One read of Claude Developer Platform
239 pages moved out of 688 read.
api/beta/agents Changed · +90 / -6 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `model: BetaManagedAgentsModel or BetaManagedAgentsModelConfigParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaManagedAgentsAgent`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsAgent object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `description: optional string or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsAgent object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` #### Returns
api/beta/agents/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/agents/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/agents/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
manage-claude/compliance-faq Changed · +2 / -2 lines
</Accordion> <Accordion title="Do Cowork and Claude Code sessions appear in the Compliance API?"> - Yes. Cowork sessions in Claude Desktop that run on users' machines, and Claude Code sessions in the terminal, in Claude Desktop, or in an IDE extension, are captured while users are signed in with their Claude Enterprise account and are available through the [local session endpoints](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-local-sessions). Cowork sessions started on claude.ai web or mobile, which run in the cloud in Anthropic-managed environments, are available through the [remote session endpoints](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-remote-sessions). Each family has a list endpoint that returns session metadata and a messages endpoint that returns the session transcript (user prompts, assistant responses, and tool calls and results). The local family adds a third endpoint that retrieves one session's metadata. All of these endpoints use your existing Compliance Access Key with `read:compliance_user_data`; no new key or scope is needed. + Yes. Cowork sessions in Claude Desktop that run on users' machines, Claude Code sessions (in the terminal, in Claude Desktop, or in an IDE extension), sessions in the Claude Science desktop app, and Claude for Microsoft 365 sessions in Excel, PowerPoint, Word, and Outlook are captured while users are signed in with their Claude Enterprise account and are available through the [local session endpoints](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-local-sessions). Cowork sessions started on claude.ai web or mobile, which run in the cloud in Anthropic-managed environments, are available through the [remote session endpoints](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-remote-sessions). Each family has a list endpoint that returns session metadata and a messages endpoint that returns the session transcript (user prompts, assistant responses, and tool calls and results). The local family adds a third endpoint that retrieves one session's metadata. All of these endpoints use your existing Compliance Access Key with `read:compliance_user_data`; no new key or scope is needed. Local sessions are captured as their requests reach the Claude API, so nothing is installed on the device, and on-device activity that never reaches the API is not captured. Claude Code sessions authenticated with a Claude Console API key, Claude Code sessions run through a third-party cloud platform (Amazon Bedrock, Google Cloud, or Microsoft Foundry), and Claude Code on the web are not captured. Claude Code on the web also runs in the cloud in Anthropic-managed environments, but it is not a remote session; the remote session endpoints return Cowork sessions only. Organizations with [HIPAA readiness](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention#hipaa-readiness) enabled get no local session data, and sessions for which [zero data retention (ZDR)](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention#zero-data-retention-zdr-scope) is in effect are excluded. - The local and remote session endpoints are in beta. + The local and remote session endpoints are stable for Cowork and Claude Code sessions; coverage of Claude Science and Claude for Microsoft 365 sessions is in beta. </Accordion> <Accordion title="What do Cowork and Claude Code session transcripts include?">
api/beta Changed · +12045 / -149 lines
## Beta › Organization ### Get Current Organization ## Beta › Organization › API Keys ### List API Keys ### Get API Key ### Update API Key ## Beta › Organization › External Keys ### Create External Key ### List External Keys ### Get External Key ### Update External Key ### Delete External Key ### Validate External Key ## Beta › Organization › Federation › Issuers ### Create Federation Issuer ### List Federation Issuers ### Get Federation Issuer ### Update Federation Issuer ### Archive Federation Issuer ## Beta › Organization › Federation › Rules ### Create Federation Rule ### List Federation Rules ### Get Federation Rule ### Update Federation Rule ### Archive Federation Rule ## Beta › Organization › Federation › Rules › Workspaces ### Add Federation Rule Workspace ### List Federation Rule Workspaces ### Remove Federation Rule Workspace ## Beta › Organization › Invites ### Create Invite ### List Invites ### Get Invite ### Delete Invite ## Beta › Organization › Service Accounts ### Create Service Account ### List Service Accounts ### Get Service Account ### Update Service Account ### Archive Service Account ## Beta › Organization › Service Accounts › Workspaces ### Add Workspace To Service Account ### List Workspaces For Service Account ### Remove Workspace From Service Account ## Beta › Organization › Users ### List Users ### Get User ### Update User ### Remove User ## Beta › Organization › Workspaces ### List Workspaces ### Create Workspace ### Get Workspace ### Update Workspace ### Archive Workspace ## Beta › Organization › Workspaces › Rate Limits ### List Workspace Rate Limits ## Beta › Organization › Workspaces › Members ### List Workspace Members ### Create Workspace Member ### Get Workspace Member ### Update Workspace Member ### Delete Workspace Member ## Beta › Organization › Workspaces › Service Accounts ### List Service Account Workspace Members ### Create Service Account Workspace Member ### Get Service Account Workspace Member ### Update Service Account Workspace Member ### Delete Service Account Workspace Member ## Beta › Organization › Rate Limits ### List Organization Rate Limits
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
### Anthropic Beta -- `AnthropicBeta = string or "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` +- `AnthropicBeta = string or "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Beta API Error - `BetaAPIError object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: array of BetaModelInfo`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaModelInfo object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute this request to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `Default = "default"` - `inference_geo: optional string or null`
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. + - `BetaMessageIterationUsage object` Token usage for a sampling iteration.
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. + - `output_tokens: number` The cumulative number of output tokens which were used.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute this request to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `tool_choice: optional BetaToolChoice` How the model should use the provided tools. The model can use a specific tool, any available tool, decide by itself, or not use tools at all.
If you include `tools` in your API request, the model may return `tool_use` content blocks that represent the model's use of those tools. You can then run those tools using the tool input generated by the model and then optionally return results back to the model using `tool_result` content blocks. - There are two types of tools: **client tools** and **server tools**. The behavior described below applies to client tools. For [server tools](https://platform.claude.com/docs/en/agents-and-tools/tool-use/server-tools), see their individual documentation as each has its own behavior (e.g., the [web search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool)). - - Each tool definition includes: - - * `name`: Name of the tool. - * `description`: Optional, but strongly-recommended description of the tool. - * `input_schema`: [JSON schema](https://json-schema.org/draft/2020-12) for the tool `input` shape that the model will produce in `tool_use` output content blocks. - - For example, if you defined `tools` as: - - ```json - [ - { - "name": "get_stock_price", - "description": "Get the current stock price for a given ticker symbol.", - "input_schema": { - "type": "object", - "properties": { - "ticker": { - "type": "string", - "description": "The stock ticker symbol, e.g. AAPL for Apple Inc." - } - }, - "required": ["ticker"] - } - } - ] - ``` - - And then asked the model "What's the S&P 500 at today?", the model might produce `tool_use` content blocks in the response like this: - - ```json - [ - { - "type": "tool_use", - "id": "toolu_01D7FLrfh4GYq7yT1ULFeyMV", - "name": "get_stock_price", - "input": { "ticker": "^GSPC" } - } - ] - ``` - - You might then run your `get_stock_price` tool with `{"ticker": "^GSPC"}` as an input, and return the following back to the model in a subsequent `user` message: - - ```json - [ - { - "type": "tool_result", - "tool_use_id": "toolu_01D7FLrfh4GYq7yT1ULFeyMV", - "content": "259.75 USD" - } - ] - ``` - - Tools can be used for workflows that include running client-side tools and functions, or more generally whenever you want the model to produce a particular JSON structure of output. - - See our [guide](https://platform.claude.com/docs/en/agents-and-tools/tool-use/overview) for more details. - - - `BetaTool object` - - - `input_schema: object` - - [JSON schema](https://json-schema.org/draft/2020-12) for this tool's input. - - This defines the shape of the `input` that your tool accepts and that the model will produce. - - - `type: "object"` - - - `properties: optional map[unknown] or null` - - - `required: optional array of string or null` - - - `name: string` - - Name of the tool. - - This is how the tool will be called by the model and in `tool_use` blocks. - - maxLength: 128, minLength: 1, pattern: ^[a-zA-Z0-9_-]{1,128}$ - - - `allowed_callers: optional array of "direct" or "code_execution_20250825" or "code_execution_20260120" or "code_execution_20260521"` - - - `"direct"` - - - `"code_execution_20250825"` - - - `"code_execution_20260120"` - - - `"code_execution_20260521"` - - - `cache_control: optional BetaCacheControlEphemeral or null` - - Create a cache control breakpoint at this content block. - - - `defer_loading: optional boolean` - - If true, tool will not be included in initial system prompt. Only loaded when returned via tool_reference from tool search. - - - `description: optional string` - - Description of what this tool does. - - Tool descriptions should be as detailed as possible. The more information that the model has about what the tool is and how to use it, the better it will perform. You can use natural language descriptions to reinforce important aspects of the tool input JSON schema. - - - `eager_input_streaming: optional boolean or null` - - Enable eager inp + There are two types of tools: **client tools** and **server tools**. The behavior described below applies to client tools. For [server tools](https://platform.claude.com/docs/en/agents-and-tools/tool-use/server-tools), see their individual documentation as each has its own behavior (e.g., the [we
manage-claude/compliance-api Changed · +2 / -2 lines
description: Programmatic access to your organization's Claude activity, chats, files, projects, Claude Cowork and Claude Code sessions, and users for compliance, audit, and governance. --- -The Compliance API gives Claude Enterprise and Claude Console customers programmatic access to their organization's Activity Feed. For Claude Enterprise organizations, it also covers the directory of users, roles, and groups across every linked organization; the effective settings in force for each organization; the underlying chats, files, and projects in claude.ai organizations; and Cowork and Claude Code sessions. Security, legal, and compliance teams use it to audit activity, retrieve or delete content, and feed events into downstream tooling. +The Compliance API gives Claude Enterprise and Claude Console customers programmatic access to their organization's Activity Feed. For Claude Enterprise organizations, it also covers the directory of users, roles, and groups across every linked organization; the effective settings in force for each organization; the underlying chats, files, and projects in claude.ai organizations; and Cowork, Claude Code, Claude Science, and Claude for Microsoft 365 sessions. Security, legal, and compliance teams use it to audit activity, retrieve or delete content, and feed events into downstream tooling. <Note> Two key types unlock the Compliance API. A **Compliance Access Key** (created in claude.ai) reaches every endpoint, and an **Admin API key** (created in Claude Console) reaches the Activity Feed only. See [Which key do you need?](https://platform.claude.com/docs/en/manage-claude/compliance-api-access#which-key-do-you-need) for the full key-type comparison.
The Activity Feed (`GET /v1/compliance/activities`) is available to any key that carries the `read:compliance_activities` scope; see [Query the Activity Feed](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed) for filters, pagination, and the full `Activity` object. The remaining endpoints require a Compliance Access Key carrying the relevant scope. -A Claude Enterprise tenant has one parent organization (the top-level container that centralizes identity) with linked organizations of two kinds: claude.ai organizations, where users chat and store content, and Claude Console organizations, where users manage Claude API workloads. For a key that covers the parent organization, the directory endpoints (organizations, users, roles, and groups) return data from every linked organization of either kind. The content endpoints (chats, files, projects, project attachments, and sessions) serve Claude Enterprise data only. The chat, file, and project endpoints return claude.ai chats, files, and projects. The session endpoints return transcripts of Cowork and Claude Code sessions on users' machines (local sessions), captured while users are signed in with their Claude Enterprise account. They also return transcripts of Cowork sessions started on claude.ai web or mobile, which run in the cloud in Anthropic-managed environments (remote sessions). A standalone Claude Console organization (one with no parent organization) is not part of a Claude Enterprise tenant; it uses Admin API keys and can query the Activity Feed only. +A Claude Enterprise tenant has one parent organization (the top-level container that centralizes identity) with linked organizations of two kinds: claude.ai organizations, where users chat and store content, and Claude Console organizations, where users manage Claude API workloads. For a key that covers the parent organization, the directory endpoints (organizations, users, roles, and groups) return data from every linked organization of either kind. The content endpoints (chats, files, projects, project attachments, and sessions) serve Claude Enterprise data only. The chat, file, and project endpoints return claude.ai chats, files, and projects. The session endpoints return transcripts of Cowork, Claude Code, Claude Science, and Claude for Microsoft 365 sessions on users' machines (local sessions), captured while users are signed in with their Claude Enterprise account. They also return transcripts of Cowork sessions started on claude.ai web or mobile, which run in the cloud in Anthropic-managed environments (remote sessions). A standalone Claude Console organization (one with no parent organization) is not part of a Claude Enterprise tenant; it uses Admin API keys and can query the Activity Feed only. All `/v1/compliance/*` endpoints share a rate limit of 600 requests per minute per parent organization (for a standalone Claude Console organization, per organization). The local session endpoints count only against that shared limit, and the remote session endpoints carry a second request budget on top. See [429 Too Many Requests](https://platform.claude.com/docs/en/manage-claude/compliance-errors#429-too-many-requests) for the response headers and retry contract.
api/skills/versions/retrieve Changed · +1 / -1 lines
- `version: string` - Identifies the skill version: a version ID, or — where the endpoint accepts it — the literal `latest` for the skill's most recent version. + Identifies the skill version: a version ID, or the literal `latest` for the skill's most recent version. Requests carrying the `skills-2025-10-02` beta header address versions by their Unix epoch timestamp instead (e.g., "1759178010641129").
api/skills/versions/delete Changed · +1 / -1 lines
- `version: string` - Identifies the skill version: a version ID, or — where the endpoint accepts it — the literal `latest` for the skill's most recent version. + Identifies the skill version by its version ID. Requests carrying the `skills-2025-10-02` beta header address versions by their Unix epoch timestamp instead (e.g., "1759178010641129").
api/beta/agents/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/agents/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/agents/versions Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/agents/versions/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployment_runs Changed · +30 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaManagedAgentsDeploymentRun`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/deployment_runs/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployment_runs/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments Changed · +120 / -8 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `agent: string or BetaManagedAgentsAgentParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaManagedAgentsDeployment`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeployment object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `agent: optional string or BetaManagedAgentsAgentParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeployment object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeploymentRun object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeployment object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/deployments/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/deployments/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments/pause Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments/run Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments/unpause Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/deployments/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/dreams Changed · +75 / -5 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `inputs: array of BetaDreamInput`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaDream`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaDream object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaDream object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/dreams/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/dreams/cancel Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/dreams/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/dreams/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/dreams/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments Changed · +222 / -18 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `name: string`
- `allow_package_managers: optional boolean or null` - Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false`. + Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false` on creation. Must be `true` when `packages` are specified. - `allowed_hosts: optional array of string or null`
When versioning, use the version semantics relevant for the package manager, e.g. for `pip` use `package==1.0.0`. You are responsible for validating the package and version exist. Unversioned installs the latest. + Under `limited` networking, requires `networking.allow_package_managers` to be `true`. + - `apt: optional array of string or null` Ubuntu/Debian packages to install
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaEnvironment`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaEnvironment object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `config: optional BetaCloudConfigParams or BetaSelfHostedConfigParams or null`
- `allow_package_managers: optional boolean or null` - Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false`. + Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false` on creation. Must be `true` when `packages` are specified. - `allowed_hosts: optional array of string or null`
When versioning, use the version semantics relevant for the package manager, e.g. for `pip` use `package==1.0.0`. You are responsible for validating the package and version exist. Unversioned installs the latest. + Under `limited` networking, requires `networking.allow_package_managers` to be `true`. + - `apt: optional array of string or null` Ubuntu/Debian packages to install
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaEnvironmentDeleteResponse object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaEnvironment object`
- `allow_package_managers: optional boolean or null` - Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false`. + Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false` on creation. Must be `true` when `packages` are specified. - `allowed_hosts: optional array of string or null`
When versioning, use the version semantics relevant for the package manager, e.g. for `pip` use `package==1.0.0`. You are responsible for validating the package and version exist. Unversioned installs the latest. + Under `limited` networking, requires `networking.allow_package_managers` to be `true`. + - `apt: optional array of string or null` Ubuntu/Debian packages to install
- `allow_package_managers: optional boolean or null` - Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false`. + Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false` on creation. Must be `true` when `packages` are specified. - `allowed_hosts: optional array of string or null`
When versioning, use the version semantics relevant for the package manager, e.g. for `pip` use `package==1.0.0`. You are responsible for validating the package and version exist. Unversioned installs the latest. + Under `limited` networking, requires `networking.allow_package_managers` to be `true`. + - `apt: optional array of string or null` Ubuntu/Debian packages to install
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaSelfHostedWork object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"Anthropic-Worker-ID": optional string` Unique identifier for the specific worker polling, used to track aggregated environment-level work metrics in Console
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaSelfHostedWork object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaSelfHostedWorkHeartbeatResponse object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `force: optional boolean`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaSelfHostedWorkListResponse object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `metadata: map[string]`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` #### Returns
api/beta/environments/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/create Changed · +18 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Body parameters - `name: string`
- `allow_package_managers: optional boolean or null` - Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false`. + Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false` on creation. Must be `true` when `packages` are specified. - `allowed_hosts: optional array of string or null`
Specify packages (and optionally their versions) available in this environment. When versioning, use the version semantics relevant for the package manager, e.g. for `pip` use `package==1.0.0`. You are responsible for validating the package and version exist. Unversioned installs the latest. + + Under `limited` networking, requires `networking.allow_package_managers` to be `true`. - `apt: optional array of string or null`
api/beta/environments/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/update Changed · +18 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Body parameters - `config: optional BetaCloudConfigParams or BetaSelfHostedConfigParams or null`
- `allow_package_managers: optional boolean or null` - Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false`. + Permits outbound access to public package registries (PyPI, npm, etc.) beyond those listed in the `allowed_hosts` array. Defaults to `false` on creation. Must be `true` when `packages` are specified. - `allowed_hosts: optional array of string or null`
Specify packages (and optionally their versions) available in this environment. When versioning, use the version semantics relevant for the package manager, e.g. for `pip` use `package==1.0.0`. You are responsible for validating the package and version exist. Unversioned installs the latest. + + Under `limited` networking, requires `networking.allow_package_managers` to be `true`. - `apt: optional array of string or null`
api/beta/environments/work Changed · +120 / -8 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaSelfHostedWork object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"Anthropic-Worker-ID": optional string` Unique identifier for the specific worker polling, used to track aggregated environment-level work metrics in Console
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaSelfHostedWork object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaSelfHostedWorkHeartbeatResponse object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `force: optional boolean`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaSelfHostedWorkListResponse object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `metadata: map[string]`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/environments/work/ack Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/work/heartbeat Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/work/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/work/poll Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` - `"Anthropic-Worker-ID": optional string`
api/beta/environments/work/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/work/stats Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/environments/work/stop Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/environments/work/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/files Changed · +75 / -5 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters (form-data) - `file: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaFileMetadata`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Example ```bash
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaFileMetadata object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/files/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/files/download Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Example
api/beta/files/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/files/retrieve_metadata Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/files/upload Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters (form-data)
api/beta/memory_stores Changed · +220 / -24 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `name: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsMemoryStore`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsMemoryStore object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `description: optional string or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeletedMemoryStore object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsMemoryStore object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `content: string or null`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: optional array of BetaManagedAgentsMemoryListItem`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsMemory object`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `content: optional string or null`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsDeletedMemory object` - Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). The memory's version history persists and remains listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) until the store itself is deleted. + Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). Deleting a memory does not erase its version history: its versions remain listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) while they are retained (each version is kept for at least the version retention period after it was written, unless the store itself is deleted). - `id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: optional array of BetaManagedAgentsMemoryVersion`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
api/beta/memory_stores/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/memory_stores/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/memory_stores/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/memory_stores/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/memory_stores/memories Changed · +83 / -13 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `content: string or null`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsMemoryListItem`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsMemory object`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `content: optional string or null`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeletedMemory object` - Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). The memory's version history persists and remains listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) until the store itself is deleted. + Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). Deleting a memory does not erase its version history: its versions remain listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) while they are retained (each version is kept for at least the version retention period after it was written, unless the store itself is deleted). - `id: string`
- `BetaManagedAgentsDeletedMemory object` - Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). The memory's version history persists and remains listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) until the store itself is deleted. + Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). Deleting a memory does not erase its version history: its versions remain listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) while they are retained (each version is kept for at least the version retention period after it was written, unless the store itself is deleted). - `id: string`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
api/beta/memory_stores/memories/create Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Body parameters - `content: string or null`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
api/beta/memory_stores/memories/delete Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaManagedAgentsDeletedMemory object` - Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). The memory's version history persists and remains listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) until the store itself is deleted. + Tombstone returned by [Delete a memory](/docs/en/api/beta/memory_stores/memories/delete). Deleting a memory does not erase its version history: its versions remain listable via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) while they are retained (each version is kept for at least the version retention period after it was written, unless the store itself is deleted). - `id: string`
api/beta/memory_stores/memories/list Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `data: optional array of BetaManagedAgentsMemoryListItem`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
api/beta/memory_stores/memories/retrieve Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaManagedAgentsMemory object`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
api/beta/memory_stores/memories/update Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Body parameters - `content: optional string or null`
- `memory_version_id: string` - ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the full history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). + ID of the `memory_version` representing this memory's current content (a `memver_...` value). This is the authoritative head pointer; `memory_version` objects do not carry an `is_latest` flag, so compare against this field instead. Enumerate the history via [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list). - `path: string`
api/beta/memory_stores/memory_versions Changed · +52 / -10 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsMemoryVersion`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
- `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
api/beta/memory_stores/memory_versions/list Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `data: optional array of BetaManagedAgentsMemoryVersion`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
api/beta/memory_stores/memory_versions/redact Changed · +17 / -3 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
api/beta/memory_stores/memory_versions/retrieve Changed · +17 / -3 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaManagedAgentsMemoryVersion object` - A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and persist after the memory is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. + A `memory_version` object: one immutable, attributed row in a memory's append-only history. Every non-no-op mutation to a memory produces a new version. Versions belong to the store (not the individual memory) and are not deleted with the memory; each version is retained for at least the version retention period after it was written, unless the store itself is deleted. Retrieving a redacted version returns 200 with `content`, `path`, `content_size_bytes`, and `content_sha256` set to `null`; branch on `redacted_at`, not HTTP status. - `id: string`
- `memory_id: string` - ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the full lineage including the `deleted` row. + ID of the memory this version snapshots (a `mem_...` value). Remains valid after the memory is deleted; pass it as `memory_id` to [List memory versions](/docs/en/api/beta/memory_stores/memory_versions/list) to retrieve the memory's retained versions, including the `deleted` row while the lineage is retained. - `memory_store_id: string`
api/beta/memory_stores/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/memory_stores/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/messages Changed · +206 / -44 lines
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute this request to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `Default = "default"` - `inference_geo: optional string or null`
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. + - `BetaMessageIterationUsage object` Token usage for a sampling iteration.
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. + - `output_tokens: number` The cumulative number of output tokens which were used.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute this request to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `tool_choice: optional BetaToolChoice` How the model should use the provided tools. The model can use a specific tool, any available tool, decide by itself, or not use tools at all.
- `enabled: optional boolean or null` - Whether this member is offered to the model. Default is per member, per the toolset's documentation. A member whose enabled resolves false is withheld from the served schema. - - - `screenshot: optional BetaBrowserScreenshotConfig or null` - - `screenshot`'s config overrides. - - - `defer_loading: optional boolean or null` - - Defer loading for this member. Must resolve to the same value on every enabled member of the toolset. - - - `enabled: optional boolean or null` - - Whether this member is offered to the model. Default is per member, per the toolset's documentation. A member whose enabled resolves false is withheld from the served schema. - - - `scroll: optional BetaBrowserScrollConfig or null` - - `scroll`'s config overrides. - - - `defer_loading: optional boolean or null` - - Defer loading for this member. Must resolve to the same value on every enabled member of the toolset. - - - `enabled: optional boolean or null` - - Whether this member is offered to the model. Default is per member, per the toolset's documentation. A member whose enabled resolves false is withheld from the served schema. - - - `scroll_to: optional BetaBrowserScrollToConfig or null` - - `scroll_to`'s config overrides. - - - `defer_loading: optional boolean or null` - - Defer loading for this member. Must resolve to the same value on every enabled member of the toolset. - - - `enabled: optional boolean or null` - - Whether this member is offered to the model. Default is per member, per the toolset's documentation. A member whose enabled resolves false is withheld from the served schema. - - - `switch_tab: optional BetaBrowserSwitchTabConfig or null` - - `switch_tab`'s config overrides. - - - `defer_loading: optional boolean or null` - - Defer loading for this member. Must resolve to the same value on every enabled member of the toolset. - - - `enabled: optional boolean or null` - - Whether this member is offered to the model. Default is per member, per the toolset's documentation. A member whose enabled resolves false is withheld from the served schema. - - - `triple_click: optional BetaBrowserTripleClickConfig or null` - - `triple_click`'s config overrides. - - - `defer_loading: optional boolean or null` - - Defer loading for this member. Must resolve to the same value on every enabled member of the toolset. - - - `enabled: optional boolean or null` - - Whether this member is offered to the model. Default is per member, per the toolset's documentation. A member whose enab + Whether this member is offered to the model. Default is per member, per the
api/beta/messages/batches Changed · +112 / -16 lines
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute the requests in this batch to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header. Applies to every request in the batch; an individual request whose `user_profile_id` body field conflicts with this header is errored.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `Default = "default"` - `inference_geo: optional string or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaMessageBatch object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaMessageBatch`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaMessageBatch object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaDeletedMessageBatch object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaMessageBatchIndividualResponse object`
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. + - `BetaMessageIterationUsage object` Token usage for a sampling iteration.
The request asks the model to reproduce its internal reasoning in the response text. To get reasoning in a structured form instead, use [adaptive thinking](https://platform.claude.com/docs/en/build-with-claude/adaptive-thinking). - - `"general_harms"` - - The request could be related to an area that was determined as harmful. Benign work might sometimes trigger this category. - - - `explanation: string or null` - - Human-readable explanation of the refusal. - - This text is not guaranteed to be stable. `null` when no explanation is available for the category. - - - `fallback_credit_token: string or null` - - Opaque code that refunds the cache-miss cost when retrying this refused - request on the fallback model. Pass it as `fallback_credit_token` on the - retry request. Expires 5 minutes after the refusal. - - The retry is sent either with the same request body (`system`, `messages`, - `tools`, and other render-shaping fields), or with the same body plus one - appended `assistant` message whose content is the partial text (with any - trailing whitespace stripped from the final text block) and paired - server-tool blocks from this refusal — which also authorizes that - appended turn as an assistant-prefill continuation on models that otherwise - disallow prefill. A token minted mid-server-tool-loop whose partial content - was continuable may only be redeemed the second way — if a same-body retry - is rejected with a 400 saying the token must be redeemed by continuing the - partial response, retry the second way instead. Either way: same workspace, - same platform; a mismatch is a 400. Resending a token for an already-warm - prefix is permitted but yields no additional credit. - - `null` when the refused model isn't eligible for a fallback credit. - - - `fallback_has_prefill_claim: boolean or null` - - Whether the accompanying `fallback_credit_token` may be redeemed with the - appended-assistant retry form. Only set when `fallback_credit_token` is - present. - - `true`: retry by resending the same request body plus one appended - `assistant` message whose content is this response's `content` with any - trailing whitespace stripped from the final text block and unpaired - `tool_use` blocks omitted (the same appended-turn shape described on - `fallback_credit_token`), with the token attached. `false`: retry by - resending the original request body unchanged, with the token attached — - the appended-assistant form is not available for this refusal (no - continuable partial content, or the reques + -
api/beta/messages/batches/cancel Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/messages/batches/create Changed · +21 / -3 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute the requests in this batch to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header. Applies to every request in the batch; an individual request whose `user_profile_id` body field conflicts with this header is errored.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"summarized"` - `"omitted"` + + - `"updates"` - `Default = "default"`
api/beta/messages/batches/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/messages/batches/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/messages/batches/results Changed · +19 / -3 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaMessageBatchIndividualResponse object`
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. - `BetaMessageIterationUsage object`
api/beta/messages/batches/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/messages/count_tokens Changed · +21 / -3 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute this request to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"summarized"` - `"omitted"` + + - `"updates"` - `tool_choice: optional BetaToolChoice`
api/beta/messages/create Changed · +29 / -7 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + - `"anthropic-user-profile-id": optional string` The user profile ID to attribute this request to. Use when acting on behalf of a party other than your organization. Requires the `user-profiles` beta header.
- `type: "enabled"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `BetaThinkingConfigDisabled object` - `type: "disabled"`
- `type: "adaptive"` - - `display: optional "summarized" or "omitted" or null` + - `display: optional "summarized" or "omitted" or "updates" or null` Controls how thinking content appears in the response. When set to `summarized`, thinking is returned normally. When set to `omitted`, thinking content is redacted but a signature is returned for multi-turn continuity. Defaults to `summarized`.
- `"omitted"` + - `"updates"` + - `Default = "default"` - `inference_geo: optional string or null`
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. + - `BetaMessageIterationUsage object` Token usage for a sampling iteration.
Per-iteration token usage breakdown. - Each entry represents one sampling iteration, with its own input/output token counts and cache statistics. This allows you to: + Each entry represents one sampling iteration, with its own input/output token counts and cache statistics, discriminated by `type`. For `message` entries (model sampling iterations, such as the turns of a server-side tool use loop), this allows you to: - Determine which iterations exceeded long context thresholds (>=200k tokens) - - Calculate the true context window size from the last iteration + - Calculate the context window size from the last `message` entry - Understand token accumulation across server-side tool use loops + + A `compaction` entry reports the token usage of the compaction operation itself — the server-side request that summarizes the context being closed — NOT the size of the context that was compacted away, and its token counts can be much smaller than that closed context (for example, a compaction that closes a ~200k-token context can report only a few thousand tokens). Do not derive the context window size from a `compaction` entry, even when it is the last entry. A `compaction` entry's tokens are not included in the top-level `usage` fields. When an input-token trigger is in effect (the default — 150,000 tokens unless configured otherwise), each `compaction` entry closes a context that had reached at least that threshold, though the context can exceed it by the final iteration's output and tool results. - `output_tokens: number`
api/beta/models Changed · +30 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaModelInfo`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/models/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/models/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/organization New page · 10225 lines, new page
# Organization ## Get Current Organization ### Returns ### Example #### Response (200) ## Domain types ### Beta Organization ### Beta Organization Role ## Organization › API Keys ### List API Keys #### Query parameters #### Returns #### Example ##### Response (200) ### Get API Key #### Path parameters #### Returns #### Example ##### Response (200) ### Update API Key #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ## Organization › External Keys ### Create External Key #### Body parameters #### Returns #### Example ##### Response (200) ### List External Keys #### Query parameters #### Returns #### Example ##### Response (200) ### Get External Key #### Path parameters #### Returns #### Example ##### Response (200) ### Update External Key #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Delete External Key #### Path parameters #### Returns #### Example ##### Response (200) ### Validate External Key #### Path parameters #### Returns #### Example ##### Response (200) ## Organization › Federation › Issuers ### Create Federation Issuer #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Issuers #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Federation Issuer #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Federation Issuer #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Federation Issuer #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organization › Federation › Rules ### Create Federation Rule #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rules #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Federation Rule #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Federation Rule #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Federation Rule #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organization › Federation › Rules › Workspaces ### Add Federation Rule Workspace #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rule Workspaces #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Remove Federation Rule Workspace #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organization › Invites ### Create Invite #### Body parameters #### Returns #### Example ##### Response (200) ### List Invites #### Query parameters #### Returns #### Example ##### Response (200) ### Get Invite #### Path parameters #### Returns #### Example ##### Response (200) ### Delete Invite #### Path parameters #### Returns #### Example ##### Response (200) ## Organization › Service Accounts ### Create Service Account #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Service Accounts #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Service Account #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Service Account #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Service Account #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organization › Service Accounts › Workspaces ### Add Workspace To Service Account #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Workspaces For Service Account #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Remove Workspace From Service Account #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organization › Users ### List Users #### Query parameters #### Returns #### Example ##### Response (200) ### Get User #### Path parameters #### Returns #### Example ##### Response (200) ### Update User #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Remove User #### Path parameters #### Returns #### Example ##### Response (200) ## Organization › Workspaces ### List Workspaces #### Query parameters #### Returns #### Example ##### Response (200) ### Create Workspace #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Workspace #### Path parameters #### Returns #### Example ##### Response (200) ### Update Workspace #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Workspace #### Path parameters #### Returns #### Example ##### Response (200) ## Organization › Workspaces › Rate Limits ### List Workspace Rate Limits #### Path parameters #### Query parameters #### Returns #### Example ##### Response (200) ## Organization › Workspaces › Members ### List Workspace Members #### Path parameters #### Query parameters #### Returns #### Example ##### Response (200) ### Create Workspace Member #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Get Workspace Member #### Path parameters #### Returns #### Example ##### Response (200) ### Update Workspace Member #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Delete Workspace Member #### Path parameters #### Returns #### Example ##### Response (200) ## Organization › Workspaces › Service Accounts ### List Service Account Workspace Members #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Create Service Account Workspace Member #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Service Account Workspace Member #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Service Account Workspace Member #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Delete Service Account Workspace Member #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organization › Rate Limits ### List Organization Rate Limits #### Query parameters #### Returns #### Example ##### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Organization
## Get Current Organization
**GET** `/v1/organizations/me`
Retrieve information about the organization associated with the authenticated API key.
