Anthropic Claude Code v2.1.268 Patch Release
This patch release for Anthropic Claude Code introduces several minor features and critical bug fixes. It addresses issues such as HTTP 400 errors with third-party Anthropic-compatible endpoints, WebFetch hanging, and sustained high CPU usage in idle sessions. The update also includes fixes for permission rule applications on symlinked directories, secrets exposure in error messages, and various workflow and UI improvements for developers. Users are encouraged to update for enhanced stability and reliability.
- →Added configDirectory to the output of claude auth status --json
- →Added browser-tab icons for published artifacts, chosen by Claude to match each page
- →Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted
- →Fixed Claude sometimes replying "your message came through empty" after an MCP tool call
- →Fixed plugin and marketplace errors showing a token or password from a git source URL
Features (7) ›
Added to the Claude apps gateway: with pricing: set in gateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so /cost and telemetry match the spend meter
Added a startup warning for gateways when access_control.allow_cidrs is empty, and a one-time warning the first time a request arrives from a public address
Added the gatewayInternalNetworks managed setting, letting administrators allow /login to a Claude apps gateway on their organization's own public IPv4 block
Added claude self-hosted-runner --remove-session-state (default off): delete each session's per-session directories under <base-dir>/_sessions/ when the session ends
- Added configDirectory to the output of claude auth status --json
Added --json to claude plugin install, uninstall, update, enable and disable, and errorDetails/noteDetails to each row of claude plugin list --json
- Added browser-tab icons for published artifacts, chosen by Claude to match each page
Enhancements (18) ›
Improved fullscreen mode: adding or removing a prompt line (Shift+Enter) now repaints as fast as typing a character instead of re-rendering the visible transcript
Improved --continue / --resume: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript
- Improved responsiveness during tool-heavy turns by no longer redrawing the transcript for a hidden per-tool-batch reminder
- Improved startup time in projects with .claude/workflows/ scripts: listing them no longer parses each script
Improved auto mode denials: the message Claude receives now names the rule that blocked the action and asks Claude to try a safer method and finish unrelated work before stopping to ask you
- Improved Claude in Chrome: long page reads now stay inline instead of being saved to a file and read back
- Improved the MEMORY.md truncation warning to say how many lines were cut and where the cut starts
- Improved the terminal permission prompt for artifacts: it now leads with the ask's question
Improved the prompt footer: an editor or /diff selection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer
Improved the "Usage credits required for 1M context" message to say that usage credits turned on mid-session take effect after restarting Claude Code
Improved /plugin: installing, enabling or disabling a plugin now takes effect when you close the menu; /reload-plugins is no longer needed afterwards
Changed the system prompt on Bedrock, Vertex and Foundry to deliver environment, model and settings details as attachments, matching first-party sessions
Changed Bedrock, Vertex and Foundry sessions to keep the tool list byte-stable across a conversation (late-connecting tools load deferred instead of rewriting it), matching first-party sessions
Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be offered only on Claude 3.x, Opus 4.0–4.7, Sonnet 4.0–4.6, Haiku 4.5; set CLAUDE_CODE_ENABLE_TODO_TOOLS=1 elsewhere
- Changed the artifact data-edit permission prompt in the terminal to a card that shows the document count and who can open the artifact
Changed local Cowork sessions set to skip all approvals: the Artifact tool now refuses a local file outside the session's folders, or behind a symlink, instead of reading it without asking
Changed plain WebFetch deny and ask rules to no longer apply to Artifact tool reads and updates; use an Artifact rule (or WebFetch(domain:claude.ai)) to block or gate them
- Changed the "N MCP servers need authentication" startup notice to announce each server once instead of at every launch
Fixes (38) ›
Fixed every turn failing with HTTP 400 on third-party Anthropic-compatible endpoints (ANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints reject
Fixed WebFetch hanging indefinitely on a server that keeps the response open without finishing; a fetch now fails after 300 seconds. Set CLAUDE_CODE_WEBFETCH_DEADLINE_MS to override the deadline (0 turns it off)
- Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted
Fixed sustained high CPU usage: a busy loop in long-running idle sessions no longer pins a CPU core, and rapid terminal focus reports during a session recap no longer keep the CPU high
