What
The sandbox limits which hosts and ports commands run by Claude can reach, using the sandbox.network settings. Before, project settings, which can be committed to a repository, could supply these network allowances. Now:
- When an admin sandbox mandate (managed settings require the sandbox) or a trusted network deny list applies,
sandbox.networkallowances from project and local settings are ignored. A log line says "[sandbox] admin sandbox mandate: ignoring sandbox.network." - Under
allowManagedDomainsOnly, only managed settings can replace the filtering proxy (the program that checks where sandboxed traffic goes) throughhttpProxyPortandsocksProxyPort. A project that tries is logged with "a project may not replace the filtering proxy". httpProxyPortandsocksProxyPortnow have descriptions in the settings schema.
Why
A repository's settings can no longer send sandboxed traffic through a proxy of its own or widen network access when an administrator controls the sandbox.
Documented inclaude-code/agent-sdk/python
sandbox.network
All settings modified, high confidence
| [`sandbox.network`](#sandbox-network) | Control which hosts, ports, and sockets [sandboxed](/docs/en/sandboxing#network-isolation) commands reach | Sandbox settings | Any file |see the edit
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The exact conditions under which a settings source counts as trusted are not established.
Anthropic's documentation agrees
sandbox.network on All settings