{"version":"2.1.295","anchor":"chrome-connector-needs-approval-fails-fast-when-a-claudeinch","canonical_anchor":"chrome-connector-needs-approval-fails-fast-when-a-claudeinch","heading":"Chrome deny rules now refuse claude.ai connector calls without an approval card","tier":"notice","area":"Chrome","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/chrome-connector-needs-approval-fails-fast-when-a-claudeinch","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Chrome deny rules now refuse claude.ai connector calls without an approval card\n\nWhen a ClaudeInChromeDomain deny rule covers a site, a claude.ai-proxied connector call that needs approval now fails instead of showing an approval card\n\n**Unclear.** It is not clear whether the new deny-rule check sits behind the same remote switch as the approval retry.\n\n**What**\n\nSome tools reach Claude Code through claude.ai, which passes the calls along (a proxy). That proxy can answer with error -32003 `needs_approval`, meaning the call needs your approval first. Until now Claude Code always showed an approval card after the fact in that case.\n\nNow Claude Code first checks the site against your `ClaudeInChromeDomain` deny rules, which are rules that block Claude in Chrome from certain websites.\n\n- If a deny rule covers the site, the call fails and no approval card is shown. The error code is `ccr_proxy_needs_approval_chrome_site_denied`.\n\n- If the site cannot be read and any deny rules exist, the call also fails with no card.\n\n- Otherwise the approval card appears as before, and it can now be a card for that specific site.\n\nThe retry is still controlled by the remote switch `tengu_mcp_proxy_needs_approval_retry`, which falls back to on in the code when the server sends no value. No reading of that switch has been taken.\n\n**Why**\n\nDomain deny rules you set for Chrome now also apply when a call comes through a claude.ai connector, instead of being worked around by an approval prompt you could click through.\n\n- Flag `tengu_mcp_proxy_needs_approval_retry`: Not enough to say (read for one account on one subscription tier against v2.1.295; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Chrome\n- Names: `ClaudeInChromeDomain`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}