From e17213a8da0bf119c2d6adbcbd96914c6a08913c Mon Sep 17 00:00:00 2001 From: mateo Date: Mon, 21 Sep 2026 17:10:47 +0000 Subject: [PATCH 1/5] blog: Claude Code server-side auto mode now works through LiteLLM Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../index.md | 92 +++++++++++++++++++ 1 file changed, 92 insertions(+) create mode 100644 blog/claude_code_server_side_auto_mode/index.md diff --git a/blog/claude_code_server_side_auto_mode/index.md b/blog/claude_code_server_side_auto_mode/index.md new file mode 100644 index 000000000..53c697706 --- /dev/null +++ b/blog/claude_code_server_side_auto_mode/index.md @@ -0,0 +1,92 @@ +--- +slug: claude-code-server-side-auto-mode +title: "Claude Code server-side auto mode now works through LiteLLM" +date: 2026-09-21T12:00:00 +authors: + - litellm +description: "Anthropic is moving Claude Code auto mode's safety classifier server-side. LiteLLM's AI Gateway now forwards the safeguards contract unchanged, so sessions behind LiteLLM get the free classifier. Here is what changed and how to verify it." +tags: [announcement, claude-code, anthropic, ai-gateway] +hide_table_of_contents: true +--- + +*Last Updated: September 21, 2026* + +On September 18, Anthropic started moving Claude Code auto mode's safety classifier from the client to the Claude API. With server-side auto mode, users are no longer billed for classifier calls. The rollout is gradual, beginning with the Claude Code CLI and VS Code extension, followed by the desktop app and Claude Code on the web over the following week. On September 25, auto mode becomes the default permission mode in Claude Code. + +Server-side auto mode depends on a new contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. We have shipped the fix. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, and how to confirm your deployment is ready. + +{/* truncate */} + +## What server-side auto mode needs from an AI Gateway + +Claude Code sends a `safeguards` field in the `/v1/messages` request body and expects a `safeguard_results` field back in the response. It matches each entry in `safeguard_results` to a tool use ID. The request also carries a `safeguards-2026-09-01` value in the `anthropic-beta` header. For server-side auto mode to run, a gateway has to pass `safeguards` through unchanged, return `safeguard_results` unchanged, keep tool use IDs unchanged, and forward the beta header intact. + +If any of that is dropped or rewritten, Claude Code concludes that server-side review is unavailable and offers to fall back to the client-side classifier. Users keep the experience they have today and keep paying for the classifier calls, and they see a notice telling them to contact their gateway provider. + +New Claude Code releases keep the client-side fallback until at least October 23, 2026. After that date, new releases only support server-side auto mode, so users behind a gateway that does not preserve the contract will not be able to use auto mode at all. + +## What LiteLLM was doing wrong + +LiteLLM's native `/v1/messages` endpoint builds the outbound request from an allowlist of known Anthropic Messages parameters so that the same endpoint can front Claude on Bedrock, Vertex AI, Azure AI and non-Anthropic models. `safeguards` was not on that list, so it was silently dropped before the request left the proxy. Separately, LiteLLM filters `anthropic-beta` values it does not recognize to protect providers that reject unknown beta flags, and that filter ran even when the upstream was api.anthropic.com, so `safeguards-2026-09-01` was stripped from the header too. + +Anthropic therefore received a request with no `safeguards`, returned no `safeguard_results`, and Claude Code fell back to the paid client-side classifier. + +The raw pass-through route, `POST /anthropic/v1/messages`, was never affected. It forwards the body and headers verbatim, and it already carried `safeguards` and the full beta header before the fix. + +## What changed + +[PR #42152](https://github.com/BerriAI/litellm/pull/42152), merged into `main` on September 21, 2026, makes the native `/v1/messages` route preserve the contract. `safeguards` is now a recognized request parameter and is forwarded as sent. When the resolved provider is first-party `anthropic`, the `anthropic-beta` header is forwarded unchanged instead of being filtered against the known-betas list; requests to Claude on Bedrock, Vertex AI and Azure AI keep the existing filtering because those providers still reject unknown flags. `safeguard_results` is declared on the response and streaming chunk types, and it is returned unchanged in both the JSON response and the `message_start` and `message_delta` events when streaming. LiteLLM does not rewrite tool use IDs on this route, so `safeguard_results` entries still match the tool uses they refer to. + +When `/v1/messages` is used to reach a non-Anthropic model through the adapter path, `safeguards` is stripped before the request is translated so those backends do not return a 400. Server-side auto mode is an Anthropic API feature, so it only applies when the request reaches api.anthropic.com. + +The fix ships in the next LiteLLM release after `v1.102.0`. Until you upgrade, Claude Code sessions routed through the native `/v1/messages` endpoint fall back to the client-side classifier and keep working. + +## How to verify your deployment + +Send a request that mirrors what Claude Code sends