Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

MCP sign-in now notices when a server asks for more permission

Claude Code now checks each MCP server sign-in response for a missing-permission answer and returns the server's real response

You'll notice Improvements
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
MCPArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release
What

MCP servers are outside programs that give Claude Code extra tools, and some require you to sign in through OAuth, a standard login and permission system. When Claude Code sends one of these signed-in requests, it now checks every answer the server sends back. Two answers are marked as meaning the current sign-in is not enough:

  • a 401 response, which means not authorised
  • a 403 response that reports insufficient_scope, which means the sign-in lacks a permission the server needs

This part of the code also had a fault: it returned an out-of-date value instead of the server's real response. It now returns the actual response.

Why

These answers are what a "step-up" sign-in would act on. Step-up means asking you to grant more permission when a server says your current login does not cover the request. A server-side switch for a step-up sign-in dialog read as on for this site's account and for an anonymous check, first seen on 2026-09-29.

Read from
Feature flag
tengu_mcp_step_up_auth_dialog On for this account, and not off by default

The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.

This account: on · anonymous baseline: on · compiled default in v2.1.288: on

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not shown where the step-up dialog switch is read, so the link between this change and that dialog is unconfirmed.

See this entry in the whole of v2.1.288 →

Feedback