What's changed
- Added a
codekey to the Claude apps gateway'smanaged.policies[]: the same settings ascli, also applied in Claude Desktop's Code tab; besidedesktop, it turns on Claude Desktop's gateway mode - Added
autoCompactWindowto subagent frontmatter and--agentsdefinitions, so a subagent can auto-compact earlier than the main conversation's window - Added
CLAUDE_CODE_WORKFLOW_SUBAGENT_MODELto run every workflow agent on one model while other subagents keep theirs - Added
CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MSenvironment variable to set a longer maximum delay for the backoff when retrying an overloaded (529) request - Added a note in
/pluginon a plugin whose hooks are left out because another enabled plugin has the same name - Added an
allow_largeoption to the Read tool so Claude can read a text file past the usual size limits in one call when it needs the whole file and the context has room - Fixed managed-settings
PreToolUsehooks that deny a tool call with"continue": false, and managedprompthooks that block one, refusing the call but not ending the turn - Fixed PostToolUse hooks in managed settings not applying
updatedMCPToolOutputin some sessions - Fixed headless sessions starting a folder's
.mcp.jsonor plugin MCP server that was switched off for that folder, after changing directory or reloading plugins - Fixed a Claude apps gateway that serves
allowedProviderswith"gateway"locking out laptops that name that gateway in user settings - Fixed a saved Claude apps gateway sign-in being ignored on machines whose managed settings set
forceLoginMethodtogatewaywith noforceLoginGatewayUrl(regression in 2.1.295) - Fixed
--teleportopening an empty conversation when the session's history could not be read - Fixed token counts for Haiku 5.5 and other models that take only adaptive thinking, which failed behind some gateways and were counted with budget thinking elsewhere
- Fixed resumed subagents being told that the user rejected a tool call that a session shutdown had interrupted
- Fixed hook output being altered when it contained text resembling a plugin hint tag
- Fixed secret redaction in shared transcripts and debug logs missing some values that follow a key with no value, including in JSON written inside a shell string
- Fixed a stray
52;c;…escape sequence printed on screen after copying in older VTE-based terminals such as MATE Terminal - Fixed toasts and notifications waiting unseen for as long as the
/diffpanel or dialog was open - Fixed Esc or an interrupt during a
UserPromptSubmithook or a mod'sprompt.submithook ending headless sessions, clearing the typed prompt, or letting the unchecked prompt through - Fixed SessionStart hooks of a plugin loaded after a headless session starts being skipped when a different plugin with the same name, or another spelling of it, had already run
- Fixed
claude self-hosted-runnerprinting misleading errors when registration is refused: it now names the org admin setting, or says a restarted on-demand runner needs a fresh work order - Fixed a self-hosted runner session's git fetch, pull and push failing while another session of the same repository starts on a runner with
--capacityabove 1 - Fixed workflow scripts silently truncating results, agent options and other values nested deeper than about 20,000 levels, and deeply nested results writing huge task output files
- Fixed a plugin's served
$methods running in the main session's working directory instead of the calling agent's, and ignoring the turn their calling hook holds - Fixed
$.agent.registersucceeding from a mod's hook that was still running after the mod was reloaded or removed; the call is now refused - Fixed
$.http.fetchin mods refusing aHEADrequest when the response declares aContent-Lengthover the 4 MiB body limit - Fixed
claude plugin marketplace add,marketplace updateandplugin installfailing with an internal error for a marketplace named likeconstructor;addnow refuses such names clearly - Fixed a plugin secret named
constructororprototypebeing deleted by the next save of that plugin's options - Fixed cloud sessions skipping auto mode's checks on Claude in Chrome actions that a saved permission allows when their feature flags had not loaded
- Fixed
CLAUDE_CODE_RESUME_INTERRUPTED_TURNre-running a finished turn after a restart when an MCP tool result had ended that turn - Fixed Bash permission checks auto-approving some commands that assign the
BASH_ARGV0shell variable and then use it; these now prompt for approval - Fixed Edit and NotebookEdit replacing every non-ASCII character in files that are not valid UTF-8 (Windows-1252, Shift-JIS, GBK); such edits are now refused
- Fixed a prompt sent just after
←being run twice, once unseen in the foreground, when the background service was slow to answer - Fixed a prompt sent while SessionStart hooks were still running vanishing when
←moved the session to the background; it is still not sent, but↑now brings it back - Fixed a late-loading plugin's SessionStart hook output reaching the new conversation after
/clearin headless sessions - Fixed PowerShell commands not seeing variables that hooks write to CLAUDE_ENV_FILE (when the file holds only plain assignments)
- Fixed Claude calling cloud sessions non-interactive and suggesting
/mcporclaude mcpwhen an MCP server needs authentication - Fixed
/code-reviewending on a raw JSON array in cloud sessions, the Agent SDK and IDE integrations; the findings now print as a numbered list - Fixed auto mode occasionally refusing one update to your own artifact, saying its sharing had changed when it had not
- Fixed skills synced from claude.ai never finishing their install, and being downloaded again at every sync, when several sessions share a config directory