Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Sandbox HTTPS proxy reuses connections and sends the right Host header for custom ports

The sandbox's HTTPS proxy now keeps connections open for reuse and includes a non-default port in the Host header it forwards

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

When the sandbox limits network access, some HTTPS traffic from commands passes through a proxy, a go-between that opens the encrypted connection and forwards the request. That proxy's behaviour has changed in several ways:

  • Connections to a website are now kept open and reused, one connection at a time, instead of opening a new one for every request.
  • The website's looked-up address is remembered, and forgotten again after an error.
  • The Host header, which tells the website which name was asked for, is now rebuilt with the port number when the port is not the standard one. Before, the header was removed.
  • If a reused connection is cut off by the website, the proxy now closes the command's connection instead of answering with a 502 Bad Gateway error.
  • A request refused by the allow list now gets the same refusal response as other blocked connections, with the message "Connection blocked by network allowlist".
Why

Websites on a non-standard port could receive the wrong Host header through the sandbox, which this fixes. Reusing connections also means fewer secure handshakes, so repeated requests to the same site do less work.

See this entry in the whole of v2.1.284 →

Feedback