claudekit / updates / claude-code-2-1-290
[ PATCH · ]

Claude Code 2.1.290

Closes many ways deny and ask rules and the outside-directory read block could be missed, and fixes scheduled tasks like `/loop` silently not coming back after compaction or a background hand-off. The WebSearch budget now refills at 100 calls/hour instead of ending after 200 calls.

Official announcement →

This article is a summary based on official documentation.

What changed

Claude Code 2.1.290 shipped on October 5, 2026. It is a very large release, centered on three areas. First, deny and ask rules and the outside-directory read block now hold in cases where symlinks, shell syntax or a hook rewriting a tool’s input let them slip. Second, scheduled tasks such as /loop no longer go missing or fire an extra run across compaction, background hand-offs and resumes. Third, the claude agents view, background sessions and /ultrareview uploads get a long list of reliability fixes. The items below are a selection of the changes with the most user impact.

New features

  • claude attach and claude logs by session name

    claude attach <name> and claude logs <name> are added, and part of a session name works in place of the id.

  • /claude-api managed-agents-onboard

    /claude-api managed-agents-onboard <url> sets up the Managed Agents pattern a page describes as ant apply files. /claude-api managed-agents-onboard <quickstart-name> builds a Console quickstart template, such as deep-researcher, with the ant CLI.

  • Managed settings warnings

    /status and doctor now warn when managed settings ignore user-configured sandbox allowRead paths or allowed domains. A warning also appears when a managed settings file is a link to a file outside the managed settings folder.

  • Deny button on the Claude apps gateway sign-in page

    The gateway’s sign-in approval page gets a Deny button: it ends the pending sign-in, so the waiting terminal stops within seconds.

  • Plugin hook additions

    A mod’s turn.step result gets serverToolUses (the tool calls the API ran itself, such as the advisor). The tool.check event gets agentId, so a hook can tell a subagent’s permission check from the main session’s, and ceiling, naming the approval an organization requires for a tool. The typings add ThemeKey and Color. claude plugin validate lists each hook a mod registers at a gating site with whether it has a .catch (gatingHooks under --json).

  • [Claude Tag] Fast mode in Slack

    Mention Claude with !fast to switch a thread to fast mode, moving it to Opus if needed, and !fast off to switch back. Replies show (fast) while it’s on.

  • [VSCode] Accessibility and plugin management

    A screen reader announces “Message queued.” when you send a message while Claude is working. The Manage plugins dialog can now review and run a plugin marketplace’s install or update command.

Key improvements

  • WebSearch budget refills over time

    The interactive session’s WebSearch budget used to end after 200 calls. It now refills at 100 calls/hour; CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR sets the rate, and 0 turns it off.

  • MCP startup behind a network proxy

    A server the proxy blocks (HTTP 403) is no longer retried three times.

  • Responsiveness while resuming large sessions

    Timers, input and rendering keep running while the transcript loads.

  • ❯ pointer in the / and @ suggestion lists

    The selected row now starts with a ❯ pointer, so you can see it without color.

  • Read tool message for binary files

    It now points Claude to a skill or a shell command that can read the format.

  • Claude in Chrome browser_batch timeout

    A browser_batch call now gets 90 seconds, up from 60, before it is reported as timed out.

  • /ultrareview upload errors

    Each known cause of a refused checkout now has its own message with a way to fix it, and failures at a git step name the step and what to try instead of repeating git’s own error text.

Changed behavior

  • Claude in Chrome can no longer be turned on by project settings

    Use --chrome, /chrome or your user settings.

  • CLAUDE_CODE_DISABLE_ATTACHMENTS ignores repository settings

    A repository’s .claude/settings.json or .claude/settings.local.json can no longer set it; shell, user and managed settings still can.

  • pyright and more ps forms now ask for permission

    pyright is no longer treated as a read-only command, and more forms of the ps command ask for approval instead of running without asking.

  • /code-review at medium effort

    On models without tuned review settings, including Opus 5.5 and Sonnet 5.5, it now also reports cleanup and CLAUDE.md conventions findings.

  • /model, /effort and /rename from claude agents apply right away

    Sent to a busy background session, they now apply without a confirmation instead of when the turn ends.

  • Background sessions waiting on /loop stay running

    They are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup.

  • CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC also skips the startup connection warm-up

  • [VSCode] Message timestamps show by default

    Turn them off with the Claude Code: Show Message Timestamps setting.

Bug fixes

Permissions & security

  • Plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy.
  • A project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories loading under permissions.blockReadsOutsideWorkingDirectories or a Read deny rule.
  • Some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input.
  • A deny or ask rule missing a command or path whose name came from a variable set as a prefix on declare, typeset, export or readonly.
  • Bash permission checks auto-approving some read-only commands (such as rg or git grep) whose arguments the shell would still expand as wildcards, and commands whose variable names zsh reads differently from bash; these now prompt for approval.
  • Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder.
  • An image read on macOS and Windows, or an @-mention, being able to read a file outside what was approved through a link swapped in mid-read.
  • Sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules.
  • A short form of a git clone option keeping the sandbox exemption from a pattern such as git * in sandbox.excludedCommands.
  • disableClaudeAiConnectors and allowedMcpServers URL rules not being applied to some MCP entries declared in .mcp.json, plugins or agents.
  • A user-installed mod being able to get an organization’s plugin unloaded or make an organization’s guard skip its check; such a mod is now the one unloaded.
  • --channels permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt.
  • Background workers honoring --allow-dangerously-skip-permissions on respawn without the bypass-permissions disclaimer having been accepted.
  • --restricted (and CLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket.

