+AddedCLAUDE_CODE_SESSION_ID environment variable to the Bash tool subprocess environment, matching the `session_id` passed to hooks
+AddedCLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1 env var to opt out of the fullscreen alternate-screen renderer and keep the conversation in the terminal's native scrollback
+Added a "Pasting…" footer hint while a Ctrl+V image paste is being read from the clipboard
~Updated the /tui fullscreen startup banner to describe additional renderer benefits (lower memory usage, mouse support, auto-copy on select)
↑Improved visual consistency in slash command dialogs and `/login`, `/upgrade`, `/extra-usage` dialog spacing
✓Fixed external SIGINT (e.g. IDE stop button, `kill -INT`) not running graceful shutdown — terminal modes are now restored and the `--resume` hint is printed instead of an abrupt exit
✓Fixed an uncaught exception when the terminal is closed or SSH disconnects mid-session under the native build
✓Fixed--resume failing with `no low surrogate in string` when a tool error truncation split an emoji; pre-corrupted sessions are sanitized on load
✓Fixed--permission-mode flag being ignored when resuming a plan-mode session with `-p --continue`/`--resume`, and plan mode not being re-applied after `ExitPlanMode` within the same session
✓Fixed fullscreen mode showing a blank screen after laptop sleep/wake or Ctrl+Z/`fg` until the next keystroke or stream output
✓Fixed cursor landing mid-grapheme on Ctrl+E/A/K/U/arrow keys when an Indic conjunct or ZWJ emoji wraps across lines
✓Fixed vim operators corrupting text containing decomposed (NFD) accented characters
✓Fixed pasting text starting with `/` silently swallowing the input or triggering an unknown-command reply
+Added--plugin-url <url> flag to fetch a plugin `.zip` archive from a URL for the current session
+AddedCLAUDE_CODE_FORCE_SYNC_OUTPUT=1 env var to force-enable synchronized output on terminals that auto-detection misses (e.g. Emacs `eat`)
+AddedCLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE: when set on Homebrew or WinGet installations, Claude Code runs the upgrade command in the background and prompts to restart
~Plugin manifests: themes and `monitors` should now be declared under `"experimental": { ... }`. Top-level declarations still work but `claude plugin validate` will warn
~Gateway /v1/models discovery for the `/model` picker is now opt-in via `CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1` (was automatic in 2.1.126–2.1.128)
~Ctrl+R history picker now defaults to searching all prompts across all projects, matching pre-2.1.124 behavior. Press Ctrl+S to narrow to the current project or session
~Third-party deployments (Bedrock, Vertex, Foundry, or `ANTHROPIC_BASE_URL` gateway) no longer see spinner tips pointing at first-party Anthropic surfaces
~skillOverrides setting now works: `off` hides from model and `/`, `user-invocable-only` hides from model only, `name-only` collapses description
~--channels now works with console (API key) authentication — console orgs with managed settings must set `channelsEnabled: true` to enable
~Updated/model picker: collapsed duplicate Opus 4.7 entries, and current Opus now shows as "Opus" instead of "Opus 4.7"
~Subprocesses (Bash, hooks, MCP, LSP) no longer inherit `OTEL_*` environment variables, so OTEL-instrumented apps run via the Bash tool no longer pick up the CLI's own OTLP endpoint
~MCP: workspace is now a reserved server name — existing servers with that name will be skipped with a warning
~Reconnecting MCP servers no longer flood the conversation with full tool-name lists on every reconnect — re-announced tools are summarized by server prefix
~SDK hosts now receive a persistent `localSettings` suggestion for Bash permission prompts, so "Always allow" writes to `.claude/settings.local.json`
~EnterWorktree now creates the new branch from local HEAD as documented, instead of `origin/<default-branch>` — unpushed commits are no longer dropped
