↑Improved stalled API stream handling: streams now abort after 5 minutes of no data and retry non-streaming instead of hanging indefinitely
↑Improvednetwork error messages: connection errors now show a retry message immediately instead of a silent spinner
↑Improvedfile write display: long single-line writes (e.g. minified JSON) are now truncated in the UI instead of paginating across many screens
↑Improved/doctor layout with status icons; press `f` to have Claude fix reported issues
↑Improved/config labels and descriptions for clarity
↑Improvedskill description handling: raised the listing cap from 250 to 1,536 characters and added a startup warning when descriptions are truncated
↑ImprovedWebFetch to strip `<style>` and `<script>` contents from fetched pages so CSS-heavy pages no longer exhaust the content budget before reaching actual text
↑Improved stale agent worktree cleanup to remove worktrees whose PR was squash-merged instead of keeping them indefinitely
+Added/team-onboarding command to generate a teammate ramp-up guide from your local Claude Code usage
+AddedOS CA certificate store trust by default, so enterprise TLS proxies work without extra setup (set `CLAUDE_CODE_CERT_STORE=bundled` to use only bundled CAs)
~/ultraplan and other remote-session features now auto-create a default cloud environment instead of requiring web setup first
↑Improved brief mode to retry once when Claude responds with plain text instead of a structured message
↑Improvedfocus mode: Claude now writes more self-contained summaries since it knows you only see its final message
↑Improved tool-not-available errors to explain why and how to proceed when the model calls a tool that exists but isn't available in the current context
↑Improved rate-limit retry messages to show which limit was hit and when it resets instead of an opaque seconds countdown
↑Improved refusal error messages to include the API-provided explanation when available
↑Improvedclaude -p --resume <name> to accept session titles set via `/rename` or `--name`
↑Improvedsettings resilience: an unrecognized hook event name in `settings.json` no longer causes the entire file to be ignored
↑Improved plugin hooks from plugins force-enabled by managed settings to run when `allowManagedHooksOnly` is set
✓Fixed a command injection vulnerability in the POSIX `which` fallback used by LSP binary detection
✓Fixed a memory leak where long sessions retained dozens of historical copies of the message list in the virtual scroller
✓Fixed--resume/`--continue` losing conversation context on large sessions when the loader anchored on a dead-end branch instead of the live conversation
✓Fixed--resume chain recovery bridging into an unrelated subagent conversation when a subagent message landed near a main-chain write gap
✓Fixed a crash on --resume when a persisted Edit/Write tool result was missing its `file_path`
✓Fixed a hardcoded 5-minute request timeout that aborted slow backends (local LLMs, extended thinking, slow gateways) regardless of `API_TIMEOUT_MS`
✓Fixedpermissions.deny rules not overriding a PreToolUse hook's `permissionDecision: "ask"` — previously the hook could downgrade a deny into a prompt
✓Fixed--setting-sources without `user` causing background cleanup to ignore `cleanupPeriodDays` and delete conversation history older than 30 days
+Added interactive Google Vertex AI setup wizard accessible from the login screen when selecting "3rd-party platform", guiding you through GCP authentication, project and region configuration, credential verification, and model pinning
+AddedCLAUDE_CODE_PERFORCE_MODE env var: when set, Edit/Write/NotebookEdit fail on read-only files with a `p4 edit` hint instead of silently overwriting them
+Added Monitor tool for streaming events from background scripts
+Added subprocess sandboxing with PID namespace isolation on Linux when `CLAUDE_CODE_SUBPROCESS_ENV_SCRUB` is set, and `CLAUDE_CODE_SCRIPT_CAPS` env var to limit per-session script invocations
+Added--exclude-dynamic-system-prompt-sections flag to print mode for improved cross-user prompt caching
+Addedworkspace.git_worktree to the status line JSON input, set whenever the current directory is inside a linked git worktree
+Added W3C TRACEPARENT env var to Bash tool subprocesses when OTEL tracing is enabled, so child-process spans correctly parent to Claude Code's trace tree
~LSP: Claude Code now identifies itself to language servers via `clientInfo` in the initialize request
~Updated the /claude-api skill to cover Managed Agents alongside Claude API
−Dropped /compact hints when `DISABLE_COMPACT` is set.
