← Back to Payloads
AI News2026-10-01

Claude Code v2.1.287 (Oct 1): Claude Mods Land as a New Plugin Behavior Layer, 1M Context Becomes the Default for Opus 4.7+ and Fable on Bedrock, Vertex, Foundry, and the Apps Gateway, and a 40-Item Security Sweep

Claude Code v2.1.287 (Oct 1) ships Claude Mods as a new plugin behavior layer with a first-party 'You should know' side-agent Mod, makes 1M context the default for Opus 4.7+ and Fable on Bedrock/Vertex/Foundry/apps gateway, hardens Bedrock/Vertex/Mantle auth-header paths under CLAUDE_CODE_SKIP_*_AUTH, and changes MCP `alwaysLoad: false` to defer every tool behind tool search. 100+ items including a 40-fix bug sweep.

Claude Code v2.1.287 (Oct 1): Claude Mods Land as a New Plugin Behavior Layer, 1M Context Becomes the Default for Opus 4.7+ and Fable on Bedrock, Vertex, Foundry, and the Apps Gateway, and a 40-Item Security Sweep

Originally published: 2026-10-01 22:08 UTC / 2026-10-02 00:08 Berlin / 2026-10-01 18:08 EDT Last verified: 2026-10-01 22:08 UTC No corrections at this time.

What happened

Anthropic pushed Claude Code v2.1.287 on October 1, 2026 as the first stable release after v2.1.286. The release ships two new feature families, four new environment variables and managed-settings hooks, and 40+ bug fixes — and three of the changes are first-order material for builders running production agent stacks on multi-provider gateways, managed enterprise machines, or self-hosted runners. Coverage of the Sep 28 Sonnet 5.5 default flip in v2.1.284 and the Sep 29 allowedProviders managed setting in v2.1.285 established the prior context; v2.1.287 is the capability release that lands alongside the hardening pass.

The three material changes for builders are: (1) Claude Mods, a new plugin behavior layer that lets plugins modify deeper Claude Code behavior than the existing plugin slots exposed; the first shipped Mod is "You should know", a built-in side agent that watches the main agent's run and flags things the user or Claude might miss; (2) a 1M-token context window becomes the default for Opus 4.7+ and Fable on Amazon Bedrock, Google Cloud Vertex AI, Microsoft Foundry, and the Claude apps gateway — no [1m] suffix required, with CLAUDE_CODE_DISABLE_1M_CONTEXT=1 to keep the 200K window; (3) a multi-cloud auth-header hardening under CLAUDE_CODE_SKIP_*_AUTH that closes a path where Bedrock, Vertex, and Mantle startup model checks were sending a different Authorization header than real requests when ANTHROPIC_CUSTOM_HEADERS repeated it.

What actually changed

The release notes for v2.1.287 contain 100+ items; the four that matter for builders are quoted verbatim.

1. Claude Mods. From the release notes (verbatim): "Added Claude Mods: plugins may now modify deeper behavior." The follow-up line describes the first shipped Mod: "Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin (for first-party sessions with telemetry on)." This is a new plugin slot. Pre-v2.1.287, a Claude Code plugin could extend slash commands, add MCP servers, supply skills, configure hooks, and adjust a known set of permission rules — but could not reach the deeper behaviors that affect how the model itself behaves in a turn. Mods open that surface. The first-party Mod in this release is itself a small model that runs alongside the main agent and raises flags the main agent missed; the activation gate is a regular plugin enable command plus an opt-in telemetry flag, which is the Anthropic-side acceptance criterion for using the built-in Mod.

2. 1M context default for Opus 4.7+ and Fable. From the release notes (verbatim): "Changed Opus 4.7+ and Fable to use a 1M context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway, with no [1m] suffix (CLAUDE_CODE_DISABLE_1M_CONTEXT=1 keeps 200K)." Documentation indicates the previous default required a [1m] suffix or an explicit setting; v2.1.287 makes 1M the implicit default for these two model families on the four named platforms. Builders who depended on the 200K default — typically for memory-constrained self-hosted runners, cost-controlled CI agents, or eval harnesses that compare model populations at a fixed context size — must set CLAUDE_CODE_DISABLE_1M_CONTEXT=1 in their managed environment before upgrading to preserve the previous behavior.