~Auto mode: when the classifier can't evaluate an action, the error now includes a hint (retry, `/compact`, or run with `--debug`)
~The /model picker now lists models from your gateway's `/v1/models` endpoint when `ANTHROPIC_BASE_URL` points at an Anthropic-compatible gateway
~- Added claude project purge [path] to delete all Claude Code state for a project (transcripts, tasks, file history, config entry) — supports `--dry-run`, `-y/--yes`, `-i/--interactive`, and `--all`
~--dangerously-skip-permissions now bypasses prompts for writes to `.claude/`, `.git/`, `.vscode/`, shell config files, and other previously-protected paths (catastrophic removal commands still prompt as a safety net)
~claude auth login now accepts the OAuth code pasted into the terminal when the browser callback can't reach localhost (WSL2, SSH, containers)
~claude_code.skill_activated OpenTelemetry event now fires for user-typed slash commands and carries a new `invocation_trigger` attribute (`"user-slash"`, `"claude-proactive"`, or `"nested-skill"`)
~Auto mode: the spinner now turns red when a permission check stalls, instead of looking like the tool is running
~Host-managed deployments (`CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST`) no longer auto-disable analytics on Bedrock/Vertex/Foundry
~WindowsPowerShell 7 installed via the Microsoft Store, MSI without PATH, or `.NET global tool` is now detected
~WindowsWhen the PowerShell tool is enabled, Claude now treats PowerShell as the primary shell instead of defaulting to Bash
~Read tool: removed the per-file malware-assessment reminder that could cause spurious refusals and "this is not malware" commentary on legacy models
~**Security:** Fixed allowManagedDomainsOnly / `allowManagedReadPathsOnly` being ignored when a higher-priority managed-settings source lacked a `sandbox` block
✓Fixed pasting an image larger than 2000px breaking the session — images are now downscaled on paste, and oversized images in history are automatically removed and the request retried
✓Fixed showing the login screen for "OAuth not allowed for organization" errors — now shows guidance to contact your admin
✓Fixed OAuth login failing with timeout on slow or proxied connections, in IPv6-only devcontainers, and when the browser callback can't reach localhost
✓Fixed a rare race where a concurrent credential write could clear a valid OAuth refresh token
✓Fixed API retry countdown sticking at "0s" instead of counting down between attempts
✓Fixed"Stream idle timeout" error after waking Mac from sleep mid-request
✓Fixed background and remote sessions falsely aborting with "Stream idle timeout" during long model thinking pauses
✓Fixed a hang where the assistant could finish thinking but show no output after a run of empty turns
+AddedANTHROPIC_BEDROCK_SERVICE_TIER environment variable to select a Bedrock service tier (`default`, `flex`, or `priority`), sent as the `X-Amzn-Bedrock-Service-Tier` header
~Pasting a PR URL into the `/resume` search box now finds the session that created that PR (GitHub, GitHub Enterprise, GitLab, and Bitbucket)
~/mcp now shows claude.ai connectors hidden by a manually-added server with the same URL, with a hint to remove the duplicate
~Clarified the /mcp message shown when an MCP server is still unauthorized after the browser sign-in flow
~OpenTelemetry: numeric attributes on `api_request`/`api_error` log events are now emitted as numbers, not strings
~OpenTelemetry: added claude_code.at_mention log event for `@`-mention resolution
~Voice mode: keybindings bound to Caps Lock now show an error since terminals don't deliver Caps Lock as a key event
✓Fixed/branch producing forks that fail with "tool_use ids were found without tool_result blocks" when the source session contained entries from rewound timelines
✓Fixed/model not showing the Effort option for Bedrock application inference profile ARNs, and those ARNs not receiving `output_config.effort`
