Claude Code Gateway OAuth Credential Regression: Fix and Operator Audit Checklist
Claude Code's May 28 patch fixed an OAuth credential regression that could send user Anthropic tokens to custom API gateways. Here is the gateway audit checklist for token isolation, logging, and subagent MCP policy enforcement.
Archive item produced with AI assistance from the cited source and published without individual review. Editor of record: Joe Werner.

The operational question this incident forces is simple and urgent: does your Claude Code gateway receive the credentials you intended it to receive, or could it ever receive a user's raw OAuth token instead?
Anthropic's Claude Code release published on May 28, 2026 at 00:52 UTC patches a regression with direct implications for any team running Claude Code through a custom API gateway — including OpenAI-compatible routing proxies. The fix addresses a bug where the user's Anthropic OAuth credential could be forwarded to a custom API gateway instead of the gateway's own configured token. For operators searching for the Claude Code OAuth credential regression, the practical task is not speculation; it is a focused audit of gateway token isolation, request attribution, and subagent MCP policy enforcement. A second fix in the same release closes a policy-bypass path in subagent MCP server configurations.
What happened
The regression, introduced in a prior release, affected Claude Code sessions configured to route through a custom API gateway (set via ANTHROPIC_BASE_URL or equivalent gateway configuration). In affected versions, the client could send the user's own Anthropic OAuth token — the credential tied to their Anthropic account — to the custom gateway endpoint, rather than using the gateway's configured API key or bearer token.
The bug was classified as a regression: it did not exist in earlier versions and was reintroduced by a subsequent change. The patch reverts the incorrect credential-forwarding path and restores the intended behavior: a custom gateway receives the gateway's own configured authentication material, not the operator's or user's Anthropic OAuth session.
Two additional fixes in the same release are relevant to multi-agent deployments:
Subagent MCP policy bypass closed. Subagents launched via the Agent tool were ignoring the --strict-mcp-config flag, --bare mode, remote-mode restrictions, enterprise managed-settings.json MCP configuration, and the MCP server allow/deny policies defined by the operator. In practice, this meant that an agent invoked as a subagent could access MCP servers that the operator had explicitly blocked or had not approved. The patch enforces these restrictions for subagent-launched processes, bringing them in line with the parent session's policy.
--strict-mcp-config no longer strips approved inline servers. A narrower companion fix ensures that --strict-mcp-config does not remove inline mcpServers from explicitly passed agent definitions (via --agents flag or SDK agents). This corrects an overly aggressive restriction that was blocking legitimate configurations while not preventing the policy bypass described above.
Additional changes in this release include: /model now saves the selected model as the default for new sessions; macOS background agents retain their Privacy & Security permission grants across upgrades; a stateful MCP SSE reconnect loop regression is fixed; and the Windows update rollback path is improved.
Why it matters for AI engineering teams
The credential regression is a trust-boundary violation, not a data-exposure incident in the traditional sense. No external attacker received anything — the credential was sent to an endpoint that the user or operator controlled (the custom gateway). But the violation of the intended trust boundary matters for several reasons:
-
Gateway-layer token accounting breaks. If a gateway receives an Anthropic OAuth token instead of its own configured key, requests may be incorrectly attributed. Some gateways use the incoming bearer token for billing attribution; receiving an OAuth credential instead of an API key can silently corrupt per-team or per-project usage attribution.
-
Gateway-layer access controls are bypassed. A routing proxy typically enforces rate limits, budget caps, allowed-model lists, and logging policies based on the incoming token it expects to receive. If it receives an unexpected OAuth credential, any policy keyed to token identity fails silently.
-
Credential lifecycle risk. An Anthropic OAuth token has a different validity window and revocation path than an API key. If the wrong credential type is in transit to a gateway, it is subject to capture in gateway logs — a different exposure surface than intended.
The subagent MCP bypass is an enterprise governance gap. Teams using Claude Code's multi-agent capabilities (Agent tool, claude agents) to orchestrate parallel coding sessions are the most exposed. An operator who configured managed-settings.json to restrict which MCP servers subagents could access was not getting that restriction enforced. This is a direct security gap for enterprise deployments where network MCP server access is part of the compliance boundary.