and check the response for `safeguard_results`. + +```bash +curl -s "$LITELLM_PROXY_URL/v1/messages" \ + -H "Authorization: Bearer $LITELLM_API_KEY" \ + -H "content-type: application/json" \ + -H "anthropic-version: 2023-06-01" \ + -H "anthropic-beta: safeguards-2026-09-01" \ + -d '{ + "model": "claude-sonnet-4-5", + "max_tokens": 64, + "safeguards": {"auto_mode": {"enabled": true, "version": "2026-09-01"}}, + "messages": [{"role": "user", "content": "hi"}] + }' +``` + +On a fixed proxy pointed at api.anthropic.com, the response body includes a `safeguard_results` field. On an unfixed proxy the field is absent, because Anthropic never received `safeguards`. You can also open the request in the LiteLLM logs UI and switch the Request & Response view to JSON; the logged request should show `safeguards.auto_mode` and the full `anthropic-beta` header. Anthropic has offered a test script with expected input and output for gateway providers; contact your Anthropic account team if you want to run it against your own deployment. + +If you use the `/anthropic/v1/messages` pass-through route today, no action is needed. + +--- + +### Frequently Asked Questions + +### Does this change how LiteLLM handles beta headers for Bedrock, Vertex AI or Azure AI? + +No. Beta header filtering still applies when the resolved provider is anything other than first-party `anthropic`. Those providers reject unknown beta flags, so the allowlist in `anthropic_beta_headers_config.json` remains the source of truth for them. Only requests bound for api.anthropic.com now forward the header unchanged. + +### Will my Claude Code users be broken before I upgrade? + +No. Claude Code detects that server-side review is unavailable and offers the client-side classifier. Users keep the current experience and keep being billed for classifier calls until you upgrade. After October 23, 2026, new Claude Code releases drop the client-side fallback, so upgrade before then. + +### Is this available in LiteLLM OSS? + +Yes. The fix is in LiteLLM OSS (Apache 2.0) and requires no configuration. [LiteLLM Enterprise](https://litellm.ai/enterprise) adds SSO/SCIM, air-gapped deployment, 24/7 SLA support and advanced guardrails on top. + +--- + +## Conclusion + +An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM now passes it through unchanged on every route to api.anthropic.com. Upgrade to the next release, run the check above, and your users get server-side auto mode at no cost. + +## Recommended Reading + +- [Claude Code with LiteLLM AI Gateway](https://docs.litellm.ai/docs/tutorials/claude_code_gateway) +- [Claude Code: managing Anthropic beta headers](https://docs.litellm.ai/docs/tutorials/claude_code_beta_headers) +- [Anthropic pass-through endpoints](https://docs.litellm.ai/docs/pass_through/anthropic_completion) From 4aea958d6c6217833ee2aa5a27c6510e86bc6085 Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Mon, 21 Sep 2026 11:39:20 -0700 Subject: [PATCH 2/5] blog: correct the server-side auto mode contract, release timing, and verification steps --- .../index.md | 86 +++++++++++++------ 1 file changed, 62 insertions(+), 24 deletions(-) diff --git a/blog/claude_code_server_side_auto_mode/index.md b/blog/claude_code_server_side_auto_mode/index.md index 53c697706..65df5b844 100644 --- a/blog/claude_code_server_side_auto_mode/index.md +++ b/blog/claude_code_server_side_auto_mode/index.md @@ -1,65 +1,101 @@ --- slug: claude-code-server-side-auto-mode -title: "Claude Code server-side auto mode now works through LiteLLM" +title: "Claude Code server-side auto mode through LiteLLM" date: 2026-09-21T12:00:00 authors: - litellm -description: "Anthropic is moving Claude Code auto mode's safety classifier server-side. LiteLLM's AI Gateway now forwards the safeguards contract unchanged, so sessions behind LiteLLM get the free classifier. Here is what changed and how to verify it." +description: "Anthropic is moving Claude Code auto mode's safety classifier server-side. LiteLLM's native /v1/messages route now forwards the safeguards contract on main, and the fix ships in the next release. Here is the contract, what changed, when it ships, and how to verify it." tags: [announcement, claude-code, anthropic, ai-gateway] hide_table_of_contents: true --- *Last Updated: September 21, 2026* -On September 18, Anthropic started moving Claude Code auto mode's safety classifier from the client to the Claude API. With server-side auto mode, users are no longer billed for classifier calls. The rollout is gradual, beginning with the Claude Code CLI and VS Code extension, followed by the desktop app and Claude Code on the web over the following week. On September 25, auto mode becomes the default permission mode in Claude Code. +On September 18, Anthropic started moving Claude Code auto mode's safety classifier from the client to the Claude API. Starting with Claude Code v2.1.278, released September 19, sessions on Enterprise plans and Claude API accounts ask the server to run those checks as part of their own model requests, and Anthropic does not charge for the checks when the server performs them. The rollout is gradual, beginning with the Claude Code CLI and VS Code extension, followed by the desktop app and Claude Code on the web over the following week. On September 25, auto mode becomes the default permission mode in Claude Code. -Server-side auto mode depends on a new contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. We have shipped the fix. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, and how to confirm your deployment is ready. +Server-side auto mode depends on a contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. The fix is merged on `main` and ships in the next release. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, which release carries it, and how to confirm your deployment is ready. {/* truncate */} ## What server-side auto mode needs from an AI Gateway -Claude Code sends a `safeguards` field in the `/v1/messages` request body and expects a `safeguard_results` field back in the response. It matches each entry in `safeguard_results` to a tool use ID. The request also carries a `safeguards-2026-09-01` value in the `anthropic-beta` header. For server-side auto mode to run, a gateway has to pass `safeguards` through unchanged, return `safeguard_results` unchanged, keep tool use IDs unchanged, and forward the beta header intact. +Claude Code sends a `safeguards` field in the `/v1/messages` request body, an array with one `dangerous_tool_use` entry that carries the session's permission mode, and it sets `dangerous-tool-use-2026-09-03` in the `anthropic-beta` header. The API answers with a `safeguard_results` field: one `dangerous_tool_use` entry whose `status.type` is `available` and whose `status.tool_uses` is keyed by tool use ID, each marked `evaluated` with an outcome such as `not_flagged`. When the response is streamed, `safeguard_results` arrives inside the `delta` of the final `message_delta` event. -If any of that is dropped or rewritten, Claude Code concludes that server-side review is unavailable and offers to fall back to the client-side classifier. Users keep the experience they have today and keep paying for the classifier calls, and they see a notice telling them to contact their gateway provider. +For server-side auto mode to run, a gateway has to forward request headers and body fields as they are, including ones it does not recognize such as `safeguards`, and return responses and streaming events without dropping keys such as `safeguard_results` or rewriting tool use IDs. Anthropic's [gateway compatibility guide](https://code.claude.com/docs/en/llm-gateway-protocol#feature-pass-through) spells this out. -New Claude Code releases keep the client-side fallback until at least October 23, 2026. After that date, new releases only support server-side auto mode, so users behind a gateway that does not preserve the contract will not be able to use auto mode at all. +If any of that is dropped or rewritten, the server's checks never reach the session, and Claude Code keeps using its own classifier requests, billed as before. Before the first action it would check that way, Claude Code holds the action and shows this notice, naming the gateway: + +```text +We're changing auto mode to no longer charge for classifier requests in Claude Code. However, this session isn't eligible because your requests go through , which isn't compatible with this update. Nothing breaks: auto mode keeps working, and its classifier requests are billed as before. To fix it and access the new version of auto mode, ask your gateway to implement: https://code.claude.com/docs/en/auto-mode-classifier-billing +``` + +Nothing breaks when this happens. Users keep the auto mode they have today and keep paying for the classifier calls. Anthropic has said that new Claude Code releases keep the client-side classifier until at least October 23, 2026, and that releases after that date rely on the server-side checks, so gateways have a window to catch up. Anthropic's [notice reference](https://code.claude.com/docs/en/auto-mode-classifier-billing) covers who sees the notice and what it means. ## What LiteLLM was doing wrong -LiteLLM's native `/v1/messages` endpoint builds the outbound request from an allowlist of known Anthropic Messages parameters so that the same endpoint can front Claude on Bedrock, Vertex AI, Azure AI and non-Anthropic models. `safeguards` was not on that list, so it was silently dropped before the request left the proxy. Separately, LiteLLM filters `anthropic-beta` values it does not recognize to protect providers that reject unknown beta flags, and that filter ran even when the upstream was api.anthropic.com, so `safeguards-2026-09-01` was stripped from the header too. +LiteLLM's native `/v1/messages` endpoint builds the outbound request from an allowlist of known Anthropic Messages parameters so that the same endpoint can front Claude on Bedrock, Vertex AI, Azure AI and non-Anthropic models. `safeguards` was not on that list, so it was silently dropped before the request left the proxy. Separately, LiteLLM filters `anthropic-beta` values it does not recognize to protect providers that reject unknown beta flags, and that filter ran even when the upstream was the Anthropic API, so `dangerous-tool-use-2026-09-03` was stripped from the header too. -Anthropic therefore received a request with no `safeguards`, returned no `safeguard_results`, and Claude Code fell back to the paid client-side classifier. +Anthropic therefore received a request with no `safeguards` and no beta flag, returned no `safeguard_results`, and Claude Code fell back to the paid client-side classifier. Running Claude Code v2.1.278 in auto mode against a LiteLLM release without the fix shows the notice above with your proxy's address in it, and `/status` reports the Auto mode server row as `Disabled`. -The raw pass-through route, `POST /anthropic/v1/messages`, was never affected. It forwards the body and headers verbatim, and it already carried `safeguards` and the full beta header before the fix. +The raw pass-through route, `POST /anthropic/v1/messages`, was never affected. It forwards the body and headers verbatim, and it already carried `safeguards` and the full beta header before the fix. We confirmed this by running Anthropic's gateway check against a build from before the fix: the pass-through route passes and the native route fails. ## What changed -[PR #42152](https://github.com/BerriAI/litellm/pull/42152), merged into `main` on September 21, 2026, makes the native `/v1/messages` route preserve the contract. `safeguards` is now a recognized request parameter and is forwarded as sent. When the resolved provider is first-party `anthropic`, the `anthropic-beta` header is forwarded unchanged instead of being filtered against the known-betas list; requests to Claude on Bedrock, Vertex AI and Azure AI keep the existing filtering because those providers still reject unknown flags. `safeguard_results` is declared on the response and streaming chunk types, and it is returned unchanged in both the JSON response and the `message_start` and `message_delta` events when streaming. LiteLLM does not rewrite tool use IDs on this route, so `safeguard_results` entries still match the tool uses they refer to. +[PR #42152](https://github.com/BerriAI/litellm/pull/42152), merged into `main` on September 21, 2026, makes the native `/v1/messages` route preserve the contract. `safeguards` is now a recognized request parameter and is forwarded as sent. When the resolved provider is first-party `anthropic`, the `anthropic-beta` header is forwarded unchanged instead of being filtered against the known-betas list; requests to Claude on Bedrock, Vertex AI and Azure AI keep the existing filtering because those providers still reject unknown flags. `safeguard_results` is declared on the response and streaming chunk types, and it is returned unchanged in both the JSON response and the final `message_delta` event when streaming. LiteLLM does not rewrite tool use IDs on this route, so `safeguard_results` entries still match the tool uses they refer to. + +When `/v1/messages` is used to reach a non-Anthropic model through the adapter path, `safeguards` is stripped before the request is translated so those backends do not return a 400. -When `/v1/messages` is used to reach a non-Anthropic model through the adapter path, `safeguards` is stripped before the request is translated so those backends do not return a 400. Server-side auto mode is an Anthropic API feature, so it only applies when the request reaches api.anthropic.com. +This fix covers LiteLLM's route to the Anthropic API. Claude Code also asks for server-side checks on Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry, subject to each platform's own rollout, and LiteLLM's routes to those platforms still filter the beta header, so sessions reaching Claude on them through LiteLLM are not covered by this change yet. We are tracking that as follow-up work. -The fix ships in the next LiteLLM release after `v1.102.0`. Until you upgrade, Claude Code sessions routed through the native `/v1/messages` endpoint fall back to the client-side classifier and keep working. +The merge is not in any tagged build up to `v1.103.0-rc.1`. It first ships in the release candidate cut on Saturday, September 26 (`v1.104.0-rc.1` by the current numbering), with the stable release the following week, planned for Saturday, October 3. Auto mode becomes the default on September 25, one day before that release candidate, so Claude Code sessions routed through the native `/v1/messages` endpoint on any current LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. ## How to verify your deployment -Send a request that mirrors what Claude Code sends and check the response for `safeguard_results`. +Send a request that mirrors what Claude Code sends, with a forced tool call so the server has something to evaluate, and check the response for `safeguard_results`. The model has to be a deployment that LiteLLM routes to the Anthropic API. ```bash curl -s "$LITELLM_PROXY_URL/v1/messages" \ -H "Authorization: Bearer $LITELLM_API_KEY" \ -H "content-type: application/json" \ -H "anthropic-version: 2023-06-01" \ - -H "anthropic-beta: safeguards-2026-09-01" \ + -H "anthropic-beta: dangerous-tool-use-2026-09-03" \ -d '{ - "model": "claude-sonnet-4-5", - "max_tokens": 64, - "safeguards": {"auto_mode": {"enabled": true, "version": "2026-09-01"}}, - "messages": [{"role": "user", "content": "hi"}] - }' + "model": "claude-sonnet-5", + "max_tokens": 256, + "safeguards": [{"type": "dangerous_tool_use", "classifier_context": {"v": 1, "permission_mode": "auto"}}], + "tools": [{"name": "Bash", "description": "Runs a shell command", "input_schema": {"type": "object", "properties": {"command": {"type": "string"}}, "required": ["command"]}}], + "tool_choice": {"type": "tool", "name": "Bash"}, + "messages": [{"role": "user", "content": "Run: echo hello"}] + }' | jq '{safeguard_results, tool_use_ids: [.content[] | select(.type == "tool_use") | .id]}' ``` -On a fixed proxy pointed at api.anthropic.com, the response body includes a `safeguard_results` field. On an unfixed proxy the field is absent, because Anthropic never received `safeguards`. You can also open the request in the LiteLLM logs UI and switch the Request & Response view to JSON; the logged request should show `safeguards.auto_mode` and the full `anthropic-beta` header. Anthropic has offered a test script with expected input and output for gateway providers; contact your Anthropic account team if you want to run it against your own deployment. +On a proxy built from `main` (or the release candidate above) pointed at the Anthropic API, the tool use ID in `safeguard_results` matches the one in the response content: + +```json +{ + "safeguard_results": [ + { + "type": "dangerous_tool_use", + "status": { + "type": "available", + "tool_uses": { + "toolu_01V9Z5KXn3SU71Fzr5cquHLi": { + "type": "evaluated", + "outcome": "not_flagged" + } + } + } + } + ], + "tool_use_ids": [ + "toolu_01V9Z5KXn3SU71Fzr5cquHLi" + ] +} +``` + +On a proxy without the fix, `safeguard_results` is `null`, because Anthropic never received `safeguards` or the beta flag. + +Anthropic shared a gateway check script with us that sends the same request non-streaming and streaming and checks that every tool use ID comes back evaluated. Both legs pass against a proxy built from `main`. You can also check from Claude Code itself: start a session through your proxy in auto mode, run `/status`, and look for the Auto mode server row reading `Enabled`. In non-interactive mode with `-p --output-format stream-json`, the notice above arrives as a `system` message at `warning` level, so a scripted check can grep for it. If you use the `/anthropic/v1/messages` pass-through route today, no action is needed. @@ -69,11 +105,11 @@ If you use the `/anthropic/v1/messages` pass-through route today, no action is n ### Does this change how LiteLLM handles beta headers for Bedrock, Vertex AI or Azure AI? -No. Beta header filtering still applies when the resolved provider is anything other than first-party `anthropic`. Those providers reject unknown beta flags, so the allowlist in `anthropic_beta_headers_config.json` remains the source of truth for them. Only requests bound for api.anthropic.com now forward the header unchanged. +No. Beta header filtering still applies when the resolved provider is anything other than first-party `anthropic`. Those providers reject unknown beta flags, so the allowlist in `anthropic_beta_headers_config.json` remains the source of truth for them, and server-side auto mode does not run through LiteLLM on those routes yet. Only requests bound for the Anthropic API now forward the header unchanged. ### Will my Claude Code users be broken before I upgrade? -No. Claude Code detects that server-side review is unavailable and offers the client-side classifier. Users keep the current experience and keep being billed for classifier calls until you upgrade. After October 23, 2026, new Claude Code releases drop the client-side fallback, so upgrade before then. +No. Claude Code detects that the server's checks are not reaching the session and keeps using its own classifier. Users see the notice, keep the current experience, and keep being billed for classifier calls until you upgrade. Anthropic has said new Claude Code releases keep the client-side classifier until at least October 23, 2026, so upgrade before then. ### Is this available in LiteLLM OSS? @@ -83,10 +119,12 @@ Yes. The fix is in LiteLLM OSS (Apache 2.0) and requires no configuration. [Lite ## Conclusion -An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM now passes it through unchanged on every route to api.anthropic.com. Upgrade to the next release, run the check above, and your users get server-side auto mode at no cost. +An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM's native `/v1/messages` route now passes it through unchanged on the way to the Anthropic API. Upgrade to the September 26 release candidate or the October 3 stable release, run the check above, and your users get server-side auto mode at no cost. ## Recommended Reading - [Claude Code with LiteLLM AI Gateway](https://docs.litellm.ai/docs/tutorials/claude_code_gateway) - [Claude Code: managing Anthropic beta headers](https://docs.litellm.ai/docs/tutorials/claude_code_beta_headers) - [Anthropic pass-through endpoints](https://docs.litellm.ai/docs/pass_through/anthropic_completion) +- [Anthropic: auto mode classifier request charges](https://code.claude.com/docs/en/auto-mode-classifier-billing) +- [Anthropic: LLM gateway compatibility guide](https://code.claude.com/docs/en/llm-gateway-protocol#feature-pass-through) From 7456a82837bef07ddb72877230b9592beefb80ac Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Mon, 21 Sep 2026 11:57:00 -0700 Subject: [PATCH 3/5] blog: attribute Anthropic's rollout dates and scope the September 25 default change --- blog/claude_code_server_side_auto_mode/index.