anthropics/claude-code v2.1.268
anthropics/claude-code
Captured source
source ↗published Sep 10, 2026seen 1hcaptured 1hhttp 200method plain
v2.1.268
Repository: anthropics/claude-code
Tag: v2.1.268
Published: 2026-09-10T20:30:54Z
Prerelease: no
Release notes:
What's changed
- Added to the Claude apps gateway: with
pricing:set ingateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so/costand telemetry match the spend meter - Added a startup warning for gateways when
access_control.allow_cidrsis empty, and a one-time warning the first time a request arrives from a public address - Added the
gatewayInternalNetworksmanaged setting, letting administrators allow/loginto a Claude apps gateway on their organization's own public IPv4 block - Added
claude self-hosted-runner --remove-session-state(default off): delete each session's per-session directories under/_sessions/when the session ends - Added
configDirectoryto the output ofclaude auth status --json - Added
--jsontoclaude plugin install,uninstall,update,enableanddisable, anderrorDetails/noteDetailsto each row ofclaude plugin list --json - Added browser-tab icons for published artifacts, chosen by Claude to match each page
- Fixed every turn failing with HTTP 400 on third-party Anthropic-compatible endpoints (
ANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints reject - Fixed WebFetch hanging indefinitely on a server that keeps the response open without finishing; a fetch now fails after 300 seconds. Set
CLAUDE_CODE_WEBFETCH_DEADLINE_MSto override the deadline (0 turns it off) - Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted
- Fixed sustained high CPU usage: a busy loop in long-running idle sessions no longer pins a CPU core, and rapid terminal focus reports during a session recap no longer keep the CPU high
- Fixed Claude sometimes replying "your message came through empty" after an MCP tool call
- Fixed deny and ask permission rules on symlinked directories (
/etc,/tmp,/varon macOS;/binon Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spelling - Fixed a case where a Read or Edit deny rule did not apply when an
env -C,evalor similar command the permission checker cannot analyze was on the same line - Fixed plugin and marketplace errors showing a token or password from a git source URL
- Fixed
/mcpand/pluginserver details,claude mcp list/get, and MCP login errors showing secrets resolved from${VAR}placeholders in MCP configs - Fixed prompt caching and extended thinking breaking mid-session for SDK sessions using
excludeDynamicSections: the first message is no longer re-rendered each request - Fixed entitled users being told a model is restricted after restart or in the Desktop Code tab when a cached model-access denial was stale
- Fixed a running session silently switching to the organization's default model when another Claude Code process refreshed a stale model-access entry
- Fixed long-context 429s on Fable models showing the usage-credits consent prompt instead of the 1M-context message on Pro and Team plans
- Fixed workload identity federation via a profile (as claude-code-action configures it): processes sharing the profile could fail mid-run with
401 … jti reused - Fixed MCP server OAuth sign-in failing with "No available ports for OAuth redirect" when the local callback port range can't be bound
- Fixed the conversation summary produced by
/compactand auto-compact mangling text that contained$sequences - Fixed resuming a conversation that ended with
/compact: its restored-file notes now load in the same order on every resume - Fixed SDK prompt suggestions, side questions and
/renamesending the conversation from before a compaction - Fixed
@file and/command suggestions not appearing after recalling a previous prompt with the up arrow and editing it - Fixed
claude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a second - Fixed
claude agentssession delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway - Fixed background agent and workflow rows in the agents panel expanding to many lines when their text contained line breaks
- Fixed Claude in Slack sessions losing their Slack tools when org managed settings set an MCP allowlist
- Fixed Claude in Chrome asking to allow the host "https" when a navigation URL had a scheme but a host that could not be parsed
- Fixed the spinner wrapping onto several lines when the current task's label is long; the label and the "Next:" task line now stay within one terminal row
- Fixed the
/bugand/feedbackdescription field showing no cursor when the terminal's native cursor is enabled - Fixed Remote Control sessions served by
claude remote-controlshowing a generated name instead of their session title inListAgents - Fixed
claude plugin validaterejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts - Fixed plugins silently skipping a default monitors file or root SKILL.md that could not be checked
- Fixed WebFetch's error for localhost and other dotless hostnames to explain why the URL is refused and suggest curl
- Fixed PermissionRequest hooks not firing in
--printmode - Fixed policy-helper warnings not printing on headless (
-p) runs - Fixed
/resumelisting a/forkbackground session under its parent's name instead of its own⑂fork name - Fixed
/remote-controland other claude.ai-gated commands to suggest/loginwhen signed out instead of showing a Claude for Enterprise migration message - Fixed
CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MSnot extending SessionEnd hooks that have no per-hooktimeout(they were still cancelled after 1.5 seconds) - Fixed
/autofix-prand other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to/web-setupor the web connect page - Fixed cloud-session commands such as
/teleportand/remote-envto explain when an organization policy turns them off, instead of answering "Unknown command" - Fixed Bash sandbox instructions over-stating confinement: no unenforced path lists when...
Excerpt shown — open the source for the full document.