### Returns
- `BetaOrganization object`
- `id: string`
ID of the Organization.
format: uuid
- `name: string`
Name of the Organization.
- `type: "organization"`
Object type.
For Organizations, this is always `"organization"`.
default: organization
### Example
```bash
curl https://api.anthropic.com/v1/organizations/me \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"id": "12345678-1234-5678-1234-567812345678",
"name": "Organization Name",
"type": "organization"
}
```
## Domain types
### Beta Organization
- `BetaOrganization object`
- `id: string`
ID of the Organization.
format: uuid
- `name: string`
Name of the Organization.
- `type: "organization"`
Object type.
For Organizations, this is always `"organization"`.
default: organization
### Beta Organization Role
- `BetaOrganizationRole = "admin" or "billing" or "claude_code_user" or 6 more`
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
## Organization › API Keys
### List API Keys
**GET** `/v1/organizations/api_keys`
List API Keys
#### Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `created_by_user_id: optional string`
Filter by the ID of the User who created the object.
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `status: optional "active" or "archived" or "expired" or "inactive"`
Filter by API key status.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `workspace_id: optional string`
Filter by Workspace ID.
#### Returns
- `data: array of BetaAPIKey`
- `id: string`
ID of the API key.
- `created_at: string`
RFC 3339 datetime string indicating when the API Key was created.
format: date-time
- `created_by: BetaAPIKeyCreatedBy or null`
The ID and type of the actor that created the API key, or `null` when the
creator is not recorded (legacy, workload-identity-federated, or
system-created keys).
- `id: string`
ID of the actor that created the object.
- `type: "service_account" or "user"`
Type of the actor that created the object.
- `"service_account"`
- `"user"`
- `expires_at: string or null`
RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
format: date-time
- `name: string`
Name of the API key.
- `partial_key_hint: string or null`
Partially redacted hint for the API key.
- `principal: BetaAPIKeyUserActor or BetaAPIKeyServiceAccountActor or null`
The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal.
- `BetaAPIKeyUserActor object`
- `type: "user_actor"`
Principal type. Always `"user_actor"` for a User.
default: user_actor
- `user_id: string`
ID of the User the API key acts as.
- `BetaAPIKeyServiceAccountActor object`
- `service_account_id: string`
ID of the Service Account the API key acts as.
- `type: "service_account_actor"`
Principal type. Always `"service_account_actor"` for a Service Account.
default: service_account_actor
- `scope: BetaAPIKeyOrganizationScope or BetaAPIKeyWorkspaceScope`
Where the API key belongs: its Workspace (`{"type": "workspace", "workspace_id": "wrkspc_..."}`, with the Workspace's real ID even when it is the organization's default Workspace), or the organization (`{"type": "organization"}`) for a principal-bound API key that has no Workspace.
- `BetaAPIKeyOrganizationScope object`
- `type: "organization"`
Scope type. Always `"organization"`: the API key has no Workspace. Only a principal-bound API key can have this scope.
default: organization
- `BetaAPIKeyWorkspaceScope object`
- `type: "workspace"`
Scope type. Always `"workspace"`: the API key belongs to one Workspace.
default: workspace
- `workspace_id: string`
ID of the Workspace the API key belongs to. Unlike the deprecated top-level `workspace_id`, this is the Workspace's real ID even for the organization's default Workspace.
- `status: "active" or "archived" or "expired" or "inactive"`
Status of the API key.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `type: "api_key"`
Object type.
For API Keys, this is always `"api_key"`.
default: api_key
- `workspace_id: string or null`
**Deprecated**: Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace.
Deprecated: use `scope` instead. ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. Also `null` for a principal-bound API key that has no Workspace; `scope` tells the two apart.
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
#### Example
```bash
curl https://api.anthropic.com/v1/organizations/api_keys \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
##### Response (200)
```json
{
"data": [
{
"id": "apikey_01Rj2N8SVvo6BePZj99NhmiT",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by": {
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"type": "user"
},
"expires_at": "2024-10-30T23:58:27.427722Z",
"name": "Developer Key",
"partial_key_hint": "sk-ant-api03-R2D...igAA",
"principal": {
Cut at 300 lines. The page has the rest.
api/beta/organization/api_keys New page · 779 lines, new page
# API Keys ## List API Keys ### Query parameters ### Returns ### Example #### Response (200) ## Get API Key ### Path parameters ### Returns ### Example #### Response (200) ## Update API Key ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta API Key ### Beta API Key Created By ### Beta API Key Organization Scope ### Beta API Key Service Account Actor ### Beta API Key User Actor ### Beta API Key Workspace Scope
A whole new page. There's nothing to diff it against, so here is what it says.
# API Keys
## List API Keys
**GET** `/v1/organizations/api_keys`
List API Keys
### Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `created_by_user_id: optional string`
Filter by the ID of the User who created the object.
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `status: optional "active" or "archived" or "expired" or "inactive"`
Filter by API key status.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `workspace_id: optional string`
Filter by Workspace ID.
### Returns
- `data: array of BetaAPIKey`
- `id: string`
ID of the API key.
- `created_at: string`
RFC 3339 datetime string indicating when the API Key was created.
format: date-time
- `created_by: BetaAPIKeyCreatedBy or null`
The ID and type of the actor that created the API key, or `null` when the
creator is not recorded (legacy, workload-identity-federated, or
system-created keys).
- `id: string`
ID of the actor that created the object.
- `type: "service_account" or "user"`
Type of the actor that created the object.
- `"service_account"`
- `"user"`
- `expires_at: string or null`
RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
format: date-time
- `name: string`
Name of the API key.
- `partial_key_hint: string or null`
Partially redacted hint for the API key.
- `principal: BetaAPIKeyUserActor or BetaAPIKeyServiceAccountActor or null`
The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal.
- `BetaAPIKeyUserActor object`
- `type: "user_actor"`
Principal type. Always `"user_actor"` for a User.
default: user_actor
- `user_id: string`
ID of the User the API key acts as.
- `BetaAPIKeyServiceAccountActor object`
- `service_account_id: string`
ID of the Service Account the API key acts as.
- `type: "service_account_actor"`
Principal type. Always `"service_account_actor"` for a Service Account.
default: service_account_actor
- `scope: BetaAPIKeyOrganizationScope or BetaAPIKeyWorkspaceScope`
Where the API key belongs: its Workspace (`{"type": "workspace", "workspace_id": "wrkspc_..."}`, with the Workspace's real ID even when it is the organization's default Workspace), or the organization (`{"type": "organization"}`) for a principal-bound API key that has no Workspace.
- `BetaAPIKeyOrganizationScope object`
- `type: "organization"`
Scope type. Always `"organization"`: the API key has no Workspace. Only a principal-bound API key can have this scope.
default: organization
- `BetaAPIKeyWorkspaceScope object`
- `type: "workspace"`
Scope type. Always `"workspace"`: the API key belongs to one Workspace.
default: workspace
- `workspace_id: string`
ID of the Workspace the API key belongs to. Unlike the deprecated top-level `workspace_id`, this is the Workspace's real ID even for the organization's default Workspace.
- `status: "active" or "archived" or "expired" or "inactive"`
Status of the API key.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `type: "api_key"`
Object type.
For API Keys, this is always `"api_key"`.
default: api_key
- `workspace_id: string or null`
**Deprecated**: Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace.
Deprecated: use `scope` instead. ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. Also `null` for a principal-bound API key that has no Workspace; `scope` tells the two apart.
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/api_keys \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"id": "apikey_01Rj2N8SVvo6BePZj99NhmiT",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by": {
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"type": "user"
},
"expires_at": "2024-10-30T23:58:27.427722Z",
"name": "Developer Key",
"partial_key_hint": "sk-ant-api03-R2D...igAA",
"principal": {
"type": "user_actor",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
},
"scope": {
"type": "workspace",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
},
"status": "active",
"type": "api_key",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
## Get API Key
**GET** `/v1/organizations/api_keys/{api_key_id}`
Get API Key
### Path parameters
- `api_key_id: string`
ID of the API key.
### Returns
- `BetaAPIKey object`
- `id: string`
ID of the API key.
- `created_at: string`
RFC 3339 datetime string indicating when the API Key was created.
format: date-time
- `created_by: BetaAPIKeyCreatedBy or null`
The ID and type of the actor that created the API key, or `null` when the
creator is not recorded (legacy, workload-identity-federated, or
system-created keys).
- `id: string`
ID of the actor that created the object.
- `type: "service_account" or "user"`
Type of the actor that created the object.
- `"service_account"`
- `"user"`
- `expires_at: string or null`
RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
format: date-time
- `name: string`
Name of the API key.
- `partial_key_hint: string or null`
Partially redacted hint for the API key.
- `principal: BetaAPIKeyUserActor or BetaAPIKeyServiceAccountActor or null`
The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal.
- `BetaAPIKeyUserActor object`
- `type: "user_actor"`
Principal type. Always `"user_actor"` for a User.
default: user_actor
- `user_id: string`
ID of the User the API key acts as.
- `BetaAPIKeyServiceAccountActor object`
Cut at 300 lines. The page has the rest.
api/beta/organization/api_keys/list New page · 221 lines, new page
# List API Keys ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List API Keys
**GET** `/v1/organizations/api_keys`
List API Keys
## Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `created_by_user_id: optional string`
Filter by the ID of the User who created the object.
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `status: optional "active" or "archived" or "expired" or "inactive"`
Filter by API key status.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `workspace_id: optional string`
Filter by Workspace ID.
## Returns
- `data: array of BetaAPIKey`
- `id: string`
ID of the API key.
- `created_at: string`
RFC 3339 datetime string indicating when the API Key was created.
format: date-time
- `created_by: BetaAPIKeyCreatedBy or null`
The ID and type of the actor that created the API key, or `null` when the
creator is not recorded (legacy, workload-identity-federated, or
system-created keys).
- `id: string`
ID of the actor that created the object.
- `type: "service_account" or "user"`
Type of the actor that created the object.
- `"service_account"`
- `"user"`
- `expires_at: string or null`
RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
format: date-time
- `name: string`
Name of the API key.
- `partial_key_hint: string or null`
Partially redacted hint for the API key.
- `principal: BetaAPIKeyUserActor or BetaAPIKeyServiceAccountActor or null`
The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal.
- `BetaAPIKeyUserActor object`
- `type: "user_actor"`
Principal type. Always `"user_actor"` for a User.
default: user_actor
- `user_id: string`
ID of the User the API key acts as.
- `BetaAPIKeyServiceAccountActor object`
- `service_account_id: string`
ID of the Service Account the API key acts as.
- `type: "service_account_actor"`
Principal type. Always `"service_account_actor"` for a Service Account.
default: service_account_actor
- `scope: BetaAPIKeyOrganizationScope or BetaAPIKeyWorkspaceScope`
Where the API key belongs: its Workspace (`{"type": "workspace", "workspace_id": "wrkspc_..."}`, with the Workspace's real ID even when it is the organization's default Workspace), or the organization (`{"type": "organization"}`) for a principal-bound API key that has no Workspace.
- `BetaAPIKeyOrganizationScope object`
- `type: "organization"`
Scope type. Always `"organization"`: the API key has no Workspace. Only a principal-bound API key can have this scope.
default: organization
- `BetaAPIKeyWorkspaceScope object`
- `type: "workspace"`
Scope type. Always `"workspace"`: the API key belongs to one Workspace.
default: workspace
- `workspace_id: string`
ID of the Workspace the API key belongs to. Unlike the deprecated top-level `workspace_id`, this is the Workspace's real ID even for the organization's default Workspace.
- `status: "active" or "archived" or "expired" or "inactive"`
Status of the API key.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `type: "api_key"`
Object type.
For API Keys, this is always `"api_key"`.
default: api_key
- `workspace_id: string or null`
**Deprecated**: Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace.
Deprecated: use `scope` instead. ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. Also `null` for a principal-bound API key that has no Workspace; `scope` tells the two apart.
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/api_keys \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "apikey_01Rj2N8SVvo6BePZj99NhmiT",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by": {
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"type": "user"
},
"expires_at": "2024-10-30T23:58:27.427722Z",
"name": "Developer Key",
"partial_key_hint": "sk-ant-api03-R2D...igAA",
"principal": {
"type": "user_actor",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
},
"scope": {
"type": "workspace",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
},
"status": "active",
"type": "api_key",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
api/beta/organization/api_keys/retrieve New page · 170 lines, new page
# Get API Key ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get API Key
**GET** `/v1/organizations/api_keys/{api_key_id}`
Get API Key
## Path parameters
- `api_key_id: string`
ID of the API key.
## Returns
- `BetaAPIKey object`
- `id: string`
ID of the API key.
- `created_at: string`
RFC 3339 datetime string indicating when the API Key was created.
format: date-time
- `created_by: BetaAPIKeyCreatedBy or null`
The ID and type of the actor that created the API key, or `null` when the
creator is not recorded (legacy, workload-identity-federated, or
system-created keys).
- `id: string`
ID of the actor that created the object.
- `type: "service_account" or "user"`
Type of the actor that created the object.
- `"service_account"`
- `"user"`
- `expires_at: string or null`
RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
format: date-time
- `name: string`
Name of the API key.
- `partial_key_hint: string or null`
Partially redacted hint for the API key.
- `principal: BetaAPIKeyUserActor or BetaAPIKeyServiceAccountActor or null`
The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal.
- `BetaAPIKeyUserActor object`
- `type: "user_actor"`
Principal type. Always `"user_actor"` for a User.
default: user_actor
- `user_id: string`
ID of the User the API key acts as.
- `BetaAPIKeyServiceAccountActor object`
- `service_account_id: string`
ID of the Service Account the API key acts as.
- `type: "service_account_actor"`
Principal type. Always `"service_account_actor"` for a Service Account.
default: service_account_actor
- `scope: BetaAPIKeyOrganizationScope or BetaAPIKeyWorkspaceScope`
Where the API key belongs: its Workspace (`{"type": "workspace", "workspace_id": "wrkspc_..."}`, with the Workspace's real ID even when it is the organization's default Workspace), or the organization (`{"type": "organization"}`) for a principal-bound API key that has no Workspace.
- `BetaAPIKeyOrganizationScope object`
- `type: "organization"`
Scope type. Always `"organization"`: the API key has no Workspace. Only a principal-bound API key can have this scope.
default: organization
- `BetaAPIKeyWorkspaceScope object`
- `type: "workspace"`
Scope type. Always `"workspace"`: the API key belongs to one Workspace.
default: workspace
- `workspace_id: string`
ID of the Workspace the API key belongs to. Unlike the deprecated top-level `workspace_id`, this is the Workspace's real ID even for the organization's default Workspace.
- `status: "active" or "archived" or "expired" or "inactive"`
Status of the API key.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `type: "api_key"`
Object type.
For API Keys, this is always `"api_key"`.
default: api_key
- `workspace_id: string or null`
**Deprecated**: Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace.
Deprecated: use `scope` instead. ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. Also `null` for a principal-bound API key that has no Workspace; `scope` tells the two apart.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "apikey_01Rj2N8SVvo6BePZj99NhmiT",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by": {
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"type": "user"
},
"expires_at": "2024-10-30T23:58:27.427722Z",
"name": "Developer Key",
"partial_key_hint": "sk-ant-api03-R2D...igAA",
"principal": {
"type": "user_actor",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
},
"scope": {
"type": "workspace",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
},
"status": "active",
"type": "api_key",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
```
api/beta/organization/api_keys/update New page · 190 lines, new page
# Update API Key ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update API Key
**POST** `/v1/organizations/api_keys/{api_key_id}`
Update API Key
## Path parameters
- `api_key_id: string`
ID of the API key.
## Body parameters
- `name: optional string or null`
Name of the API key.
maxLength: 500, minLength: 1
- `status: optional "active" or "archived" or "inactive" or null`
Status of the API key.
- `"active"`
- `"archived"`
- `"inactive"`
## Returns
- `BetaAPIKey object`
- `id: string`
ID of the API key.
- `created_at: string`
RFC 3339 datetime string indicating when the API Key was created.
format: date-time
- `created_by: BetaAPIKeyCreatedBy or null`
The ID and type of the actor that created the API key, or `null` when the
creator is not recorded (legacy, workload-identity-federated, or
system-created keys).
- `id: string`
ID of the actor that created the object.
- `type: "service_account" or "user"`
Type of the actor that created the object.
- `"service_account"`
- `"user"`
- `expires_at: string or null`
RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
format: date-time
- `name: string`
Name of the API key.
- `partial_key_hint: string or null`
Partially redacted hint for the API key.
- `principal: BetaAPIKeyUserActor or BetaAPIKeyServiceAccountActor or null`
The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal.
- `BetaAPIKeyUserActor object`
- `type: "user_actor"`
Principal type. Always `"user_actor"` for a User.
default: user_actor
- `user_id: string`
ID of the User the API key acts as.
- `BetaAPIKeyServiceAccountActor object`
- `service_account_id: string`
ID of the Service Account the API key acts as.
- `type: "service_account_actor"`
Principal type. Always `"service_account_actor"` for a Service Account.
default: service_account_actor
- `scope: BetaAPIKeyOrganizationScope or BetaAPIKeyWorkspaceScope`
Where the API key belongs: its Workspace (`{"type": "workspace", "workspace_id": "wrkspc_..."}`, with the Workspace's real ID even when it is the organization's default Workspace), or the organization (`{"type": "organization"}`) for a principal-bound API key that has no Workspace.
- `BetaAPIKeyOrganizationScope object`
- `type: "organization"`
Scope type. Always `"organization"`: the API key has no Workspace. Only a principal-bound API key can have this scope.
default: organization
- `BetaAPIKeyWorkspaceScope object`
- `type: "workspace"`
Scope type. Always `"workspace"`: the API key belongs to one Workspace.
default: workspace
- `workspace_id: string`
ID of the Workspace the API key belongs to. Unlike the deprecated top-level `workspace_id`, this is the Workspace's real ID even for the organization's default Workspace.
- `status: "active" or "archived" or "expired" or "inactive"`
Status of the API key.
- `"active"`
- `"archived"`
- `"expired"`
- `"inactive"`
- `type: "api_key"`
Object type.
For API Keys, this is always `"api_key"`.
default: api_key
- `workspace_id: string or null`
**Deprecated**: Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace.
Deprecated: use `scope` instead. ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. Also `null` for a principal-bound API key that has no Workspace; `scope` tells the two apart.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{}'
```
### Response (200)
```json
{
"id": "apikey_01Rj2N8SVvo6BePZj99NhmiT",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by": {
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"type": "user"
},
"expires_at": "2024-10-30T23:58:27.427722Z",
"name": "Developer Key",
"partial_key_hint": "sk-ant-api03-R2D...igAA",
"principal": {
"type": "user_actor",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q"
},
"scope": {
"type": "workspace",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
},
"status": "active",
"type": "api_key",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
```
api/beta/organization/external_keys New page · 1067 lines, new page
# External Keys ## Create External Key ### Body parameters ### Returns ### Example #### Response (200) ## List External Keys ### Query parameters ### Returns ### Example #### Response (200) ## Get External Key ### Path parameters ### Returns ### Example #### Response (200) ## Update External Key ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Delete External Key ### Path parameters ### Returns ### Example #### Response (200) ## Validate External Key ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta AWS External Key Config ### Beta Azure External Key Config ### Beta Azure External Key Config Param ### Beta External Key ### Beta External Key Attached Attachment ### Beta External Key Unattached Attachment ### Beta GCP External Key Config ### External Key Delete Response ### External Key Validate Response
A whole new page. There's nothing to diff it against, so here is what it says.
# External Keys
## Create External Key
**POST** `/v1/organizations/external_keys`
Create an external key config owned by the caller's organization.
### Body parameters
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfigParam`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfigParam object`
Azure Key Vault provider configuration.
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `display_name: optional string or null`
Human-friendly display name.
maxLength: 255, minLength: 1
- `geo: optional "us"`
Data residency geo. Only `us` is supported.
### Returns
- `BetaExternalKey object`
CMEK external key config belonging to the caller's organization.
Configs are organization-scoped. Workspaces attach to a config; once any
workspace references it, the provider fields become effectively immutable
(existing encrypted data needs the config for decrypt).
- `id: string`
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.
- `attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment`
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.
- `BetaExternalKeyAttachedAttachment object`
- `type: "attached"`
default: attached
- `BetaExternalKeyUnattachedAttachment object`
- `type: "unattached"`
default: unattached
- `created_at: string`
format: date-time
- `display_name: string or null`
Human-friendly display name. Null if none was set.
- `geo: string`
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfig object`
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `type: "external_key"`
default: external_key
- `updated_at: string`
format: date-time
### Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws"
}
}'
```
#### Response (200)
```json
{
"id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"attachment": {
"type": "attached"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "prod-us-key",
"geo": "us",
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws",
"region": "us-east-1",
"role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
},
"type": "external_key",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
## List External Keys
**GET** `/v1/organizations/external_keys`
List external key configs in the caller's organization.
Results are ordered by creation time (newest first). Use the
`next_page` cursor from the response to fetch subsequent pages.
### Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Returns
- `data: array of BetaExternalKey`
- `id: string`
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.
- `attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment`
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.
- `BetaExternalKeyAttachedAttachment object`
- `type: "attached"`
default: attached
- `BetaExternalKeyUnattachedAttachment object`
- `type: "unattached"`
default: unattached
- `created_at: string`
format: date-time
- `display_name: string or null`
Human-friendly display name. Null if none was set.
- `geo: string`
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
Cut at 300 lines. The page has the rest.
api/beta/organization/external_keys/create New page · 210 lines, new page
# Create External Key ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create External Key
**POST** `/v1/organizations/external_keys`
Create an external key config owned by the caller's organization.
## Body parameters
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfigParam`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfigParam object`
Azure Key Vault provider configuration.
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `display_name: optional string or null`
Human-friendly display name.
maxLength: 255, minLength: 1
- `geo: optional "us"`
Data residency geo. Only `us` is supported.
## Returns
- `BetaExternalKey object`
CMEK external key config belonging to the caller's organization.
Configs are organization-scoped. Workspaces attach to a config; once any
workspace references it, the provider fields become effectively immutable
(existing encrypted data needs the config for decrypt).
- `id: string`
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.
- `attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment`
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.
- `BetaExternalKeyAttachedAttachment object`
- `type: "attached"`
default: attached
- `BetaExternalKeyUnattachedAttachment object`
- `type: "unattached"`
default: unattached
- `created_at: string`
format: date-time
- `display_name: string or null`
Human-friendly display name. Null if none was set.
- `geo: string`
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfig object`
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `type: "external_key"`
default: external_key
- `updated_at: string`
format: date-time
## Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws"
}
}'
```
### Response (200)
```json
{
"id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"attachment": {
"type": "attached"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "prod-us-key",
"geo": "us",
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws",
"region": "us-east-1",
"role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
},
"type": "external_key",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
api/beta/organization/external_keys/delete New page · 43 lines, new page
# Delete External Key ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Delete External Key
**DELETE** `/v1/organizations/external_keys/{external_key_id}`
Delete an external key config.
The request is rejected if any workspace still references this config.
## Path parameters
- `external_key_id: string`
ID of the External Key.
maxLength: 2048
## Returns
- `id: string`
ID of the deleted External Key.
- `type: "external_key_deleted"`
default: external_key_deleted
## Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "ekey_01AbCdEfGhIjKlMnOpQrStUv",
"type": "external_key_deleted"
}
```
api/beta/organization/external_keys/list New page · 155 lines, new page
# List External Keys ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List External Keys
**GET** `/v1/organizations/external_keys`
List external key configs in the caller's organization.
Results are ordered by creation time (newest first). Use the
`next_page` cursor from the response to fetch subsequent pages.
## Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Returns
- `data: array of BetaExternalKey`
- `id: string`
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.
- `attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment`
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.
- `BetaExternalKeyAttachedAttachment object`
- `type: "attached"`
default: attached
- `BetaExternalKeyUnattachedAttachment object`
- `type: "unattached"`
default: unattached
- `created_at: string`
format: date-time
- `display_name: string or null`
Human-friendly display name. Null if none was set.
- `geo: string`
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfig object`
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `type: "external_key"`
default: external_key
- `updated_at: string`
format: date-time
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results. Pass as `?page=` to fetch the next page.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"attachment": {
"type": "attached"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "prod-us-key",
"geo": "us",
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws",
"region": "us-east-1",
"role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
},
"type": "external_key",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
],
"next_page": "next_page"
}
```
api/beta/organization/external_keys/retrieve New page · 145 lines, new page
# Get External Key ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get External Key
**GET** `/v1/organizations/external_keys/{external_key_id}`
Retrieve a single external key config in the caller's organization by ID.
## Path parameters
- `external_key_id: string`
ID of the External Key.
maxLength: 2048
## Returns
- `BetaExternalKey object`
CMEK external key config belonging to the caller's organization.
Configs are organization-scoped. Workspaces attach to a config; once any
workspace references it, the provider fields become effectively immutable
(existing encrypted data needs the config for decrypt).
- `id: string`
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.
- `attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment`
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.
- `BetaExternalKeyAttachedAttachment object`
- `type: "attached"`
default: attached
- `BetaExternalKeyUnattachedAttachment object`
- `type: "unattached"`
default: unattached
- `created_at: string`
format: date-time
- `display_name: string or null`
Human-friendly display name. Null if none was set.
- `geo: string`
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfig object`
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `type: "external_key"`
default: external_key
- `updated_at: string`
format: date-time
## Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"attachment": {
"type": "attached"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "prod-us-key",
"geo": "us",
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws",
"region": "us-east-1",
"role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
},
"type": "external_key",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
api/beta/organization/external_keys/update New page · 217 lines, new page
# Update External Key ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update External Key
**POST** `/v1/organizations/external_keys/{external_key_id}`
Partially update an external key config. Omitted fields are left unchanged.
`display_name` is always editable. `geo` and `provider_config` cannot
be changed once any workspace references this config, because previously
encrypted data requires the original key identity to decrypt.
## Path parameters
- `external_key_id: string`
ID of the External Key.
maxLength: 2048
## Body parameters
- `display_name: optional string or null`
Human-friendly display name.
maxLength: 255, minLength: 1
- `geo: optional "us" or null`
Data residency geo. Only `us` is supported.
- `provider_config: optional BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfigParam or null`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfigParam object`
Azure Key Vault provider configuration.
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
## Returns
- `BetaExternalKey object`
CMEK external key config belonging to the caller's organization.
Configs are organization-scoped. Workspaces attach to a config; once any
workspace references it, the provider fields become effectively immutable
(existing encrypted data needs the config for decrypt).
- `id: string`
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.
- `attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment`
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.
- `BetaExternalKeyAttachedAttachment object`
- `type: "attached"`
default: attached
- `BetaExternalKeyUnattachedAttachment object`
- `type: "unattached"`
default: unattached
- `created_at: string`
format: date-time
- `display_name: string or null`
Human-friendly display name. Null if none was set.
- `geo: string`
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
- `provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig`
KMS provider identity and auth coordinates.
- `BetaAWSExternalKeyConfig object`
- `kms_arn: string`
Full ARN of the AWS KMS key.
maxLength: 2048
- `type: "aws"`
- `region: optional string or null`
AWS region. Derived from `kms_arn` if omitted.
- `role_arn: optional string or null`
**Deprecated**
IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored.
- `BetaGCPExternalKeyConfig object`
- `key_name: string`
Full resource name of the Cloud KMS key.
- `type: "gcp"`
- `BetaAzureExternalKeyConfig object`
- `key_name: string`
Name of the key within the vault.
- `tenant_id: string`
Azure AD tenant ID.
- `type: "azure"`
- `vault_uri: string`
Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.
- `client_id: optional string or null`
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
- `type: "external_key"`
default: external_key
- `updated_at: string`
format: date-time
## Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{}'
```
### Response (200)
```json
{
"id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"attachment": {
"type": "attached"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "prod-us-key",
"geo": "us",
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws",
"region": "us-east-1",
"role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
},
"type": "external_key",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
api/beta/organization/external_keys/validate New page · 55 lines, new page
# Validate External Key ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Validate External Key
**POST** `/v1/organizations/external_keys/{external_key_id}/validate`
Validate an external key config against the customer's KMS.
Anthropic performs an encrypt/decrypt roundtrip against the configured
KMS key and waits up to 30 seconds for the result. The response status is
`success` if the roundtrip succeeded, or `failure` with an error
message if it failed or timed out.
## Path parameters
- `external_key_id: string`
ID of the External Key.
maxLength: 2048
## Returns
- `error: string or null`
Error message when status is `failure`. Null otherwise.
- `status: "failure" or "success"`
`success` — encrypt/decrypt roundtrip succeeded. `failure` — the roundtrip failed or timed out; see `error`.
- `"failure"`
- `"success"`
- `type: "external_key_validation"`
default: external_key_validation
## Example
```bash
curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/validate \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"error": "error",
"status": "failure",
"type": "external_key_validation"
}
```
api/beta/organization/federation New page · 3816 lines, new page
# Federation ## Federation › Issuers ### Create Federation Issuer #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Issuers #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Federation Issuer #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Federation Issuer #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Federation Issuer #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Federation › Rules ### Create Federation Rule #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rules #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Federation Rule #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Federation Rule #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Federation Rule #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Federation › Rules › Workspaces ### Add Federation Rule Workspace #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rule Workspaces #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Remove Federation Rule Workspace #### Path parameters #### Headers #### Returns #### Example ##### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Federation
## Federation › Issuers
### Create Federation Issuer
**POST** `/v1/organizations/federation_issuers`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Register an OIDC issuer that Anthropic will trust for workload identity
federation in your organization.
The `jwks` field controls how the issuer's signing keys are obtained and
takes one of three shapes selected by `type`: `discovery` (resolve keys
through OIDC discovery), `explicit_url` (fetch keys from a fixed JWKS
URL), or `inline` (provide a static key set). When `jwks.type` is
`discovery` and no `discovery_base` is set, the issuer URL must be
publicly reachable over HTTPS so Anthropic can fetch the discovery
document; for `explicit_url` and `inline` modes the issuer URL is only
matched as the JWT's `iss` claim and is not fetched.
#### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
#### Body parameters
- `issuer_url: string`
The `iss` claim value to match against.
minLength: 1
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `check_jti: optional boolean or null`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `jwks: optional BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained. Defaults to OIDC discovery.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `max_jwt_lifetime_seconds: optional number or null`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
maximum: 176400, exclusiveMinimum: 0
#### Returns
- `BetaFederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Anthropic periodically fetches the issuer's signing keys in the
background. These fields summarize the most recent fetches so the
health of the JWKS endpoint can be monitored.
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/issuers New page · 1853 lines, new page
# Issuers ## Create Federation Issuer ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## List Federation Issuers ### Query parameters ### Headers ### Returns ### Example #### Response (200) ## Get Federation Issuer ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Update Federation Issuer ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## Archive Federation Issuer ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Domain types ### Beta Federation Issuer ### Beta Federation Issuer Poll Status ### Beta JWKS Discovery ### Beta JWKS Explicit URL ### Beta JWKS Inline
A whole new page. There's nothing to diff it against, so here is what it says.
# Issuers
## Create Federation Issuer
**POST** `/v1/organizations/federation_issuers`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Register an OIDC issuer that Anthropic will trust for workload identity
federation in your organization.
The `jwks` field controls how the issuer's signing keys are obtained and
takes one of three shapes selected by `type`: `discovery` (resolve keys
through OIDC discovery), `explicit_url` (fetch keys from a fixed JWKS
URL), or `inline` (provide a static key set). When `jwks.type` is
`discovery` and no `discovery_base` is set, the issuer URL must be
publicly reachable over HTTPS so Anthropic can fetch the discovery
document; for `explicit_url` and `inline` modes the issuer URL is only
matched as the JWT's `iss` claim and is not fetched.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Body parameters
- `issuer_url: string`
The `iss` claim value to match against.
minLength: 1
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `check_jti: optional boolean or null`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `jwks: optional BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained. Defaults to OIDC discovery.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `max_jwt_lifetime_seconds: optional number or null`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
maximum: 176400, exclusiveMinimum: 0
### Returns
- `BetaFederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Anthropic periodically fetches the issuer's signing keys in the
background. These fields summarize the most recent fetches so the
health of the JWKS endpoint can be monitored.
- `consecutive_failures: number`
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/issuers/archive New page · 292 lines, new page
# Archive Federation Issuer ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Archive Federation Issuer
**POST** `/v1/organizations/federation_issuers/{federation_issuer_id}/archive`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Archive a federation issuer.
Idempotent; re-archiving returns the issuer with its original
`archived_at`. Rejected with 400 if any live (non-archived) federation
rule still references the issuer; archive those rules first (a rule's
issuer cannot be changed), or recreate them against another issuer.
## Path parameters
- `federation_issuer_id: string`
ID of the federation issuer to archive.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaFederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Anthropic periodically fetches the issuer's signing keys in the
background. These fields summarize the most recent fetches so the
health of the JWKS endpoint can be monitored.
- `consecutive_failures: number`
Consecutive fetch failures since the last success.
