Unclear What Claude Code does when the managed MCP server list fails to be read is not shown.
What
Organisations can supply MCP servers to every user through managedMcpServers in managed settings. MCP servers are outside programs that give Claude extra tools. This release changes how that list is read and enforced.
- If the list cannot be parsed, the fallback is now
MANAGED_MCP_SERVERS_PARSE_FAILEDinstead of an empty list, and the tool policy becomes{'*':'blocked'}, which blocks every server. - Policy is now matched to a server by its identity, its url or name, and merges in settings from organisation plugins.
- An entry can use the transport
MCP_TRANSPORT_POLICY_ONLY. Such entries only carry policy. They are left out when Claude Code collects the network hosts it must reach, and an exported helper filters them out. - The helper that works out those hosts was replaced. Custom web search URLs now use
singleHostEgressand GitHub hosts useegressAddress.
Why
A broken managed server list now locks MCP servers down instead of leaving them unrestricted. If MCP tools suddenly stop working in a managed setup, check that the managed settings file is valid.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
What Claude Code does when the managed MCP server list fails to be read is not shown.