claudekit / updates / claude-code-2-1-288
[ PATCH · ]

Claude Code 2.1.288

A prompt cleared with Ctrl+C can now be brought back with Up, /code-review gains `--max-findings`, and the agents view adds Ctrl+F to find a session by name. Mid-response API timeouts no longer fail the turn, and fixes focus on resume, auto mode, plugins, permission safeguards, and cloud sessions.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.288 shipped on October 2, 2026. It adds everyday conveniences such as recovering a prompt cleared with Ctrl+C, controlling how many findings /code-review reports, and finding a session by name in the agents view. Fixes cluster around mid-response timeouts and --resume reliability, auto mode, plugins and mods, permission safeguards, and cloud sessions. Behavior changes include the background command time limit and the rename of claude project purge.

New features

  • Recover a prompt cleared with Ctrl+C

    Clearing a draft with Ctrl+C used to lose it. Now pressing Up on the empty prompt brings the draft back, including pasted text and images.

  • --max-findings <n>|all for /code-review

    /code-review reported findings up to a fixed limit. --max-findings now reports more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default.

  • Ctrl+F and Alt+↑/↓ in the agents view

    Ctrl+F finds a session by name, and Alt+↑/↓ jumps between groups. Both, and rename, can be rebound in keybindings.json.

  • Re-authenticate prompt for MCP OAuth scope

    When an MCP server asks for more OAuth scope during a tool call, Claude Code now shows a re-authenticate prompt.

  • $.ui.selection() for mods

    Returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row.

  • Built-in gh api in cloud sessions

    Cloud sessions whose image has no GitHub CLI now get a built-in gh api. The built-in also no longer sends control characters from file names, jq filters or GitHub errors to the terminal.

  • Screen reader mode: permission mode announcement

    When you approve a plan, including with Shift+Tab, screen reader mode announces the new permission mode.

Key improvements

  • Auto mode in long conversations

    When a conversation grew too long for the client-side safety classifier to review, every tool call prompted or failed. The conversation is now compacted instead.

  • Remote Control recovery from an expired server credential

    Sessions stay connected during renewal, and are kept if renewal gives up after a server outage.

  • Faster first turn in cloud sessions

    A new conversation’s first turn no longer waits for a stdio MCP server whose config sets alwaysLoad: false.

  • Screen reader mode

    • Short announcements, such as a deleted word, now stay on screen until your next key press or until something above them on screen changes.
    • Answered questions in question dialogs now say “answered” beside their box.
  • Built-in gh api on self-hosted runners

    A refused gh command now prints its gh api equivalent, --paginate follows every page of a repository’s lists, and a nested claude no longer removes it.

  • Other improvements

    • “You should know” notes say “we”, “the main agent” or “you” depending on who was responsible for a decision.
    • An artifact database write refused at the database’s size limit now states the limit and what frees space.
    • Bash permission prompts give a shorter reason when part of a command can’t be checked before it runs.
    • Improved /usage-credits message for Team and Enterprise members whose organization has turned off usage credit requests.
    • [Claude Tag] Claude also follows a related Slack thread in another channel that it only read, so updates there reach the conversation that depends on them.
    • [Claude Tag] Save errors on a channel’s Configure page: too-long channel instructions now say to shorten them, and a save refused for lost access no longer says to try again.

Changed behavior

  • Background command time limit (changed)

    The limit now applies only in unattended sessions (-p, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit.

  • Auto mode classifier model (changed)

    The client-side auto mode classifier ignores an ANTHROPIC_DEFAULT_SONNET_MODEL pin that names Claude Sonnet 5.5 or Opus 5.5 and uses Claude Sonnet 5 instead.

  • claude project purge → claude purge (changed)

    The old name still works and prints a notice.

  • Enter in agents view search (changed)

    With the n: filter or Ctrl+F search, Enter opens the session whose name matches best instead of the top row.

  • /autocompact per model (changed)

    The auto-compact window is saved per model, so each model keeps its own setting when you switch.

  • MCP URL prompts (changed)

    URL prompts from servers that can’t report when you’re done now wait for “I’m done, continue” before the tool call continues, so you can finish in the browser first.

Bug fixes

Responses, compaction & resume

  • Mid-response API timeouts failing the turn; non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried.
  • Long conversations failing with “Prompt is too long” instead of auto-compacting when the last reply reported zero token usage.
  • --resume sometimes dropping files and other context that a compaction had just restored.
  • A resumed session sometimes not saving the last response of a turn, so the next --resume showed the prompt unanswered.
  • Resume occasionally loading a transcript cut short when the same session rewrote the file during the load.
  • Resuming a conversation started on 2.1.286 or earlier dropping the model’s earlier thinking.
  • The first request in a fresh environment or after a model switch using the built-in output limit and auto-compact window, not the server’s; that request may now wait up to 1.5 seconds.
  • Unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts.

