What changed
Claude Code 2.1.287 shipped on October 1, 2026. It introduces Claude Mods, which let plugins modify deeper behavior, along with a first built-in mod, You should know. Behavior changes include a default 1M context window on Bedrock, Vertex, Foundry and the Claude apps gateway, a broader meaning for MCP alwaysLoad: false, and stricter handling of risky shell writes. Fixes cluster around screen reader mode, files sent from Remote Control and cloud sessions, MCP connections, model switching, and permission safeguards.
New features
-
Claude Mods
Plugins may now modify deeper behavior in Claude Code.
-
You should know (built-in mod)
A side agent watches your back and flags things you or Claude might miss. Turn it on with
/plugin enable cc-plugin-you-should-know@builtin(for first-party sessions with telemetry on). -
n:<text>filter in the agents viewFinding a session in
claude agentsmeant scanning the list. The newn:<text>filter matches session names and tasks; a filter now shows matches in collapsed sections, and Enter opens the first match. -
URL prompts from MCP servers
MCP servers on the 2025-11-25 protocol can now send URL prompts, for example to sign in. If a server no longer connects after this update, add
"bareElicitationCapability": trueto its MCP config entry. -
prompt_texton the OpenTelemetryuser_prompteventBackends that nest dotted keys had trouble with
prompt. The event now carriesprompt_text, a copy ofprompt; drop or mask it wherever you drop or maskprompt. -
Built-in
gh apifor self-hosted runnersSessions that use Anthropic-managed git on macOS and Linux machines without the GitHub CLI installed now get a built-in
gh api(REST only). -
[Windows] Startup warning when no shell tool is left
Denying the Bash tool also turns off the PowerShell tool, leaving Claude with no shell tool. Claude Code now warns about this at startup.
-
[VSCode] additions
- “Run in background” on a running command or sub-agent, to move it to the background and keep working.
- The output of background shells and Monitors on their cards in the agent map.
Key improvements
-
/confignavigationSettings that cycle now show ‹ › and step both ways with ←/→, narrow terminals stack each value under its label, and PgUp/PgDn page the list.
-
Plugin marketplace errors and dependencies
Marketplace errors now say in plain words why a marketplace was ignored or refused, and what to do. Plugin listings note when a plugin’s dependencies were not installed, and updating a plugin retries an install that did not finish.
-
Files Claude sends from cloud sessions and Remote Control
An upload that fails on a timeout, a network error or a 502, 503 or 504 is now retried once. Large files stream from disk instead of being read into memory, and a file over the size limit is refused with the server’s limit named. When a file can’t be sent for a reason that may be temporary, Claude mentions that you can ask for it again in a few minutes, and it explains server refusals such as an oversized image.
-
Large MCP tool results
Large MCP tool results now use less memory and produce smaller session files, with no extra upload to count tokens for results far over the limit.
-
MCP startup in headless mode
A remote server whose first connect fails transiently is now retried without waiting for the slowest server to finish connecting.
-
Priority “now” messages in SDK sessions
A message sent with priority “now” no longer cancels a running web fetch or web search; it keeps loading in the background.
-
/skillnames typed mid-messageClaude is now told they are skills, including
disable-model-invocationones. -
[Windows] Faster Bash tool
A subshell that ran before every command has been removed.
-
Other improvements
/memory: the left and right arrow keys flip its on/off settings, such as Auto-memory.- Better contrast for the prompt input border in light themes and for the ❯ before your earlier messages.
- The prompt for a held message from another session, and MCP and other tool permission prompts, now show their content between dashed lines, matching file edit prompts.
- When Amazon Bedrock rejects a model ID, the Claude apps gateway’s error shows developers which model is unavailable, and the gateway log names the ID that was sent.
- [VSCode] The Manage plugins dialog says what went wrong when a marketplace add, remove or refresh fails.
- [Claude Tag] In long Slack threads, background work no longer reposts Claude’s task list as a new message on its own, so people following the thread aren’t notified.
- [Code Review] The failed-review card on a pull request whose conversation is locked now says the lock blocked the review and that nothing was posted or charged.
