Auto mode is the permission mode in which Claude Code decides for itself whether an action needs your approval. For people using Claude Code directly with Anthropic, those decisions can be made by a classifier running on Anthropic's servers. A classifier is a model that judges whether an action is safe. Whether that happens is controlled by a server-side setting, the tengu_smooth_chipmunk gate.
The fallback for that setting has changed. When the server sends no value, Claude Code used to leave the server-side classifier out. It now uses the classifier, provided the other checks pass.
Claude Code settles this once per session, so a change on the server does not reach a session that is already running. People using a third-party provider such as Bedrock or Vertex go through a separate path and are not affected.
For anyone the server has not given a value, auto mode's permission decisions are now sent to the server-side classifier by default. Which accounts actually get this is still decided remotely.
tengu_smooth_chipmunk Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.282: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.282. It isn't a statement about your account. What a flag value here can and cannot tell you
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.