Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260928T203705Z

5 pages moved out of 255 read.

Pages moved 5 significant first
Pages read 255 in this capture
Captured 20:37 UTC
Corpus hash 376bebf8977d corpus-hash

What this read moved

1-5 of 5

cowork/changelog Changed · +20 / -0 lines

from line 2
22 
33> Release notes for Claude Desktop
44 
5<Update label="v2.9939.4" description="2026-09-27">
6 Bundled Claude Code version: 2.1.284.
7 
8 **General**
9 
10 * Fixed sessions failing on every message with an API error caused by certain web search results or earlier extended thinking in the conversation's history.
11 
12 **Code**
13 
14 * Fixed the warning about a changed organization not appearing in sessions.
15 
16 **Cowork**
17 
18 * No user-facing changes.
19 
20 **3P**
21 
22 * No user-facing changes.
23</Update>
24 
525<Update label="v2.9939.2" description="2026-09-24">
626 Bundled Claude Code version: 2.1.281.
727 

government/security/security-and-data-handling Changed · +6 / -4 lines

from line 60
6060 
6161### Network egress, required domains, and proxies
6262 
63The desktop application and the sandbox honor the operating system's proxy settings, and a single allowlist controls outbound network access from Claude's tools. You manage the allowlist with the **Allowed network hosts** setting on the [Config](/docs/government/config/settings#allowed-network-hosts) page.
63The desktop application follows the operating system's proxy settings, and a single allowlist controls outbound network access from Claude's tools. You manage the allowlist with the **Allowed network hosts** setting on the [Config](/docs/government/config/settings#allowed-network-hosts) page.
6464 
6565<AccordionGroup>
6666 <Accordion title="What does the egress allowlist control?">
from line 68
6868 </Accordion>
6969 
7070 <Accordion title="Which domains does Claude Desktop need to reach?">
71 For configuration and model inference, the application reaches the Claude for Government service hostname provided to your agency during onboarding. Sign-in happens in the user's default browser, which must reach that same hostname, the Claude for Government sign-in service (a separate host that your Anthropic representative provides), and your agency's identity provider. See the network prerequisites in [Connect Claude Desktop to Claude for Government](/docs/government/deploy-desktop/configure#before-you-begin). Claude for Government does not publish IP addresses for its service and sign-in hosts, so allow both by hostname on port 443. The [IP addresses](https://platform.claude.com/docs/en/api/ip-addresses) page in the Claude API documentation covers the Claude API, not the Claude for Government hosts. Anthropic-bound telemetry endpoints are not contacted in Claude for Government. Allow `downloads.claude.ai` for the agent helper that runs Chat, Cowork, and Code sessions and for the sandbox virtual machine image, which the app fetches at session start when it does not already have them (not required if your agency uses the offline installer variant that bundles both), and `www.claudeusercontent.com` for the artifact preview frame. For automatic application updates, the required hosts depend on how your agency distributes the client; see the network-requirements table in [Telemetry and egress](/docs/third-party/claude-desktop/telemetry) and confirm the update hosts for your deployment before finalizing your allowlist.
71 For configuration and model inference, the application reaches the Claude for Government service hostname provided to your agency during onboarding. Sign-in happens in the user's default browser, which must reach that same hostname, the Claude for Government sign-in service (a separate host that your Anthropic representative provides), and your agency's identity provider. See the network prerequisites in [Connect Claude Desktop to Claude for Government](/docs/government/deploy-desktop/configure#before-you-begin). Claude for Government does not publish IP addresses for its service and sign-in hosts, so allow both by hostname on port 443. The [IP addresses](https://platform.claude.com/docs/en/api/ip-addresses) page in the Claude API documentation covers the Claude API, not the Claude for Government hosts. Anthropic-bound telemetry endpoints are not contacted in Claude for Government. Allow `downloads.claude.ai` for the agent helper that runs Chat, Cowork, and Code sessions and for the sandbox virtual machine image, which the app fetches at session start when it does not already have them (not required if your agency uses the offline installer variant that bundles both). The app also reaches the hosts listed under Non-essential services in [Required egress paths](/docs/third-party/claude-desktop/telemetry#required-egress-paths). If traffic is blocked, the app will run without icons, previews, and widgets. For automatic application updates, the required hosts depend on how your agency distributes the client; see the network-requirements table in [Telemetry and egress](/docs/third-party/claude-desktop/telemetry) and confirm the update hosts for your deployment before finalizing your allowlist.
7272 </Accordion>
7373 
7474 <Accordion title="Can administrators control when Claude Desktop updates?">
from line 88
8888 </Accordion>
8989 
9090 <Accordion title="Can all traffic route through a single proxy?">
91 Yes. Both the desktop application and the sandbox honor the operating system's proxy settings, including PAC URLs, and route all outbound traffic through your proxy. TLS inspection at your proxy should work; validate this in your environment before rollout. See [Network proxy](/docs/third-party/claude-desktop/network-proxy) for details. Web search requests pass through your proxy to the Claude for Government service, and the service's onward call to the search provider originates from inside the FedRAMP High boundary.
91 Yes, with a caveat for Linux. The desktop application follows the operating system's proxy settings, including PAC URLs, and so does the Cowork sandbox on macOS and Windows. On Linux, no proxy settings reach the Cowork sandbox, and its commands connect directly. See [Network proxy](/docs/third-party/claude-desktop/network-proxy#traffic-that-bypasses-the-app-proxy) for the traffic that bypasses the proxy.
92 
93 TLS inspection at your proxy should work; validate this in your environment before rollout. Web search requests pass through your proxy to the Claude for Government service, and the service's onward call to the search provider originates from inside the FedRAMP High boundary.
9294 </Accordion>
9395</AccordionGroup>
9496 
from line 142
140142 
141143<AccordionGroup>
142144 <Accordion title="Is there an inline DLP or inspection point?">
143 No. Claude for Government does not include an inline content-inspection or DLP gate. The available inspection points are your own network proxy, which sees all endpoint traffic, and the desktop's OpenTelemetry export, which sends tool-call metadata (tool name, connector, outcome, duration, and approval status) to your collector for after-the-fact review. You set the OpenTelemetry endpoint with **Telemetry endpoint** on the [Config](/docs/government/config/settings#telemetry-endpoint) page. The **Telemetry content capture** setting on the [Config](/docs/government/config/settings#telemetry-content-capture) page adds prompt, response, and tool content to the export for the categories you select, and nothing is selected by default. See [Telemetry and egress](/docs/third-party/claude-desktop/telemetry).
145 No. Claude for Government does not include an inline content-inspection or DLP gate. The available inspection points are your own network proxy, which sees the traffic routed through it, and the desktop's OpenTelemetry export, which sends tool-call metadata (tool name, connector, outcome, duration, and approval status) to your collector for after-the-fact review. You set the OpenTelemetry endpoint with **Telemetry endpoint** on the [Config](/docs/government/config/settings#telemetry-endpoint) page. The **Telemetry content capture** setting on the [Config](/docs/government/config/settings#telemetry-content-capture) page adds prompt, response, and tool content to the export for the categories you select, and nothing is selected by default. See [Telemetry and egress](/docs/third-party/claude-desktop/telemetry).
144146 </Accordion>
145147 
146148 <Accordion title="What is logged for connector actions and outbound requests?">

