{"name":"tengu_mcp_step_up_auth_dialog","slug":"tengu-mcp-step-up-auth-dialog","family":"flag","title":"Feature flags","noun":"feature flag","description":"Claude Code can offer to sign in to an MCP server again with wider permissions when a tool call is refused for missing scope","description_source":"entry","described_by":{"version":"2.1.281","anchor":"mcp-step-up-re-authentication-prompt-for-403-insufficient-sc"},"presence":{"first_seen":"2.1.281","removed_in":null,"in_current_build":true,"newest_mined":"2.1.283","builds":3,"mined_builds":126,"first_cited":{"version":"2.1.281","released_at":"2026-09-23 17:01:17","spans":1}},"aliases":[],"entries":[{"version":"2.1.281","anchor":"mcp-step-up-re-authentication-prompt-for-403-insufficient-sc","heading":"MCP step-up re-authentication prompt for 403 insufficient_scope (dark-launched)","line":"Claude Code can offer to sign in to an MCP server again with wider permissions when a tool call is refused for missing scope","released_at":"2026-09-23 17:01:17","reason":"gate cited by this entry, found in this entry's text"},{"version":"2.1.281","anchor":"mcp-tool-calls-can-ask-for-consent-and-re-authenticate-when","heading":"MCP tool calls can ask for consent and re-authenticate when a server returns 403 insufficient_scope (gated off)","line":"MCP tool calls refused for missing permissions can prompt you to sign in again and retry, behind a gate","released_at":"2026-09-23 17:01:17","reason":"gate cited by this entry, found in this entry's text"}],"entries_total":2,"docs":[],"docs_total":0,"gates":[{"version":"2.1.281","state":"off","account":false,"baseline":false,"code_default":false}],"related":[{"name":"tengu_mcp_auto_background","slug":"tengu-mcp-auto-background","description":null},{"name":"tengu_mcp_cgroup","slug":"tengu-mcp-cgroup","description":"On Linux you can force MCP servers into their own memory cgroup with an environment variable."},{"name":"tengu_mcp_claudeai_eligibility_gate","slug":"tengu-mcp-claudeai-eligibility-gate","description":null},{"name":"tengu_mcp_claudeai_proxy_401","slug":"tengu-mcp-claudeai-proxy-401","description":"MCP proxy 401 telemetry now sanitizes the error code before logging it"},{"name":"tengu_mcp_cli_command_executed","slug":"tengu-mcp-cli-command-executed","description":null},{"name":"tengu_mcp_connect_timeout_retry","slug":"tengu-mcp-connect-timeout-retry","description":"MCP connect timeouts now respect the global timeout and get retried instead of failing."},{"name":"tengu_mcp_degraded","slug":"tengu-mcp-degraded","description":"MCP events are forwarded for logging with identifying fields stripped, and skipped entirely if analytics are off."},{"name":"tengu_mcp_delete","slug":"tengu-mcp-delete","description":"MCP CLI commands now hash server names in telemetry instead of sending them raw."},{"name":"tengu_mcp_directory_bff","slug":"tengu-mcp-directory-bff","description":null},{"name":"tengu_mcp_directory_visibility","slug":"tengu-mcp-directory-visibility","description":null}],"url":"https:\/\/changelogs.core-directive.com\/reference\/flag\/tengu-mcp-step-up-auth-dialog","family_url":"https:\/\/changelogs.core-directive.com\/reference\/flag.json"}