RBAC Groups
api/admin/rbac_groups
History
api/admin/rbac_groups Changed · +8 / -72 lines
### Headers ### Headers ### Headers ### Headers ### Headers #### Headers #### Headers #### Headers
List RBAC Groups in the Claude Enterprise tenant. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. ### Query parameters
Optionally set to the `next_page` token from the previous response. -### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - ### Returns - `data: array of RbacGroup`
Retrieve an RBAC Group by ID. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. ### Path parameters
ID of the RBAC Group. -### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - ### Returns - `RbacGroup object`
Create an RBAC Group in the Claude Enterprise tenant. Groups created via the API have source type `"direct"`. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. -### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - ### Body parameters - `name: string`
Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. ### Path parameters
ID of the RBAC Group. -### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - ### Body parameters - `name: optional string or null`
Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. ### Path parameters
ID of the RBAC Group. -### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - ### Returns - `RbacGroupDeleted object`
List members of an RBAC Group. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. #### Path parameters
Optionally set to the `next_page` token from the previous response. -#### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - #### Returns - `data: array of RbacGroupMember`
Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. #### Path parameters
ID of the RBAC Group. -#### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. - #### Body parameters - `user_id: string`
Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. -The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. +The RBAC Groups API is available to Claude Enterprise organizations only. #### Path parameters
- `user_id: string` ID of the User. - -#### Headers - -- `"anthropic-beta": optional array of string` - - Optional header to specify the beta version(s) you want to use. - - To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. #### Returns
api/admin/rbac_groups Changed · +114 / -135 lines
### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers #### Response (200) ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ## RBAC Groups › Members ### List RBAC Group Members #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Add RBAC Group Member #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Remove RBAC Group Member #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types # Members ## List RBAC Group Members ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Add RBAC Group Member ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Remove RBAC Group Member ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Rbac Group Member ### Rbac Group Member Deleted
---- -title: RBAC Groups -url: https://platform.claude.com/docs/en/api/admin/rbac_groups ---- - # RBAC Groups ## List RBAC Groups -**get** `/v1/organizations/rbac_groups` +**GET** `/v1/organizations/rbac_groups` List RBAC Groups in the Claude Enterprise tenant. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Query Parameters +### Query parameters - `limit: optional number`
Defaults to `20`. Ranges from `1` to `1000`. + default: 20, maximum: 1000, minimum: 1 + - `page: optional string` Optionally set to the `next_page` token from the previous response. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
RFC 3339 timestamp of when the RBAC Group was created. + format: date-time + - `name: string` Name of the RBAC Group. Not uniqueness-enforced.
For RBAC Groups, this is always `"rbac_group"`. - - `"rbac_group"` + default: rbac_group - `updated_at: string` RFC 3339 timestamp of when the RBAC Group was last updated. + format: date-time + - `has_more: boolean` Indicates if there are more results in the requested page direction.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Get RBAC Group -**get** `/v1/organizations/rbac_groups/{group_id}` +**GET** `/v1/organizations/rbac_groups/{group_id}` Retrieve an RBAC Group by ID. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +### Path parameters - `group_id: string` ID of the RBAC Group. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `RbacGroup object { id, created_at, name, 4 more }` +- `RbacGroup object` - `id: string`
RFC 3339 timestamp of when the RBAC Group was created. + format: date-time + - `name: string` Name of the RBAC Group. Not uniqueness-enforced.
For RBAC Groups, this is always `"rbac_group"`. - - `"rbac_group"` + default: rbac_group - `updated_at: string` RFC 3339 timestamp of when the RBAC Group was last updated. + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Create RBAC Group -**post** `/v1/organizations/rbac_groups` +**POST** `/v1/organizations/rbac_groups` Create an RBAC Group in the Claude Enterprise tenant. Groups created via the API have source type `"direct"`. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `name: string` Name of the RBAC Group. Not uniqueness-enforced. + maxLength: 255, minLength: 1 + ### Returns -- `RbacGroup object { id, created_at, name, 4 more }` +- `RbacGroup object` - `id: string`
RFC 3339 timestamp of when the RBAC Group was created. + format: date-time + - `name: string` Name of the RBAC Group. Not uniqueness-enforced.
For RBAC Groups, this is always `"rbac_group"`. - - `"rbac_group"` + default: rbac_group - `updated_at: string` RFC 3339 timestamp of when the RBAC Group was last updated. + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Update RBAC Group -**post** `/v1/organizations/rbac_groups/{group_id}` +**POST** `/v1/organizations/rbac_groups/{group_id}` Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +### Path parameters - `group_id: string` ID of the RBAC Group. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `name: optional string or null` Name of the RBAC Group. Not uniqueness-enforced. + maxLength: 255, minLength: 1 + ### Returns -- `RbacGroup object { id, created_at, name, 4 more }` +- `RbacGroup object` - `id: string`
RFC 3339 timestamp of when the RBAC Group was created. + format: date-time + - `name: string` Name of the RBAC Group. Not uniqueness-enforced.
