Claude Code changelog: what's new each month
Every stable Claude Code release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.
October 2026 · so far
6 releases: 2.1.287 → 2.1.292
October brought powerful new capabilities for Claude Code, including Claude Mods for deeper plugin behavior modification, improved session management, and significant enhancements to API integration and permission handling.
Highlights
- Claude Mods now let plugins modify deeper agent behavior beyond their traditional scope.
- New built-in "You should know" mod watches your work and flags potential issues you might miss.
- Added prompt caching support for mods and new mod hooks for granular control over tool calls and permissions.
- Improved session recovery and navigation with Ctrl+F search, undo for cleared prompts, and better error handling.
- Enhanced MCP server support with URL prompts for authentication and re-authentication for scope changes.
New
- Claude Mods system for plugins to modify deeper behavior and hook into permission checks.
- Built-in "You should know" mod that watches sessions and flags missed issues.
- Name-based session filtering with n: syntax in the agents view.
- $.ui.selection() API for mods to access selected text and transcript rows.
- Prompt recovery with Up arrow to restore drafts cleared with Ctrl+C.
- Prompt caching for mods using $.model.complete with cache blocks.
- serverToolUses in mod turn.step hook showing API tool calls made by the advisor.
- claude attach and claude logs commands that accept partial session names.
Improved
- MCP servers can now request additional OAuth scope with re-authentication prompts during tool calls.
- Large files open faster in plugin code panes through optimized layout rendering.
- Mid-response API timeouts now continue from partial responses in non-interactive sessions and subagents.
- Keyboard navigation in agents view with Ctrl+F to find sessions and Alt+↑/↓ to jump between groups.
- Subagent permission checks now properly respect deny rules on nested compound shell commands.
- Terminal no longer freezes on code blocks with many unclosed script tags or deeply nested substitutions.
- Read deny rules now apply to files accessed through symlinks.
- Subagent auto mode now properly checks availability before entering auto mode.
Fixed
- Fast mode staying off in remote sessions owned by agents with no user account when organization allows it.
- Mid-response API timeouts failing turns; thinking-only responses now retry properly.
- Plugin list and update showing stale copies of locally installed plugins and breaking hot reload.
- Installed mods not loading in the first session after an upgrade.
- Regressions where cloud sessions could drop permission prompt answers and lose final session messages.
- Sandboxed commands being able to read /ultrareview staged file copies.
September 2026
27 releases: 2.1.257 → 2.1.286
September brought three new default models with improved capabilities and pricing, plus major usability improvements for permissions, file handling, and multi-session workflows. The month focused on reliability, safety controls, and better integration with enterprise deployments.
- Auto mode for Claude API and Enterprise users now defaults to server-side classifier instead of local classifier.
- availableModels managed setting with "exact" now only allows exact model versions, blocking new releases until explicitly listed.
Highlights
- Claude Opus 5.5, Sonnet 5.5, and Fable 5.1 are now available as default models with 1M context windows and improved cache pricing.
- New Containment Escape rule in auto mode prevents unauthorized credential fetches and cross-tenant access unless marked expected.
- Diff panel in fullscreen mode shows uncommitted changes alongside the conversation as Claude edits files.
- Fast mode now available in Claude Code Remote sessions with permission controls.
- Fixed critical issues with concurrent sessions losing changes, prompt cache invalidation, and multi-model subagent handling.
New
- Claude Fable 5.1, Claude Opus 5.5, and Claude Sonnet 5.5 as default models with 1M context and improved cache reads.
- Time format and timezone settings for 12-hour, 24-hour, UTC, or custom strftime patterns in timestamps.
- Diff panel alongside conversation in fullscreen mode showing uncommitted file changes made by Claude.
- AGENTS.md support as an alternative to CLAUDE.md for project instructions.
- Fast mode in Claude Code Remote sessions (cloud and self-hosted runners) with organization permission controls.
- Mouse support in fullscreen mode for settings panels, skill lists, and various scrollable lists.
- Plugin eval command to run plugin test suites and get reproducible scored results with JSON and HTML reports.
- Effort level slider with keybinding actions to adjust effort without typing commands.