Changed behavior
-
1M context by default for Opus 4.7+ and Fable (changed)
On Bedrock, Vertex, Foundry and the Claude apps gateway, Opus 4.7+ and Fable now use a 1M context window by default, with no
[1m]suffix.CLAUDE_CODE_DISABLE_1M_CONTEXT=1keeps 200K. -
MCP
alwaysLoad: false(changed)Setting
alwaysLoad: falseon an MCP server now defers all of that server’s tools behind tool search. -
Risky shell writes (changed)
- A shell write through a repo-committed symlink onto a sensitive file or out of the working tree now names where it lands and waits for a person, on lines with a
~target too. - Whole-tool
Bashallow rules and allowing hooks now prompt for, rather than run, shell writes to files Claude Code’s file tools refuse outright (the Anthropic profile store, the host credentials file).
- A shell write through a repo-committed symlink onto a sensitive file or out of the working tree now names where it lands and waits for a person, on lines with a
-
Replies and slash commands in
claude agents(changed)Replies from
claude agentsarrive as queued messages; slash commands other than/stopsent while a turn is running now run when it ends. -
Permission prompt order (changed)
Waiting permission prompts show oldest first, so a new prompt no longer covers the one you’re reading. Prompts with a countdown still open on top.
-
Effort level on automatic model switches (changed)
An automatic model switch after a flagged message now keeps your current effort level instead of the new model’s default.
-
Other changes
- Right-click paste on Windows and Linux, and middle-click paste on Linux, happen when the button is released; moving the pointer away before releasing cancels it.
- Screen reader mode writes new or changed lines without first pausing with the cursor at the start of the line; set
CLAUDE_AX_PREPARK_MS=50to restore the pause. - [VSCode] The Claude in Chrome “Enabled by default” switch also connects the editor’s own sessions, which still ask before browser actions.
Bug fixes
Permissions & security
- A dangerous
rm(such as one on/or the home directory) losing its always-ask safeguard when the same command also redirected output to a~or wildcard path. - Organization per-tool permission ceilings being silently dropped for an MCP tool named
__proto__. - Bash permission prompts showing internal parser names such as “Contains simple_expansion” instead of a plain explanation.
- Sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable.
- A revoked claude.ai login showing a generic
API Error: 401instead of “OAuth token revoked”; in-pmode the error now starts with “Failed to authenticate”.
Models & context
- Picking Fable in
/modelon a claude.ai login saving the current version’s id; your saved default now follows the newest Fable like Opus and Sonnet do. - Switching between Opus 5.5 and Sonnet 5.5 (
/model,opusplan) rewriting earlier MCP tool announcements, which could drop earlier extended thinking. claude -pand SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running.- Bedrock and Vertex startup model checks ignoring an enforced
availableModelslist, which could collapse/modelto one Opus row. - Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail’s message when the reply began with thinking.
/advisorpairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped.- Fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it.
- A folder’s CLAUDE.md being attached a second time after resuming a session or after a compaction.
- The commit attribution reminder being delivered inside a tool result after a compaction.
CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETASnot removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject.- [Bedrock, Vertex, Mantle] Model availability checks under
CLAUDE_CODE_SKIP_*_AUTHsending a differentAuthorizationheader than real requests whenANTHROPIC_CUSTOM_HEADERSrepeats it.
Remote Control & cloud sessions
- Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries.
claude remote-controlfailing to register behind an HTTP proxy with a misleading “Check your organization permissions” error.- [macOS] Remote Control sessions started with
claude remote-controlstopping mid-turn when the Mac went to idle sleep. - Files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds.
- PNG, JPEG and WebP images over 8,000 pixels on a side failing to send from a remote session; Claude now sends a scaled-down copy.
- Messages sent from the Claude apps with 17 to 20 attached files delivering only the first 16.
- Cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted.
- Repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory.
- SessionStart hooks from synced plugins not running in new cloud sessions.
- A plugin reload that overlapped the startup
--plugin-urldownload corrupting the session’s cached copy of the plugin archive. - [Cloud sessions] Occasional failures to fetch from or push to GitHub when GitHub briefly refused a newly issued access token.
MCP & plugins
- An MCP connector tool call occasionally running twice, or the connector’s calls failing until restart, when its server changed which MCP protocol version it supports.
- Headless sessions reporting an MCP server as needing authentication after one refused call, even though later calls succeed.
- Claude being told to page large MCP results saved as JSON with Read’s offset and limit, which cannot split one long line.
claude plugin marketplace add --sparseandgit-subdirplugin installs failing with “transport ‘http’ not allowed” when the repository is served over plain http.
