下面三张卡回答的是「如果这个入口现在发流量,会从哪出去」—— 工具用和该入口相同的代理配置自己发了一次探测。所以进程没在跑,卡片照样有值。想看「它此刻正连着谁」,去左边的「实时连接」,那里才是真实观测。 These three cards answer “where would this entry point exit if it sent traffic now” — the tool probes using that entry point's own proxy config. A card has a value even when the process is not running. For “what is it connected to right now”, see Live sockets — that one is observation.
这个工具在你没允许之前,一个探测请求都不会发。 Monitoring is off by default. Flip the switch or press “Probe now”.
Nothing is probed until you say so.
本轮结论What this round found
0采过一轮之后,这里会列出需要你处理的事:某个入口落在受限地区、两个入口出口不一致、某个域名没被分流规则覆盖到。 After a round, this card lists what needs action: an entry point landing in a restricted region, two entry points exiting different countries, a domain your routing rules never matched.
为什么这张卡是暗的:一屏里只留一个视线落点,而它应该落在「要动手的事」上,不是落在汇总数字上。
结论是算出来的,不是复述数字:出口国家在入口之间不一致、某条路径下的域名没被规则覆盖、连接的真实目的地拿不到 —— 这三类都会在这里出现。
One dark card per screen, and it belongs on the thing you must act on — not on a summary you can already see.
These lines are computed, not restated: exits disagreeing across entry points, domains a routing rule never matched, destinations we cannot see.
遥测发往哪里Where telemetry goes
只做 TLS 握手量延迟,不发任何数据 —— 往别人的遥测 intake 写东西是污染它的数据。 TLS handshake only, no payload — writing into someone's telemetry intake pollutes their data.
Claude Code 里硬编码了 Datadog US5 站点的日志 intake,桌面端和网页端另外带一套浏览器端 SDK,错误上报走 Sentry 的 US 区。采一轮就能看到各自的延迟。 Claude Code hardcodes the Datadog US5 logs intake; desktop and web add a browser SDK, and crash reports go to Sentry's US region. Run a round to see each one's latency.
US5 是 Datadog 的一个站点代号,落地在美国的 Google Cloud 上(实测解析到 GCP 的地址段)。关闭办法见 docs/02-telemetry.md。 US5 is a Datadog site code; it resolves into Google Cloud address space in the US. How to turn it off: docs/02-telemetry.md.
出口变更Exit changes
只在变了的时候记一条Logged only on change出口 IP 或地区变化时才在这里留一行。每轮都记等于把一屏日志变成噪声,而你关心的只有「什么时候变的」。 A line appears only when the exit IP or region changes. Logging every round would be noise; the question is always “when did it change”.
本机的路径Paths on this machine
CLI 只认 HTTPS_PROXY 环境变量,桌面端和浏览器认 macOS 系统代理。两份配置不同,出口就可以不同 —— 这是这个工具存在的理由。
The CLI reads only HTTPS_PROXY; desktop and browsers read the macOS system proxy. Two different configs mean two different exits — which is why this tool exists.
每个域名 × 每条路径Every domain × every path
出口 IP 是目的地那侧看到的源地址,不是本机接口地址。点表头排序。 The exit IP is what the destination sees, not a local interface address. Click a header to sort.
| 出口 IPExit IP | 边缘机房Colo | ||||
|---|---|---|---|---|---|
| 采一轮才有内容Run a round first | |||||
Claude 的进程此刻连着谁What Claude is connected to right now
用 lsof 读进程的 socket,不抓包、不看内容、不需要 root。三条限制写在下面,因为它们决定了哪几行你不能当成结论。
Reads process sockets with lsof — no capture, no payload, no root. The three limits below decide which rows you may not read as conclusions.
| 入口Entry | 目的地Destination | 性质Kind | 归属Owner | 连接数Sockets |
|---|---|---|---|---|
| 采一轮才有内容Run a round first | ||||
一、走本机代理的连接,目的地是不可见的。
桌面端和浏览器把流量交给系统代理,lsof 只能看到「它连了 127.0.0.1」。
真实目的地在代理进程里,要补上这一段得打开分流器的控制接口。
二、fake-ip 地址不是真实主机。
开了 TUN 的机器上,198.18.x.x 是分流器发给每个域名的占位地址。
好处是每个域名一个独立占位地址,反而能反查出域名;坏处是查这个 IP 的归属毫无意义。
三、浏览器里无法归属到 Claude 的连接不列出。
浏览器同时连着几十个别的站点。列出来既是噪声,也等于把你在访问哪些网站写进采样文件 —— 这个工具没有理由知道那些。
1. Destinations behind a local proxy are invisible.
Desktop and browsers hand traffic to the system proxy, so lsof only sees a connection to 127.0.0.1.
