
Thirteen change-impact and engineering articles shipped this week. Three themes carried it: Anthropic made Sonnet the new default with five breaking API changes (Claude Sonnet 5.5 launched at the same $2/$10 list price as Sonnet 5, but thinking: {"type": "disabled"} now returns 400, forced tool use returns 400, and computer-use tool declarations on Claude API and Google Cloud reject computer_20251124); Anthropic turned the Sonnet 4.5 sunset into a 60-day forced migration (deprecation announced Sept 30, retirement Nov 30, 2026, with the replacement priced 33% lower across input, output, and cache reads); and the Claude API was unavailable for thirty-eight minutes mid-week — Claude.ai, Claude Code, Claude Cowork, and the Claude API all elevated errors between 14:00 and 14:59 UTC on Sept 29, with the status page explicitly warning that "some messages sent between 14:00 and 14:59 UTC may not have been saved." Plus OpenAI shipped GPT-6.1 Sol with a 50% cache-read cut, an Ultrafast tier on GPT-6 Astra, and computer use added to the Agents API on a single Sept 29 changelog; three Claude Code releases in five days (v2.1.284, v2.1.285, v2.1.287) brought Sonnet 5.5 default, allowedProviders managed setting, a non-streaming retry budget fix, the new Claude Mods plugin behavior layer, and 1M context becoming the implicit default for Opus 4.7+ and Fable on four hosting platforms; two OpenAI Codex drops (v0.158.0 and v0.159.0) added MCP OAuth with pre-registered client secrets, an opt-in bearer token on the direct exec-server WebSocket, an opt-in instant_interrupt live-steering primitive, and .aws directories protected by default under sandbox-writable roots; MCP TypeScript SDK v2.2.0/v1.31.0 shipped a credential-confused-deputy guard via required expectedIssuer and an AuthorizationServerMismatchError; and OpenClaw v2026.8.35 (Oct 2) named GPT-6.1 Sol, stopped durable worker retries from freezing hosts, and made plugin settings survive updates.
All items below cite primary sources. Prices, model IDs, version numbers, and changelog text are surfaced verbatim from the documentation they came from. Where a claim is inferred, it is labeled.
claude-sonnet-5-5) as GA on the Claude API, Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry. List pricing is $2 input / $10 output per MTok — unchanged from Sonnet 5. Cache reads remain $0.20/MTok (0.1x multiplier). The headline capability is a 1M-token context window with always-on adaptive thinking steered by the effort parameter. The tokenizer produces the same token counts as Sonnet 5, so the 1M window is genuinely 1M, not the ~770K effective window the Opus-4.7+ tokenizer would impose. The Anthropic platform release notes state explicitly: "Code written for Claude Sonnet 5 can break on Claude Sonnet 5.5 in five ways." Those five breaks: (i) thinking: {"type": "disabled"} returns 400 invalid_request_error; the replacement is thinking: {"type": "between_tools"} (the lowest thinking setting, no beta header needed), and it is rejected at xhigh and max effort and cannot be combined with budget_tokens, display, or block_binding; (ii) tool_choice: {"type": "any"} and {"type": "tool", "name": "..."} both return 400 (tool_choice: type "tool" and "any" are not supported for this model); the fix is to use tool_choice: {"type": "auto"} with strict: true on the tool schema; (iii) thinking blocks are now tied to the model and conversation — Sonnet 5.5 reads blocks from Sonnet 5, Opus 4.8, Haiku 4.5, and earlier, but not from Opus 5, Opus 5.5, Fable, or Mythos; the API also checks whether anything before a Sonnet 5.5 thinking block has changed (system prompt, tools, earlier messages) and enforces that by default for accounts created on or after August 31, 2026 00:00 UTC on Claude API, Bedrock, and Google Cloud, returning 400 on a replayed block after such a change; the opt-in/out is thinking-binding-controls-2026-08-01 with thinking.block_binding.prefix_mismatch_behavior: "drop_block"; (iv) on Claude API and Google Cloud, computer_20251124 is rejected with 'claude-sonnet-5-5' does not support tool types: computer_20251124; only computer_toolset_20260801 is accepted. On Amazon Bedrock, computer_20251124 is still accepted — a multi-cloud agent stack needs both declarations; (v) the advisor tool no longer accepts Opus 4.8, Opus 4.7, or Sonnet 5 as advisors to Sonnet 5.5. A sixth non-400 change: text between tool calls comes back in thinking blocks by default, so streaming UX appears to pause between tool calls until thinking.display is set or between_tools is enabled. The same day, Claude Code v2.1.284 made Sonnet 5.5 the default Sonnet model on the Anthropic API and shipped 60+ additional