↑Improved/resume filter hint labels and added project/worktree/branch names in the filter indicator
↑Improved footer indicators (Focus, notifications) to stay on the mode-indicator row instead of wrapping at narrow terminal widths
↑Improved/agents with a tabbed layout: a Running tab shows live subagents, and the Library tab adds Run agent and View running instance actions
↑Improved/reload-plugins to pick up plugin-provided skills without requiring a restart
↑ImprovedAccept Edits mode to auto-approve filesystem commands prefixed with safe env vars or process wrappers
↑ImprovedVim mode: `j`/`k` in NORMAL mode now navigate history and select the footer pill at the input boundary
↑Improved hook errors in the transcript to include the first line of stderr for self-diagnosis without `--debug`
↑ImprovedOTEL tracing: interaction spans now correctly wrap full turns under concurrent SDK calls, and headless turns end spans per-turn
+Added● N running indicator in `/agents` next to agent types with live subagent instances
+Added syntax highlighting for Cedar policy files (`.cedar`, `.cedarpolicy`)
~Updated/claude-api skill to cover Managed Agents alongside the Claude API
↑ImprovedAccept Edits mode to auto-approve filesystem commands prefixed with safe env vars or process wrappers (e.g. `LANG=C rm foo`, `timeout 5 mkdir out`)
↑Improved auto mode and bypass-permissions mode to auto-approve sandbox network access prompts
↑Improvedsandbox: `sandbox.network.allowMachLookup` now takes effect on macOS
↑Improvedimage handling: pasted and attached images are now compressed to the same token budget as images read via the Read tool
↑Improved slash command and @-mention completion to trigger after CJK sentence punctuation, so Japanese/Chinese input no longer requires a space before `/` or `@`
↑Improved Bridge sessions to show the local git repo, branch, and working directory on the claude.ai session card
↑Improvedfooter layout: indicators (Focus, notifications) now stay on the mode-indicator row instead of wrapping below
↑Improved context-low warning to show as a transient footer notification instead of a persistent row
✓Fixed--dangerously-skip-permissions being silently downgraded to accept-edits mode after approving a write to a protected path
✓Fixed and hardened Bash tool permissions, tightening checks around env-var prefixes and network redirects, and reducing false prompts on common commands
✓Fixed permission rules with names matching JavaScript prototype properties (e.g. `toString`) causing `settings.json` to be silently ignored
✓Fixed managed-settings allow rules remaining active after an admin removed them until process restart
✓Fixed Bedrock requests failing with `403 "Authorization header is missing"` when using `AWS_BEARER_TOKEN_BEDROCK` or `CLAUDE_CODE_SKIP_BEDROCK_AUTH` (regression in 2.1.94)
+VSCodeAdded a warning banner when settings.json files fail to parse, so users know their permission rules are not being applied
~Changed default effort level from medium to high for API-key, Bedrock/Vertex/Foundry, Team, and Enterprise users (control this with `/effort`)
~Plugin skills declared via `"skills": ["./"]` now use the skill's frontmatter `name` for the invocation name instead of the directory basename, giving a stable name across install methods
↑Improved--resume to resume sessions from other worktrees of the same repo directly instead of printing a `cd` command
↑VSCodeReduced cold-open subprocess work on starting a session
✓Fixed agents appearing stuck after a 429 rate-limit response with a long Retry-After header — the error now surfaces immediately instead of silently waiting
✓Fixed Console login on macOS silently failing with "Not logged in" when the login keychain is locked or its password is out of sync — the error is now surfaced and `claude doctor` diagnoses the fix
✓Fixed plugin skill hooks defined in YAML frontmatter being silently ignored
✓Fixed plugin hooks failing with "No such file or directory" when `CLAUDE_PLUGIN_ROOT` was not set
✓Fixed${CLAUDE_PLUGIN_ROOT} resolving to the marketplace source directory instead of the installed cache for local-marketplace plugins on startup
✓Fixed scrollback showing the same diff repeated and blank pages in long-running sessions
