v2.1.220
Bug fixes and reliability improvements
Primary source ↗Bug fixes and reliability improvements
Primary source ↗Added Claude Opus 5 (`claude-opus-5`), now the default Opus model — 1M context, fast mode at $10/$50 per Mtok · Added `sandbox.network.strictAllowlist` setting to deny non-allowlisted hosts for sandboxed commands without prompting · Added `DirectoryAdded` hook that fires after `/add-dir` or the SDK `register_repo_root` control request registers a new working directory mid-session · Added `mcp_server_errors` to the headless stream-json init event, listing `--mcp-config` entries skipped by config
Primary source ↗Changed `/code-review` to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target · Added screen-reader announcements of deleted text for word and line deletions (`Option+Delete`, `Ctrl+W`, `Cmd+Backspace`, `Ctrl+U`, `Ctrl+K`) in `--ax-screen-reader` mode · Fixed Windows paths with `\u`-prefixed segments (like `C:\Users\unicorn`) being corrupted into CJK characters in tool inputs, which made those files inaccessible · F
Primary source ↗Added emoji shortcode autocomplete in the prompt input: type `:heart:` to insert ❤️, or `:hea` for suggestions — disable with the `emojiCompletionEnabled` setting · Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently · Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session · Fixed Windows auto-update fai
Primary source ↗Added `sandbox.filesystem.disabled` setting to skip filesystem isolation while keeping network egress control · Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes · Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session · Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first —
Primary source ↗Claude no longer runs the `/verify` and `/code-review` skills on its own; invoke them with `/verify` or `/code-review` when you want them
Primary source ↗Fixed single-segment `dir/**` allow rules like `Edit(src/**)` auto-approving writes to nested `dir/` directories anywhere in the tree instead of only `<cwd>/dir` · Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions · Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer · Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always pr
Primary source ↗`/fork` now copies your conversation into a new background session (its own row in `claude agents`) while you keep working; the in-session subagent it used to launch is now `/subtask` · Added `claude auto-mode reset` to restore the default auto-mode configuration, with a confirmation prompt (pass `--yes` to skip) · Added a session-wide limit on WebSearch tool calls (default 200, tunable via `CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION`) to stop runaway search loops · Added a per-session cap on suba
Primary source ↗Added `--forward-subagent-text` flag and `CLAUDE_CODE_FORWARD_SUBAGENT_TEXT` environment variable to include subagent text and thinking in stream-json output · Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote characters, so tool inputs cannot visually alter the approval message · Fixed auto mode overriding a PreToolUse hook's `ask` decision for unsandboxed Bash — a hook `ask` now floors the decision at a prompt · Fixed p
Primary source ↗Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck · Added a startup warning for `Write(path)`, `NotebookEdit(path)`, and `Glob(path)` permission rules — use `Edit(path)` or `Read(path)` instead · Fixed `isolation: 'worktree'` subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree · Fixed the `ultracode` keyword opt-in firing on non-human-originated
Primary source ↗Fixed /model and other dialogs being blocked in `claude agents` background sessions (reverts an overly broad guard)
Primary source ↗Added screen reader mode: opt-in plain-text rendering for screen reader users. Run `claude --ax-screen-reader`, set CLAUDE_AX_SCREEN_READER=1, or add "axScreenReader": true to settings. · Added `vimInsertModeRemaps` setting: map two-key insert-mode sequences like `jj` to Escape in vim mode · Added `CLAUDE_CODE_PROCESS_WRAPPER`: agent view and the background service now honor a corporate launcher by running every Claude Code self-spawn through a required wrapper executable · Added mouse-click sup
Primary source ↗Auto mode is now available without `CLAUDE_CODE_ENABLE_AUTO_MODE` opt-in on Bedrock, Vertex AI, and Foundry; disable via `disableAutoMode` in settings · Fixed the terminal freezing and keystrokes lagging while streaming responses containing very long lists, tables, paragraphs, or code blocks · Fixed remote managed settings from a non-interactive run (`claude -p`, the SDK) being permanently recorded as consented without ever showing the security consent dialog · Fixed spurious prompt-injection wa
Primary source ↗Added directory path suggestions to `/cd`, matching `/add-dir` behavior · Added a `/doctor` check that proposes trimming checked-in `CLAUDE.md` files by cutting content Claude could derive from the codebase · `/commit-push-pr` now auto-allows `git push` to the repo's configured push remote (`remote.pushDefault`, or the sole remote when only one is configured) in addition to `origin` · Gateway: `/login` now supports Anthropic-operated public gateway endpoints · `EnterWorktree` now asks for confir
