What
A gateway is a server an organization sets up for Claude traffic to pass through. Checking whether a gateway address is trusted used to be only a local comparison against forceLoginGatewayUrl or gatewayInternalNetworks. Now:
- For an https gateway host that is not on the built-in list (
claude.fedstart.com,claude.palantirfedstart.com) and fails the normal checks, Claude Code asks the host at/gateway-api/gateway-hosts/checkwhich deployment serves it. - It then confirms with that deployment using a client certificate. The host is accepted only if the deployment lists it and reports that DNS (the system that turns names into addresses) points at it. Accepted hosts are logged as "accepted: vouched for by".
- A host that
forceLoginGatewayUrldoes not name is refused unless it is vouched for. - The check sends the session's login token (
Bearerplus the session JWT) and the managed login pins (hostLoginPins). - The check can run through a proxy, handling a proxy login request (HTTP 407) with
proxyAuthHelper. It has timeouts, with messages such as "could not be confirmed as a recognized Claude gateway host within", and each failure has its own message, for example when the gateway address carries a query, fragment or user name.
Why
Organizations can reach Claude gateways at hostnames beyond the two built in, without listing every address in settings. If a host is refused, the message says which step of the check failed.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear which login steps use this confirmation or whether a switch controls it.