Claude docs changes for September 1st, 2026 [diff]
Executive Summary
- New "account on hold" handling: a suspended Claude account now gets a dedicated error state and structured error code (
account_on_hold) across the CLI, hooks, and Agent SDK, instead of being reported as a generic expired login. - Sandbox settings that let the sandbox proxy read/reroute/authenticate traffic or weaken isolation (
sandbox.network.tlsTerminate, proxy ports,sandbox.credentials, and others) now require developer approval when delivered via server-managed settings — previously applied silently. - One-off routine scheduling from the CLI (
/schedule) is now generally available, and/scheduleno longer depends on feature-flag fetching. - Subagents running in the background by default (introduced gradually in v2.1.198) is now fully rolled out, and
/tasksnow shows which model and effort level a subagent is running on. - Code execution and programmatic tool calling now support Claude Fable 5 and Claude Mythos 5, and cross-account KMS keys are no longer supported for Claude Platform on AWS CMEK.
New Claude Code versions
2.1.252
Major bug fixes
- Fixed Bash commands failing with "task output swap refused (tasks dir moved or linked)" on some Macs
- Fixed "always allow" not saving in a project that has no
.claude/settings.local.jsonyet - Fixed Remote Control sessions hosted by Claude Desktop or VS Code stalling for minutes after a tool finished when the connection to claude.ai was degraded
- Fixed background task notifications with very large failure output (for example git errors on a full disk) making the conversation exceed the API request size limit
Claude Code changes
Changed documents
agent-sdk/subagents [Source]
- Subagents running in the background by default is now fully rolled out; before v2.1.198 an Agent tool call omitting
run_in_backgroundran synchronously. [line 154] [Source] - Clarified that the built-in
general-purposesubagent is available even when you define no agents of your own, and documented thesubagent_type is requirederror returned whenCLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS=1removes it. [line 161] [Source]
agent-sdk/typescript [Source]
- Added
'account_on_hold'as a newSDKAssistantMessageErrorvalue, returned when the authenticated account is suspended. [line 1139] [Source]
amazon-bedrock [Source]
- Guardrail headers delivered through a Claude apps gateway policy now count as settings that need developer approval. [line 371] [Source]
claude-apps-gateway [Source]
- When a gateway's pinned TLS certificate rotates, developers now also see the security approval dialog again (not just the trust prompt), since approval memory is keyed to the pinned certificate. [line 233] [Source]
claude-apps-gateway-config [Source]
- Added sandbox settings that intercept traffic, inject credentials, or weaken isolation (e.g.
sandbox.network.tlsTerminate, the proxy port settings) to the list of settings a gateway policy can only deliver with developer approval. [line 566] [Source]
costs [Source]
- In self-serve Enterprise, Enterprise trial, and AWS-Marketplace-billed Enterprise organizations,
/usage-creditsnow requires Claude Code v2.1.248 or later; earlier versions reject it. [line 76] [Source]
env-vars [Source]
- An
ANTHROPIC_CUSTOM_HEADERSvalue that sets a credential, org/tenant, routing, or API-behavior header now counts as a setting that needs developer approval when delivered via server-managed settings. [line 125] [Source] CLAUDE_CODE_AUTO_COMPACT_WINDOWis now also capped at the model's context window. [line 192] [Source]CLAUDE_CODE_SUBPROCESS_ENV_SCRUBnow also strips any variable Claude Code recognizes as a credential and credentials embedded in package registry URLs, not just the fixed Anthropic/cloud-provider list. [line 344] [Source]- With feature-flag fetching off, messaging sessions beyond the local machine is now also unavailable, while scheduling from the CLI with
/scheduleno longer needs feature-flag fetching (see theroutinesentry below). [line 480] [Source]
errors [Source]
- New "Your account is on hold" section, covering the
account_on_holdstructured error code shown when a Claude account is suspended; before v2.1.235 this was reported as a generic "Login expired" instead. [lines 917-925] [Source]
hooks [Source]
- Added
account_on_holdto theStopFailureerror type values, in both the matcher table and the hook input field reference. [line 294] [Source]
hooks-guide [Source]
- Added
