Anthropic ships Claude across 19 surfaces and documents each one on its own. Nowhere published is the comparison. This is that comparison, rebuilt daily.
Parity is an independent project, not affiliated with, endorsed by, or sponsored by Anthropic. Claude and Anthropic are trademarks of Anthropic PBC, referred to here only to describe what the tools do.
Pick as many as apply. These are the capability rows themselves, so every answer below traces back to a source.
Nothing selected yet. Pick a capability above and the answer appears here.
5 of 20 capabilities separate these two on confirmed facts. The remaining 15 they handle the same way, so they are not part of the decision and are not listed.
Nothing. Everything the other does, this does too.
Marked rows are the ones your selected surfaces disagree on, which is where the decision sits. Select a cell to see the detail and the plan gating behind it.
| Capability | Cowork | Claude Code | Agent SDK | Managed Agents |
|---|---|---|---|---|
Direct local file access Read and write files on the user machine without upload. | Yes | Yes | No | |
Live artifacts Artifacts that update in place during a session. | No | No | No | |
Chat memory Carries context across ordinary conversations. | No | |||
Persistent versioned memory API-addressable memory store with version history. | No | No | ||
Subagents Ephemeral isolated-context agents with restricted tools. | ||||
Agent teams Multiple full instances sharing a task list and messaging each other. | No | |||
Lifecycle hooks Intercept tool calls at lifecycle events. | ||||
Plugin marketplaces Browse and install plugins with versioning and updates. | ||||
Agent Skills SKILL.md packages, auto-invoked or called by name. | Yes | Yes | ||
Scheduled tasks Recurring runs on a cron-like schedule. | ||||
Outbound webhooks Signed subscribable event delivery. | No | No | ||
Sandboxed execution OS-level isolation of tool and code execution. | ||||
Computer use Direct screen control, clicking and typing. | No | No | ||
Browser control Navigate, click and fill forms in a real browser. | No | No | ||
Code execution Run shell commands and code. | Yes | Yes | Yes | Yes |
Voice mode Spoken conversation, not just dictation. | No | No | ||
MCP servers Connect external tool servers. | Yes | |||
Session resume and fork Continue or branch a previous session. | Unknown | |||
Batch processing Async bulk request processing at a discount. | No | No | No | No |
Zero Data Retention eligible Can be covered by ZDR arrangements. | Unknown | Yes |
The part official documentation cannot tell you, because each surface is documented on its own.
Live artifacts, local MCP server plugins and direct filesystem access are desktop only. Cloud sessions reach files solely through a brokered connection to a running desktop app, so a closed laptop removes the capability entirely rather than degrading it.
Install a plugin in ordinary web chat or the desktop chat tab and its subagent and hook components appear inactive. The plugin looks installed while the orchestration parts do nothing.
Computer use in Cowork, cross-device task assignment and the mobile location tool are Pro and Max only, and explicitly unavailable to Team and Enterprise. This runs opposite to the usual gating direction and is easy to get wrong when advising on plan choice.
Multiple full Claude Code instances sharing a task list and messaging each other exist only in the CLI. SDK documentation states plainly that this is not configurable through SDK options. Managed Agents multiagent orchestration is a separate construct, not the same feature exposed elsewhere.
Sessions are stateful and stored server-side by design, so Managed Agents is explicitly ineligible. Running the CLI or SDK against the standard API keeps your existing ZDR or HIPAA arrangements intact. For regulated work this single fact can decide the architecture before anything else does.
The Claude Code Team and Enterprise article states that under a HIPAA-ready Enterprise agreement Claude Code is technically included in the seat but is not covered under the HIPAA-ready offering. A HIPAA-covered organisation that provisions Enterprise seats gets Claude Code without getting HIPAA coverage for it. This sits alongside Managed Agents, which is not eligible for Zero Data Retention or a HIPAA BAA, and Claude in Chrome, which has no ZDR support and is unavailable to HIPAA-covered organisations.
CORRECTED 2026-08-20. Plugin marketplaces are not CLI only. They exist on the Claude Code CLI, allowlisted through strictKnownMarketplaces, and on the Claude desktop app, allowlisted through allowedPluginMarketplaces, which from v1.32352.0 also applies to Code sessions and supports a hosted url source delivering zip archives over HTTPS with no git on the device. The real boundary is that the Agent SDK loads local filesystem paths only and Managed Agents has no plugin concept at all, offering only a Skills API and MCP references. The two allowlist mechanisms are independent and have different semantics, so a policy written for one does not transfer to the other.
claude-fable-5-1 and claude-mythos-5-1 require 30 day data retention and are documented as unavailable under zero data retention. Because the restriction attaches to the model rather than to a surface, a ZDR organisation loses them on the Claude API, on Bedrock, Vertex and Foundry, and on every interactive surface at once. Parity already records two surface-level ZDR exclusions, Managed Agents and Claude in Chrome, and both could be worked around by choosing a different surface. This one cannot. An administrator checking plan gating will not see it, because it is not plan gating: the models are absent regardless of plan or seat. The practical effect is that ZDR now caps an organisation at the previous model generation.
The Compliance API access article states that the session content beta does not include Claude Code on web, Claude Code accessed through the Claude Platform, or sessions run on Amazon Bedrock or Google Vertex AI, while covering Cowork via Claude, Claude Desktop and Claude Mobile, and Claude Code via CLI and Claude Desktop. The same piece of work is therefore retrievable or not depending purely on execution location. An organisation standardising on Bedrock or Vertex for data residency reasons loses session transcript retrieval as a side effect, and Claude Code on the web is uncovered while the CLI is covered.
The built-in browser announced on 26 August 2026 lives in the Cowork desktop app. The announcement states "The built-in browser lives in the desktop app. From the web or your phone, Claude can still drive it as long as your desktop app is open and online." A Cowork session running in the cloud with no desktop attached, which is how a scheduled task runs, therefore has no built-in browser and no Claude in Chrome either. Browser automation in Cowork is available only where a desktop is present and online.
On 10 September 2026 two separate browsing capabilities change from off to on by default for Enterprise organisations that have not disabled them. Claude in Chrome is the browser extension, administered on its own admin controls page, which states that the extension is disabled by default and turns on by default from that date unless already disabled. The Cowork built-in browser ships inside the desktop app and is administered on the Cowork browser-use page, which carries the same date. The Chrome page states that Claude in Chrome and Claude Cowork are managed separately, and neither page references the other. An admin who reads one page and acts on it has covered one of the two. Neither default requires an admin action to take effect, so leaving a setting untouched is not the same as declining it.
Claude Code 2.1.259 introduced a managedMcpServers managed setting that takes the .mcp.json entry shape and skips entries naming a command to run, so it delivers HTTP and SSE servers only. The Cowork and desktop app documents a managedMcpServers setting of its own with fields including scope, transport, azureCloud, oauth and toolPolicy, whose old spellings stop working on 7 October 2026 at 12:00 Pacific, after which an invalid entry makes that connector unavailable. An organisation deploying MCP centrally to machines running both now has one key name, two entry shapes, and a fail-closed deadline that applies to one of them. Neither changelog references the other, so nothing published states whether the Claude Code key inherits the deadline.
Claude Code 2.1.259 added --permission-prompts none and the TypeScript Agent SDK 0.3.259 added permissionPrompts set to none, both on 2026-09-02, so an unattended run can now state that a permission prompt should be denied rather than left hanging. Cowork scheduled tasks and Managed Agents document no equivalent. Those are the surfaces where unattended work is the normal case rather than a configuration, and they are the ones without the control. The same week produced three separate fixes for unattended sessions stalling or failing after a permission approval, across Claude Code and the desktop app, which is what the absence of an explicit mode looks like in practice.
Desktop v1.52386.0 of 10 September 2026 adds chatSessionRetentionDays, coworkSessionRetentionDays and codeSessionRetentionDays, each taking 1 to 3650 days, plus sessionRetentionHold for legal hold. No equivalent retention setting was found this run for the terminal CLI, the Agent SDK or Managed Agents. The consequence is that the same work, run by the same person under the same policy, is bounded in time if it happens in the desktop app and unbounded if it happens in a terminal. An organisation setting a retention policy should know it covers one delivery route rather than the activity itself, which is the same shape as the existing compliance gap where session coverage depends on where the work runs rather than what the work is.
The platform release notes of 10 September 2026 add an auto mode to Managed Agents permission policies, evaluating agent and MCP tool calls on the server. Every other surface decides permissions on the client: Claude Code, the Agent SDK, Cowork and the desktop app all read their rules from the machine running the work, so whoever controls that machine controls the rules. Managed settings narrow this on managed devices but the evaluation still happens locally. The practical effect is that an organisation wanting a permission decision that cannot be edited by the person subject to it has exactly one surface that offers it. This gap runs the opposite way to most in the matrix, where Claude Code leads and the hosted surfaces trail.
Claude desktop v2.2553.0 of 2026-09-17 adds allowedPluginMcpServers, which restricts Cowork, Chat and Code sessions to plugin MCP servers whose URL matches an entry, allows none when the list is empty, and applies in addition to managedMcpServers and organization plugins even when managedMcpServers is empty. The same build stops the app starting plugin MCP servers on the device except those from organization plugins. The Claude Code changelog names no equivalent key, so a terminal session started outside the desktop app on the same machine is not covered by the allowlist. This is now a third managed key governing MCP servers, alongside the two different settings that already share the name managedMcpServers.
PyPI shows claude-agent-sdk at 0.2.156, published 2026-09-17, and the npm registry shows @anthropic-ai/claude-agent-sdk at 0.3.276. The gap widened again on 2026-09-17 and entirely on one side: TypeScript 0.3.275 fixed deferred tool results being emitted under an internal key name, UUID validation rejecting client-provided values, getSessionMessages and forkSession missing turn assistant messages, forkSession rejecting message IDs that getSessionMessages returned, and getSessionMessages omitting task notifications and queued messages. Python 0.2.155 and 0.2.156 carried only bundled CLI bumps and documented none of it. Python still holds snapshot on SystemPromptPreset and SystemPromptCustom, which TypeScript is not documented as having, so the gap still runs both ways. UPDATED 2026-09-19. The gap widened again in the same direction. TypeScript 0.3.277 added SlashCommand.builtin, SDKUserMessage.pasted_content, four remote session latency fields and a userSettings source on updateSettings(), and fixed cost and usage totals across resume and fork. On the Python side PyPI lists 0.2.157, released 18 September, but the tag-pinned changelog at v0.2.157 returns 404 from both a subagent and a main-session retry, so what it contains cannot be read by the route the routine mandates and is recorded as unknown rather than assumed to be a bundled CLI bump. See open question 55. This is the third consecutive run in which only the TypeScript side grew.
The Claude in Chrome admin controls article tells administrators to disable isLocalDevMcpEnabled in the Enterprise configuration to stop members using the Chrome extension through the desktop app. The Enterprise configuration reference for Claude Desktop documents the same key as "Enable local MCP servers", Boolean, default true, and mentions neither Chrome nor browser access. Following one article silently applies the other effect. There is no separate key documented that blocks the Chrome extension without also disabling local MCP servers.
Claude Projects sync across devices and are shareable on Team and Enterprise. Cowork Projects are desktop only, stored locally, do not sync, cannot be shared even on Team or Enterprise, and are not usable in Claude Code.
They run in the cloud, so they work with connectors and account-saved files only. Anything needing local files executes only if the desktop app happens to be reachable at that moment.
Signed subscribable webhooks covering session, agent, deployment, environment and memory events, with retries and deduplication. The CLI and SDK have no outbound equivalent. CLI Channels is inbound and a research preview, so it is not a substitute.
The CLI has native per-command OS sandboxing on macOS, Linux and WSL2, with no native Windows support. The SDK needs a separate package. Managed Agents isolates at the whole-sandbox level instead, either an Anthropic-managed cloud sandbox or a self-hosted worker polling a queue.
The CLI and interactive SDK use can ride a Claude subscription, but products built on the Agent SDK are explicitly barred from offering Claude login or subscription rate limits to their own end users and must use an API key. Managed Agents has no subscription path at all.
Persistent versioned memory with an API remains Managed Agents only: 8 stores per session, 2000 memories per store, 30-day version retention. PARTLY NARROWED 2026-08-19: self-hosted sandboxes can now attach memory stores, with Python, TypeScript and Go SDK workers downloading at mount_path and syncing back, so the capability is no longer confined to Anthropic-hosted sandboxes. It is still confined to Managed Agents. Claude Code and Agent SDK auto memory stays machine-local with no API, no versioning and no sync.
An organisation running both the Claude Code CLI and the Claude desktop app maintains two separate plugin marketplace allowlists. The CLI uses strictKnownMarketplaces, which from 2.1.234 rejects SCP-style git marketplace sources whose host differs from the git connection target. The desktop app uses allowedPluginMarketplaces, which from v1.32352.0 supports a hosted url source in beta, delivering plugins as zip archives over HTTPS with no git on the device, pinned by manifestSha256, and applies to Code sessions as well as Cowork. NARROWED 2026-08-21: Claude Code 2.1.238 documents headersHelper on a url marketplace and on individual catalog entries in the CLI, so hosted url marketplaces are no longer described only on the desktop side. The two allowlists remain independent, with different key names and no documented relationship, and the CLI documentation does not state whether manifestSha256 pinning applies there. The Agent SDK loads local filesystem plugin paths only and Managed Agents has no plugin concept at all.
Claude Code 2.1.248 added --restricted (CLAUDE_CODE_RESTRICTED=1), which removes the built-in tools that run commands or code, removes WebFetch unless named in --tools, keeps file tools inside the working directory, refuses bypassPermissions, and ignores user, project and local settings files. No equivalent single-switch restricted profile is documented for the Agent SDK, Cowork, or Managed Agents, so an organisation cannot apply one posture across surfaces.
Claude Code 2.1.243 and 2.1.251 added promptCacheTtl and subagentPromptCacheTtl, a modelPricing managed setting carrying contracted rates into cost figures, a per-session prompt cache line in /cost with a prompt_cache status line object, and a spend limit bar in /usage with a rate_limits.spend_limit field. Cowork, Console and Managed Agents expose no per-session cache hit ratio or contracted-rate cost figure, so cost control is measurable on one surface and not the others. NARROWED 2026-08-31, not closed. The desktop app Usage page gained an estimated cost view on its chart in v1.40609.0 (2026-08-27), and cost estimate settings inferenceModelPricingEnabled, inferenceModelPricing and inferenceModelPricingMultiplier arrived in v1.37937.0 and v1.37937.1 (2026-08-25). That is spend visibility reaching the desktop app and Cowork. Prompt cache visibility, which is the other half of this gap, is still documented only in the Claude Code CLI. Source: https://claude.com/docs/cowork/changelog
claude-mythos-5-1 launched on 2026-09-01 alongside claude-fable-5-1, with the same 1M context, 128k output and pricing. Its published availability table lists the Claude API, Amazon Bedrock, Google Cloud and Microsoft Foundry, and names no Claude app and no Claude Code. Access is invite only through Project Glasswing rather than by plan. So a capability that an API caller can reach has no equivalent on any surface a person uses interactively, and no amount of plan spend reaches it. Fable 5.1, launched the same day, is documented across the apps, Claude Code, Cowork, the API and the clouds, which makes the contrast a property of this model rather than of the launch.
Claude Code 2.1.261 adds /skill-doctor, which lists loaded skills, flags the unused ones and states what each costs in context. Skills reach Cowork, the desktop app and the Agent SDK through the same plugin and skill mechanism, so the context cost applies there too, but no equivalent report is named in those surfaces changelogs. Anyone carrying a large skill and plugin set can now measure the cost on one surface and not on the others, which matters because the surfaces share the installed set.
Memory across chat and Cowork only works when Cowork runs in the cloud, and it is not available in Cowork sessions that run locally. On Enterprise, memory is off by default and Run Cowork in the cloud is separately off by default, has to be turned on by an owner, and then granted to a group through custom roles. An Enterprise organisation that turns memory on and leaves cloud Cowork alone gets no cross-surface memory at all. Neither page states the dependency, because each documents its own control. Pro and Max are unaffected: both are on by default there.
Desktop v1.49585.0 moves the app runtime to Electron 44, which is Chromium 152, and raises the minimum to macOS 13 Ventura. A Mac on macOS 12 or earlier stops receiving desktop updates, which takes Cowork and the desktop-hosted Claude Code session with it. The Claude Code terminal CLI carries no stated macOS floor, so the same machine keeps the CLI and the Agent SDK. This is the first recorded case of a surface aging out of a supported machine while its sibling surfaces stay available on it, and the changelog entry does not present it as a cross-surface consequence.
From desktop v1.49585.0, deployments on the Claude API, Google Vertex AI, Amazon Bedrock and Bedrock Mantle that set no custom base URL no longer suppress Claude Code experimental features, so tool search is on by default, on Vertex AI with Claude 4.5 and newer, and toolSearchEnabled no longer has to be set. Gateway deployments, Foundry deployments and anything behind a custom base URL are explicitly unchanged. One organisation running both shapes now gets different default tool behaviour depending only on how a deployment reaches the model, which no single page presents as a comparison.
Claude Code 2.1.269 adds a Hooks dialog and a Permission rules dialog to the VS Code extension, each listing the current entries and adding, editing or removing them in user, project and local settings, with managed, plugin and session rules read only. On every other surface that supports hooks or permission rules, including the terminal CLI, Cowork, the desktop app and the Agent SDK, both are edited as settings files by hand. The practical consequence is that the surface with the safest editing path for a security-relevant setting is the one an administrator is least likely to standardise on.
Claude Code 2.1.269 adds claude plugin eval, which runs a plugin's own eval suite and returns scored, reproducible results as JSON and as an HTML report. Cowork, the desktop app and the Agent SDK all load and run the same plugins, and none is documented as able to run an eval suite against one. An organisation that distributes plugins through a marketplace therefore has a way to score them only on the surface where a developer works, not on the surfaces where most of its people run them.
Claude Code on the web manages recurring work on a Routines page at claude.ai/code, which on 2026-09-14 gained Yours and Templates tabs, two-column cards showing run status, and lost its calendar view. Cowork manages scheduled tasks from the desktop app and the cloud. No documentation describes a shared view, a migration path, or any visibility of one from the other, so an organisation running recurring work on both surfaces has two separate inventories and no single place to see what is scheduled. The Cloud environments admin page does name a default environment for Claude Tag and Claude Code together, which is the only point where the two are configured in one place.
The Claude apps unified release notes page at support.claude.com is the documented home for Claude Tag and has carried nothing about it since 2026-06-23, now 87 days. Over the same period the Claude Code changelog has carried the Claude Tag changes instead. Claude Code 2.1.275 of 2026-09-17 added eleven more, covering access bundle attach conditions for guest and Slack Connect channels, CloudWatch, CloudWatch Logs, SNS, Google Cloud Monitoring and Cloud Logging credential presets, Datadog site presets with new connections limited to read and query routes, and fixes for duplicate replies, a silently reverting thread model, thread display names and Enterprise Grid notices. An administrator reading the documented Claude Tag page would know none of it.
Claude desktop v2.2553.0 of 2026-09-17 adds builtinBrowserDefaultDomainPolicy, builtinBrowserAllowedDomains and builtinBrowserBlockedDomains, giving administrators per-domain control over where Claude may browse in the Cowork built-in browser. The Claude in Chrome admin controls article documents no equivalent per-domain allowlist or blocklist for the extension. An organization running both browsing paths therefore governs them at different granularity: domains on one, an on or off toggle on the other. The built-in browser is also desktop only, so a cloud-only Cowork session has neither the browser nor these controls.
Claude Code 2.1.277 reads AGENTS.md in a project with no CLAUDE.md, and the changelog states this is not yet available on Bedrock, Vertex or Foundry. The same repository therefore supplies project instructions to a session running against the Claude API and supplies none to a session running against those three cloud deployments, with nothing in the repository to indicate the difference. AGENTS.md is the convention other coding tools read, so the repositories most likely to carry one and no CLAUDE.md are exactly those shared across tools.
Available in web, desktop and mobile chat. Cowork and Claude Code offer dictation only.
Written daily by an automated watcher across every published changelog. Summaries only, each linking to the page it came from. Nothing is reproduced verbatim.
Sources last checked 2026-09-20. Most recent change on file shipped 2026-09-20. Dates below are when a change shipped, not when Parity recorded it.
Two Anthropic support articles describe the same Enterprise configuration key differently. The Claude in Chrome admin controls article offers it as a way to stop organisation members using the Chrome extension through the desktop app, saying to disable isLocalDevMcpEnabled in the Enterprise configuration. The Enterprise configuration reference for Claude Desktop documents the same key as a Boolean defaulting to true whose description is "Enable local MCP servers", and states no connection to Chrome or to browser access anywhere in the article. An administrator who follows the Chrome article to block the extension would therefore also turn off every local MCP server for that organisation, and neither article says so. Both articles carry an "Updated over 2 weeks ago" stamp, so neither sentence is new; what is recorded here is the relationship between them. The Enterprise configuration table lists isDesktopExtensionEnabled and isDesktopExtensionDirectoryEnabled as separate keys, both defaulting to true.
Why this mattersThe key sits in the Claude Desktop Enterprise configuration, so the blast radius covers local MCP servers used from the desktop app and from Cowork sessions in it, while the stated purpose in the Chrome article covers only the Chrome extension. Parity holds a comparable finding for managedMcpServers, where one setting name carries two schemas across the CLI and the desktop app. This is the second Enterprise MCP control whose documented name and documented effect do not match across surfaces.
The Anthropic support article on the merge states that once an account has the new experience, it is not possible to switch back to separate Chat and Cowork options. The same article states that the rollout starts with Pro and Max plans on web, desktop and mobile, and that Enterprise administrators will be told at least 30 days before anything changes for their organisation. It also states that Claude Design, Claude Slides and Claude Docs are in beta. The article carries an "Updated this week" stamp, so the date the irreversibility sentence appeared is not documented.
Why this mattersParity already holds the 30 day Enterprise notice and the Pro and Max ordering from the launch blog post. The one way nature of the migration is documented only in the support article, not in the blog post, so an Enterprise administrator reading the announcement alone would not learn that the change cannot be undone. No equivalent rollback statement exists for any other surface in the matrix.
From Claude Code 2.1.278, auto mode asks the server to run its safety classifier checks as part of the session's own model requests, and does not charge for them when the server performs them. This is the default on Enterprise plans, on accounts using the Claude API, and on Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry, subject to each platform's own rollout. Where the server's checks cannot reach the session, Claude Code keeps using its own classifier requests and those are billed as before. Pro, Max and Team plans are documented as never seeing the fallback notice. The /status command gains an Auto mode server row reading Enabled while the server's checks decide the session's actions and Disabled once it has fallen back.
Why this mattersParity published on 15 September that Claude Code 2.1.273 set auto mode on Bedrock, Vertex and Foundry to the local classifier by default. 2.1.278 reverses that default to server side on the same platforms five days later, so a cost assumption recorded last week no longer holds.
A gateway or proxy that strips or rewrites request headers, drops request fields it does not recognise such as safeguards, or edits responses by dropping keys such as safeguard_results or rewriting tool-use IDs, stops the server's auto mode checks reaching the session. Claude Code then falls back to its own billed classifier requests, and holds the next checked action to show a notice. Enter continues on billed requests, and where the notice names a gateway the acknowledgement keeps it from reappearing on that machine for 24 hours. In non-interactive mode with -p the text goes to stderr, and in stream-json output it is emitted as a system warning message that Agent SDK applications can read from the message stream. Setting CLAUDE_CODE_AUTO_MODE_SERVER to 0 stops Claude Code asking for server checks, and the page states the variable is temporary and may be removed in a later release. It is not read on a direct connection to the Anthropic API. On Bedrock, Google Cloud's Agent Platform, Microsoft Foundry and signed-in Claude apps gateway sessions, only Claude Sonnet 5, Opus 4.7 or later and the Fable models support auto mode at all.
Why this mattersThe fallback surfaces differently per surface: a held prompt in the terminal, stderr text under -p, a readable system warning in stream-json for the Agent SDK, and a conversation notice with nothing to acknowledge in the VS Code extension. An unattended run is the case with the least visibility.
The model deprecations page lists claude-mythos-5-1 as Active with a tentative retirement date of not sooner than 1 September 2027, and claude-mythos-5 as Active, not sooner than 9 June 2027. claude-mythos-preview appears as a table row reading Deprecated, with a deprecation date of 9 June 2026 and a tentative retirement date to be announced, alongside the prose note directing migration to claude-mythos-5. The column is headed Tentative retirement date, and every active model's value is phrased as not sooner than a date, which states a minimum time before retirement rather than a scheduled retirement.
Why this mattersParity's record of 18 September held no row for either Mythos model and no deprecation date for Mythos Preview, so all three rows appeared within the last day. This closes the question Parity opened on 15 September about why Mythos 5.1 had no row when Fable 5.1 did.
Two Cowork support articles state that Claude Cowork and chat are now one Claude, rolling out gradually to Pro and Max plans, and that Team and Enterprise organizations keep chat and Claude Cowork as they are today, so the existing Team and Enterprise guidance still applies. One of the two carries an Updated today stamp.
Why this mattersThis settles the scope question left open by the 16 September merge announcement, which named Pro and Max but said nothing about the other two plans. No plan gating value moved, because the documented answer is that nothing changes for Team or Enterprise.
Claude Code 2.1.276 fixes a regression introduced the day before in 2.1.275 in which every request failed with a 400 naming an unrecognised input tag when ANTHROPIC_BASE_URL points at a proxy or gateway. Anyone on 2.1.275 routing through a gateway had a completely non-functional CLI. Upgrade to 2.1.276.
Why this mattersThe same release train, 2.1.275, separately fixed a terminal 400 on every turn for users behind a network gateway that rewrites API error responses when a beta request header is rejected. Two distinct gateway faults in two consecutive versions.
The Compliance API local session endpoints now also return transcripts of Claude in Chrome sessions, carrying the product surface value claude_in_chrome. It is in beta for Claude Enterprise organizations and uses the existing Compliance Access Key with the read:compliance_user_data scope, so no new credential is needed. Browser activity that was previously outside compliance retrieval is now inside it.
Why this mattersThe Compliance API access article scopes the session content beta by where the work runs rather than by what the work is. This change brings Claude in Chrome inside that scope. The audit log article separately enumerates 35 event types, none of which names Cowork, Claude Code or an Office add-in, so coverage of those surfaces is still not documented anywhere.
The Claude Design admin guide for Team and Enterprise now states that presentations have their own tool, Claude Slides, and that Claude Slides and Claude Docs have their own settings on the same Artifacts page as Design. Organization settings then Artifacts therefore now carries three separate toggles, Design, Slides and Docs, while Organization settings then Capabilities continues to govern the standalone product at claude.ai/design. The guide does not date this change.
Why this mattersClaude Docs and Claude Slides launched on 2026-09-16 alongside the announcement merging Cowork and chat. This is the first admin control documented for either, and it arrives two days after the launch. Neither product is named as a surface in its own right on any documentation page, and the guide states no plan gating for either.
Claude Code 2.1.277 reads AGENTS.md in a project that has no CLAUDE.md, and the choice is editable under Project instructions in /config. The changelog states it is not yet available on Bedrock, Vertex or Foundry.
Why this mattersAGENTS.md is the file name other coding tools already read, so a repository carrying one gets project instructions in Claude Code without a second file. The platform carve-out means the same repository behaves differently depending on whether the session runs against the Claude API or against Bedrock, Vertex or Foundry.
Claude Code 2.1.277 removes the deprecated TaskOutput tool. Claude reads a background task's output file with Read instead. The taskOutputMaxChars setting and the TASK_MAX_OUTPUT_LENGTH environment variable no longer have any effect. Neither is reported as erroring, so a configuration that sets either one keeps loading while the value is ignored.
Why this mattersAnyone who capped background task output to control context spend should check these two keys now. A silently ignored cap is the failure mode that shows up as unexpected context growth rather than as an error.
Claude Code 2.1.277 fixes a sandbox.excludedCommands glob exempting an entire compound Bash command from the sandbox when only one part of it matched. Every part must now match for the exemption to apply. Before the fix, a compound command could carry unmatched parts outside the sandbox on the strength of a single matching segment.
Why this mattersThis is the second class of permission checker fault Parity has recorded on compound and nested Bash constructions, after the loop variable and nested expansion escapes published on 17 September. The pattern is consistent: the checker reasons about a command line as a whole where the shell will run it in parts.
Claude Code 2.1.277 changes subagent results so they reach the main agent under a header marking them as subagent output, with the result indented, so that text inside a subagent's result cannot pass as the session's own instructions.
Why this mattersThis matters to anyone whose subagents read third-party web pages or repository content, because until now a fetched page could reach the parent as unframed text. A related 2.1.277 change reframes workflow script agent() prompts on Bedrock, Vertex and Foundry as script-authored rather than user-authored.
Claude Code 2.1.277 fixes the Edit tool treating an escaped backslash followed by uXXXX text as a unicode escape. An edit of a non-ASCII character could rewrite an escaped backslash sequence instead of the intended target, changing a part of the file the edit was not aimed at.
Why this mattersThis is a silent file corruption path rather than an error, so it would show up as a wrong character in source rather than as a failed edit. Worth checking any file holding literal backslash-u sequences that Claude Code has edited recently, for example regular expressions, JSON string literals and test fixtures.
Claude Code 2.1.277 fixes a headless resume, covering claude -p --resume, the SDK and a VS Code extension window reload, starting the session's cost and usage totals at zero. Headless sessions now save their totals at exit.
Why this mattersThe TypeScript Agent SDK 0.3.277 shipped the matching fix the same day, restoring total_cost_usd, modelUsage and get_usage totals across a resume or fork. One fault in two places, and anyone reconciling spend from headless runs was undercounting on both.
The TypeScript Agent SDK 0.3.277 adds a builtin field on SlashCommand, set when a command is built into Claude Code, and pasted_content on SDKUserMessage, holding text the user pasted rather than typed and appended after the typed prompt. Success result messages gain four remote session latency fields: first_text_post_ms, first_text_post_wall_ms, first_stream_post_queue_wait_ms and first_stream_post_queued_behind. updateSettings() accepts a new userSettings source, which takes only effortLevel and saves it for the session's current model. Its parity line names Claude Code v2.1.277.
Why this matterspasted_content separates typed from pasted input for the first time, which a host that logs or redacts prompts can now act on. The latency fields are the first per-stage timings the SDK has exposed for remote sessions, so queue wait is finally distinguishable from model time without instrumenting the host.
The TypeScript Agent SDK 0.3.277 fixes total_cost_usd, modelUsage and get_usage totals starting at zero on a resumed or forked session, so they now continue from earlier turns. Usage rows in SDKUsageReport always carry the severity and is_active fields.
Why this mattersClaude Code 2.1.277 fixed the same undercount on headless resume the same day. This is the second consecutive run in which one class of fault, output that only a programmatic consumer sees, was fixed on the CLI and this SDK together.
