What happened
When Claude Code commits code or opens a pull request for you, it adds short metadata lines to the bottom of the message, called trailers. One says who worked on the change: Co-Authored-By: Claude. If you’re using Claude Code through the web at claude.ai, or through Remote Control (which lets you steer a coding session from your phone or another device), it can add a second, separate trailer: Claude-Session: https://claude.ai/code/session_<id>, a link back to the exact conversation that produced the commit.
A builder posting on Hacker News described disabling the “co-authored by” signature in their config, only to find Claude Code still appending the session-link trailer by default. That’s not one setting failing. It’s two different settings that most people assume are one.
Claude Code’s current settings reference lists them separately, under an attribution object you can set in any settings file: attribution.commit changes or hides the “Co-Authored-By” line, attribution.pr does the same for pull request descriptions, and attribution.sessionUrl is the one that omits the session link from commits made through claude.ai or Remote Control. The older includeCoAuthoredBy setting some people still have in their config is deprecated and doesn’t cover the session link at all.
A GitHub issue filed against Anthropic’s own repository shows this isn’t only a matter of missing the second setting. That reporter had already disabled the older includeCoAuthoredBy setting, and still found the session-link trailer in roughly 318 commits across six private repositories over a two-week window. They traced it to a regression tied to Claude Code version 2.1.258. The issue is open, tagged as a confirmed bug with steps anyone can follow to reproduce it, and as of this writing Anthropic hasn’t posted a public response or fix.
Why this matters for you
A commit trailer isn’t a draft. Once you push it, it’s part of your repository’s permanent history. The only way to remove it afterward is to rewrite that history, which changes every commit’s ID from that point forward and breaks things for anyone who has already pulled the branch. That’s disruptive enough that most teams won’t do it just to erase a stray link.
It’s not clear whether someone without access to your Claude account can open that session link and see anything inside it. What is clear is that the link itself becomes permanent, public metadata: proof that a specific AI session, tied to your account, produced that exact commit. On a public repository, anyone browsing the code sees it. On a private one, every pull request reviewer sees it. If your team has a policy against broadcasting which commits were AI-generated, or simply doesn’t want internal session identifiers sitting in shared history, that’s precisely the detail a setting like this exists to suppress, and precisely what’s slipping through.
What builders should do next
First, check whether you’re already affected. Run this in any repository where you’ve used Claude Code through claude.ai or Remote Control:
git log --all --grep="Claude-Session"
This searches every commit on every branch for the trailer. If it returns nothing, you’re clear. If it returns commits, they’re already in your history, and removing them means rewriting that history, so weigh that disruption against just leaving them.
Second, stop new ones from landing. Add this to .claude/settings.json, the configuration file Claude Code reads on startup, in a specific project, or to ~/.claude/settings.json to cover every project on your machine:
{
"attribution": {
"sessionUrl": false
}
}
If your settings still reference the older includeCoAuthoredBy key, add the attribution block instead. It’s the setting that’s actually documented to control the session link, rather than the older name that only ever controlled the “Co-Authored-By” line. Start a fresh Claude Code session after saving the change, since settings changes generally don’t apply retroactively to a session that’s already running.
This only applies if you use Claude Code’s web interface or Remote Control. If you only run Claude Code locally from your terminal, this particular trailer was never part of your commits.
The bottom line
This is the second time this month a BuilderWithin report has found a gap between what a Claude Code setting claims to control and what actually shows up in your repository, after MCP login tokens on Linux turning out to be stored in a plaintext file despite being described as “stored securely.” Neither case is a dramatic exploit. Both are the same pattern: a setting with a name that implies more coverage than it delivers. Until Anthropic responds to the open issue, the only way to know your commits are clean is to check them yourself.
End of article