- Scheduled tasks and
/loopwere silently broken after compaction, backgrounding, and resume. If you use/loopwith an interval or reminders, they could stop firing after a compaction, never start after a left-arrow or/backgroundhand-off, or fire extra runs on resume. Fixed in 2.1.290 (more below). pyrightnow asks for permission before running. It is no longer treated as a read-only command, so expect an approval prompt the first time it runs this session.- WebSearch budget now refills instead of running out. The old hard cap of 200 calls per session is replaced by 100 calls/hour that replenish over time (
CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOURsets the rate, 0 turns it off). - Mod authors: four new hook properties landed.
serverToolUsesonturn.stepresults,agentIdandceilingontool.check, andThemeKey/Colortypes in the typings. Also,claude plugin validatenow reports whether each gating hook has a.catch.
New in 2.1.291, 2.1.290
2.1.291 (October 6, 2026)
- Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts
- Fixed a regression in 2.1.288 where the last messages of a session could be lost when quitting
2.1.290 (October 6, 2026)
- Added
serverToolUsesto the result of a mod'sturn.stephook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end - Added
agentIdto thetool.checkevent of plugin hooks, so a hook can tell a subagent's permission check from the main session's - Added
ceilingto the question and verdict a mod'stool.checkhook reads, naming the approval an organization requires for a tool - Added
ThemeKeyandColortypes to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name - Added to
claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a.catch(gatingHooksunder--json) - Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds
- Added
claude attach <name>andclaude logs <name>: part of a session name works in place of the id - Added
/claude-api managed-agents-onboard <url>to set up the Managed Agents pattern a page describes asant applyfiles - Added
/claude-api managed-agents-onboard <quickstart-name>to build a Console quickstart template, such asdeep-researcher, with theantCLI - Added a warning when a managed settings file is a link to a file outside the managed settings folder
- Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains
- Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta
- Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors
- Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown
- Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run
- Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an
offsetto read on - Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep
- Fixed
/rewindnot listing a prompt sent while Claude was still working - Fixed scheduled tasks (
/loopwith an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on - Fixed scheduled tasks set in the foreground never firing after a left-arrow or
/backgroundhand-off, and recurring ones firing an extra run on every resume, respawn or fork - Fixed headless
--json-schemaruns exiting non-zero withis_error: trueon asuccessresult when the connection dropped after the structured output was already delivered - Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy
- Fixed a project
CLAUDE.md, rule orAGENTS.mdsymlinked outside the working directories loading underpermissions.blockReadsOutsideWorkingDirectoriesor aReaddeny rule - Fixed URL allow and deny patterns with a wildcard inside an
xn--host label matching differently from one process to the next - Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions
- Fixed
/ultrareviewdropping uncommitted changes without a warning on Windows whengit stash createfailed, and refusing them after agit add -Nfile was deleted or moved - Fixed the
plansDirectorysetting's project-root check for paths that contain a backslash on macOS and Linux - Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in
- Fixed the background daemon's log passing terminal control characters to the screen under
claude daemon runandclaude daemon logs; they now show as\uXXXXescapes - Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds
- Fixed a plugin hook with a
.catchbeing unloaded, and its.catchskipped, when the hook kept the hooks worker busy on a prompt or tool call - Fixed a mod's
turn.stepresult listing a tool call that a mid-response model fallback had discarded - Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file
- Fixed
claude plugin validateand plugin loading refusing a hooks module that destructures an option named like one of its top-level functions - Fixed
/ultrareviewfailing to upload uncommitted changes whencore.safecrlf=trueis set in git's configuration - Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings
- Windows: Fixed multi-line
!shell blocks in skills and commands failing when the file is saved with CRLF line endings - Fixed Claude Code hanging until killed when a
/permissionstab was clicked while searching in fullscreen mode - Fixed conversation compaction sometimes failing with a "null is not an object" error
- Fixed plugin hooks reading an empty