✓Fixed multiline user prompts in the transcript indenting wrapped lines under the `❯` caret instead of under the text
✓Fixed Shift+Space inserting the literal word "space" instead of a space character in search inputs
+AddedforceRemoteSettingsRefresh policy setting: when set, the CLI blocks startup until remote managed settings are freshly fetched, and exits if the fetch fails (fail-closed)
+Added interactive Bedrock setup wizard accessible from the login screen when selecting "3rd-party platform" — guides you through AWS authentication, region configuration, credential verification, and model pinning
+Added per-model and cache-hit breakdown to `/cost` for subscription users
~/release-notes is now an interactive version picker
~Remote Control session names now use your hostname as the default prefix (e.g. `myhost-graceful-unicorn`), overridable with `--remote-control-session-name-prefix`
~Pro users now see a footer hint when returning to a session after the prompt cache has expired, showing roughly how many tokens the next turn will send uncached
~Linux sandbox now ships the `apply-seccomp` helper in both npm and native builds, restoring unix-socket blocking for sandboxed commands
−Removed/tag command
−Removed/vim command (toggle vim mode via `/config` → Editor mode)
↑Improved Write tool diff computation speed for large files (60% faster on files with tabs/`&`/`$`)
✓Fixed subagent spawning permanently failing with "Could not determine pane count" after tmux windows are killed or renumbered during a long-running session
✓Fixed prompt-type Stop hooks incorrectly failing when the small fast model returns `ok:false`, and restored `preventContinuation:true` semantics for non-Stop prompt-type hooks
✓Fixed tool input validation failures when streaming emits array/object fields as JSON-encoded strings
✓Fixed an API 400 error that could occur when extended thinking produced a whitespace-only text block alongside real content
✓Fixed accidental feedback survey submissions from auto-pilot keypresses and consecutive-prompt digit collisions
✓Fixed misleading "esc to interrupt" hint appearing alongside "esc to clear" when a text selection exists in fullscreen mode during processing
✓Fixed Homebrew install update prompts to use the cask's release channel (`claude-code` → stable, `claude-code@latest` → latest)
✓Fixedctrl+e jumping to the end of the next line when already at end of line in multiline prompts
+Added MCP tool result persistence override via `_meta["anthropic/maxResultSizeChars"]` annotation (up to 500K), allowing larger results like DB schemas to pass through without truncation
+AddeddisableSkillShellExecution setting to disable inline shell execution in skills, custom slash commands, and plugin commands
+Added support for multi-line prompts in `claude-cli://open?q=` deep links (encoded newlines `%0A` no longer rejected)
~Plugins can now ship executables under `bin/` and invoke them as bare commands from the Bash tool
~/feedback now explains why it's unavailable instead of disappearing from the slash menu
~Edit tool now uses shorter `old_string` anchors, reducing output tokens
↑Improved/claude-api skill guidance for agent design patterns including tool surface decisions, context management, and caching strategy
↑Improvedperformance: faster `stripAnsi` on Bun by routing through `Bun.stripANSI`
✓Fixed transcript chain breaks on `--resume` that could lose conversation history when async transcript writes fail silently
✓Fixedcmd+delete not deleting to start of line on iTerm2, kitty, WezTerm, Ghostty, and Windows Terminal
✓Fixed plan mode in remote sessions losing track of the plan file after a container restart, which caused permission prompts on plan edits and an empty plan-approval modal
✓Fixed JSON schema validation for `permissions.defaultMode: "auto"` in settings.json
✓Fixed Windows version cleanup not protecting the active version's rollback copy
+Added/powerup — interactive lessons teaching Claude Code features with animated demos
+AddedCLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE env var to keep the existing marketplace cache when `git pull` fails, useful in offline environments
