Skip to content
Proposals/Stand up claude self-hosted-runner and enable cr
proposalteamP5Worth a lookClaude Code

Stand up claude self-hosted-runner and enable cross-session SendMessage

Use v2.1.224’s self-hosted runner so Team/Enterprise web, mobile, and desktop sessions run on your machines, then wire cross-session SendMessage/ListAgents and crossSessionInbound approval for multi-machine agent handoffs.

Why this loop

v2.1.224 adds claude self-hosted-runner so Team and Enterprise web, mobile, and desktop sessions execute on machines or containers you operate. The same release adds cross-session SendMessage with ListAgents discovery (macOS and Linux, any of your machines) plus crossSessionInbound and dialogExpiry: inbound messages to a session with bypassed permissions are held for approval; messages to other sessions auto-deliver. Failed inbox writes now surface as errors instead of a false “Message sent”. Long (>200 char) project paths no longer leak session list/rename/fork/delete//resume across projects under a shared sanitized prefix. Pin session compute to owned hosts, then use ListAgents/SendMessage for multi-machine handoffs with explicit approval on bypassed-permission inbounds.

Proposed actions

  1. On each Team/Enterprise machine or container that should host Claude Code web, mobile, and desktop sessions, execute: claude self-hosted-runner
  2. In Claude Code settings, set crossSessionInbound and dialogExpiry so cross-session messages to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver.
  3. On macOS or Linux, in a running Claude Code session, call ListAgents to discover other sessions on any of your machines, then SendMessage to hand off work; confirm a failed teammate inbox write is reported as an error, not “Message sent”.
  4. For any project path longer than 200 characters, run session list, rename, fork, delete, and /resume and confirm they stay in that project’s session directory instead of another project under a shared sanitized prefix.
  5. From an attached web or mobile Remote Control client, trigger compaction and /clear: confirm compaction progress and the post-compaction boundary appear, /clear resets propagate, and a session recreated after server expiry does not upload prior local conversation history.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Paste into Claude Code / CLAUDE.md task

DevAgentRadar → Claude Code

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

Context

Assistant: Claude Code Proposal: Stand up claude self-hosted-runner and enable cross-session SendMessage Summary: Use v2.1.224’s self-hosted runner so Team/Enterprise web, mobile, and desktop sessions run on your machines, then wire cross-session SendMessage/ListAgents and crossSessionInbound approval for multi-machine agent handoffs. Primary source: https://github.com/anthropics/claude-code/releases/tag/v2.1.224

Why it matters

v2.1.224 adds claude self-hosted-runner so Team and Enterprise web, mobile, and desktop sessions execute on machines or containers you operate. The same release adds cross-session SendMessage with ListAgents discovery (macOS and Linux, any of your machines) plus crossSessionInbound and dialogExpiry: inbound messages to a session with bypassed permissions are held for approval; messages to other sessions auto-deliver. Failed inbox writes now surface as errors instead of a false “Message sent”. Long (>200 char) project paths no longer leak session list/rename/fork/delete//resume across projects under a shared sanitized prefix. Pin session compute to owned hosts, then use ListAgents/SendMessage for multi-machine handoffs with explicit approval on bypassed-permission inbounds.

Suggested actions

  1. On each Team/Enterprise machine or container that should host Claude Code web, mobile, and desktop sessions, execute: claude self-hosted-runner
  2. In Claude Code settings, set crossSessionInbound and dialogExpiry so cross-session messages to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver.
  3. On macOS or Linux, in a running Claude Code session, call ListAgents to discover other sessions on any of your machines, then SendMessage to hand off work; confirm a failed teammate inbox write is reported as an error, not “Message sent”.
  4. For any project path longer than 200 characters, run session list, rename, fork, delete, and /resume and confirm they stay in that project’s session directory instead of another project under a shared sanitized prefix.
  5. From an attached web or mobile Remote Control client, trigger compaction and /clear: confirm compaction progress and the post-compaction boundary appear, /clear resets propagate, and a session recreated after server expiry does not upload prior local conversation history.

Config surfaces this release may change

  • sandbox settings (high confidence) — check your repo before applying
  • context and compaction settings (high confidence) — check your repo before applying
  • agent context files (high confidence) — check your repo before applying
  • background and headless runs (high confidence) — check your repo before applying
  • skills — check your repo before applying
  • permission rules — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/claude-code-v2-1-224-stand-up-claude-self-hosted-runner-and-enable-cross and mark Applied, Skipped, or Failed. Proposal id: 49d8bef6-9687-4b10-9603-55920165532f

Your job

  1. Restate the change in one sentence.
  2. Propose a minimal plan for my repo (or a throwaway pilot).
  3. Implement only what I approve; prefer small diffs and tests.
  4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.

agentmcpmodelsecurityideRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

Claude Codev2.1.224Aug 7, 2026

v2.1.224

Added self-hosted environments: claude self-hosted-runner turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans · Added archive plugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning · Added a cancel-and-confirm step when removing an unavailable paste changes a command's text · Added ANTHROPIC_BEDROCK_REGION_PREFIX env var for Bedrock to prefer a specific cross-region inference profile over the AWS_REGION-derived one · +31 more changes
Verified excerpt — the source's own words

What's changed

  • Added self-hosted environments: claude self-hosted-runner turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans
  • Added archive plugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning
  • Added a cancel-and-confirm step when removing an unavailable paste changes a command's text
  • Added ANTHROPIC_BEDROCK_REGION_PREFIX env var for Bedrock to prefer a specific cross-region inference profile over the AWS_REGION-derived one
  • Added crossSessionInbound and dialogExpiry settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver
  • Added sandbox credential-masking options: extract and onExtractNoMatch for structured env values, decode: "jwt" with maskClaims for JWT-aware masking, and awsPairs/sigv4 for AWS SigV4 re-signing; these need network.tlsTerminate and are honored only from user, managed, or --settings settings

Excerpt ends here — this release continues at the source ↗.

Primary source ↗