AddedserverToolUses to the result of a mod's `turn.step` hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
AddedagentId to the `tool.check` event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
Addedceiling to the question and verdict a mod's `tool.check` hook reads, naming the approval an organization requires for a tool
AddedThemeKey and `Color` types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
Added to claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a `.catch` (`gatingHooks` under `--json`)
Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds
Addedclaude attach <name> and `claude logs <name>`: part of a session name works in place of the id
Added/claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as `ant apply` files
Added/claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as `deep-researcher`, with the `ant` CLI
Added a warning when a managed settings file is a link to a file outside the managed settings folder
Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains
VSCodeAdded a screen reader announcement, "Message queued.", when you send a message while Claude is working
VSCodeAdded a way to review and run a plugin marketplace's install or update command from the Manage plugins dialog
Claude TagAdded fast mode in Slack: mention Claude with `!fast` to switch a thread to fast mode, moving it to Opus if needed, and `!fast off` to switch back; replies show (fast) while it's on
Claude TagAdded the optional Path prefixes field when creating a custom connection in an access bundle, so its allow rule can cover only those paths instead of the whole host
~changed 25
ChangedCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC to also skip the startup connection warm-up
Changed Claude in Chrome so that a project's settings files can no longer turn it on; use `--chrome`, `/chrome` or your user settings
Changed the Bash tool to ask for permission before running `pyright`, which is no longer treated as a read-only command
Changed what a mod's $.process.spawn rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result
Changed the background daemon's log to write a multi-line message as one JSON-quoted line
Changed skills and custom commands to refuse a `!` shell command that contains raw control characters other than tab and newline, with a message that shows where they are
Changed/artifacts: opening an artifact in your browser now closes the list
Changed Bash permission checks so that more forms of the `ps` command ask for approval instead of running without asking
Changed plugin hooks so long text is clipped and logged instead of being refused or dropped silently
Changed background sessions whose scheduled task is gone: they now move to Completed about 20 seconds later and can be updated or shut down when idle
Changed the "Press ← again" confirm on a just-cleared prompt: a second ← no longer has to wait a second before it switches, and holding ← down now switches too
Changed the errors shown when the /ultrareview upload fails at a git step: they name the step and what to try, and no longer repeat git's own error text
Changed/code-review at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5
Changed an in-process teammate's agent_id in Agent results to its agent ID (its `name@team` address stays in `teammate_id`); TeammateIdle hooks no longer fire from its subagents or forks
Changed background sessions waiting on a scheduled wakeup (`/loop`): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup
Changed/model, `/effort` and `/rename` sent from `claude agents` to a busy background session to apply right away, without a confirmation, instead of when the turn ends
Changed the Claude apps gateway's minimum supported PostgreSQL version from 14 to 11
Changed the interactive session's WebSearch budget to refill over time (100 calls/hour; `CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR` sets the rate, 0 turns it off) instead of ending after 200 calls
ChangedCLAUDE_CODE_DISABLE_ATTACHMENTS so a repository's `.claude/settings.json` or `.claude/settings.local.json` can no longer set it; shell, user and managed settings still can
Changedclaude plugin update on a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins
Changed the built-in gh api in cloud sessions: a host other than github.com set in `GH_HOST` or `GH_REPO` is now refused (use `--hostname` or a full URL), and stderr notes requests to other hosts
Changed the claude-api skill's Managed Agents examples to turn off the web tools unless the agent needs them and to use the `auto` permission policy
Self-hosted runnersChangedclaude --environment <id> to create its session through the current Sessions API; printed and JSON session ids keep their session_… form
VSCodeChanged message timestamps to show by default (turn them off with the Claude Code: Show Message Timestamps setting)
Claude TagChanged the channel instructions limit to 8,192 characters instead of bytes, so non-English text gets the same room, and added a character count beside Save on the Configure page
↑improved 19
Improved MCP startup behind a network proxy: a server the proxy blocks (HTTP 403) is no longer retried three times
Improved permission prompts from background agents to show the Ctrl+X Ctrl+K shortcut that stops all background agents
Improved the built-in plugin-authoring skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section