+Added.husky to protected directories (acceptEdits mode)
~Changed--resume picker to no longer show sessions created by `claude -p` or SDK invocations
−RemovedGet-DnsClientCache and `ipconfig /displaydns` from auto-allow (DNS cache privacy)
↑Improvedperformance: eliminated per-turn JSON.stringify of MCP tool schemas on cache-key lookup
↑Improvedperformance: SSE transport now handles large streamed frames in linear time (was quadratic)
↑Improvedperformance: SDK sessions with long conversations no longer slow down quadratically on transcript writes
↑Improved/resume all-projects view to load project sessions in parallel, improving load times for users with many projects
✓Fixed an infinite loop where the rate-limit options dialog would repeatedly auto-open after hitting your usage limit, eventually crashing the session
✓Fixed--resume causing a full prompt-cache miss on the first request for users with deferred tools, MCP servers, or custom agents (regression since v2.1.69)
✓FixedEdit/`Write` failing with "File content has changed" when a PostToolUse format-on-save hook rewrites the file between consecutive edits
✓FixedPreToolUse hooks that emit JSON to stdout and exit with code 2 not correctly blocking the tool call
✓Fixed collapsed search/read summary badge appearing multiple times in fullscreen scrollback when a CLAUDE.md file auto-loads during a tool call
✓Fixed auto mode not respecting explicit user boundaries ("don't push", "wait for X before Y") even when the action would otherwise be allowed
✓Fixed click-to-expand hover text being nearly invisible on light terminal themes
✓Fixed UI crash when malformed tool input reached the permission dialog
+Added"defer" permission decision to `PreToolUse` hooks — headless sessions can pause at a tool call and resume with `-p --resume` to have the hook re-evaluate
+AddedCLAUDE_CODE_NO_FLICKER=1 environment variable to opt into flicker-free alt-screen rendering with virtualized scrollback
+AddedPermissionDenied hook that fires after auto mode classifier denials — return `{retry: true}` to tell the model it can retry
+Added named subagents to @ mention typeahead suggestions
+AddedMCP_CONNECTION_NONBLOCKING=true for `-p` mode to skip the MCP connection wait entirely, and bounded `--mcp-config` server connections at 5s instead of blocking on the slowest server
~Auto mode: denied commands now show a notification and appear in `/permissions` → Recent tab where you can retry with `r`
~ChangedEdit to work on files viewed via `Bash` with `sed -n` or `cat`, without requiring a separate `Read` call first
~Changed hook output over 10,000 characters to be saved to disk with a file path + a 2,000-character preview instead of being injected directly into context
~ChangedcleanupPeriodDays: 0 in settings.json to be rejected with a validation error — it previously silently disabled transcript persistence
~Changed thinking summaries to no longer be generated by default in interactive sessions — set `showThinkingSummaries: true` in settings.json to restore
~Documented TaskCreated hook event and its blocking behavior
~Preserved task notifications when backgrounding a running command with Ctrl+B
~PowerShell tool on Windows: external-command arguments containing both a double-quote and whitespace now prompt instead of auto-allowing (PS 5.1 argument-splitting hardening)
↑Improved collapsed tool summary to show "Listed N directories" for `ls`/`tree`/`du` instead of "Read N files"
↑Improved Bash tool to warn when a formatter/linter command modifies files you have previously read, preventing stale-edit errors
↑Improved@-mention typeahead to rank source files above MCP resources with similar names
↑Improved PowerShell tool prompt with version-appropriate syntax guidance (5.1 vs 7+)
✓FixedEdit(//path/**) and `Read(//path/**)` allow rules to check the resolved symlink target, not just the requested path
✓Fixed voice push-to-talk not activating for some modifier-combo bindings, and voice mode on Windows failing with "WebSocket upgrade rejected with HTTP 101"
✓Fixed Edit/Write tools doubling CRLF on Windows and stripping Markdown hard line breaks (two trailing spaces)
✓FixedStructuredOutput schema cache bug causing ~50% failure rate when using multiple schemas
