An In-Depth Investigation of Claude Code's Account Ban Mechanisms
This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文
From: https://github.com/instructkr/claude-code Original: https://bytedance.sg.larkoffice.com/docx/QNsIdi8VFoKm00xY8SRlkXxygve
An In-Depth Investigation of Claude Code's Account Ban Mechanisms
Based on an analysis of leaked Claude Code source code, this report examines its data collection, reporting mechanisms, and account ban triggers
I. Key Findings
Claude Code has built an enterprise-grade user tracking and behavioral analytics system, combining Device ID (a permanent identifier) + environment fingerprints (40+ dimensions) + behavioral telemetry (640+ event types) to build comprehensive user profiles. Account bans are not triggered by a single factor, but by an assessment across multiple dimensions.
The 5 Most Likely Reasons for Account Bans
| Rank | Reason | Risk Level | Details |
|---|---|---|---|
| 1 | Subscription abuse/account sharing | Very high | Device ID correlation across devices detects multiple devices sharing the same account |
| 2 | Rate limit violations | High | Exceeding rateLimitTier quotas or making frequent calls in a short period |
| 3 | Content policy violations | High | Message content fingerprints + anti-distillation detection |
| 4 | Automation abuse | Medium | CI/CD environment detection + non-interactive mode identification + abnormal token consumption |
| 5 | Unofficial clients/tampering | Medium | Failed fingerprint validation + anomalies in version attribution headers |
II. Identity Tracking System
2.1 Persistent Identifiers
Claude Code uses the following identifiers to permanently track users across sessions:
| Identifier | Generation Method | Storage Location | Lifetime |
|---|---|---|---|
| Device ID | randomBytes(32).toString('hex') |
~/.claude.json |
Permanent, unless manually deleted |
| Account UUID | Issued by the server during OAuth login | ~/.claude.json |
Tied to the account |
| Organization UUID | Issued during OAuth login | Same as above | Tied to the organization |
| Session ID | randomUUID() generated for each session |
Memory | Single session |
OAuth or git config user.email |
Same as above | Tied to identity |
Device ID is a 256-bit random value generated on first launch and stored permanently. It is the primary identifier in all reported events, allowing Anthropic to precisely correlate all activity on the same device.
2.2 Message Content Fingerprint
Source location: src/utils/fingerprint.ts
算法:SHA256( "59cf53e54c78" + 首条消息[4] + 首条消息[7] + 首条消息[20] + 版本号 )[:3]
This 3-character fingerprint is embedded in:
- The
cc_versionfield of the HTTP Headerx-anthropic-billing-header - The System Prompt
Suspected purpose: The backend can use this fingerprint to validate the legitimacy of request sources and detect forged requests from unofficial clients.
2.3 Identity Information Included in Every API Request
HTTP Headers:
x-app: cli
User-Agent: claude-cli/2.x.x (external, cli)
X-Claude-Code-Session-Id: {SESSION_UUID}
x-anthropic-billing-header: cc_version=2.x.x.{FINGERPRINT}; cc_entrypoint=cli
x-client-request-id: {REQUEST_UUID}
Request Body metadata:
user_id: JSON 编码的 Device ID + Account UUID + Session ID
III. Environment Fingerprint Collection (40+ Dimensions)
Claude Code performs extensive enumeration of the user's environment at startup. All the information below is reported to the server.
