claudekit / updates / claude-code-2-1-286
[ PATCH · ]

Claude Code 2.1.286

The permission prompt now shows a count such as "2 of 5" when several requests stack up, and the "N more" rows of fullscreen lists respond to the mouse. Failed API requests now share one retry limit per model call (at most 14 requests by default), and `--bare` connects only the MCP servers named on the command line. Fixes focus on `--resume` losing turns, secret redaction in logs and transcripts, Remote Control, subagents and MCP connections.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.286 shipped on September 30, 2026. Permission prompts and fullscreen list screens get a cleanup: stacked permission requests show a count, every permission prompt now matches the look of file edit prompts, and list screens such as /hooks, /mcp and /skills line up each row’s details in one column. Behavior changes include a single retry limit per model call, a narrower --bare mode, and stricter npm sources for plugin installs. Fixes cluster around claude --resume losing turns, secrets leaking into redacted logs and transcripts, Remote Control messages and attachments, subagents, and MCP connections.

New features

  • Permission request count

    When several permission requests stack up, the permission prompt now shows a count such as “2 of 5”, so you know how many are left.

  • Mouse support for “N more” rows in fullscreen mode

    Click one of the “N more” rows of a list to jump to that end of the list, with hover and pressed states.

  • [VSCode] additions

    • Bookmarks: save Claude’s responses and keep them in view in a Bookmarks side panel.
    • The questions Claude asks and your answers now stay in the conversation: after you answer a question card, a Questions row shows each question with your picks.
    • Option previews on question cards in the chat panel: the highlighted choice’s mockup or snippet shows beside or under the options.
    • Rows under a message that open to the terminal output, browser tab, browser instructions and selected code sent with it.
  • [Claude Tag] Add channel button on the spend limits page

    An Add channel button on Claude Tag’s spend limits page in admin settings lets you set a limit on any channel, including a private one, from its channel ID or Slack link.

Key improvements

  • Commit guidance for a verify skill

    When your project or user skills include one named verify, Claude is now told to run it right before committing, except for docs-only and tests-only commits.

  • Consistent permission prompts

    Fetch, skill, file read, sandbox network, Claude in Chrome, workflow script and notebook edit permission prompts now match the look of file edit prompts. Bash, PowerShell and Monitor prompts show the command between dashed lines.

  • Send now (ctrl+enter) in a subagent’s view

    Ctrl+enter now moves the subagent’s running command to the background, so your message is read right away instead of waiting for the command to finish.

  • claude.ai artifact link reads

    WebFetch now asks the same questions as the Artifact tool’s read: no artifact prompt while the session’s network access is on, and one per artifact while it is off. An auto-mode yes no longer counts where only you can answer.

  • List scrollbars in fullscreen mode

    In most lists the bar no longer shifts as the “N more” rows come and go, and it now has ↑/↓ arrows you can click or hold to scroll.

  • Context window in fallback notices

    The model fallback notice and the autocompact-thrashing error now say when a fallback dropped the context window from 1M to 200K tokens.

  • Other improvements

    • Replies from background agents to your messages no longer open with a separate recap of what you said.
    • The external editor (Ctrl+G): editors that take a line number now open on the line your cursor is on in the prompt.
    • Slash command suggestions respond faster while typing when many skills or plugin commands are installed; command descriptions now match by word prefix.
    • The output style picker opens on your current style instead of Default, with each style’s description on the line under its name; number keys no longer pick a style.
    • The closing line of a hook’s detail screen in /hooks now says “this hook” instead of “it”.
    • SDK and -p sessions stay responsive when a host re-sends an MCP server enable for a server that is already connected.
    • The protocol page a Claude apps gateway serves at /protocol now says not to reject unknown input and matches what Claude Code sends today.
    • [VSCode] The Manage plugins dialog says when a turned-off plugin is still on because of other settings, and explains a plugin folder clash.
    • [Claude Tag] Titles of sessions started from Slack, as shown on claude.ai, now read as the words you typed, without Slack user IDs or escape codes.

