Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Bridge attestation enforcement now falls back to on

The tengu_bridge_attestation_enforce flag now falls back to on instead of off when no trusted value is found, and its config has a new source order

Group of 2 Under the hood Internal Changes
JSON All of v2.1.288
Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Device AttestationArea: what it touches
Internal ChangesKind: in v2.1.288,
Internal ChangesSection of the release

What

Claude Code can receive requests from another device over a bridge. Attestation is a check that the device sending them is genuine. Whether that check is enforced is controlled by the feature flag tengu_bridge_attestation_enforce, a switch Anthropic controls from its servers. How the flag is read has changed:

  • It used to fall back to off when no value was available. It is now read through a helper whose safe value is on (safe: true).
  • The helper ignores a value from the server that differs from the safe value unless an extra check passes.
  • The settings object tengu_bridge_attestation_enforce_config is now resolved from the server payload, a saved copy on disk, or an override, and its acceptLevel is merged with a default.

The flag server returned on for this site's account and for an anonymous check, but no reading has been taken under this release yet. Nothing has been read about the config.

Why

When no trusted value is found, attestation enforcement now falls back to on rather than off, which changes the default security stance for bridged requests.

Read from
Feature flag
tengu_bridge_attestation_enforce On for this account, and not off by default

The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.

This account: on · anonymous baseline: on · compiled default in v2.1.288: not a boolean we can read

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

tengu_bridge_attestation_enforce_config Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.288: not a boolean we can read

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat the switch falls back to when no value is present could not be determined.

See this entry in the whole of v2.1.288 →

Feedback