Skip to content

blog: Claude Code server-side auto mode through LiteLLM - #1595

Merged
mateo-berri merged 5 commits into
mainfrom
litellm_claude_code_server_side_auto_mode_blog
Sep 21, 2026
Merged

mateo-berri merged 5 commits into
mainfrom
litellm_claude_code_server_side_auto_mode_blog

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Announcement post for Anthropic's Claude Code auto mode change: the safety classifier moved server-side starting with Claude Code v2.1.278 on September 19, Anthropic told us the rollout started September 18 and that auto mode becomes the default permission mode on September 25, and new Claude Code releases keep the client-side classifier until at least October 23. Customers have been asking about it in support

The post explains the safeguards / safeguard_results / anthropic-beta contract Claude Code needs, why LiteLLM's native /v1/messages route dropped it (allowlist without safeguards, beta filter applied to first-party Anthropic), what BerriAI/litellm#42152 changed (merged to main on September 21, not in any tagged build up to v1.103.0-rc.1, shipping in the dev release cut Tuesday September 22, then the release candidate cut Saturday September 26 and the stable release planned for Saturday October 3), that /anthropic/v1/messages pass-through was never affected, that the Bedrock, Vertex AI and Foundry routes through LiteLLM are not covered yet, and a curl check readers can run to confirm safeguard_results comes back

Corrections in 4aea958

The first draft guessed the contract. Verified against the Anthropic API directly, Anthropic's docs and Anthropic's gateway check script: the beta flag is dangerous-tool-use-2026-09-03 (not safeguards-2026-09-01), safeguards is an array with a dangerous_tool_use entry (not {"auto_mode": ...}), and when streaming safeguard_results sits on the final message_delta only (not message_start). The release wording names the September 26 release candidate and October 3 stable instead of "next release after v1.102.0". The claim that the feature "only applies when the request reaches api.anthropic.com" is gone, since Claude Code also asks for server-side checks on Bedrock, Vertex AI and Foundry and LiteLLM's routes to those still filter the beta header, so the post says those are not covered yet. The logs UI sentence was cut as unverified, and the "contact your Anthropic account team" sentence now says what happened: Anthropic shared the check script with us and it passes against main. The title dropped "now works" because the fix is on main and not in a release yet. The curl uses claude-sonnet-5 with a forced tool call so the server has a tool use to evaluate, and the post shows the exact output to expect. The post also quotes the notice Claude Code shows, the /status row, and the CLAUDE_CODE_AUTO_MODE_SERVER=0 opt-out from Anthropic's docs

Corrections in 7456a82

The September 18 rollout start, the CLI-then-desktop rollout order, the September 25 default change and the October 23 client-side classifier sunset come from Anthropic's heads-up to gateway partners and are not in Anthropic's public docs, so the post now attributes each of them ("Anthropic told us") instead of stating them as public fact. The sentence "on September 25 auto mode becomes the default permission mode in Claude Code" read as a change for every account, while Anthropic's permission modes reference already lists auto as the built-in default on Pro, Max and Team and Manual on Enterprise plans and Claude API keys, so the post now states that public table next to the attributed September 25 sentence. The post also carries the consequence Anthropic named for after October 23: releases past that date only support server-side auto mode, so auto mode is not available behind a gateway that does not support it

Corrections in 2605abf and 72e30b8

2605abf (Devin, on a teammate's ask in the thread that commissioned the post) says the fix ships in the dev release cut on Tuesday, September 22. Dev releases are cut from main HEAD on Tuesdays and Thursdays (v1.103.0-dev.1 on September 15 and v1.103.0-dev.2 on September 17, both target=main, published to PyPI as 1.103.0.devN, to Docker Hub as v1.103.0-dev.N, and as GitHub pre-releases), and gh api repos/BerriAI/litellm/compare/e912ebe...v1.103.0-dev.2 answers behind, so the September 22 cut is the first build that carries merge e912ebe. 72e30b8 keeps that as the headline and puts the September 26 release candidate and the October 3 stable dates back next to it, since 2605abf had replaced them with "the next stable release following on the usual schedule", and says in one sentence what a dev release is and which tag to look for (v1.104.0-dev.1 by the current numbering, litellm==1.104.0.dev1 on PyPI)

Proof

The post's curl against a proxy built from main at 36b8be7d81 (contains the merge of #42152), anthropic/claude-sonnet-5 deployment:

{
  "safeguard_results": [
    {
      "type": "dangerous_tool_use",
      "status": {
        "type": "available",
        "tool_uses": {
          "toolu_01V9Z5KXn3SU71Fzr5cquHLi": {
            "type": "evaluated",
            "outcome": "not_flagged"
          }
        }
      }
    }
  ],
  "tool_use_ids": [
    "toolu_01V9Z5KXn3SU71Fzr5cquHLi"
  ]
}

The same curl against a proxy at 701c2b7256 (the parent of that merge):

{
  "safeguard_results": null,
  "tool_use_ids": [
    "toolu_01KZcDdS6gRJeWaXcdzgwbeN"
  ]
}

Anthropic's gateway check script against the main proxy: PASS non-streaming and PASS streaming, each with the tool use id evaluated. Against the pre-fix proxy: FAIL on both legs on the native route and PASS on /anthropic/v1/messages, which is the pass-through claim in the post

Real Claude Code 2.1.278 with ANTHROPIC_BASE_URL pointed at each proxy, run as claude -p "Use the Bash tool to run exactly this command, then reply with only its output: echo hello" --permission-mode auto --model claude-sonnet-5 --output-format stream-json --verbose --max-turns 4. The pre-fix proxy emits this event right after the tool use, and the main proxy emits no informational event at all:

{"type": "system", "subtype": "informational", "level": "warning", "content": "We're changing auto mode to no longer charge for classifier requests in Claude Code. However, this session isn't eligible because your requests go through 127.0.0.1:54832, which isn't compatible with this update. Nothing breaks: auto mode keeps working, and its classifier requests are billed as before. To fix it and access the new version of auto mode, ask your gateway to implement: https://code.claude.com/docs/en/auto-mode-classifier-billing"}

The same two proxies driven from the interactive Claude Code TUI under tmux, started as env -u ANTHROPIC_API_KEY -u CLAUDECODE ANTHROPIC_BASE_URL=http://127.0.0.1:<port> ANTHROPIC_AUTH_TOKEN=<proxy key> claude --permission-mode auto --model claude-sonnet-5, given the same "echo hello" prompt and then /status. Both sessions ran the command in auto mode ("Ran 1 shell command", then "hello", footer "auto mode on"). The /status pane against main (port 28261):

   Version:                    2.1.278
   Auth token:                 ANTHROPIC_AUTH_TOKEN
   Anthropic base URL:         http://127.0.0.1:28261
   Model:                      claude-sonnet-5
   Auto mode server:           Enabled

Against the pre-fix proxy (port 54832):

   Version:                    2.1.278
   Auth token:                 ANTHROPIC_AUTH_TOKEN
   Anthropic base URL:         http://127.0.0.1:54832
   Model:                      claude-sonnet-5
   Auto mode server:           Disabled

The interactive pre-fix session showed no notice dialog. Anthropic's notice reference says acknowledging a notice that named a gateway keeps it from reappearing on the machine for 24 hours, and the headless run above had already surfaced the notice for that gateway address, so the /status row is the observable difference on this machine

node scripts/check-writing-style.js blog/claude_code_server_side_auto_mode passes and the post body compiles with @mdx-js/mdx at 72e30b8. npm run build passed on the first draft

Link to Devin session: https://app.devin.ai/sessions/b25349259cd14617919eccb1bbc1366f
Open in Devin Desktop: https://app.devin.ai/desktop/session/b25349259cd14617919eccb1bbc1366f?variant=devin
Requested by: @mateo-berri


Note

Low Risk
Documentation-only change with no runtime or configuration impact.

Overview
Adds a new announcement post at blog/claude_code_server_side_auto_mode/index.md explaining Anthropic’s shift to server-side Claude Code auto mode safety checks and what LiteLLM customers need to know.

The article documents the safeguards / safeguard_results / anthropic-beta pass-through contract, why native /v1/messages previously dropped those fields, what PR #42152 fixes (and that /anthropic/v1/messages was already fine), release timing (v1.104.0-dev.1 through stable), Bedrock/Vertex/Foundry gaps, and a curl plus Claude Code /status verification path. It also includes FAQs, rollout timelines attributed to Anthropic, and links to related docs.

Reviewed by Cursor Bugbot for commit 72e30b8. Bugbot is set up for automated code reviews on this repo. Configure here.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@vercel

vercel Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
litellm Ready Ready Preview Sep 21, 2026 7:10pm UTC

Request Review

@mateo-berri mateo-berri changed the title blog: Claude Code server-side auto mode now works through LiteLLM blog: Claude Code server-side auto mode through LiteLLM Sep 21, 2026
@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 72e30b8. Configure here.

@mateo-berri mateo-berri left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mateo-berri
mateo-berri merged commit 31b7cac into main Sep 21, 2026
5 checks passed
@mateo-berri
mateo-berri deleted the litellm_claude_code_server_side_auto_mode_blog branch September 21, 2026 19:11

This branch was successfully deployed

1 active deployment
Preview — 72e30b8b Deployed Sep 21, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants