Claude Code 2.1.295 lets hooks fail closed and lets the gateway limit models and time to first byte per upstream
Guard hooks no longer let actions through when they break, and the enterprise gateway gets finer per-upstream routing and timeouts.
// Key points
- Command and HTTP hooks get onFailure: "block": a hook that can't start, times out or exits with an unexpected code blocks the action instead of letting it through.
- Every Claude apps gateway upstream can take an optional models list, so only those models are sent there, on failover too; cloud upstreams such as Bedrock, Vertex and Foundry support timeouts.upstream_ttfb_ms to cap how long a stream may take to start before it fails over or returns a 502.
- Program Status Protocol (OSC 7501) support lets terminals that implement it show whether Claude Code is working, waiting on you or done.
- A new CLAUDE_CODE_RETRY_WATCHDOG_MAX_WAIT_MS limits how long unattended retry mode waits out 429 and 529 errors.
Builder's takeFail closed is the default a safety hook should have: a guard that lets everything through when it crashes is no guard. I'd switch hooks that block deletions or production config pushes to block, and add health checks for the hooks themselves so a broken one doesn't stall the whole team.