Changed behavior

  • One retry limit per model call (changed)

    One limit now covers a whole model call, so with the default retry settings a failing call sends at most 14 requests.

  • Narrower --bare mode (changed)

    --bare now connects only the MCP servers named on the command line, sends the model no system reminders, and starts no background tasks. Under --bare, a shell command that reaches its timeout now stops instead of moving to the background.

  • npm sources for plugin installs (changed)

    Plugin installs refuse npm sources that are git repositories or folders, and install plugin dependencies only from registry packages.

  • Send now (ctrl+enter) and a skill’s shell command (changed)

    Ctrl+enter moves a skill’s own shell command to the background instead of ending it.

  • List screens (changed)

    • List screens (/artifacts, /mcp, /skills, /hooks and others) always line up each row’s details in one column after the names.
    • Overflow rows read ”↑ N more” / ”↓ N more” instead of “N more above” / “N more below”.
    • /hooks opens on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three.
    • The theme picker is a scrolling list that fits your terminal instead of pushing the preview off screen; number keys no longer pick a theme.
  • /exit’s Remove worktree (changed)

    Remove worktree now runs after Claude Code stops the servers and shells it started there, which on Windows could keep the folder from being deleted.

  • Other changes

    • Prompts sent while nothing is running or queued show in the normal text color right away instead of gray.
    • The WebFetch error for a rate-limited domain safety check tells Claude not to retry it in a loop.
    • The claude-api skill’s Managed Agents examples create environments with limited networking.
    • The browser link is removed from /ultrareview and claude ultrareview output.
    • [VSCode] Stop and Escape end only the current turn; background agents keep running and can be stopped one by one from the agent map.
    • [VSCode] The ”✻ Claude Code” status bar item shows in every window, so you can open Claude when no file is open.
    • [Cloud sessions] A routine’s page reads “Due” with the scheduled time, instead of a next run time in the past, when a scheduled run is late and hasn’t started.

Bug fixes

Resume & auth

  • claude --resume and --continue sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed.
  • Several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire.
  • macOS sessions still showing “Not logged in” or “Login expired” after /login succeeds in another Claude Code window when a leftover ~/.claude/.credentials.json exists.
  • Every turn failing when the Anthropic API refuses the model your default or a model alias resolves to; Claude Code now retries once on the previous model of the same tier.
  • Refusal and --fallback-model retries failing when the fallback model can’t run fast; they now run at standard speed, with a one-time notice in interactive sessions.
  • claude auth status reporting a Console sign-in’s stored API key as claude.ai; it now reports api_key, and the VS Code extension treats that session as an API key session.
  • /status listing an Anthropic profile beside an API key as if both were in effect; the profile is now marked as not in use.
  • API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions.
  • The commit attribution reminder being re-sent inside tool output when a model fallback lasts only one turn.
  • [Windows] claude --bg and the agents view refusing a folder that claude already trusts when its trust record was saved with different letter case.

Secret redaction in logs & transcripts

  • MCP error messages showing a credential’s value when “Bearer” or “Basic” came before its key name.
  • Percent-encoded Bearer tokens being only partly masked in error messages.
  • Redacted logs and transcripts showing a secret whose key name has an invisible character inside, such as a zero-width space.
  • Logs and transcripts showing part of a URL password that contains punctuation such as ), quotes, ], & or a second @, or that runs past a / to a bracketed host such as [::1] in an ssh URL.
  • The session transcript in the zip that /feedback saves to disk containing invalid JSON lines after secret redaction.