changes, including dollar amounts in /usage and the status line, /mcp reconnect all, auth: { google: {} } for OTLP telemetry on Google Cloud, private_key_jwt client authentication between the Claude apps gateway and identity providers, and ANTHROPIC_FOUNDRY_RESOURCE validation that closes a host-injection vector on Microsoft Foundry.model in .claude/settings.json or in API request bodies will start talking to Sonnet 5.5 on the next session. Operators with prompt libraries that send thinking: {"type": "disabled"} or rely on forced tool use (tool_choice: "any" / "tool") will start getting 400s. Multi-cloud stacks that route by region (Claude API first, Bedrock on capacity error) need conditional tool declarations because computer_20251124 is accepted on Bedrock and rejected on Claude API / Google Cloud. Builders storing and replaying thinking blocks across users (multi-tenant agent infrastructure, cross-account caches) will see blocks dropped silently under the default drop_block behavior, or 400s on accounts created after Aug 31 when the system prompt changes.thinking: {"type": "disabled"} at high effort or below will fail or behave differently on Sonnet 5.5; switch to {"type": "between_tools"}. Forced tool use on a specific tool returns a different error class. Thinking-block model binding means cached sessions created against Sonnet 5 may not transfer cleanly to Sonnet 5.5; treat warm caches as cold for the first few hours of cutover. On Claude API and Google Cloud, computer_20251124 declarations are rejected; on Bedrock, they are still accepted. Provider-default swaps (e.g., a Vertex AI application letting the Anthropic model ID default to the latest Sonnet GA) will 400 production agent stacks overnight.model: claude-sonnet-5 explicitly in Claude Code settings and API request bodies if you need to stay on Sonnet 5 during migration. Audit prompt libraries for thinking: {"type": "disabled"} and forced-tool-use patterns. Replace disabled with between_tools at high effort or below where the existing prompt relied on disabling thinking. For multi-cloud stacks, include both computer_20251124 and computer_toolset_20260801 in tool declarations, with a guard that only the API/Google-Cloud paths drop computer_20251124. For Gateway operators, verify rate_limits.spend_limit now exposes used_usd, limit_usd, and period; wire those into spend dashboards. Verify claude mcp add now refuses plugins-restricted configurations with a usable message rather than silently accepting them. For Microsoft Foundry deployments, confirm ANTHROPIC_FOUNDRY_RESOURCE is set to a plain resource name before deploying v2.1.284. If you store thinking blocks across users, send the thinking-binding-controls-2026-08-01 beta header with prefix_mismatch_behavior: "drop_block" deliberately and audit the response's input_transformations array.claude-sonnet-4-5-20250929 and set a hard retirement date of November 30, 2026. Requests to the model past that date will fail. The recommended replacement is claude-sonnet-5-5. The deprecations page is explicit: "Requests to models past the retirement date will fail." The platform release note for Sept 30 reads: "We announced the deprecation of the Claude Sonnet 4.5 model (claude-sonnet-4-5-20250929), with retirement on the Claude API scheduled for November 30, 2026. We recommend migrating to Claude Sonnet 5.5." The 60-day window is the deprecation policy floor — the deprecations page states Anthropic provides at least 60 days' notice for publicly released models. The Sonnet 5.5 migration guide has a dedicated "Claude Sonnet 4.5 or earlier" checklist: replace assistant prefills; parse tool call input with a standard JSON parser; on Amazon Bedrock, move computer use from computer_20250124 to computer_20251124; set output_config.effort explicitly; remove any context-window beta header; remove interleaved-thinking-2025-05-14, and replace fine-grained-tool-streaming-2025-05-14 with eager_input_streaming; move output_format to output_config.format. The migration guide also notes that forced tool use (tool_choice: {type: "any" | "tool"}) returns a 400 error on Claude Sonnet 5.5. The pricing delta from the live pricing page (verified 2026-10-01 14:08 UTC): Sonnet 4.5 at $3.00 input / $3.75 cache write 5m / $6.00 cache write 1h / $0.30 cache read / $15.00 output; Sonnet 5.5 at $2.00 / $2.50 / $4.00 / $0.20 / $10.00. The replacement is 33% cheaper on input, output, and cache reads; Batch tier drops from $1.50/$7.50 to $1.00/$5.00 for the same -33% delta.tool_choice: any and tool, and thinking: {"type": "disabled"} at non-between_tools levels. The migration guide has explicit before/after request bodies for each. Bedrock and Vertex