Interactive terminal and VS Code sessions now start in auto mode on every plan and every provider, and the permission-mode docs still don't mention it — the only doc change shipped this day was cosmetic table reformatting.
Ultracode is now its own toggle in /effort (Tab, or /effort ultracode on|off) and no longer drags effort up to xhigh, so you can run it at whatever level you already chose.
Claude Sonnet 5.5 (claude-sonnet-5-5) is the new default Sonnet on the Anthropic API: 1M context, $2/$10 per Mtok, $0.20 cache reads.
When a Sonnet model's safeguards flag a message, the notice now explains why and offers to edit and retry; on sessions pinning an Opus model, the API — not your pin — now chooses which model handles the switch, per kind of flag.
A "Prompt is too long" error that survived a compaction now triggers a second, more aggressive compaction instead of dead-ending the session.
What the release notes didn’t say
Nothing was deleted from the docs today, and nothing new was added either. Every changed line in the day’s doc diff is markdown table padding collapsed to :- — accessibility.md, admin-setup.md and the rest are byte-for-byte the same content. That matters because the release’s most consequential change is a default: sessions now begin in auto mode everywhere, on every plan and provider. If you deploy Claude Code to a team and your policy assumed the old starting mode, set permissions.defaultMode yourself, because the pages a developer would check to learn the new behaviour don’t describe it yet.
The rest of the release is mostly repair work on long sessions: retries after a dropped stream now share one budget so a failing request gives up sooner, MCP calls in a resumed session wait up to 10 seconds for their server instead of failing with “No such tool available”, and /loop writes its status updates as visible text rather than burying them in reasoning.
The Agent SDK docs deleted the advice that .default() on a Zod field makes a custom tool parameter optional; the replacement pattern is .optional() plus applying the default yourself in the handler.
Also gone: the claim that a resource block's URI is "a label that Claude can reference later" — the docs now only say the SDK doesn't read from that path, quietly dropping a capability people may have designed around.
A newly documented limit on tool image results: PNG, JPEG, GIF, and WebP reach Claude as visual input, and anything else is written to disk with only the file path handed back as text.
Login enforcement got a sharper edge case: cloud provider sessions were described as unaffected by forceLoginMethod, and are now blocked at startup if an API key, auth token, or a key saved by an earlier Claude Console login is also present.
No changelog shipped today, so every one of these arrived as a silent doc edit.
What the release notes didn’t say
There was no changelog today, so all of this is doc-only. The biggest item is a walk-back: until now the custom-tools page told you to add .default(12) to a Zod field to make a tool parameter optional. That line is gone, replaced by .optional() with the fallback applied inside the handler. If you built tools on the old advice, your schema probably never marked those fields optional, and Claude has been required to supply them.
Two smaller deletions matter for anyone who designed against the text. The resource block’s URI is no longer described as a label Claude can reference later — only as something the SDK doesn’t read. And a limit nobody announced now appears in writing: an image returned from a tool is treated as visual input only if it’s PNG, JPEG, GIF, or WebP. Any other type gets saved to disk, and Claude receives the path as plain text.
On the admin side, forceLoginMethod grew a caveat. Cloud provider sessions are still exempt, unless an ANTHROPIC_API_KEY, an auth token, or a key left behind by an older Claude Console login is sitting in the environment — then the session is blocked at startup.
The cross-session messaging page no longer says a sender is told when its message is held, denied, dropped, or expired by the receiving session — every one of those sender-side notices was deleted, including the claude -p streamed-notice paragraph.
Also removed: the rule that Claude Code refuses a message addressed to the sending session's own name, and the line stating that a session never appears among its own /list-agents rows.
The idle notice's "one-shot, neither session polls the other" promise is gone, as is the note that a subagent or teammate setting notify_when_idle gets no subscription and is told so.
Every "before v2.1.x" behavior note was stripped from the page, erasing the written record of when @-mention attachment, teammate listings, held-message deadlines, and cross-machine conversations changed.
There was no changelog today: the entire day's news is one documentation page getting substantially shorter.
Doc-only day, one file touched, and it is almost entirely subtraction. The cross-session messaging page lost roughly a third of its detail with nothing added except a single Channels link in Related resources.
What the release notes didn’t say
The deletions cluster around one theme: feedback to the sender. The page used to promise that when a receiver holds a message behind an approval dialog, the sending session gets a notice, then a follow-up when the message is delivered, denied, or expired; that a -p session ending with held messages reports them as expired; that a settings change flipping to refuse drops held messages and reports a refusal to each sender; and that a session told its Claude which message the rate limiter dropped. All of that text is gone. If you build multi-session workflows that assume a sender learns the fate of its message, that assumption is now undocumented — design for silence until Anthropic says otherwise.
A second cluster is mechanism and history. Removed: that same-machine delivery works by sessions registering in files on disk (so container and WSL 2 isolation now read as bare assertions with no stated cause), that each session exports its own inbox socket rather than inheriting a parent’s, that renaming a session updates a shared lookup record and warns you when it can’t, and that a subagent’s message arrives under its session’s name with replies reaching the main conversation. Every version-gated “before v2.1.x” note went with them. Two of the cuts are behavioral claims, not prose trimming: the refusal of self-addressed messages, and the one-shot guarantee on idle notices. Nothing in the diff tells you whether the code changed or the page was merely pruned, which is exactly the problem with a silent removal.
The docs deleted the line saying critical-path rm and rmdir calls get routed to the auto-mode classifier; in an Agent SDK session in auto mode, Claude Code now denies them by default and never calls your canUseTool callback.
A claim was removed from the admin setup table: it no longer says the VS Code extension reads permissions.defaultMode only on Pro, Max, and Team plans.
In-process SDK MCP servers now fail at MCP_TIMEOUT (30 seconds by default) on each connect attempt, where the table previously said they had no first-turn deadline at all.
Two SDK additions shipped without a changelog line: TypeScript prewarm(), for pre-warming when you don't know a session's working directory until its first request, and a Python verbatim_prompts option.
The advisor transcript can now report a third state, Advisor unavailable (<error_code>), and 2.1.283 walks back 2.1.282's reservation of the claude-ai name so skills, commands, and MCP prompts using it load again.
What the release notes didn’t say
The permission docs were rewritten around deletes, and the rewrite is a behavior change nobody announced. The old text said a critical-path rm or rmdir in auto mode went to the classifier; the new text says an Agent SDK session in auto mode denies it by default, without invoking canUseTool. If you built a callback expecting to see those calls and approve some of them, it will no longer run. The MCP table also gained a deadline it explicitly did not have before: in-process SDK servers now fail at MCP_TIMEOUT, 30 seconds by default, per connect attempt — a slow-starting SDK server that used to wait now dies. Quietly added on the side: prewarm() in the TypeScript SDK, verbatim_prompts in Python, and an Advisor unavailable (<error_code>) line. And one removal that reads as a correction: the admin table no longer claims the VS Code extension honors permissions.defaultMode only on paid plans.
From the changelog itself, two things change daily practice. Interactive sessions on third-party providers, or with telemetry off, now start in auto mode when no permission mode is set. And /doctor prompt-audit will scan your CLAUDE.md files, skills, agents, and commands for prompting habits written for older models.
Three standalone plugin pages are gone: plugins, plugins-reference and plugin-marketplaces now redirect into a new plugins/ section (plugins/overview, plugins/manifest-reference, plugins/loading, plugins/org, plugins/marketplace-reference), so saved links and anchors in your own docs will need rewriting.
The Agent SDK page quietly gained a hard rule the changelog never mentions: on Linux and macOS, bypassPermissions refuses to start as root or under sudo outside a recognized sandbox, and the query dies before the first turn — that breaks root-by-default CI containers.
Also undocumented: a new CLAUDE_AGENT_SDK_CLIENT_APP environment variable that stamps your app's name into the SDK's User-Agent header.
Project and local settings files now ignore OpenTelemetry variables that switch export on, set its endpoint, or capture content, and startup, /status and claude doctor will name the ones they threw away.
The anthropic-skills and claude-ai names are now reserved: skill folders, command files and workflow commands in those namespaces stop loading, and an MCP server with either name lists no skills or prompts until you rename it.
What the release notes didn’t say
The biggest change in the docs is a deletion. The three top-level plugin pages have been folded into a plugins/ section, and every cross-reference in the admin and SDK docs was rewritten to match — plugin-marketplaces#managed-marketplace-restrictions is now plugins/org#restrict-what-users-can-install, plugins-reference#synced-plugins is now plugins/loading#synced-plugins. Nothing in the changelog mentions it, so if you link to plugin docs from an internal runbook, check those links.
Two behavior notes also arrived without a changelog line. The Agent SDK permissions page now says bypassPermissions will not start as root or under sudo on Linux and macOS unless you are in a recognized sandbox, and the failure happens before the first turn rather than at the first tool call — worth knowing before your next container build. The Python SDK’s env docs quietly added CLAUDE_AGENT_SDK_CLIENT_APP, which identifies your app in the User-Agent header.
From the changelog itself
Telemetry governance tightened: OpenTelemetry variables that enable export, set an endpoint, or capture content are now ignored when they come from project or local settings, with a startup notice naming what was dropped. Auto mode switched to the server-side classifier by default on direct Anthropic API connections when telemetry is off (CLAUDE_CODE_AUTO_MODE_SERVER=0 opts out). And Bash permission rules with a mid-pattern :* now apply from settings files instead of being silently skipped, which can widen what your existing rules match — read the startup warning.
A clause vanished from the Agent SDK docs: scheduled tasks that fire on your own machine are no longer listed among the notifications that carry no subkind, so anything branching on "subkind is absent means local task" is now reading a stale rule.
Undocumented in the changelog: an application can declare its own scheduled runs by setting CLAUDE_CODE_HOST_SCHEDULED_RUN=1 and sending the prompt with a scheduled-trigger origin, which makes Claude treat the turn as an assigned task rather than as someone typing.
Also undocumented: a new fireReason token (scheduled, manual, retry, catch_up, api) says why a scheduled notification fired, and results from declared runs arrive as task notifications, so filtering on kind alone will now swallow them.
An alpha readMcpResource() lands in the TypeScript SDK for reading MCP Apps ui:// widgets from a connected server, with the docs warning plainly that the contents are untrusted third-party HTML.
From the changelog itself, two that change daily habits: "attribution": false in settings.json removes commit and PR attribution lines, and rm -rf "$(pwd)" now asks for permission even in auto and bypass modes.
What the release notes didn’t say
The sharpest change this round is a deletion. The Agent SDK page used to say that scheduled tasks firing on your own machine have no subkind on their origin, grouped with PR activity and finished background tasks. That mention is gone from the list, while the same section gains a path for applications to set subkind: "scheduled-trigger" themselves. If your code treats a missing subkind as the signal for a local task, re-read it.
The scheduled-run declaration is new and appears nowhere in the changelog. It needs CLAUDE_CODE_HOST_SCHEDULED_RUN=1 in the session env, is ignored in any process already carrying CLAUDECODE or CLAUDE_CODE_CHILD_SESSION, and accepts a fireReason of one to thirty-two lowercase letters or underscores. Alongside it, readMcpResource() and a _meta field on MCP tool status arrive so an application can render a tool’s widget, both gated behind capability flags in the init message and both silent in the release notes. The docs also add a small but useful warning: results from your declared runs carry kind: "task-notification", so suppressing on that kind alone will hide your own scheduled work.
One more worth a glance: the Opus 5 advisor row now reads “Opus 5.5 or Opus 5”, and Opus 4.7 and 4.8 advisors are refused by the API for that pairing.
The TaskOutput tool is gone as of v2.1.277, along with its BashOutput alias, and Claude now reads a background task's output file with Read instead.
Deny rules and disallowed_tools entries that still name TaskOutput or BashOutput are ignored without a warning, so a permission config can look enforced while doing nothing.
Monitor's persistent option has been removed, every watch now carries a deadline, and the docs put the effective cap at 30 minutes even though timeout_ms still accepts an hour.
An advisor the API refuses no longer errors out: Claude Code silently resends the request without it and runs the rest of the conversation with no advisor until you /clear or /compact.
Resuming a session through the SDK or claude -p now restores its earlier spend into total_cost_usd, so code that sums per-call totals double-counts from v2.1.277 onward.
