Claude Code 2.1.296: headless runs skip a switched-off MCP server
Claude Code 2.1.296 fixed claude -p starting a .mcp.json or plugin MCP server that was switched off. What that means for Sume's paid tools in CI.

Claude Code 2.1.296 (Oct 9, 2026) fixed headless sessions starting a folder's .mcp.json or plugin MCP server that had been switched off for that folder, after changing directory or reloading plugins. If you disabled Sume in a repo and a CI script still ran claude -p there, the server could connect in those cases before this fix; on 2.1.296 or later it stays off.
What the changelog says
The fix sits in the 2.1.296 notes next to the MCP description cap change. It concerns the on/off choice, not authentication, so it changes whether the server connects at all.
| Item | Detail | Source |
|---|---|---|
| Fixed in | 2.1.296, Oct 9, 2026 | Changelog |
| Symptom | headless sessions started a switched-off .mcp.json or plugin server after a directory change or plugin reload | Changelog |
| Interactive toggle | disabledMcpServers is a per-project opt-out list for user, plugin and managed servers and claude.ai connectors | MCP docs |
| Where /mcp choices are stored | disabledMcpServers in ~/.claude.json | MCP docs |
| Approval lists for .mcp.json | enabledMcpjsonServers / disabledMcpjsonServers, a separate pair | MCP docs |
Why it matters for a paid server
With an API key, Sume's hosted server exposes the full tool set, including paid tools such as generate_video and generate_image, per the tools and gates page. A headless run has no one to click Allow. A server you believed was off but that connected anyway meant a prompt in a script could reach tools you had meant to exclude.
Sume's own guards still hold in that case: paid calls need an idempotency_key, and max_spend_usd caps a call when you pass it. They are guards on a call, not a replacement for keeping the server disconnected.
A CI check that does not depend on the fix
Do not rely on a disable flag alone. For CI that must not spend, point the job at an explicit config and give it a read-only credential, so even a wrongly connected server cannot create paid work. Under OAuth mcp:read, write and paid tools are hidden and return insufficient_scope.
After upgrading, run a headless job in a folder where you switched Sume off, and have it print the tools it sees. A tool list containing generate_video means the server connected; an absent Sume entry means the fix is working. Then repeat in a folder where Sume is on and confirm that tools_list still answers, so you know the toggle works in both directions.
Sources
Related posts
More in Developers
- Claude Code 2.1.296 raises the MCP instructions cap to 4,096
Claude Code 2.1.296 doubled the default MCP instructions cap to 4,096 characters. Sume's server instructions are about 10,900, so the cap still applies.
- Clear a full Sume queue: cancel queued jobs after 429 queue_full
When submits fail with 429 queue_full, list queued jobs with GET /v1/jobs?status=queued and cancel the ones you no longer need. Safe on a 409, with a script.
- Empty job_id next to job_ids: how Sume MCP treats placeholders
Some agent clients fill every optional tool field with empty strings, zeros and empty arrays. What Sume's MCP drops, what it keeps, and what still errors.
- Crash-safe Sume submit: write the key first, reconcile on boot
If a worker dies between POST and saving the job id, list queued and processing jobs, match idempotency_key, and resubmit only keys still unknown.
Written by Sume