{"version":"2.1.287","anchor":"org-mcp-permission-maps-now-validated-and-null-prototype","canonical_anchor":"org-mcp-permission-maps-now-validated-and-null-prototype","heading":"Unrecognized MCP permission values in organization policy now block the server","tier":"notice","area":"MCP","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/org-mcp-permission-maps-now-validated-and-null-prototype","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Unrecognized MCP permission values in organization policy now block the server\n\nAn organization policy value for an MCP server's maximum permission that Claude Code does not recognize is now treated as blocked\n\n**What**\n\nAn organization's policy can set the most permission each MCP server is allowed. MCP servers are add-ons that give Claude extra tools. Claude Code now checks each of these values. Any value it does not recognize is treated as \"blocked\", where before the raw value was copied as it was. The lists of permissions per server are also now built so that a server with an unusual name, such as `__proto__`, cannot interfere with them.\n\n**Why**\n\nA typo or an unexpected value in policy now fails closed. The server is blocked instead of getting whatever that value would have allowed.\n\n- Area: MCP\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}