inference-hooks-configuration changedmanage-claude/inference-hooks-configuration
Nearest release: v2.1.292, published 11 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+18added
Lines−4removed
From line
57
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits12to this page, all time
The whole hunk
from line 57, old and new numbered
/
from line 57
5757 | Result | What to check |
5858 | ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
5959 | URL rejected | The URL failed a structural check. Use an `https://` URL on port 443. |
60 | Private or internal IP | The host resolves to a private or internal address. Use a publicly routable host. |
60 | Private or internal IP | The URL's host is a private or internal IP address, an IPv6 address, or `localhost`. Use a publicly routable host. |
6161 | Timeout | The AI security server did not return a verdict within the timeout. |
62 | Transport error | DNS resolution, the TLS handshake, or the connection failed. |
62 | Transport error | DNS resolution, the TLS handshake, or the connection failed, or the hostname resolves to a private address. |
6363 | Non-200 status | The AI security server responded with a status other than 200. Verdicts must come back as HTTP 200; redirects are not followed and count as failures. |
6464 | Unparseable response | The AI security server responded, but the body is not a valid verdict. |
6565 | Signing secret required | Your organization has no signing secret, so the test would be sent unsigned. Click **Generate secret** under **Request signing**, then test again. |
from line 117
117117* **Failures per minute:** webhook failures over the last two minutes, averaged.
118118* **Block rate:** denials as a share of your AI security server's verdicts, shown while the rollout percentage is below 100.
119119* **Circuit breaker tripped:** when the breaker last tripped, if it has.
120* **Recent errors:** each entry is reduced to a timestamp, an error type, and a one-line reason. Entries never include request content or your endpoint URL.
120* **Recent errors:** each entry shows when the failure happened, an error type, and a category. The category is `webhook_error` for a problem with your endpoint or the connection to it, or `relay_error` for a failure inside Anthropic's systems. Entries never include request content or your endpoint URL. The list keeps the 10 most recent failures and clears an hour after the last one.
121121
122The error types in **Recent errors** mean:
123
124| Error shown | What it means | Counts toward the circuit breaker |
125| ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------- |
126| `DlpWebhookTimeoutError` · `webhook_error` | Your AI security server didn't return a verdict within the **Prompt verdict timeout (ms)** you set. | Yes |
127| `DlpWebhookStatusError` · `webhook_error` | Your AI security server answered with an HTTP status other than 200, such as a redirect. | Yes |
128| `DlpWebhookResponseError` · `webhook_error` | Your AI security server answered 200, but the body isn't a valid verdict or is larger than 64 KiB. | Yes |
129| `DlpWebhookTransportError` · `webhook_error` | The connection failed or dropped before a complete answer arrived: for example, the hostname didn't resolve or resolved to a private address, the connection was refused or reset, or the TLS handshake failed. A network problem on Anthropic's side can also show up this way. | No |
130| `DlpWebhookDisallowedAddressError` · `webhook_error` | The endpoint URL's host is a private or internal IP address, an IPv6 address, or `localhost`. A hostname that resolves to such an address shows as a transport error instead. | Yes |
131| `DlpWebhookBlockedError` · `webhook_error` | The endpoint URL isn't an `https://` URL on port 443, or can't be parsed, so no request was sent. | No |
132| `DlpWebhookRelayError` · `relay_error` | The failure was inside Anthropic's systems, and your AI security server usually wasn't contacted. | No |
133
134In shadow mode, no error counts toward the circuit breaker.
135
122136The panel is best-effort: if Anthropic cannot read the counters it shows zero failures and no errors rather than an error of its own, so a healthy-looking panel is not by itself proof that your AI security server is healthy. **Failures per minute** counts every failure, including the network and DNS errors that never trip the circuit breaker, so it can be high while **Circuit breaker tripped** stays empty.
123137
124138## Circuit breaker
from line 155
141155
142156## Audit trail
143157
144Inference hooks activity is recorded in your organization's [Activity Feed](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed): configuration changes, denials, circuit breaker trips, and requests that proceeded without inspection under your failure handling setting. While the circuit breaker is tripped, no per-request Inference hooks activities are recorded; the trip activity is the feed's record of that window. Denial records carry identifiers that let you join each denial to the matching record in your own system.
158Inference hooks activity is recorded in your organization's [Activity Feed](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed): configuration changes, denials, circuit breaker trips, and requests that proceeded without inspection because no verdict could be obtained. That last kind is recorded only while **Enforce verdicts** is on and **Mode** is **Allow the request**. Its reason is `endpoint_timeout`, `endpoint_error` for any other problem calling your AI security server, or `internal_error` for a failure on Anthropic's side. Under **Block the request** or **Shadow mode**, failed requests aren't recorded individually, and the circuit breaker's automatic recovery isn't recorded. While the circuit breaker is tripped, no per-request Inference hooks activities are recorded; the trip activity is the feed's record of that window. Denial records carry identifiers that let you join each denial to the matching record in your own system.
145159
146160## Turn Inference hooks off
147161
No line in this hunk matches that.