3.1 System Information
| Collection Dimension | Data Source | Example Value |
|---|---|---|
| Operating system | process.platform |
darwin/linux/win32 |
| CPU architecture | process.arch |
x64/arm64 |
| Node.js version | process.version |
v20.x.x |
| Linux distribution | /etc/os-release |
ubuntu 22.04 |
| Linux kernel | os.release() |
6.5.0-xxx |
| WSL version | Parsing /proc/version |
WSL2 |
3.2 Runtime Environment Detection (40+ Types)
Claude Code automatically identifies runtime environments through environment variables and file checks:
CI/CD platforms:
- GitHub Actions(
GITHUB_ACTIONS) - GitLab CI(
GITLAB_CI) - CircleCI(
CIRCLECI) - Buildkite(
BUILDKITE) - Jenkins(
JENKINS_URL)
Cloud development environments:
- GitHub Codespaces(
CODESPACES) - Gitpod(
GITPOD_WORKSPACE_ID) - Replit(
REPL_ID) - Vercel(
VERCEL) - Railway(
RAILWAY_ENVIRONMENT)
Cloud platforms:
- AWS Lambda/Fargate/ECS/EC2
- GCP Cloud Run
- Azure Functions/App Service
Containers and virtualization:
- Docker (checks for the
/.dockerenvfile) - Kubernetes(
KUBERNETES_SERVICE_HOST) - WSL(
WSL_DISTRO_NAME)
Terminals and IDEs:
- VSCode(
VSCODE_*) - Cursor(
CURSOR_TRACE_ID) - JetBrains(
TERMINAL_EMULATOR=JetBrains-JediTerm) - tmux/screen/SSH
3.3 Development Toolchain
| Detection Type | Method | Collected Data |
|---|---|---|
| Package managers | which npm/yarn/pnpm |
List of available package managers |
| Runtimes | which bun/deno/node |
List of available runtimes |
| VCS | Checks for .git/.hg/.svn, etc. |
Version control system type |
| Git repository | git remote get-url origin |
First 16 characters of the SHA256 hash |
3.4 GitHub Actions-Specific Collection
In CI environments, the following additional information is collected:
| Field | Contents |
|---|---|
GITHUB_ACTOR_ID |
ID of the actor who triggered the workflow |
GITHUB_REPOSITORY_ID |
Repository ID |
GITHUB_REPOSITORY_OWNER_ID |
Repository owner ID |
GITHUB_EVENT_NAME |
Event type |
RUNNER_ENVIRONMENT |
Runner environment |
RUNNER_OS |
Runner operating system |
IV. Telemetry Reporting System
4.1 Three Parallel Reporting Channels
This content cannot currently be displayed outside the Lark document
4.2 First-Party Event Logging (The Core Channel)
Reporting endpoint: https://api.anthropic.com/api/event_logging/batch
Reporting frequency: Batches sent every 5 seconds, up to 200 events per batch
Failure recovery: Events that fail to send are persisted to the ~/.claude/telemetry/ directory and automatically retried on the next launch (up to 8 attempts, with exponential backoff)
Key event types (the most important among 640+ types):
| Event Name | Reported Data | Relevance to Account Bans |
|---|---|---|
tengu_init |
Full environment fingerprint, device information | High - environment anomaly detection |
tengu_api_success |
Model name, token usage, duration, cost in USD, TTFT | Very high - usage monitoring |
tengu_api_error |
Error type, HTTP status code, retry count | Medium - anomalous patterns |
tengu_tool_use_* |
Tool name, execution duration, success/failure | Medium - behavioral patterns |
tengu_exit |
Session duration, total token usage | High - session-level statistics |
tengu_oauth_* |
Login/refresh/failure events | High - account security |
tengu_cancel |
Cancellation actions | Low |
tengu_auto_mode_* |
Auto mode usage | Medium - automation detection |
Actual data:
{
// ===== Event header =====
"event_type": "ClaudeCodeInternalEvent", // Event category
"event_data": {
// ===== Basic event information =====
"event_name": "tengu_config_cache_stats", // Event name: configuration cache statistics
"event_id": "ed1cae38-01a8-44dd-...", // Unique event ID
"client_timestamp": "2026-03-22T10:26:10.747Z", // Client timestamp
// ===== User identifiers (core tracking fields) =====
"device_id": "eab29b910fcc91bxxxxxxxxx8f3c3e6d53d06",
// Your permanent device ID (256-bit)
"session_id": "8c503d21-2d92-...", // Current session ID
"email": "xxx@gmail.com", // Your email address (reported directly in plaintext)
"auth": {
"organization_uuid": "b2c3112d-...", // Organization UUID
"account_uuid": "7616b4d3-..." // Account UUID
},
// ===== Client information =====
"model": "claude-opus-4-6[1m]", // Model in use
"user_type": "external", // User type (not an internal employee)