Improved
- Auto mode now defaults to server-side classifier for Claude API, Enterprise, Bedrock, Vertex, and gateway users, removing classifier overhead charges.
- Permission rules with path patterns now properly handle files given as option values and compound commands in Bash.
- Read permission behavior improved with confirmation prompt before first file read outside working directories, with option to block.
- Prompt cache miss causes now shown in /cost and status line (e.g. tool definitions changed, idle past TTL).
- Concurrent sessions no longer silently revert each other's workspace trust and MCP state changes.
- Bash tool results now include a diff of changed files when the Bash tool handles file edits.
- MCP server disconnection now shows notification pointing to /mcp; automatic reconnection backed off when retrying.
- Better error messages for 401/403 errors naming which credential to refresh or pointing to gateway administrator.
Fixed
- Claude Code no longer fails to launch on macOS 12 (Monterey).
- Concurrent sessions no longer lose changes to ~/.claude.json, workspace trust, and MCP/project state.
- Conversations with rejected thinking no longer get rejected again on every later turn.
- Permission rules with parentheses in paths no longer dropped as invalid by Bash sandbox.
- Read-only git commands no longer unexpectedly ask for permission after session has been running.
- Resumed foreground-spawned subagents no longer change their tool list and system prompt, breaking prompt-cache reuse.
August 2026
27 releases: 2.1.221 → 2.1.252
August brought major infrastructure improvements, security hardening, and new collaboration features to Claude Code. The month focused on self-hosted environments, cross-session messaging, and enhanced sandboxing controls.
- Subagent forking is now on by default: subagent type "fork" now inherits full conversation and prompt cache.
- Interactive sessions on one machine keep unique names: conflicts receive name-word-word variants instead of reusing names.
Highlights
- Self-hosted runners let you run Claude Code sessions on your own machines or containers for Team and Enterprise plans.
- Sessions can now message each other directly using SendMessage and discover others with ListAgents, enabling collaboration across machines.
- Subagent forking is now on by default, giving spawned agents access to your full conversation and prompt cache.
- Focus view hides tool activity details behind an expandable summary for cleaner chat interaction.
- New Concise output style lets Claude skip preamble and get straight to results.
New
- Self-hosted runners: run Claude Code on your own infrastructure with server-supplied hook support and graceful shutdown options.
- Cross-session messaging: sessions on one machine can send messages to each other and discover connected peers.
- Archive plugin source: install plugins from a ZIP file over HTTPS with optional SHA-256 pinning.
- Plugin marketplace command sources: resolve plugin directories via a local command applied each session without restart.
- Spellcheck setting: underlines misspelled words in prompt input using installed aspell, hunspell, or ispell.
- SendFeedback tool: Claude can draft feedback reports for you to review when issues occur.
- GitLab support: plugin marketplaces now support GitLab URLs and merge request tracking.
- Concise output style: new built-in option that leads with results and skips narration.
Improved
- Focus view toggle (Ctrl+Alt+F) hides tool activity behind an expandable per-turn summary with a live running-tool indicator.
- Sandbox credential masking now supports JWT with maskClaims, structured env extraction, and AWS SigV4 re-signing.
- Slash-command menu improved: blue marks selected row, matched characters bold, emoji and accents preserved.
- MCP OAuth servers on macOS no longer intermittently fail with 401 errors after keychain timeouts.
- Permission check warnings added for Bash allow rules with wildcards before subcommands.
- Auto mode now properly releases subagent tool results to prevent unbounded memory growth in long sessions.
- Session names kept unique on one machine: name conflicts get name-word-word variants.
- Prompt caching now works for sessions using an LLM gateway or custom base URL.
Fixed
- Bash permission bypass where zsh could execute hidden commands in regex conditionals is now blocked.
- PowerShell permission checks mishandling paths with quote characters on Windows.
- Worktree-isolated sessions were able to run destructive git commands against main checkout; isolation now applies to all session types.
- PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks.
- Long responses partly disappearing while streaming and being printed twice in terminal.
- File tools following a symlink swapped after permission check, allowing reads or writes outside approved locations.
Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Claude Code: pricing, features and alternatives · All changelogs
