From the Inside Claude Code: The Claude Code Ecosystem architecture map

Public API code reaches straight into Session Store instead of going through a session entry point

risk · medium · inferred

Session Store, the SessionStore protocol and in-memory store with validation, is imported directly by the public API. ClaudeSDKClient calls validate_session_store_options, and the package exports file pulls in InMemorySessionStore and project_key_for_directory. Internal Client and Session Resume use the same validation. So the session boundary is crossed at the storage layer, not at one session-level entry point.

Impact: A change to store validation or to the in-memory store's signature has to be followed in the client and the package exports, not only inside session management.

Recommendation (small effort): Expose store validation and the in-memory store through one session-management entry point, and have ClaudeSDKClient and the package exports import from that instead of from Session Store.

The trail

  1. Session Store
  2. ClaudeSDKClient
  3. Package Exports
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com