MCP servers (Model Context Protocol servers, which give Claude extra tools) can refuse a tool call with an HTTP 403 error saying the login lacks a permission. The extra permission is named as a requestedScope. Claude Code can now respond by asking you:
"needs additional permissions for this tool ... Re-authenticate now?"
If you agree, it runs the OAuth sign-in again (the login flow many MCP servers use), reconnects to the server and retries the tool once. It only asks in these cases:
- HTTP MCP servers only
- Not servers using XAA
- Not calls made by a subagent (a helper Claude starts to handle part of a task)
- Not non-interactive sessions
- Not servers on a denylist
If several calls to the same server hit this at once, only one sign-in runs. Outcomes are reported under mcp_step_up_reauth. All of this sits behind the tengu_mcp_step_up_auth_dialog gate.
A tool that needs more access than you first granted can be fixed with one sign-in, so the call does not simply fail. The flag server returned tengu_mcp_step_up_auth_dialog off for this site's own account and for an anonymous baseline. No reading has been taken under this release yet.
tengu_mcp_step_up_auth_dialog Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.281: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.281. It isn't a statement about your account. What a flag value here can and cannot tell you
New in this build: tengu_mcp_step_up_auth_dialog