Claude Code 2.1.200: Manual Permission Mode and the AskUserQuestion Change Every Operator Must Audit
Claude Code 2.1.200 renames the default permission mode to "Manual" and removes auto-continue from AskUserQuestion dialogs — two changes that will stall CI pipelines and background agent workflows without an explicit config update.
Archive item produced with AI assistance from the cited source and published without individual review. Editor of record: Joe Werner.

Two behavior changes in Claude Code 2.1.200 — shipping today — will silently break existing CI setups and background agent workflows if you do not act before the next deploy.
The first: AskUserQuestion dialogs no longer auto-continue by default. Any unattended pipeline that relied on the previous auto-advance behavior will now hang waiting for input. The second: the permission mode previously called "default" is now labeled "Manual" in the CLI, VS Code, and JetBrains — and the config key "defaultMode": "default" must be audited even though a compatibility alias is provided.
Beyond these two, the release ships ten-plus background agent and daemon reliability fixes that will matter for teams running Claude Code at scale.
What happened
Claude Code 2.1.200 is available now via npm install -g @anthropic-ai/claude-code. Three categories of change:
Permission model rename. The mode that required manual approval for every tool call — previously labeled "default" — is now officially called "Manual". The CLI --help, VS Code extension, and JetBrains plugin all reflect the new label. Existing config using "defaultMode": "default" or --permission-mode default is accepted as a compatibility alias, so nothing breaks immediately, but you should migrate to "manual" to stay current with documentation.
AskUserQuestion no longer auto-continues. When Claude Code poses a clarifying question to the user during an unattended run, the dialog previously timed out and auto-advanced. In 2.1.200 it waits indefinitely until a human responds — unless you opt into an idle timeout via /config. Teams that run Claude Code in CI, background daemon mode, or as a subagent expect zero-interaction execution; this change introduces a new class of stall.
Background agent and daemon hardening. Twelve fixes in this release address daemon lifecycle issues:
- Stale
daemon.lockfiles whose PID was reused by the OS no longer restart a crashed agent loop. - Build recency is now judged by an embedded timestamp instead of version string, preventing an older reinstalled build from hijacking the daemon.
- Orphan cleanup corruption that permanently disabled cleanup is fixed.
- Older binaries no longer strip fields written by newer versions when restarting the daemon.
- Socket auth tokens are preserved across daemon restarts.
- Subagents cut off by a rate limit before producing any output now return a clean failure instead of an empty result.
- Control bytes from background agent output no longer reach the terminal.
- Project-scoped plugins now load correctly from git worktrees of the same repository.
Why it matters for AI engineering teams
The AskUserQuestion change is the highest-urgency item. The previous auto-continue behavior was technically undefined — nowhere was it documented as guaranteed — but teams built around it in practice. Subagents running in background daemon mode could post a clarifying question mid-task and keep moving; now they stop. If your routing layer invokes Claude Code as an unattended worker (for example as a subagent under an orchestrator agent), any AskUserQuestion in the tool execution path will cause the downstream job to time out rather than complete with partial output.
The permission mode rename is a lower-priority migration, but it has a documentation and onboarding cost: any runbook, Terraform module, Kubernetes manifest, or setup guide that references "defaultMode": "default" is now technically stale, even if it still works. Auditing and updating this is cheap now; skipping it compounds documentation debt over time.
The daemon fixes matter for teams at scale. The daemon.lock PID-reuse bug and the orphan cleanup corruption could cause a crashed daemon to restart worker agents in a loop or to accumulate zombie processes. If you observed Claude Code background sessions consuming unexpected resources after a crash, 2.1.200 addresses the root causes.
The git worktree plugin-loading fix is relevant to monorepo setups where project-scoped plugins are declared in a worktree of the same repository — a common pattern for teams that maintain agent configurations alongside source code.
The router/operator angle
Unattended workflow auditing. Any system prompt or orchestration instruction that routes model requests through Claude Code in background mode should be tested against 2.1.200 with explicit attention to AskUserQuestion triggers. Identify whether any tool calls, file reads, or planning steps could produce a clarifying question; either suppress them via system prompt, pre-approve tools so the question never arises, or set an idle timeout via /config if some interactivity is acceptable.
Config drift management. Teams running Claude Code via managed settings — for example via CLAUDE.json files or shared Cursor profiles distributed through a team MCP marketplace — should audit every instance of "defaultMode" or --permission-mode to ensure the string is updated from "default" to "manual". The behavior is unchanged; the label is not. A config that says "default" still works, but a human reading it will expect different behavior from what the docs now describe.
Daemon stability for gateway-adjacent setups. If you proxy Claude Code requests through a local gateway process that monitors daemon health, the build-recency and lock-file fixes reduce the risk of a reinstall or OS-level PID reuse causing a daemon takeover. Version-pin your Claude Code installs in CI and document the expected build timestamp if you use any health-check logic that inspects the running daemon version.
Rate-limit surface change. The fix that makes subagents report clean failures (instead of empty results) when cut off by a rate limit will change observable behavior at your routing layer: calls that previously returned silently empty will now return error objects. Update any result-handling logic that treated an empty response as a success signal.
What routing teams should watch or try
- Check your CI and unattended pipeline configs before updating to 2.1.200. Run a test invocation with a task likely to trigger
AskUserQuestionand confirm it either times out gracefully (if you set an idle timeout) or never produces the question (if you pre-approve relevant tools). - Audit
defaultModein all managed config files. The compatibility alias means this is not urgent, but clean it up while you have the context. - Review daemon monitoring logic if you track
daemon.lockPID or version strings — these semantics changed in 2.1.200. - Teams on the claude-code-2199 reliability release should plan a sequential upgrade: the 2.1.199 fixes and the 2.1.200 daemon hardening are complementary and together stabilize the full background agent lifecycle.

Claude Code 2.1.216: Worktree Git Isolation Escape Patched and Quadratic Session Slowdown Fixed
Claude Code 2.1.216 closes a worktree subagent git isolation bypass and eliminates quadratic session slowdowns. Here is the operator audit checklist and what the new sandbox.filesystem.disabled setting changes.

Claude Code 2.1.275 Broke Every Gateway Proxy. 2.1.276 Fixed It the Same Day.
A new internal request tag in 2.1.275 caused 400 errors on every proxy-routed API call. 2.1.276 hotfixed it the same day. Breakdown of the failure, affected configs, and three secondary operator changes worth auditing.

Claude Code 2.1.274: MCP Reliability Overhaul, Gateway Postgres Config, and Self-Healing Transcripts
Claude Code 2.1.274 fixes six MCP failure modes that silently break production tool sessions, adds store.connect_timeout_seconds and CLAUDE_CODE_GATEWAY_DRAIN_TIMEOUT_MS to the Claude apps gateway, and makes corrupted transcripts self-heal instead of looping forever.