Anthropic’s Claude Code v2.1.295 adds fail-closed hooks

Anthropic released Claude Code versions 2.1.294 and 2.1.295 on October 8, 2026, introducing 143 changes focused on security enhancements and operational control for coding-agent workflows. The updates added a new onFailure: “block” option to command and HTTP hooks that blocks operations when hooks fail to launch, time out, or exit with unexpected codes, addressing concerns about fail-safe behavior in development environments.

The dual release marks a significant shift in how Claude Code handles security validation failures, moving from a default fail-open approach to offering developers explicit fail-closed controls. This change comes as enterprises increasingly deploy AI coding assistants in production workflows where security guardrails are critical.

Enhanced Hook Security Controls
The flagship feature in version 2.1.295 allows command hooks and HTTP hooks to block operations completely if a hook fails to launch, times out, or exits with an unexpected exit code. Previously, Claude Code would allow operations to proceed when validation hooks encountered errors, a behavior security teams identified as risky for sensitive development environments.
The fail-closed option provides organizations with stronger enforcement mechanisms for security policies. When enabled, any malfunction in a validation hook prevents the associated action from executing, rather than permitting it by default. This architectural change aligns with enterprise security practices that prioritize preventing unauthorized actions over maximizing availability.

Version 2.1.294 also fixed a critical issue where prompt hooks and agent hooks written as instructions were allowing operations that should have been blocked, representing a notable security gap in earlier releases.
Model Compatibility and Beta Feature Handling
The 2.1.295 release fixed an issue where all model requests with the context-1m beta designation would fail in environments where gateway, Bedrock, Vertex, or Foundry rejects the beta, with Claude Code now retrying without the beta designation. This improvement ensures broader compatibility across different AI platform deployments and prevents workflow interruptions when enterprise environments use restrictive model configurations.
The fix addresses a common pain point for organizations deploying Claude Code across heterogeneous infrastructure, where different AI service providers may support varying feature sets and beta capabilities.

Built-in Tool Restrictions
Version 2.1.295 corrected a flaw where the –tools and –restricted flags were not being applied to built-in tools registered after startup, closing a potential security bypass. This ensures that runtime restrictions apply consistently across all tools available to the coding agent, regardless of when they are loaded into the environment.
Context and Broader Implications
The timing of these security-focused updates coincides with heightened scrutiny of AI coding assistants in enterprise environments. Recent reports indicate that some major technology companies are reevaluating their reliance on third-party AI coding tools, with concerns about model distillation, data security, and operational control driving internal policy changes.
The introduction of fail-closed hook behavior gives security teams the controls they have requested for production deployments. Organizations can now implement validation hooks that definitively prevent risky operations, rather than relying on best-effort guardrails that might fail open under error conditions.
Developer feedback on the hook system has emphasized the need for predictable, deterministic security controls. The new onFailure: “block” parameter addresses this requirement while maintaining backward compatibility for teams that prefer or require fail-open behavior for their workflows.
Release Timeline and Adoption
Both Claude Code v2.1.294 and v2.1.295 were released on October 8, 2026, with the updates distributed through Anthropic’s standard release channels. The rapid succession of versions suggests an iterative approach to delivering security improvements, with 2.1.294 containing foundational fixes and 2.1.295 building additional capabilities on that foundation.
Multiple automated tracking systems and package repositories documented the new versions within hours of release, indicating active monitoring of Claude Code updates across the developer ecosystem. The changes affect all deployment modes of Claude Code, including VSCode extensions, command-line interfaces, and integrated development environment plugins.
Key Facts
- Claude Code v2.1.295 was published October 8, 2026 with 143 changes
- New onFailure: “block” option for command and HTTP hooks blocks operations when hooks fail, time out, or exit with unexpected codes
- Version 2.1.294 fixed prompt and agent hooks written as instructions allowing operations that should be blocked
- Fixed context-1m model requests failing in restrictive environments, with automatic retry without beta designation
- Corrected –tools and –restricted flags not applying to built-in tools registered after startup
Sources
- Classmethod: Major Updates in Claude Code v2.1.294-v2.1.295
- Developers Digest: Coding Agent Hooks – Fail-Open vs Fail-Closed
- AFP: Anthropic Bans Cruel Behavior Against Claude AI
- Ground News: Meta Reportedly Reduces Claude Usage