"entrypoint": "cli", // Entry point
"is_interactive": true, // Interactive mode
"client_type": "cli", // Client type
"betas": "claude-code-20250219,oauth-2025-04-20,...", // Enabled Beta features
// ===== Environment fingerprint (50+ dimensions) =====
"env": {
"platform": "darwin", // macOS
"platform_raw": "darwin", // Raw platform
"arch": "arm64", // Apple Silicon
"node_version": "v24.3.0", // Node.js version
"terminal": "tmux", // Terminal type
"package_managers": "npm,pnpm", // Installed package managers
"runtimes": "deno,node", // Installed runtimes
"is_running_with_bun": true, // Whether running with Bun
"is_ci": false, // Not a CI environment
"is_claubbit": false,
"is_github_action": false, // Not GitHub Actions
"is_claude_code_action": false,
"is_claude_ai_auth": true, // Uses Claude.ai OAuth authentication
"is_claude_code_remote": false, // Not in remote mode
"is_conductor": false,
"is_local_agent_mode": false,
"deployment_environment": "unknown-darwin",
"version": "2.1.81", // Claude Code version
"version_base": "2.1.81",
"build_time": "2026-03-20T21:26:18Z", // Build time
"vcs": "git" // Version control system
},
// ===== Process resource monitoring (after Base64 decoding) =====
"process": {
"uptime": 22.29, // Process has been running for 22 seconds
"rss": 391266304, // Memory usage: 373MB
"heapTotal": 52228096, // Total heap size: 50MB
"heapUsed": 133928806, // Heap used: 128MB
"external": 88280115, // External memory: 84MB
"arrayBuffers": 23265130, // ArrayBuffer 22MB
"constrainedMemory": 51539607552, // Constrained memory: 48GB (your total memory)
"cpuUsage": {
"user": 1814859, // User-mode CPU time in microseconds
"system": 325661 // Kernel-mode CPU time in microseconds
},
"cpuPercent": 3.80 // CPU usage: 3.8%
},
// ===== Additional metadata (after Base64 decoding) =====
"additional_metadata": {
"rh": "a1eebab6bdf541b1", // Your Git repository's remote hash
"cache_hits": 2534, // Cache hit count
"cache_misses": 6, // Cache miss count
"hit_rate": 0.9976 // Hit rate: 99.76%
}
}
}
4.3 Metadata Attached to Each Event
Core fields:
session_id - Session ID
device_id - Device ID (permanent)
account_uuid - Account UUID
organization_uuid - Organization UUID
subscription_type - Subscription type (pro/max/enterprise/team)
rate_limit_tier - Rate limit tier
model - Model used
version - Client version
platform - Operating system
arch - CPU architecture
entrypoint - Entry point (cli/sdk/bridge)
is_interactive - Whether interactive mode is enabled
is_ci - Whether running in a CI environment
Environment fingerprint (env object):
terminal - Terminal type
package_managers - Package managers
runtimes - Runtimes
is_docker - Docker environment
deployment_env - Deployment environment type
linux_distro_* - Linux distribution information
Process resources (Base64-encoded):
uptime - Process uptime
rss - Memory usage
heapUsed - Heap memory usage
cpuPercent - CPU usage
4.4 Datadog Reporting
Endpoint: https://http-intake.logs.us5.datadoghq.com/api/v2/logs
Hardcoded Client Token: pubbbf48e6d78dae54bceaa4acf463299bf
Allowlist: 64 event types
Tagged fields (for backend aggregation, analysis, and alerting):
| Tag | Description | Relevance to Account Bans |
|---|---|---|
userBucket |
User grouping (IDs hashed into 30 buckets) | High - User segmentation |
subscriptionType |
Subscription type | Very high - Quota management |
model |
Model used | High - Resource consumption |
toolName |
Tool name | Medium - Behavioral patterns |
platform |
Operating system | Low |
provider |
API provider | Medium |
version |
Client version | Medium - Outdated version detection |
4.5 Bidirectional Data Exchange with GrowthBook
SDK Key: sdk-zAZezfDKGoZuXXKe (external users)
User attributes sent to GrowthBook:
| Attribute | Description |
|---|---|
id |
Device ID |
sessionId |
Session ID |
platform |
Operating system |
organizationUUID |
Organization ID |
accountUUID |
Account ID |
subscriptionType |
Subscription type |
rateLimitTier |
Rate limit tier |
firstTokenTime |
Timestamp of first use |
| Attribute | Description |
|---|---|
email |
User email |
appVersion |
Client version |
Purpose: The server can use these attributes to precisely control feature flags, assign A/B experiments, and even disable features for specific users.