Requests & API reliability

  • Requests failing behind proxies and gateways that reject one of Claude Code’s beta headers with a status other than 400, or together with a second beta.
  • Long sessions with hundreds of images getting stuck on “Request rejected as unprocessable by the model” errors.
  • A turn ending at once when the API’s output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown.
  • Resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run.
  • WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an offset to read on.
  • Automatic compaction giving up with “Prompt is too long”, and background agents failing with “Agent stalled”, when a Mac went to sleep. A response interrupted by computer sleep is also no longer treated as a stalled stream on Bedrock, Vertex, Foundry and custom gateways.
  • Conversation compaction sometimes failing with a “null is not an object” error.
  • Unbounded memory use when an HTTP MCP server sends a very large response.
  • Slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL).

Scheduled tasks & /loop

  • Scheduled tasks (/loop with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on.
  • Scheduled tasks set in the foreground never firing after a ← or /background hand-off, and recurring ones firing an extra run on every resume, respawn or fork.
  • /loop and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after .claude/scheduled_tasks.json was deleted.
  • Cloud sessions staying asleep after a container restart lost a pending /loop wakeup or scheduled task; Claude is now told and can schedule it again.

Background sessions & agents view

  • Esc in the agents view confirming “Press enter again to restart this session”; Esc now just reopens the session.
  • Esc after an n: or Ctrl+F search moving focus to a section header, where Ctrl+X twice would delete every session in the section, and repeated Ctrl+X deleting the whole next section.
  • claude agents saving a slash command or multiple-choice answer it could not deliver, then sending it by itself the next time the session restarted.
  • “Restart this session fresh” and claude respawn re-sending an earlier message instead of starting with an empty conversation.
  • Sessions moved to the background while idle reopening as “no saved transcript” after a restart or idle cleanup; they now resume their conversation.
  • Replies sent just after a background session crashed being refused after 2 seconds; they are now retried for up to 12 seconds while the session restarts.
  • claude agents failing with “Couldn’t restart the background service” after a Homebrew upgrade (takes effect from the upgrade after this one).
  • Background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree.

/ultrareview

  • Dropping uncommitted changes without a warning on Windows when git stash create failed.
  • Failing to upload uncommitted changes when core.safecrlf=true is set.
  • Uploading uncommitted changes unfiltered for files under a git filter driver named unset or unspecified; the upload now stops and asks you to rename the driver.
  • Silently leaving uncommitted work out of the upload in a repository that keeps its branches outside .git (git 2.54+); it now refuses with an explanation.

Freezes & performance

  • A crash (“Maximum call stack size exceeded”) when a response nested lists or quotes thousands of levels deep.
  • A freeze after sending some very long messages, and when the secret scan or a permission prompt met long token-like text.
  • A freeze before the first request and in the /sandbox Config tab on Linux and WSL when a sandbox read rule such as ~/**/.env covers a large folder.
  • The rewind menu (Esc Esc / /rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file.
  • A slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing.

Sessions, settings & more

  • Skills not being found when asked for by the name in SKILL.md when their folder has a different name; the skill listing now shows both names.
  • A subdirectory’s AGENTS.md not being attached when a file under it is @-mentioned.
  • Plan mode not being restored when resuming a session with --continue or --resume <session-id>.
  • /rewind not listing a prompt sent while Claude was still working.
  • claude --teleport and /teleport deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash; the stash is now refused, and says why.
  • You should know writing its notes in English regardless of the language setting.
  • CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to dialogExpiry.
  • First launch asking to pick a login method again after claude auth login or with a credentials file already in the config directory.
  • macOS /login reporting success when the keychain refused the new login.
  • Errors reading “Premature close” instead of naming the missing program when a tool such as git or gh is not installed (macOS, Linux).
  • Sandboxed commands that pipe a heredoc into another command (cat <<EOF | python3) asking for approval on every run.
  • Windows: multi-line ! shell blocks in skills and commands failing when the file is saved with CRLF line endings.
  • /chrome “Reconnect extension” not restoring browser tools after a failed Chrome connection, with an explanation added when it can’t.
  • Claude replying in an endless loop when a plugin’s async Stop hook passes an unquoted script path under a folder with a space, such as Application Support.

Plugins & mods

  • A plugin hook with a .catch being unloaded, and its .catch skipped, when the hook kept the hooks worker busy on a prompt or tool call.
  • A mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded.
  • A mod’s prompt.submit hook that drops a prompt after calling next(e) being ignored silently; the hook is now reported as failed, by name.
  • A mod’s pane, band or inline pane being redrawn without end when its tree changed height at every drawing.
  • Mods staying off for people who reach Claude through a gateway (ANTHROPIC_BASE_URL with ANTHROPIC_AUTH_TOKEN) and have no Anthropic account.

VS Code & cloud sessions

  • [VSCode] A permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it.
  • [VSCode] A blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place.
  • [VSCode] The branch switch dialog offering to switch when it could not check for uncommitted changes.
  • [Cloud sessions] The working indicator spinning on for several seconds after Claude’s reply had finished.
  • [Remote Control] A computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds.

Notes

  • If you turned on Claude in Chrome through project settings, it no longer turns on that way. Move it to --chrome, /chrome or your user settings.
  • If you relied on pyright or ps running without asking, they now prompt for approval. Add an allow rule if you need them to run unattended.
  • Heavy WebSearch users in long sessions no longer hit a hard stop at 200 calls; the budget refills at 100 calls/hour, adjustable with CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR.
  • The fix for /loop not coming back after compaction covers compactions made from this version on.
  • If you installed with Homebrew, the fix for “Couldn’t restart the background service” takes effect from the upgrade after this one.
  • Mod authors can look at serverToolUses, agentId and ceiling on tool.check, and gatingHooks in claude plugin validate --json.