Primary source ↗Added an auto mode rule that blocks tampering with session transcript files · Fixed `--json-schema` silently producing unstructured output when the schema was invalid, and schemas using the `format` keyword being rejected · Fixed a message sent while Claude was working being silently lost when the turn ended at the `--max-turns` limit · Fixed Windows worktree removal deleting files outside the worktree when an NTFS junction or directory symlink existed inside it · Fixed background agents staying
Primary source ↗Fixed hook events not streaming during SessionStart hooks in headless sessions, which could cause remote workers to be idle-reaped mid-hook
Primary source ↗Added a warning when your login is about to expire, so you can re-authenticate before background sessions are interrupted · Added a grey ⏸ badge to the footer when in manual permission mode, making the active mode always visible · Added the session's additional working directories to MCP `roots/list`, with `notifications/roots/list_changed` sent when the set changes · Fixed opening or switching background agent sessions on macOS stalling for 15–20 seconds due to a false low-memory detection (reg
Primary source ↗Added a "Dynamic workflow size" setting in `/config` for controlling how large Claude generally makes dynamic workflows (small/medium/large agent counts) — an advisory guideline, not an enforced cap · Added `workflow.run_id` and `workflow.name` OpenTelemetry attributes to telemetry emitted by workflow-spawned agents, so a workflow run's activity can be reconstructed from OTel data · Fixed a crash in the inline Ctrl+R history search when accepting or cancelling while the search was still scanning
Primary source ↗Claude Sonnet 5 sessions no longer use the mid-conversation system role for harness reminders
Primary source ↗Changed `AskUserQuestion` dialogs to no longer auto-continue by default; opt into an idle timeout via `/config` · Changed the "default" permission mode to "Manual" across the CLI, `--help`, VS Code, and JetBrains; `--permission-mode manual` and `"defaultMode": "manual"` are accepted alongside `default` · Fixed a crash at startup when `disabledMcpServers` or `enabledMcpServers` in `.claude.json` is set to a non-array value · Fixed background sessions silently stopping mid-turn after sleep/wake or
Primary source ↗Stacked slash-skill invocations like `/skill-a /skill-b do XYZ` now load all leading skills (up to 5), not just the first · Fixed SSL certificate errors (TLS-inspecting proxies, missing `NODE_EXTRA_CA_CERTS`, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hint · Fixed streaming responses being discarded when the API emits a mid-stream overloaded/server error after partial output — the partial is now kept with an incomplete-response noti
Primary source ↗Subagents now run in the background by default, so Claude keeps working while they run and is notified when they finish (previously a gradual rollout) · Claude in Chrome is now generally available · Added background agent notifications in `claude agents` — sessions that need input or finish now fire the `Notification` hook (`agent_needs_input` / `agent_completed`) · Added `/dataviz` skill for chart and dashboard design guidance with a runnable color-palette validator · Gateway: added Claude Plat
Primary source ↗Introducing Claude Sonnet 5: now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2/$10 per Mtok through August 31. Update to version 2.1.197 for access. https://www.anthropic.com/news/claude-sonnet-5
Primary source ↗Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in `/model` when you haven't picked one yourself · Added readable default names for sessions at start, making them easier to identify and message · Added clickable file attachments in chat — Cmd/Ctrl-click reveals the file in Finder/Explorer · Security: `claude mcp list`/`get` no longer spawn `.mcp.json` servers that a repo self-approved via a committed `.claude/setting
Primary source ↗Added `CLAUDE_CODE_DISABLE_MOUSE_CLICKS` to disable mouse click/drag/hover in fullscreen mode while keeping wheel scroll · Fixed hook matchers with hyphenated identifiers (e.g. `code-reviewer`, `mcp__brave-search`) accidentally substring-matching — they now exact-match. Use `mcp__brave-search__.*` to match all tools from a hyphenated MCP server. · Fixed voice dictation on macOS capturing silence in long-running sessions after the default input device changes · Fixed voice dictation auto-submit n
Primary source ↗Added `autoMode.classifyAllShell` setting to route all Bash/PowerShell commands through the auto-mode classifier instead of only arbitrary-code-execution patterns · Added auto-mode denial reasons to the transcript, the denial toast, and `/permissions` recent denials · Added `claude_code.assistant_response` OpenTelemetry log event containing the model's response text. Redacted unless `OTEL_LOG_ASSISTANT_RESPONSES=1`; when that var is unset it follows `OTEL_LOG_USER_PROMPTS`, so deployments that a
