Claude Code 2.1.284 ships Sonnet 5.5 at the leaked price

If you open a new Claude Code session in the terminal or VS Code and have never set a permission mode, it now starts in auto mode, whatever your plan or provider. According to the v2.1.284 release notes on GitHub, the same release makes Claude Sonnet 5.5 the default Sonnet on the Anthropic API, with 1M context, $2/$10 per Mtok and $0.20/Mtok cache reads.
At a glance
- Claude Code 2.1.284 adds the claude-sonnet-5-5 model ID, shows gateway spend limits in dollars in /usage, and moves Ultracode out of the /effort slider into its own toggle.
- When auto mode is about to read a file outside your working directories, its prompt now offers "Yes, but ask again next time". That answer approves the single read, and you are asked again about later ones.
- The permissions.defaultMode setting still overrides the new auto default, so if you want to approve every action yourself, you have to set it. The notes give no data on how auto mode performs.
In case you missed the launch: according to CellCog, Anthropic released Sonnet 5.5 on September 28, 2026 as claude-sonnet-5-5 on the Claude API, Amazon Bedrock, Google Cloud and Microsoft Foundry, and calls it the second model in the Claude 5.5 family. AI×AI reported that Claude Opus 5.5 came out first, on September 22, 2026, and that leaked staging benchmark sheets for Sonnet 5.5 followed. For comparison, Finout lists Sonnet 4.6 at $3.00 input and $15.00 output per million tokens.
Sonnet 5.5 costs $2 in and $10 out per million tokens, with a 1M context window
Claude Code adds the model as claude-sonnet-5-5 and makes it the default Sonnet on the Anthropic API. The release notes give four numbers: a 1M-token context window, $2 per million input tokens, $10 per million output tokens, and $0.20 per million tokens for cache reads.
According to CellCog, that is the same price as Sonnet 5, and Anthropic says Sonnet 5.5 runs 30%+ faster and costs up to 30% less for most work. CellCog reports these scores from Anthropic's launch table: on Terminal-Bench 4.0, Sonnet 5.5 gets 70.6%, Sonnet 5 gets 10.3% and Opus 5.5 gets 66.4%. On GDPval-AA v2.1, Sonnet 5.5 scores 1844 and Opus 5.5 scores 1846.
CellCog adds that Anthropic still calls Opus 5.5 clearly stronger on complex, open-ended work. The same outlet lists a maximum output of 128K tokens (300K on the Batch API, in beta) and a June 2026 knowledge cutoff. It also reports that Sonnet 5.5 is the first Sonnet-tier model to launch with the cyber safeguards Anthropic otherwise keeps for its top models.
Auto mode is the starting mode on every plan and provider
The change applies to interactive terminal and VS Code sessions with no permission mode configured. If you have set permissions.defaultMode, your setting still wins. Auto mode's prompt before a read outside the working directories also gets a third answer. "Yes, but ask again next time" approves that one read and keeps asking about later ones.
Two safety changes ship alongside it. When a Sonnet model's safeguards flag a message, the notice now explains why and offers to edit and retry. Some sessions pin an Opus model through ANTHROPIC_DEFAULT_OPUS_MODEL or modelOverrides. On the Anthropic API, safety-related model switches in those sessions now go to the model the API picks for each kind of flag, not to the pinned model.
Gateway spend limits now read like "$271.40 / $500.00 spent this month"
If your organization runs the Claude apps gateway, /usage and the status line now show the spend limit in dollars, as long as the gateway runs this version or later. The status line's rate_limits.spend_limit field gains used_usd, limit_usd and period. The gateway also accepts request headers up to 256 KiB. That fixes the 431 errors that blocked every request from users whose identity provider lists many groups.
Ultracode is now its own toggle in /effort, which you reach with Tab or /effort ultracode [on|off]. It no longer forces xhigh effort and stays on at any effort level. Three new keybinding actions, effortSlider:decreaseEffort, increaseEffort and toggleUltracode, let you rebind the slider's keys in keybindings.json. In VS Code the same switch sits under the Effort slider, and the model pill shows "· Ultracode".
Compaction runs a second time when a request is still too long
Several fixes target turns that used to end in an error. If a request is still too long after compacting, Claude Code compacts again and keeps less of the recent conversation. An overloaded or server error right after a thinking block now gets a retry. A damaged response stream is retried or reported as interrupted, instead of showing "JSON Parse error" or writing "undefined" into an answer.
MCP gets two changes. The new /mcp reconnect all retries every server that failed to connect or needs authentication. In a resumed session, a tool call now waits up to 10 seconds for a server that is still connecting. One change goes the other way: retries after a connection drops mid-response now share a single budget with the request's other retries, so a failing request gives up sooner.
In auto mode, a second model reviews each action instead of you
According to the Claude Code docs, manual mode (config value default) stops and asks you before most actions that edit files, run shell commands or reach the network. In auto mode, a second model that the docs call the classifier reviews those actions in your place, with safety checks running in the background. It works like a front desk that decides which deliveries go upstairs, so the tenant doesn't have to answer every knock.
The docs treat reads outside the working directories as a special case. While permissions.blockReadsOutsideWorkingDirectories is on, recognized file-reading Bash commands still prompt, even in auto mode and bypassPermissions mode. So does any unsandboxed retry that needs approval to run outside that scope. The new "ask again next time" answer appears in exactly this prompt.
The release notes describe the new default but give no figures on how often the classifier approves something a person would have refused. The Sonnet 5.5 benchmark numbers here come from CellCog's reading of Anthropic's table, not from the notes. In our view, approving a single read is the right size of exception for a default that now applies on every plan: you can look outside the working directory once without granting that access for good.
Before auto mode reaches your team
The release notes give no date for the next build and don't say whether Anthropic will reconsider the auto default. If you'd rather keep approving actions yourself, set permissions.defaultMode now, because it still overrides the new default. Gateway admins only get the dollar figures once the gateway itself runs this version or later, so check which version your gateway runs.
Related stories
- Leaks put Claude Sonnet 5.5 at $2 input, release next week
- Opus 5.5 takes the default seat in Claude Code
- Leak puts expandable usage limits in Claude Code desktop
- Claude Code gets a wrap-up budget at the 5-hour limit
- Two Claude Code sessions ate 32% of a team's bill
- Claude Code cloud sessions go GA with credit outside limits
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
