Claude Code now has a dedicated path for accounts placed on hold: a new OAuthAccountOnHoldError/OAuthCallbackError pair, an account_on_hold login-screen state, a cli_setup_token branch, an api_request_account_on_hold error branch, a tengu_oauth_refresh_token_account_on_hold refresh outcome, and an account_on_hold value added to the StopFailure hook matcher list. The local OAuth callback listener now handles ?error= redirects (previously only code was handled), and an appeal link is validated to be https-only, pointing at claude.ai or anthropic.com or a subdomain, else it falls back to a fixed restricted-access URL.
Every entry point funnels through one detector gated on tengu_lively_beaver, which falls back to off. Nothing in the build sets this gate true, and the hook metadata doesn't even advertise account_on_hold unless it is.
tengu_lively_beaver Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.235: not a boolean we can read
Read once, for one account on one subscription tier, against v2.1.235. It isn't a statement about your account. What a flag value here can and cannot tell you
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.