Source: ai-research/claude-code-docs-changelog-2026-10-09.md — code.claude.com changelog, versions v2.1.290–v2.1.296 (October 5–9, 2026), fetched 2026-10-09. The official What’s New digest page code.claude.com/docs/en/whats-new/2026-w41 returned HTTP 404 (consistent with all prior sweeps since W38; Tavily OAuth unavailable non-interactive; x-search ENOENT). v2.1.289 (October 3) is covered in Week 40 as it falls within the W40 calendar window.

Product: Claude Code · Date: 2026-10-05 to 2026-10-09

Week 41 delivers Claude Haiku 5.5 as the headline launch — the third and final model in the Claude 5.5 family (after Opus 5.5 in W39 and Sonnet 5.5 in W40), at 0.50 per Mtok with 1M context (v2.1.293, October 7). The week also ships a major new hook capability (onFailure: "block" in v2.1.295), an effort parameter for the Agent tool (v2.1.292), --marketplace <source> for plugin install, a CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL env var for workflow control (v2.1.296), Sonnet 5.5 cache reads price cut to $0.10/Mtok (v2.1.296), and MCP description limits raised. Continues Week 40.

Key Takeaways

  • Claude Haiku 5.5 (claude-haiku-5-5) launched October 7 — the new default Haiku on the Anthropic API, 1M context, 0.50 per Mtok. Completes the Claude 5.5 model family (v2.1.293). See Claude Haiku 5.5.
  • onFailure: "block" for command and HTTP hooks (v2.1.295): a hook that fails (non-zero exit or HTTP error) can now be configured to block the underlying tool call or action, not just log the failure.
  • effort parameter for the Agent tool (v2.1.292): set the effort level for a specific subagent call without changing the session default. See Subagents.
  • --marketplace <source> for claude plugin install (v2.1.292): install a plugin from a named marketplace source directly, not just the default. See Plugins and Marketplaces.
  • CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL env var (v2.1.296): pins the model used for workflow subagents independently of the session’s main model.
  • Sonnet 5.5 cache reads price cut: 0.10/Mtok (v2.1.296). Matches Opus 5.5 cache read pricing.
  • MCP tool description and server instruction limit raised: 2,048 → 4,096 characters in the standard path (v2.1.296). Tool search still cuts at 16,384 (up from 2,048 in v2.1.295).
  • autoCompactWindow for subagents (v2.1.296): control the compaction window independently for subagent sessions.
  • allow_large option for the Read tool (v2.1.296): allow reading files larger than the default size gate without an additional confirmation.
  • agent.spawn for teammates (v2.1.289, W40 boundary): spawning new agent teammates via agent.spawn in a running session.
  • prompt.autocomplete mod event (v2.1.292): plugins using the Mods system can now listen to and respond to prompt autocomplete events. See Claude Mods.
  • Claude in Chrome no longer configurable via project settings files (v2.1.290): must be enabled at user or managed settings level.
  • prompt and agent hooks security fix (v2.1.294): hooks written as instructions that allowed actions they should block are now rejected.

Release table

VersionDate (UTC)Shape
v2.1.2892026-10-03agent.spawn for teammates; idle/waiting in $.agent.list(); VS Code auth revert; 23 fixes
v2.1.2902026-10-05serverToolUses in turn.step; agentId in tool.check; partial names for claude attach/claude logs; Deny on gateway sign-in; pyright confirm; 131 fixes
v2.1.2912026-10-06Regression fixes for v2.1.290 (cloud permission prompts) and v2.1.288 (last messages lost on quit)
v2.1.2922026-10-06effort for Agent tool; --marketplace for plugin install; prompt.autocomplete mod event; prompt caching in $.model.complete; local stdio MCP defaults to 2026-07-28 protocol; 64 fixes
v2.1.2932026-10-07Claude Haiku 5.5 launch; agentType in subagentStatusLine; isDeferred for $.tool.register; skill sync cadence 10 min → 40 min; 38 fixes
v2.1.2942026-10-08Security: prompt/agent hook instruction-bypass fix; improved Stop/SubagentStop prompt hook judgment
v2.1.2952026-10-08onFailure: "block" for command/HTTP hooks; Program Status Protocol (OSC 7501); CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS; MCP tool search cut at 16,384 chars; subagents preload ≤32 skills; 97 fixes
v2.1.2962026-10-09CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL; autoCompactWindow for subagents; allow_large for Read; code key in managed.policies[]; Sonnet 5.5 cache reads $0.10/Mtok; MCP limit 2,048→4,096 chars; 56 fixes