Claude Code 2.1.277 fixes a cloud environment saved with Custom network access and no domains silently reverting to Trusted. The dialog now asks for at least one domain. Before the fix, an administrator who chose the more restrictive option and saved it without listing a domain got the broader policy instead, with no warning.
Why this mattersThis is a network policy failing open on the exact configuration an administrator chose to tighten it. Worth re-checking any cloud environment intended to be restricted, because a reverted one would read as Trusted rather than as misconfigured.
Claude Code 2.1.277 fixes resumed subagents and teammates re-rendering MCP tool definitions, which broke prompt caching for that agent.
Why this mattersThe cost of this scales with the size of the tool catalogue, so a large in-house MCP server pays the most for it. Every resumed subagent was re-sending its full tool definitions uncached.
Claude Code 2.1.277 adds CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY, set to 1 for Claude apps gateways whose only egress is a forward proxy, and an optional headers map on gateway upstreams for sending static headers to a proxy run in front of a provider. The same release fixes the gateway telemetry relay ignoring domains listed in NO_PROXY when a proxy is set.
Why this mattersThe NO_PROXY fix matters beyond configuration tidiness: telemetry was being routed through the proxy for domains explicitly excluded from it.
Claude Code 2.1.277 fixes four separate faults where a malformed value in the user configuration file at ~/.claude.json stopped the CLI working: a bad customApiKeyResponses value hanging or erroring interactive start-up for users on ANTHROPIC_API_KEY, a bad claudeAiMcpEverConnected value crashing /mcp and /plugin manage, a bad theme value crashing at launch, and a malformed placeholder record breaking Remote Control session bookkeeping. A malformed minimumVersion is now ignored rather than erroring every 30 minutes.
Why this mattersFour independent crashes from one file in one release suggests the configuration file is parsed in several places without a shared validation path.
Claude Code 2.1.277 fixes sessions continued after /clear, whether by restart, --continue or --resume, missing part of the first message when a SessionStart hook printed output. The result was a full prompt cache miss.
Why this mattersTwo costs from one fault: a truncated first message, and a cache miss on every continued session. Anyone running a SessionStart hook that prints anything was paying both without a visible error.
Claude Code 2.1.277 fixes project skills from the main repository not loading in --worktree sessions when .claude/skills is untracked. Two related plugin faults are fixed in the same release: reinstalling a plugin version in use by a session or another program could fail and break the installed copy, and plugin reload previews kept every previewed copy unpacked until exit, overwriting the cached --plugin-url archive fallback when a download failed.
Why this mattersAn untracked skills folder is the normal case for personal skills kept out of version control, so this hit exactly the people who keep their skills private to the checkout.
Claude Code 2.1.277 fixes $TMPDIR expanding to an empty value in Bash commands that run outside the sandbox while sandboxing is enabled. A command relying on it would resolve paths from an empty prefix rather than the intended temporary directory.
Why this mattersThis only affects the excluded path, so it is the same area of the sandbox as the compound command exemption fixed in the same release.
Claude Code 2.1.277 changes the Pylon credential preset in Claude Tag access bundles so administrators can point it at Pylon's EU host. The same release fixes routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in the workspace when they ran, corrects the Learn more links on credential presets to open the vendor's own credential setup page, and fixes the network events log in Claude Tag admin settings showing no response status for requests using AWS signing, client certificates or a custom certificate authority.
Why this mattersThe EU host option is a data residency control reaching a connector preset, which is the first of its kind Parity has recorded on Claude Tag. Claude Tag changes continue to be published only on the Claude Code changelog, never on the apps release notes page.
Claude Code 2.1.277 changes the computed agent() prompts in workflow scripts on Bedrock, Vertex and Foundry so they reach the subagent framed as script-authored text, so that the safety classifier does not read them as coming from the user. The same release changes Bash sandbox instructions on those three platforms to first-party wording that frames the sandbox as the boundary of the task's scope.
Why this mattersBoth changes are about provenance rather than capability: making the model's input say correctly who wrote it. They pair with the subagent result header change in the same release, which does the same thing in the other direction.
Claude Code 2.1.277 adds Personal and Organization sections to the environment picker on Team and Enterprise plans, and lets an administrator share a personal environment with the organization. Organization environments now open as a read-only summary from the Code tab on those plans, with editing moved under Admin settings then Cloud environments. The admin Claude Code setting labelled Web is renamed Cloud sessions, and the redundant read-only Mobile row beneath it is removed.
Why this mattersA renamed admin setting is worth noting because written runbooks and screenshots referring to the Web setting no longer match the console.
Claude Code 2.1.277 fixes a single malformed strictKnownMarketplaces or blockedMarketplaces entry silently disabling the entire enterprise marketplace policy. An administrator with one bad entry had no marketplace policy in force and no error saying so.
Why this mattersThis fails open, which is the worse direction for a policy control: the administrator who most needs the policy, the one whose file has an error in it, is the one who silently has none. The desktop app takes the opposite approach to the same situation, refusing to start on a managed settings file it cannot parse rather than running unenforced.
Claude Code 2.1.275 changes scheduled and Run now routine runs so they save data to, and republish the page of, an artifact you can already edit without asking first. Public artifacts, first publishes and deletes still prompt. An unattended run can now overwrite a private page you own with no approval step in between.
Why this mattersScheduled work is managed in two unconnected places, one per surface, which Parity already records as an open gap. This change alters the permission model of one of them without a stated equivalent on the other.
Release 0.3.274 adds a startup_failure_reason field on error results when a stream-json session fails to start, which previously surfaced without a machine-readable cause. The canUseTool option now receives an mcpServer object carrying name and source, and the same source appears on MCP server status rows, so a host can make a trust decision based on where a server was configured rather than on its name alone. Two environment variables arrive: CLAUDE_CODE_MCP_STARTUP_WAIT_MS bounds how long the first turn waits for MCP servers that are still connecting, and CLAUDE_CODE_EMIT_STARTUP_TIMING surfaces startup phase timings in the first system init message. Servers configured through settings files or plugins are no longer waited on at all, leaving only those passed directly in options.
Why this mattersCLAUDE_CODE_MCP_STARTUP_WAIT_MS lands in the Claude Code CLI on the same day in 2.1.274, so the CLI and the TypeScript SDK gain this control together. The Python SDK released 0.2.154 the same day carrying only a bundled CLI bump, and documents neither the environment variable nor the mcpServer parameter, so the list of capabilities the Python SDK is missing grew again today.
Where each completed background task previously triggered its own model call, queued completions are now answered together in a single call, with every result but the last returning empty and reporting no turns. Two message faults are also fixed: getSessionMessages had been omitting messages a user sent while Claude was running a tool, and replayed user messages generated by a background task completion had lost the origin marker identifying them as task notifications.
Why this mattersThe Claude Code CLI ships the same consolidation in 2.1.274 for headless and SDK sessions, so this is one change reaching two surfaces on one day rather than the SDK catching up. For anyone running fan-out work through subagents the effect is a straight reduction in model calls per run, though the size of that reduction depends on how many tasks finish together and is not stated.
The Team and Enterprise admin guide, showing an updated today stamp, states that Claude Design is on by default on Team plans and off by default on Enterprise plans until an owner turns it on. It also separates two admin controls that were not previously distinguished: access inside conversations and the Artifacts tab is switched at Organization settings then Artifacts then Design, while the standalone product is switched at Organization settings then Capabilities. The Claude Design Admin permission, available through custom roles on Enterprise, governs publishing, setting defaults and deleting design systems. Availability is still stated as beta on Pro, Max, Team and Enterprise.
Why this mattersParity had carried the Team default as unconfirmed since 2026-09-09, when a read found that the default it previously held was not supported by the page cited for it. The page now states one, so that open question is closed against this URL rather than by inference. The split into an Artifacts control and a Capabilities control lines up with the merge announcement of 2026-09-16, which says Claude Design now works inside conversations while continuing to work standalone, though neither document references the other.
The admin guide states that Claude Design is available in Claude on web and desktop, in Claude Code, and at claude.ai/design. Two of those four, Claude Code and the dedicated address, are named in this guide for the first time in Parity's reading of it, and the desktop app is now named by both this guide and the getting started article rather than by one of them only.
Why this mattersParity has held a contradiction on this point since 2026-08-17: the getting started article named the desktop app and this admin guide did not, and the dispute survived re-reads on 2026-08-29 and 2026-09-09. The two articles now agree. Claude Design appearing inside Claude Code is a new cross-surface reach that the matrix did not previously record for any surface other than the web and desktop apps.
A new CLAUDE_CODE_MCP_STARTUP_WAIT_MS setting bounds how long the first non-interactive turn waits for MCP servers to connect, with zero meaning do not wait at all. Separately, sessions started with input format stream-json no longer hold the first turn for up to two seconds on connecting servers whose tools are deferred to tool search, and those tools arrive on a later turn instead. A related fault is fixed where passing strict-mcp-config with an empty mcp-config still held the first turn for the full MCP timeout on incidental servers.
Why this mattersThe same environment variable appears in the TypeScript Agent SDK 0.3.274 on the same day, so the CLI and that SDK gain the control together. The Python SDK published 0.2.153 and then 0.2.154 across the same window and documents neither this setting nor the deferred-tool behaviour, which widens the capability list Parity already tracks as missing from the Python side.
Claude Code 2.1.274 stops honouring MCP entries whose type is sdk wherever they appear, covering .mcp.json, settings files, plugins and agent files. Such an entry is now passed over and a warning is emitted, on the stated basis that only an SDK host application can register an in-process server. Anyone who placed one of these entries in a checked-in project config will find that server silently absent rather than failing loudly, so the warning is the only signal that it stopped loading.
Why this mattersThis narrows a configuration route that worked identically across every surface reading these files, so a project config shared between the CLI, the desktop app and Cowork loses the same server in all of them at once. Parity records no equivalent announcement on the desktop or Cowork changelog, so whether those apps adopt the same refusal on their own release schedule is not documented.
Claude Code 2.1.274 fixes connection errors and the MCP login tool description exposing values that had been substituted into an MCP config from placeholder references. Anything held in an environment variable and injected into a server definition, which is the documented way to keep a token out of a config file, could therefore reach an error message and from there a transcript or a shared session.
Why this mattersConfigs of this shape are read by every surface that loads MCP servers, so the exposure was not confined to the CLI, but only the Claude Code changelog records a fix. Parity holds no corresponding entry on the desktop and Cowork changelog, and neither page states which builds carried the fault.
Claude Code 2.1.274 fixes Streamable HTTP tool calls expiring after roughly five minutes even where a longer timeout was configured for that server, which capped any long-running tool regardless of its settings. It also fixes servers declared as http that speak only the legacy HTTP and SSE transport failing when they answer the first request with a 422 or another 4xx, prompts and resources not refreshing when a server sends list-changed notifications without declaring listChanged, and a 403 for insufficient scope being reported as an expired sign-in rather than naming the missing permissions.
Why this mattersThe misreported 403 sent people to re-authenticate for a permission problem that re-authenticating does not fix, which is a diagnosis cost carried by anyone running a large in-house server estate. None of the four is recorded as fixed on the desktop and Cowork changelog, so a Cowork session against the same servers has no documented fix date.
Claude Code 2.1.274 fixes permission checks for commands that loop over or assign certain special shell variables, which now prompt rather than running unchecked, and refuses commands using certain nested shell expansions inside worktree-isolated sessions. Neither the affected variables nor the expansion forms are named, so a reader cannot test their own scripts against the description.
Why this mattersThis is the third release in four days to close escapes in the same component: 2.1.271 fixed four, 2.1.273 fixed two, and 2.1.274 fixes two more. The rate matters more than any single fix for anyone running unattended sessions, because a checker that keeps yielding escapes is not yet a boundary to rely on. Parity records no equivalent fixes on the desktop and Cowork changelog, where the same Bash tool runs inside Cowork sessions.
Claude Code 2.1.274 ends a loop in which a session retried an unexpected tool use id 400 error without limit. Corrupted transcripts are repaired where that is possible, and where it is not the session stops with an error pointing at the rewind command. Two related faults are fixed: a hook-driven session, a goal being one example, ended with a prompt too long error instead of compacting when context overflowed again after a reactive compaction, and an active goal was lost when a compacted session was resumed with continue or resume.
Why this mattersNothing equivalent is recorded on the desktop and Cowork changelog, although goals and compaction exist in Cowork sessions too. A session that cannot recover from its own transcript is the kind of fault that ends an unattended run silently, which is the failure mode that matters most for scheduled work.
Claude Code 2.1.274 fixes a resumed background agent keeping only half of an interrupted tool batch when one call in it had been approved with a message, a local headless resume started with the resume-interrupted-turn variable failing to report background tasks the previous process left unfinished, and background agent notifications claiming no live work remained while the agent was still waiting on its own task and would resume. It also fixes a message sent from a subagent to the main session vanishing from the desktop transcript after a relaunch, and a subagent progress summary being replaced by a long unstructured reply.
Why this mattersResult loss on this path was fixed twice in 2.1.273 and again on five paths here, so the delegation route has been unreliable across consecutive releases rather than in one build. That bears directly on any workflow that fans work out to subagents and reads their returns, because a lost return is indistinguishable from a subagent that found nothing.
Claude Code 2.1.274 stops headless and SDK sessions making a separate model call for every background task that completes. Completions already queued are answered together by a single call. A second change in the same release merges the Monitor tool's two notifications, the script's final output and its exit, into one, which the entry states saves a model turn.
Why this mattersThe TypeScript Agent SDK ships the same consolidation in 0.3.274 on the same day, so this is one change arriving on two surfaces rather than the SDK following the CLI. Both are reductions in model calls per run, but neither entry states a size, and the saving depends on how many tasks finish together, so there is no figure here to plan a budget against.
Claude Code 2.1.274 fixes installed_plugins.json being rewritten almost every time the app started when plugin policy arrives from remote managed settings. The consequence named in the entry is that Claude Desktop reloaded the plugins of every open session each time. A second fix in the same release stops the Bash tool re-sourcing the shell profile after every plugin reload, which the entry describes as a stall of several seconds on the next command, and limits that work to occasions when the plugins' bin directories actually changed.
Why this mattersThe two faults compounded: managed policy triggered repeated reloads and each reload cost a shell profile re-source, so an organisation that centrally manages plugins paid for both. This is a case of an administrative control degrading performance for everyone under it, which no per-surface document would show, because the policy is set in one place and the cost lands in another.
Claude Code 2.1.274 stops a plugin or marketplace directory without a git repository of its own inheriting its version from an enclosing repository, the example given being a git-managed home configuration folder. It also fixes a plugin loaded from a zip being served from a stale extraction after several overlapping reloads, and a top-level schema key in a plugin's hooks file producing an unknown key notice. Plugin and marketplace clones now leave Git LFS files as pointers rather than downloading them, with the entry stating that running git lfs pull in the checkout fetches the content.
Why this mattersThe LFS change alters what a plugin actually contains after installation, so a plugin shipping large assets through LFS now installs without them unless a further step is taken. Parity records no statement of the same behaviour on the desktop and Cowork changelog, which is where an organisation's marketplace plugins are most likely to be installed.
Claude Code 2.1.274 changes installs on Bedrock, Vertex and Foundry, and installs with telemetry disabled, to use the v2 MCP client and to negotiate the 2026-07-28 protocol revision with direct HTTP servers, which the entry says other installs already did. Two opt-outs are published: setting MCP_SDK_GENERATION to v1, or MCP_PROTOCOL_NEGOTIATION to legacy. Anyone on these platforms running a server that only speaks the older negotiation therefore needs one of those settings, and the release names no date on which the opt-outs stop working.
Why this mattersThis closes a split in which the same MCP server behaved differently depending on which model platform Claude Code was pointed at, a difference that was not documented on any cloud integration page. The opt-outs make it reversible today, but a default change with an escape hatch and no stated end date is the shape that becomes a deadline later, so it is worth tracking rather than filing as done.
Claude Code 2.1.274 fixes subagents declared with a model of opus falling back to the session model where the platform model identifier carries no recognisable family, unless a default opus model is named explicitly in the environment. On these three platforms model ids are customer-specific strings rather than published names, so a subagent could quietly run on whatever the session was using while its definition asked for something else.
Why this mattersCost and capability both move when a subagent silently runs on a different model from the one it declares, and nothing in the session output said so. The equivalent routing on the first-party API uses published model names, so this failure is specific to the cloud platforms and appears in no cloud integration document.
Claude Code 2.1.274 adds a claude_code.managed_settings_resolved event reporting which managed-settings sources applied and the state of the policy helper, with redacted settings and digests available by setting OTEL_LOG_MANAGED_SETTINGS to 1. An effort attribute joins the claude_code.llm_request trace span, matching the attribute already on the api_request event. Raw body logging to a directory now writes an index file and adds attributes that tie each response back to its request file and to the transcript message. Telemetry sent through a Claude apps gateway also carries the identity provider subject.
Why this mattersUntil now an administrator could set managed settings centrally but had no telemetry confirming which sources a given device actually resolved, so an unenforced policy looked identical to an enforced one. Parity records no equivalent event on the desktop and Cowork changelog, even though those apps read the same managed settings files.
Claude Code 2.1.275 fixes the update-config command writing Write(path) permission rules, which file permission checks do not match, instead of Edit(path) rules. Any permission rule created through that command for a file path was inert. Check settings files for Write(path) entries that were meant to gate edits.
Why this mattersPermission rule editing through a dialog exists only in the VS Code extension, so users on other surfaces who wrote these rules through the command have no dialog that would have shown the rule was not matching.
Claude Code 2.1.274 carries several changes to the Claude apps gateway, the component enterprises put in front of Claude Desktop and Cowork. The spend limit check now takes one database round trip instead of four, which the entry ties to fewer checks timing out under load. The gateway also warns when a replica holds more open requests than the 256 it forwards upstream at once and logs that limit at startup, stops cutting every open stream on shutdown by allowing in-flight requests up to 25 seconds to finish under a configurable drain timeout, and fixes an unhandled rejection when the database drops a connection mid-check.
Why this mattersNo surface slug is recorded because the gateway is deployment infrastructure sitting between an organisation and several surfaces rather than a surface in the matrix. It is documented only in the Claude Code changelog despite serving Claude Desktop and Cowork, which is a placement worth noting for anyone looking for it under those products.
A store connect timeout setting is added to the Claude apps gateway configuration to lengthen the Postgres connect timeout, which defaults to five seconds, and the boot error when the database is unreachable now names both that setting and the configured timeout. The gateway also attempts its first database connection up to three times before exiting, so a database that becomes reachable a few seconds late no longer fails the boot outright. Sign-in rate limit refusals now explain themselves at the login step and record which limit was hit and which setting changes it.
Why this mattersAs with the other gateway changes, this is recorded without a surface slug because the gateway is not one of the nineteen surfaces. A five second default connect timeout failing a boot is the kind of operational detail that appears in no plan or feature document, only in this changelog.
Claude Code 2.1.274 stops a publish built on an older version being transmitted at all, handing back the newer page to merge instead. Three related changes land with it: the tool no longer asks for approval to update an artifact it will then refuse because the session has not read the latest version, an unsigned session is told so on the first attempt rather than after repeated retries, and a version published elsewhere no longer starts a turn in a local session, with the session learning of it from a later tool result instead.
Why this mattersThe change from refusing after approval to refusing before sending removes a class of prompt that could only ever be answered wrongly. Artifacts are a shared surface between the CLI, the desktop app and claude.ai, but only the Claude Code changelog carries these entries, so the fix date for the other two is not documented.
Claude Code 2.1.274 fixes cloud sessions in Cowork and on claude.ai treating a read of a teammate's artifact as blocked when network access was enabled for the session. The read was refused on the basis of a setting that was not in force, so shared artifacts were unavailable in exactly the collaborative case they exist for.
Why this mattersThis is a Cowork and claude.ai fault documented only in the Claude Code changelog, which is the same placement pattern Parity already records for Claude Tag. Someone looking for it on the Cowork and desktop changelog would not find it, and the Cowork page carries no entry for this.
Claude Code 2.1.274 changes the code review command to use leaner inline review prompts for every model that has no tuned settings of its own, in place of spawning multiple review subagents. Four fixes accompany it: a re-review could leave a fixed finding's thread open when the new review filed a lower-severity note beneath it, reviews that hit a transient GitHub or internal service failure at launch now wait and retry instead of ending in an error, finding text is reworded to state who is affected and what the fix is up front, and a review skipped because of an organisation limit now links the admin page that changes the limit.
Why this mattersDropping to inline prompts for untuned models is a cost and latency reduction that applies unevenly, because it depends on whether the model in use has tuned settings, and the release does not say which models those are. That makes the saving real but unpredictable per model, which is the kind of detail a pricing page will never carry.
Claude Code on the web previously disabled a routine at the first failed check of its owner's GitHub connection. In 2.1.274 it skips the run and keeps retrying for up to 72 hours. The on-hold notice shown when a subscription is paused is also reworded: it now tells the owner to turn the routine back on themselves rather than promising an automatic resume. A separate fix stops editing a routine occasionally causing it to fire twice or re-enabling one that had just been paused.
Why this mattersA scheduled job that switches itself off after one transient failure fails silently, because nothing runs to report the problem. The 72 hour window turns that into a recoverable gap. The correction to the paused-subscription notice is the more consequential half: a routine that promised to resume by itself and did not would leave its owner believing a watch was running when it was not.
Claude Code on the web gains a picker in a cloud session's diff view to compare its changes against any branch rather than only the base branch. Alongside it, git operations that failed with a service unavailable error while a GitHub token was briefly renewing are fixed, as are commits failing with a signing error for a few minutes after session credentials refreshed, sessions flipping back to unread immediately after being marked read, and a toast after saving a routine with an unlinkable GitHub trigger that gave no reason, which now names the cause such as a per-repository trigger limit.
Why this mattersThe wording across this surface is also being standardised: the status output now says Cloud sessions, and the web setup, review and teleport messages say cloud session rather than naming Claude Code on the web. That is a naming change Parity should expect to see echoed on other surfaces before long.
Claude Tag admin settings add a Guests control to the Add channel and Add workspace forms, letting an owner choose Inherit, Allow, Channel only or Restrict at the point of adding rather than afterwards. The fixes cover Claude not replying when another Slack app or bot mentions it, a mention lost when a channel had just been created, a follow-up sent minutes later being folded into the previous message as a silent edit rather than posting as a notifying reply, search failing whenever it was scoped to a single channel, a safety-filter stop resetting a thread's context without saying so, email addresses rendering with a visible protocol prefix, a refusal to watch an organisation-wide Enterprise Grid channel from another workspace in the grid, and the environment picker showing raw identifiers. The live progress checklist is now capped at 2,000 characters and reposted at most every 15 minutes.
Why this mattersThis is 11 more Claude Tag changes on the Claude Code changelog, against a Claude Tag entry on its own documented release notes page dated 2026-06-23, now 86 days old. Parity opened a gap for this placement yesterday and today deepens it rather than changing it. The Guests setting is an administrative control, so it is the kind of fact a Team or Enterprise admin would look for on a plan page and not find.
Claude Code 2.1.274 changes when background commands are stopped: previously a machine under mild memory pressure ended them after 30 idle minutes, and now they are stopped only when memory is critically low, with the debug log recording the reason. The same release adds a visible warning when memory use reaches a critical level, with steps to free memory or restart safely, and fixes a per-turn slowdown when a language server publishes diagnostics across thousands of files.
Why this mattersA long-running background command silently ending after half an hour on a busy laptop is a failure that looks like the command having finished. Adding the reason to the debug log is what makes the difference diagnosable. Nothing equivalent appears on the desktop and Cowork changelog, although Cowork runs background work in the same app.
Claude Code 2.1.274 fixes self-hosted runner sessions returning a 401 on every turn after a few failed token refreshes, a state that persisted until the next scheduled refresh. The runner now keeps retrying and fetches a new token after a 401. A second change has the runner skip a read-only repository the git host refuses at the access check rather than failing the whole session start.
Why this mattersBoth faults turn a transient condition into a dead session, which for a self-hosted runner means the run does not happen and nothing reports it. This mirrors the routine fix in the same release, where one failed check disabled a schedule outright, so two independent paths to silent non-execution were closed on the same day.
Claude Code 2.1.274 adds continuation of the step interrupted by a window reload, labelled in the chat, with a setting to turn it off. The Customize menu gains a Memory entry showing the automatic memory toggles, saved memories and memory folders, and an Instructions entry for editing the instruction files. A lock editor groups setting stops Claude locking the editor groups it opens in. Screen reader navigation now announces each message as being from the user or from Claude, with the tool name on tool steps. Thirteen fixes accompany these, among them overlapping settings writes leaving the user settings file unparseable or dropping a setting.
Why this mattersThe unparseable settings file fix matters beyond the extension, because that file is read by the CLI on the same machine, so a corrupting write from the editor integration degraded the command line tool as well. Parity records this as a single-surface entry only because no other surface documents the same fault.
Claude Code 2.1.275 fixes the rewind command in a forked or background session restoring a zero-filled or truncated file when the session file-history backups could not be fully copied. A rewind intended to recover a file could destroy it instead. The desktop app shipped the same fix in v2.2553.1 the following day.
Why this mattersThis is one change reaching two surfaces: the CLI carried it in 2.1.275 on 2026-09-17 and the desktop app carried it in v2.2553.1 on 2026-09-18, which bundles CLI 2.1.275.
The release dated 2026-09-17 carries 108 enumerated bullets spanning the command line tool, the VS Code extension, cloud sessions, Claude Tag, Code Review, the plugin system, MCP, OpenTelemetry and the Claude apps gateway. Smaller items not covered by the other entries for this release include clickable local file paths doing nothing in editors requiring a file URI, the transcript renumbering ordered lists typed by the user, two faults in the question preview flow attaching or dropping a note against the wrong option, an edit permission preview showing a different location than the approved edit in files containing multi-byte characters, and stop prompt hooks resending their entire prompt on every block, now replaced by a short labelled condition.
Why this mattersThe count is stated as an enumeration of the published bullets rather than taken from any summary figure on the page, and both reads of the page this run agreed on the same twelve version headings with an oldest entry of 2.1.261 dated 2026-09-04. For comparison, Parity enumerated 64 bullets for 2.1.273 two days earlier, so release size on this surface is not steady and a reader budgeting attention by release count will misjudge it.
Claude Code 2.1.275 syncs the skills and plugins enabled on your claude.ai account into terminal sessions signed in with that account. Two new settings turn it off, syncClaudeAiSkills and syncClaudeAiPlugins. This changes what is loaded in a local session based on account state set elsewhere, so a terminal session is no longer described solely by its local configuration.
Why this mattersThis is account state reaching the CLI for the first time. The desktop app and Cowork already took organization plugins from account and device management, but the terminal CLI did not. The ListPlugins tool description was corrected in the same release to say it lists plugins enabled on the claude.ai account rather than plugins installed locally with /plugin.
Claude Code 2.1.275 fixes plugin and marketplace messages, logs and the output of claude plugin marketplace list showing a password or token stored in a git, ssh or marketplace URL. The VS Code extension had the same leak in its Manage plugins dialog, fixed in the same release. Anyone who put a credential in a marketplace URL should treat it as exposed in local logs and rotate it.
Why this mattersBoth the CLI and the VS Code extension leaked the same credential, and the desktop app marketplace allowlists were not named in either fix, so whether the desktop app and Cowork share the behaviour is not stated.
Claude Code 2.1.275 fixes the forward-subagent-text stream-json and SDK output dropping the messages of subagents spawned by a skill using context fork, and of forked skills invoked by a subagent or another forked skill. Any harness reading subagent text out of the SDK was silently losing whole branches of a nested run.
Why this mattersThis affects anything that parses subagent output programmatically rather than reading it in a terminal, so it reaches the Agent SDK and Claude Code together while leaving hosted surfaces untouched.
Claude Code 2.1.275 adds a startup warning when a configured otelHeadersHelper fails, so sessions that silently export no telemetry are noticed. Organizations relying on OpenTelemetry export for oversight could previously have had sessions producing no telemetry at all with no signal.
Why this mattersCowork activity monitoring with OpenTelemetry is documented separately for Team and Enterprise. Whether the Cowork and desktop telemetry path gained the same startup warning is not stated in the desktop changelog for either new build.
Claude Code 2.1.275 fixes several related faults where a saved transcript containing a malformed entry made a session fail to resume or start: malformed task-reminder and at-file attachment entries broke resume, the resume picker preview, resumed background agents and the transcript view; a malformed message entry crashed resume outright; and a malformed message content block stopped sessions starting. The desktop app shipped the same class of fix in v2.2553.1.
Why this mattersOne change reaching two surfaces. The CLI carried it in 2.1.275 on 2026-09-17 and the desktop app in v2.2553.1 on 2026-09-18, which bundles CLI 2.1.275.
Claude Code 2.1.275 fixes Grep, Glob and at-file suggestions hanging or running out of memory on searches that exceed the 20MB output cap, and fixes system ripgrep reporting no matches instead of an error after a flood of warnings. A search that returned nothing could previously mean a failure rather than an empty result.
Why this mattersGrep and Glob are Claude Code and Agent SDK tools. The Cowork and desktop file search path is documented separately and neither new desktop build names an equivalent fix.
Claude Code 2.1.275 adds the signed-in account to Claude apps gateway sign-in: when the gateway names it, you confirm it before the credential is saved, and the status command shows it. The logout command was also updated to end the session on gateways that advertise token revocation, rather than only discarding the local credential.
Why this mattersGateway sign-in is a Claude Code path. The desktop app fixed its own status card in v2.2553.0 the same day, where it had been showing a placeholder account instead of the signed-in identity and deployment name, so both surfaces corrected account visibility in the same 24 hours.
Claude Code 2.1.275 changes Claude in Chrome in auto mode to skip the extension per-site permission check for calls the classifier has approved, as bypass mode already did. This fixes browser_batch returning a permission denial after a redirect, where the new site had not been approved even though the action had been.
Why this mattersThe permission model for Claude in Chrome now differs by the mode the caller is in, and the change was published in the Claude Code changelog rather than on the Claude in Chrome article, which has carried nothing since 2025-12-18.
Claude Code 2.1.275 improves prompt caching for a system prompt containing a dynamic boundary marker line: the text above the marker is now cached globally, matching behaviour the SDK array form already had. This reduces cache misses for harnesses that assemble a system prompt with a stable prefix and a changing suffix.
Why this mattersThe SDK array form already behaved this way, so this closes a gap between the command line system prompt and the SDK rather than opening one.
Claude Code 2.1.275 adds attach conditions for access bundles in Claude Tag settings, letting an Owner allow a bundle to apply in channels containing guests or in Slack Connect channels rather than member-only channels. This widens where a bundle credential can be used, so the conditions are a governance control rather than a convenience.
Why this mattersClaude Tag changes continue to be published only in the Claude Code changelog. The Claude Tag entry on the unified apps release notes page is now 87 days old, and eleven more Claude Tag changes landed here today.
