Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.278 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.260 ·

MCP toolPolicy simplified: ask-session mode dropped from the wildcard rule docs

MCP toolPolicy docs and wildcard logic were simplified by dropping the ask-session case.

TierUnder the hoodhow much it should matter to you
Useful1my rating, 1 to 5
Signal1worth watching, 1 to 5
AreaMCPwhat it touches
KindImprovementsin v2.1.260,
Under the hood

MCP toolPolicy docs and wildcard logic were simplified by dropping the ask-session case.

The long-form docs for managedMcpServers' toolPolicy were rewritten and simplified. The previous documentation of an "ask-session" clamp — session-scoped "Allow for this task" tool approval with special wildcard precedence rules — no longer appears, and the wildcard precedence logic itself was simplified to remove the special ask-session case.

Read from
Names in the bundletoolPolicy
What the documentation says
Documented inclaude-code/desktop
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up toolPolicy, on MCP, plugins, skills, and hooks. | `.mcp.json` | MCP servers bundled with this plugin. A JSON object keyed by server name: `{"mcpServers": {"<name>": {"type": "http", "url": "...", "oauth": true}}}`. A remote entry uses `type` (`http` or `sse`), not `transport`, and suppo… third-party/claude-desktop/extensions see the edit
How sure we are
Two sources agreeTwo things we can check say the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up toolPolicy, on MCP, plugins, skills, and hooks.
Anthropic's release notes agreeChanged Claude apps gateway to also refuse to start, naming the field, when a desktop policy misspells a field in a nested object of a…

See this entry in the whole of v2.1.260 →