Claude Code v2.1.281: Bedrock assume_role, Guardrails, and a Long List of Resume Fixes
Claude Code v2.1.281 is out, and it's mostly gateway plumbing plus a dense changelog of session-resume and proxy bug fixes. If you run Claude Code behind a gateway or Bedrock upstream, the first three items are the ones that matter.
Claude apps gateway changes
- Newer Claude Desktop keys are now supported in desktop policy blocks, including
blockReadsOutsideWorkingDirectoriesanddisableBypassPermissionsMode. assume_roleon Bedrock upstreams: the gateway calls Bedrock as an IAM role it assumes through STS, in another AWS account if needed, and optionally one session per developer.guardrail: {id, version}on Bedrock upstreams applies an Amazon Bedrock guardrail to every request sent through them. Note the constraint: set it on all Bedrock upstreams or none.telemetry.resource_attributeslets you put fixed labels on telemetry from Claude Desktop and/loginsessions.
Attribution off, and a cross-version caveat
Set "attribution": false in settings.json to hide all commit and PR attribution. One caveat worth reading twice if you commit settings files to a shared repo:
{
"attribution": false
}Older CLI versions skip a settings file that holds this key, so keep it in object form in files shared across versions. A bare boolean form is the version you don't want.
MCP and plugin tooling
- MCP URL-mode elicitation on 2026-07-28 protocol connections — servers can ask Claude Code to open a browser-based flow. No waiting dialog is left on screen when the server has no way to confirm completion.
claude plugin validatenow checks MCP servers and reports.mcp.jsonentries that would be silently dropped at load, undeclared${user_config.*}references, and insecure URLs./insightsadded an auto mode recommendation that estimates how many permission prompts auto mode could have handled in your recent sessions./skills,/mcpand/pluginInstalled lists got a scrollbar in fullscreen mode (mouse-over, clickable, draggable) like/workflowshas.
The fix list
Most of this release is repair work on resumed sessions and streams. Highlights:
- A crash ("unrecoverable interface error") that could end a session mid-retry of an API request.
- A turn that could retry indefinitely, ignoring
--max-turns, when the model alternated unparseable tool calls and output-limit truncation. - Resumed sessions re-sending earlier turns in a changed form — parallel tool-call turns, MCP tool call inputs, tool-search results while a server was reconnecting — which could make the API drop prior reasoning.
- Resuming a very large session restoring only its last few messages.
- A session resumed after a restart during a pending permission prompt sending a different history than before, breaking the prompt cache from that point on.
- Resuming a session that ended during a tool call: Claude now sees the call and is told its outcome is unknown, and manual resume no longer injects a hidden "Continue" message.
- Prompt cache loss when an MCP server disconnects mid-conversation, or is still connecting after a resume, while tool search is off (e.g. behind a proxy or gateway).
- Responses cut short by a proxy that closes the stream cleanly being shown as complete with no warning, and tool calls running twice on duplicated stream events.
- "Content block not found" when a proxy drops a stream event mid-response — the partial response is now kept, and web search keeps results that already arrived.
- Empty completed responses being requested twice when the connection dropped before the stream's final event.
- Stop reason lost when a proxy sends a trailing usage-only frame.
CLAUDE_CODE_RETRY_WATCHDOGsessions failing on the first 5xx or dropped connection after a run of 429/529 waits, plus uncapped silent sleeps on a longRetry-Afterfrom a 5xx.- Fast mode retrying rate-limited requests back to back when the server sent
Retry-After: 0. - An oversized image from one tool leaving sibling tool calls unanswered, or ending the turn with no final message.
- Conversations permanently stuck on
tool_use.name: String should have at most 200 charactersafter an overlong tool name. - Tool calls failing with "Failed to get memory usage" — or reported as failed after they ran — when Claude Code can't read its own memory usage, e.g. after running out of file descriptors.
--input-format stream-jsonsessions (Agent SDK, VS Code extension) and scheduled cloud sessions failing every turn.
If you're on the Agent SDK, VS Code extension, or a gateway-fronted Bedrock setup, this is a straight upgrade — several of the fixes target exactly those paths.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Claude Code v2.1.157: Auto-Load Plugins from .claude/skills, Improved Agents & Worktrees
Claude Code v2.1.157 automatically loads plugins from .claude/skills, adds claude plugin init scaffolding, honors agent setting in settings.json, and fixes numerous bugs across agents, worktrees, and terminal integration.

OpenClaw 2026.3.2 Update Disables Agent Tools by Default
OpenClaw 2026.3.2 disables all agent tool permissions by default, preventing tools like exec and web_fetch from working. The fix requires adding a configuration to openclaw.json.

Why I Won't Read LLM Authored Fiction: Statistical Profiles and the Median Writing Problem
Chris McCormick explains why he avoids LLM-authored fiction, arguing that its statistical profile is too close to the median, nudging readers' minds toward the statistically normal rather than the creatively unique.
Claude Code 2.1.233: GitLab MR support, memory limits, and security fixes
Claude Code v2.1.233 adds GitLab merge request URLs, opt-in memory limits for Bash, and fixes NTLM credential leak and CPU spin.