Claude Code 2.1.288 shipped October 2. Per the ClaudeKit rundown, the notables: /code-review --max-findings, restoring a Ctrl+C-cleared prompt with Up, mid-response API timeouts no longer killing the turn, and resume, auto, plugin, permission safeguard, and cloud session fixes.
This post goes deep on one item. When an MCP server demands an extra OAuth scope mid tool call, a re-auth prompt appears. It looks small but means a lot. Step-up authorization, re-checking scope at the moment of action instead of "connected means fully allowed," is entering at product level.
Background: MCP OAuth was always cranky
Claude Code issues show years of MCP OAuth pain. Google Workspace re-auths every session, Slack wipes tokens on one 401 and opens a browser, Atlassian never uses the refresh token it holds, and DCR mints fresh clients that pile up as server-side ghosts.
The pain kinds:
- re-auth every session (refresh tokens unused)
- multi-session desync (A works, B asks for auth)
- lying status (claude mcp list says Connected on expired tokens)
- full reconnect on drops (no re-auth button, disconnect first)
2.1.288 does not claim to fix all of it. But the direction is clear. Permission fixes now ship as a release pillar. Permission safeguards landing next to resume and timeout is the signal.
What changed: ask again at action time
Unpacking the core change.
Before: approve once at connect → everything on that link allowed
Now: extra scope mid tool call → re-auth prompt
→ permission = per-action check, not a one-time ticket
That is step-up authorization. Light permissions normally, stepped-up approval only on riskier actions. Same idea as banks re-asking OTP on transfers.
Step-up sample:
- reads (issue lookup): pass on the existing link
- writes (posting comments): first confirmation
- danger (deletes, deploys, payments, outside sends): scope re-check plus human sign-off
It locks exactly into layer 2 approvals from the four-layer security post. "Stop when hard to undo" arrives as product behavior.
Building your own MCP server: design it this way
The update's design hints, from the server builder side.
1. Never take wide scopes:
- split read, write, and danger scopes
- default link reads only, extra scopes on demand
2. Demand separate approval on danger actions:
- never check only "is OAuth linked"
- add a scope re-check path before deletes, outside sends, payments
3. Report status honestly:
- never say Connected on expired tokens
- expose "re-auth needed" as a state
4. Spend tokens carefully:
- use refresh tokens when held (no reissue loops)
- avoid duplicate DCR registrations (no ghost clients)
It matches the "open read-only first" order from the MCP comparison. This time Claude Code answers back: "we will ask again when it gets risky." Both sides meeting completes it.
What came along: review and recovery
The release's other fixes hit practice directly.
- /code-review --max-findings: cap finding counts (noise control)
- Ctrl+C recovery: Up restores a cleared prompt (mistake recovery)
- mid-response timeouts no longer kill turns (long-job survival up)
- background command limits apply to unattended sessions only (-p, SDK, CI, cloud)
The timeout fix especially points the Durable direction. Runtimes, not models, save long jobs. The review cap echoes the DeepsecBench lesson from the Cyber Index post: finding well beats finding lots.
CodeBridge Mini Lab: audit your MCP permissions
1. List MCP servers in use (local, remote, OAuth or not)
2. Tag each server:
[ ] Are scopes split read, write, danger
[ ] Do danger actions carry separate approval
[ ] Is expired and 401 behavior defined (no silent failure)
3. For servers you built:
- add a re-auth path on extra-scope demand
- expose status honestly (no Connected lies)
4. Upgrade to 2.1.288 and verify:
- tame review noise with /code-review --max-findings
- validate changed resume and timeout behavior on 1 long job
It adds one permission line to the verification loop from using Claude Code on real projects.
Conclusion: permission is a conversation, not a ticket
One line to close.
Approved once is not the end. Asking again whenever it gets risky is normal.
The 2.1.288 re-auth prompt looks like small UI, but it shows agent permission models maturing. Builders should walk the same way. Not wide-open trust, but narrowly opened and answered ask by ask. That is permission in the agent era.
Further reading
- Why you must not run agents without permissions in the computer-use era
- MCP vs Agents SDK vs WebMCP
- Using Claude Code on real projects
References
- ClaudeKit: Claude Code 2.1.288 (Oct 2, 2026)
- Claude Code Docs: Changelog
- MCPBundles: Claude Code MCP Commands
Go deeper with a course
To practice controlling agents through permission, approval, and verification flows, this course builds CLAUDE.md, skills, hooks, subagents, and MCP in real projects, exactly like the step-up design here.