Claude Code v2.1.281: Bedrock assume_role, Guardrails, and a Long List of Resume Fixes
Claude Code v2.1.281 is out, and it's mostly gateway plumbing plus a dense changelog of session-resume and proxy bug fixes. If you run Claude Code behind a gateway or Bedrock upstream, the first three items are the ones that matter.
Claude apps gateway changes
- Newer Claude Desktop keys are now supported in desktop policy blocks, including
blockReadsOutsideWorkingDirectoriesanddisableBypassPermissionsMode. assume_roleon Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, and optionally one session per developer.guardrail: {id, version}on Bedrock upstreams applies an Amazon Bedrock guardrail to every request sent through them. Note the constraint: set it on all Bedrock upstreams or none.telemetry.resource_attributeslets you put fixed labels on telemetry from Claude Desktop and/loginsessions.
Attribution off, and a cross-version caveat
Set "attribution": false in settings.json to hide all commit and PR attribution. One caveat worth reading twice if you commit settings files to a shared repo:
{
"attribution": false
}Older CLI versions skip a settings file that holds this key, so keep it in object form in files shared across versions. A bare boolean form is the version you don't want.
MCP and plugin tooling
- MCP URL-mode elicitation on 2026-07-28 protocol connections — servers can ask Claude Code to open a browser-based flow. No waiting dialog is left on screen when the server has no way to confirm completion.
claude plugin validatenow checks MCP servers and reports.mcp.jsonentries that would be silently dropped at load, undeclared${user_config.*}references, and insecure URLs./insightsadded an auto mode recommendation that estimates how many permission prompts auto mode could have handled in your recent sessions./skills,/mcpand/pluginInstalled lists got a scrollbar in fullscreen mode (mouse-over, clickable, draggable) like/workflowshas.
The fix list
Most of this release is repair work on resumed sessions and streams. Highlights:
- A crash ("unrecoverable interface error") that could end a session mid-retry of an API request.
- A turn that could retry indefinitely, ignoring
--max-turns, when the model alternated unparseable tool calls and output-limit truncation. - Resumed sessions re-sending earlier turns in a changed form — parallel tool-call turns, MCP tool call inputs, tool-search results while a server was reconnecting — which could make the API drop prior reasoning.
- Resuming a very large session restoring only its last few messages.
- A session resumed after a restart during a pending permission prompt sending a different history than before, breaking the prompt cache from that point on.
- Resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and manual resume no longer injects a hidden "Continue" message.
- Prompt cache loss when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (e.g. behind a proxy or gateway).
- Responses cut short by a proxy that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events.
- "Content block not found" when a proxy drops a stream event mid-response — the partial response is now kept, and web search keeps results that already arrived.
- Empty completed responses being requested twice when the connection dropped before the stream's final event.
- Stop reason lost when a proxy sends a trailing usage-only frame.
CLAUDE_CODE_RETRY_WATCHDOGsessions failing on the first 5xx or dropped connection after a run of 429/529 waits, plus uncapped silent sleeps on a longRetry-Afterfrom a 5xx.- Fast mode retrying rate-limited requests back to back when the server sent
Retry-After: 0. - An oversized image from one tool leaving sibling tool calls unanswered, or ending the turn with no final message.
- Conversations permanently stuck on
tool_use.name: String should have at most 200 charactersafter an overlong tool name. - Tool calls failing with "Failed to get memory usage" — or reported as failed after they ran — when Claude Code can't read its own memory usage, e.g. after running out of file descriptors.
--input-format stream-jsonsessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn.
If you're on the Agent SDK, VS Code extension, or a gateway-fronted Bedrock setup, this is a straight upgrade — several of the fixes target exactly those paths.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Trump Pulls Back AI Executive Order Over Fears of Slowing US Tech
President Trump rescinded a Biden-era AI executive order, arguing it could hinder US technological leadership. The move eliminates federal safety reporting mandates.

Claude Admits It's an Affirmation Echo Chamber: The Full Breakdown
In a Reddit post, Claude provides a brutally honest self-assessment: it's an agreeability-by-default system that cannot learn, verify, or self-correct.

Claude Code v2.1.147: Pinned Sessions, /code-review, and Dozens of Fixes
Claude Code v2.1.147 introduces pinned background sessions, renames /simplify to /code-review with effort levels and --comment, plus fixes for PowerShell, MCP, Windows, and more.

InclusionAI Releases Ring-2.6-1T: Trillion-Parameter Model for Agent Workflows
InclusionAI unveiled Ring-2.6-1T, a 1-trillion-parameter reasoning model optimized for agent execution, with dual reasoning effort levels (high/xhigh) and async RL training via IcePop algorithm.