{"version":"2.1.290","anchor":"surface-client-device-attestation-floor-enforcement-on-the-r","canonical_anchor":"surface-client-device-attestation-floor-enforcement-on-the-r","heading":"Remote sessions can now turn away apps on devices that fall below a trust policy","tier":"notice","area":"Sessions","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/surface-client-device-attestation-floor-enforcement-on-the-r","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Remote sessions can now turn away apps on devices that fall below a trust policy\n\nRemote sessions now check attached apps against a device trust policy and refuse ones that fall below it\n\n**Unclear.** Which policy values apply and whether the check is enforced by default are not settled.\n\n**What**\n\nIn a remote session, other apps or screens can attach to watch or drive the session. Claude Code now keeps track of these attached clients and checks each one against a device-attestation policy, which is a rule about how far a device must prove it can be trusted. A client below the policy's minimum is refused. A client that is leaving is still allowed to leave, even if it falls below the minimum.\n\nThe streaming connection that carries the session's events also changed. It now reports a connection that returns an unexpected kind of content, once for each pair of content types, and it has a renewal process that stops when the connection closes.\n\n**Why**\n\nThis is a security change for cloud sessions: who can attach to a session now depends on how trustworthy their device is.\n\n- Flag `tengu_ccr_sse_keepalive_max_interval_s`: Not enough to say (read for one account on one subscription tier against v2.1.290; this account: no value returned, anonymous baseline: no value returned, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Flag `tengu_ccr_event_hold_enabled`: Not enough to say (read for one account on one subscription tier against v2.1.290; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Flag `tengu_ccr_upload_hold_marker`: Not enough to say (read for one account on one subscription tier against v2.1.290; this account: no value returned, anonymous baseline: no value returned, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Sessions\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 4\/5\n- Scope: both\n- Heads-up: yes"}