{"version":"2.1.286","anchor":"plugin-messages-can-carry-asuser-mcp-session-and-host-chat","canonical_anchor":"plugin-messages-can-carry-asuser-mcp-session-and-host-chat","heading":"Plugin messages, chat keys and MCP servers get new handling for remote sessions","tier":"internal","area":"Remote Control","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/plugin-messages-can-carry-asuser-mcp-session-and-host-chat","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Plugin messages, chat keys and MCP servers get new handling for remote sessions\n\nPlugin messages can be marked as coming from the user, a chat key format is now validated, and MCP servers can be refused or removed on remote workers\n\n**Unclear.** It is not clear what switches these paths on or what the user-only flags change in practice.\n\n**What**\n\nSeveral related pieces changed in how Claude Code handles messages and tool servers in sessions that run on remote machines, called workers:\n\n- Messages that come from a plugin now keep a flag saying whether they should be treated as coming from the user.\n\n- Consent checks for artifacts now take a flag limiting them to the user.\n\n- A host chat key in the form `chat:<uuid>` is now checked and reported as unset, malformed, ignored or used.\n\n- An MCP server (an outside program that gives Claude extra tools) can be refused with the message \"Not admitted: this name is reserved for a first-party server, and this entry cannot be added after session start\".\n\n- An MCP server can be removed with the message \"Removed: its per-tool limits are more than this worker can keep; it returns when the session next moves to another worker\".\n\n**Why**\n\nIf a tool server disappears or is refused during a remote session, these messages explain why: its name clashes with one of Anthropic's own servers, or it asks for more per-tool limits than the current worker supports.\n\n- Area: Remote Control\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5"}