✓FixedVertex AI / Bedrock returning `invalid_request_error: output_config: Extra inputs are not permitted` on session-title generation and other structured-output queries
✓FixedVertex AI `count_tokens` endpoint returning 400 errors for users behind proxy gateways
✓FixedspinnerTipsOverride.excludeDefault not suppressing the time-based spinner tips
✓Fixed ToolSearch missing MCP tools that connected after session start in nonblocking mode
✓Fixed!exit / `!quit` in bash mode terminating the CLI instead of running as a shell command
✓Fixed images sent to newer models being resized to 2576px per side instead of the correct 2000px maximum
~PostToolUse hooks can now replace tool output for all tools via `hookSpecificOutput.updatedToolOutput` (previously MCP-only)
~Fullscreen mode: typing into the prompt no longer jumps scroll back to the bottom after you've scrolled up to read earlier output
~Dialogs that overflow the terminal are now scrollable with arrow keys, PgUp/PgDn, home/end, and mouse wheel in both fullscreen and non-fullscreen modes
~Clicking any line of a long URL that wraps across rows in fullscreen mode now opens the full URL
~SDK and claude -p: `CLAUDE_CODE_FORK_SUBAGENT=1` now works in non-interactive sessions
~--dangerously-skip-permissions no longer prompts for writes to `.claude/skills/`, `.claude/agents/`, and `.claude/commands/`
~/terminal-setup now enables iTerm2's "Applications in terminal may access clipboard" setting so `/copy` works, including from tmux
~MCP servers that hit a transient error during startup now auto-retry up to 3 times instead of staying disconnected
+Addedclaude ultrareview [target] subcommand to run `/ultrareview` non-interactively from CI or scripts — prints findings to stdout (`--json` for raw output) and exits 0 on completion or 1 on failure
~WindowsGit for Windows (Git Bash) is no longer required — when absent, Claude Code uses PowerShell as the shell tool
~Skills can now reference the current effort level with `${CLAUDE_EFFORT}` in their content
+AddedprUrlTemplate setting to point the footer PR badge at a custom code-review URL instead of github.com
+AddedCLAUDE_CODE_HIDE_CWD environment variable to hide the working directory in the startup logo
~/config settings (theme, editor mode, verbose, etc.) now persist to `~/.claude/settings.json` and participate in project/local/policy override precedence
~--from-pr now accepts GitLab merge-request, Bitbucket pull-request, and GitHub Enterprise PR URLs
~--print mode now honors the agent's `tools:` and `disallowedTools:` frontmatter, matching interactive-mode behavior
~--agent <name> now honors the agent definition's `permissionMode` for built-in agents
~PowerShell tool commands can now be auto-approved in permission mode, matching Bash behavior
~Hooks: PostToolUse and `PostToolUseFailure` hook inputs now include `duration_ms` (tool execution time, excluding permission prompts and PreToolUse hooks)
~Subagent and SDK MCP server reconfiguration now connects servers in parallel instead of serially
~Plugins pinned by another plugin's version constraint now auto-update to the highest satisfying git tag
~Vim mode: Esc in INSERT no longer pulls a queued message back into the input; press Esc again to interrupt
+Addedclaude plugin tag to create release git tags for plugins with version validation
~Merged /cost and `/stats` into `/usage` — both remain as typing shortcuts that open the relevant tab
~Create and switch between named custom themes from `/theme`, or hand-edit JSON files in `~/.claude/themes/`; plugins can also ship themes via a `themes/` directory
~Hooks can now invoke MCP tools directly via `type: "mcp_tool"`
~WSL on Windows can now inherit Windows-side managed settings via the `wslInheritsWindowsSettings` policy key
~Auto mode: include "$defaults" in `autoMode.allow`, `autoMode.soft_deny`, or `autoMode.environment` to add custom rules alongside the built-in list instead of replacing it
