One first-party request path sends the attribution header even if you opted out via env var.
What's wrong with this entry?
The builder for the attribution header now takes an options argument, and one specific first-party, non-unix-socket path passes ignoreEnvOptOut, which makes the header be sent even when CLAUDE_CODE_ATTRIBUTION_HEADER is set to opt out.
ignoreEnvOptOut
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.227
Billing attribution header carries a prompt id and validates its values
Both mention attribution header
-
v2.1.246
Plugin provenance can be supplied via CLAUDE_CODE_PLUGIN_ATTRIBUTION
Both mention attribution