{"version":"2.1.285","anchor":"mcp-serve-tool-calls-use-parsed-permission-context","canonical_anchor":"mcp-serve-tool-calls-use-parsed-permission-context","heading":"Tools offered through mcp serve can apply permissions and refuse calls","tier":"notice","area":"MCP","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/mcp-serve-tool-calls-use-parsed-permission-context","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Tools offered through `mcp serve` can apply permissions and refuse calls\n\nWhen Claude Code runs as an MCP server, tool calls can now carry permission settings and be refused with a message\n\n**Unclear.** What supplies these permission settings with each call is not clear.\n\n**What**\n\n`mcp serve` runs Claude Code as an MCP server. MCP (Model Context Protocol) is a standard way for one program to offer tools to another, so this lets other programs use Claude Code's tools.\n\nWhen a tool call arrives, Claude Code now uses permission settings passed in with the call, if there are any. It can refuse the call and send back a message saying why. Before, every call used default settings.\n\n**Why**\n\nPermission rules can now apply to tools that other programs call through `mcp serve`, not only to tools used directly inside Claude Code.\n\n- Area: MCP\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}