Anthropic released Claude Code v2.1.286 on September 30, 2026. Alongside the usual interface fixes, it contains several changes that matter to teams running the harness unattended or in CI.
Reliability and cost control:
- A single retry limit now covers an entire model call, so "with the default retry settings a failing call sends at most 14 requests."
- If the API refuses the model that a default or alias resolves to, Claude Code "now retries once on the previous model of the same tier" instead of failing every turn. Fallback notices now say when the fallback cut the context window from 1M to 200K tokens.
- Fixes for
--resumeand--continuelosing every turn after a batch of parallel tool calls, and for API 400 errors when a tool or hook returned a non-text value. --barenow connects only the MCP servers named on the command line, sends no system reminders and starts no background tasks.
Secrets and supply chain:
- Several redaction gaps are closed. MCP error messages could show a credential's value when "Bearer" or "Basic" preceded its key name. Percent-encoded tokens were only partly masked. Secrets whose key names contained invisible characters, and URL passwords containing punctuation, slipped past redaction in logs and transcripts.
- Plugin installs now refuse npm sources that are git repositories or folders, and install plugin dependencies only from registry packages.
- The gateway spend meter had been pricing 1-hour prompt-cache writes at the cheaper 5-minute rate, and counting only the first model call's input on streamed turns that run server-side tools. Both are fixed, so reported spend may rise to its correct level.
Why it matters: as coding agents run for hours under automation, the harness rather than the model decides how much a failure costs and what leaks into logs. A fixed retry budget makes the worst case of a failing call predictable. Same-tier fallback trades a hard failure for a quiet model switch, so pipelines that pin a model should watch for the fallback notice. The redaction fixes are a reason to upgrade and to check whether older transcripts or feedback bundles hold credentials that need rotating.
Claude Code 2.1.286 caps a failing model call at 14 requests by default, falls back to the previous same-tier model on refusals, restricts plugin dependencies to registry packages and closes several credential-redaction gaps; upgrade, and audit older logs for leaked secrets.