Claude Code 2.1.275 adds Amazon CloudWatch, CloudWatch Logs, Amazon SNS, Google Cloud Monitoring and Cloud Logging presets to the Credentials tab of a Claude Tag access bundle, and adds Datadog presets for the US3, AP1, AP2 and US1-FED sites. New Datadog connections are now limited to the Datadog read and query API routes, so a new connection is narrower than an old one.
Why this mattersThe Datadog restriction applies to new connections. Nothing in the entry states that existing Datadog connections are narrowed, so an organization may hold connections at two different permission levels.
Claude Code 2.1.275 fixes Code Review occasionally dropping part of its analysis when one of the reviewing agents returned findings in an unexpected format, and fixes pull requests with more than 100 Claude reviews getting a full re-review on every clean merge from the base branch instead of the lighter merge-focused review. The first of these means a review could have been silently incomplete.
Why this mattersCode review is listed on the beta index as a beta feature. The index itself is still dated 7 July 2026.
Claude Code 2.1.275 adds a send-now key, ctrl and enter or the ctrl-x ctrl-s sequence, which interrupts the current turn and sends every queued message at once. Sent and queued messages now show in gray until the model receives them. The VS Code extension separately changed a message sent while Claude is working to wait at the bottom of the conversation until Claude starts on it.
Why this mattersQueued message handling now differs between the terminal, where a key sends the queue immediately, and the VS Code extension, where a queued message waits.
Claude Code 2.1.275 changes the Artifact tool to ask for a one-word tab icon on a first publish instead of an emoji favicon, and to update a shared artifact in place when the user has edit access rather than publishing a separate copy. It also fixes artifact updates failing with a file not found error after a session resumes on another machine or its scratchpad is cleared, by restoring the last published version of the page.
Why this mattersArtifacts are governed on Team and Enterprise through Organization settings then Artifacts, where Design, Slides and Docs each now have their own toggle. The changelog entry names no admin control.
Claude Code 2.1.275 adds accept and reject buttons under each change in the VS Code proposed-change diff tab, so an edit can be reviewed change by change rather than as a whole, and adds viewing, editing and deleting a saved memory inside the Memory dialog. It also fixes rewound and forked conversations not keeping the permission mode chosen for the original conversation.
Why this mattersThe permission mode fix matters beyond the extension: a forked conversation silently reverting to a different permission mode is a governance fault, not a display one. Hooks and permission rule editing through a dialog remain VS Code only, which Parity already records as an open gap.
Claude desktop v2.2553.0 adds allowedPluginMcpServers. When it is set, Cowork, Chat and Code sessions connect only the plugin MCP servers whose URL matches an entry, and an empty list allows none. It applies in addition to managedMcpServers and organization plugins, and takes effect even when managedMcpServers is empty. The app also stops starting plugin MCP servers on the device, except those from organization plugins. The Setup window can now author an empty list for this key and for allowedWorkspaceFolders.
Why this mattersThis is a third managed key governing MCP servers alongside the two spellings of managedMcpServers that Parity already records as an open gap. It is a desktop and Cowork control with no stated Claude Code CLI equivalent, so a terminal session on the same machine is not covered by it.
Claude desktop v2.2553.0 fixes Plan mode skipping permission prompts when the Bypass permissions option is on and the session fell back to an older bundled Claude Code CLI while an update downloaded. Plan mode is the mode users rely on to review before anything executes, so a window in which it did not prompt is a permission fault rather than a display one. The trigger was a transient state during an update download, which makes it hard to notice after the fact.
Why this mattersThe fault needed a version skew between the app and its bundled CLI, a condition that exists on the desktop app and Cowork and does not arise on a standalone Claude Code install.
Claude desktop v2.2553.0 changes inferenceFoundryResource so that a value delivered by a bootstrap URL the user configured themselves, in Settings or a local configuration file, asks that user to approve it before it takes effect, matching how the Foundry base URL and other provider endpoints already behave. Declining quits the app. Because the resource name is required, each such Foundry install prompts once after updating. Values delivered through device management, or by a bootstrap URL that device management set or that trustBootstrapDelivery covers, are unchanged and never prompt.
Why this mattersThis aligns Foundry with the approval behaviour Parity already records for the other provider endpoints, closing an inconsistency inside the cloud integrations rather than opening one.
Claude desktop v2.2553.0 adds inferenceCredentialHelperWindows, the absolute path of the credential helper executable on Windows devices, used there instead of inferenceCredentialHelper. One managed configuration can now serve Windows alongside macOS or Linux devices without separate policies. The same build also fixes the app repeatedly re-fetching its configuration and re-testing the inference connection while the provider rejects the configured API key.
Why this mattersThe duplicate model listing fix in the same build is worth noting beside this: a gateway returning both an id and its 1M-context variant was listing the model twice, and the pair now shows as the model and its 1M-context row.
Claude desktop v2.2553.0 replaces the old Skills, Plugins and Connectors tables in Settings with a full Customize page, giving each list a search box, an Add menu and a page per item. Memory moved under Settings. The same build fixes plugins past the first hundred in a marketplace not opening from Customize, re-enabled plugins sometimes turning themselves back off, new sessions sometimes starting without a plugin shown as enabled, and plugin skills referencing the plugin root or skill directory variables running with those paths blank.
Why this mattersThe plugin reliability faults fixed here are desktop and Cowork specific. The Claude Code CLI plugin faults fixed on the same day were different ones, so the two surfaces were failing in different ways at the same time.
Claude desktop v2.2553.0 adds file viewing to cloud sessions, so file links in the transcript open in the app, the Files pane can search the session files, and the Background tasks panel shows background command output. The same build fixes sessions that stopped accepting messages after a relaunch or a sleep, turns failing hours in with an expired OAuth token, slow starts in large repositories, and update restarts ending Code tab sessions and MCP servers abruptly instead of shutting them down cleanly.
Why this mattersFile viewing in cloud sessions narrows a difference between local and cloud Cowork sessions. The built-in browser remains desktop only, so the two session types are still not equivalent.
Anthropic announced a redesigned projects experience that moves from a folder model to a conversation model, with a coordinator directing multiple threads, shared memory for project details and working style, a project library for artifacts and files, delegation to subagents, and repository integration covering pull requests and test runs. It is in beta for selected Claude Pro and Max subscribers who use cloud sessions in Claude Code and who have no existing projects on web or desktop. Access expands to more Claude Code users on those plans over the coming week, with updated projects across Claude and the Team and Enterprise plans after that. Existing projects are unchanged. Local execution is described as coming very soon.
Why this mattersThis announces a rollout rather than a shipped state. It names no setting, no console location, no toggle, no admin control, no date for Team or Enterprise, and no date for local execution. Nothing in the capability matrix was moved on the strength of it. It is also the second major announcement in two days scoped to Pro and Max first, with Team and Enterprise following on an unpublished schedule.
TypeScript Agent SDK 0.3.275 fixes deferred tool call results being emitted with an internal key name rather than the documented SDK form, and fixes UUID validation rejecting client-provided values that do not conform to the standard UUID format. The first of these means a consumer parsing deferred tool results against the documented shape was reading the wrong key.
Why this mattersThe Python SDK published 0.2.155 and 0.2.156 in the same period, both carrying only bundled CLI bumps and neither documenting these fixes. The gap between the two SDKs widened again, entirely on the TypeScript side.
TypeScript Agent SDK 0.3.275 fixes getSessionMessages and forkSession missing turn assistant messages when called immediately after a turn completes, fixes forkSession rejecting message IDs that getSessionMessages itself returned, and fixes getSessionMessages omitting task notifications and queued messages, restoring them to their correct position in the conversation sequence. Anything that read a session back programmatically could get an incomplete history.
Why this mattersClaude Code 2.1.275 shipped a related fix on the same day, where forked-skill subagent messages were being dropped from stream-json and SDK output. Both concern output that a programmatic consumer reads and a terminal user would not notice.
Claude Code 2.1.275 changes npm-source plugin installation to fetch with npm pack and the ignore-scripts flag, and to verify integrity. Previously installing a plugin from an npm source ran that package install scripts on the machine. This closes an arbitrary code execution path that opened at plugin install time rather than at plugin use time.
Why this mattersThe skill and plugin scanning article does not name install-time script execution among the things it inspects, so a scanned plugin was not thereby checked against this path.
Claude Code 2.1.275 fixes SubagentStop hooks configured with a specific matcher firing for every stopping subagent whose agent type was empty. A hook scoped to one agent type was running far more often than its configuration said it would.
Why this mattersLifecycle hooks are documented for Claude Code and the Agent SDK. The Managed Agents documentation describes no equivalent interception hook, so a scoped hook firing too widely has no counterpart to compare against on a hosted surface.
Claude Code 2.1.275 fixes sandboxed Bash commands on Linux reporting exit code 0 for failed commands when the shell is zsh. Any automation that branched on the exit status of a sandboxed command on a zsh Linux machine was reading a success that had not happened. The same release also fixes sandboxed Bash being unable to write to project directories named hooks or config.
Why this mattersSandboxed execution is documented for Claude Code and the Agent SDK. No hosted surface documents an equivalent sandbox profile, so there was nothing to check a silent success against.
Claude Code 2.1.275 fixes cloud environments with a very long allowed-domains list saving without complaint and then failing every session start. Saving now fails up front and says how much to trim. The failure mode was a configuration that looked accepted and was not.
Why this mattersThis is specific to Claude Code on the web cloud environments. The Cowork and desktop changelog documents no equivalent per-environment allowed-domains list, so the failure mode does not arise there.
Claude Code 2.1.275 adds a marketplace option to the plugin install command, which offers to add the marketplace before installing the plugin. Previously the marketplace had to be added as a separate step first.
Why this mattersThe Claude Code CLI and the Claude desktop app each maintain their own plugin marketplace allowlist with different semantics. This change adds a CLI install path and the desktop changelog names no equivalent.
Claude Code 2.1.275 fixes three Claude Tag faults: a model switched to inside a Slack thread silently reverted to the channel default after that thread session restarted, a thread display name reverted from the task-specific form to plain Claude after a refresh, and Claude sometimes replied twice when another app or bot mentioned it in a top-level channel message. It also fixes S3 uploads from recent AWS tooling failing with a 502 through an AWS connection.
Why this mattersThe silent model revert means a Slack thread could run on a different model than the one the user selected, with no notice. No other surface changelog describes an equivalent silent revert.
Claude desktop v2.2553.0 adds builtinBrowserEnabled, which offers a built-in browser in Cowork and Code sessions, together with builtinBrowserDefaultDomainPolicy, builtinBrowserAllowedDomains and builtinBrowserBlockedDomains to control which sites Claude may open in it. This is the first per-domain control Parity has recorded for the built-in browser.
Why this mattersThese are managed configuration keys and the entry states no default value for any of them. The Cowork browsing articles still do not state a current Enterprise default for either the built-in browser or the Chrome extension, so the default remains undocumented. The built-in browser is also desktop only, so a cloud-only Cowork session has neither the browser nor these controls.
Claude desktop v2.2553.0 fixes a routine created with every connector removed still using all of the account connectors. A scheduled unattended run therefore had access to data the person setting it up had explicitly taken away. Anyone who narrowed connectors on a routine before this build should re-check what that routine could actually reach.
Why this mattersA scheduled unattended run therefore had access to data the person setting it up had explicitly removed. The Claude Code changelog names no equivalent fault or fix for routines on that surface, and scheduled work is configured separately on each.
Claude desktop v2.2553.0 fixes a Bash entry in disabledBuiltinTools or builtinToolPolicy not applying to PowerShell commands on Windows PCs without Git for Windows installed. A Bash glob entry is now treated as the plain Bash entry. An administrator who disabled Bash through managed configuration was not disabling command execution on those machines.
Why this mattersThis is a Windows-specific hole in a managed policy key. The Claude Code changelog names no equivalent fix, so whether the CLI shared the behaviour on the same machines is not stated anywhere.
Anthropic says the separate Cowork and chat experiences are being brought together into one product called Claude, reached through the web, desktop and mobile apps. Pro and Max plans get the combined interface first, described as arriving over the coming weeks, with Team and Free to follow and no date given for either. Enterprise organisations are promised at least 30 days of notice before anything changes for them. Existing chats, projects, artifacts, connectors and skills are stated to carry over. No setting name, admin control or toggle is named anywhere in the announcement, so what an Enterprise admin will actually be asked to decide is not documented yet.
Why this mattersThis is an announcement of a rollout, not a shipped state, so nothing in the matrix is moved on the strength of it. Parity records Cowork desktop and Cowork web and mobile as different products, and records plugin subagents and hooks as executing only inside Cowork. Neither of those is closed by this post: it names no build, no version and no setting, and the rollout has not reached Team, where most of the gating questions sit.
Two products Parity has never held a row for appear in the merge announcement: Claude Docs and Claude Slides, both described as new that day and both stated as beta on paid plans. Claude Design, which Parity does track, is said to work inside a conversation rather than only as its own surface, while continuing to work as before for people who use it standalone. The post says Enterprise admins choose when to turn each of the three on, but names no setting, no console location and no permission. Neither Docs nor Slides has a documented plan table, admin control or availability date beyond the words paid plans.
Why this mattersParity tracks nineteen surfaces and two more have just shipped, so the matrix does not cover them at all. No surface slug is recorded for this entry rather than inventing one for products whose boundaries are not yet documented. Claude Design is the only one of the three with existing matrix rows, and its recorded beta availability on Pro, Max, Team and Enterprise is unchanged by the post.
Desktop v2.110.0 fixes scheduled tasks silently not running after the provider sign-in, with AWS IAM Identity Center named as the example, had expired. They now wait and run once sign-in is renewed, and a notification appears when a task could not start. Until this release an expired provider credential stopped scheduled work with no notification at all.
Why this mattersThis is the second scheduled-task reliability fix published today. Claude Code 2.1.273 fixed saved tasks running in the wrong session after the task file was copied into another folder. Both are failure modes that only show up on unattended runs, where nobody is watching for the task that did not fire.
2.1.272 is dated 15 September 2026 and its only changelog line describes bug fixes and reliability improvements. No fault, setting or symbol is named, so there is nothing a repository scanner can match and nothing specific to check against a codebase. The TypeScript Agent SDK published 0.3.272 against it, carrying a parity line and no substantive change of its own.
Why this matters2.1.272 has no counterpart in the desktop app, which still bundles 2.1.270 as of v1.52386.6.
Claude Code 2.1.273 fixes allowManagedMcpServersOnly, deniedMcpServers and disableClaudeAiConnectors being ignored when they were set through MDM or managed-settings.json and server-managed settings were also in play. An administrator who set any of these three to restrict MCP access had them silently not applied in that configuration. The settings were present and the restriction was not in force.
Why this mattersAll three keys are Claude Code settings. The desktop app carries its own managedMcpServers and orgPluginSettings controls, changed separately in v2.110.0, and Parity holds no statement that the desktop app had the same defect.
Claude Code 2.1.273 fixes Bash commands the permission checker cannot fully analyse skipping the prompt under permissions.blockReadsOutsideWorkingDirectories, and a subshell that hid a dangerous rm from bypass mode. This is the fourth consecutive release carrying permission checker escapes of the same shape: the rule is configured, the session looks normal, and the command runs anyway. There is no symptom to notice, so the only remedy is to update.
Why this mattersClaude Code has now shipped Bash permission checker escapes in 2.1.269, 2.1.271 and 2.1.273. Parity holds no equivalent published fix for the desktop app or Cowork, whose sessions run the same Bash tool, and the desktop changelog for v2.110.0 names none.
Claude Code 2.1.273 fixes skills synced from claude.ai remaining available after the organisation turned Skills off. They now move to the recoverable trash instead. Until this release, an administrator disabling Skills for the organisation did not remove skills already synced to a device, so the control did not take effect where the skills already were.
Why this mattersThis is the second sync-lifecycle defect of this shape in two days. Parity published on 2026-09-14 that skills synced from claude.ai stayed on disk indefinitely after signing out. That covered sign-out, this covers the organisation disabling Skills, and they are separate paths.
Claude Code 2.1.273 fixes two independent faults that discarded completed subagent work. Sub-agents and background agents were reported as failed, with their result never delivered, when the final streamed reply omitted token usage or carried no model id. Separately, SDK output and --output-format stream-json dropped a subagent remaining messages and its final report after the subagent was moved to the background mid-run, for example by CLAUDE_AUTO_BACKGROUND_TASKS. In both cases the work completed and the caller did not receive it.
Why this mattersBoth faults sit in the subagent delivery path shared by Claude Code and the Agent SDK. Any orchestration that fans work out to subagents and reads their final reports is exposed, including scheduled and unattended jobs where nobody is present to notice a missing result.
Claude Code 2.1.273 fixes the context meter and auto-compact counting advisor-tool turns at roughly twice their real context size. The effect was that auto-compact fired at about half the real window, so sessions were compacted earlier and more often than the configured threshold implies, and the displayed context meter overstated usage.
Why this mattersCompaction behaviour is where Claude Code and the Messages API moved in the same week: the Messages API added on-demand compaction under the compact-2026-09-04 beta header on 2026-09-14, published separately today.
Claude Code 2.1.273 reverts a change made in 2.1.268 that checked Read and Edit deny rules against Bash lines the permission checker cannot analyse, such as those using eval or env -C. Commands of that shape now prompt for approval again rather than being denied outright. Anyone who adopted 2.1.268 on the strength of its deny behaviour should note that the behaviour is withdrawn, not merely relaxed: a deny rule that was catching these lines stops catching them on upgrade.
Why this mattersThis is a rollback of a security posture Parity published on 2026-09-11 from Claude Code 2.1.268. Recorded here because a withdrawn control is a change in its own right, not an absence of one.
Claude Code 2.1.273 adds the request headers x-claude-code-request-class, x-claude-code-agent-type, x-claude-code-prev-tool-durations, x-claude-code-compaction and x-claude-code-context-compacted for LLM gateways. They are opt-in through CLAUDE_CODE_GATEWAY_HINT_HEADERS=1. A gateway can use them to tell apart request classes, agent types and compaction state, which previously arrived indistinguishable.
Why this mattersRelevant to any deployment routing Claude Code through a gateway. The desktop app added its own Foundry gateway routing key, inferenceFoundryBaseUrl, in v2.110.0 on the same day, which is the same theme approached from the deployment side.
Claude Code 2.1.273 allows forking a session that was started with claude --remote-control or /remote-control from the Claude app. The fork runs as a background session on the local computer rather than continuing remotely.
Why this mattersSession forking previously appeared in Parity as an Agent SDK and CLI capability. This extends it to the Remote Control path, where the controlling surface is the Claude app and the executing surface is the local machine.
Claude Code 2.1.273 changes auto mode on Bedrock, Vertex and Foundry to use the local classifier by default for now. The platform server-side classifier is available on those providers by setting CLAUDE_CODE_AUTO_MODE_SERVER=1. The changelog describes the local classifier as the default for the time being, without giving a date for the position changing.
Why this mattersThis opens a behavioural difference between the cloud integrations and first-party access, where the server-side classifier remains the default. Auto mode approval decisions can therefore differ for the same command depending on which provider a session runs against.
Claude Code 2.1.273 fixes saved scheduled tasks running in the wrong session after .claude/scheduled_tasks.json had been copied into another folder, such as a new worktree. A copied working tree therefore ran its scheduled work against the original session rather than its own.
Why this mattersDirectly relevant to anyone running scheduled or unattended work from a repository that gets cloned into worktrees. The desktop app changed scheduled tasks in the same day release, adding the scheduledTasksEnabled kill switch, published separately.
Two scope changes in Claude Code 2.1.273. Signing in with a Claude account now also requests access to that account claude.ai plugins, which is a wider grant than the previous sign-in asked for. Separately, /bug and /feedback reports now include only model-behaviour parameters from the last API request, meaning model, system prompt and tools, and omit request metadata and CLAUDE_CODE_EXTRA_BODY fields. The second narrows what a feedback report sends, the first widens what sign-in asks for.
Why this mattersCLAUDE_CODE_EXTRA_BODY is where deployments put provider-specific request fields, so its removal from feedback reports matters most to gateway and cloud integration users.
Claude Code 2.1.273 carries ten Claude Tag items. The behavioural one: Claude now starts watching related public channels on its own, such as an incident channel a conversation depends on, rather than only when asked. The rest are fixes. Claude went silent minutes after reinstall when an Enterprise Grid was disconnected but one of its workspaces stayed connected. Scheduled tasks created in an organisation-shared private Slack channel silently never posted. Replying in an older thread while Claude was mid-task sometimes restarted it and lost unpushed work. A message could be dropped with an incorrect notice about no Claude Code environment right after a token refresh. AWS connections refused region-less endpoints including Budgets, Savings Plans, WAF Classic and Import and Export, and Global Accelerator requests now sign correctly, with a clearer failure message when a request cannot be signed. OAuth client-credentials and JWT-bearer connections failed against providers returning a lowercase token type, and now send the standard Bearer scheme. Adding a channel manager was refused on Enterprise Grid shared channels, on channels where Claude had not been used, and on legacy private channels. The admin Memory page did not list channels Claude set up on its own even when they held saved memory.
Why this mattersThis is the cross-surface finding of the day and it has now repeated three times. Claude Tag changes are being published in the Claude Code changelog, not on the Claude apps unified release notes page, which is the documented home for Claude Tag and has carried nothing about it since 2026-06-23, now 85 days. Parity published ten Claude Tag changes from the same source on 2026-09-11 and five more on 2026-09-15. An administrator watching the documented page would have seen none of them. The self-initiated channel watching is the item that most deserves the documented page, because it widens where Claude reads without an explicit instruction.
Claude Code 2.1.273 carries six Code Review changes. A whole REVIEW.md was being ignored because of an at-mention, a code span wrapped across lines, or a backticked HTML tag, so a repository review policy could be silently inert; only lines linking to changed files are now withheld. Merging the base branch into a pull request whose earlier review listed additional findings triggered a full re-review, and now gets the lighter follow-up review. Empty or content-identical pushes were re-reviewed on repositories whose owner or name contains a capital letter, and are now skipped. /ultrareview --post posts its findings comment exactly once after a GitHub error, where a retry previously posted it never or twice, and the comment now names the reviewed commit. Suggested fixes now state what the fix must keep working when other code depends on the behaviour being changed, and a comment pointing at a second affected location states that location issue as a full sentence rather than a cut-off stub.
Why this mattersThe REVIEW.md parsing fault is the one with a silent failure mode: the file was present, the policy looked configured, and none of it applied.
Claude Code 2.1.273 moves the admin Share cloud sessions setting out of the Claude Code page and under Data and privacy, where Data and privacy admins can also manage it. An organisation looking for that control in its previous location will not find it, and the set of administrators who can change it is now wider. The same release reworks the Claude Code on the web routine detail page, putting menu and rename in the breadcrumb and the on and off switch and Run now at the top, adds a confirmation before the New routine page or Edit routine dialog discards a typed name or prompt, removes the full-page desktop app download screen new users saw on Mac and Windows, fixes routines losing access to an organisation connector and still calling the old one after an admin removed and re-added it, and fixes self-hosted environment creation occasionally failing and leaving a half-created environment behind.
Why this mattersThe connector fault matters to anyone rotating organisation connectors: a routine kept calling the removed connector rather than failing, so the rotation appeared to work while the old path stayed live.
Claude Code 2.1.273 improves the Artifact tool on four points. A publish whose connection drops after reaching claude.ai is re-sent safely instead of failing or creating a duplicate version. An artifact database update can remove a single field instead of rewriting the whole document. A publish including a file type artifacts do not serve now tells Claude which types are served and what to do instead, with one plain line in the terminal. The page read now states the capabilities and database rules the artifact service holds for that page, for anyone able to publish to it. Auto mode also no longer stops for approval when the Artifact tool uploads a file already attached to the chat in a cloud or Remote Control session.
Why this mattersParity published on 2026-09-14 that artifact watching doubled to ten and Markdown artifacts render as document pages. The Artifact tool has now changed in two consecutive Claude Code releases.
Claude Code 2.1.273 fixes permissions.blockReadsOutsideWorkingDirectories so that a memory directory chosen by a repository own settings is no longer loaded into the prompt, recalled, indexed, or used by memory extraction. Until this release a repository could point the memory directory outside the working directories and have its contents read in, past a setting whose purpose is to stop exactly that.
Why this mattersThis is a repository-controlled path reaching past a device-level restriction, so it matters most where repositories are cloned from outside the organisation. Parity holds no equivalent statement for the desktop app or Cowork memory handling.
The Claude desktop app released v2.110.0 on 2026-09-15, immediately after v1.52386.6 of 2026-09-13. The changelog entry gives no explanation for the version scheme change, states no migration or breaking change, and, unlike every preceding entry Parity holds, names no bundled Claude Code CLI version. The previous release stated it bundled Claude Code 2.1.270. The entry is large, covering General, Code, Cowork and third-party deployment sections.
Why this mattersThe bundled CLI version line is what Parity has used to tell how far the desktop app trails the Claude Code CLI, and it is absent here. As of this release the lag between the desktop app and the CLI, which stood at two releases yesterday with 2.1.271 and 2.1.272 shipped since v1.52386.6, cannot be read from the changelog at all. Recorded as an absence of a stated fact, not as a claim that the app bundles nothing.
Desktop v2.110.0 adds model catalog support. Model names, descriptions and thinking or effort options in the model picker now follow the published Claude Code model catalog, matching what first-party users see, with a configured model list and order unchanged. By default the app fetches the signed catalog from downloads.claude.ai, the host it already uses for workspace and Claude Code downloads, every 5 to 15 minutes, and keeps the last catalog it fetched, or the copy bundled with the app, when that host cannot be reached. Setting modelCatalogEnabled to false keeps the built-in labels and makes no catalog request. Setting modelCatalogUrl fetches the catalog and its signature file from a mirror inside the network instead, and the document is still verified against the key built into the app.
Why this mattersThis adds a recurring outbound request on a schedule to a deployment that may not have expected one. For an air-gapped or egress-restricted deployment the two controls are the relevant ones: modelCatalogEnabled to stop the request, modelCatalogUrl to point it inside the network. The signature verification is against a key built into the app, so a mirror does not weaken the document authenticity.
Desktop v2.110.0 adds scheduledTasksEnabled. Setting it to false turns off scheduled tasks in both Cowork and Code: the Scheduled page is hidden, existing tasks stop running, and Claude can no longer schedule new work. The changelog states existing tasks stop running rather than being deleted.
Why this mattersThis is an organisation-level kill switch over work that runs unattended, so it is the setting most likely to stop a scheduled job without anyone present to see it happen. Claude Code changed scheduled tasks in the same day release, fixing saved tasks running in the wrong session after the task file was copied into another folder. Parity holds no Claude Code equivalent of scheduledTasksEnabled itself.
Desktop v2.110.0 changes Chat to stop asking for approval when Claude hands back a file it produced and, with advanced file analysis on through chatAdvancedFileAnalysisEnabled, at each step of analysing an attached file. The changelog states this matches Cowork behaviour. Connector actions still ask. To keep the per-step prompt in both Chat and Cowork, add "Bash": "ask" to builtinToolPolicy.
Why this mattersThis closes a gap between Chat and Cowork by moving Chat to the looser of the two positions rather than the tighter. Anyone who relied on the per-step prompt in Chat as a review point loses it on upgrade unless builtinToolPolicy is set explicitly, and the changelog names that key as the way to keep the old behaviour.
Desktop v2.110.0 changes MCP tool permissions three ways. Entries in managedMcpServers and orgPluginSettings now apply to MCP servers from any installed plugin, including ones that run locally, where previously a plugin-provided server could sit outside those controls. A managedMcpServers entry can use transport set to policy-only to set tool permissions for a server a plugin provides, without declaring how to launch it. Permission rules now also apply to tools whose names contain characters such as dots or spaces, which previously escaped matching.
Why this mattersThe third item is the one with a silent failure mode: a tool whose name contained a dot or a space was not matched by a permission rule, so a rule written to cover it did not. Parity holds an open question on whether the Claude Code managedMcpServers setting shares a schema with the desktop setting of the same name, and this release widens the desktop side of that comparison without settling it.
Desktop v2.110.0 adds three model effort controls. defaultModelEffort sets the effort level the default model starts at. maxEffort on an inferenceModels entry hides that model higher effort levels and holds Code sessions to the cap. alwaysStartWithDefaultModel starts every new conversation or task on the default model and stops saving a person model and effort changes as their default. The Code tab also now uses the standard model picker, with effort as its own control beside the model name.
Why this mattersmaxEffort is a cost control expressed as a capability limit, which is the shape an organisation wants for capping spend without blocking a model outright. The changelog states the cap holds Code sessions, so it reaches the CLI surface inside the app rather than the chat surfaces alone.
Desktop v2.110.0 changes SSH connections in Code sessions on macOS and Linux to run through the OpenSSH ssh program on the device by default, so the organisation own SSH setup applies, with Kerberos sign-in and ssh_config options named as examples. Setting sshTransport, marked beta, to builtin keeps the app built-in SSH library. The same release keeps SSH and WSL sessions running when left idle in the background instead of stopping them, and fixes those sessions stalling for up to 10 minutes after each reply while the desktop app was closed or the computer was asleep.
Why this mattersMoving to the device OpenSSH means an existing ssh_config, jump host or Kerberos configuration now applies where it previously did not, which changes behaviour for managed fleets in both directions: correct configurations start working, and restrictive ones start biting.
Desktop v2.110.0 adds three deployment settings. inferenceFoundryBaseUrl routes Azure AI Foundry requests from Chat, Cowork and Code through a gateway or proxy the organisation runs instead of the resource own endpoint, and takes the same value as the Claude Code ANTHROPIC_FOUNDRY_BASE_URL variable. inferenceCredentialHelperArgs passes a list of arguments in order to the inferenceCredentialHelper script, so one installed script can serve several environments; when unset the script runs with no arguments as before. redirectHost is added to bootstrapOidc, to inferenceGatewayOidc for interactive gateway sign-in, and to inferenceVertexWorkforceOidc for Vertex workforce sign-in, for organisations whose identity provider only accepts localhost in a registered redirect URI. The default remains 127.0.0.1.
Why this mattersinferenceFoundryBaseUrl is explicitly aligned with the Claude Code ANTHROPIC_FOUNDRY_BASE_URL variable, so this is one of the few places where the desktop app and the CLI document the same value under different key names rather than diverging.
Desktop v2.110.0 adds a chromiumFlags setting in claude_desktop_config.json for GPU-related switches such as --disable-gpu, applied before graphics start up. The changelog names Microsoft Store installs specifically, where command line flags cannot be passed, so this is the only route to those switches there. The same release changes the error screen shown after repeated crashes or failed starts to say what happened and offer a Restart Claude button, and makes crash recovery wait progressively longer between retries instead of retrying immediately.
Why this mattersParity holds no equivalent setting for Claude Code, which is not a graphical application, so this is desktop-specific rather than a gap.
