groundy
Ethics, Policy & Safety

Anthropic Bans Third-Party Subscription Auth: The Three-Stage Repricing

Anthropic's push from blocking third-party Claude subscription auth to a metered Agent SDK credit, then the June 15 pause that left programmatic usage on subscription limits.

Published Updated 21 references
On this page7 sections

Anthropic’s crackdown on third-party developer tools piggybacking on Claude subscription authentication has become a three-stage repricing with an unfinished fourth act. Open-source CLIs such as OpenCode routed requests through Claude Max subscription tokens at subscription rates rather than API list prices. Enforcement arrived in February 2026, formal policy on April 4, and a metered Agent SDK credit on May 13. Then, on June 15, the day the credit was to take effect, Anthropic paused it. Programmatic usage is drawing from subscription limits again while the plan is revised, leaving automated workflows built around flat-rate access in a temporary reprieve, and keeping the argument over platform control and flat-rate AI pricing open.

What Actually Happened

In February 2026, developers using OpenCode, a popular open-source coding agent, found their Claude Max subscription credentials had stopped working. (GitHub Issue #7410) Anthropic had patched the authentication pathway that let third-party tools use subscription tokens for API access. Making the relay work at all meant pretending to be the official client: as one Hacker News commenter put the distinction, OpenCode was “a separate harness grabbing a user’s Claude Code session and pretending to be Claude Code.” (Hacker News) The Register later tied the enforcement wave to OpenClaw, an open-source autonomous agent harness whose long-running, token-heavy tasks pushed Anthropic to get serious about a third-party-harness ban it had rarely enforced. (The Register)

The core issue is straightforward economics. Anthropic’s $200/month Claude Max subscription is far cheaper than the pay-as-you-go API for heavy use: a month of Claude Code can easily consume tokens that would have cost more than $1,000 at API prices. (Hacker News) Third-party tools had reverse-engineered the subscription authentication flow so their users could reach Claude’s models at subscription rates; Anthropic’s response was to close that loophole entirely.

What began as server-side enforcement became formal policy on April 4, 2026. Anthropic announced that Claude Code subscribers could no longer use subscription limits for third-party tools including OpenClaw, with the cutoff effective at noon Pacific that day, and offered a pay-as-you-go billing path billed separately from subscriptions. OpenClaw creator Peter Steinberger and board member Dave Morin “tried to talk sense into Anthropic” and secured only a one-week delay of the pricing change. (TechCrunch)

Six weeks later, Anthropic reversed course, partially. On May 13, 2026, it announced an “Agent SDK credit” effective June 15: all paid subscribers would become eligible for a monthly credit ($20 for Pro, $100 for Max 5x, $200 for Max 20x; Team seats $20 to $100; Enterprise seats up to $200) (VentureBeat; The New Stack) covering Agent SDK calls, claude -p, Claude Code GitHub Actions, and third-party apps authenticated through the Agent SDK, including OpenClaw. The credit would be metered at API list rates, non-rollover, non-transferable, capped at the credit amount, with overage only if the subscriber explicitly enabled extra usage billing. (The Register; The Decoder) Anthropic framed it as clarity: programmatic usage “gets its own dedicated budget,” with subscription limits “reserved for interactive use.” The original path of grabbing OAuth tokens to power a custom agent stayed off-limits.

Then the switch did not flip. OpenClaw’s provider documentation, which tracks Anthropic’s support articles, records the June 15 reversal in four bullets: (OpenClaw provider docs)

  • Anthropic’s June 15, 2026 support update paused the previously announced separate Agent SDK credit plan.
  • Subscription-plan Claude Agent SDK, claude -p, and third-party app usage still draw from the signed-in subscription’s usage limits.
  • The previously announced monthly Agent SDK credit is not available while Anthropic revises that plan.
  • Console/API-key logins use pay-as-you-go API billing and do not receive the subscription Agent SDK credit.

User reports have not been uniform; some Hacker News commenters describe third-party usage being billed as extra usage rather than plan limits. (Hacker News) What is clear is that the metered cap, the centerpiece of the May announcement, is not currently in force.

Anthropic developer Lydia Hallie’s X visualization of the announced split, captioned “you don’t pay extra,” received a Community Note within hours: the credit was new, but programmatic usage that previously counted against subsidized subscription limits would burn a fixed-dollar pool at API list rates. (The Decoder; canonical reference) The Register’s read on the fine print was blunter: unused credit “gets lost,” and “it’s not redeemable currency.” (The Register)

Who Is Affected and Who Isn’t

The community reaction, particularly on Hacker News, initially read like a blanket ban on third-party development. The reality was more layered.

Tool / Access MethodStatusWhy
OpenClawSanctioned with an asterisk: OAuth relay blocked (enforced February 2026, formal policy April 4); Claude CLI and claude -p paths treated as allowed; announced June 15 credit pool pausedOpenClaw docs: subscription-plan Agent SDK, claude -p, and third-party app usage currently draws from subscription limits
AWS Bedrock / Vertex AIUnaffectedOfficial commercial API channels; the headless-mode docs note Bedrock and Vertex “use their usual provider credentials” (Hacker News)
Anthropic API (pay-as-you-go)UnaffectedStandard API key authentication; API-key accounts are not eligible for the subscription credit (The New Stack)
Claude Agent SDKAPI keys required for production third-party productsThe SDK docs state Anthropic “does not allow third party developers to offer claude.ai login or rate limits for their products” (Hacker News); the subscription-side credit that would soften this is paused

One Hacker News commenter drew the line the same way the table does: running an agentic application inside an official Claude Code session is compliant, but “What’s not allowed is grabbing the oauth tokens and using these for your own custom agent, which is what was (and still is) banned.” (Hacker News)

The Terms of Service Were Always Clear, Sort Of

Anthropic’s Consumer Terms of Service prohibit accessing the services “through automated or non-human means, whether through a bot, script, or otherwise,” with a critical exception: “when you are accessing our Services via an Anthropic API Key or where we otherwise explicitly permit it.” (Consumer Terms) The Commercial Terms go further, barring customers from accessing the services “to build a competing product or service… except as expressly approved by Anthropic.” (Commercial Terms)

The ambiguity was real for months: Anthropic’s own Agent SDK had not explicitly disallowed third-party applications (The Register), and staff clarifications contradicted each other as the policy moved (Hacker News). That has been resolved in one direction. The Agent SDK documentation now states: “Unless previously approved, Anthropic does not allow third party developers to offer claude.ai login or rate limits for their products, including agents built on the Claude Agent SDK. Please use the API key authentication methods described in this document instead.” (Hacker News, quoting the SDK docs) The June 15 pause changes the billing treatment, not that prohibition.

Why Anthropic Is Drawing This Line

The business logic is not subtle. Claude Code is Anthropic’s primary developer relationship channel.

Revenue protection. The Register’s summary is hard to improve on: Anthropic, “mindful that it will need to show a profit eventually, has been trying to push customers toward its metered API and to constrain consumption of flat-rate subscription tokens.” (The Register) The scale explains the pressure. Anthropic crossed a $30 billion annualized revenue run rate by early May 2026, up from $14 billion in February, with CEO Dario Amodei telling the Code with Claude conference that the company had planned for 10x annualized growth and “saw 80x.” (VentureBeat) The subscription exists to capture developer mindshare, not per-user margin, and third-party tools enjoying the same economics without driving engagement through Claude Code undermine that.

