Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.293 ·

Managed MCP config adds a policy-only transport and stricter address and argument checks

The managed MCP config schema gains a policy-only transport, an OIDC redirectHost option, and checks for cloud-metadata hosts and unsafe helper arguments

Group of 2 Use it now New Features
JSON All of v2.1.293
Use it nowTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
New FeaturesKind: in v2.1.293,
What probably matters to youSection of the release

What

MCP servers are outside tools Claude can connect to. Organisations can manage their setup through a managed config, whose allowed shape is set by a schema. The schema bundled in this release changes in several ways.

  • A new policy-only MCP transport sets the tool policy for a plugin's server without connecting to anything (exported as MCP_TRANSPORT_POLICY_ONLY, labelled "Tool permissions only (plugin server)").
  • A redirectHost option for OIDC sign-in accepts 127.0.0.1 or localhost. An OAuth message now mentions a Google client for authorizationServer.
  • The gateway resource field accepts AD FS relying-party identifiers (audienceIdentifier). Fields also gain executionTarget markers.
  • New cloud-metadata and link-local host checks: CLOUD_METADATA_IPV4, CLOUD_METADATA_IPV6, CLOUD_METADATA_HOSTS, CLOUD_METADATA_HOST_NAMES and isLinkLocalOrMetadataHost. Before, only isLoopbackHost and isSafeMcpCommand were in this list. URLs can also reject query strings and fragments.
  • New helper-argument checks: safeHelperArg, safeWindowsHelperPath, HELPER_ARG_UNSAFE_MESSAGE and hasNoHelperBreakoutChars, which point to rejecting arguments containing characters that could break out to the shell.
  • New filters and notes: isPluginMcpToolPolicyUnreadable, isConnectableMcpEntry, connectableMcpServers and PLUGIN_MCP_TOOL_POLICY_CHANNEL_NOTE. The config reference module also exports isEmptyRowValue.

Why

These checks point to blocking MCP or helper addresses that target cloud metadata or link-local addresses, which are special internal addresses on a network, and to filtering lists down to servers that can actually be connected. The schema is mostly for Claude Desktop admins and is bundled here, but it is not reachable from the command line.

See this entry in the whole of v2.1.293 →

Feedback