Claude Code v2.1.291 is not a flashy release. It fixes two things:
1. Cloud sessions dropping answers to permission prompts
(regression from 2.1.290)
2. Losing final session messages on quit
(regression from 2.1.288)
Boring? For anyone running coding agents in production, it is the opposite. A lost approval answer means "the user allowed it but it did not run — or something ran that was never allowed." A lost final message means "there is no record of what happened." Both strike at the heart of reliability.
Yesterday (v2.1.290) matters more: permission plumbing
The day-earlier release carries the real substance — a continuation of our Mods article:
serverToolUses
→ added to a mod's turn.step hook result
→ the tool calls the API ran itself,
each with id, name, input, start and end
→ work done off your machine lands on the ledger too
agentId
→ added to the tool.check event of plugin hooks
→ tells a subagent's permission check
apart from the main session's
→ never confuse "whose decision is this" again
ceiling
→ added to the question and verdict a tool.check hook reads
→ names the approval level the organization
requires for a tool
→ pass "this needs higher sign-off" into the decision
| Addition | Where it lands | Problem it solves |
|---|---|---|
ceiling |
Approval question and verdict | Express org sign-off chains in code |
agentId |
Approval request event | Separate subagent from main-session requests |
serverToolUses |
Turn execution result | Include server-side runs in audit trails |
The shift: approval decisions move from binary yes/no toward decisions that account for org rules, the acting agent, and where execution happened. Production-touching work can carry a high ceiling, subagent-originated requests get their own policy — all writable on the hook side.
Why "who called what, approved by what" beats UX
As coding agents grow stronger, background execution outgrows what humans watch on screen. Reliability then rests on four recorded fields, not pretty UI:
agentId who (main session or which subagent)
tool call what (which tool, which arguments)
approval by what (which approval, which ceiling)
result how it ended (success, failure, side effects)
That is why the two v2.1.291 bugs hurt: dropped approval answers empty the approval column, lost quit-time messages empty the result column. With two columns empty, nobody can later answer "so what happened in production."
CodeBridge mini lab: log traces, not just outputs
Turn the briefing's action into an experiment. When you build a Claude Code plugin or Mod, start with the trace schema — not output logging.
One line per tool execution (JSONL recommended):
{
"ts": "execution time",
"agentId": "main | subagent name",
"tool": "tool name",
"args": "argument summary (mask secrets)",
"ceiling": "applied approval level",
"decision": "allow | deny | ask",
"result": "exit code / summary",
"serverSide": "server execution (serverToolUses)"
}
Weekly review questions:
[ ] any unexpected subagent-originated calls?
[ ] did high-ceiling work run under proper approval?
[ ] any server-side runs missing from local logs?
[ ] any repeated denials to promote into rules?
Combined with step-up approvals from our MCP re-auth article and execution grouping from our observability article, the approve-execute-observe loop is complete.
One practical update tip: check claude --version, and native installs need claude update plus a restart. Self-hosted cloud runners need the host binary upgraded and runners restarted. "Up to date" on the stable channel does not necessarily mean 2.1.291.
Conclusion: strong agents need ledgers first
One line to close:
Models decide an agent's capability; records decide its reliability.
v2.1.290 laid the recordable material, v2.1.291 stops records from vanishing. The order is right. Take your plugins and Mods in the same order: trace structure of agentId + tool call + approval + result first, automation second.
One sharp next step: attach the 8-field JSONL logging above to this week's Claude Code work. Read the log in a week, and the approval gate you need next will show itself.
Further reading
- The Mods era: reshaping Claude Code
- Ask again when MCP wants more
- Using Claude Code on real projects
References
Go deeper with a course
To practice building approval gates and trace structures by hand, stack CLAUDE.md, skills, hooks, subagents, and MCP on real projects — exactly like this article's mini lab.