What's changed
- Added fast mode in Claude Code Remote sessions (cloud and self-hosted runners): the host's fast-mode setting or
/fasttyped in the session applies where your organization allows it - Added mouse support to the
/configpanel in fullscreen mode: the wheel scrolls the settings list, a click on a setting's value changes it, and the row under the pointer is highlighted - Added
claude self-hosted-runner --drain-marker-file <path>: when that file exists at a SIGTERM drain, the runner reports its exit to the server as a host drain (telemetry only) - Added per-command
allowed_domainsto Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refused - Added
omitClaudeMdto agent frontmatter and--agentsJSON, letting custom and plugin subagents run without user, project and local CLAUDE.md files; managed policy files still load - Added
--accept-command <sha256>toclaude plugin installandclaude plugin updateto accept exactly the command a previous--jsonrun displayed, instead of-y - Added support for a
multiplierabove 1, up to 10, in themodelPricingmanaged setting and the Claude apps gatewaypricingblock, for marked-up internal chargeback rates - Added a spinner tip pointing Bedrock, Vertex AI, Foundry and LLM gateway users to the Claude desktop app; the claude.ai desktop app tip now suggests
/desktop, which offers to download the app - Fixed a cached organization policy being reused after switching accounts, organizations, or API keys, and the policy not refreshing until the hourly check when the credential changes mid-session
- Fixed the tool and command lists not updating when the organization policy finishes loading after startup or changes mid-session
- Fixed an enterprise
managed-mcp.jsonthat can't be read or parsed being ignored: it now keeps exclusive MCP control (user, project and plugin servers don't load) and warns at startup - Fixed org policy being fetched through, and rejected by, third-party local proxies set via
ANTHROPIC_UNIX_SOCKET; they are again treated like other custom gateways, including for Remote Control - Fixed cloud sessions rejecting every subagent tool call ("updatedInput … failed schema validation") when a workflow or agent approval was applied after the session's worker restarted
- Fixed
/fast offanswering "Fast mode unavailable" instead of turning fast mode off when the organization has fast mode disabled - Fixed sessions started with
CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECKre-sending fast requests every turn after the API rejected fast mode; the rejection now stands and its reason is shown - Fixed fast mode under
CLAUDE_CODE_RETRY_WATCHDOGfailing the turn on a usage-credits limit, or retrying an overload at fast speed, instead of falling back to standard speed - Fixed Bash permission checks missing the file that
fmt,columnand similar commands read when it follows an option the checker doesn't recognize - Fixed Bash permission checks skipping files a wildcard expands to when the wildcard sits in a command's pattern or option value (for example
grep -v dir/* file) - Fixed Bash permission checks so that shell variable declaration flags cannot misrepresent the command being run
- Fixed Bash commands with two directory changes, a subshell, or a
cd+gitchain skipping the prompt underpermissions.blockReadsOutsideWorkingDirectoriesin bypass and auto mode - Fixed a stale
.git/config.lockbreakinggit checkout -b,git push -uandgit configfor the rest of a session after a sandboxed command failed to start (Linux) - Fixed settings file changes made outside the session going unnoticed on macOS machines whose system file-event service is saturated; the watcher now falls back to polling
- Fixed resumed
claude -psessions whose tools all come from MCP servers failing with "At least one tool must have defer_loading=false" - Fixed turns failing with "API returned an empty or malformed response" when an LLM gateway returns the non-streaming reply as
text/plain - Fixed sustained high CPU usage and repeated tool-list requests when an MCP server sends
list_changednotifications in a tight loop - Fixed MCP OAuth mishandling client registrations: denying consent forced a new one, one for another redirect URI was reused, and a concurrent write could delete a valid one or keep a mismatched one
- Fixed tool search returning no match when Claude selects an MCP tool by its bare name instead of its full
mcp__server__toolname - Fixed Ctrl+O cancelling pending MCP server reconnects, and
/mcpsent from Remote Control failing while the transcript view is open - Fixed the Claude in Chrome prompt telling the model to load tools through ToolSearch when ToolSearch is unavailable
- Fixed cross-session messages held by the receiving session's permission-mode policy leaving no trace: headless senders now get a delivery notice, and
SendMessageresults no longer imply it was read - Fixed Claude starting a second copy of a background command (such as a watch task or dev server) that was still running after the conversation was compacted
- Fixed
/modelwarning about losing the conversation cache when switching back to the model the conversation actually ran on - Fixed
/reload-skillsreporting a skill count that disagreed with the slash menu after/cd - Fixed
/resumeand/continueshowing only 1-2 sessions in fullscreen mode on short terminals - Fixed
/resumeand/teleportkeeping the previous conversation's file-read tracking, so Claude could edit files the resumed conversation had never read - Fixed
--resumedropping the 1M context window ([1m]) when the resumed session's model family differs from the configured default model - Fixed artifacts attached with
/artifactsdisappearing from the session after--resume