Claude Code 2.1.296: headless runs skip a switched-off MCP server

Claude Code 2.1.296 fixed claude -p starting a .mcp.json or plugin MCP server that was switched off. What that means for Sume's paid tools in CI.

4 min readSume
All posts

Claude Code 2.1.296 (Oct 9, 2026) fixed headless sessions starting a folder's .mcp.json or plugin MCP server that had been switched off for that folder, after changing directory or reloading plugins. If you disabled Sume in a repo and a CI script still ran claude -p there, the server could connect in those cases before this fix; on 2.1.296 or later it stays off.

What the changelog says

The fix sits in the 2.1.296 notes next to the MCP description cap change. It concerns the on/off choice, not authentication, so it changes whether the server connects at all.

Claude Code changelog and MCP docs, read 2026-10-10
ItemDetailSource
Fixed in2.1.296, Oct 9, 2026Changelog
Symptomheadless sessions started a switched-off .mcp.json or plugin server after a directory change or plugin reloadChangelog
Interactive toggledisabledMcpServers is a per-project opt-out list for user, plugin and managed servers and claude.ai connectorsMCP docs
Where /mcp choices are storeddisabledMcpServers in ~/.claude.jsonMCP docs
Approval lists for .mcp.jsonenabledMcpjsonServers / disabledMcpjsonServers, a separate pairMCP docs

Why it matters for a paid server

With an API key, Sume's hosted server exposes the full tool set, including paid tools such as generate_video and generate_image, per the tools and gates page. A headless run has no one to click Allow. A server you believed was off but that connected anyway meant a prompt in a script could reach tools you had meant to exclude.

Sume's own guards still hold in that case: paid calls need an idempotency_key, and max_spend_usd caps a call when you pass it. They are guards on a call, not a replacement for keeping the server disconnected.

A CI check that does not depend on the fix

Do not rely on a disable flag alone. For CI that must not spend, point the job at an explicit config and give it a read-only credential, so even a wrongly connected server cannot create paid work. Under OAuth mcp:read, write and paid tools are hidden and return insufficient_scope.

After upgrading, run a headless job in a folder where you switched Sume off, and have it print the tools it sees. A tool list containing generate_video means the server connected; an absent Sume entry means the fix is working. Then repeat in a folder where Sume is on and confirm that tools_list still answers, so you know the toggle works in both directions.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume