Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.238 Home All releases olderv2.1.237 v2.1.239newer
Claude Code v2.1.238

Cross-session peer identity is now keyed to the account, still off by default

Not switched on
Useful2 Signal4
Cross-Session Messaging Notable not in their notes

Session-to-session messaging identity now follows your account, but the whole feature is off by default.

Peer identity derives from host plus credential and recomputes on account change, needing CLAUDE_CODE_HARBOR_KITE or a flag that falls back to false.

Feature flag
tengu_harbor_kite On for this account, and not off by default

The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.

This account: on · anonymous baseline: on · compiled default in v2.1.238: on

tengu_harbor_kite_win Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.238: on

Read once, for one account on one subscription tier, against v2.1.238. It isn't a statement about your account. What a flag value here can and cannot tell you

CLAUDE_CODE_HARBOR_KITE
What

Identity for talking to other sessions is now derived from the host plus the current credential (account and organization ids, or a fingerprint of the bearer token) and recomputed when the account changes. This sits under cross-session messaging, whose compiled fallback is false: it needs CLAUDE_CODE_HARBOR_KITE set, or the tengu_harbor_kite flag on, and on Windows also tengu_harbor_kite_win, which also falls back to false.

Details
  • A supervised child handed an identity that fails the safety check logs a refusal and gets no Remote Control identity at all.
  • The REPL reports its own cross_session_inbound availability as session metadata.
Evidence

cross_session_inbound

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.238 →