
Claude Code v2.1.263 to v2.1.266 Major Updates - plugin-dir Folder Specification and MCP Connection Fixes
This page has been translated by machine translation. View original
This is Ishikawa from the Cloud Business Division. I'd like to summarize the Claude Code updates from v2.1.263 to v2.1.266 (2026-09-06 to 2026-09-08, UTC). v2.1.262 and v2.1.264 are not published on npm. Today, I tried out the new folder specification feature for plugin-dir.
The previous update article is here.
Update Summary
This covers 3 versions (v2.1.263 to v2.1.266, 2026-09-06 to 2026-09-08, UTC). The CHANGELOG has 52 entries, with 50 of them concentrated in v2.1.265. The breakdown is: 34 fixes, 10 improvements/performance/developer experience, 4 new features, 2 security, 1 potentially breaking change, and 1 documentation fix. v2.1.266 has only 1 entry, and v2.1.263 has no individual entries in the CHANGELOG.
Notable Updates
Folders containing plugins can now be specified with --plugin-dir (v2.1.265)
You can now specify a folder containing plugins with --plugin-dir. Child folders with manifests are each loaded, and adding or removing child folders during execution is reflected automatically.
For those validating multiple plugins together or distributing a set of plugins internally, this feels like a change that reduces the effort of specifying each one.
cd is maintained across turns in non-interactive sessions (v2.1.265)
An issue was fixed where non-interactive sessions (stream-json input with -p, Agent SDK, cloud sessions) would reset the shell working directory with each new user message. cd is now maintained across turns. This applies to the 3 types of non-interactive sessions listed in the CHANGELOG.
For those using multi-turn automated processing with -p stream-json input or the Agent SDK, it's worth checking since procedures that assume directory changes will now work as intended.
MCP servers configured as http fall back to the legacy transport (v2.1.265)
An issue was fixed where an MCP server configured as http could not connect if it only spoke the legacy HTTP+SSE transport. It now falls back to SSE as per the MCP specification. This applies to servers configured as http that only speak legacy HTTP+SSE.
For those who couldn't connect to MCP servers configured with http and were questioning their configuration, this fix may resolve the issue.
Fix for all requests failing with CLAUDE_CODE_USE_GATEWAY (v2.1.266)
The undocumented environment variable CLAUDE_CODE_USE_GATEWAY was previously ignored unless both ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN were set, but in v2.1.265 it began forcing sign-in to the Cloud gateway on its own. As a result, configurations using this variable alongside API keys, apiKeyHelper, or custom authentication headers had all requests failing with "Not signed in to the Cloud gateway." In v2.1.266, this variable is once again ignored on its own, and no configuration changes are needed.
This only affects configurations that set CLAUDE_CODE_USE_GATEWAY while also using API keys, apiKeyHelper, or custom authentication headers, but those affected should consider upgrading to v2.1.266.
Fix for plugin path containment check bypass (v2.1.265)
On macOS and Linux, an issue was fixed where plugin paths containing backslashes could bypass symlink containment checks.
For those who load plugins obtained from external sources, it's worth updating.
Artifacts created by others are treated as untrusted content (v2.1.265)
The handling of artifacts created by others when loaded with the Artifact tool has been improved. Summaries treat the page as untrusted content and flag embedded instructions rather than passing them through directly.
For those who load artifacts created by others, this feels like a change that reduces the opportunity for instructions to be introduced via summaries.
Target Versions and Period
| Version | Release Date (UTC) |
|---|---|
| v2.1.263 | 2026-09-06 |
| v2.1.265 | 2026-09-08 |
| v2.1.266 | 2026-09-08 |
v2.1.263 has no individual entries in the CHANGELOG, only a single line: "Bug fixes and reliability improvements."
New Features
- Folders containing plugins can now be specified with
--plugin-dir. Child folders with manifests are each loaded, and adding or removing child folders during execution is reflected automatically (v2.1.265) - A 1 GB limit has been added for tool results saved to disk. If a saved file is truncated, this will be indicated in the in-conversation preview (v2.1.265)
user.emailanduser.groupshave been added to telemetry sent by Claude Desktop and Cowork via the Claude apps gateway, bringing them in line with terminal sessions (v2.1.265)- [VS Code] A feature to automatically archive sessions that have been inactive for a certain period has been added (new setting "Archive inactive sessions", default 14 days) (v2.1.265)
Improvements
--worktreestartup on large repositories has been improved, with new worktree checkouts parallelized (requires git 2.32 or later) (v2.1.265)- Resume time for long sessions that have read many files has been improved (v2.1.265)
- The agent detail view in
/workflowshas been improved. Tool calls now show running/failed/completed status, sub-agents with task lists display them, and pressing Enter expands the input and result of each call (v2.1.265) - Handling of slash commands entered mid-prompt has been improved. Suggestions are now shown as a list rather than a single suggestion (opened with Tab in non-fullscreen mode), and plugin skills can be found by unqualified name (v2.1.265)
- OAuth clients are no longer registered for remote MCP servers that require sign-in until authentication actually occurs (v2.1.265)
- Error messages when images exceeding the size limit cannot be decoded now indicate the cause and how to address it, rather than just showing the limit (v2.1.265)
- The description of the permission option for the
.claudefolder has been updated to match what is actually permitted (editing files in the project's.claudefolder or~/.claudeduring the session) (v2.1.265) - Image processing has switched to using the runtime's built-in image support, and the CLI no longer extracts native image modules to a temporary directory (v2.1.265)
- For plugin display metadata, marketplace entries now take priority over
plugin.jsonin the Installed tab andclaude plugin details, withplugin.jsonfilling in any gaps (v2.1.265) - OpenTelemetry for Claude apps gateway sessions now sends directly to the collector specified by
OTEL_EXPORTER_OTLP_ENDPOINTin gateway managed settings. Sessions without a specified collector use the previous relay (v2.1.265)
Fixes (Major)
A selection of fixes related to stability and usability.
