude --resume <id> "prompt"is sent to it as its next turn. -
Subagents in auto mode
A subagent’s run now ends as soon as it hands its report back to its caller, instead of taking extra turns that reach no one.
-
Claude in Chrome computer names
The native host now reports your computer’s name, so connected browsers can be labeled by computer instead of “Browser 1” / “Browser 2”.
-
Artifact tool results
- Results now suggest publishing in the same step as writing or editing the page, which can save a round trip.
- Publish results use fewer tokens: the note on updating an artifact is shorter, and where to find your artifacts is no longer repeated after every publish.
-
Git URL validation for plugins
Plugin marketplace errors now name why a git address is refused instead of citing enterprise policy, and validation of git URLs for plugins, marketplaces and the current repository’s remote is improved.
-
Other improvements
- Pictures Claude sends as BMP, HEIC, HEIF, AVIF or TIFF files now show a preview in the Claude apps where Claude Code can convert them.
- Over Remote Control, a
/btwside question asked of a session hosted by an app such as Claude Desktop now sees the turn in progress, not only the last finished one. - During a non-streaming fallback request with partial messages on, the SDK now gets a
pingstream event every 30 seconds on the Anthropic API, Claude Platform on AWS and gateways. - Better per-turn performance when many permission deny rules and MCP tools are configured.
- Faster exit from the ctrl+o transcript view in long sessions when fullscreen rendering is off.
- [VSCode] A failed plugin action in Manage plugins now opens a popup that explains it and, where there is one, offers the fix.
- [Code Review] The check run now says when your repository’s REVIEW.md wasn’t applied, for example on a very large pull request or when REVIEW.md is a symbolic link.
Changed behavior
-
Time limit for background Bash and PowerShell commands (changed)
Commands run with
run_in_backgroundnow stop after theirtimeout(default 30 min, max 2 h), and Claude is notified when one is stopped. -
1M context behind a custom
ANTHROPIC_BASE_URL(changed)Sessions behind a custom
ANTHROPIC_BASE_URLuse the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable). Run/autocompact 200kif your gateway stops at 200K. -
Auto mode for
claude -pand the Python Agent SDK (changed)On third-party providers or with telemetry off, they start in auto mode when no permission mode is configured, like interactive sessions;
--permission-modestill overrides it. The one-time offer to make auto mode your default also shows in these setups when your user settings default to another mode. -
WebFetch withheld until the organization policy loads (changed)
Team and Enterprise sessions, and sessions whose sign-in plan Claude Code can’t determine, withhold WebFetch until the organization policy loads if it couldn’t be loaded at startup.
-
Code Review and
/ultrareviewwithdisableWorkflows(changed)Code Review’s pull request reviews and
/ultrareviewnow run whendisableWorkflowsis on, unless the machine running the review has it set by its own administrator (MDM or the managed-settings file). -
Admin-required sandbox protections (changed)
Project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies.
-
MCP tool
alwaysLoadprecedence (changed)A tool that sets its own
_meta['anthropic/alwaysLoad']to false stays deferred when its--mcp-config, Agent SDK or plugin server is set toalwaysLoad. -
widgetsMCP server name reserved (changed)In cloud sessions and on self-hosted runners, your own server named
widgets, or a close spelling such aswidgets_, no longer loads, so rename it. -
Auto-memory in
/memory(changed)Auto-memory can no longer be turned on from a background session or from a session one of Claude Code’s own tools started; turning it off there still works.
-
claude mcp getfor plugin stdio servers (changed)Hides the command, arguments, and environment values of stdio MCP servers provided by plugins; variable names are still shown.
-
SigV4 Host header on Bedrock, Mantle and Claude Platform on AWS (changed)
Requests to a base URL with a non-default port include the port in the SigV4-signed Host header. Bedrock, Vertex and Mantle start-up model checks now identify themselves as Claude Code, like other Claude Code requests.
-
/ultrareviewuploads on macOS and Linux (changed)- Uploading a local repository requires git 2.31 or newer; checkouts made with
--separate-git-dirare refused instead of being uploaded with an older method. - On git 2.31 or newer, a partial clone is sent as a working-tree snapshot. On older git versions, a partial clone missing some of its working tree’s files is refused instead of fetched; a clone made without
--filteruploads. - Symbolic refs are left out when uploading a local checkout, and a checkout whose current branch is a symbolic ref is refused with an explanation.
