# Monitor Claude Code Network Connections on Mac: Security with FireAI > Claude Code runs commands and opens connections on your Mac. What Anthropic documents about its permissions and domains, and how FireAI flags a new destination or upload spike. FireAI Security & Research Team (HisnLabs) · Published 2026-10-04 Canonical: https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai Claude Code is a coding agent from Anthropic that runs in a terminal on your Mac. It reads your project, edits files and runs shell commands on your behalf, and every one of those actions can end in a network connection. This article sets out what Anthropic documents about how Claude Code runs on macOS, what it can reach, and which connections are normal, then shows how to watch them with FireAI. Where a fact comes from Anthropic’s documentation, the source is listed at the end. ## What Claude Code is and how it runs on a Mac Anthropic’s setup page lists three ways to install Claude Code on macOS. The recommended native installer is a `curl` script that downloads a binary and updates itself in the background. Homebrew offers two casks, `claude-code` for the stable channel and `claude-code@latest` for the latest one, and Homebrew installs do not auto-update. A global npm package, `@anthropic-ai/claude-code`, is also available; according to the same page it installs the same native binary and the installed `claude` binary does not itself invoke Node. On macOS the binary is documented as signed by “Anthropic PBC” and notarized by Apple, and you can check it with `codesign --verify --verbose`. *Terminal* ```console # check the signature of the claude binary, as the setup page describes $ codesign --verify --verbose ./claude ``` ## What it can access, and the documented permission model Claude Code acts with the permissions of the account that starts it. Anthropic’s security page describes two starting points. In Manual mode it starts read-only, and asks before it edits files, runs tests or executes commands, with a built-in set of read-only commands such as `ls`, `cat` and `git status` running without a prompt. Auto mode is the built-in starting mode for interactive terminal and VS Code sessions: a separate classifier model reviews actions and blocks the ones it judges unsafe, while your explicit ask and deny rules still apply. Three documented details matter for network behaviour. First, commands that fetch content from the web, such as `curl` and `wget`, are not auto-approved by default. Second, the working directory boundary is a permission prompt, so a Bash command you approve can still write anywhere your user account can. Third, an optional sandboxed Bash tool, configured with `/sandbox`, applies filesystem and network isolation to shell commands at the operating system level. Anthropic notes that the sandbox covers shell commands only, and that file tools, MCP servers and hooks run outside it. The security page also states that no system is completely immune to all attacks, and recommends reviewing suggested commands, avoiding piping untrusted content directly to Claude, and using virtual machines for scripts that touch external web services. ## The domains Claude Code documents Anthropic’s network configuration page lists the URLs the standalone CLI needs. These are the vendor-documented ones most relevant to a firewall: | Host | Documented purpose | | --- | --- | | api.anthropic.com | Claude API requests, the WebFetch domain safety check, feature flag fetches and telemetry event logging | | claude.ai, claude.com, platform.claude.com | Account sign-in and OAuth token exchange | | mcp-proxy.anthropic.com | MCP connectors from claude.ai | | downloads.claude.ai | Native installer, auto-updater, update checks and plugin downloads | | registry.npmjs.org | npm and bun installs of Claude Code, plugin installs and npx-launched MCP servers | | github.com, raw.githubusercontent.com | Cloning plugin marketplaces; the changelog feed for /release-notes | | http-intake.logs.us5.datadoghq.com, browser-intake-us5-datadoghq.com | Optional operational telemetry and error reports; documented as disabled with DISABLE_TELEMETRY or CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC | *Source: Claude Code documentation, Enterprise network configuration, “Network access requirements”.* The same page says Claude Code respects the standard `HTTPS_PROXY` and `HTTP_PROXY` variables and does not support SOCKS proxies. Anything outside this list, such as a package registry reached by a build command Claude runs, is the project’s own traffic, not Claude Code’s. ## Why a network view still helps Permission prompts show you the command Claude Code wants to run. They do not show every connection that results from commands you approved earlier, from an MCP server, from a plugin, or from a script in the repository. A network-level view answers a narrower and complementary question: where did this machine actually connect while the agent was working? That is the question FireAI’s Agent profile is designed to answer. > Claude Code asks before it acts. A network firewall adds a second view of where it connects. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Watching Claude Code with FireAI FireAI is a firewall for macOS made by HisnLabs, and since version 1.0.2 it has a feature called [Agent profile](https://hisnlabs.com/en/docs/agent-profile). It recognises 19 AI agents, learns where each one normally connects, and flags unusual behaviour for you to review. Claude Code is recognised by its code signature. ![FireAI's Activity list filtered on "claude": three claude rows, to api.anthropic.com and to DNS lookups, each shown with the Claude Code character, and a Brave Browser Helper row to claude.ai with an ordinary app icon.](https://cdn.hisnlabs.com/blog/monitor-claude-code-activity.png) *FireAI's Activity list on a Mac: the claude command-line process carries the Claude Code character, while a browser visiting claude.ai stays an ordinary app.* Claude Code is one of the three agents FireAI checks against its developer’s code signature, so a match is more than a name. FireAI also recognises the agent’s child processes, such as a shell, git or curl that the agent runs, by walking up the process’s parents until it reaches the agent. Those connections are therefore counted as the agent’s own. ## What FireAI flags 1. For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain. Nothing is flagged during this learning period. 2. After that, a first-ever destination outside the learned baseline is flagged for review. 3. An upload spike is flagged too: an hour in which the agent sent at least 4 times its busiest hour so far, and never less than 25 MB. Agent profile uses only metadata, meaning host names and byte counts. FireAI never reads the payload of a connection, and it cannot read inside an encrypted one. ## Set it up for Claude Code 1. Install FireAI and finish the setup, then keep using Claude Code as you normally do. The 3-day learning period starts from what FireAI sees. 2. Open Suggestions and look at the AI agents card. It lists the agents FireAI has recognised and what it has learned about each. 3. When Claude Code reaches a destination it has never contacted, the flag appears in the AI agents card and in [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions). Swipe left to block, or right for “It’s fine”. 4. Block creates a rule for the process that connected. “It’s fine” adds the destination to the agent’s baseline so it is not flagged again. 5. If you want the agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of flagged. 6. A blocked destination shows in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent can reach it right away. Keep blocked creates a block rule, so the destination stays blocked in every mode. > **Note:** The Agent profile security mode arrived in FireAI 1.0.3. While an agent is still learning nothing is blocked, and upload spikes are flagged, not blocked. An allow rule you wrote yourself for a website, domain or address still wins, and DNS and your local network are never blocked. > Want to see where Claude Code connects on your Mac? FireAI is free to try. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limits - FireAI does not prevent prompt injection. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag, and let you block, the path data would take out of your Mac. - FireAI cannot see prompts, the contents of MCP tools, or which files Claude Code reads, such as ~/.ssh. TLS hides the payload, and FireAI is not inside the agent. - Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature. - During the 3-day learning period nothing is flagged. - In the Agent profile mode, a connection to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, it is blocked until you allow it. - FireAI’s plain-words explanation of a flag is written from facts it measured. It never says a destination is safe or dangerous. The decision is yours. ## Related guides The same approach applies to the other agents FireAI recognises: [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile). > FireAI is built by HisnLabs and runs on your Mac, with no cloud account. Download it and see which destinations your agents have contacted. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## How FireAI and HisnLabs fit in Claude Code asks before it acts. A network firewall adds a second view of where it connects. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [Claude Code documentation: Security](https://code.claude.com/docs/en/security) - [Claude Code documentation: Network configuration](https://code.claude.com/docs/en/network-config) - [Claude Code documentation: Advanced setup](https://code.claude.com/docs/en/setup) - [Claude Code documentation: Sandboxing](https://code.claude.com/docs/en/sandboxing) - [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile) - [FireAI docs: Quick Review and Suggestions](https://hisnlabs.com/en/docs/quick-review-suggestions) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes)