Let Admins Name Which APIs You Can Reach — Claude Code v2.1.285 Puts the Agent's "Outbound Mouth" Behind a Permission List
Claude Code v2.1.285 adds allowedProviders to limit which API endpoints may be used, CLAUDE_CODE_DISABLE_WEB_FETCH to turn off WebFetch, and a sandbox that lower-level settings can't loosen. In the age of unattended operation, the controls for administrators to tighten the agent's "outbound mouth" a
As running coding agents unattended becomes more common, Anthropic used Claude Code v2.1.285, released on September 29, to add a batch of settings that let administrators tighten where an agent is allowed to connect. The focus here isn't the speed or smarts of generation — it's narrowing the channels through which traffic leaves the machine.
Deciding the Connection Targets Themselves with an Allowlist
The headline feature is a new admin-facing setting, allowedProviders. It restricts the API endpoints a given machine is permitted to use to only the ones you specify. The selectable targets are as follows, and any route not listed here becomes unavailable.
- Anthropic API (the first-party endpoint)
- Custom endpoints (a custom URL such as an internal gateway)
- Amazon Bedrock / Mantle
- Google Vertex AI
- Microsoft Foundry
- Claude Platform on AWS
- Cloud gateways
Until now, you could lock down which models an agent was allowed to use (availableModels) and set spending caps, but the question of "which provider's endpoint it connects to" was largely left up to the machine itself. v2.1.285 lets the organization name that connection target. For example, a boundary like "internally, funnel everything through Bedrock and forbid anything else" can now be enforced with a single setting.
The Exit to the Web Can Be Closed with a Switch, Too
Two more changes affecting outbound traffic came in as well. The WebFetch tool, which lets an agent go fetch web pages on its own, now has an explicit off switch.
- Setting the environment variable
CLAUDE_CODE_DISABLE_WEB_FETCHdisables WebFetch entirely. - On Team / Enterprise, if the organization policy can't be loaded at startup, WebFetch is held back until the policy is in place (i.e., the agent won't be allowed to fetch externally while its policy is unconfirmed).
The ability for an agent to read external sites is convenient, but it can also become an entry point for "prompt injection," where the model ends up following instructions slipped into a fetched page. In situations where you can't restrict what gets fetched, being able to shut the channel itself becomes the safer option.
The Sandbox at Your Feet Can't Be Loosened by Lower-Level Settings
This release also tightens things in a different direction: making sure the defenses an administrator puts in place can't be gutted by on-the-ground settings. From project-level settings, you can no longer disable or relax a sandbox that an administrator has made mandatory, swap out the proxy on an admin-defined deny list, extend a strict allowlist, or re-open a read that was denied. Permission overrides have been arranged so that the higher level wins.
The Assumptions of Unattended Operation Are Being Quietly Rearranged
Claude Code has already been moving toward making the default an automatic mode that shifts approval from a human to an AI checkpoint. The less a human presses "yes" at every step, the more it matters to have narrowed in advance the routes through which the agent talks to the outside world. The settings bundled into v2.1.285 amount to laying that groundwork.
For enterprises, it becomes easier to build operations like "funnel connections to the endpoints that are cleared for compliance, and turn off web fetching for sensitive repositories" into a standard menu. At the same time, this kind of control is double-edged. Close off WebFetch and the agent's ability to look up the latest information on its own drops; restrict the connection targets and you introduce trade-offs against availability and redundancy. Rather than swinging all the way to "tighten it and it's safe," the realistic approach is to treat this as an operational-design problem — tuning how far the channel is open according to how sensitive the repository is.
Note that the same version also includes things like claude --desktop, which opens the desktop app in the current directory, and claude plugin configure for checking and saving a plugin's configuration values, but the center of gravity of the release as a whole sits on "retightening outbound communication and permissions."
References: Claude Code changelog (official) / Claude Code Updates by Anthropic - Releasebot