- Fix for file operations being completely denied in sandboxed environments on Windows: When running inside AppContainer or restricted token sandboxes, Read, Write, and Edit were rejecting all files with "symlink resolution changed after permission was checked" (v2.1.265)
- Fix for prompt cache reuse being broken by sub-agent related issues: Fixed an issue where resuming a sub-agent launched in the foreground changed the tool list and system prompt prefix, and an issue where agent teammates and resumed sub-agents moved the SubagentStart hook context and pre-loaded skills outside the prompt prefix after the 2nd turn (v2.1.265)
- Fix for resuming after process termination during tool execution: The previous prompt is no longer overwritten, and interrupted tool calls are preserved and recorded as interrupted (v2.1.265)
- Fix for
/model opusplan[1m]being rejected: It was being rejected as "Model not found" (v2.1.265) - Fix for clean filters in nested repositories being executed: Claude Code's own git status/diff verification was executing clean filters configured in nested repositories within the working tree (v2.1.265)
- Fix for
/modeldisplaying success even when saving fails: "Saved as default" was displayed even when writing to the config file failed. It now displays the fact that saving failed and the reason (v2.1.265) - Fix for background sessions being terminated mid-turn: This occurred in
--bgsessions when a message arrived just before the idle timeout (v2.1.265) - Fix for VS Code sidebar going blank: After keeping a conversation open for more than 10 minutes, the sidebar chat would go blank after a Reload Window or restart (v2.1.265)
- A subtly welcome fix: The wait time for 2-key shortcuts has been extended to 3 seconds, and a notification appears on timeout (v2.1.265). For those who occasionally saw operations appear unresponsive over tmux, this feels like an effective fix despite being subtle.
- In addition, numerous minor bugs have been fixed related to plugin display metadata and load-time warnings, Remote Control and cloud session connector display, dialog behavior for
/config,/clear, etc., syntax highlighting and transcript display, error code descriptions forclaude-apiskills, and more.
Breaking Changes / Deprecations
- Machines with
forceLoginGatewayUrlin managed settings are now treated as Claude apps gateway sessions from startup, the same asforceLoginMethod: "gateway". Any remaining claude.ai logins or API keys are not used (v2.1.265)
The CHANGELOG records this as "Changed" without explicitly marking it as Breaking. However, since the way authentication is used changes on machines with existing configurations, I'm treating it separately as a potentially breaking change. Below is a configuration example.
After the change (v2.1.265 and later)
# managed settings (example - no changes to settings)
{
"forceLoginGatewayUrl": "https://gateway.example.com"
}
# Behavior from startup (v2.1.265 and later)
# Treated as a Claude apps gateway session from startup,
# the same as forceLoginMethod: "gateway"
# Any remaining claude.ai logins or API keys are not used
Trying Out the --plugin-dir Folder Specification
I confirmed the folder specification feature added in v2.1.265 using Claude Code v2.1.266 in a test environment. I prepared a parent folder containing 2 child folders with manifests.
% tree plugin-lab
plugin-lab
├── alpha
│ └── skills
│ └── blogcheck-alpha
│ └── SKILL.md
└── beta
└── skills
└── blogcheck-beta
└── SKILL.md
I put the absolute path of plugin-lab into the environment variable LAB.
% LAB=/Users/ishikawa/projects/20260909-v2.1.266/plugin-lab
I launched claude, passing the environment variable LAB to --plugin-dir.
claude --plugin-dir "$LAB" --strict-mcp-config
I ran the prompt: "Please answer without using tools. List all available skills whose names start with blogcheck."

By specifying the parent folder just once, both plugins from the child folders were loaded and their respective skills became available. In situations where you're testing multiple plugins together, being able to just pass one parent folder instead of listing multiple --plugin-dir entries makes preparation easier.
Closing
v2.1.265 has 50 entries, but most of them feel like fixes that affect specific use cases. For those using plugins, MCP, or non-interactive sessions, it's worth checking whether any entries apply to you. Since v2.1.266 is a regression fix for v2.1.265, those who have upgraded to v2.1.265 should go ahead and upgrade to v2.1.266 as well.
If there are any changes that catch your interest, why not update and check them out?
References
