Agent proxy startup accepts a handed-over token and reports where its certificate came from
Agent proxy startup can use a handed-over token instead of reading a file, and now records timings and ca_source to help diagnose slow or failed starts
Group of 2You'll noticeNo documentation foundImprovements
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Cloud SessionsArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release
What
In cloud sessions, Claude Code can start an agent proxy, a local relay that network traffic passes through, which needs a certificate (CA) and a token.
Startup can now use a token handed to it directly, so the token file is not read.
Startup records how long fetching the certificate, writing it to the trusted list, bringing the relay up and gathering inputs each took, and where the certificate came from (ca_source).
When setting up the certificate fails, the failure report now also carries ca_source. Before, it had no details.
The check for jq on the PATH now has a time limit and records when it times out.
Environment variables are read through a shared helper.
Why
If a cloud session is slow to start or the proxy certificate fails, the extra detail shows which step was slow and where the certificate came from. The time limit on the jq check stops that one check from holding up startup.