Skip to content

Claude Code v2.1.288

Released · Anthropic

Security fixChanges context and compaction settings, background and headless runs, hooks, permission rules, MCP server config, agent context files

What the release notes say

What's changed

  • Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row

  • Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal

  • Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images

  • Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call

  • Added --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default

  • Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json

  • Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab

  • Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried

  • Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage

  • Fixed --resume sometimes dropping files and other context that a compaction had just restored

  • Fixed a resumed session sometimes not saving the last response of a turn, so that the next --resume showed the prompt unanswered

  • Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load

  • Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking

  • Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off

  • Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash

  • Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent

  • Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it

  • Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes

  • Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device

  • Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted

  • Fixed a plugin's pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code

  • Fixed plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults

  • Fixed a plugin's tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree

  • Fixed git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)

  • Fixed plugins loaded with --plugin-dir not showing "Configure options" in /plugin

  • Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running

  • Fixed sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references

  • Fixed Bash tool permission check to prompt before a BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently

  • Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt

  • Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn

  • Fixed OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals

  • Fixed permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event

  • Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved

  • Fixed unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts

  • Fixed /login reporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (anthropics/claude-code#73861)

  • Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request

  • Fixed a second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in

  • Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults

  • Fixed headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it

  • Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses

  • Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed