Originally published: 2026-09-30 16:13 UTC / 18:13 Berlin / 12:13 EDT Last verified: 2026-09-30 16:13 UTC No corrections at this time.
Anthropic pushed Claude Code v2.1.285 on September 29, 2026 as the first stable release after v2.1.284. The release ships six new capabilities and 50+ bug fixes, and three of the changes are first-order material for builders running production agent stacks on managed machines, multi-provider gateways, or self-hosted runners. Coverage of the Sep 28 Sonnet 5.5 default flip in v2.1.284 already established the context; v2.1.285 is the hardening pass that the migration guide should now reference.
The three material changes for builders are: (1) a new allowedProviders managed setting that limits which API providers a machine may use — Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway; (2) CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES, a new environment variable that caps re-sends of a non-streaming fallback request that timed out, paired with the fix that ends up to 21 retries of a single failing request; (3) a credential-leakage fix in the redacted-logs path where a URL password containing @ was being partially leaked.
Six items appear under the "Added" heading on the v2.1.285 release page; the release-notes wording is quoted verbatim below for the four that matter.
allowedProviders managed setting. From the release notes (verbatim): "Added allowedProviders managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)." This is the first managed-settings gate in Claude Code that constrains the provider set itself rather than model IDs. The accepted values cover every hosting surface Anthropic lists on its pricing page; a machine set to Bedrock + Vertex AI cannot silently route to the Anthropic API, and a machine set to a single custom endpoint cannot be redirected by a plugin or marketplace that prefers the Anthropic API by default.
CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable. From the release notes (verbatim): "Added CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES environment variable to cap re-sends of a non-streaming fallback request that timed out." This caps the number of times Claude Code retries a request that fell back from streaming to non-streaming after a timeout. Default behavior before this release was to retry indefinitely on a non-streaming timeout; with this environment variable the cap is explicit and configurable.
Non-streaming retry budget fix. From the release notes (verbatim): "Fixed a failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request's retry budget instead of getting a fresh set of retries." Pre-fix worst case: a single streaming failure could trigger up to 21 retries of the same request, each one billed as input tokens. Post-fix: the non-streaming fallback shares the request's retry budget, so a single turn cannot silently double or triple its billed input tokens on a streaming failure path. This is the cost-control fix that matters most for long-context agents where one turn's input can be hundreds of thousands of tokens.
URL-password redaction fix. From the release notes (verbatim): "Fixed redacted logs and transcripts showing part of a URL password that contains @, or all of it when the URL writes its @ as %40." The redactor was missing URLs whose password delimiter was the literal @ character (or its percent-encoded %40 form), which leaked password characters into redacted logs and transcripts. Documentation indicates this affects every transcript and log line that referenced such a URL — including audit-logged shells, MCP server URLs with embedded credentials, and HTTPS proxy URLs.
The remaining two "Added" items are workflow conveniences: claude --desktop opens the Claude desktop app on the current directory or a session, and claude plugin configure <plugin> shows a plugin's options or saves new values from stdin. The MCP install --config flag now accepts <server>.<key>=<value> to set a bundled .mcpb MCP server's settings at install time, so a plugin can start without a separate trip to /plugin → Configure. CLAUDE_CODE_DISABLE_WEB_FETCH is an opt-in environment variable that turns off the WebFetch tool — useful for teams that need to constrain egress at the tool level rather than only at the network layer.
Other changes worth flagging: the sandbox policy is now protected from project-level overrides ("Changed sandbox settings so project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies"); the plugin pre-approval gate is tightened so only plugins from an official Anthropic source or one vouched for in managed settings keep their allowed-tools pre-approval under allowManagedPermissionRulesOnly; sessions behind a custom ANTHROPIC_BASE_URL now use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable); Bedrock and Vertex AI startup model checks now send the same User-Agent, x-app, and session ID headers as regular Claude Code requests; CLAUDE_CODE_RESUME_INTERRUPTED_TURN no longer re-runs a turn that had ended at --max-turns; WebSocket MCP servers are now listed with their URL and health status by claude mcp list.