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/blog/claude_code_server_side_auto_mode/index.md b/blog/claude_code_server_side_auto_mode/index.md index 65df5b844..139fdd235 100644 --- a/blog/claude_code_server_side_auto_mode/index.md +++ b/blog/claude_code_server_side_auto_mode/index.md @@ -11,7 +11,7 @@ hide_table_of_contents: true *Last Updated: September 21, 2026* -On September 18, Anthropic started moving Claude Code auto mode's safety classifier from the client to the Claude API. Starting with Claude Code v2.1.278, released September 19, sessions on Enterprise plans and Claude API accounts ask the server to run those checks as part of their own model requests, and Anthropic does not charge for the checks when the server performs them. The rollout is gradual, beginning with the Claude Code CLI and VS Code extension, followed by the desktop app and Claude Code on the web over the following week. On September 25, auto mode becomes the default permission mode in Claude Code. +Anthropic is moving Claude Code auto mode's safety classifier from the client to the Claude API. Starting with Claude Code v2.1.278, released September 19, sessions on Enterprise plans and Claude API accounts ask the server to run those checks as part of their own model requests, and Anthropic does not charge for the checks when the server performs them. Anthropic told us the rollout started on September 18 and is gradual, beginning with the Claude Code CLI and VS Code extension and followed by the desktop app and Claude Code on the web over the following week, and that on September 25 auto mode becomes the default permission mode in Claude Code. Today the built-in default is auto on Pro, Max and Team plans and Manual on Enterprise plans and Claude API keys, the accounts that typically sit behind a gateway, per Anthropic's [permission modes reference](https://code.claude.com/docs/en/permission-modes). Server-side auto mode depends on a contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. The fix is merged on `main` and ships in the next release. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, which release carries it, and how to confirm your deployment is ready. @@ -29,7 +29,7 @@ If any of that is dropped or rewritten, the server's checks never reach the sess We're changing auto mode to no longer charge for classifier requests in Claude Code. However, this session isn't eligible because your requests go through , which isn't compatible with this update. Nothing breaks: auto mode keeps working, and its classifier requests are billed as before. To fix it and access the new version of auto mode, ask your gateway to implement: https://code.claude.com/docs/en/auto-mode-classifier-billing ``` -Nothing breaks when this happens. Users keep the auto mode they have today and keep paying for the classifier calls. Anthropic has said that new Claude Code releases keep the client-side classifier until at least October 23, 2026, and that releases after that date rely on the server-side checks, so gateways have a window to catch up. Anthropic's [notice reference](https://code.claude.com/docs/en/auto-mode-classifier-billing) covers who sees the notice and what it means. +Nothing breaks when this happens. Users keep the auto mode they have today and keep paying for the classifier calls. Anthropic has told us that new Claude Code releases keep the client-side classifier until at least October 23, 2026, that releases after that date only support server-side auto mode, and that from then on auto mode is not available behind a gateway that does not support the server-side classifier, so gateways have a window to catch up. Anthropic's [notice reference](https://code.claude.com/docs/en/auto-mode-classifier-billing) covers who sees the notice and what it means. ## What LiteLLM was doing wrong @@ -47,7 +47,7 @@ When `/v1/messages` is used to reach a non-Anthropic model through the adapter p This fix covers LiteLLM's route to the Anthropic API. Claude Code also asks for server-side checks on Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry, subject to each platform's own rollout, and LiteLLM's routes to those platforms still filter the beta header, so sessions reaching Claude on them through LiteLLM are not covered by this change yet. We are tracking that as follow-up work. -The merge is not in any tagged build up to `v1.103.0-rc.1`. It first ships in the release candidate cut on Saturday, September 26 (`v1.104.0-rc.1` by the current numbering), with the stable release the following week, planned for Saturday, October 3. Auto mode becomes the default on September 25, one day before that release candidate, so Claude Code sessions routed through the native `/v1/messages` endpoint on any current LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. +The merge is not in any tagged build up to `v1.103.0-rc.1`. It first ships in the release candidate cut on Saturday, September 26 (`v1.104.0-rc.1` by the current numbering), with the stable release the following week, planned for Saturday, October 3. Anthropic's September 25 default change lands one day before that release candidate, so Claude Code sessions routed through the native `/v1/messages` endpoint on any current LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. ## How to verify your deployment @@ -109,7 +109,7 @@ No. Beta header filtering still applies when the resolved provider is anything o ### Will my Claude Code users be broken before I upgrade? -No. Claude Code detects that the server's checks are not reaching the session and keeps using its own classifier. Users see the notice, keep the current experience, and keep being billed for classifier calls until you upgrade. Anthropic has said new Claude Code releases keep the client-side classifier until at least October 23, 2026, so upgrade before then. +No. Claude Code detects that the server's checks are not reaching the session and keeps using its own classifier. Users see the notice, keep the current experience, and keep being billed for classifier calls until you upgrade. Anthropic has told us new Claude Code releases keep the client-side classifier until at least October 23, 2026, and that releases after that date need the server-side classifier for auto mode, so upgrade before then. ### Is this available in LiteLLM OSS? From 2605abfeeefb68b68baa1088cd7f73f0ceca2b88 Mon Sep 17 00:00:00 2001 From: mateo Date: Mon, 21 Sep 2026 19:01:12 +0000 Subject: [PATCH 4/5] blog: fix ships in the September 22 dev release Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- blog/claude_code_server_side_auto_mode/index.