{"version":"2.1.281","anchor":"new-repository-trust-proof-headers-when-creating-cloud-sessi","canonical_anchor":"cloud-session-create-can-now-send-repositories-trusted-behi","heading":"Cloud session creation can attach repository-trust proof, behind tengu_violin_fingerboard","tier":"soon","area":"Cloud Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/new-repository-trust-proof-headers-when-creating-cloud-sessi","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Cloud session creation can attach repository-trust proof, behind tengu_violin_fingerboard\n\nCreating a device-bound cloud session can now send a repositories_trusted field with device-proof headers, controlled by the tengu_violin_fingerboard flag\n\n**What**\n\nA cloud session is a Claude Code session that runs on Anthropic's servers. A device-bound one is tied to your device. When Claude Code creates one from a local checkout (a copy of a repository on your machine), it can now attach a `repositories_trusted` field together with trusted-device proof headers:\n\n- This only happens when the `tengu_violin_fingerboard` flag is on and the checkout folder is trusted. The flag falls back to off when no value is set.\n\n- If the folder is not trusted or there is no token, nothing extra is sent and the create goes ahead without the field.\n\n- If the server refuses the field with an error, Claude Code logs it and repeats the create without the field.\n\n- Refusals are sorted into reasons such as `not_covered`, `untrusted_device` and `session_stale`.\n\n- Whether the field was sent, not sent, or refused and then retried is recorded.\n\nBefore, the create request carried only its usual details and the flag did not exist. For `tengu_violin_fingerboard`, the flag server returned on for this site's account and for an anonymous baseline check, but no reading has been taken under this release yet.\n\n**Why**\n\nThis lets a cloud session carry proof that the repository it starts from is trusted on your device. Because a refused field leads to a retry without it, creating a cloud session should still work when the server does not accept the field.\n\n- Flag `tengu_violin_fingerboard`: Off by default, switched on for this account (read for one account on one subscription tier against v2.1.281; this account: on, anonymous baseline: on, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Cloud Sessions\n- Tier: Nothing to try yet\n- Useful: 3\/5\n- Signal: 3\/5\n- Present in the build but not switched on"}