Claude Code can receive requests from another device over a bridge to run tools on this machine. A tool is an action Claude can take, such as running a command. Each tool says where the sender of a request is checked. Until now, that was always inside the tool itself.
A tool can now ask for the check to happen before it runs. Claude Code then checks the sender and refuses the request if the check holds it back. No tool asks for this yet, so nothing changes in practice.
This moves a security check to one central place, instead of each tool doing its own.
tengu_bridge_attestation_enforce Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.283: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.283. It isn't a statement about your account. What a flag value here can and cannot tell you
It is not clear whether any tool opts in in a less direct way, or whether the refusal depends on the bridge's enforcement setting.