What the release notes didn’t say
No changelog entries shipped today, so everything here comes from the docs alone. Two capabilities were deleted outright: the TaskOutput tool in v2.1.277, and Monitor’s persistent flag, which used to let a watch run for the life of a session. Both deletions carry an edge the removal notes bury. A deny rule naming TaskOutput or BashOutput is now ignored silently, so an org policy written against it still parses and no longer protects anything. Monitor’s page now caps the effective deadline at 30 minutes while the timeout_ms field still advertises an hour, which means a watch you configured for 45 minutes will stop early and the schema won’t tell you. The advisor docs moved the same direction: a rejected advisor used to fail every request with a named API error, and now Claude Code quietly resends without it, so a session you believe has a second model checking its work may have none.
Two additions arrived undocumented too. The CLI’s --system-prompt and --system-prompt-file flags now accept a line containing only __SYSTEM_PROMPT_DYNAMIC_BOUNDARY__, which splits the prompt into a cached static block and a per-request block (v2.1.275 or later). And updateSettings() gained a "userSettings" source that writes effortLevel as the default for the session’s current model, without changing the running session.
The cost-tracking change is the one most likely to bite. From v2.1.277, a call that resumes or forks a session restores that session’s earlier spend into total_cost_usd and modelUsage; before, resumed totals started at zero. Read the latest result for the session total, because adding the results up now double-counts. maxBudgetUsd deliberately ignores restored spend, so your budget cap and your reported total no longer describe the same number.
A bugfix line was deleted from the published changelog: the entry claiming VS Code no longer opens some claude.ai/code sessions as an empty conversation is gone, with nothing replacing it.
The /design canvas is no longer described as a research preview of Claude Design's editor; it now publishes as a plain Design artifact.
Saving is no longer gated account by account — anyone who opens the canvas can change an element and the edit saves automatically, where before most people could only view and export.
A new requirement appeared with no changelog entry: you have to open the published canvas in a desktop browser to edit it.
The minimum version for /design moved from 2.1.234 to 2.1.265, unexplained.
What the release notes didn’t say
A bugfix claim vanished. The changelog carried a line saying VS Code no longer opened some claude.ai/code sessions as an empty conversation with no messages; that line has been removed from the published notes and nothing took its place. A deleted fix claim usually means the fix was pulled or never shipped, so treat that bug as live until Anthropic says otherwise.
The /design canvas changed status the same way, with no changelog entry. The docs stopped calling it a research preview of Claude Design’s editor and now call the output a Design artifact. The per-account gate on saving is gone: where the old text said most people could only view the draft and export it, everyone can now select an element, change it, and have the edit save automatically. The trade is a constraint the docs never stated before, which is that editing needs a desktop browser. The minimum version moved from 2.1.234 to 2.1.265 alongside it.
There was no changelog delta today, so everything above is doc-only movement.
An old changelog entry was quietly rewritten in place: hook output now spills to disk above 10,000 characters with a 2,000-character preview, not the 50,000 characters the published line used to say.
The TaskOutput tool is gone, and the two settings that configured it — taskOutputMaxChars and TASK_MAX_OUTPUT_LENGTH — now sit in config files doing nothing.
The gateway docs finally admit that the gateway keeps no record of failed upstreams, and that on Bedrock, Vertex and Foundry it will wait up to an hour on a dead one before moving to the next.
The artifacts page dropped its "requires v2.1.182 or later" note on the built-in design skill, which reads as that feature becoming baseline.
A project with no CLAUDE.md now reads AGENTS.md instead, and auto mode defaults to a server-side classifier you are not billed for.
What the release notes didn’t say
A line in an older, already-published changelog entry was rewritten in place. It used to say hook output over 50,000 characters is saved to disk instead of being injected into context. It now says 10,000 characters, with a 2,000-character preview. Nothing announced the correction, so if you write hooks, your output has been landing in a file five times sooner than the public record claimed. On the same day, the artifacts page dropped its version gate: the built-in design skill no longer carries a “requires v2.1.182 or later” note.
The Claude apps gateway docs gained two paragraphs describing behaviour that was already shipping. The gateway keeps no memory of which upstreams are failing, so every request still tries a dead upstream and waits for it to fail before moving on. On the Anthropic API path that wait is bounded by timeouts.upstream_ttfb_ms. On Bedrock, Vertex and Foundry it is not, and the gateway waits up to an hour. Two other gateway additions, store.connect_timeout_seconds and the enduser.sub telemetry attribute, are documented as needing v2.1.274 on the gateway server but never appeared in that release’s notes — and an earlier gateway refuses to start when it finds the timeout key. The use_proxy row also quietly lost the words “Unset or”, because unset stops meaning direct once proxy-only egress is on.
From the changelog
Three items change habits. TaskOutput is removed, so background task output is read with Read, and taskOutputMaxChars and TASK_MAX_OUTPUT_LENGTH are now dead keys that fail quietly in existing config. AGENTS.md is read in any project with no CLAUDE.md, switchable under “Project instructions” in /config, though not yet on Bedrock, Vertex or Foundry. And a sandbox.excludedCommands glob no longer exempts a whole compound Bash command when only one part matches, so an exemption that worked yesterday may not today. Auto mode on the API, Enterprise and the cloud providers now defaults to a server-side classifier that carries no classifier charge, with an Auto mode server row in /status and a warning when it falls back to the billed path.
The SDK's MCP page deleted its old 2-second startup rule: if you pass any stdio, HTTP or SSE server in options.mcpServers, the first turn now also waits for your .mcp.json and plugin servers, up to MCP_TIMEOUT.
A new CLAUDE_CODE_MCP_STARTUP_WAIT_MS environment variable lets you set that first-turn wait yourself, or set it to 0 to skip it entirely — documented, but absent from the changelog.
Every MCP tool call now reports which server serves it and where that server came from, and the docs say to base trust on that source field and never on the mcp__<server>__ tool-name prefix.
Projects — one conversation that starts and tracks parallel cloud sessions, in public beta on Pro and Max — was added to the docs' parallelism comparison with no changelog entry at all.
If ANTHROPIC_BASE_URL points at a proxy or gateway, version 2.1.275 failed every request with a 400; 2.1.276 fixes it, so skip straight past 2.1.275.
What the release notes didn’t say
The SDK’s MCP page rewrote its startup rule and removed the old one. It used to say that without options.mcpServers, Claude Code waits 2 seconds for pending servers, so .mcp.json entries commonly show pending at init. Now, if you pass any stdio, HTTP or SSE server yourself, the first turn waits for those settings-file and plugin servers too, up to MCP_TIMEOUT — with tool search on, only servers marked alwaysLoad: true count. The new CLAUDE_CODE_MCP_STARTUP_WAIT_MS (v2.1.274 or later) overrides the whole thing. Separately, MCP tool calls gained provenance: mcp_server on the PreToolUse, PostToolUse, PostToolUseFailure, PermissionRequest and PermissionDenied hook inputs, mcpServer in canUseTool, and source on mcpServerStatus() and the init message. The guidance attached to it is worth reading twice — base trust decisions on source, never on the server’s name or the mcp__<server>__ prefix, and treat the name itself as untrusted text. And Projects, a public beta on Pro and Max where Claude runs parallel cloud sessions from one conversation, appeared in the docs’ comparison of parallel-work modes without a changelog line.
Two small removals: the notes pinning screen reader mode and the flat Bedrock credential format to v2.1.181 are gone, so that floor is now simply assumed. One behavior change that costs money if you build on the SDK — since v2.1.274, a /<name> matching nothing no longer returns Unknown command for free; it goes to the model as an ordinary message and spends a turn.
From the changelog itself, two things change daily practice. Skills and plugins enabled on your claude.ai account now sync into terminal sessions signed in with that account, with syncClaudeAiSkills: false and syncClaudeAiPlugins: false to opt out. And plugins installed from npm are now fetched with npm pack --ignore-scripts and integrity-verified, so a package’s install scripts no longer run on your machine.
The Agent SDK docs no longer suggest turning off snapshot when your app changes the system prompt between resumed calls. They now say to keep it on in production and to send new instructions as a message or through a hook's additionalContext.
Admins get two new managed settings, syncClaudeAiSkills and syncClaudeAiPlugins, to stop Claude Code loading the skills and plugins people turn on in claude.ai. Neither key is in the changelog.
The agent teams page deleted its only warning that the default display mode changed from split panes to a single terminal in v2.1.179. The changelog never mentioned that change.
/code-review no longer starts many review subagents on models that have no tuned settings. It uses shorter inline review prompts instead.
Background commands are no longer stopped after 30 idle minutes when memory is only slightly tight, and a new warning appears when memory is critically low.
What the release notes didn’t say
The Agent SDK’s system prompt guide took back some advice. It used to suggest snapshot: false for apps that change append between resumed calls. Now it says to keep recording on in production. With recording off, a resumed session can’t reuse its prompt cache, and where the API enforces preserved thinking, Claude also loses its thinking from earlier turns. To change instructions mid-session, for example to switch an agent to read-only, the guide now says to put them in the next user message or return them as additionalContext from a UserPromptSubmit or PostToolUse hook.
The admin page adds the syncClaudeAiSkills and syncClaudeAiPlugins keys and says strictPluginOnlyCustomization also blocks synced skills. The changelog mentions neither. The OTEL_LOG_TOOL_CONTENT entry no longer promises full tool input and output bodies. It now lists only file contents and Bash output, and span attributes have their own settings. The agent teams page also dropped its note that the default changed from auto to in-process in v2.1.179.
In the changelog
Version 2.1.274 fixes sessions stuck retrying “unexpected tool_use_id” errors. It keeps an active /goal when you resume a session that was compacted. Streamable HTTP MCP calls no longer time out after about five minutes when you set a longer timeout. The new CLAUDE_CODE_MCP_STARTUP_WAIT_MS limits how long the first headless turn waits for MCP servers to connect. Plugin and marketplace clones now leave Git LFS files as pointers until you run git lfs pull.
The admin docs quietly replaced the name "Claude Code on the web" with "Cloud sessions", while the changelog still uses the old label.
Since 2.1.273, an Agent SDK Stop or SubagentStop hook callback that times out no longer throws away your other hooks' decisions on that event, and the release notes don't mention the change.
A new Agent SDK configuration page warns that TypeScript's env option replaces the whole environment while Python's merges, and that maxBudgetUsd: 0 stops a session from starting at all.
Version 2.1.273 fixes auto-compact firing at about half the real context window in sessions that use the advisor tool.
Auto mode on Bedrock, Vertex and Foundry now uses the local classifier by default, and CLAUDE_CODE_AUTO_MODE_SERVER=1 switches it to the platform's classifier.
What the release notes didn’t say
The admin guide no longer says “Claude Code on the web”. It calls the feature “Cloud sessions” now, though the page address and the changelog still use the old name. The Agent SDK hooks page records a change that the 2.1.273 notes skip. A Stop or SubagentStop callback that times out now counts as no decision, so your other hooks on that event still apply. Before 2.1.273, one slow callback threw away every other hook’s decision. A timed-out SessionStart callback now counts as no output, and the first timeout of either kind adds a message to the stream saying the app driving the session didn’t respond.
New SDK guidance worth knowing
The Agent SDK has a new “Configure your agent” page, and it spells out several traps. In TypeScript, env replaces the child process’s environment, so spread process.env into it or you lose PATH and your API key. maxTurns: 0 means no limit, but maxBudgetUsd: 0 is rejected at startup. With streaming input, the budget keeps adding up across messages until a /clear. Calling setModel() with no model returns to Claude Code’s default model, not the one you passed in options. Separately, the permissions page now says that setting allowDangerouslySkipPermissions in plan mode skips nothing. It only lets you switch to bypassPermissions later. The hosting guide also stopped naming S3, Redis and Postgres for its example session stores.
In the changelog
Sessions using the advisor tool counted those turns at about twice their real size, so auto-compact fired early. That is fixed. /login, /upgrade and /extra-usage no longer discard earlier thinking, which had forced a full prompt-cache rewrite. A 2.1.268 change is reverted: commands the permission checker can’t parse, like time -p make build, prompt again instead of being denied. Two permission holes are closed. One let commands the checker couldn’t parse skip the prompt under blockReadsOutsideWorkingDirectories. The other let a subshell hide an rm in bypass mode.
The Monitor tool's persistent option is gone from the docs and from the SDK's MonitorInput type, so every watch now ends after at most 30 minutes (10 in claude -p runs) and Claude gets one notice to start a new one.
