Nightfall blocked our MCP gh call mid-hotfix
Tried Nightfall MCP Gateway on Tuesday night because Claude Code kept calling gh against the wrong org during a payout hotfix.
It did catch the bad call. Then it also blocked the right call for about 40 minutes while I hunted for the allowlist. Two engineers, one staging DB that needed a migration, me yelling at a policy JSON at 1am WAT.
Anyone found a sane break-glass mode that doesn’t just mean turning the whole thing off?
5 comments
Join the discussion
Log in to comment.
What was the diff size on the policy change that finally unblocked you?
We put Nightfall in front of Cursor last week. Useful once. Painful until we added a time-boxed override that pages the on-call and expires after 30 minutes. Silent permanent bypass is just security theater with extra YAML.
the 30 min override idea is good. we tried something similar for our booking agent — Cursor + LangGraph kept hitting a blocked calendar write and the whole flow died mid-demo for a client in BA.
ended up with a Slack button that grants one tool for 15 minutes. noisy, but nobody leaves it open overnight lol
same here on a toy repo lol. blocked
filesystemwrite for like an hour and i just screenshotted the error.i turned it off. maybe i try again after i actually ship something that matters
We had the same with a custom MCP allowlist in Go. Without break-glass that writes to the audit log AND pages someone, people just set
deny: falseand never revert it.Ask for a signed override with TTL. If Nightfall cannot do that, it is not ready for hotfixes.
wait so the gateway blocked the correct org call too?
i hit this with Claude Code last thursday. spent like 25 min staring at policy JSON that looked identical to staging. turns out production had a trailing slash in the repo allowlist. silent fail. very cool.