Claude Code v2.1.283 Adds Model Allow/Deny Settings and Prompt Audit

✍️ OpenClawRadar📅 Published: September 26, 2026🔗 Source
Ad

Claude Code v2.1.283 is out, and the headline changes are administrative: two new managed settings that let orgs pin and block specific models, plus a prompt-audit command for finding stale prompt patterns written against older models.

Model control settings

  • availableModelsMatch: set to "exact" and each availableModels entry allows only the model version it names — new releases stay blocked until an admin lists them explicitly.
  • deniedModels: blocks specific models even when availableModels would allow them.

The combination gives you a denylist with a strict allowlist on top, so a rollout can't silently pick up a newer model version.

Prompt audit and OTEL content logging

  • /doctor prompt-audit (also /checkup prompt-audit) audits your CLAUDE.md files, skills, agents, and commands for prompting patterns written for older models.
  • With OTEL_LOG_TOOL_CONTENT=1, MCP tool, WebFetch, and WebSearch outputs are now added to the tool.output OpenTelemetry span event.

Gateway additions

  • New hint header x-claude-code-prompt-id lets LLM gateways group requests that serve one user prompt. Opt in with CLAUDE_CODE_GATEWAY_HINT_HEADERS=1.
  • An opt-in load_test_mode block in the Claude apps gateway config builds and signs requests but doesn't send them upstream, and clients get a canned reply — so you can load test a deployment in isolation.
  • A mantle upstream provider was added to the Claude apps gateway for Amazon Bedrock's Mantle endpoint.
Ad

Notable fixes

  • SDK sessions no longer lose a deferred tool call or finished tool result when a turn ends early, plus fixes for a held approval prompt after worker restart and a non-streaming fallback's result.usage.
  • MCP progress notifications are no longer discarded once a long-running tool call moves to the background; the background task shows the latest progress.
  • stdio MCP servers are no longer left running when a session ends mid-startup.
  • A brief HTTP 404 from a stateless remote MCP server (e.g. a proxy mid-redeploy) no longer leaves that server unusable for the rest of the session while showing as connected.
  • MCP sign-in for a server with no valid URL no longer fails with an opaque SDK error, and /mcp stops offering Authenticate for those servers.
  • /model now accepts Sonnet 4.6 or Sonnet 5 with [1m] when the id carries a date or -v1:0 suffix; the picker also stops showing a hardcoded Haiku version and price when ANTHROPIC_DEFAULT_HAIKU_MODEL pins something else.
  • Dynamic workflows started during a model fallback no longer run every agent on the fallback model.
  • DISABLE_PROMPT_CACHING_HAIKU now takes effect when Haiku is the session's main model.
  • Plugin fixes: validation no longer accepts names it can't install, catches outputStyles/themes/monitors/lspServers paths missing or outside the plugin dir, reports MCP servers declared in plugin.json, lists what marketplace remove uninstalled, fixes case-only id collisions in uninstall, and recovers installed_plugins.json files with invalid or unreadable records.
  • /context now counts MCP server instructions as their own row.

Also added: click-to-expand for truncated messages from other sessions in fullscreen mode, path in --plugin-dir load-failure entries in the stream-json system/init plugin_errors, a fix for the weekly Fable limit not appearing in /usage and VS Code meters when telemetry is disabled, and screen-reader permission dialogs no longer reading quoted commands and paths as dialog text.

📖 Read the full source: GitHub Claude-Code

Ad

👀 See Also