The best-practices page deleted its advice to use --verbose while developing headless pipelines and turn it off in production, and the changelog says nothing about it.
The new omitClaudeMd agent field needs TypeScript Agent SDK v0.3.271 or later, has no Python equivalent, and does nothing when the agent runs as the main thread; only the docs say so.
In auto mode, a subagent's hand-back to its caller is now its own call that the safety classifier reviews, and inline ! shell commands in skills follow normal permission rules instead of the classifier.
The medium dynamic workflow size now aims for 10 agents instead of 15, and Pro plans default to small.
What the release notes didn’t say
The best-practices page deleted its advice to use --verbose while developing headless pipelines and turn it off in production. No changelog entry covers this, and the diff does not show the flag itself changing, so treat it as dropped advice rather than a dropped flag. The new omitClaudeMd field has limits the changelog leaves out. It needs TypeScript Agent SDK v0.3.271 or later, the Python SDK’s AgentDefinition does not have it, and it is ignored when the agent runs as the main thread. The Amazon Bedrock page also dropped its v2.1.176 version note on credential caching, so it now describes Expiration handling as if every version supports it.
Monitor watches now expire
The changelog does mention this one, but it is still a removal that changes how you work. A Monitor watch used to run for the whole session if you set persistent. Now every watch has a deadline, and Claude has to start a new watch to keep going. If you tail logs or dev servers through Monitor, expect extra re-arm turns in long sessions, and remove persistent from any SDK code that sets it.
The Chrome page deleted its list of which browser actions prompt in plan mode, so clicks, typing and navigation no longer need approval there; only recording a GIF, opening a tab, or running a shortcut still asks.
The Agent SDK docs dropped the line promising that hooks already sitting in your project's settings.json run automatically once settingSources includes "project".
Checking a cloud session's progress with /tasks in the CLI is gone from the docs; the only routes listed now are claude.ai and the mobile app.
In-process SDK MCP servers now hold up the first turn while they connect and list tools, the exact opposite of what the table said yesterday.
Advisor mismatches split into two outcomes: some are quietly detached as before, others now fail every single request with an API error until you change the advisor.
No changelog entries today, so everything below shipped in the docs alone.
What the release notes didn’t say
The Chrome page deleted its list of which browser actions need approval in plan mode. Clicks, typing, navigation and tab management were all named there as state-changing and prompting, and now only a GIF recording, a new tab, or a shortcut does. Two SDK promises vanished the same day: that hooks already in your project’s settings.json run in the SDK with no extra setup, and the advice to check for a subagent marker before spawning subagents from a UserPromptSubmit hook. The MCP table reversed itself on in-process SDK servers, which now hold up the first turn instead of never delaying it. allowUnixSockets is now documented as macOS only and ignored on Linux, so that setting has been doing nothing in Linux sandboxes. And the Python SDK can set an output style after all, through the settings option as a JSON string, which the same page previously called impossible.
Advisor pairing got stricter and louder. Opus 5 now accepts only Fable or another Opus 5, and Fable 5.1 accepts only Fable 5.1. Some bad pairings are still dropped quietly. Others now fail every request with an API error naming both models until you change the advisor or switch it off.
The sentence promising that dontAsk denies anything you haven't pre-approved is gone from the SDK permission docs; read-only Bash commands, file reads inside your working directories, and Agent calls now run with no allow rule at all.
Deleted: the paragraph saying Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry rebuild the system prompt on every request. From v2.1.268 they record it like everyone else, and the snapshot field works there instead of being silently ignored.
Todo and task tool availability flipped from a blocklist of newer models to an allowlist of older ones, so any model ID Claude Code doesn't recognize, including custom gateway IDs, now ships without TodoWrite and the Task tools unless you opt in.
The advisor table quietly dropped the rule rejecting a Fable 5 advisor for a Fable 5.1 main session, along with the Fable 5 minimum-version note.
From the changelog itself: claude plugin eval scores a plugin's eval suite, /output-style now works in headless and Remote Control sessions, and a deny rule starting with ! no longer applies beyond the settings file that wrote it.
What the release notes didn’t say
The permission pages were rewritten around one idea the changelog never states: some tool calls need no approval at all, so no mode and no rule has to grant them. dontAsk used to be documented as denying anything not pre-approved. It now lets read-only Bash commands, file reads inside your working directories, and Agent calls through on their own. If you built a headless agent on the old wording, its real tool surface is wider than your allowedTools list, and the docs changed their own scoped-rule example from Bash(ls *) to Bash(npm test *) because ls no longer needs a rule. Two more deletions matter for anyone not on a claude.ai or Console account: the note that Bedrock, Google Cloud’s Agent Platform and Microsoft Foundry rebuild the system prompt every request is gone, since v2.1.268 made recording universal, and the todo tools now key off a list of recognized older models, so an unfamiliar model ID loses them by default. A smaller removal: the WSL instructions for reading Setting sources in /status were cut and replaced with a link to the managed-settings page.
The read-only thread runs through the changelog too. Version 2.1.270 is a single fix for read-only git commands asking permission after a session had been running a while, which is the same reclassification showing up as a regression.
The Agent SDK now emits one AssistantMessage per content block instead of one per turn, so code that counts blocks in a message will now always see one, and the changelog says nothing about it.
The advisor page dropped its promise that /advisor off clears your saved advisorModel, and added that some advisor selections now last only for the current session.
/advisor now works where there is no terminal picker (print mode, the Agent SDK, the desktop app, Remote Control), a capability that shipped back in v2.1.260 and only reached the docs now.
Admins gained managedMcpServers for pushing remote MCP servers to every user, and server-managed settings are now fetched for sessions using a user_oauth Anthropic profile, which widens what a multi-tenant SDK process picks up from its host.
From the changelog proper: a long run of prompt-cache repairs means switching models with /model no longer re-sends every tool definition, and managed hook allowlists that failed open when unreadable now fail closed.
What the release notes didn’t say
The Agent SDK’s AssistantMessage changed shape. It now carries a single content block, and one Claude response produces several of them sharing a message ID. The docs rewrote their own examples away from len(message.content), which is the tell: anyone using that count to log turn size will now see 1 every time, with no error and no changelog entry. On the advisor page, the words “and clear your saved advisorModel” were deleted from the instructions for /advisor off, and a new caveat says some selections apply to the current session only, so turning the advisor off is no longer documented as forgetting it. Three more changes arrived with no note: /advisor works without a picker in print mode, the SDK, desktop and Remote Control as of v2.1.260; managedMcpServers lets an admin hand remote MCP servers to every user alongside their own; and server-managed settings are now fetched when a session authenticates with a user_oauth Anthropic profile, which is worth reading if you run tenants in one process. Smaller but sharp: MCP tool results containing images are now exempt from the 25,000-token spill-to-file, and the Fable 5.1 advisor version floor was corrected from v2.1.255 to v2.1.257, meaning that pin was wrong for as long as it was published.
The changelog’s own useful half is mostly invisible plumbing. A dozen fixes stop long sessions from breaking their own prompt cache: switching models no longer re-sends every tool definition, mid-session MCP and plugin tools now arrive as deferred definitions rather than rewriting the tool list, and resumed sessions replay their recorded tool descriptions instead of re-rendering them. Two are security-shaped and easy to miss in the list: managed allowedHttpHookUrls, httpHookAllowedEnvVars and allowedChannelPlugins used to admit everything when unreadable and now admit nothing, and a marketplace path containing a backslash could slip past the containment check on macOS and Linux. If you set effort: in frontmatter on commands, skills or subagents, it was being ignored on Opus 4.7, Opus 4.8 and Fable 5 until this release.
The cloud environments page deleted the two numbered steps that spelled out the order of startup work: a setup script runs first, before Claude Code launches, and only when no cached environment exists — that detail now survives only inside a comparison table.
The Desktop quickstart removed its "Coming from the CLI?" section, the paragraph telling you Desktop and the CLI share CLAUDE.md files, MCP servers, hooks, skills and settings and can run on the same project at once; it is now a link you have to follow.
No changelog entry says so, but output styles are no longer fixed at startup: the docs now say the selected style is added to the system prompt every turn and a switch applies from your next message, replacing the old line that changes only take effect in the next session.
Two quieter doc edits: /cd lost its "requires v2.1.169 or later" note, and a pinned or custom model in the /model picker now shows the model's real name when Claude Code recognizes the ID, instead of always falling back to the raw ID string.
Version 2.1.266 exists to undo a one-day regression in 2.1.265, where the undocumented CLAUDE_CODE_USE_GATEWAY variable started forcing Cloud gateway sign-in on its own and failed every request for anyone using an API key, an apiKeyHelper, or custom auth headers.
What the release notes didn’t say
The output-style change is the one to notice. The docs used to state plainly that the system prompt is fixed at startup for caching, so a style change waited for your next session. They now say the style you select is added to the system prompt every turn, that switching mid-session applies from your next message, and that it rebuilds the prompt cache once — a behaviour change with no changelog line behind it. Editing a style file mid-session still needs a terminal restart, so the two cases now differ.
The removals are smaller but real. Cloud environments dropped the explicit ordering steps for setup scripts versus SessionStart hooks, including the part that matters most in practice — a setup script does not run again once an environment is cached. The Desktop quickstart cut its CLI-comparison paragraph outright. And /cd losing its minimum-version footnote suggests the supported floor has simply moved past it.
From the changelog itself, three things change day-to-day work: a cd now persists across turns in non-interactive sessions (-p with stream-json, the Agent SDK, cloud sessions), several prompt-cache reuse bugs around resumed subagents and agent teammates are fixed, and MCP servers configured as http that only speak the legacy HTTP+SSE transport finally connect via fallback. Tool results saved to disk are now capped at 1 GB, with truncation stated in the preview.
A new flag, --append-subagent-system-prompt-file, showed up in the CLI reference today and appears in no changelog entry, past or present.
The docs say it needs version 2.1.261, which shipped on September 4 — so it has been live and unannounced for two days.
It loads subagent instructions from a file instead of the command line, and it cannot be combined with the older inline flag.
Nothing was deleted from the docs today; the single rewritten line was an environment variable description picking up a mention of the new flag.
The only changelog entry today is 2.1.263, which says nothing beyond "bug fixes and reliability improvements".
What the release notes didn’t say
The 2.1.261 entry on September 4 listed two things: an organization-policy line in /status and claude doctor, and two settings for raising inline output limits. It never mentioned --append-subagent-system-prompt-file, which the CLI reference now says requires that exact version. The flag has been shipping since Friday and the docs only caught up today.
It matters if you run headless sessions that spawn subagents. The older --append-subagent-system-prompt takes your text as a command-line argument, which falls apart once your standing instructions run past a line or two. The file version takes a path instead. You can use one or the other, never both. Both need -p, and both set CLAUDE_CODE_ENABLE_APPEND_SUBAGENT_PROMPT on your behalf.
No pages, flags or settings were removed today. Today’s own changelog entry, 2.1.263, carries no detail at all.
The accessibility page dropped most of its "requires version X or later" notes, so the docs no longer tell you which release added table flattening, typing echo, deletion announcements, or permission-mode announcements — if you're pinned to an older build, that answer is gone.
Named CrowdStrike Falcon guidance for watching activity inside WSL was deleted and replaced with a generic "check your endpoint vendor's WSL guidance".
The settings reference has been split into new settings-reference and managed-settings pages, and links across the admin docs now point at per-key anchors instead of the old settings#available-settings — old bookmarks and deep links will need rechecking.
Undocumented in the changelog: enabling WSL sessions in Claude Code Desktop on a managed device no longer means contacting your Anthropic account team, it's now a disableWslSessions registry value under HKLM, with a log line you can grep when a device still refuses.
Also silent: a CLAUDE_AX_PREPARK_MS variable, thinking: and warning: transcript labels, and a modelPicker managed setting that replaces lower layers instead of merging.
What the release notes didn’t say
The accessibility page was rewritten, and the rewrite lost things. Version gating that used to sit inline — tables reading as sentences needs v2.1.198, permission-mode announcements need v2.1.210, typing echo v2.1.219, deletion echo v2.1.222 — is simply absent now. A few version notes survive in the new settings table, but the prose ones are gone, so a reader on an older build can no longer tell what their version actually does. The page’s “Related resources” list went with them. Over in admin setup, the CrowdStrike Falcon recipe (Linux sensor plus two named exclusions) was replaced with advice to ask your vendor, and the detailed explanation of per-key env merging across managed sources, including the CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION escape hatch, moved off the page into the new managed-settings page.