5. Server-Side Remote Control Mechanisms
Anthropic can remotely control client behavior through the following mechanisms, without users knowing.
5.1 Policy Limits (Organization-Level Policy Restrictions)
Endpoint: /api/claude_code/policy_limits
Polling frequency: Every hour
Capabilities:
- Disable specific tools
- Restrict feature access
- Enforce organizational security policies
5.2 Remote Managed Settings (Remote Configuration Push)
Endpoint: /api/claude_code/settings
Capabilities:
- Push
settings.jsonconfiguration remotely - Modify client behavior
- Enterprise governance
5.3 Forced Version Upgrades
GrowthBook can deliver minimum version requirements through the tengu_version_config configuration, forcing users on older versions to upgrade.
5.4 Gradual Rollout Control via Feature Flags
Through GrowthBook, the server can target specific users/organizations to:
- Turn off specific features
- Adjust rate limits
- Modify sampling rates
- Enable/disable Beta features
6. In-Depth Analysis of Account Ban Triggers
6.1 Identity Correlation Detection (Account Sharing)
This content cannot currently be displayed outside the Feishu document
Detection criteria:
- The same Account UUID appears on multiple Device IDs
- Devices with different IP addresses, operating systems, and time zones use the same account
- Logins from different geographic locations within a short period
6.2 Rate Limit Violations
Detection pipeline:
- Each API request reports
tengu_api_success, including token usage and the model - The server aggregates by
account_uuid+subscription_type+rate_limit_tier - Quota threshold exceeded → 429 error → Continued violations → Account ban triggered
Key metrics reported:
| Metric | Description |
|---|---|
inputTokens |
Input token count |
outputTokens |
Output token count |
cacheReadTokens |
Cache read tokens |
cacheCreationTokens |
Cache creation tokens |
costUsd |
Cost per request in USD |
duration |
Request duration |
model |
Model used |
6.3 Content Policy Violations
Defense 1 - Anti-Distillation:
API requests include anti_distillation: ["fake_tools"] to detect whether someone is using Claude Code output to train competing models.
Defense 2 - Message Fingerprinting:
Characters are extracted from specific positions in the first message to compute a fingerprint, which is embedded in the Header and System Prompt so the backend can verify request integrity.
Defense 3 - Additional Protection Flag:
The x-anthropic-additional-protection: true header can trigger stricter server-side content review.
