Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

MCP step-up re-authentication prompt for 403 insufficient_scope (dark-launched)

Claude Code can offer to sign in to an MCP server again with wider permissions when a tool call is refused for missing scope

Nothing to try yet Notable In Development
JSON All of v2.1.281
Nothing to try yetTier: how much it should matter to you
5Useful: my rating, 1 to 5
4Signal: worth watching, 1 to 5
MCPArea: what it touches
In DevelopmentKind: in v2.1.281,
What probably matters to youSection of the release
What

An MCP server is an outside service that gives Claude extra tools. Some of these servers use OAuth, a sign-in flow in your browser that grants Claude Code a set of permissions called scopes. A new flow handles the case where a tool call to such a server over HTTP is refused because the sign-in lacks a scope the server names. Claude Code can ask "Re-authenticate now?", run the sign-in again asking for the wider scope, and then reconnect to the server. If several refusals from the same server arrive together, they share one prompt.

The prompt is not shown in several cases, including:

  • subagents, which are helper agents Claude starts for part of a task
  • non-interactive sessions, where nobody is there to answer
  • XAA-OAuth servers

The prompt is controlled by the tengu_mcp_step_up_auth_dialog gate, a server-side switch. In readings taken before this release, the flag server returned it off for this site's account and for an anonymous baseline.

Why

Once in use, this would let you fix a missing-permission error by signing in again from the prompt instead of removing and re-adding the server.

Read from
Feature flag
tengu_mcp_step_up_auth_dialog Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.281: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.281. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
One source agreesOne thing we can check says the same as this entry.
The name it cites is new in this buildNew in this build: tengu_mcp_step_up_auth_dialog

See this entry in the whole of v2.1.281 →

Feedback