Cloud sessions can be bound to your machine so local tools only run there, currently gated off.
Device binding for cloud sessions is built behind a flag, with unbound sessions as the fallback.
tengu_violin_wood Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.227: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.227. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
New machinery ties a remote or cloud session to the device that started it, so local tools only run for that machine. Session creation registers the machine and signs a proof of the binding. It is gated on tengu_violin_wood, checked asynchronously, and any error means the session is simply not bound.
- Session creation is refused outright in combinations not yet supported, reported as
device_bind_project_unsupportedanddevice_bind_agent_unsupported. - Binding failures degrade to an unbound session and emit
tengu_device_bind_skippedortengu_device_bind_failed. - Three new server rejection causes are recognised:
bind_attestation_stale,bound_session_unattested_write, anduntrusted_device.
bound_session_unattested_write
Strings lifted out of the shipped bundle, so the claim above can be checked against them.