Claude Code 2.1.239: The Proxy Bug That Silently Doubled Your Bedrock API Bill
A stripped Content-Type response header from proxies, API gateways, or load balancers caused Claude Code to re-run every Bedrock turn in non-streaming mode — billing you twice per request. Here is how to verify exposure and what else 2.1.239 fixes for gateway operators.
Archive item produced with AI assistance from the cited source and published without individual review. Editor of record: Joe Werner.

When Claude Code's changelog notes "Fixed Bedrock streaming behind proxies that strip the response Content-Type header, which silently doubled billed API calls by re-running every turn non-streaming," most teams read it and move on. That's a mistake. This is a billing incident, not a UX fix, and it's the kind that accumulates invisibly across every Bedrock turn your team has run since deploying Claude Code behind a proxy.
What was happening and why
Amazon Bedrock's streaming API uses a response format based on HTTP chunked transfer with Content-Type: application/vnd.amazon.eventstream. Claude Code reads this content-type header on the response to decide how to handle the incoming stream.
When a proxy strips that header — and many do by default — Claude Code sees an unexpected or missing content-type on a streaming response and falls back to non-streaming mode. It then re-runs the request to get the full response. The result is two complete API calls billed for what the user experienced as one turn.
Corporate HTTP proxies, nginx reverse proxies, and AWS Application Load Balancers all have default behaviors that can strip or rewrite response headers. The proxy_hide_header directive in nginx, for example, is a common hardening recommendation. AWS ALBs can rewrite content-type for certain response shapes. If your Bedrock traffic flows through any intermediate layer — which it does in most enterprise deployments — this was happening to you.
The fix in 2.1.239 changes how Claude Code handles the content-type check so that it no longer falls back when the header is absent or unexpected. Existing streaming is preserved; the failure mode is removed.
How to assess whether you were affected
The billing doubling only occurs on turns where Claude Code successfully establishes a Bedrock streaming session but the proxy strips the response Content-Type. You can verify retrospectively:
Check your Bedrock API call volume. Pull Bedrock invocation metrics from CloudWatch (AWS/Bedrock, metric InvocationCount) for the period you ran Claude Code behind a proxy. If the call count is roughly 2× what you'd expect from turn count, you were affected.
Inspect your proxy headers. From a host behind your proxy, run:
curl -v -X POST https://bedrock-runtime.<region>.amazonaws.com/model/... \
-H "Content-Type: application/json" \
--aws-sigv4 "aws:amz:<region>:bedrock" \
-d '{"prompt":"ping","max_tokens":1}' 2>&1 | grep -i content-type
If the response Content-Type is absent or replaced with something like application/octet-stream, your proxy is stripping it.
For nginx: check for proxy_hide_header directives in your config. proxy_hide_header Content-Type; applied to the Bedrock upstream would trigger this. This is sometimes added as a blanket security hardening step without accounting for streaming endpoints.
The cross-provider picture
This bug is specific to Claude Code on Bedrock. The direct Anthropic API (api.anthropic.com) uses a different streaming protocol and content-type pattern; Claude Code handles that path through a separate code branch unaffected by this fix. Vertex AI's Claude endpoint also uses a different streaming negotiation.
Teams that route Claude Code through TheRouter or another gateway pointed at the Anthropic direct API were not exposed. Teams using Bedrock through any proxy layer — AWS API Gateway, an internal enterprise HTTP gateway, an ALB in front of Bedrock — should check their setup and audit their Bedrock billing from the period before 2.1.239.
The other two gateway fixes in 2.1.239
Two more changes matter for operators running Claude Code in enterprise or self-hosted environments.
HTTPS_PROXY not honored during Bedrock SSO credential refresh. When Claude Code uses Bedrock with an SSO profile and awsAuthRefresh enabled, it runs a pre-check to verify credentials before the first request. That pre-check was making a direct HTTPS connection, bypassing HTTPS_PROXY. In environments where Bedrock is only reachable through a proxy (common in VPC-confined setups), Claude Code would hang at startup or fail silently. The fix makes the credential pre-check honor the proxy setting.
Data-residency cost premium now visible. Anthropic charges a 1.1× premium on inference for data-residency workspaces (US-only inference routing). Before 2.1.239, the /cost command, the status line, and --max-budget-usd calculations did not include this premium. Teams running data-residency workspaces were seeing cost estimates 9% lower than their actual Bedrock bills. The fix adds the 1.1× multiplier to all cost estimates and budget enforcement.
What to do now
If you run Claude Code on Bedrock behind any proxy:
- Update to 2.1.239 immediately — the billing doubling fix is in this release.
- Audit your Bedrock invocation count for the prior 30–60 days against your turn count. AWS Bedrock pricing is per request; if you see a 2× ratio, you have a case for a billing inquiry.
- Verify your proxy doesn't strip Content-Type response headers for Bedrock traffic specifically.
- Check the HTTPS_PROXY setting if you were seeing startup hangs on Bedrock with SSO — update to 2.1.239 and ensure
HTTPS_PROXYis set beforeawsAuthRefreshruns. - If you run a data-residency workspace, expect your
/costreadout and budget limits to look 10% higher after updating — that's the fix, not a pricing change.
Teams not using Bedrock are not exposed to the billing doubling. The HTTPS_PROXY and data-residency fixes also only apply to Bedrock deployments.
What TheRouter users should watch or try
If you point Claude Code at TheRouter's OpenAI-compatible endpoint rather than directly at Bedrock, none of the three Bedrock-specific fixes apply to that traffic path — your requests never touch Bedrock's streaming negotiation. The data-residency premium and SSO pre-check are both Bedrock-side behaviors.
If you do route some of your Claude Code traffic through Bedrock as a fallback or primary provider via TheRouter, apply the same audit steps above to that Bedrock leg. The bug is in Claude Code's Bedrock integration, not in the routing layer.
See the Claude Code on Amazon Bedrock docs for the complete proxy configuration reference.

Claude Code 2.1.218 Fixes a Silent Bedrock Billing Bug: Every Operator Running ARN-Mapped Models Must Audit Their Cost Logs
Claude Code misattributed all Bedrock application-inference-profile ARN traffic to the same model ID since February 2026, collapsing Haiku and Opus costs to ~$0.23 per call. Version 2.1.218 fixes ARN resolution — but your historical gateway spend logs are wrong.

Claude Code 2.1.273: Five New Gateway Headers and a Classifier Flip on Bedrock, Vertex, and Foundry
Claude Code 2.1.273 ships opt-in gateway hint headers exposing request class, agent type, and compaction state to any LLM proxy. It also flips the auto mode classifier to local-only on Bedrock, Vertex AI, and Foundry — only one change has a revert path.

Claude Code 2.1.268: The Three-Version Gateway Breakage Operators Missed, and Four New Controls
Since 2.1.265, every turn through a third-party Anthropic-compatible endpoint failed with HTTP 400. Version 2.1.268 fixes it and adds gatewayInternalNetworks CIDR policy, pricing sync to gateway.yaml, and byte-stable prompt caches for Bedrock, Vertex, and Foundry.