Claude Haiku 5.5 launch (v2.1.293, October 7)

Claude Haiku 5.5 (claude-haiku-5-5) is the new default Haiku model on the Anthropic API. It completes the Claude 5.5 family:

  • Price: 0.50 output per Mtok
  • Context: 1M tokens
  • Default Haiku on the Anthropic API from v2.1.293

The Claude 5.5 model family is now complete: Opus 5.5 (20, W39), Sonnet 5.5 (10, W40), Haiku 5.5 (0.50, W41).

Hooks: onFailure: "block" (v2.1.295)

A new field for command and HTTP hooks. When set to "block", a hook failure (non-zero exit code for command hooks, non-2xx response for HTTP hooks) blocks the underlying action — the same effect as exit code 2 from a blocking hook handler, but configured declaratively rather than through the exit code convention.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bin/validate-bash-call",
            "onFailure": "block"
          }
        ]
      }
    ]
  }
}

Useful when the hook script itself fails unexpectedly (e.g., missing binary, network error) and you want that failure to be safe-by-default rather than silently passing the underlying call through. See Hooks.

Agent tool: effort parameter (v2.1.292)

The Agent tool now accepts an effort parameter: "low", "medium", "high", "xhigh", or "max". This sets the effort level for the spawned subagent independently of the session’s current effort level, without requiring an env var or /effort command mid-session.

Practical pattern: run coordinator at xhigh effort for planning, spawn worker subagents at medium or high to save cost on bulk execution, without switching the session’s effort level between calls.

See Subagents and Dynamic Workflows.

Plugin install: --marketplace <source> (v2.1.292)

claude plugin install <plugin> --marketplace <source> installs from a named marketplace. Before this release, plugin install always drew from the default marketplace (Anthropic-hosted). This flag lets you specify an alternative marketplace source registered in settings.

See Plugins and Marketplaces.

MCP description limits raised (v2.1.295, v2.1.296)

Two limits changed:

  • Standard path (regular MCP tool descriptions and server instructions): 2,048 → 4,096 characters (v2.1.296). Overridable with CLAUDE_CODE_MAX_MCP_DESCRIPTION_LENGTH.
  • Tool search path (descriptions loaded via ToolSearch): 2,048 → 16,384 characters (v2.1.295). Longer descriptions pass through when Claude uses tool search to load schemas.

See MCP.

Sonnet 5.5 cache reads price cut (v2.1.296)

Sonnet 5.5 cache read pricing drops from 0.10 per Mtok — matching Opus 5.5’s cache read rate. This is a retroactive change; the cut applies to all requests after v2.1.296 ships, not only new sessions. Practically, any prompt-cache-heavy workflow using Sonnet 5.5 (large CLAUDE.md, long system prompts, repeated context re-injection) halves its cache-hit cost.

Local stdio MCP: protocol version 2026-07-28 default (v2.1.292)

Local stdio MCP servers now negotiate protocol version 2026-07-28 by default instead of the earlier version. This may affect servers that do not support the newer protocol. If a local stdio MCP server stops connecting after updating to v2.1.292, add "protocol": "2025-11-25" to its MCP config entry to pin the older version. See MCP.

agent.spawn for teammates (v2.1.289)

The agent SDK surface gains agent.spawn for spawning new teammates in a running session. Previously, agent creation was handled at session init; agent.spawn enables dynamic teammate creation mid-session. $.agent.list() now also returns idle and waiting states, giving more granular visibility into teammate lifecycle. See Claude Code Agent Teams.