Hooks, skills & SDK
- Hooks configured with
asyncRewakewaking Claude over and over with “found issues” notifications when the hook’s script file is missing; the broken hook is now reported once. - The transcript’s “N hooks ran” summary and the verbose debug log’s matched-hooks count including Claude Code’s internal callbacks, so one configured hook no longer shows as two.
--output-format stream-jsonand the SDK not streaming the turns of acontext: forkskill run by typing/<skill>as the prompt, as they do for the Skill tool’s fork.- Tool heartbeats not reaching SDK hosts while the model’s response stream was stalled with no data arriving.
--include-partial-messagessending a cut-short reply’smessage_stoplate or never, so apps could show the reply as still in progress.
Agents view & background sessions
- Background sessions that could not be reopened from
claude agentsafter the agent exited and removed the worktree the session was started in. claude agentssometimes not showing the permission prompt a background session is waiting on.
Screen reader mode & accessibility
- The cursor left away from the typed text in search boxes (such as
/resumeand/permissions) and sign-in code fields. - Enter refused with nothing typed on
/rewind’s summarize options, whose added context is optional. - A “Tab to amend” hint on approval prompts, where Tab does nothing.
- Arrow keys that do nothing listed in
/permissionsand/mcp, and “Select with numbers” said in empty menus or while a search box has the keys. - The changed lines left out in file edit approval prompts and other diffs.
- The
claude --teleportprogress screen, and an MCP form field while it is being checked, sent to the screen reader again on every spinner frame. - The top lines of a second approval prompt, a changed
/configrow or the rejected-plan line left out when the previous screen was taller than the terminal window. - Times in
claude agentschanging every second; they now change at most every 10 seconds. - The running-tool dot and three spinners still moving with the “Reduce motion” setting on, and
/rewind’s confirm screen updating its “ago” time while you type a note.
Other
- The Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached.
- A cause of fullscreen sessions on slow or busy machines exiting with “Claude Code exited after an unrecoverable interface error” while a scroll key was held in a long conversation.
/feedbackand/bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report./ultrareviewgiving advice about.git/info/attributeswhen the upload stops on a committed.gitattributesit cannot read (such as one saved as UTF-16), and upload refusals advising you to copy a variable named by a repository’s settings file into your own user settings./desktopquoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause.- [Windows] Interactive
claudehanging or crashing with “Raw mode is not supported” when its input is piped or redirected; it now says why and exits (use-pfor piped input).
[VSCode]
- Settings dialogs blaming a timeout when Claude Code’s reply was too large to confirm a save.
- Reopening a cloud session that the side bar already brought to this machine opening it again in a new tab; the side bar is shown instead.
- The side bar’s Web tab not listing cloud sessions started after the window loaded; a failed load now says “Remote server is not connected” instead of “No web sessions yet”.
- A tab restored after a reload starting a second Claude process on a conversation the side bar already has open; it now shows the “still open somewhere else” notice.
- Tool-row file links, session-list links and two hints showing in plain text.
- A background agent’s still-running command showing as failed once the main turn ended.
- A user’s own
/usageor/contextcommand opening the extension’s dialog instead of running when picked from the command menu. - File links in the plan preview tab doing nothing when clicked; they now open the file like links in chat replies.
- Opening a tool’s input or output in an editor tab failing with “Timeout waiting after 1000ms” on remote hosts such as WSL when the tab is slow to appear.
[Claude Tag]
- Claude posting a failure warning, such as a spend limit notice, in a Slack thread when a background event like GitHub activity woke it and nobody was waiting on a reply.
- The spend limits page in admin settings leaving out recently created and private channels in organizations with many channels.
[Code Review]
- Finding comments and their “Why this was flagged” text stopping mid-sentence; they now end on a complete sentence.
- Code Review skipping a pull request after a new push when its review had failed twice on the previous commit; it now reviews the latest commit.
Notes
- You should know is opt-in — turn it on with
/plugin enable cc-plugin-you-should-know@builtin; it is for first-party sessions with telemetry on. - Opus 4.7+ and Fable use a 1M context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway — set
CLAUDE_CODE_DISABLE_1M_CONTEXT=1to keep 200K. - If an MCP server no longer connects after this update, add
"bareElicitationCapability": trueto its MCP config entry. - MCP servers with
alwaysLoad: falsenow have all of their tools deferred behind tool search. - If you collect prompts via OpenTelemetry, handle
prompt_texttoo — drop or mask it wherever you drop or maskprompt. - Slash commands other than
/stopsent while a turn is running now run when it ends.