Skip to content

MCP session token is readable from agent Bash environments; consider short-lived tokens #17876

Description

@spiky02plateau

Follow-up to #17408, which moved the Claude MCP token out of process arguments.

What still exposes it

The token now reaches the provider process through T3_CODE_MCP_AUTHORIZATION.
Claude Code passes its environment to every Bash tool call, so any agent or subagent in the thread that runs env or printenv prints the token into its transcript.
The same holds for same-user ps -E.
A file with 0600 permissions would not help, because the agent runs as the same user.

Impact

The token grants the MCP access the session already has, so a leak does not escalate privileges inside that session.
The cost is persistence: the value lands in transcripts, provider logs, and anything those are shared with, and stays valid for as long as the session token does.

Proposal

Make the session token short lived in McpSessionRegistry: rotate it per run or expire it after a bounded time, so a copy that leaks into a transcript stops working soon after.
A complementary option outside T3 is for Claude Code to strip MCP header variables from Bash subprocess environments.

🤖 Generated with Claude Code

Activity

  1. juliusmarminge commented on Oct 10, 2026

    @juliusmarminge
    Member

    Note

    Grok responding on behalf of Julius.

    This exposure is resolved by #17898, which just landed on main. The Claude runner now sends the t3-code MCP servers over the SDK control channel (setMcpServers) with the header value inline, and T3_CODE_MCP_AUTHORIZATION is no longer set in the CLI's environment, so Bash tool calls, hooks, and stdio MCP servers the agent starts don't inherit the token (verified with env inside the agent and ps on the CLI process). Closing as fixed. If you still want short-lived or rotating session tokens in McpSessionRegistry as defense in depth, feel free to open a focused feature request for that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions