Claude Code 2.1.196: Org Default Models, Stream Watchdog, and a Tighter Remote Control Boundary
Three operator-relevant changes in v2.1.196 reshape how you govern model selection, stream reliability, and custom-endpoint security for Claude Code deployments.

Your Claude Code fleet just got a new layer of admin-plane control. Version 2.1.196, released on June 30, 2026, ships three changes that every operator managing a multi-team or enterprise deployment needs to understand before the next upgrade cycle: organization-level default model configuration, a streaming idle watchdog enabled by default across all providers, and a security guard that disables Remote Control when ANTHROPIC_BASE_URL points at a non-Anthropic host.
What changed
Organization default models — admin-plane routing, finally.
Admins can now set a default model for the entire organization directly from the org console. The chosen model shows up as "Org default" (or "Role default") in the /model picker for any user who has not made a personal selection. This is a long-awaited gap closure: previously, teams that wanted to steer all developers toward a specific model tier had to push a managedSettings.json with defaultModel and rely on policy enforcement. Now there is a first-class UI surface for this in the org console, backed by the same managed settings layer.
Stream watchdog on by default for all providers.
The streaming idle watchdog — which aborts and retries when a response stream produces no events for five consecutive minutes — is now enabled by default for every provider. Previously it was opt-in or limited to Anthropic's own endpoint. Operators running Claude Code against non-Anthropic hosts (Bedrock, Vertex, Foundry, or a custom gateway) will now see stalled streams auto-recovered without manual intervention. The escape hatch is CLAUDE_ENABLE_STREAM_WATCHDOG=0.
Remote Control disabled on non-Anthropic base URLs.
When ANTHROPIC_BASE_URL is set to a host that is not api.anthropic.com, Remote Control is now automatically disabled. This matches the existing behavior for CLAUDE_CODE_USE_BEDROCK, _VERTEX, and _FOUNDRY. The motivation is security: Remote Control relies on Anthropic's session infrastructure; routing it through an arbitrary proxy or gateway creates an unintended control channel. Operators who use a gateway in front of Anthropic (with the gateway calling Anthropic on the backend) are not affected — only deployments that route traffic to a genuinely different backend are.
Additional notable fixes include:
- MCP OAuth scope bug fixed: the OAuth client was requesting the full
scopes_supportedcatalog from the authorization server when no scope was specified. This causedinvalid_scopefailures on GitLab self-hosted and other enterprise IdPs that enforce strict scope validation. Fixed in 2.1.196. - Background session reliability: long-running commands now survive process stops, restarts, and updates, including on Windows where background shells are now handed off rather than killed.
- Agents view fixes: keyboard focus, stale status rows, and PR-link rendering in the
claude agentspanel are resolved. claude mcp list/getnow sandboxed: these commands no longer auto-spawn MCP servers self-approved via a committed.claude/settings.jsonin untrusted workspaces. Untrusted workspace servers show⏸ Pending approval.
Why it matters for AI engineering teams
The org default model feature is operationally significant for teams that run Claude Code through TheRouter or another AI gateway. If your gateway maps the org console's "default" to a specific upstream model, the org console selection becomes a routing policy decision — one that now has a first-class UI behind it rather than a JSON file that developers may not know about.
The stream watchdog change closes a reliability gap that has been a source of silent failures for teams routing through Bedrock, Vertex, or custom inference endpoints. Previously a stalled provider response would hang indefinitely, requiring the developer to manually interrupt. Now the watchdog fires at the five-minute mark and retries, giving your fallback routing logic a chance to activate.
The Remote Control base-URL guard matters if your security posture requires isolating Claude Code's control plane. Any deployment that sets ANTHROPIC_BASE_URL to a gateway or proxy should audit whether Remote Control was previously active and whether that exposure was intentional.
The router/operator angle
Three action items fall directly on operators:
1. Align org console default with gateway model routing. If you use TheRouter or another gateway that normalizes model IDs, make sure the model name configured in the org console matches what your gateway accepts. A mismatch between the admin-console default and your gateway's model catalog will cause users to see "Org default" in the picker but get routing errors at inference time. Audit this before rolling out 2.1.196.
2. Audit stream watchdog impact on custom endpoints. The new default-on watchdog will now issue retries on stalled streams from your custom gateway. If your gateway has long-latency first-token responses (>5 minutes for a first chunk), you may see spurious retries. Check CLAUDE_ENABLE_STREAM_WATCHDOG=0 to disable if needed while you optimize your upstream timeout chain.
3. Check Remote Control exposure for gateway deployments. If you set ANTHROPIC_BASE_URL to point at your own API gateway (which then calls Anthropic), Claude Code now disables Remote Control. If your team was relying on Remote Control for background agent management in this topology, you need to either restructure the deployment (keep ANTHROPIC_BASE_URL unset and configure the gateway at a different layer) or accept that Remote Control is no longer available in that configuration.
For the MCP OAuth fix: if you operate GitLab self-hosted or any enterprise IdP as an MCP OAuth provider, this fix should resolve the invalid_scope failures that appeared when no explicit scope was configured. Upgrade to 2.1.196 and verify that your OAuth flow completes without scope errors.
What TheRouter users should watch or try
Teams routing Claude Code through TheRouter should verify that the model name set in the org console (e.g., claude-opus-4-8-20260801) is listed in your TheRouter model catalog. If you use TheRouter's model-aliasing feature to normalize upstream model IDs, map the org console value to the alias your developers expect to see. The org default model is now the first visible routing signal a developer encounters — making sure it lines up with your gateway's routing table avoids confusing failures on first use.
The stream watchdog is a net positive for TheRouter deployments: stalled upstream streams that previously caused invisible hangs will now trigger automatic retries. This aligns with TheRouter's provider fallback model — the watchdog fires first, and if the retry also stalls, your fallback policy kicks in.
For background on managed settings and org-level Claude Code governance, see the Claude Code operator documentation.

Claude Code 2.1.228: The Settings-Merge Bug That Put Custom Headers in the Wrong Tier
2.1.228 fixes a settings-merge bug where marketplace entries could silently inherit custom headers from lower-precedence settings tiers, and makes Vertex AI credential failures fast — two changes that change how you audit operator deployments.

Claude Code Artifacts Now Call MCP Connectors with Viewer-Scoped Auth: What Operators Must Know
Claude Code Artifacts can now pull live data through each viewer's own MCP connectors — not the creator's. That inversion changes how teams build shared internal dashboards, who owns the credential chain, and what your AI gateway must account for.

Claude Code Origin Story Routing: Why Anthropic's Terminal Agent History Matters
Claude Code origin story routing turns Anthropic's official history into an operator checklist for terminal agents, permissions, context, and parallel swarms.