Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

MCP over HTTP: oversized responses no longer drop the connection

An MCP server response that is too large now fails only that request, and malformed messages after a login challenge get their own close reason

Group of 2 You'll notice Bug Fixes
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
MCPArea: what it touches
Bug FixesKind: in v2.1.288,
Bug FixesSection of the release

What

MCP (Model Context Protocol) servers connect Claude Code to outside tools and data. This change affects MCP servers reached over the http and claudeai-proxy transports. A transport is the way messages travel between Claude Code and the server.

  • An oversized response now raises a new kind of error and logs a message saying the server sent a response larger than a set number of MB. Claude Code stops reading it and fails the request it answered. The connection stays open.
  • If a malformed message arrives while an authentication challenge is open, the transport closes with the reason 'malformed message after an auth challenge'. An authentication challenge is a request from the server to log in. Before, every malformed response closed with 'malformed JSON-RPC message (response truncated)'.
  • The OAuth login provider now tracks whether an authentication challenge is open (authChallengeOpen).
  • The probe timeout is now passed through when connecting.

Why

One very large reply from an MCP server no longer cuts off the whole server, so its other tools keep working. When a connection breaks during a login step, the close reason now says so, which makes the problem easier to track down.

Read from
Feature flag
tengu_mcp_legacy_sse_fallback Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.288: on

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether the legacy SSE fallback switch plays any part in these changes.

See this entry in the whole of v2.1.288 →

Feedback