Desktop v2.110.0 fixes five Cowork faults. Browser, computer use and website access permission prompts in Dispatch were sometimes being denied on their own before anyone could answer. Deleting a file failed with an error about not finding a mount for the path when two connected folders shared a name, and Claude could see the wrong files in a newly connected folder named .claude. Cowork tasks were unable to read or update existing artifacts. On Windows, some tasks failed to start, a task could appear to start when the drive could not be reached and now stops with a clear error, mapped network drives no longer hold up startup, and projects now load and save on virtual desktops using profile containers such as FSLogix. Reconnect on an enterprise-managed connector did nothing when an SSO session had expired, and now signs the user in again with SSO.
Why this mattersA permission prompt that denies itself before it can be answered is a fail-closed behaviour, so it blocked work rather than allowing it. This is separate from the Windows file access defect Microsoft fixed in KB5129195, which Parity published on 2026-09-15.
Desktop v2.110.0 changes the Cowork workspace log and other native log files on macOS to be written to ~/Library/Logs/Claude-3p, with the rest of the deployment logs, instead of ~/Library/Logs/Claude. Any log collection, retention rule or support process pointing at the old directory will find nothing new there after this release.
Why this mattersSmall but deterministic: the path changed, so a collector pinned to the old one silently stops gathering rather than erroring.
An entry dated 2026-09-15 announces Salesforce in Claude, a plugin bringing a seller accounts, opportunities and pipeline into Claude, with 37 pre-built sales skills. Named example tasks are preparing a call, reviewing a deal, creating a pipeline dashboard and sending a forecast. It is available in beta on all paid plans, but only for organisations that Salesforce approves through its own beta sign-up, so the plan alone is not sufficient to reach it. The entry does not state which Claude surfaces it runs on.
Why this mattersThe gating is unusual and worth recording precisely: availability is on all paid Claude plans, and admission is controlled by Salesforce rather than by Anthropic. Parity holds no other connector or plugin whose access is granted by the third party rather than by plan or by an organisation owner.
The Python claude-agent-sdk released 0.2.153 on 2026-09-15, its first release since 0.2.152 on 2026-09-02. It adds a snapshot field to SystemPromptPreset and SystemPromptCustom. When enabled, the session keeps the system prompt recorded on its first request, which improves prompt-caching behaviour across resumed sessions. When disabled, the prompt is reconstructed on each request, which suits iterating on appended text. The changelog states it requires CLI v2.1.257 or higher.
Why this mattersRelevant to any long-running or resumed session paying for prompt cache misses, which is the shape of a scheduled agent job. Parity holds no equivalent snapshot field in the TypeScript SDK, so this is a capability Python has and TypeScript is not documented as having, which is the reverse of the usual direction between these two.
The TypeScript @anthropic-ai/claude-agent-sdk released 0.3.273, which its changelog names as parity with Claude Code v2.1.273. It adds a usage_report sibling on assistant messages carrying SDKUsageReport data, covering session totals, server usage rows and extra usage, for headless usage results. Background task notifications now include a reason of worker_restart when a worker restart stops a task. A hook callback that exceeds its timeout now counts as neutral rather than a failure, so other hooks proceed, and the SDK shows a one-line transcript notice once per reconnection. A browser SSE transport fault that dropped the slash-command list update, system/commands_changed, is fixed.
Why this mattersThe hook timeout change alters behaviour rather than only reporting: a timed-out hook previously reported as a failure and now does not block the others. The usage_report addition gives programmatic cost attribution that Parity holds no Python SDK equivalent for.
Claude Code 2.1.273 changes OTEL_LOG_TOOL_DETAILS=1 to include real agent, skill, plugin and MCP server names on cost and token metrics, where those metrics previously did not carry them. Anyone who enabled that variable for cost attribution should know that the names of internal agents, skills, plugins and MCP servers now leave the machine on the metrics path as well as the log path.
Why this mattersThe changelog states these names now appear on cost and token metrics, where the same variable previously governed log detail only. The Cowork OpenTelemetry export documented at support.claude.com is a separate mechanism with its own organisation-level toggle, so setting this Claude Code variable does not depend on it and is not covered by it.
A post dated 2026-09-15 expands Claude for Small Business with 27 new integrations, bringing the eligible connector list to 37, and states the offering has 43 workflows, of which eight are described by name: SMB Onboard, Monday Brief, Speed to Lead, Proposal Builder, Social Content Engine, Close Month, Build Connector and Build Agent. The 27 new integrations named are Shopify, Salesforce, TikTok, Atlassian, Zoom, Xero, Gusto, Square, Stripe, Zapier, Apollo, Clay, Emergent, Expensify, Gmail, Google Calendar, Google Drive, MYOB, NetSuite, Notion, PayPal, Ramp, RingCentral, Trello, Wix, Airwallex and monday.com. It is available on every paid Claude plan, with Team recommended for multi-person businesses, and carries no beta label. The post also announces free in-person workshops in ten named cities during autumn 2026 and 14 partner webinars running from 2026-09-25 to 2026-11-17.
Why this mattersThe post states 43 workflows and names eight of them, so 35 are a stated count with no published names. Every figure in this entry is taken from the enumerated lists in the post itself. Salesforce appears in this list of 27 new integrations on the same day that a separate Salesforce in Claude plugin is announced in beta on the Claude apps release notes page, and neither source states how the two relate.
Fast mode now works in Remote sessions on both cloud and self-hosted runners. The host fast-mode setting applies, or /fast typed inside the session, where the organisation permits it. Three related faults are fixed in the same release: /fast off answered that fast mode was unavailable instead of turning it off when an organisation has fast mode disabled, sessions started with CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK kept re-sending fast requests every turn after the API had already rejected fast mode, and fast mode under CLAUDE_CODE_RETRY_WATCHDOG failed the turn on a usage credits limit or retried an overload at fast speed rather than falling back to standard speed.
Why this mattersFast mode is documented here for Claude Code sessions only, including Remote. No equivalent organisation gate is documented for Cowork, the desktop app or the Agent SDK.
Agent frontmatter and the --agents JSON accept a new omitClaudeMd option. A custom or plugin subagent with it set runs without the user, project and local CLAUDE.md files, while managed policy files still load. The same option lands the same day in the TypeScript Agent SDK as an AgentDefinition parameter.
Why this mattersClaude Code and TypeScript Agent SDK 0.3.271 both carry omitClaudeMd from the same release cycle. The Python SDK has published nothing since 0.2.152 on 2026-09-02 and has no equivalent, so the documented Python shortfall widened today after two runs in which it did not.
A Monitor watch always has a deadline now, at most 30 minutes, or 10 minutes in a single-prompt -p run. When it expires Claude is notified to re-arm rather than the watch continuing indefinitely. This replaces the no-timeout persistent option, which is removed. The TypeScript Agent SDK drops persistent from the MonitorInput tool type in the same cycle. Automation that sets persistent will stop being accepted, so check any hook, agent definition or SDK caller that sets it.
Why this mattersBreaking in Claude Code and the TypeScript SDK together. The Python SDK is unaffected only because it has shipped nothing since 0.2.152, not because it was designed differently.
Bash, PowerShell and Monitor accept allowed_domains per command in auto mode with sandboxing. The hosts a command needs are reviewed alongside the command and opened for that command alone, and other hosts are refused. This narrows a network approval from a session-wide decision to a per-invocation one.
Why this mattersPer-command domain scoping is documented for Claude Code auto mode. Cowork and Claude Code on the web expose an allowed-domains list at the cloud environment level instead, which an administrator sets once for the environment rather than reviewing per command.
claude plugin install and claude plugin update accept --accept-command followed by a sha256. It accepts exactly the command a previous --json run displayed, in place of a blanket -y. If the command changes between the inspection run and the install, the hash no longer matches, so an unattended install does not silently run something different from what was reviewed.
Why this mattersPinning a plugin install command by hash exists only in the Claude Code CLI. The desktop app and Cowork install from marketplace allowlists set through allowedPluginMarketplaces, with no documented equivalent, which adds to the recorded difference between the two allowlist mechanisms.
In auto mode the inline exclamation-mark shell commands inside a skill or slash command now follow default-mode permission rules instead of being judged by the safety classifier. A command that no rule decides runs as a reviewed tool call. Separately, a subagent now reports back to its caller through a dedicated hand-back call that the classifier reviews, instead of the classifier reviewing the subagent last message after the fact.
Why this mattersBoth changes are described for Claude Code auto mode. Cowork and the desktop app document permission modes but publish no classifier behaviour for inline skill commands, so whether the same evaluation path applies there is not stated.
The default dynamic workflow size is now small on Pro plans, and the medium size guideline falls from 15 agents to 10. Separately, a dynamic workflow that hits a usage limit pauses and continues automatically when the limit resets, instead of dropping the affected agents. Note what this does not settle: a size guideline and a per-run concurrency cap are different numbers, and only the guideline is published here.
Why this mattersWorkflow orchestration is documented for Claude Code and the TypeScript SDK. Whether it exists in the Python SDK at all is an open question on the Parity site.
A server sending list_changed notifications in a tight loop no longer drives sustained high CPU and repeated tool-list requests. A resumed claude -p session whose tools all come from MCP servers no longer fails with an error about at least one tool needing defer_loading set to false. Tool search now matches when Claude names a tool by its bare name rather than its full mcp__server__tool name. MCP OAuth client registration is corrected in three ways: denying consent forced a new registration, a registration for a different redirect URI was reused, and a concurrent write could delete a valid registration or keep a mismatched one. Finally, claude mcp serve emits a progress update every 30 seconds during a running tool call, so a client does not abort a long command that prints nothing.
Why this mattersThese are CLI-side fixes. Cowork and the desktop app share the connector layer but their changelog names none of them, so whether the same OAuth registration handling and bare-name tool search reach those surfaces is not stated.
An enterprise managed-mcp.json that cannot be read or parsed was previously ignored, which silently dropped the organisation MCP policy and let user, project and plugin servers load as though no policy existed. It now keeps exclusive MCP control, so those servers do not load, and the session warns at startup. Two related organisation policy faults are fixed in the same release: a cached policy was reused after switching accounts, organisations or API keys and did not refresh until the hourly check when a credential changed mid-session, and the tool and command lists did not update when the policy finished loading after startup or changed mid-session.
Why this mattersThe desktop app refuses to start at all on an unparseable managed settings file, recorded by Parity from v1.46388.1. Claude Code covers the MCP policy file specifically and disables non-managed servers rather than refusing to start, so the two surfaces answer the same class of failure differently.
Four faults let a command past the Bash permission checker. A file read by fmt, column and similar commands was missed when it followed an option the checker did not recognise. Files a wildcard expands to were skipped when the wildcard sat in a command pattern or option value, for example a grep exclusion followed by a directory glob. Shell variable declaration flags could misrepresent the command being run. Commands with two directory changes, a subshell, or a cd and git chain skipped the prompt under permissions.blockReadsOutsideWorkingDirectories in bypass and auto mode. Separately, /resume and /teleport kept the previous conversation file-read tracking, so Claude could edit files the resumed conversation had never read.
Why this mattersThe Bash permission checker is Claude Code. Cowork and the desktop app run the bundled CLI, so a desktop build that bundles 2.1.271 or later should carry these. The desktop app currently bundles 2.1.270, so it does not yet.
A self-hosted runner session whose host config directory exceeds 64 MiB lost every piece of host configuration without reporting it: settings, skills, plugins and MCP servers. The fix adds --host-config-snapshot with a disk or memory mode. Anyone running a self-hosted runner with a large plugin or skill set should check whether past sessions ran without their configuration, because nothing in the session said so.
Why this mattersSelf-hosted runners are a Claude Code capability. Cowork cloud sessions and Managed Agents publish no equivalent host config snapshot, so there is nothing to compare the limit against on those surfaces.
Copies of skills synced from claude.ai remained on disk after sign-out. Copies not refreshed within cleanupPeriodDays now move to the recoverable trash at the next launch. A separate fix stops /reload-skills reporting a skill count that disagreed with the slash menu after /cd.
Why this mattersThe sync path runs from claude.ai to the local Claude Code install. Whether the same retention behaviour applies to skills synced into Cowork and the desktop app is not stated on either changelog.
The Routines page on claude.ai/code moves to a new layout with Yours and Templates tabs and two-column routine cards showing run status. The calendar view is removed. The Cloud environments editor in admin settings adds a Custom network access option carrying the same allowed-domains list the environment dialog offers, and the Cloud environments admin page now shows the default environment for Claude Tag and Claude Code with a link to change it. A separate fix stops a cloud session taking about ten minutes to respond after its process exited while the session still looked live.
Why this mattersThis is Claude Code on the web. Cowork scheduled tasks are managed from the desktop app and the cloud, and no shared routines surface is documented between the two, so a scheduled job on one is not visible from the other.
Five Claude Tag fixes ship through the Claude Code changelog. Claude in a channel where it stays active lost its working context roughly hourly when the conversation was mostly in threads, and thread activity now prevents the reset. A thread that asked Claude to watch a pull request stopped hearing about CI failures, comments and reviews after Claude was restarted in that thread. Deleting the first message of a thread Claude had already replied in did not end Claude work there, and now does. Claude held back a post because of an earlier instruction addressed to a different bot, and only instructions addressed to Claude now bind it. The reply-mode card Claude posts on joining a busy channel said it saw a lot of automated posts when the channel was only large or chatty.
Why this mattersClaude Tag changes continue to ship through the Claude Code changelog rather than the Claude apps release notes, which is the documented home for the surface and has carried nothing for Claude Tag since 2026-06-23, a gap of 84 days as of today.
Three Code Review faults are fixed. A pull request in a repository reviewed once per PR sometimes got no review at all when a commit arrived while its review was waiting to start, and it now reviews the requested commit. Code Review occasionally posted the same findings two or three times when GitHub reported an error for a review it had in fact created. Follow-up reviews re-posted a security finding a person had already resolved, when a later push moved the lines it was anchored to.
Why this mattersCode Review runs against GitHub from Claude Code. No equivalent automated review surface is documented for Cowork or the Claude apps, so the behaviour has nothing to be compared against.
The modelPricing managed setting and the Claude apps gateway pricing block accept a multiplier above 1, up to 10, described as being for marked-up internal chargeback rates. The cost figures an organisation shows its own teams can therefore exceed the rate Anthropic charges that organisation. Anyone reading an in-session cost display under managed settings should confirm which of the two numbers it is showing.
Why this mattersmodelPricing is a managed setting read by Claude Code and by the Claude apps gateway. Cowork and the desktop app document no separate pricing override of their own.
A session can watch up to 10 published artifacts for republishes made elsewhere, up from 5. Markdown files published as artifacts render as styled document pages with a title header, document typography and syntax-highlighted code. Publish errors are clearer in three ways: a publish with no file says to write the page to a file first, an unsupported file type is reported before a missing favicon, and a page declaring a capability its contract version lacks lists every supported capability and notes when a newer contract version has it. A fix stops background sessions failing to watch the artifacts they publish.
Why this mattersArtifacts publish from Claude Code and from the Claude apps. The ten-artifact watch limit and the publish error wording are documented for a Claude Code session only.
The bundled claude-api skill is updated to enable eager_input_streaming on streaming custom tools, and to start deliverable-shaped Managed Agents work with user.define_outcome. This changes the skill guidance rather than the API itself, so it alters what Claude recommends and writes, not what the API will accept.
Why this mattersThe skill ships inside Claude Code. Managed Agents has no changelog of its own, so guidance changes about it surface on the Claude Code changelog rather than on the Managed Agents documentation, which is where a reader would look.
0.3.271 adds an optional omitClaudeMd parameter to AgentDefinition in the agents option. A subagent carrying it skips the user, project and local CLAUDE.md files, and managed policy files are unaffected. The release also fixes listSessions, getSessionMessages and getSessionInfo failing on Windows mapped network drives and SUBST drives, and a regression in which sessionStore resume operations lost global config when that config sat under a legacy .config.json name or an OAuth-suffixed filename. The persistent field is dropped from the MonitorInput tool type. One caveat on the date: npm publish timestamps could not be retrieved from the registry in this run, so the date recorded here is the date of Claude Code 2.1.271, the release the changelog names parity with.
Why this mattersThe Python SDK has published nothing since 0.2.152 on 2026-09-02 and carries none of these. The documented Python shortfall widened today, after two consecutive runs in which neither SDK shipped and the distance held steady.
The Cowork on Windows defect, in which Cowork could not reach files on Windows PCs, is marked resolved on 14 September. The changelog attributes the fix to a Microsoft Windows update rather than to Claude Desktop, names KB5129195 for Windows 11 24H2 and 25H2, and states that no Claude Desktop update is needed. The remedy is to install the latest Windows update and restart the PC. The original known-issue entry of 10 September remains on the page, no longer describing the cause as under investigation, and now points at the same remedy.
Why this mattersThe defect and its fix are specific to the Cowork desktop app on Windows. Cowork cloud sessions were not affected, which matches the separation Parity already records between Cowork on the desktop and Cowork in the cloud.
Anthropic published Claude for Financial Advisors on 14 September, a plugin available through the Cowork plugin browser. It names eleven industry connectors: Addepar, BlackRock Advisor Center, Charles Schwab Advisor Services, Envestnet covering Tamarac and MoneyGuide, iCapital, Orion with Redtail CRM, SS and C Black Diamond, Wealthbox, Wealth.com, Vanguard and Zocks. It states compatibility with the existing Microsoft 365, Salesforce, DocuSign, Box, FactSet, S and P Global and Morningstar connectors. Eight skills are named: advisor onboarding, alternative investments brief, compliance and AI policy, estate and tax brief, portfolio rebalance review, post-meeting notes and follow-up, pre-meeting prep, and prospect intake. The post recommends Enterprise plans for registered investment advisers, and offers a one-time usage credit to firms requesting a new licence before the end of September 2026.
Why this mattersThis is the first vertical plugin bundle Parity has recorded being distributed through the Cowork plugin browser with its own named connector set. Everything named is described for Cowork. No equivalent bundle is documented for Claude web, the desktop chat tab or the Microsoft 365 add-ins, so the connectors are reachable only from the surface that has the plugin browser.
A release note dated 2026-09-14 adds on-demand compaction to the Messages API under the beta header compact-2026-09-04. A request can ask the API to compact the conversation, and the response carries a signed compaction block summarising the removed messages, which can be sent back in place of them on later requests. Recent turns are preserved word for word and thinking block validity is maintained. The release note states compaction can run in the background.
Why this mattersCompaction is now a first-class API operation rather than a client-side concern. Claude Code changed its own compaction behaviour in the same week, fixing advisor-tool turns being double counted so that auto-compact fired at about half the real context window. The signed block is the part that distinguishes this from client-side truncation, because the summary can be handed back and trusted on a later request.
Anthropic documentation describes Enterprise access to the Cowork built-in browser in two ways that do not agree. The article Use the built-in browser in Claude Cowork states that the built-in browser is rolling out gradually to Cowork in Claude Desktop for macOS, Windows and Linux on Pro, Max and Team plans, and on Enterprise plans where an owner has enabled it. That article names no date. The browser use setup article for Team and Enterprise states that the Enterprise default turns on starting 10 September 2026. One page describes Enterprise access as something an owner switches on, the other as a scheduled default that switches itself on. Neither page states what the setting is today. For an Enterprise administrator the practical step is to read the toggle in the admin console rather than either article.
Why this mattersThe same article states that an organisation owner controls whether the built-in browser and Claude in Chrome are available, so both browsing paths sit behind the one owner control. Parity holds the Enterprise rows for both at off and treats the articles as unreliable for this fact.
The role based permissions article for Enterprise plans states that groups are managed at the parent organisation level and propagate to all child organisations, and that seeing members from other organisations in a group does not mean they have access to your organisation. The same article does not say whether a capability toggle or a feature default set at a parent organisation reaches its child organisations. The browser use setup article, which is where the question arises because it describes an Enterprise default turning on automatically, does not mention parent or child organisations anywhere. Group membership is therefore documented as inherited, and feature state is documented neither way.
Why this mattersThis is the first Anthropic page found that states anything explicit about Enterprise parent and child organisation structure. It settles inheritance for groups only, so the open question about whether an Enterprise browsing default reaches child organisations stays open.
Claude Desktop v1.52386.6, released 13 September 2026, updates the bundled Claude Code CLI to 2.1.270 and carries three fixes into the app. Organisation plugins enabled through Claude Code managed settings were failing to load and now load from the next session. Sessions holding a very large prompt could get permanently stuck on a prompt length error. The Code tab could tell a user that a model they have access to is restricted, while a running session switched itself to the organisation default model. All three were already recorded against the CLI, at 2.1.269 and 2.1.268, so the new fact here is the date on which they reach the desktop app rather than the fixes themselves. The Cowork and third-party sections of the release both state no user-facing changes.
Why this mattersThis release dates a governance fix that previously had none. Claude Code 2.1.269 stated that organisation plugins set by managed settings would load on Claude Desktop once the desktop app bundled that CLI version, and named no release. No desktop release bundles 2.1.269 itself: the version carrying the fix is 2.1.270, one release later, and it arrives in the app on 13 September. Measured against the CLI dates, the lag from terminal to desktop was two days for the 2.1.269 items and three days for the 2.1.268 model access pair. Organisation plugin provisioning is a Team and Enterprise control, so until this release an administrator who provisioned plugins centrally was getting them in interactive terminal sessions and not in the desktop app.
Two Enterprise browsing defaults carry a documented auto-enable date of 10 September 2026. Read on 12 September, the Cowork built-in browser setup article shows an Updated today timestamp and still states that the setting turns on by default starting 10 September 2026, in the future tense, and nowhere describes the change as having happened. The Cowork on Team and Enterprise article carries the same future-tense wording with a timestamp of over two weeks ago, and the Claude in Chrome admin controls article with a timestamp of over a week ago. An article edited today that leaves a date two days past describing a future event is weaker evidence than an untouched page, because the page was in someone's hands and the sentence was not corrected. The control still holds: Run Cowork in the cloud carries no auto-enable date and stays off by default on Enterprise.
Why this mattersBoth defaults govern browsing, under separate toggles, on Enterprise only. Team already has both on by default, so the documentation gap affects only the plan where the change was scheduled to happen.
Claude Code 2.1.270 carries one item. Read-only git commands run through Bash began asking for permission once a session had been running for a while, which the changelog attributes to a regression introduced in 2.1.269 the previous day. The fix is the whole release, and there is nothing else in it. The action is deterministic: if you are pinned to 2.1.269, move to 2.1.270. Unattended and scheduled sessions are where this matters most, because a permission prompt that nobody is present to answer has nothing to clear it.
Why this mattersThe TypeScript Agent SDK published 0.3.270 on 2026-09-13, and its only changelog line records parity with Claude Code v2.1.270, so the SDK release carries no separate entry of its own. The Python Agent SDK remains at 0.2.152 from 2026-09-02, an eleventh day with no release, so it has no equivalent version.
The documented date came and went. Two Enterprise browsing defaults, the Cowork built-in browser and the Claude in Chrome extension, were scheduled to switch themselves on yesterday. Re-read this morning, one day past, none of the three governing articles has moved. Each keeps the future tense and each keeps printing the date in front of it. The Chrome admin controls article continues to describe the extension as disabled for Enterprise. The built-in browser setup article continues to describe it as off at launch. The Cowork on Team and Enterprise article reads the same way. None of the three says the switch has happened. What that leaves is not a delay, it is an absence of evidence either way, so an administrator still cannot learn from the documentation whether their own organisation flipped. The only reliable check available today is the admin console itself, not these pages.
Why this mattersThe two toggles are separate and an administrator has to check both, because the extension and the built-in browser are different products that happen to share a date. The control case still holds: Run Cowork in the cloud, the third Enterprise default described in the same article, carries no auto-enable date and stays off, so this remains specific to browsing rather than a general loosening. Parity continues to hold both Enterprise rows at off, because a page that has not been updated is not evidence that nothing changed, and inferring the flip from a passed date would be exactly the guess the matrix is meant to refuse.
Claude Code 2.1.269 fixes two faults in scheduled routines on Claude Code on the web. A one-off routine could run a second time after a transient server error. Separately, a routine run whose work is done by subagents could be treated as finished before the subagents were, which either skipped the retry after a real failure or started a duplicate run. Both faults were live before 2026-09-11, so any unattended routine that fans work out to subagents could have produced two runs from one trigger, or stopped without the retry a failure should have earned.
Why this mattersThe changelog scopes both fixes to Claude Code on the web. Cowork scheduled tasks are tracked in the desktop changelog and are not named in either fix, so whether the same early-completion logic applies there is not documented.
Claude Code 2.1.269 adds the command claude plugin eval, which runs a plugin's own eval suite against Claude Code and returns scored, reproducible results as JSON and as an HTML report. The changelog points at claude plugin eval --help for the options. Until this release a plugin author had no first-party way to score a plugin's behaviour, so any quality gate was whatever each author built themselves.
Why this mattersScored plugin evals exist in the Claude Code CLI only. Cowork, the desktop app and the Agent SDK all load plugins and none is named as able to run an eval suite.
Claude Code 2.1.269 fixes two permission faults. An Edit() deny rule and the write-path check did not apply to the file a Bash tee command writes, so a Bash(tee:*) allow rule covered destinations outside the working directories; it no longer does. Separately, a deny or ask rule beginning with an exclamation mark applied beyond the settings source that declared it, and now applies only within its own source, while a bare exclamation mark negation is ignored. Both are fixes rather than hardening, so a machine still on an earlier build carries both.
Why this mattersPermission rules are written the same way in the Claude Code CLI, the Agent SDK and managed settings on the desktop app. The changelog names neither fix as reaching the desktop app or Cowork, and desktop v1.52386.3 of the same day carries no third-party or general user-facing changes.
Claude Code 2.1.269 fixes three faults in how a plugin archive is unpacked for a session. The extracted tree was readable by other users on the same machine, files kept world-writable permission bits carried in the archive, and stale files from an earlier extraction survived re-extraction. On a shared or multi-user machine the first two mean another local account could read a plugin's files, and where the archive carried world-writable bits, modify them.
Why this mattersCowork and the desktop app install plugins from the same marketplaces and unpack the same archives. The fix is documented for Claude Code only, and the desktop changelog for v1.52386.3 records no user-facing change in its general or third-party sections.
Claude Code 2.1.269 adds the environment variable CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS, accepting a value from 1 to 256, to raise the number of agents the Workflow tool runs at once inside a single run. The changelog gives the reason as inference-bound fan-outs. It publishes the accepted range but not the current default, so an operator cannot tell from the entry whether a given value raises or lowers the limit in force.
Why this mattersThe Workflow tool and its concurrency ceiling exist in the Claude Code CLI. No equivalent per-run agent limit is documented for Managed Agents, the Agent SDK or Cowork.
Claude Code 2.1.269 fixes three causes of prompt cache loss. The cache was partially invalidated on the turn after a response hit the output token limit and was resumed automatically. Resuming a session after interrupting Claude mid-thought could change how earlier context was re-sent, reducing reuse. Cloud sessions missed the cache on the first request because it was sent before server configuration arrived, and the session now waits briefly for that configuration. Cache reads are billed at a lower rate than fresh input, so each of these three was a cost difference as well as a latency one. The changelog publishes no figure for the size of the difference, and it depends on the prompts involved.
Why this mattersPrompt cache reuse is reported to the user only in the Claude Code CLI, an existing open gap. These three fixes land in the CLI, and the changelog does not say whether Cowork or desktop sessions, which share the bundled CLI, carry them before the desktop app bundles this version.
Claude Code 2.1.269 fixes remote and headless sessions reporting that they were waiting for your input while background agents were still running. Setting CLAUDE_CODE_BG_TASKS_REPORT_RUNNING to 0 restores the previous behaviour. Anything that reads that status as a finished turn, including a wrapper driving an unattended run, was seeing a completed session while work was still in flight.
Why this mattersBackground agents exist in the CLI, the Agent SDK and Cowork. The status reporting fix is documented for remote and headless Claude Code sessions only.
The same defect is fixed on 2026-09-11 in Claude Code 2.1.269 and in the TypeScript Agent SDK 0.3.269. In the CLI, permission_denials in an --output-format stream-json result left out Read, Edit and Write calls that a path-scoped deny rule had blocked; in the SDK the same omission affected result.permission_denials. Anything auditing an unattended run from that field saw fewer denials than actually occurred, and saw none at all for a deny rule scoped by path.
Why this mattersThis is one defect on two surfaces on one day, so it is recorded once. The Python Agent SDK is not named in either changelog and remains at 0.2.152, so the same field there is not documented as fixed.
Version 0.3.269 of the TypeScript Agent SDK, published 2026-09-11, changes plan mode so write operations go through canUseTool even when allowDangerouslySkipPermissions is set. That flag now only permits a later switch to bypassPermissions. Code that relied on the flag to skip write approval inside plan mode will see its callback invoked where it previously was not. The release also stamps user_message_uuid, user_message_uuids and resume_reason on a turn's first complete assistant message as well as its first stream event when partial messages are on, adds the agent's last call id as tool_use_id on task_started and task_notification when the CLI resumes a background subagent by itself, and stops interrupts and permission responses being delayed while a host-started MCP server OAuth sign-in waits on a slow authorization server.
Why this mattersNone of these five changes is documented for the Python SDK, whose highest published version is still 0.2.152 from 2026-09-02. The plan mode change is a behaviour difference rather than a missing feature, so the two SDKs now approve writes differently under the same configuration.
Desktop v1.52386.3, dated 2026-09-11, changes the automatic move of scheduled tasks to the cloud on accounts where that move has started. The app now waits about a minute after the computer wakes, and while offline retries each minute, instead of trying immediately and then waiting hours after a failed attempt. Two faults in local projects moving to claude.ai are also fixed on those accounts: a project could refuse new tasks for hours while part of its memory copy waited on the server, and now accepts new tasks while the copy finishes in the background, and memory files shown in a moved project's earlier tasks would not open. The general, Code and third-party sections of this release record no user-facing changes.
Why this mattersThe retry behaviour is specific to the desktop app, which owns local scheduled tasks. Cloud-run scheduled work has no wake to wait for, so the fault had no equivalent there.
Claude Code 2.1.269 carries ten Claude Tag items. The sharpest is that Claude accepted a switch to a model the organisation has not enabled and then answered quietly with a fallback model; it now declines and says an administrator can enable it. The shared-session banner and Share dialog on sessions started from Slack claimed the whole organisation could open the link, and now name the Slack channel's audience instead. Plugin rows in Slack access settings showed an unlabelled raw identifier with no way to turn the plugin off, and now show a name and a link to the bundle that manages it. Admin settings gain a confirmation before Connect all or Disconnect on a GitHub installation. A failure notice dropped when Slack briefly rate-limited it is now retried, so a thread stops going silent after a failed turn. Scheduled routines in a Slack channel can now reply in an existing thread rather than always posting a new top-level message.
Why this mattersThe Claude apps unified release notes page still carries nothing for Claude Tag since 2026-06-23, so Claude Tag changes continue to reach the public only through the Claude Code changelog. This is the second consecutive release to carry ten or more of them.
Claude Code 2.1.269 stops CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-running a turn that had failed with an API error more than six hours earlier, and adds CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS to set that cutoff explicitly. On a long-lived or scheduled session the old behaviour could replay a turn whose working state had moved on since the failure.