3. Multi-cloud auth-header hardening. From the release notes (verbatim): "Bedrock, Vertex, Mantle: Fixed model availability checks under CLAUDE_CODE_SKIP_*_AUTH sending a different Authorization header than real requests when ANTHROPIC_CUSTOM_HEADERS repeats it." Pre-fix: the startup model-check on these three providers was reading ANTHROPIC_CUSTOM_HEADERS and producing a header set that disagreed with what subsequent real requests sent, which means a custom IdP / gateway / SSO policy that filters on the Authorization header could pass the startup check but fail the first real request. Post-fix: startup checks send the same header shape as production traffic. The Claude apps gateway also got a complementary change ("Improved the Claude apps gateway's error when Amazon Bedrock rejects a model ID: developers now see which model is unavailable, and the gateway log names the ID that was sent") so the failure mode that the auth-header fix prevents is now also more visible when it does fire.

4. MCP server alwaysLoad: false defers all tools behind tool search. From the release notes (verbatim): "Changed MCP server alwaysLoad: false to defer all of that server's tools behind tool search." Pre-v2.1.287, an MCP server flagged alwaysLoad: false would still register some of its tools eagerly; post-fix, every tool behind such a server is deferred and only loaded when the model calls tool_search. For teams running dozens of MCP servers in a single session — a common pattern in agent-stacks-as-product deployments — this is the change that finally makes per-server lazy loading actually lazy. Documentation indicates this pairs with the v2.1.285 hardening of claude mcp list and the WebSocket MCP server health-status listing; the cumulative effect is that the model's tool-prompt no longer carries every MCP server's tool definitions by default.

The remaining "Added" and "Changed" items are smaller but real: an n:<text> filter for the agents view; prompt_text added to the OpenTelemetry user_prompt event (with a recommendation to drop or mask it wherever prompt is dropped); URL prompts from MCP servers on the 2025-11-25 protocol (the release notes flag a backwards-compat note — if a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry); a Windows startup warning when denying the Bash tool also turns off the PowerShell tool so Claude has no shell; a built-in gh api (REST only) for self-hosted runner sessions that use Anthropic-managed git where the GitHub CLI is not installed; /advisor pairing fixes (Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped); and a configurable CLAUDE_CODE_SUBAGENT_MODEL_FORCE to pin subagent model selection past the per-agent model: override.

Why developers and founders should care

Mods is a new product surface, not just a new feature. The first-party "You should know" Mod in this release is itself a side agent that watches the main agent. That is a meaningful product statement: Anthropic is shipping a model-watches-model pattern as a first-party Claude Code feature, and exposing it through a plugin slot that third-party developers can also build against. For builders building agent-stacks-as-products, the Mod slot is the integration target for cross-cutting observability, audit, and second-opinion tools — the same role that MCP servers filled for tool calling in 2025. Teams that already ship a Claude Code plugin should evaluate whether their plugin's value lives in a Mod slot before v2.1.287 becomes table-stakes.

The 1M default flips a cost and capability calculation on four hosting platforms. Opus 4.7+ and Fable users on Bedrock, Vertex, Foundry, or the Claude apps gateway now have 1M-token context by default; the input-token bill on a typical long-context turn roughly doubles versus 200K, and the prompt-cache strategy changes too because cache invalidation rules interact with the larger context window. For self-hosted runner operators on memory-constrained machines, the implicit-default flip is a footgun: an upgrade that silently doubles a turn's prompt-cache footprint can push a runner OOM under load. CLAUDE_CODE_DISABLE_1M_CONTEXT=1 is the documented opt-out and belongs in any managed environment that pins the 200K context budget.

The Bedrock and Vertex auth-header fix closes a real audit gap. A custom IdP / gateway / SSO policy that filters on the Authorization header was previously vulnerable to a startup-check vs. real-request mismatch — the startup check would pass, the first real request would fail, and the failure looked like an IdP rejection on a model that the platform itself said was available. The fix means Bedrock and Vertex AI operators running their own auth layers can now trust the model-availability signal that Claude Code's startup check produces. The complementary apps-gateway error improvement means the failure path is more visible if the auth-header fix is incomplete or if a custom header slips through in a future release.

MCP server lazy-loading is now actually lazy. The alwaysLoad: false semantic change is the smallest item in this section but the largest for teams running many MCP servers in a single session. Pre-fix, every MCP server's tool definitions were still injected into the model's tool prompt at session start; the cost was prompt-cache amplification and tool-cache pressure. Post-fix, an alwaysLoad: false server contributes nothing to the tool prompt until the model calls tool_search. For deployments in the dozens-of-MCP-servers range, this is the change that finally makes per-server lazy loading work.

