Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Unrecognized MCP permission values in organization policy now block the server

An organization policy value for an MCP server's maximum permission that Claude Code does not recognize is now treated as blocked

You'll notice Improvements
JSON All of v2.1.287
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
MCPArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What

An organization's policy can set the most permission each MCP server is allowed. MCP servers are add-ons that give Claude extra tools. Claude Code now checks each of these values. Any value it does not recognize is treated as "blocked", where before the raw value was copied as it was. The lists of permissions per server are also now built so that a server with an unusual name, such as __proto__, cannot interfere with them.

Why

A typo or an unexpected value in policy now fails closed. The server is blocked instead of getting whatever that value would have allowed.

How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeFixed organization per-tool permission ceilings being silently dropped for an MCP tool named __proto__

See this entry in the whole of v2.1.287 →

Feedback