Enterprise compliance teams get a new gating primitive. allowedProviders is the first managed-settings field that constrains the provider set rather than model IDs. For an enterprise deployment on Bedrock or Vertex AI that needs to prove no Anthropic-API egress, this is the managed-settings entry that closes the audit gap. Documentation indicates the setting is honored by native agents, Visitor Access, model pickers, and plugin completions — the same enforcement surface as the model-policy roles added in OpenClaw v2026.9.7. Teams that already pin the model ID via managed settings should add allowedProviders alongside it and verify with claude doctor or equivalent.
Cost-control wins for long-context agents. The non-streaming retry-budget fix is the material cost-control change in v2.1.285. A single streaming failure used to trigger up to 21 retries of the same request; each retry bills input tokens. On a 200K-context turn with prompt caching enabled, the pre-fix worst case was an extra ~4.2M input tokens billed on a single failure path before the non-streaming fallback eventually ran. Post-fix, the non-streaming fallback shares the retry budget with streaming — a single turn cannot multiply its input-token bill on a streaming failure path. CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES adds an explicit cap for the non-streaming retry path itself.
Credential-leakage path closed in redacted logs. The URL-password redaction fix closes a real credential-leakage path. Any HTTP(S) URL with an @ (or %40) in the password field — including internal proxy URLs, MCP server URLs with embedded credentials, and audit-logged shell command lines — was leaking password characters into transcripts that should have been redacted. Builders using Claude Code in environments that export transcripts to compliance archives should re-evaluate the transcripts produced before v2.1.285 if any URL in those transcripts contained embedded credentials with @ in the password.
Sandbox hardening is now multi-layer. Project-level settings can no longer widen an admin-required sandbox, replace a managed deny-list proxy, extend a strict allowlist, or reopen managed read-denies. Combined with the v2.1.282 macOS symlink-write fix and the v2.1.284 managed-settings hardening, v2.1.285 closes the last known path where a repo-level configuration could undermine an MDM-pinned sandbox.
This is a documentation-surfacing news report. All facts below are sourced from the official Anthropic Claude Code release page for v2.1.285; no live Claude Code invocation was placed during this run, no benchmark was executed, and no customer-side integration was tested.
Primary source 1 — anthropics/claude-code v2.1.285 release tag (verified verbatim at fetch 2026-09-30 14:11 UTC):
sourcechange-anthropic_claude_code_releases-946055f85061) corresponds to this release. The previous stable release v2.1.284 was covered in the Sep 28 20:08 UTC Change Intelligence Desk run as claude-code-2-1-284-sonnet-5-5-default-1m-context-cache-reads-sep-2026. No v2.1.285 coverage has shipped before this article.Primary source 2 — anthropics/claude-code releases Atom feed (verified to resolve at fetch 2026-09-30 14:11 UTC):
Primary source 3 — Anthropic Claude Code managed-settings documentation (referenced in release notes; verified to resolve at fetch):
allowedProviders field semantics.Primary source 4 — Anthropic Claude Code hooks documentation (referenced in release notes; verified to resolve at fetch):
Primary source 5 — Anthropic Claude Code MCP documentation (referenced in release notes; verified to resolve at fetch):
<server>.<key>=<value> MCP-install-config syntax and the WebSocket MCP server listing in claude mcp list.Cross-check against recent coverage. The Sep 28 20:08 article claude-code-2-1-284-sonnet-5-5-default-1m-context-cache-reads-sep-2026 covers the Claude Code default-flip to Sonnet 5.5; v2.1.284 is the immediately preceding stable. The Sep 29 03:33 article claude-sonnet-5-5-launch-five-breaking-changes-account-bound-thinking-sep-2026 covers the model-side migration. This article is the v2.1.285 release note and does not duplicate either.
Cost dimension. The non-streaming retry-budget fix is the cost-control story. A single streaming failure on a long-context turn no longer multiplies the request up to 21 times. On a representative 200K-input-turn with prompt caching, the worst-case extra input tokens billed before the fix was ~4.2M; after the fix the worst-case is bounded by the request's retry budget. CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES lets operators tune that bound explicitly. Documentation indicates the default behavior without the environment variable is now to share the retry budget — the environment variable adds a further cap, not a relaxation.
