Trusted Device Enrollment#
tengu_sessions_elevated_auth_enforcement On for this account, and not off by defaultThe flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.
This account: on · anonymous baseline: on · compiled default in v2.1.86: no gate table built for this version
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.86. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
Claude Code now automatically enrolls your device as a trusted device, sending a X-Trusted-Device-Token header with API requests for enhanced session security.
- Enrollment happens automatically in the background when you're logged in via OAuth
- Device is registered with the display name
Claude Code on <hostname> · <platform> - The token is persisted locally and reused across sessions
- You can override with the
CLAUDE_TRUSTED_DEVICE_TOKENenvironment variable - Enrollment can be skipped in essential-traffic mode
Trusted device enrollment flow (search for "[trusted-device] Enrolled device_id=") — gated by tengu_sessions_elevated_auth_enforcement flag
[Gradual Rollout] — gated by the tengu_sessions_elevated_auth_enforcement feature flag.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.