Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.260 ·

URL schema now rejects credentialed URLs and gained an allowHttp option

MCP server URLs with embedded credentials are now rejected, and plain-http can be explicitly allowed.

TierYou'll noticehow much it should matter to you
Useful2my rating, 1 to 5
Signal1worth watching, 1 to 5
AreaMCPwhat it touches
KindImprovementsin v2.1.260,
You'll notice Notable No documentation found

MCP server URLs with embedded credentials are now rejected, and plain-http can be explicitly allowed.

The shared URL schema used for MCP server URLs and similar fields now rejects URLs containing embedded userinfo (user:pass@host), reporting a dedicated CREDENTIALED_URL_MESSAGE error. A new allowHttp option can be set on the schema to permit plain-http URLs beyond the existing loopback-http allowance.

Read from
Names in the bundleallowHttp

See this entry in the whole of v2.1.260 →

Feedback