AI operators need to confirm partner-side retirement schedules because Anthropic notes that partner-operated platforms set their own retirement dates. The Sonnet 4.5 Bedrock ID is anthropic.claude-sonnet-4-5-20250929-v1:0; on Vertex it is claude-sonnet-4-5@20250929.tool_choice: {type: "tool"} to force invocation will silently break on November 30. Prompt libraries that send thinking: {"type": "disabled"} will start getting 400s. Assistant prefills in the system prompt will return 400. Multi-cloud stacks that route by partner platform need to track partner-side retirement dates separately — a Bedrock or Vertex model may keep working into 2027 after the Anthropic API retirement.claude-sonnet-4-5-20250929 traffic. Audit prompt libraries for the three Sonnet-4.5-isms. Plan the refactor against the migration checklist before the November 30 cutoff. Confirm partner-side retirement dates for Bedrock and Vertex AI before scheduling partner-platform migrations. Inferred: treat the cost figures as Anthropic list prices; not measured on a live trace.claude-sonnet-4-5-20250929 | Deprecated | September 30, 2026 | November 30, 2026; Sonnet 5.5 migration guide; Anthropic pricing page — pricing table cross-checked at 2026-10-01 14:08 UTC.gpt-6.1-sol) is released for "complex coding and professional work at a lower cost than GPT-6 Astra" at $2 input / $0.10 cached input / $2.50 cache write / $10 output per 1M tokens for prompts up to 272K input tokens — same base list price as GPT-6 Sol but cached input drops from $0.20/MTok to $0.10/MTok (a 50% cut on cache reads). Long-context inputs (>272K) are $4 / $0.20 cached / $5 cache write / $15. The model supports multi-agent delegation in beta on the Responses API. (b) GPT-6 Astra Ultrafast mode is added to the Responses API: use gpt-6-astra with service_tier: "ultrafast" to reduce the time between generated output tokens. Available to API customers, subject to rate limits, with global processing and US data residency — EU and other regional inference residency are not supported. (c) Computer use is added to the Agents API: agents can complete tasks in an OpenAI-hosted browser, with website access approvals and sign-in handled by your application. The Agents API was first surfaced as a public beta on Sept 10; this is the capability release that adds a managed browser surface to the beta harness.gpt-6-astra (not GPT-6.1 Sol, GPT-6 Sol, or GPT-6 Luna) — if you want the latency tier on a coding workload, you have to route through Astra, which is the more expensive model ($10/$50 list vs. $2/$10). Multi-agent delegation is in beta on GPT-6.1 Sol — expect API-shape churn; pin a versioned API header. Agents API computer use is in the public-beta Agents API; if you're already on the Responses API directly, this change does not affect your stack.gpt-6-astra with service_tier: "ultrafast" against your latency budget; confirm residency posture before promising the latency tier to EU users. If you're evaluating or already on the Agents API, add computer use to your tool inventory and document the website-access approval and sign-in flow you want your application to enforce. Skip if you are cache-light, residency-bound to EU, or not on the Agents API.platform.claude.com was also degraded. The 15:11 UTC update states explicitly: "Some messages sent between 14:00 and 14:59 UTC may not have been saved." A secondary issue appeared at 14:59 UTC and ran through ~15:30 UTC: single sign-on and "Sign in with Apple" were unavailable, and new chats, voice conversations, Claude Code/Cowork sessions, purchases, and file uploads were blocked for affected users. The full product surface was degraded for 38 minutes of primary impact, with a secondary sign-in tail running another 30 minutes. This is the second Claude API elevated-error incident inside seven days — the Sept 22 incident hit Opus 5, Fable 5/5.1, and Mythos 5/5.1 with elevated errors for ~1h20m.api.anthropic.com calls between 14:00 and 14:59 UTC on Sept 29 — retry-after, 5xx, connection-reset, and timeout errors are the patterns. Audit Claude.ai conversations that were active in the 14:00-14:59 UTC window for missing turns. Track incident cadence and update your "Claude availability" assumption to "good but occasionally unavailable for ~30-90 min monthly" rather than "always on." Confirm whether SSO providers saw the same secondary sign-in tail in your environment./v1/organization/* surfaces no longer require a beta header; (ii) Admin API gains Enterprise analytics, spend limits, and RBAC groups and roles — per-workspace spend limits and a role-based access-control model with named groups and roles are now first-class SDK endpoints; (iii) Admin API