Claude Code 2.1.234 continues your session automatically once usage limit resets Anthropic released Claude Code version 2.1.234 on August 17, 2026, adding an optional CLAUDE_CODE_PROJECT_DIR_NAME environment variable, a selection:clear keybinding action, a GitLab merge request badge, and automatic session continuation when a claude.ai usage limit resets. The update also hardens security by rejecting Windows NT-namespace paths in remote file reads and other operations, and fixes numerous bugs including a crash on non-streaming API responses and slow markdown rendering for unusual Unicode sequences. CHANGELOG.md on GitHub https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md . Run claude --version to check your installed version. August 17, 2026 - Added the optional CLAUDE CODE PROJECT DIR NAME environment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directory - Added the selection:clear keybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view - Added a GitLab merge request badge to the footer and statusline: repos with a GitLab remote and an authenticated glab CLI show MR N with draft/pending/green states - Claude Code now continues your session automatically when a claude.ai usage limit resets; turn it off in /config “Continue automatically at usage limit” - Claude is now told to use your account email only to identify you, and not to send it to unrelated services unless you ask - Security: remote file reads, session restore, CLAUDE.md includes, workflow scripts and file uploads now reject Windows NT-namespace \??\ paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vector - Fixed auto mode in very long sessions repeatedly re-checking and denying sandboxed commands’ network access after the conversation had been compacted - Fixed session-scoped permission answers including denies being dropped when answering background subagent tool permission prompts - Fixed a crash when an API response on the non-streaming fallback path typically via third-party gateways contained a thinking block missing its thinking field or a text block missing its text field - Fixed markdown rendering becoming extremely slow for some messages containing unusual Unicode sequences - Fixed SendMessage rejecting a recipient copied from ListAgents when the session name is at the 200-character cap or emoji-heavy - Fixed repository detection mis-reading the host of git remotes with unusual userinfo, producing links and repo-specific behavior for the wrong host - Fixed MCP diagnostics printing resolved secrets: scope-conflict warnings now show the configured ${VAR} form, and connection-failure details show only the server origin - Fixed strictKnownMarketplaces allowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to - Fixed modal text such as the /login OAuth URL losing characters when copied in fullscreen - Fixed a --- horizontal rule in rendered markdown running into the line after it - Fixed consecutive shell commands splitting into multiple “Ran 1 shell command” rows when todo/task updates were interleaved between them - Fixed dialogs like /permissions opened while a shell command was running being dismissed when the command finished - Fixed a queued shell command being sent to the model as plain text after pressing up-arrow to edit the queued input - Fixed queued messages reappearing in the prompt history while still queued, Esc while selecting a queued message no longer interrupts the turn, and mode no longer sticks after a mid-turn submit - Fixed accepting the “Try the new fullscreen renderer?” prompt restarting the session without its permission mode e.g. --dangerously-skip-permissions , tool allow/deny rules, model or effort flags - Fixed /tui dropping launch --allowed-tools / --disallowed-tools rules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can’t carry over - Fixed trust prompts omitting the repository-wide scope warning when the directory was first seen before the repository existed there - Fixed a case where an IDE diff tab closing during a permission re-prompt could answer the new prompt with the previous input - Fixed: files sent to the user during Remote Control sessions hosted by Claude Code Desktop or VS Code now upload, so they open on phone and web instead of showing an empty card - Fixed: after /login while CLAUDE CODE OAUTH TOKEN is set, the stale-token reminder no longer leaks into Claude’s automatically resumed turn — it now appears only to you - Fixed: permission previews now relay only to channel servers admitted by the inbound trust gate, and a server’s explicit permission-capability opt-out is honored - Fixed: credential masking on relayed permission previews can no longer hide commands, paths, or destinations from the approver; oversized private-key blocks now redact under full-strength redaction - Fixed: provider API tokens that mask on permission previews now mask even when directly followed by shell delimiters - Fixed Claude Desktop inter-session messages being silently dropped by the recipient session when cross-session messaging read as disabled, which left the sender’s query “thinking” for many minutes - Remote Control: signing this computer in to a different claude.ai account or organization now stops the running session within seconds and says why, instead of a misleading HTTP 404 hours later - Remote Control sessions started from Claude Code Desktop or VS Code now keep phones and claude.ai/code updated on the session’s permission mode and claude.ai/code on the model as they change - Remote Control: effort picks made on a phone or on claude.ai/code now apply to terminal- and Desktop/VS Code-hosted sessions, and the session publishes its effort level to connected clients SendMessage and ListAgents now say when your account’s session list was too long to check completely, instead of treating unseen sessions as absent- Expired Anthropic profile credential now points you at /login when a claude.ai login would take precedence - Improved the transcript: your own prompts now render markdown highlighted code blocks, inline code, lists the same way replies do - Improved the “API returned an empty or malformed response” error to say what came back content type, body kind, size, request ID and why the original streaming request failed - Improved auto-generated session titles to read as short, specific names e.g. “Login button bug” rather than sentences restating your request e.g. “Fix the login button on mobile” - Reduced the context cost of loading the built-in claude-api skill from ~200k+ tokens to ~25k by loading reference docs on demand /permissions can now be opened while Claude is working — rule changes apply to the rest of the current turn /add-dir