Wood Chen

An In-Depth Investigation of Claude Code's Account Ban Mechanisms

0 comments461 views2k words

This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文

From: https://github.com/instructkr/claude-code Original: https://bytedance.sg.larkoffice.com/docx/QNsIdi8VFoKm00xY8SRlkXxygve

An In-Depth Investigation of Claude Code's Account Ban Mechanisms

Based on an analysis of leaked Claude Code source code, this report examines its data collection, reporting mechanisms, and account ban triggers

I. Key Findings

Claude Code has built an enterprise-grade user tracking and behavioral analytics system, combining Device ID (a permanent identifier) + environment fingerprints (40+ dimensions) + behavioral telemetry (640+ event types) to build comprehensive user profiles. Account bans are not triggered by a single factor, but by an assessment across multiple dimensions.

The 5 Most Likely Reasons for Account Bans

Rank Reason Risk Level Details
1 Subscription abuse/account sharing Very high Device ID correlation across devices detects multiple devices sharing the same account
2 Rate limit violations High Exceeding rateLimitTier quotas or making frequent calls in a short period
3 Content policy violations High Message content fingerprints + anti-distillation detection
4 Automation abuse Medium CI/CD environment detection + non-interactive mode identification + abnormal token consumption
5 Unofficial clients/tampering Medium Failed fingerprint validation + anomalies in version attribution headers

II. Identity Tracking System

2.1 Persistent Identifiers

Claude Code uses the following identifiers to permanently track users across sessions:

Identifier Generation Method Storage Location Lifetime
Device ID randomBytes(32).toString('hex') ~/.claude.json Permanent, unless manually deleted
Account UUID Issued by the server during OAuth login ~/.claude.json Tied to the account
Organization UUID Issued during OAuth login Same as above Tied to the organization
Session ID randomUUID() generated for each session Memory Single session
Email OAuth or git config user.email Same as above Tied to identity

Device ID is a 256-bit random value generated on first launch and stored permanently. It is the primary identifier in all reported events, allowing Anthropic to precisely correlate all activity on the same device.

2.2 Message Content Fingerprint

Source location: src/utils/fingerprint.ts

算法:SHA256( "59cf53e54c78" + 首条消息[4] + 首条消息[7] + 首条消息[20] + 版本号 )[:3]

This 3-character fingerprint is embedded in:

  • The cc_version field of the HTTP Header x-anthropic-billing-header
  • The System Prompt

Suspected purpose: The backend can use this fingerprint to validate the legitimacy of request sources and detect forged requests from unofficial clients.

2.3 Identity Information Included in Every API Request

HTTP Headers:
  x-app: cli
  User-Agent: claude-cli/2.x.x (external, cli)
  X-Claude-Code-Session-Id: {SESSION_UUID}
  x-anthropic-billing-header: cc_version=2.x.x.{FINGERPRINT}; cc_entrypoint=cli
  x-client-request-id: {REQUEST_UUID}

Request Body metadata:
  user_id: JSON 编码的 Device ID + Account UUID + Session ID

III. Environment Fingerprint Collection (40+ Dimensions)

Claude Code performs extensive enumeration of the user's environment at startup. All the information below is reported to the server.

3.1 System Information

Collection Dimension Data Source Example Value
Operating system process.platform darwin/linux/win32
CPU architecture process.arch x64/arm64
Node.js version process.version v20.x.x
Linux distribution /etc/os-release ubuntu 22.04
Linux kernel os.release() 6.5.0-xxx
WSL version Parsing /proc/version WSL2

3.2 Runtime Environment Detection (40+ Types)

Claude Code automatically identifies runtime environments through environment variables and file checks:

CI/CD platforms:

  • GitHub Actions(GITHUB_ACTIONS)
  • GitLab CI(GITLAB_CI)
  • CircleCI(CIRCLECI)
  • Buildkite(BUILDKITE)
  • Jenkins(JENKINS_URL)

Cloud development environments:

  • GitHub Codespaces(CODESPACES)
  • Gitpod(GITPOD_WORKSPACE_ID)
  • Replit(REPL_ID)
  • Vercel(VERCEL)
  • Railway(RAILWAY_ENVIRONMENT)

Cloud platforms:

  • AWS Lambda/Fargate/ECS/EC2
  • GCP Cloud Run
  • Azure Functions/App Service

Containers and virtualization:

  • Docker (checks for the /.dockerenv file)
  • Kubernetes(KUBERNETES_SERVICE_HOST)
  • WSL(WSL_DISTRO_NAME)

Terminals and IDEs:

  • VSCode(VSCODE_*)
  • Cursor(CURSOR_TRACE_ID)
  • JetBrains(TERMINAL_EMULATOR=JetBrains-JediTerm)
  • tmux/screen/SSH

3.3 Development Toolchain

Detection Type Method Collected Data
Package managers which npm/yarn/pnpm List of available package managers
Runtimes which bun/deno/node List of available runtimes
VCS Checks for .git/.hg/.svn, etc. Version control system type
Git repository git remote get-url origin First 16 characters of the SHA256 hash

3.4 GitHub Actions-Specific Collection

In CI environments, the following additional information is collected:

Field Contents
GITHUB_ACTOR_ID ID of the actor who triggered the workflow
GITHUB_REPOSITORY_ID Repository ID
GITHUB_REPOSITORY_OWNER_ID Repository owner ID
GITHUB_EVENT_NAME Event type
RUNNER_ENVIRONMENT Runner environment
RUNNER_OS Runner operating system

IV. Telemetry Reporting System

4.1 Three Parallel Reporting Channels

This content cannot currently be displayed outside the Lark document

4.2 First-Party Event Logging (The Core Channel)

Reporting endpoint: https://api.anthropic.com/api/event_logging/batch

Reporting frequency: Batches sent every 5 seconds, up to 200 events per batch

Failure recovery: Events that fail to send are persisted to the ~/.claude/telemetry/ directory and automatically retried on the next launch (up to 8 attempts, with exponential backoff)

Key event types (the most important among 640+ types):

Event Name Reported Data Relevance to Account Bans
tengu_init Full environment fingerprint, device information High - environment anomaly detection
tengu_api_success Model name, token usage, duration, cost in USD, TTFT Very high - usage monitoring
tengu_api_error Error type, HTTP status code, retry count Medium - anomalous patterns
tengu_tool_use_* Tool name, execution duration, success/failure Medium - behavioral patterns
tengu_exit Session duration, total token usage High - session-level statistics
tengu_oauth_* Login/refresh/failure events High - account security
tengu_cancel Cancellation actions Low
tengu_auto_mode_* Auto mode usage Medium - automation detection

Actual data:

{
      // ===== Event header =====
      "event_type": "ClaudeCodeInternalEvent",     // Event category

      "event_data": {
          // ===== Basic event information =====
          "event_name": "tengu_config_cache_stats", // Event name: configuration cache statistics
          "event_id": "ed1cae38-01a8-44dd-...",     // Unique event ID
          "client_timestamp": "2026-03-22T10:26:10.747Z",  // Client timestamp

          // ===== User identifiers (core tracking fields) =====
          "device_id": "eab29b910fcc91bxxxxxxxxx8f3c3e6d53d06",
                                                     // Your permanent device ID (256-bit)
          "session_id": "8c503d21-2d92-...",         // Current session ID
          "email": "xxx@gmail.com",              // Your email address (reported directly in plaintext)
          "auth": {
              "organization_uuid": "b2c3112d-...",   // Organization UUID
              "account_uuid": "7616b4d3-..."         // Account UUID
          },

          // ===== Client information =====
          "model": "claude-opus-4-6[1m]",           // Model in use
          "user_type": "external",                   // User type (not an internal employee)
          "entrypoint": "cli",                       // Entry point
          "is_interactive": true,                    // Interactive mode
          "client_type": "cli",                      // Client type
          "betas": "claude-code-20250219,oauth-2025-04-20,...",  // Enabled Beta features

          // ===== Environment fingerprint (50+ dimensions) =====
          "env": {
              "platform": "darwin",                  // macOS
              "platform_raw": "darwin",              // Raw platform
              "arch": "arm64",                       // Apple Silicon
              "node_version": "v24.3.0",             // Node.js version
              "terminal": "tmux",                    // Terminal type
              "package_managers": "npm,pnpm",        // Installed package managers
              "runtimes": "deno,node",               // Installed runtimes
              "is_running_with_bun": true,           // Whether running with Bun
              "is_ci": false,                        // Not a CI environment
              "is_claubbit": false,
              "is_github_action": false,             // Not GitHub Actions
              "is_claude_code_action": false,
              "is_claude_ai_auth": true,             // Uses Claude.ai OAuth authentication
              "is_claude_code_remote": false,        // Not in remote mode
              "is_conductor": false,
              "is_local_agent_mode": false,
              "deployment_environment": "unknown-darwin",
              "version": "2.1.81",                   // Claude Code version
              "version_base": "2.1.81",
              "build_time": "2026-03-20T21:26:18Z",  // Build time
              "vcs": "git"                           // Version control system
          },

          // ===== Process resource monitoring (after Base64 decoding) =====
          "process": {
              "uptime": 22.29,                       // Process has been running for 22 seconds
              "rss": 391266304,                      // Memory usage: 373MB
              "heapTotal": 52228096,                 // Total heap size: 50MB
              "heapUsed": 133928806,                 // Heap used: 128MB
              "external": 88280115,                  // External memory: 84MB
              "arrayBuffers": 23265130,              // ArrayBuffer 22MB
              "constrainedMemory": 51539607552,      // Constrained memory: 48GB (your total memory)
              "cpuUsage": {
                  "user": 1814859,                   // User-mode CPU time in microseconds
                  "system": 325661                   // Kernel-mode CPU time in microseconds
              },
              "cpuPercent": 3.80                     // CPU usage: 3.8%
          },

          // ===== Additional metadata (after Base64 decoding) =====
          "additional_metadata": {
              "rh": "a1eebab6bdf541b1",             // Your Git repository's remote hash
              "cache_hits": 2534,                    // Cache hit count
              "cache_misses": 6,                     // Cache miss count
              "hit_rate": 0.9976                     // Hit rate: 99.76%
          }
      }
  }

4.3 Metadata Attached to Each Event

Core fields:
  session_id          - Session ID
  device_id           - Device ID (permanent)
  account_uuid        - Account UUID
  organization_uuid   - Organization UUID
  subscription_type   - Subscription type (pro/max/enterprise/team)
  rate_limit_tier     - Rate limit tier
  model               - Model used
  version             - Client version
  platform            - Operating system
  arch                - CPU architecture
  entrypoint          - Entry point (cli/sdk/bridge)
  is_interactive      - Whether interactive mode is enabled
  is_ci               - Whether running in a CI environment

Environment fingerprint (env object):
  terminal            - Terminal type
  package_managers     - Package managers
  runtimes            - Runtimes
  is_docker           - Docker environment
  deployment_env      - Deployment environment type
  linux_distro_*      - Linux distribution information

Process resources (Base64-encoded):
  uptime              - Process uptime
  rss                 - Memory usage
  heapUsed            - Heap memory usage
  cpuPercent          - CPU usage

4.4 Datadog Reporting

Endpoint: https://http-intake.logs.us5.datadoghq.com/api/v2/logs

Hardcoded Client Token: pubbbf48e6d78dae54bceaa4acf463299bf

Allowlist: 64 event types

Tagged fields (for backend aggregation, analysis, and alerting):

Tag Description Relevance to Account Bans
userBucket User grouping (IDs hashed into 30 buckets) High - User segmentation
subscriptionType Subscription type Very high - Quota management
model Model used High - Resource consumption
toolName Tool name Medium - Behavioral patterns
platform Operating system Low
provider API provider Medium
version Client version Medium - Outdated version detection

4.5 Bidirectional Data Exchange with GrowthBook

SDK Key: sdk-zAZezfDKGoZuXXKe (external users)

User attributes sent to GrowthBook:

Attribute Description
id Device ID
sessionId Session ID
platform Operating system
organizationUUID Organization ID
accountUUID Account ID
subscriptionType Subscription type
rateLimitTier Rate limit tier
firstTokenTime Timestamp of first use
Attribute Description
email User email
appVersion Client version

Purpose: The server can use these attributes to precisely control feature flags, assign A/B experiments, and even disable features for specific users.


5. Server-Side Remote Control Mechanisms

Anthropic can remotely control client behavior through the following mechanisms, without users knowing.

5.1 Policy Limits (Organization-Level Policy Restrictions)

Endpoint: /api/claude_code/policy_limits

Polling frequency: Every hour

Capabilities:

  • Disable specific tools
  • Restrict feature access
  • Enforce organizational security policies

5.2 Remote Managed Settings (Remote Configuration Push)

Endpoint: /api/claude_code/settings

Capabilities:

  • Push settings.json configuration remotely
  • Modify client behavior
  • Enterprise governance

5.3 Forced Version Upgrades

GrowthBook can deliver minimum version requirements through the tengu_version_config configuration, forcing users on older versions to upgrade.

5.4 Gradual Rollout Control via Feature Flags

Through GrowthBook, the server can target specific users/organizations to:

  • Turn off specific features
  • Adjust rate limits
  • Modify sampling rates
  • Enable/disable Beta features

6. In-Depth Analysis of Account Ban Triggers

6.1 Identity Correlation Detection (Account Sharing)

This content cannot currently be displayed outside the Feishu document

Detection criteria:

  • The same Account UUID appears on multiple Device IDs
  • Devices with different IP addresses, operating systems, and time zones use the same account
  • Logins from different geographic locations within a short period

6.2 Rate Limit Violations

Detection pipeline:

  1. Each API request reports tengu_api_success, including token usage and the model
  2. The server aggregates by account_uuid + subscription_type + rate_limit_tier
  3. Quota threshold exceeded → 429 error → Continued violations → Account ban triggered

Key metrics reported:

Metric Description
inputTokens Input token count
outputTokens Output token count
cacheReadTokens Cache read tokens
cacheCreationTokens Cache creation tokens
costUsd Cost per request in USD
duration Request duration
model Model used

6.3 Content Policy Violations

Defense 1 - Anti-Distillation:

API requests include anti_distillation: ["fake_tools"] to detect whether someone is using Claude Code output to train competing models.

