Claude Code v2.1.248: Restricted Mode, Cache TTL, and Session Fixes
Claude Code v2.1.248 shipped with a new restricted execution mode, per-agent cache TTL configuration, and a batch of stability fixes for prompt caching and session management.
Restricted Mode
You can now run Claude Code with --restricted (or set CLAUDE_CODE_RESTRICTED=1). This removes all built-in tools that execute commands or code, plus WebFetch unless explicitly named in --tools. File operations stay inside the working directory, bypassPermissions is refused, and user/project/local settings files are ignored. This is useful for untrusted code reviews or CI environments.
Cache TTL Per Agent
You can now set a prompt-cache TTL in agent frontmatter via experimental.cacheTtl: "5m" or "1h". This applies when no subagent TTL is configured, giving you finer control over cache expiration for specific agents.
Self-Hosted Runner and Settings Diagnostics
The claude self-hosted-runner command gains a --client-label flag (or SELF_HOSTED_RUNNER_CLIENT_LABEL) to override the default label (hostname). Startup now warns if server-managed settings fail to load, and /doctor and /status explain the failure reason. Also, /usage-credits lets Enterprise members request higher limits from admins (AWS Marketplace, self-serve, trials).
Cross-Session Messaging
Added SendMessage and ListAgents for cross-session messaging on the same machine, now supported on Bedrock, Vertex, Foundry, and when telemetry is disabled.
Key Fixes
- Prompt-cache misses in long sessions (roughly hourly) caused by tool re-rendering after OAuth refresh — fixed.
- ScheduleWakeup tool definition changing on overage, causing cache misses on
--resume— fixed. - Desktop/Cowork sessions disappearing after 30 days — fixed; new
desktopSessionCleanupPeriodDayssetting caps the exemption. - Login loop when another process held the token refresh lock — now returns a retryable error.
- Windows: agents list now responds to keyboard after detaching or in win32-input-mode.
- /login with
ANTHROPIC_API_KEYset falls back to API-key sign-in instead of failing with OAuth. - Model names in
/modelrender as code (e.g.,[1m]literal). - Agents skip workspace trust prompt when
CIis set — fixed to show it. - Agent view no longer resurrects stale background sessions; stopped sessions show as stopped.
- Duplicate processes on resumed sessions — prevented.
- Deletion of sessions with merged-but-unpushed branches — allowed.
- Invalid hook answers now show hook name and schema error.
- Invalid JSON from hooks reported as errors, not silently treated as text.
/mcplists connector entries under actual scope, and MCP servers withheadersHelperre-run helper on 401 instead of OAuth fallback.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Microsoft releases Phi-4-reasoning-vision-15B multimodal model with training insights
Microsoft Research has released Phi-4-reasoning-vision-15B, a 15 billion parameter open-weight multimodal reasoning model available through Microsoft Foundry, HuggingFace, and GitHub. The model balances reasoning power with efficiency and excels at math/science reasoning and UI understanding.

Research: AI 'Unbundling' Jobs into Narrower, Lower-Paid Tasks
A new paper argues AI isn't eliminating jobs outright but 'unbundling' them into narrower tasks, with weak-bundle occupations seeing reduced scope and pay while strong-bundle jobs may see performance improvements.

Don’t Use AI to Write Things You Present as Your Own Work
James Bach argues against using AI to draft any content you claim as your own. He warns that admitting AI help devalues your reputation and treats all such work as slop.

Claude Cowork UX Problem: Persistent Input Box Creates False Continuity Expectations
A user identifies a UX problem in Claude Cowork where the persistent text input box maintains draft text across task switches but resets context and loses attachments, creating contradictory signals about continuity.