Claude Code

Claude Code 2.1.285 can switch off WebFetch and open the desktop app from the terminal

3 min read AI-generated

Claude Desktop jumps from 2.9939.4 to 2.16120.0 the same day and can create a Google Doc straight from the Output picker.

Featured image for "Claude Code 2.1.285 can switch off WebFetch and open the desktop app from the terminal"

2.1.285 hit npm on Tuesday at 17:32 UTC, one day after 2.1.284. The changelog is unusually long and most of it is fixes. The new features fit on one hand, but they earn their place.

Four new switches

CLAUDE_CODE_DISABLE_WEB_FETCH turns the WebFetch tool off entirely. If you work somewhere Claude shouldn’t be fetching URLs, you no longer need a permission rule for it.

claude --desktop opens the Claude desktop app on the directory you’re standing in. With --continue or --resume <id> it lands on a specific session. That’s the bridge that was missing: start in the terminal, carry on in the app.

claude plugin configure <plugin> lists a plugin’s options and which of them are still unset, and takes new values from stdin with --values-stdin. Alongside it, claude plugin install --config now understands <server>.<key>=<value>, so a bundled .mcpb MCP server gets its settings at install time and starts without a trip through /plugin → Configure.

And for organisations: allowedProviders is a managed setting that limits which API providers a machine may use at all. The list covers the Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS and a Cloud gateway.

Claude Desktop jumps to 2.16120.0

Anthropic shipped the desktop app the same day, with a version jump from 2.9939.4 to 2.16120.0. It bundles Claude Code 2.1.284, not the new 285.

Two things stand out. The Output picker in a new chat can now create a Google Doc, Sheet or Slides deck directly when Google Drive is connected. And video outputs play inline in the file pane, with thumbnails in the chat.

Two changes matter on the Code side. Max effort now applies to the current session only, as in the CLI, so new sessions no longer start at Max. And worktree cleanup got gentler: a session’s worktree survives until the session is archived, however long it sits idle, and anything you or the CLI create under .claude/worktrees is never removed by the app. There’s a matching fix for a bug where archiving a session deleted uncommitted work in an older worktree.

On the admin side, deniedPluginMcpServers arrives: URL patterns for remote servers that plugins may not connect to. A match stays blocked even when allowedPluginMcpServers admits it.

Fixes you’ll actually notice

Four are worth naming. Redacted logs and transcripts leaked part of a URL password containing @, and all of it when the URL wrote that @ as %40. Switching models mid-session through a set_model request left the new model stuck on the built-in output-token limit and the old auto-compact window until restart. Sandbox auto-allow asked for approval on every run of inline scripts like python3 -c just because they contained an =. And Claude Code refused to start when the OS denied reading the managed settings file; it now warns and starts without those policies.

The provider lock is the line that matters for companies

The terminal bridge is the nicest addition, but allowedProviders is the consequential one. Until now an organisation could dictate what Claude Code is allowed to do, not whose infrastructure it talks to. Anyone tied to Bedrock or Vertex for compliance reasons had to trust that nobody would point a machine at their own endpoint. That gap is closed.

That the desktop app still bundles 2.1.284 shows, incidentally, how far the two tracks have drifted apart. If you want the new switches, you want the CLI.

Sources

Claude CodeAnthropicReleasesCowork