Network requirements changedclaude-science/network-requirements
Nearest release: v2.1.283, published an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 25 Sep 2026 17:38 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+44added
Lines−44removed
From line
12
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits9to this page, all time
The whole hunk
from line 12, old and new numbered
/
from line 12
1212
1313Every Claude Science install makes these connections, which travel through the member's outbound proxy and TLS inspection, so they need the proxy and corporate-certificate settings from the corporate networks page. All are outbound HTTPS on TCP 443.
1414
15| Domain | Required when | Purpose |
16| --------------------------------------- | --------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
17| `claude.ai` | Always | Browser-based sign-in, usage analytics, feature configuration, and the catalog of available connectors |
18| `platform.claude.com` | Always | Completing sign-in (the OAuth token exchange) |
19| `api.anthropic.com` | Always | The Claude API for every request Claude makes, plus account and usage information |
20| `o1158394.ingest.us.sentry.io` | When telemetry is on (the default) | Crash and error reporting (the error type and where it happened in Claude Science's own code, never error messages, conversation content, or research data); blocking it degrades diagnostics only |
21| `*.mcp.claude.com` | When members use the Anthropic-hosted connectors | PubMed, ClinicalTrials.gov, ChEMBL, and bioRxiv connectors |
22| `storage.googleapis.com` | When automatic updates are on | Update manifests and installers |
23| `downloads.claude.ai` | On Windows, at first launch and when an update changes it | The app window engine, the component that displays the app window |
24| `api.github.com`, `codeload.github.com` | When members import skills from a GitHub repository | Fetching the skill repository's contents |
15| Domain | Required when | Purpose |
16| - | - | - |
17| `claude.ai` | Always | Browser-based sign-in, usage analytics, feature configuration, and the catalog of available connectors |
18| `platform.claude.com` | Always | Completing sign-in (the OAuth token exchange) |
19| `api.anthropic.com` | Always | The Claude API for every request Claude makes, plus account and usage information |
20| `o1158394.ingest.us.sentry.io` | When telemetry is on (the default) | Crash and error reporting (the error type and where it happened in Claude Science's own code, never error messages, conversation content, or research data); blocking it degrades diagnostics only |
21| `*.mcp.claude.com` | When members use the Anthropic-hosted connectors | PubMed, ClinicalTrials.gov, ChEMBL, and bioRxiv connectors |
22| `storage.googleapis.com` | When automatic updates are on | Update manifests and installers |
23| `downloads.claude.ai` | On Windows, at first launch and when an update changes it | The app window engine, the component that displays the app window |
24| `api.github.com`, `codeload.github.com` | When members import skills from a GitHub repository | Fetching the skill repository's contents |
2525
2626Custom connectors and remote compute that members add reach whatever hosts they are configured with, so allow those case by case. Installs with telemetry turned off (see [Telemetry](/docs/claude-science/manage-on-devices#telemetry)) send no error reports, and blocking `o1158394.ingest.us.sentry.io` affects only error reporting, not the rest of the app.
2727
from line 29
2929
3030When Claude searches the scientific literature or retrieves full text, the app itself contacts these hosts over its own connections, which pass through your outbound proxy and TLS inspection like the app connections above, so the proxy must allow them even though several are also on the sandbox allowlist. Full-text downloads come from wherever the open-access copy of an article is hosted, so on a network that allows only listed hosts, expect retrieval of some full-text copies to fail; the domains below keep literature search and PubMed retrieval working.
3131
32| Domain | Required when | Purpose |
33| ------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------- |
34| `api.unpaywall.org` | When Claude retrieves full text | Locating open-access copies of articles |
35| `doi.org` | When Claude resolves a DOI | DOI resolution |
36| `eutils.ncbi.nlm.nih.gov`, `www.ncbi.nlm.nih.gov` | When Claude searches PubMed | PubMed/PMC article records and full-text files |
37| `api.semanticscholar.org`, `api.crossref.org` | When Claude searches the literature | Scholarly search and citation metadata |
38| `api.openalex.org` | When a member adds an OpenAlex API key | Validating the stored key |
39| `api.elsevier.com`, `api.springernature.com` | Only when the member has stored those publishers' API keys | Publisher full-text APIs |
32| Domain | Required when | Purpose |
33| - | - | - |
34| `api.unpaywall.org` | When Claude retrieves full text | Locating open-access copies of articles |
35| `doi.org` | When Claude resolves a DOI | DOI resolution |
36| `eutils.ncbi.nlm.nih.gov`, `www.ncbi.nlm.nih.gov` | When Claude searches PubMed | PubMed/PMC article records and full-text files |
37| `api.semanticscholar.org`, `api.crossref.org` | When Claude searches the literature | Scholarly search and citation metadata |
38| `api.openalex.org` | When a member adds an OpenAlex API key | Validating the stored key |
39| `api.elsevier.com`, `api.springernature.com` | Only when the member has stored those publishers' API keys | Publisher full-text APIs |
4040
4141## Analysis sandbox domains
4242
from line 48
4848
4949These domains supply Python, R, and system packages when Claude builds an analysis environment. Members can't turn them off. An organization that manages the allowlist can turn the CRAN and Bioconductor, npm, and GitHub domains off, and the PyPI and conda domains off once an organization package mirror replaces them.