- Uploading a local repository requires git 2.31 or newer; checkouts made with
-
Windows project settings
env(changed)Project and local settings
envno longer setALLUSERSPROFILE,SystemDrive, or theCommonProgramFilesvariables; set them in user or managed settings instead. -
Other changes
/tasksfolds background work Claude Code runs for itself under one “System tasks” row; press Enter on it to show those tasks./config chrome=truedirects you to the /config panel instead of enabling Claude in Chrome by default;/config chrome=falsestill turns it off when it was on./claude-apican no longer be run from Remote Control clients.- [VSCode] Manage plugins asks before removing a marketplace or turning off a plugin that your project’s shared
.claude/settings.jsonturns on. - [Cloud sessions]
MCP_DISCOVERY_CACHE=1, when set in your cloud environment’s variables rather than a settings file, reuses your connectors’ tool lists after a session restart; other MCP servers are no longer cached and connect at startup.
Bug fixes
Subagents & permission modes
- Fork subagents not keeping the session’s plan mode or
dontAskmode; a fork now runs under its parent’s permission mode and cannot exit plan mode. claude -pwithCLAUDE_CODE_FORK_SUBAGENT=1: a subagent’s own Agent call now runs in the foreground, so the subagent gets the child’s result.claude -p --permission-prompt-toolauto-denying a background subagent’s permission request; it now goes to the prompt tool.- Background subagents in auto mode prompting a second, redundant reply after each report.
- A reply sent from
claude agentsto a background session waiting on a permission prompt sometimes approving the pending command. - Hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response.
- Auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else’s artifact when you had approved that artifact earlier in another permission mode.
- The PowerShell tool’s permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory).
.claude/settings.local.jsonallow rules being held back outside a git repository when git’s trace2 output is configured.
Plugins & marketplaces
- Plugin and marketplace installs and updates over SSH ignoring the ssh program set in
GIT_SSHor in your git config’score.sshCommand. - Installing a plugin into an installed plugin’s cache or data folder when their ids differ only in
.,-,@or (macOS, Windows) capitals; the install is now refused. claude plugin disableandenablewith a fullname@marketplaceid changing a settings entry in another letter case instead of the installed plugin’s own.- Plugins silently skipping a bundled
.mcpbMCP server that still needs configuration;/plugin, the install message andclaude plugin installnow say so and point to Configure.
MCP servers
- Switching off an MCP server added mid-session in SDK and
-psessions leaving its tools available. claude mcp listleaving out WebSocket (ws) MCP servers; each is now listed with its URL and health status.claude mcp getshowing no Type, Command, Args, or Environment for stdio servers whose config entry omits thetypefield.claude mcp list,claude mcp get, and the not-found error ofclaude mcp remove,loginandlogoutprinting line breaks and terminal escape sequences from MCP server names and values.
API requests & retries
- A failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request’s retry budget instead of getting a fresh set of retries.
- Responses blocked by the API’s output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter’s error right away.
/costand SDKmodelUsagereporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected.- Switching models mid-session with a
set_modelrequest (such as the Agent SDK’ssetModel) leaving the new model on the built-in output-token limit and auto-compact window until restart. - Amazon Bedrock mid-stream
modelTimeoutExceptionandserviceUnavailableExceptionerrors showing a raw JSON body instead of the error message. - Sessions that authenticate with
ANTHROPIC_AUTH_TOKENagainst the Anthropic API never loading the organization’s policy. - WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block.
Artifact tool
- Publishes after a conversation rewind (Esc Esc) overwriting a file’s newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file.
- Publishing a page letting Claude overwrite its source file without re-reading it when Claude’s earlier read was cut short or the file had changed since.
- An
Artifactallow rule (“don’t ask again”) letting the Artifact tool publish a file outside the working directories without asking; add the file’s folder with--add-dirfor the rule to cover it. - A publish reported as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded.
- Dismissing a row (x) in
/artifactsunlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it. - Cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published.
/ultrareview
- Failing to upload the working tree on macOS and Linux from a git worktree whose per-worktree config sets
core.longpaths. - Uploads including uncommitted changes to credential files whose name has a colon before the extension, such as
server:8443.key. - Uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks.
- A misleading “core.worktree is set” error when the project folder briefly could not be read.
- [WSL] Refusing to upload a checkout on a Linux volume when a changed file’s name has a colon or ends in a dot or space.
- [Windows] Uploading a linked worktree of a repository rooted at your home folder in some cases.
Remote Control & cloud sessions
- Files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice.
- Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume).
claude remote-control --helpsaying--[no-]chromedefaults to the machine’s/chromesetting; spawned sessions keep Claude in Chrome off unless--chromeis passed.- Cloud session creation and
/remote-envreading only the newest 20 of an account’s environments. - The first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283.
- Cloud sessions reporting the uploads folder as missing before any file had been uploaded.
Sessions, hooks & auth
- Synchronous hooks hanging Claude Code while a background process the hook started (for example
some-daemon &) kept its output open; the hook now finishes shortly after its own process exits. - A cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up.
- A failed
agent(),parallel()orpipeline()call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session. - Compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields.