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/blog/claude_code_server_side_auto_mode/index.md b/blog/claude_code_server_side_auto_mode/index.md index 139fdd235..6af7f80cd 100644 --- a/blog/claude_code_server_side_auto_mode/index.md +++ b/blog/claude_code_server_side_auto_mode/index.md @@ -4,7 +4,7 @@ title: "Claude Code server-side auto mode through LiteLLM" date: 2026-09-21T12:00:00 authors: - litellm -description: "Anthropic is moving Claude Code auto mode's safety classifier server-side. LiteLLM's native /v1/messages route now forwards the safeguards contract on main, and the fix ships in the next release. Here is the contract, what changed, when it ships, and how to verify it." +description: "Anthropic is moving Claude Code auto mode's safety classifier server-side. LiteLLM's native /v1/messages route now forwards the safeguards contract, and the fix ships in the dev release on September 22. Here is the contract, what changed, when it ships, and how to verify it." tags: [announcement, claude-code, anthropic, ai-gateway] hide_table_of_contents: true --- @@ -13,7 +13,7 @@ hide_table_of_contents: true Anthropic is moving Claude Code auto mode's safety classifier from the client to the Claude API. Starting with Claude Code v2.1.278, released September 19, sessions on Enterprise plans and Claude API accounts ask the server to run those checks as part of their own model requests, and Anthropic does not charge for the checks when the server performs them. Anthropic told us the rollout started on September 18 and is gradual, beginning with the Claude Code CLI and VS Code extension and followed by the desktop app and Claude Code on the web over the following week, and that on September 25 auto mode becomes the default permission mode in Claude Code. Today the built-in default is auto on Pro, Max and Team plans and Manual on Enterprise plans and Claude API keys, the accounts that typically sit behind a gateway, per Anthropic's [permission modes reference](https://code.claude.com/docs/en/permission-modes). -Server-side auto mode depends on a contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. The fix is merged on `main` and ships in the next release. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, which release carries it, and how to confirm your deployment is ready. +Server-side auto mode depends on a contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. The fix is merged on `main` and ships in the dev release on Tuesday, September 22. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, which release carries it, and how to confirm your deployment is ready. {/* truncate */} @@ -47,7 +47,7 @@ When `/v1/messages` is used to reach a non-Anthropic model through the adapter p This fix covers LiteLLM's route to the Anthropic API. Claude Code also asks for server-side checks on Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry, subject to each platform's own rollout, and LiteLLM's routes to those platforms still filter the beta header, so sessions reaching Claude on them through LiteLLM are not covered by this change yet. We are tracking that as follow-up work. -The merge is not in any tagged build up to `v1.103.0-rc.1`. It first ships in the release candidate cut on Saturday, September 26 (`v1.104.0-rc.1` by the current numbering), with the stable release the following week, planned for Saturday, October 3. Anthropic's September 25 default change lands one day before that release candidate, so Claude Code sessions routed through the native `/v1/messages` endpoint on any current LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. +The merge is not in any tagged build up to `v1.103.0-rc.1`. It ships in the dev release on Tuesday, September 22, ahead of Anthropic's September 25 default change, with the next stable release following on the usual schedule. Claude Code sessions routed through the native `/v1/messages` endpoint on any earlier LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. ## How to verify your deployment @@ -69,7 +69,7 @@ curl -s "$LITELLM_PROXY_URL/v1/messages" \ }' | jq '{safeguard_results, tool_use_ids: [.content[] | select(.type == "tool_use") | .id]}' ``` -On a proxy built from `main` (or the release candidate above) pointed at the Anthropic API, the tool use ID in `safeguard_results` matches the one in the response content: +On a proxy built from `main` (or the September 22 dev release) pointed at the Anthropic API, the tool use ID in `safeguard_results` matches the one in the response content: ```json { @@ -119,7 +119,7 @@ Yes. The fix is in LiteLLM OSS (Apache 2.0) and requires no configuration. [Lite ## Conclusion -An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM's native `/v1/messages` route now passes it through unchanged on the way to the Anthropic API. Upgrade to the September 26 release candidate or the October 3 stable release, run the check above, and your users get server-side auto mode at no cost. +An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM's native `/v1/messages` route now passes it through unchanged on the way to the Anthropic API. Upgrade to the September 22 dev release or the next stable release, run the check above, and your users get server-side auto mode at no cost. ## Recommended Reading From 72e30b8b9064d4eef2fd6ad249372266f4e02e68 Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Mon, 21 Sep 2026 12:05:51 -0700 Subject: [PATCH 5/5] blog: keep the release candidate and stable dates next to the September 22 dev release --- blog/claude_code_server_side_auto_mode/index.