Claude Code v2.1.126: Model Picker, Project Purge, OAuth Fixes, and Security Improvements

✍️ OpenClawRadar📅 Published: May 1, 2026🔗 Source
Claude Code v2.1.126: Model Picker, Project Purge, OAuth Fixes, and Security Improvements
Ad

Anthropic released Claude Code v2.1.126 with several notable features and fixes. Here's what changed.

Model Picker for Gateways

The /model picker now lists models from your gateway's /v1/models endpoint when ANTHROPIC_BASE_URL points at an Anthropic-compatible gateway. This makes it easier to switch models in proxied setups.

New Command: claude project purge

Added claude project purge [path] to delete all Claude Code state for a project — transcripts, tasks, file history, and config entry. Supports --dry-run, -y/--yes, -i/--interactive, and --all flags.

Security and Permissions

  • --dangerously-skip-permissions now bypasses prompts for writes to .claude/, .git/, .vscode/, shell config files, and other previously-protected paths. Catastrophic removal commands still prompt as a safety net.
  • Fixed allowManagedDomainsOnly / allowManagedReadPathsOnly being ignored when a higher-priority managed-settings source lacked a sandbox block.
  • Windows: clipboard writes no longer expose copied content in process command-line arguments visible to EDR/SIEM telemetry; also fixes >22KB selections not reaching the clipboard.

OAuth and Login Fixes

  • claude auth login now accepts the OAuth code pasted into the terminal when the browser callback can't reach localhost (WSL2, SSH, containers).
  • Fixed OAuth login failing with timeout on slow or proxied connections, in IPv6-only devcontainers, and when the browser callback can't reach localhost.
  • Fixed showing the login screen for "OAuth not allowed for organization" errors — now shows guidance to contact your admin.
  • Fixed a rare race where a concurrent credential write could clear a valid OAuth refresh token.
Ad

Windows Improvements

  • PowerShell 7 installed via Microsoft Store, MSI without PATH, or .NET global tool is now detected.
  • When the PowerShell tool is enabled, Claude now treats PowerShell as the primary shell instead of defaulting to Bash.
  • Fixed Japanese/Korean/Chinese text rendering as garbled characters on Windows in no-flicker mode.

Other Notable Fixes

  • Fixed pasting an image larger than 2000px breaking the session — images are now downscaled on paste, and oversized images in history are automatically removed and the request retried.
  • Fixed "Stream idle timeout" error after waking Mac from sleep mid-request.
  • Fixed background and remote sessions falsely aborting with "Stream idle timeout" during long model thinking pauses.
  • Fixed overly fast trackpad scrolling in Cursor and VS Code 1.92–1.104 integrated terminals.
  • Fixed Ctrl+L clearing the prompt input — it now only forces a screen redraw, matching readline behavior.
  • Fixed deferred tools (WebSearch, WebFetch, etc.) not being available to skills with context: fork and other subagents on their first turn.
  • Fixed plan-mode tools being unavailable in interactive sessions launched with --channels.
  • Fixed Agent SDK hang when the model emits a malformed tool name in a parallel tool call batch.

Telemetry and Auto Mode

  • claude_code.skill_activated OpenTelemetry event now fires for user-typed slash commands and carries a new invocation_trigger attribute ("user-slash", "claude-proactive", or "nested-skill").
  • Auto mode: the spinner now turns red when a permission check stalls, instead of looking like the tool is running.
  • Host-managed deployments (CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST) no longer auto-disable analytics on Bedrock/Vertex/Foundry.

For full details, see the release notes.

📖 Read the full source: GitHub Claude-Code

Ad

👀 See Also

Claude Code's Illusion of Finished Work: Why Reviewing the Agent's Path Matters More Than the Diff
Tools

Claude Code's Illusion of Finished Work: Why Reviewing the Agent's Path Matters More Than the Diff

Claude Code can produce a clean diff, passing tests, and a good summary—yet still miss real behavior, security concerns, or architecture constraints. The author argues that reviewing the chain of actions (plans, files read, commands run, test output) is now essential, not just the final diff.

OpenClawRadar
Argyph: A Single MCP Server for Claude Code with 19 Structured Code Understanding Tools
Tools

Argyph: A Single MCP Server for Claude Code with 19 Structured Code Understanding Tools

Argyph is a local MCP server that gives Claude Code 19 tools — go-to-definition, find-references, call graphs, semantic search, token-budgeted repo packing — replacing multiple separate MCP servers with one install. No API key required; all processing stays on your machine.

OpenClawRadar
General Bots: Open-source AI agent platform for self-hosted enterprise automation
Tools

General Bots: Open-source AI agent platform for self-hosted enterprise automation

General Bots is an open-source platform started in 2019 that provides AI agents, workflow automation, document processing, and integrations with local AI model support, designed for organizations needing full control over their infrastructure.

OpenClawRadar
Spec27: Spec-Driven Validation for AI Agents – API-Level Testing Without Internal Access
Tools

Spec27: Spec-Driven Validation for AI Agents – API-Level Testing Without Internal Access

Spec27 is a new tool from Safe Intelligence for spec-driven validation of AI agents. It tests agent behavior from the outside in, running adversarial and robustness checks against primary interfaces without needing SDKs, gateways, or internal traces.

OpenClawRadar