Primary source ↗Added `/rewind` support for resuming a conversation from before `/clear` was run · Fixed scroll position jumping to the bottom while reading earlier output during a streaming response · Fixed background agents resurrecting after being stopped — stopping an agent from the tasks panel is now permanent · Fixed `/voice` showing a generic "not available" message when disabled by an organization's policy — it now explains the restriction · Fixed `/login` URL opening truncated in Windows Terminal when
Primary source ↗Bug fixes and reliability improvements
Primary source ↗Added `sandbox.credentials` setting to block sandboxed commands from reading credential files and secret environment variables · Added org-configured model restrictions to the model picker, `--model`, `/model`, and `ANTHROPIC_MODEL`, with a "restricted by your organization's settings" message when a restricted model is selected · Added mouse click support to select menus (permission prompts, `/model`, `/config`, etc.) in fullscreen mode · Fixed `--resume` failing with "No conversation found" whe
Primary source ↗Added `claude mcp login <name>` and `claude mcp logout <name>` to authenticate MCP servers from the CLI without opening the interactive `/mcp` menu, with `--no-browser` stdin redirect support for completing over SSH · Added status filtering (press `f`) to the `/workflows` agent detail view · Added a "Skills" section to the `/plugin` Installed tab · Added `teammateMode: "iterm2"` setting with a warning when auto mode cannot find the `it2` CLI · Added "Claude Platform on AWS - refresh credentials"
Primary source ↗The stream-stall hint now reads "Waiting for API response · will retry in …" instead of "No response from API · Retrying in …", and triggers after 20s of silence instead of 10s
Primary source ↗Improved auto mode safety: destructive git commands (`git reset --hard`, `git checkout -- .`, `git clean -fd`, `git stash drop`) are now blocked when you didn't ask to discard local work, `git commit --amend` is blocked when the commit wasn't made by the agent this session, and `terraform destroy`/`pulumi destroy`/`cdk destroy` are blocked unless you asked for the specific stack Added a warning wh
Primary source ↗Added `/config key=value` syntax to set any setting from the prompt (e.g. `/config thinking=false`) — works in interactive, `-p`, and Remote Control Added `sandbox.allowAppleEvents` opt-in setting that lets sandboxed commands send Apple Events on macOS Added `CLAUDE_CLIENT_PRESENCE_FILE` environment variable: point it at a marker file to suppress mobile push notifications while you're at the machi
Primary source ↗Fixed mid-stream connection drops: partial responses are now preserved instead of showing a raw error, and the spinner no longer gets stuck at "running tool" Fixed mouse-wheel scrolling in WSL2 under Windows Terminal and VS Code (regression in 2.1.172) Fixed a sandbox `denyRead`/`allowRead` glob over a large directory tree making the Bash tool description enormous and the session unusable on Linux
Primary source ↗Agent teams: removed the `TeamCreate` and `TeamDelete` tools. With `CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1` set, every session now has one implicit team — spawn teammates directly with the Agent tool's `name` parameter, no setup step needed. The `team_name` parameter on the Agent tool is still accepted but ignored. Added `Tool(param:value)` syntax for permission rules to match a tool's input param
Primary source ↗Session titles are now generated in the language of your conversation (set the `language` setting to pin a specific language) Added `footerLinksRegexes` setting for regex-matched link badges in the footer row, configurable via user or managed settings Improved Bedrock credential caching: credentials from `awsCredentialExport` are now cached until their `Expiration` instead of a fixed 1 hour
Primary source ↗Added `enforceAvailableModels` managed setting — when enabled, the `availableModels` allowlist also constrains the Default model (a Default that would resolve to a disallowed model now falls back to the first allowed model), and user or project settings can no longer widen a managed `availableModels` list
Primary source ↗Added `wheelScrollAccelerationEnabled` setting to disable mouse-wheel scroll acceleration in fullscreen mode Fixed the `/model` picker hiding the model family that Default resolves to — Opus now appears as its own row on Max/Team Premium/Enterprise plans, Sonnet on Pro/Team plans, and Opus on pay-as-you-go API accounts Fixed `/model` picker showing a hardcoded Sonnet version label when `ANTHROPIC_
Primary source ↗Fixed Fable 5 model names with a `[1m]` suffix not being normalized — Fable 5 includes 1M context by default, so the suffix is now stripped automatically Fixed a spurious "sandbox dependencies missing" startup warning on Windows when sandbox was enabled in settings
Primary source ↗Sub-agents can now spawn their own sub-agents (up to 5 levels deep) Amazon Bedrock now reads the AWS region from `~/.aws` config files when `AWS_REGION` isn't set, matching AWS SDK precedence; `/status` shows where the region came from Added a search bar when browsing a marketplace's plugins in `/plugin`
Primary source ↗[changelog-md] CHANGELOG.md
markdown_changelog · every 120m
https://raw.githubusercontent.com/anthropics/claude-code/main/CHANGELOG.md[github-releases] GitHub Releases
github_releases · every 60m
https://github.com/anthropics/claude-code/releases