{"version":"2.1.288","anchor":"dynamic-tool-hints-and-mcp-legacy-sse-fallback-context","canonical_anchor":"dynamic-tool-hints-and-mcp-legacy-sse-fallback-context","heading":"MCP over HTTP: oversized responses no longer drop the connection","tier":"notice","area":"MCP","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/dynamic-tool-hints-and-mcp-legacy-sse-fallback-context","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### MCP over HTTP: oversized responses no longer drop the connection\n\nAn MCP server response that is too large now fails only that request, and malformed messages after a login challenge get their own close reason\n\n**Unclear.** It is not clear whether the legacy SSE fallback switch plays any part in these changes.\n\n**What**\n\nMCP (Model Context Protocol) servers connect Claude Code to outside tools and data. This change affects MCP servers reached over the `http` and `claudeai-proxy` transports. A transport is the way messages travel between Claude Code and the server.\n\n- An oversized response now raises a new kind of error and logs a message saying the server sent a response larger than a set number of MB. Claude Code stops reading it and fails the request it answered. The connection stays open.\n\n- If a malformed message arrives while an authentication challenge is open, the transport closes with the reason 'malformed message after an auth challenge'. An authentication challenge is a request from the server to log in. Before, every malformed response closed with 'malformed JSON-RPC message (response truncated)'.\n\n- The OAuth login provider now tracks whether an authentication challenge is open (`authChallengeOpen`).\n\n- The probe timeout is now passed through when connecting.\n\n**Why**\n\nOne very large reply from an MCP server no longer cuts off the whole server, so its other tools keep working. When a connection breaks during a login step, the close reason now says so, which makes the problem easier to track down.\n\n- Flag `tengu_mcp_legacy_sse_fallback`: Not enough to say (read for one account on one subscription tier against v2.1.288; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: MCP\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}