Claude Code v2.1.290: Plugin Hook Tuning, Managed Agents Onboarding, and a Long List of Session Fixes
Claude Code v2.1.290 is out, and it's mostly a maintenance release with several plugin-hook API additions and a long fix list. The headline items are new fields exposed to mods and plugin hooks, plus a few CLI conveniences.
Plugin and mod hook changes
serverToolUsesis now in the result of a mod'sturn.stephook — it lists the tool calls the API ran itself (the advisor), each with id, name, input, start, and end.agentIdwas added to thetool.checkevent of plugin hooks, so a hook can distinguish a subagent's permission check from the main session's.ceilingwas added to the question and verdict a mod'stool.checkhook reads, naming the approval an organization requires for a tool.ThemeKeyandColortypes were added to the plugin hooks typings so editors can autocomplete theme colors a mod's drawing can name.
claude plugin validate now lists each hook a mod registers at a gating site along with whether it has a .catch (as gatingHooks under --json). A related fix addresses plugin hooks with .catch being unloaded and their .catch skipped when the hook kept throwing.
CLI and onboarding additions
claude attach <name>andclaude logs <name>now accept part of a session name instead of a full id./claude-api managed-agents-onboard <url>sets up the Managed Agents pattern a page describes asant applyfiles./claude-api managed-agents-onboard <quickstart-name>builds a Console quickstart template (e.g.deep-researcher) using theantCLI.- A Deny button was added to the Claude apps gateway's sign-in approval page — the waiting terminal stops within seconds.
Two new warnings: one when a managed settings file is a symlink to a file outside the managed settings folder, and one in /status and doctor when managed settings ignore user-configured sandbox allowRead paths or allowed domains.
Fixes worth noting
- Requests behind proxies and gateways that reject beta headers with non-400 statuses, or together with a second beta, now succeed.
- Long sessions with hundreds of images no longer get stuck on "Request rejected as unprocessable by the model" errors.
- When the API's output content filter stops a reply while Claude is still thinking, the request is retried once before the error is shown.
- Resumed subagents/teammates no longer lose earlier thinking and prompt cache after receiving a mid-run message.
WebFetchno longer silently drops text past 100,000 characters; it reports how much was unread and accepts anoffset.- Scheduled tasks (
/loopwith interval, reminders) survive compaction on resume from this version on, and foreground scheduled tasks now fire after a←or/backgroundhand-off. - Headless
--json-schemaruns no longer exit non-zero withis_error: truewhen the connection drops after structured output is delivered. - Plan mode no longer lets the auto mode classifier approve non-read-only connector tools with a server-pushed ask policy.
- Project
CLAUDE.md, rules, orAGENTS.mdsymlinked outside working directories no longer load underpermissions.blockReadsOutsideWorkingDirectoriesor aReaddeny rule. /ultrareviewon Windows no longer drops uncommitted changes without warning whengit stash createfails.- The background daemon's log no longer passes terminal control characters to the screen under
claude daemon run/claude daemon logs; they show as\uXXXXescapes.
If you're running Claude Code in CI or behind a corporate proxy, the beta header fix and the managed settings warnings are probably the ones you'll care about most.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Why OpenClaw is Not Responding: Users Express Concerns
OpenClaw users are facing issues with non-responsive AI coding agents. The discussion on Reddit sheds light on the possible causes and user feedback.

Anthropic Refuses Pentagon Safety Removal Demands, Loses Federal Contracts
Anthropic refused Pentagon demands to remove safety guardrails from Claude for military applications, leading to a $200M contract cancellation and a presidential order banning federal agency use of their technology.

Token Efficiency as an Act of Refusal: Why AI Companies Want You Wasteful
LLM providers profit from dependency. Token efficiency is an act of refusal. Don't generate what you won't read.

Anthropic Acquires Stainless for $300M+ — Now Owns Dominant MCP Server Generator
Anthropic bought SDK generator Stainless for $300M+. Stainless generates most production MCP servers from OpenAPI specs. The hosted product is winding down; new signups stopped Monday.