Recovering the real destination requires the router's own control API.
2. fake-ip addresses are not real hosts.
With TUN on, 198.18.x.x is a placeholder the router assigns per domain. The upside: one placeholder per
domain means we can map it back to a name. The downside: looking up that IP's owner is meaningless.
3. Browser sockets we cannot attribute to Claude are not listed.
A browser is connected to dozens of other sites. Listing them is noise — and it would write your browsing into the sample file.
模型 API 的往返耗时Round-trip to the model API
柱高是 p50,轨道是 1500 ms 的量纲。没有轨道,一根矮柱只读作「矮」。 Bar height is p50 against a 1500 ms track. Without the track a short bar only reads as “short”.
刻度里 ·C 是 Claude Code,·D 是桌面端 / 浏览器;鼠标停在柱子上看完整域名和 p50。
同一个域名两条路径差得远,说明差异来自代理链路而不是这个域名本身。都慢才是 Claude 那侧或你的宽带的问题。
In the ticks, ·C is Claude Code and ·D is desktop/browser; hover a bar for the full domain and p50.
A wide gap between two paths for the same domain means the difference is the proxy chain, not the domain. Both slow points at Claude's side or your uplink.
一次请求的四段Four phases of one request
总耗时慢有四种完全不同的原因,修法也完全不同:DNS 慢换解析器,TCP 慢换出口节点,TLS 慢多半是链路丢包重传,首字节 慢是服务端或中间代理在等。所以这里从来不给一个总数了事。 Four different causes hide behind one “slow”, each with a different fix: DNS → change resolver; TCP → change exit node; TLS → usually loss and retransmit; first byte → the server or an intermediate proxy is waiting. A single total never tells you which.
分位数(按当前窗口)Percentiles over the current window
p50 是中位数——把所有测量排序后取正中间那个,一半请求比它快、一半比它慢。用它而不是平均值,因为一次抖动就能把平均值拉飞。p95 是第 95 百分位,只有 5% 的请求比它更慢,代表「最糟的日常情况」。n 太小时分位数没有统计意义,n=3 的 p95 基本就等于最大值。 p50 is the median — sort every measurement and take the middle one; half the requests are faster, half slower. It is used instead of the mean because a single spike drags a mean anywhere. p95 means only 5% of requests are slower, i.e. the worst everyday case. With a small n percentiles carry no statistical weight: at n=3, p95 is essentially the max.
| 域名Domain | 入口Entry | n | p50 | p95 | 最快min | 最慢max |
|---|---|---|---|---|---|---|
| 至少采两轮才有分位数Needs at least two rounds | ||||||
中间每一跳的延迟与丢包Latency and loss, hop by hop
四段延迟答不了「中间哪一跳出了问题」。丢包会让 TLS 握手忽快忽慢,但每一段的平均值看起来都正常 —— 只有丢包率能直接说明这件事。 The four-phase breakdown cannot say which hop is at fault. Loss makes the TLS handshake erratic while every phase average still looks fine — only a loss rate names it.
mtr;没装会在这里告诉你怎么装。
One sweep covers every Claude domain plus the control, taking one to two minutes — which is why it has its own switch and interval rather than riding the main monitor. Domains resolving to the same address are traced once; tracing one path seven times says nothing new. Requires mtr; if it is missing this panel says how to install it.
怎么读这张表How to read it
开了 TUN / 系统代理时,这条路径量的是本机到代理服务器那一段,不是代理到 Claude 那一段 —— 后半段在本机看不见。1.1.1.1 作为对照组同理。
With TUN or a system proxy on, this measures your machine to the proxy, not the proxy to Claude — the far half is invisible from here. The same caveat applies to the 1.1.1.1 control.
诊断与解决方案Findings and fixes
每条都带三样东西:判据(算出它的实测数字)、成因(不是现象的复述)、下一步(可以直接照做的命令或配置)。没有判据的建议不值得照做。 Each carries three things: the evidence that produced it, the cause (not a restatement of the symptom), and a next step you can actually run. A recommendation without evidence is not worth following.
环境检查Environment checks
这些和具体域名无关,是「这台机器此刻」的事实:IPv6 通不通、时钟准不准、TLS 有没有被中间人拆开、两个权威 DNS 源是否一致、代理端口有没有进程在听。 These are machine-level facts rather than per-domain ones: IPv6 reachability, clock accuracy, whether TLS is being intercepted, whether two authoritative DNS sources agree, and whether the proxy port is actually listening.
出口稳定性Exit stability
按当前窗口统计over the current window| 入口Entry | 轮数rounds | 出现过的地址addresses | 网络数networks | 地址变更IP changes | 跨国变更country changes | 判定verdict |
|---|---|---|---|---|---|---|
| 至少采两轮才能看出漂移Needs at least two rounds | ||||||
按天归档Archived by day
每轮只存结论性字段(约 1 KB),按天分文件,所以一天大约几 MB。点卡片选中一天或多天看汇总;选中之后可以删掉 —— 长期开着监控,历史会一直涨,删除必须是一等功能。 Only conclusion fields are stored (about 1 KB per round), one file per day, so a day costs a few MB. Click cards to select one or more days; selected days can be deleted — with monitoring left running, history grows forever, so deletion is a first-class feature.
还没有归档数据。打开监控跑一段时间,这里会按天出现。 No archive yet. Turn monitoring on for a while and days will show up here.
出口国家构成Exit countries
选中一天或多天后显示。超过 4 类会合并成「其余」——环图切片多于 4 片就只能靠图例才读得懂,那说明它已经不工作了。 Shown once days are selected. More than four categories collapse into “rest” — beyond four slices a donut can only be read via its legend, which means it has stopped working.
出口网络构成Exit networks
按 ASN 分。国家相同但 ASN 不同,说明是**不同的网络**,只是恰好在同一个国家。 Grouped by ASN. Same country with different ASNs means genuinely different networks that merely share a country.
按小时分布By hour
柱高是该小时的 p50 往返耗时,轨道是当天最大值。空的小时表示那时候没在采样。 Bar height is that hour's p50 round trip against the day's max. Empty hours mean sampling was off.
出现过的出口地址Exit addresses seen
国家相同也要看地址same country still differs by address| 出口地址Address | 协议Family | 位置Location | 网络Network | 占比Share |
|---|---|---|---|---|
| 选中一天或多天后显示Select days to see this | ||||
本机解析 vs 公网权威Local resolution vs public authority
左边是进程真正会连的地址,右边是这个域名真实指向哪(走 DoH 拿,报文加密,中间的分流器改不了里面的答案)。两者不一致就是本机 DNS 被改写了 —— 「我以为流量走 A、其实走 B」几乎都从这里开始。 Left is the address processes will actually dial. Right is where the name really points, fetched over DoH — the payload is encrypted, so a local router cannot rewrite the answer. A mismatch means local DNS was rewritten, which is where almost every “I thought it went via A” begins.
| 域名Domain | 本机Local | 权威Authority | 专用解析器Resolver | 判定Verdict |
|---|---|---|---|---|
| 采一轮才有内容Run a round first | ||||
遥测会上报哪些字段What telemetry reports
静态提取:只读你自己电脑上那个文件里的明文字符串,不解密流量、不注入进程、不修改任何东西。Claude Code 是未加密的 JS bundle,构造上报内容的那段代码本来就是明文。 Static extraction: reads plain strings out of a file already on your disk. No decryption, no injection, nothing modified. Claude Code ships as an unencrypted JS bundle, so the code that builds the payload is readable as-is.
这里答不了什么:静态提取只能知道「会发哪些字段」,不知道「某一次具体发了什么值」。后者要解密 TLS —— 需要装一个根 CA,而根 CA 私钥一旦泄露,本机所有 HTTPS 都可被解密。这个代价大于收益,所以本仓不做,也不提供做这件事的工具。 What this cannot answer: static extraction reveals which fields can be sent, never what a specific request actually contained. That would require decrypting TLS, which means installing a root CA — and a leaked root CA key means every HTTPS session on this machine is readable. The cost outweighs the benefit, so this repo does not do it.
Claude 会连哪些域名Domains Claude reaches
每一行都有取证来源:从 Claude Code 的单文件可执行和桌面端 app.asar 里抽出的字符串,加上本机 lsof 真实抓到过的连接。复现命令写在 docs/01-endpoints.md,可以自己跑一遍对账。
Every row carries its evidence: strings pulled from the Claude Code single-file executable and the desktop app.asar, plus connections actually observed via lsof. Reproduction commands are in docs/01-endpoints.md.
导出的文件可以直接发给别人:里面只有域名和用途,没有出口 IP、没有代理端口、没有进程名、没有 ASN 归属、也没有延迟数字。父域不认识的域名(可能是你自己配的 MCP 服务器)默认被扣下不导出,只报个数。 The exported file is safe to share: domains and purposes only — no exit IP, no proxy port, no process name, no ASN, no latency figures. Domains under an unrecognised parent (possibly your own MCP server) are withheld by default and only counted.