The /sandbox status now shows whether the HTTPS inspection certificate is trusted and how to fix it.
What's wrong with this entry?
The sandbox status view now tells you if HTTPS interception is actually set up, and what to do when it isn't.
- Adds a "TLS inspection CA:" row rendering either "trusted" or "not trusted".
- When the untrusted CA is the managed one, the row suggests "· run /sandbox install".
- Otherwise it advises "· ask your administrator to trust the configured sandbox CA — see https://code.claude.com/docs/en/sandboxing".
- Only computed when the sandbox TLS-terminate configuration is present; on Windows this means the CA source is not "unavailable". Otherwise the trust field is null and the row is hidden entirely.
TLS inspection CA:
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.228
Headless plugin install refreshes the plugin cache in the background
Both mention install
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox