You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
Bug FixesKind: in v2.1.280,
Bug FixesSection of the release
What
Claude Code's configurable proxy authentication helper (enabled via CLAUDE_CODE_ENABLE_PROXY_AUTH_HELPER) kicks in when a proxy responds with an HTTP 407 (authentication required) status. Previously this only checked a single, direct status field. It now uses a new helper that also recognizes 407 errors buried inside a proxy-tunnel error (ERR_PROXY_TUNNEL) or wrapped inside other exception types, and extracts the proxy-authenticate challenge header from those cases too. The retry decision now goes through an additional gating step before the auth cache is reset and the pending challenge is stored.
Why
Some proxies report authentication failures as tunnel/CONNECT errors rather than a plain HTTP response, so this change lets the proxy auth helper catch and retry those cases too, instead of missing them and failing the connection.