What changed
Claude Code 2.1.290 shipped on October 5, 2026. It is a very large release, centered on three areas. First, deny and ask rules and the outside-directory read block now hold in cases where symlinks, shell syntax or a hook rewriting a tool’s input let them slip. Second, scheduled tasks such as /loop no longer go missing or fire an extra run across compaction, background hand-offs and resumes. Third, the claude agents view, background sessions and /ultrareview uploads get a long list of reliability fixes. The items below are a selection of the changes with the most user impact.
New features
-
claude attachandclaude logsby session nameclaude attach <name>andclaude logs <name>are added, and part of a session name works in place of the id. -
/claude-api managed-agents-onboard/claude-api managed-agents-onboard <url>sets up the Managed Agents pattern a page describes asant applyfiles./claude-api managed-agents-onboard <quickstart-name>builds a Console quickstart template, such asdeep-researcher, with theantCLI. -
Managed settings warnings
/statusand doctor now warn when managed settings ignore user-configured sandboxallowReadpaths or allowed domains. A warning also appears when a managed settings file is a link to a file outside the managed settings folder. -
Deny button on the Claude apps gateway sign-in page
The gateway’s sign-in approval page gets a Deny button: it ends the pending sign-in, so the waiting terminal stops within seconds.
-
Plugin hook additions
A mod’s
turn.stepresult getsserverToolUses(the tool calls the API ran itself, such as the advisor). Thetool.checkevent getsagentId, so a hook can tell a subagent’s permission check from the main session’s, andceiling, naming the approval an organization requires for a tool. The typings addThemeKeyandColor.claude plugin validatelists each hook a mod registers at a gating site with whether it has a.catch(gatingHooksunder--json). -
[Claude Tag] Fast mode in Slack
Mention Claude with
!fastto switch a thread to fast mode, moving it to Opus if needed, and!fast offto switch back. Replies show (fast) while it’s on. -
[VSCode] Accessibility and plugin management
A screen reader announces “Message queued.” when you send a message while Claude is working. The Manage plugins dialog can now review and run a plugin marketplace’s install or update command.
Key improvements
-
WebSearch budget refills over time
The interactive session’s WebSearch budget used to end after 200 calls. It now refills at 100 calls/hour;
CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOURsets the rate, and 0 turns it off. -
MCP startup behind a network proxy
A server the proxy blocks (HTTP 403) is no longer retried three times.
-
Responsiveness while resuming large sessions
Timers, input and rendering keep running while the transcript loads.
-
❯pointer in the / and @ suggestion listsThe selected row now starts with a
❯pointer, so you can see it without color. -
Read tool message for binary files
It now points Claude to a skill or a shell command that can read the format.
-
Claude in Chrome
browser_batchtimeoutA
browser_batchcall now gets 90 seconds, up from 60, before it is reported as timed out. -
/ultrareviewupload errorsEach known cause of a refused checkout now has its own message with a way to fix it, and failures at a git step name the step and what to try instead of repeating git’s own error text.
Changed behavior
-
Claude in Chrome can no longer be turned on by project settings
Use
--chrome,/chromeor your user settings. -
CLAUDE_CODE_DISABLE_ATTACHMENTSignores repository settingsA repository’s
.claude/settings.jsonor.claude/settings.local.jsoncan no longer set it; shell, user and managed settings still can. -
pyrightand morepsforms now ask for permissionpyrightis no longer treated as a read-only command, and more forms of thepscommand ask for approval instead of running without asking. -
/code-reviewat medium effortOn models without tuned review settings, including Opus 5.5 and Sonnet 5.5, it now also reports cleanup and CLAUDE.md conventions findings.
-
/model,/effortand/renamefromclaude agentsapply right awaySent to a busy background session, they now apply without a confirmation instead of when the turn ends.
-
Background sessions waiting on
/loopstay runningThey are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup.
-
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICalso skips the startup connection warm-up -
[VSCode] Message timestamps show by default
Turn them off with the Claude Code: Show Message Timestamps setting.
Bug fixes
Permissions & security
- Plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy.
- A project
CLAUDE.md, rule orAGENTS.mdsymlinked outside the working directories loading underpermissions.blockReadsOutsideWorkingDirectoriesor aReaddeny rule. - Some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input.
- A deny or ask rule missing a command or path whose name came from a variable set as a prefix on
declare,typeset,exportorreadonly. - Bash permission checks auto-approving some read-only commands (such as
rgorgit grep) whose arguments the shell would still expand as wildcards, and commands whose variable names zsh reads differently from bash; these now prompt for approval. - Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder.
- An image read on macOS and Windows, or an @-mention, being able to read a file outside what was approved through a link swapped in mid-read.
- Sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules.
- A short form of a
git cloneoption keeping the sandbox exemption from a pattern such asgit *insandbox.excludedCommands. disableClaudeAiConnectorsandallowedMcpServersURL rules not being applied to some MCP entries declared in.mcp.json, plugins or agents.- A user-installed mod being able to get an organization’s plugin unloaded or make an organization’s guard skip its check; such a mod is now the one unloaded.
--channelspermission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt.- Background workers honoring
--allow-dangerously-skip-permissionson respawn without the bypass-permissions disclaimer having been accepted. --restricted(andCLAUDE_CODE_RESTRICTED=1) sessions opening the cross-session messaging socket.
Requests & API reliability
- Requests failing behind proxies and gateways that reject one of Claude Code’s beta headers with a status other than 400, or together with a second beta.
- Long sessions with hundreds of images getting stuck on “Request rejected as unprocessable by the model” errors.
