# Claude Code 2.1.238: plugin headersHelper auth, self-hosted-runner proxy flags, long-session memory fix

> A wide maintenance release: plugin marketplaces and MCP configs can now mint HTTP headers via a `headersHelper` command (gated behind folder trust and stripped of inherited credential env vars), self-hosted runners get graceful-shutdown and proxy-authorization options, and unbounded memory growth in long interactive sessions is fixed. Most of the rest is Remote Control and cross-session messaging reliability. Anyone relying on the Ctrl+L double-press `/clear` shortcut loses it.

| | |
|---|---|
| **Tool** | Claude Code |
| **Version** | 2.1.238 |
| **Kind** | release |
| **Published** | 2026-08-20 |
| **Observed** | 2026-08-21 |
| **Significance** | 3/5 |
| **Breaking** | no |
| **Categories** | feature, fix, security, api-change |

## What changed


**New**
- `keybindingFlavor` setting; `"readline"` makes Ctrl+W delete back to the previous whitespace (default `"classic"` unchanged)
- `headersHelper` on url marketplaces and catalog entries runs a command that mints HTTP headers (e.g. short-lived tokens) for catalog and same-origin archive fetches; a catalog entry's helper runs only on install/update, after the command is shown, with a `[y/N]` prompt (or `-y`)
- `claude self-hosted-runner --defer-shutdown-max-min <minutes>`: on SIGTERM keep serving attached sessions, park the rest after N minutes, then exit
- `claude self-hosted-runner --proxy-authorization-command` / `--proxy-authorization-file` for egress proxies needing a fresh `Proxy-Authorization` per connection

**Changed**
- Ctrl+L / Cmd+K in fullscreen always just repaint; the double-press `/clear` shortcut is removed (1-row nvim terminals no longer trigger `/clear` loops)
- `claude mcp list` / `get` show disabled servers as `⊘ Disabled` instead of health-checking them
- `headersHelper` in a project `.mcp.json`, and inline MCP servers in project or `--add-dir` agent files, require that folder's trust dialog to have been accepted — including under `claude -p`
- Project/plugin/agent-file `headersHelper` runs without inherited credential env vars; user, managed and claude.ai-scope helpers run from the Claude config dir
- Cross-session messaging surfaces refusals (`crossSessionInbound: "refuse"`) and dropped inboxes to the sender instead of reporting silent success
- Bundled `claude-api` skill updated for the Managed Agents Aug 19 release (web search/fetch domain settings, memory stores on self-hosted sandboxes)

**Fixed**
- Unbounded memory growth in long sessions — subagent tool results released once out of the display window
- Custom/project/plugin output styles drifting back to the default voice mid-session
- stdio MCP servers getting `server/discover` before `initialize`, forcing lazy servers to boot every session
- Self-hosted runners removed after a single slow or lost poll, handing a healthy session to another runner
- Leftover `/tmp/claude-*-cwd` files after a killed, timed-out or interrupted Bash command
- Worktree-isolation Bash refusals citing a redirect the command didn't have
- MCP elicitation dialogs blank for URLs over 4,096 chars; permission prompts dropping "don't ask again" on narrow terminals; diff text clipped on emoji/tab lines
- Held Backspace ignored on Ctrl+H terminals over slow SSH/mosh; suspended (Ctrl+Z) sessions leaving bracketed-paste on with a hidden cursor
- Proxy connection refusals reported as generic network errors
- `/model` and `/effort` cache-miss warning firing on an already-expired cache
- `CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true` not holding when near but not over the usage limit
- Remote Control: per-task Stop no-op on CLI-hosted sessions; exits on a message with no valid role; inherited session-scoped env vars via `claude remote-control`; crashed sessions unavailable until restart; mid-turn web/Desktop messages vanishing from the transcript; phone/web model picks not reflected in the terminal; "login expired" on brief network hiccups; failed-reconnect report on sign-out
- `ListAgents`/`SendMessage`: "Remote Control is not connected" in server-mode and Desktop/IDE-hosted sessions; pre-warmed idle worker no longer exposed until a task claims it

**Improved**
- Faster bare `claude` startup on macOS; update check deferred ~10s after launch
- Bash permission checking for zsh-specific conditional syntax
- Remote Control tolerates brief HTTP 403 refusals from an edge/VPN/proxy for up to 3 minutes, naming the blocker if it persists


## Sources

- [changelog_md](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md) — retrieved 2026-08-21


## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/claude-code/2-1-238
Entity: https://changelogs.info/claude-code
Event ID: `evt_2026-08-20_claude-code_2-1-238`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
