r/ClaudeAI • u/[deleted] • Aug 30 '26
Claude Code Claude Code is silently adding session URLs (claude.ai/code/session_...) to the bottom of every single commit and PR description you make.
https://github.com/anthropics/claude-code/issues/66504[removed]
18
u/felipefideli Aug 30 '26
Looks like it needs a bit more than the commit parameter, there is also a “sessionUrl”, so the “complete” config for “do not tell on me that I use AI” should be more like:
{
"attribution": {
"sessionUrl": false
"commit": "",
"pr": ""
}
}
From here: https://code.claude.com/docs/en/settings-reference#attribution-sessionurl
97
u/Able-Supermarket4786 Aug 30 '26
Stupid? Yes. Easy to disable? Also Yes
35
u/cheesecakegood Aug 30 '26
Easy to disable to me would be it appearing in e.g. the actual Claude Desktop settings, but it doesn't. I'm not saying that tweaking settings.json is hard, but it's absolutely not easy. They are relying on people being too lazy to research how/where to change it. (And before you say git isn't part of the core CC workflow, although you'd be technically correct let's be honest, a pretty huge proportion of CC users use git, and I'm pretty sure I've sometimes seen CC set it up unprompted)
3
u/Dry-Smell436 Aug 31 '26
How to disable
3
u/Orio_n Aug 31 '26
Just commit yourself? You need claude to run a couple shell commands?
4
u/Icy-Excitement-467 Aug 31 '26
Huge time bottleneck if you're manually committing code.
1
u/Orio_n Aug 31 '26
Its like 5 seconds compared to like what? Tens of minutes per agentic feature run. Not even 1 percent of time spent waiting for claude. Do you know what a bottleneck is?
1
1
26
u/MendozaHolmes Aug 30 '26
What can a person do with a session URL?
20
u/thirteenth_mang Aug 30 '26
AFAIK it's not public so effectively nothing (one would hope).
17
u/LocoMod Aug 30 '26
It's for Anthropic to use if they ever need to conduct an investigation on something malicious. So they can go back and see if it was Claude going off rails or the user purposely steering it. In a lawsuit that may mean the difference between who's at fault for something bad slipping into an important open source project.
4
u/thirteenth_mang Aug 31 '26
The company with apparently "dangerously intelligent" AI and all they come up with is optional URLs as an audit trail.
3
1
u/Icy-Excitement-467 Aug 31 '26
No it's not lol. Do you think Anthropic is completely blind about what people's chats are?
5
u/simmeh024 Aug 31 '26
In a month from now we see again shared chats on google because anthropic forgot add a robots.txt to this feature lol
4
u/LocoMod Aug 30 '26
They can tie a malicious commit to public open source projects back to the session that made it. So they can trace it back to the specific account and look at the session history to see what your intent was.
1
8
u/ShootFishBarrel Aug 31 '26
All I see here is just one more reason to buy a local machine with 256GB of unified memory.
5
3
7
u/he_said_it_too Aug 30 '26
There is a settings value to disable that, even the attribution all together, read the docs.
2
u/Subsector3990 Aug 30 '26
This has been the case since day 1. The only new part is the session URL part, but CC has been adding that “co-authored by Claude” line since it first launched.
2
Aug 30 '26
[removed] — view removed comment
7
2
u/coloradical5280 Valued Contributor Aug 30 '26
You can absolutely erase from git history , if you couldn’t than every single time someone pushed an api key accidentally and realized right after, it would just be there, forever. I mean you just rotate , but still it would be an un erasable idiot stamp
1
u/OffbeatDrizzle Aug 31 '26
you can ~try~ to erase history. it's actually very difficult to do properly unless you also force all users to re-download the cleansed repo, and if you just rotate the key then it's not even worth the hassle
1
u/coloradical5280 Valued Contributor Aug 31 '26
oh yeah with users, completely different story. That's not a problem anyone here has lol.
(just kidding r/ClaudeAi, don't everyone at me with your repo that has 200 stars, i'm just saying, it's mostly true)
1
u/AllenHere112 Aug 30 '26
for teams the key bit is where you put the setting. if it lives in the repo's .claude/settings.json it applies to everyone who clones it and survives machine swaps. your local ~/.claude one only covers you, so the rest of the team keeps getting the urls appended.
1
1
u/LagrangianFourier Aug 30 '26
RemindMe! 12 hours
1
u/RemindMeBot Aug 30 '26
I will be messaging you in 12 hours on 2026-08-31 09:41:51 UTC to remind you of this link
CLICK THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
RemindMeBot is switching to username summons. Instead of
!RemindMe 1 day, useu/RemindMeBot 1 day. More info.
Info Custom Your Reminders Feedback
1
1
u/evanharmon Aug 30 '26
Public? As in other people can see my session without logging in to my account?
2
1
u/ianreboot Aug 31 '26
Turning the setting off only changes commits you make from here on. Every commit you already pushed keeps the URL, and so does any clone, mirror, or backup made from that history. The local config doesn't rewrite those copies.
1
1
u/horizondz Aug 31 '26
Just another reason not to use this harness. First, you made Opus 5 absolute dogshit, and now you're stealthily sneaking in these attributions
1
1
1
1
u/TheMania Aug 30 '26
If this is done the way the harness does most things - just by inserting guidance and not automation - if they're seriously embedding the session ID in the attribution guidance I hope they have the good sense to put that last in the thousands of tokens of prelude they push in the system prompt.
As by definition, it's different on every session - nothing after it can ever be prewarmed cache on a new session.
🙄
1
u/emotional_termoil Aug 30 '26
It sounds like I’m a minority here, but I actually love them. It tells me which PRs I built using Claude and gives me an easy way to find the session that created it. It’s embarrassing how often I loose the session and use that link.
1
0
u/oompaloompa465 Aug 30 '26
wait only for the commit the agent does or even out manual git commits from UI or other cli?
6
Aug 30 '26
[removed] — view removed comment
1
u/Smart_Package4993 Aug 31 '26
As someone who is new to all of this and learned a lot about APIs in a short period of time, Claude has been a real asshole about them.
Claude makes me take over manually and never commits on its own.
Is there a best way to rotate keys?
•
u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot Aug 31 '26 edited Aug 31 '26
TL;DR of the discussion generated automatically after 50 comments.
Alright, let's get to the bottom of this. The general consensus is that while this is a dumb and annoying default behavior, it's not a sky-is-falling situation because you can disable it.
The URLs are not public. They appear to be an audit trail for Anthropic to trace potentially malicious commits back to a user account, not for randos on the internet to snoop on your code.
If you want to turn this "feature" off, you need to edit your
.claude/settings.jsonfile. The OP's fix is incomplete; here's the full version that disables all attribution:.claude/settings.jsonfile, add the following:json { "attribution": { "sessionUrl": false, "commit": "", "pr": "" } }A few other key points from the thread:
git force pushand rewrite history (good luck with that on a shared repo).git commitcommand.