gains Plugins and Plugin Marketplaces — the plugin surface (skills, marketplace entries, install policies) is now programmable, including the new ability to remove a plugin's org-wide installation setting; (iv) Admin API gains per-user usage and cost reports — row-level reports that break usage and cost down by individual user, paginated and time-bounded. Plus (v) MCP tunnels beta with a typed Tunnel exposing a read-only transport object and a one-time relay token in the create response (must be captured on first call, not retrievable later). Plus (vi) a refusal stop reason and stop_details on Managed Agents session idle events — refusal becomes a first-class terminal state (stop_reason="refusal") in your retry logic instead of an exception that needs string-matching. Plus (vii) repository error types on Managed Agents session errors — repository errors (file not found, permission denied, branch protected) have dedicated error classes. Two more first-order items in the bug-fix bucket: memory store description, metadata, and archived_at are now required at the type level (a type-level breaking change that fails at SDK construction time); and the credentials loader refuses config files that group or others can write (a security hardening that closes a privilege-escalation path on shared hosts).client.beta.organization.* can now be refactored to the GA client without a beta-version pin. Founders running seat-based Enterprise contracts — the Admin API exposes Enterprise analytics, spend ceilings, and the user-to-group mapping as SDK endpoints rather than Console-only workflows. Platform owners managing multi-tenant or regulated environments — RBAC groups and roles are the first SDK-level primitive for "this user can do X, that user cannot." Compliance and audit teams that need a per-user usage and cost breakdown for chargeback, attribution, or end-user spend visibility — the row-level report is the data source. Operators of managed-agent stacks with persistent memory — the memory-store required-fields fix is a type-level break that needs a one-line update per call site. Multi-tenant teams running an internal MCP bridge — the MCP tunnels beta primitive is the first SDK-level surfacing of Anthropic's managed bridge for connecting a remote MCP server to a Claude API session without exposing the MCP server to the public internet.beta namespace from client.beta.organization.* calls, and adopting the GA client. Inferred: the cost of the migration is proportional to the size of the call-site surface; treat as inferred.description, metadata, or archived_at will now fail at SDK construction time. Refusal handling that string-matches on stop_reason needs to be updated to handle the new structured stop_details payload. Repository error handlers that string-match on Managed Agents session errors should adopt the new dedicated error classes. Config files on shared hosts with umask 002 defaults may fail the load and surface a clear error rather than silently loading a config that a teammate could have edited.mypy on your integration code; the new memory-store required fields will surface as type errors at the call site. Drop the beta namespace from client.beta.organization.* calls and adopt the GA client. Wire the Admin API Enterprise analytics, RBAC groups and roles, and per-user usage reports into your internal tooling if you run seat-based contracts. Audit your Claude Code plugin manifests against the new programmable Plugin Marketplace surface. For Managed Agents, replace string-matching refusal and repository error handlers with the new typed stop reasons and error classes. Inferred: cross-check the type-level break against your test suite; treat as inferred.allowedProviders managed setting, non-streaming retry budget fix, and URL-password redaction fix(i) allowedProviders managed setting — the first managed-settings gate that constrains the provider set itself rather than model IDs. Accepted values: Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway. A machine set to Bedrock + Vertex AI cannot silently route to the Anthropic API; a machine set to a single custom endpoint cannot be redirected by a plugin or marketplace that prefers the Anthropic API by default. (ii) Non-streaming retry budget fix — pre-fix, a single streaming failure could trigger up to 21 retries of the same request, each one billed as input tokens; post-fix, the non-streaming fallback shares the request's retry budget instead of getting a fresh set of retries. (iii) CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable — caps re-sends of a non-streaming fallback request that timed out. (iv) URL-password redaction fix — the redactor was missing