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/blog/claude_code_server_side_auto_mode/index.md b/blog/claude_code_server_side_auto_mode/index.md index 6af7f80cd..38859492d 100644 --- a/blog/claude_code_server_side_auto_mode/index.md +++ b/blog/claude_code_server_side_auto_mode/index.md @@ -13,7 +13,7 @@ hide_table_of_contents: true Anthropic is moving Claude Code auto mode's safety classifier from the client to the Claude API. Starting with Claude Code v2.1.278, released September 19, sessions on Enterprise plans and Claude API accounts ask the server to run those checks as part of their own model requests, and Anthropic does not charge for the checks when the server performs them. Anthropic told us the rollout started on September 18 and is gradual, beginning with the Claude Code CLI and VS Code extension and followed by the desktop app and Claude Code on the web over the following week, and that on September 25 auto mode becomes the default permission mode in Claude Code. Today the built-in default is auto on Pro, Max and Team plans and Manual on Enterprise plans and Claude API keys, the accounts that typically sit behind a gateway, per Anthropic's [permission modes reference](https://code.claude.com/docs/en/permission-modes). -Server-side auto mode depends on a contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. The fix is merged on `main` and ships in the dev release on Tuesday, September 22. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, which release carries it, and how to confirm your deployment is ready. +Server-side auto mode depends on a contract between Claude Code and the API that some gateways did not preserve, LiteLLM included. The fix is merged on `main` and ships in the dev release cut on Tuesday, September 22, then in the release candidate cut on Saturday, September 26 and the stable release planned for Saturday, October 3. This post explains what Claude Code needs from an AI Gateway, what LiteLLM was doing wrong, what changed, which release carries it, and how to confirm your deployment is ready. {/* truncate */} @@ -47,7 +47,7 @@ When `/v1/messages` is used to reach a non-Anthropic model through the adapter p This fix covers LiteLLM's route to the Anthropic API. Claude Code also asks for server-side checks on Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry, subject to each platform's own rollout, and LiteLLM's routes to those platforms still filter the beta header, so sessions reaching Claude on them through LiteLLM are not covered by this change yet. We are tracking that as follow-up work. -The merge is not in any tagged build up to `v1.103.0-rc.1`. It ships in the dev release on Tuesday, September 22, ahead of Anthropic's September 25 default change, with the next stable release following on the usual schedule. Claude Code sessions routed through the native `/v1/messages` endpoint on any earlier LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. +The merge is not in any tagged build up to `v1.103.0-rc.1`. It ships in the dev release cut from `main` on Tuesday, September 22, ahead of Anthropic's September 25 default change. Dev releases are pre-release builds published to PyPI, Docker Hub and GitHub releases as `-dev.N` tags, so this one is `v1.104.0-dev.1` by the current numbering (`litellm==1.104.0.dev1` on PyPI). The release candidate cut on Saturday, September 26 carries it next, with the stable release the following week, planned for Saturday, October 3. Claude Code sessions routed through the native `/v1/messages` endpoint on any earlier LiteLLM release see the notice and keep using the client-side classifier until you upgrade. If you would rather your users not see the notice in the meantime, Anthropic documents setting `CLAUDE_CODE_AUTO_MODE_SERVER=0` in the environment Claude Code starts from, which tells it not to ask the gateway for server-side checks. ## How to verify your deployment @@ -119,7 +119,7 @@ Yes. The fix is in LiteLLM OSS (Apache 2.0) and requires no configuration. [Lite ## Conclusion -An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM's native `/v1/messages` route now passes it through unchanged on the way to the Anthropic API. Upgrade to the September 22 dev release or the next stable release, run the check above, and your users get server-side auto mode at no cost. +An AI Gateway in front of Claude Code has to forward provider contracts it did not exist for when they were designed. The `safeguards` field is one of those, and LiteLLM's native `/v1/messages` route now passes it through unchanged on the way to the Anthropic API. Upgrade to the September 22 dev release, the September 26 release candidate or the October 3 stable release, run the check above, and your users get server-side auto mode at no cost. ## Recommended Reading