{"version":"2.1.288","anchor":"mcp-step-up-auth-tracks-server-answers","canonical_anchor":"mcp-step-up-auth-tracks-server-answers","heading":"MCP sign-in now notices when a server asks for more permission","tier":"notice","area":"MCP","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/mcp-step-up-auth-tracks-server-answers","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### MCP sign-in now notices when a server asks for more permission\n\nClaude Code now checks each MCP server sign-in response for a missing-permission answer and returns the server's real response\n\n**Unclear.** It is not shown where the step-up dialog switch is read, so the link between this change and that dialog is unconfirmed.\n\n**What**\n\nMCP servers are outside programs that give Claude Code extra tools, and some require you to sign in through OAuth, a standard login and permission system. When Claude Code sends one of these signed-in requests, it now checks every answer the server sends back. Two answers are marked as meaning the current sign-in is not enough:\n\n- a 401 response, which means not authorised\n\n- a 403 response that reports `insufficient_scope`, which means the sign-in lacks a permission the server needs\n\nThis part of the code also had a fault: it returned an out-of-date value instead of the server's real response. It now returns the actual response.\n\n**Why**\n\nThese answers are what a \"step-up\" sign-in would act on. Step-up means asking you to grant more permission when a server says your current login does not cover the request. A server-side switch for a step-up sign-in dialog read as on for this site's account and for an anonymous check, first seen on 2026-09-29.\n\n- Flag `tengu_mcp_step_up_auth_dialog`: On for this account, and not off by default (read for one account on one subscription tier against v2.1.288; this account: on, anonymous baseline: on, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: MCP\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}