Repository navigation
blog: Claude Code server-side auto mode through LiteLLM - #1595
Merged
mateo-berri merged 5 commits intoSep 21, 2026
Merged
Conversation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Contributor
Author
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
… verification steps
Contributor
|
bugbot run |
Contributor
|
bugbot run |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
moe-berri
approved these changes
Sep 21, 2026
…er 22 dev release
Contributor
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 72e30b8. Configure here.
mateo-berri
deleted the
litellm_claude_code_server_side_auto_mode_blog
branch
September 21, 2026 19:11
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Announcement post for Anthropic's Claude Code auto mode change: the safety classifier moved server-side starting with Claude Code v2.1.278 on September 19, Anthropic told us the rollout started September 18 and that auto mode becomes the default permission mode on September 25, and new Claude Code releases keep the client-side classifier until at least October 23. Customers have been asking about it in support
The post explains the
safeguards/safeguard_results/anthropic-betacontract Claude Code needs, why LiteLLM's native/v1/messagesroute dropped it (allowlist withoutsafeguards, beta filter applied to first-party Anthropic), what BerriAI/litellm#42152 changed (merged tomainon September 21, not in any tagged build up to v1.103.0-rc.1, shipping in the dev release cut Tuesday September 22, then the release candidate cut Saturday September 26 and the stable release planned for Saturday October 3), that/anthropic/v1/messagespass-through was never affected, that the Bedrock, Vertex AI and Foundry routes through LiteLLM are not covered yet, and a curl check readers can run to confirmsafeguard_resultscomes backCorrections in 4aea958
The first draft guessed the contract. Verified against the Anthropic API directly, Anthropic's docs and Anthropic's gateway check script: the beta flag is
dangerous-tool-use-2026-09-03(notsafeguards-2026-09-01),safeguardsis an array with adangerous_tool_useentry (not{"auto_mode": ...}), and when streamingsafeguard_resultssits on the finalmessage_deltaonly (notmessage_start). The release wording names the September 26 release candidate and October 3 stable instead of "next release after v1.102.0". The claim that the feature "only applies when the request reaches api.anthropic.com" is gone, since Claude Code also asks for server-side checks on Bedrock, Vertex AI and Foundry and LiteLLM's routes to those still filter the beta header, so the post says those are not covered yet. The logs UI sentence was cut as unverified, and the "contact your Anthropic account team" sentence now says what happened: Anthropic shared the check script with us and it passes againstmain. The title dropped "now works" because the fix is onmainand not in a release yet. The curl usesclaude-sonnet-5with a forced tool call so the server has a tool use to evaluate, and the post shows the exact output to expect. The post also quotes the notice Claude Code shows, the/statusrow, and theCLAUDE_CODE_AUTO_MODE_SERVER=0opt-out from Anthropic's docsCorrections in 7456a82
The September 18 rollout start, the CLI-then-desktop rollout order, the September 25 default change and the October 23 client-side classifier sunset come from Anthropic's heads-up to gateway partners and are not in Anthropic's public docs, so the post now attributes each of them ("Anthropic told us") instead of stating them as public fact. The sentence "on September 25 auto mode becomes the default permission mode in Claude Code" read as a change for every account, while Anthropic's permission modes reference already lists auto as the built-in default on Pro, Max and Team and Manual on Enterprise plans and Claude API keys, so the post now states that public table next to the attributed September 25 sentence. The post also carries the consequence Anthropic named for after October 23: releases past that date only support server-side auto mode, so auto mode is not available behind a gateway that does not support it
Corrections in 2605abf and 72e30b8
2605abf (Devin, on a teammate's ask in the thread that commissioned the post) says the fix ships in the dev release cut on Tuesday, September 22. Dev releases are cut from