✓Fixed memory leak where large JSON inputs were retained as LRU cache keys in long-running sessions
✓Fixed a crash when removing a message from very large session files (over 50MB)
✓Fixed LSP server zombie state after crash — server now restarts on next request instead of failing until session restart
✓Fixed prompt history entries containing CJK or emoji being silently dropped when they fall on a 4KB boundary in `~/.claude/history.jsonl`
+AddedCLAUDE_CODE_MCP_SERVER_NAME and `CLAUDE_CODE_MCP_SERVER_URL` environment variables to MCP `headersHelper` scripts, allowing one helper to serve multiple servers
+Added conditional if field for hooks using permission rule syntax (e.g., `Bash(git *)`) to filter when they run, reducing process spawning overhead
+Added timestamp markers in transcripts when scheduled tasks (`/loop`, `CronCreate`) fire
+Added trailing space after [Image #N] placeholder when pasting images
~Deep link queries (claude-cli://open?q=…) now support up to 5,000 characters, with a "scroll to review" warning for long pre-filled prompts
~MCP OAuth now follows RFC 9728 Protected Resource Metadata discovery to find the authorization server
~Plugins blocked by organization policy (`managed-settings.json`) can no longer be installed or enabled, and are hidden from marketplace views
~PreToolUse hooks can now satisfy `AskUserQuestion` by returning `updatedInput` alongside `permissionDecision: "allow"`, enabling headless integrations that collect answers via their own UI
~tool_parameters in OpenTelemetry tool_result events are now gated behind `OTEL_LOG_TOOL_DETAILS=1`
↑Improved @-mention file autocomplete performance on large repositories
↑Improved PowerShell dangerous command detection
↑Improved scroll performance with large transcripts by replacing WASM yoga-layout with a pure TypeScript implementation
↑Reduced UI stutter when compaction triggers on large sessions
✓Fixed/compact failing with "context exceeded" when the conversation has grown too large for the compact request itself to fit
✓Fixed/plugin enable and `/plugin disable` failing when a plugin's install location differs from where it's declared in settings
✓Fixed--worktree exiting with an error in non-git repositories before the `WorktreeCreate` hook could run
✓FixeddeniedMcpServers setting not blocking claude.ai MCP servers
✓Fixedswitch_display in the computer-use tool returning "not available in this session" on multi-monitor setups
✓Fixed crash when OTEL_LOGS_EXPORTER, `OTEL_METRICS_EXPORTER`, or `OTEL_TRACES_EXPORTER` is set to `none`
✓Fixed diff syntax highlighting not working in non-native builds
✓Fixed MCP step-up authorization failing when a refresh token exists — servers requesting elevated scopes via `403 insufficient_scope` now correctly trigger the re-authorization flow
+Added PowerShell tool for Windows as an opt-in preview. Learn more at https://code.claude.com/docs/en/tools-reference#powershell-tool
+AddedANTHROPIC_DEFAULT_{OPUS,SONNET,HAIKU}_MODEL_SUPPORTS env vars to override effort/thinking capability detection for pinned default models for 3p (Bedrock, Vertex, Foundry), and `_MODEL_NAME`/`_DESCRIPTION` to customize the `/model` picker label
+AddedCLAUDE_STREAM_IDLE_TIMEOUT_MS env var to configure the streaming idle watchdog threshold (default 90s)
+Addedmanaged-settings.d/ drop-in directory alongside `managed-settings.json`, letting separate teams deploy independent policy fragments that merge alphabetically
+AddedCwdChanged and `FileChanged` hook events for reactive environment management (e.g., direnv)
+Addedsandbox.failIfUnavailable setting to exit with an error when sandbox is enabled but cannot start, instead of running unsandboxed
+Added--bare flag for scripted `-p` calls — skips hooks, LSP, plugin sync, and skill directory walks; requires `ANTHROPIC_API_KEY` or an `apiKeyHelper` via `--settings` (OAuth and keychain auth disabled); auto-memory fully disabled
+Added--channels permission relay — channel servers that declare the permission capability can forward tool approval prompts to your phone
~Resuming a session that was in a worktree now switches back to that worktree
~UpdatedMCP OAuth to support Client ID Metadata Document (CIMD / SEP-991) for servers without Dynamic Client Registration
