The device bridge lets a cloud session (a Claude Code session running on Anthropic's servers) use tools on your own computer. Before connecting, the bridge now refuses to offer those tools when it cannot check a device's proof and either of these holds:
- your organization enforces the Trusted Devices policy, or an earlier refusal suggests it does
- whether Trusted Devices is required could not be determined
When this happens you see a notice saying "This computer's tools are not offered to your cloud session over the device bridge", with the reason. This only applies to one bridge connection type and only when the switch tengu_sessions_elevated_auth_enforcement is on. That switch falls back to off, though the flag server has returned it on for this site's account and for the anonymous baseline in earlier readings.
In organizations that require trusted devices, cloud sessions will not receive this computer's tools over the bridge, and the notice explains why instead of the tools silently failing.
tengu_sessions_elevated_auth_enforcement Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.282: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.282. It isn't a statement about your account. What a flag value here can and cannot tell you
The code path no longer asks a flag before it runs.
What the "off switch" the notice asks you to remove is, and when the bridge connection type applies, is not settled.