For RBAC Groups, this is always `"rbac_group"`. - - `"rbac_group"` + default: rbac_group - `updated_at: string` RFC 3339 timestamp of when the RBAC Group was last updated. + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Delete RBAC Group -**delete** `/v1/organizations/rbac_groups/{group_id}` +**DELETE** `/v1/organizations/rbac_groups/{group_id}` Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +### Path parameters - `group_id: string` ID of the RBAC Group. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `RbacGroupDeleted object { id, type }` +- `RbacGroupDeleted object` - `id: string`
For RBAC Groups, this is always `"rbac_group_deleted"`. - - `"rbac_group_deleted"` + default: rbac_group_deleted ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Rbac Group -- `RbacGroup object { id, created_at, name, 4 more }` +- `RbacGroup object` - `id: string`
RFC 3339 timestamp of when the RBAC Group was created. + format: date-time + - `name: string` Name of the RBAC Group. Not uniqueness-enforced.
For RBAC Groups, this is always `"rbac_group"`. - - `"rbac_group"` + default: rbac_group - `updated_at: string` RFC 3339 timestamp of when the RBAC Group was last updated. + format: date-time + ### Rbac Group Deleted -- `RbacGroupDeleted object { id, type }` +- `RbacGroupDeleted object` - `id: string`
For RBAC Groups, this is always `"rbac_group_deleted"`. - - `"rbac_group_deleted"` + default: rbac_group_deleted -# Members +## RBAC Groups › Members -## List RBAC Group Members +### List RBAC Group Members -**get** `/v1/organizations/rbac_groups/{group_id}/members` +**GET** `/v1/organizations/rbac_groups/{group_id}/members` List members of an RBAC Group. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +#### Path parameters - `group_id: string` ID of the RBAC Group. -### Query Parameters +#### Query parameters - `limit: optional number`
Defaults to `20`. Ranges from `1` to `1000`. + default: 20, maximum: 1000, minimum: 1 + - `page: optional string` Optionally set to the `next_page` token from the previous response. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Returns +#### Returns - `data: array of RbacGroupMember`
RFC 3339 timestamp of when the User was added to the RBAC Group. + format: date-time + - `email: string` Email of the User.
For RBAC Group Members, this is always `"rbac_group_member"`. - - `"rbac_group_member"` + default: rbac_group_member - `user_id: string`
Token to provide in as `page` in the subsequent request to retrieve the next page of data. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
} ``` -## Add RBAC Group Member +### Add RBAC Group Member -**post** `/v1/organizations/rbac_groups/{group_id}/members` +**POST** `/v1/organizations/rbac_groups/{group_id}/members` Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +#### Path parameters - `group_id: string` ID of the RBAC Group. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +#### Body parameters - `user_id: string` ID of the User. -### Returns +#### Returns -- `RbacGroupMember object { created_at, email, group_id, 2 more }` +- `RbacGroupMember object` - `created_at: string` RFC 3339 timestamp of when the User was added to the RBAC Group. + format: date-time + - `email: string` Email of the User.
For RBAC Group Members, this is always `"rbac_group_member"`. - - `"rbac_group_member"` + default: rbac_group_member - `user_id: string` ID of the User. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## Remove RBAC Group Member +### Remove RBAC Group Member -**delete** `/v1/organizations/rbac_groups/{group_id}/members/{user_id}` +**DELETE** `/v1/organizations/rbac_groups/{group_id}/members/{user_id}` Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +#### Path parameters - `group_id: string`
ID of the User. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Returns +#### Returns -- `RbacGroupMemberDeleted object { group_id, type, user_id }` +- `RbacGroupMemberDeleted object` - `group_id: string`
Deleted object type. For RBAC Group Members, this is always `"rbac_group_member_deleted"`. - - `"rbac_group_member_deleted"` + default: rbac_group_member_deleted - `user_id: string` ID of the User. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q" } ``` - -## Domain Types - -### Rbac Group Member - -- `RbacGroupMember object { created_at, email, group_id, 2 more }` - - - `created_at: string` - - RFC 3339 timestamp of when the User was added to the RBAC Group. - - - `email: string` - - Email of the User. - - - `group_id: string` - - ID of the RBAC Group. - - - `type: "rbac_group_member"` - - Object type. - - For RBAC Group Members, this is always `"rbac_group_member"`. - - - `"rbac_group_member"` - - - `user_id: string` - - ID of the User. - -### Rbac Group Member Deleted - -- `RbacGroupMemberDeleted object { group_id, type, user_id }` - - - `group_id: string` - - ID of the RBAC Group. - - - `type: "rbac_group_member_deleted"` - - Deleted object type. For RBAC Group Members, this is always `"rbac_group_member_deleted"`. - - - `"rbac_group_member_deleted"` - - - `user_id: string` - - ID of the User.
api/admin/rbac_groups First recorded · 787 lines, first recorded
# RBAC Groups ## List RBAC Groups ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Get RBAC Group ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Create RBAC Group ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Update RBAC Group ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Delete RBAC Group ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### Rbac Group ### Rbac Group Deleted # Members ## List RBAC Group Members ### Path Parameters ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Add RBAC Group Member ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Remove RBAC Group Member ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### Rbac Group Member ### Rbac Group Member Deleted
The first capture of this source. The page was already there, and this is what it said.
