Remote managed settings are settings an organisation's administrator publishes, which Claude Code downloads. When Claude Code goes through a cloud gateway to get them (a gateway is a go-between server that forwards requests), it now refuses if the gateway's address lies outside the network where it was verified. That fails with errorKind gateway_public_address and is not retried. The error text reads "Cloud gateway connection outside the network it was checked on".
The fetch result also reports more detail:
authType,credentialOrigin, andtokenRefreshOutcome(OAuth sign-in only)errnoon timeouts and network errorsretriedAfter401andforcedRefreshOutcomeafter a forced token refresh
When the credentials carry no pin fingerprint, a verified hostVerdict can now supply the secure connection. The User-Agent header, which identifies the client to the server, changes when both CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST and CLAUDE_CODE_USE_GATEWAY are set.
If a gateway unexpectedly points somewhere public, Claude Code now stops instead of sending the request there. When fetching settings fails, the extra details make it easier to see whether sign-in, credentials or the network was the problem.