Claude Code v2.1.285 Adds Desktop Handoff, Plugin Config CLI, and Provider Restrictions

✍️ OpenClawRadar📅 Published: September 30, 2026🔗 Source
Ad

Claude Code v2.1.285 landed with three new CLI surfaces and a batch of fixes concentrated around subagents, plugins, and MCP. If you run claude -p in CI or wire Claude Code into an SSH-heavy workflow, several of these are worth the upgrade on their own.

New environment variables

  • CLAUDE_CODE_DISABLE_WEB_FETCH — turns off the WebFetch tool entirely. Useful when you're running against untrusted input and don't want the agent reaching out to URLs it scraped from the repo.
  • CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES — caps how many times a non-streaming fallback request gets re-sent after a timeout. Without a cap, a flaky endpoint can trigger repeated re-sends with no ceiling.

Plugin and desktop commands

claude --desktop opens the Claude desktop app on the current directory, or attaches to an existing session with --continue / --resume <id>. It's the handoff path from terminal to GUI without re-establishing context.

claude plugin configure <plugin> prints a plugin's options and marks which ones are unset. Add --values-stdin to read new values from stdin and save them, which makes plugin config scriptable.

claude plugin install --config now accepts <server>.<key>=<value> pairs, so a bundled .mcpb MCP server's own settings can be set at install time. The server starts with those values instead of sending you into /plugin → Configure after the fact.

allowedProviders managed setting

A new managed setting, allowedProviders, limits which API providers a machine may use: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway. This is the fleet-policy knob — lock a build machine or a regulated environment to one provider without relying on per-user config.

Ad

Notable fixes

  • claude -p with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent actually receives the child's result.
  • Plugin and marketplace installs over SSH now respect the ssh program set in GIT_SSH or core.sshCommand, instead of ignoring both.
  • Claude Code no longer refuses to start when the OS denies reading the managed settings file. It warns and starts without those policies. Other read errors and unparseable files still halt every session.
  • Model switching mid-session via a set_model request (like the Agent SDK's setModel) no longer leaves the new model stuck on the built-in output-token limit and auto-compact window until restart.
  • Redacted logs and transcripts no longer leak part of a URL password containing @, or all of it when the URL writes @ as %40.
  • SSH passphrase and new-host prompts from worktree and /teleport fetches now fail fast instead of hijacking the terminal.
  • Disabling an MCP server added mid-session in SDK and -p sessions now actually removes its tools.
  • claude -p --permission-prompt-tool: a background subagent's permission request routes to the prompt tool instead of being auto-denied.
  • claude mcp list, claude mcp get, and the not-found errors of mcp remove, login, and logout no longer print line breaks and terminal escape sequences embedded in MCP server names and values.
  • Sandbox auto-allow stops asking for approval on every run of inline scripts like python3 -c and node -e just because they contain =.
  • Fork subagents now inherit the parent's permission mode, including dontAsk and plan mode, and cannot exit plan mode.
  • Background subagents in auto mode no longer prompt a second, redundant reply after each report.
  • Cloud session creation and /remote-env no longer read only the newest 20 environments on an account.
  • Remote Control marks a message read when Claude starts on it, not when it arrives, and a message queued at terminal quit now arrives on the next resume.
  • Plugin installs are refused when ids differ only in ., -, @, or capitals (macOS, Windows), which previously could drop a plugin into another installed plugin's cache or data folder.
  • Hooks and SDK permission callbacks on ExitPlanMode no longer see a missing or outdated plan when the plan was written in the same response.

There's also a fix for the first reply in cloud sessions arriving tens of milliseconds late — a regression introduced in 2.1.283.

📖 Read the full source: GitHub Claude-Code

Ad

👀 See Also