Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Stricter approvals for MCP tools in remote sessions and on the session's desktop

MCP tools that may act on the session's desktop now ask every time, and remote-session MCP tools cannot be always-allowed

Group of 3 You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Auto ModeArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear What the "arbiter" mode corresponds to for users is unclear.

What

MCP tools are tools supplied by outside servers that Claude can call. Claude Code tightens when these can run without asking you.

  • Some MCP tools are now marked as able to act on the session's desktop. Each call to one asks for approval, with the message "may act on this session's desktop, so each call is reviewed; allow rules, hooks and plugins cannot approve it." The option to always allow it is not offered, though the automatic classifier can still approve it. A specific allowlisted server and tool pair is exempt.
  • In remote sessions, when an MCP tool asks for approval, the option to always allow it is not offered.
  • In a remote session (CLAUDE_CODE_REMOTE set) using the "arbiter" mode with tengu_buzzing_pelican on, a hook's approval of an MCP tool is sent to the auto-mode classifier, a check that decides whether the action is safe, instead of being final, and always-allow rules are ignored. Nothing has been read about tengu_buzzing_pelican yet.
  • The existing check tied to tengu_cowork_auto_mode_include_allowed_write_mcp now reports whether it applied because of server policy or because of a remote session. The flag server returned on for this site's account and for the anonymous baseline; no reading has been taken under this release.

Why

Tools that could act on a desktop can no longer be waved through by a saved rule, a hook or a plugin, so you see each call. In remote sessions, a single "always allow" no longer covers future MCP calls. Expect more approval prompts where these tools are used.

Read from
Feature flag
tengu_buzzing_pelican Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.290: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

tengu_virtual_knuth Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.290: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.290. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat the "arbiter" mode corresponds to for users is unclear.
The name it cites is new in this buildNew in this build: tengu_buzzing_pelican

See this entry in the whole of v2.1.290 →

Feedback