- `last_fetched_at: string or null`
When the last successful fetch completed.
format: date-time
- `next_poll_at: string or null`
When the next fetch is scheduled. Null if paused.
format: date-time
- `type: "federation_issuer"`
default: federation_issuer
- `updated_at: string`
When this issuer was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"check_jti": true,
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"issuer_url": "https://token.actions.githubusercontent.com",
"jwks": {
"type": "discovery",
"ca_cert_pem": "ca_cert_pem",
"discovery_base": "discovery_base"
},
"jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
"max_jwt_lifetime_seconds": 0,
"name": "github-actions",
"poll_status": {
"consecutive_failures": 0,
"last_fetched_at": "2019-12-27T18:11:19.117Z",
"next_poll_at": "2019-12-27T18:11:19.117Z"
},
"type": "federation_issuer",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
api/beta/organization/federation/issuers/create New page · 369 lines, new page
# Create Federation Issuer ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Federation Issuer
**POST** `/v1/organizations/federation_issuers`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Register an OIDC issuer that Anthropic will trust for workload identity
federation in your organization.
The `jwks` field controls how the issuer's signing keys are obtained and
takes one of three shapes selected by `type`: `discovery` (resolve keys
through OIDC discovery), `explicit_url` (fetch keys from a fixed JWKS
URL), or `inline` (provide a static key set). When `jwks.type` is
`discovery` and no `discovery_base` is set, the issuer URL must be
publicly reachable over HTTPS so Anthropic can fetch the discovery
document; for `explicit_url` and `inline` modes the issuer URL is only
matched as the JWT's `iss` claim and is not fetched.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `issuer_url: string`
The `iss` claim value to match against.
minLength: 1
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `check_jti: optional boolean or null`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `jwks: optional BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained. Defaults to OIDC discovery.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `max_jwt_lifetime_seconds: optional number or null`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
maximum: 176400, exclusiveMinimum: 0
## Returns
- `BetaFederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Anthropic periodically fetches the issuer's signing keys in the
background. These fields summarize the most recent fetches so the
health of the JWKS endpoint can be monitored.
- `consecutive_failures: number`
Consecutive fetch failures since the last success.
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/issuers/list New page · 304 lines, new page
# List Federation Issuers ## Query parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Federation Issuers
**GET** `/v1/organizations/federation_issuers`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List federation issuers in your organization.
Archived issuers are excluded unless `include_archived=true`.
## Query parameters
- `include_archived: optional boolean`
Include archived resources. Defaults to false.
default: false
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `data: array of BetaFederationIssuer`
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Anthropic periodically fetches the issuer's signing keys in the
background. These fields summarize the most recent fetches so the
health of the JWKS endpoint can be monitored.
- `consecutive_failures: number`
Consecutive fetch failures since the last success.
- `last_fetched_at: string or null`
When the last successful fetch completed.
format: date-time
- `next_poll_at: string or null`
When the next fetch is scheduled. Null if paused.
format: date-time
- `type: "federation_issuer"`
default: federation_issuer
- `updated_at: string`
When this issuer was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_issuers \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"check_jti": true,
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"issuer_url": "https://token.actions.githubusercontent.com",
"jwks": {
"type": "discovery",
"ca_cert_pem": "ca_cert_pem",
"discovery_base": "discovery_base"
},
"jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
"max_jwt_lifetime_seconds": 0,
"name": "github-actions",
"poll_status": {
"consecutive_failures": 0,
"last_fetched_at": "2019-12-27T18:11:19.117Z",
"next_poll_at": "2019-12-27T18:11:19.117Z"
},
"type": "federation_issuer",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/issuers/retrieve New page · 286 lines, new page
# Get Federation Issuer ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Federation Issuer
**GET** `/v1/organizations/federation_issuers/{federation_issuer_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Retrieve a federation issuer by its ID (`fdis_...`).
## Path parameters
- `federation_issuer_id: string`
ID of the federation issuer.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaFederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Anthropic periodically fetches the issuer's signing keys in the
background. These fields summarize the most recent fetches so the
health of the JWKS endpoint can be monitored.
- `consecutive_failures: number`
Consecutive fetch failures since the last success.
- `last_fetched_at: string or null`
When the last successful fetch completed.
format: date-time
- `next_poll_at: string or null`
When the next fetch is scheduled. Null if paused.
format: date-time
- `type: "federation_issuer"`
default: federation_issuer
- `updated_at: string`
When this issuer was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"check_jti": true,
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"issuer_url": "https://token.actions.githubusercontent.com",
"jwks": {
"type": "discovery",
"ca_cert_pem": "ca_cert_pem",
"discovery_base": "discovery_base"
},
"jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
"max_jwt_lifetime_seconds": 0,
"name": "github-actions",
"poll_status": {
"consecutive_failures": 0,
"last_fetched_at": "2019-12-27T18:11:19.117Z",
"next_poll_at": "2019-12-27T18:11:19.117Z"
},
"type": "federation_issuer",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
api/beta/organization/federation/issuers/update New page · 373 lines, new page
# Update Federation Issuer ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update Federation Issuer
**POST** `/v1/organizations/federation_issuers/{federation_issuer_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Partially update a federation issuer.
Setting `jwks` replaces the full JWKS shape at once. Archived issuers
cannot be updated; this returns 400. Create a new issuer instead.
Updating an issuer that backs a rule with a scope outside
`workspace:developer` or `workspace:inference` requires a Console
session.
## Path parameters
- `federation_issuer_id: string`
ID of the federation issuer to update.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `check_jti: optional boolean or null`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `issuer_url: optional string or null`
Replaces the `iss` claim value to match against. For discovery-mode issuers without a `discovery_base`, this is also the URL Anthropic fetches the OIDC discovery document and signing keys from, so changing it repoints the JWKS source. Changing the issuer URL to a well-known shared platform is rejected while any live rule under this issuer would not constrain tenant identity.
minLength: 1
- `jwks: optional BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline or null`
Replaces the entire JWKS configuration.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled: optional boolean or null`
Only `false` is accepted, to re-enable polling after the system pauses it. Polling is paused automatically; sending `true` is rejected.
- `max_jwt_lifetime_seconds: optional number or null`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
maximum: 176400, exclusiveMinimum: 0
- `name: optional string or null`
Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
## Returns
- `BetaFederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline`
How signing keys are obtained for signature verification.
- `BetaJWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `BetaJWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `BetaJWKSInline object`
JWKS supplied directly; no network fetch.
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `type: "inline"`
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: BetaFederationIssuerPollStatus or null`
Status of automatic JWKS polling for a federation issuer.
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/rules New page · 2396 lines, new page
# Rules ## Create Federation Rule ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## List Federation Rules ### Query parameters ### Headers ### Returns ### Example #### Response (200) ## Get Federation Rule ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Update Federation Rule ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## Archive Federation Rule ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Domain types ### Beta Federation Rule ### Beta Federation Rule Match ### Beta Federation Rule Workspace ### Beta Service Account Target ## Rules › Workspaces ### Add Federation Rule Workspace #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rule Workspaces #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Remove Federation Rule Workspace #### Path parameters #### Headers #### Returns #### Example ##### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Rules
## Create Federation Rule
**POST** `/v1/organizations/federation_rules`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Create a federation rule owned by your organization.
The referenced issuer and the target service account must already exist
in the same organization; invalid references are rejected with a 400
error. The workspace reference is validated. Membership is not checked
at rule creation: token exchange resolves a single enabled workspace per
call and is rejected unless the target service account is a member of
that workspace (it is implicitly a member of the default workspace).
Rules on well-known shared issuers (GitHub Actions, GitLab, Buildkite,
Terraform Cloud, Google) must constrain tenant identity via an
identity-bearing claim, a tenant-pinning subject prefix (such as
`repo:YOUR_ORG/...`), or a CEL condition referencing one of those
identity claims (e.g. `claims.repository_owner`). OAuth callers may only
manage rules whose `oauth_scope` is `workspace:developer` or
`workspace:inference`; other scopes require a Console session.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Body parameters
- `issuer_id: string`
Tagged ID of the federation issuer.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. At least one of `subject_prefix` (other than a wildcard-only value like `*`), `claims`, or `condition` is required; `audience` alone is not sufficient.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `oauth_scope: string`
Space-separated OAuth scopes. OAuth callers may only set `workspace:developer` or `workspace:inference`; other scopes (such as `org:admin`) require a Console session.
minLength: 1
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Service account's display name at read time. Ignored on writes.
- `applies_to_all_workspaces: optional boolean`
When true, enable this rule for every workspace in the org (including workspaces created later).
- `attributes: optional map[string] or null`
CEL expressions `{name: expr}` extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.
- `description: optional string or null`
Optional free-text description.
maxLength: 2000
- `token_lifetime_seconds: optional number`
Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
maximum: 86400, minimum: 60
- `workspace_id: optional string or null`
Tagged ID of the workspace to enable this rule for. Required unless `applies_to_all_workspaces` is true. Additional workspaces can be added via the `/federation_rules/{federation_rule_id}/workspaces` sub-resource.
### Returns
- `BetaFederationRule object`
Authorization rule binding an external OIDC identity to Anthropic.
Evaluates the match conditions and mints an OAuth access token for the
resolved target, scoped to a single workspace where the rule is enabled
(chosen by the caller at exchange time when the rule is enabled for more
than one). For rules enabled via `workspace_ids` or
`applies_to_all_workspaces`, the target service account must be a member
of that workspace (it is implicitly a member of the default workspace);
rules carrying only the legacy `workspace_id` binding do not enforce
this.
- `id: string`
Tagged ID of the federation rule.
- `applies_to_all_workspaces: boolean`
When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
- `archived_at: string or null`
If set, this rule is archived and rejects token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
- `attributes: map[string] or null`
CEL expressions extracting named values from claims. Not yet supported; always null.
- `created_at: string`
When this rule was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this rule.
- `description: string or null`
Optional free-text description.
- `issuer_id: string`
Tagged ID of the issuer whose tokens this rule accepts.
- `issuer_name: string or null`
Issuer's display name at read time.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Admin-chosen slug identifier.
- `oauth_scope: string`
Space-separated OAuth scopes granted on the minted token.
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/rules/archive New page · 297 lines, new page
# Archive Federation Rule ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Archive Federation Rule
**POST** `/v1/organizations/federation_rules/{federation_rule_id}/archive`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Archive a federation rule.
Token exchange through this rule stops immediately. Idempotent;
re-archiving returns the rule with its original `archived_at`. Archiving
clears the rule's workspace targeting (`workspace_id` and
`workspace_ids` are emptied). Tokens already minted before archive
remain valid until they expire. OAuth callers may only manage rules
whose `oauth_scope` is `workspace:developer` or `workspace:inference`;
other scopes require a Console session.
## Path parameters
- `federation_rule_id: string`
ID of the federation rule to archive.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaFederationRule object`
Authorization rule binding an external OIDC identity to Anthropic.
Evaluates the match conditions and mints an OAuth access token for the
resolved target, scoped to a single workspace where the rule is enabled
(chosen by the caller at exchange time when the rule is enabled for more
than one). For rules enabled via `workspace_ids` or
`applies_to_all_workspaces`, the target service account must be a member
of that workspace (it is implicitly a member of the default workspace);
rules carrying only the legacy `workspace_id` binding do not enforce
this.
- `id: string`
Tagged ID of the federation rule.
- `applies_to_all_workspaces: boolean`
When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
- `archived_at: string or null`
If set, this rule is archived and rejects token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
- `attributes: map[string] or null`
CEL expressions extracting named values from claims. Not yet supported; always null.
- `created_at: string`
When this rule was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this rule.
- `description: string or null`
Optional free-text description.
- `issuer_id: string`
Tagged ID of the issuer whose tokens this rule accepts.
- `issuer_name: string or null`
Issuer's display name at read time.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Admin-chosen slug identifier.
- `oauth_scope: string`
Space-separated OAuth scopes granted on the minted token.
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Service account's display name at read time. Ignored on writes.
- `token_lifetime_seconds: number`
Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
- `type: "federation_rule"`
default: federation_rule
- `updated_at: string`
When this rule was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
- `workspace_id: string or null`
Legacy single-workspace binding. Prefer `workspace_ids` and the `/federation_rules/{federation_rule_id}/workspaces` sub-resource for managing workspace enablement.
- `workspace_ids: array of string`
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty).
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}
```
api/beta/organization/federation/rules/create New page · 389 lines, new page
# Create Federation Rule ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Federation Rule
**POST** `/v1/organizations/federation_rules`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Create a federation rule owned by your organization.
The referenced issuer and the target service account must already exist
in the same organization; invalid references are rejected with a 400
error. The workspace reference is validated. Membership is not checked
at rule creation: token exchange resolves a single enabled workspace per
call and is rejected unless the target service account is a member of
that workspace (it is implicitly a member of the default workspace).
Rules on well-known shared issuers (GitHub Actions, GitLab, Buildkite,
Terraform Cloud, Google) must constrain tenant identity via an
identity-bearing claim, a tenant-pinning subject prefix (such as
`repo:YOUR_ORG/...`), or a CEL condition referencing one of those
identity claims (e.g. `claims.repository_owner`). OAuth callers may only
manage rules whose `oauth_scope` is `workspace:developer` or
`workspace:inference`; other scopes require a Console session.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `issuer_id: string`
Tagged ID of the federation issuer.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. At least one of `subject_prefix` (other than a wildcard-only value like `*`), `claims`, or `condition` is required; `audience` alone is not sufficient.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `oauth_scope: string`
Space-separated OAuth scopes. OAuth callers may only set `workspace:developer` or `workspace:inference`; other scopes (such as `org:admin`) require a Console session.
minLength: 1
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Service account's display name at read time. Ignored on writes.
- `applies_to_all_workspaces: optional boolean`
When true, enable this rule for every workspace in the org (including workspaces created later).
- `attributes: optional map[string] or null`
CEL expressions `{name: expr}` extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.
- `description: optional string or null`
Optional free-text description.
maxLength: 2000
- `token_lifetime_seconds: optional number`
Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
maximum: 86400, minimum: 60
- `workspace_id: optional string or null`
Tagged ID of the workspace to enable this rule for. Required unless `applies_to_all_workspaces` is true. Additional workspaces can be added via the `/federation_rules/{federation_rule_id}/workspaces` sub-resource.
## Returns
- `BetaFederationRule object`
Authorization rule binding an external OIDC identity to Anthropic.
Evaluates the match conditions and mints an OAuth access token for the
resolved target, scoped to a single workspace where the rule is enabled
(chosen by the caller at exchange time when the rule is enabled for more
than one). For rules enabled via `workspace_ids` or
`applies_to_all_workspaces`, the target service account must be a member
of that workspace (it is implicitly a member of the default workspace);
rules carrying only the legacy `workspace_id` binding do not enforce
this.
- `id: string`
Tagged ID of the federation rule.
- `applies_to_all_workspaces: boolean`
When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
- `archived_at: string or null`
If set, this rule is archived and rejects token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
- `attributes: map[string] or null`
CEL expressions extracting named values from claims. Not yet supported; always null.
- `created_at: string`
When this rule was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this rule.
- `description: string or null`
Optional free-text description.
- `issuer_id: string`
Tagged ID of the issuer whose tokens this rule accepts.
- `issuer_name: string or null`
Issuer's display name at read time.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Admin-chosen slug identifier.
- `oauth_scope: string`
Space-separated OAuth scopes granted on the minted token.
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/rules/list New page · 305 lines, new page
# List Federation Rules ## Query parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Federation Rules
**GET** `/v1/organizations/federation_rules`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List federation rules in your organization.
Optionally filter by issuer with `issuer_id`. Archived rules are excluded
unless `include_archived=true`.
## Query parameters
- `include_archived: optional boolean`
Include archived resources. Defaults to false.
default: false
- `issuer_id: optional string`
Filter to rules referencing this federation issuer.
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `data: array of BetaFederationRule`
- `id: string`
Tagged ID of the federation rule.
- `applies_to_all_workspaces: boolean`
When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
- `archived_at: string or null`
If set, this rule is archived and rejects token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
- `attributes: map[string] or null`
CEL expressions extracting named values from claims. Not yet supported; always null.
- `created_at: string`
When this rule was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this rule.
- `description: string or null`
Optional free-text description.
- `issuer_id: string`
Tagged ID of the issuer whose tokens this rule accepts.
- `issuer_name: string or null`
Issuer's display name at read time.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Admin-chosen slug identifier.
- `oauth_scope: string`
Space-separated OAuth scopes granted on the minted token.
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Service account's display name at read time. Ignored on writes.
- `token_lifetime_seconds: number`
Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
- `type: "federation_rule"`
default: federation_rule
- `updated_at: string`
When this rule was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
- `workspace_id: string or null`
Legacy single-workspace binding. Prefer `workspace_ids` and the `/federation_rules/{federation_rule_id}/workspaces` sub-resource for managing workspace enablement.
- `workspace_ids: array of string`
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty).
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/rules/retrieve New page · 288 lines, new page
# Get Federation Rule ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Federation Rule
**GET** `/v1/organizations/federation_rules/{federation_rule_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Retrieve a federation rule by its ID (`fdrl_...`).
## Path parameters
- `federation_rule_id: string`
ID of the federation rule.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaFederationRule object`
Authorization rule binding an external OIDC identity to Anthropic.
Evaluates the match conditions and mints an OAuth access token for the
resolved target, scoped to a single workspace where the rule is enabled
(chosen by the caller at exchange time when the rule is enabled for more
than one). For rules enabled via `workspace_ids` or
`applies_to_all_workspaces`, the target service account must be a member
of that workspace (it is implicitly a member of the default workspace);
rules carrying only the legacy `workspace_id` binding do not enforce
this.
- `id: string`
Tagged ID of the federation rule.
- `applies_to_all_workspaces: boolean`
When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
- `archived_at: string or null`
If set, this rule is archived and rejects token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
- `attributes: map[string] or null`
CEL expressions extracting named values from claims. Not yet supported; always null.
- `created_at: string`
When this rule was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this rule.
- `description: string or null`
Optional free-text description.
- `issuer_id: string`
Tagged ID of the issuer whose tokens this rule accepts.
- `issuer_name: string or null`
Issuer's display name at read time.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Admin-chosen slug identifier.
- `oauth_scope: string`
Space-separated OAuth scopes granted on the minted token.
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Service account's display name at read time. Ignored on writes.
- `token_lifetime_seconds: number`
Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
- `type: "federation_rule"`
default: federation_rule
- `updated_at: string`
When this rule was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
- `workspace_id: string or null`
Legacy single-workspace binding. Prefer `workspace_ids` and the `/federation_rules/{federation_rule_id}/workspaces` sub-resource for managing workspace enablement.
- `workspace_ids: array of string`
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty).
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}
```
api/beta/organization/federation/rules/update New page · 388 lines, new page
# Update Federation Rule ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update Federation Rule
**POST** `/v1/organizations/federation_rules/{federation_rule_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Partially update a federation rule.
`issuer_id` is immutable. `match` and `target` are replaced as whole
objects when set. Referenced service accounts and workspaces must exist
in your organization; invalid references are rejected with a 400 error.
Archived rules cannot be updated; this returns 400. Create a new rule
instead. Rules on well-known shared issuers (GitHub Actions, GitLab,
Buildkite, Terraform Cloud, Google) must constrain tenant identity via
an identity-bearing claim, a tenant-pinning subject prefix (such as
`repo:YOUR_ORG/...`), or a CEL condition referencing one of those
identity claims (e.g. `claims.repository_owner`). On these issuers the
requirement is re-checked on every update; if an existing rule's stored
match does not yet constrain tenant identity, any update (even a rename
or description change) must also supply a conforming `match` in the same
request. OAuth callers may only manage rules whose `oauth_scope` is
`workspace:developer` or `workspace:inference`; other scopes require a
Console session.
## Path parameters
- `federation_rule_id: string`
ID of the federation rule to update.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `applies_to_all_workspaces: optional boolean or null`
When true, enables this rule for every workspace in the org (including workspaces created later). Setting `false` is rejected with 400 if no workspace would remain enabled; a rule with only a legacy `workspace_id` binding continues to mint.
- `attributes: optional map[string] or null`
Replaces the CEL expressions `{name: expr}` extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.
- `description: optional string or null`
Replaces the description. Omit to leave unchanged; send `null` to clear (the field is stored as an empty string).
maxLength: 2000
- `match: optional BetaFederationRuleMatch or null`
Does the incoming JWT qualify?
All populated fields must pass; omitted fields are skipped. At least one
of `subject_prefix` (other than a wildcard-only value like `*`), `claims`,
or `condition` is required; `audience` alone is not sufficient.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: optional string or null`
Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `oauth_scope: optional string or null`
Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set `workspace:developer` or `workspace:inference`; other scopes (such as `org:admin`) require a Console session.
minLength: 1
- `target: optional BetaServiceAccountTarget or null`
Bind to a fixed service account by ID.
- `service_account_id: string`
Tagged ID of the service account to mint tokens for.
- `type: "service_account"`
- `service_account_name: optional string or null`
Service account's display name at read time. Ignored on writes.
- `token_lifetime_seconds: optional number or null`
Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
maximum: 86400, minimum: 60
- `workspace_id: optional string or null`
Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the `/federation_rules/{federation_rule_id}/workspaces` sub-resource instead.
## Returns
- `BetaFederationRule object`
Authorization rule binding an external OIDC identity to Anthropic.
Evaluates the match conditions and mints an OAuth access token for the
resolved target, scoped to a single workspace where the rule is enabled
(chosen by the caller at exchange time when the rule is enabled for more
than one). For rules enabled via `workspace_ids` or
`applies_to_all_workspaces`, the target service account must be a member
of that workspace (it is implicitly a member of the default workspace);
rules carrying only the legacy `workspace_id` binding do not enforce
this.
- `id: string`
Tagged ID of the federation rule.
- `applies_to_all_workspaces: boolean`
When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
- `archived_at: string or null`
If set, this rule is archived and rejects token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
- `attributes: map[string] or null`
CEL expressions extracting named values from claims. Not yet supported; always null.
- `created_at: string`
When this rule was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this rule.
- `description: string or null`
Optional free-text description.
- `issuer_id: string`
Tagged ID of the issuer whose tokens this rule accepts.
- `issuer_name: string or null`
Issuer's display name at read time.
- `match: BetaFederationRuleMatch`
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
- `audience: optional string or null`
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
- `claims: optional map[string] or null`
Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
- `condition: optional string or null`
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
maxLength: 4096
- `subject_prefix: optional string or null`
Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
maxLength: 1024
- `name: string`
Admin-chosen slug identifier.
- `oauth_scope: string`
Space-separated OAuth scopes granted on the minted token.
- `target: BetaServiceAccountTarget`
Identity that tokens minted via this rule act as. Currently always a `service_account` target.
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/rules/workspaces New page · 527 lines, new page
# Workspaces ## Add Federation Rule Workspace ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## List Federation Rule Workspaces ### Path parameters ### Query parameters ### Headers ### Returns ### Example #### Response (200) ## Remove Federation Rule Workspace ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Domain types ### Workspace Remove Response
A whole new page. There's nothing to diff it against, so here is what it says.
# Workspaces
## Add Federation Rule Workspace
**POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Enable a federation rule for a workspace.
Idempotent; re-enabling returns the existing enablement. The rule and
workspace must both belong to your organization. Membership of the
rule's target service account in this workspace is not checked at
enablement: token exchange into this workspace is rejected unless the
target is a member (it is implicitly a member of the default workspace).
Archived rules are rejected with 400. OAuth callers may only manage rules
whose `oauth_scope` is `workspace:developer` or `workspace:inference`;
other scopes require a Console session.
### Path parameters
- `federation_rule_id: string`
ID of the federation rule.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Body parameters
- `workspace_id: string`
Tagged ID of the workspace to enable this rule for.
### Returns
- `BetaFederationRuleWorkspace object`
- `created_at: string`
When this workspace was enabled for the rule.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known.
- `federation_rule_id: string`
Tagged ID of the federation rule.
- `type: "federation_rule_workspace"`
default: federation_rule_workspace
- `workspace_id: string`
Tagged ID of the workspace this rule is enabled for.
- `workspace_name: string or null`
Workspace display name. Populated when listing; null in the enable response.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_id": "workspace_id"
}'
```
#### Response (200)
```json
{
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"federation_rule_id": "federation_rule_id",
"type": "federation_rule_workspace",
"workspace_id": "workspace_id",
"workspace_name": "workspace_name"
}
```
## List Federation Rule Workspaces
**GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List workspaces where this federation rule is enabled.
Returns all workspace enablements in a single response; the `limit` and
`page` parameters are accepted but have no effect, and `next_page` is
always `null`. Returns explicit per-workspace enablements only; for
rules with `applies_to_all_workspaces` or a legacy single
`workspace_id`, check those fields on the rule itself.
### Path parameters
- `federation_rule_id: string`
ID of the federation rule.
### Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
Cut at 300 lines. The page has the rest.
api/beta/organization/federation/rules/workspaces/add New page · 175 lines, new page
# Add Federation Rule Workspace ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Add Federation Rule Workspace
**POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Enable a federation rule for a workspace.
Idempotent; re-enabling returns the existing enablement. The rule and
workspace must both belong to your organization. Membership of the
rule's target service account in this workspace is not checked at
enablement: token exchange into this workspace is rejected unless the
target is a member (it is implicitly a member of the default workspace).
Archived rules are rejected with 400. OAuth callers may only manage rules
whose `oauth_scope` is `workspace:developer` or `workspace:inference`;
other scopes require a Console session.
## Path parameters
- `federation_rule_id: string`
ID of the federation rule.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `workspace_id: string`
Tagged ID of the workspace to enable this rule for.
## Returns
- `BetaFederationRuleWorkspace object`
- `created_at: string`
When this workspace was enabled for the rule.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known.
- `federation_rule_id: string`
Tagged ID of the federation rule.
- `type: "federation_rule_workspace"`
default: federation_rule_workspace
- `workspace_id: string`
Tagged ID of the workspace this rule is enabled for.
- `workspace_name: string or null`
Workspace display name. Populated when listing; null in the enable response.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_id": "workspace_id"
}'
```
### Response (200)
```json
{
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"federation_rule_id": "federation_rule_id",
"type": "federation_rule_workspace",
"workspace_id": "workspace_id",
"workspace_name": "workspace_name"
}
```
api/beta/organization/federation/rules/workspaces/list New page · 183 lines, new page
# List Federation Rule Workspaces ## Path parameters ## Query parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Federation Rule Workspaces
**GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List workspaces where this federation rule is enabled.
Returns all workspace enablements in a single response; the `limit` and
`page` parameters are accepted but have no effect, and `next_page` is
always `null`. Returns explicit per-workspace enablements only; for
rules with `applies_to_all_workspaces` or a legacy single
`workspace_id`, check those fields on the rule itself.
## Path parameters
- `federation_rule_id: string`
ID of the federation rule.
## Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `data: array of BetaFederationRuleWorkspace`
- `created_at: string`
When this workspace was enabled for the rule.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known.
- `federation_rule_id: string`
Tagged ID of the federation rule.
- `type: "federation_rule_workspace"`
default: federation_rule_workspace
- `workspace_id: string`
Tagged ID of the workspace this rule is enabled for.
- `workspace_name: string or null`
Workspace display name. Populated when listing; null in the enable response.
- `next_page: string or null`
Opaque cursor for the next page; null when there are no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"federation_rule_id": "federation_rule_id",
"type": "federation_rule_workspace",
"workspace_id": "workspace_id",
"workspace_name": "workspace_name"
}
],
"next_page": "next_page"
}
```
api/beta/organization/federation/rules/workspaces/remove New page · 147 lines, new page
# Remove Federation Rule Workspace ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Remove Federation Rule Workspace
**DELETE** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Disable a federation rule for a workspace.
Idempotent; succeeds even if the enablement was already removed. OAuth
callers may only manage rules whose `oauth_scope` is
`workspace:developer` or `workspace:inference`; other scopes require a
Console session.
## Path parameters
- `federation_rule_id: string`
ID of the federation rule.
- `workspace_id: string`
ID of the workspace to disable for.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `federation_rule_id: string`
Tagged ID of the federation rule.
- `type: "federation_rule_workspace_deleted"`
default: federation_rule_workspace_deleted
- `workspace_id: string`
Tagged ID of the workspace named in the delete request. Removal is idempotent.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces/$WORKSPACE_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"federation_rule_id": "federation_rule_id",
"type": "federation_rule_workspace_deleted",
"workspace_id": "workspace_id"
}
```
api/beta/organization/invites New page · 565 lines, new page
# Invites ## Create Invite ### Body parameters ### Returns ### Example #### Response (200) ## List Invites ### Query parameters ### Returns ### Example #### Response (200) ## Get Invite ### Path parameters ### Returns ### Example #### Response (200) ## Delete Invite ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta Organization Invite ### Invite Delete Response
A whole new page. There's nothing to diff it against, so here is what it says.
# Invites
## Create Invite
**POST** `/v1/organizations/invites`
Invite a user to join the organization by email.
On plans that draw members from a finite pool of purchased seats, the invite automatically consumes a seat from the lowest tier with availability; there is no seat-tier parameter. When no seat is free the request fails with a 400 error rather than purchasing a seat.
### Body parameters
- `email: string`
Email of the User.
format: email
- `role: "billing" or "claude_code_user" or "developer" or 2 more`
Role for the invited User.
The accepted values depend on the organization type. Console and API organizations accept `user`, `developer`, `billing`, and `claude_code_user`; `admin` cannot be assigned through the API. Claude Enterprise organizations accept `user` and `managed`.
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"user"`
- `rbac_group_ids: optional array of string`
RBAC group IDs to assign to the User when the Invite is accepted. A non-empty array is accepted only for a Claude Enterprise organization with RBAC groups, and requires the key to carry the `write:rbac_groups` scope.
maxItems: 100
### Returns
- `BetaOrganizationInvite object`
- `id: string`
ID of the Invite.
- `accepted_at: string or null`
RFC 3339 datetime string indicating when the Invite was accepted, or null.
format: date-time
- `email: string`
Email of the User being invited.
- `expires_at: string`
RFC 3339 datetime string indicating when the Invite expires.
format: date-time
- `invited_at: string`
RFC 3339 datetime string indicating when the Invite was created.
format: date-time
- `rbac_group_ids: array of string`
RBAC group IDs recorded on the Invite (Claude Enterprise organizations), to be assigned to the User when the Invite is accepted. `[]` when none.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `status: "accepted" or "deleted" or "expired" or "pending"`
Status of the Invite.
- `"accepted"`
- `"deleted"`
- `"expired"`
- `"pending"`
- `type: "invite"`
Object type.
For Invites, this is always `"invite"`.
default: invite
### Example
```bash
curl https://api.anthropic.com/v1/organizations/invites \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"email": "[email protected]",
"role": "user"
}'
```
#### Response (200)
```json
{
"id": "invite_015gWxCN9Hfg2QhZwTK7Mdeu",
"accepted_at": "2019-12-27T18:11:19.117Z",
"email": "[email protected]",
"expires_at": "2024-11-20T23:58:27.427722Z",
"invited_at": "2024-10-30T23:58:27.427722Z",
"rbac_group_ids": [
"string"
],
"role": "admin",
"status": "pending",
"type": "invite"
}
```
## List Invites
**GET** `/v1/organizations/invites`
List the organization's invites.
### Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `email: optional string`
Filter by the email address the Invite was sent to. Matches the same way as the Users list's `email` filter (normalized, case-insensitive).
format: email
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `roles: optional array of string`
Filter to items whose `role` equals one of the supplied values. Repeatable; values are OR'ed together.
Accepted values depend on the organization type: Console and API organizations accept `user`, `developer`, `billing`, `admin`, and `claude_code_user`; Claude Enterprise organizations accept `user`, `owner`, `primary_owner`, `membership_admin`, and `managed`.
- `statuses: optional array of "accepted" or "expired" or "pending"`
Filter by Invite status. Repeatable; values are OR'ed together. Omit to return `pending`, `accepted`, and `expired` Invites alike.
- `"accepted"`
- `"expired"`
- `"pending"`
### Returns
- `data: array of BetaOrganizationInvite`
- `id: string`
ID of the Invite.
- `accepted_at: string or null`
RFC 3339 datetime string indicating when the Invite was accepted, or null.
format: date-time
- `email: string`
Email of the User being invited.
- `expires_at: string`
RFC 3339 datetime string indicating when the Invite expires.
format: date-time
- `invited_at: string`
RFC 3339 datetime string indicating when the Invite was created.
format: date-time
- `rbac_group_ids: array of string`
RBAC group IDs recorded on the Invite (Claude Enterprise organizations), to be assigned to the User when the Invite is accepted. `[]` when none.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `status: "accepted" or "deleted" or "expired" or "pending"`
Status of the Invite.
- `"accepted"`
- `"deleted"`
- `"expired"`
- `"pending"`
- `type: "invite"`
Object type.
For Invites, this is always `"invite"`.
default: invite
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/invites \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"id": "invite_015gWxCN9Hfg2QhZwTK7Mdeu",
"accepted_at": "2019-12-27T18:11:19.117Z",
"email": "[email protected]",
"expires_at": "2024-11-20T23:58:27.427722Z",
"invited_at": "2024-10-30T23:58:27.427722Z",
Cut at 300 lines. The page has the rest.
api/beta/organization/invites/create New page · 144 lines, new page
# Create Invite ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Invite
**POST** `/v1/organizations/invites`
Invite a user to join the organization by email.
