allowedMcpServersnow governs only servers users add, not managed ones. If your allowlist was keeping amanaged-mcp.jsonserver off, it will load on upgrade; usedeniedMcpServersto block it instead. (more below)- New
managedMcpServersmanaged setting lets organizations push HTTP/SSE MCP servers to every user. Command-based entries are skipped, so only remote (HTTP/SSE) servers can be distributed this way. --permission-prompts nonedenies anything that would prompt on unattended headless hosts. Your active permission mode still decides normally; this flag only catches what would otherwise block waiting for input no one will give.- Bash file-deny rules now cover option values (
-f.env),git diff/git grepfile operands, andcd && catcompounds. Second consecutive version tightening deny-rule coverage after 2.1.257's redirect and reader-command fix. (more below)
New in 2.1.259
2.1.259 (September 3, 2026)
- Added
managedMcpServersmanaged setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as.mcp.json); entries that name a command to run are skipped - Added
--permission-prompts nonefor unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps deciding - Added recognition of
glab mr create/merge/close/reopen/note/updateso GitLab merge requests show asMR !Nin the collapsed tool summary and refresh the footer MR badge - Added
--jsontoclaude plugin validatefor a machine-readable validation report - Fixed concurrent sessions silently reverting each other's
~/.claude.jsonchanges, workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at once - Fixed a conversation whose thinking was rejected once being rejected again on every later turn
- Fixed Bash
Read()deny rules not covering files given as option values (--ignore-revs-file=.env,-f.env,@file),git diff/git grepfile operands, orcd DIR && cat FILEcompounds;grep -r/cp -rover a directory holding a denied file now asks - Fixed the prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled
- Fixed fullscreen mode showing a blank conversation after a long turn with hundreds of tool calls
- Fixed auto mode running a turn on a model it doesn't support when a command or skill's frontmatter
model:named one; the turn now keeps the session model - Fixed
CLAUDE_CODE_MAX_CONTEXT_TOKENSbeing ignored for Vertex-style model IDs (@YYYYMMDDsuffix) of model versions Claude Code doesn't recognize - Fixed the live output preview of a running shell command hiding its newest lines when an earlier line wrapped
- Fixed a background GitHub connection check that ran on every launch for claude.ai users; the result is now remembered across launches
- Fixed
--resumefailing (and--continueopening an empty conversation) when a saved session contains an attachment entry with no payload - Fixed frontmatter
model:on custom commands and skills being ignored in interactive sessions - Fixed Artifact publishing failing once with an "unexpected parameter
note" error in conversations continued from an older version - Fixed managed
forceRemoteSettingsRefreshbeing ignored at startup when a policy helper configured by MDM or the managed settings file had already run - Fixed worktree isolation refusing hook-created worktrees on machines where
git rev-parsefails with a message other than "not a git repository" - Fixed OpenTelemetry metrics and events from cloud sessions missing the
user.email,organization.id, anduser.account_uuidattributes - Fixed MCP servers that disconnect while their tools are being listed at startup showing as connected with no tools instead of reporting the error
- Fixed the file edit permission dialog sometimes showing a changed line cut short with no indication
- Fixed repository detection dropping a known repo identity after a transient git probe failure
- Fixed managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value cannot be parsed: Claude Code now refuses to start and names the source
- Fixed Stop not actually stopping background agents and workflows in remote-control sessions: killed tasks now stay visible and re-stoppable until their processes exit
- Fixed resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents
- Fixed marketplace repo URLs on github.com with a trailing slash or dangling
?/#producing an unusable.gitclone URL - Fixed blocking Stop hooks causing the turn after a block to lose the model's reasoning from that turn and, on some models, miss the prompt cache
- Fixed remote (claude.ai) sessions taking 60 seconds to start a turn after a browser-hosted MCP server's page had gone away
- Fixed worktree-isolated sessions refusing common Bash loops, xargs pipelines and launcher-wrapped commands that cannot reach the main checkout
- Improved terminal resize and first-render performance for long responses by reusing text measurements
- Improved
/workflowsagent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle - Improved headless/SDK session start: the first turn begins up to 50 ms sooner when MCP servers finish connecting
- Improved
/install-github-appto explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repository - Improved nested background subagent results to be saved in the parent subagent's transcript, so resumed subagents keep them and shared transcripts show the delivery
- Changed
allowedMcpServersto govern only servers users add: a literalmanaged-mcp.jsonserver your allowlist used to filter out now loads on upgrade; usedeniedMcpServersto keep it off - [VSCode] Added an Active quick filter and a status filter menu (Needs input, Working, Completed) to the session list sidebar
- Fixed remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused
Notes
The managed MCP story now has three distinct levers. managedMcpServers (new in 2.1.259) pushes HTTP/SSE servers to every user in the organization. allowedMcpServers (semantics changed in 2.1.259) controls which servers users can add themselves. deniedMcpServers blocks specific servers regardless of source. The important migration detail: if your allowedMcpServers list was implicitly blocking a managed-mcp.json server by not including it, that server will now load on upgrade. The fix is to add it to deniedMcpServers explicitly.
Bash deny-rule tightening is now a two-version pattern. 2.1.257 fixed deny rules not applying to < file redirects and reader commands like tac and egrep. 2.1.259 extends coverage to option values (--ignore-revs-file=.env, -f.env, @file), git diff/git grep file operands, and cd DIR && cat FILE compounds. If you rely on deny rules to protect sensitive files (.env, credentials), these two versions together close a meaningful set of gaps. The pattern suggests Anthropic is systematically auditing every way a Bash command can reference a file path.