terrapinfinance.com. It serves the MCP endpoint, every API call made through it, and document downloads. Over MCP, download_document returns a short-lived URL rather than the file bytes, and fetching that URL is an ordinary network request your egress rules apply to — but it points at terrapinfinance.com as well, so the single entry covers it.
Terrapin used to serve download URLs from
s3.eu-central-003.backblazeb2.com. It no longer does, and you can drop that host from your allowlist.Where to set it
In Claude Desktop, the allowed-domains list is under Settings → Capabilities → Network access on Free, Pro, and Max. On Team and Enterprise it is an administrator policy under Organization settings → Capabilities → Code execution → Allow network egress, and the in-app setting will not override it. In Claude Code, run/sandbox to inspect the current policy, or add the host to sandbox.network.allowedDomains in ~/.claude/settings.json:
settings.json
POST https://terrapinfinance.com/mcp through with the Authorization header intact; proxies that strip it make every call fail with 401.