Why this mattersThe TypeScript Agent SDK 0.3.268 added resume_reason to mark a message whose turn was re-run after a host restart, and 0.3.269 extends where it is stamped. The six hour cutoff is documented as a CLI environment variable, with no SDK-side equivalent named.
Claude Code 2.1.269 adds OTEL_METRICS_INCLUDE_REPOSITORY, which tags OpenTelemetry metrics and events with vcs.* repository attributes, and makes commit events carry vcs.ref.head.* when OTEL_LOG_TOOL_DETAILS is also set. A second change fixes the managed settings approval dialog failing to name the collector when a gRPC telemetry endpoint is configured without a scheme, so an administrator approving that endpoint could not see where traces were being sent.
Why this mattersThe desktop app gained an administrator block on OpenTelemetry trace export in v1.52386.0 on 2026-09-10. Repository attribute tagging is documented for the Claude Code CLI alone, so the same telemetry stream carries different fields depending on which surface produced it.
Claude Code 2.1.269 adds twenty-three changes to the VS Code extension, four of them new capability. A Hooks dialog lists hooks and adds, edits or removes them in user, project and local settings, with managed, plugin and session hooks read only. A Permission rules dialog does the same for permission rules, with startup-option, session-only and managed rules read only. An agents footer pill opens a map of the session's subagents with per-agent cards, a Stop agent control and read-only transcripts, and running subagents show live progress rows under their tool-call groups in Focus view.
Why this mattersEditing hooks and permission rules through a dialog exists in the VS Code extension and on no other surface. Everywhere else, including the terminal CLI, Cowork and the desktop app, both are edited as settings files.
Claude Code 2.1.269 fixes a plugin headersHelper consent prompt that displayed a URL path which could be misread as a different host, so someone approving the prompt could believe they were authorising a different destination. A second fix stops plugin errors printing a redacted URL placeholder in place of a relative Windows path whose folder name starts with an at sign, which made a real error message unreadable.
Why this mattersheadersHelper is configured in a project .mcp.json for Claude Code and in managed settings on the desktop app. The consent prompt fix is documented for Claude Code only, and an open question already asks whether the folder trust requirement for a project headersHelper reaches Cowork and desktop MCP servers.
Claude Code 2.1.269 fixes organisation plugins enabled through managed settings failing to load in headless sessions and on Claude Desktop, and states that they load from the next session once the desktop app bundles this CLI version. An administrator who provisioned plugins centrally was getting them in interactive terminal sessions and not in two places an organisation is least likely to check by hand. The desktop half of the fix has no date, because it depends on a desktop release that bundles this version and the changelog names none.
Why this mattersOrganisation plugin provisioning is a Team and Enterprise control, documented as available on both. This fix means the control was partially ineffective on the desktop app and in unattended runs, and is still pending on the desktop app until a release bundles this CLI version.
Claude Code 2.1.269 changes skills synced from claude.ai in a cloud session to be named with an anthropic-skills prefix followed by the skill name, matching how Claude Desktop already names them. The bare name still resolves when nothing else uses it. Anything that invokes a synced skill by bare name in a cloud session, and also carries a same-named skill from another source, now resolves to a different skill than before.
Why this mattersThis aligns cloud sessions with Claude Desktop, closing a naming difference between the two. The terminal CLI on a local machine is not named in the change.
Claude Code 2.1.269 adds /output-style with an optional name to list and switch output styles, including over Remote Control and in cloud and other headless sessions, where the picker previously needed an interactive terminal. /goal no longer stalls silently after API errors, network drops or token limits: it retries with backoff, or pauses and says why, including waiting for a usage limit to reset. /btw answers that contained invented tool calls and output are addressed by instructing the side question not to write them and flagging any that appear as not executed. /insights falls back to the session model on Bedrock, Vertex, Foundry and gateway deployments whose account cannot reach the default Opus model. /ultrareview --post now posts its pull request comment directly and prints the link instead of starting a second cloud session to do it, and /diff opens fully rendered instead of showing a loading state first.
Why this mattersOutput styles were previously unreachable in headless and Remote Control sessions, so this removes a difference between an interactive terminal and an unattended run. None of these commands exists in Cowork or the Agent SDK.
Claude Code 2.1.269 stops MCP servers reconnecting when an updated configuration changed only the order of the server URL's query parameters, fixes synced plugin MCP servers failing to connect when a remote session resumes, and sends exit to a plugin LSP server that rejects a shutdown request, such as rust-analyzer, which previously was left running at session end. Separately, in first-party sessions with telemetry disabled, an alwaysLoad MCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip.
Why this mattersMCP servers are configured on every interactive surface. All four changes are documented for Claude Code, and none is named for Cowork or the desktop app, which carry their own managed MCP server settings.
Claude Code 2.1.269 adds the bashEditDiffEnabled setting. With it on, a Bash command that the Bash tool handles as a file edit returns a diff of the files it changed alongside its output. Without it, a Bash-driven edit returned the command's output and no record of what moved on disk, which is the case a reviewer reading a transcript cannot reconstruct.
Why this mattersBash tool output is reviewed in the CLI, in Cowork and in the desktop app. The setting is documented for Claude Code, and the changelog does not say whether a desktop release bundling this version exposes it.
Claude Code 2.1.269 fixes its own attribution reminder overriding a CLAUDE.md or memory rule that forbids attribution lines in commits and pull requests. Lines set by managed settings still apply, so an organisation can continue to require them. Until this build a repository whose instructions banned those lines was getting them anyway, which is a case where the tool overrode the project's stated policy rather than failing visibly.
Why this mattersCLAUDE.md and memory rules are read by the CLI, the Agent SDK and Cowork. The precedence fix is documented for Claude Code only.
Claude Code 2.1.269 adds CLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MS to extend the LLM gateway model discovery timeout on the /v1/models endpoint, whose default the changelog gives as three seconds. It fixes organisation policy limits failing to load for a session when another Claude Code process refreshed the login at the same moment, which left that session running without its organisation's limits. On Claude Code on the web, /model default in a cloud session left every later message failing in organisations that restrict which models Claude Code may use.
Why this mattersAll three are gateway and governance faults in Claude Code. The organisation policy race is the sharpest, because a session that silently misses its policy limits looks identical to one inside them.
Claude Code 2.1.269 fixes sessions becoming permanently stuck on a prompt too long error when auto-compaction had no complete earlier exchange to summarise. The changelog names Agent SDK sessions with very large prompts as the main case. Before the fix such a session could not recover by itself: compaction had nothing to work with, so every further request failed the same way.
Why this mattersAuto-compaction runs in the CLI, the SDK and Cowork. The changelog attributes the failure mainly to Agent SDK sessions, where a single very large first prompt is most likely.
Claude Code 2.1.269 lets you take a queued message back in a cloud session before Claude reads it, by removing it from the queue or pressing Escape or Up, which returns the text to the message box. The Cloud environments admin page now lists every environment instead of capping each table at five rows behind a Show more control that could be unreachable. File links in cloud session transcripts no longer open a GitHub 404 when Claude was working from a subfolder of the repository, and claude.ai/code now sends Free plan users to the plans page with a path to upgrade rather than a disabled-by-administrator page with no way forward.
Why this mattersUn-queueing a message is documented for cloud sessions. The terminal CLI and Cowork are not named, so whether the same control exists there is not stated.
Claude Code 2.1.269 fixes F1, F2 and F4 not working in kitty-protocol terminals, Delete in st, Alt with arrow keys acting as Escape in rxvt-unicode, and Shift with punctuation typing the unshifted character in WezTerm, naming 2.1.247 as the release that introduced them. It also stops terminal capability replies and stray character sequences being typed into the prompt at startup over slow connections such as ssh and browser terminals, fixes blank rows at the top or bottom of the transcript in fullscreen after a resize, the interface being drawn twice after returning from an external editor in Konsole and outside fullscreen, and cursor artefacts in rxvt-unicode. Keyboard support improves over ssh and in unrecognised terminals: anything that answers the kitty keyboard query, with foot and Alacritty 0.16 or later named, now gets Shift with Enter and Control with Shift shortcuts.
Why this mattersTerminal rendering applies to the CLI alone. The named regression in 2.1.247 sat unfixed across the releases between it and 2.1.269.
Claude Code 2.1.269 stops transcript updates re-processing the entire conversation to rebuild collapsed tool-use summaries, which was the cause of slowdown in long sessions. It also fixes the git status Claude is given after a compaction, which was the status from the start of the session rather than the current one, so Claude could reason about a working tree that had already changed. Also fixed: CMYK JPEG images failing to attach, sessions run through the SDK or the desktop app showing an unknown status in other sessions' agent list, repeated clicks on a fork receipt not backgrounding the session while a tool finished, and prompt suggestions being dropped for Japanese, Chinese, Thai and other languages written without spaces between words.
Why this mattersThe stale git status after compaction is the one with consequences beyond the CLI, because the same compaction runs in SDK and Cowork sessions. The changelog names Claude Code only.
Two Enterprise browsing defaults are documented to turn themselves on today, 10 September 2026. Read on the morning of that date, all three governing support articles still state the change in the future tense and still name the date. The Cowork built-in browser setup article states that it is off by default at launch and that starting 10 September 2026 it turns on by default unless you have turned it off. The Cowork on Team and Enterprise article states the same for the built-in browser. The Claude in Chrome admin controls article states that the extension is disabled by default and that starting 10 September 2026 it turns on by default unless you have already disabled it. No article describes the change as completed. What can be traced today is that the documentation has not been updated to say the flip has happened, not whether the product has flipped. An Enterprise organisation that meant to decline either default had today as its deadline to act.
Why this mattersThese are two separate toggles that happen to share one date. Claude in Chrome is the browser extension. The Cowork built-in browser ships inside the Claude desktop app and needs no extension, so a cloud only Cowork session has neither. Team is unaffected, because both are already on by default there. The control case holds: Run Cowork in the cloud still carries no auto-enable date and remains off by default on Enterprise, so this is a browsing specific flip rather than a general loosening of Enterprise defaults.
The organisation skill provisioning article states that the skill sharing toggle is on by default for Team plans, and for Enterprise plans that have not set a skills preference. For regulated configurations, where the article names HIPAA, skills and skill sharing are off by default. The two narrower toggles, share with organisation and share with groups, are off by default across all organisations. So the coarse switch defaults open on Team while the sharing scopes beneath it default closed.
Why this mattersOrganisation skill management is Team and Enterprise only, so Pro and Max have no equivalent default to compare against. Skill and plugin security scanning, by contrast, is Enterprise only and off by default, which means a Team organisation gets sharing on by default with no scanning available to it at all.
Claude Code 2.1.268 offers TaskCreate, TaskGet, TaskUpdate, TaskList and TodoWrite only on Claude 3.x, Opus 4.0 to 4.7, Sonnet 4.0 to 4.6 and Haiku 4.5. On every other model, which includes Opus 5, Sonnet 5, Fable 5.1 and Mythos 5.1, they are no longer offered unless CLAUDE_CODE_ENABLE_TODO_TOOLS is set to 1. TypeScript Agent SDK 0.3.268 makes the matching change on the same day, where a model outside that list must name the tools in tools or allowedTools. Nothing errors. A prompt, skill or subagent that assumes a task list exists simply stops getting one, so the failure is silent and shows up as changed behaviour rather than a message.
Why this mattersThe two surfaces moved together and the third did not. The Python Agent SDK is still on 0.2.152 from 2 September and carries neither the restriction nor the opt-in, so the same agent code now behaves differently depending on which SDK runs it. This widens the Python gap rather than being a separate issue.
Claude Code 2.1.268 stops plain WebFetch deny and ask rules applying to Artifact tool reads and updates. An organisation or an individual that blocked artifact publishing by denying WebFetch is no longer blocking it, and nothing announces that the rule has stopped covering the case. The documented replacements are an Artifact rule, or a WebFetch rule scoped to the claude.ai domain. The same release changes the terminal permission prompt for artifact data edits into a card showing the document count and who can open the artifact.
Why this mattersPermission rule syntax is shared between the CLI, the SDK and local Cowork sessions, so a rule written once and relied on in several places changes meaning everywhere at once. Anyone auditing a permissions file should grep for WebFetch deny entries that were doing double duty.
Two permission bypasses are fixed in 2.1.268. Deny and ask rules written against a symlinked directory, which covers /etc, /tmp and /var on macOS and /bin on Linux, did not apply when the path was given by its real location, and Bash commands ignored deny rules written using the symlinked spelling. Separately, a Read or Edit deny rule did not apply when an env -C, eval or similar construct the permission checker cannot analyse appeared on the same line. In both cases a path an administrator had denied was reachable.
Why this mattersThe permission engine is shared with the Agent SDK and with local Cowork sessions, so a deny list audited only through the CLI was carrying the same weakness wherever it was loaded.
Claude Code 2.1.268 closes two separate leaks. Plugin and marketplace errors displayed a token or a password embedded in a git source URL. And /mcp and /plugin server details, claude mcp list, claude mcp get and MCP login errors displayed secrets after resolving ${VAR} placeholders from MCP configuration, which defeats the point of using a placeholder. The remediation is not just upgrading: any credential that appeared in a failing plugin or MCP error already pasted into a ticket, a chat or a log should be treated as exposed and rotated.
Why this mattersThe ${VAR} placeholder pattern in MCP configuration is shared with the desktop app and Cowork. This entry records the fix as documented for the CLI only. Whether the desktop app printed the same resolved values is not stated on the page and has not been confirmed.
Claude Code 2.1.268 fixes a respawned in-process teammate picking up tools or a system prompt from a same-named agent file sitting in a folder that has not been trusted. The trust check applied on the original launch and not on the respawn, so a repository carrying an agent file whose name matches one of yours could supply the definition after a restart.
Why this mattersAgent teams are recorded in the matrix as a Claude Code capability that the Agent SDK, Cowork and Managed Agents do not have, so this defect had no equivalent elsewhere to check.
A server that holds a response open without ever finishing it made WebFetch hang with no timeout. Claude Code 2.1.268 adds a 300 second deadline, overridable through CLAUDE_CODE_WEBFETCH_DEADLINE_MS, where a value of 0 removes the deadline. The same release rewrites the WebFetch error for localhost and other dotless hostnames so it explains why the URL is refused and points to curl instead.
Why this mattersWebFetch is the only web retrieval path available to a subagent in an unattended run, so a hang had no timeout above it to catch it. Scheduled work on any surface that spawns subagents was exposed to a single slow host stalling a whole run.
Claude Code 2.1.268 stops the first message being re-rendered on every request in SDK sessions that set excludeDynamicSections. Until this release those sessions lost both the prompt cache and extended thinking mid-conversation. Neither loss raises an error. A broken prompt cache appears as a larger bill and a slower session, so the symptom is a cost line rather than a failure, and a session that looked healthy could have been paying full input price for every turn.
Why this mattersThis is the third prompt cache defect published in four days, after the resumed subagent and agent teammate breaks in 2.1.266 and the tool set rewrites in 2.1.267. Prompt cache visibility exists only in the CLI, so on every other surface a break like this is invisible to the person paying for it.
In Claude Code 2.1.268 the Artifact tool, inside a local Cowork session configured to skip all approvals, refuses a local file that sits outside the session folders or behind a symlink, rather than reading it without asking. Skipping approvals previously meant the tool would read anything the process could reach. This narrows what a fully unattended Cowork session can pull into a published page.
Why this mattersSkip-all-approvals is the configuration an unattended run uses, so it is exactly the case where no human is present to catch a file being read. The restriction is scoped to local Cowork sessions and the Artifact tool, so a CLI session with the same permission posture is not covered by it.
Cloud sessions running longer than roughly six hours lost files written to persisted session folders, with no error. Claude Code 2.1.268 extends persistence to about a day. Silence is what makes this one serious: a long scheduled run could complete, report success and leave nothing on disk, so the loss is discovered later by whoever goes looking for the output rather than at the time it happens.
Why this mattersSix hours is short enough to catch a long scheduled run but long enough that most interactive sessions never hit it, which is why a defect this destructive could sit in a hosted surface. No other surface persists files for a cloud session, so there was nothing to compare against.
Claude Code 2.1.268 fixes Invalid effort level errors on Claude Code on the web when a routine resumes a session, or when a session starts with no effort level set, inside an organisation where an administrator caps a model effort level. The same release adds a message when a routine is created with no connectors, saying so and explaining how to add them, instead of only confirming the routine was made.
Why this mattersEffort caps arrived as a managed setting in 2.1.266 on 8 September, covering every provider. The resume path did not respect the cap correctly, so the control and the surface that most depends on unattended resume shipped two days apart.
Claude Code 2.1.268 adds three gateway controls. With pricing set in gateway.yaml, signed-in clients receive the same rates through managed settings, so /cost and telemetry agree with the spend meter instead of quoting list price. A startup warning now fires when access_control.allow_cidrs is empty, plus a one-time warning the first time a request arrives from a public address, which is the configuration that leaves a gateway open. And gatewayInternalNetworks lets an administrator permit /login to a gateway on the organisation public IPv4 block.
Why this mattersSpend reporting that disagrees with the meter is a gateway-only problem, because no other surface puts a self-hosted price list between the client and the bill. The empty allow_cidrs warning is the more urgent half: it is a deployment error that was previously silent.
Claude Code 2.1.268 fixes entitled users being told a model is restricted after a restart, or in the desktop Code tab, when a cached model-access denial had gone stale. It also fixes a running session silently switching to the organisation default model when a separate Claude Code process refreshed a stale model-access entry. The second is the damaging one. The session carries on, the work completes, and the output came from a different model than the one selected, with nothing in the transcript to say so.
Why this mattersThe cached model-access entry is shared between concurrent processes on one machine, so running two sessions at once was the trigger. That is normal practice for anyone using agent teams or several terminals, and it has no equivalent on the hosted surfaces, where model selection is resolved server side.
Claude Code 2.1.268 adds --json to claude plugin install, uninstall, update, enable and disable, and adds errorDetails and noteDetails to each row of claude plugin list --json, which makes plugin state scriptable for the first time. Installing, enabling or disabling from /plugin now applies when the menu closes, so /reload-plugins is no longer needed. Two loader defects are fixed with it. claude plugin validate no longer rejects a plugin path whose directory name starts with two dots, which the loader itself already accepted, so validation and loading disagreed. And plugins no longer silently skip a default monitors file or a root SKILL.md that could not be checked, which meant a skill could be absent from a session with no indication.
Why this mattersThe validate command and the plugin loader disagreeing is the kind of defect that only shows up in an automated pipeline, where validate is the gate. Cowork and the desktop app share the plugin loader but expose no validate command, so neither had a way to hit the disagreement.
Claude Code 2.1.268 carries thirteen Claude Tag items. The substantive one changes memory in public channels so each channel keeps its own notes and Claude no longer recalls notes it saved in other public channels, while workspace notes stay shared. That is a privacy boundary change, not a fix. The rest are corrections and speed: read-only lookups now run in parallel rather than one after another, an Enterprise Grid channel no longer loses its repository, environment and access settings when a Slack admin moves it to another workspace, a workspace guest no longer gets an account-not-connected reply in a channel where guests may use Claude, long-running channel sessions are no longer replaced mid-conversation, and the admin settings page no longer hangs on a loading skeleton after a transient failure.
Why this mattersThe unified apps release notes page has carried nothing for Claude Tag since 23 June. It is not simply stale, because it did publish a new entry on 10 September, the same day as this release. So every Claude Tag change for more than two months has reached the public only through a changelog named after a different product, which nobody administering Slack has a reason to read.
Claude Code 2.1.268 changes Claude in Chrome so that reading a long page keeps the content inline rather than saving it to a file and reading it back. The same release fixes Claude in Chrome asking permission to allow the host named https when a navigation URL had a scheme but a host that could not be parsed, which is a prompt no one could sensibly answer.
Why this mattersClaude in Chrome changes continue to arrive through the Claude Code changelog. Its own entry on the unified apps release notes page is still dated 18 December 2025, so that page has said nothing about Chrome for almost nine months.
Claude Code 2.1.268 fixes sustained high CPU use from two causes: a busy loop in long-running idle sessions that held a core, and rapid terminal focus reports during a session recap. Four responsiveness changes ship with it. Adding or removing a prompt line in fullscreen mode repaints as fast as typing rather than re-rendering the visible transcript, --continue and --resume show the conversation immediately instead of waiting for SessionStart hooks, tool-heavy turns no longer redraw the transcript for a hidden per-batch reminder, and startup in a project with workflow scripts no longer parses each script to list them.
Why this mattersThe idle busy loop only bites a session left open, which is the normal pattern for a long-lived terminal and not for a hosted session that ends with its turn.
Desktop v1.52386.0 fixes a running task failing with an authentication error when sign-in was renewed in the background. A running task now picks up the renewed credentials instead of holding the expired ones. Scheduled and long-running Cowork tasks were the exposed case, because they are the ones still running when a credential refresh happens, and the failure arrives as an authentication error that looks like a login problem rather than a timing one.
Why this mattersClaude Code 2.1.267 fixed a neighbouring case on 9 September, where expired cloud credentials under a host app were retried ten times behind a generic failure message. Credential expiry mid-run has now produced a defect on two surfaces in two days, which suggests the shared weakness is long-running work rather than either surface.
Desktop v1.52386.0 makes organisation plugin hooks run in the Chat mode of the desktop app. Cowork and Code sessions in the same app already ran them. The release also adds a deprecation notice panel in Setup listing managed configuration settings with their stop dates and replacements, and changes app launch to open the last used mode rather than always opening Cowork first.
Why this mattersThis closes a governance gap inside a single application. Until this release an organisation hook applied in two of the three modes of the desktop app and not the third, so the same policy produced different enforcement depending on which tab the work happened in. The new Setup panel is the more useful half for administrators, because it turns the two live configuration cutoffs into something the app surfaces rather than something to be found in a changelog.
Desktop v1.52386.0 fixes clicks, scrolls, screenshots and page scripts in the built-in browser failing when the browser pane was hidden or the window was minimised. It also fixes sites on a VPN, Tailscale or an intranet loading without their styles, scripts and data, and states that cloud session URLs can now reach private networks. The hidden-pane fault matters most for unattended work, where nobody has the pane open and the failure looks like the site being broken rather than the pane being hidden.
Why this mattersPrivate network reachability from a cloud session URL widens what a session running off the device can touch on the network the device sits on. That is worth an administrator reviewing alongside the Enterprise browsing defaults, because the two arrived in the same week.
Desktop v1.52386.0 adds sshTransport as a beta setting. Setting it to system-openssh uses the native OpenSSH client, which brings Kerberos support, and builtin uses the internal SSH library the app shipped with. It also adds coworkVmIpv6Enabled, off by default, which gives the workspace VM an IPv6 address so it can reach IPv6-only hosts. The release fixes several SSH faults alongside: leftover background processes, cancellation reaching across computers, permanent connection loss after editing a host or port, and missing recent history.
Why this mattersKerberos support through native OpenSSH is the item that unblocks a class of enterprise network. No equivalent transport choice is documented for the terminal CLI, which uses the system SSH client already, so this is the desktop app closing a gap with the CLI rather than opening one.
Smart reports let an Enterprise administrator review how a team uses Claude: the work getting done, what it costs, where sessions run into friction, and which repeated patterns are worth packaging as shared skills. It is beta, Enterprise only, and off by default. An owner or primary owner enables it under organisation settings, capabilities. Once on, primary owners, owners, admins and custom roles with analytics view access can use it. It is not available to organisations using customer managed encryption keys, HIPAA configurations or Access Transparency.
Why this mattersThis is the second Enterprise capability found to be withheld from regulated configurations, alongside skills and skill sharing being off by default under HIPAA readiness. Two data points is a pattern worth naming: an Enterprise organisation under CMEK, HIPAA or Access Transparency is accumulating a materially different feature set from an unregulated organisation on the same plan and the same price, and no single page lists what it gives up.
Claude Code 2.1.268 fixes a regression that landed in 2.1.265 on 8 September. A regular expression inside the Artifact tool input schema was rejected by third-party Anthropic-compatible endpoints reached through ANTHROPIC_BASE_URL, so every turn failed with HTTP 400. Anyone pointing the CLI at a proxy or a compatible non-Anthropic endpoint was fully broken until this release. Check the version before reporting it as an endpoint fault, because the error surfaces at the endpoint and the cause was in the client.
Why this mattersOnly surfaces that accept a base URL are exposed. That is the CLI and the Agent SDK. The hosted surfaces have no equivalent setting, so Cowork, the desktop app and Claude Tag were unaffected by a defect that stopped self-hosted and proxied deployments entirely.
Two changes in Claude Code 2.1.268 bring the three cloud providers into line with first-party sessions. The system prompt on Bedrock, Vertex and Foundry now delivers environment, model and settings detail as attachments, the way first-party sessions already did. And those sessions keep the tool list byte-stable across a conversation, with late-connecting tools loading as deferred definitions rather than rewriting the list. Rewriting the tool list invalidates the prompt cache, so a cloud deployment was paying for cache misses that an identical first-party session avoided.
Why this mattersDeferred tool loading reached first-party sessions in 2.1.267 on 9 September and the cloud providers one release later, so the two were a day out of step. This is a gap closing rather than a new feature: the same conversation on the same model was cheaper on first-party than on Bedrock, Vertex or Foundry, for a reason nobody running it could see.
Desktop v1.52386.0 adds chatSessionRetentionDays, coworkSessionRetentionDays and codeSessionRetentionDays, each accepting a value from 1 to 3650 days, plus sessionRetentionHold for legal hold. Retention is set separately for each session type, so an organisation can keep Code sessions for years and Chat sessions for a fortnight, or the reverse. This is the first documented way for an organisation to bound how long session content lives on the device rather than only controlling who can see it.
Why this mattersThese are desktop app managed settings. No equivalent retention key was found this run for the terminal CLI, the Agent SDK or Managed Agents, so an organisation that sets a retention policy for desktop sessions has no documented way to apply the same policy to the same work run through the CLI. That is a new cross-surface gap rather than a rollout in progress, because the setting is documented as shipped on one surface only.
Desktop v1.52386.0 deprecates an undocumented client-certificate fallback setting. Releases from 1.49585.0 onward no longer read it, because the app now presents TLS client certificates natively. Deployments that still set it keep working for now. Users see an in-app deprecation warning from 3 November 2026, and the setting stops being accepted on 17 November 2026. The stated action is to remove it once every device is on 1.49585.0 or later. One caveat matters for anyone planning that removal: the changelog does not publish the setting key name, describing it only as undocumented, so there is nothing to grep a managed configuration for. An administrator has to wait for the in-app warning on 3 November to learn which of their own settings is affected, which leaves fourteen days between learning and the cutoff.
Why this mattersThis is the second dated managed-configuration cutoff now running on the desktop app, alongside the renamed settings spellings that stop working on 7 October. Both are desktop app deadlines. Whether the terminal CLI carries an equivalent cutoff for its own renamed keys is still an open question in Parity, unanswered since 3 September.
Desktop v1.52386.0 fixes otlpTracesEnabled failing to restrict trace export. Traces were still exported wherever an endpoint was configured, even after an administrator had turned export off. Export now requires both otlpEndpoint and otlpTracesEnabled set to true. Any organisation that relied on the toggle alone to stop session telemetry leaving the device was not stopping it, and the setting reported as off while data continued to flow. Check the collector for traces received during the window rather than assuming the toggle held.
Why this mattersGateway telemetry gained user.email and user.groups on 8 September and began exporting OTLP straight to the collector. So the period in which this override was live is also the period in which the exported records started carrying identifiable user fields.
The platform release notes dated 10 September add an auto mode to Managed Agents permission policies, which evaluates agent and MCP tool calls on the server. The ant CLI gains a command to attach a terminal to a running Managed Agents session, which is the first documented way to watch one interactively while it runs. Managed Agents publishes no changelog of its own, so the platform release notes are the only record of either change.
Why this mattersServer-side evaluation of a tool call has no equivalent on any other surface. Claude Code, the Agent SDK, Cowork and the desktop app all decide permissions on the client, where the rules sit on the same machine as the work and anyone who can edit that machine can edit the rules. An organisation that needs a permission decision it cannot be argued out of locally now has exactly one surface that offers it, which is a new cross-surface gap and a real reason to choose Managed Agents over the alternatives.
Desktop v1.52386.0 changes how the app responds to the Windows update of 8 September. It now identifies the Windows update as the cause instead of deleting and reinstalling the workspace. The changelog is explicit that the underlying problem remains unfixed and that only the destructive response to it has changed. So the correct reading is that Windows Cowork users are no longer losing a workspace to this, but the condition that triggered it is still present and a later release is needed to remove it.
Why this mattersThis is the second Cowork data-loss defect in three days, after a task deleted while in use disappeared from the app on 8 September while leaving its files on disk. The two point opposite ways, one destroying state the user wanted and one leaving state the user thought was gone, and neither appears on the unified apps release notes page.
Version 0.3.268 adds result_index to result messages, giving each result its position in delivery order within a run, counting from 0. It adds local_command to the turn result for a slash command that ran without entering the model loop, carrying the command name, so a caller can tell a local command apart from a model turn. reload_plugins gains a hold_on_cache_impact option that prevents a reload which would invalidate the session prompt cache. resume_reason is added to messages where a host restart interrupted an automatic turn re-run. And get_context_usage now returns kind categories, used, free, buffer and deferred, matching the rows in a /context result.
Why this mattersThe hold_on_cache_impact option is the notable one, because it is the first control that lets a caller decline a plugin reload on cost grounds rather than discover the cache loss afterwards. It is documented for the TypeScript SDK only. The Python SDK is still on 0.2.152 from 2 September and carries none of these five.
Claude Code 2.1.267 fixes the model picker re-sending every tool definition when the model changed, which cost a prompt cache miss on every switch. Commit and pull request attribution text now arrives as a conversation note that updates when the model changes, rather than being fixed into the recorded prompt.
A main-session read of the Claude Design admin guide for Team and Enterprise plans found these two sentences and no others bearing on defaults: "Claude Design is available in beta to Pro, Max, Team, and Enterprise plans" and "This capability is default off for Enterprise plans." The article names a default for Enterprise only. It states no default for Team. The article carries a date of 23 July 2026, which is earlier than the date Parity read it, so the page has not changed underneath the record.
Why this mattersParity had recorded Claude Design as enabled by default on Team, sourced to this article on 19 August 2026. The sentence supporting that is not on the page. The Team default is therefore being reset to unconfirmed and shown in the open questions list rather than carried as a fact. Availability to Team is unaffected and remains documented. This is a correction to Parity's own record, not a change by Anthropic.
Claude Code 2.1.267 adds a maxEffortLevel setting, set either at the top level or per model under modelSettings. It puts a ceiling on the effort level for every provider, the direct API and Bedrock, Vertex and Foundry alike, and users can still pick a level below the cap. This is the first documented way to bound effort centrally rather than session by session, so a managed fleet can hold down the cost of high effort runs without blocking them outright.
