← AUTOMATER NEWSROOM

Claude Code 2.1.295 Makes Failing Hooks Block, Adds Terminal Status and Gateway Model Pinning

Anthropic's Claude Code 2.1.295 makes broken guard hooks block the action, adds OSC 7501 terminal status, pins models per gateway upstream, and fixes MCP reconnect loops. Here is what to change this week.

Flow diagram of a Claude Code guard hook: a tool action passes to a command or HTTP hook with onFailure block, runs when the hook exits cleanly, and is blocked when the hook cannot run.Flow diagram of a Claude Code guard hook: a tool action passes to a command or HTTP hook with onFailure block, runs when the hook exits cleanly, and is blocked when the hook cannot run.
How onFailure block works in Claude Code 2.1.295: the action runs only when the guard hook completes cleanly. Illustration by Automater based on Anthropic's v2.1.295 release notes.

Anthropic shipped Claude Code v2.1.295 on October 8, and the through-line is fail-closed operation: when a guard hook breaks, the action it guards now stops instead of slipping through. The release notes and the project changelog list the change first, and the releases index shows v2.1.295 as the current Latest release, published Oct. 8 at 19:48 UTC from commit 602df92.

GitHub release page for anthropics/claude-code v2.1.295 showing the release notes published 08 Oct 19:48, including onFailure block, OSC 7501 status and gateway changes.
The v2.1.295 release page on GitHub, published by Anthropic on Oct. 8, 2026, listing the new onFailure block hook behavior, terminal status support and gateway changes. Source: GitHub (anthropics/claude-code). · Original source

Broken hooks now block the action

The headline change is onFailure: "block" for command and HTTP hooks. A hook that cannot start, times out, or exits with an unexpected code now blocks the action instead of letting it through. Before this release, a missing script or a wedged endpoint effectively meant no guard at all; now each hook can opt into the opposite default.

That is the fail-closed switch fleet operators keep asking for, and it belongs in the same runbook as a consent state machine that stops on decline. An illustrative guard:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "./scripts/guard.sh",
            "timeout": 10,
            "onFailure": "block"
          }
        ]
      }
    ]
  }
}

The key line is the last property on the hook entry. Treat every hook that gates a production lane — secret scanning, allowlist checks, policy verdicts — as a candidate, and test the failure path itself: kill the script, let it time out, confirm the block.

Terminals can show what Claude Code is doing

Version 2.1.295 adds Program Status Protocol support (OSC 7501): terminals that implement it can show whether Claude Code is working, waiting on you, or done. That is status straight from the harness rather than inferred from output, which helps the stall-flag and keepalive practice around parallel and background lanes.

Headless runs get textual equivalents. When a claude -p run stays open after its last turn, Claude Code now writes a line to stderr, when stderr is a terminal, saying what the run is waiting for. A separate fix stops claude -p text output from dropping earlier responses when background work starts another turn; each turn’s response now prints when that turn ends.

The gateway grows real routing controls

The Claude apps gateway changes are the other large block, and they push it further toward being the control plane operators already treat it as:

Setting What it does in 2.1.295
models list on each upstream Only the listed models are sent to that upstream, on failover too; one * in an entry is a wildcard
timeouts.upstream_ttfb_ms Caps how long a stream may take to start on Bedrock, Vertex, Foundry and other cloud upstreams, then fails over or returns a 502
forceLoginMethod: "gateway" and forceLoginGatewayUrl /login opens on your own gateway, from user settings on machines with no managed settings
upstream_request_id and the request-id header The gateway’s inference audit event carries the upstream’s request ID, and successful responses return a request ID matching Claude Code telemetry

Two adjacent fixes matter for routed fleets: requests no longer fail across the board on [1m] models when an upstream refuses the context-1m beta (Claude Code resends without it), and token counts behind a gateway on Bedrock now come from the AWS CountTokens API instead of a one-token model request — grant bedrock:CountTokens to use it. Background requests behind a gateway now run on Haiku 4.5 instead of the session’s model, falling back to the session’s model where the gateway does not serve Haiku 4.5.

Diagram of a Claude apps gateway routing requests to upstreams, where each upstream has its own pinned models allowlist that also applies on failover.Diagram of a Claude apps gateway routing requests to upstreams, where each upstream has its own pinned models allowlist that also applies on failover.
Per-upstream model pinning added to the Claude apps gateway in Claude Code 2.1.295. Illustration by Automater based on Anthropic's changelog.

MCP reconnect loops are gone

Four fixes land on remote MCP reliability, and they retire whole categories of workaround script:

  • Remote MCP servers in headless and SDK sessions no longer stay disconnected after an outage longer than 15 seconds, and a server that drops each connection right after it connects now sees reconnects back off, up to 30 seconds.
  • A server whose error reply happens to contain a network error name no longer has its connection dropped.
  • A server that repeats a pagination cursor is no longer asked for the same page up to 20 times at every connect.
  • CSS, JavaScript and XML files returned by MCP tools are saved with their real extensions instead of .bin, which the Read tool refuses.

claude.ai connectors now negotiate MCP protocol version 2026-07-28 by default on installs that fetch no flags, with MCP_PROTOCOL_NEGOTIATION=legacy to opt out — the stateless-spec shift covered in our MCP 2026 spec explainer. WebSocket MCP servers now close on messages over 16 MiB, matching the limit the other transports already had.

What to do this week

  1. Upgrade. Native installations update themselves in the background; Homebrew and WinGet do not. Run brew upgrade claude-code (or claude-code@latest) or winget upgrade Anthropic.ClaudeCode, per the Claude Code docs.
  2. Add onFailure: "block" to every hook that guards a lane, then test the failure path.
  3. Pin a models list on each gateway upstream and set timeouts.upstream_ttfb_ms so a stuck stream fails over instead of hanging.
  4. Delete the MCP reconnect-storm scripts; the backoff now lives in the harness.
  5. Cap unattended retries with CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS, which limits how long unattended retry mode waits out 429 and 529 errors.

The version lands about 15 hours after v2.1.294, which fixed instruction-written prompt and agent hooks that allowed what they should block, and a day after 2.1.293 made Haiku 5.5 the default Haiku model. Read together, the arc is consistent: hooks that are written wrong get judged correctly, and now hooks that fail are treated as a denial. For fleets running Claude Code unattended, 2.1.295 is the release where the guard rail stops failing open.

Sources

  1. Release v2.1.295 · anthropics/claude-code · GitHub
  2. Claude Code 2.1.295 Makes Failing Hooks Block, Adds Terminal Status and Gateway Model Pinning
  3. Releases · anthropics/claude-code · GitHub
  4. Overview - Claude Code Docs