Context optimization. Anthropic’s first-party tools are engineered to maximize “prompt cache hit rates,” reusing previously processed text to save compute; third-party tools like OpenClaw, which run agents through services like Discord or Telegram, often bypassed those efficiencies. Head of Claude Code Boris Cherny called such workloads “really hard for us to do sustainably.” (VentureBeat) The Register described the underlying pattern as customers “gorging on tokens at the all-you-can-eat subscription trough.” (The Register)

Ecosystem control. Anthropic is in a platform race. If developers build muscle memory around OpenClaw or other multi-provider tools, switching costs evaporate. One commenter argued the policy whiplash comes from not picking a strategy: “Restricting third-party harnesses maximizes Claude Code revenue; allowing them maximizes model-layer lock-in through developer habit.” (Hacker News) Keeping developers inside Claude Code and its growing official plugin ecosystem keeps them inside Anthropic’s ecosystem.

The structural endpoint, paused. The May 13 credit system was the visible expression of all three pressures: interactive usage (claude.ai chat, Claude Code in the terminal, Cowork) stays on the flat-rate subscription, while agentic and programmatic workflows land on API-rate metering with a monthly fuse. A community analysis quantified the envelope: assuming 50,000 tokens per run split evenly between input and output, the $200 Max 20x credit would have covered roughly 440 Sonnet 4.6 runs or 265 Opus 4.7 runs per month at API list prices (dev.to), and put the effective cost increase for teams built around flat-rate claude -p at 12x to 175x depending on workload, with Theo Browne’s “25x cut” as the middle estimate. None of that is in force. The June 15 pause leaves programmatic usage on subscription limits; the split is announced architecture, not yet operative billing.

The Developer Community Response

The reaction split into camps.

The pragmatists acknowledged Anthropic was within its rights. Replying to the complaint that a $200 all-you-can-eat plan was indefensible next to $1,000+ API costs, one commenter wrote: “Hard disagree. Companies can and do subsidize products to gather market share. It’s just a loss leader.” (Hacker News) By the April Tell HN thread, the top argument was plain oversubscription math: “Every single one of them oversells their capacity. The power users that use the services a lot are subsidized by those who don’t use it as much.” (Hacker News)

The open-source advocates argued Anthropic should have restructured pricing long ago. “Anthropic shouldn’t have an all-you-can-eat plan for $200 when their pay-as-you-go plan would cost more than $1,000+ for comparable usage,” argued a widely quoted HN comment. “Their subscription plans should just sell you API credits at, like, 20% off.” (Hacker News)

The workaround crowd quietly pushed fixes. Steinberger reported that Anthropic’s classifier kept getting routed around and that it was “trivial to do so with a few renames,” adding “I’m not playing that game.” (Hacker News) Others wrapped claude -p in an OpenAI-compatible API proxy, conceding it “probably violates every AI company’s ToS” and that Anthropic “may auto-detect and bill it as extra usage.” (Hacker News)

A fourth current ran through the later threads: exhaustion with the communication itself. As the guidance shifted again, one commenter wrote that Anthropic had proved “unreliable when it comes to CC.” (Hacker News) Steinberger, in the same thread, reported that Anthropic’s classifier still blocked parts of OpenClaw’s system prompt in practice, “so the actual behavior today does not match what was communicated publicly.”

What This Means Going Forward

For developers building on Claude today:

  1. Use official API keys for production work. The Agent SDK documentation states that SDK use is governed by the Commercial Terms “including when you use it to power products and services that you make available to your own customers and end users.” (Agent SDK docs) Anything you ship to others should use API keys, not subscription credentials.

  2. Track what closed and what paused. The OAuth-token relay was blocked in February, formally banned April 4, and stays closed. claude -p subprocess invocations and Claude CLI reuse were later confirmed as allowed (Hacker News), and the June 15 credit switch was paused before it took effect, so subscription-plan programmatic usage currently draws from subscription limits. OpenClaw’s docs advise checking claude auth status, /status, and Anthropic’s support articles when billing predictability matters, because Anthropic can change the behavior without notice. (OpenClaw provider docs)

  3. Price against current model rates, not May’s. Whenever metering returns, model tier sets the burn rate. Fable 5 launched June 9, 2026 at $10 per million input and $50 per million output tokens, double the $5/$25 that Opus 4.7 listed at the time (Anthropic; dev.to). Subscription plans were to include Fable 5 through June 22, with usage credits required after; instead, access was suspended June 12 and restored July 1. Opus 5.5 arrived September 22, costing 40% less to run than Opus 5. (Anthropic Newsroom) Budget calculations made against a single model’s rate age quickly.