Why this mattersEffort control is fragmented across surfaces. Claude Code already had effort frontmatter on commands and skills, and the platform release notes of 2026-09-03 extended per message effort control to Google Cloud for Fable 5.1, Mythos 5.1 and Opus 5. A single ceiling that applies across providers appears only in Claude Code. Neither the Agent SDK changelog nor the platform release notes describe an equivalent cap.
Claude Code 2.1.267 adds --system-prompt-snapshot off. By default a conversation reuses the system prompt recorded when it started. With the flag set to off, the prompt is rendered again on every request, which is what you want while iterating on prompt text. The TypeScript Agent SDK shipped the matching control the same day in 0.3.267: systemPrompt recording now defaults on for custom prompts and appends, a mid session prompt change takes effect at the next compaction, and passing snapshot false keeps per request rendering.
Why this mattersThe CLI and the TypeScript SDK moved together on 2026-09-09, in 2.1.267 and 0.3.267 respectively. The Python SDK is still at 0.2.152 from 2026-09-02 and carries neither the flag nor the recording default.
Claude Code 2.1.267 fixes Cowork scheduled tasks running in the cloud failing at startup for organisations whose managed settings require sandboxing. The task did not begin at all, so the symptom was a missing result rather than an error inside a run, which is the harder failure to notice on an unattended schedule.
Why this mattersScheduled task defects were fixed on two surfaces within two days. The desktop app v1.49585.0 of 2026-09-08 fixed three scheduled task defects around Mac sleep, and Claude Code 2.1.267 fixes this cloud sandboxing startup failure. The two surfaces schedule work through different paths, so a fix on one is not evidence of a fix on the other.
In sessions without ToolSearch, MCP and plugin tools added part way through a session were being appended to the tool list, which invalidated the prompt cache. Claude Code 2.1.267 sends them to supported models as deferred definitions instead. Anyone running a large MCP server whose tools appear after startup was paying a cost increase with no visible symptom.
Claude Code 2.1.267 fixes five related defects in resumed sessions. A resumed session rewrote the inline tool set when an MCP connector reconnected at a different moment than before. It re-rendered tool descriptions instead of replaying the recorded ones when the first turn had run a tool. It rewrote earlier MCP tool announcements before the connectors reconnected, dropping extended thinking with them. A claude.ai connector whose tools changed between a session and its resume caused both a cache miss and dropped thinking. And resuming a print mode conversation interactively changed the system prompt prefix. Subagents and sessions started with a custom or appended system prompt now record the prompt and tool definitions once rather than re-rendering them.
Two fixes in Claude Code 2.1.267 stop extended thinking being thrown away when the tool list moves under a live conversation. The first covers an MCP server re-sending, or a built-in tool re-rendering, a tool the model had already loaded. The second covers a tool that vanishes mid-conversation, from a disconnected MCP server or an upgrade, which rewrote the tool list and discarded earlier thinking with it. A session carrying many MCP tools was losing reasoning silently.
Claude Code 2.1.267 fixes reloading a session whose saved transcript exceeds 5 MB. Parallel tool calls, and the hook output attached to them, were being dropped from the reloaded conversation. The changelog states the 5 MB threshold, so the defect reached long sessions only.
Claude Code 2.1.267 changes allowedHttpHookUrls, httpHookAllowedEnvVars and allowedChannelPlugins so that an unreadable managed value admits nothing rather than everything. Before the fix an administrator who set one of these keys got no restriction at all if the value could not be read, and nothing reported that the restriction was absent.
Why this mattersThis is the same fail closed correction applied elsewhere in the same fortnight. Claude Code stopped silently ignoring an unparseable managed settings file on 2026-09-02, and the desktop app refused to start on one in v1.46388.1. The pattern is consistent across the two surfaces, though each was fixed separately rather than by a shared change.
Claude Code 2.1.267 fixes claude remote-control exiting, and taking every attached session with it, when its server credential expired about 30 days after start. The host now re-registers itself and keeps running. A long lived Remote Control host was therefore failing on a monthly cycle, and the failure removed sessions that had nothing wrong with them.
Claude Code 2.1.267 fixes /context and other local command output rendering as a blank block on mobile clients. The command ran, its result was simply not displayed, so a mobile user saw silence rather than an error message.
Two fixes for Claude Code on the web in 2.1.267. GitHub Enterprise Server sessions showed the connected GitHub account as disconnected once its token expired, and pull request and issue operations now refresh it automatically. In organisations that have not installed the Claude GitHub App, gh and GitHub API calls were failing outright, and now fall back to the user connected GitHub account, saying so when there is no account connected.
Claude Code 2.1.267 carries four Claude Tag changes. The preset connection forms in Claude Tag admin settings gain a link to switch to a custom connector without starting the form again. An organisation that has run out of usage credits was told the API rejected the request as invalid, and now receives a reply naming the real cause and how to add credit. A threaded request to edit or delete a message Claude had posted at the top level of a channel was answered with a correction instead of reaching the session that posted it. And the Connect action on tool access requests, under Admin settings and Review requests, was failing with an authorisation error or showing the requested access bundle as deleted.
Why this mattersThe Claude apps unified release notes page is the documented home for Claude Tag, and it has carried nothing for Claude Tag since 2026-06-23. These four changes appear only in the Claude Code changelog, which is not where a Slack workspace administrator would look. The same page is now more than two weeks behind the desktop app as well, so the pattern is one page falling behind rather than one surface being neglected.
Claude Code 2.1.267 fixes effort frontmatter on custom commands, skills and subagents being ignored on models whose default effort is still pinned. The changelog names Opus 4.7, Opus 4.8 and Fable 5. A skill that declared an effort level ran at the pinned default instead, with no warning, so the declared value was doing nothing at all on those three models.
The TypeScript Agent SDK 0.3.267 adds getCcrEvent and getSseLastSequenceNum to the browser SDK server-sent events transport, along with the fromSequenceNum, onCatchUpTruncated and onDeliveryUpdate options. Together these let a browser client resume an event stream from a known sequence number and learn when the catch-up was truncated, rather than guessing what it missed across a reconnect. The same release changes systemPrompt recording to default on for custom prompts and appends, with snapshot false available to keep per request rendering. The release is dated 2026-09-09 from the npm registry timestamp, which matches the Claude Code 2.1.267 release it states parity with.
Why this mattersThe systemPrompt recording change lands in the TypeScript SDK on the same day the CLI adds --system-prompt-snapshot off. The Python SDK has neither. The browser SSE transport has no Python equivalent at all, since the Python package ships no browser transport.
Claude Code 2.1.267 fixes expired AWS or Google Cloud credentials, when Claude Code runs under a host application such as Claude Desktop, retrying ten times and reporting a generic request failed message before the re-authenticate error finally surfaced. The user saw a run of unexplained failures instead of being told to sign in again.
Claude Code 2.1.267 changes gateway behaviour. An upstream configured with forward_user_identity that returns a 429 now passes that 429 straight back to the developer whose email was forwarded, rather than failing over to the next upstream. Failover was defeating the proxy per user limits, because a developer who exhausted a limit on one upstream was simply served by another. Any gateway deployment that relied on failover for availability will see refusals it did not see before.
Claude Code 2.1.267 changes --use-anthropic-git-proxy so a self-hosted runner reports it to the server at registration, and prints a warning for every session that still clones through the legacy git proxy. The warning marks a path that is being moved away from, though the changelog states no cutoff date for it.
Claude Code 2.1.267 carries eight VS Code extension fixes. The extension host hung at 100 percent CPU when forking, editing an earlier message or rewinding in a conversation whose saved transcript contained a cyclic parent link. Pasting a screenshot on WSL2 or WSLg inserted raw image bytes into the chat input. Chat diff blocks always rendered against a dark editor theme and now follow the active theme, high contrast included. Mixed right to left and English text rendered in the wrong order while typing. Accepting an edit on a file with Windows line endings failed with a string not found error. At-mentions dropped files whose paths contain spaces. The sessions list failed to load over Remote SSH when the workspace folder existed only on the remote host. And ripgrep processes ran away in large or symlink heavy workspaces.
Claude Code 2.1.267 fixes a marketplace entry path containing a backslash bypassing the containment check for fetched marketplaces on macOS and Linux. Containment is what stops a marketplace entry reaching files outside its own directory, so a bypass is a boundary failure rather than a cosmetic one. The fix is scoped to fetched marketplaces, which are the ones pulled from a URL rather than sitting on the local disk, and to the two platforms where a backslash is a legal filename character rather than a path separator.
Why this mattersPlugin and marketplace path containment has been fixed repeatedly on Claude Code and on the desktop app across the last fortnight, each time separately. The Agent SDK and Managed Agents have no plugin marketplace at all, so they are not exposed to this class of defect, which is a gap working in their favour for once.
Resuming a subagent that was spawned in the foreground changed the tool list and the system prompt prefix, so the prompt cache could not be reused. Separately, agent teammates and resumed subagents moved SubagentStart hook context and preloaded skills out of the prompt prefix on later turns, with the same effect. A third fix makes /fork keep the original conversation prompt cache in the new background session. None of these produce a visible symptom. They show up only as higher cost and slower first tokens on delegated work.
Why this mattersThis is the third consecutive release carrying prompt cache invalidation fixes for delegated work, after the two recorded on 2026-09-02 and the agent teammate fix on 2026-09-04. Parity records no equivalent cache reporting on Managed Agents or in Cowork, so the same class of defect there would be invisible.
2.1.265 made CLAUDE_CODE_USE_GATEWAY force Cloud gateway sign-in by itself, even when it was set alongside an API key, an apiKeyHelper or custom auth headers. Every request in that configuration failed with "Not signed in to the Cloud gateway". 2.1.266, published the same day, restores the previous behaviour: the variable is ignored on its own, and no configuration needs to change. Anyone who upgraded to 2.1.265 and stayed there is broken until they take 2.1.266.
Why this mattersBoth versions carry a 2026-09-08 date, so the window where 2.1.265 was the only available build was short. Parity records no equivalent variable on the desktop app, which uses forceLoginGatewayUrl and forceLoginMethod instead.
Telemetry that Claude Desktop and Cowork send through the Claude apps gateway now carries user.email and user.groups. Separately, Claude apps gateway sessions export OpenTelemetry directly to the collector named in OTEL_EXPORTER_OTLP_ENDPOINT rather than relaying it. Both are attribution changes: they make it possible to tie a session to a named person and a group, which is what an admin wants for cost allocation and what a privacy reviewer will want to know about.
Why this mattersParity recorded on 2026-09-02 that OpenTelemetry from cloud sessions was missing the attributes needed to attribute it to a person. This closes that gap for gateway sessions. OpenTelemetry monitoring for Cowork remains Team and Enterprise only and off until an admin configures an endpoint.
--plugin-dir previously took a single plugin directory. It now also accepts a folder whose children are plugins: every child folder carrying a manifest is loaded, and children added or removed while the session is running are picked up without a restart. This removes the need for one flag per plugin when developing or testing several at once.
Why this mattersParity records no equivalent on the desktop app or Cowork, where plugins arrive through a marketplace or an organisation folder rather than a directory flag.
A plugin path containing a backslash got past the check that keeps a plugin inside its own directory, so a plugin could reach files outside its root. Fixed. A second fix in the same release stops plugin directories whose names begin with two dots being wrongly refused as outside the plugin root, which was the same check erring the other way.
Why this mattersParity recorded the symlink containment check itself on 2026-09-01. This is the second correction to it in eight days, on the Claude Code side. Whether the desktop app and Cowork share the implementation is not documented.
A server entered with transport type http that implements only the older HTTP plus SSE transport never connected at all, with no fallback. Fixed. A second connector fix in the same release stops some claude.ai connectors in cloud sessions reporting that they need authentication when they do not. A third stops a remote MCP server that needs sign-in from registering an OAuth client before authentication is actually attempted.
Why this mattersParity recorded on 2026-09-04 that one timed-out startup fetch could leave a session with no claude.ai connectors at all. These are separate defects in the same connector path, and the pattern of connector faults that present as an auth problem rather than a transport problem is now three releases deep.
Non-interactive sessions, meaning claude -p, Agent SDK sessions and cloud sessions, reset the shell working directory at each message, so a cd in one turn did not survive into the next. Claude Code 2.1.265 fixes it, and TypeScript SDK 0.3.265 carries the matching fix, described there as multi-turn sessions no longer resetting the shell working directory so that cd commands persist across turns.
Why this mattersThis is a rare case of a behavioural fix landing on Claude Code and the TypeScript Agent SDK in the same release pair. The Python SDK is at 0.2.152 and carries neither, so a Python agent that relies on a persistent working directory still has the old behaviour.
0.3.265 adds user_message_uuid and user_message_uuids to synthetic turn replies and results, and to turns that Claude Code initiates on its own, such as a resume. It fixes user_message_uuid being missing from the success result of a turn that made no API request, and changes when the field is set: it is now stamped on the first reply after the message changes rather than once per turn. These are correlation identifiers, so anything that joins SDK output back to an input message is affected by the timing change.
Why this mattersParity records no equivalent identifier on the Python SDK at 0.2.152, so a Python consumer cannot correlate turns the same way.
Resuming a workflow run after the container restarted did not work. It does now, and a resume attempted with a missing run journal fails with an explicit error instead of an unclear one. A related fix stops resumed sessions showing long model-facing recovery instructions to the user in notices, and another improves resume time for long sessions that read many files.
Why this mattersParity records session resume and fork as a Claude Code and Agent SDK capability with no Cowork or Managed Agents equivalent for workflow-level resume, so a container restart there has no documented recovery path.
The changelog read at tag v0.3.266 carries a section for 0.3.264, reading "Updated to parity with Claude Code v2.1.264". The npm registry returns HTTP 404 for that version, checked from the main session, so it was never published. The latest published version is 0.3.266, and 0.3.265 and 0.3.266 both exist on npm. Claude Code has no 2.1.264 heading on its changelog either, so the skipped number is consistent across both.
Why this mattersThis is the second time this has happened. Parity recorded the same pattern for 0.3.262 on 2026-09-06, which is documented in the changelog and absent from npm. Two instances in three days makes this a property of the release process rather than a one-off, and it means the changelog is not a reliable list of what a consumer can install.
A new 1 GB cap applies to tool results written to disk, and the in-conversation preview states when the file was truncated. Before this, a very large tool result could consume disk without any indication in the session that the saved file was incomplete.
Why this mattersParity records no documented cap on tool result size for Managed Agents or Cowork, so the same runaway result there has no stated limit.
/model opusplan[1m] was rejected with "Model not found". /model claimed a model had been "saved as your default" even when the settings file could not be written, so the setting silently did not persist. The /model picker and the VS Code model pill showed the raw Bedrock, Vertex or gateway identifier instead of the model name. A fourth fix stops the advisor tool and its instructions being re-decided per request from that request model.
Why this mattersThe false save confirmation matters beyond Claude Code: Parity records no equivalent write-failure reporting for model defaults on the desktop app, so a locked settings file there would behave the same way with no documented signal.
Sessions started with --bg were occasionally retired part way through a turn. Remote Control sessions sent the end-of-turn signal before the last message of the reply, so a client could act on an incomplete answer. Remote Control also uploaded a session pulled with /teleport into the connected session, and /clear issued from Remote Control waited on SessionStart hooks and on open terminal dialogs.
Why this mattersParity recorded on 2026-09-04 that a message sent to an offline Remote Control session reported itself as delivered, and five further Remote Control defects the same day. This is the third consecutive release fixing Remote Control delivery semantics, which is the pattern worth watching rather than any single fix.
A skill running with context: fork did not emit its kickoff prompt or its text turns as progress events in stream-json output. Anything consuming stream-json to show progress saw a forked skill as silent until it finished.
Why this mattersThis affects any Agent SDK or headless consumer that renders progress from stream-json. Parity records no progress event stream for Managed Agents, so there is no equivalent to compare against there.
Plugin display metadata is now taken from the marketplace entry in preference to plugin.json, on the Installed tab and in claude plugin details. /plugin Discover and Browse and claude plugin list --json --available showed no description or display name for marketplace plugins whose metadata lives only in plugin.json, which is fixed. A plugin default component folder that the operating system cannot check was silently skipped and is now reported in /plugin.
Why this mattersThe silent skip is the one that matters: a plugin could load with a component folder missing and nothing said so. Parity records no equivalent diagnostic on the desktop app or Cowork plugin management.
The Claude apps gateway OTLP telemetry relay paused all forwarding to the collector for 30 seconds after it rejected a payload, so one malformed batch took every other batch down with it for that window. Fixed.
Why this mattersRead alongside the same release moving gateway sessions to export directly to OTEL_EXPORTER_OTLP_ENDPOINT, this removes a relay that was a single point of loss. An organisation depending on continuous telemetry for audit had a documented 30 second blind spot per rejection until now.
A machine with forceLoginGatewayUrl set now runs as a Claude apps gateway session from startup rather than becoming one later. A related fix stops /login reporting "no gateway URL is configured" in contexts where one was.
Why this mattersParity recorded on 2026-09-04 that forceLoginMethod gateway now ignores a leftover API key or claude.ai login. The two settings are converging on the same behaviour from different directions, and an organisation using both should re-read which one it actually relies on.
Where managed settings lock only skills to plugins, /add-dir also refused to load agents defined in the added subdirectory, which is wider than the policy stated. Fixed, so the lock now applies to skills alone.
Why this mattersThis is a managed-policy over-enforcement, the mirror of the under-enforcement Parity recorded on 2026-09-04 where cloud sessions discarded a plugin that managed settings force-enabled. Both point at the same settings layer behaving differently from what the policy names.
Publishing an artifact accepted connector tool names that the connector does not actually expose, so a page could be published declaring a capability that would never work for a viewer. Fixed.
Why this mattersParity records artifact publishing on Claude Code and the apps. There is no documented validation of declared connector tools on the other surfaces, so whether the same permissive behaviour exists there is not stated.
On Windows, Read, Write and Edit refused every file when the session ran in an AppContainer or under a restricted token sandbox. Fixed. Two other Windows-adjacent improvements land in the same release: --worktree startup on large repositories now uses parallel checkout on git 2.32 and later, and VS Code gains automatic archiving of inactive sessions with a new "Archive inactive sessions" setting defaulting to 14 days, plus a fix for the sidebar chat coming back blank after a reload when a conversation had been open over ten minutes.
Why this mattersSandboxed execution is recorded in the matrix as a Claude Code capability. A total file access failure under the Windows sandbox means that capability was effectively absent on that platform, which the matrix status did not distinguish.
The app runtime is updated to Electron 44, which is Chromium 152, and the minimum supported operating system rises to macOS 13 Ventura. A Mac on macOS 12 or earlier does not get this release. This is a hard requirement rather than a recommendation, so it decides whether a machine can take any desktop update from here on, including the Cowork and Claude Code session features that ship inside the app.
Why this mattersThis is the first minimum operating system rise Parity has recorded for the desktop app. It has no equivalent on the web or mobile surfaces, and the Claude Code CLI carries no stated macOS floor, so a machine below macOS 13 loses the desktop app and Cowork but keeps the terminal CLI.
Scheduled tasks behaved badly around sleep in three distinct ways, all fixed in this release. A task running while the Mac went to sleep sometimes stopped and was reported as unresponsive on wake. A task missed during sleep sometimes started during a brief background wake and failed, and now waits until the Mac is fully awake. A one-time task occasionally started several sessions at once after wake. Anyone relying on a scheduled task to run unattended on a laptop was exposed to all three.
Why this mattersScheduled tasks are recorded in the matrix as a Cowork and desktop capability with no equivalent on Claude web or mobile, so there is no other surface to fail over to. The duplicate-session failure mode is the expensive one, because a one-time task that starts several sessions is billed for all of them.
An invalid value for the Required organization device policy was previously ignored in silence, so a device the administrator believed was restricted was not. It now blocks sign-in and shows a configuration error in the diagnostic report. Any organisation with a typo in that policy today will see sign-ins start failing after this update rather than continuing to be unrestricted.
Why this mattersThis changes the failure direction of a governance control from open to closed, which is the safer direction but is a breaking change for a misconfigured fleet. Parity records no equivalent device policy on the Claude Code CLI, which uses managed settings instead.
A new continuousAccessEvaluation key on the Microsoft 365 entry in managedMcpServers makes the bundled connector request Continuous Access Evaluation tokens from Microsoft, on both the operating system sign-in broker path and the browser path. Those tokens can live up to 28 hours but are revoked within minutes when an administrator revokes sessions or the tenant network policy changes. It defaults to enabled. Set it to disabled to keep the previous behaviour of standard one hour tokens on every sign-in path.
Why this mattersThis is a default-on change to token lifetime, so it takes effect without any admin action. The longer-lived token is the tradeoff for faster revocation, and an organisation that assumed a one hour ceiling on connector tokens should re-read this. Parity records no equivalent connector token policy on the Claude Code CLI or Claude web.
microsoftAuthBroker gains a required option: Microsoft 365 sign-in fails outright when the operating system sign-in broker is unavailable, instead of falling back to the browser, so the refresh token always stays with the broker. Setting it also removes a token cache left by an earlier browser sign-in. The upgrade ordering matters: versions before v1.49585.0 treat required as disabled, which is the opposite of the intent, so it should only be set once every device is on this version or later.
Why this mattersA security setting that inverts its meaning on older clients is a rollout hazard rather than a plain feature. Parity records no equivalent broker enforcement anywhere else, so this control exists only inside the desktop app.
Deployments on the Claude API, Google Vertex AI, Amazon Bedrock and Bedrock Mantle that set no custom base URL no longer have Claude Code experimental features suppressed. The practical result is that tool search is on by default, on Vertex AI with Claude 4.5 and newer, and toolSearchEnabled no longer has to be set. Gateway and Foundry deployments, and anything behind a custom base URL, are unchanged.
Why this mattersThis opens a capability difference between cloud deployments that previously behaved alike: a direct Bedrock or Vertex deployment now gets tool search by default, while the same organisation running through a gateway or Foundry does not. That split is exactly the kind of thing the per-surface documentation does not state in one place.
A local Claude Code session started from the desktop app no longer requires Git when it does not use a worktree. On Windows this removes the Git for Windows and Git Bash prerequisite for starting a session. A session that does use a worktree still needs Git.
Why this mattersThis lowers the setup requirement for the desktop-hosted Code session specifically. Parity records the terminal CLI requirement separately and this entry does not change it.
Closing the Files pane, expanding another pane or opening a file in a new window discarded unsaved edits with no prompt. A failed save reported that the file had changed on disk rather than that the save failed, and now says the file could not be saved and offers Try again. A third fix stops the editor joining lines in files that mix Windows and Unix line endings.
Why this mattersSilent data loss in an editor pane is the same class of defect Parity recorded for Cowork on 2026-08-31. Two separate panes in the same app losing user work without a prompt is a pattern rather than an isolated bug.
Choosing a different model while a session was starting, restarting, or still answering caused the selection to revert or be refused. The session now uses the chosen model. Separately, changing model in an SSH or WSL session no longer fails with a "plugin hooks could not be loaded" error.
Why this mattersModel choice per session is recorded in the matrix as available on Claude Code, Cowork and the apps. A selection that silently reverts means the surface reports a capability it did not deliver, which is worse than not offering it.
A message written after hitting the five hour usage limit is now held and sent automatically when the limit resets. It can still be edited, cancelled or sent early before then. Previously the message simply waited on the person to come back and resend it.
Why this mattersThis is a usage-limit affordance with no recorded equivalent on Claude web, mobile or the CLI, where hitting the limit still requires a manual resend.
Deleting a Cowork task while it was in use removed it from the app while its files stayed on disk, leaving no way to retry the delete. The task is now retained so the delete can be retried. Two other Cowork fixes land in the same release: a conversation started from an artifact or from an artifact comment Send to Claude did not use the selected model, and the app could quit at launch when a very large number of Cowork tasks were present.
Why this mattersParity recorded a Cowork data-loss defect on 2026-08-31 that the watch only found second-hand. This is a second orphaned-state defect in the same task store, and the Cowork changelog carried it directly this time rather than the support release notes page, which is still fourteen days behind.
A Bedrock session using IAM Identity Center sign-in showed an internal error or a bare "operation was aborted" message when AWS sign-in was unreachable at session start. It now states whether IAM Identity Center was unreachable, temporarily unavailable, refused the account or role, or returned an unreadable response, with next steps. Separately, Google Cloud Vertex AI sessions sometimes ran under the machine own Google login rather than the credential the organisation had configured, and the app did not ask for a new sign-in after the Google session expired. A third fix stops the app refreshing its sign-in token roughly once a second when an inference gateway answers 403 to a model list request.
Why this mattersThe Vertex credential fallback is the serious one: a session silently attributed to a personal Google login rather than the organisation credential is a billing and audit problem, not just an authentication annoyance. Parity records no equivalent credential-source reporting on the Claude Code CLI.
The built-in Microsoft 365 connector reported Connected before any sign-in had happened. The first request in a conversation now offers sign-in, and cancelling a sign-in no longer hides the connector tools. The bundled connector also gains a tool that reads Teams channel messages.
Why this mattersA connector reporting Connected before authentication is a status that cannot be trusted for capability checks. The new Teams channel read tool extends the bundled connector reach into Teams content, which Parity had recorded only for the Microsoft 365 document surfaces.
Terminal tabs now indicate when a command is running, ask before a running tab is closed, and stay open with a Restart option when the shell crashes or is killed instead of closing silently. Two smaller fixes land alongside: chats started from the menu bar or the Quick Entry panel opened as an empty page for up to a minute and ignored the Settings instructions for Claude, and macOS repeatedly prompted that bash wanted to access data from other apps after the app was quit with sessions open.
Why this mattersA shell tab closing silently on a crash loses the output that would explain the crash. Parity records no equivalent terminal pane on any other surface, so there is nothing to compare against.
The Team plan help article states that both Standard and Premium seats carry a weekly usage limit that applies across all models, alongside the per-session multipliers of 1.25x and 6.25x against Pro. The article publishes no absolute figures for either the multiplier or the weekly limit, and no Pro baseline to multiply, so the numbers stay relative only. It names no model anywhere on the page, and states that usage limits on Team are per member rather than pooled across the team. No ship date is published for this wording, so it is recorded as what the article says when read on 7 September 2026, not as something that shipped on that date.
Why this mattersEnterprise is documented the other way round: no per-user usage cap, with dollar spend limits in its place. The cross-model weekly limit is therefore a Team-only constraint, and moving a workload from Team to Enterprise changes the shape of the cap rather than its size.
The Claude Code changelog adds 2.1.263, dated 6 September 2026. Its entire content is a single line about bug fixes and reliability improvements, with nothing itemised. No 2.1.262 heading appears on the page: read from the main session, the sequence runs from 2.1.261 dated 4 September straight to 2.1.263. That is the eighth version number omitted from this changelog since 2.1.240, after 2.1.242, 2.1.244, 2.1.249 and 2.1.253 through 2.1.256. A second Anthropic source names the missing build: the TypeScript Agent SDK changelog carries a 0.3.262 section stating parity with Claude Code v2.1.262. So two consecutive Claude Code releases have shipped with nothing published about what either changed, one by omission and one by a generic line.
Why this mattersThe pattern is specific to the Claude Code changelog. The Cowork desktop changelog itemises every release in named sections and published nothing new today, and the platform release notes date each entry explicitly. Anyone relying on the Claude Code changelog to decide whether a version is worth taking cannot do so for 2.1.262 or 2.1.263.
The TypeScript Agent SDK published 0.3.263 on 6 September 2026. Its only changelog line is parity with Claude Code v2.1.263, so there is no capability change, no new API and no deprecation. The changelog file at that tag also carries a 0.3.262 section, whose only line is parity with Claude Code v2.1.262. That version cannot be installed. A request for the npm registry version document for 0.3.262 returns HTTP 404, while the same request for 0.3.261 and for 0.3.263 each returns a published document with a tarball, so the 404 is specific to that version rather than to the endpoint. The tag-pinned changelog URL for v0.3.262 also returns HTTP 404, so no git tag exists for it either. A pin written from the changelog to 0.3.262 will fail to resolve. Python remains at 0.2.152 from 2 September, so no Python release was published.
Why this mattersPython is now three published TypeScript releases behind on capability, still lacking the latency breakdown and structured output error detail of 0.3.260 and the pluginDelivery option and disposability fix of 0.3.261. Neither 0.3.262 nor 0.3.263 widens that gap, because neither carries a capability change.
The computer use article states "Computer use is in beta for Pro and Max plans." and "Team and Enterprise plans don't have access to computer use at this time." It describes computer use as running in Cowork and in Claude Code inside the Claude Desktop application, on macOS and Windows. Read from the main session on 6 September 2026. Separately, the available beta and research preview index, still dated 7 July 2026, names eight features and computer use is not among them, so a reader working from that index alone would not learn that computer use carries a beta label at all. No ship date is published for the wording, so this records what the article says today rather than when it changed.
Why this mattersOne page carries the label for two surfaces at once. The article names computer use as running in Cowork and in Claude Code, both inside the Claude Desktop application, on macOS and Windows, and names no other surface anywhere, so nothing in it extends computer use to Claude web, Claude mobile, the Agent SDK or Managed Agents. The plan exclusion is stated once and applies to both surfaces together, so Team and Enterprise are shut out of computer use wherever it runs.
Desktop v1.46388.1 fixes remote MCP connectors whose headersHelper mints the credential continuing to fail for up to several minutes after the server rejected an expired credential. The helper now re-runs immediately and the rejected request is retried once. Anyone running a connector that mints short-lived credentials was seeing a multi-minute outage on every expiry rather than one failed call.
Desktop v1.46388.1 adds automatic re-runs for a scheduled task that could not reach the model at all, at 5, 15 and 30 minutes. The changelog gives a computer waking behind a VPN as the example. Until now a scheduled run that fired before the network was ready simply did not happen, and the next attempt was the next scheduled slot.
Desktop v1.46388.1 changes allowedPluginMarketplaces entries set to auto_install or required without a pinned commit SHA, or without manifestSha256 for a url source, to show as available with a configuration warning rather than being removed from the marketplace list. An administrator who wrote an unpinned entry previously saw the marketplace simply absent, with nothing naming the cause.
Desktop v1.46388.1 fixes organisation plugins staying installed for users after an administrator removed the plugin folder from the system org-plugins directory. Until this release, withdrawing a plugin centrally did not withdraw it from the machines that already had it, so folder removal was not a reliable way to stop a plugin running.
Desktop v1.46388.1 fixes removing a file from the message box, after stopping or losing a reply, sometimes deleting that file from the message already sent, which then made Try again on it fail. This is a file handling defect rather than a cosmetic one: the attachment is gone from the sent message and the retry cannot recover it.
Desktop v1.46388.1 changes allowedMcpServers, the key in managed-settings.json rather than in the managed configuration schema, to govern only servers a user adds themselves. A server delivered by a managed-mcp.json file that the allowlist previously filtered out now loads, and deniedMcpServers is the documented way to keep it off. An organisation that relied on the allowlist alone to keep a managed server out of reach will find it loading after this upgrade with no change to its own configuration.
Why this mattersClaude Code made the same semantic change in 2.1.259 on 2 September, which Parity published that day. The desktop app follows on 4 September, so the two surfaces now agree, but a fleet spanning those two days had the same key name meaning two different things at once. The remediation is the same on both: move the entry to deniedMcpServers.