~--continue/`--resume` now find sessions that added the current directory via `/add-dir`
~/color now syncs the session accent color to claude.ai/code when Remote Control is connected
~The /model picker now honors `ANTHROPIC_DEFAULT_*_MODEL_NAME`/`_DESCRIPTION` overrides when using a custom `ANTHROPIC_BASE_URL` gateway
✓Fixed/mcp menu hiding OAuth Authenticate/Re-authenticate actions for servers configured with `headersHelper`, and HTTP/SSE MCP servers with custom headers being stuck in "needs authentication" after a transient 401
✓Fixed MCP step-up authorization silently refreshing instead of prompting for re-consent when the server's `insufficient_scope` 403 names a scope the current token already has
✓Fixed an unhandled promise rejection when an MCP server's OAuth flow times out or is cancelled
✓FixedMCP OAuth refresh proceeding without its cross-process lock under contention
✓Fixed macOS keychain race where a concurrent MCP token refresh could overwrite a freshly-refreshed OAuth token, causing unexpected "Please run /login" prompts
✓Fixed OAuth token refresh failing when the server revokes a token before its local expiry time
✓Fixed credential save crash on Linux/Windows corrupting `~/.claude/.credentials.json`
~plugin install on an already-installed plugin now installs any missing dependencies instead of stopping at "already installed"
~Plugin dependency errors now say "not installed" with an install hint, and `claude plugin marketplace add` now auto-resolves missing dependencies from configured marketplaces
~Managed-settings blockedMarketplaces and `strictKnownMarketplaces` are now enforced on plugin install, update, refresh, and autoupdate
~Advisor Tool (experimental): dialog now carries an "experimental" label, learn-more link, and startup notification when enabled; sessions no longer get stuck with "Advisor tool result content could not be processed" errors on every prompt and `/compact`
~The cleanupPeriodDays retention sweep now also covers `~/.claude/tasks/`, `~/.claude/shell-snapshots/`, and `~/.claude/backups/`
~OpenTelemetry: user_prompt events now include `command_name` and `command_source` for slash commands; `cost.usage`, `token.usage`, `api_request`, and `api_error` now include an `effort` attribute when the model supports effort levels. Custom/MCP command names are redacted unless `OTEL_LOG_TOOL_DETAILS=1` is set
~Native builds on macOS and Linux: the `Glob` and `Grep` tools are replaced by embedded `bfs` and `ugrep` available through the Bash tool — faster searches without a separate tool round-trip (Windows and npm-installed builds unchanged)
~WindowsCached where.exe executable lookups per process for faster subprocess launches
↑Improved/model: selections now persist across restarts even when the project pins a different model, and the startup header shows when the active model comes from a project or managed-settings pin
↑Faster startup when both local and claude.ai MCP servers are configured (concurrent connect now default)
✓FixedPlain-CLI OAuth sessions dying with "Please run /login" when the access token expires mid-session — the token is now refreshed reactively on 401
✓FixedWebFetch hanging on very large HTML pages by truncating input before HTML-to-markdown conversion
✓Fixed a crash when a proxy returns HTTP 204 No Content — now surfaces a clear error instead of a `TypeError`
✓Fixed/login having no effect when launched with `CLAUDE_CODE_OAUTH_TOKEN` env var and that token expires
✓Fixed prompt-input undo (Ctrl+_) doing nothing immediately after typing, and skipping a state on each undo step
✓FixedNO_PROXY not being respected for remote API requests when running under Bun
✓Fixed rare spurious escape/return triggers when key names arrive as coalesced text over slow connections
✓Fixed SDK reload_plugins reconnecting all user MCP servers serially