URLs whose password delimiter was the literal @ character (or its percent-encoded %40 form), which leaked password characters into redacted logs and transcripts. Three more hardening items in the same release: sandbox policy is protected from project-level overrides (project settings can no longer widen an admin-required sandbox, replace the managed deny-list proxy, extend a strict allowlist, or reopen managed read-denies); plugin pre-approval gate tightened so only plugins from an official Anthropic source or one vouched for in managed settings keep their allowed-tools pre-approval under allowManagedPermissionRulesOnly; Bedrock and Vertex AI startup model checks now send the same User-Agent, x-app, and session ID headers as regular Claude Code requests.allowedProviders is the managed-settings entry that closes the audit gap. Cost-conscious operators running long-context agents where one turn's input can be hundreds of thousands of tokens — the non-streaming retry-budget fix is the cost-control change. Builders using Claude Code in environments that export transcripts to compliance archives — the URL-password redaction fix is a real credential-leakage fix that should prompt a re-evaluation of transcripts produced before v2.1.285 if any URL contained embedded credentials with @ in the password. Self-hosted runner operators and platform teams running MDM-pinned sandboxes — the project-settings hardening closes the last known path where a repo-level configuration could undermine an MDM-pinned sandbox.CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES adds an explicit cap for the non-streaming retry path itself. Inferred: the ~4.2M input-token figure is derived math from a 200K-context turn × 21 retries; treat as inferred.@ in the password may need to be re-evaluated and re-redacted. A machine set to allowedProviders: ["bedrock", "vertex"] will refuse Anthropic-API calls — a valid hardening but a one-line config change away from a hard error if your routing assumed fallback. CLAUDE_CODE_DISABLE_WEB_FETCH is a new opt-in environment variable that turns off the WebFetch tool; leaving the env var unset preserves existing behavior.allowedProviders alongside any model-ID pin and verify with claude doctor or equivalent. If you operate long-context agents, validate the new retry-budget behavior against your existing retry instrumentation. Re-evaluate transcripts produced before v2.1.285 that contain URLs with embedded credentials and @ in the password — re-redact and re-export where necessary. Tune CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES to a value that bounds the worst case without flapping on legitimate timeout. If you run a managed fleet with a curated sandbox policy, verify the new project-settings hardening has not broken a path you depend on.(i) Claude Mods — a new plugin behavior layer that lets plugins modify deeper Claude Code behavior than the existing plugin slots exposed (slash commands, MCP servers, skills, hooks, permission rules). The first shipped Mod is "You should know", a built-in side agent that watches the main agent's run and flags things the user or Claude might miss; activation is /plugin enable cc-plugin-you-should-know@builtin for first-party sessions with telemetry on. (ii) 1M context default for Opus 4.7+ and Fable — on Amazon Bedrock, Google Cloud Vertex AI, Microsoft Foundry, and the Claude apps gateway, these two model families now use 1M context by default with no [1m] suffix required. The opt-out is CLAUDE_CODE_DISABLE_1M_CONTEXT=1 to keep the 200K window. (iii) Multi-cloud auth-header hardening — under CLAUDE_CODE_SKIP_*_AUTH, Bedrock, Vertex, and Mantle startup model checks were sending a different Authorization header than real requests when ANTHROPIC_CUSTOM_HEADERS repeated it. The fix makes startup checks send the same header shape as production traffic. A complementary change: the Claude apps gateway's error when Amazon Bedrock rejects a model ID now names the ID that was sent. A fourth smaller change: MCP server alwaysLoad: false now defers all of that server's tools behind tool search — pre-v2.1.287, an MCP server flagged alwaysLoad: false would still register some of its tools eagerly; post-fix, every tool behind such a server is deferred and only loaded when the model calls tool_search.Authorization header. Builder audience for the MCP alwaysLoad: false change: every team running dozens of MCP servers in a single session.CLAUDE_CODE_DISABLE_1M_CONTEXT=1 before upgrading. Custom IdP / gateway / SSO policies on Bedrock and Vertex that previously passed the startup check but failed the first real request will now pass the startup check consistently. The MCP