answeronturn.completefor a subagent that hands its report back in auto mode - Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded
- Fixed a mod's
prompt.submithook that drops a prompt after callingnext(e)being ignored silently: the hook is now reported as failed, by name - Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing
- Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
- Fixed a case where a user-installed mod could get an organization's plugin unloaded; the mod is now the one unloaded
- Fixed
disableClaudeAiConnectorsandallowedMcpServersURL rules not being applied to some MCP entries declared in.mcp.json, plugins or agents - Fixed a mod's inline pane being redrawn without end when its tree changed height at every drawing
- Fixed an
@-mention under the read block or--restrictedbeing able to read a file outside the working directories through a link changed mid-read - Fixed Esc in the agents view confirming "Press enter again to restart this session"; Esc now just reopens the session
- Fixed agent view losing a background session's
/looprun count, countdown and live status line after the session enters a worktree that it creates - Fixed
claude agentssessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent's prompt - Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on
declare,typeset,exportorreadonly - Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder
- Fixed a case where a user-installed mod could make an organization's guard skip its check; such a mod is now unloaded
- Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters
- Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted
- Fixed You should know writing its notes in English regardless of the
languagesetting - Fixed a freeze after sending some very long messages
- Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing
- Fixed
claude respawnre-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation - Fixed Esc after an
n:or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section - Fixed
claude agentssaving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted - Fixed
/ultrareviewuploading uncommitted changes unfiltered for files under a git filter driver namedunsetorunspecified; the upload now stops and asks you to rename the driver - Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore
- Fixed
claude --teleportand/teleportdeleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why - Fixed Esc confirming agent view's "Press enter again to restart this session fresh" prompt
- Fixed agent view's
/looprun count freezing and its countdown disappearing after/clear; the count now restarts with the new conversation - Fixed
--channelspermission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt - Fixed
/chrome"Reconnect extension" not restoring browser tools after a failed Chrome connection, and added an explanation when it can't (anthropics/claude-code#98135) - Fixed mods staying off for people who reach Claude through a gateway (
ANTHROPIC_BASE_URLwithANTHROPIC_AUTH_TOKEN) and have no Anthropic account - Fixed replies sent from
claude agentsjust after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts - Fixed slash commands and answers to a multiple-choice question that
claude agentscould not deliver to a running session being saved and sent by themselves the next time it was restarted - Fixed sandboxed commands that pipe a heredoc into another command (
cat <<EOF | python3) asking for approval on every run - Fixed
claude agentsfailing with "Couldn't restart the background service" and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one) - Fixed agent view's "restart this session fresh" re-sending an earlier message from the session instead of starting with an empty conversation
- Fixed Bash permission checks auto-approving some read-only commands (such as
rgorgit grep) whose arguments the shell would still expand as wildcards; these now prompt for approval - Fixed
claude plugin testrefusing to run after an upgrade because of an out-of-date saved setting - Fixed Bash permission checks auto-approving certain commands whose variable names zsh reads differently from bash; these now prompt for approval
- Fixed a short form of a
git cloneoption keeping the sandbox exemption from a git pattern such asgit *insandbox.excludedCommands; it is now treated like the long form - Fixed the first feature-flag request of a session ignoring a proxy or API endpoint set in a project's settings
- Fixed
/ultrareviewof a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside.git(git 2.54+); it now refuses with an explanation - Fixed cloud sessions staying asleep after a container restart lost a pending
/loopwakeup or scheduled task; Claude is now told and can schedule it again - Fixed the Claude apps gateway's retention sweep deleting a returning developer's identity row refreshed at the same moment, on PostgreSQL versions without the November 2025 fixes
- Fixed sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules
- Fixed the Claude apps gateway failing to start when the certificate it presents to the identity provider has an empty subject
- Fixed the Claude apps gateway exiting with a bare "Invalid URL" when
store.postgres_urlcan't be parsed; the error now names the setting and says what the URL may hold - Fixed background agents failing with "Agent stalled" and Workflow tool subagents restarting from their prompt when a Mac woke from sleep
- Fixed slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL)
- Fixed a response interrupted by computer sleep being treated as a stalled stream on Bedrock, Vertex, Foundry, and custom gateways
- Fixed a freeze before the first request and in the
/sandboxConfig tab on Linux and WSL when a sandbox read rule such as~/**/.envcovers a large folder - Fixed skills not being found when asked for by the name in SKILL.md when their folder has a different name (for example a non-English name): the skill listing now shows both names
- Fixed a plan written in plan mode being lost when a cloud session's container restarted before the plan was presented
- Fixed the Bash tool occasionally losing shell aliases, functions and plugin PATH entries for a whole session when its first command ran seconds after startup on a new config directory
- Fixed unbounded memory use when an HTTP MCP server sends a very large response
- Fixed artifact operations failing in a Claude Code run started from inside a cloud session (for example
claude -prun from the Bash tool) - Fixed files sent from remote sessions sometimes being refused as "not the one approved" when four or more were sent at once
- Fixed plan mode not being restored when resuming a session with
--continueor--resume <session-id>in the terminal - Fixed a marketplace named after another GitHub marketplace's download folder stopping that marketplace from downloading
- Fixed automatic compaction giving up with "Prompt is too long" when a Mac went to sleep while it was running
- Fixed the rewind menu (Esc Esc /
/rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file - Fixed a subdirectory's AGENTS.md not being attached when a file under it is @-mentioned
- Fixed self-hosted runner sessions resumed after a stopped runner failing with "missing but already registered worktree" when the sessions folder is a relative symlink
- Fixed a freeze when the secret scan or a permission prompt met long token-like text
- Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands
- Fixed
CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5mbeing read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back todialogExpiry - Fixed a stall when an MCP server's tool listing contains very long runs of combining characters
- Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block
- Fixed Claude in Chrome's browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog's list going stale after a switch
- Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree
- Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login
- Fixed
--restricted(andCLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket - Fixed sessions moved to the background while idle reopening as "no saved transcript" after a restart or idle cleanup; they now resume their conversation
- Fixed background workers honoring
--allow-dangerously-skip-permissionson respawn without the bypass-permissions disclaimer having been accepted - Fixed Claude replying in an endless loop when a plugin's async Stop hook passes an unquoted script path under a folder with a space, such as Application Support
- Fixed a freeze of several seconds when secret masking met very long unbroken text
- Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input
- Fixed first launch asking to pick a login method again after
claude auth loginor with a credentials file already in the config directory - Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts
- Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do
- Fixed macOS
/loginreporting success when the keychain refused the new login and kept an old one it could not remove - Fixed SDK hosts using
--include-partial-messagesseeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming - Fixed sandboxed Bash commands on Linux running
ConfigChangehooks and reloading settings mid-command when.claude/settings.jsonor.claude/settings.local.jsondoes not exist - Fixed errors reading "Premature close" instead of naming the missing program when a tool Claude Code runs, such as git or gh, is not installed (macOS, Linux)
- Fixed
/loopand other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after.claude/scheduled_tasks.jsonwas deleted - Fixed edits to the file a symlinked settings file points at running without the settings-file permission question
- Improved MCP startup behind a network proxy: a server the proxy blocks (HTTP 403) is no longer retried three times
- Improved permission prompts from background agents to show the Ctrl+X Ctrl+K shortcut that stops all background agents
- Improved the built-in
plugin-authoringskill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README's install section - Improved the reply to
/pluginin the desktop app's Code tab: it now says where to install and manage plugins there - Improved the Bash changed-files view: when a chained command includes git merge, pull or checkout, it lists the files without full diffs
