Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.277 ·

New 'repository trust' confirmation flow for cloud sessions

Cloud sessions can now ask you to confirm 'repository trust,' with device-binding checks, a feature flag, and session-level trust reporting

TierNothing to try yethow much it should matter to you
Useful3my rating, 1 to 5
Signal3worth watching, 1 to 5
AreaCloud Sessionswhat it touches
KindIn Developmentin v2.1.277,
Group of 4 Nothing to try yet No documentation found

Cloud sessions can now ask you to confirm 'repository trust,' with device-binding checks, a feature flag, and session-level trust reporting

What

  • A new "repository trust" confirmation question type was added to the remote/cloud-session permission pipeline. Answering yes marks everything attached to that cloud session as trusted.
  • The client refuses to show the confirmation unless the input matches exactly the digest served by the server. If the terminal isn't the device the cloud session is bound to, it adds a warning that the answer can't prove which device it came from, telling you to answer from claude.ai web, desktop, or mobile instead. If the terminal can't render the question at all, it leaves it unanswered for other devices along with an explanatory note.
  • Tool-result rendering gained a matching "refusal" display: for repository-trust folder-wait errors, a localized message keyed repository_trust.folder_waits.<reason> is now shown instead of the plain error view, and detached/backgrounded tool call results are rendered with a dedicated rows/table-style component.
  • A new nameRepositoryTrustAnswers capability flag, off by default, was added, gated behind a first-party check and a growthbook flag.
  • The cloud session view now reports a repositoryTrust fingerprint and a directory-sync retention cutoff for directory-synced sessions.

Why

This gives Claude Code a way to ask for and record explicit trust confirmation before treating everything attached to a cloud session as trusted, with safeguards so the confirmation can only meaningfully be answered from the device the session is actually bound to.

Read from
Names in the bundlenameRepositoryTrustAnswerstengu_violin_bridgepin
Feature flag
tengu_violin_bridgepin Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.277: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.277. It isn't a statement about your account. What a flag value here can and cannot tell you

What has happened since
Flag reading moved The flag server now returns on for tengu_violin_bridgepin, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.

See this across every release →

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat nameRepositoryTrustAnswers actually enables is not stated in the finding.
The name it cites is new in this buildNew in this build: tengu_violin_bridgepin

See this entry in the whole of v2.1.277 →

Feedback