  4. Budget for the announced direction, not the current state. The sequence so far is two re-costings and one suspension: April 4’s walkback, May 13’s metering, and a June 15 pause with no new effective date. The fine print says the credit “may be modified or discontinued.” (canonical reference) If your automation would exceed the credit at API rates, decide now whether to enable capped overage, hybrid-route background work to another provider, or move to API keys.

One forward risk: Steinberger flagged that Claude Code’s new --bare flag “skips OAuth and keychain reads” and is documented as “the recommended mode for scripted and SDK calls, and will become the default for -p in a future release.” If that transition lands, it further tightens the path from subscription-subsidized claude -p to API-key-only programmatic access. (Hacker News)

The Broader Competitive Context

The enforcement also illuminates the landscape Anthropic is navigating. Cursor reached $2 billion in annualized revenue in February 2026 and forecasts more than $6 billion by year end (TechCrunch). TechCrunch describes a company reliant on third-party models that operated at negative gross margins until its proprietary Composer model and cheaper outside models pushed it into slight profitability, with enterprise sales now margin-positive and individual accounts still loss-making. How Cursor pays its model suppliers is not documented in that reporting; the Cursor growth story tracks the trajectory in detail.

What Anthropic was chasing was not large commercial players like Cursor but the long tail of indie developers and small teams who could cut AI spend dramatically by routing through a personal Max subscription. That is a compute subsidy Anthropic absorbs. (Hacker News)

OpenClaw is still available despite the blocks. Its provider documentation recommends an Anthropic API key over the Claude CLI path for shared production automation, and notes it supports subscription-style options from other model providers as well. (OpenClaw provider docs) In a brief flashpoint on April 10, Anthropic temporarily suspended Steinberger’s personal account over what a company message called “suspicious” activity (he was by then employed by rival OpenAI); the account was reinstated a few hours later, after the post went viral, and per TechCrunch an Anthropic engineer told him the company had never banned anyone for using OpenClaw and offered to help. (TechCrunch)

The repricing pressure reaches beyond OpenClaw. T3.gg CEO Theo Browne stated publicly that he would have to “make the Claude Code experience on T3 Code significantly worse” to avoid burning through users’ Agent SDK credits. (dev.to) The split Anthropic is pushing toward, subscriptions for individuals and API keys for anyone building a product on top, is stated in its own SDK documentation rather than inferred from its enforcement actions. (Hacker News) The Agent SDK credit was a concession to that boundary’s limits, a metered on-ramp capping costs without a full API billing relationship. The pause means Anthropic has not yet managed to switch that compromise on.

The Agent SDK documentation, requiring API keys and prohibiting subscription credential relay for production products, codifies the boundary in developer tooling rather than only legal terms. (Hacker News) The May 13 credit was the next iteration, and the June 15 pause shows the guardrails are negotiable in both directions. For anyone building against Claude subscription auth, the operative lesson from seven months of policy churn is to treat every configuration, permissive or restrictive, as provisional.

References

Follow the links in the article for context. The supporting material is collected here for further reading.

  1. Anthropic Commercial Terms of Service, Sections A and Danthropic.comAccessed
  2. Anthropic Newsroomanthropic.comAccessed
  3. Claude Agent SDK documentationplatform.claude.comAccessed
  4. OpenClaw provider documentation: Anthropicdocs.openclaw.aiAccessed
  5. Anthropic tosses agents into the API billing pooltheregister.comAccessed
  6. Anthropic: Introducing Claude Fable 5 and Claude Mythos 5anthropic.comAccessed

Join the discussion

Share a useful perspective or ask a question about this article.

Discussion guidelinesComments privacy