~/config search now matches option values (e.g. searching "vim" finds the Editor mode setting)
~/doctor can now be opened while Claude is responding, without waiting for the current turn to finish
~/reload-plugins and background plugin auto-update now auto-install missing plugin dependencies from marketplaces you've already added
~Bash tool now surfaces a hint when `gh` commands hit GitHub's API rate limit, so agents can back off instead of retrying
~The Usage tab in Settings now shows your 5-hour and weekly usage immediately and no longer fails when the usage endpoint is rate-limited
~Agent frontmatter hooks: now fire when running as a main-thread agent via `--agent`
~Slash command menu now shows "No commands match" when your filter has zero results, instead of disappearing
~Claude Code and installer now use `https://downloads.claude.ai/claude-code-releases` instead of `https://storage.googleapis.com/claude-code-dist-86c565f3-f756-42ad-8dfa-d59b1c096819/claude-code-releases`
!Sandbox auto-allow no longer bypasses the dangerous-path safety check for `rm`/`rmdir` targeting `/`, `$HOME`, or other critical system directories
↑Faster MCP startup when multiple stdio servers are configured; `resources/templates/list` is now deferred to first `@`-mention
✓Fixed Devanagari and other Indic scripts rendering with broken column alignment in the terminal UI
✓Fixed Ctrl+- not triggering undo in terminals using the Kitty keyboard protocol (iTerm2, Ghostty, kitty, WezTerm, Windows Terminal)
✓Fixed Cmd+Left/Right not jumping to line start/end in terminals that use the Kitty keyboard protocol (Warp fullscreen, kitty, Ghostty, WezTerm)
✓Fixed Ctrl+Z hanging the terminal when Claude Code is launched via a wrapper process (e.g. `npx`, `bun run`)
✓Fixed scrollback duplication in inline mode where resizing the terminal or large output bursts would repeat earlier conversation history
✓Fixed modal search dialogs overflowing the screen at short terminal heights, hiding the search box and keyboard hints
✓Fixed scattered blank cells and disappearing composer chrome in the VS Code integrated terminal during scrolling
✓Fixed an intermittent API 400 error related to cache control TTL ordering that could occur when a parallel request completed during request setup
+Addedxhigh effort level for Opus 4.7, sitting between `high` and `max`. Available via `/effort`, `--effort`, and the model picker; other models fall back to `high`
+Added"Auto (match terminal)" theme option that matches your terminal's dark/light mode — select it from `/theme`
+Added/less-permission-prompts skill — scans transcripts for common read-only Bash and MCP tool calls and proposes a prioritized allowlist for `.claude/settings.json`
+Added/ultrareview for running comprehensive code review in the cloud using parallel multi-agent analysis and critique — invoke with no arguments to review your current branch, or `/ultrareview <PR#>` to fetch and review a specific GitHub PR
+AddedOTEL_LOG_RAW_API_BODIES environment variable to emit full API request and response bodies as OpenTelemetry log events for debugging
~Claude Opus 4.7 xhigh is now available! Use /effort to tune speed vs. intelligence
~Auto mode is now available for Max subscribers when using Opus 4.7
~/effort now opens an interactive slider when called without arguments, with arrow-key navigation between levels and Enter to confirm
~Auto mode no longer requires `--enable-auto-mode`
~WindowsPowerShell tool is progressively rolling out. Opt in or out with `CLAUDE_CODE_USE_POWERSHELL_TOOL`. On Linux and macOS, enable with `CLAUDE_CODE_USE_POWERSHELL_TOOL=1` (requires `pwsh` on PATH)
~Read-only bash commands with glob patterns (e.g. `ls *.ts`) and commands starting with `cd <project-dir> &&` no longer trigger a permission prompt
~Suggest the closest matching subcommand when `claude <word>` is invoked with a near-miss typo (e.g. `claude udpate` → "Did you mean `claude update`?")