- A turn ending at once when the API’s output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown.
- Resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run.
- WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an
offsetto read on. - Automatic compaction giving up with “Prompt is too long”, and background agents failing with “Agent stalled”, when a Mac went to sleep. A response interrupted by computer sleep is also no longer treated as a stalled stream on Bedrock, Vertex, Foundry and custom gateways.
- Conversation compaction sometimes failing with a “null is not an object” error.
- Unbounded memory use when an HTTP MCP server sends a very large response.
- Slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL).
Scheduled tasks & /loop
- Scheduled tasks (
/loopwith an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on. - Scheduled tasks set in the foreground never firing after a ← or
/backgroundhand-off, and recurring ones firing an extra run on every resume, respawn or fork. /loopand other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after.claude/scheduled_tasks.jsonwas deleted.- Cloud sessions staying asleep after a container restart lost a pending
/loopwakeup or scheduled task; Claude is now told and can schedule it again.
Background sessions & agents view
- Esc in the agents view confirming “Press enter again to restart this session”; Esc now just reopens the session.
- Esc after an
n:or Ctrl+F search moving focus to a section header, where Ctrl+X twice would delete every session in the section, and repeated Ctrl+X deleting the whole next section. claude agentssaving a slash command or multiple-choice answer it could not deliver, then sending it by itself the next time the session restarted.- “Restart this session fresh” and
claude respawnre-sending an earlier message instead of starting with an empty conversation. - Sessions moved to the background while idle reopening as “no saved transcript” after a restart or idle cleanup; they now resume their conversation.
- Replies sent just after a background session crashed being refused after 2 seconds; they are now retried for up to 12 seconds while the session restarts.
claude agentsfailing with “Couldn’t restart the background service” after a Homebrew upgrade (takes effect from the upgrade after this one).- Background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree.
/ultrareview
- Dropping uncommitted changes without a warning on Windows when
git stash createfailed. - Failing to upload uncommitted changes when
core.safecrlf=trueis set. - Uploading uncommitted changes unfiltered for files under a git filter driver named
unsetorunspecified; the upload now stops and asks you to rename the driver. - Silently leaving uncommitted work out of the upload in a repository that keeps its branches outside
.git(git 2.54+); it now refuses with an explanation.
Freezes & performance
- A crash (“Maximum call stack size exceeded”) when a response nested lists or quotes thousands of levels deep.
- A freeze after sending some very long messages, and when the secret scan or a permission prompt met long token-like text.
- A freeze before the first request and in the
/sandboxConfig tab on Linux and WSL when a sandbox read rule such as~/**/.envcovers a large folder. - The rewind menu (Esc Esc /
/rewind) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file. - A slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing.
Sessions, settings & more
- Skills not being found when asked for by the name in SKILL.md when their folder has a different name; the skill listing now shows both names.
- A subdirectory’s AGENTS.md not being attached when a file under it is @-mentioned.
- Plan mode not being restored when resuming a session with
--continueor--resume <session-id>. /rewindnot listing a prompt sent while Claude was still working.claude --teleportand/teleportdeleting the files in a folder that had replaced a tracked file of the same name when you chose to stash; the stash is now refused, and says why.- You should know writing its notes in English regardless of the
languagesetting. CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5mbeing read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back todialogExpiry.- First launch asking to pick a login method again after
claude auth loginor with a credentials file already in the config directory. - macOS
/loginreporting success when the keychain refused the new login. - Errors reading “Premature close” instead of naming the missing program when a tool such as git or gh is not installed (macOS, Linux).
- Sandboxed commands that pipe a heredoc into another command (
cat <<EOF | python3) asking for approval on every run. - Windows: multi-line
!shell blocks in skills and commands failing when the file is saved with CRLF line endings. /chrome“Reconnect extension” not restoring browser tools after a failed Chrome connection, with an explanation added when it can’t.- Claude replying in an endless loop when a plugin’s async Stop hook passes an unquoted script path under a folder with a space, such as Application Support.
Plugins & mods
- A plugin hook with a
.catchbeing unloaded, and its.catchskipped, when the hook kept the hooks worker busy on a prompt or tool call. - A mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded.
- A mod’s
prompt.submithook that drops a prompt after callingnext(e)being ignored silently; the hook is now reported as failed, by name. - A mod’s pane, band or inline pane being redrawn without end when its tree changed height at every drawing.
- Mods staying off for people who reach Claude through a gateway (
ANTHROPIC_BASE_URLwithANTHROPIC_AUTH_TOKEN) and have no Anthropic account.
VS Code & cloud sessions
- [VSCode] A permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it.
- [VSCode] A blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place.
- [VSCode] The branch switch dialog offering to switch when it could not check for uncommitted changes.
- [Cloud sessions] The working indicator spinning on for several seconds after Claude’s reply had finished.
- [Remote Control] A computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds.
Notes
- If you turned on Claude in Chrome through project settings, it no longer turns on that way. Move it to
--chrome,/chromeor your user settings. - If you relied on
pyrightorpsrunning without asking, they now prompt for approval. Add an allow rule if you need them to run unattended. - Heavy WebSearch users in long sessions no longer hit a hard stop at 200 calls; the budget refills at 100 calls/hour, adjustable with
CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR. - The fix for
/loopnot coming back after compaction covers compactions made from this version on. - If you installed with Homebrew, the fix for “Couldn’t restart the background service” takes effect from the upgrade after this one.
- Mod authors can look at
serverToolUses,agentIdandceilingontool.check, andgatingHooksinclaude plugin validate --json.