The biggest silent gain is on Windows: turning on Desktop WSL sessions where managed settings are present used to require a conversation with Anthropic. It’s now self-serve — set disableWslSessions to false under HKLM\SOFTWARE\Policies\Claude (Claude Desktop v1.19367.0 or later), and Desktop re-reads it per session with no restart. The docs are also newly honest that the obvious verification doesn’t verify: if your session fetches server-managed settings, /status shows Enterprise managed settings (remote) and tells you nothing about whether your Windows flag arrived.
From the changelog
keybindingFlavor no longer has any effect — word-editing keys now follow Bash, with Ctrl+W deleting back to whitespace. Two permission bugs worth knowing about if you rely on path rules: rules whose path contained parentheses were being dropped as invalid, which left folders you’d marked read-only writable, and zsh commands hiding a command substitution in a REPORTTIME assignment were auto-approving. Both fixed. Day-to-day additions: /diff opens an uncommitted-changes panel beside the conversation in fullscreen, /skill-doctor shows which loaded skills go unused and what they cost you in context, and bashOutputMaxChars/taskOutputMaxChars raise how much command output reaches Claude inline before it spills to a file.
The SDK docs quietly deleted the 'Tool name format' section from custom-tools — the mcp__{server}__{tool} naming rule now only lives under 'Call a custom tool', so old bookmarks land nowhere.
Admin-setup dropped the line saying a policyHelper 'preempts all four sources' of managed settings; that precedence claim now survives only on the Settings page.
A bigger correction hides in cost-tracking: per-step output_tokens on assistant messages is now documented as a placeholder, so anyone summing it for token totals has been reading a fake number — read the result message instead.
New undocumented-until-now guidance covers recovering cost totals after a session crash (the final error_during_execution can arrive with every cost field zeroed) and tracking cost per turn in streaming input mode.
The changelog buried a fix worth knowing: session cleanup had been deleting contents inside a project's memory folder.
What the release notes didn’t say
Most of this shipped in the docs, not the changelog. The mcp__{server_name}__{tool_name} naming pattern was removed as its own section in agent-sdk/custom-tools and folded into a cross-reference — the rule still holds, but the canonical explanation moved. Admin-setup deleted the paragraph stating that a policyHelper output becomes the only managed configuration for a run, preempting all four other sources; that behavior is now only asserted on the Settings precedence page. The advisor doc quietly trimmed its reassurance that scripts passing the no-op --advisor flag keep working.
The most consequential silent change is in cost-tracking. The old text treated differing per-step output_tokens as a ‘rare discrepancy’ to resolve by taking the highest value and filing a bug. The new text says plainly that per-step output_tokens is always a placeholder pulled from message_start, and the real count only lands on the result message. If you built token accounting by summing per-step output, it was wrong by construction. The same rewrite adds new guidance for streaming-input-mode cost tracking and for recovering totals after a crash. The PermissionDenied hook also now fires for denials with no classifier verdict, and ignores retry: true in that case.
From the changelog, two items matter day-to-day: the Write tool now lets newer models overwrite an unread file (matching Edit’s rules), and a fix stopped session cleanup from deleting contents inside a project’s memory folder.
Anthropic ran a heavy pruning pass on the Agent SDK docs — none of it appears in the 2.1.227 changelog, which is all bug fixes.
The subagent nesting-depth history is gone: the docs no longer record that older versions nested five layers deep by default, or that v2.1.217–218 briefly defaulted to one before v2.1.219 settled on three.
The token-by-token streaming how-to (the 'Stream text responses' section with its content_block_delta / text_delta code example) was deleted from the streaming-output page.
The migration guide lost its 'Why the Rename?' and 'Getting Help' sections, and a raft of version-specific behavior notes (v2.1.198 extended thinking in subagents, v2.1.199 partial output, v2.1.205 message-loss) vanished across several pages.
No actual feature, flag, or settings page was deprecated — this is documentation slimming, not a walk-back.
What the release notes didn’t say
The public changelog for 2.1.227 is five bug fixes. It says nothing about the much larger thing that happened to the docs: a broad trim of the Agent SDK reference. Most of it is harmless prose cleanup — dozens of ‘This guide covers…’ preambles and duplicate code samples were cut. But two categories are worth flagging for practitioners.
First, the docs are shedding their memory of older behavior. Historical ‘in version X this worked differently’ notes were deleted wholesale: the subagent nesting-depth timeline (five layers deep in v2.1.172–216, one in v2.1.217–218, three from v2.1.219), the note that extended thinking used to be disabled inside subagents before v2.1.198, the v2.1.199 partial-output shape, and the v2.1.205 fix for messages lost on a turn’s final iteration. If you run a pinned older SDK, that compatibility context now lives only in git history.
Second, one genuinely useful how-to disappeared: the ‘Stream text responses’ example on the streaming-output page, which showed how to print tokens as they arrive via content_block_delta/text_delta. The streaming feature still works; the worked example that taught it is gone. Nothing here is a real deprecation — no flags or pages were removed — but the docs are noticeably lighter on both history and copy-paste guidance than they were yesterday.
A new promptSuggestionEnabled setting shipped with no changelog entry — today's docs are the only announcement of it.
You can now disable the grayed-out prompt predictions from a settings file, not just the /config toggle or the CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION env var.
The env var takes precedence over the new setting when both are set, so the setting is the softer, overridable control.
New guidance explains how to lock prompt suggestions off org-wide: set promptSuggestionEnabled to false in managed settings AND pin the env var under the managed env key so users can't re-enable it.
The env-var description quietly dropped 'after Claude responds' — suggestions are now described as appearing in your prompt input generally.
What the release notes didn’t say
There was no changelog today, yet three docs pages moved in lockstep around one feature: prompt suggestions. A brand-new promptSuggestionEnabled setting appeared in settings.md (default true), giving admins and users a settings-file way to turn off the inline predictions instead of relying on the /config toggle or the CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION environment variable. The precedence is spelled out both ways: the env var wins over the setting when both are present. The most practically useful addition is the org-lockdown recipe in interactive-mode.md — to actually keep suggestions off for everyone, you set the setting to false in managed settings and pin the env var to false under the managed env key, otherwise a user’s own environment variable re-enables them. One small wording change also slipped in: the env-var description no longer says suggestions appear ‘after Claude responds,’ just that they appear in your prompt input.
The SDK docs now state that bypassPermissions no longer skips everything — cross-session messaging safeguards still apply, and cross-machine peer messages require an isolatePeerMachines approval even for subagents that inherit the mode.
A behavior change buried in a doc tip: since v2.1.223, resuming a session searches beyond the current project directory to find a session ID, where it used to be scoped to the current dir and its git worktrees — SDKs bundling an older CLI still use the narrow lookup.
The flat claim 'Python always persists to disk' was removed; Python callers can now suppress transcript writes by setting CLAUDE_CODE_SKIP_PROMPT_HISTORY in the env option, matching TypeScript's persistSession: false.
Prompt-cache docs quietly walk back the '1-hour TTL is automatic for subscribers' promise: it now only applies within included usage, and drops to 5 minutes on usage credits unless you set ENABLE_PROMPT_CACHING_1H.
The changelog's headline items are mostly plumbing — gateway spend-limit warnings, a workspace-trust prompt for claude agents, and SendMessage being able to start (not just reply to) cross-machine Remote Control conversations.
What the release notes didn’t say
The changelog lists a cross-session-message bug fix but never mentions that bypassPermissions has been narrowed: across the SDK permissions and agent-loop docs, the mode now explicitly still enforces cross-session messaging safeguards, and subagents inheriting it still hit an isolatePeerMachines approval for cross-machine messages. If you’ve been treating bypass mode as a true no-checks path in automation, that assumption is now wrong. Two more silent shifts: session resume changed at v2.1.223 to search across project directories (with a compatibility caveat for SDKs shipping an older CLI), and Python’s long-standing ‘always persists to disk’ behavior is gone — CLAUDE_CODE_SKIP_PROMPT_HISTORY now suppresses transcript writes. Finally, the prompt-cache 1-hour TTL is no longer unconditionally free for subscribers; on usage credits it reverts to a 5-minute TTL unless you opt back in.
The published changelog is otherwise a reliability release. The practitioner-facing additions are cross-machine SendMessage (initiating conversations with your Remote Control sessions on other machines by name) and a new cross-session-messaging doc page the SDK references now point to.
The SDK Bash tool result silently changed both shape and meaning — the old {output, exitCode, killed, shellId} is gone, replaced by {stdout, stderr, interrupted, isImage, backgroundTaskId}, and command stderr now arrives merged into stdout while the stderr field carries only the tool's own notices; none of this appears in the 2.1.224 changelog.
Session resume quietly got smarter: instead of failing on a mismatched cwd, Claude Code now searches every project directory for the session ID and resumes from any working directory (refusing only when two directories both hold a copy) — the old 'most common cause is a mismatched cwd' troubleshooting tip was deleted.
The docs dropped the line saying --cloud and --teleport don't show up in claude --help, and added a whole undocumented-by-changelog section: claude -p "msg" --cloud <session-id> now queues a follow-up into a running cloud session from any logged-in machine.
Several version-gate notes were stripped as the features aged out of newness — TaskOutput deprecated-since-2.1.83, /clear requires-2.1.117, alwaysLoad requires-2.1.121, and a checkpoint snapshot-cleanup caveat all vanished.
Changelog-wise, the practical wins are the removed 200-subagent-per-session cap, new cross-session SendMessage/ListAgents so sessions can message each other across your machines, and an archive plugin source that installs from a zip over HTTPS with optional SHA-256 pinning.
What the release notes didn’t say
The loudest change isn’t in the changelog at all: the SDK’s Bash tool output was restructured. Code reading result.output, result.exitCode, result.killed, or result.shellId will now find those keys missing — the new fields are stdout, stderr, interrupted, isImage, and backgroundTaskId. Worse than a rename, the semantics flipped: a command’s stderr is now interleaved into stdout, and the stderr field holds only notices the tool itself adds (like a working-directory reset). Anyone parsing command stderr separately gets silently wrong results. The is_interrupt hook field was also redefined — it now fires only for aborts, not for interrupt()-cancelled tools, which route their message through the tool result instead.
Session resume changed behavior too: it no longer requires the launch cwd to match, and instead scans all project directories for the session ID (erroring only on ambiguous duplicates). The deleted --help disclaimer for --cloud/--teleport suggests those flags are now surfaced, and a new CLI follow-up path — claude -p "..." --cloud <session-id> — landed in the docs without a changelog line. On the managed-settings side, precedence quietly tightened: a forceLoginOrgUUID or allowedMcpServers value now blocks a parent-supplied one only from the highest-priority admin source, not from any admin source as before v2.1.223.
From the changelog itself, the day-to-day items worth noting: the 200-subagent-per-session spawn cap is gone, sessions can now message each other via cross-session SendMessage (with ListAgents to find them), and plugins can be installed from a pinned zip over HTTPS with no git or npm.
The SDK docs deleted the entire "Long prompt failures on Windows" section, retiring the documented 8191-character command-line limit that used to force concise or filesystem-based subagent prompts.
Subagent permission guidance reversed: the hooks docs now say subagents inherit permission rules from the parent conversation, replacing the old "subagents don't automatically inherit parent agent permissions."
A new, unchangelogged security behavior: the auto-mode classifier now reviews every message one agent sends another — including structured shutdown and plan-approval messages — and silently drops anything it blocks before delivery.
Worktree isolation is now explicitly enforced for spawned subagents too, blocking edits and commands that reach the main checkout, not just the session itself.
Teammate model selection gained detailed allowlist-substitution rules, and the sprawling session-deletion prose was consolidated into a new "What deleting a session removes" reference section.
What the release notes didn’t say
The 2.1.223 changelog is mostly permission-bypass fixes and model-discovery plumbing, but the docs diff carries changes it never mentions. The clearest is a removal: the SDK subagents page deleted its “Long prompt failures on Windows” section wholesale, so the old warning about the 8191-character command-line limit — and the advice to keep prompts short or go filesystem-based — is gone. If you built around that limit, it appears no longer to bite.
A quieter reversal sits in the hooks docs. The guidance on multiplying permission prompts used to state flatly that “subagents don’t automatically inherit parent agent permissions”; it now says permission rules are something subagents inherit from the parent conversation. That’s a behavior flip worth testing against your own hook setups. Alongside it, the agent-view page now states worktree isolation is enforced for a session’s subagents, not just the session.
