Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Hosted remote sessions can take the agent proxy certificate from an environment variable

In hosted remote sessions, the agent proxy can read its certificate authority from CCR_AGENT_PROXY_CA_CERT_B64 instead of always downloading it

Use it now Notable No documentation found New Features
JSON All of v2.1.285
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
SessionsArea: what it touches
New FeaturesKind: in v2.1.285,
What probably matters to youSection of the release
What

In hosted remote sessions, Claude Code runs on a remote machine instead of your own computer. There, traffic can go through an agent proxy, a middleman that forwards requests. The proxy needs a certificate authority (CA), the certificate that lets connections through it be trusted. Previously Claude Code always downloaded that CA. It can now read it from the CCR_AGENT_PROXY_CA_CERT_B64 environment variable, which holds the certificate as base64-encoded PEM text.

This applies when CLAUDE_CODE_REMOTE and CCR_AGENT_PROXY_ENABLED are set. Claude Code checks the value before using it:

  • The text must be valid base64.
  • It must be within a size limit.
  • It must contain a certificate block.

If the value fails any check, Claude Code ignores it and downloads the CA as before. It also ignores the variable in essential-traffic-only mode. A separate background check later downloads the CA the proxy is serving and rewrites the stored certificate bundle if the two differ.

CCR_AGENT_PROXY_CA_CERT_B64 and CLAUDE_CODE_MCP_SERVE_SETTINGS were also added to the list of environment variables that are passed through to child processes.

Why

Supplying the certificate up front lets a hosted session start faster, without waiting on a download. Because the background check rewrites the bundle when the served certificate differs, a certificate that has been replaced does not leave the session stuck with an old one.

Read from
Names in the bundleCCR_AGENT_PROXY_CA_CERT_B64
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what normally sets this variable, or whether the background certificate check always runs.
The name it cites is new in this buildNew in this build: CCR_AGENT_PROXY_CA_CERT_B64

See this entry in the whole of v2.1.285 →

Feedback