Remote Control & cloud sessions

  • Remote Control sessions (including claude remote-control) staying connected after your organization’s policy turns Remote Control off; they now disconnect with a notice.
  • Claude not being told when a file attached to a message sent over Remote Control did not arrive, and a file sometimes getting only 10 seconds for its last download try.
  • A Remote Control message that arrived while Claude Code was exiting being marked delivered and then never answered; it now stays queued for the session’s next run.
  • Cloud sessions with very large histories never waking up because the container was stopped while the transcript was still loading.
  • Files with very long names not reaching a cloud session when attached to it.
  • [Cloud sessions] An answered question card or approved tool call getting no reply when the session had gone idle after Claude sent a message.
  • [Cloud sessions] Clearing an organization environment’s setup script in admin settings leaving new cloud sessions still running the old script.
  • [Cloud sessions] The Runner actions menu on the self-hosted environments admin page closing on its own a few seconds after it opened.
  • [Cloud sessions] Routine runs whose cloud session never started showing as Succeeded in the Runs pane, the routine’s page and the sidebar; they now show as Failed.
  • [Cloud sessions] Clicking an audio or video file in a cloud session’s Outputs card opening an empty file search instead of playing the file.

MCP & plugins

  • MCP connectors listing no tools for up to a day after their server dropped the older MCP handshake.
  • A repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working.
  • Headless sessions repeating the “MCP servers require authentication” reminder after a successful re-authentication when the MCP discovery cache is enabled.
  • /usage not crediting an MCP server for a tool call made while that server was still connecting or had only just connected, such as right after a restart.
  • Plugins enabled on claude.ai occasionally going missing from Claude Code for a session after a transient server error.
  • Plugin errors for a marketplace Claude Code refuses to load saying “not found”; they now say why and how to fix it.
  • /plugin’s Discover tab showing a marketplace name unquoted in its “Checking … for new plugins” line when its rows already show that name in quotes.

Subagents & background work

  • A message typed into a running subagent showing twice in its transcript after the subagent read it.
  • Subagent hand-back messages showing a raw task id instead of the agent’s name when the subagent had no registered name.
  • Foreground subagents sometimes missing the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions that have them enabled.
  • Subagents spawned with worktree isolation loading the project CLAUDE.md and its imports a second time from the worktree copy on their first file read.
  • Workflow tool subagents being restarted from their original prompt when a connection stalled for a few minutes mid-response.
  • /compact, /clear, and /rewind typed while viewing a background agent’s or teammate’s transcript silently acting on the main conversation; a dialog now names the target and asks first.
  • Background jobs showing done while waiting for your approval.

Display

  • A click on the space between words of a collapsed row (such as “Thought for 4s”) highlighting the row without expanding it in fullscreen mode.
  • A row with no details, such as an action row with a long name, pushing every other row’s details to the right in list screens.

Claude apps gateway

  • The spend meter pricing 1-hour prompt cache writes at the cheaper 5-minute rate.
  • The spend meter counting only the first model call’s input tokens on streamed turns that run a server-side tool such as web search.

[VSCode]

  • A second copy of a conversation opening in a tab when it was already open in the side bar; the side bar now switches to it.
  • Settings dialogs reporting a failed save, without re-checking, when Claude Code printed more than 1 MB of output.
  • An endless “Teleporting session…” spinner when the extension stops responding.

[Claude Tag]

  • Memory recall finding nothing in organizations that cannot use the default Sonnet model.
  • A Slack channel losing its Claude settings when an Enterprise Grid admin moves it to another workspace and the first post afterward doesn’t mention Claude.
  • Claude in a Slack thread occasionally starting over on a fresh machine, losing work it hadn’t pushed, when your reply answered a question it had just asked.
  • Public channel names on the spend limits page showing as raw Slack IDs in larger organizations.

Notes

  • A failing API call now sends at most 14 requests with the default retry settings — one retry limit covers the whole model call.
  • --bare now connects only the MCP servers named on the command line — it also sends no system reminders and starts no background tasks, and a shell command that reaches its timeout stops instead of moving to the background.
  • Plugins whose npm source is a git repository or folder no longer install — plugin dependencies install only from registry packages.
  • A project or user skill named verify now runs right before Claude commits — except for docs-only and tests-only commits.
  • Number keys no longer pick a theme or an output style in their pickers.
  • [VSCode] Stop and Escape no longer stop background agents — stop them one by one from the agent map.