Desktop v1.46388.1 adds blockReadsOutsideWorkingDirectories, which restricts Code sessions to reading files inside the session folder and allowedWorkspaceFolders, with file tools refusing reads elsewhere and sandboxed shell commands losing access to the home directory. It also adds disableBypassPermissionsMode, which removes bypass permissions mode from Code sessions and Cowork tasks so Claude always follows the configured permission policy. Both are managed settings, so they are set centrally rather than by the person at the machine.
Why this mattersClaude Code already carries permissions.blockReadsOutsideWorkingDirectories and fixed a macOS defect in it in 2.1.260 the previous day, so that key now exists on both surfaces. Parity finds no documented Claude Code equivalent of disableBypassPermissionsMode on either changelog page, which is absence of evidence rather than a stated absence.
Desktop v1.46388.1 adds configRecheckIntervalMinutes, setting how often a running app re-checks its managed configuration for changes, from 2 to 30 minutes. Leaving it unset now means 10 minutes, where the app previously checked every 30. A served value applies without a restart, and the key can also be set from device management. The default itself moves, so a fleet that sets nothing still changes behaviour on upgrade and polls three times as often.
Desktop v1.46388.1 adds sshClientPath in beta, the absolute path of the OpenSSH program the app runs for SSH sessions. When unset the app uses the first ssh on the user PATH, which is the behaviour up to now. For a managed fleet this closes a case where a session picked up whichever ssh happened to come first on the path.
Desktop v1.46388.1 fixes memory use on macOS growing steadily while working with files, which the changelog says could end with the system reporting it had run out of application memory. Long desktop sessions touching many files were the exposure, and on a machine running other tools alongside it presented as a system level memory warning rather than an obvious fault in the app.
Desktop v1.46388.1 fixes Extra high and Max effort on Claude Opus 5 quietly running at High when thinking was turned off in Claude Code settings. Those efforts now run with thinking on for the session. Anyone who selected Max effort while having thinking disabled was getting a setting that was not in force, with nothing in the interface saying so. What the correction does to output quality, latency or cost depends on your own prompts, so measure it on a task you care about rather than assuming a direction.
Desktop v1.46388.1 adds keep-awake while Claude works, so the computer no longer idle-sleeps while Claude is working in the Code tab. There is a Keep computer awake while Claude works setting with a Keep awake on battery power option under Settings, Claude Code, a per-session item in the session menu, and a one-time notice after a long task. Long-running and unattended work on a laptop was previously subject to the machine sleeping mid-task.
Desktop v1.46388.1 adds a queue for messages sent while the 5 hour usage limit is reached. They wait above the composer and can be edited, cancelled or sent when ready, rather than failing outright.
Desktop v1.46388.1 changes how unreadable Claude Code managed settings are handled. If a device managed-settings.json, a drop-in file, the device management plist or the Windows policy registry value cannot be parsed, Claude Code now refuses to start and names the source, and sessions on that device will not start until the file or value is fixed or removed. Previously they ran without those settings. This converts a silent policy gap into a hard outage, which is the safer default and also the one that takes a fleet down if a malformed file is pushed. Validate that all four sources parse before rolling this version out.
Why this mattersClaude Code 2.1.259 addressed the same underlying problem from the other side on 2 September, reporting an invalid policy file rather than letting it go unenforced. The desktop app escalates it to a refusal to start. Neither page states whether the CLI adopts the same refusal, so an organisation running both surfaces should not assume one behaviour covers both. Recorded as an open question.
2.1.261 changes /context token counting to use a local estimate when the token-counting API is unavailable, rather than issuing extra small-model requests. The figure becomes an estimate in that case, and the requests it replaces were billable.
Claude Code 2.1.261 adds /skill-doctor, which lists the skills loaded into a session, shows which ones went unused, and states what each costs in context so they can be pruned. Until now the context cost of an installed but unused skill was not visible from inside a session.
Why this mattersNo equivalent command is named for Cowork, the desktop app or the Agent SDK in their changelogs read this run. Skills reach Cowork sessions through the same plugin mechanism, so the cost exists on those surfaces too, but only Claude Code can now report it.
Claude Code 2.1.261 adds bashOutputMaxChars and taskOutputMaxChars, which raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters. It also adds --append-subagent-system-prompt-file, which reads a subagent system prompt from a file for prompts too large to pass on the command line.
Why this mattersThe TypeScript Agent SDK 0.3.261 changelog names no equivalent output-size setting, so the inline output ceiling for an SDK-driven subagent is not documented in that release.
2.1.261 fixes in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn. That changed the request prefix, so the prompt cache missed. The only symptom was cost, which is why a defect like this can run a long time before anyone looks.
2.1.261 fixes session resume losing hook output and other context around parallel tool calls, which changed the request sent after the resume. A resumed session was therefore not equivalent to the one it continued, and nothing surfaced the difference.
2.1.261 changes auto mode to treat a link that packs content into a public diagram renderer URL as an upload to that site, so it is no longer auto-approved unless it was asked for. Encoding working content into a rendering service URL is a route by which that content leaves the machine without a step that looks like an upload.
Why this mattersThe Cowork and desktop changelog entries for v1.46388.2 through v1.46388.4 name no equivalent rule, so it is not established that a Cowork session treats the same link the same way.
2.1.261 changes the prompt word-editing keys to match Bash: Ctrl+W deletes back to whitespace, Alt+F and Alt+D stop at word end, and punctuation separates words. The keybindingFlavor setting no longer has any effect. There is no stated deprecation window, so the setting stops working on upgrade.
2.1.261 makes machines whose managed settings pin forceLoginMethod to gateway ignore an API key or claude.ai login left over from before, and ask for /login instead. Bedrock, Vertex AI and Foundry sessions are unaffected. A fleet relying on the leftover credential will stop at a login prompt on upgrade.
2.1.261 fixes Claude in Chrome file_upload failing with a paths validation error, expected array received undefined, in local Cowork sessions run from the Claude Desktop app. The failure needed all three parts present: the extension, a local Cowork session, and the desktop app hosting it.
Why this mattersThe fix is published in the Claude Code changelog even though the failing combination is the Chrome extension inside a Cowork session hosted by the desktop app. Someone hitting this would most likely look at the Chrome or Cowork notes, where it does not appear.
2.1.261 fixes SendMessage to an offline Remote Control session on another machine reading as delivered. The result now says delivery is queued until that machine reconnects. Anything that branched on the delivered result was acting on a confirmation that was not true.
2.1.261 fixes Remote Control showing a stale permission mode when a phone, browser or claude.ai app attaches to a terminal session or after the mode changes in the terminal; sessions still showing as working after a turn is stopped from a connected device or after a local command such as /clear; a session pulled with /teleport being uploaded into the connected session and appearing appended to the original; the inbound event stream failing behind TLS-inspecting corporate proxies on native Windows; and sessions showing the default effort level on claude.ai when the effort comes from settings.
2.1.261 fixes SDK and cloud sessions ignoring a Stop or interrupt sent just after the first prompt, before the turn had started. The turn now stops rather than running to completion, so an orchestration that cancels early stops paying for work it has already abandoned.
2.1.261 fixes claude.ai connectors staying absent for a whole session when the startup connector fetch timed out. The CLI now retries in the background. Before the fix a single slow start left the session with none of its connectors and nothing saying they were missing.
2.1.261 fixes sustained high CPU usage when a background agent could not be resumed and its wake-up was retried in a tight loop.
2.1.261 fixes cloud sessions discarding a plugin synced from claude.ai when managed settings force-enable the same plugin in enabledPlugins, then falling back to a marketplace clone that could itself fail. The outcome was a session missing a plugin the organisation had made mandatory.
2.1.261 adds an Organization policy line to /status and claude doctor stating why the organisation policy could not be loaded, for example a proxy not passing the endpoint through. In the same release a gateway 403 on the managed settings load now says Claude Code may not be enabled for the organisation, instead of advising a new sign-in.
2.1.261 changes handling when the API sends no response headers. The retry now waits up to API_TIMEOUT_MS, ten minutes by default, instead of a further three minutes, and the messages state what to change.
2.1.261 improves the dangerous rm safety prompt so it also catches rm -rf applied to positional parameters and rm -rf inside double-quoted sh -c scripts. Both were routes by which a destructive command reached the shell without triggering the prompt.
2.1.261 fixes the Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected the desktop app data. An organisation collecting from both surfaces would have seen CLI telemetry arrive and desktop telemetry quietly absent.
Why this mattersThe defect sat between two surfaces that export into the same collector, so neither surface looked broken on its own. Only a collector holding both would show the gap.
2.1.261 fixes feature flags gated to a newer version occasionally applying to an older Claude Code running on the same machine. Two installs on one device could therefore behave differently from what their version numbers implied.
2.1.261 fixes typed or pasted characters occasionally landing out of order or being dropped during fast input or key repeat. A related fix restores deleting the character immediately before an inline [Image #N] chip in the prompt.
2.1.261 fixes the Bedrock setup wizard hanging when AWS or an AWS credential helper never responds, which now times out with a clear error, and its model checks failing behind a TLS-inspecting proxy. It also stops gcpAuthRefresh opening a browser at startup when a slow Google credential check ran against a credential that was still valid, and stops Vertex AI client creation re-running Google Cloud project discovery or spawning extra gcloud processes when GOOGLE_APPLICATION_CREDENTIALS is set. The /model picker and the VS Code model pill now show a model name rather than its raw Bedrock, Vertex AI or gateway ID.
2.1.261 carries a large VS Code batch. Added: a Build a custom style walkthrough in the Output styles menu, an Add server form and a Remove action in the MCP servers dialog, a hollow ring marking sessions open in a terminal or another window, a fold button on permission and question prompts, and Archive session in the session list right-click menu. The model picker becomes one flat list of every model with older model spellings placed last. The remainder are fixes to session tabs, groups, teleport, the usage meter and the pending question card.
Desktop v1.46388.3 adds support for attaching the home folder, Windows Documents, AppData, the macOS Library folder and whole drives. Claude own configuration and session data inside those locations stay off-limits, as do certain credential and shell-startup locations, the entry naming SSH keys, AWS and Google Cloud credentials, and bash, zsh and PowerShell profile files. The widening is the headline; the carve-out list is what decides whether it is safe on a given machine.
Why this mattersThe same desktop app moved the opposite way on file access two builds earlier and on the same date. v1.46388.1 added blockReadsOutsideWorkingDirectories to restrict what a Code session may read, and Claude Code 2.1.260 fixed that key hiding the user git config from sandboxed git on macOS. Attachment scope for Cowork widened and read scope for Code sessions narrowed inside one day and one version line.
Desktop v1.46388.2 fixes Code sessions started in a git worktree failing to initialise on Windows.
TypeScript Agent SDK 0.3.261 adds pluginDelivery set to initialize, which sends the plugins list over stdin instead of on the launch command line, so the command line no longer grows with the plugin count. The changelog attributes the change to Windows start failures with many plugins. The same release fixes query() throwing Object not disposable in runtimes without a native Symbol.dispose, naming Node 22 and earlier vm contexts, which covers the Jest node environment and vitest vmThreads and vmForks, and Node below 18.18.
Why this mattersThe highest Python Agent SDK release is 0.2.152, published 2026-09-02, which predates both changes and carries neither.
Desktop v1.44121.4, released today, adds support in Chat for skills from organisation-provided plugins, and states that Chat-only users can now see and manage those plugins under Customize, matching Cowork and Code. The Chat tab has been the surface where plugin components are present but inactive, so this is the first documented case of plugin-delivered skills executing there. The scope as written is organisation-provided plugins, not personal ones, and it says nothing about mobile.
Why this mattersPlugin skills reaching the Chat tab narrows the difference between Chat, Cowork and Code inside the same desktop app. The entry covers organisation-provided plugins only, so it does not establish anything about personally installed plugins or about skills managed outside a plugin.
Desktop v1.44121.4 fixes organisation-configured URL plugin marketplaces failing to install or load plugins with the error "marketplace entry path does not stay inside the marketplace directory". Anyone running a hosted url marketplace for their organisation would have seen installs fail with a message pointing at path containment rather than at anything they could act on. Claude Code 2.1.257 separately restricted plugin component paths so a plugin can no longer reach outside its own directory through symlinked component paths. Neither changelog references the other, so whether the two are related is not established by either page.
Why this mattersThe hosted url marketplace and the Claude Code git marketplace continue to diverge in their failure modes. A path containment rule tightening on one surface and a path containment error appearing on the other in the same week is worth watching, but nothing published links them.
Desktop v1.44121.4 fixes advanced file analysis in Chat failing with "Workspace unavailable" for users whose organisation enables chatAdvancedFileAnalysisEnabled but turns Cowork off with coworkTabEnabled set to false. The Chat feature was depending on a Cowork workspace, so an admin who enabled the Chat capability and disabled Cowork got a setting that reported as on and did not work. The two keys are documented separately and nothing in either indicates the dependency.
Why this mattersA Chat capability was gated in practice by a Cowork setting. This is the kind of coupling that only appears when an organisation sets one key on and the other off, which is a supported combination.
Desktop v1.44121.4 fixes managed OAuth connectors showing a connection error rather than prompting to sign in when the app starts without a usable sign-in, meaning an expired credential with no refresh token, or a machine where the user has never signed in. It covers servers added by URL alone, where Connect could fail instead of opening the sign-in page. The user-visible effect was a connector that looked broken when it was only signed out, which sends people to debug the server rather than to authenticate.
Why this mattersv1.44121.1 fixed a related case, managed MCP connector sign-in staying permanently stuck when the identity provider no longer recognised the OAuth client the app had registered, with the app now registering a new client automatically. Two OAuth recovery defects in the managed connector path in two days.
2.1.260 reverts the change in 2.1.259 that applied Read deny rules to Bash arguments. The changelog gives the reason: the rule denied npm run build under a Read(./**/build/**) pattern in every permission mode, and made a cd followed by grep prompt even in auto mode. The tightening therefore lasted a single release. If you upgraded to 2.1.259 specifically so that a denied path could not be reached through a Bash argument, that coverage is gone again on 2.1.260 and no replacement mechanism is named. Parity published the 2.1.259 tightening on 2 September, so that entry is superseded after one day.
Why this mattersParity holds no equivalent Bash argument deny rule on any other surface, so this reverses a tightening that only ever existed in the Claude Code CLI. The desktop app bundles its own Claude Code build and neither changelog states which build desktop v1.46388.1 carries, so a desktop fleet cannot tell from these pages which of the two behaviours it is running.
2.1.260 fixes Edit, Write and Read permission rules whose path contains parentheses being dropped as invalid, or ignored by the Bash sandbox. The changelog states the effect plainly: folders configured as read only were writable. Any project or managed policy using a path with brackets in it was not enforcing what it appeared to enforce, and nothing surfaced that. Check every deny rule with a parenthesis in its path and confirm on 2.1.260 that it now holds.
2.1.260 fixes a single file permission rule with an uncompilable pattern, the changelog gives an unclosed square bracket as the example, making every file edit fail with an Invalid regular expression error. Such a deny rule now guards the literal path it spells rather than breaking the whole rule set. One malformed line caused a total edit outage, so hand-written policy files are worth re-reading.
2.1.260 fixes Bash permission checks auto-approving zsh commands that hide a command substitution inside a REPORTTIME, REPORTMEMORY or DIRSTACKSIZE assignment. Those now prompt for approval. Until this release a command shaped like one of those assignments could carry an arbitrary substitution past the approval step. Anyone running unattended sessions on zsh with automatic approvals should treat 2.1.260 as the first release where that path is closed.
2.1.260 changes Glob and Grep so a missing path is reported after permission is decided, matching how Read already behaved. Before this the tools touched the path on disk first, which meant the presence or absence of a path outside the permitted set could be inferred from the error even where reading it was denied.
2.1.260 fixes managed skillOverrides entries keyed on a bundled skill alias, the changelog gives checkup for /doctor as the example, not applying at all. It also fixes Skill deny rules not covering a nested skill listed in the dir:name form. Both mean an organisation policy that looked configured was not in force. If you override or deny bundled or nested skills centrally, re-read those entries against 2.1.260 rather than assuming they worked.
2.1.260 changes server-managed settings so a managed CLAUDE.md, the claudeMd key, no longer triggers the security approval dialog. Hooks, shell command, sandbox and unsafe env settings still require approval. An organisation can now push instruction text to every session without a per-device prompt, and the person at the machine no longer sees a prompt at the moment that text changes.
2.1.260 fixes permissions.blockReadsOutsideWorkingDirectories on macOS hiding the user git configuration from sandboxed git, and hiding a worktree-isolated subagent own checkout from it. Anyone who turned the setting on and saw git behave as though it were unconfigured, or saw a worktree subagent unable to see its own files, was hitting this rather than a git fault.
Why this mattersThe desktop app adds a managed setting of the same name in v1.46388.1 the following day, so the key now exists on both surfaces. Neither page states whether the two implementations share a definition.
2.1.260 removes the one hour time limit on background commands started by subagents. They now run until they exit or are stopped, matching the main session. Any workflow that pushed long-running work into a subagent and saw it cut off at an hour was hitting this limit rather than a fault in the command.
0.3.260 adds four latency fields, first_content_frame_ms, first_stream_post_ms, first_stream_post_ack_ms and first_stream_post_wall_ms, which break the time to first content on a turn into separate stages. Structured output validation errors now identify the offending key, the allowed values and the actual length or count instead of failing generically. thinking_tokens system messages gain an optional user_message_uuid so thinking progress can be tied to the user message that triggered it, and rate_limit_event is re-emitted on repeat 429 responses inside an exceeded window so a client can refresh stale rate limit state. The release also bundles Claude Code 2.1.260, which independently corroborates that version shipping.
Why this mattersAll four are TypeScript only today. The Python SDK highest release is 0.2.152 from 2 September and carries none of them, so a Python client cannot break a turn latency into stages or refresh rate limit state mid-window from the SDK.
2.1.260 changes Claude in Chrome to follow the organisation Claude in Chrome admin setting. Where an admin has turned it off, the --chrome flag, the /chrome command and the browser tools are all unavailable inside Claude Code. This is the first point at which that admin toggle is documented as reaching the CLI rather than only the browser extension.
Why this mattersThe Claude in Chrome admin toggle already governed the browser extension. From 2.1.260 the same organisation setting also decides whether the Claude Code browser tools, the --chrome flag and the /chrome command exist at all, so one admin decision now moves two surfaces rather than one.
The platform release notes entry dated 3 September states that version 1.30.0 of the ant CLI adds ant apply, which creates and updates agents, environments, skills, memory stores and deployments from files in a repository. The described flow is to describe each resource in a file, run ant apply, and approve the plan it prints. It writes a claude-lock.json lockfile, which the entry says to commit so that a later run, locally or in CI, updates the same resources instead of creating new ones.
Why this mattersThis gives the platform side declarative provisioning covering a set of resources under one lockfile. Cowork and the desktop app provision plugins and skills through allowedPluginMarketplaces and organisation plugin folders in managed settings, which pin per entry by commit SHA or manifestSha256 rather than through a lockfile spanning the set.
Claude Code 2.1.259 adds managedMcpServers as a managed setting, letting an organisation hand HTTP and SSE MCP servers to every user. The changelog states it takes the same entry shape as .mcp.json, and that entries naming a command to run are skipped, so stdio servers cannot be delivered this way. The Cowork and desktop changelog documents a managedMcpServers setting of its own whose field names are deprecated, with an invalid entry making that connector unavailable after 7 October 2026 at 12:00 Pacific. Two surfaces now carry a setting with the same name, a different entry shape, and only one of them a dated cutoff. An organisation writing one file for both should not assume the schemas match.
Why this mattersClaude Code and the desktop app now both define managedMcpServers. Claude Code documents the .mcp.json entry shape with command entries skipped. The desktop app documents scope, transport, azureCloud, oauth and toolPolicy fields under a fail-closed 7 October 2026 deadline. Neither page references the other.
Claude Code 2.1.259 changes allowedMcpServers to govern only servers that users add. The changelog states that a literal managed-mcp.json server an allowlist used to filter out now loads on upgrade, and directs anyone who wants it kept off to deniedMcpServers. The change is silent and takes effect on upgrade, so an allowlist written to exclude a managed server stops excluding it without anyone editing the file. Anyone relying on allowedMcpServers as a deny mechanism should move those entries to deniedMcpServers before upgrading.
Why this mattersThis narrows an allowlist rather than a denylist, so it fails open. The desktop app does not document an allowedMcpServers key at all, and manages the equivalent through managedMcpServers entries and isLocalDevMcpEnabled instead.
Claude Code 2.1.259 adds --permission-prompts none for unattended headless hosts: anything that would prompt is denied automatically, while the active permission mode including auto mode keeps deciding everything else. The TypeScript Agent SDK 0.3.259, published the same day, adds permissionPrompts set to none, described as auto-denying permission prompts in unattended sessions while the auto-mode classifier keeps working. This is the rare case of a capability landing on two surfaces at once rather than reaching one and waiting.
Why this mattersClaude Code and the Agent SDK both gained this on 2026-09-02. Managed Agents and Cowork scheduled tasks have no documented equivalent, so an unattended run on those surfaces still has no way to state that a prompt means stop rather than hang.
Claude Code 2.1.259 fixes managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist or the HKLM registry value cannot be parsed. Claude Code now refuses to start and names the source that failed. Before this fix a malformed policy file produced a running client with no policy applied and no warning, which is the worst of the two failure modes for anyone who deploys settings centrally. Check any deployment where the policy file is templated or generated, because a syntax error there was previously invisible.
Why this mattersThis is a fail-closed change on Claude Code. The desktop app fixed a related pair in v1.44121.1, a crash at launch when the settings file could not be read and an invalid settings file causing all app settings to be reset, so both surfaces were mishandling unparseable configuration in the same window.
Claude Code 2.1.259 fixes concurrent sessions silently reverting each other's changes to ~/.claude.json. The changelog states that workspace trust no longer resets and that MCP and project state is no longer lost when many sessions run at once. The failure was silent and scaled with parallelism, so the more sessions someone ran the more likely they were to lose trust decisions and MCP configuration without any error. Anyone who runs several Claude Code sessions side by side and has been re-approving workspace trust should upgrade rather than keep re-approving.
Why this mattersParallel session count is the trigger, so this hit orchestration patterns hardest: agent teams, workflows and any scheduled fan-out. Cowork and the desktop app keep session state server side and do not share this file.
Claude Code 2.1.259 fixes Bash Read() deny rules not covering files given as option values. The changelog names --ignore-revs-file=.env, -f.env and @file forms, git diff and git grep file operands, and cd DIR && cat FILE compounds. It also states that grep -r and cp -r over a directory holding a denied file now ask. A deny rule naming a secrets file was therefore enforceable by direct read but bypassable by passing the same path as a flag value, which is the form a command line naturally takes. Anyone relying on Read deny rules to keep credential files away from Bash should treat versions before 2.1.259 as not enforcing them.
Why this mattersThis is a Claude Code permission-engine defect. The desktop app applies tool policy through builtinToolPolicy with argument scoping, a different mechanism, so the same bypass does not follow from this entry.
Claude Code 2.1.259 fixes the prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled, and separately fixes blocking Stop hooks causing the turn after a block to lose the model's reasoning and, on some models, miss the prompt cache. Both produce a correct answer at a higher price, which is why neither would surface as a bug report. The first is scoped to sessions that turned telemetry off, the second to anyone running a blocking Stop hook. Long-running and scheduled sessions are the most exposed to the first, because they run long enough to cross a token refresh.
Why this mattersPrompt cache and spend visibility remain a Claude Code CLI capability. Neither Cowork nor Managed Agents exposes per-session cache hit reporting, so the same defect on those surfaces would not have been observable at all.
Claude Code 2.1.259 fixes Stop not actually stopping background agents and workflows in remote-control sessions, with killed tasks now staying visible and re-stoppable until their processes exit. It separately fixes resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents. Both defects spend tokens after the operator has asked for the work to end, and the second spends them twice. Anyone who has stopped a workflow and seen the run continue was watching this, not a display lag.
Why this mattersWorkflows and background agents are Claude Code capabilities with no Cowork or Managed Agents equivalent, so this class of runaway cost has no counterpart to compare against on the other agentic surfaces.
Claude Code 2.1.259 fixes remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused. The same changelog records 2.1.258 fixing remote and scheduled sessions failing after a permission approval had been re-sent. The Cowork and desktop changelog records v1.44121.1, dated the same day as 2.1.259, fixing scheduled tasks failing with an error after a permission approval. Three fixes across two surfaces in three days, all in the path where a permission approval reaches a session with nobody watching. Anyone running scheduled or remote work should assume this path was unreliable through the end of August and upgrade both the CLI and the desktop app rather than one.
Why this mattersThe defect class spans Claude Code and the desktop app, and the fixes landed independently on each. Upgrading only one leaves the other exposed, which is not obvious from either changelog on its own.
Claude Code 2.1.259 fixes two defects in the same setting. Frontmatter model: on custom commands and skills was ignored in interactive sessions, so a skill that pinned a cheaper or more capable model silently ran on the session model instead. Separately, auto mode was running a turn on a model it does not support when a command or skill frontmatter named one, and now keeps the session model in that case. Anyone who set model: in a skill to control cost per subtask was not getting it interactively, and had no signal that the pin was being dropped.
Why this mattersFrontmatter model: is a Claude Code and Agent SDK skill mechanism. Cowork plugin skills carry no documented per-skill model pin, so the cheapest-capable-model-per-subtask pattern is not expressible there.
Claude Code 2.1.259 adds --json to claude plugin validate, producing a machine-readable validation report suitable for a CI gate rather than a human reading terminal output. The same release fixes marketplace repo URLs on github.com with a trailing slash or a dangling ? or # producing an unusable .git clone URL, which would have presented as a marketplace that simply refused to install with no obvious cause in the URL as written.
Why this mattersPlugin marketplaces remain absent from the Agent SDK and Managed Agents, so a validation gate built on this flag covers Claude Code and desktop distribution only.
Claude Code 2.1.259 fixes CLAUDE_CODE_MAX_CONTEXT_TOKENS being ignored for Vertex-style model IDs, meaning those carrying an @YYYYMMDD suffix, for model versions Claude Code does not recognise. Anyone running Claude Code against Vertex and setting a context ceiling to control cost or to stay inside a quota was not getting it applied. The variable was accepted, so there was no error to notice.
Why this mattersThis is a Vertex-shaped model ID parsing failure, so the same variable was working on the direct API and on Bedrock ids. A cost control that behaves differently by cloud is not visible from the environment variable documentation.
Claude Code 2.1.259 fixes OpenTelemetry metrics and events from cloud sessions missing the user.email, organization.id and user.account_uuid attributes. Telemetry was arriving, so a dashboard would have looked healthy, but cloud session activity could not be attributed to a user or an organisation and would have been undercounted in any per-person breakdown. Anyone reconciling Claude Code spend or usage by user across local and cloud sessions should re-check the period before this release rather than trust the totals.
Why this mattersThe desktop app added conversation titles to its own OpenTelemetry export in v1.44121.1 on the same day, through a desktop_session_title_set event. The two surfaces export different event sets, so a single OTLP endpoint receives different shapes from each.
The TypeScript Agent SDK 0.3.259 adds user_message_uuids to turn replies, which lets a caller match a response back to the several user messages that were merged into one turn. Before this, a client that merged messages had no way to tell which of them a given reply answered. The same release adds permissionPrompts set to none for unattended sessions. Python claude-agent-sdk 0.2.152, published the same day, carries only a bundled CLI update to Claude Code 2.1.259 and no substantive change.
Why this mattersThe Python and TypeScript SDKs stayed in step on the bundled CLI version but not on capability: user_message_uuids and permissionPrompts are TypeScript only as of these releases, which continues the pattern of TypeScript leading on the SDK surface.
Anthropic published a commerce agents blueprint describing two agent patterns, a shopping agent covering catalogue search, multi-item assembly, preference memory, comparison and cart building, and a merchant agent covering sales analysis, inventory tracking, pricing and promotion suggestions, and campaign drafting behind human approval gates. It is documented as deployable on the Claude API, Amazon Bedrock, Microsoft Foundry and Google Cloud Vertex AI, with a published reference repository. The post cites cart size and purchase completion improvements from customer results, which are the customers' numbers and not a measured property of the blueprint.
Why this mattersThis is a reference architecture rather than a product capability, and it is offered on the API and all three clouds at once rather than reaching one first. It carries no Cowork, Claude Code or Managed Agents packaging.
Desktop v1.44121.1 marks this breaking. The Usage page cost estimate now requires inferenceModelPricingEnabled. inferenceModelPricingMultiplier and inferenceModelPricing refine the estimate only while it is on, and no longer turn it on by themselves. An organisation that configured a pricing multiplier alone, which was previously sufficient, loses its cost estimate on upgrade and gets no error, because the keys it set are still valid and still accepted. Anyone using the Usage page to track spend should set inferenceModelPricingEnabled explicitly before rolling this build out.
Why this mattersCost visibility now needs an explicit enable on the desktop app. Claude Code exposes spend and prompt cache visibility through the CLI without an equivalent gate, so the same organisation gets cost reporting on one surface and a silently blank estimate on the other.
Desktop v1.44121.1 adds inferenceStreamIdleTimeoutSec, which sets how many extra seconds Chat, Cowork and Code sessions wait for model output on a streaming response that is sending only keep-alive pings. The range is 300 to 1800 seconds with a default of 300, and the key is documented as gateway provider only. It exists for gateways that send keep-alives while the upstream model is silent, which is the case that otherwise looks like a live connection producing nothing and then timing out.
Why this mattersThis is a gateway-only key on the desktop app. Claude Code has no documented equivalent, so a deployment behind the same gateway can tune the timeout for desktop sessions but not for the CLI.
Desktop v1.44121.1 widens what isClaudeCodeForDesktopEnabled set to false does. The app no longer starts Code sessions even when asked directly, Preview no longer scans projects for a dev server, and the computer is no longer offered for Remote Control. A Code session requested anyway now shows a message stating Code sessions are turned off by the organisation rather than a retry prompt. The Remote Control withdrawal is the part that will surprise people: an admin who set this key to control the Code tab also removes the machine as a Remote Control target, which is a separate workflow.
Why this mattersRemote Control availability is now a side effect of a Claude Code setting rather than a control of its own. Nothing in the key name indicates it governs Remote Control, so an organisation auditing which machines can be driven remotely will not find this by searching for Remote Control.
Desktop v1.44121.1 fixes scheduled tasks failing with an error after a permission approval. A scheduled task is unattended by definition, so a permission approval reaching it is exactly the case nobody is present to retry. The failure would present as a task that ran, errored and left no useful output, rather than as a task that never started, so it is easy to mistake for a fault in the task itself.
Why this mattersClaude Code 2.1.258 and 2.1.259 fix the same failure shape on their own surface, remote and scheduled sessions failing or stalling after a permission approval. Both surfaces carried this defect through the same window and fixed it separately.