5050
51| Domain | Purpose |
52| ----------------------------------------------------------------------------------------- | ----------------------------------------------- |
53| `pypi.org`, `*.pypi.org`, `files.pythonhosted.org` | Python packages from PyPI |
54| `conda.anaconda.org`, `repo.anaconda.com`, `anaconda.org`, `*.anaconda.org`, `*.conda.io` | conda packages |
55| `cran.r-project.org`, `cloud.r-project.org`, `bioconductor.org`, `www.bioconductor.org` | R packages from CRAN and Bioconductor |
56| `registry.npmjs.org` | npm packages for connectors that need them |
57| `github.com`, `*.github.com`, `*.githubusercontent.com` | Tools and packages published as GitHub releases |
51| Domain | Purpose |
52| - | - |
53| `pypi.org`, `*.pypi.org`, `files.pythonhosted.org` | Python packages from PyPI |
54| `conda.anaconda.org`, `repo.anaconda.com`, `anaconda.org`, `*.anaconda.org`, `*.conda.io` | conda packages |
55| `cran.r-project.org`, `cloud.r-project.org`, `bioconductor.org`, `www.bioconductor.org` | R packages from CRAN and Bioconductor |
56| `registry.npmjs.org` | npm packages for connectors that need them |
57| `github.com`, `*.github.com`, `*.githubusercontent.com` | Tools and packages published as GitHub releases |
5858
5959Claude Science itself does not require GitHub; the package manager ships inside the app. The GitHub domains are used only when a package Claude installs is published as a GitHub release or a member imports a skill from a GitHub repository, and blocking them fails only those operations.
6060
from line 66
6666
6767These groups are on by default. Members can turn them off during onboarding or anytime under **Settings** > **Network**. When the organization manages the allowlist, the organization's per-domain switches apply instead.
6868
69| Group | Domains |
70| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
71| NCBI and NIH | `*.ncbi.nlm.nih.gov`, `*.nih.gov`, `cactus.nci.nih.gov` |
72| Genomics and biology | `rest.ensembl.org`, `grch37.rest.ensembl.org`, `*.ensembl.org`, `reactome.org`, `*.reactome.org`, `rest.kegg.jp`, `*.kegg.jp`, `cellguide.cellxgene.cziscience.com`, `gnomad.broadinstitute.org`, `gtexportal.org`, `jaspar.elixir.no`, `www.encodeproject.org`, `mygene.info`, `rfam.org`, `www.cbioportal.org`, `sparql.rhea-db.org`, `bindingdb.org`, `www.bindingdb.org`, `r12.finngen.fi`, `pheweb.jp`, `api.genome.ucsc.edu`, `unibind.uio.no` |
73| Proteomics | `rest.uniprot.org`, `*.uniprot.org`, `string-db.org`, `*.string-db.org`, `*.ebi.ac.uk`, `search.foldseek.com`, `rcsb.org`, `*.rcsb.org`, `*.proteinatlas.org` |
74| Literature and citations | `api.semanticscholar.org`, `api.biorxiv.org`, `www.biorxiv.org`, `api.crossref.org`, `doi.org`, `api.openalex.org`, `arxiv.org`, `*.arxiv.org`, `api.grants.gov` |
75| Clinical and pharma | `api.fda.gov`, `clinicaltrials.gov`, `*.clinicaltrials.gov`, `api.clinpgx.org`, `api.platform.opentargets.org`, `cancer.sanger.ac.uk`, `actionability.clinicalgenome.org`, `search.clinicalgenome.org`, `erepo.genome.network`, `civicdb.org`, `www.antibodyregistry.org`, `cartblanche22.docking.org`, `files.docking.org` |
69| Group | Domains |
70| - | - |
71| NCBI and NIH | `*.ncbi.nlm.nih.gov`, `*.nih.gov`, `cactus.nci.nih.gov` |
72| Genomics and biology | `rest.ensembl.org`, `grch37.rest.ensembl.org`, `*.ensembl.org`, `reactome.org`, `*.reactome.org`, `rest.kegg.jp`, `*.kegg.jp`, `cellguide.cellxgene.cziscience.com`, `gnomad.broadinstitute.org`, `gtexportal.org`, `jaspar.elixir.no`, `www.encodeproject.org`, `mygene.info`, `rfam.org`, `www.cbioportal.org`, `sparql.rhea-db.org`, `bindingdb.org`, `www.bindingdb.org`, `r12.finngen.fi`, `pheweb.jp`, `api.genome.ucsc.edu`, `unibind.uio.no` |
73| Proteomics | `rest.uniprot.org`, `*.uniprot.org`, `string-db.org`, `*.string-db.org`, `*.ebi.ac.uk`, `search.foldseek.com`, `rcsb.org`, `*.rcsb.org`, `*.proteinatlas.org` |