On plans that draw members from a finite pool of purchased seats, the invite automatically consumes a seat from the lowest tier with availability; there is no seat-tier parameter. When no seat is free the request fails with a 400 error rather than purchasing a seat.
## Body parameters
- `email: string`
Email of the User.
format: email
- `role: "billing" or "claude_code_user" or "developer" or 2 more`
Role for the invited User.
The accepted values depend on the organization type. Console and API organizations accept `user`, `developer`, `billing`, and `claude_code_user`; `admin` cannot be assigned through the API. Claude Enterprise organizations accept `user` and `managed`.
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"user"`
- `rbac_group_ids: optional array of string`
RBAC group IDs to assign to the User when the Invite is accepted. A non-empty array is accepted only for a Claude Enterprise organization with RBAC groups, and requires the key to carry the `write:rbac_groups` scope.
maxItems: 100
## Returns
- `BetaOrganizationInvite object`
- `id: string`
ID of the Invite.
- `accepted_at: string or null`
RFC 3339 datetime string indicating when the Invite was accepted, or null.
format: date-time
- `email: string`
Email of the User being invited.
- `expires_at: string`
RFC 3339 datetime string indicating when the Invite expires.
format: date-time
- `invited_at: string`
RFC 3339 datetime string indicating when the Invite was created.
format: date-time
- `rbac_group_ids: array of string`
RBAC group IDs recorded on the Invite (Claude Enterprise organizations), to be assigned to the User when the Invite is accepted. `[]` when none.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `status: "accepted" or "deleted" or "expired" or "pending"`
Status of the Invite.
- `"accepted"`
- `"deleted"`
- `"expired"`
- `"pending"`
- `type: "invite"`
Object type.
For Invites, this is always `"invite"`.
default: invite
## Example
```bash
curl https://api.anthropic.com/v1/organizations/invites \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"email": "[email protected]",
"role": "user"
}'
```
### Response (200)
```json
{
"id": "invite_015gWxCN9Hfg2QhZwTK7Mdeu",
"accepted_at": "2019-12-27T18:11:19.117Z",
"email": "[email protected]",
"expires_at": "2024-11-20T23:58:27.427722Z",
"invited_at": "2024-10-30T23:58:27.427722Z",
"rbac_group_ids": [
"string"
],
"role": "admin",
"status": "pending",
"type": "invite"
}
```
api/beta/organization/invites/delete New page · 43 lines, new page
# Delete Invite ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Delete Invite
**DELETE** `/v1/organizations/invites/{invite_id}`
Delete a pending invite.
## Path parameters
- `invite_id: string`
ID of the Invite.
## Returns
- `id: string`
ID of the Invite.
- `type: "invite_deleted"`
Deleted object type.
For Invites, this is always `"invite_deleted"`.
default: invite_deleted
## Example
```bash
curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "invite_015gWxCN9Hfg2QhZwTK7Mdeu",
"type": "invite_deleted"
}
```
api/beta/organization/invites/list New page · 166 lines, new page
# List Invites ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Invites
**GET** `/v1/organizations/invites`
List the organization's invites.
## Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `email: optional string`
Filter by the email address the Invite was sent to. Matches the same way as the Users list's `email` filter (normalized, case-insensitive).
format: email
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `roles: optional array of string`
Filter to items whose `role` equals one of the supplied values. Repeatable; values are OR'ed together.
Accepted values depend on the organization type: Console and API organizations accept `user`, `developer`, `billing`, `admin`, and `claude_code_user`; Claude Enterprise organizations accept `user`, `owner`, `primary_owner`, `membership_admin`, and `managed`.
- `statuses: optional array of "accepted" or "expired" or "pending"`
Filter by Invite status. Repeatable; values are OR'ed together. Omit to return `pending`, `accepted`, and `expired` Invites alike.
- `"accepted"`
- `"expired"`
- `"pending"`
## Returns
- `data: array of BetaOrganizationInvite`
- `id: string`
ID of the Invite.
- `accepted_at: string or null`
RFC 3339 datetime string indicating when the Invite was accepted, or null.
format: date-time
- `email: string`
Email of the User being invited.
- `expires_at: string`
RFC 3339 datetime string indicating when the Invite expires.
format: date-time
- `invited_at: string`
RFC 3339 datetime string indicating when the Invite was created.
format: date-time
- `rbac_group_ids: array of string`
RBAC group IDs recorded on the Invite (Claude Enterprise organizations), to be assigned to the User when the Invite is accepted. `[]` when none.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `status: "accepted" or "deleted" or "expired" or "pending"`
Status of the Invite.
- `"accepted"`
- `"deleted"`
- `"expired"`
- `"pending"`
- `type: "invite"`
Object type.
For Invites, this is always `"invite"`.
default: invite
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/invites \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "invite_015gWxCN9Hfg2QhZwTK7Mdeu",
"accepted_at": "2019-12-27T18:11:19.117Z",
"email": "[email protected]",
"expires_at": "2024-11-20T23:58:27.427722Z",
"invited_at": "2024-10-30T23:58:27.427722Z",
"rbac_group_ids": [
"string"
],
"role": "admin",
"status": "pending",
"type": "invite"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
api/beta/organization/invites/retrieve New page · 113 lines, new page
# Get Invite ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Invite
**GET** `/v1/organizations/invites/{invite_id}`
Retrieve an invite by ID.
## Path parameters
- `invite_id: string`
ID of the Invite.
## Returns
- `BetaOrganizationInvite object`
- `id: string`
ID of the Invite.
- `accepted_at: string or null`
RFC 3339 datetime string indicating when the Invite was accepted, or null.
format: date-time
- `email: string`
Email of the User being invited.
- `expires_at: string`
RFC 3339 datetime string indicating when the Invite expires.
format: date-time
- `invited_at: string`
RFC 3339 datetime string indicating when the Invite was created.
format: date-time
- `rbac_group_ids: array of string`
RBAC group IDs recorded on the Invite (Claude Enterprise organizations), to be assigned to the User when the Invite is accepted. `[]` when none.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `status: "accepted" or "deleted" or "expired" or "pending"`
Status of the Invite.
- `"accepted"`
- `"deleted"`
- `"expired"`
- `"pending"`
- `type: "invite"`
Object type.
For Invites, this is always `"invite"`.
default: invite
## Example
```bash
curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "invite_015gWxCN9Hfg2QhZwTK7Mdeu",
"accepted_at": "2019-12-27T18:11:19.117Z",
"email": "[email protected]",
"expires_at": "2024-11-20T23:58:27.427722Z",
"invited_at": "2024-10-30T23:58:27.427722Z",
"rbac_group_ids": [
"string"
],
"role": "admin",
"status": "pending",
"type": "invite"
}
```
api/beta/organization/rate_limits New page · 193 lines, new page
# Rate Limits ## List Organization Rate Limits ### Query parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta Organization Rate Limit ### Beta Organization Rate Limit Value
A whole new page. There's nothing to diff it against, so here is what it says.
# Rate Limits
## List Organization Rate Limits
**GET** `/v1/organizations/rate_limits`
List Messages API rate limits for your organization.
Each entry corresponds to one rate-limit group (either a model family
or an API-surface category such as the Files API or Message Batches)
and contains the set of limiter values that apply to it.
This endpoint currently returns every matching entry in a single page
regardless of `limit`; follow `next_page` so that clients keep working
when pagination is enabled.
### Query parameters
- `group_type: optional "batch" or "files" or "model_group" or 3 more`
Filter by group type.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limit: optional number`
Maximum number of items to return per page. Ranges from `1` to `1000`.
Accepted for request-shape compatibility and currently ignored: every entry is returned in a single page.
maximum: 1000, minimum: 1
- `model: optional string`
Filter to the single entry containing this model. Accepts full model names and aliases. Returns 404 if the model is not found or has no rate limits for this organization.
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Returns
- `data: array of BetaOrganizationRateLimit`
Rate-limit entries for the organization, one per group.
- `id: string`
Stable identifier for this rate-limit group within the organization.
- `group_type: "batch" or "files" or "model_group" or 3 more`
The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limits: array of BetaOrganizationRateLimitValue`
The limiter values that apply to this group.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The configured limit value for this limiter type.
- `models: array of string or null`
Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`.
- `type: "rate_limit"`
Object type. Always `rate_limit` for organization rate-limit entries.
default: rate_limit
- `next_page: string or null`
Token to provide in as `page` in the subsequent request to retrieve the next page of data.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/rate_limits \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"id": "id",
"group_type": "batch",
"limits": [
{
"type": "type",
"value": 0
}
],
"models": [
"string"
],
"type": "rate_limit"
}
],
"next_page": "next_page"
}
```
## Domain types
### Beta Organization Rate Limit
- `BetaOrganizationRateLimit object`
- `id: string`
Stable identifier for this rate-limit group within the organization.
- `group_type: "batch" or "files" or "model_group" or 3 more`
The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limits: array of BetaOrganizationRateLimitValue`
The limiter values that apply to this group.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The configured limit value for this limiter type.
- `models: array of string or null`
Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`.
- `type: "rate_limit"`
Object type. Always `rate_limit` for organization rate-limit entries.
default: rate_limit
### Beta Organization Rate Limit Value
- `BetaOrganizationRateLimitValue object`
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The configured limit value for this limiter type.
api/beta/organization/rate_limits/list New page · 131 lines, new page
# List Organization Rate Limits ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Organization Rate Limits
**GET** `/v1/organizations/rate_limits`
List Messages API rate limits for your organization.
Each entry corresponds to one rate-limit group (either a model family
or an API-surface category such as the Files API or Message Batches)
and contains the set of limiter values that apply to it.
This endpoint currently returns every matching entry in a single page
regardless of `limit`; follow `next_page` so that clients keep working
when pagination is enabled.
## Query parameters
- `group_type: optional "batch" or "files" or "model_group" or 3 more`
Filter by group type.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limit: optional number`
Maximum number of items to return per page. Ranges from `1` to `1000`.
Accepted for request-shape compatibility and currently ignored: every entry is returned in a single page.
maximum: 1000, minimum: 1
- `model: optional string`
Filter to the single entry containing this model. Accepts full model names and aliases. Returns 404 if the model is not found or has no rate limits for this organization.
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Returns
- `data: array of BetaOrganizationRateLimit`
Rate-limit entries for the organization, one per group.
- `id: string`
Stable identifier for this rate-limit group within the organization.
- `group_type: "batch" or "files" or "model_group" or 3 more`
The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limits: array of BetaOrganizationRateLimitValue`
The limiter values that apply to this group.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The configured limit value for this limiter type.
- `models: array of string or null`
Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`.
- `type: "rate_limit"`
Object type. Always `rate_limit` for organization rate-limit entries.
default: rate_limit
- `next_page: string or null`
Token to provide in as `page` in the subsequent request to retrieve the next page of data.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/rate_limits \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "id",
"group_type": "batch",
"limits": [
{
"type": "type",
"value": 0
}
],
"models": [
"string"
],
"type": "rate_limit"
}
],
"next_page": "next_page"
}
```
api/beta/organization/retrieve New page · 45 lines, new page
# Get Current Organization ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Current Organization
**GET** `/v1/organizations/me`
Retrieve information about the organization associated with the authenticated API key.
## Returns
- `BetaOrganization object`
- `id: string`
ID of the Organization.
format: uuid
- `name: string`
Name of the Organization.
- `type: "organization"`
Object type.
For Organizations, this is always `"organization"`.
default: organization
## Example
```bash
curl https://api.anthropic.com/v1/organizations/me \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "12345678-1234-5678-1234-567812345678",
"name": "Organization Name",
"type": "organization"
}
```
api/beta/organization/service_accounts New page · 1704 lines, new page
# Service Accounts ## Create Service Account ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## List Service Accounts ### Query parameters ### Headers ### Returns ### Example #### Response (200) ## Get Service Account ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Update Service Account ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## Archive Service Account ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Domain types ### Beta Service Account ### Beta Service Account Workspace Member ## Service Accounts › Workspaces ### Add Workspace To Service Account #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### List Workspaces For Service Account #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Remove Workspace From Service Account #### Path parameters #### Headers #### Returns #### Example ##### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Service Accounts
## Create Service Account
**POST** `/v1/organizations/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Create a service account.
A service account is a named workload identity that federation rules
target. `organization_role` is `developer` (default) or `admin`; a rule
may only be created or retargeted to grant `org:admin` scope when the
target's `organization_role` is `admin`. Creating an `admin`-role service
account requires an interactive credential (a user OAuth token or a
Console session) — a workload may only create `developer`-role service
accounts.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Body parameters
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `description: optional string or null`
Optional free-text description.
maxLength: 2000
- `organization_role: optional "admin" or "developer"`
Org-level role. Defaults to `developer`.
- `"admin"`
- `"developer"`
### Returns
- `BetaServiceAccount object`
Named non-human identity within the caller's organization.
A service account is a pure identity: name + org. Authorization lives on
whatever references it (federation rules).
- `id: string`
Tagged ID of the service account.
- `archived_at: string or null`
If set, this service account is archived.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
- `created_at: string`
When this service account was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this service account.
- `description: string or null`
Optional free-text description.
- `name: string`
Admin-chosen slug identifier.
- `organization_role: "admin" or "developer"`
Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
- `"admin"`
- `"developer"`
- `type: "service_account"`
default: service_account
- `updated_at: string`
When this service account was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"name": "ci-deploy-bot"
}'
```
#### Response (200)
```json
{
"id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"name": "ci-deploy-bot",
"organization_role": "admin",
"type": "service_account",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
## List Service Accounts
**GET** `/v1/organizations/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List service accounts in the caller's organization.
Results are ordered by creation time, newest first. Use `limit` and the
`next_page` cursor to paginate; set `include_archived=true` to include
archived service accounts.
### Query parameters
- `include_archived: optional boolean`
Include archived resources. Defaults to false.
default: false
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
Cut at 300 lines. The page has the rest.
api/beta/organization/service_accounts/archive New page · 200 lines, new page
# Archive Service Account ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Archive Service Account
**POST** `/v1/organizations/service_accounts/{service_account_id}/archive`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Archive a service account.
Idempotent; re-archiving returns the service account with its original
`archived_at`. Rejected with 400 if any live (non-archived) federation
rule still targets this service account, same as issuer archival; archive
those rules first or change their target to another service account.
## Path parameters
- `service_account_id: string`
ID of the service account to archive.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaServiceAccount object`
Named non-human identity within the caller's organization.
A service account is a pure identity: name + org. Authorization lives on
whatever references it (federation rules).
- `id: string`
Tagged ID of the service account.
- `archived_at: string or null`
If set, this service account is archived.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
- `created_at: string`
When this service account was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this service account.
- `description: string or null`
Optional free-text description.
- `name: string`
Admin-chosen slug identifier.
- `organization_role: "admin" or "developer"`
Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
- `"admin"`
- `"developer"`
- `type: "service_account"`
default: service_account
- `updated_at: string`
When this service account was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"name": "ci-deploy-bot",
"organization_role": "admin",
"type": "service_account",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
api/beta/organization/service_accounts/create New page · 222 lines, new page
# Create Service Account ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Service Account
**POST** `/v1/organizations/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Create a service account.
A service account is a named workload identity that federation rules
target. `organization_role` is `developer` (default) or `admin`; a rule
may only be created or retargeted to grant `org:admin` scope when the
target's `organization_role` is `admin`. Creating an `admin`-role service
account requires an interactive credential (a user OAuth token or a
Console session) — a workload may only create `developer`-role service
accounts.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
maxLength: 255, minLength: 1
- `description: optional string or null`
Optional free-text description.
maxLength: 2000
- `organization_role: optional "admin" or "developer"`
Org-level role. Defaults to `developer`.
- `"admin"`
- `"developer"`
## Returns
- `BetaServiceAccount object`
Named non-human identity within the caller's organization.
A service account is a pure identity: name + org. Authorization lives on
whatever references it (federation rules).
- `id: string`
Tagged ID of the service account.
- `archived_at: string or null`
If set, this service account is archived.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
- `created_at: string`
When this service account was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this service account.
- `description: string or null`
Optional free-text description.
- `name: string`
Admin-chosen slug identifier.
- `organization_role: "admin" or "developer"`
Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
- `"admin"`
- `"developer"`
- `type: "service_account"`
default: service_account
- `updated_at: string`
When this service account was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"name": "ci-deploy-bot"
}'
```
### Response (200)
```json
{
"id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"name": "ci-deploy-bot",
"organization_role": "admin",
"type": "service_account",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
api/beta/organization/service_accounts/list New page · 214 lines, new page
# List Service Accounts ## Query parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Service Accounts
**GET** `/v1/organizations/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List service accounts in the caller's organization.
Results are ordered by creation time, newest first. Use `limit` and the
`next_page` cursor to paginate; set `include_archived=true` to include
archived service accounts.
## Query parameters
- `include_archived: optional boolean`
Include archived resources. Defaults to false.
default: false
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `data: array of BetaServiceAccount`
- `id: string`
Tagged ID of the service account.
- `archived_at: string or null`
If set, this service account is archived.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
- `created_at: string`
When this service account was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this service account.
- `description: string or null`
Optional free-text description.
- `name: string`
Admin-chosen slug identifier.
- `organization_role: "admin" or "developer"`
Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
- `"admin"`
- `"developer"`
- `type: "service_account"`
default: service_account
- `updated_at: string`
When this service account was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"name": "ci-deploy-bot",
"organization_role": "admin",
"type": "service_account",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
],
"next_page": "next_page"
}
```
api/beta/organization/service_accounts/retrieve New page · 194 lines, new page
# Get Service Account ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Service Account
**GET** `/v1/organizations/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Retrieve a service account by its ID (`svac_...`).
## Path parameters
- `service_account_id: string`
ID of the service account.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaServiceAccount object`
Named non-human identity within the caller's organization.
A service account is a pure identity: name + org. Authorization lives on
whatever references it (federation rules).
- `id: string`
Tagged ID of the service account.
- `archived_at: string or null`
If set, this service account is archived.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
- `created_at: string`
When this service account was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this service account.
- `description: string or null`
Optional free-text description.
- `name: string`
Admin-chosen slug identifier.
- `organization_role: "admin" or "developer"`
Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
- `"admin"`
- `"developer"`
- `type: "service_account"`
default: service_account
- `updated_at: string`
When this service account was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"name": "ci-deploy-bot",
"organization_role": "admin",
"type": "service_account",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
api/beta/organization/service_accounts/update New page · 217 lines, new page
# Update Service Account ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update Service Account
**POST** `/v1/organizations/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Update a service account.
Only `description` and `organization_role` are mutable; `name` cannot be
changed. Archived service accounts cannot be updated; this returns 400.
Setting `organization_role` to `admin` (even when unchanged) requires an
interactive credential (a user OAuth token or a Console session).
## Path parameters
- `service_account_id: string`
ID of the service account to update.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `description: optional string or null`
Replaces the description. Omit to leave unchanged; send `null` to clear (the field is stored as an empty string).
maxLength: 2000
- `organization_role: optional "admin" or "developer" or null`
Replaces the org-level role. Omit or send `null` to leave unchanged.
- `"admin"`
- `"developer"`
## Returns
- `BetaServiceAccount object`
Named non-human identity within the caller's organization.
A service account is a pure identity: name + org. Authorization lives on
whatever references it (federation rules).
- `id: string`
Tagged ID of the service account.
- `archived_at: string or null`
If set, this service account is archived.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
- `created_at: string`
When this service account was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this service account.
- `description: string or null`
Optional free-text description.
- `name: string`
Admin-chosen slug identifier.
- `organization_role: "admin" or "developer"`
Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
- `"admin"`
- `"developer"`
- `type: "service_account"`
default: service_account
- `updated_at: string`
When this service account was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{}'
```
### Response (200)
```json
{
"id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"name": "ci-deploy-bot",
"organization_role": "admin",
"type": "service_account",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
api/beta/organization/service_accounts/workspaces New page · 565 lines, new page
# Workspaces ## Add Workspace To Service Account ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## List Workspaces For Service Account ### Path parameters ### Query parameters ### Headers ### Returns ### Example #### Response (200) ## Remove Workspace From Service Account ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Domain types ### Workspace Remove Response
A whole new page. There's nothing to diff it against, so here is what it says.
# Workspaces
## Add Workspace To Service Account
**POST** `/v1/organizations/service_accounts/{service_account_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Add a service account to a workspace with the given `workspace_role`.
Mirror of `POST /workspaces/{workspace_id}/service_accounts`, addressed
from the service-account side; both create the same membership. If the
service account is already an explicit member of the workspace, its
`workspace_role` is replaced with the value supplied here. Archived
workspaces return 400. Archived service accounts cannot be added and are
rejected.
### Path parameters
- `service_account_id: string`
ID of the service account.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Body parameters
- `workspace_id: string`
Tagged workspace ID to add the service account to.
- `workspace_role: BetaNoBillingWorkspaceRole`
Role to assign to the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Returns
- `BetaServiceAccountWorkspaceMember object`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}'
```
#### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
## List Workspaces For Service Account
**GET** `/v1/organizations/service_accounts/{service_account_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List the workspaces a service account is a member of.
Each entry includes the service account's `workspace_role` in that
workspace. Use `limit` and the `next_page` cursor to paginate. When the
service account has no explicit default-workspace membership, the
implicit (`implicit: true`) membership is returned as the first entry on
the first page; with `limit=1` the first page may return up to 2 entries
(the implicit entry plus one explicit membership) so a pagination cursor
can be derived. Memberships are returned only while
the service account is active. Without a `page` cursor, an archived
service account returns an empty list. A `page` cursor that does not
match an active membership returns a 400 invalid-request error. A cursor
stops matching when the membership is removed, the workspace is deleted,
or the service account is archived. Restart pagination from the first
page to recover.
### Path parameters
- `service_account_id: string`
ID of the service account.
### Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
Cut at 300 lines. The page has the rest.
api/beta/organization/service_accounts/workspaces/add New page · 194 lines, new page
# Add Workspace To Service Account ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Add Workspace To Service Account
**POST** `/v1/organizations/service_accounts/{service_account_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Add a service account to a workspace with the given `workspace_role`.
Mirror of `POST /workspaces/{workspace_id}/service_accounts`, addressed
from the service-account side; both create the same membership. If the
service account is already an explicit member of the workspace, its
`workspace_role` is replaced with the value supplied here. Archived
workspaces return 400. Archived service accounts cannot be added and are
rejected.
## Path parameters
- `service_account_id: string`
ID of the service account.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `workspace_id: string`
Tagged workspace ID to add the service account to.
- `workspace_role: BetaNoBillingWorkspaceRole`
Role to assign to the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Returns
- `BetaServiceAccountWorkspaceMember object`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}'
```
### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/service_accounts/workspaces/list New page · 199 lines, new page
# List Workspaces For Service Account ## Path parameters ## Query parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Workspaces For Service Account
**GET** `/v1/organizations/service_accounts/{service_account_id}/workspaces`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List the workspaces a service account is a member of.
Each entry includes the service account's `workspace_role` in that
workspace. Use `limit` and the `next_page` cursor to paginate. When the
service account has no explicit default-workspace membership, the
implicit (`implicit: true`) membership is returned as the first entry on
the first page; with `limit=1` the first page may return up to 2 entries
(the implicit entry plus one explicit membership) so a pagination cursor
can be derived. Memberships are returned only while
the service account is active. Without a `page` cursor, an archived
service account returns an empty list. A `page` cursor that does not
match an active membership returns a 400 invalid-request error. A cursor
stops matching when the membership is removed, the workspace is deleted,
or the service account is archived. Restart pagination from the first
page to recover.
## Path parameters
- `service_account_id: string`
ID of the service account.
## Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `data: array of BetaServiceAccountWorkspaceMember`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
],
"next_page": "next_page"
}
```
api/beta/organization/service_accounts/workspaces/remove New page · 150 lines, new page
# Remove Workspace From Service Account ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Remove Workspace From Service Account
**DELETE** `/v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Remove a service account from a workspace.
Mirror of `DELETE /workspaces/{workspace_id}/service_accounts/{service_account_id}`,
addressed from the service-account side. Removal is idempotent (returns
200 even if the membership was already removed). A DELETE against the
implicit default-workspace membership returns 200 but is a no-op and the
membership persists; deleting an explicit default-workspace row reverts
to the implicit `workspace_user` membership. Archived workspaces return
400.
## Path parameters
- `service_account_id: string`
ID of the service account.
- `workspace_id: string`
ID of the workspace.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `service_account_id: string`
Tagged service account ID (`svac_...`) named in the delete request. Removal is idempotent; see the endpoint description for the implicit-membership no-op.
- `type: "service_account_workspace_member_deleted"`
default: service_account_workspace_member_deleted
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`) named in the delete request.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces/$WORKSPACE_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"service_account_id": "service_account_id",
"type": "service_account_workspace_member_deleted",
"workspace_id": "workspace_id"
}
```
api/beta/organization/users New page · 435 lines, new page
# Users ## List Users ### Query parameters ### Returns ### Example #### Response (200) ## Get User ### Path parameters ### Returns ### Example #### Response (200) ## Update User ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Remove User ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta Organization User ### User Remove Response
A whole new page. There's nothing to diff it against, so here is what it says.
# Users
## List Users
**GET** `/v1/organizations/users`
List the organization's members.
### Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `email: optional string`
Filter by user email.
format: email
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `roles: optional array of string`
Filter to items whose `role` equals one of the supplied values. Repeatable; values are OR'ed together.
Accepted values depend on the organization type: Console and API organizations accept `user`, `developer`, `billing`, `admin`, and `claude_code_user`; Claude Enterprise organizations accept `user`, `owner`, `primary_owner`, `membership_admin`, and `managed`.
### Returns
- `data: array of BetaOrganizationUser`
- `id: string`
ID of the User.
- `added_at: string`
RFC 3339 datetime string indicating when the User joined the Organization.
format: date-time
- `email: string`
Email of the User.
- `name: string`
Name of the User.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `type: "user"`
Object type.
For Users, this is always `"user"`.
default: user
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/users \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"added_at": "2024-10-30T23:58:27.427722Z",
"email": "[email protected]",
"name": "Jane Doe",
"role": "admin",
"type": "user"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
## Get User
**GET** `/v1/organizations/users/{user_id}`
Retrieve a member of the organization by user ID.
### Path parameters
- `user_id: string`
ID of the User.
### Returns
- `BetaOrganizationUser object`
- `id: string`
ID of the User.
- `added_at: string`
RFC 3339 datetime string indicating when the User joined the Organization.
format: date-time
- `email: string`
Email of the User.
- `name: string`
Name of the User.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `type: "user"`
Object type.
For Users, this is always `"user"`.
default: user
### Example
```bash
curl https://api.anthropic.com/v1/organizations/users/$USER_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"added_at": "2024-10-30T23:58:27.427722Z",
"email": "[email protected]",
"name": "Jane Doe",
"role": "admin",
"type": "user"
}
```
## Update User
**POST** `/v1/organizations/users/{user_id}`
Update a member's organization role.
### Path parameters
- `user_id: string`
ID of the User.
### Body parameters
- `role: "billing" or "claude_code_user" or "developer" or 2 more`
New role for the User.
The accepted values depend on the organization type. Console and API organizations accept `user`, `developer`, `billing`, and `claude_code_user`; `admin` cannot be assigned through the API. Claude Enterprise organizations accept `user` and `managed`.
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"user"`
### Returns
- `BetaOrganizationUser object`
- `id: string`
ID of the User.
- `added_at: string`
RFC 3339 datetime string indicating when the User joined the Organization.
format: date-time
- `email: string`
Email of the User.
- `name: string`
Name of the User.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `type: "user"`
Object type.
For Users, this is always `"user"`.
default: user
### Example
```bash
Cut at 300 lines. The page has the rest.
api/beta/organization/users/list New page · 127 lines, new page
# List Users ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Users
**GET** `/v1/organizations/users`
List the organization's members.
## Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `email: optional string`
Filter by user email.
format: email
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `roles: optional array of string`
Filter to items whose `role` equals one of the supplied values. Repeatable; values are OR'ed together.
Accepted values depend on the organization type: Console and API organizations accept `user`, `developer`, `billing`, `admin`, and `claude_code_user`; Claude Enterprise organizations accept `user`, `owner`, `primary_owner`, `membership_admin`, and `managed`.
## Returns
- `data: array of BetaOrganizationUser`
- `id: string`
ID of the User.
- `added_at: string`
RFC 3339 datetime string indicating when the User joined the Organization.
format: date-time
- `email: string`
Email of the User.
- `name: string`
Name of the User.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `type: "user"`
Object type.
For Users, this is always `"user"`.
default: user
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/users \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"added_at": "2024-10-30T23:58:27.427722Z",
"email": "[email protected]",
"name": "Jane Doe",
"role": "admin",
"type": "user"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
api/beta/organization/users/remove New page · 43 lines, new page
# Remove User ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Remove User
**DELETE** `/v1/organizations/users/{user_id}`
Remove a member from the organization.
## Path parameters
- `user_id: string`
ID of the User.
## Returns
- `id: string`
ID of the User.
- `type: "user_deleted"`
Deleted object type.
For Users, this is always `"user_deleted"`.
default: user_deleted
## Example
```bash
curl https://api.anthropic.com/v1/organizations/users/$USER_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"type": "user_deleted"
}
```
api/beta/organization/users/retrieve New page · 84 lines, new page
# Get User ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get User
**GET** `/v1/organizations/users/{user_id}`
Retrieve a member of the organization by user ID.
## Path parameters
- `user_id: string`
ID of the User.
## Returns
- `BetaOrganizationUser object`
- `id: string`
ID of the User.
- `added_at: string`
RFC 3339 datetime string indicating when the User joined the Organization.
format: date-time
- `email: string`
Email of the User.
- `name: string`
Name of the User.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `type: "user"`
Object type.
For Users, this is always `"user"`.
default: user
## Example
```bash
curl https://api.anthropic.com/v1/organizations/users/$USER_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"added_at": "2024-10-30T23:58:27.427722Z",
"email": "[email protected]",
"name": "Jane Doe",
"role": "admin",
"type": "user"
}
```
api/beta/organization/users/update New page · 106 lines, new page
# Update User ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update User
**POST** `/v1/organizations/users/{user_id}`
Update a member's organization role.
## Path parameters
- `user_id: string`
ID of the User.
## Body parameters
- `role: "billing" or "claude_code_user" or "developer" or 2 more`
New role for the User.
The accepted values depend on the organization type. Console and API organizations accept `user`, `developer`, `billing`, and `claude_code_user`; `admin` cannot be assigned through the API. Claude Enterprise organizations accept `user` and `managed`.
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"user"`
## Returns
- `BetaOrganizationUser object`
- `id: string`
ID of the User.
- `added_at: string`
RFC 3339 datetime string indicating when the User joined the Organization.
format: date-time
- `email: string`
Email of the User.
- `name: string`
Name of the User.
- `role: BetaOrganizationRole`
Organization role of the User.
- `"admin"`
- `"billing"`
- `"claude_code_user"`
- `"developer"`
- `"managed"`
- `"membership_admin"`
- `"owner"`
- `"primary_owner"`
- `"user"`
- `type: "user"`
Object type.
For Users, this is always `"user"`.
default: user
## Example
```bash
curl https://api.anthropic.com/v1/organizations/users/$USER_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"role": "user"
}'
```
### Response (200)
```json
{
"id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"added_at": "2024-10-30T23:58:27.427722Z",
"email": "[email protected]",
"name": "Jane Doe",
"role": "admin",
"type": "user"
}
```
api/beta/organization/workspaces New page · 2544 lines, new page
# Workspaces ## List Workspaces ### Query parameters ### Returns ### Example #### Response (200) ## Create Workspace ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## Get Workspace ### Path parameters ### Returns ### Example #### Response (200) ## Update Workspace ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Archive Workspace ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta Allowed Inference Geo ### Beta Data Residency ### Beta Data Residency Create Config ### Beta Data Residency Update Config ### Beta No Billing Workspace Role ### Beta Workspace ### Beta Workspace Member ### Beta Workspace Role ## Workspaces › Rate Limits ### List Workspace Rate Limits #### Path parameters #### Query parameters #### Returns #### Example ##### Response (200) ## Workspaces › Members ### List Workspace Members #### Path parameters #### Query parameters #### Returns #### Example ##### Response (200) ### Create Workspace Member #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Get Workspace Member #### Path parameters #### Returns #### Example ##### Response (200) ### Update Workspace Member #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Delete Workspace Member #### Path parameters #### Returns #### Example ##### Response (200) ## Workspaces › Service Accounts ### List Service Account Workspace Members #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Create Service Account Workspace Member #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Get Service Account Workspace Member #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Update Service Account Workspace Member #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Delete Service Account Workspace Member #### Path parameters #### Headers #### Returns #### Example ##### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Workspaces
## List Workspaces
**GET** `/v1/organizations/workspaces`
List Workspaces
### Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `include_archived: optional boolean`
Whether to include Workspaces that have been archived in the response
default: false
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
### Returns
- `data: array of BetaWorkspace`
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK integration guide for the
required key configuration, including the value used during key validation.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: BetaDataResidency`
Data residency configuration.
- `allowed_inference_geos: array of string or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of string`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: string`
Default inference geo applied when requests omit the parameter.
- `workspace_geo: string`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "default_inference_geo",
"workspace_geo": "workspace_geo"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
## Create Workspace
**POST** `/v1/organizations/workspaces`
Create Workspace
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Body parameters
- `name: string`
Name of the Workspace.
maxLength: 40, minLength: 1
- `data_residency: optional BetaDataResidencyCreateConfig or null`
Data residency configuration for the workspace. If omitted, defaults to `workspace_geo: "us"`, `allowed_inference_geos: "unrestricted"`, and `default_inference_geo: "global"`.
- `allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null`
Permitted inference geo values. Defaults to 'unrestricted' if omitted, which allows all geos. Use the string 'unrestricted' to allow all geos, or a list of specific geos.
- `Geos = array of BetaAllowedInferenceGeo`
- `"global"`
- `"us"`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: optional "global" or "us" or null`
Default inference geo applied when requests omit the parameter. Defaults to 'global' if omitted. Must be a member of `allowed_inference_geos` unless `allowed_inference_geos` is `"unrestricted"`.
- `"global"`
- `"us"`
- `workspace_geo: optional "us" or null`
Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted.
- `display_color: optional string or null`
Hex color code representing the Workspace in the Anthropic Console.
Cut at 300 lines. The page has the rest.
api/beta/organization/workspaces/archive New page · 121 lines, new page
# Archive Workspace ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Archive Workspace
**POST** `/v1/organizations/workspaces/{workspace_id}/archive`
Archive Workspace
## Path parameters
- `workspace_id: string`
## Returns
- `BetaWorkspace object`
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK integration guide for the
required key configuration, including the value used during key validation.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: BetaDataResidency`
Data residency configuration.
- `allowed_inference_geos: array of string or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of string`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: string`
Default inference geo applied when requests omit the parameter.
- `workspace_geo: string`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "default_inference_geo",
"workspace_geo": "workspace_geo"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
```
api/beta/organization/workspaces/create New page · 274 lines, new page
# Create Workspace ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Workspace
**POST** `/v1/organizations/workspaces`
Create Workspace
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `name: string`
Name of the Workspace.
maxLength: 40, minLength: 1
- `data_residency: optional BetaDataResidencyCreateConfig or null`
Data residency configuration for the workspace. If omitted, defaults to `workspace_geo: "us"`, `allowed_inference_geos: "unrestricted"`, and `default_inference_geo: "global"`.
- `allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null`
Permitted inference geo values. Defaults to 'unrestricted' if omitted, which allows all geos. Use the string 'unrestricted' to allow all geos, or a list of specific geos.
- `Geos = array of BetaAllowedInferenceGeo`
- `"global"`
- `"us"`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: optional "global" or "us" or null`
Default inference geo applied when requests omit the parameter. Defaults to 'global' if omitted. Must be a member of `allowed_inference_geos` unless `allowed_inference_geos` is `"unrestricted"`.
- `"global"`
- `"us"`
- `workspace_geo: optional "us" or null`
Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted.
- `display_color: optional string or null`
Hex color code representing the Workspace in the Anthropic Console.
maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$
- `external_key_id: optional string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `tags: optional map[string] or null`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
## Returns
- `BetaWorkspace object`
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK integration guide for the
required key configuration, including the value used during key validation.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: BetaDataResidency`
Data residency configuration.
- `allowed_inference_geos: array of string or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of string`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: string`
Default inference geo applied when requests omit the parameter.
- `workspace_geo: string`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"name": "x",
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"tags": {
"env": "prod",
"team": "platform"
}
}'
```
### Response (200)
```json
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "default_inference_geo",
"workspace_geo": "workspace_geo"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
```
api/beta/organization/workspaces/list New page · 159 lines, new page
# List Workspaces ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Workspaces
**GET** `/v1/organizations/workspaces`
List Workspaces
## Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `include_archived: optional boolean`
Whether to include Workspaces that have been archived in the response
default: false
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
## Returns
- `data: array of BetaWorkspace`
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK integration guide for the
required key configuration, including the value used during key validation.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: BetaDataResidency`
Data residency configuration.
- `allowed_inference_geos: array of string or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of string`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: string`
Default inference geo applied when requests omit the parameter.
- `workspace_geo: string`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "default_inference_geo",
"workspace_geo": "workspace_geo"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
api/beta/organization/workspaces/members New page · 424 lines, new page
# Members ## List Workspace Members ### Path parameters ### Query parameters ### Returns ### Example #### Response (200) ## Create Workspace Member ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Get Workspace Member ### Path parameters ### Returns ### Example #### Response (200) ## Update Workspace Member ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Delete Workspace Member ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Member Remove Response
A whole new page. There's nothing to diff it against, so here is what it says.
# Members
## List Workspace Members
**GET** `/v1/organizations/workspaces/{workspace_id}/members`
List Workspace Members
### Path parameters
- `workspace_id: string`
ID of the Workspace.
### Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
### Returns
- `data: array of BetaWorkspaceMember`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
## Create Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/members`
Create Workspace Member
### Path parameters
- `workspace_id: string`
ID of the Workspace.
### Body parameters
- `user_id: string`
ID of the User.
- `workspace_role: BetaNoBillingWorkspaceRole`
Role of the new Workspace Member. Cannot be `workspace_billing`.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Returns
- `BetaWorkspaceMember object`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_role": "workspace_admin"
}'
```
#### Response (200)
```json
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
```
## Get Workspace Member
**GET** `/v1/organizations/workspaces/{workspace_id}/members/{user_id}`
Get Workspace Member
### Path parameters
- `workspace_id: string`
ID of the Workspace.
- `user_id: string`
ID of the User.
### Returns
- `BetaWorkspaceMember object`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
```
## Update Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/members/{user_id}`
Update Workspace Member
### Path parameters
- `workspace_id: string`
ID of the Workspace.
- `user_id: string`
ID of the User.
### Body parameters
- `workspace_role: BetaWorkspaceRole`
New workspace role for the User.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Returns
- `BetaWorkspaceMember object`
- `type: "workspace_member"`
Object type.
Cut at 300 lines. The page has the rest.
api/beta/organization/workspaces/members/add New page · 87 lines, new page
# Create Workspace Member ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/members`
Create Workspace Member
## Path parameters
- `workspace_id: string`
ID of the Workspace.
## Body parameters
- `user_id: string`
ID of the User.
- `workspace_role: BetaNoBillingWorkspaceRole`
Role of the new Workspace Member. Cannot be `workspace_billing`.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Returns
- `BetaWorkspaceMember object`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_role": "workspace_admin"
}'
```
### Response (200)
```json
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/workspaces/members/list New page · 101 lines, new page
# List Workspace Members ## Path parameters ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Workspace Members
**GET** `/v1/organizations/workspaces/{workspace_id}/members`
List Workspace Members
## Path parameters
- `workspace_id: string`
ID of the Workspace.
## Query parameters
- `after_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
- `before_id: optional string`
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
## Returns
- `data: array of BetaWorkspaceMember`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `first_id: string or null`
First ID in the `data` list. Can be used as the `before_id` for the previous page.
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `last_id: string or null`
Last ID in the `data` list. Can be used as the `after_id` for the next page.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}
```
api/beta/organization/workspaces/members/remove New page · 52 lines, new page
# Delete Workspace Member ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Delete Workspace Member
**DELETE** `/v1/organizations/workspaces/{workspace_id}/members/{user_id}`
Delete Workspace Member
## Path parameters
- `workspace_id: string`
ID of the Workspace.
- `user_id: string`
ID of the User.
## Returns
- `type: "workspace_member_deleted"`
Deleted object type.
For Workspace Members, this is always `"workspace_member_deleted"`.
default: workspace_member_deleted
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"type": "workspace_member_deleted",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}
```
api/beta/organization/workspaces/members/retrieve New page · 68 lines, new page
# Get Workspace Member ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Workspace Member
**GET** `/v1/organizations/workspaces/{workspace_id}/members/{user_id}`
Get Workspace Member
## Path parameters
- `workspace_id: string`
ID of the Workspace.
- `user_id: string`
ID of the User.
## Returns
- `BetaWorkspaceMember object`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/workspaces/members/update New page · 88 lines, new page
# Update Workspace Member ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/members/{user_id}`
Update Workspace Member
## Path parameters
- `workspace_id: string`
ID of the Workspace.
- `user_id: string`
ID of the User.
## Body parameters
- `workspace_role: BetaWorkspaceRole`
New workspace role for the User.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Returns
- `BetaWorkspaceMember object`
- `type: "workspace_member"`
Object type.
For Workspace Members, this is always `"workspace_member"`.
default: workspace_member
- `user_id: string`
ID of the User.
- `workspace_id: string`
ID of the Workspace.
- `workspace_role: BetaWorkspaceRole`
Role of the Workspace Member.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_role": "workspace_admin"
}'
```
### Response (200)
```json
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/workspaces/rate_limits New page · 217 lines, new page
# Rate Limits ## List Workspace Rate Limits ### Path parameters ### Query parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta Workspace Rate Limit ### Beta Workspace Rate Limit Value
A whole new page. There's nothing to diff it against, so here is what it says.
# Rate Limits
## List Workspace Rate Limits
**GET** `/v1/organizations/workspaces/{workspace_id}/rate_limits`
List rate-limit overrides configured for a workspace.
Returns only the groups and limiter types that have a workspace-level
override. Groups without overrides inherit the organization limits and
are not listed; use `GET /v1/organizations/rate_limits` to see those.
This endpoint currently returns every matching entry in a single page
regardless of `limit`; follow `next_page` so that clients keep working
when pagination is enabled.
### Path parameters
- `workspace_id: string`
The ID of the workspace.
### Query parameters
- `group_type: optional "batch" or "files" or "model_group" or 3 more`
Filter by group type.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limit: optional number`
Maximum number of items to return per page. Ranges from `1` to `1000`.
Accepted for request-shape compatibility and currently ignored: every entry is returned in a single page.
maximum: 1000, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Returns
- `data: array of BetaWorkspaceRateLimit`
Rate-limit entries for the workspace, one per group that has at least one override.
- `group_type: "batch" or "files" or "model_group" or 3 more`
The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limits: array of BetaWorkspaceRateLimitValue`
The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
- `org_limit: number or null`
The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The workspace-level override value for this limiter type.
- `models: array of string or null`
Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`.
- `rate_limit_id: string`
The `id` of the RateLimit group this override applies to.
- `type: "workspace_rate_limit"`
Object type. Always `workspace_rate_limit` for workspace rate-limit entries.
default: workspace_rate_limit
- `workspace_id: string`
ID of the Workspace this override applies to.
- `next_page: string or null`
Token to provide in as `page` in the subsequent request to retrieve the next page of data.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"group_type": "batch",
"limits": [
{
"org_limit": 0,
"type": "type",
"value": 0
}
],
"models": [
"string"
],
"rate_limit_id": "rate_limit_id",
"type": "workspace_rate_limit",
"workspace_id": "workspace_id"
}
],
"next_page": "next_page"
}
```
## Domain types
### Beta Workspace Rate Limit
- `BetaWorkspaceRateLimit object`
- `group_type: "batch" or "files" or "model_group" or 3 more`
The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limits: array of BetaWorkspaceRateLimitValue`
The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
- `org_limit: number or null`
The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The workspace-level override value for this limiter type.
- `models: array of string or null`
Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`.
- `rate_limit_id: string`
The `id` of the RateLimit group this override applies to.
- `type: "workspace_rate_limit"`
Object type. Always `workspace_rate_limit` for workspace rate-limit entries.
default: workspace_rate_limit
- `workspace_id: string`
ID of the Workspace this override applies to.
### Beta Workspace Rate Limit Value
- `BetaWorkspaceRateLimitValue object`
- `org_limit: number or null`
The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The workspace-level override value for this limiter type.
api/beta/organization/workspaces/rate_limits/list New page · 143 lines, new page
# List Workspace Rate Limits ## Path parameters ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Workspace Rate Limits
**GET** `/v1/organizations/workspaces/{workspace_id}/rate_limits`
List rate-limit overrides configured for a workspace.
Returns only the groups and limiter types that have a workspace-level
override. Groups without overrides inherit the organization limits and
are not listed; use `GET /v1/organizations/rate_limits` to see those.
This endpoint currently returns every matching entry in a single page
regardless of `limit`; follow `next_page` so that clients keep working
when pagination is enabled.
## Path parameters
- `workspace_id: string`
The ID of the workspace.
## Query parameters
- `group_type: optional "batch" or "files" or "model_group" or 3 more`
Filter by group type.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limit: optional number`
Maximum number of items to return per page. Ranges from `1` to `1000`.
Accepted for request-shape compatibility and currently ignored: every entry is returned in a single page.
maximum: 1000, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Returns
- `data: array of BetaWorkspaceRateLimit`
Rate-limit entries for the workspace, one per group that has at least one override.
- `group_type: "batch" or "files" or "model_group" or 3 more`
The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`.
- `"batch"`
- `"files"`
- `"model_group"`
- `"skills"`
- `"token_count"`
- `"web_search"`
- `limits: array of BetaWorkspaceRateLimitValue`
The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
- `org_limit: number or null`
The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
- `type: string`
The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`).
- `value: number`
The workspace-level override value for this limiter type.
- `models: array of string or null`
Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`.
- `rate_limit_id: string`
The `id` of the RateLimit group this override applies to.
- `type: "workspace_rate_limit"`
Object type. Always `workspace_rate_limit` for workspace rate-limit entries.
default: workspace_rate_limit
- `workspace_id: string`
ID of the Workspace this override applies to.
- `next_page: string or null`
Token to provide in as `page` in the subsequent request to retrieve the next page of data.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"group_type": "batch",
"limits": [
{
"org_limit": 0,
"type": "type",
"value": 0
}
],
"models": [
"string"
],
"rate_limit_id": "rate_limit_id",
"type": "workspace_rate_limit",
"workspace_id": "workspace_id"
}
],
"next_page": "next_page"
}
```
api/beta/organization/workspaces/retrieve New page · 122 lines, new page
# Get Workspace ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Workspace
**GET** `/v1/organizations/workspaces/{workspace_id}`
Get Workspace
## Path parameters
- `workspace_id: string`
ID of the Workspace.
## Returns
- `BetaWorkspace object`
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK integration guide for the
required key configuration, including the value used during key validation.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: BetaDataResidency`
Data residency configuration.
- `allowed_inference_geos: array of string or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of string`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: string`
Default inference geo applied when requests omit the parameter.
- `workspace_geo: string`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "default_inference_geo",
"workspace_geo": "workspace_geo"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
```
api/beta/organization/workspaces/service_accounts New page · 928 lines, new page
# Service Accounts ## List Service Account Workspace Members ### Path parameters ### Query parameters ### Headers ### Returns ### Example #### Response (200) ## Create Service Account Workspace Member ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## Get Service Account Workspace Member ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Update Service Account Workspace Member ### Path parameters ### Headers ### Body parameters ### Returns ### Example #### Response (200) ## Delete Service Account Workspace Member ### Path parameters ### Headers ### Returns ### Example #### Response (200) ## Domain types ### Service Account Remove Response
A whole new page. There's nothing to diff it against, so here is what it says.
# Service Accounts
## List Service Account Workspace Members
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List the service accounts that are members of a workspace.
Each entry includes the service account's `workspace_role`. Use `limit`
and the `next_page` cursor to paginate. Archived workspaces return 400;
use `GET /service_accounts/{id}/workspaces` to audit memberships of an
archived workspace. The implicit default-workspace membership is not
included in this list. Memberships of archived service accounts are
omitted from the results.
### Path parameters
- `workspace_id: string`
ID of the workspace.
### Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
### Returns
- `data: array of BetaServiceAccountWorkspaceMember`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
],
"next_page": "next_page"
}
```
## Create Service Account Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Add a service account to a workspace with the given `workspace_role`.
The role determines what the service account can do in the workspace and
which workspace-scoped permissions it can be granted when authenticating
through federation. Every service account is already an implicit
`workspace_user` member of the default workspace; adding it explicitly
assigns a chosen role. If the service account is already an explicit
member of the workspace, its `workspace_role` is replaced with the
value supplied here. Archived workspaces return 400. Archived service
accounts cannot be added and are rejected.
### Path parameters
- `workspace_id: string`
ID of the workspace.
### Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
Cut at 300 lines. The page has the rest.
api/beta/organization/workspaces/service_accounts/add New page · 196 lines, new page
# Create Service Account Workspace Member ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Create Service Account Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Add a service account to a workspace with the given `workspace_role`.
The role determines what the service account can do in the workspace and
which workspace-scoped permissions it can be granted when authenticating
through federation. Every service account is already an implicit
`workspace_user` member of the default workspace; adding it explicitly
assigns a chosen role. If the service account is already an explicit
member of the workspace, its `workspace_role` is replaced with the
value supplied here. Archived workspaces return 400. Archived service
accounts cannot be added and are rejected.
## Path parameters
- `workspace_id: string`
ID of the workspace.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `service_account_id: string`
Tagged service account ID to add.
- `workspace_role: BetaNoBillingWorkspaceRole`
Role to assign to the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Returns
- `BetaServiceAccountWorkspaceMember object`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"service_account_id": "service_account_id",
"workspace_role": "workspace_admin"
}'
```
### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/workspaces/service_accounts/list New page · 192 lines, new page
# List Service Account Workspace Members ## Path parameters ## Query parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# List Service Account Workspace Members
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List the service accounts that are members of a workspace.
Each entry includes the service account's `workspace_role`. Use `limit`
and the `next_page` cursor to paginate. Archived workspaces return 400;
use `GET /service_accounts/{id}/workspaces` to audit memberships of an
archived workspace. The implicit default-workspace membership is not
included in this list. Memberships of archived service accounts are
omitted from the results.
## Path parameters
- `workspace_id: string`
ID of the workspace.
## Query parameters
- `limit: optional number`
Number of results per page.
default: 20, maximum: 100, minimum: 1
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `data: array of BetaServiceAccountWorkspaceMember`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
],
"next_page": "next_page"
}
```
api/beta/organization/workspaces/service_accounts/remove New page · 148 lines, new page
# Delete Service Account Workspace Member ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Delete Service Account Workspace Member
**DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Remove a service account from a workspace.
Removal is idempotent (returns 200 even if the membership was already
removed). A DELETE against the implicit default-workspace membership
returns 200 but is a no-op and the membership persists; deleting an
explicit default-workspace row reverts to the implicit `workspace_user`
membership. Archived workspaces return 400.
## Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `service_account_id: string`
Tagged service account ID (`svac_...`) named in the delete request. Removal is idempotent; see the endpoint description for the implicit-membership no-op.
- `type: "service_account_workspace_member_deleted"`
default: service_account_workspace_member_deleted
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`) named in the delete request.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"service_account_id": "service_account_id",
"type": "service_account_workspace_member_deleted",
"workspace_id": "workspace_id"
}
```
api/beta/organization/workspaces/service_accounts/retrieve New page · 175 lines, new page
# Get Service Account Workspace Member ## Path parameters ## Headers ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Get Service Account Workspace Member
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Retrieve a service account's membership in a workspace.
Returns the membership record, including the service account's
`workspace_role` in this workspace. Archived workspaces return 400. For
the default workspace, returns the implicit (`implicit: true`)
membership when no explicit membership exists; an explicitly added
membership is returned with its assigned role. An archived service
account returns 404.
## Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Returns
- `BetaServiceAccountWorkspaceMember object`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/workspaces/service_accounts/update New page · 193 lines, new page
# Update Service Account Workspace Member ## Path parameters ## Headers ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update Service Account Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Change a service account's role in a workspace.
The new `workspace_role` replaces the current one. Only explicit
memberships can be updated; to set a role on the implicit
default-workspace membership, add the service account explicitly with
`POST /workspaces/{workspace_id}/service_accounts`. Archived workspaces
return 400. Archived service accounts cannot be updated and are
rejected.
## Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
## Headers
- `"anthropic-beta": optional array of AnthropicBeta`
Optional header to specify the beta version(s) you want to use.
- `string`
- `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more`
- `"message-batches-2024-09-24"`
- `"prompt-caching-2024-07-31"`
- `"computer-use-2024-10-22"`
- `"computer-use-2025-01-24"`
- `"pdfs-2024-09-25"`
- `"token-counting-2024-11-01"`
- `"token-efficient-tools-2025-02-19"`
- `"output-128k-2025-02-19"`
- `"files-api-2025-04-14"`
- `"mcp-client-2025-04-04"`
- `"mcp-client-2025-11-20"`
- `"dev-full-thinking-2025-05-14"`
- `"interleaved-thinking-2025-05-14"`
- `"code-execution-2025-05-22"`
- `"extended-cache-ttl-2025-04-11"`
- `"context-1m-2025-08-07"`
- `"context-management-2025-06-27"`
- `"model-context-window-exceeded-2025-08-26"`
- `"skills-2025-10-02"`
- `"fast-mode-2026-02-01"`
- `"output-300k-2026-03-24"`
- `"user-profiles-2026-03-24"`
- `"user-profiles-2026-08-18"`
- `"advisor-tool-2026-03-01"`
- `"managed-agents-2026-04-01"`
- `"cache-diagnosis-2026-04-07"`
- `"dreaming-2026-04-21"`
- `"thinking-token-count-2026-05-13"`
- `"server-side-fallback-2026-06-01"`
- `"server-side-fallback-2026-07-01"`
- `"fallback-credit-2026-06-01"`
- `"fallback-credit-2026-07-01"`
- `"agent-memory-2026-07-22"`
- `"mid-conversation-tool-changes-2026-07-01"`
- `"compact-2026-01-12"`
- `"computer-use-2025-11-24"`
- `"mcp-tunnels-2026-06-22"`
- `"structured-outputs-2025-11-13"`
- `"task-budgets-2026-03-13"`
- `"thinking-display-updates-2026-08-18"`
- `"ce-user-management-2026-07-13"`
## Body parameters
- `workspace_role: BetaNoBillingWorkspaceRole`
New role for the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Returns
- `BetaServiceAccountWorkspaceMember object`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: BetaWorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_role": "workspace_admin"
}'
```
### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
api/beta/organization/workspaces/update New page · 181 lines, new page
# Update Workspace ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
# Update Workspace
**POST** `/v1/organizations/workspaces/{workspace_id}`
Update Workspace
## Path parameters
- `workspace_id: string`
## Body parameters
- `data_residency: optional BetaDataResidencyUpdateConfig or null`
Data residency configuration for the workspace.
- `allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null`
Permitted inference geo values. Use 'unrestricted' to allow all geos, or a list of specific geos.
- `Geos = array of BetaAllowedInferenceGeo`
- `"global"`
- `"us"`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: optional "global" or "us" or null`
Default inference geo applied when requests omit the parameter. Must be a member of `allowed_inference_geos` unless `allowed_inference_geos` is `"unrestricted"`.
- `"global"`
- `"us"`
- `display_color: optional string`
Hex color code representing the Workspace in the Anthropic Console.
maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$
- `external_key_id: optional string`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: optional string`
Name of the Workspace.
maxLength: 40, minLength: 1
- `tags: optional map[string] or null`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
## Returns
- `BetaWorkspace object`
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK integration guide for the
required key configuration, including the value used during key validation.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: BetaDataResidency`
Data residency configuration.
- `allowed_inference_geos: array of string or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of string`
- `Unrestricted = "unrestricted"`
- `default_inference_geo: string`
Default inference geo applied when requests omit the parameter.
- `workspace_geo: string`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. This
field is write-once: once a key is attached to a Workspace it cannot be
detached or replaced. To rotate key material, rotate the underlying key on
your cloud KMS; the `external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"tags": {
"env": "prod",
"team": "platform"
}
}'
```
### Response (200)
```json
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "default_inference_geo",
"workspace_geo": "workspace_geo"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
```
api/beta/sessions Changed · +288 / -22 lines
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `agent: string or BetaManagedAgentsAgentParams or BetaManagedAgentsAgentWithOverridesParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsSession`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsSession object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `agent: optional BetaManagedAgentsSessionAgentUpdate`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeletedSession object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsSession object`
Model identifier and configuration. - - `name: string` - - `skills: array of BetaManagedAgentsAnthropicSkill or BetaManagedAgentsCustomSkill` - - - `BetaManagedAgentsAnthropicSkill object` - - A resolved Anthropic-managed skill. - - - `skill_id: string` - - - `type: "anthropic"` - - - `version: string` - - - `BetaManagedAgentsCustomSkill object` - - A resolved user-created custom skill. - - - `skill_id: string` - - - `type: "custom"` - - - `version: string` - - - `system: string or null` - - - `tools: array of BetaManagedAgentsAgentToolset20260401 or BetaManagedAgentsMCPToolset or BetaManagedAgentsCustomTool` - - - `BetaManagedAgentsAgentToolset20260401 object` - - - `configs: array of BetaManagedAgentsAgentToolConfig` - - - `BetaManagedAgentsBashToolConfig object` - - Configuration for the bash tool. - - - `enabled: boolean` - - - `name: "bash"` - - - `permission_policy: BetaManagedAgentsAlwaysAllowPolicy or BetaManagedAgentsAlwaysAskPolicy` - - Permission policy for tool execution. - - - `BetaManagedAgentsAlwaysAllowPolicy object` - - Tool calls are automatically approved without user confirmation. - - - `type: "always_allow"` - - - `BetaManagedAgentsAlwaysAskPolicy object` - - Tool calls require user confirmation before execution. - - - `type: "always_ask"` - - - `type: "bash"
api/beta/sessions/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/sessions/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/events Changed · +45 / -3 lines
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsSessionEvent`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `events: array of BetaManagedAgentsEventParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsStreamSessionEvents = BetaManagedAgentsUserMessageEvent or BetaManagedAgentsUserInterruptEvent or BetaManagedAgentsUserToolConfirmationEvent or 34 more`
- `result: string` - Evaluation verdict. 'satisfied': criteria met, session goes idle. 'needs_revision': criteria not met, another revision cycle follows. 'max_iterations_reached': evaluation budget exhausted with criteria still unmet — one final acknowledgment turn follows before the session goes idle, but no further evaluation runs. 'failed': grader determined the rubric does not apply to the deliverables. 'interrupted': user sent an interrupt while evaluation was in progress. - - - `type: "span.outcome_evaluation_end"` - - - `usage: BetaManagedAgentsSpanModelUsage` - - Token usage for a single model request. - - - `cache_creation_input_tokens: number` - - Tokens used to create prompt cache in this request. - - format: int32 - - - `cache_read_input_tokens: number` - - Tokens read from prompt cache in this request. - - format: int32 - - - `input_tokens: number` - - Input tokens consumed by this request. - - format: int32 - - - `output_tokens: number` - - Output tokens generated by this request. - - form + Evaluation verdict. 'satisfied': criteria met, session goes idle. 'needs_revision': criteria not met, another revision cycle follows. 'max_iterations_reached': evaluation budget exhausted with criteria still unmet — one final acknowledgment turn follows before the s
api/beta/sessions/events/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/events/send Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/sessions/events/stream Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/resources Changed · +75 / -5 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `file_id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaManagedAgentsSessionResource`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsGitHubRepositoryResource object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `authorization_token: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/sessions/resources/add Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/sessions/resources/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/resources/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/resources/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/resources/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/sessions/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/threads Changed · +79 / -9 lines
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsSessionThread`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsSessionThread object`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsSessionThread object`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: optional array of BetaManagedAgentsSessionEvent`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsStreamSessionThreadEvents = BetaManagedAgentsUserMessageEvent or BetaManagedAgentsUserInterruptEvent or BetaManagedAgentsUserToolConfirmationEvent or 34 more`
- `BetaManagedAgentsSessionUpdatedEvent object` - Emitted when an UpdateSession request changed at least one field. Carries only the fields that changed; absent fields were not part of the update. The new configuration applies from the next turn. - - - `id: string` - - Unique identifier for this event. - - - `processed_at: string` - - A timestamp in RFC 3339 format - - format: date-time - - - `type: "session.updated"` - - - `agent: optional BetaManagedAgentsSessionAgent or null` - - Resolved `agent` definition for a `session`. Snapshot of the `agent` at `session` creation time. - - - `id: string` - - - `description: string or null` - - - `mcp_servers: array of BetaManagedAgentsMCPServerURLDefinition` - - - `name: string` - - - `type: "url"` - - - `url: string` - - - `model: BetaManagedAgentsModelConfig` - - Model identifier and configuration. - - - `id: BetaManagedAgentsModel` - - The model that will power your agent. - - See [models](https://docs.anthropic.com/en/docs/models-overview) for additional details and options. - - - `"claude-sonnet-5" or "claude-fable-5" or "claude-opus-5" or 10 more` - - The model that will power your agent. - - See [models](https://docs.anthropic.com/en/docs/models-overview) for additional details and options. - - - `"claude-sonnet-5"` - - High-performance model for coding and agents - - - `"claude-fable-5"` - - Next generation of intelligence for the hardest knowledge work and coding problems - - - `"claude-opus-5"` - - Powerful intelligence for long-running agents and coding - - - `"claude-opus-4-8"` - - Powerful intelligence for long- + Emit
api/beta/sessions/threads/archive Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaManagedAgentsSessionThread object`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
api/beta/sessions/threads/events Changed · +30 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsSessionEvent`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/sessions/threads/events/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/threads/events/stream Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/sessions/threads/list Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `data: optional array of BetaManagedAgentsSessionThread`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
api/beta/sessions/threads/retrieve Changed · +16 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ## Returns - `BetaManagedAgentsSessionThread object`
- `agent: BetaManagedAgentsSessionThreadAgent or BetaManagedAgentsAdvisor` - A session-resolved multiagent roster entry. + The resolved agent a session thread runs: a saved-agent snapshot, the platform advisor entry, or an inline-defined (ephemeral) agent snapshot. - `BetaManagedAgentsSessionThreadAgent object`
api/beta/sessions/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/skills Changed · +135 / -9 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters (form-data) - `files: array of string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters (form-data) - `files: array of string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: array of object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Example ```bash
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` #### Returns
api/beta/skills/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters (form-data)
api/beta/skills/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/skills/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/skills/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/skills/versions Changed · +75 / -5 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters (form-data) - `files: array of string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Example ```bash
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `id: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/skills/versions/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters (form-data)
api/beta/skills/versions/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/skills/versions/download Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Example
api/beta/skills/versions/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/skills/versions/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels Changed · +150 / -10 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `display_name: optional string or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaTunnel object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaTunnel`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaTunnel object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaTunnelToken object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `reason: optional string or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `ca_certificate_pem: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaTunnelCertificate object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: array of BetaTunnelCertificate`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` #### Returns
api/beta/tunnels/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/certificates Changed · +60 / -4 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `ca_certificate_pem: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaTunnelCertificate object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaTunnelCertificate`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/tunnels/certificates/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/certificates/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/tunnels/certificates/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/certificates/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/tunnels/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/reveal_token Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/tunnels/rotate_token Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/user_profiles Changed · +75 / -5 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `access_type: optional "application" or "passthrough"`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of BetaUserProfile`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaUserProfile object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `access_type: optional "application" or "passthrough" or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/user_profiles/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/user_profiles/create_enrollment_url Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/user_profiles/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/user_profiles/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/user_profiles/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/vaults Changed · +195 / -13 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `display_name: string`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsVault`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsVault object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `display_name: optional string or null`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeletedVault object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsVault object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `data: optional array of BetaManagedAgentsCredential`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsCredential object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Body parameters - `auth: optional BetaManagedAgentsMCPOAuthUpdateParams or BetaManagedAgentsStaticBearerUpdateParams or BetaManagedAgentsEnvironmentVariableUpdateParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsDeletedCredential object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + #### Returns - `BetaManagedAgentsCredential object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` #### Returns
api/beta/vaults/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/vaults/credentials Changed · +105 / -7 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `auth: BetaManagedAgentsMCPOAuthCreateParams or BetaManagedAgentsStaticBearerCreateParams or BetaManagedAgentsEnvironmentVariableCreateParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: optional array of BetaManagedAgentsCredential`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsCredential object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Body parameters - `auth: optional BetaManagedAgentsMCPOAuthUpdateParams or BetaManagedAgentsStaticBearerUpdateParams or BetaManagedAgentsEnvironmentVariableUpdateParams`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsDeletedCredential object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `BetaManagedAgentsCredential object`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/beta/vaults/credentials/archive Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/credentials/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/vaults/credentials/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/credentials/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/credentials/mcp_oauth_validate Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/credentials/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/credentials/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/beta/vaults/delete Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/beta/vaults/update Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/completions Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Body parameters
api/completions/create Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Body parameters
api/models Changed · +30 / -2 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"mid-conversation-tool-changes-2026-07-01"` + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` + ### Returns - `data: array of ModelInfo`
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ### Returns
api/models/list Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
api/models/retrieve Changed · +15 / -1 lines
- `string` - - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 31 more` + - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 38 more` - `"message-batches-2024-09-24"`
- `"agent-memory-2026-07-22"` - `"mid-conversation-tool-changes-2026-07-01"` + + - `"compact-2026-01-12"` + + - `"computer-use-2025-11-24"` + + - `"mcp-tunnels-2026-06-22"` + + - `"structured-outputs-2025-11-13"` + + - `"task-budgets-2026-03-13"` + + - `"thinking-display-updates-2026-08-18"` + + - `"ce-user-management-2026-07-13"` ## Returns
manage-claude/admin-api Changed · +1609 / -140 lines
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
**The Admin API is unavailable for individual accounts.** To collaborate with teammates and add members, set up your organization in **Console → Settings → Organization**. </Tip> -The [Admin API](https://platform.claude.com/docs/en/api/admin) allows you to programmatically manage your organization's resources, including organization members, workspaces, and API keys. This provides programmatic control over administrative tasks that would otherwise require manual configuration in the [Claude Console](https://platform.claude.com/). +The [Admin API](https://platform.claude.com/docs/en/api/admin) lets you manage your organization's members, workspaces, invites, and API keys programmatically instead of by hand in the [Claude Console](https://platform.claude.com/). <Check> **The Admin API requires special access**
</Check> <Note> - **Claude Enterprise:** Claude Enterprise (claude.ai) organizations use the Admin API too, with a scoped API key created in claude.ai. Of the endpoints on this page, only members and invites are available to them, alongside Claude-Enterprise-only endpoints: groups and custom-role reads, and [spend limits](https://platform.claude.com/docs/en/manage-claude/spend-limits-api). See [User management](https://platform.claude.com/docs/en/manage-claude/user-management) for Claude Enterprise. + **Claude Enterprise:** Claude Enterprise (claude.ai) organizations call the Admin API with a scoped API key created in claude.ai. From this page, only the members and invites endpoints apply to them. They also get Enterprise-only endpoints: group and custom-role reads, and [spend limits](https://platform.claude.com/docs/en/manage-claude/spend-limits-api). See [User management](https://platform.claude.com/docs/en/manage-claude/user-management). </Note> <Note> - **Claude Platform on AWS:** Most of the Admin API is not available on Claude Platform on AWS. Workspace endpoints (create, get, list, update, and archive on `/v1/organizations/workspaces`) are available. Other endpoints including organization members, workspace members, invites, API keys, usage reports, cost reports, and rate limit reports are not available. See [Claude Platform on AWS](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws) for details. + **Claude Platform on AWS:** Only the workspace endpoints (create, get, list, update, and archive on `/v1/organizations/workspaces`) are available on Claude Platform on AWS. Organization members, workspace members, invites, API keys, and the usage, cost, and rate limit reports aren't. See [Claude Platform on AWS](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws). </Note> ## Authentication -Authenticate with either credential. An Admin API key covers most endpoints; the service-account, federation-issuer, and federation-rule endpoints accept only an `org:admin` OAuth token. The following examples call the [organization info endpoint](https://platform.claude.com/docs/en/manage-claude/admin-api#accessing-organization-info) both ways. +Authenticate with either credential. An Admin API key covers most endpoints. The service-account, federation-issuer, and federation-rule endpoints accept only an `org:admin` OAuth token. The following examples call the [organization info endpoint](https://platform.claude.com/docs/en/manage-claude/admin-api#accessing-organization-info) both ways. + +The Python, TypeScript, C#, Go, Java, PHP, and Ruby SDKs expose the Admin API under `client.beta.organization`, and the `ant` CLI under `ant beta:organization`. The examples on this page use the default client, which reads an Admin API key from `ANTHROPIC_API_KEY` or an OAuth bearer token from `ANTHROPIC_AUTH_TOKEN`. SDK list methods in Python, TypeScript, C#, Go, and Java return an iterator that fetches more pages on demand, so `limit` sets the page size, not the total. The PHP, Ruby, and curl examples return one page. In the CLI, `--limit` caps the results on the member, invite, workspace, workspace-member, and API-key lists. For each endpoint's parameters and responses, see the [Admin API reference](https://platform.claude.com/docs/en/api/admin). ### OAuth bearer token -Log in with the [`ant` CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart) under a dedicated profile, requesting the `org:admin` scope (see [Admin access](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication#admin-access)), then export the bearer token. A dedicated profile keeps your routine commands from running with elevated access: +Log in with the [`ant` CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart) under a dedicated profile with the `org:admin` scope (see [Admin access](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication#admin-access)), then export the bearer token. `--profile admin` stores the `org:admin` credential under its own profile and makes it the CLI's active profile. The exported variable applies to every SDK and CLI call in that shell. Use a shell you reserve for administration, unset the variable when you're done, and switch the CLI back with `ant profile activate default`: ```bash CLI ant auth login --profile admin --scope "org:admin" -export ANTHROPIC_OAUTH_TOKEN=$(ant auth print-credentials --profile admin --access-token) +export ANTHROPIC_AUTH_TOKEN=$(ant auth print-credentials --profile admin --access-token) ``` -Interactive tokens are short-lived; if requests start returning 401, re-run the `export` command, which refreshes the token automatically. +Interactive tokens are short-lived. If requests start returning 401, re-run the `export` command to refresh the token. + +The SDKs and the `ant` CLI read `ANTHROPIC_AUTH_TOKEN` automatically. Leave `ANTHROPIC_API_KEY` unset in the same shell so they send the bearer token. Automated workloads skip the login: they authenticate through workload identity federation, and the SDKs and CLI perform the token exchange from the federation environment variables. See [Bootstrap a workload to manage WIF](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#bootstrap-a-workload-to-manage-wif). Call the Admin API with the exported token: -```bash cURL -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \ - --header "anthropic-version: 2023-06-01" \ - --header "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" -``` +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization retrieve + ``` + + ```python Python + client = anthropic.Anthropic() + + organization = client.beta.organization.retrieve() + + print(f"id: {organization.id}") + print(f"name: {organization.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const organization = await client.beta.organization.retrieve(); + + console.log(`id: ${organization.id}`); + console.log(`name: ${organization.name}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var organization = await client.Beta.Organization.Retrieve(); + + Console.WriteLine($"id: {organization.ID}"); + Console.WriteLine($"name: {organization.Name}"); + ``` + + ```go Go + client := anthropic.NewClient() + + organization, err := client.Beta.Organization.Get(context.Background()) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", organization.ID) + fmt.Printf("name: %s\n", organization.Name) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var organization = client.beta().organization().retrieve(); + + IO.println("id: " + organization.id()); + IO.println("name: " + organization.name()); + ``` + + ```php PHP + $client = new Client(); + + $organization = $client->beta->organization->retrieve(); + + echo "id: {$organization->id}\n"; + echo "name: {$organization->name}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + organization = client.beta.organization.retrieve + + puts "id: #{organization.id}" + puts "name: #{organization.name}" + ``` +</CodeGroup> An `org:admin` token grants access to the whole organization, regardless of the workspace the underlying profile or [federation rule](https://platform.claude.com/docs/en/manage-claude/admin-api#federation-rules) is bound to.