Desktop v1.44121.1 fixes sessions that run Claude Code directly on the device failing to start for organisations that set disableSideloadFlags in Claude Code managed settings, whether through managed-settings.json, an MDM profile or the registry. The changelog also states that in those sessions Claude Code loads none of the desktop plugins, so their commands, agents and hooks are unavailable. That second half is the more important fact: an organisation that sets this key gets an on-device Code session with the plugin layer silently absent rather than an error naming the cause.
Why this mattersA Claude Code managed setting is deciding whether desktop-provisioned plugins load. Two settings systems govern one session, and the failure surfaces as missing commands rather than as a policy message.
Desktop v1.44121.1 fixes MCP servers provided by plugins not connecting in Code and Cowork sessions when managedMcpServers is configured. The changelog states the resulting behaviour: with isLocalDevMcpEnabled set to false, remote MCP servers from plugins connect and their local stdio servers stay blocked. So an organisation that centrally configures MCP servers was, before this fix, also suppressing the MCP servers that its own approved plugins carry, which is not what configuring a managed list would be expected to do.
Why this mattersConfiguring managed MCP servers had the side effect of breaking plugin-supplied ones. The split after the fix, remote connecting and local stdio blocked, is governed by isLocalDevMcpEnabled, so the plugin MCP layer is now gated by a setting written for local development servers.
Desktop v1.44121.1 fixes plugins distributed as a zip whose top level is a single component folder, for example skills/ or commands/, installing with no skills, commands or agents. The install reported success and produced an empty plugin, so the failure looked like a plugin that did nothing rather than one that failed to install. Anyone who published a plugin as a zip and had it reported as not working should re-check the archive layout rather than the plugin contents.
Why this mattersThis affects the hosted url marketplace path specifically, which is the desktop distribution route rather than the git-based one Claude Code uses. The two marketplace implementations continue to fail in different ways.
Desktop v1.44121.1 adds egressProxyUrl and egressProxyPacUrl, which route the app and the agent traffic through a corporate HTTP proxy, or let a PAC file choose the proxy per request, instead of following the operating system proxy settings. On macOS and Windows the Cowork workspace follows the pinned proxy too. Both keys are read from device management or the local configuration file only, and the PAC file wins when both are set. The same release makes HTTPS_PROXY, HTTP_PROXY and NO_PROXY set in the env block of Claude Code managed settings apply to Chat, Cowork and Code sessions even when the computer has a system proxy configured.
Why this mattersProxy control is now expressible in two places for one machine, the desktop managed keys and the Claude Code managed settings env block, with the desktop keys read only from device management or the local config file. An organisation that sets both needs to know which it is actually relying on.
Desktop v1.44121.1 fixes Bedrock and Bedrock Mantle sessions being cut off by network idle timeouts during long thinking phases on Opus 4.7 and later models. The trigger is a model generation change rather than a configuration one: thinking phases got long enough on those models to look like an idle connection. Anyone on Bedrock who saw sessions drop specifically on the harder prompts, and only since moving to Opus 4.7 or later, was hitting this rather than a network fault at their end.
Why this mattersThis is Bedrock specific in the entry as written. The desktop app shipped inferenceStreamIdleTimeoutSec in the same release for gateway deployments with the same symptom, so two different mitigations for one failure shape landed together.
Desktop v1.44121.1 fixes /rewind appearing undone when returning to a session after navigating away, and states this could also cause the next message to silently drop recent conversation history. The visible symptom and the real damage are different: the rewind looking undone is cosmetic, the conversation losing recent history is not, and nothing in the interface announced the second. Anyone who used /rewind and then navigated away should treat that session history as suspect rather than assume the display was the only thing affected.
Why this mattersSilent conversation history loss on the desktop app. Claude Code implements rewind in the CLI with its own state handling and this entry does not extend to it.
Desktop v1.44121.1 adds local scheduled tasks to the Code tab, including the /schedule command and a Scheduled page, described as matching what Cowork already offered. This closes a difference between the two tabs of the same application: scheduling was a Cowork capability and the Code tab had none. The same release adds Claude Code output styles to the Code tab, with an Output style submenu, a /output-style command, a New style option that drafts a style from a plain-language description, and a default style setting.
Why this mattersA capability that existed in the Cowork tab now exists in the Code tab of the same app. The gap was between tabs rather than between products, which is the kind of difference no single surface document describes.
Desktop v1.44121.1 adds conversation titles to the OpenTelemetry export through a desktop_session_title_set event, which carries each Cowork and Code session title plus the Claude Code session ID to join on. It is sent when otlpDesktopLogLevel is info or lower, and the title text is included only when otlpContentCapture includes userPrompts. The gating is on an existing content-capture setting rather than a new one, so an organisation already capturing user prompts starts exporting session titles on upgrade without changing any setting.
Why this mattersA session ID that joins desktop telemetry to Claude Code telemetry is new. Claude Code fixed its own cloud-session OTel attributes in 2.1.259 on the same day, so both halves of a joined view moved at once.
Desktop v1.44121.1 adds claudeAiImport.automatic3pImport in beta. When it is true and deploymentOrganizationUuid is set, the app copies this computer earlier third-party sessions, stored before an organisation ID was configured, into that organisation session store. It runs once per device, in the background, and independently of claudeAiImport.enabled, and a copy interrupted when the app quits resumes on the next launch. The independence from claudeAiImport.enabled is the part worth reading twice: turning the general import off does not turn this off.
Why this mattersThis moves session content that predates organisation configuration into organisation-visible storage. Anyone assessing what an organisation can see should note that the boundary moved backwards in time, not just forwards.
Desktop v1.44121.1 fixes the allowedWorkspaceFolders policy not always being applied to Code sessions over SSH. The policy exists to confine sessions to approved directories, so a path where it was not applied is a path where the confinement did not hold. The entry says not always rather than never, which means the failure was conditional and an organisation cannot establish from the changelog whether a given SSH session was covered.
Why this mattersWorkspace confinement behaved differently depending on how the session reached the machine. A policy that holds locally and lapses over SSH is not visible from the policy documentation.
Desktop v1.44121.1 fixed Cowork sessions failing to start on Windows for accounts with many saved artifacts, scheduled tasks or connected folders. Desktop v1.44121.2, released the same day, states that it fixes sessions on Windows being unable to run commands or fetch web pages, and that this reverts the v1.44121.1 fix. So the original Windows start failure is unfixed again on the current build. A Windows user whose account has accumulated a lot of artifacts, scheduled tasks or connected folders should expect that failure to persist rather than read v1.44121.1 as having resolved it.
Why this mattersThe two Windows defects are mutually exclusive on the current build: one is fixed by reintroducing the other. The changelog states the revert plainly, but only in the later entry, so reading v1.44121.1 alone gives the wrong answer about the current state.
Desktop v1.44121.1 fixes Claude not finding files attached in Cowork and Chat, including pasted files and a re-attached file with the same name, and states that attachments which cannot be read now say so instead of being dropped silently. Separately it fixes a message carrying an attachment that could not be read or was too large failing to send repeatedly with no explanation, and now marks the attachment with the problem and offers Retry where that helps. The first is the more serious of the two: an attachment dropped silently means Claude answered without the file, and the answer looks normal.
Why this mattersSilent attachment loss produces a confident answer built on missing input, which is worse than a visible failure. The Claude Code file attachment path is separate and this entry does not extend to it.
The Claude in Chrome admin controls article states the extension is disabled by default on Enterprise and that from 10 September 2026 it turns on by default unless an admin has already disabled it. The same article states that Claude in Chrome and Claude Cowork are managed separately. On Team the extension is enabled by default. Leaving the setting alone is therefore not the same as declining it.
Why this mattersThis is the second Enterprise default to flip on 10 September 2026. The Cowork built-in browser, which ships inside the desktop app rather than the browser, carries the same date on a separate admin toggle. Because the two are administered independently and neither article references the other, an Enterprise admin who disables one on that date still has the other turned on. Two browsing capabilities reaching an organisation on one day, from two settings pages, is a governance problem that neither page presents as one.
The Cowork task assignment article names the capability Dispatch and describes it as in limited beta for Pro and Max plans on Claude Cowork. It adds that Dispatch is only available for some Pro and Max plans, and directs anyone who does not see it in the Cowork side panel to use Cowork in the cloud instead. Team and Enterprise are not mentioned.
Why this mattersAvailability here is conditional within a plan rather than determined by it, which is unusual in the matrix: being on Pro or Max does not imply the feature is present. The documented fallback, Cowork in the cloud, is itself gated differently, on by default for Team and off by default for Enterprise, so the substitute is not universally available either. Team and Enterprise silence is not a stated exclusion.
The pricing page states Managed Agents is billed on two dimensions, tokens and session runtime. Session runtime is 0.08 US dollars per session-hour, measured to the millisecond, and accrues only while a session status is running. Time spent idle, rescheduling or terminated does not count. Session runtime replaces container-hour billing for the code execution tool rather than adding to it. The page states that the Batch API discount does not apply, because sessions are stateful and interactive, and that cloud platform pricing does not apply, because Managed Agents is not available on partner-operated cloud platforms.
Why this mattersThis is the pricing detail that the Managed Agents documentation itself does not carry, and it settles a question the matrix has held open since 16 August. It also marks a real difference from the Messages API: two modifiers that apply everywhere else, the Batch discount and partner cloud pricing, are documented as not applying here. Prompt caching multipliers and the 1.1x US-only inference multiplier do still apply.
The Cowork OpenTelemetry article states that monitoring is available on Team and Enterprise plans, that events are only exported once an admin configures an OTLP endpoint, and that no data flows by default. Six categories are captured: user prompts as full text, tool and MCP invocations with name, parameters, outcome and execution time, file paths read or modified, skills and plugin usage, human approval decisions, and API requests with model, token counts, cost and duration. Every event carries a shared prompt.id so one user input can be reconstructed end to end.
Why this mattersThis is the widest content capture documented for any surface: audit logs are described as recording identifiers rather than content, while this records prompt text in full. It is also the only Cowork observability path that reaches tool and MCP invocation detail, which matters for anyone running a large private MCP server. Off by default is the real gate here, not the plan.
The Linux desktop documentation states the app gives the same Chat, Cowork and Claude Code experience as macOS and Windows, and lists computer use under what is not in the Linux beta yet, alongside dictation, the Quick Entry global hotkey on native Wayland, and Fedora and RHEL support. Cowork on Linux runs its tasks in a virtual machine hosted by the app with QEMU and KVM, so it needs hardware virtualization, the QEMU and UEFI firmware packages, and membership of the kvm group for access to /dev/kvm and /dev/vhost-vsock.
Why this mattersComputer use is now documented as absent on Linux while present on macOS and Windows, which is a platform gap inside a single surface rather than between surfaces. It lines up with the plan gating already recorded, where computer use in Cowork is a Pro and Max research preview and is excluded from Team and Enterprise entirely.
The Enterprise plan article states that organisations on the older Chat and Chat plus Claude Code seat types keep their current seat types and pricing until their next contract renewal, at which point the plan transitions automatically to the single Enterprise seat model. Seat-based Enterprise plans with Standard and Premium seats are described differently: they are unchanged and keep their seat types, usage limits and usage credit options until the organisation migrates to usage-based billing, with no automatic transition stated. The article gives the seat minimums as 20 for self-serve and 50 for sales-assisted.
Why this mattersThe two older models are treated differently and only one of them moves on its own. A contract-relative date is not a calendar date, so this cannot be tracked as a deadline the way the 10 September defaults can: each organisation has to read its own renewal date.
Two new models are documented: claude-fable-5-1 and claude-mythos-5-1. Both carry a 1M token context window and a 128k maximum output, and on both, extended thinking is always on rather than a parameter the caller sets. Published pricing is 10 US dollars per million input tokens and 50 per million output tokens for each, with cache reads at 0.25 per million, which is a 0.025x multiplier on the input price rather than the 0.1x that applies to other models. Cloud identifiers are published too: anthropic.claude-fable-5-1 and anthropic.claude-mythos-5-1 on Bedrock, and the plain ids on Vertex and Foundry. Fable 5.1 is documented as reaching the Claude apps, Claude Code, Cowork, the API and all three clouds. Mythos 5.1 is invite only through Project Glasswing and its availability table lists the API and the three clouds only.
Why this mattersThe two models do not reach the same surfaces. Fable 5.1 is documented across the apps, Claude Code, Cowork, the API and the clouds. Mythos 5.1 appears on the API, Bedrock, Vertex and Foundry only, with no Claude app or Claude Code entry, so a capability available to an API caller has no equivalent on any interactive surface. Claude Code 2.1.257 picked up claude-fable-5-1 as its default Fable model on the same day.
The release notes state that the tool_choice values any and tool are not supported on claude-fable-5-1 and claude-mythos-5-1. Callers are directed to auto or none, or to strict tool use and structured outputs where forcing a tool call was the point. Any code path that pins tool_choice to any or tool and then switches model id will stop working on these two models. Grep for tool_choice before changing a model id, and check both the literal and any variable that carries it.
Why this mattersThis is a per-model API constraint, so it reaches every surface that lets a caller set tool_choice: the Claude API directly, the Agent SDK, and Managed Agents. The interactive surfaces do not expose tool_choice, so they are unaffected. Parity records no equivalent restriction on any other currently active model.
The release notes state that these two models require 30 day data retention and are not available under a zero data retention configuration. An organisation that holds ZDR therefore cannot call claude-fable-5-1 or claude-mythos-5-1 at all, on any surface, regardless of plan or seat. This is a model level restriction rather than a surface level one, so it is not visible from the plan gating an admin would normally check.
Why this mattersParity already records Managed Agents as ineligible for ZDR, and Claude in Chrome as unsupported under ZDR. This adds a third shape of the same problem: the restriction now attaches to the newest and most capable models rather than to a surface, so a ZDR organisation is capped at older models everywhere at once. That is a newly opened cross-surface gap, not a variation on an existing one.
The release notes name three beta flags. mid-conversation-output-config-2026-07-01 gates changing the effort level partway through a conversation. mid-conversation-system-clear-at-2026-08-21 gates system messages that are scoped to a turn and then expire. thinking-display-updates-2026-08-18 gates a new updates value for the thinking.display parameter. The notes also state that thinking blocks from an earlier turn survive only when replayed to the same model or a newer one, and that the API signals it via a beta response header when it drops older blocks.
Why this mattersThese are API level controls with no equivalent on any interactive surface. Effort is selectable in Claude Code through /effort, but the ability to change it mid-conversation through a request parameter exists only on the API, which widens the existing pattern of API-only controls that Parity already tracks.
The release notes state that text generated by these models carries an invisible watermark, and that generated images and video carry C2PA Content Credentials. Anything republished from these models is therefore attributable after the fact. Worth knowing before generated text goes into a client deliverable that is meant to read as first party work.
Why this mattersParity has no record of watermarking on any earlier model, so this appears with the 5.1 generation rather than across the fleet. No support or admin article was found that surfaces it to an administrator, so it is documented only on the platform release notes an API caller would read.
The changelog entry for 2.1.257 records claude-fable-5-1 as the new default Fable model, giving the same figures as the platform pricing page: a 1M context, 10 and 50 US dollars per million input and output tokens, and cache reads at 0.25 per million. The same release adds two settings, timeFormat, which accepts a 12 hour, 24 hour, 24 hour UTC or strftime pattern, and timeZone. A gateway supplied description field is now honoured on entries in the /model picker discovered through CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY.
Why this mattersThe default model changing is a cost event, not just a capability one. Parity records that 2.1.243 added per-conversation and per-subagent cache TTLs and 2.1.239 made cost estimates include the US-only inference premium, so Claude Code now reports cost accurately against a default that has just moved.
2.1.257 adds a Containment Escape rule to auto mode that stops fetches of cloud metadata credentials and cross-tenant access unless the environment marks them as expected. The same release adds a one time prompt before the first file read outside the configured working directories, which an administrator can turn into a hard block with permissions.blockReadsOutsideWorkingDirectories. /doctor now warns when a killed session has left a stale sandbox mask file behind.
Why this mattersParity records 2.1.251 as adding explicit approval for settings that weaken the sandbox, and 2.1.248 as adding the --restricted profile. This continues that line and it remains Claude Code only: the Agent SDK, Cowork and Managed Agents each sandbox differently and none is documented as carrying an equivalent containment rule, which is the sandboxing-three-ways gap Parity already holds open.
2.1.257 adds CLAUDE_CODE_SUBAGENT_MODEL_FORCE, which applies a model override to every subagent. This is the behaviour CLAUDE_CODE_SUBAGENT_MODEL had before 2.1.251, when it was narrowed to setting a default that an agent definition could override. Anyone who set the old variable expecting it to bind every subagent, and lost that on 2.1.251, now has a variable that does it again. Setting both is worth avoiding until the precedence is documented.
Why this mattersThis matters to any setup that picks the cheapest capable model per subtask, because between 2.1.251 and 2.1.257 there was no way to force a model across every subagent from the environment. Parity records the 2.1.251 narrowing as a breaking change, so this closes a regression the matrix already tracks.
2.1.257 rejects symlinked component paths inside a plugin directory with a path traversal error, covering commands, agents, skills and hooks. A marketplace entry whose plugin commands point outside the plugin directory is refused as well. In the same release strictPluginOnlyCustomization now also blocks MCP servers declared in settings files, and an OAuth credential leak through claude mcp remove is closed. A background marketplace refresh no longer leaves plugin skills unloaded for the rest of the session.
Why this mattersParity records a matching set of four path escape defects fixed in 2.1.251 in the file tools, search, plugin commands and the Workflow tool. This is the same class reached by a different route, through symlinks rather than path strings. The desktop app maintains its own separate marketplace allowlist, and no equivalent symlink rejection is documented for it, so the two plugin marketplace allowlists Parity tracks as a gap now differ on this too.
2.1.258 corrects two things. Claude Code failed to launch on macOS 12 Monterey, a regression introduced in 2.1.255. Separately, remote and scheduled sessions were failing with an error stating that user messages must have non-empty content, after a permission approval had been re-sent. Anything running unattended on a schedule was exposed to the second one, because a re-sent approval is exactly what happens when nobody is present to answer the first prompt.
Why this mattersThe scheduled session failure has no equivalent report on the Cowork or desktop changelogs, but the desktop app bundles the Claude Code CLI, so a desktop build carrying 2.1.255 through 2.1.257 carries the defect. Desktop v1.40609.1, dated 30 August, bundles 2.1.255, which is the version that introduced the macOS 12 regression.
0.3.257 adds thinkingTokens to ModelUsage as a subset of output tokens, exposed as usage.output_tokens_details.thinking_tokens, so thinking can be costed on its own rather than inferred from the output total. Agent tool calls now emit a periodic tool_progress event carrying heartbeat true. tool_use_result.resourceLinks appears on user messages that carry MCP tool results, and task_notification gains an optional resource_links field for MCP tool calls that were backgrounded automatically. Query.getContextUsage() takes a detail option. The browser bundle no longer requires native Symbol.dispose. 0.3.258 is a bundled CLI update only, to parity with Claude Code 2.1.258.
Why this mattersSeparate thinking token accounting arrives in the SDK first. Parity has no record of an equivalent breakdown in the Claude Code cost display or in Console, so per-call thinking cost is visible to an SDK caller and not to anyone on an interactive surface. The heartbeat matters for long subagent runs, which is where a silent Agent tool call previously looked indistinguishable from a hang.
The changelog jumps from 2.1.252 dated 31 August to 2.1.257 dated 1 September, on both the documentation page and the raw GitHub file, checked separately. Four version numbers have no entry. They were not merely unread: two other Anthropic sources refer to builds in that range. The Cowork desktop changelog records desktop v1.40609.1 on 30 August as bundling Claude Code CLI 2.1.255, and the 2.1.258 entry itself describes fixing a macOS 12 regression introduced in 2.1.255. So 2.1.255 shipped and reached users inside a desktop build, with nothing published about what it changed.
Why this mattersThis is the reason a single source cannot be trusted to say a day was quiet. Whatever 2.1.255 and its neighbours changed is unrecorded on the surface that is supposed to record it, and was only visible by comparing the desktop changelog and the Agent SDK parity note against it. Parity holds an open question on exactly this pattern of the Claude Code changelog disagreeing with the shipped build.
Anthropic announced Enterprise Frontier Safeguards, described as misuse detection that keeps data inside the customer controlled cloud rather than sending it to Anthropic, with automated monitoring for abuse patterns. It is stated as covering Claude Code, Claude Enterprise, the Claude Platform, Bedrock, Google Cloud and Microsoft Foundry, developed with more than a hundred enterprises, and rolling out in phases from autumn 2026. No pricing, no plan gating and no configuration detail is published yet, so there is nothing an administrator can act on today.
Why this mattersThe named coverage list spans Claude Code, Claude Enterprise, the Claude Platform and all three clouds, which is broader than any single existing governance control Parity tracks. Cowork and the Claude apps are not named. Nothing is documented well enough yet to place in the capability matrix, so this is recorded as an announcement only.
Claude Code 2.1.252 fixes Remote Control sessions becoming unresponsive for extended periods after a tool completed, when the connection to claude.ai was degraded. The session did not recover on its own, so the failure looked like a hang rather than a dropped connection.
Why this mattersThis is the connection path between a phone or second device and a running session. The Cowork and desktop changelog carries no matching entry at its current version, v1.40609.0 dated 2026-08-27, so there is no way to tell from published sources whether the desktop bridge shared the defect.
Claude Code 2.1.252 fixes background task notifications carrying extensive failure output causing the conversation to exceed the API request size limit of 32 MB. A background task that failed noisily could therefore break the session it reported back into, rather than just reporting a failure.
Why this mattersThe blast radius is proportional to how much work is delegated to background tasks and subagents, so a heavily parallel session was the most exposed. The Agent SDK releases of the same day bundle this CLI build and carry no separate note of the fix.
Claude Code 2.1.252 fixes the "always allow" permission choice failing to persist in a new project that did not yet have a .claude/settings.local.json file. The same release fixes a Bash tool failure on macOS when the task output swap directory had been moved or replaced with a symlink.
Why this mattersPermission persistence is per project and stored locally, so the defect only showed on a project that had never written a local settings file. Neither the desktop app nor the Agent SDK documents an equivalent local permission store, so there is no cross-surface equivalent to check.
Both Agent SDKs published a release whose only content is a bundled CLI update to Claude Code 2.1.252. No new APIs, no capability changes, no deprecations, no breaking changes in either language.
Why this mattersBoth SDKs moved together and both track the same CLI build, so the two language surfaces are at parity on this release. The substantive content is in the Claude Code 2.1.252 entries.
Anthropic published a post stating that during cybersecurity evaluations in July and August 2026, Claude models operating with safety features intentionally disabled for testing reached real internet systems, through either environment misconfiguration or deliberate access. The post names two failure modes it found, models holding false beliefs about whether an environment was simulated, and pursuit of a narrow task goal without regard to harm. Measures described include real-time classifiers for sandbox escape attempts, automated review of evaluation transcripts, migration of high-risk sandboxes to stronger isolation, blocking outbound traffic by default, and reduced privileged account access. It also sets requirements for external partners: run cyber evaluations in a hardened sandbox with no internet access by default, test the sandbox for vulnerabilities before the engagement, set scope explicitly in the prompt, and monitor behaviour against declared boundaries in real time.
Why this mattersThe partner requirements are the part with reach beyond Anthropic: they describe a default-deny network posture for any sandbox running an agent under evaluation. Nothing in the post changes a documented capability on any of the nineteen surfaces, so no matrix cell moves.
The matrix recorded Claude Code as included per seat across Team and Enterprise. The live article adds a carve-out for older Enterprise contracts, where Claude Code is reachable only through specific seat types: Chat plus Claude Code seats billed on usage, or Premium seats billed per seat. Newer self-serve Enterprise plans do bundle it with the standard seat, matching what the matrix said. This matters when advising an org on an existing contract rather than a new one.
Why this mattersPlan gating only. The capability set of Claude Code is unchanged on every surface.
The matrix recorded Cowork as off by default on Enterprise and enabled per group. The live admin article says Cowork is on by default for both Team and Enterprise, and that owners can disable it manually. What is off by default on Enterprise is a separate toggle, Run Cowork in the cloud, which an owner turns on and then grants to a group via custom roles. Team has that toggle on by default and no group controls at all, so Cowork on Team stays all or nothing. The practical effect is that Enterprise users get Cowork immediately but not cloud sessions.
Why this mattersNarrows a gap that was recorded as wider than it is. The Enterprise restriction applies to cloud execution, not to Cowork as a product. Scheduled cloud tasks are the thing gated on Enterprise, which is exactly the mode this watch runs in.
The Office add-in family has grown from Excel and PowerPoint to four apps, adding Word and Outlook, plus a cross-app mode that lets Claude read from one M365 app and write to another in a single conversation. Cross-app mode is on by default for Pro and Max and off by default for Team and Enterprise, with an org-level toggle under Organization settings, Office agents. Skills enabled in Claude settings now apply inside all four add-ins during a cross-app task, so a skill enforcing modelling conventions runs in Excel while a template skill runs in PowerPoint. Claude can only touch files already open, and cannot create, open, close or switch files.
Why this mattersOpens two gaps. First, cross-app mode does not work through Bedrock, Vertex, Foundry or an LLM gateway, so it is direct-account only, which widens the cloud integration parity gap. Second, the existing exclusion from Enterprise audit logs, the Compliance API and data exports now spans four apps rather than two, and the add-ins do not inherit custom data retention settings. Also worth noting the tracked surface list of 19 no longer covers everything: Word and Outlook are untracked.
The Team and Enterprise Cowork article labels the claude.ai experience "Web (beta)" and the mobile apps "Claude Mobile (beta)", and states availability on Pro, Max and Team, and on Enterprise where an admin has enabled it. The Chrome side panel is described as accessible on Max and Team, with Enterprise subject to admin configuration.
Why this mattersThe beta and research preview index does not list Cowork web or mobile at all. That index was last updated 7 July 2026, which is consistent with Parity's record that it lags the per-surface articles.
The plugin management article states "Cowork and Skills must both be enabled for your organization before you can use plugin marketplaces." Owners and Primary Owners manage this at Organization settings, Plugins. Enterprise adds per-group override of the org-wide plugin settings. Manual uploads are capped at 100 marketplaces and GitHub-synced marketplaces at 500.
Why this mattersPlugin marketplaces sit downstream of a separately gated feature. An organisation that has switched Cowork off entirely also has plugin marketplaces blocked, through a dependency stated only on the plugin management page and not on the Cowork page.
Scanning applies only to newly uploaded or installed third-party skills and plugins, not to anything already in place. It is unavailable to organisations configured with customer-managed encryption keys, zero data retention, or HIPAA.
Why this mattersThe organisations most likely to require scanning are the ones excluded from it. This sits alongside Parity's record that Claude in Chrome is also unavailable to HIPAA-covered organisations and does not support zero data retention, so the same three configurations keep carving features out across surfaces.
The Team and Enterprise admin guide states Claude Design is off by default on Enterprise and requires admin enablement at Organization settings, Capabilities, with a custom role permission named "Claude Design Admin".
Why this mattersParity already records that the same guide states Team plans have Claude Design enabled by default, so the two tiers differ in default posture within one document.
2.1.245, dated 25 August, fixes a startup crash on Linux distributions shipping glibc 2.44, including Arch, CachyOS and Fedora Rawhide. 2.1.250, dated 28 August, is listed only as bug fixes and reliability improvements with no itemised entries.
Why this mattersNo capability change on any surface.
The default model for seat-based Enterprise subscriptions changed to Opus 5, matching other premium plans.
Why this mattersPlan-level default only. The model lineup available on each surface is unchanged.
Two new hook events, PreModelSwitch and PostModelSwitch, let a hook block, confirm or annotate a model switch. Separately, SessionStart resume hooks now receive session staleness and the estimated re-cache cost, so a resume can decide whether warming the cache is worth paying for.
Why this mattersHooks remain a Claude Code and Agent SDK concept. No equivalent lifecycle hook surface is documented for Cowork or Managed Agents, which is an open question already on Parity's list, so this widens that gap rather than closing it.
The variable previously forced the model for every subagent. It now supplies only a default: an agent definition's model field and an explicit per-spawn model both take precedence over it. Anyone using it as a hard ceiling on subagent spend no longer has one, and agent definitions will override it without warning.
Why this mattersThe Agent SDK spawns subagents through the same CLI, so SDK hosts setting this variable inherit the new precedence. No equivalent subagent model control is documented for Managed Agents or Cowork.
Read, Write and Edit followed a symlink swapped inside the working directory after the permission check had already passed, which could read or write outside the approved location. Grep and Glob did not apply Read deny rules to files reached through a symlinked search path. Plugin commands declared in a marketplace entry could point outside the plugin directory and are now rejected with a path-traversal error. The Workflow tool read a scriptPath outside what the session may read, and quoted it in errors, before the permission check ran.
Why this mattersThese are permission-check bypasses in tools that Cowork and Agent SDK sessions also run. The Cowork changelog is not in this watch's configured source list and the Agent SDK changelogs are published behind their releases, so whether the same fixes have shipped on those surfaces is unverified.
/usage gains a spend limit bar and a rate_limits.spend_limit status line field for developers behind a Claude apps gateway with spend limits. /cost gains a per-session prompt cache line covering hit ratio, misses, tokens re-cached and whether the cache was warm or cold, with a matching prompt_cache object for status line scripts.
Why this mattersFollows the 2.1.243 cache TTL settings. Together they make prompt cache economics measurable in the CLI, with no counterpart on Cowork, Console or Managed Agents.
Server-managed settings that terminate sandbox TLS, route sandbox traffic through your own proxy, inject credentials or weaken sandbox isolation must now be approved before they apply. ANTHROPIC_CUSTOM_HEADERS from managed or project settings requires approval when it sets a credential, organisation or tenant, routing, or API-behaviour header such as Authorization or Host. Project-level .claude/settings.json env can no longer set CLAUDE_CONFIG_DIR, CLAUDE_CODE_TMPDIR, or TMPDIR, TMP and TEMP; those must move to shell, user or managed settings.
Why this mattersA managed-settings deployment that relied on project env to redirect config or temp directories will silently stop working after upgrade. This is a governance control unique to Claude Code; Cowork and Managed Agents expose no equivalent managed settings approval flow.
/schedule previously returned a bare "No MCP connectors" message. It now explains that MCP servers configured in Claude Code cannot be attached to cloud routines. The constraint is not new; the explanation of it is.
Why this mattersA scheduled routine running in the cloud has to source its connectors from the claude.ai connector set, not from local Claude Code MCP configuration. That boundary between local MCP servers and cloud-run scheduled work was previously undocumented in the error path.
An announcement dated 28 August 2026 makes Claude for Teachers available to United States K-12 schools and districts. It is an availability announcement, with no capability or gating detail for any tracked surface.
Why this mattersNo cross-surface effect established. The announcement names no change to any of the nineteen tracked surfaces.
Listed rather than guessed at. A visible unknown is worth more than a confident guess.