6.4 Automated Abuse Detection
| Detection Signal | Source | Description |
|---|---|---|
is_ci: true |
Environment variable CI |
Flagged as a CI environment |
is_github_action: true |
GITHUB_ACTIONS |
Running in GitHub Actions |
is_interactive: false |
TTY detection | Non-interactive invocation |
entrypoint: "sdk" |
Entry point | Invoked through the SDK rather than the CLI |
auto_mode_* events |
Auto mode | AFK automatic execution mode |
Risk combination: Non-interactive + SDK entry point + High-frequency calls + Heavy token consumption → Suspected automated abuse
6.5 Client Tampering Detection
| Detection Point | Method | Consequence |
|---|---|---|
| Version fingerprint | cc_version={VER}.{FINGERPRINT} |
Fingerprint mismatch → Flagged as anomalous |
| User-Agent | Format validation | Nonstandard format → Possibly an unofficial client |
| Beta Headers | Expected header set | Missing/extra headers → Anomaly |
| System Prompt | Contains attribution information | Tampering → Detected |
7. Complete Data Flow Overview
This content cannot currently be displayed outside the Feishu document
8. Summary of All External Communication Endpoints
| Destination | URL | Frequency | Data | Can be disabled |
|---|---|---|---|---|
| Primary API | api.anthropic.com |
Every conversation | Conversation content + identity + metadata | No |
| 1P events | api.anthropic.com/api/event_logging/batch |
Every 5 seconds | 640+ events + environment fingerprint | Yes |
| Datadog | datadoghq.com |
Every 15 seconds | 64 event types + tags | Yes |
| GrowthBook | api.anthropic.com |
Every 20 minutes | User attributes exchanged for feature configuration | Yes |
| OAuth | platform.claude.com |
Login/refresh | Token + account information | No |
| Policy limits | api.anthropic.com/api/claude_code/policy_limits |
Hourly | Organization policy queries | Yes |
| Remote settings | api.anthropic.com/api/claude_code/settings |
Background polling | settings.json delivery | Yes |
| Domain checks | api.anthropic.com/api/web/domain_info |
Before WebFetch | Target domain | No |
| Destination | URL | Frequency | Data | Can be disabled |
|---|---|---|---|---|
| MCP proxy | mcp-proxy.anthropic.com |
MCP calls | MCP request data | No |
| Version updates | storage.googleapis.com |
Version checks | Update package downloads | Yes |
| Changelog | raw.githubusercontent.com |
After updates | Changelog retrieval | Yes |
9. Recommendations for Protecting Yourself
9.1 Environment Variable Controls
| Environment variable | Effect |
|---|---|
DISABLE_TELEMETRY=1 |
Disables Datadog + 1P events + feedback surveys |
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 |
Disables all nonessential network traffic (telemetry + updates + GrowthBook) |
CLAUDE_CODE_USE_BEDROCK=1 |
Uses AWS Bedrock (automatically disables all analytics) |
CLAUDE_CODE_USE_VERTEX=1 |
Uses GCP Vertex (automatically disables all analytics) |
9.2 Usage Precautions
| Behavior | Risk | Recommendation |
|---|---|---|
| Sharing an account across multiple devices | Very high | Use a separate subscription for each device |
| Making many API calls in a short period | High | Limit call frequency |
| Large-scale use in CI/CD | Medium | Use an API Key rather than OAuth |
| Tampering with the client/forging Headers | High | Do not modify the official client |
| Not upgrading for a long time | Low–medium | Keep up with official updates |
9.3 Cleaning Up Key Files
| File/directory | Contents | Recommendation |
|---|---|---|
~/.claude.json |
Device ID + account information | Delete the userID field to reset the device identifier |
~/.claude/telemetry/ |
Cached failed telemetry events | Clean up regularly |
~/.claude/.credentials.json |
Plaintext credentials (when Keychain is unavailable) | Ensure Keychain is available |
~/.claude/projects/ |
Complete conversation history | Regularly remove sensitive conversations |
10. Summary
Claude Code's data collection system can be summarized as a three-layer model:
| Layer | Data | Purpose |
|---|---|---|
| Identity layer | Device ID + Account UUID + Email + Fingerprint | Precisely track users |
| Environment layer | OS + architecture + terminal + CI + containers + deployment environment | Build a device fingerprint |
| Behavior layer | 640+ events + Token usage + tool calls + process resources | Analyze usage patterns |
These three layers of data are reported in real time through three channels (1P API + Datadog + GrowthBook), giving the server a complete usage profile of each user. It can detect anomalies across multiple dimensions and trigger account bans.
The safest approach: use third-party providers Bedrock/Vertex (which automatically disable all analytics), or set DISABLE_TELEMETRY=1 + limit usage frequency + use one account per person.
Comments 0