Configuration file reference changedclaude-science/configuration-file-reference
Nearest release: v2.1.268, published under an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 10 Sep 2026 18:09 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+18added
Lines−18removed
From line
14
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits6to this page, all time
The whole hunk
from line 14, old and new numbered
/
from line 14
1414
1515The `[network]` table configures the app's own connections.
1616
17| Key | Type | Default | Effect |
18| ----------------- | ------------------------------------ | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
19| `proxy` | string (URL) | unset | The outbound proxy for the app's HTTP and HTTPS connections, for example `http://proxy.example.corp:8080`. Supply Basic-authentication credentials in the address. An `https://` (TLS-to-proxy) address applies to the app's own connections only; sandboxed package downloads connect directly when the proxy is `https://`, so prefer `http://`. A proxy variable in the app's environment (including `ALL_PROXY`) takes precedence over this key, which takes precedence over the Settings proxy field and the proxy detected from macOS or Windows system settings. |
20| `no_proxy` | string (comma-separated) | unset | Hosts that bypass the proxy, as exact hostnames or domain suffixes in one comma-separated string, for example `".example.corp,registry.example.corp"`. Combined with the `NO_PROXY` environment variable and, when the macOS or Windows system settings supply the proxy address, the system's bypass list. Loopback addresses always bypass the proxy. |
21| `ca_bundle` | string (absolute path) | unset | PEM file added to the app's default TLS trust for sign-in, the Claude API, Anthropic-hosted connectors, update checks, and [cloud storage](/docs/claude-science/cloud-storage) access from Settings (Amazon S3, S3-compatible stores, and Google Cloud Storage with an HMAC key); use it for a corporate root behind TLS inspection. It covers the app's own connections only, while package downloads use `[conda] ca_bundle`. The value must be an absolute path outside the app's data directory (`~/.claude-science`), temporary directories, and any directory you have granted Claude write access to; a system location such as `/etc/claude-science/corporate-ca.pem`, or a folder under `C:\ProgramData` on Windows, is recommended. The file must exist, parse as a PEM bundle, and contain no private key; a failing value is ignored with a warning. On Windows, when this key and `[conda] ca_bundle` are both unset, the roots in the computer's Trusted Root Certification Authorities store are trusted automatically instead. |
22| `mcp_x509_strict` | `"auto"`, `"relaxed"`, or `"strict"` | `"auto"` | How strictly local connectors check a corporate certificate's profile. With `"auto"`, Claude Science relaxes the strict check when it detects TLS inspection from a configured `[network] ca_bundle`. Connectors pick up a change at their next relaunch. |
17| Key | Type | Default | Effect |
18| - | - | - | - |
19| `proxy` | string (URL) | unset | The outbound proxy for the app's HTTP and HTTPS connections, for example `http://proxy.example.corp:8080`. Supply Basic-authentication credentials in the address. An `https://` (TLS-to-proxy) address applies to the app's own connections only; sandboxed package downloads connect directly when the proxy is `https://`, so prefer `http://`. A proxy variable in the app's environment (including `ALL_PROXY`) takes precedence over this key, which takes precedence over the Settings proxy field and the proxy detected from macOS or Windows system settings. |
20| `no_proxy` | string (comma-separated) | unset | Hosts that bypass the proxy, as exact hostnames or domain suffixes in one comma-separated string, for example `".example.corp,registry.example.corp"`. Combined with the `NO_PROXY` environment variable and, when the macOS or Windows system settings supply the proxy address, the system's bypass list. Loopback addresses always bypass the proxy. |
21| `ca_bundle` | string (absolute path) | unset | PEM file added to the app's default TLS trust for sign-in, the Claude API, Anthropic-hosted connectors, update checks, and [cloud storage](/docs/claude-science/cloud-storage) access from Settings (Amazon S3, S3-compatible stores, and Google Cloud Storage with an HMAC key); use it for a corporate root behind TLS inspection. It covers the app's own connections only, while package downloads use `[conda] ca_bundle`. The value must be an absolute path outside the app's data directory (`~/.claude-science`), temporary directories, and any directory you have granted Claude write access to; a system location such as `/etc/claude-science/corporate-ca.pem`, or a folder under `C:\ProgramData` on Windows, is recommended. The file must exist, parse as a PEM bundle, and contain no private key; a failing value is ignored with a warning. On Windows, when this key and `[conda] ca_bundle` are both unset, the roots in the computer's Trusted Root Certification Authorities store are trusted automatically instead. |
22| `mcp_x509_strict` | `"auto"`, `"relaxed"`, or `"strict"` | `"auto"` | How strictly local connectors check a corporate certificate's profile. With `"auto"`, Claude Science relaxes the strict check when it detects TLS inspection from a configured `[network] ca_bundle`. Connectors pick up a change at their next relaunch. |
2323
2424### Package download keys
2525
2626The `[conda]` table configures where analysis environments fetch packages from and how those downloads verify certificates.