Evidence and verification

This is a documentation-surfacing news report. All facts below are sourced from the official Anthropic Claude Code release page for v2.1.287; no live Claude Code invocation was placed during this run, no benchmark was executed, and no customer-side integration was tested.

Primary source 1 — anthropics/claude-code v2.1.287 release tag (verified verbatim at fetch 2026-10-01 22:08 UTC):

  • URL: <https://github.com/anthropics/claude-code/releases/tag/v2.1.287>
  • Section title: "What's changed"
  • Contains the full item list: two "Added Claude Mods" lines, the 1M-context default flip, the MCP alwaysLoad semantic change, the auth-header hardening, the n:&lt;text&gt; filter, the OTel prompt_text field, the URL prompts from MCP servers on the 2025-11-25 protocol, the Windows startup warning, the self-hosted runner gh api addition, the /advisor pairing fixes, the CLAUDE_CODE_SUBAGENT_MODEL_FORCE environment variable, the apps-gateway error improvement, the four-bedrock/vertex/mantle auth-header fix, the 40+ bug-fix items, the VSCode additions and fixes, and the agent-cloud-session fixes.
  • Verified release date: the v2.1.287 entry is timestamped 2026-10-01T18:43:19Z on the atom feed and is the topmost stable release. The previous stable release v2.1.286 (Sep 30 19:10 UTC) was an in-between release with no dedicated coverage in mr.technology because its six capability additions were already covered by the v2.1.285 article.

Primary source 2 — anthropics/claude-code releases Atom feed (verified to resolve at fetch 2026-10-01 22:08 UTC):

  • URL: <https://github.com/anthropics/claude-code/releases.atom>
  • Confirms v2.1.287 is the topmost stable release; v2.1.286, v2.1.285, v2.1.284, v2.1.283, v2.1.282, v2.1.281, v2.1.280, v2.1.278, v2.1.277, and earlier are listed below in descending order.
  • Confirms v2.1.287 is the first stable release after v2.1.286 (Sep 30 19:10:13 UTC).

Primary source 3 — Anthropic Claude Code managed-settings documentation (referenced for the 1M context opt-out; verified to resolve at fetch):

  • URL: <https://docs.claude.com/en/docs/claude-code/iam>
  • Cross-referenced for CLAUDE_CODE_DISABLE_1M_CONTEXT semantics and the 200K fallback.

Primary source 4 — Anthropic Claude Code plugins documentation (referenced for Mods; verified to resolve at fetch):

  • URL: <https://docs.claude.com/en/docs/claude-code/plugins>
  • Cross-referenced for the Mod slot contract and the /plugin enable &lt;id&gt;@builtin invocation pattern.

Primary source 5 — Anthropic Claude Code MCP documentation (referenced for the alwaysLoad semantic; verified to resolve at fetch):

  • URL: <https://docs.claude.com/en/docs/claude-code/mcp>
  • Cross-referenced for the alwaysLoad: false and bareElicitationCapability semantics.

Cross-check against recent coverage. The Sep 28 article claude-code-2-1-284-sonnet-5-5-default-1m-context-cache-reads-sep-2026 covers the Sonnet 5.5 default flip. The Sep 30 article claude-code-2-1-285-allowedproviders-managed-setting-nonstreaming-retry-budget-sep-2026 covers allowedProviders and the non-streaming retry-budget fix. The Sep 25-26 articles cover v2.1.282 (managed-settings hardening + macOS symlink plugin self-approval), v2.1.283 (enterprise model gateway), and v2.1.281 (Bedrock assume_role + guardrail). This article is the v2.1.287 release note and does not duplicate any prior coverage; the v2.1.286 release was a small follow-up (six capability additions, mostly on the credential-redaction and remote-control paths) that did not warrant a standalone mr.technology article.

Cost, risk, and limitations

Cost dimension. The 1M-context default flip is the cost-control story for v2.1.287, not the cost-creation one. On a long-context turn, doubling the context window from 200K to 1M roughly doubles the input-token bill per turn and changes the prompt-cache amplification behavior on subsequent turns. Pre-v2.1.287, builders had to opt in by appending [1m] or setting an explicit managed-settings field; the opt-in was the cost-control. v2.1.287 inverts that — the implicit default is 1M, and the cost-control is the explicit CLAUDE_CODE_DISABLE_1M_CONTEXT=1 opt-out. Self-hosted runner operators running on 32-64 GB instances that were sized for 200K-context workloads should add this opt-out to their managed environment before upgrading.