account_on_holdto theStopFailureerror type values in the matcher-field table. [line 659] [Source]
llm-gateway-connect [Source]
- Routing and tenant header names set via
ANTHROPIC_CUSTOM_HEADERSnow count as headers that need developer approval. [line 278] [Source]
monitoring-usage [Source]
- When a
PreToolUsehook defers a tool call, Claude Code now preserves the trace context so the tool's spans join the original turn's trace as children when the session resumes. [line 170] [Source]
routines [Source]
- One-off scheduling from the CLI is now generally available; it was previously a gradual rollout, with a fallback to the web UI. [line 114] [Source]
/scheduleno longer depends on feature-flag fetching, so it now works even withDISABLE_TELEMETRY,DO_NOT_TRACK,CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC, orDISABLE_GROWTHBOOKset. [line 347] [Source]
sandboxing [Source]
- Sandbox
maskentries,network.tlsTerminate, andcredentials.allowPlaintextInjectdelivered via server-managed settings now count as settings needing developer approval. [line 489] [Source]
server-managed-settings [Source]
- New "Sandbox network and isolation settings" category requiring developer approval: settings that let the sandbox proxy read, reroute, or authenticate traffic, or that weaken isolation (
sandbox.network.tlsTerminate, the proxy port settings,sandbox.credentials,sandbox.allowAppleEvents,sandbox.enableWeakerNestedSandbox,sandbox.enableWeakerNetworkIsolation,sandbox.filesystem.disabled, and the Unix-socket/Mach-lookup settings). Before v2.1.251 Claude Code applied these without approval. [line 197] [Source] - Approval for a Claude apps gateway sign-in is now scoped per gateway and tied to its pinned certificate, rather than following the generic "any other credential" rule. [line 209] [Source]
- Documented exactly which
ANTHROPIC_CUSTOM_HEADERSvalues require approval based on their content (credential, org/tenant, routing, or API-behavior headers) as of v2.1.251; previously any value applied without approval. [line 239] [Source]
sub-agents [Source]
/tasksnow shows which model a subagent is running on, plus its effort level when the subagent's definition (or the skill it forked from) sets one. Requires Claude Code v2.1.242 or later. [line 312] [Source]- Claude Code now shows a startup warning when subagents' combined descriptions pass a 15,000-token limit; every subagent still loads. [line 684] [Source]
API changes
Changed documents
agents-and-tools/agent-skills/enterprise [Source]
- Skill content scanning for Claude Enterprise organizations is no longer marked as a beta feature. [lines 43-45] [Source]
agents-and-tools/tool-use/code-execution-tool [Source]
- The code execution tool's compatibility table now lists Claude Fable 5 and Claude Mythos 5 as supported models, and notes that Claude Mythos Preview supports it on the Claude API and Microsoft Foundry. [lines 622-632] [Source]
agents-and-tools/tool-use/programmatic-tool-calling [Source]
- The compatibility table now lists Claude Fable 5 and Claude Mythos 5 as supported models, and notes that Claude Haiku 4.5 accepts the required tool version but doesn't support programmatic tool calling. [lines 736-746] [Source]
build-with-claude/token-counting [Source]
- Token-counting endpoint rate limits raised across all usage tiers: Start 2,000 → 5,000 RPM, Build 4,000 → 10,000 RPM, Scale 8,000 → 20,000 RPM. [lines 242-246] [Source]
manage-claude/cmek-aws-kms [Source]
- Cross-account KMS keys are no longer supported for Claude Platform on AWS: the key must now be in the AWS account that hosts your organization, checked at registration time. [line 211] [Source]
manage-claude/inference-hooks-endpoint [Source]
- Documented circuit-breaker auto-recovery: starting 10 minutes after a trip, Anthropic sends about one test request per minute to your AI security server, and a valid verdict automatically resets the breaker (an admin can still reset it manually at any time). [lines 263-267] [Source]
Note: several manage-claude pages (admin-api-keys, api-and-data-retention, compliance-api-access, compliance-sessions, inference-hooks) broadened their wording from "Cowork and Claude Code sessions" to "sessions" / "apps such as Cowork and Claude Code," suggesting the Compliance API's session capture now covers more apps than before; no other content changed on those pages, so they're summarized here rather than listed individually.
PENDING: awaiting remaining background analysis of docs-md/api/api/compliance, docs-md/api/api top-level, docs-md/api/about-claude.