2727
28| Key | Type | Default | Effect |
29| ----------------------- | ---------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
30| `channel_mirror` | string (URL) | unset | Base URL of an internal conda mirror. Channel names resolve beneath it, so `<channel_mirror>/conda-forge/noarch/repodata.json` must return the conda-forge index. Setting it removes the public conda hosts from the sandbox allowlist and admits the mirror host, which environment builds contact directly from the workstation, not through an outbound proxy. Must be `https://` on port 443 or 8443 (an `http://` URL is accepted only when `allow_insecure_mirror` is set), by DNS name, with no embedded credentials. A deployed value these rules reject prevents the app from starting. An [organization package mirror](/docs/claude-science/admin-controls#organization-package-mirror) set under **Organization settings** > **Claude Science** takes precedence over this key. |
31| `pip_index_url` | string (URL) | unset | A PEP 503 simple index for Python packages, for example an Artifactory or Nexus PyPI remote ending in `/simple`. Setting it removes the public Python hosts from the sandbox allowlist. Same URL rules as `channel_mirror`, including the startup failure on an invalid value, and the same precedence of an organization package mirror. |
32| `ca_bundle` | string (absolute path) | unset | A complete PEM bundle (public roots plus your corporate roots) that package downloads verify against, replacing the default trust list; in this release the bundle alone may not be sufficient for pip, which verifies against the operating system's trust store. On macOS and Linux this key affects package downloads only, and it never fixes sign-in; behind TLS inspection, set `[network] ca_bundle` as well. When unset, Linux uses your distribution's system certificate bundle. On Windows, package downloads verify against the Windows certificate store and do not read this key; leave it unset there unless you need a custom bundle, because a file set on Windows becomes the complete certificate list that code inside sessions trusts and turns off the app's automatic use of the Windows certificate store. Same path rules as `[network] ca_bundle`. |
33| `allow_insecure_mirror` | boolean | `false` | Allows `http://` mirror URLs in this file (the Settings page accepts `https://` only). Off by default because a plaintext mirror lets an on-path attacker substitute packages. |
34| `ssl_no_revoke` | boolean | `true` | Windows only. When `true`, conda package downloads skip the certificate-revocation check, which networks that inspect TLS usually cannot answer. Set it to `false` to require the check, so that a revoked or uncheckable certificate is rejected. pip downloads and the app's own connections are unaffected. |
28| Key | Type | Default | Effect |
29| - | - | - | - |
30| `channel_mirror` | string (URL) | unset | Base URL of an internal conda mirror. Channel names resolve beneath it, so `<channel_mirror>/conda-forge/noarch/repodata.json` must return the conda-forge index. Setting it removes the public conda hosts from the sandbox allowlist and admits the mirror host, which environment builds contact directly from the workstation, not through an outbound proxy. Must be `https://` on port 443 or 8443 (an `http://` URL is accepted only when `allow_insecure_mirror` is set), by DNS name, with no embedded credentials. A deployed value these rules reject prevents the app from starting. An [organization package mirror](/docs/claude-science/admin-controls#organization-package-mirror) set under **Organization settings** > **Claude Science** takes precedence over this key. |
31| `pip_index_url` | string (URL) | unset | A PEP 503 simple index for Python packages, for example an Artifactory or Nexus PyPI remote ending in `/simple`. Setting it removes the public Python hosts from the sandbox allowlist. Same URL rules as `channel_mirror`, including the startup failure on an invalid value, and the same precedence of an organization package mirror. |
32| `ca_bundle` | string (absolute path) | unset | A complete PEM bundle (public roots plus your corporate roots) that package downloads verify against, replacing the default trust list; in this release the bundle alone may not be sufficient for pip, which verifies against the operating system's trust store. On macOS and Linux this key affects package downloads only, and it never fixes sign-in; behind TLS inspection, set `[network] ca_bundle` as well. When unset, Linux uses your distribution's system certificate bundle. On Windows, package downloads verify against the Windows certificate store and do not read this key; leave it unset there unless you need a custom bundle, because a file set on Windows becomes the complete certificate list that code inside sessions trusts and turns off the app's automatic use of the Windows certificate store. Same path rules as `[network] ca_bundle`. |
33| `allow_insecure_mirror` | boolean | `false` | Allows `http://` mirror URLs in this file (the Settings page accepts `https://` only). Off by default because a plaintext mirror lets an on-path attacker substitute packages. |
34| `ssl_no_revoke` | boolean | `true` | Windows only. When `true`, conda package downloads skip the certificate-revocation check, which networks that inspect TLS usually cannot answer. Set it to `false` to require the check, so that a revoked or uncheckable certificate is rejected. pip downloads and the app's own connections are unaffected. |
3535
3636### Sandbox network keys
3737
3838The `[sandbox.network]` table adjusts the network allowlist the analysis sandbox enforces. Members see the same allowlist under **Settings** > **Network**.
3939
40| Key | Type | Default | Effect |
41| ----------------- | ---------------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
42| `enabled` | boolean | `true` | When `false`, code Claude runs has no network access: package installs and data fetches inside the analysis fail, while the app's own connections are unaffected. This is a no-network mode, not a way to skip the allowlist. |
43| `allowed_domains` | array of strings | `[]` | Domains added to the built-in allowlist, as exact hostnames or wildcards such as `*.example.org`. While the organization manages the [network allowlist](/docs/claude-science/admin-controls#network-allowlist) under **Organization settings** > **Claude Science**, these domains are set aside and the organization's list applies. |
44| `denied_domains` | array of strings | `[]` | Domains added to the built-in denylist. A denied domain is blocked even if it also appears on the allowlist, and the built-in denylist entries cannot be removed. |
40| Key | Type | Default | Effect |
41| - | - | - | - |
42| `enabled` | boolean | `true` | When `false`, code Claude runs has no network access: package installs and data fetches inside the analysis fail, while the app's own connections are unaffected. This is a no-network mode, not a way to skip the allowlist. |
43| `allowed_domains` | array of strings | `[]` | Domains added to the built-in allowlist, as exact hostnames or wildcards such as `*.example.org`. While the organization manages the [network allowlist](/docs/claude-science/admin-controls#network-allowlist) under **Organization settings** > **Claude Science**, these domains are set aside and the organization's list applies. |
44| `denied_domains` | array of strings | `[]` | Domains added to the built-in denylist. A denied domain is blocked even if it also appears on the allowlist, and the built-in denylist entries cannot be removed. |
4545
4646## Related resources
4747
No line in this hunk matches that.