Risk dimension. The largest risk for teams running Claude Code on managed machines is that v2.1.287 ships two implicit-default flips (the 1M context window and the alwaysLoad: false MCP semantic) that interact with prior managed-settings configurations. A runner that previously held the 200K context budget will silently move to 1M on upgrade; a session that previously had all MCP tools eagerly registered will silently defer them on upgrade. Builders should audit their managed environments and run a single-turn smoke test before rolling out v2.1.287 to production.

The Mods slot itself is opt-in (/plugin enable cc-plugin-you-should-know@builtin for the first-party Mod, equivalent enable commands for third-party Mods), so there is no implicit exposure. The telemetry flag on the first-party Mod is the activation gate, which is the Anthropic-side acceptance criterion.

Limitations of this report. This is documentation-surfacing only. No live Claude Code session was placed against v2.1.287 to confirm the Mod slot, the 1M context default, or the alwaysLoad: false semantic. The 40+ bug-fix items are summarized at the category level (security, MCP, TUI, VSCode, remote control, multi-cloud); the per-item analysis is sourced from the release notes verbatim, not from a measured workload. The MCP bareElicitationCapability backwards-compat note is sourced from the release notes verbatim and was not tested against a real MCP server. Treat this report as a release-notes walkthrough, not as a verification log.

Mr. Technology verdict

Claude Code v2.1.287 is a capability release, not just a hardening release. The Mods slot is the most consequential product-surface change in a Claude Code release this year; the first-party "You should know" Mod is a model-watches-model pattern that Anthropic is shipping as a default. The 1M-context default flip on Bedrock, Vertex, Foundry, and the apps gateway is the second-most consequential, and it is the kind of implicit-default change that requires a managed-settings update for any self-hosted runner sized for 200K. The Bedrock, Vertex, Mantle auth-header fix is the security change that matters most for enterprise multi-cloud deployments. The alwaysLoad: false MCP semantic change is the operational change that matters most for teams running many MCP servers in a single session.

For builders who already pin managed-settings, v2.1.287 is a direct upgrade — add CLAUDE_CODE_DISABLE_1M_CONTEXT=1 if you need to preserve the 200K budget, audit your MCP servers' alwaysLoad values, and verify the auth-header fix on your Bedrock or Vertex deployment. For builders on a casual install, the 1M default flip is the only change with immediate cost-control implications; the rest of v2.1.287 is forward-looking capability work.

Recommended action

Today, for teams running Claude Code on managed machines: 1. Add CLAUDE_CODE_DISABLE_1M_CONTEXT=1 to your managed environment if any machine is sized for 200K-context workloads. This preserves the 200K budget; without it, v2.1.287 silently moves Opus 4.7+ and Fable sessions to 1M on Bedrock, Vertex, Foundry, and the apps gateway. 2. Audit your MCP server configurations for alwaysLoad: false. v2.1.287 changes the semantic so that every tool behind such a server is now deferred behind tool_search; if your eval or test harness depends on eager tool registration, the harness behavior will change. 3. For Bedrock, Vertex, or Mantle operators with a custom IdP / gateway / SSO policy: verify the auth-header fix on a single Bedrock session. If your IdP was filtering on the Authorization header and rejecting the first real request while the startup check passed, the fix should clear it. The apps-gateway error improvement means the failure mode is more visible if the fix is incomplete. 4. Decide whether to enable the first-party "You should know" Mod (/plugin enable cc-plugin-you-should-know@builtin). The Mod requires telemetry on; opt in if your compliance posture allows it.

This week: 5. For teams shipping Claude Code plugins: evaluate whether your plugin's value lives in a Mod slot. The Mod slot is the integration target for cross-cutting observability, audit, and second-opinion tools; third-party Mods can fill the same role as the first-party one. 6. For self-hosted runner operators: confirm your runner sizing supports the new 1M default if you do not opt out. Long-context turns now consume ~5x the input tokens of a 200K-context turn; runner memory and disk-cache sizing should be reviewed. 7. For Bedrock and Vertex operators: confirm your custom IdP / gateway now passes the startup model-check with the same Authorization header as production traffic. If the auth-header fix interacts with your IdP's audit log, expect the audit volume to look different on v2.1.287.

Skip if not in scope: If you run Claude Code on an unmanaged personal machine with no compliance, cost-control, or multi-MCP-server requirements, the 1M default flip and the alwaysLoad change do not affect you materially. The Mods slot is opt-in and the auth-header fix is automatic. The MCP URL-prompt protocol change (2025-11-25) only matters if you operate an MCP server that surfaces URL prompts.

Sources

Related Dispatches