~Changed plan mode to hide the "clear context" option by default (restore with `"showClearContextOnPlanAccept": true`)
~Disabled line-by-line response streaming on Windows (including WSL in Windows Terminal) due to rendering issues
↑Improved MCP read/search tool calls to collapse into a single "Queried {server}" line (expand with Ctrl+O)
↑Improved! bash mode discoverability — Claude now suggests it when you need to run an interactive command
↑Improved plugin freshness — ref-tracked plugins now re-clone on every load to pick up upstream changes
↑ImprovedRemote Control session titles to refresh after your third message
✓Fixed multiple concurrent Claude Code sessions requiring repeated re-authentication when one session refreshes its OAuth token
✓Fixed voice mode silently swallowing retry failures and showing a misleading "check your network" message instead of the actual error
✓Fixed voice mode audio not recovering when the server silently drops the WebSocket connection
✓FixedCLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS not suppressing the structured-outputs beta header, causing 400 errors on proxy gateways forwarding to Vertex/Bedrock
✓Fixed--channels bypass for Team/Enterprise orgs with no other managed settings configured
✓Fixed a crash on Node.js 18
✓Fixed unnecessary permission prompts for Bash commands containing dashes in strings
✓Fixed plugin hooks blocking prompt submission when the plugin directory is deleted mid-session
+Addedrate_limits field to statusline scripts for displaying Claude.ai rate limit usage (5-hour and 7-day windows with `used_percentage` and `resets_at`)
+Addedeffort frontmatter support for skills and slash commands to override the model effort level when invoked
+Added--channels (research preview) — allow MCP servers to push messages into your session
~Simplified plugin install tips to use a single `/plugin install` command instead of a two-step flow
↑Improved responsiveness of @ file autocomplete in large git repositories
↑Improved/effort to show what auto currently resolves to, matching the status bar indicator
↑Improved/permissions — Tab and arrow keys now switch tabs from within a list
↑Improved background tasks panel — left arrow now closes from the list view
↑Reduced memory usage on startup in large repositories (~80 MB saved on 250k-file repos)
✓Fixed--resume dropping parallel tool results — sessions with parallel tool calls now restore all tool_use/tool_result pairs instead of showing `[Tool result missing]` placeholders
✓Fixed voice mode WebSocket failures caused by Cloudflare bot detection on non-browser TLS fingerprints
✓Fixed 400 errors when using fine-grained tool streaming through API proxies, Bedrock, or Vertex
✓Fixed/remote-control appearing for gateway and third-party provider deployments where it cannot function
✓Fixed/sandbox tab switching not responding to Tab or arrow keys
✓Fixed managed settings (enabledPlugins, `permissions.defaultMode`, policy-set env vars) not being applied at startup when `remote-settings.json` was cached from a prior session
+AddedANTHROPIC_CUSTOM_MODEL_OPTION env var to add a custom entry to the `/model` picker, with optional `_NAME` and `_DESCRIPTION` suffixed vars for display
~Terminal notifications (iTerm2/Kitty/Ghostty popups, progress bar) now reach the outer terminal when running inside tmux with `set -g allow-passthrough on`
~Response text now streams line-by-line as it's generated
~**Security:** Fixed silent sandbox disable when `sandbox.enabled: true` is set but dependencies are missing — now shows a visible startup warning
↑Improved memory usage and startup time when resuming large sessions
✓Fixedgit log HEAD failing with "ambiguous argument" inside sandboxed Bash on Linux, and stub files polluting `git status` in the working directory
✓Fixedcc log and `--resume` silently truncating conversation history on large sessions (>5 MB) that used subagents
✓Fixed infinite loop when API errors triggered stop hooks that re-fed blocking errors to the model
✓Fixeddeny: ["mcp__servername"] permission rules not removing MCP server tools before sending to the model, allowing it to see and attempt blocked tools