{"version":"2.1.281","anchor":"remote-managed-settings-fetch-public-address-gateway-refusa","canonical_anchor":"remote-managed-settings-fetch-public-address-gateway-refusa","heading":"Remote managed settings fetch: public-address gateway refusal and richer diagnostics","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/remote-managed-settings-fetch-public-address-gateway-refusa","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Remote managed settings fetch: public-address gateway refusal and richer diagnostics\n\nFetching remote managed settings now refuses gateways that resolve to a public address and reports more about failures\n\n**What**\n\nRemote managed settings are settings an organisation's administrator publishes, which Claude Code downloads. When Claude Code goes through a cloud gateway to get them (a gateway is a go-between server that forwards requests), it now refuses if the gateway's address lies outside the network where it was verified. That fails with errorKind `gateway_public_address` and is not retried. The error text reads \"Cloud gateway connection outside the network it was checked on\".\n\nThe fetch result also reports more detail:\n\n- `authType`, `credentialOrigin`, and `tokenRefreshOutcome` (OAuth sign-in only)\n\n- `errno` on timeouts and network errors\n\n- `retriedAfter401` and `forcedRefreshOutcome` after a forced token refresh\n\nWhen the credentials carry no pin fingerprint, a verified `hostVerdict` can now supply the secure connection. The User-Agent header, which identifies the client to the server, changes when both `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` and `CLAUDE_CODE_USE_GATEWAY` are set.\n\n**Why**\n\nIf a gateway unexpectedly points somewhere public, Claude Code now stops instead of sending the request there. When fetching settings fails, the extra details make it easier to see whether sign-in, credentials or the network was the problem.\n\n- Area: Managed Settings\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5"}