Defense 2 - Message Fingerprinting:

Characters are extracted from specific positions in the first message to compute a fingerprint, which is embedded in the Header and System Prompt so the backend can verify request integrity.

Defense 3 - Additional Protection Flag:

The x-anthropic-additional-protection: true header can trigger stricter server-side content review.

6.4 Automated Abuse Detection

Detection Signal Source Description
is_ci: true Environment variable CI Flagged as a CI environment
is_github_action: true GITHUB_ACTIONS Running in GitHub Actions
is_interactive: false TTY detection Non-interactive invocation
entrypoint: "sdk" Entry point Invoked through the SDK rather than the CLI
auto_mode_* events Auto mode AFK automatic execution mode

Risk combination: Non-interactive + SDK entry point + High-frequency calls + Heavy token consumption → Suspected automated abuse

6.5 Client Tampering Detection

Detection Point Method Consequence
Version fingerprint cc_version={VER}.{FINGERPRINT} Fingerprint mismatch → Flagged as anomalous
User-Agent Format validation Nonstandard format → Possibly an unofficial client
Beta Headers Expected header set Missing/extra headers → Anomaly
System Prompt Contains attribution information Tampering → Detected

7. Complete Data Flow Overview

This content cannot currently be displayed outside the Feishu document


8. Summary of All External Communication Endpoints

Destination URL Frequency Data Can be disabled
Primary API api.anthropic.com Every conversation Conversation content + identity + metadata No
1P events api.anthropic.com/api/event_logging/batch Every 5 seconds 640+ events + environment fingerprint Yes
Datadog datadoghq.com Every 15 seconds 64 event types + tags Yes
GrowthBook api.anthropic.com Every 20 minutes User attributes exchanged for feature configuration Yes
OAuth platform.claude.com Login/refresh Token + account information No
Policy limits api.anthropic.com/api/claude_code/policy_limits Hourly Organization policy queries Yes
Remote settings api.anthropic.com/api/claude_code/settings Background polling settings.json delivery Yes
Domain checks api.anthropic.com/api/web/domain_info Before WebFetch Target domain No
Destination URL Frequency Data Can be disabled
MCP proxy mcp-proxy.anthropic.com MCP calls MCP request data No
Version updates storage.googleapis.com Version checks Update package downloads Yes
Changelog raw.githubusercontent.com After updates Changelog retrieval Yes

9. Recommendations for Protecting Yourself

9.1 Environment Variable Controls

Environment variable Effect
DISABLE_TELEMETRY=1 Disables Datadog + 1P events + feedback surveys
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 Disables all nonessential network traffic (telemetry + updates + GrowthBook)
CLAUDE_CODE_USE_BEDROCK=1 Uses AWS Bedrock (automatically disables all analytics)
CLAUDE_CODE_USE_VERTEX=1 Uses GCP Vertex (automatically disables all analytics)

9.2 Usage Precautions

Behavior Risk Recommendation
Sharing an account across multiple devices Very high Use a separate subscription for each device
Making many API calls in a short period High Limit call frequency
Large-scale use in CI/CD Medium Use an API Key rather than OAuth
Tampering with the client/forging Headers High Do not modify the official client
Not upgrading for a long time Low–medium Keep up with official updates

9.3 Cleaning Up Key Files

File/directory Contents Recommendation
~/.claude.json Device ID + account information Delete the userID field to reset the device identifier
~/.claude/telemetry/ Cached failed telemetry events Clean up regularly
~/.claude/.credentials.json Plaintext credentials (when Keychain is unavailable) Ensure Keychain is available
~/.claude/projects/ Complete conversation history Regularly remove sensitive conversations

10. Summary

Claude Code's data collection system can be summarized as a three-layer model:

Layer Data Purpose
Identity layer Device ID + Account UUID + Email + Fingerprint Precisely track users
Environment layer OS + architecture + terminal + CI + containers + deployment environment Build a device fingerprint
Behavior layer 640+ events + Token usage + tool calls + process resources Analyze usage patterns

These three layers of data are reported in real time through three channels (1P API + Datadog + GrowthBook), giving the server a complete usage profile of each user. It can detect anomalies across multiple dimensions and trigger account bans.

The safest approach: use third-party providers Bedrock/Vertex (which automatically disable all analytics), or set DISABLE_TELEMETRY=1 + limit usage frequency + use one account per person.

Related posts

Comments 0