Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.225 Home All releases olderv2.1.224 v2.1.226newer

Device bridge websocket URLs are checked against a host allowlist

Use it now
Useful3 Signal0
Sessions Notable not in their notes

The device bridge now only connects to approved hosts, with local overrides limited to localhost.

CLAUDE_REMOTE_TOOLS_BRIDGE_URL
What

The device-registration bridge validates its dial URL before connecting, so it cannot be pointed at an arbitrary websocket host.

Details
  • new isAllowedUrl check requires wss:, no username or password in the URL, and a hostname in {bridge.claudeusercontent.com, bridge-staging.claudeusercontent.com}
  • an operator-overridden base URL is allowed only through a separate same-origin check, which permits ws: only for localhost, 127.0.0.1 and [::1]
  • no such check existed in 2.1.224
  • the bridge only runs when non-essential egress is allowed, the provider is first-party, and the allow_remote_sessions policy permits it; the base URL is overridable via CLAUDE_REMOTE_TOOLS_BRIDGE_URL
Evidence

bridge-staging.claudeusercontent.com

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.225 →