What
The sandbox limits which websites commands run by Claude can reach. When sandbox.network.strictAllowlist is on, or an administrator requires the sandbox, Claude Code now ignores websites allowed in project settings and local settings. Before, those were added to the list. This covers:
sandbox.network.allowedDomainsWebFetch(domain:)permission rules
A debug log notes how many entries were ignored.
Why
A repository you clone can no longer widen which websites the sandbox allows through its own settings files. Websites you need must be allowed in user or managed settings instead.
Names in the bundlesandbox.network.strictAllowlist
network.strictAllowlist
All settings modified, high confidence
| [`sandbox.network.strictAllowlist`](#sandbox-network-strictallowlist) | Deny hosts outside the [allowlist](/docs/en/sandboxing#network-isolation) instead of prompting | Sandbox settings | User or managed |see the edit
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear what switches on the administrator sandbox requirement.
Anthropic's documentation agrees
network.strictAllowlist on All settings