The router/operator angle
Credential-isolation design is a shared responsibility between the client and the gateway. This regression makes concrete a risk that is easy to design around with a few explicit choices.
On the client side: Claude Code uses ANTHROPIC_BASE_URL to redirect requests to a custom endpoint. When this environment variable is set, the intended behavior is that the client uses the gateway's authentication — not the user's Anthropic account credential. The regression broke this contract. After patching to this release, the contract is restored.
On the gateway side: a well-designed API gateway should reject tokens it does not recognize. If your gateway issues its own API keys and receives a bearer token that does not match any known key, it should return 401 immediately. This is a defense-in-depth property that would have made the credential regression visible as an authentication failure rather than a silent credential swap. If you have not audited what token formats your gateway accepts and rejects, this is the moment to do so.
Checklist for gateway operators running Claude Code:
- Update all Claude Code installations to the May 28 release before continuing multi-user or multi-tenant gateway deployments.
- Audit gateway access logs for any sessions that authenticated with an unexpected token format or length compared to your issued API keys. OAuth tokens have distinct structures from API keys.
- Confirm that
ANTHROPIC_BASE_URLis set and thatANTHROPIC_API_KEYis set to the gateway-issued key, not a user's Anthropic key, in all client configurations that route through your gateway. - For subagent deployments: verify that your
managed-settings.jsonMCP policies are now being enforced end-to-end by running a test subagent invocation and confirming it cannot reach a blocked MCP server. - Review gateway token-validation logic: if your gateway accepts any well-formed bearer token rather than validating against a known key store, tighten this. Token-type validation is a cheap and effective regression detection mechanism.
MCP policy enforcement gap requires an architectural review. If your Claude Code deployment uses multi-agent orchestration with MCP servers, the previous behavior created a gap between the policy you configured and what subagents actually enforced. You should treat any MCP server accesses that occurred in subagent sessions before this patch as potentially unaudited — compare what your managed-settings.json allowed against what subagents actually connected to by reviewing session logs.
What TheRouter users should watch or try
Teams routing Claude Code through TheRouter or any OpenAI-compatible API gateway should treat this as a two-step action:
-
Ensure all Claude Code clients are on the May 28 release (v2.1.150 or later). The credential regression only affects sessions going through a custom gateway, which is the typical setup when using a routing proxy.
-
Verify your token configuration is explicit. Claude Code should be configured with the gateway-issued key as
ANTHROPIC_API_KEYand the gateway URL asANTHROPIC_BASE_URL. If you manage Claude Code deployments at the team level, confirm these environment variables are set in CI, container environments, and developer.envfiles.
TheRouter records per-request attribution and billing based on the API key it receives. If affected sessions sent an Anthropic OAuth token to the gateway, those requests may have been rejected (preferred) or logged under an unexpected identity. Reviewing your gateway request logs from before the patch date for anomalous authentication events is the most direct audit path.
The subagent MCP policy enforcement fix is relevant for teams using Claude Code's background agent capabilities (claude --bg, claude agents, Agent tool). After updating, test that your MCP allow/deny policy is applied consistently to both parent and subagent sessions before resuming production workloads.

Claude Code 2.1.269: Three Operator Changes Hidden Inside a 60-Fix Release
Claude Code 2.1.269 ships with a gateway discovery timeout override, a hard cap on concurrent workflow agents, and a fix for deny rules that were silently applying beyond their config source. Each one changes how operators govern Claude Code at scale.

Claude Code 2.1.222 Fixes Silent Gateway Stream Drops and a Background-Task Hook Bypass
Three fixes in Claude Code 2.1.222 directly affect operators running custom ANTHROPIC_BASE_URL gateways: stream idle timeout now respects keepalives from any endpoint, a PreToolUse hook bypass in background tasks is closed, and worktree git-command scope is hardened.

Claude Code 2.1.275 Broke Every Gateway Proxy. 2.1.276 Fixed It the Same Day.
A new internal request tag in 2.1.275 caused 400 errors on every proxy-routed API call. 2.1.276 hotfixed it the same day. Breakdown of the failure, affected configs, and three secondary operator changes worth auditing.