Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.219 Home All releases olderv2.1.218 v2.1.220newer
Claude Code v2.1.219

MCP allow/deny rules compare expanded env-var values

You'll notice
Useful3 Signal0
MCP

Your MCP allow and deny rules now match servers whose commands or URLs use environment variables.

allowedMcpServersdeniedMcpServers
What

Matching a server against allowedMcpServers and deniedMcpServers now expands environment-variable references in the configured command and URL before comparing, so rules match what actually runs rather than the literal template.

Details
  • The deny path uses a fallback env when expansion needs one.
  • An allow-rule URL whose expansion is flagged unsafeExpansion is skipped rather than treated as a match.
  • A separate new validator flags untrimmed whitespace in MCP config command, url, args, and env/header names and values.
Evidence

unsafeExpansion

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.219 →