Models & providers

  • Session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns structured outputs off.
  • A Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request.
  • A second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in.
  • Sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation.

Auto mode & permissions

  • A dangerous rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule (#96300).
  • A BASHPID assignment whose value the shell would evaluate as arithmetic being allowed silently; the Bash tool permission check now prompts.
  • PreToolUse and PermissionRequest hooks being skipped when matching them failed or the tool’s input could not be serialized to JSON; the call is now blocked.
  • Sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references.
  • Auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash.
  • Auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent.
  • Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with disableAutoMode or an older model); typing, navigation and JavaScript still ask.
  • sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on.
  • /login reporting “Login successful” when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn’t take effect (#73861).
  • /login in a --bare session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work.

Plugins & mods

  • A mod’s button sometimes running a different button’s action when pressed on a view drawn before Claude Code restarted.
  • A plugin’s pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code.
  • Plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults.
  • A plugin’s tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree.
  • git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04’s 2.34).
  • claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key; the clone now falls back to HTTPS and prints a notice.
  • owner/repo plugin marketplaces showing only the second attempt’s error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top.
  • Plugins loaded with --plugin-dir not showing “Configure options” in /plugin.
  • Background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running.
  • Agent teams: a plugin-defined agent spawned by name running with the defaults instead of its own prompt, tools, disallowedTools and effort.
  • claude plugin test reporting mods as turned off remotely when it had only read an out-of-date saved setting.

MCP, LSP & hooks

  • MCP tool calls sometimes running twice when a remote server’s result was over 16 MB or could not be parsed.
  • Subagents in Claude Desktop’s Code tab getting none of the tools of a user-configured MCP server named memory.
  • The Agent tool in claude mcp serve always reporting no available agents and rejecting every subagent_type.
  • LSP tool calls hanging indefinitely when a language server uses dynamic capability registration or stops responding; requests now time out after 60s (per-server requestTimeout).
  • Path-scoped .claude/rules and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them).
  • idle_prompt notification hooks firing while background agents are still running (#93672).
  • The InstructionsLoaded hook omitting agent_id and agent_type when a subagent’s file access loads a rule or nested CLAUDE.md; rules and nested CLAUDE.md files loaded on file access now also report effort.
  • OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals.
  • Permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event.

Cloud sessions & Remote Control

  • Cloud sessions that restarted on a newly picked model replying with that model after the server refused it.
  • Restarted cloud sessions restoring a model that the organization’s enforced model list refuses.
  • Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes.
  • Prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device.
  • Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved.
  • Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process.
  • Claude reporting a message to another session as delivered when that session held it; the notice now says it wasn’t delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn.
  • [Cloud sessions] The Cloud sessions switch in Claude Code admin settings staying locked off while an unrelated security setting was loading or had failed to load.
  • [Cloud sessions] Pressing Stop while a self-hosted runner was still starting not cancelling the queued message, which could then run once the runner was up.

Terminal & accessibility

  • Fullscreen sessions exiting with “unrecoverable interface error” when opening the background tasks dialog while a plugin or mod showed rows above the prompt.
  • The keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, /tui).
  • The “What should Claude do instead?” hint showing on the Interrupted row after sending queued messages with ctrl+enter.
  • The terminal cursor not following the typed text in the fullscreen transcript viewer’s search and in /theme’s custom color search.
  • /permissions in screen reader mode: typing a rule’s number now picks it instead of opening the search box.

Other

  • Headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it.
  • A stall when launching an agent whose tools: lists very many Agent(...) entries.
  • The npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder claude stub was installed.
  • Claude leaving out your organization’s design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings.

[VSCode]

  • A claude.ai connector staying on “Needs authentication” after you authorize it; the MCP servers dialog now offers Check connection.
  • The opt-in New Conversation shortcut (Cmd/Ctrl+N) starting a conversation in every visible Claude view instead of only the one you are in.
  • The chat view resuming the next saved session after you archive the one it shows; it now starts a new conversation instead.

[Claude Tag]

  • Claude Tag admin settings offering a “Remove this scope” option, which always failed, on channels whose settings were created automatically.

Notes

  • Cleared a prompt with Ctrl+C? Press Up on the empty prompt to bring the draft back.
  • The background command time limit now applies only in unattended sessions (-p, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit.
  • claude project purge is now claude purge — the old name still works but prints a notice, so update scripts that use it.
  • If Mantle or your gateway rejects structured outputs, set CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn them off.
  • An ANTHROPIC_DEFAULT_SONNET_MODEL pin to Sonnet 5.5 or Opus 5.5 is ignored by the client-side auto mode classifier, which uses Claude Sonnet 5 instead.
  • /autocompact is now saved per model — check each model’s setting after you switch.