Improved the reply to /plugin in the desktop app's Code tab: it now says where to install and manage plugins there
Improved the Bash changed-files view: when a chained command includes git merge, pull or checkout, it lists the files without full diffs
Improved the Claude apps gateway's log when an upstream's cloud credentials or connection fail: the warning now ends with the underlying cause
Improved the error shown when a cloud session is started without a claude.ai sign-in: it now names `claude auth login` and /login and no longer blames API-key authentication
Improved the Read tool's message for binary files: it now points Claude to a skill or a shell command that can read the format
Improved the error shown when a git config file stops the `/ultrareview` upload: it is about half as long and says what kind of file is the problem
Improved the errors shown when the /ultrareview upload refuses a checkout: each known cause now has its own message, with a way to fix it
Improved the Claude apps gateway to log a warning during the last 30 days before the certificate it presents to the identity provider expires
ImprovedClaude in Chrome: a `browser_batch` call now gets 90 seconds, up from 60, before it is reported as timed out
Improved the Claude apps gateway's browser sign-in pages: brand fonts, centered layout, and dark mode
Improved responsiveness while resuming large sessions: timers, input and rendering keep running while the transcript loads
Improved the / and @ suggestion lists: the selected row now starts with a ❯ pointer, so you can see it without color
VSCodeImprovedContinue After Reload: tabs reopened after VS Code restarts its extensions now also finish a step the restart interrupted
VSCodeImproved file pills in messages: hovering one now shows the file's path from the project folder, so same-named files can be told apart
Claude TagImproved Claude's notice in your direct messages when your own Claude plan's usage limit is reached: it shows within seconds and says when the limit resets
Claude TagImproved the earlier Claude in Slack app's reply when it can't start a session: it now says what failed and who can fix it, in full only once per thread
✓fixed 131
Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta
Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors
Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown
Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run
Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an `offset` to read on
Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep
Fixed/rewind not listing a prompt sent while Claude was still working
Fixed scheduled tasks (/loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on
Fixed scheduled tasks set in the foreground never firing after a ← or `/background` hand-off, and recurring ones firing an extra run on every resume, respawn or fork
Fixed headless --json-schema runs exiting non-zero with `is_error: true` on a `success` result when the connection dropped after the structured output was already delivered
Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy
Fixed a project CLAUDE.md, rule or `AGENTS.md` symlinked outside the working directories loading under `permissions.blockReadsOutsideWorkingDirectories` or a `Read` deny rule
Fixed URL allow and deny patterns with a wildcard inside an `xn--` host label matching differently from one process to the next
Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions
Fixed/ultrareview dropping uncommitted changes without a warning on Windows when `git stash create` failed, and refusing them after a `git add -N` file was deleted or moved
Fixed the plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux
Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in
Fixed the background daemon's log passing terminal control characters to the screen under `claude daemon run` and `claude daemon logs`; they now show as `\uXXXX` escapes
Self-hosted runnerFixed a crafted, very long line of a session's error output freezing the runner for several seconds
Fixed a plugin hook with a .catch being unloaded, and its `.catch` skipped, when the hook kept the hooks worker busy on a prompt or tool call
Fixed a mod's turn.step result listing a tool call that a mid-response model fallback had discarded
Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file
Fixedclaude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions
Fixed/ultrareview failing to upload uncommitted changes when `core.safecrlf=true` is set in git's configuration
Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings
WindowsFixed multi-line ! shell blocks in skills and commands failing when the file is saved with CRLF line endings
FixedClaude Code hanging until killed when a `/permissions` tab was clicked while searching in fullscreen mode
Fixed conversation compaction sometimes failing with a "null is not an object" error
Fixed plugin hooks reading an empty `answer` on `turn.complete` for a subagent that hands its report back in auto mode
Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded
Fixed a mod's prompt.submit hook that drops a prompt after calling `next(e)` being ignored silently: the hook is now reported as failed, by name
Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing
Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded
FixeddisableClaudeAiConnectors and `allowedMcpServers` URL rules not being applied to some MCP entries declared in `.mcp.json`, plugins or agents
Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing
Fixed an @-mention under the read block or `--restricted` being able to read a file outside the working directories through a link changed mid-read
Fixed Esc in the agents view confirming "Press enter again to restart this session — it isn't responding"; Esc now just reopens the session
Fixed agent view losing a background session's `/loop` run count, countdown and live status line after the session enters a worktree that it creates
Fixedclaude agents sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt
Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on `declare`, `typeset`, `export` or `readonly`
Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder
Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded
Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters
Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted
Fixed You should know writing its notes in English regardless of the `language` setting
Fixed a freeze after sending some very long messages
Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing
Fixedclaude respawn re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation
Fixed Esc after an n: or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section
Fixedclaude agents saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted
Fixed/ultrareview uploading uncommitted changes unfiltered for files under a git filter driver named `unset` or `unspecified`; the upload now stops and asks you to rename the driver
Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore
Fixedclaude --teleport and `/teleport` deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why
Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt
Fixed agent view's /loop run count freezing and its countdown disappearing after `/clear`; the count now restarts with the new conversation
Fixed--channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt
Fixed/chrome "Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135)
Fixed mods staying off for people who reach Claude through a gateway (`ANTHROPIC_BASE_URL` with `ANTHROPIC_AUTH_TOKEN`) and have no Anthropic account
Fixed replies sent from claude agents just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts
Fixed slash commands and answers to a multiple-choice question that `claude agents` could not deliver to a running session being saved and sent by themselves the next time it was restarted
Fixed sandboxed commands that pipe a heredoc into another command (`cat <<EOF | python3`) asking for approval on every run
Fixedclaude agents failing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one)
Fixed agent view's "restart this session fresh" re-sending an earlier message from the session instead of starting with an empty conversation
Fixed Bash permission checks auto-approving some read-only commands (such as `rg` or `git grep`) whose arguments the shell would still expand as wildcards; these now prompt for approval
Fixedclaude plugin test refusing to run after an upgrade because of an out-of-date saved setting
Fixed Bash permission checks auto-approving certain commands whose variable names zsh reads differently from bash; these now prompt for approval
Fixed a short form of a git clone option keeping the sandbox exemption from a git pattern such as `git *` in `sandbox.excludedCommands`; it is now treated like the long form
Fixed the first feature-flag request of a session ignoring a proxy or API endpoint set in a project's settings
Fixed/ultrareview of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside `.git` (git 2.54+); it now refuses with an explanation
Fixed cloud sessions staying asleep after a container restart lost a pending `/loop` wakeup or scheduled task; Claude is now told and can schedule it again
Fixed the Claude apps gateway's retention sweep deleting a returning developer's identity row refreshed at the same moment, on PostgreSQL versions without the November 2025 fixes
Fixed sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules
Fixed the Claude apps gateway failing to start when the certificate it presents to the identity provider has an empty subject
Fixed the Claude apps gateway exiting with a bare "Invalid URL" when `store.postgres_url` can't be parsed; the error now names the setting and says what the URL may hold
Fixed background agents failing with "Agent stalled" and Workflow tool subagents restarting from their prompt when a Mac woke from sleep
Fixed slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL)
Fixed a response interrupted by computer sleep being treated as a stalled stream on Bedrock, Vertex, Foundry, and custom gateways
Fixed a freeze before the first request and in the `/sandbox` Config tab on Linux and WSL when a sandbox read rule such as `~/**/.env` covers a large folder
Fixed skills not being found when asked for by the name in SKILL.md when their folder has a different name (for example a non-English name): the skill listing now shows both names
Fixed a plan written in plan mode being lost when a cloud session's container restarted before the plan was presented
Fixed the Bash tool occasionally losing shell aliases, functions and plugin PATH entries for a whole session when its first command ran seconds after startup on a new config directory
Fixed unbounded memory use when an HTTP MCP server sends a very large response
Fixed artifact operations failing in a Claude Code run started from inside a cloud session (for example `claude -p` run from the Bash tool)