~Plan files are now named after your prompt (e.g. `fix-auth-race-snug-otter.md`) instead of purely random words
↑Improved/setup-vertex and `/setup-bedrock` to show the actual `settings.json` path when `CLAUDE_CONFIG_DIR` is set, seed model candidates from existing pins on re-run, and offer a "with 1M context" option for supported models
↑Improvedplugin error handling: dependency errors now distinguish conflicting, invalid, and overly complex version requirements; fixed stale resolved versions after `plugin update`; `plugin install` now recovers from interrupted prior installs
✓Fixed terminal display tearing (random characters, drifting input) in iTerm2 + tmux setups when terminal notifications are sent
✓Fixed@ file suggestions re-scanning the entire project on every turn in non-git working directories, and showing only config files in freshly-initialized git repos with no tracked files
✓Fixed LSP diagnostics from before an edit appearing after it, causing the model to re-read files it just edited
✓Fixed tab-completing /resume immediately resuming an arbitrary titled session instead of showing the session picker
✓Fixed/context grid rendering with extra blank lines between rows
✓Fixed/clear dropping the session name set by `/rename`, causing statusline output to lose `session_name`
✓Fixed Claude calling a non-existent `commit` skill and showing "Unknown skill: commit" for users without a custom `/commit` command
✓Fixed 429 rate-limit errors on Bedrock/Vertex/Foundry referencing status.claude.com (it only covers Anthropic-operated providers)
+Added option to show Claude's last response as commented context in the `Ctrl+G` external editor (enable via `/config`)
~ChangedCtrl+O to toggle between normal and verbose transcript only; focus view is now toggled separately with the new `/focus` command
~--resume/`--continue` now resurrects unexpired scheduled tasks
~/context, `/exit`, and `/reload-plugins` now work from Remote Control (mobile/web) clients
~Write tool now informs the model when you edit the proposed content in the IDE diff before accepting
~Bash tool now enforces the documented maximum timeout instead of accepting arbitrarily large values
~SDK/headless sessions now read `TRACEPARENT`/`TRACESTATE` from the environment for distributed trace linking
~Session recap is now enabled for users with telemetry disabled (Bedrock, Vertex, Foundry, `DISABLE_TELEMETRY`). Opt out via `/config` or `CLAUDE_CODE_ENABLE_AWAY_SUMMARY=0`.
~Hardened "Open in editor" actions against command injection from untrusted filenames
↑Improved/plugin Installed tab — items needing attention and favorites appear at the top, disabled items are hidden behind a fold, and `f` favorites the selected item
↑Improved/doctor to warn when an MCP server is defined in multiple config scopes with different endpoints
✓Fixed MCP tool calls hanging indefinitely when the server connection drops mid-response on SSE/HTTP transports
✓Fixed non-streaming fallback retries causing multi-minute hangs when the API is unreachable
✓Fixed session recap, local slash-command output, and other system status lines not appearing in focus mode
✓Fixed high CPU usage in fullscreen when text is selected while a tool is running
✓Fixed plugin install not honoring dependencies declared in `plugin.json` when the marketplace entry omits them; `/plugin` install now lists auto-installed dependencies
+AddedENABLE_PROMPT_CACHING_1H env var to opt into 1-hour prompt cache TTL on API key, Bedrock, Vertex, and Foundry (`ENABLE_PROMPT_CACHING_1H_BEDROCK` is deprecated but still honored), and `FORCE_PROMPT_CACHING_5M` to force 5-minute TTL
+Added recap feature to provide context when returning to a session, configurable in `/config` and manually invocable with `/recap`; force with `CLAUDE_CODE_ENABLE_AWAY_SUMMARY` if telemetry disabled.
+Added"verbose" indicator when viewing the detailed transcript (`Ctrl+O`)
↑Improved/model to warn before switching models mid-conversation, since the next response re-reads the full history uncached
↑Improved/resume picker to default to sessions from the current directory; press `Ctrl+A` to show all projects
↑Improvederror messages: server rate limits are now distinguished from plan usage limits; 5xx/529 errors show a link to status.claude.com; unknown slash commands suggest the closest match
↑Reduced memory footprint for file reads, edits, and syntax highlighting by loading language grammars on demand
✓Fixed paste not working in the `/login` code prompt (regression in 2.1.105)
✓Fixed subscribers who set DISABLE_TELEMETRY falling back to 5-minute prompt cache TTL instead of 1 hour
✓Fixed Agent tool prompting for permission in auto mode when the safety classifier's transcript exceeded its context window
✓Fixed Bash tool producing no output when `CLAUDE_ENV_FILE` (e.g. `~/.zprofile`) ends with a `#` comment line
✓Fixedclaude --resume <session-id> losing the session's custom name and color set via `/rename`
✓Fixed session titles showing placeholder example text when the first message is a short greeting
✓Fixed terminal escape codes appearing as garbage text in the prompt input after `--teleport`
✓Fixed/feedback retry: pressing Enter to resubmit after a failure now works without first editing the description