- Fixed Claude sometimes replying "your message came through empty" after an MCP tool call
Fixed deny and ask permission rules on symlinked directories (/etc, /tmp, /var on macOS; /bin on Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spelling
Fixed a case where a Read or Edit deny rule did not apply when an env -C, eval or similar command the permission checker cannot analyze was on the same line
- Fixed plugin and marketplace errors showing a token or password from a git source URL
Fixed /mcp and /plugin server details, claude mcp list/get, and MCP login errors showing secrets resolved from ${VAR} placeholders in MCP configs
Fixed prompt caching and extended thinking breaking mid-session for SDK sessions using excludeDynamicSections: the first message is no longer re-rendered each request
- Fixed entitled users being told a model is restricted after restart or in the Desktop Code tab when a cached model-access denial was stale
Fixed a running session silently switching to the organization's default model when another Claude Code process refreshed a stale model-access entry
- Fixed long-context 429s on Fable models showing the usage-credits consent prompt instead of the 1M-context message on Pro and Team plans
Fixed workload identity federation via a profile (as claude-code-action configures it): processes sharing the profile could fail mid-run with 401 … jti reused
- Fixed MCP server OAuth sign-in failing with "No available ports for OAuth redirect" when the local callback port range can't be bound
- Fixed the conversation summary produced by /compact and auto-compact mangling text that contained $ sequences
- Fixed resuming a conversation that ended with /compact: its restored-file notes now load in the same order on every resume
- Fixed SDK prompt suggestions, side questions and /rename sending the conversation from before a compaction
- Fixed @ file and / command suggestions not appearing after recalling a previous prompt with the up arrow and editing it
Fixed claude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a second
Fixed claude agents session delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway
- Fixed background agent and workflow rows in the agents panel expanding to many lines when their text contained line breaks
- Fixed Claude in Slack sessions losing their Slack tools when org managed settings set an MCP allowlist
- Fixed Claude in Chrome asking to allow the host "https" when a navigation URL had a scheme but a host that could not be parsed
Fixed the spinner wrapping onto several lines when the current task's label is long; the label and the "Next:" task line now stay within one terminal row
- Fixed the /bug and /feedback description field showing no cursor when the terminal's native cursor is enabled
- Fixed Remote Control sessions served by claude remote-control showing a generated name instead of their session title in ListAgents
- Fixed claude plugin validate rejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts
- Fixed plugins silently skipping a default monitors file or root SKILL.md that could not be checked
- Fixed WebFetch's error for localhost and other dotless hostnames to explain why the URL is refused and suggest curl
- Fixed PermissionRequest hooks not firing in --print mode
- Fixed policy-helper warnings not printing on headless (-p) runs
- Fixed /resume listing a /fork background session under its parent's name instead of its own ⑂ fork name
Fixed /remote-control and other claude.ai-gated commands to suggest /login when signed out instead of showing a Claude for Enterprise migration message
Fixed CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS not extending SessionEnd hooks that have no per-hook timeout (they were still cancelled after 1.5 seconds)
Fixed /autofix-pr and other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to /web-setup or the web connect page
Fixed cloud-session commands such as /teleport and /remote-env to explain when an organization policy turns them off, instead of answering "Unknown command"
Fixed Bash sandbox instructions over-stating confinement: no unenforced path lists when filesystem isolation is off, and strict mode no longer claims commands can never run unsandboxed
https://github.com/anthropics/claude-code/releases/tag/v2.1.268
Related releases
- Anthropic Introduces Smart Reports for Claude Enterprise Teams Claude Release Notes ·
- Anthropic Enhances Claude Managed Agents with `auto` Policy, CLI Connect Claude Platform Release Notes ·
- Anthropic Python SDK v1.5.0 Introduces Managed Agent and Tooling Enhancements Anthropic Python SDK Releases ·
- Anthropic Claude Code v2.1.267 Delivers New Controls and Bug Fixes Claude Code Releases ·
- Anthropic Claude-code v2.1.266 Fixes LLM Gateway Regression Claude Code Releases ·
- Anthropic Releases Claude Code v2.1.265 with Bug Fixes and Improvements Claude Code Releases ·