- Improved the Claude apps gateway's log when an upstream's cloud credentials or connection fail: the warning now ends with the underlying cause
- Improved the error shown when a cloud session is started without a claude.ai sign-in: it now names
claude auth loginand /login and no longer blames API-key authentication - Improved the Read tool's message for binary files: it now points Claude to a skill or a shell command that can read the format
- Improved the error shown when a git config file stops the
/ultrareviewupload: it is about half as long and says what kind of file is the problem - Improved the errors shown when the
/ultrareviewupload refuses a checkout: each known cause now has its own message, with a way to fix it - Improved the Claude apps gateway to log a warning during the last 30 days before the certificate it presents to the identity provider expires
- Improved Claude in Chrome: a
browser_batchcall now gets 90 seconds, up from 60, before it is reported as timed out - Improved the Claude apps gateway's browser sign-in pages: brand fonts, centered layout, and dark mode
- Improved responsiveness while resuming large sessions: timers, input and rendering keep running while the transcript loads
- Improved the / and @ suggestion lists: the selected row now starts with a pointer, so you can see it without color
- Changed
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICto also skip the startup connection warm-up - Changed Claude in Chrome so that a project's settings files can no longer turn it on; use
--chrome,/chromeor your user settings - Changed the Bash tool to ask for permission before running
pyright, which is no longer treated as a read-only command - Changed what a mod's
$.process.spawnrejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result - Changed the background daemon's log to write a multi-line message as one JSON-quoted line
- Changed skills and custom commands to refuse a
!shell command that contains raw control characters other than tab and newline, with a message that shows where they are - Changed
/artifacts: opening an artifact in your browser now closes the list - Changed Bash permission checks so that more forms of the
pscommand ask for approval instead of running without asking - Changed plugin hooks so long text is clipped and logged instead of being refused or dropped silently
- Changed background sessions whose scheduled task is gone: they now move to Completed about 20 seconds later and can be updated or shut down when idle
- Changed the "Press left-arrow again" confirm on a just-cleared prompt: a second left-arrow no longer has to wait a second before it switches, and holding left-arrow down now switches too
- Changed the errors shown when the
/ultrareviewupload fails at a git step: they name the step and what to try, and no longer repeat git's own error text - Changed
/code-reviewat medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5 - Changed an in-process teammate's
agent_idin Agent results to its agent ID (itsname@teamaddress stays inteammate_id); TeammateIdle hooks no longer fire from its subagents or forks - Changed background sessions waiting on a scheduled wakeup (
/loop): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup - Changed
/model,/effortand/renamesent fromclaude agentsto a busy background session to apply right away, without a confirmation, instead of when the turn ends - Changed the Claude apps gateway's minimum supported PostgreSQL version from 14 to 11
- Changed the interactive session's WebSearch budget to refill over time (100 calls/hour;
CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOURsets the rate, 0 turns it off) instead of ending after 200 calls - Changed
CLAUDE_CODE_DISABLE_ATTACHMENTSso a repository's.claude/settings.jsonor.claude/settings.local.jsoncan no longer set it; shell, user and managed settings still can - Changed
claude plugin updateon a plugin loaded from a directory to print just its reason, without the "Failed to update plugin" prefix, as for built-in plugins - Changed the built-in
gh apiin cloud sessions: a host other than github.com set inGH_HOSTorGH_REPOis now refused (use--hostnameor a full URL), and stderr notes requests to other hosts - Changed the
claude-apiskill's Managed Agents examples to turn off the web tools unless the agent needs them and to use theautopermission policy - Self-hosted runners: Changed
claude --environment <id>to create its session through the current Sessions API; printed and JSON session ids keep their session_ form - [VSCode] Added a screen reader announcement, "Message queued.", when you send a message while Claude is working
- [VSCode] Added a way to review and run a plugin marketplace's install or update command from the Manage plugins dialog
- [VSCode] Fixed a blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place
- [VSCode] Fixed settings dialogs blaming a timeout when Claude Code stopped unexpectedly during a save
- [VSCode] Fixed the branch switch dialog offering to switch when it could not check for uncommitted changes
- [VSCode] Fixed a permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it
