Claude Code v2.1.225 Fixes OAuth Token Rotation, Adds Gateway Spend-Limit Support

Claude Code v2.1.225 shipped with a mix of bug fixes and new features, headlined by gateway spend-limit support and a fix for a nasty 401 that could break headless sessions.
Key Fixes
- OAuth token rotation: Fixed a transient 401 that replaced a long-lived
CLAUDE_CODE_OAUTH_TOKENwith a short-lived token from a stored login, breaking headless sessions until restart. Now the token is handled correctly. - macOS MCP OAuth: Fixed intermittent 401 bursts on MCP OAuth servers after a keychain read timeout, making authentication more reliable.
- Auto mode safety filter: Safety-filter refusals of its own permission check no longer count toward the consecutive-block limit. The action is still denied, but the model is told to move on rather than retry.
- Headless sessions: Cross-session messages no longer stay parked without notice or expiry during startup or in headless mode.
- Remote Control resume: Fixed conversation history breaking after very large conversations were compacted.
- Agent list hover: Hovering over a session in another project no longer changes the directory for the next agent.
- self-hosted-runner: Exits at startup with a clear error if
--base-dircannot be created or written, instead of registering and failing every session. - Web sessions: Fixed sessions being misreported as stuck, which caused a growing event backlog to resend on every reconnect.
- VSCode Focus view: Fixed folding that hid the latest to-do list, pending question context, and settled answers. Thinking-only folds now show "Thought for Ns" and auto-collapse when the turn completes.
New Features and Improvements
- Gateway spend limits: Added support for gateway spend limits in usage warnings. The limit-reached message now names the cap, its reset time, and the operator's message. (Requires the gateway on 2.1.225).
- Workspace trust for agents:
claude agentsnow prompts for workspace trust in untrusted directories, matchingclaudebehavior. - Remote Control photos: Photos attached from the Claude app are now shown directly to Claude, instead of being read from disk with a separate tool call.
- SendMessage: Can now start a conversation with Remote Control sessions on other machines by name (ListAgents shows them as
name [ref]), instead of only replying after they message you first. Also, a Remote Control recipient you already confirmed is never swapped for a same-named session on this machine when its own list couldn't be checked.
This release is primarily a stability pass, addressing several long-standing issues in headless and remote workflows. The gateway spend limit support is particularly useful for teams with cost controls.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Claude Code: Feedback Honeypot Overrides Privacy Opt-Out — Users Report Session Transcript Trap
Anthropic's Claude Code now prompts users to allow session transcript review — pressing 'n' for no logs 'Thanks for your feedback' and may still train models. Dismiss key behavior is unclear.

Coding Agent Session Logs Are Stored Locally, Could Enable Open Federated Training
Coding agents like Claude Code and Codex CLI store detailed session logs locally, including tasks, reasoning, tool calls, and environment responses. A Reddit post proposes using this data via federated learning to create an open equivalent to proprietary training datasets.

KV Cache Architecture Evolution: From GPT-2 to Mamba
Analysis of KV cache memory costs shows GPT-2 used 300 KiB/token, Llama 3 reduced it to 128 KiB/token with grouped-query attention, and DeepSeek V3 achieved 68.6 KiB/token with multi-head latent attention. Mamba/SSMs eliminate KV cache entirely with fixed-size hidden states.

ETH Zurich Study Questions Value of AGENTS.md Files for AI Coding Agents
New research from ETH Zurich finds LLM-generated AGENTS.md files reduce AI agent task success by 3% and increase inference costs by over 20%, while human-written files offer only marginal 4% gains with similar cost increases.