cowork/guide/plugins Changed · +2 / -2 lines

from line 27
2727 
2828<Steps>
2929 <Step title="Browse the marketplace">
30 Select **Discover** to see available plugins. The default marketplace
31 is Anthropic's official catalog; you can add other marketplaces by URL.
30 Select **Discover** to see available plugins. The default marketplace is
31 Anthropic's official catalog; you can add other marketplaces by URL.
3232 </Step>
3333 
3434 <Step title="Install">

government/deploy-desktop/windows-checklist Changed · +1 / -1 lines

from line 63
6363* **App traffic.** Allow Claude Desktop on every device to reach the Claude for Government host, which carries the app's configuration and chat traffic.
6464* **Browser sign-in traffic.** Allow the browser on every device to reach the Claude for Government host, the Claude for Government sign-in service (a separate host that your Anthropic representative provides), and your agency's identity provider. Sign-in happens in each user's default browser, not in the app.
6565* **`downloads.claude.ai`.** The app downloads two components from this host: the agent helper described under [Application control rules](#application-control-rules), which Chat, Cowork, and Code all need, and the Cowork workspace, which Cowork tasks and Advanced file analysis in Chat need. The app downloads each one whenever the device does not already have the version that the app needs, typically after an install or an app update. The offline installer includes both, so devices installed with it need this host only for application updates while automatic updates are on.
66* **`www.claudeusercontent.com`.** This host serves the frame that displays artifact previews.
66* **Hosts for icons, previews, and widgets.** For connector icons, the artifact preview frame, and the interactive widgets that some connectors display, the app reaches the hosts listed under Non-essential services in [Required egress paths](/docs/third-party/claude-desktop/telemetry#required-egress-paths), including `www.claudeusercontent.com` and `www.google.com`. If traffic is blocked, the app will run without icons, previews, and widgets.
6767* **Update hosts.** While [automatic updates](/docs/government/deploy-desktop/configure#automatic-updates) are on, also allow the hosts listed under Auto-updates in [Required egress paths](/docs/third-party/claude-desktop/telemetry#required-egress-paths). The telemetry rows there never apply, because Claude for Government does not send telemetry to Anthropic.
6868* **Hosts your tools and connectors use.** Allow the hosts you add to [Allowed network hosts](/docs/government/config/settings#allowed-network-hosts) (such as package registries), the addresses of any connectors you configure on the Config page (including Microsoft 365 if you set up that connector), and your telemetry collector if you set one.
6969* **Proxies.** The app and the Cowork workspace follow the operating system's proxy settings, including PAC files, as described under [Network proxy](/docs/third-party/claude-desktop/network-proxy). If your proxy inspects TLS, validate sign-in, a chat, and a Cowork task on a pilot device before rollout.

third-party/claude-desktop/configuration-changelog Changed · +4 / -0 lines

from line 4
44 
55Configuration keys by Claude Desktop release. Each section lists keys added in that release, with the MDM key name (for plist/registry deployment) and the equivalent JSON shape (for local-file or bootstrap remote configuration).
66 
7<Update label="v2.9939.4" description="2026-09-27">
8 No configuration changes in this release.
9</Update>
10 
711<Update label="v2.9939.2" description="2026-09-24">
812 **Changed:**
913 
Feedback