Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.86 Home All releases olderv2.1.85 v2.1.87newer
Claude Code v2.1.86

Trusted Device Enrollment

Feature flag
tengu_sessions_elevated_auth_enforcement On for this account, and not off by default

The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.

This account: on · anonymous baseline: on · compiled default in v2.1.86: no gate table built for this version

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.86. It isn't a statement about your account. What a flag value here can and cannot tell you

What

Claude Code now automatically enrolls your device as a trusted device, sending a X-Trusted-Device-Token header with API requests for enhanced session security.

Details
  • Enrollment happens automatically in the background when you're logged in via OAuth
  • Device is registered with the display name Claude Code on <hostname> · <platform>
  • The token is persisted locally and reused across sessions
  • You can override with the CLAUDE_TRUSTED_DEVICE_TOKEN environment variable
  • Enrollment can be skipped in essential-traffic mode
Evidence

Trusted device enrollment flow (search for "[trusted-device] Enrolled device_id=") — gated by tengu_sessions_elevated_auth_enforcement flag

[Gradual Rollout] — gated by the tengu_sessions_elevated_auth_enforcement feature flag.

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.86 →