Security fix: prompt and agent hook instruction bypass (v2.1.294)

A bug where prompt and agent hooks written as instructions could allow actions they were supposed to block is fixed in v2.1.294. Specifically, prompt hooks on Stop and SubagentStop events are now judged more accurately, so Claude is less likely to stop early when a prompt-type hook returns feedback. Update if you rely on prompt or agent hooks for blocking policy.

Other notable additions (v2.1.290)

  • serverToolUses in turn.step results: agent SDK callers can now see the raw MCP tool uses within a step, useful for observability and audit pipelines.
  • agentId in tool.check events: hooks can now read which agent is calling the tool, useful for multi-agent setups with per-agent policies.
  • Partial session names for claude attach <name> and claude logs <name>: you no longer need the full session ID — a unique substring is enough.
  • Deny button on the gateway sign-in approval page: operators can explicitly deny a gateway sign-in request.
  • Bash asks before running pyright: Bash now confirms before invoking pyright (which can be slow and resource-intensive), matching the pattern for npm install and similar expensive commands.

Program Status Protocol (OSC 7501) (v2.1.295)

Claude Code now supports OSC 7501, a terminal protocol for reporting running program status to the terminal emulator. Terminal emulators that implement OSC 7501 (including recent Ghostty builds) can display Claude Code’s current status (thinking, waiting for permission, idle) in the terminal title bar, taskbar, or a status pane, without any additional tooling.

Breaking and behaviour changes

  • Claude in Chrome disabled via project settings files (v2.1.290): claude --chrome and Chrome sidebar can no longer be enabled via a project’s .claude/settings.json. Use user-level (~/.claude/settings.json) or managed settings instead.
  • Bash confirms before pyright (v2.1.290): in auto mode or interactive sessions, Bash will ask before running pyright.
  • claude.ai skill sync cadence: 10 min → 40 min (v2.1.293): cloud-synced skills check for updates less frequently.
  • Subagents preload ≤32 skills (v2.1.295): subagents will not load more than 32 skills at startup, regardless of how many are available.
  • Local stdio MCP: protocol version 2026-07-28 by default (v2.1.292): see above.

Try It

  • Haiku 5.5 as a cheap worker model: Use ANTHROPIC_DEFAULT_HAIKU_MODEL=claude-haiku-5-5 or pin it in availableModels to route cheap bulk tasks to the new Haiku.
  • Add onFailure: "block" to PreToolUse command hooks that should fail safe — if the validation script crashes, the tool call is blocked rather than silently allowed.
  • Pin workflow subagent model: set CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL=claude-sonnet-5-5 to prevent workflow agents from inheriting the session’s Opus model and burning quota.
  • Pass effort: "medium" on Agent tool calls for bulk worker subagents to reduce cost on tasks that do not need xhigh reasoning.
  • Re-check MCP server descriptions: the 4,096-char limit doubles the allowance — servers that were truncated can now send richer context to improve tool selection.

Open Questions

  • Haiku 5.5 on Bedrock, Vertex and Foundry: v2.1.293 says “the Anthropic API” as the default Haiku. Are Bedrock/Vertex/Foundry defaults also updated simultaneously or on a delay?
  • onFailure: "block" on post-event hooks: the field is documented for command and HTTP hooks. Does it apply to PostToolUse and PostToolUseFailure events (where “blocking” the already-completed tool call is undefined)?
  • autoCompactWindow for subagents: the changelog names the field but does not describe the accepted values. Is it a token count, a time window, or a toggle?
  • code key in managed.policies[]: purpose and accepted values are not described in the changelog entry.
  • isDeferred for $.tool.register: use case not described — presumably marks a tool as deferred (available on demand rather than preloaded), matching the isDeferred concept elsewhere in the SDK.