Opus 5 is now the default model for seat-based Enterprise subscriptions. This huge release also patches symlink/path-traversal security holes and fixes 19 hang-related bugs.
PreModelSwitch and PostModelSwitch hook events (block, confirm, or annotate a model switch); SessionStart resume hooks now receive session staleness and the estimated re-cache cost/usage and a rate_limits.spend_limit status line field for developers behind a Claude apps gateway with spend limits/cost (hit ratio, misses, tokens re-cached, warm/cold) and a matching prompt_cache object for status line scriptsattach, logs, stop, respawn, and rm to claude --help; the --resume message for a running background session now names the exact claude attach <id> command/schedule to explain that MCP servers configured in Claude Code can't be attached to cloud routines, instead of a bare "No MCP connectors" message/tasksCLAUDE_CODE_PROVIDER_MANAGED_BY_HOST (e.g. Claude Desktop): a session given a Bedrock model ID or ARN no longer waits for inference-profile discoveryscriptPath outside what the session may read before the permission check ranRead(...) deny rules to files reached through a symlinked search pathhigh in that caseSendMessage to that session id now delivers through Claude Desktop instead of failing with "not reachable"from was the agent type, which is not an address)disableAutoMode arriving mid-session not moving an already-running auto-mode session back to default mode/status and retrying gateway 401s with it, though requests never use it/mcp reconnect on Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session--input-format stream-json: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessionsgit worktree add/usage-credits for Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached--worktree --tmux with a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly/dev/tty, such as emacs -nw and microadditionalDirectories entry containing a null byte crashing startup, or breaking /add-dir and later settings updates when it came from an SDK host, IDE, or hook; it is now skippedscreen terminal typeclaude mcp add --header and claude mcp add-json help text naming the wrong transportsclaude ultrareview and /ultrareview waiting the full 30 minutes when the cloud session fails to start; they now stop early and report the reasonOPTIND=1/0, RANDOM=2+2); these now prompt for approval←, /background, --bg) losing a Vertex/Bedrock gateway (ANTHROPIC_*_BASE_URL + CLAUDE_CODE_SKIP_*_AUTH) exported in the shell, so every request failedclaude --bg --model fable on Max plans stopping to ask for usage credits while the interactive session on the same account still had Fable allowance/bug and /share reporting that /feedback was disabled; tips, /help, and refusal messages no longer suggest /feedback when an org policy or env var turns it off/radio to be available on Bedrock, Vertex AI, Foundry, and Claude Platform on AWS, and when telemetry is disabledCLAUDE_CODE_SUBAGENT_MODEL to set the default subagent model rather than override everything: an agent definition's model: and an explicit per-spawn model now take precedence over itCo-Authored-By: Claude Code when the active model isn't a recognized Claude model (e.g. third-party models behind a custom ANTHROPIC_BASE_URL)/effort to save your default effort level per model, so each model keeps its own setting when you switchDISABLE_TELEMETRYgh auth token, GH_TOKEN, or GITHUB_TOKEN) instead of gh pr viewANTHROPIC_CUSTOM_HEADERS from managed or project settings to require approval when it sets a credential, org/tenant, routing, or API-behavior header (e.g. Authorization, Host).claude/settings.json env to no longer set CLAUDE_CONFIG_DIR, CLAUDE_CODE_TMPDIR, or TMPDIR/TMP/TEMP; set them in your shell, user, or managed settings instead/remote-control