Covering Claude Code releases from March 17 – April 1, 2026.

Claude Code ships fast — 13 releases in two weeks. Most changelogs are walls of bug fixes. This post pulls out the changes that actually matter for day-to-day usage, organized by theme.

For the full changelog: github.com/anthropics/claude-code/blob/main/CHANGELOG.md


Hooks & Automation

"defer" Permission Decision (v2.1.89)

PreToolUse hooks can now return "defer" as a permission decision. This pauses a headless session at the tool call instead of allowing or denying it. Resume later with -p --resume and the hook re-evaluates.

This is a game-changer for CI/CD: your pipeline can pause at a dangerous operation, wait for human approval via an external system, then resume.

{
  "hooks": {
    "PreToolUse": [{
      "matcher": "Bash",
      "if": "Bash(rm *)",
      "hooks": [{
        "type": "command",
        "command": "scripts/check-approval.sh"
      }]
    }]
  }
}

The script returns {"permissionDecision": "defer"} when approval is pending.

PermissionDenied Hook (v2.1.89)

A new hook event that fires after the auto mode safety classifier denies a command. Return {retry: true} to tell the model it can try a different approach.

Useful for building custom fallback logic — e.g., if curl is denied, suggest using the WebFetch tool instead.

CwdChanged and FileChanged Hooks (v2.1.83)

Two new reactive hook events:

  • CwdChanged — fires when the working directory changes (great for direnv-style environment loading)
  • FileChanged — fires when a watched file is modified

These enable environment-aware workflows without polling.

StopFailure Hook (v2.1.78)

Fires when a turn ends due to an API error (rate limit, auth failure, etc.) — distinct from Stop, which fires on successful completion. Use this to implement alerting or automatic retry logic.

TaskCreated Hook (v2.1.84)

Fires when a background task is created via TaskCreate. Documented as a blocking hook in v2.1.89 — your script runs before the task starts, so you can inject context or validate the task.


Security & Sandboxing

sandbox.failIfUnavailable (v2.1.83)

Previously, if sandbox was enabled but dependencies were missing (e.g., bubblewrap not installed on Linux), Claude Code would silently fall back to running unsandboxed. Now you can set:

{
  "sandbox": {
    "enabled": true,
    "failIfUnavailable": true
  }
}

Claude Code exits with an error instead of running without protection. Essential for any environment where sandboxing is a security requirement, not a nice-to-have.

CLAUDE_CODE_SUBPROCESS_ENV_SCRUB=1 (v2.1.83)

Set this environment variable to strip Anthropic and cloud provider credentials from subprocess environments — Bash tool commands, hooks, and MCP stdio servers won’t see your API keys.

managed-settings.d/ Drop-in Directory (v2.1.83)

Enterprise admins can now deploy independent policy fragments alongside managed-settings.json:

/etc/claude-code/
├── managed-settings.json
└── managed-settings.d/
    ├── 01-security-team.json
    ├── 02-platform-team.json
    └── 03-compliance.json

Files merge alphabetically. Different teams can own their own policy fragments without merge conflicts.


MCP & Plugins

MCP_CONNECTION_NONBLOCKING=true (v2.1.89)

In -p mode, this skips the MCP connection wait entirely. Additionally, --mcp-config server connections are now bounded at 5 seconds instead of blocking on the slowest server.

For CI pipelines where MCP servers might be flaky or slow, this prevents your entire headless run from hanging on a connection timeout.

MCP Tool Descriptions Capped at 2KB (v2.1.84)

MCP tool descriptions and server instructions are now truncated at 2KB. This prevents OpenAPI-generated MCP servers (which can have enormous schema descriptions) from consuming your entire context window.

If you’ve been losing context to a bloated MCP server, this fix is automatic.

Plugin userConfig with Keychain Storage (v2.1.83)

Plugins can now declare configuration options in their manifest (manifest.userConfig). Users are prompted at enable time, and values marked sensitive: true are stored in the system keychain (macOS) or a protected credentials file (other platforms). No more .env files for plugin secrets.