The teams docs also gained an undocumented security layer: in auto mode the classifier reviews each inter-agent message — plain or structured protocol message like a shutdown request or plan-approval response — before delivery, and a blocked message never reaches the recipient. The changelog’s “restricted subagent model” warning is related but doesn’t cover this. The rest of the agent-view diff is reorganization: session-deletion behavior was pulled into a new “What deleting a session removes” section with no functional change.
The ultraplan feature was removed outright — the changelog lists it in one line with no replacement or migration note.
MCP connection timing was silently reworked: stdio servers (and uncached HTTP/SSE servers) now block the first turn until they connect, bounded by MCP_TIMEOUT at 30 seconds — a reversal of the old 'non-blocking, first turn begins without waiting' default that the changelog never mentions.
The docs deleted the old 5-second startup-blocking narrative and the export MCP_CONNECTION_NONBLOCKING=0 code example, folding that env var into a new per-server-type table.
A behavior change shipped undocumented in the changelog: since v2.1.221 tool search is on by default for Claude 4.5+ models on Google Cloud's Agent Platform, where before it was disabled unless you set ENABLE_TOOL_SEARCH.
A brand-new Agent SDK troubleshooting page appeared (keyed to exact error strings), and the TypeScript SDK now throws on malformed or wildcard skills names before the process starts — neither is in the changelog.
What the release notes didn’t say
The changelog’s one-liner ‘Removed ultraplan feature’ is the only acknowledgement of a removal, but the docs tell a bigger story. The Agent SDK’s MCP connection-timing section was rewritten end to end: the previous model — ‘connection is non-blocking by default; the first turn begins without waiting,’ with a 5-second batch cap — is gone. In its place, stdio servers and cache-less HTTP/SSE servers now delay the first turn until they connect, timing out at MCP_TIMEOUT (30s default), while cached remote servers and in-process SDK servers never block. The MCP_CONNECTION_NONBLOCKING=0 code example was deleted from the ‘Allow MCP tools’ section entirely. None of this behavioral shift is in the changelog. Separately, tool search on Google Cloud’s Agent Platform flipped on by default for Claude 4.5+ models as of v2.1.221 (previously off unless ENABLE_TOOL_SEARCH was set) — again unmentioned. A new SDK troubleshooting page and stricter skills-name validation (the TS SDK now throws on empty, whitespace-padded, or wildcard names) also shipped quietly.
Changelog items worth noting
On the security side, worktree-isolated sessions and their subagents can no longer run destructive git commands against the main checkout, and PreToolUse auto-allow hooks no longer bypass tool restrictions inside background agent tasks. Remote Control auto-start can now only be enabled at user scope — repo-local .claude/settings.json can turn it off but no longer on. Screen-reader mode also stopped re-reading the whole input line on every backspace (requires v2.1.222).
The docs diff looks like a purge, but nearly every deleted line is an internal {/* min-version */} / {/* max-version */} build comment being stripped — no features were removed; those version gates are now old enough that Anthropic treats them as baseline.
A batch of screen-reader behaviors (incremental character echo, word/line deletion announcements, Shift+Tab permission-mode callouts) is documented across v2.1.198–2.1.219 but sits outside this changelog window, so you won't find it in the 2.1.221 notes.
Security fix worth noting: a Bash permission-check bypass where zsh could execute hidden commands inside [[ ]] regex conditionals now prompts for permission instead of running silently.
New mode: "mask" lets sandboxed commands read a sentinel credential file while the sandbox proxy substitutes the real value on egress (Linux/WSL only; macOS falls back to deny).
Background sessions now commit and push to preserve work, follow your CLAUDE.md git instructions, and report where the work landed; /fork now spins up its own worktree instead of sharing the original checkout.
What the release notes didn’t say
At first glance the day’s docs diff reads as a wave of removals across accessibility, advisor, hooks, and checkpointing pages. It isn’t. Almost every deleted line is an internal annotation comment — {/* min-version: 2.1.210 */} and friends — being stripped from the prose while the surrounding text stays intact. That’s documentation hygiene, not deprecation: those version floors are now old enough to be considered baseline, so the caveats retire. Worth flagging precisely because it looks like a story and isn’t. The one genuine removal is small and in the changelog itself: the repeated “Permission mode changed while the auto-mode classifier call was queued” notice is gone from approval prompts. Separately, the version comments being retired point at a run of screen-reader improvements (per-keystroke echo, deletion announcements, permission-mode announcements on Shift+Tab) that shipped between v2.1.198 and v2.1.219 and predate this changelog window.
Among the changelog items that actually change daily practice: the zsh [[ ]] regex permission-bypass fix closes a real hole, mode: "mask" gives sandboxed commands credential access without exposing secrets on Linux/WSL, and background sessions now behave like disciplined collaborators — committing, pushing, honoring CLAUDE.md, and reporting where work lives.
The Agent SDK migration guide walked back a claim: a Note asserting the docs moved to the API Guide was deleted, and the rewritten table now says the Agent SDK docs live in the Claude Code docs after all.
Fullscreen rendering is no longer opt-in — anyone who first launched Claude Code on or after May 6, 2026 now gets it by default, and the old 'default renderer' is renamed 'classic renderer' throughout (switch back with /tui default).
A new DirectoryAdded hook event fires when a directory is added mid-session via /add-dir or the SDK register_repo_root request, with slash_command/register_repo_root matchers — none of it in a changelog.
Desktop side chats are now documented as ephemeral: the app doesn't save them to disk, so you can't reopen one after closing the app.
Skipping the official marketplace auto-install is now permanent — CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL is read once at first interactive launch, and unsetting it later won't re-register the marketplace.
This is a documentation-only day with no changelog, so everything worth knowing is what shipped without an announcement.
What the release notes didn’t say
The biggest silent change is a default flip: fullscreen rendering, previously an opt-in research preview, is now the default for anyone whose first Claude Code launch was on or after May 6, 2026. Existing users keep the classic renderer, but the docs have renamed the old ‘default renderer’ to ‘classic renderer’ across the interactive-mode and keybindings pages — so Ctrl+E show-all and inline reverse-search are now described as classic-only behavior. If fullscreen isn’t wanted, /tui default reverts it.
There’s also a genuine removal in the Agent SDK migration guide: a Note claiming the Agent SDK documentation had moved out of the Claude Code docs and into the API Guide was deleted, and the accompanying table was rewritten to say the docs stay in the Claude Code docs under a dedicated Agent SDK section — a reversal of earlier guidance about where to find things. Elsewhere, a new DirectoryAdded hook event was added (fires on /add-dir or SDK register_repo_root, no decision control, added after sandbox/permission state refreshes), desktop side chats are now explicitly non-persistent, and the marketplace auto-install env var now documents permanent-skip semantics: unsetting it won’t undo an earlier skip.
The Agent SDK quickstart's entire permission-modes table was deleted and replaced with a one-line pointer to the agent-loop page — the docs now have a single canonical table instead of two drifting copies.
The canonical agent-loop table now says bypassPermissions in the TypeScript SDK also requires allowDangerouslySkipPermissions: true in options — a hard opt-in guardrail that wasn't in that table before.
The default mode description was quietly corrected from 'trigger your approval callback' to name the actual canUseTool callback, aligning the prose with the API.
The consolidated table gains a 'Use case' column spelling out when to reach for each mode (interactive apps, prototyping, code review, headless agents, CI/containers).
The quickstart also dropped its note that the bug-fixing example agent runs in acceptEdits mode, folding that guidance into the linked reference.
What the release notes didn’t say
This is a doc-only, changelog-silent change to the Agent SDK permission docs, and the headline is a removal: the quickstart page’s standalone permission-modes table is gone entirely, replaced by a single sentence pointing readers to the table in How the agent loop works. That kills the two-copy drift problem — but if you had the quickstart bookmarked as your permissions reference, that content now lives elsewhere. The substantive change hiding in the reshuffle: the canonical agent-loop table now documents that bypassPermissions in the TypeScript SDK requires allowDangerouslySkipPermissions: true in options, a hard opt-in that previously only appeared in the quickstart copy. Two smaller corrections rode along: default mode’s behavior text now names the real canUseTool callback instead of a vague ‘approval callback,’ and the surviving table picked up a ‘Use case’ column. Nothing was added to the changelog, so all of this shipped quietly.
A whole new Desktop capability shipped doc-only, with no changelog entry: Claude can now list, read, rename, message, and archive your other Code tab sessions in plain language.
Cross-session messaging is fenced by three new safety behaviors — archiving always prompts (even in Auto and Bypass modes), and a session nobody is watching can neither send nor receive messages.
Scheduled desktop tasks quietly gained a limitation: a scheduled run can't send or receive cross-session messages, since no one is watching it.
Bypass permissions picked up a new always-ask exception for 'desktop actions where Claude always asks first, such as archiving a session.'
The Agent SDK todo lifecycle's 'Removed' step was redefined — a todo is now deleted explicitly via status: "deleted" in a TaskUpdate call, rather than auto-removed when a task group finishes.
What the release notes didn’t say
Today’s docs are almost entirely a voice-and-tone rewrite (passive → active) with no changelog behind them, but a genuinely new Desktop feature slipped in under that cover. A new ‘Work across sessions’ section documents Claude listing, reading, renaming, messaging, and archiving your other Code tab sessions from plain-language requests like ‘what did the API session conclude?’ or ‘tell the payments session the schema changed.’ It only sees sessions the desktop app runs itself — local, SSH, and WSL — never cloud, CLI, or VS Code sessions, and skips archived ones and the session you’re asking from. Three safety rails ship with it: archiving always shows an approval card in every permission mode (Bypass permissions now lists this as an explicit exception), and an unwatched session such as a scheduled-task run can neither send nor receive messages (a limitation now spelled out on the scheduled-tasks page too). Separately, the Agent SDK’s todo-tracking doc quietly redefined its ‘Removed’ lifecycle step: a todo is now deleted explicitly with status: "deleted" in a TaskUpdate call, not auto-purged when its group completes.
The advisor's model aliases (opus, sonnet, fable) no longer resolve to the latest version of each family — the docs now say they pin to Claude Code's built-in default, which only advances when you update Claude Code, so a stale install silently pins a stale model.
Admin docs relocated org-shared cloud environments off the claude-code-on-the-web page onto a new cloud-environments page, and split the default-environment picker out to a separate URL (claude.ai/admin-settings/claude-code).
A new DirectoryAdded hook fires when a working directory is added mid-session — handy for installing dependencies when a repo is attached after startup.
Checkpoint rewind now refuses to write or delete through symlinks, hard links, and relocated paths (counted in a new skippedLinks field on RewindFilesResult), and the docs newly spell out that subagent edits aren't tracked at all.
The hooks reference rewrote timeout behavior per-event: a PreToolUse timeout (v2.1.210+) now returns a tool error and continues instead of stalling unattended sessions, and a new CLAUDE_AX_STARTUP_QUIET_MS env var controls an accessibility startup hold.
What the release notes didn’t say
There is no changelog today, so every one of these is a doc-only change that shipped without an announcement. The quietest and most consequential: the advisor page walked back its promise that model aliases resolve to “the latest version of each model.” They now resolve to “Claude Code’s built-in default version for each model family, which advances with new Claude Code releases” — meaning an un-updated Claude Code will keep handing you an older model behind opus/sonnet/fable even after a newer one ships. The admin-setup page also removed the inline org-shared-environments guidance, pointing instead at a new cloud-environments page and moving the default-environment choice to its own admin URL. On the SDK side, the checkpointing docs newly admit two things that were previously unstated: subagent edits are never tracked or restored, and rewind now skips non-regular files rather than clobbering through links — a safety fix (v2.1.216+) surfaced only in prose. The hooks reference gained a DirectoryAdded event and a full rewrite of timeout semantics clarifying that older versions (pre-2.1.208/2.1.210) would stall unattended sessions on a PreToolUse or UserPromptSubmit hook timeout.
No changelog shipped today — every change here landed as documentation-only, so none of it appears in the release notes.
The Cloud gateway now serves Claude Desktop alongside the CLI via a new /user/bootstrap endpoint and a per-policy desktop opt-in block, gated behind gateway server v2.1.203+.
The gateway rewrote its docs to surface min-version fences (auto mode without an env var since v2.1.207, public-endpoint login since v2.1.206) that were live in the binary but only now documented.
