Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.268 ·

Sandbox network allowlist gains per-command rules and consolidated strict-allowlist checks

Sandbox network permission checks can now allow specific commands extra domains and give clearer denial reasons

Group of 3 You'll notice Internal Changes
JSON All of v2.1.268
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Sandbox NetworkArea: what it touches
Internal ChangesKind: in v2.1.268,
ImprovementsSection of the release

What

  • A new per-command allowlist map is checked after the global strictAllowlist/config rules fail, letting a specific command's own allowed_domains grant network access ("Allowed by per-command rule"). A companion UI formatter shows these as "Also lets this command reach, beyond the sandbox allowlist: ..." with long host lists truncated at 160 characters.
  • The network-permission gate now consults this per-command allowlist (looked up by an origin key) after global config rules but before falling back to strict-allowlist denial, and the strict-allowlist short-circuit was reordered to run earlier. User-denial callbacks can now return an object with a custom reason string instead of just true/false.
  • The strict network allowlist check (sandbox.network.strictAllowlist) was consolidated into a single helper that replaces an inline chain, and a related combined check now also factors in the CLAUDE_CODE_EVAL_CONFINED environment variable to decide whether allowed domains should be forced empty.

Why This lets individual commands be granted extra network access beyond the sandbox's global allowlist, gives clearer explanations when network access is denied, and tightens how the strict-allowlist and eval-confinement settings interact.

Read from
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up sandbox.network.strictAllowlist, on All settings. | [`sandbox.network.strictAllowlist`](#sandbox-network-strictallowlist) | Deny hosts outside the [allowlist](/docs/en/sandboxing#network-isolation) instead of prompting | Sandbox settings | User or managed | settings-reference see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up sandbox.network.strictAllowlist, on All settings.

See this entry in the whole of v2.1.268 →

Feedback