{"version":"2.1.281","anchor":"mcp-step-up-re-authentication-prompt-for-403-insufficient-sc","canonical_anchor":"mcp-step-up-re-authentication-prompt-for-403-insufficient-sc","heading":"MCP step-up re-authentication prompt for 403 insufficient_scope (dark-launched)","tier":"soon","area":"MCP","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/mcp-step-up-re-authentication-prompt-for-403-insufficient-sc","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### MCP step-up re-authentication prompt for 403 insufficient_scope (dark-launched)\n\nClaude Code can offer to sign in to an MCP server again with wider permissions when a tool call is refused for missing scope\n\n**What**\n\nAn MCP server is an outside service that gives Claude extra tools. Some of these servers use OAuth, a sign-in flow in your browser that grants Claude Code a set of permissions called scopes. A new flow handles the case where a tool call to such a server over HTTP is refused because the sign-in lacks a scope the server names. Claude Code can ask \"Re-authenticate now?\", run the sign-in again asking for the wider scope, and then reconnect to the server. If several refusals from the same server arrive together, they share one prompt.\n\nThe prompt is not shown in several cases, including:\n\n- subagents, which are helper agents Claude starts for part of a task\n\n- non-interactive sessions, where nobody is there to answer\n\n- XAA-OAuth servers\n\nThe prompt is controlled by the `tengu_mcp_step_up_auth_dialog` gate, a server-side switch. In readings taken before this release, the flag server returned it off for this site's account and for an anonymous baseline.\n\n**Why**\n\nOnce in use, this would let you fix a missing-permission error by signing in again from the prompt instead of removing and re-adding the server.\n\n- Flag `tengu_mcp_step_up_auth_dialog`: Off in both readings (read for one account on one subscription tier against v2.1.281; this account: off, anonymous baseline: off, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: MCP\n- Tier: Nothing to try yet\n- Useful: 5\/5\n- Signal: 4\/5\n- Present in the build but not switched on"}