If your network blocks artifact content, the message names the exact domain to allowlist.
What's wrong with this entry?
When your environment's network allowlist denies the host that serves artifact content, the guidance now says the live version can be neither read nor handed over, and names the exact domain to add and where to add it.
- The domain to allow is
*.frame.claudeusercontent.com, added in environment settings, or in admin settings if the environment is shared. - Only appears when that host is in the session's denied-egress set.
*.frame.claudeusercontent.com
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.