{
 "schemaVersion": "1.0.0",
 "generatedAt": "2026-08-13T21:20:39Z",
 "claimContract": "A result describes only what this exact build did in this exact test. It does not establish purpose, retention, training use, sale, safety, or behavior in another account, region, operating system, or scenario.",
 "method": {
  "platform": "macOS 15 arm64",
  "network": "Existing operator VPN remained enabled. The lab does not claim a geographic cohort.",
  "capture": "Fresh per-run config and data directories; one CLI process per local mitmproxy instance; HTTP(S) proxy; dedicated test CA where accepted.",
  "redaction": "No credentials, header values, query strings, request bodies, response bodies, prompts, model output, file paths, or IP addresses are published.",
  "repeats": 3,
  "statusVocabulary": [
   "observed",
   "not_observed",
   "opaque",
   "inconclusive",
   "not_tested"
  ]
 },
 "tool": {
  "id": "claude-code",
  "name": "Claude Code",
  "vendor": "Anthropic",
  "version": "2.1.229",
  "binarySha256": "d732f0ba0a539c58c2ffcaef06ed03b4e523726f0cb6cc27b3a5b7e7ae0a7a21",
  "testedAt": "2026-08-13T21:14:00Z",
  "path": "/claude-code/telemetry",
  "feed": "/claude-code/telemetry/feed.xml",
  "status": "measured",
  "headline": "The documented nonessential-traffic opt-out changed the wire trace in 3/3 startup runs.",
  "summary": "Default runs reached Anthropic event logging and a Datadog intake. With all documented telemetry and nonessential-traffic flags set, neither route was observed in three repeats.",
  "scenario": "Fresh profile, fixed prompt, deliberately invalid API key. Authentication failed as designed; this measures startup and failed-request traffic, not a successful coding session.",
  "configs": [
   {
    "id": "default",
    "label": "Documented defaults",
    "repeats": 3,
    "requestCounts": [
     25,
     25,
     24
    ],
    "destinations": [
     {
      "host": "api.anthropic.com",
      "owner": "Anthropic",
      "classification": "first_party",
      "observedIn": 3,
      "paths": [
       {
        "method": "POST",
        "path": "/api/event_logging/v2/batch",
        "counts": [
         3,
         3,
         2
        ],
        "status": "observed"
       },
       {
        "method": "POST",
        "path": "/api/eval/:opaque",
        "counts": [
         1,
         1,
         1
        ],
        "status": "observed"
       },
       {
        "method": "GET",
        "path": "/api/claude_cli/bootstrap",
        "counts": [
         1,
         1,
         1
        ],
        "status": "observed"
       },
       {
        "method": "GET",
        "path": "/mcp-registry/v0/servers",
        "counts": [
         4,
         4,
         4
        ],
        "status": "observed"
       },
       {
        "method": "POST",
        "path": "/v1/messages",
        "counts": [
         12,
         12,
         12
        ],
        "status": "observed"
       }
      ]
     },
     {
      "host": "http-intake.logs.us5.datadoghq.com",
      "owner": "Datadog",
      "classification": "third_party",
      "observedIn": 3,
      "paths": [
       {
        "method": "POST",
        "path": "/api/v2/logs",
        "counts": [
         1,
         1,
         1
        ],
        "status": "observed"
       }
      ]
     }
    ]
   },
   {
    "id": "documented-opt-out",
    "label": "All documented opt-outs",
    "flags": [
     "CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1",
     "DISABLE_TELEMETRY=1",
     "DISABLE_ERROR_REPORTING=1",
     "DO_NOT_TRACK=1"
    ],
    "repeats": 3,
    "requestCounts": [
     8,
     8,
     8
    ],
    "destinations": [
     {
      "host": "api.anthropic.com",
      "owner": "Anthropic",
      "classification": "first_party",
      "observedIn": 3,
      "paths": [
       {
        "method": "GET",
        "path": "/api/claude_code/settings",
        "counts": [
         1,
         1,
         1
        ],
        "status": "observed"
       },
       {
        "method": "GET",
        "path": "/api/claude_code/policy_limits",
        "counts": [
         1,
         1,
         1
        ],
        "status": "observed"
       },
       {
        "method": "POST",
        "path": "/v1/messages",
        "counts": [
         6,
         6,
         6
        ],
        "status": "observed"
       },
       {
        "method": "POST",
        "path": "/api/event_logging/v2/batch",
        "counts": [
         0,
         0,
         0
        ],
        "status": "not_observed"
       },
       {
        "method": "POST",
        "path": "/api/eval/:opaque",
        "counts": [
         0,
         0,
         0
        ],
        "status": "not_observed"
       },
       {
        "method": "GET",
        "path": "/api/claude_cli/bootstrap",
        "counts": [
         0,
         0,
         0
        ],
        "status": "not_observed"
       },
       {
        "method": "GET",
        "path": "/mcp-registry/v0/servers",
        "counts": [
         0,
         0,
         0
        ],
        "status": "not_observed"
       }
      ]
     },
     {
      "host": "http-intake.logs.us5.datadoghq.com",
      "owner": "Datadog",
      "classification": "third_party",
      "observedIn": 0,
      "paths": [
       {
        "method": "POST",
        "path": "/api/v2/logs",
        "counts": [
         0,
         0,
         0
        ],
        "status": "not_observed"
       }
      ]
     }
    ]
   }
  ],
  "evidence": {
   "harness": "scripts/mitm-sanitize.py",
   "rawCaptureSha256": [
    "f8b4554250421912852c7e0e08c94576774733649c034dc6e71cf843a37f8fbe",
    "fc8cff38a2eea8f099c39f116ea34929415bfc96d47d3d8c72364929866d5496",
    "c12a95e1b1895fea3ce87603c5d328adbb1f9ed9e4b0ca513170f1839f5713fb",
    "2e9b0628ed3c137c8670a9e3a7233b51d4c34d69b530d114efd15cd8f37ef0cf",
    "6a6b10609d90189443a13b9f057ff86ad52f7dd1edfc6b0dfb0a823972a02037",
    "bd83a0cb42e99c69e616ea0df1bd0e80b8ff32c41be2334f8b6694b712b74579"
   ],
   "sanitizedManifestSha256": [
    "7459f20995b062ee4804f2aabbfe9ce63b249053e12a0b65c5bd47f121d3e735",
    "0b08c23af0037baa4fa3b3ab420fc5269a027919511acb8dd8f414dc4d2c5a16",
    "8805cf8a9695be0f444086186e1c9f174512461eba5e176c354b23c05029d313",
    "86a3741daa0eea70988fe8acd1c4fe5389ebd5acf8ace77c9419216164e68778",
    "fe6c665982d04de99afe89fe9d962303720fa0a8cc09d9d81a527df34b306ad1",
    "4461b019425e880ead0297b7fe386f73b33fad29ad7df354bcba0d78d61a1a1d"
   ]
  },
  "limitations": [
   "The API key was intentionally invalid, so no successful model response or tool call occurred.",
   "The test used macOS arm64 and one network path behind the operator's existing VPN.",
   "Not observed means absent from these three captures, not impossible in another cohort or later run.",
   "Request and response bodies are withheld; field-purpose and retention claims are out of scope."
  ],
  "manifest": "/evidence/claude-code-2.1.229.json"
 }
}