Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-docs

Network proxy changedthird-party/claude-desktop/network-proxy

Nearest release: v2.1.261, published under an hour before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 4 Sep 2026 18:19 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.

Upstream edited
Recorded here
Lines+20added
Lines−20removed
From line 32 where the diff opens
First seen 2 Sep 2026 this site's first read of the page
Recorded edits4to this page, all time

The whole hunk

from line 32, old and new numbered
/
lines
from line 32
3232 
3333If you want the app, the agent, and (on macOS and Windows) Cowork's sandboxed shell to use a specific proxy regardless of what the device's OS settings say, set one of two managed configuration keys:
3434 
35| Key | Value | Effect |
36| ------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
37| `egressProxyUrl` | An `http://` or `https://` proxy URL, for example `http://proxy.example.com:8080` | The app sends its traffic through this proxy, and the agent receives it as `HTTPS_PROXY` and `HTTP_PROXY` in every session on the device. On macOS and Windows, commands in Cowork's sandboxed shell receive the same variables. Loopback and `.local` hosts still connect directly. |
35| Key | Value | Effect |
36| - | - | - |
37| `egressProxyUrl` | An `http://` or `https://` proxy URL, for example `http://proxy.example.com:8080` | The app sends its traffic through this proxy, and the agent receives it as `HTTPS_PROXY` and `HTTP_PROXY` in every session on the device. On macOS and Windows, commands in Cowork's sandboxed shell receive the same variables. Loopback and `.local` hosts still connect directly. |
3838| `egressProxyPacUrl` | An `http://` or `https://` URL to a PAC script, for example `http://wpad.example.com/proxy.pac` | The app evaluates the script per request. The agent receives the single proxy the script returns for your inference endpoint. On macOS and Windows, Cowork's sandboxed shell is handed a copy of the script when the sandbox starts and evaluates it per request itself. If both keys are set, this one wins. |
3939 
4040Both keys are read once at launch; a change takes effect the next time the app starts. While either key is set, the OS proxy settings are ignored for the app, the agent, and (on macOS and Windows) Cowork's sandboxed shell; with neither key set, the sandboxed shell keeps following the OS settings as described under [Default behavior](#default-behavior). SOCKS URLs and URLs with embedded credentials (`user:password@`) are rejected.
from line 63
6363 
6464The table summarizes which proxy source each kind of traffic follows. "App proxy" means the pinned key if one is set, otherwise the OS settings, with PAC rules applied per request.
6565 
66| Traffic | Proxy it follows |
67| ------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------- |
68| App window, in-app sign-in, connection test, model list | App proxy |
69| Inference requests from Chat, Cowork, and Code sessions | The single proxy resolved for the inference endpoint (from the pinned key or the OS), or Claude Code managed settings if deployed |
70| Agent web fetch, remote MCP servers, and plugin installs in Code sessions | Same single proxy as inference |
71| Web Fetch and managed MCP servers in Chat and Cowork sessions | App proxy (the app makes these connections) |
72| Plugin marketplace sync and `aws` CLI calls the app makes for Bedrock sign-in | App proxy, resolved for the specific host |
73| Cowork sandbox download from `downloads.claude.ai` | App proxy |
74| Telemetry and crash reports to Anthropic, if enabled | App proxy |
75| OpenTelemetry export to your collector | App proxy for the app's own events; the same single proxy as inference for Claude Code metrics and logs |
76| Commands in Cowork's sandboxed shell on macOS and Windows | The pinned key if one is set (a pinned PAC script is evaluated per request inside the sandbox), otherwise the OS proxy settings |
77| Commands in Cowork's sandboxed shell on Linux | None; commands connect directly |
78| The agent in an [SSH remote Code session](/docs/third-party/claude-desktop/ssh-remote-sessions) | None from the device; the remote host's own network route applies |
79| App update check and download | OS proxy settings only |
80| Credential helper and header helper scripts you configure | None injected; the script's own environment applies |
81| Brokered Microsoft Entra sign-in (Company Portal on macOS, Web Account Manager on Windows) | The OS broker's own settings |
82| Pages opened in the system browser | The browser's own settings |
66| Traffic | Proxy it follows |
67| - | - |
68| App window, in-app sign-in, connection test, model list | App proxy |
69| Inference requests from Chat, Cowork, and Code sessions | The single proxy resolved for the inference endpoint (from the pinned key or the OS), or Claude Code managed settings if deployed |
70| Agent web fetch, remote MCP servers, and plugin installs in Code sessions | Same single proxy as inference |
71| Web Fetch and managed MCP servers in Chat and Cowork sessions | App proxy (the app makes these connections) |
72| Plugin marketplace sync and `aws` CLI calls the app makes for Bedrock sign-in | App proxy, resolved for the specific host |
73| Cowork sandbox download from `downloads.claude.ai` | App proxy |
74| Telemetry and crash reports to Anthropic, if enabled | App proxy |
75| OpenTelemetry export to your collector | App proxy for the app's own events; the same single proxy as inference for Claude Code metrics and logs |
76| Commands in Cowork's sandboxed shell on macOS and Windows | The pinned key if one is set (a pinned PAC script is evaluated per request inside the sandbox), otherwise the OS proxy settings |
77| Commands in Cowork's sandboxed shell on Linux | None; commands connect directly |
78| The agent in an [SSH remote Code session](/docs/third-party/claude-desktop/ssh-remote-sessions) | None from the device; the remote host's own network route applies |
79| App update check and download | OS proxy settings only |
80| Credential helper and header helper scripts you configure | None injected; the script's own environment applies |
81| Brokered Microsoft Entra sign-in (Company Portal on macOS, Web Account Manager on Windows) | The OS broker's own settings |
82| Pages opened in the system browser | The browser's own settings |
8383 
8484## Traffic that bypasses the app proxy
8585 
Feedback