Skip to content

Claude Code v2.1.296

Released · Anthropic

Security fixChanges settings files, hooks

What the release notes say

What's changed

  • Added a code key to the Claude apps gateway's managed.policies[]: the same settings as cli, also applied in Claude Desktop's Code tab; beside desktop, it turns on Claude Desktop's gateway mode
  • Added autoCompactWindow to subagent frontmatter and --agents definitions, so a subagent can auto-compact earlier than the main conversation's window
  • Added CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL to run every workflow agent on one model while other subagents keep theirs
  • Added CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MS environment variable to set a longer maximum delay for the backoff when retrying an overloaded (529) request
  • Added a note in /plugin on a plugin whose hooks are left out because another enabled plugin has the same name
  • Added an allow_large option to the Read tool so Claude can read a text file past the usual size limits in one call when it needs the whole file and the context has room
  • Fixed managed-settings PreToolUse hooks that deny a tool call with "continue": false, and managed prompt hooks that block one, refusing the call but not ending the turn
  • Fixed PostToolUse hooks in managed settings not applying updatedMCPToolOutput in some sessions
  • Fixed headless sessions starting a folder's .mcp.json or plugin MCP server that was switched off for that folder, after changing directory or reloading plugins
  • Fixed a Claude apps gateway that serves allowedProviders with "gateway" locking out laptops that name that gateway in user settings
  • Fixed a saved Claude apps gateway sign-in being ignored on machines whose managed settings set forceLoginMethod to gateway with no forceLoginGatewayUrl (regression in 2.1.295)
  • Fixed --teleport opening an empty conversation when the session's history could not be read
  • Fixed token counts for Haiku 5.5 and other models that take only adaptive thinking, which failed behind some gateways and were counted with budget thinking elsewhere
  • Fixed resumed subagents being told that the user rejected a tool call that a session shutdown had interrupted
  • Fixed hook output being altered when it contained text resembling a plugin hint tag
  • Fixed secret redaction in shared transcripts and debug logs missing some values that follow a key with no value, including in JSON written inside a shell string
  • Fixed a stray 52;c;… escape sequence printed on screen after copying in older VTE-based terminals such as MATE Terminal
  • Fixed toasts and notifications waiting unseen for as long as the /diff panel or dialog was open
  • Fixed Esc or an interrupt during a UserPromptSubmit hook or a mod's prompt.submit hook ending headless sessions, clearing the typed prompt, or letting the unchecked prompt through
  • Fixed SessionStart hooks of a plugin loaded after a headless session starts being skipped when a different plugin with the same name, or another spelling of it, had already run
  • Fixed claude self-hosted-runner printing misleading errors when registration is refused: it now names the org admin setting, or says a restarted on-demand runner needs a fresh work order
  • Fixed a self-hosted runner session's git fetch, pull and push failing while another session of the same repository starts on a runner with --capacity above 1
  • Fixed workflow scripts silently truncating results, agent options and other values nested deeper than about 20,000 levels, and deeply nested results writing huge task output files
  • Fixed a plugin's served $ methods running in the main session's working directory instead of the calling agent's, and ignoring the turn their calling hook holds
  • Fixed $.agent.register succeeding from a mod's hook that was still running after the mod was reloaded or removed; the call is now refused
  • Fixed $.http.fetch in mods refusing a HEAD request when the response declares a Content-Length over the 4 MiB body limit
  • Fixed claude plugin marketplace add, marketplace update and plugin install failing with an internal error for a marketplace named like constructor; add now refuses such names clearly
  • Fixed a plugin secret named constructor or prototype being deleted by the next save of that plugin's options
  • Fixed cloud sessions skipping auto mode's checks on Claude in Chrome actions that a saved permission allows when their feature flags had not loaded
  • Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a finished turn after a restart when an MCP tool result had ended that turn
  • Fixed Bash permission checks auto-approving some commands that assign the BASH_ARGV0 shell variable and then use it; these now prompt for approval
  • Fixed Edit and NotebookEdit replacing every non-ASCII character in files that are not valid UTF-8 (Windows-1252, Shift-JIS, GBK); such edits are now refused
  • Fixed a prompt sent just after ← being run twice, once unseen in the foreground, when the background service was slow to answer
  • Fixed a prompt sent while SessionStart hooks were still running vanishing when ← moved the session to the background; it is still not sent, but ↑ now brings it back
  • Fixed a late-loading plugin's SessionStart hook output reaching the new conversation after /clear in headless sessions
  • Fixed PowerShell commands not seeing variables that hooks write to CLAUDE_ENV_FILE (when the file holds only plain assignments)
  • Fixed Claude calling cloud sessions non-interactive and suggesting /mcp or claude mcp when an MCP server needs authentication
  • Fixed /code-review ending on a raw JSON array in cloud sessions, the Agent SDK and IDE integrations; the findings now print as a numbered list
  • Fixed auto mode occasionally refusing one update to your own artifact, saying its sharing had changed when it had not
  • Fixed skills synced from claude.ai never finishing their install, and being downloaded again at every sync, when several sessions share a config directory