mainHEAD on Tuesdays and Thursdays (v1.103.0-dev.1 on September 15 and v1.103.0-dev.2 on September 17, bothtarget=main, published to PyPI as1.103.0.devN, to Docker Hub asv1.103.0-dev.N, and as GitHub pre-releases), andgh api repos/BerriAI/litellm/compare/e912ebe...v1.103.0-dev.2answersbehind, so the September 22 cut is the first build that carries merge e912ebe. 72e30b8 keeps that as the headline and puts the September 26 release candidate and the October 3 stable dates back next to it, since 2605abf had replaced them with "the next stable release following on the usual schedule", and says in one sentence what a dev release is and which tag to look for (v1.104.0-dev.1by the current numbering,litellm==1.104.0.dev1on PyPI)Proof
The post's curl against a proxy built from
mainat 36b8be7d81 (contains the merge of #42152),anthropic/claude-sonnet-5deployment:{ "safeguard_results": [ { "type": "dangerous_tool_use", "status": { "type": "available", "tool_uses": { "toolu_01V9Z5KXn3SU71Fzr5cquHLi": { "type": "evaluated", "outcome": "not_flagged" } } } } ], "tool_use_ids": [ "toolu_01V9Z5KXn3SU71Fzr5cquHLi" ] }The same curl against a proxy at 701c2b7256 (the parent of that merge):
{ "safeguard_results": null, "tool_use_ids": [ "toolu_01KZcDdS6gRJeWaXcdzgwbeN" ] }Anthropic's gateway check script against the
mainproxy: PASS non-streaming and PASS streaming, each with the tool use id evaluated. Against the pre-fix proxy: FAIL on both legs on the native route and PASS on/anthropic/v1/messages, which is the pass-through claim in the postReal Claude Code 2.1.278 with
ANTHROPIC_BASE_URLpointed at each proxy, run asclaude -p "Use the Bash tool to run exactly this command, then reply with only its output: echo hello" --permission-mode auto --model claude-sonnet-5 --output-format stream-json --verbose --max-turns 4. The pre-fix proxy emits this event right after the tool use, and themainproxy emits noinformationalevent at all:{"type": "system", "subtype": "informational", "level": "warning", "content": "We're changing auto mode to no longer charge for classifier requests in Claude Code. However, this session isn't eligible because your requests go through 127.0.0.1:54832, which isn't compatible with this update. Nothing breaks: auto mode keeps working, and its classifier requests are billed as before. To fix it and access the new version of auto mode, ask your gateway to implement: https://code.claude.com/docs/en/auto-mode-classifier-billing"}The same two proxies driven from the interactive Claude Code TUI under tmux, started as
env -u ANTHROPIC_API_KEY -u CLAUDECODE ANTHROPIC_BASE_URL=http://127.0.0.1:<port> ANTHROPIC_AUTH_TOKEN=<proxy key> claude --permission-mode auto --model claude-sonnet-5, given the same "echo hello" prompt and then/status. Both sessions ran the command in auto mode ("Ran 1 shell command", then "hello", footer "auto mode on"). The/statuspane againstmain(port 28261):Against the pre-fix proxy (port 54832):
The interactive pre-fix session showed no notice dialog. Anthropic's notice reference says acknowledging a notice that named a gateway keeps it from reappearing on the machine for 24 hours, and the headless run above had already surfaced the notice for that gateway address, so the
/statusrow is the observable difference on this machinenode scripts/check-writing-style.js blog/claude_code_server_side_auto_modepasses and the post body compiles with@mdx-js/mdxat 72e30b8.npm run buildpassed on the first draftLink to Devin session: https://app.devin.ai/sessions/b25349259cd14617919eccb1bbc1366f
Open in Devin Desktop: https://app.devin.ai/desktop/session/b25349259cd14617919eccb1bbc1366f?variant=devin
Requested by: @mateo-berri
Note
Low Risk
Documentation-only change with no runtime or configuration impact.
Overview
Adds a new announcement post at
blog/claude_code_server_side_auto_mode/index.mdexplaining Anthropic’s shift to server-side Claude Code auto mode safety checks and what LiteLLM customers need to know.The article documents the
safeguards/safeguard_results/anthropic-betapass-through contract, why native/v1/messagespreviously dropped those fields, what PR #42152 fixes (and that/anthropic/v1/messageswas already fine), release timing (v1.104.0-dev.1through stable), Bedrock/Vertex/Foundry gaps, and a curl plus Claude Code/statusverification path. It also includes FAQs, rollout timelines attributed to Anthropic, and links to related docs.Reviewed by Cursor Bugbot for commit 72e30b8. Bugbot is set up for automated code reviews on this repo. Configure here.