Cloud session requests can attach a trusted-device token, but the header is added only when flagged on.
An X-Trusted-Device-Token header is wired into cloud session requests behind a flag that is off.
tengu_violin_wood Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.227: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.227. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
Cloud session event, poll and title requests now build their auth headers asynchronously so they can wait for a trusted-device token and attach it as X-Trusted-Device-Token. The extra header is gated on tengu_violin_wood; without it the header builder returns nothing extra and requests are unchanged.
- Trusted-device tokens already existed; what is new is that ordinary request paths now await one before sending.
X-Trusted-Device-Token
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.