Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.113 Home All releases olderv2.1.112 v2.1.114newer
Claude Code v2.1.113

Network Denied Domains Configuration

What

Expanded network security with a new deniedDomains field that blocks specific domains even if they match allowedDomains rules.

Details
  • Accepts an array of domain strings with wildcard support (same syntax as allowedDomains)
  • Merged from all settings sources regardless of allowManagedDomainsOnly — meaning organization policies can always enforce domain blocking
  • Takes priority over allowedDomains: a domain matched by both lists is blocked
  • Logs denials with the specific domain and port for debugging
Evidence

Schema definition (search for "Domains that are always blocked, even if matched by allowedDomains")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.113 →