- [VSCode] Fixed sign-in and new sessions giving no clear reason when Claude Code cannot find or start its program
- [VSCode] Fixed the agent map showing a nested sub-agent with "Tool calls (0)" and placing the agents it starts under the main agent
- [VSCode] Improved Continue After Reload: tabs reopened after VS Code restarts its extensions now also finish a step the restart interrupted
- [VSCode] Improved file pills in messages: hovering one now shows the file's path from the project folder, so same-named files can be told apart
- [VSCode] Changed message timestamps to show by default (turn them off with the Claude Code: Show Message Timestamps setting)
- [Cloud sessions] Fixed turning off prompt suggestions through a cloud environment's environment variables having no effect in new cloud sessions
- [Cloud sessions] Fixed the working indicator in a cloud session spinning on for several seconds after Claude's reply had finished; it now stops with the reply
- [Cloud sessions] Fixed History on a never-run routine's page still saying "No runs yet" after you pressed Run now; it now shows the new run
- [Cloud sessions] Fixed an unarchived cloud session looking as if Claude were still working until you sent another message
- [Remote Control] Fixed a computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds
- [Claude Tag] Added fast mode in Slack: mention Claude with
!fastto switch a thread to fast mode, moving it to Opus if needed, and!fast offto switch back; replies show (fast) while it's on - [Claude Tag] Added the optional Path prefixes field when creating a custom connection in an access bundle, so its allow rule can cover only those paths instead of the whole host
- [Claude Tag] Fixed members with the Claude Tag Admin permission getting "Couldn't load memory files" on the Activity page's Memory tab; they can now read workspace and channel memory
- [Claude Tag] Fixed a workspace guest's Confirm on a Claude settings card in Slack removing its buttons for everyone; only the guest sees the refusal, and members can still confirm or cancel
- [Claude Tag] Fixed scheduled routines in Slack channels running on a model other than the channel's default; each run that starts a new session now uses the current default model
- [Claude Tag] Fixed GitHub repositories in an access bundle attached by a channel-name rule being refused in the channels the rule covers; Claude can now add, list and clone them there
- [Claude Tag] Improved Claude's notice in your direct messages when your own Claude plan's usage limit is reached: it shows within seconds and says when the limit resets
- [Claude Tag] Improved the earlier Claude in Slack app's reply when it can't start a session: it now says what failed and who can fix it, in full only once per thread
- [Claude Tag] Changed the channel instructions limit to 8,192 characters instead of bytes, so non-English text gets the same room, and added a character count beside Save on the Configure page
- [Code Review] Fixed blocking review comments sometimes opening with a "nit" label that contradicted their severity
- [Code Review] Fixed tips to comment "@claude review" being posted on fork and Manual-mode pull requests in organizations that have turned Code Review off
Notes
Scheduled tasks have been quietly unreliable since compaction was added. The /loop and reminder fixes in 2.1.290 address three separate failure modes: tasks vanishing after a compaction, tasks never firing after you background a session, and recurring tasks firing extra runs on resume or fork. That last one could mean a monitor or polling loop ran twice per cycle without you noticing. The compaction fix only covers compactions made from 2.1.290 on, so if you have a long-running session from an older version, restarting it is the clean path. A related cloud-session fix ensures that a container restart no longer silently loses a pending /loop wakeup.
The sandbox tightened around several "read-only" commands. pyright is the most visible, but rg and git grep with shell-expandable wildcard arguments, ps in more forms, and Monitor tool commands under sandbox auto-allow all moved from auto-approved to prompted. If your workflow auto-allows these via settings rules, they will still pass; otherwise, expect new prompts on first use.
WebFetch's 100K character truncation was silent until now. If you relied on WebFetch for long pages (documentation, changelogs, specs), results were silently cut at 100,000 characters with no indication. 2.1.290 now reports how much text was dropped and accepts an offset parameter to page through the rest. Worth knowing if you ever got suspiciously incomplete web reads.
Several symlink-based file access bypasses were closed. An image read on macOS and Windows could return a file outside what was approved by swapping a link mid-read; @-mentions under --restricted or the read block could escape the working directories the same way; and a user-installed mod could get an organization's plugin unloaded or make its guard skip a check. If you run in a managed or restricted environment, these are the fixes that matter most.