alwaysLoad: false semantic change is silent — clients that previously relied on a false server's tools being eagerly registered will see them absent from the tool prompt until the model calls tool_search. The bundled plugin-creator skill that was in the v0.159.0 Codex release is unrelated here, but teams with onboarding docs that reference the Anthropic plugin-creator skill should update them.CLAUDE_CODE_DISABLE_1M_CONTEXT=1 in your managed environment before upgrading. If you already ship a Claude Code plugin, evaluate whether your plugin's value lives in a Mod slot before v2.1.287 becomes table-stakes. For Bedrock and Vertex AI operators running a custom auth layer, verify the model-availability signal that Claude Code's startup check produces is now consistent with real-request behavior. For deployments running dozens of MCP servers in a single session, the alwaysLoad: false change finally makes per-server lazy loading work — verify the tool search path is wired up.instant_interrupt live-steering, and .aws default protectionrust-v0.158.0 (Sept 28) lands five first-class features: (i) MCP servers with pre-registered OAuth client secrets — codex mcp add --oauth-client-secret connects to MCP servers that require a registered application identity (the gap between a registered OAuth application at an upstream IdP and Codex MCP integration is now closed); (ii) bearer-token security on direct exec-server WebSocket connections — opt-in via codex-websocket-auth; pre-v0.158.0, the exec-server WebSocket accepted connections without authentication, and the bearer-token opt-in is the first default-off mechanism that closes the unauthenticated path for shared-host deployments; (iii) TUI copy-on-select and right-click paste with Markdown preservation; (iv) image generation and editing can request transparent backgrounds explicitly; (v) terminal input approval is enabled by default for commands running with elevated permissions — pre-v0.158.0, the implicit behavior was "no prompt for elevated commands"; v0.158.0 flips the default to require an explicit approval step, paired with a tightening on runtime-only grants that reduces spurious reviews. rust-v0.159.0 (Sept 29) adds (i) opt-in instant_interrupt — the setting adds code-mode yielding on new user input; when a user sends a message while a Codex turn is mid-flight, Codex preempts the in-progress model response (or running code-mode call) instead of queueing the message until the current step finishes. The change is opt-in, behind a flag, not default. (ii) App-server thread-history pagination — app-server clients can now anchor thread-history pagination to a specific item. (iii) .aws directories protected by default under sandbox-writable roots — closes an obvious credential-exfiltration path through writable-root whitelists. (iv) macOS TLS trust evaluation in network-enabled Seatbelt profiles and remote environments requiring proxy access. (v) Native Mermaid rendering expands — more flowchart edges, labels, and node groups render in the TUI. (vi) Windows launches no longer spawn stray console windows for MCP servers, code-mode hosts, and piped commands. The release also removes the bundled plugin-creator skill and the tui.prompt_suggestions setting (cleanup of two features that were used less after the v0.158.0 lifecycle changes).v0.158.0: teams that already maintain a registered OAuth application at an upstream IdP (Auth0, Okta, Azure AD, WorkOS, internal IdP) and want scoped per-user MCP access; multi-tenant Codex deployments that should be running the bearer-token opt-in; unattended Codex installs that rely on elevated-permission commands being approved without an interactive prompt. v0.159.0: every long-running-agent operator (the instant_interrupt change is the meaningful one for autonomous workers, multi-step refactors, and overnight batch runs); every team running Codex against an AWS-backed stack (the .aws default protection closes a real credential-exfiltration path); every Windows-onboarding path (the embedded-mode fallback fixes a launch path that previously spawned stray console windows)..aws default protection is a security fix, not a pricing change. The preemption cost under instant_interrupt is unstated — the changelog does not document whether the preempted partial response is billed, partially billed, or discarded. For interactive use this is irrelevant; for batched autonomous work where you sometimes inject steering messages mid-run, expect to test your provider bill before assuming zero cost for preempted tokens. Inferred: the preemption-cost question is unverified; treat as inferred..aws default protection only fires under "writable roots" — if your