What
MCP servers are outside tools Claude can connect to. Organisations can manage their setup through a managed config, whose allowed shape is set by a schema. The schema bundled in this release changes in several ways.
- A new
policy-onlyMCP transport sets the tool policy for a plugin's server without connecting to anything (exported asMCP_TRANSPORT_POLICY_ONLY, labelled "Tool permissions only (plugin server)"). - A
redirectHostoption for OIDC sign-in accepts127.0.0.1orlocalhost. An OAuth message now mentions a Google client forauthorizationServer. - The gateway resource field accepts AD FS relying-party identifiers (
audienceIdentifier). Fields also gainexecutionTargetmarkers. - New cloud-metadata and link-local host checks:
CLOUD_METADATA_IPV4,CLOUD_METADATA_IPV6,CLOUD_METADATA_HOSTS,CLOUD_METADATA_HOST_NAMESandisLinkLocalOrMetadataHost. Before, onlyisLoopbackHostandisSafeMcpCommandwere in this list. URLs can also reject query strings and fragments. - New helper-argument checks:
safeHelperArg,safeWindowsHelperPath,HELPER_ARG_UNSAFE_MESSAGEandhasNoHelperBreakoutChars, which point to rejecting arguments containing characters that could break out to the shell. - New filters and notes:
isPluginMcpToolPolicyUnreadable,isConnectableMcpEntry,connectableMcpServersandPLUGIN_MCP_TOOL_POLICY_CHANNEL_NOTE. The config reference module also exportsisEmptyRowValue.
Why
These checks point to blocking MCP or helper addresses that target cloud metadata or link-local addresses, which are special internal addresses on a network, and to filtering lists down to servers that can actually be connected. The schema is mostly for Claude Desktop admins and is bundled here, but it is not reachable from the command line.