Fixed files sent from remote sessions sometimes being refused as "not the one approved" when four or more were sent at once
Fixed plan mode not being restored when resuming a session with `--continue` or `--resume <session-id>` in the terminal
Fixed a marketplace named after another GitHub marketplace's download folder stopping that marketplace from downloading
Fixed automatic compaction giving up with "Prompt is too long" when a Mac went to sleep while it was running
Fixed the rewind menu (Esc Esc / /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file
Fixed a subdirectory's AGENTS.md not being attached when a file under it is @-mentioned
Fixed self-hosted runner sessions resumed after a stopped runner failing with "missing but already registered worktree" when the sessions folder is a relative symlink
Fixed a freeze when the secret scan or a permission prompt met long token-like text
Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands
FixedCLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to `dialogExpiry`
Fixed a stall when an MCP server's tool listing contains very long runs of combining characters
Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block
Fixed Claude in Chrome's browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog's list going stale after a switch
Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree
Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login
Fixed--restricted (and `CLAUDE_CODE_RESTRICTED=1`) sessions opening the cross-session messaging socket
Fixed sessions moved to the background while idle reopening as "no saved transcript" after a restart or idle cleanup; they now resume their conversation
Fixed background workers honoring `--allow-dangerously-skip-permissions` on respawn without the bypass-permissions disclaimer having been accepted
Fixed Claude replying in an endless loop when a plugin's async Stop hook passes an unquoted script path under a folder with a space, such as Application Support
Fixed a freeze of several seconds when secret masking met very long unbroken text
Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input
Fixed first launch asking to pick a login method again after `claude auth login` or with a credentials file already in the config directory
Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts
Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do
Fixed macOS /login reporting success when the keychain refused the new login and kept an old one it could not remove
Fixed SDK hosts using --include-partial-messages seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming
Fixed sandboxed Bash commands on Linux running `ConfigChange` hooks and reloading settings mid-command when `.claude/settings.json` or `.claude/settings.local.json` does not exist
Fixed errors reading "Premature close" instead of naming the missing program when a tool Claude Code runs, such as git or gh, is not installed (macOS, Linux)
Fixed/loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after `.claude/scheduled_tasks.json` was deleted
Fixed edits to the file a symlinked settings file points at running without the settings-file permission question
VSCodeFixed a blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place
VSCodeFixed settings dialogs blaming a timeout when Claude Code stopped unexpectedly during a save
VSCodeFixed the branch switch dialog offering to switch when it could not check for uncommitted changes
VSCodeFixed a permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it
VSCodeFixed sign-in and new sessions giving no clear reason when Claude Code cannot find or start its program
VSCodeFixed the agent map showing a nested sub-agent with "Tool calls (0)" and placing the agents it starts under the main agent
Cloud sessionsFixed turning off prompt suggestions through a cloud environment's environment variables having no effect in new cloud sessions
Cloud sessionsFixed the working indicator in a cloud session spinning on for several seconds after Claude's reply had finished; it now stops with the reply
Cloud sessionsFixed History on a never-run routine's page still saying "No runs yet" after you pressed Run now; it now shows the new run
Cloud sessionsFixed an unarchived cloud session looking as if Claude were still working until you sent another message
Remote ControlFixed a computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds
Claude TagFixed members with the Claude Tag Admin permission getting "Couldn't load memory files" on the Activity page's Memory tab; they can now read workspace and channel memory
Claude TagFixed a workspace guest's Confirm on a Claude settings card in Slack removing its buttons for everyone; only the guest sees the refusal, and members can still confirm or cancel
Claude TagFixed scheduled routines in Slack channels running on a model other than the channel's default; each run that starts a new session now uses the current default model
Claude TagFixed GitHub repositories in an access bundle attached by a channel-name rule being refused in the channels the rule covers; Claude can now add, list and clone them there
Code ReviewFixed blocking review comments sometimes opening with a "nit" label that contradicted their severity
Code ReviewFixed tips to comment "@claude review" being posted on fork and Manual-mode pull requests in organizations that have turned Code Review off