sandbox config does not list your working tree as a writable root, this change does not affect you. The bundled plugin-creator skill removal means onboarding docs that reference it need an update. The auto follow-up prompt suggestions removal is silent — anyone who scripted their workflow to skip the suggestions UI needs to remove that step.instant_interrupt on or leave it off; document the choice in your internal agent config. If you run Codex on Windows or in restricted launchers, validate the embedded-mode fallback against your launcher policy before promoting the version. Update internal onboarding docs to drop references to the bundled plugin-creator skill and tui.prompt_suggestions. Re-run your prompt-cache invalidation tests — the preemption path touches executor / TUI credential-boundary preservation..aws protection); PR #47601 and PR #47648 (bearer token); PR #47891 (MCP OAuth client secret).expectedIssuer, AuthorizationServerMismatchError, and stored OAuth tokens carry an issuer fieldv1.31.0 lands on the legacy v1.x line at 18:52:02 UTC, with two commits: a feature landing that binds stored OAuth credentials to the authorization server that issued them (#2888), and a version-bump chore (#2890). v2.2.0 lands at 19:24:07 UTC across the modular @modelcontextprotocol/* packages (client, server, core, server-legacy, codemod), with per-package releases timestamped 19:07:43-19:07:55 UTC; node, express, hono, fastify packages unchanged. The substantive change is OAuth issuer binding. Per the v2.2.0 release notes: "Constructing ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider or CrossAppAccessProvider without expectedIssuer is deprecated and logs a warning. Set it to the issuer of the authorization server the credentials were registered with. (#2887)" A future release is expected to make the parameter mandatory. v1.31.0 carries the same shape. fetchToken() checks which authorization server the client information belongs to. It throws AuthorizationServerMismatchError before sending anything when the provider's client information is bound to a different authorization server. (#2887)" This is a credential-confused-deputy guard: if a client object bound to authorization server A is asked to fetch a token from authorization server B, the SDK now refuses before any network call. Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it. List calls auto-walk nextCursor. listTools(), listPrompts(), listResources() and listResourceTemplates() called without a cursor now follow nextCursor until the server stops sending one. listMaxPages still caps the walk. (#2886)" This is a behaviour change for callers that previously paged explicitly. Two operational fixes worth surfacing: a CommonJS TypeScript regression in 2.1.0 is fixed (the jose types are inlined into the declaration files), and the v1-to-v2 codemod keeps a file's leading comment block and directives above the rewritten imports.ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, or CrossAppAccessProvider — the change is a parameter addition now and a mandatory parameter in a future v2.x release. Every team that relies on default storage schemas with strict validators (Zod, JSON-Schema) — an unknown-field rejection could surface as a write failure on the next token refresh. Every team with cursorless list*() calls — the list-auto-walk is silent and will return more data per call subject to listMaxPages. Every team planning a v1→v2 migration — v1.31.0 is the natural pivot point.issuer, passing expectedIssuer to provider constructors, and reviewing list-cursor usage. Inferred: the migration cost is proportional to the call-site surface and the storage-schema strictness; treat as inferred.listMaxPages cap — for servers with thousands of items, this could increase the per-call payload substantially. The CommonJS TypeScript regression fix unblocks CommonJS consumers on the 2.1.0 line.ClientCredentialsProvider, PrivateKeyJwtProvider, StaticPrivateKeyJwtProvider, and CrossAppAccessProvider constructions. Pass expectedIssuer explicitly to silence the deprecation warning now and avoid the future mandatory change. Update OAuth tokens and client information schemas to allow the optional issuer field; verify both writes and reads round-trip the field. Audit listTools(), listPrompts(), listResources(), listResourceTemplates() for cursorless usage; for servers with thousands of items, set listMaxPages explicitly to bound auto-walk payload. Start v1→v2 migration from v1.31.0 baseline. Use the v1-to-v2 codemod to migrate imports; verify leading comment blocks survive the rewrite. Inferred: the migration cost figures are not measured; treat as inferred.