To create an Admin API key for your organization type, see [Create an Admin API key](https://platform.claude.com/docs/en/manage-claude/admin-api-keys). -```bash cURL -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization retrieve + ``` + + ```python Python + client = anthropic.Anthropic() + + organization = client.beta.organization.retrieve() + + print(f"id: {organization.id}") + print(f"name: {organization.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const organization = await client.beta.organization.retrieve(); + + console.log(`id: ${organization.id}`); + console.log(`name: ${organization.name}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var organization = await client.Beta.Organization.Retrieve(); + + Console.WriteLine($"id: {organization.ID}"); + Console.WriteLine($"name: {organization.Name}"); + ``` + + ```go Go + client := anthropic.NewClient() + + organization, err := client.Beta.Organization.Get(context.Background()) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", organization.ID) + fmt.Printf("name: %s\n", organization.Name) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var organization = client.beta().organization().retrieve(); + + IO.println("id: " + organization.id()); + IO.println("name: " + organization.name()); + ``` + + ```php PHP + $client = new Client(); + + $organization = $client->beta->organization->retrieve(); + + echo "id: {$organization->id}\n"; + echo "name: {$organization->name}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + organization = client.beta.organization.retrieve + + puts "id: #{organization.id}" + puts "name: #{organization.name}" + ``` +</CodeGroup> ## How the Admin API works -When you use the Admin API: - -1. You make requests using either credential from the [Authentication](https://platform.claude.com/docs/en/manage-claude/admin-api#authentication) section - -2. The API allows you to manage: - - * Organization members and their roles - * Organization member invites - * Workspaces and their members - * API keys - * Service accounts, federation issuers, and federation rules (these endpoints require an `org:admin` OAuth token; Admin API keys are not accepted) - -This is useful for: - -* Automating user onboarding/offboarding -* Programmatically managing workspace access -* Monitoring and managing API key usage +Authenticate with either credential from [Authentication](https://platform.claude.com/docs/en/manage-claude/admin-api#authentication), then manage the following resources: + +* Organization members and their roles +* Organization invites +* Workspaces and their members +* API keys +* Service accounts, federation issuers, and federation rules (`org:admin` OAuth token only) + +Common uses include automating onboarding and offboarding, managing workspace access, and auditing API keys. ## Organization roles and permissions -There are five organization-level roles. See more details in the [API Console roles and permissions](https://support.claude.com/en/articles/10186004-api-console-roles-and-permissions) article. +There are five organization-level roles. For details, see [API Console roles and permissions](https://support.claude.com/en/articles/10186004-api-console-roles-and-permissions). | Role | Permissions | | ------------------ | ------------------------------------------------------------------------------ |
| billing | Can use playground and manage billing details | | admin | Can do all of the preceding, plus manage users | -Organization owners and primary owners have all admin permissions and can additionally manage admins. All references to the admin role on this page also apply to owners and primary owners. +Organization owners and primary owners have all admin permissions and can also manage admins. All references to the admin role on this page also apply to owners and primary owners. ## Key concepts ### Organization members -You can list [organization members](https://platform.claude.com/docs/en/api/admin-api/users/get-user), update member roles, and remove members. +List [organization members](https://platform.claude.com/docs/en/api/admin-api/users/get-user), update their roles, and remove them. + +List the members of your organization: <CodeGroup> ```bash cURL - # List organization members curl "https://api.anthropic.com/v1/organizations/users?limit=10" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" - - # Update member role - curl "https://api.anthropic.com/v1/organizations/users/{user_id}" \ - --header "anthropic-version: 2023-06-01" \ - --header "content-type: application/json" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - --data '{"role": "developer"}' - - # Remove member - curl --request DELETE "https://api.anthropic.com/v1/organizations/users/{user_id}" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:users list --limit 10 + ``` + + ```python Python + client = anthropic.Anthropic() + + users = client.beta.organization.users.list(limit=10) + + # Automatically fetches more pages as needed. + for user in users: + print(f"{user.id}: {user.email} ({user.role})") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const users = await client.beta.organization.users.list({ limit: 10 }); + + for await (const user of users) { + console.log(`${user.id}: ${user.email} (${user.role})`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.Users.List(new() { Limit = 10 }); + + await foreach (var user in page.Paginate()) + { + Console.WriteLine($"{user.ID}: {user.Email} ({user.Role.Raw()})"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + users := client.Beta.Organization.Users.ListAutoPaging(context.Background(), anthropic.BetaOrganizationUserListParams{ + Limit: anthropic.Int(10), + }) + + for users.Next() { + user := users.Current() + fmt.Printf("%s: %s (%s)\n", user.ID, user.Email, user.Role) + } + if err := users.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.users.UserListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = UserListParams.builder() + .limit(10) + .build(); + var users = client.beta().organization().users().list(params); + + for (var user : users.autoPager()) { + IO.println(user.id() + ": " + user.email() + " (" + user.role().asString() + ")"); + } + } + ``` + + ```php PHP + $client = new Client(); + + $users = $client->beta->organization->users->list(limit: 10); + + foreach ($users->getItems() as $user) { + echo "{$user->id}: {$user->email} ({$user->role})\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + users = client.beta.organization.users.list(limit: 10) + + users.data.each do |user| + puts "#{user.id}: #{user.email} (#{user.role})" + end ``` </CodeGroup> -### Organization invites - -You can invite users to organizations and manage those [invites](https://platform.claude.com/docs/en/api/admin-api/invites/get-invite). +Update a member's role: <CodeGroup> ```bash cURL - # Create invite - curl --request POST "https://api.anthropic.com/v1/organizations/invites" \ - --header "anthropic-version: 2023-06-01" \ - --header "content-type: application/json" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - --data '{ - "email": "[email protected]", + curl "https://api.anthropic.com/v1/organizations/users/user_01XyDMpzjS89pFZXqSFUBDr6" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{"role": "developer"}' + ``` + + ```bash CLI + ant beta:organization:users update \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --role developer + ``` + + ```python Python + client = anthropic.Anthropic() + + user = client.beta.organization.users.update( + "user_01XyDMpzjS89pFZXqSFUBDr6", role="developer" + ) + + print(f"id: {user.id}") + print(f"role: {user.role}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const user = await client.beta.organization.users.update("user_01XyDMpzjS89pFZXqSFUBDr6", { + role: "developer" + }); + + console.log(`id: ${user.id}`); + console.log(`role: ${user.role}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Users; + // ... + + AnthropicClient client = new(); + + var user = await client.Beta.Organization.Users.Update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + new() { Role = Role.Developer } + ); + + Console.WriteLine($"id: {user.ID}"); + Console.WriteLine($"role: {user.Role.Raw()}"); + ``` + + ```go Go + client := anthropic.NewClient() + + user, err := client.Beta.Organization.Users.Update( + context.Background(), + "user_01XyDMpzjS89pFZXqSFUBDr6", + anthropic.BetaOrganizationUserUpdateParams{ + Role: anthropic.BetaOrganizationUserUpdateParamsRoleDeveloper, + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", user.ID) + fmt.Printf("role: %s\n", user.Role) + ``` + + ```java Java + import com.anthropic.models.beta.organization.users.UserUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = UserUpdateParams.builder() + .role(UserUpdateParams.Role.DEVELOPER) + .build(); + var user = client.beta().organization().users() + .update("user_01XyDMpzjS89pFZXqSFUBDr6", params); + + IO.println("id: " + user.id()); + IO.println("role: " + user.role().asString()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\Users\UserUpdateParams\Role; + // ... + + $client = new Client(); + + $user = $client->beta->organization->users->update( + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + role: Role::DEVELOPER, + ); + + echo "id: {$user->id}\n"; + echo "role: {$user->role}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + user_id = "user_01XyDMpzjS89pFZXqSFUBDr6" + user = client.beta.organization.users.update(user_id, role: :developer) + + puts "id: #{user.id}" + puts "role: #{user.role}" + ``` +</CodeGroup> + +Remove a member from the organization: + +<CodeGroup> + ```bash cURL + curl -X DELETE "https://api.anthropic.com/v1/organizations/users/user_01XyDMpzjS89pFZXqSFUBDr6" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:users remove --user-id user_01XyDMpzjS89pFZXqSFUBDr6 + ``` + + ```python Python + client = anthropic.Anthropic() + + removed_user = client.beta.organization.users.remove("user_01XyDMpzjS89pFZXqSFUBDr6") + + print(f"id: {removed_user.id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const removedUser = await client.beta.organization.users.remove( + "user_01XyDMpzjS89pFZXqSFUBDr6" + ); + + console.log(`id: ${removedUser.id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var removedUser = await client.Beta.Organization.Users.Remove("user_01XyDMpzjS89pFZXqSFUBDr6"); + + Console.WriteLine($"id: {removedUser.ID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + removedUser, err := client.Beta.Organization.Users.Remove(context.Background(), "user_01XyDMpzjS89pFZXqSFUBDr6") + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", removedUser.ID) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var removedUser = client.beta().organization().users() + .remove("user_01XyDMpzjS89pFZXqSFUBDr6"); + + IO.println("id: " + removedUser.id()); + ``` + + ```php PHP + $client = new Client(); + + $removedUser = $client->beta->organization->users->remove( + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + ); + + echo "id: {$removedUser->id}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + user_id = "user_01XyDMpzjS89pFZXqSFUBDr6" + removed_user = client.beta.organization.users.remove(user_id) + + puts "id: #{removed_user.id}" + ``` +</CodeGroup> + +### Organization invites + +Invite users to your organization and manage pending [invites](https://platform.claude.com/docs/en/api/admin-api/invites/get-invite). + +Invite a user to your organization: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/invites" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "email": "[email protected]", "role": "developer" }' - - # List invites - curl "https://api.anthropic.com/v1/organizations/invites?limit=10" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" - - # Delete invite - curl --request DELETE "https://api.anthropic.com/v1/organizations/invites/{invite_id}" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" + ``` + + ```bash CLI + ant beta:organization:invites create --email [email protected] --role developer + ``` + + ```python Python + client = anthropic.Anthropic() + + invite = client.beta.organization.invites.create( + email="[email protected]", role="developer" + ) + + print(f"id: {invite.id}") + print(f"email: {invite.email}") + print(f"status: {invite.status}") + print(f"expires_at: {invite.expires_at}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const invite = await client.beta.organization.invites.create({ + email: "[email protected]", + role: "developer" + }); + + console.log(`id: ${invite.id}`); + console.log(`email: ${invite.email}`); + console.log(`status: ${invite.status}`); + console.log(`expires_at: ${invite.expires_at}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Invites; + // ... + + AnthropicClient client = new(); + + var invite = await client.Beta.Organization.Invites.Create(new() + { + Email = "[email protected]", + Role = Role.Developer + }); + + Console.WriteLine($"id: {invite.ID}"); + Console.WriteLine($"email: {invite.Email}"); + Console.WriteLine($"status: {invite.Status.Raw()}"); + Console.WriteLine($"expires_at: {invite.ExpiresAt:O}"); + ``` + + ```go Go + client := anthropic.NewClient() + + invite, err := client.Beta.Organization.Invites.New(context.Background(), anthropic.BetaOrganizationInviteNewParams{ + Email: "[email protected]", + Role: anthropic.BetaOrganizationInviteNewParamsRoleDeveloper, + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", invite.ID) + fmt.Printf("email: %s\n", invite.Email) + fmt.Printf("status: %s\n", invite.Status) + fmt.Printf("expires_at: %s\n", invite.ExpiresAt.Format(time.RFC3339)) + ``` + + ```java Java + import com.anthropic.models.beta.organization.invites.InviteCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = InviteCreateParams.builder() + .email("[email protected]") + .role(InviteCreateParams.Role.DEVELOPER) + .build(); + var invite = client.beta().organization().invites().create(params); + + IO.println("id: " + invite.id()); + IO.println("email: " + invite.email()); + IO.println("status: " + invite.status().asString()); + IO.println("expires_at: " + invite.expiresAt()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\Invites\InviteCreateParams\Role; + // ... + + $client = new Client(); + + $invite = $client->beta->organization->invites->create( + email: '[email protected]', + role: Role::DEVELOPER, + ); + + echo "id: {$invite->id}\n"; + echo "email: {$invite->email}\n"; + echo "status: {$invite->status}\n"; + echo "expires_at: {$invite->expiresAt->format(DATE_ATOM)}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + invite = client.beta.organization.invites.create(email: "[email protected]", role: :developer) + + puts "id: #{invite.id}" + puts "email: #{invite.email}" + puts "status: #{invite.status}" + puts "expires_at: #{invite.expires_at.iso8601}" ``` </CodeGroup> -### Workspaces - -For a comprehensive guide to workspaces, including Console and API examples, see [Workspaces](https://platform.claude.com/docs/en/manage-claude/workspaces). - -### Workspace members - -Manage [user access to specific workspaces](https://platform.claude.com/docs/en/api/admin-api/workspace_members/get-workspace-member): +List pending invites: <CodeGroup> ```bash cURL - # Add member to workspace - curl --request POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members" \ - --header "anthropic-version: 2023-06-01" \ - --header "content-type: application/json" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - --data '{ - "user_id": "user_xxx", + curl "https://api.anthropic.com/v1/organizations/invites?limit=10" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:invites list --limit 10 + ``` + + ```python Python + client = anthropic.Anthropic() + + invites = client.beta.organization.invites.list(limit=10) + + # Automatically fetches more pages as needed. + for invite in invites: + print(f"{invite.id}: {invite.email} ({invite.status})") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const invites = await client.beta.organization.invites.list({ limit: 10 }); + + for await (const invite of invites) { + console.log(`${invite.id}: ${invite.email} (${invite.status})`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.Invites.List(new() { Limit = 10 }); + + await foreach (var invite in page.Paginate()) + { + Console.WriteLine($"{invite.ID}: {invite.Email} ({invite.Status.Raw()})"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + invites := client.Beta.Organization.Invites.ListAutoPaging(context.Background(), anthropic.BetaOrganizationInviteListParams{ + Limit: anthropic.Int(10), + }) + + for invites.Next() { + invite := invites.Current() + fmt.Printf("%s: %s (%s)\n", invite.ID, invite.Email, invite.Status) + } + if err := invites.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.invites.InviteListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = InviteListParams.builder() + .limit(10) + .build(); + var invites = client.beta().organization().invites().list(params); + + for (var invite : invites.autoPager()) { + IO.println(invite.id() + ": " + invite.email() + " (" + invite.status().asString() + ")"); + } + } + ``` + + ```php PHP + $client = new Client(); + + $invites = $client->beta->organization->invites->list(limit: 10); + + foreach ($invites->getItems() as $invite) { + echo "{$invite->id}: {$invite->email} ({$invite->status})\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + invites = client.beta.organization.invites.list(limit: 10) + + invites.data.each do |invite| + puts "#{invite.id}: #{invite.email} (#{invite.status})" + end + ``` +</CodeGroup> + +Delete an invite: + +<CodeGroup> + ```bash cURL + curl -X DELETE "https://api.anthropic.com/v1/organizations/invites/invite_015gWxHNr6h6TdRPZTmuCGnn" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:invites delete --invite-id invite_015gWxHNr6h6TdRPZTmuCGnn + ``` + + ```python Python + client = anthropic.Anthropic() + + deleted_invite = client.beta.organization.invites.delete( + "invite_015gWxHNr6h6TdRPZTmuCGnn" + ) + + print(f"id: {deleted_invite.id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const deletedInvite = await client.beta.organization.invites.delete( + "invite_015gWxHNr6h6TdRPZTmuCGnn" + ); + + console.log(`id: ${deletedInvite.id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var deletedInvite = await client.Beta.Organization.Invites.Delete( + "invite_015gWxHNr6h6TdRPZTmuCGnn" + ); + + Console.WriteLine($"id: {deletedInvite.ID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + deletedInvite, err := client.Beta.Organization.Invites.Delete(context.Background(), "invite_015gWxHNr6h6TdRPZTmuCGnn") + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", deletedInvite.ID) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var deletedInvite = client.beta().organization().invites() + .delete("invite_015gWxHNr6h6TdRPZTmuCGnn"); + + IO.println("id: " + deletedInvite.id()); + ``` + + ```php PHP + $client = new Client(); + + $deletedInvite = $client->beta->organization->invites->delete( + inviteID: 'invite_015gWxHNr6h6TdRPZTmuCGnn', + ); + + echo "id: {$deletedInvite->id}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + invite_id = "invite_015gWxHNr6h6TdRPZTmuCGnn" + deleted_invite = client.beta.organization.invites.delete(invite_id) + + puts "id: #{deleted_invite.id}" + ``` +</CodeGroup> + +### Workspaces + +See [Workspaces](https://platform.claude.com/docs/en/manage-claude/workspaces) for Console and API examples. + +### Workspace members + +Manage [user access to specific workspaces](https://platform.claude.com/docs/en/api/admin-api/workspace_members/get-workspace-member): + +Add a member to a workspace: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "user_id": "user_01XyDMpzjS89pFZXqSFUBDr6", "workspace_role": "workspace_developer" }' - - # List workspace members - curl "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members?limit=10" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" - - # Update member role - curl --request POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members/{user_id}" \ - --header "anthropic-version: 2023-06-01" \ - --header "content-type: application/json" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - --data '{ - "workspace_role": "workspace_admin" - }' - - # Remove member from workspace - curl --request DELETE "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members/{user_id}" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" + ``` + + ```bash CLI + ant beta:organization:workspaces:members add \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --workspace-role workspace_developer + ``` + + ```python Python + client = anthropic.Anthropic() + + member = client.beta.organization.workspaces.members.add( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + user_id="user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_role="workspace_developer", + ) + + print(f"user_id: {member.user_id}") + print(f"workspace_role: {member.workspace_role}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const member = await client.beta.organization.workspaces.members.add( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + { + user_id: "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_role: "workspace_developer" + } + ); + + console.log(`user_id: ${member.user_id}`); + console.log(`workspace_role: ${member.workspace_role}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Workspaces; + + AnthropicClient client = new(); + + var member = await client.Beta.Organization.Workspaces.Members.Add( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + new() + { + UserID = "user_01XyDMpzjS89pFZXqSFUBDr6", + WorkspaceRole = BetaNoBillingWorkspaceRole.WorkspaceDeveloper + } + ); + + Console.WriteLine($"user_id: {member.UserID}"); + Console.WriteLine($"workspace_role: {member.WorkspaceRole.Raw()}"); + ``` + + ```go Go + client := anthropic.NewClient() + + member, err := client.Beta.Organization.Workspaces.Members.Add( + context.Background(), + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + anthropic.BetaOrganizationWorkspaceMemberAddParams{ + UserID: "user_01XyDMpzjS89pFZXqSFUBDr6", + WorkspaceRole: anthropic.BetaNoBillingWorkspaceRoleWorkspaceDeveloper, + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("user_id: %s\n", member.UserID) + fmt.Printf("workspace_role: %s\n", member.WorkspaceRole) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.BetaNoBillingWorkspaceRole; + import com.anthropic.models.beta.organization.workspaces.members.MemberAddParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberAddParams.builder() + .userId("user_01XyDMpzjS89pFZXqSFUBDr6") + .workspaceRole(BetaNoBillingWorkspaceRole.WORKSPACE_DEVELOPER) + .build(); + var member = client.beta().organization().workspaces().members() + .add("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", params); + + IO.println("user_id: " + member.userId()); + IO.println("workspace_role: " + member.workspaceRole().asString()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\Workspaces\NoBillingWorkspaceRole; + // ... + + $client = new Client(); + + $member = $client->beta->organization->workspaces->members->add( + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + workspaceRole: NoBillingWorkspaceRole::WORKSPACE_DEVELOPER, + ); + + echo "user_id: {$member->userID}\n"; + echo "workspace_role: {$member->workspaceRole}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + member = client.beta.organization.workspaces.members.add( + workspace_id, + user_id: "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_role: :workspace_developer + ) + + puts "user_id: #{member.user_id}" + puts "workspace_role: #{member.workspace_role}" ``` </CodeGroup> -### API keys - -Monitor and manage [API keys](https://platform.claude.com/docs/en/api/admin/api_keys/list). Each key in the response includes its `expires_at` timestamp (`null` for keys without an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration)): +List the members of a workspace: <CodeGroup> ```bash cURL - # List API keys - curl "https://api.anthropic.com/v1/organizations/api_keys?limit=10&status=active&workspace_id=wrkspc_xxx" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" - - # Update API key - curl --request POST "https://api.anthropic.com/v1/organizations/api_keys/{api_key_id}" \ - --header "anthropic-version: 2023-06-01" \ - --header "content-type: application/json" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - --data '{ + curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members?limit=10" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:workspaces:members list \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \ + --limit 10 + ``` + + ```python Python + client = anthropic.Anthropic() + + members = client.beta.organization.workspaces.members.list( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", limit=10 + ) + + # Automatically fetches more pages as needed. + for member in members: + print(f"{member.user_id}: {member.workspace_role}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const members = await client.beta.organization.workspaces.members.list( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + { limit: 10 } + ); + + for await (const member of members) { + console.log(`${member.user_id}: ${member.workspace_role}`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.Workspaces.Members.List( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + new() { Limit = 10 } + ); + + await foreach (var member in page.Paginate()) + { + Console.WriteLine($"{member.UserID}: {member.WorkspaceRole.Raw()}"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + members := client.Beta.Organization.Workspaces.Members.ListAutoPaging( + context.Background(), + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + anthropic.BetaOrganizationWorkspaceMemberListParams{ + Limit: anthropic.Int(10), + }, + ) + + for members.Next() { + member := members.Current() + fmt.Printf("%s: %s\n", member.UserID, member.WorkspaceRole) + } + if err := members.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.members.MemberListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberListParams.builder() + .limit(10) + .build(); + var members = client.beta().organization().workspaces().members() + .list("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", params); + + for (var member : members.autoPager()) { + IO.println(member.userId() + ": " + member.workspaceRole().asString()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $members = $client->beta->organization->workspaces->members->list( + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + limit: 10, + ); + + foreach ($members->getItems() as $member) { + echo "{$member->userID}: {$member->workspaceRole}\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + members = client.beta.organization.workspaces.members.list(workspace_id, limit: 10) + + members.data.each do |member| + puts "#{member.user_id}: #{member.workspace_role}" + end + ``` +</CodeGroup> + +Update a workspace member's role: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members/user_01XyDMpzjS89pFZXqSFUBDr6" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{"workspace_role": "workspace_admin"}' + ``` + + ```bash CLI + ant beta:organization:workspaces:members update \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \ + --workspace-role workspace_admin + ``` + + ```python Python + client = anthropic.Anthropic() + + member = client.beta.organization.workspaces.members.update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + workspace_role="workspace_admin", + ) + + print(f"user_id: {member.user_id}") + print(f"workspace_role: {member.workspace_role}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const member = await client.beta.organization.workspaces.members.update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + { + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + workspace_role: "workspace_admin" + } + ); + + console.log(`user_id: ${member.user_id}`); + console.log(`workspace_role: ${member.workspace_role}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Workspaces; + + AnthropicClient client = new(); + + var member = await client.Beta.Organization.Workspaces.Members.Update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + new() + { + WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + WorkspaceRole = BetaWorkspaceRole.WorkspaceAdmin + } + ); + + Console.WriteLine($"user_id: {member.UserID}"); + Console.WriteLine($"workspace_role: {member.WorkspaceRole.Raw()}"); + ``` + + ```go Go + client := anthropic.NewClient() + + member, err := client.Beta.Organization.Workspaces.Members.Update( + context.Background(), + "user_01XyDMpzjS89pFZXqSFUBDr6", + anthropic.BetaOrganizationWorkspaceMemberUpdateParams{ + WorkspaceID: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + WorkspaceRole: anthropic.BetaWorkspaceRoleWorkspaceAdmin, + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("user_id: %s\n", member.UserID) + fmt.Printf("workspace_role: %s\n", member.WorkspaceRole) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.BetaWorkspaceRole; + import com.anthropic.models.beta.organization.workspaces.members.MemberUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberUpdateParams.builder() + .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + .workspaceRole(BetaWorkspaceRole.WORKSPACE_ADMIN) + .build(); + var member = client.beta().organization().workspaces().members() + .update("user_01XyDMpzjS89pFZXqSFUBDr6", params); + + IO.println("user_id: " + member.userId()); + IO.println("workspace_role: " + member.workspaceRole().asString()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\Workspaces\WorkspaceRole; + // ... + + $client = new Client(); + + $member = $client->beta->organization->workspaces->members->update( + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + workspaceRole: WorkspaceRole::WORKSPACE_ADMIN, + ); + + echo "user_id: {$member->userID}\n"; + echo "workspace_role: {$member->workspaceRole}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + user_id = "user_01XyDMpzjS89pFZXqSFUBDr6" + member = client.beta.organization.workspaces.members.update( + user_id, + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + workspace_role: :workspace_admin + ) + + puts "user_id: #{member.user_id}" + puts "workspace_role: #{member.workspace_role}" + ``` +</CodeGroup> + +Remove a member from a workspace: + +<CodeGroup> + ```bash cURL + curl -X DELETE "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members/user_01XyDMpzjS89pFZXqSFUBDr6" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:workspaces:members remove \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + ``` + + ```python Python + client = anthropic.Anthropic() + + removed_member = client.beta.organization.workspaces.members.remove( + "user_01XyDMpzjS89pFZXqSFUBDr6", workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + print(f"user_id: {removed_member.user_id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const removedMember = await client.beta.organization.workspaces.members.remove( + "user_01XyDMpzjS89pFZXqSFUBDr6", + { workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" } + ); + + console.log(`user_id: ${removedMember.user_id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var removedMember = await client.Beta.Organization.Workspaces.Members.Remove( + "user_01XyDMpzjS89pFZXqSFUBDr6", + new() { WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" } + ); + + Console.WriteLine($"user_id: {removedMember.UserID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + removedMember, err := client.Beta.Organization.Workspaces.Members.Remove( + context.Background(), + "user_01XyDMpzjS89pFZXqSFUBDr6", + anthropic.BetaOrganizationWorkspaceMemberRemoveParams{ + WorkspaceID: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("user_id: %s\n", removedMember.UserID) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.members.MemberRemoveParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberRemoveParams.builder() + .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + .build(); + var removedMember = client.beta().organization().workspaces().members() + .remove("user_01XyDMpzjS89pFZXqSFUBDr6", params); + + IO.println("user_id: " + removedMember.userId()); + } + ``` + + ```php PHP + $client = new Client(); + + $removedMember = $client->beta->organization->workspaces->members->remove( + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + ); + + echo "user_id: {$removedMember->userID}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + user_id = "user_01XyDMpzjS89pFZXqSFUBDr6" + removed_member = client.beta.organization.workspaces.members.remove( + user_id, + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + puts "user_id: #{removed_member.user_id}" + ``` +</CodeGroup> + +### API keys + +Monitor and manage [API keys](https://platform.claude.com/docs/en/api/admin/api_keys/list). Each key in the response includes its `expires_at` timestamp (`null` for keys without an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration)): + +List the active API keys in a workspace: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/api_keys?limit=10&status=active&workspace_id=wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:api-keys list \ + --limit 10 \ + --status active \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + ``` + + ```python Python + client = anthropic.Anthropic() + + api_keys = client.beta.organization.api_keys.list( + limit=10, status="active", workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + # Automatically fetches more pages as needed. + for api_key in api_keys: + print(f"{api_key.id}: {api_key.name} ({api_key.status})") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const apiKeys = await client.beta.organization.apiKeys.list({ + limit: 10, + status: "active", + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + }); + + for await (const apiKey of apiKeys) { + console.log(`${apiKey.id}: ${apiKey.name} (${apiKey.status})`); + } + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.ApiKeys; + + AnthropicClient client = new(); + + var page = await client.Beta.Organization.ApiKeys.List(new() + { + Limit = 10, + Status = ApiKeyListParamsStatus.Active, + WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + }); + + await foreach (var apiKey in page.Paginate()) + { + Console.WriteLine($"{apiKey.ID}: {apiKey.Name} ({apiKey.Status.Raw()})"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + apiKeys := client.Beta.Organization.APIKeys.ListAutoPaging(context.Background(), anthropic.BetaOrganizationAPIKeyListParams{ + Limit: anthropic.Int(10), + Status: anthropic.BetaOrganizationAPIKeyListParamsStatusActive, + WorkspaceID: anthropic.String("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"), + }) + + for apiKeys.Next() { + apiKey := apiKeys.Current() + fmt.Printf("%s: %s (%s)\n", apiKey.ID, apiKey.Name, apiKey.Status) + } + if err := apiKeys.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.apikeys.ApiKeyListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ApiKeyListParams.builder() + .limit(10) + .status(ApiKeyListParams.Status.ACTIVE) + .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + .build(); + var apiKeys = client.beta().organization().apiKeys().list(params); + + for (var apiKey : apiKeys.autoPager()) { + IO.println(apiKey.id() + ": " + apiKey.name() + " (" + apiKey.status().asString() + ")"); + } + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\APIKeys\APIKeyListParams\Status; + // ... + + $client = new Client(); + + $apiKeys = $client->beta->organization->apiKeys->list( + limit: 10, + status: Status::ACTIVE, + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + ); + + foreach ($apiKeys->getItems() as $apiKey) { + echo "{$apiKey->id}: {$apiKey->name} ({$apiKey->status})\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + api_keys = client.beta.organization.api_keys.list( + limit: 10, + status: :active, + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + api_keys.data.each do |api_key| + puts "#{api_key.id}: #{api_key.name} (#{api_key.status})" + end + ``` +</CodeGroup> + +Rename or deactivate an API key: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/api_keys/apikey_01Rj2N8SVvo6BePZj99NhmiT" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ "status": "inactive", "name": "New Key Name" }' ``` + + ```bash CLI + ant beta:organization:api-keys update \ + --api-key-id apikey_01Rj2N8SVvo6BePZj99NhmiT \ + --status inactive \ + --name "New Key Name" + ``` + + ```python Python + client = anthropic.Anthropic() + + api_key = client.beta.organization.api_keys.update( + "apikey_01Rj2N8SVvo6BePZj99NhmiT", status="inactive", name="New Key Name" + ) + + print(f"id: {api_key.id}") + print(f"name: {api_key.name}") + print(f"status: {api_key.status}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const apiKey = await client.beta.organization.apiKeys.update( + "apikey_01Rj2N8SVvo6BePZj99NhmiT", + { + status: "inactive", + name: "New Key Name" + } + ); + + console.log(`id: ${apiKey.id}`); + console.log(`name: ${apiKey.name}`); + console.log(`status: ${apiKey.status}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.ApiKeys; + + AnthropicClient client = new(); + + var apiKey = await client.Beta.Organization.ApiKeys.Update( + "apikey_01Rj2N8SVvo6BePZj99NhmiT", + new() + { + Status = Status.Inactive, + Name = "New Key Name" + } + ); + + Console.WriteLine($"id: {apiKey.ID}"); + Console.WriteLine($"name: {apiKey.Name}"); + Console.WriteLine($"status: {apiKey.Status.Raw()}"); + ``` + + ```go Go + client := anthropic.NewClient() + + apiKey, err := client.Beta.Organization.APIKeys.Update( + context.Background(), + "apikey_01Rj2N8SVvo6BePZj99NhmiT", + anthropic.BetaOrganizationAPIKeyUpdateParams{ + Status: anthropic.BetaOrganizationAPIKeyUpdateParamsStatusInactive, + Name: anthropic.String("New Key Name"), + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", apiKey.ID) + fmt.Printf("name: %s\n", apiKey.Name) + fmt.Printf("status: %s\n", apiKey.Status) + ``` + + ```java Java + import com.anthropic.models.beta.organization.apikeys.ApiKeyUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ApiKeyUpdateParams.builder() + .status(ApiKeyUpdateParams.Status.INACTIVE) + .name("New Key Name") + .build(); + var apiKey = client.beta().organization().apiKeys() + .update("apikey_01Rj2N8SVvo6BePZj99NhmiT", params); + + IO.println("id: " + apiKey.id()); + IO.println("name: " + apiKey.name()); + IO.println("status: " + apiKey.status().asString()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\APIKeys\APIKeyUpdateParams\Status; + // ... + + $client = new Client(); + + $apiKey = $client->beta->organization->apiKeys->update( + apiKeyID: 'apikey_01Rj2N8SVvo6BePZj99NhmiT', + status: Status::INACTIVE, + name: 'New Key Name', + ); + + echo "id: {$apiKey->id}\n"; + echo "name: {$apiKey->name}\n"; + echo "status: {$apiKey->status}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + api_key_id = "apikey_01Rj2N8SVvo6BePZj99NhmiT" + api_key = client.beta.organization.api_keys.update( + api_key_id, + status: :inactive, + name: "New Key Name" + ) + + puts "id: #{api_key.id}" + puts "name: #{api_key.name}" + puts "status: #{api_key.status}" + ``` </CodeGroup> ### Service accounts -Create and manage service accounts (`svac_...`), the non-human identities that [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation) tokens act as. Admin API keys are not accepted on the service-account, federation-issuer, or federation-rule endpoints; use an `org:admin` OAuth token. See [Manage WIF with the Admin API](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#service-accounts). +Create and manage service accounts (`svac_...`), the non-human identities that [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation) tokens act as. These endpoints, like the federation-issuer and federation-rule endpoints, require an `org:admin` OAuth token. See [Manage WIF with the Admin API](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#service-accounts). ### Federation issuers
