Claude Code 2.1.295 Makes Failing Hooks Block, Adds Terminal Status and Gateway Model Pinning
Anthropic's Claude Code 2.1.295 makes broken guard hooks block the action, adds OSC 7501 terminal status, pins models per gateway upstream, and fixes MCP reconnect loops. Here is what to change this week.
Anthropic shipped Claude Code v2.1.295 on October 8, and the through-line is fail-closed operation: when a guard hook breaks, the action it guards now stops instead of slipping through. The release notes and the project changelog list the change first, and the releases index shows v2.1.295 as the current Latest release, published Oct. 8 at 19:48 UTC from commit 602df92.

Broken hooks now block the action
The headline change is onFailure: "block" for command and HTTP hooks. A hook that cannot start, times out, or exits with an unexpected code now blocks the action instead of letting it through. Before this release, a missing script or a wedged endpoint effectively meant no guard at all; now each hook can opt into the opposite default.
That is the fail-closed switch fleet operators keep asking for, and it belongs in the same runbook as a consent state machine that stops on decline. An illustrative guard:
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "./scripts/guard.sh",
"timeout": 10,
"onFailure": "block"
}
]
}
]
}
}
The key line is the last property on the hook entry. Treat every hook that gates a production lane — secret scanning, allowlist checks, policy verdicts — as a candidate, and test the failure path itself: kill the script, let it time out, confirm the block.
Terminals can show what Claude Code is doing
Version 2.1.295 adds Program Status Protocol support (OSC 7501): terminals that implement it can show whether Claude Code is working, waiting on you, or done. That is status straight from the harness rather than inferred from output, which helps the stall-flag and keepalive practice around parallel and background lanes.
Headless runs get textual equivalents. When a claude -p run stays open after its last turn, Claude Code now writes a line to stderr, when stderr is a terminal, saying what the run is waiting for. A separate fix stops claude -p text output from dropping earlier responses when background work starts another turn; each turn’s response now prints when that turn ends.
The gateway grows real routing controls
The Claude apps gateway changes are the other large block, and they push it further toward being the control plane operators already treat it as:
| Setting | What it does in 2.1.295 |
|---|---|
models list on each upstream |
Only the listed models are sent to that upstream, on failover too; one * in an entry is a wildcard |
timeouts.upstream_ttfb_ms |
Caps how long a stream may take to start on Bedrock, Vertex, Foundry and other cloud upstreams, then fails over or returns a 502 |
forceLoginMethod: "gateway" and forceLoginGatewayUrl |
/login opens on your own gateway, from user settings on machines with no managed settings |
upstream_request_id and the request-id header |
The gateway’s inference audit event carries the upstream’s request ID, and successful responses return a request ID matching Claude Code telemetry |
Two adjacent fixes matter for routed fleets: requests no longer fail across the board on [1m] models when an upstream refuses the context-1m beta (Claude Code resends without it), and token counts behind a gateway on Bedrock now come from the AWS CountTokens API instead of a one-token model request — grant bedrock:CountTokens to use it. Background requests behind a gateway now run on Haiku 4.5 instead of the session’s model, falling back to the session’s model where the gateway does not serve Haiku 4.5.
MCP reconnect loops are gone
Four fixes land on remote MCP reliability, and they retire whole categories of workaround script:
- Remote MCP servers in headless and SDK sessions no longer stay disconnected after an outage longer than 15 seconds, and a server that drops each connection right after it connects now sees reconnects back off, up to 30 seconds.
- A server whose error reply happens to contain a network error name no longer has its connection dropped.
- A server that repeats a pagination cursor is no longer asked for the same page up to 20 times at every connect.
- CSS, JavaScript and XML files returned by MCP tools are saved with their real extensions instead of
.bin, which the Read tool refuses.
claude.ai connectors now negotiate MCP protocol version 2026-07-28 by default on installs that fetch no flags, with MCP_PROTOCOL_NEGOTIATION=legacy to opt out — the stateless-spec shift covered in our MCP 2026 spec explainer. WebSocket MCP servers now close on messages over 16 MiB, matching the limit the other transports already had.
What to do this week
- Upgrade. Native installations update themselves in the background; Homebrew and WinGet do not. Run
brew upgrade claude-code(orclaude-code@latest) orwinget upgrade Anthropic.ClaudeCode, per the Claude Code docs. - Add
onFailure: "block"to every hook that guards a lane, then test the failure path. - Pin a
modelslist on each gateway upstream and settimeouts.upstream_ttfb_msso a stuck stream fails over instead of hanging. - Delete the MCP reconnect-storm scripts; the backoff now lives in the harness.
- Cap unattended retries with
CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS, which limits how long unattended retry mode waits out 429 and 529 errors.
The version lands about 15 hours after v2.1.294, which fixed instruction-written prompt and agent hooks that allowed what they should block, and a day after 2.1.293 made Haiku 5.5 the default Haiku model. Read together, the arc is consistent: hooks that are written wrong get judged correctly, and now hooks that fail are treated as a denial. For fleets running Claude Code unattended, 2.1.295 is the release where the guard rail stops failing open.