Claude Code v2.1.286 Fixes Resume Data Loss, Credential Leaks, and MCP Auth Bugs

✍️ OpenClawRadar📅 Published: October 1, 2026🔗 Source
Ad

Claude Code v2.1.286 is a bug-fix release with a handful of changes that matter if you run long sessions, use MCP connectors, or work behind an auth proxy. Here's what actually changed.

Resume and session integrity

  • claude --resume and --continue were sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed. That one's fixed.
  • API 400 errors after a tool or hook returned an object, number, or boolean instead of text — including in resumed sessions — are resolved.
  • Cloud sessions with very large histories could hang forever because the container was stopped while the transcript was still loading.
  • A Remote Control message that arrived during exit was marked delivered and then never answered. It now stays queued for the session's next run.

Credential and secret handling

Several fixes here, and they're the kind of bugs that quietly leak values into logs:

  • MCP error messages were showing a credential's value when Bearer or Basic appeared before the key name.
  • Percent-encoded Bearer tokens were only partly masked in error messages.
  • Redacted logs and transcripts could show a secret whose key name contained an invisible character (e.g. a zero-width space).
  • URL passwords containing punctuation like ), quotes, ], &, or a second @ were only partially redacted, as were ssh URLs with bracketed hosts like [::1].
  • The session transcript inside the zip saved by /feedback could contain invalid JSON lines after secret redaction.

Auth and login fixes

  • Multiple Claude Code processes and IDE extensions were each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expired.
  • macOS sessions kept showing "Not logged in" / "Login expired" after /login succeeded in another window if a leftover ~/.claude/.credentials.json existed.
  • claude auth status reported a Console sign-in's stored API key as claude.ai; it now reports api_key, and the VS Code extension treats that session as an API key session.
  • /status listed an Anthropic profile next to an API key as if both were active. The profile is now marked not in use.
Ad

Model fallback and MCP

  • When the Anthropic API refuses the model your default or an alias resolves to, every turn used to fail. Claude Code now retries once on the previous model of the same tier.
  • Refusal and --fallback-model retries no longer fail when the fallback model can't run fast; they run at standard speed with a one-time notice in interactive sessions.
  • MCP connectors could list no tools for up to a day after their server dropped the older MCP handshake.
  • /usage now credits an MCP server for a tool call made while it was connecting or had just connected (e.g. right after a restart).
  • Repeat MCP sign-in requests no longer replace the pending sign-in link and break it.

UI and subagent fixes

  • Permission prompts now show a count like "2 of 5" when requests stack up.
  • Fullscreen list "N more" rows support mouse clicks to jump to that end of the list, with hover and pressed states.
  • A message typed into a running subagent no longer shows twice after the subagent reads it.
  • Subagent hand-back messages show the agent's name instead of a raw task id when no name was registered.
  • Foreground subagents no longer miss task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions where they're enabled.
  • Subagents spawned with worktree isolation no longer reload the project CLAUDE.md and its imports a second time from the worktree copy on first file read.

If you're on an older 2.1.x build, this is worth pulling — the resume data loss and credential-redaction fixes in particular are the kind of thing you don't want to discover in production.

📖 Read the full source: GitHub Claude-Code

Ad

👀 See Also