Skip to content

Claude Code v2.1.290

Released · Anthropic

Security fixChanges hooks, permission rules

What the release notes say

What's changed

  • Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end
  • Added agentId to the tool.check event of plugin hooks, so a hook can tell a subagent's permission check from the main session's
  • Added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool
  • Added ThemeKey and Color types to the plugin hooks typings, so an editor lists the theme colors a mod's drawing can name
  • Added to claude plugin validate: each hook a mod registers at a gating site is listed with whether it has a .catch (gatingHooks under --json)
  • Added a Deny button to the Claude apps gateway's sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds
  • Added claude attach <name> and claude logs <name>: part of a session name works in place of the id
  • Added /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern a page describes as ant apply files
  • Added /claude-api managed-agents-onboard <quickstart-name> to build a Console quickstart template, such as deep-researcher, with the ant CLI
  • Added a warning when a managed settings file is a link to a file outside the managed settings folder
  • Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains
  • Fixed requests failing behind proxies and gateways that reject one of Claude Code's beta headers with a status other than 400, or together with a second beta
  • Fixed long sessions with hundreds of images getting stuck on "Request rejected as unprocessable by the model" errors
  • Fixed a turn ending at once when the API's output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown
  • Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run
  • Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an offset to read on
  • Fixed a crash ("Maximum call stack size exceeded") when a response nested lists or quotes thousands of levels deep
  • Fixed /rewind not listing a prompt sent while Claude was still working
  • Fixed scheduled tasks (/loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on
  • Fixed scheduled tasks set in the foreground never firing after a ← or /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork
  • Fixed headless --json-schema runs exiting non-zero with is_error: true on a success result when the connection dropped after the structured output was already delivered
  • Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy
  • Fixed a project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule
  • Fixed URL allow and deny patterns with a wildcard inside an xn-- host label matching differently from one process to the next
  • Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions
  • Fixed /ultrareview dropping uncommitted changes without a warning on Windows when git stash create failed, and refusing them after a git add -N file was deleted or moved
  • Fixed the plansDirectory setting's project-root check for paths that contain a backslash on macOS and Linux
  • Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in
  • Fixed the background daemon's log passing terminal control characters to the screen under claude daemon run and claude daemon logs; they now show as \uXXXX escapes
  • Self-hosted runner: Fixed a crafted, very long line of a session's error output freezing the runner for several seconds
  • Fixed a plugin hook with a .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call
  • Fixed a mod's turn.step result listing a tool call that a mid-response model fallback had discarded
  • Fixed a Cowork cloud session's reply sometimes never finishing when its container restarted just after Claude sent a message or a file
  • Fixed claude plugin validate and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions
  • Fixed /ultrareview failing to upload uncommitted changes when core.safecrlf=true is set in git's configuration
  • Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings
  • Windows: Fixed multi-line ! shell blocks in skills and commands failing when the file is saved with CRLF line endings
  • Fixed Claude Code hanging until killed when a /permissions tab was clicked while searching in fullscreen mode
  • Fixed conversation compaction sometimes failing with a "null is not an object" error
  • Fixed plugin hooks reading an empty answer on turn.complete for a subagent that hands its report back in auto mode
  • Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded
  • Fixed a mod's prompt.submit hook that drops a prompt after calling next(e) being ignored silently: the hook is now reported as failed, by name
  • Fixed a mod's pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing