{"version":"2.1.285","anchor":"hipaa-policy-gate-for-api-credential-warming-and-mcp-task-wo","canonical_anchor":"hipaa-policy-gate-for-api-credential-warming-and-mcp-task-wo","heading":"Background sign-in warm-up request, blocked under HIPAA policy","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/hipaa-policy-gate-for-api-credential-warming-and-mcp-task-wo","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Background sign-in warm-up request, blocked under HIPAA policy\n\nClaude Code sends a background \/v1\/me request to prepare sign-in, and new HIPAA policy entries can deny it and MCP task worker wake-up\n\n**Unclear.** Where the worker-restart policy is checked, and so what exactly stops happening, is not confirmed.\n\n**What**\n\nClaude Code now sends a small background request to `GET \/v1\/me` to prepare its sign-in with the Anthropic API. The request runs quietly without waiting for an answer, retries with a growing delay, and gives up after a timeout. It is skipped unless:\n\n- the provider is Anthropic's own API (`firstParty`) and not a gateway, and\n\n- the policy check `allow_api_auth_warm` passes.\n\nTwo new policy entries are denied for organisations under HIPAA rules when no cached answer is available:\n\n- `allow_api_auth_warm` (requirement HIPAA-R59), which controls this warm-up request\n\n- `allow_mcp_task_worker_wake` (requirement HIPAA-R57), which controls waking an MCP task worker. MCP is the system that connects Claude Code to outside tools.\n\n**Why**\n\nThe warm-up is a network call Claude Code makes on its own in the background. Organisations under HIPAA rules will not get this warm-up or the MCP task worker wake-up.\n\n- Area: Managed Settings\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5"}