{"version":"2.1.285","anchor":"agent-proxy-accepts-ca-cert-from-env-var-ccr-agent-proxy-ca","canonical_anchor":"agent-proxy-accepts-ca-cert-from-env-var-ccr-agent-proxy-ca","heading":"Hosted remote sessions can take the agent proxy certificate from an environment variable","tier":"use","area":"Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/agent-proxy-accepts-ca-cert-from-env-var-ccr-agent-proxy-ca","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Hosted remote sessions can take the agent proxy certificate from an environment variable\n\nIn hosted remote sessions, the agent proxy can read its certificate authority from `CCR_AGENT_PROXY_CA_CERT_B64` instead of always downloading it\n\n**Unclear.** It is not clear what normally sets this variable, or whether the background certificate check always runs.\n\n**What**\n\nIn hosted remote sessions, Claude Code runs on a remote machine instead of your own computer. There, traffic can go through an agent proxy, a middleman that forwards requests. The proxy needs a certificate authority (CA), the certificate that lets connections through it be trusted. Previously Claude Code always downloaded that CA. It can now read it from the `CCR_AGENT_PROXY_CA_CERT_B64` environment variable, which holds the certificate as base64-encoded PEM text.\n\nThis applies when `CLAUDE_CODE_REMOTE` and `CCR_AGENT_PROXY_ENABLED` are set. Claude Code checks the value before using it:\n\n- The text must be valid base64.\n\n- It must be within a size limit.\n\n- It must contain a certificate block.\n\nIf the value fails any check, Claude Code ignores it and downloads the CA as before. It also ignores the variable in essential-traffic-only mode. A separate background check later downloads the CA the proxy is serving and rewrites the stored certificate bundle if the two differ.\n\n`CCR_AGENT_PROXY_CA_CERT_B64` and `CLAUDE_CODE_MCP_SERVE_SETTINGS` were also added to the list of environment variables that are passed through to child processes.\n\n**Why**\n\nSupplying the certificate up front lets a hosted session start faster, without waiting on a download. Because the background check rewrites the bundle when the served certificate differs, a certificate that has been replaced does not leave the session stuck with an old one.\n\n- Area: Sessions\n- Names: `CCR_AGENT_PROXY_CA_CERT_B64`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 3\/5"}