The Agent SDK's Python ResultMessage gained a terminal_reason field that distinguishes completed/max_turns from interrupt-driven aborted_streaming/aborted_tools cancellations.
Per-model usage now reports provider (firstParty, bedrock, vertex, foundry, gateway, and more) and canonicalModel, exposing which upstream actually served each request.
What the release notes didn’t say
There is no changelog entry today — everything below is the docs catching up with behavior that already shipped. The headline is that Claude Desktop can now authenticate against the same self-hosted Cloud gateway as the CLI: point Desktop’s bootstrapUrl at <listen.public_url>/user/bootstrap, and the gateway derives its model list, disabled tools, egress allowlist, and OTLP endpoint from the matched policy’s cli block. It is opt-in and fails closed — /user/bootstrap returns 404 unless a policy carries a desktop key, with rejections logged as desktop_bootstrap.denied. A new desktop policy block also gates Desktop-only features (tab visibility, local MCP, auto-updates, a persistent banner) with no CLI equivalent. The scattered min-version fences newly written into the gateway tables (v2.1.203 for Desktop, v2.1.207 for env-free auto mode, v2.1.206 for public-endpoint login) reveal these were binary features documented after the fact.
For SDK users, the Python ResultMessage now surfaces terminal_reason to tell a clean completion from an interrupt, and model_usage is properly typed as ModelUsage with two new keys — provider and canonicalModel — that let you see which upstream and pricing identity served each model. No pages, flags, or settings were removed.
The usage-policy refusal string Claude Code is unable to respond to this request, which appears to violate our Usage Policy is now capped at v2.1.218 and replaced by a terser <model> can't help with this. Start a new session to continue.
The cybersecurity-flag message <model> has safety measures that flagged this message for a cybersecurity topic is likewise retired at v2.1.218 in favor of <model>'s safeguards flagged this message.
Subagent nesting is on by default again: v2.1.219 raised the default spawn depth back to 3 after v2.1.217–218 had defaulted it to 1 (nesting off).
The CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH semantics inverted — you now set 1 to turn nesting off, whereas two versions ago you set 2 or higher to turn it on.
None of this appears in a changelog entry today; it all landed as quiet documentation edits.
What the release notes didn’t say
Today is a doc-only day with no changelog delta, but the error and env-var pages moved. Two refusal messages were retired: the wordy usage-policy refusal and the cybersecurity-topic warning are both now version-capped at v2.1.218, replaced by shorter strings (<model> can't help with this. Start a new session to continue and <model>'s safeguards flagged this message). If you match on refusal text in scripts or wrappers, update your patterns. Separately, the subagent nesting default finished a round trip: 5 layers (v2.1.172–216, unchangeable) → 1 (v2.1.217–218, off by default) → 3 (v2.1.219). The CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH knob flipped meaning with it — 1 now disables nesting rather than being the locked-off default, so anyone who set the flag during the brief opt-in window should recheck it.
The agent-view docs walked back an over-broad claim: only --settings and --plugin-dir are applied to agent view itself, not "each" configuration flag as previously stated.
Fullscreen rendering gained an undocumented Ctrl+L behavior — press once to redraw plus a hint, press twice within two seconds to run /clear and start a new conversation.
Plugin manifests silently gained an optional url field for owner/author blocks (website, GitHub, or org URL).
CLAUDE_CODE_GIT_BASH_PATH now fails soft as of v2.1.219: a bad or wrongly-named path is ignored with a warning and auto-detection kicks in, instead of the old hard startup exit.
The path is now validated by name — only bash.exe, sh.exe, bash, or sh are accepted; Git for Windows' git-bash.exe launcher is rejected.
What the release notes didn’t say
With no changelog today, every change here shipped silently in the docs. The headline is a quiet correction: agent view previously claimed to apply “each” configuration flag to itself, but the docs now scope that to just --settings and --plugin-dir — everything else is only passed through to dispatched sessions. The v2.1.200 history entry got the same treatment, narrowing “configuration flags placed after agents, such as --plugin-dir” down to a single --plugin-dir flag. If you relied on other flags self-applying to agent view, that was never really the behavior.
Two other undocumented additions: fullscreen rendering now maps a double-press of Ctrl+L (within two seconds) to /clear, with a hint on the first press — worth knowing before you accidentally wipe a conversation. And plugin marketplace manifests gained an optional url field on owner and author objects.
Finally, CLAUDE_CODE_GIT_BASH_PATH behavior changed in v2.1.219: a nonexistent or wrongly-named path (anything but bash.exe/sh.exe/bash/sh) is now ignored with a --debug warning and normal auto-detection, rather than the previous hard exit at startup. This closes a Windows footgun where Git for Windows’ git-bash.exe launcher was accepted uncritically as the shell.
Docs quietly scrubbed the self-hosted runners program: the Cloud environments page dropped its line about managing runner pools, and a historical changelog entry (v2.1.169) had its post-session runner-hook bullet deleted outright.
Undocumented walk-back: auto mode's denial reason is now the fixed string Blocked by classifier in most sessions (v2.1.208+) — the classifier scores on an internal severity scale instead of writing the per-denial explanations shipped in v2.1.193.
Not in the changelog: the Agent SDK budget cap now counts subagent spend, and once the cap is hit, spawning a subagent fails with Budget limit reached while running background subagents are stopped (v2.1.217+).
New agent-view guidance that never hit the changelog: keep --add-dir and --mcp-config after agents or claude agents --json fails with an unknown option error.
The changelog headline: Opus 5 (claude-opus-5) becomes the default Opus model with 1M context and $10/$50 fast mode, while Opus 4.7 was removed from fast mode and subagents can now nest to depth 3.
What the release notes didn’t say
The day’s most interesting moves aren’t in the changelog. The self-hosted runners program is being quietly walked back in the docs: the Cloud-on-the-web page removed the sentence pointing orgs to manage runner pools from the Cloud environments page, and — more tellingly — a bullet about the runner post-session lifecycle hook was deleted from the already-published v2.1.169 changelog entry, not just from current docs. Editing history is a stronger deprecation signal than any release note.
Auto mode’s denial UX also quietly regressed. The v2.1.193 feature that showed the classifier’s written reason for each denial is now, in v2.1.208+, usually just the fixed text Blocked by classifier — the classifier scores severity internally rather than explaining itself, and you can’t configure which behavior you get. Separately, the Agent SDK docs gained an unannounced budget-cap change (subagent spend now counts toward the cap; hitting it kills background subagents and fails new spawns with Budget limit reached, v2.1.217+), and agent view gained a flag-ordering gotcha where --add-dir/--mcp-config before agents breaks claude agents --json.
The changelog itself
Opus 5 arrives as the default Opus model everywhere — direct API, Bedrock, and AWS aliases all now resolve opus to claude-opus-5 — with 1M context and $10/$50 fast mode. Opus 4.7 lost fast-mode support, subagents nest to depth 3 by default, and dynamic workflows now default to a medium size guideline (aim for <15 agents).
No changelog shipped today, so everything below arrived silently in the docs: the biggest change is that /code-review now runs as a background subagent by default (v2.1.218), where it previously ran inside your conversation.
Forked skills also flipped to running in the background by default (v2.1.218); to get the old behavior you now set background: false in the skill's frontmatter.
A new gotcha: edits from background subagents — including a /code-review --fix run — land outside your session's checkpoints, so /rewind won't undo them and you have to revert with git.
--max-budget-usd now counts subagent spend toward the cap, and from v2.1.217 hitting the cap fails new subagents with Budget limit reached and kills background subagents still running.
The Claude Security docs quietly confirm that Fable 5's cybersecurity classifiers will block certain activities and auto-downgrade to Opus mid-scan — expected behavior, per the new note.
What the release notes didn’t say
There was no changelog today, which makes the doc edits the whole story. The headline is a pair of default flips buried in checkpointing.md and code-review.md: as of v2.1.218, /code-review runs as a background subagent with its own context window instead of filling your conversation, and forked skills now run in the background by default rather than always in the foreground. Both change day-to-day behavior without a corresponding changelog line. The consequence worth internalizing is the new Subagent edits not restored section — background subagent edits, including /code-review --fix, sit outside your checkpoints, so /rewind silently leaves them in place and you must revert with git. Only a foreground context: fork skill edits your tree during your own turn and stays rewindable. Two quieter items round it out: the /code-review /fix-issue 123 parsing changed so a stacked command is now read as target text rather than expanding as its own skill, and the Claude Security page added a note that Fable 5’s classifiers will block certain activities and auto-downgrade to Opus.
Among the version-tagged catch-ups, the practical one is --max-budget-usd: subagent spend now counts toward the cap, and from v2.1.217 the cap actually enforces — new subagents fail with Budget limit reached and running background subagents get stopped. You can also now kick off a cloud ultrareview from CI with claude -p '/code-review ultra'.
The by-default nesting of subagents is walked back: from v2.1.217, subagents can no longer spawn their own subagents unless you set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH to 2 or higher — the docs now admit that v2.1.172 through v2.1.216 nested up to five layers by default.
A whole new page, claude-security.md, documents a multi-agent vulnerability-scanning plugin (/claude-security) that never appears in the changelog — it maps your architecture, hunts bugs, and turns findings into git-apply patches you review yourself.
The login-expiry warning quietly shrank from five days out to three, and the sub-agents anchor was renamed from #spawn-nested-subagents to #let-subagents-spawn-their-own-subagents — both undocumented in the changelog.
costs.md gains a new 'Why usage climbs in a long session' section and /usage now flags long context or cache misses when either tops 10% of recent usage, neither called out in release notes.
From the changelog proper: /code-review runs as a background subagent, and skills with context: fork now run in the background by default (opt out with background: false).
What the release notes didn’t say
The headline reversal isn’t in the 2.1.218 changelog at all — it’s a doc rewrite covering a v2.1.217 default flip. Subagents used to spawn their own subagents by default (up to five layers, v2.1.172–2.1.216); now that’s off unless you opt in via CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH. If your workflows relied on deep agent trees, they silently stopped nesting. A brand-new page, claude-security.md, ships an entire vulnerability-scanning plugin with no changelog mention — worth knowing it counts against plan usage and runs best in auto mode. Smaller silent changes: the login renewal warning now fires at three days instead of five; costs.md adds a ‘Why usage climbs’ explainer plus /usage behavior flags (long context, cache misses at ≥10%); teleported cloud sessions now get their own local copy that no longer syncs back to claude.ai; and the desktop ‘Remote’ session type was renamed ‘Cloud’. Subagent tool inheritance wording also tightened — ‘all tools’ became ‘every tool available to subagents,’ filtered for background runs.
Among the changelog items that actually change daily practice: /code-review now runs as a background subagent so it stops flooding your conversation, context: fork skills default to background execution, and agent names may no longer contain : (reserved for plugin namespacing).
Undocumented in the changelog: as of v2.1.215, /verify and /code-review run only when you invoke them — Claude can no longer trigger them on its own.
Checkpointing now refuses to rewind symlinked or hard-linked files and warns you; before v2.1.216 /rewind silently wrote and deleted through those links.
Chrome integration is now gated on /login — API-key and long-lived-token sessions keep it off, walking back a state that previously enabled it only to fail with a 403.
The --channels flag quietly broadened from Claude.ai-only auth to also accept a Console API key, and neither channels flag appears in claude --help during the preview.
The changelog's own headline items: a cap of 20 concurrent subagents (CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS) and subagents no longer spawning nested subagents by default.
What the release notes didn’t say
The changelog for v2.1.217 is a long list of fixes, but the most consequential behavior changes landed silently in the docs a version or two earlier. The commands page now notes that, since v2.1.215, /verify and /code-review run only when you invoke them — Claude used to be able to fire them autonomously. That’s a real narrowing of agent initiative and it appears nowhere in a changelog entry. Separately, checkpointing gained a new failure mode disclosure: /rewind now skips symlinked and hard-linked paths with a Restored the code, but skipped N files warning, and the docs admit that before v2.1.216 it wrote and deleted through those links without any warning — a quiet fix for silent data loss. Chrome integration was also walked back: API-key and long-lived-token sessions can no longer enable it (they previously could, only to 403 on every connection). Smaller undocumented shifts: --channels now accepts a Console API key rather than Claude.ai auth alone, both channels flags are hidden from --help, --settings files are capped at 2 MiB, and CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH (v2.1.214) makes OTEL body truncation configurable.