74| Literature and citations | `api.semanticscholar.org`, `api.biorxiv.org`, `www.biorxiv.org`, `api.crossref.org`, `doi.org`, `api.openalex.org`, `arxiv.org`, `*.arxiv.org`, `api.grants.gov` |
75| Clinical and pharma | `api.fda.gov`, `clinicaltrials.gov`, `*.clinicaltrials.gov`, `api.clinpgx.org`, `api.platform.opentargets.org`, `cancer.sanger.ac.uk`, `actionability.clinicalgenome.org`, `search.clinicalgenome.org`, `erepo.genome.network`, `civicdb.org`, `www.antibodyregistry.org`, `cartblanche22.docking.org`, `files.docking.org` |
7676
7777### Optional compute integrations
7878
7979These domains matter only when a member turns on the matching integration.
8080
81| Domain | Required when | Purpose |
82| --------------------------------- | ------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
83| `health.api.nvidia.com` | When members enable NVIDIA-hosted BioNeMo inference | NVIDIA's hosted inference endpoint; a member can enter a different endpoint host when connecting BioNeMo under **Settings** > **Compute** |
84| `nvcr.io` | When members run NVIDIA NIM containers locally | Pulling NVIDIA container images |
85| `api.modal.com`, `*.w.modal.host` | When members connect a Modal account for remote compute | Modal's API and its dynamic worker hosts, reached from the member's machine |
81| Domain | Required when | Purpose |
82| - | - | - |
83| `health.api.nvidia.com` | When members enable NVIDIA-hosted BioNeMo inference | NVIDIA's hosted inference endpoint; a member can enter a different endpoint host when connecting BioNeMo under **Settings** > **Compute** |
84| `nvcr.io` | When members run NVIDIA NIM containers locally | Pulling NVIDIA container images |
85| `api.modal.com`, `*.w.modal.host` | When members connect a Modal account for remote compute | Modal's API and its dynamic worker hosts, reached from the member's machine |
8686
8787### Domains the sandbox always blocks
8888
from line 94
9494
9595Sign-in pages and interactive previews load in the member's web browser, so they are governed by your web-filtering policy rather than the outbound proxy or the sandbox allowlist. If your policy blocks these domains, sign-in pages fail to load or interactive previews render blank or broken.
9696
97| Domain | Purpose |
98| ----------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
99| `claude.ai` | The sign-in authorization page |
100| `console.anthropic.com` | The sign-in fallback page, which shows a one-time code the member pastes into the app when the browser cannot return to the app's local callback address |
101| `cdn.jsdelivr.net`, `esm.sh`, `unpkg.com`, `cdnjs.cloudflare.com` | JavaScript display libraries for interactive previews |
102| `3dmol.org`, `3dmol.csb.pitt.edu` | Molecular structure viewer |
103| `*.claudemcpcontent.com` | Isolated frames that display Claude's HTML previews and interactive connector output. A standard desktop install serves these frames from the app's own local address, so this entry matters mainly where members open Claude Science from a non-local address |
97| Domain | Purpose |
98| - | - |
99| `claude.ai` | The sign-in authorization page |
100| `console.anthropic.com` | The sign-in fallback page, which shows a one-time code the member pastes into the app when the browser cannot return to the app's local callback address |
101| `cdn.jsdelivr.net`, `esm.sh`, `unpkg.com`, `cdnjs.cloudflare.com` | JavaScript display libraries for interactive previews |
102| `3dmol.org`, `3dmol.csb.pitt.edu` | Molecular structure viewer |
103| `*.claudemcpcontent.com` | Isolated frames that display Claude's HTML previews and interactive connector output. A standard desktop install serves these frames from the app's own local address, so this entry matters mainly where members open Claude Science from a non-local address |
104104
105105## Related resources
106106
No line in this hunk matches that.