TL;DR
Self-hosted environments are here for Team and Enterprise.
claude self-hosted-runnerturns your own machines or containers into session hosts for Claude Code web, mobile, and desktop clients.Sessions can now message each other across your machines. Cross-session
SendMessageandListAgentswork across macOS and Linux, so multi-agent collaboration no longer requires shared terminals.Sandbox deny entries with trailing slashes were silently bypassable. If you set
denyRead: "~/.aws/"or similar, audit those entries; the trailing slash bypassed the rule on Linux and macOS.The 200-subagent-per-session spawn cap is removed. Long-running sessions no longer refuse new agents; concurrency and depth limits still apply (more below).
Feedback transcript shares now include your system prompt. With consent, the feedback survey uploads your CLAUDE.md instructions, tool definitions, and model parameters alongside the transcript; secrets are still redacted.
New in 2.1.224
2.1.224 (August 7, 2026)
- Added self-hosted environments:
claude self-hosted-runnerturns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans - Added
archiveplugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning - Added a cancel-and-confirm step when removing an unavailable paste changes a command's text
- Added
ANTHROPIC_BEDROCK_REGION_PREFIXenv var for Bedrock to prefer a specific cross-region inference profile over theAWS_REGION-derived one - Added
crossSessionInboundanddialogExpirysettings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver - Added sandbox credential-masking options:
extractandonExtractNoMatchfor structured env values,decode: "jwt"withmaskClaimsfor JWT-aware masking, andawsPairs/sigv4for AWS SigV4 re-signing; these neednetwork.tlsTerminateand are honored only from user, managed, or--settingssettings - Added cross-session
SendMessage: Claude Code sessions can now message each other, on any of your machines, withListAgentsto discover them (macOS and Linux) - Fixed long (>200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list, rename, fork, delete and
/resumeno longer cross projects - Fixed
SendMessagereporting "Message sent" when the write to a teammate's inbox had actually failed; failed deliveries are now reported as errors - Fixed sandbox filesystem deny entries written with a trailing slash (e.g.
denyRead: "~/.aws/") being silently bypassable on Linux and macOS - Fixed sandbox violation details never appearing in Bash tool results; Claude now sees which file or network access was denied and why
- Fixed MCP tools that connect mid-turn being deferred for tool search without their names announced to the model
- Fixed plugin install records being silently corrupted when the same plugin is installed in multiple projects
- Fixed recalled or restored paste content occasionally attaching wrong data or silently losing text when the paste had aged out or placeholder numbers collided
- Fixed copy-on-select on Wayland sometimes not reaching the clipboard; the two selection writes no longer race
- Fixed the feedback survey's transcript share silently failing on long sessions; a failed share now shows an error instead of a success message
- Fixed Remote Control auto-start intermittently failing with "Remote credentials fetch failed" on a cold start with a stale login token
- Fixed Remote Control and SDK clients showing a blank "(no content)" message after
/clearand other output-less commands - Fixed a Remote Control session recreated after its server session expired uploading prior local conversation history into the new session
- Improved fullscreen mode to keep the full pre-compaction history in scrollback across repeated compactions, instead of only the most recent interval
- Improved Remote Control: attached web and mobile clients now see compaction progress and the post-compaction boundary instead of a silent pause;
/clearresets now propagate to attached clients - Improved Remote Control: connection failures now show a persistent failure indicator with details and a reconnect shortcut, instead of only an 8-second toast
- Removed the 200-subagent-per-session spawn cap; long-running sessions no longer refuse new agents (concurrency and depth limits still apply)
- Changed managed settings: the approval prompt no longer re-appears after re-login or org switching when the organization's settings are unchanged
- Changed the feedback-survey transcript share: with your consent it now also uploads the last request's model settings, the system prompt (which includes your CLAUDE.md instructions), tool definitions, and model parameters. Secrets are redacted as before, and these fields are dropped first if the share is too large
- Changed the Bash tool description to always note that command output is displayed to the model, not reliably to the user
- Changed recalled paste placeholder numbers to renumber when accepted into the input
- Changed Remote Control to archive the stale server session instead of leaving a dead one listed when a fresh session is minted after compaction or
/resume - [VSCode] Fixed the extension showing Remote Control as connected after the connection failed
- Fixed a session resume silently reconnecting Remote Control after the user turned it off (
--resume, SDK hosts, and the VS Code extension) - [VSCode] Fixed sessions not honoring
remoteControlAtStartupwhen explicitly enabled
Notes
Subagent spawn cap, removed after two versions
2.1.212 introduced the 200-subagent-per-session cap to stop runaway delegation loops. 2.1.217 refined it with CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION and added /clear as a reset. 2.1.224 removes the lifetime cap entirely, relying instead on the concurrency limit (default 20, from 2.1.217) and the depth limit (CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH, default 3 since 2.1.219). If you were hitting the 200-spawn wall in long workflow sessions, the wall is gone. If you had CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION in your env, it no longer does anything.
Sandbox credential masking gets structured extraction
The new extract, decode: "jwt", and awsPairs/sigv4 options move sandbox credential handling from blanket denial to surgical masking. Sandboxed commands see a sentinel copy of the credential file while the proxy substitutes real values on egress. This extends the mode: "mask" capability from 2.1.221, which introduced file-level masking. All of these require network.tlsTerminate and are only honored from user, managed, or --settings settings, not project-level.