What probably matters to youSection of the release
What
In hosted remote sessions, Claude Code runs on a remote machine instead of your own computer. There, traffic can go through an agent proxy, a middleman that forwards requests. The proxy needs a certificate authority (CA), the certificate that lets connections through it be trusted. Previously Claude Code always downloaded that CA. It can now read it from the CCR_AGENT_PROXY_CA_CERT_B64 environment variable, which holds the certificate as base64-encoded PEM text.
If the value fails any check, Claude Code ignores it and downloads the CA as before. It also ignores the variable in essential-traffic-only mode. A separate background check later downloads the CA the proxy is serving and rewrites the stored certificate bundle if the two differ.
CCR_AGENT_PROXY_CA_CERT_B64 and CLAUDE_CODE_MCP_SERVE_SETTINGS were also added to the list of environment variables that are passed through to child processes.
Why
Supplying the certificate up front lets a hosted session start faster, without waiting on a download. Because the background check rewrites the bundle when the served certificate differs, a certificate that has been replaced does not leave the session stuck with an old one.