(i) GPT-6.1 Sol support — the integration covers all five surfaces an OpenAI model lands on inside OpenClaw: routing, discovery, reasoning, the harness, and the Reef guard-model boundary. If you run OpenClaw with OpenAI as your provider, GPT-6.1 Sol becomes selectable on v2026.8.35 without additional configuration. (ii) Durable worker retries stop freezing hosts — pre-fix, a durable worker that retried a long-running operation could hold the host's resources open until the retry budget was exhausted; on a small host, a single stuck retry could pin a CPU, a database connection, or a socket and degrade every other agent on the same machine. Post-fix, the retry path yields the host. (iii) Plugin settings survive updates and migrations — a plugin whose settings schema did not match the new gateway version previously had its settings silently dropped during recovery or migration; post-fix, the settings are preserved and the inventory record is retained. (iv) Failed requests can no longer replace earlier questions with a steer — pre-fix, a turn that failed could overwrite the prior user question with a steering message in the next turn, hiding the original ask. (v) Cron output recovery is uncapped and complete — pre-fix, a cron reply longer than the buffer cap was being truncated, and a CLI subagent's full answer could be cut off in the parent. Post-fix, cron output is recovered at full size, and the CLI subagent answer is delivered whole. (vi) Session, MCP, and tools hardening — rejects malformed session targets (defends against session ID forgery), preserves spawned working directories, projects deeply nested MCP results safely (path-traversal-shape bug), keeps remote MCP bundles working in native sessions that broke in a prior release. (vii) Channels: Gmail, IMAP, Matrix, Telegram — Gmail transient binds recovered, IMAP backlog processing bounded, Matrix direct mappings restored, Telegram progress restored when hooks suppress previews. (viii) Secrets, sandboxing, runtime, and WebChat — secret entry kinds retained during value rotation, admitted secret-egress execution restored, read-only copied skills repaired without escaping their confined roots (sandbox escape path closed), redaction stalls prevented, stale thinking-catalog waits cancelled, required Visual C++ runtime installed after a managed llama.cpp launch failure./.vol/ access paths must be re-scoped (also covered in the prior roundup).Sept 28 was a single coordinated release day: Anthropic released Claude Sonnet 5.5, the Sonnet 5.5 prompt-engineering reference page, the Sonnet 5.5 system-prompts page, and Claude Code v2.1.284 (which made Sonnet 5.5 the default Sonnet model) within the same 24-hour window. The Anthropic platform release notes and the Anthropic pricing page both reflect the new model on the same day. For teams that have not pinned a model, the cutover is silent — every Anthropic API request that does not specify a model is now talking to Sonnet 5.5. The cache economics story is upside-down: list price is unchanged, but the relative cost of Sonnet 5.5 versus Fable 5.1 is now wider than it was a month ago because Fable 5.1 dropped its cache-read multiplier to 0.025x ($0.25/MTok) on September 1, 2026. The breaking-change list is real: five of the changes return 400, and they affect the request shapes that the typical Anthropic SDK wrapper or eval harness relies on. The migration window is open, and Sonnet 4.5's November 30 retirement is on the same page.
Between Sept 28 and Oct 1, Claude Code shipped v2.1.284, v2.1.285, v2.1.286, and v2.1.287 (v2.1.286 was a small in-between release with no dedicated coverage). The pattern is now: a model or capability drop (v2.1.284 Sonnet 5.5 default), a hardening pass (v2.1.285 allowedProviders and retry budget), a same-week capability drop (v2.1.287 Claude Mods and 1M context default). v2.1.287 ships a 40+ bug-fix sweep alongside the capability drop — including the multi-cloud auth-header hardening, the MCP alwaysLoad: false semantic change, and the new CLAUDE_CODE_SUBAGENT_MODEL_FORCE environment variable. If you are managing a Claude Code fleet, the operational question is not whether to upgrade but how to keep the upgrade cadence sustainable — and which subset of releases you put behind a soak test before promoting to a fleet.
NOVELTY_LOW source-change items and surfaces them when they ship stable.claude-sonnet-4-5-20250929 traffic in the first week of October.expectedIssuer mandatory.instant_interrupt is opt-in; expect the next drop to expand or stabilize the preemption path.Originally published: 2026-10-03 02:00 Berlin / 2026-10-03 00:00 UTC Last verified: 2026-10-03 00:00 UTC No corrections at this time.
— Mr. Technology