Claude Code v2.1.285 Adds Desktop Handoff, Plugin Config CLI, and Provider Restrictions
Claude Code v2.1.285 landed with three new CLI surfaces and a batch of fixes concentrated around subagents, plugins, and MCP. If you run claude -p in CI or wire Claude Code into an SSH-heavy workflow, several of these are worth the upgrade on their own.
New environment variables
CLAUDE_CODE_DISABLE_WEB_FETCH— turns off the WebFetch tool entirely. Useful when you're running against untrusted input and don't want the agent reaching out to URLs it scraped from the repo.CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES— caps how many times a non-streaming fallback request gets re-sent after a timeout. Without a cap, a flaky endpoint can trigger repeated re-sends with no ceiling.
Plugin and desktop commands
claude --desktop opens the Claude desktop app on the current directory, or attaches to an existing session with --continue / --resume <id>. It's the handoff path from terminal to GUI without re-establishing context.
claude plugin configure <plugin> prints a plugin's options and marks which ones are unset. Add --values-stdin to read new values from stdin and save them, which makes plugin config scriptable.
claude plugin install --config now accepts <server>.<key>=<value> pairs, so a bundled .mcpb MCP server's own settings can be set at install time. The server starts with those values instead of sending you into /plugin → Configure after the fact.
allowedProviders managed setting
A new managed setting, allowedProviders, limits which API providers a machine may use: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway. This is the fleet-policy knob — lock a build machine or a regulated environment to one provider without relying on per-user config.
Notable fixes
claude -pwithCLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent actually receives the child's result.- Plugin and marketplace installs over SSH now respect the ssh program set in
GIT_SSHorcore.sshCommand, instead of ignoring both. - Claude Code no longer refuses to start when the OS denies reading the managed settings file. It warns and starts without those policies. Other read errors and unparseable files still halt every session.
- Model switching mid-session via a
set_modelrequest (like the Agent SDK'ssetModel) no longer leaves the new model stuck on the built-in output-token limit and auto-compact window until restart. - Redacted logs and transcripts no longer leak part of a URL password containing
@, or all of it when the URL writes@as%40. - SSH passphrase and new-host prompts from worktree and
/teleportfetches now fail fast instead of hijacking the terminal. - Disabling an MCP server added mid-session in SDK and
-psessions now actually removes its tools. claude -p --permission-prompt-tool: a background subagent's permission request routes to the prompt tool instead of being auto-denied.claude mcp list,claude mcp get, and the not-found errors ofmcp remove,login, andlogoutno longer print line breaks and terminal escape sequences embedded in MCP server names and values.- Sandbox auto-allow stops asking for approval on every run of inline scripts like
python3 -candnode -ejust because they contain=. - Fork subagents now inherit the parent's permission mode, including
dontAskand plan mode, and cannot exit plan mode. - Background subagents in auto mode no longer prompt a second, redundant reply after each report.
- Cloud session creation and
/remote-envno longer read only the newest 20 environments on an account. - Remote Control marks a message read when Claude starts on it, not when it arrives, and a message queued at terminal quit now arrives on the next resume.
- Plugin installs are refused when ids differ only in
.,-,@, or capitals (macOS, Windows), which previously could drop a plugin into another installed plugin's cache or data folder. - Hooks and SDK permission callbacks on ExitPlanMode no longer see a missing or outdated plan when the plan was written in the same response.
There's also a fix for the first reply in cloud sessions arriving tens of milliseconds late — a regression introduced in 2.1.283.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Study Shows Claude Opus Agent Failures Were Architectural, Not Alignment Issues
A study placed Claude Opus and Kimi K2.5 in a live environment with email, shell access, and persistent storage. The models demonstrated correct values but experienced serious failures due to missing architectural safeguards like stakeholder models and execution boundaries.

Claude Cowork Usage Limits Doubled to 10 Hours Through July 5
Anthropic doubled the 5-hour usage limits in Claude Cowork to 10 hours for the next month on all paid plans. Available through July 5 via the desktop app.

CBP's Clearview AI Deal: Facial Recognition for Tactical Targeting
U.S. Customs and Border Protection has contracted Clearview AI for tactical targeting, using face recognition technology on billions of internet-scraped images.

SAP Freezes Most Travel and Hiring Due to AI's Soaring Cost — Except AI Itself
SAP suspended most travel and hiring due to AI's soaring cost, with exceptions only for AI-related hires and travel, according to an internal email obtained by 404 Media.