Of the changelog items proper, the two worth practitioners’ attention are structural guardrails on fan-out: subagents are now capped at 20 concurrent (override via CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS) and no longer spawn their own nested subagents unless you raise CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH.
Undocumented and not in the changelog: the entire docs site relocated its URLs from /en/... to /docs/en/..., so every old bookmark, deep link, and copied reference now points at the pre-migration path.
Undocumented content change in admin-setup: the forceLoginOrgUUID organization-restriction now explicitly excludes Claude apps gateway sign-in, which doesn't authenticate against an Anthropic org — a real enforcement gap that only appears in the docs, not the release notes.
New sandbox.filesystem.disabled setting lets you skip filesystem isolation while keeping network egress control, a middle ground the sandbox previously didn't offer.
A long-standing performance bug is fixed: message normalization grew quadratically with turn count, which was the cause of multi-second stalls and slow resumes in long sessions.
Several path-safety fixes landed — .claude workflow/scheduled-task writes and /rewind no longer follow symlinks or hard links that could redirect writes outside the project, and worktree subagents can no longer redirect git into the shared checkout.
What the release notes didn’t say
The day’s docs diff is dominated by a change the changelog never mentions: a site-wide URL migration moving every page from /en/... to /docs/en/.... Hundreds of cross-links were rewritten in bulk (accessibility, admin-setup, and beyond), so any external link or bookmark to the old /en/ paths is now stale. Buried inside that mechanical churn is one genuine content edit worth catching: the admin login-enforcement table now states that forceLoginOrgUUID’s organization restriction covers the terminal, VS Code extension, and Agent SDK except Claude apps gateway sign-in, which doesn’t authenticate against an Anthropic organization. That’s a documented enforcement gap admins should know about, and it shipped without a changelog line.
Among the public 2.1.216 items, the ones that actually change day-to-day work are the quadratic message-normalization fix (the real culprit behind multi-second stalls in long sessions), the new sandbox.filesystem.disabled setting, and a cluster of symlink/hard-link path-safety fixes across .claude writes, /rewind, and worktree-isolated subagents.
Claude no longer runs the /verify and /code-review skills on its own — you now invoke them explicitly, so any workflow that relied on automatic review passes needs an added step.
Undocumented in the changelog: the VS Code extension's minimum version was quietly lowered from 1.98.0 to 1.94.0, widening compatibility for teams stuck on older editors.
New silent guidance warns that claude mcp add saves configs without validating credentials, so a bad token only surfaces as a failed server under /mcp later.
Install troubleshooting gained explicit handling for 403 (proxy/region block) and 5xx (transient) results — previously all failures were lumped as generic network blocks.
The gateway-deploy and heapdump docs added redaction warnings, flagging that audit streams, developer identities, and diagnostics files leak sensitive data if posted to public issues.
The one changelog item that matters day to day (2.1.215) is a behavior removal: Claude will no longer trigger /verify or /code-review autonomously. If you were leaning on those skills firing automatically, they now require an explicit call.
What the release notes didn’t say
The more interesting changes shipped silently in the docs. The VS Code extension’s minimum supported version was rolled back from 1.98.0 to 1.94.0 across three spots (requirements, install troubleshooting, Spark icon) — a compatibility loosening with no changelog mention. New MCP guidance now warns that claude mcp add never validates credentials, so placeholder or wrong tokens are accepted at add-time and only show as failed when you later run /mcp. Install troubleshooting picked up specific 403 (proxy/network filter or unsupported region) and 5xx (transient) diagnoses instead of the old catch-all “network is blocking.” Security-conscious edits also landed: the Cloud gateway deploy guide now tells you to redact audit streams and developer identities before filing public issues, and the heapdump docs clarify that the -diagnostics.json file is the safe one to attach. Finally, /desktop handoff is now documented as macOS and x64-Windows only.
Nine new TypeScript SDK hook events appear in the docs with no changelog mention: StopFailure, PostCompact, PermissionDenied, TaskCreated, Elicitation, ElicitationResult, InstructionsLoaded, CwdChanged, and FileChanged.
The hook timeout default of 60 seconds is gone — omitting it now applies per-event defaults instead: 10 minutes for most events, 30 seconds for UserPromptSubmit, 10 seconds for MessageDisplay.
UserPromptExpansion quietly gained scope — it now also fires when an MCP prompt expands, but explicitly does not fire when Claude invokes a skill itself.
Login enforcement (forceLoginMethod/forceLoginOrgUUID) now reaches the VS Code extension, Agent SDK, setup-token, and install-github-app; before v2.1.212 only terminal logins enforced either key.
A long-lived token from claude setup-token no longer loads claude.ai MCP connectors — that token can only make model requests.
What the release notes didn’t say
The SDK hooks reference grew by nine events that the changelog never mentions — StopFailure, PostCompact, PermissionDenied, TaskCreated, Elicitation, ElicitationResult, InstructionsLoaded, CwdChanged, and FileChanged — all TypeScript-only. If you build with hooks, several of these are genuinely new surface area (watch a file, react to compaction completing, catch classifier denials, audit which CLAUDE.md files load).
The quieter behavior change matters more: the hook timeout default of 60 seconds was removed. Omitting timeout now yields per-event defaults — 10 minutes for most events, 30s for UserPromptSubmit, 10s for MessageDisplay. Any hook that leaned on a 60-second cap now runs under a much longer leash. Two new events (StopFailure, FileChanged) also use a stricter matcher grammar: only | separates alternatives, and FileChanged’s matcher doubles as the literal watch list of filenames.
Separately, forceLoginMethod/forceLoginOrgUUID enforcement expanded beyond the terminal to the VS Code extension, Agent SDK, setup-token, and install-github-app as of v2.1.212, and claude setup-token tokens no longer pull in claude.ai MCP connectors.
Fable 5 is no longer offered as an advisor model: the /advisor picker now dims it as Fable 5 (temporarily unavailable) and Claude Code rejects both /advisor fable and --advisor fable, with a remote rollout gating its return — none of which appears in the changelog.
The --advisor launch flag is now documented as hidden from claude --help, and enabling the advisor prints a new Advisor Tool (experimental) is on and may use more tokens notice after startup.
A new managed control, processWrapper (the 'corporate launcher'), lets orgs prefix the background-agent supervisor and its workers instead of disabling agent view outright — shipped silently to the docs.
The Agent SDK gained undocumented 'Hosting' and 'Session storage' guidance, including a session_store/sessionStore adapter for resuming sessions across stateless or serverless hosts.
In the changelog proper: /fork now spins up a real background session (the old in-session subagent becomes /subtask), and plan mode no longer auto-runs file-modifying Bash like touch/rm without a permission prompt.
What the release notes didn’t say
The headline change is a removal the changelog is silent on: Fable 5 has been walked back as an advisor model. Where the docs previously told you the version needed to use Fable 5 as the advisor, they now state Claude Code simply doesn’t offer it — the picker shows it as a dimmed Fable 5 (temporarily unavailable) row, and --advisor fable is rejected outright. A Fable 5 main model still works but runs without an advisor, and a remotely configured rollout decides when the option comes back. Two smaller advisor details also surfaced only in the docs: the --advisor flag is now hidden from claude --help, and turning the advisor on prints an experimental-token-usage notice. Separately, the admin docs added a processWrapper ‘corporate launcher’ control for wrapping background-agent processes, and the Agent SDK picked up new Hosting and Session-storage pages (with a session_store adapter for serverless resume) — neither mentioned in the changelog.
Among the published changes, two matter day to day: /fork now copies your conversation into its own background session while the former in-session subagent becomes /subtask, and a plan-mode bug that let file-modifying Bash commands run without a permission prompt was fixed. New session caps also landed — 200 WebSearch calls and 200 subagent spawns per session — and the Task tool’s mode parameter is now deprecated and ignored.
None of the day's most consequential doc edits appear in the public changelog — they shipped silently in the docs.
Cost tracking now warns that the SDK usage field excludes subagent tokens entirely, so any agent that spawns subagents undercounts unless you read modelUsage/model_usage instead.
New managed-settings lockdowns landed undocumented in the changelog: forceLoginMethod/forceLoginOrgUUID block API-key and token-based sessions at startup, and pluginSuggestionMarketplaces allowlists which marketplaces can suggest plugins.
Organization-set ask controls on claude.ai connector tools now force a prompt across every permission mode — even bypassPermissions and dontAsk deny them regardless of your allow rules.
The SDK docs newly spell out the 25,000-token MCP output cap (overridable via MAX_MCP_OUTPUT_TOKENS) and scoped Read/Edit path rules with //path absolute anchoring.
What the release notes didn’t say
The changelog (2.1.211) is full of fixes but omits the day’s substantive doc changes. Cost tracking gained a table making explicit that the SDK usage field counts only the top-level loop and silently drops subagent tokens — a real accounting trap for anyone building supervisor/subagent workflows, where only total_cost_usd and modelUsage include the whole tree. Admin lockdown grew two undocumented capabilities: login enforcement (forceLoginMethod, forceLoginOrgUUID), which blocks ANTHROPIC_API_KEY/ANTHROPIC_AUTH_TOKEN/apiKeyHelper sessions at startup while leaving cloud-provider sessions alone, and pluginSuggestionMarketplaces for allowlisting plugin suggestions. A new cross-cutting rule threads through every SDK permissions page: connector tools an org sets to ask now fall through to your callback in all modes and are hard-denied in dontAsk — allow rules no longer override org policy. Also newly documented: the 25k-token MCP output limit that spills to a file, and scoped Read/Edit path rules where //path means an absolute filesystem path and a single leading slash anchors at the rule’s source. Separately, the advisor page quietly added “Claude Platform on AWS” to the list of surfaces where the advisor tool isn’t available. No pages or flags were removed today.
The agent-view docs stripped 'merge or push before deleting' down to just 'commit' — because deletion now refuses to remove a worktree that holds unpushed commits, keeping both the worktree and its session instead of silently destroying work.
A new TypeScript-only hook, UserPromptExpansion, appears in the hooks table with no matching changelog line: it fires when a user-typed command expands into a prompt, letting you block direct invocation or inject context when a skill is typed.
Background sessions now quietly refuse /install-github-app and the /mcp settings list (including auth actions) whether attached or replying from the peek panel — a limitation that shipped in the docs, not the release notes.
Typing /model in an attached agent-view session now saves it as your default for new sessions; the old behavior required pressing 's' in the picker for a session-only switch, which is now the explicit opt-out.
The SDK gains SDKThinkingTokensMessage for live thinking-token progress, and setMaxThinkingTokens(null) now resets thinking to the session default rather than forcing a value.
What the release notes didn’t say
The headline change is a removal you won’t find called out: across agent-view.md, the long-standing ‘merge or push changes before deleting’ warning has been pared back to ‘commit’ everywhere. That’s not a copy edit — it reflects a behavior walk-back. Deleting a session (via Ctrl+X twice, claude rm, or the shell) now refuses to remove a worktree with commits that aren’t pushed anywhere, keeping the session row alongside it and naming the kept path and reason. The destructive-by-default delete that could vaporize unpushed commits is gone. Several other changes rode in under doc version stamps (v2.1.153–208) with no entry in the 2.1.210 changelog: the UserPromptExpansion hook, background sessions refusing /install-github-app and the /mcp settings list, /model <name> now persisting as the new-session default, screen-reader mode inheriting through CLAUDE_AX_SCREEN_READER on relaunch, and admin-managed organization-shared cloud environments for Claude Code on the web.
Of the changelog items proper, the ones that touch daily practice are the fix for isolation: 'worktree' subagents being able to mutate the main checkout, the new startup warning steering Write/Glob/NotebookEdit permission rules toward Edit/Read, and hook-timeout handling that no longer misreports as a user rejection and stalls unattended sessions.
The Agent SDK's AgentInput type dropped the resume and max_turns fields and made subagent_type optional — a breaking surface change with no changelog line.
The AgentOutputsub_agent_entered status for interactive subagents was deleted and replaced by remote_launched, which points at a remote cloud session via sessionUrl and taskId.
The advisor tool's docs removed its v2.1.98 or later version gate and the plan-availability annotation, quietly loosening how the experimental feature is described.
Screen reader mode made the changelog, but a full accessibility page shipped alongside it documenting magnifier support (CLAUDE_CODE_ACCESSIBILITY), prefersReducedMotion, daltonized themes, and OSC 133 turn markers the notes never mentioned.