## Accessing organization info -Get information about your organization programmatically with the `/v1/organizations/me` endpoint. - -For example: - -```bash cURL -curl "https://api.anthropic.com/v1/organizations/me" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +The `/v1/organizations/me` endpoint returns the organization that your credential belongs to: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/me" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization retrieve + ``` + + ```python Python + client = anthropic.Anthropic() + + organization = client.beta.organization.retrieve() + + print(f"id: {organization.id}") + print(f"name: {organization.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const organization = await client.beta.organization.retrieve(); + + console.log(`id: ${organization.id}`); + console.log(`name: ${organization.name}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var organization = await client.Beta.Organization.Retrieve(); + + Console.WriteLine($"id: {organization.ID}"); + Console.WriteLine($"name: {organization.Name}"); + ``` + + ```go Go + client := anthropic.NewClient() + + organization, err := client.Beta.Organization.Get(context.Background()) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", organization.ID) + fmt.Printf("name: %s\n", organization.Name) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var organization = client.beta().organization().retrieve(); + + IO.println("id: " + organization.id()); + IO.println("name: " + organization.name()); + ``` + + ```php PHP + $client = new Client(); + + $organization = $client->beta->organization->retrieve(); + + echo "id: {$organization->id}\n"; + echo "name: {$organization->name}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + organization = client.beta.organization.retrieve + + puts "id: #{organization.id}" + puts "name: #{organization.name}" + ``` +</CodeGroup> ```json {
} ``` -This endpoint is useful for programmatically determining which organization an Admin API key belongs to. - -For complete parameter details and response schemas, see the [Organization Info API reference](https://platform.claude.com/docs/en/api/admin-api/organization/get-me). +For parameter details and response schemas, see the [Organization Info API reference](https://platform.claude.com/docs/en/api/admin-api/organization/get-me). ## Usage and cost reports
## Compliance API -Retrieve audit and activity data for your organization with the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api). Admin API keys can read the Activity Feed only; for full access, see [Set up the Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api-access). +Retrieve audit and activity data for your organization with the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api). Admin API keys can read only the Activity Feed. For full access, see [Set up the Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api-access). ## Best practices -To effectively use the Admin API: - * Use meaningful names and descriptions for workspaces and API keys -* Implement proper error handling for failed operations +* Handle errors from failed operations * Regularly audit member roles and permissions * Clean up unused workspaces and expired invites * Monitor API key usage, audit each key's [`expires_at`](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration), and rotate keys periodically
</Accordion> <Accordion title="Can I create new API keys through the Admin API?"> - No, new API keys can only be created through the Claude Console for security reasons. The Admin API can only manage existing API keys. + No. You create API keys in the Claude Console. The Admin API can only read, rename, and change the status of existing keys. </Accordion> <Accordion title="What happens to API keys when removing a user?"> - API keys persist in their current state as they are scoped to the organization, not to individual users. + They're unaffected. API keys belong to the organization, not to individual users. </Accordion> <Accordion title="Can organization admins be removed through the API?"> - No, organization members with the admin role cannot be removed through the API for security reasons. + No. The API can't remove members with the admin role. </Accordion> <Accordion title="How long do organization invites last?"> - Organization invites expire after 21 days. There is currently no way to modify this expiration period. + Invites expire after 21 days. The expiration period isn't configurable. </Accordion> </AccordionGroup>
api/skills/versions Changed · +2 / -2 lines
- `version: string` - Identifies the skill version: a version ID, or — where the endpoint accepts it — the literal `latest` for the skill's most recent version. + Identifies the skill version: a version ID, or the literal `latest` for the skill's most recent version. Requests carrying the `skills-2025-10-02` beta header address versions by their Unix epoch timestamp instead (e.g., "1759178010641129").
- `version: string` - Identifies the skill version: a version ID, or — where the endpoint accepts it — the literal `latest` for the skill's most recent version. + Identifies the skill version by its version ID. Requests carrying the `skills-2025-10-02` beta header address versions by their Unix epoch timestamp instead (e.g., "1759178010641129").
manage-claude/cmek-aws-kms Changed · +339 / -30 lines
For organizations on [Claude Platform on AWS](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws), the external key endpoints are not yet available. Register and attach your key in the Claude Console instead. There is no separate validation step; the key policy is first exercised when a workspace starts using the key, so a key policy problem surfaces at that point rather than at registration. </Note> - ```bash - curl -sS https://api.anthropic.com/v1/organizations/external_keys \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{ - "display_name": "<friendly-name>", - "geo": "us", - "provider_config": { - "type": "aws", - "kms_arn": "<key-arn-from-create-key-step>", - "role_arn": "arn:aws:iam::915198916910:role/anthropic-cmek-client-us" + <CodeGroup> + ```bash cURL + curl -sS "https://api.anthropic.com/v1/organizations/external_keys" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "display_name": "<friendly-name>", + "geo": "us", + "provider_config": { + "type": "aws", + "kms_arn": "<key-arn-from-create-key-step>" + } + }' + ``` + + ```bash CLI + ant beta:organization:external-keys create <<'YAML' + display_name: "<friendly-name>" + geo: us + provider_config: + type: aws + kms_arn: "<key-arn-from-create-key-step>" + YAML + ``` + + ```python Python + client = anthropic.Anthropic() + + external_key = client.beta.organization.external_keys.create( + display_name="<friendly-name>", + geo="us", + provider_config={"type": "aws", "kms_arn": "<key-arn-from-create-key-step>"}, + ) + + print(f"id: {external_key.id}") + print(f"display_name: {external_key.display_name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const externalKey = await client.beta.organization.externalKeys.create({ + display_name: "<friendly-name>", + geo: "us", + provider_config: { + type: "aws", + kms_arn: "<key-arn-from-create-key-step>" } - }' - ``` + }); + console.log(`id: ${externalKey.id}`); + console.log(`display_name: ${externalKey.display_name}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.ExternalKeys; + + AnthropicClient client = new(); + + var externalKey = await client.Beta.Organization.ExternalKeys.Create(new() + { + DisplayName = "<friendly-name>", + Geo = Geo.Us, + ProviderConfig = new BetaAwsExternalKeyConfig + { + KmsArn = "<key-arn-from-create-key-step>" + } + }); + + Console.WriteLine($"id: {externalKey.ID}"); + Console.WriteLine($"display_name: {externalKey.DisplayName}"); + ``` + + ```go Go + client := anthropic.NewClient() + + externalKey, err := client.Beta.Organization.ExternalKeys.New(context.Background(), anthropic.BetaOrganizationExternalKeyNewParams{ + DisplayName: anthropic.String("<friendly-name>"), + Geo: anthropic.BetaOrganizationExternalKeyNewParamsGeoUs, + ProviderConfig: anthropic.BetaOrganizationExternalKeyNewParamsProviderConfigUnion{ + OfAWS: &anthropic.BetaAWSExternalKeyConfigParam{ + KMSARN: "<key-arn-from-create-key-step>", + }, + }, + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", externalKey.ID) + fmt.Printf("display_name: %s\n", externalKey.DisplayName) + ``` + + ```java Java + import com.anthropic.models.beta.organization.externalkeys.BetaAwsExternalKeyConfig; + import com.anthropic.models.beta.organization.externalkeys.ExternalKeyCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ExternalKeyCreateParams.builder() + .displayName("<friendly-name>") + .geo(ExternalKeyCreateParams.Geo.US) + .providerConfig(BetaAwsExternalKeyConfig.builder() + .kmsArn("<key-arn-from-create-key-step>") + .build()) + .build(); + var externalKey = client.beta().organization().externalKeys().create(params); + + IO.println("id: " + externalKey.id()); + IO.println("display_name: " + externalKey.displayName().orElseThrow()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\ExternalKeys\ExternalKeyCreateParams\Geo; + // ... + + $client = new Client(); + + $externalKey = $client->beta->organization->externalKeys->create( + displayName: '<friendly-name>', + geo: Geo::US, + providerConfig: [ + 'type' => 'aws', + 'kmsARN' => '<key-arn-from-create-key-step>', + ], + ); + + echo "id: {$externalKey->id}\n"; + echo "display_name: {$externalKey->displayName}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + external_key = client.beta.organization.external_keys.create( + display_name: "<friendly-name>", + geo: :us, + provider_config: { + type: :aws, + kms_arn: "<key-arn-from-create-key-step>" + } + ) + + puts "id: #{external_key.id}" + puts "display_name: #{external_key.display_name}" + ``` + </CodeGroup> + The response contains the external key ID: ```json
<Step title="Validate the key"> Trigger an encrypt and decrypt round-trip against your key. - ```bash - curl -sS -X POST https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{}' - ``` + <CodeGroup> + ```bash cURL + curl -sS -X POST "https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + ```bash CLI + ant beta:organization:external-keys validate --external-key-id "ekey_<id>" + ``` + + ```python Python + client = anthropic.Anthropic() + + validation = client.beta.organization.external_keys.validate("ekey_<id>") + + print(f"status: {validation.status}") + print(f"error: {validation.error}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const validation = await client.beta.organization.externalKeys.validate("ekey_<id>"); + + console.log(`status: ${validation.status}`); + console.log(`error: ${validation.error}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var validation = await client.Beta.Organization.ExternalKeys.Validate("ekey_<id>"); + + Console.WriteLine($"status: {validation.Status.Raw()}"); + Console.WriteLine($"error: {validation.Error}"); + ``` + + ```go Go + client := anthropic.NewClient() + + validation, err := client.Beta.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>") + if err != nil { + log.Fatal(err) + } + + fmt.Printf("status: %s\n", validation.Status) + fmt.Printf("error: %s\n", validation.Error) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var validation = client.beta().organization().externalKeys().validate("ekey_<id>"); + + IO.println("status: " + validation.status().asString()); + IO.println("error: " + validation.error().orElse("")); + ``` + + ```php PHP + $client = new Client(); + + $validation = $client->beta->organization->externalKeys->validate( + externalKeyID: 'ekey_<id>', + ); + + echo "status: {$validation->status}\n"; + echo "error: {$validation->error}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + external_key_id = "ekey_<id>" + validation = client.beta.organization.external_keys.validate(external_key_id) + + puts "status: #{validation.status}" + puts "error: #{validation.error}" + ``` + </CodeGroup> + A successful response looks like this: ```json
<Step title="Attach the key to a workspace"> Once the key is validated, attach it to a new workspace before you send any requests to that workspace. For a workspace that already receives requests, the key can take [up to a day to take effect](https://platform.claude.com/docs/en/manage-claude/cmek#how-it-works). - ```bash - curl -sS -X POST https://api.anthropic.com/v1/organizations/workspaces/<workspace-id> \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{ - "external_key_id": "ekey_<id>" - }' - ``` + <CodeGroup> + ```bash cURL + curl -sS -X POST "https://api.anthropic.com/v1/organizations/workspaces/<workspace-id>" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "external_key_id": "ekey_<id>" + }' + ``` + + ```bash CLI + ant beta:organization:workspaces update \ + --workspace-id "<workspace-id>" \ + --external-key-id "ekey_<id>" + ``` + + ```python Python + client = anthropic.Anthropic() + + workspace = client.beta.organization.workspaces.update( + "<workspace-id>", external_key_id="ekey_<id>" + ) + + print(f"id: {workspace.id}") + print(f"external_key_id: {workspace.external_key_id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const workspace = await client.beta.organization.workspaces.update("<workspace-id>", { + external_key_id: "ekey_<id>" + }); + + console.log(`id: ${workspace.id}`); + console.log(`external_key_id: ${workspace.external_key_id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var workspace = await client.Beta.Organization.Workspaces.Update("<workspace-id>", new() + { + ExternalKeyID = "ekey_<id>" + }); + + Console.WriteLine($"id: {workspace.ID}"); + Console.WriteLine($"external_key_id: {workspace.ExternalKeyID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + workspace, err := client.Beta.Organization.Workspaces.Update( + context.Background(), + "<workspace-id>", + anthropic.BetaOrganizationWorkspaceUpdateParams{ + ExternalKeyID: anthropic.String("ekey_<id>"), + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", workspace.ID) + fmt.Printf("external_key_id: %s\n", workspace.ExternalKeyID) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.WorkspaceUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = WorkspaceUpdateParams.builder() + .externalKeyId("ekey_<id>") + .build(); + var workspace = client.beta().organization().workspaces().update("<workspace-id>", params); + + IO.println("id: " + workspace.id()); + IO.println("external_key_id: " + workspace.externalKeyId().orElseThrow()); + } + ``` + + ```php PHP + $client = new Client(); + + $workspace = $client->beta->organization->workspaces->update( + workspaceID: '<workspace-id>', + externalKeyID: 'ekey_<id>', + ); + + echo "id: {$workspace->id}\n"; + echo "external_key_id: {$workspace->externalKeyID}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "<workspace-id>" + workspace = client.beta.organization.workspaces.update( + workspace_id, + external_key_id: "ekey_<id>" + ) + + puts "id: #{workspace.id}" + puts "external_key_id: #{workspace.external_key_id}" + ``` + </CodeGroup> </Step> </Steps> </Tab>
manage-claude/cmek-azure-key-vault Changed · +358 / -30 lines
<Step title="Register the key with Anthropic"> Create an external key configuration through the Admin API. - ```bash - curl -sS https://api.anthropic.com/v1/organizations/external_keys \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{ - "display_name": "<friendly-name>", - "geo": "us", - "provider_config": { - "type": "azure", - "vault_uri": "https://<your-vault-name>.vault.azure.net/", - "key_name": "<your-key-name>", - "tenant_id": "<your-tenant-id>" + <CodeGroup> + ```bash cURL + curl -sS "https://api.anthropic.com/v1/organizations/external_keys" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "display_name": "<friendly-name>", + "geo": "us", + "provider_config": { + "type": "azure", + "vault_uri": "https://<your-vault-name>.vault.azure.net/", + "key_name": "<your-key-name>", + "tenant_id": "<your-tenant-id>" + } + }' + ``` + + ```bash CLI + ant beta:organization:external-keys create <<'YAML' + display_name: "<friendly-name>" + geo: us + provider_config: + type: azure + vault_uri: "https://<your-vault-name>.vault.azure.net/" + key_name: "<your-key-name>" + tenant_id: "<your-tenant-id>" + YAML + ``` + + ```python Python + client = anthropic.Anthropic() + + external_key = client.beta.organization.external_keys.create( + display_name="<friendly-name>", + geo="us", + provider_config={ + "type": "azure", + "vault_uri": "https://<your-vault-name>.vault.azure.net/", + "key_name": "<your-key-name>", + "tenant_id": "<your-tenant-id>", + }, + ) + + print(f"id: {external_key.id}") + print(f"display_name: {external_key.display_name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const externalKey = await client.beta.organization.externalKeys.create({ + display_name: "<friendly-name>", + geo: "us", + provider_config: { + type: "azure", + vault_uri: "https://<your-vault-name>.vault.azure.net/", + key_name: "<your-key-name>", + tenant_id: "<your-tenant-id>" } - }' - ``` + }); + console.log(`id: ${externalKey.id}`); + console.log(`display_name: ${externalKey.display_name}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.ExternalKeys; + + AnthropicClient client = new(); + + var externalKey = await client.Beta.Organization.ExternalKeys.Create(new() + { + DisplayName = "<friendly-name>", + Geo = Geo.Us, + ProviderConfig = new BetaAzureExternalKeyConfigParam + { + VaultUri = "https://<your-vault-name>.vault.azure.net/", + KeyName = "<your-key-name>", + TenantID = "<your-tenant-id>" + } + }); + + Console.WriteLine($"id: {externalKey.ID}"); + Console.WriteLine($"display_name: {externalKey.DisplayName}"); + ``` + + ```go Go + client := anthropic.NewClient() + + externalKey, err := client.Beta.Organization.ExternalKeys.New(context.Background(), anthropic.BetaOrganizationExternalKeyNewParams{ + DisplayName: anthropic.String("<friendly-name>"), + Geo: anthropic.BetaOrganizationExternalKeyNewParamsGeoUs, + ProviderConfig: anthropic.BetaOrganizationExternalKeyNewParamsProviderConfigUnion{ + OfAzure: &anthropic.BetaAzureExternalKeyConfigParam{ + VaultURI: "https://<your-vault-name>.vault.azure.net/", + KeyName: "<your-key-name>", + TenantID: "<your-tenant-id>", + }, + }, + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", externalKey.ID) + fmt.Printf("display_name: %s\n", externalKey.DisplayName) + ``` + + ```java Java + import com.anthropic.models.beta.organization.externalkeys.BetaAzureExternalKeyConfigParam; + import com.anthropic.models.beta.organization.externalkeys.ExternalKeyCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ExternalKeyCreateParams.builder() + .displayName("<friendly-name>") + .geo(ExternalKeyCreateParams.Geo.US) + .providerConfig(BetaAzureExternalKeyConfigParam.builder() + .vaultUri("https://<your-vault-name>.vault.azure.net/") + .keyName("<your-key-name>") + .tenantId("<your-tenant-id>") + .build()) + .build(); + var externalKey = client.beta().organization().externalKeys().create(params); + + IO.println("id: " + externalKey.id()); + IO.println("display_name: " + externalKey.displayName().orElseThrow()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\ExternalKeys\ExternalKeyCreateParams\Geo; + // ... + + $client = new Client(); + + $externalKey = $client->beta->organization->externalKeys->create( + displayName: '<friendly-name>', + geo: Geo::US, + providerConfig: [ + 'type' => 'azure', + 'vaultURI' => 'https://<your-vault-name>.vault.azure.net/', + 'keyName' => '<your-key-name>', + 'tenantID' => '<your-tenant-id>', + ], + ); + + echo "id: {$externalKey->id}\n"; + echo "display_name: {$externalKey->displayName}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + external_key = client.beta.organization.external_keys.create( + display_name: "<friendly-name>", + geo: :us, + provider_config: { + type: :azure, + vault_uri: "https://<your-vault-name>.vault.azure.net/", + key_name: "<your-key-name>", + tenant_id: "<your-tenant-id>" + } + ) + + puts "id: #{external_key.id}" + puts "display_name: #{external_key.display_name}" + ``` + </CodeGroup> + The response contains the external key ID: ```json
<Step title="Validate the key"> Trigger an encrypt and decrypt round-trip against your key. This confirms that Anthropic can authenticate to your tenant and perform wrap and unwrap operations. - ```bash - curl -sS -X POST https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" -d '{}' - ``` + <CodeGroup> + ```bash cURL + curl -sS -X POST "https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + ```bash CLI + ant beta:organization:external-keys validate --external-key-id "ekey_<id>" + ``` + + ```python Python + client = anthropic.Anthropic() + + validation = client.beta.organization.external_keys.validate("ekey_<id>") + + print(f"status: {validation.status}") + print(f"error: {validation.error}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const validation = await client.beta.organization.externalKeys.validate("ekey_<id>"); + + console.log(`status: ${validation.status}`); + console.log(`error: ${validation.error}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var validation = await client.Beta.Organization.ExternalKeys.Validate("ekey_<id>"); + + Console.WriteLine($"status: {validation.Status.Raw()}"); + Console.WriteLine($"error: {validation.Error}"); + ``` + + ```go Go + client := anthropic.NewClient() + + validation, err := client.Beta.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>") + if err != nil { + log.Fatal(err) + } + + fmt.Printf("status: %s\n", validation.Status) + fmt.Printf("error: %s\n", validation.Error) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var validation = client.beta().organization().externalKeys().validate("ekey_<id>"); + + IO.println("status: " + validation.status().asString()); + IO.println("error: " + validation.error().orElse("")); + ``` + + ```php PHP + $client = new Client(); + + $validation = $client->beta->organization->externalKeys->validate( + externalKeyID: 'ekey_<id>', + ); + + echo "status: {$validation->status}\n"; + echo "error: {$validation->error}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + validation = client.beta.organization.external_keys.validate("ekey_<id>") + + puts "status: #{validation.status}" + puts "error: #{validation.error}" + ``` + </CodeGroup> + A successful response looks like this: ```json
<Step title="Attach the key to a workspace"> Once the key is validated, attach it to a new workspace before you send any requests to that workspace. For a workspace that already receives requests, the key can take [up to a day to take effect](https://platform.claude.com/docs/en/manage-claude/cmek#how-it-works). - ```bash - curl -sS -X POST https://api.anthropic.com/v1/organizations/workspaces/<workspace-id> \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{ - "external_key_id": "ekey_<id>" - }' - ``` + <CodeGroup> + ```bash cURL + curl -sS -X POST "https://api.anthropic.com/v1/organizations/workspaces/<workspace-id>" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "external_key_id": "ekey_<id>" + }' + ``` + + ```bash CLI + ant beta:organization:workspaces update \ + --workspace-id "<workspace-id>" \ + --external-key-id "ekey_<id>" + ``` + + ```python Python + client = anthropic.Anthropic() + + workspace = client.beta.organization.workspaces.update( + "<workspace-id>", external_key_id="ekey_<id>" + ) + + print(f"id: {workspace.id}") + print(f"external_key_id: {workspace.external_key_id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const workspace = await client.beta.organization.workspaces.update("<workspace-id>", { + external_key_id: "ekey_<id>" + }); + + console.log(`id: ${workspace.id}`); + console.log(`external_key_id: ${workspace.external_key_id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var workspace = await client.Beta.Organization.Workspaces.Update("<workspace-id>", new() + { + ExternalKeyID = "ekey_<id>" + }); + + Console.WriteLine($"id: {workspace.ID}"); + Console.WriteLine($"external_key_id: {workspace.ExternalKeyID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + workspace, err := client.Beta.Organization.Workspaces.Update( + context.Background(), + "<workspace-id>", + anthropic.BetaOrganizationWorkspaceUpdateParams{ + ExternalKeyID: anthropic.String("ekey_<id>"), + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", workspace.ID) + fmt.Printf("external_key_id: %s\n", workspace.ExternalKeyID) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.WorkspaceUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = WorkspaceUpdateParams.builder() + .externalKeyId("ekey_<id>") + .build(); + var workspace = client.beta().organization().workspaces().update("<workspace-id>", params); + + IO.println("id: " + workspace.id()); + IO.println("external_key_id: " + workspace.externalKeyId().orElseThrow()); + } + ``` + + ```php PHP + $client = new Client(); + + $workspace = $client->beta->organization->workspaces->update( + workspaceID: '<workspace-id>', + externalKeyID: 'ekey_<id>', + ); + + echo "id: {$workspace->id}\n"; + echo "external_key_id: {$workspace->externalKeyID}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace = client.beta.organization.workspaces.update( + "<workspace-id>", + external_key_id: "ekey_<id>" + ) + + puts "id: #{workspace.id}" + puts "external_key_id: #{workspace.external_key_id}" + ``` + </CodeGroup> </Step> </Steps> </Tab>
manage-claude/cmek-google-cloud-kms Changed · +340 / -29 lines
<Step title="Register the key with Anthropic"> Create an external key configuration through the Admin API, using the resource name from the Note the full key resource name step under Encryption key setup. - ```bash - curl -sS https://api.anthropic.com/v1/organizations/external_keys \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{ - "display_name": "<friendly-name>", - "geo": "us", - "provider_config": { - "type": "gcp", - "key_name": "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>" + <CodeGroup> + ```bash cURL + curl -sS "https://api.anthropic.com/v1/organizations/external_keys" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "display_name": "<friendly-name>", + "geo": "us", + "provider_config": { + "type": "gcp", + "key_name": "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>" + } + }' + ``` + + ```bash CLI + ant beta:organization:external-keys create <<'YAML' + display_name: "<friendly-name>" + geo: us + provider_config: + type: gcp + key_name: "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>" + YAML + ``` + + ```python Python + client = anthropic.Anthropic() + + external_key = client.beta.organization.external_keys.create( + display_name="<friendly-name>", + geo="us", + provider_config={ + "type": "gcp", + "key_name": "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>", + }, + ) + + print(f"id: {external_key.id}") + print(f"display_name: {external_key.display_name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const externalKey = await client.beta.organization.externalKeys.create({ + display_name: "<friendly-name>", + geo: "us", + provider_config: { + type: "gcp", + key_name: + "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>" } - }' - ``` + }); + console.log(`id: ${externalKey.id}`); + console.log(`display_name: ${externalKey.display_name}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.ExternalKeys; + + AnthropicClient client = new(); + + var externalKey = await client.Beta.Organization.ExternalKeys.Create(new() + { + DisplayName = "<friendly-name>", + Geo = Geo.Us, + ProviderConfig = new BetaGcpExternalKeyConfig + { + KeyName = "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>" + } + }); + + Console.WriteLine($"id: {externalKey.ID}"); + Console.WriteLine($"display_name: {externalKey.DisplayName}"); + ``` + + ```go Go + client := anthropic.NewClient() + + externalKey, err := client.Beta.Organization.ExternalKeys.New(context.Background(), anthropic.BetaOrganizationExternalKeyNewParams{ + DisplayName: anthropic.String("<friendly-name>"), + Geo: anthropic.BetaOrganizationExternalKeyNewParamsGeoUs, + ProviderConfig: anthropic.BetaOrganizationExternalKeyNewParamsProviderConfigUnion{ + OfGCP: &anthropic.BetaGCPExternalKeyConfigParam{ + KeyName: "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>", + }, + }, + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", externalKey.ID) + fmt.Printf("display_name: %s\n", externalKey.DisplayName) + ``` + + ```java Java + import com.anthropic.models.beta.organization.externalkeys.ExternalKeyCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ExternalKeyCreateParams.builder() + .displayName("<friendly-name>") + .geo(ExternalKeyCreateParams.Geo.US) + .gcpProviderConfig("projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>") + .build(); + var externalKey = client.beta().organization().externalKeys().create(params); + + IO.println("id: " + externalKey.id()); + IO.println("display_name: " + externalKey.displayName().orElseThrow()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\ExternalKeys\ExternalKeyCreateParams\Geo; + // ... + + $client = new Client(); + + $externalKey = $client->beta->organization->externalKeys->create( + displayName: '<friendly-name>', + geo: Geo::US, + providerConfig: [ + 'type' => 'gcp', + 'keyName' => 'projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>', + ], + ); + + echo "id: {$externalKey->id}\n"; + echo "display_name: {$externalKey->displayName}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + external_key = client.beta.organization.external_keys.create( + display_name: "<friendly-name>", + geo: :us, + provider_config: { + type: :gcp, + key_name: "projects/<your-project-id>/locations/<region>/keyRings/<your-keyring-name>/cryptoKeys/<your-key-name>" + } + ) + + puts "id: #{external_key.id}" + puts "display_name: #{external_key.display_name}" + ``` + </CodeGroup> + The response contains the external key ID: ```json
<Step title="Validate the key"> Trigger an encrypt and decrypt round-trip against your key. - ```bash - curl -sS -X POST https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{}' - ``` + <CodeGroup> + ```bash cURL + curl -sS -X POST "https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + ```bash CLI + ant beta:organization:external-keys validate --external-key-id "ekey_<id>" + ``` + + ```python Python + client = anthropic.Anthropic() + + validation = client.beta.organization.external_keys.validate("ekey_<id>") + + print(f"status: {validation.status}") + print(f"error: {validation.error}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const validation = await client.beta.organization.externalKeys.validate("ekey_<id>"); + + console.log(`status: ${validation.status}`); + console.log(`error: ${validation.error}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var validation = await client.Beta.Organization.ExternalKeys.Validate("ekey_<id>"); + + Console.WriteLine($"status: {validation.Status.Raw()}"); + Console.WriteLine($"error: {validation.Error}"); + ``` + + ```go Go + client := anthropic.NewClient() + + validation, err := client.Beta.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>") + if err != nil { + log.Fatal(err) + } + + fmt.Printf("status: %s\n", validation.Status) + fmt.Printf("error: %s\n", validation.Error) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var validation = client.beta().organization().externalKeys().validate("ekey_<id>"); + + IO.println("status: " + validation.status().asString()); + IO.println("error: " + validation.error().orElse("")); + ``` + + ```php PHP + $client = new Client(); + + $validation = $client->beta->organization->externalKeys->validate( + externalKeyID: 'ekey_<id>', + ); + + echo "status: {$validation->status}\n"; + echo "error: {$validation->error}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + external_key_id = "ekey_<id>" + validation = client.beta.organization.external_keys.validate(external_key_id) + + puts "status: #{validation.status}" + puts "error: #{validation.error}" + ``` + </CodeGroup> + A successful response looks like this: ```json
