What
Some remote sessions send their network traffic through an agent proxy (a go-between that sits in front of the internet). This only applies when CLAUDE_CODE_REMOTE and CCR_AGENT_PROXY_ENABLED are set. These sessions changed in several ways:
CCR_AGENT_PROXY_CA_WATCH_ENABLEDis a new environment variable that Claude Code now reads.- Two sets of certificates (the files that prove a secure connection is trusted) now count as the same when they contain the same two certificates in the other order. Before, they had to match byte for byte.
- Installing the proxy's certificate into the system's trusted list now reports whether it worked, and a retry is marked as incomplete.
- The
ghshim (a small stand-in for the GitHub command-line tool) now lives in its own folder for each session, undersessions/<id>/bin, instead of one shared folder. That folder is added to the command search path. - Setting up the shim now checks whether one was inherited from elsewhere, checks whether
jqis available, and skips some relaying. - Claude's instructions now say that when the shim is not a stand-in,
ghin Bash is the machine's own GitHub command-line tool.
Why
This affects how remote sessions decide which secure connections to trust and which gh command Claude actually runs. Keeping the shim per session stops one session's setup from affecting another's.
Names in the bundleCLAUDE_CODE_REMOTECCR_AGENT_PROXY_ENABLED
Documented inclaude-code/cloud-environments
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
What `CCR_AGENT_PROXY_CA_WATCH_ENABLED` turns on is not shown.