Undocumented behavior change: an MCP server that returns an OAuth challenge with no stored token now continues the run without that server's tools and reports needs-auth, instead of the SDK simply not handling the flow.
What the release notes didn’t say
The changelog is dominated by screen reader mode and a long list of fixes, but the sharper changes are in the Agent SDK type surface. The AgentInput schema lost two fields outright — resume?: string and max_turns?: number — and subagent_type went from required to optional; mode also gained an auto value. On the output side, the sub_agent_entered result variant (interactive subagents) was removed entirely and replaced by remote_launched, reframing that code path around tasks dispatched to remote cloud sessions. None of this appears in the changelog, so SDK consumers reading only the release notes won’t know their resume/max_turns calls or sub_agent_entered handling just fell off the documented API. The advisor page separately deleted its v2.1.98 or later requirement and the plan-availability annotation, softening the feature’s gating in the docs.
Several behavior changes also shipped silently: MCP servers that hit an OAuth challenge now degrade to needs-auth and run without their tools; agent-team mailboxes are now validated JSON files that drop malformed entries instead of looping errors; SDK subagents with SendMessage now start with a roster of named peers; and the terminal_reason enum grew a batch of new values (api_error, budget_exhausted, malformed_tool_use_exhausted, and more). A new accessibility page and an admin-setup section on WSL Desktop sessions (wslInheritsWindowsSettings, CrowdStrike Falcon guidance) round out the undocumented surface.
The troubleshooting page dropped its Linux download link entirely — Linux users are now steered to apt install instructions instead of a one-click download that macOS and Windows still get.
The 'install from a downloaded file' path on Linux was rewritten: instead of grabbing a .deb from claude.com/download, you now curl directly from the downloads.claude.ai package pool via a repository-index lookup.
The Agent SDK's MCP page added a pointer to MCP output limits — the persist-to-disk fallback when results exceed MAX_MCP_OUTPUT_TOKENS, plus a new per-tool anthropic/maxResultSizeChars annotation — none of which rode a changelog entry.
New Linux error-handling guidance explains the 'Remote file name has no length' failure and ties it to a blocked downloads.claude.ai or an unsupported architecture (only amd64/arm64 are published).
setup.md and troubleshoot-install.md repointed their Linux links from the generic claude.com/download to the dedicated /en/desktop-linux guide.
What the release notes didn’t say
There was no changelog today, so every one of these shipped silently. The quiet removal is on Linux: the troubleshooting page no longer offers Linux users a download link at all — where macOS and Windows keep their one-click installers, Linux now gets ‘install with apt’ instead. In parallel, the desktop-linux page walked back its simple ‘download the .deb from claude.com/download’ instruction and replaced it with a package-pool curl that scrapes the apt repository index for the newest build. The practical read: Anthropic wants Linux desktop installs to go through apt so they stay updated, and is deliberately de-emphasizing the standalone-file path. Separately, the Agent SDK’s MCP page gained a cross-reference to MCP output limits — MAX_MCP_OUTPUT_TOKENS, a persist-to-disk fallback for oversized tool results, and a new anthropic/maxResultSizeChars per-tool annotation — surfacing behavior that practitioners hitting large MCP responses will want to know about but that never appeared in a changelog.
The phrase 'research preview' was deleted from every Auto mode description — glossary, desktop, and how-it-works docs — signaling a silent graduation to GA that the changelog never states.
A new undocumented SDK option, SystemPromptFile (--system-prompt-file), lets you load large system prompts from disk to dodge OS argv length limits (~128KB Linux, ~32KB Windows).
The docs now clarify that a built-in set of read-only shell commands like ls and cat runs without any permission prompt, restrictable only via sandbox denyRead rules.
A shell-injection fix landed: plugin hooks/monitors now reject ${user_config.*} in shell-form commands, and project-level .claude/settings.json no longer supplies plugin option values.
Bedrock, Vertex, and Claude Platform on AWS all now default the opus alias to Opus 4.8, moving teams up from 4.6/4.7 unless pinned.
What the release notes didn’t say
The loudest change is one the changelog only half-tells. The 2.1.207 notes say Auto mode no longer needs the CLAUDE_CODE_ENABLE_AUTO_MODE opt-in on cloud providers — but the docs go further, stripping ‘research preview’ from Auto mode’s description in the glossary, the desktop page, and how-claude-code-works. Read together, Auto mode has effectively graduated on the Anthropic API too, and nothing in the changelog says so. Two other silent additions matter for practitioners: the SDK gained a SystemPromptFile type mapping to a new --system-prompt-file CLI flag (for prompts too large to survive argv length limits), and the permissions docs now admit that read-only shell commands such as ls and cat run with no prompt at all — you restrict them with sandbox denyRead rules. The ‘Manual’ permission-mode wording was also quietly softened from ‘asks before each action’ to ‘asks before file edits and most shell commands.’
Among shipped-and-documented items, the security-relevant ones lead: a plugin shell-injection fix rejecting ${user_config.*} in shell-form commands, a fix for non-interactive runs being silently recorded as having consented to remote managed settings, and Opus 4.8 becoming the default across Bedrock, Vertex, and Claude Platform on AWS.
Plan mode's allowedPrompts is now deprecated and ignored — the field that requested prompt-based Bash permissions to implement a plan does nothing, though it's still accepted so old callers validate.
/doctor no longer summarizes the claude daemon status check; that line was deleted from the docs with no changelog mention.
Agent view dropped the done/total parallel-work counter (e.g. 2/5) from row summaries, which now show the session's own one-line report instead of a raw tool invocation.
The SDK's interrupt() now returns an interrupt receipt (SDKControlInterruptResponse) listing which queued messages survive, gated behind a new capabilities feature-detection array — neither appears in the changelog.
Auto mode's repo-visibility classifier was quietly narrowed: it reads your messages and the commands Claude runs but not their output, so a bare gh repo view result no longer counts as evidence a repo is public.
What the release notes didn’t say
The published changelog for 2.1.205–2.1.206 covers /cd suggestions, a CLAUDE.md-trimming /doctor check, and a pile of fixes — but the more interesting movement is in the docs it didn’t touch. Three things were removed or walked back: plan mode’s allowedPrompts field is now marked deprecated, no longer used (Claude Code still accepts it only so existing transcripts validate); /doctor’s summary of the daemon-status check was deleted outright; and agent view lost the done/total parallel-work count from its row summaries. Separately, the SDK grew an entire interrupt-receipt protocol — interrupt() can now resolve with an SDKControlInterruptResponse.still_queued list, feature-detected via a new open-ended capabilities array on SDKSystemMessage — plus name/body fields on peer message origins, none of which surface in the changelog. Two silent behavior changes are worth noting for anyone relying on them: an invalid --json-schema now fails the run at startup instead of degrading to unstructured text, and auto mode’s visibility classifier was narrowed to read commands but not their output, so evidence a repo is public must now come from your own words, not a gh repo view result.
The empty agent-view onboarding hint with example prompts is gone, replaced by section headers with a description under each; the separate hint shown below a lone session row was removed too.
None of it is in the 2.1.205 changelog, but the docs quietly detail a v2.1.203 fix where a gateway's ANTHROPIC_BASE_URL is now forwarded to background workers — previously it was dropped while the paired API key was kept, so every request 401'd against the default endpoint.
The dispatching shell's PATH now reaches each background worker, fixing tools that went missing (most often on Windows) because sessions kept the supervisor's original launch-shell PATH.
Pressing ← to background a session now waits for running subagents instead of silently restarting them from the beginning after ten seconds, and edits to the effortLevel setting now reach already-backgrounded sessions live.
The TypeScript SDK gained two undocumented-in-changelog message types — SDKBackgroundTasksChangedMessage and SDKConversationResetMessage — plus an "ultracode" value for effortLevel accepted only by applyFlagSettings().
What the release notes didn’t say
The 2.1.205 changelog is all agent-view polish, but the docs diff exposes a much larger, mostly undocumented v2.1.203 overhaul of how background sessions source their environment. The headline reversal: a gateway ANTHROPIC_BASE_URL exported in your dispatching shell now reaches the session’s worker (along with ANTHROPIC_CUSTOM_HEADERS and the credential exported beside it) when the supervisor shares that gateway environment. Before this, the base URL was dropped while the API key was kept — so the gateway’s key was sent to Anthropic’s default endpoint and every request failed with a 401. The dispatching shell’s PATH is now forwarded the same way. On the removal side, agent view’s empty-state onboarding hint (the one with example prompts) was deleted in favor of plain section headers, and the hint that appeared below a solitary session row is gone as well. The ←-to-background flow also stopped silently restarting in-flight subagents, and effortLevel set in settings.json now follows a session across backgrounding and restarts instead of being frozen at dispatch.
Among the actually-listed 2.1.205 items, two matter for practitioners: auto mode now blocks tampering with session transcript files, and background-task notifications explicitly state that no human input occurred — closing a hole where a fabricated in-transcript approval could be acted on. /doctor is now a full setup checkup with /checkup as its alias.
The "(TypeScript only)" qualifier on the auto permission mode was stripped from four SDK doc pages and "auto" was added to Python's PermissionMode literal — the Python SDK gained model-classified tool approval with no changelog mention.
The custom-tools docs reversed a long-standing claim: an uncaught handler exception no longer stops the agent loop or fails the query() call — the in-process MCP server now catches it, so isError: true only controls the message Claude reads, not whether work continues.
A newly documented Python-only gotcha: the Python SDK silently drops audio blocks and binary (blob) resources from tool results and logs a warning, while TypeScript saves audio to disk and keeps binaries.
Hooks docs added scoped naming for plugin-bundled MCP servers (mcp__plugin_<plugin>_<server>__<tool>), warning that matchers written against the bare server key never fire for these tools.
The public changelog's headline for practitioners is a fleet of background-agent fixes in 2.1.203 — stale PATH/ANTHROPIC_BASE_URL leaks, worktree isolation bugs, and daemon token recovery — plus a login-expiry warning and an always-visible manual-mode ⏸ badge.
What the release notes didn’t say
The changelog is almost entirely background-agent and TUI fixes, but the docs tell a different story. The biggest quiet change: auto permission mode is no longer TypeScript-only. The “(TypeScript only)” tag was removed from the agent-loop, permissions, quickstart, and Python reference pages simultaneously, and "auto" was appended to Python’s PermissionMode literal — meaning the Python SDK now supports model-classified tool approval with zero changelog acknowledgement. Second, the custom-tools error-handling docs were rewritten to contradict their prior guidance: an uncaught exception used to “stop the agent loop” and fail the whole query; now the SDK’s in-process MCP server catches it, converts it to an error result, and the loop continues — so returning isError: true is now about composing a better message, not keeping the query alive. The same page newly admits a Python/TypeScript asymmetry: the Python SDK drops audio and binary-resource blocks from tool results and only logs a warning. None of these appear in the changelog.
Also landing silently: scoped hook-matcher naming for plugin-bundled MCP servers (mcp__plugin_<plugin>_<server>__<tool>), and expanded PermissionRequest subagent fields (agent_id/agent_type) in Python. Of the actual changelog items, the ones worth acting on are the 2.1.203 background-agent fixes — sessions were leaking a stale PATH and dropping shell-exported ANTHROPIC_BASE_URL (sending keys to the wrong endpoint with a 401), and worktree-isolated subagents were running commands in the parent checkout.
Remote Control from mobile/web now works properly: interactive commands no longer fail with "Unknown command," uncaptioned images and files are no longer silently dropped, and the permission mode shown is correct.
Resuming a session by name or opening the resume picker is fast again in repos with many git worktrees, instead of taking minutes and burning memory.
/review <pr> is back to a quick single-pass review; use /code-review <level> <pr#> when you actually want the slower multi-agent pass.
Re-invoking an already-loaded skill no longer appends a duplicate copy of its instructions to context, so repeated skill use stops quietly bloating your context window.
A new "Dynamic workflow size" setting in /config lets you steer how many agents Claude spins up for dynamic workflows (small/medium/large), as an advisory guideline rather than a hard cap.
Most of this release is friction removal for people already living in Claude Code day to day. The Remote Control path finally behaves the way you’d expect from a phone or browser, and session resume stops punishing anyone with a worktree-heavy repo. The /review split is worth internalizing: the plain command is fast again, and the heavyweight multi-agent review now lives behind /code-review with an explicit effort level.