{"version":"2.1.293","anchor":"managed-mcp-config-policy-only-transport-and-redirect-host","canonical_anchor":"managed-mcp-config-policy-only-transport-and-redirect-host","heading":"Managed MCP config adds a policy-only transport and stricter address and argument checks","tier":"use","area":"Managed Settings","scope":"both","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/managed-mcp-config-policy-only-transport-and-redirect-host","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Managed MCP config adds a policy-only transport and stricter address and argument checks\n\nThe managed MCP config schema gains a policy-only transport, an OIDC redirectHost option, and checks for cloud-metadata hosts and unsafe helper arguments\n\n**What**\n\nMCP servers are outside tools Claude can connect to. Organisations can manage their setup through a managed config, whose allowed shape is set by a schema. The schema bundled in this release changes in several ways.\n\n- A new `policy-only` MCP transport sets the tool policy for a plugin's server without connecting to anything (exported as `MCP_TRANSPORT_POLICY_ONLY`, labelled \"Tool permissions only (plugin server)\").\n\n- A `redirectHost` option for OIDC sign-in accepts `127.0.0.1` or `localhost`. An OAuth message now mentions a Google client for `authorizationServer`.\n\n- The gateway resource field accepts AD FS relying-party identifiers (`audienceIdentifier`). Fields also gain `executionTarget` markers.\n\n- New cloud-metadata and link-local host checks: `CLOUD_METADATA_IPV4`, `CLOUD_METADATA_IPV6`, `CLOUD_METADATA_HOSTS`, `CLOUD_METADATA_HOST_NAMES` and `isLinkLocalOrMetadataHost`. Before, only `isLoopbackHost` and `isSafeMcpCommand` were in this list. URLs can also reject query strings and fragments.\n\n- New helper-argument checks: `safeHelperArg`, `safeWindowsHelperPath`, `HELPER_ARG_UNSAFE_MESSAGE` and `hasNoHelperBreakoutChars`, which point to rejecting arguments containing characters that could break out to the shell.\n\n- New filters and notes: `isPluginMcpToolPolicyUnreadable`, `isConnectableMcpEntry`, `connectableMcpServers` and `PLUGIN_MCP_TOOL_POLICY_CHANNEL_NOTE`. The config reference module also exports `isEmptyRowValue`.\n\n**Why**\n\nThese checks point to blocking MCP or helper addresses that target cloud metadata or link-local addresses, which are special internal addresses on a network, and to filtering lists down to servers that can actually be connected. The schema is mostly for Claude Desktop admins and is bundled here, but it is not reachable from the command line.\n\n- Area: Managed Settings\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 3\/5\n- Scope: both\n- Heads-up: no"}