The message means Claude Code resolved your login to an organization that does not allow claude.ai subscription sign-in for Claude Code. On a Team or Enterprise seat that is a real admin policy, and only an admin can change it. On a personal Pro or Max plan there is no admin to ask: every claude.ai account has an auto-generated personal organization, and 39 issues on the Claude Code GitHub between April and September 2026 quote this message or its oauth_org_not_allowed form, about half of them titled as personal Pro or Max accounts. There the cause is a lapsed payment or a sign-in fault on Anthropic's side, and no local setting clears it. One command, /status, tells you which case you are in. In every case the message names the ways forward itself: an API key, or your admin.
The error
Your organization has disabled Claude subscription access for Claude Code · Use an Anthropic API key instead, or ask your admin to enable access
# the same refusal as the API returns it (reported as oauth_org_not_allowed):
API Error: 403 {"type":"error","error":{"type":"permission_error",
"message":"OAuth authentication is currently not allowed for this organization."}}Causes and fixes at a glance
| Cause | Fix |
|---|---|
| A Team or Enterprise admin has turned off claude.ai subscription sign-in for Claude Code — /status shows your company under Organization | Ask the admin to enable it, or which method the organization allows instead: a Claude Console seat, SSO or a cloud provider. |
| The plan is not actually active: a renewal failed on an expired card, or the account is still marked past due after the invoice was paid | Check claude.ai → Settings → Billing. Update the card; if the invoice shows paid and the account does not, that is for Anthropic support. |
| A personal Pro or Max plan refused under its own auto-generated organization (“your-email's Organization”) — a known Anthropic-side sign-in bug | /logout, then /login once. If it returns, contact Anthropic support with your /status output; nothing on your machine clears it. |
| You need Claude Code working today, whichever case it is | Use an API key — the message's own first suggestion. It bills per token and parks the subscription only while it is set. |
Read /status before changing anything
Run /status inside Claude Code. Two rows decide the case: Login method, and Organization. A company name under Organization means a real policy (next step). Your own email followed by “'s Organization”, on a Pro or Max plan, means a personal account (the step after). Check for a second credential while you are there: when a login and an API key are both configured, /status marks the one that is not in use.
Company organization: the admin decides
The setting belongs to the organization, and Anthropic's error reference sends you to the admin for it: enable Claude subscription access for Claude Code, or say which method is allowed instead — a Claude Console seat billed per token, SSO, or a cloud provider such as Amazon Bedrock. Do not route around it with a personal key on that machine. When managed settings pin the login to the organization (forceLoginOrgUUID or forceLoginMethod), Claude Code refuses ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN and apiKeyHelper at startup anyway.
Personal Pro or Max: billing first, then sign out and in, then escalate
Open claude.ai → Settings → Billing before anything else. Reports on the Claude Code GitHub trace this message to a renewal that failed on an expired card and to an account left past due after its invoice was paid — Claude Code reads a lapsed plan the same way as a disabled one. If billing is clean, run /logout, then claude again: logging out also resets first-launch setup, so you get a clean /login. If the message comes back, the fault is in how Anthropic maps your personal organization to the plan, and there is no admin toggle to find. Duplicate reports on the Claude Code GitHub are closed into anthropics/claude-code#72027, which the stale bot closed on September 13, 2026 without a fix, while new reports kept arriving through September. Contact Anthropic support from claude.ai with your /status output and reference that issue.
Keep working on a key without touching the login
Credentials in the environment outrank the subscription login in Claude Code's precedence order, so a key scoped to one command leaves the login alone for when access comes back. An Anthropic Console key goes in ANTHROPIC_API_KEY, and Claude Code asks once to approve it. A gateway key goes in ANTHROPIC_AUTH_TOKEN together with ANTHROPIC_BASE_URL. A shell function keeps plain claude on the subscription:
# claude → your subscription login, unchanged
# claude-key → a pay-as-you-go key, only for this command
claude-key() {
ANTHROPIC_BASE_URL=https://api.kunavo.com \
ANTHROPIC_AUTH_TOKEN=sk-kn-... \
ANTHROPIC_MODEL=claude-sonnet-5 \
ANTHROPIC_DEFAULT_OPUS_MODEL=claude-opus-5 \
ANTHROPIC_DEFAULT_HAIKU_MODEL=claude-haiku-4-5 \
claude "$@"
}If you’re calling through Kunavo
Kunavo is one of the API-key routes the message points to: Claude Code reads ANTHROPIC_BASE_URL and ANTHROPIC_AUTH_TOKEN natively, so the switch is environment variables, not a reinstall, and the key bills per token from a prepaid balance with no monthly fee. It does not repair the subscription — only Anthropic can — and on a company machine whose policy blocks environment credentials it will not start either. Use it where the account and the machine are yours. Which variable holds a gateway key, and why the other one can fail silently, is in ANTHROPIC_AUTH_TOKEN vs ANTHROPIC_API_KEY.
FAQ
Why does it say my organization disabled access when I'm on a personal Pro plan?
Every claude.ai account belongs to an organization, even a personal one: /status shows it as your email followed by “'s Organization”. Reports on the Claude Code GitHub since April 2026 describe that personal organization being refused while billing shows the plan as active. There is no admin to ask; /logout and /login is worth one try, and if the message returns the fix is Anthropic's, through support.
Will using an API key cancel or change my subscription?
No. While ANTHROPIC_API_KEY or ANTHROPIC_AUTH_TOKEN is set, Claude Code authenticates with the key instead of the login and bills the key per token. Remove the variable and the subscription login is used again. Scoping the key to a shell function, rather than exporting it in your profile, means you never have to remember to remove it.
My company disabled it. Can I just use my own API key?
Only where the organization allows it. Anthropic's error reference tells you to use a method your organization has enabled. If managed settings restrict login to the organization with forceLoginOrgUUID or forceLoginMethod, Claude Code blocks ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN and apiKeyHelper at startup. On a work machine, ask the admin.
Does an API key fix the Claude desktop app too?
No. Claude Desktop signs in with OAuth and does not read ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN or apiKeyHelper. The environment variables fix the CLI and the surfaces that wrap it, such as the VS Code extension and the Agent SDK.
Is there an official fix yet?
Not one announced as of September 30, 2026. The GitHub issue that duplicates are closed into, #72027, was closed by the stale bot on September 13 without a fix, and new reports with the same wording were filed in September. Anthropic's error reference describes only the admin-policy case.
Related guides
- ANTHROPIC_AUTH_TOKEN vs ANTHROPIC_API_KEY — which one Claude Code actually reads
- Claude Code API key — where to get one, where to put it, and why the wrong variable fails silently
- Is Claude Code free? What's free, what isn't, and what a month costs
- Claude API “credit balance is too low” / 402 insufficient_quota — the fix
More error semantics live in the error reference; getting a key takes a minute via sign up and the authentication docs.