Claude Code v2.1.268: Fixes HTTP 400 on Third-Party Endpoints, WebFetch Hangs, and Secret Leaks
Claude Code v2.1.268 is out, and it's mostly a bug-fix release with a few gateway and plugin additions. The headline item for anyone not pointing at Anthropic's own API: every request on third-party Anthropic-compatible endpoints was failing with HTTP 400 since v2.1.265.
The HTTP 400 regression
If you're running Claude Code against a proxy or self-hosted endpoint via ANTHROPIC_BASE_URL, every turn has been failing since 2.1.265. The cause: a regex in the Artifact tool's input schema that those endpoints reject. If you skipped 2.1.265–2.1.267, upgrading here is the fix.
WebFetch no longer hangs forever
WebFetch would hang indefinitely on a server that kept the response open without finishing. Fetches now fail after 300 seconds. Override with an env var:
CLAUDE_CODE_WEBFETCH_DEADLINE_MS=<ms> # 0 turns the deadline off
Gateway additions
pricing:ingateway.yamlnow propagates to signed-in Claude Code clients via managed settings, so/costand telemetry line up with the spend meter.- Startup warning when
access_control.allow_cidrsis empty, plus a one-time warning the first time a request arrives from a public address. - New
gatewayInternalNetworksmanaged setting lets admins allow/loginto a Claude apps gateway on their org's own public IPv4 block.
Secrets no longer leak in errors
- Plugin and marketplace errors no longer print a token or password from a git source URL.
/mcp,/pluginserver details,claude mcp list/get, and MCP login errors no longer display secrets resolved from${VAR}placeholders in MCP configs.
Permission and tooling fixes
- Deny/ask rules on symlinked directories (
/etc,/tmp,/varon macOS;/binon Linux) were not applying when a path was given by its real location. Bash commands also ignored deny rules written on a symlinked path spelling. - Read/Edit deny rules were skipped when
env -C,eval, or a similar unanalyzable command sat on the same line. - A respawned in-process teammate could pick up tools or a system prompt from a same-named agent file in an untrusted folder.
Session and CPU fixes
- A busy loop in long-running idle sessions no longer pins a CPU core; rapid terminal focus reports during a session recap no longer keep CPU high.
- SDK sessions using
excludeDynamicSectionsno longer break prompt caching and extended thinking mid-session — the first message isn't re-rendered each request. /compactand auto-compact summaries no longer mangle text containing$sequences.- Restored-file notes from a
/compact-ended conversation now load in the same order on every resume.
JSON output and runner flags
--jsonadded toclaude plugin install,uninstall,update,enable,disable, witherrorDetails/noteDetailsper row ofclaude plugin list --json.configDirectoryadded toclaude auth status --json.claude self-hosted-runner --remove-session-state(default off) deletes per-session directories under<base-dir>/_sessions/when a session ends.
Also fixed: MCP OAuth sign-in failing with "No available ports for OAuth redirect" when the local callback port range can't be bound, workload identity federation via a profile failing mid-run with 401 … jti reused, and stale model-access denials telling entitled users a model is restricted.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Claude MAX Plan Now Includes 1M Token Context Window at No Extra Cost
The Claude MAX plan has been automatically upgraded to include a 1 million token context window without additional API-based usage charges, with users reporting significantly reduced token usage and elimination of context window management overhead.

Andon Labs' AI Agent Mona Runs a Real Cafe in Stockholm — Full Breakdown
Andon Labs gave an AI agent named Mona a lease and real money to open a cafe in Stockholm. She handled bureaucracy, suppliers, and hiring, but hit walls like BankID and had to make suboptimal choices.

Developer Switches from Cursor Composer 2 and Kimi 2.6 to Qwen3.6:35b-a3b for Enterprise Workloads
A developer reports using Qwen3.6:35b-a3b for daily work on a 500-700k LOC enterprise suite, citing better performance than Kimi 2.6 and DeepSeek 4 Pro/Flash, with costs ~$0.08/1M tokens on OpenRouter.

The double standard in AI-assisted creation: coding vs. writing
A Reddit discussion highlights the contrasting reception between AI-assisted coding (vibe coding) and AI-assisted writing, noting identical workflows but different cultural perceptions.