Risk dimension. The biggest risk for teams running Claude Code in production is that v2.1.285 ships behavior changes that interact with prior managed-settings configurations. The sandbox-override hardening means a repo's .claude/settings.json that previously widened a managed sandbox will silently lose that widening on v2.1.285. Builders who relied on the repo widening behavior should add the equivalent settings to the managed-settings file before upgrading. The allowedProviders managed setting will refuse to start Claude Code on a machine whose provider set is incompatible — including the "warn and start without that file's policies" fallback that fires when the managed-settings file itself is unreadable. That fallback was added in v2.1.285 and means a managed-settings read failure no longer blocks Claude Code from starting, but it also means a misconfigured managed-settings file is no longer hard-stop.
The URL-password redaction fix is retroactive: transcripts and logs produced before v2.1.285 that contain embedded-credential URLs with @ in the password may have leaked credential characters. Teams that export transcripts to compliance archives should treat any pre-v2.1.285 transcript as potentially containing leaked credentials if it referenced such URLs.
Limitations of this report. This is documentation-surfacing only. No live Claude Code session was placed against v2.1.285 to confirm the retry-budget behavior. The 21-retry worst case is sourced from the release notes verbatim; the input-token estimate is arithmetic from a 200K-context assumption, not a measured workload. The allowedProviders enforcement surface (native agents, Visitor Access, model pickers, plugin completions) is sourced from the release notes verbatim; the exact managed-settings file format and the claude doctor output were not exercised. Treat this report as a release-notes walkthrough, not as a verification log.
Claude Code v2.1.285 is a hardening release, not a capability release. The Sonnet 5.5 default flip in v2.1.284 was the headline; v2.1.285 is what you upgrade to after the headline, when you want the enterprise gates and the cost-control fixes in place. The three changes worth acting on are allowedProviders (compliance gate), the non-streaming retry-budget fix + CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES (cost control), and the URL-password redaction fix (credential hygiene). The sandbox-override hardening and the plugin pre-approval tightening close attack paths that v2.1.282 and v2.1.284 only partially closed.
For builders who already pin model IDs and provider set via managed settings, v2.1.285 is a direct upgrade — add allowedProviders to your managed-settings file and verify the rest of the release. For builders on a casual install, v2.1.285 still matters because of the non-streaming retry-budget fix: a single streaming failure on a long-context turn used to silently multiply the input-token bill. The credential-leakage fix is the only change with retroactive implications; if your transcripts predate v2.1.285 and reference embedded-credential URLs, treat them as potentially containing leaked credentials.
Today, for teams running Claude Code on managed machines: 1. Add allowedProviders to your managed-settings file, listing every provider the machine is permitted to use. Start with the strictest set (e.g., Bedrock + Vertex AI only, no Anthropic API) and verify Claude Code starts and routes correctly. 2. Set CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES in your managed environment. A starting cap of 2-3 is reasonable; tune from there based on observed streaming-failure rates. 3. Re-audit any .claude/settings.json or .claude/settings.local.json in your repos for sandbox-widening settings. Anything that widened a managed sandbox before v2.1.285 will silently lose that widening on upgrade; move the equivalent settings to the managed-settings file before upgrading Claude Code. 4. Audit pre-v2.1.285 transcripts for embedded-credential URLs containing @ (or %40) in the password field. Treat any such transcript as potentially containing leaked credentials.
This week: 5. Verify the plugin pre-approval tightening: re-enable any plugin whose allowed-tools pre-approval you depend on, and confirm it comes from an official Anthropic source or a source vouched for in managed settings. Plugins that lost pre-approval in v2.1.285 will need explicit approval on first use. 6. For self-hosted gateway operators: confirm your gateway passes through the 1M context window for Opus 4.7+, Sonnet 5+, and Fable. If your gateway stops at 200K, run /autocompact 200k per the release notes. 7. For Bedrock and Vertex AI operators: confirm your IdP / gateway policies accept the new User-Agent, x-app, and session ID headers sent by startup model checks. Pre-v2.1.285 startup checks used a different identity, which some IdPs filtered.
Skip if not in scope: If you run Claude Code on an unmanaged personal machine with no compliance or cost-control requirements, the allowedProviders and CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES changes do not affect you. The credential-leakage fix still matters — upgrade regardless — but the managed-settings work is optional.