Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

No behaviour change to MCP policy exemptions in remote bypass mode

The rule that exempts MCP server policy denials in remote bypass-permissions sessions behaves the same as before

Under the hood Internal Changes
JSON All of v2.1.286
Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
0Signal: worth watching, 1 to 5
MCPArea: what it touches
Internal ChangesKind: in v2.1.286,
Internal ChangesSection of the release
What

This rule concerns remote sessions (CLAUDE_CODE_REMOTE) running in bypassPermissions mode, where Claude Code acts without asking permission. In those sessions, denials from the MCP server policy can be exempted when tengu_mcp_server_policy_bypass_exempt is on. Its built-in default is on unless it is switched off remotely. MCP servers are outside programs that give Claude Code extra tools.

Only internal names in this code changed. The logic is the same.

Why

In practice, nothing is different for users.

Read from
Feature flag
tengu_mcp_server_policy_bypass_exempt Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.286: on

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.286. It isn't a statement about your account. What a flag value here can and cannot tell you

What the documentation says
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up bypassPermissions, on Configure the sandboxed Bash tool. * **`bypassPermissions` mode**: the retry runs without a prompt sandboxing see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up bypassPermissions, on Configure the sandboxed Bash tool.

See this entry in the whole of v2.1.286 →

Feedback