Claude Code 2.1.295: what changed (fail-closed hooks, retry watchdog cap, gateway models)
Claude Code 2.1.295: hooks can fail closed, unattended retry gets a max wait, the apps gateway gets per-upstream models and TTFB timeouts. Plus MCP and Chrome fixes.
Since the 2.1.290–2.1.291 fiche, the Claude Code CHANGELOG has reached 2.1.295. It's additive: no breaking change. For operators, three things matter: hooks can now fail closed, unattended retry mode gets a max wait, and the Claude apps gateway gets per-upstream model lists and a time-to-first-byte timeout. This is a short catch-up, not the full list.
Hooks: onFailure: "block"
Added
onFailure: "block"for command and HTTP hooks: a hook that can't start, times out, or exits with an unexpected code blocks the action instead of letting it through
Until now a broken policy hook failed open. If you gate Bash or edits with hooks, read the fail-closed hooks Spec. The hooks docs don't list the field yet.
Retry watchdog max wait
Added
CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MSto limit how long unattended retry mode (CLAUDE_CODE_RETRY_WATCHDOG) waits out 429 and 529 errors
Useful for CI and overnight runs that shouldn't sit on a 429 for hours. It sits next to the 529 base-delay knob from 2.1.292 (overloaded retry Spec). Units are milliseconds per the name; the default is [GAP].
Claude apps gateway
Added an optional
modelslist to every Claude apps gateway upstream: only the listed models are sent there, on failover too, and one*in an entry is a wildcard
Added support for
timeouts.upstream_ttfb_mson the Claude apps gateway's Bedrock, Vertex, Foundry and other cloud upstreams
Also: forceLoginMethod: "gateway" and forceLoginGatewayUrl now work from user settings on machines with no managed settings, upstream_request_id lands in the inference audit event, and successful responses carry a request-id header that matches telemetry. For policy at org level, see managed settings.
Fixes worth knowing
[1m]models stopped failing on gateways, Bedrock, Vertex, or Foundry that refuse the context-1m beta; Claude Code resends without it.- Remote MCP in headless/SDK sessions reconnects after outages over 15 s, with backoff up to 30 s instead of a tight loop.
- Claude in Chrome now applies a
host:80deny rule to plainhttp://pages. - Subagents in their own linked worktree no longer see the parent's git branch and status (Agent Teams vs subagents).
claude -ptext output no longer drops earlier responses when background work starts another turn.
One-liners: OSC 7501 Program Status Protocol for terminals; /copy picker gets quoted text; plugin install/enable warns when the settings file it writes doesn't load; claude plugin validate suggests a README install line.
Upgrade readout
| Operator | Action |
|---|---|
| Hook-based policy | Upgrade, add onFailure: "block", test a broken path |
| Unattended / CI retry | Set CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS |
| Gateway admins | Add per-upstream models, set timeouts.upstream_ttfb_ms |
[1m] on cloud providers | Upgrade: fixes all-requests-failing |
| Everyone else | Routine upgrade |
Sources (checked 2026-10-09, ~08:40 CEST)
- Claude Code CHANGELOG.md (raw): 2.1.295 bullets. The CHANGELOG doesn't date versions, so the release day is [GAP].