---
title: RBAC Groups
url: https://platform.claude.com/docs/en/api/admin/rbac_groups
---
# RBAC Groups
## List RBAC Groups
**get** `/v1/organizations/rbac_groups`
List RBAC Groups in the Claude Enterprise tenant.
The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header.
### Query Parameters
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
- `page: optional string`
Optionally set to the `next_page` token from the previous response.
### Header Parameters
- `"anthropic-beta": optional array of string`
Optional header to specify the beta version(s) you want to use.
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
### Returns
- `data: array of RbacGroup`
- `id: string`
ID of the RBAC Group.
- `created_at: string`
RFC 3339 timestamp of when the RBAC Group was created.
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
- `roles: array of string or null`
RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. `null` means role data was temporarily unavailable — retry to distinguish from an empty list.
- `source_type: "direct" or "scim"`
How the RBAC Group was created: `"direct"` for groups created directly (for example, in the organization's admin settings), `"scim"` for groups provisioned by the identity provider.
- `"direct"`
- `"scim"`
- `type: "rbac_group"`
Object type.
For RBAC Groups, this is always `"rbac_group"`.
- `"rbac_group"`
- `updated_at: string`
RFC 3339 timestamp of when the RBAC Group was last updated.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `next_page: string or null`
Token to provide in as `page` in the subsequent request to retrieve the next page of data.
### Example
```http
curl https://api.anthropic.com/v1/organizations/rbac_groups \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"data": [
{
"id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
"created_at": "2024-10-30T23:58:27.427722Z",
"name": "Engineering",
"roles": [
"rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
],
"source_type": "direct",
"type": "rbac_group",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
],
"has_more": false,
"next_page": "eyJjdXJzb3IiOiAicmJhY19ncm91cF8wMSJ9"
}
```
## Get RBAC Group
**get** `/v1/organizations/rbac_groups/{group_id}`
Retrieve an RBAC Group by ID.
The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header.
### Path Parameters
- `group_id: string`
ID of the RBAC Group.
### Header Parameters
- `"anthropic-beta": optional array of string`
Optional header to specify the beta version(s) you want to use.
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
### Returns
- `RbacGroup object { id, created_at, name, 4 more }`
- `id: string`
ID of the RBAC Group.
- `created_at: string`
RFC 3339 timestamp of when the RBAC Group was created.
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
- `roles: array of string or null`
RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. `null` means role data was temporarily unavailable — retry to distinguish from an empty list.
- `source_type: "direct" or "scim"`
How the RBAC Group was created: `"direct"` for groups created directly (for example, in the organization's admin settings), `"scim"` for groups provisioned by the identity provider.
- `"direct"`
- `"scim"`
- `type: "rbac_group"`
Object type.
For RBAC Groups, this is always `"rbac_group"`.
- `"rbac_group"`
- `updated_at: string`
RFC 3339 timestamp of when the RBAC Group was last updated.
### Example
```http
curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
"created_at": "2024-10-30T23:58:27.427722Z",
"name": "Engineering",
"roles": [
"rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
],
"source_type": "direct",
"type": "rbac_group",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
## Create RBAC Group
**post** `/v1/organizations/rbac_groups`
Create an RBAC Group in the Claude Enterprise tenant. Groups created via the API have source type `"direct"`.
The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header.
### Header Parameters
- `"anthropic-beta": optional array of string`
Optional header to specify the beta version(s) you want to use.
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
### Body Parameters
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
### Returns
- `RbacGroup object { id, created_at, name, 4 more }`
- `id: string`
ID of the RBAC Group.
- `created_at: string`
RFC 3339 timestamp of when the RBAC Group was created.
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
- `roles: array of string or null`
RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. `null` means role data was temporarily unavailable — retry to distinguish from an empty list.
- `source_type: "direct" or "scim"`
How the RBAC Group was created: `"direct"` for groups created directly (for example, in the organization's admin settings), `"scim"` for groups provisioned by the identity provider.
- `"direct"`
- `"scim"`
- `type: "rbac_group"`
Object type.
For RBAC Groups, this is always `"rbac_group"`.
- `"rbac_group"`
- `updated_at: string`
RFC 3339 timestamp of when the RBAC Group was last updated.
### Example
```http
curl https://api.anthropic.com/v1/organizations/rbac_groups \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \
-d '{
"name": "Engineering"
}'
```
#### Response
```json
{
"id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
"created_at": "2024-10-30T23:58:27.427722Z",
"name": "Engineering",
"roles": [
"rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
],
"source_type": "direct",
"type": "rbac_group",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
## Update RBAC Group
**post** `/v1/organizations/rbac_groups/{group_id}`
Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API.
The RBAC Groups API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header.
### Path Parameters
- `group_id: string`
Cut at 300 lines.