Claude Code v2.1.286: model-refusal fallback, permission-prompt counts, safer credential logs#

Published by

Part of the Claude Code Version Tracker series. | Official Env Vars | Official Changelog

Claude Code v2.1.286 keeps a session running when the API refuses your default model: it retries once on the previous model of the same tier instead of failing every turn. Stacked permission requests now show a "2 of 5" count, and a shared lock stops several processes from each opening a login browser when GCP or AWS credentials expire. It follows v2.1.285.

Model refusals stop breaking the session#

When the Anthropic API refuses the model your default or an alias resolves to, every turn used to fail.[1] The session now retries once on the previous model of the same tier. Refusal and --fallback-model retries that could not run fast now run at standard speed, with a one-time notice in interactive sessions. When a fallback drops the context window from 1M to 200K tokens, the fallback notice and the autocompact-thrashing error say so. A separate change puts one retry limit on a whole model call, so with the default retry settings a failing call sends at most 14 requests.

Stacked prompts and safer credential logs#

When several permission requests stack up, the prompt now shows a count such as "2 of 5". Much of the rest of the release closes ways a secret could leak into an error message, log, or transcript:[1]

  • MCP error messages no longer show a credential's value when "Bearer" or "Basic" comes before its key name.
  • Percent-encoded bearer tokens, previously masked only in part, are now fully masked.
  • A secret whose key name has an invisible character inside, such as a zero-width space, is now redacted.
  • URL passwords with punctuation such as ), quotes, ], &, a second @, or that run past a / to a bracketed host like [::1] in an ssh URL are no longer left in logs.
  • The transcript in the zip that /feedback saves no longer contains invalid JSON lines after redaction.

One login browser when credentials expire#

Several Claude Code processes and IDE extensions each opened a login browser when gcpAuthRefresh or awsAuthRefresh credentials expired.[1] A coordination lock now lets one process handle the refresh. The escape hatch is an environment variable.

VariableWhat It Does
CLAUDE_CODE_DISABLE_AUTH_REFRESH_LOCKTurns off the lock that coordinates a GCP or AWS credential refresh across processes. With the lock on, one process refreshes and opens a single login browser instead of each process opening its own. Added in v2.1.286.

Plugins, sessions, and Remote Control#

Plugin installs now refuse npm sources that are git repositories or folders, and install plugin dependencies only from registry packages.[1] A plugin error for a marketplace Claude Code refuses to load now says why and how to fix it instead of "not found". claude --resume and --continue no longer lose every turn after a batch of parallel tool calls when the earlier session crashed, and cloud sessions with very large histories now wake up instead of stopping while the transcript loads. Remote Control sessions disconnect with a notice when an organization's policy turns Remote Control off.

--bare now connects only the MCP servers named on the command line, sends the model no system reminders, and starts no background tasks; under --bare, a shell command that reaches its timeout stops instead of moving to the background. When your project or user skills include one named verify, Claude is told to run it right before committing, except for docs-only and tests-only commits. In VS Code, this build adds a Bookmarks side panel for saved responses, records the questions Claude asks and your answers in the conversation, and shows a preview of the highlighted choice beside a question card.

What These Tell Us#

The model layer got more tolerant of transient API refusals and model changes. A same-tier retry when a model is refused, fallbacks that run at standard speed, a notice when the context window shrinks from 1M to 200K, and a bounded per-call retry budget all keep a turn from failing outright.

Redaction now covers more of the shapes a secret takes in error messages, logs, and the /feedback zip. With the single-browser auth-refresh lock, the credential path is where much of this release's work landed.

On the surrounding tools, plugin install limits sources to registry packages and refuses git repositories and folders, and --bare narrows what a scripted session connects and starts. Both bound what runs without a prompt.

Sources#

  1. Claude Code Official Changelog, v2.1.286 release notes

This analysis is conducted for educational and research purposes under fair use principles. All trademarks and software referenced belong to their respective owners.


Previous Claude Code analysis: v2.1.285 (September 29, 2026)

All 60 Claude Code analyses: Claude Code Version Tracker · Official Claude Code changelog