MCP OAuth Improvements

  • v2.1.85: RFC 9728 Protected Resource Metadata discovery for finding the authorization server
  • v2.1.81: Client ID Metadata Document (CIMD / SEP-991) support for servers without Dynamic Client Registration

These make it easier to connect to corporate MCP servers that use standard OAuth flows.

--channels Permission Relay (v2.1.80/v2.1.81, research preview)

MCP servers that declare the permission capability can forward tool approval prompts to your phone via a channel server. Still in research preview, but the vision is clear: approve dangerous commands from your phone while Claude works autonomously on your laptop.


Performance & UX

Read Tool Optimization (v2.1.86)

The Read tool now uses a compact line-number format and deduplicates unchanged re-reads. If Claude reads the same file twice without changes, the second read uses far fewer tokens. Meaningful savings in long sessions with lots of file reading.

CLAUDE_CODE_NO_FLICKER=1 (v2.1.89)

Opt into flicker-free alt-screen rendering with virtualized scrollback. If you’ve noticed visual jitter during heavy streaming (especially in iTerm2 under tmux), try this.

Line-by-Line Response Streaming (v2.1.78)

Response text now streams line-by-line as it’s generated instead of waiting for the full response. Makes the output feel significantly more responsive.

Note: Disabled on Windows (including WSL in Windows Terminal) due to rendering issues. Fixed in v2.1.81.

Idle-Return Prompt (v2.1.84)

After 75+ minutes idle, Claude Code nudges you to /clear. Stale sessions waste tokens re-caching old context that’s no longer relevant.

/status Works Mid-Response (v2.1.83)

Previously, /status was queued until Claude finished its current turn. Now it responds immediately — useful when you want to check model or context info without interrupting work.

Skills paths: Accepts YAML List (v2.1.84)

Skill frontmatter paths: now accepts a YAML list of globs instead of a single path. Makes it easier to scope skills to multiple directories:

---
name: api-review
paths:
  - "app/api/**"
  - "app/schemas/**"
  - "tests/api/**"
---

Named Subagents in @ Typeahead (v2.1.89)

Custom agents defined in .claude/agents/ now appear in @ mention typeahead suggestions alongside files and MCP resources.

Edit Without Prior Read (v2.1.89)

The Edit tool now works on files that were viewed via cat or sed -n in the Bash tool, without requiring a separate Read call first. One less permission prompt in common workflows.

PowerShell Tool (v2.1.84, opt-in preview)

Windows users get a native PowerShell tool. Opt-in via settings — see the tools reference for details.


Model & Output

Opus 4.6 Output Limits (v2.1.77)

Default maximum output tokens for Opus 4.6 increased to 64K tokens, with an upper bound of 128K tokens. The 128K upper bound also applies to Sonnet 4.6. This means Claude can generate substantially longer responses — useful for large refactors, comprehensive documentation, and code generation.


Notable Bug Fixes

A few fixes worth knowing about, because you might have been hitting them:

  • Autocompact thrash loop (v2.1.89): If context refilled immediately after compacting three times in a row, Claude Code would burn API calls in an infinite loop. Now stops with an actionable error.
  • Nested CLAUDE.md re-injection (v2.1.89): In long sessions that read many files, nested CLAUDE.md files could be re-injected dozens of times. Fixed.
  • Background subagents vanishing after compaction (v2.1.83): Could cause duplicate agents to be spawned. Fixed.
  • caffeinate not terminating on exit (v2.1.83): Prevented Mac from sleeping after quitting Claude Code. Fixed.
  • Terminal stuck in enhanced keyboard mode (v2.1.85): Ctrl+C and Ctrl+D didn’t work after quitting in Ghostty, Kitty, and WezTerm. Fixed.
  • Prompt cache misses in long sessions (v2.1.89): Tool schema bytes changing mid-session caused cache misses. Fixed — should improve costs in long sessions.