What
A cloud session is a Claude Code session that runs on Anthropic's servers. A device-bound one is tied to your device. When Claude Code creates one from a local checkout (a copy of a repository on your machine), it can now attach a repositories_trusted field together with trusted-device proof headers:
- This only happens when the
tengu_violin_fingerboardflag is on and the checkout folder is trusted. The flag falls back to off when no value is set. - If the folder is not trusted or there is no token, nothing extra is sent and the create goes ahead without the field.
- If the server refuses the field with an error, Claude Code logs it and repeats the create without the field.
- Refusals are sorted into reasons such as
not_covered,untrusted_deviceandsession_stale. - Whether the field was sent, not sent, or refused and then retried is recorded.
Before, the create request carried only its usual details and the flag did not exist. For tengu_violin_fingerboard, the flag server returned on for this site's account and for an anonymous baseline check, but no reading has been taken under this release yet.
Why
This lets a cloud session carry proof that the repository it starts from is trusted on your device. Because a refused field leads to a retry without it, creating a cloud session should still work when the server does not accept the field.
tengu_violin_fingerboard Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.281: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.281. It isn't a statement about your account. What a flag value here can and cannot tell you
The finding does not say what the server does with `repositories_trusted` once it accepts it.
New in this build: tengu_violin_fingerboard