CLAUDE_CODE_RESUME_INTERRUPTED_TURNre-running a turn that had ended at--max-turns.claude attach,logs,stop,respawnandrmstarting a new session with the command name as its prompt when options came before it, such as from a shell alias.- Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file’s policies. Other read errors and unparseable files stop every session.
- SSH passphrase and new-host prompts from worktree and
/teleportfetches taking over the terminal; these fetches now fail fast instead of asking. - Sign-in that could wait forever after the browser showed success.
- A rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time.
- Redacted logs and transcripts showing part of a URL password that contains
@, or all of it when the URL writes its@as%40. - Sandbox auto-allow asking for approval on every run of many inline scripts (
python3 -c,node -e) just because they contain=. /autofix-prand/schedulesaying the Claude GitHub App is not installed on a repository whose install status had not been checked yet.- An approved Edit never going through when its target is a device, such as a file symlinked to /dev/null, and the approval came from the IDE diff view or changed the edit.
- The
/claude-apieval runner scaffold and report builder writing through a symlink or hard link planted at an output file. - The
/claude-apieval runner scaffold counting responses cut off atmax_tokensin the score averages; they are now marked truncated and counted separately.
Display & input
- The fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish.
- A brief freeze (up to a second) partway through long sessions outside fullscreen mode, which came back after
/clearor/compact. showing as literal text in the terminal when a reply uses it to indent text, such as row labels in a markdown table.- Vim mode: after editing in the external editor (Ctrl+G),
xorrin NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt.
[VSCode]
- Pressing Enter after typing a slash command running an unrelated menu item picked by fuzzy match, or doing nothing.
- Escape stopping the running turn instead of closing the command menu after clicking one of its rows.
- Every file Read, Write and Edit stalling for ten minutes and then being skipped when the editor stops responding to the extension’s automatic save before the tool runs.
- Opening a conversation that is already open in another window or app starting a second copy of it without warning; it now asks first.
- Opening Past conversations replacing a live conversation with its saved copy.
- A message sent while Claude was working disappearing from the conversation after the session was reopened.
- Restored tabs re-running an interrupted turn when VS Code was started with
CLAUDE_CODE_RESUME_INTERRUPTED_TURNset, even with Continue After Reload off. - Tabs stuck on a conversation that can’t be resumed; the error now says so and offers to start a new conversation.
- A Claude tab reloaded after an extension restart staying blank instead of saying how to recover.
- A message that quotes a Claude Code or IDE tag losing the rest of its text in the chat.
- A hook’s reason for blocking or stopping a prompt disappearing after a window reload.
- An open agent transcript losing the agent’s newer messages during a long session, and the agent map’s transcript view leaving out messages sent to a running agent.
- The agent map labeling a sub-agent with the session’s model instead of the model it actually ran on (e.g. under
CLAUDE_CODE_SUBAGENT_MODEL_FORCEor an agent’s ownmodel). - The conversation disappearing from a session when many agents run, and the chat panel stalling when a long session trims its oldest rows.
- Uninstalling a plugin from the Manage plugins dialog removing the wrong installation or failing for a plugin installed for the project.
- The session list’s Web tab showing the previous account’s sessions after an account switch.
- Sign-in staying on the authorization-code step after going back and choosing the same sign-in method again.
- The editor tab keeping an old name after a session was renamed with /rename, by a SessionStart hook, or on claude.ai.
[Cloud sessions]
- Run now on a routine showing internal error text when the run is refused before it starts; it now shows the same explanation as the routine’s failure notification.
[Claude Tag]
- The Default model setting in admin settings and a channel’s Configure page offering models your organization can’t use, which made saves or new sessions fail.
- The note under Claude’s Slack messages saying it answered on a fallback model, and why, disappearing when Claude later edited that message.
[Code Review]
- The organization menu in the “Add a repository” dialog showing only a few of your GitHub organizations; it now loads more as you scroll.
Notes
- Background Bash and PowerShell commands now stop after a time limit (default 30 min, max 2 h) — the limit is the command’s
timeoutwithrun_in_background, and Claude is notified when one is stopped. - Sessions behind a custom
ANTHROPIC_BASE_URLnow use the 1M context window — run/autocompact 200kif your gateway stops at 200K. claude -pand the Python Agent SDK on third-party providers or with telemetry off start in auto mode when no permission mode is configured — pass--permission-modeto keep a different mode.- The MCP server name
widgetsis reserved in cloud sessions and on self-hosted runners — rename your own server if it uses that name or a close spelling. /ultrareviewon macOS and Linux requires git 2.31 or newer to upload a local repository.- On Windows, move
ALLUSERSPROFILE,SystemDriveandCommonProgramFilesvariables out of project and local settingsenvinto user or managed settings.