MEASURED · TESTED Aug 14, 2026
Does Claude Code phone home?
The documented opt-out removed every observed nonessential route in 3/3 fixed-window runs.
RETEST QUEUEDUpstream 2.1.233 was detected Aug 14, 2026. Every result on this page remains scoped to tested build 2.1.232.
PREVIOUS TESTED BUILD 2.1.229 · Aug 13, 2026Exact official npm native binary, fresh profile and workspace, fixed prompt, deliberately invalid API key, fixed 45-second observation window. Authentication failed as designed; this measures startup and failed-request traffic, not successful coding work.
RELEASE CHANGE · 2.1.229 → 2.1.232
Not comparable across this protocol change.
The previous build used 1.0.0-legacy-response-only; this build uses 2.0.0 with a fixed window and request-time capture. Showing a version delta would mix tool behavior with measurement changes.
default
Documented defaults
- RUNS
- 3/3
- REQUESTS
- 29 · 29 · 29
| Destination | Route | Observed | Counts | Class |
|---|---|---|---|---|
| api.anthropic.comAnthropic | GET /api/:opaque |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /api/claude_cli/bootstrap |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /api/claude_code/organizations/metrics_enabled |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /api/claude_code/policy_limits |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /api/claude_code/settings |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /mcp-registry/v0/servers |
OBSERVED | 4 / 4 / 4 | first party |
| api.anthropic.comAnthropic | POST /api/eval/:opaque |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | POST /api/event_logging/v2/batch |
OBSERVED | 4 / 4 / 4 | first party |
| api.anthropic.comAnthropic | POST /v1/messages |
OBSERVED | 14 / 14 / 14 | first party |
| http-intake.logs.us5.datadoghq.comDatadog | POST /api/v2/logs |
OBSERVED | 1 / 1 / 1 | third party |
documented-opt-out
Documented nonessential-traffic opt-out
- RUNS
- 3/3
- REQUESTS
- 9 · 9 · 9
| Destination | Route | Observed | Counts | Class |
|---|---|---|---|---|
| api.anthropic.comAnthropic | GET /api/:opaque |
NOT OBSERVED | 0 / 0 / 0 | first party |
| api.anthropic.comAnthropic | GET /api/claude_cli/bootstrap |
NOT OBSERVED | 0 / 0 / 0 | first party |
| api.anthropic.comAnthropic | GET /api/claude_code/organizations/metrics_enabled |
NOT OBSERVED | 0 / 0 / 0 | first party |
| api.anthropic.comAnthropic | GET /api/claude_code/policy_limits |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /api/claude_code/settings |
OBSERVED | 1 / 1 / 1 | first party |
| api.anthropic.comAnthropic | GET /mcp-registry/v0/servers |
NOT OBSERVED | 0 / 0 / 0 | first party |
| api.anthropic.comAnthropic | POST /api/eval/:opaque |
NOT OBSERVED | 0 / 0 / 0 | first party |
| api.anthropic.comAnthropic | POST /api/event_logging/v2/batch |
NOT OBSERVED | 0 / 0 / 0 | first party |
| api.anthropic.comAnthropic | POST /v1/messages |
OBSERVED | 7 / 7 / 7 | first party |
| http-intake.logs.us5.datadoghq.comDatadog | POST /api/v2/logs |
NOT OBSERVED | 0 / 0 / 0 | third party |
WHAT THIS SUPPORTS
Default runs contacted Anthropic API routes and a Datadog intake. With all four documented nonessential-traffic flags set, only Anthropic settings, policy-limit and failed message requests remained in the final three-run batch.
WHAT IT DOES NOT SUPPORT
- The API key was intentionally invalid, so no successful model response or tool call occurred.
- The final evidence uses macOS arm64, one network path behind the operator's existing VPN and a fixed 45-second window.
- Processes still running at 45 seconds were terminated by the harness; this is not a natural-exit measurement.
- Not observed means absent from these captures, not impossible in another cohort or later run.
- Request and response bodies are withheld; purpose, retention, training and privacy claims are out of scope.
EVIDENCE CHAIN
Hashes identify the private raw captures and public sanitized manifests.
Raw captures are withheld because they contain request and response bodies. Sanitized manifests contain route facts only.
Binary SHA-256
7b39c1588df919d001dea3ffd5651adb682f2451b5a0e18d42d4233296b53cc7Raw capture SHA-256
17e9574b61177cdff88515966dedaebd09fd3f6cf30cfe2cc1f0f615ba7b8cf4
ac7db7715de83b4eaea5c05152d7eb1141afbf26f38483b940207fa523148ae3
40057aa240aa943c802735ab0a80b102866ba90f21e7be477eed7099cdd78bec
ceb8e72fcc1d8c623c3dd634a9a57b171e2a89f8413cea33a03cf47add089892
1251b03f7384bf08e09333ef5a389e0ec0556109a7fa80a1d2dcd7da532d6722
8d41c47bfba284f1bb3eb143be336a942bef5b804f85797fbc0d1979b7a1435aSanitized manifest SHA-256
9c10dffb8e935366d9bb3d669e4a59f8872d9c4c1802020500e35e8f4f54fd48
46c84cd74bfbb84cb0935edb71ace6a6b3339dfb12884e94bc1d0c40b710c687
0306fd5598456cd63423288237c2ac9da5ecd7f7bc1e74bb80597a8f24e93d5c
a2c9892dba3e000ef8648503428e1a5cb81539a2212a4e27b1c19b030f101b29
c03f611ef8c16aff759c68c30a1040469881286f5d182265e686a5cffe400713
644e14c6213a436367df25c87506f5c01619cef5588ef3c4c6382a369431ca42