<Step title="Attach the key to a workspace"> Once the key is validated, attach it to a new workspace before you send any requests to that workspace. For a workspace that already receives requests, the key can take [up to a day to take effect](https://platform.claude.com/docs/en/manage-claude/cmek#how-it-works). - ```bash - curl -sS -X POST https://api.anthropic.com/v1/organizations/workspaces/<workspace-id> \ - -H "x-api-key: <anthropic-admin-api-key>" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -d '{ - "external_key_id": "ekey_<id>" - }' - ``` + <CodeGroup> + ```bash cURL + curl -sS -X POST "https://api.anthropic.com/v1/organizations/workspaces/<workspace-id>" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "external_key_id": "ekey_<id>" + }' + ``` + + ```bash CLI + ant beta:organization:workspaces update \ + --workspace-id "<workspace-id>" \ + --external-key-id "ekey_<id>" + ``` + + ```python Python + client = anthropic.Anthropic() + + workspace = client.beta.organization.workspaces.update( + "<workspace-id>", external_key_id="ekey_<id>" + ) + + print(f"id: {workspace.id}") + print(f"external_key_id: {workspace.external_key_id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const workspace = await client.beta.organization.workspaces.update("<workspace-id>", { + external_key_id: "ekey_<id>" + }); + + console.log(`id: ${workspace.id}`); + console.log(`external_key_id: ${workspace.external_key_id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var workspace = await client.Beta.Organization.Workspaces.Update("<workspace-id>", new() + { + ExternalKeyID = "ekey_<id>" + }); + + Console.WriteLine($"id: {workspace.ID}"); + Console.WriteLine($"external_key_id: {workspace.ExternalKeyID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + workspace, err := client.Beta.Organization.Workspaces.Update( + context.Background(), + "<workspace-id>", + anthropic.BetaOrganizationWorkspaceUpdateParams{ + ExternalKeyID: anthropic.String("ekey_<id>"), + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", workspace.ID) + fmt.Printf("external_key_id: %s\n", workspace.ExternalKeyID) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.WorkspaceUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = WorkspaceUpdateParams.builder() + .externalKeyId("ekey_<id>") + .build(); + var workspace = client.beta().organization().workspaces().update("<workspace-id>", params); + + IO.println("id: " + workspace.id()); + IO.println("external_key_id: " + workspace.externalKeyId().orElseThrow()); + } + ``` + + ```php PHP + $client = new Client(); + + $workspace = $client->beta->organization->workspaces->update( + workspaceID: '<workspace-id>', + externalKeyID: 'ekey_<id>', + ); + + echo "id: {$workspace->id}\n"; + echo "external_key_id: {$workspace->externalKeyID}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "<workspace-id>" + workspace = client.beta.organization.workspaces.update( + workspace_id, + external_key_id: "ekey_<id>" + ) + + puts "id: #{workspace.id}" + puts "external_key_id: #{workspace.external_key_id}" + ``` + </CodeGroup> </Step> </Steps> </Tab>
manage-claude/compliance-sessions Changed · +17 / -13 lines
--- <Note> - The endpoints on this page are available only to Claude Enterprise organizations and are in beta. They work with the same Compliance Access Key and `read:compliance_user_data` scope as the [chat, file, and project endpoints](https://platform.claude.com/docs/en/manage-claude/compliance-content-data); no new key, scope, setting, or client update is required. See [Set up the Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api-access). + The endpoints on this page are available only to Claude Enterprise organizations. The local and remote session endpoints are stable for Cowork and Claude Code sessions; coverage of Claude Science and Claude for Microsoft 365 sessions is in beta. The endpoints work with the same Compliance Access Key and `read:compliance_user_data` scope as the [chat, file, and project endpoints](https://platform.claude.com/docs/en/manage-claude/compliance-content-data); no new key, scope, setting, or client update is required. See [Set up the Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api-access). </Note> <Check>
**Prerequisite:** None for listing sessions organization-wide. To filter the remote session list (sessions in the cloud) to specific users, you need user IDs from [List organization users](https://platform.claude.com/docs/en/manage-claude/compliance-org-data#list-organization-users); the local session list has no user filter. </Check> -The endpoints on this page expose transcripts of the sessions your users run in Claude apps and agents (today, Cowork and Claude Code) from your Claude Enterprise organizations to compliance reviewers. Each session is a single conversation with Claude; its transcript is the sequence of user prompts, assistant responses, and tool calls and results in that conversation. The endpoints support eDiscovery (electronic discovery) exports and data loss prevention (DLP) enforcement. +The endpoints on this page expose transcripts of the sessions your users run in Claude apps and agents (today: Cowork, Claude Code, Claude Science, and Claude for Microsoft 365) from your Claude Enterprise organizations to compliance reviewers. Each session is a single conversation with Claude; its transcript is the sequence of user prompts, assistant responses, and tool calls and results in that conversation. The endpoints support eDiscovery (electronic discovery) exports and data loss prevention (DLP) enforcement. The Compliance API groups sessions into two endpoint families according to where they run: local session endpoints for sessions on users' machines, and remote session endpoints for sessions that run in the cloud in Anthropic-managed environments. Both families are read-only, and neither is available to Admin API keys (`sk-ant-admin01-...`): calls authenticated with an Admin API key return [403 Forbidden](https://platform.claude.com/docs/en/manage-claude/compliance-errors#403-forbidden). The following table maps each product, and where it runs, to the endpoint family that returns its sessions and the `product_surface` value that identifies them in responses. Products are added to this table as coverage expands. -| Product and where it runs | Endpoint family | `product_surface` | -| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------- | ----------------- | -| Cowork in Claude Desktop, running on the user's machine | Local session endpoints (`/v1/compliance/apps/sessions/local`) | `cowork` | -| Claude Code in the terminal, in Claude Desktop, or in an IDE extension, running on the user's machine | Local session endpoints | `claude_code` | -| Cowork sessions started on claude.ai web or mobile, running in the cloud in Anthropic-managed environments | Remote session endpoints (`/v1/compliance/apps/sessions/remote`) | `cowork_remote` | +| Product and where it runs | Endpoint family | `product_surface` | +| ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | +| Cowork in Claude Desktop, running on the user's machine | Local session endpoints (`/v1/compliance/apps/sessions/local`) | `cowork` | +| Claude Code in the terminal, in Claude Desktop, or in an IDE extension, running on the user's machine | Local session endpoints | `claude_code` | +| Claude Science desktop app, running on the user's machine | Local session endpoints | `claude_science` | +| Claude for Microsoft 365 (the Claude add-ins for Excel, PowerPoint, Word, and Outlook), running in the Microsoft 365 desktop or web apps | Local session endpoints | `office_agents/excel`, `office_agents/powerpoint`, `office_agents/word`, or `office_agents/outlook` (`office_agents` when the app is not identified) | +| Cowork sessions started on claude.ai web or mobile, running in the cloud in Anthropic-managed environments | Remote session endpoints (`/v1/compliance/apps/sessions/remote`) | `cowork_remote` | Capture of local sessions is tied to the Compliance API being enabled for your organization and applies while users are signed in with their Claude Enterprise account. The session endpoints do not return the following:
| Setup | Works with your existing Compliance Access Key | Works with your existing Compliance Access Key | Admin configures an OTLP endpoint and content-capture settings | | Infrastructure | Anthropic-hosted | Anthropic-hosted | You run the collector and storage | | ID prefix | `clls_` | `cse_` | N/A | -| `product_surface` values | `cowork`, `claude_code` | `cowork_remote` | N/A | +| `product_surface` values | `cowork`, `claude_code`, `claude_science`, and values beginning with `office_agents` | `cowork_remote` | N/A | | Retention | 6 years by default, or your organization's custom conversation retention period when a finite one is set; held by Anthropic | 6 years, held by Anthropic | Your infrastructure, your policies | | User prompts and assistant responses | Yes | Yes | Yes, subject to content-capture settings | | Tool inputs | Truncated to 10,000 bytes per input by default; up to about 1 MiB on request | Truncated to 10,000 bytes per input by default; up to about 1 MiB on request | Truncated summaries |
## Sessions on users' machines (local sessions) -Local sessions run on users' machines while they are signed in with their Claude Enterprise account: today, Cowork in Claude Desktop, and Claude Code in the terminal, in Claude Desktop, or in an IDE extension. +Local sessions run on users' machines while they are signed in with their Claude Enterprise account: today, Cowork in Claude Desktop, Claude Code (in the terminal, in Claude Desktop, or in an IDE extension), the Claude Science desktop app, and Claude for Microsoft 365 in Excel, PowerPoint, Word, and Outlook. The Compliance API exposes local sessions through three endpoints: `GET /v1/compliance/apps/sessions/local` lists session metadata, `GET /v1/compliance/apps/sessions/local/{session_id}` retrieves one session's metadata, and `GET /v1/compliance/apps/sessions/local/{session_id}/messages` returns one session's transcript. All three require the `read:compliance_user_data` scope and count only against the shared Compliance API rate limit; they are not subject to the second request budget that applies to the remote session endpoints. See [429 Too Many Requests](https://platform.claude.com/docs/en/manage-claude/compliance-errors#429-too-many-requests). If local sessions are not available to your parent organization, all three endpoints return 404 with the message `Local sessions are not available.` (see [Local session not found](https://platform.claude.com/docs/en/manage-claude/compliance-errors#local-session-not-found)); while session listings or captured content are temporarily unavailable, they return 503 (see [Local sessions temporarily unavailable](https://platform.claude.com/docs/en/manage-claude/compliance-errors#local-sessions-temporarily-unavailable)).
Results are sorted in reverse chronological order (newest first) by `created_at`, with ties broken in a fixed server-side order, and capped at `limit` results per response (default 100, max 500). The endpoint paginates forward only with `page` and `next_page` tokens (see [Paginate results](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed#paginate-results)): pass the response's `next_page` value back as the `page` query parameter on the next request, and stop when `next_page` is `null`. The response has no `has_more` field. Complete a list walk within 24 hours of starting it; an older list cursor is still accepted but is re-evaluated against the current retention boundary, so sessions whose oldest retained activity is about to age out of the retention period can be skipped. -In each session object, `user.id` is always set and survives account deletion; `user.email_address` is `null` when the user's account has been deleted or the user is no longer a member of an organization your key can read. `workspace_id` is `null` when the session was not associated with a workspace. A local session corresponds to one client session ID: starting a new conversation in the client, or clearing its context, begins a new session record. Treat `id` values as opaque strings; the format may change without notice. +In each session object, `user.id` is always set and survives account deletion; `user.email_address` is `null` when the user's account has been deleted or the user is no longer a member of an organization your key can read. `workspace_id` is `null` when the session was not associated with a workspace. A local session corresponds to one client session ID: starting a new conversation in the client, or clearing its context, begins a new session record. For Claude Science, the list can also include separate sessions for the app's own background work (for example, naming the conversation; on newer app versions also its reviewer and delegation tracks), and on older app versions some of that background work appears as extra messages inside the conversation's own transcript. A Claude Science conversation that continues across some app updates appears as two sessions. These behaviors are expected. Treat `id` values as opaque strings; the format may change without notice. +For Claude for Microsoft 365, deleting a conversation in the add-in happens only on the client, so it is not reflected in the API: local sessions have no `deleted_at` field, and the session stays listed until retention removes it. + Local sessions carry an `updated_at` but no `status`: a local session has no server-side lifecycle status, and its visibility is governed by retention instead. A local session is captured as the series of Claude API calls (inference calls) that the client makes during the session, and retention applies to each captured call individually. `created_at` is the timestamp of the session's earliest retained call and `updated_at` the timestamp of its last, both UTC. As older calls age past the retention period, `created_at` advances accordingly, and once every call in a session has aged out, the session is no longer returned; `updated_at` tracks the most recent call and is unaffected until then. Because `created_at` can shift between runs, deduplicate on `id` when you re-walk the list over time. To keep transcripts current as sessions gain messages, poll with the `updated_at.gte` filter, overlapping consecutive windows. On the list endpoint `updated_at` is a lower bound: for a session still active at a page or `created_at.lt` window boundary it can momentarily lag the session's true last activity, and a new call only becomes queryable after the short processing delay noted earlier. Because of that lag, set each run's `updated_at.gte` a few minutes before your previous run's start time, not to the previous run's time exactly. A bound set to the exact previous time silently and permanently drops a session whose final call was still indexing at that moment, because once the bound advances past that call no later run returns it. Deduplicate the returned sessions on `id`, re-fetch their transcripts, and deduplicate messages on `id`. Retrieving a session, or its messages, always reflects the exact latest retained call, so a periodic reconciliation pass over an older window is a more thorough alternative to widening the overlap. The list is built from session activity metadata, so it can include sessions whose transcript content was not captured, for example sessions that ran before capture began for your organization (as far back as your retention period allows); the transcript of such a session returns each message with its content marked unavailable (see [Retrieve a local session transcript](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-a-local-session-transcript)).
To fetch one session's metadata directly, pass its ID to `GET /v1/compliance/apps/sessions/local/{session_id}`. The response is the same session object the list endpoint returns, with no envelope and no transcript content. A malformed session ID returns [400 Bad Request](https://platform.claude.com/docs/en/manage-claude/compliance-errors#400-bad-request). A single [404 Not Found](https://platform.claude.com/docs/en/manage-claude/compliance-errors#404-not-found) covers four cases that the response does not distinguish: the session is not in an organization your key can read (including sessions under another parent organization), it does not exist, zero data retention is in effect for it, or every call in it has aged past retention. -`product_surface` (string or `null`) identifies the product that created the session: `cowork` for Cowork sessions running on the user's machine in Claude Desktop, and `claude_code` for Claude Code sessions. New values appear as coverage expands. +`product_surface` (string or `null`) identifies the product that created the session: `cowork` (Cowork in Claude Desktop on the user's machine), `claude_code` (Claude Code), `claude_science` (Claude Science), or one of `office_agents/excel`, `office_agents/powerpoint`, `office_agents/word`, and `office_agents/outlook` (Claude for Microsoft 365, by app; `office_agents` alone when the app is not identified). New values appear as coverage expands. <Note> **Build forward-compatible handlers.** Pass through unrecognized `product_surface` values, and ignore fields your handler does not expect, so your integration keeps working as new product surfaces ship.
* Thinking blocks are never included. * The request's system prompt is never returned. A marker message reading `[system prompt content not shown]` stands in for it (normally once per session; a session with no captured content carries no marker). * Tool definitions and MCP server configuration are not part of the transcript. -* Images, PDFs, and other binary or structured blocks are not returned. Each appears as a `text` block reading `[<block type> content not shown]` (for example, `[image content not shown]`) with `truncated` set to `true`. Non-text items inside a tool result are replaced by one `[N non-text item(s) not shown]` entry, and the tool result block's `truncated` is `true`. -* Citation metadata on `text` blocks is omitted, and the affected block carries `truncated` set to `true`. +* Images, PDFs, and other binary or structured blocks are not returned. Each appears as a `text` block reading `[<block type> content not shown]` (for example, `[image content not shown]`) with `truncated` set to `true`. Non-text items inside a tool result, such as [web search](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool) results or the output of the [code execution tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool), are replaced by one `[N non-text item(s) not shown]` entry, and the tool result block's `truncated` is `true`. The matching tool call, with the search query or the code in its `input`, is still returned. +* Citation metadata on `text` blocks, such as the source citations on an answer that draws on web search results, is omitted. The text itself is returned, and the block carries `truncated` set to `true`. Project instruction files such as `CLAUDE.md` appear as ordinary user-role content. Skill content appears when the client sends it as message content and is not distinguished from other user text. For a coverage summary, see the [Compliance API FAQ](https://platform.claude.com/docs/en/manage-claude/compliance-faq#data-coverage-and-retention); for a table comparing local sessions with remote sessions and OpenTelemetry logging, see this page's introduction.
manage-claude/rate-limits-api Changed · +643 / -25 lines
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
**Admin API key required.** These endpoints require an Admin API key, which is different from a standard Claude API key. See [Create an Admin API key](https://platform.claude.com/docs/en/manage-claude/admin-api-keys) to find where to create one for your organization type and which scopes to select. </Check> +The SDK and CLI examples on this page construct the default client, which reads the Admin API key from the `ANTHROPIC_API_KEY` environment variable. The SDKs expose these endpoints as `client.beta.organization.rate_limits` and `client.beta.organization.workspaces.rate_limits`; the Python, TypeScript, C#, Go, and Java list methods return an iterator that follows `next_page` for you, while the PHP, Ruby, and curl examples read one page. + ## Quick start List the rate limits configured for your organization: -```bash cURL -curl "https://api.anthropic.com/v1/organizations/rate_limits" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/rate_limits" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:rate-limits list + ``` + + ```python Python + client = anthropic.Anthropic() + + rate_limits = client.beta.organization.rate_limits.list() + + for group in rate_limits: + models = f" ({', '.join(group.models)})" if group.models else "" + print(f"{group.group_type}{models}") + for limit in group.limits: + print(f" {limit.type}: {limit.value}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rateLimits = await client.beta.organization.rateLimits.list(); + + for await (const group of rateLimits) { + const models = group.models ? ` (${group.models.join(", ")})` : ""; + console.log(`${group.group_type}${models}`); + for (const limit of group.limits) { + console.log(` ${limit.type}: ${limit.value}`); + } + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var rateLimits = await client.Beta.Organization.RateLimits.List(); + + await foreach (var group in rateLimits.Paginate()) + { + var models = group.Models is null ? "" : $" ({string.Join(", ", group.Models)})"; + Console.WriteLine($"{group.GroupType.Raw()}{models}"); + foreach (var limit in group.Limits) + { + Console.WriteLine($" {limit.Type}: {limit.Value}"); + } + } + ``` + + ```go Go + client := anthropic.NewClient() + + rateLimits := client.Beta.Organization.RateLimits.ListAutoPaging(context.Background(), anthropic.BetaOrganizationRateLimitListParams{}) + + for rateLimits.Next() { + group := rateLimits.Current() + models := "" + if len(group.Models) > 0 { + models = fmt.Sprintf(" (%s)", strings.Join(group.Models, ", ")) + } + fmt.Printf("%s%s\n", group.GroupType, models) + for _, limit := range group.Limits { + fmt.Printf(" %s: %d\n", limit.Type, limit.Value) + } + } + if err := rateLimits.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var rateLimits = client.beta().organization().rateLimits().list(); + + for (var group : rateLimits.autoPager()) { + var models = group.models() + .map(modelIds -> " (" + String.join(", ", modelIds) + ")") + .orElse(""); + IO.println(group.groupType().asString() + models); + for (var limit : group.limits()) { + IO.println(" " + limit.type() + ": " + limit.value()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $rateLimits = $client->beta->organization->rateLimits->list(); + + foreach ($rateLimits->data as $group) { + $models = $group->models ? ' (' . implode(', ', $group->models) . ')' : ''; + echo "{$group->groupType}{$models}\n"; + foreach ($group->limits as $limit) { + echo " {$limit->type}: {$limit->value}\n"; + } + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rate_limits = client.beta.organization.rate_limits.list + + rate_limits.data.each do |group| + models = group.models ? " (#{group.models.join(", ")})" : "" + puts "#{group.group_type}#{models}" + group.limits.each do |limit| + puts " #{limit.type}: #{limit.value}" + end + end + ``` +</CodeGroup> ## Organization rate limits
### List all organization rate limits -```bash cURL -curl "https://api.anthropic.com/v1/organizations/rate_limits" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/rate_limits" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:rate-limits list + ``` + + ```python Python + client = anthropic.Anthropic() + + rate_limits = client.beta.organization.rate_limits.list() + + for group in rate_limits: + models = f" ({', '.join(group.models)})" if group.models else "" + print(f"{group.group_type}{models}") + for limit in group.limits: + print(f" {limit.type}: {limit.value}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rateLimits = await client.beta.organization.rateLimits.list(); + + for await (const group of rateLimits) { + const models = group.models ? ` (${group.models.join(", ")})` : ""; + console.log(`${group.group_type}${models}`); + for (const limit of group.limits) { + console.log(` ${limit.type}: ${limit.value}`); + } + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var rateLimits = await client.Beta.Organization.RateLimits.List(); + + await foreach (var group in rateLimits.Paginate()) + { + var models = group.Models is null ? "" : $" ({string.Join(", ", group.Models)})"; + Console.WriteLine($"{group.GroupType.Raw()}{models}"); + foreach (var limit in group.Limits) + { + Console.WriteLine($" {limit.Type}: {limit.Value}"); + } + } + ``` + + ```go Go + client := anthropic.NewClient() + + rateLimits := client.Beta.Organization.RateLimits.ListAutoPaging(context.Background(), anthropic.BetaOrganizationRateLimitListParams{}) + + for rateLimits.Next() { + group := rateLimits.Current() + models := "" + if len(group.Models) > 0 { + models = fmt.Sprintf(" (%s)", strings.Join(group.Models, ", ")) + } + fmt.Printf("%s%s\n", group.GroupType, models) + for _, limit := range group.Limits { + fmt.Printf(" %s: %d\n", limit.Type, limit.Value) + } + } + if err := rateLimits.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var rateLimits = client.beta().organization().rateLimits().list(); + + for (var group : rateLimits.autoPager()) { + var models = group.models() + .map(modelIds -> " (" + String.join(", ", modelIds) + ")") + .orElse(""); + IO.println(group.groupType().asString() + models); + for (var limit : group.limits()) { + IO.println(" " + limit.type() + ": " + limit.value()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $rateLimits = $client->beta->organization->rateLimits->list(); + + foreach ($rateLimits->data as $group) { + $models = $group->models ? ' (' . implode(', ', $group->models) . ')' : ''; + echo "{$group->groupType}{$models}\n"; + foreach ($group->limits as $limit) { + echo " {$limit->type}: {$limit->value}\n"; + } + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rate_limits = client.beta.organization.rate_limits.list + + rate_limits.data.each do |group| + models = group.models ? " (#{group.models.join(", ")})" : "" + puts "#{group.group_type}#{models}" + group.limits.each do |limit| + puts " #{limit.type}: #{limit.value}" + end + end + ``` +</CodeGroup> ```json {
Pass any model ID or alias as the `model` query parameter to return only the entry that contains it: -```bash cURL -curl "https://api.anthropic.com/v1/organizations/rate_limits?model=claude-opus-5" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/rate_limits?model=claude-opus-5" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:rate-limits list --model claude-opus-5 + ``` + + ```python Python + client = anthropic.Anthropic() + + rate_limits = client.beta.organization.rate_limits.list(model="claude-opus-5") + + for group in rate_limits: + models = f" ({', '.join(group.models)})" if group.models else "" + print(f"{group.group_type}{models}") + for limit in group.limits: + print(f" {limit.type}: {limit.value}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rateLimits = await client.beta.organization.rateLimits.list({ model: "claude-opus-5" }); + + for await (const group of rateLimits) { + const models = group.models ? ` (${group.models.join(", ")})` : ""; + console.log(`${group.group_type}${models}`); + for (const limit of group.limits) { + console.log(` ${limit.type}: ${limit.value}`); + } + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var rateLimits = await client.Beta.Organization.RateLimits.List(new() + { + Model = "claude-opus-5" + }); + + await foreach (var group in rateLimits.Paginate()) + { + var models = group.Models is null ? "" : $" ({string.Join(", ", group.Models)})"; + Console.WriteLine($"{group.GroupType.Raw()}{models}"); + foreach (var limit in group.Limits) + { + Console.WriteLine($" {limit.Type}: {limit.Value}"); + } + } + ``` + + ```go Go + client := anthropic.NewClient() + + rateLimits := client.Beta.Organization.RateLimits.ListAutoPaging(context.Background(), anthropic.BetaOrganizationRateLimitListParams{ + Model: anthropic.String(anthropic.ModelClaudeOpus5), + }) + + for rateLimits.Next() { + group := rateLimits.Current() + models := "" + if len(group.Models) > 0 { + models = fmt.Sprintf(" (%s)", strings.Join(group.Models, ", ")) + } + fmt.Printf("%s%s\n", group.GroupType, models) + for _, limit := range group.Limits { + fmt.Printf(" %s: %d\n", limit.Type, limit.Value) + } + } + if err := rateLimits.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.ratelimits.RateLimitListParams; + import com.anthropic.models.messages.Model; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = RateLimitListParams.builder() + .model(Model.CLAUDE_OPUS_5.asString()) + .build(); + var rateLimits = client.beta().organization().rateLimits().list(params); + + for (var group : rateLimits.autoPager()) { + var models = group.models() + .map(modelIds -> " (" + String.join(", ", modelIds) + ")") + .orElse(""); + IO.println(group.groupType().asString() + models); + for (var limit : group.limits()) { + IO.println(" " + limit.type() + ": " + limit.value()); + } + } + } + ``` + + ```php PHP + use Anthropic\Messages\Model; + + $client = new Client(); + + $rateLimits = $client->beta->organization->rateLimits->list( + model: Model::CLAUDE_OPUS_5->value, + ); + + foreach ($rateLimits->data as $group) { + $models = $group->models ? ' (' . implode(', ', $group->models) . ')' : ''; + echo "{$group->groupType}{$models}\n"; + foreach ($group->limits as $limit) { + echo " {$limit->type}: {$limit->value}\n"; + } + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rate_limits = client.beta.organization.rate_limits.list(model: Anthropic::Model::CLAUDE_OPUS_5) + + rate_limits.data.each do |group| + models = group.models ? " (#{group.models.join(", ")})" : "" + puts "#{group.group_type}#{models}" + group.limits.each do |limit| + puts " #{limit.type}: #{limit.value}" + end + end + ``` +</CodeGroup> If the model string doesn't match any group, the endpoint returns a 404 error. The `model` parameter is supported on the organization endpoint only; the workspace endpoint doesn't accept it.
To retrieve your organization's workspace IDs, use the [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) endpoint, or find them in the [Claude Console](https://platform.claude.com/settings/workspaces). The default workspace cannot have rate limit overrides, so it has no entry on this endpoint; use the organization endpoint to read its limits. </Tip> -```bash cURL -curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/rate_limits" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/rate_limits" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:workspaces:rate-limits list \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + ``` + + ```python Python + client = anthropic.Anthropic() + + rate_limits = client.beta.organization.workspaces.rate_limits.list( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + for group in rate_limits: + models = f" ({', '.join(group.models)})" if group.models else "" + print(f"{group.group_type}{models}") + for limit in group.limits: + print(f" {limit.type}: {limit.value}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rateLimits = await client.beta.organization.workspaces.rateLimits.list( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ); + + for await (const group of rateLimits) { + const models = group.models ? ` (${group.models.join(", ")})` : ""; + console.log(`${group.group_type}${models}`); + for (const limit of group.limits) { + console.log(` ${limit.type}: ${limit.value}`); + } + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var rateLimits = await client.Beta.Organization.Workspaces.RateLimits.List( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ); + + await foreach (var group in rateLimits.Paginate()) + { + var models = group.Models is null ? "" : $" ({string.Join(", ", group.Models)})"; + Console.WriteLine($"{group.GroupType.Raw()}{models}"); + foreach (var limit in group.Limits) + { + Console.WriteLine($" {limit.Type}: {limit.Value}"); + } + } + ``` + + ```go Go + client := anthropic.NewClient() + + rateLimits := client.Beta.Organization.Workspaces.RateLimits.ListAutoPaging( + context.Background(), + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + anthropic.BetaOrganizationWorkspaceRateLimitListParams{}, + ) + + for rateLimits.Next() { + group := rateLimits.Current() + models := "" + if len(group.Models) > 0 { + models = fmt.Sprintf(" (%s)", strings.Join(group.Models, ", ")) + } + fmt.Printf("%s%s\n", group.GroupType, models) + for _, limit := range group.Limits { + fmt.Printf(" %s: %d\n", limit.Type, limit.Value) + } + } + if err := rateLimits.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var rateLimits = client.beta().organization().workspaces().rateLimits() + .list("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"); + + for (var group : rateLimits.autoPager()) { + var models = group.models() + .map(modelIds -> " (" + String.join(", ", modelIds) + ")") + .orElse(""); + IO.println(group.groupType().asString() + models); + for (var limit : group.limits()) { + IO.println(" " + limit.type() + ": " + limit.value()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $rateLimits = $client->beta->organization->workspaces->rateLimits->list( + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + ); + + foreach ($rateLimits->data as $group) { + $models = $group->models ? ' (' . implode(', ', $group->models) . ')' : ''; + echo "{$group->groupType}{$models}\n"; + foreach ($group->limits as $limit) { + echo " {$limit->type}: {$limit->value}\n"; + } + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + rate_limits = client.beta.organization.workspaces.rate_limits.list(workspace_id) + + rate_limits.data.each do |group| + models = group.models ? " (#{group.models.join(", ")})" : "" + puts "#{group.group_type}#{models}" + group.limits.each do |limit| + puts " #{limit.type}: #{limit.value}" + end + end + ``` +</CodeGroup> ```json {
Both endpoints accept an optional `group_type` query parameter that restricts the response to a single category: -```bash cURL -curl "https://api.anthropic.com/v1/organizations/rate_limits?group_type=batch" \ - --header "anthropic-version: 2023-06-01" \ - --header "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/rate_limits?group_type=batch" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:rate-limits list --group-type batch + ``` + + ```python Python + client = anthropic.Anthropic() + + rate_limits = client.beta.organization.rate_limits.list(group_type="batch") + + for group in rate_limits: + models = f" ({', '.join(group.models)})" if group.models else "" + print(f"{group.group_type}{models}") + for limit in group.limits: + print(f" {limit.type}: {limit.value}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rateLimits = await client.beta.organization.rateLimits.list({ group_type: "batch" }); + + for await (const group of rateLimits) { + const models = group.models ? ` (${group.models.join(", ")})` : ""; + console.log(`${group.group_type}${models}`); + for (const limit of group.limits) { + console.log(` ${limit.type}: ${limit.value}`); + } + } + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.RateLimits; + + AnthropicClient client = new(); + + var rateLimits = await client.Beta.Organization.RateLimits.List(new() + { + GroupType = GroupType.Batch + }); + + await foreach (var group in rateLimits.Paginate()) + { + var models = group.Models is null ? "" : $" ({string.Join(", ", group.Models)})"; + Console.WriteLine($"{group.GroupType.Raw()}{models}"); + foreach (var limit in group.Limits) + { + Console.WriteLine($" {limit.Type}: {limit.Value}"); + } + } + ``` + + ```go Go + client := anthropic.NewClient() + + rateLimits := client.Beta.Organization.RateLimits.ListAutoPaging(context.Background(), anthropic.BetaOrganizationRateLimitListParams{ + GroupType: anthropic.BetaOrganizationRateLimitListParamsGroupTypeBatch, + }) + + for rateLimits.Next() { + group := rateLimits.Current() + models := "" + if len(group.Models) > 0 { + models = fmt.Sprintf(" (%s)", strings.Join(group.Models, ", ")) + } + fmt.Printf("%s%s\n", group.GroupType, models) + for _, limit := range group.Limits { + fmt.Printf(" %s: %d\n", limit.Type, limit.Value) + } + } + if err := rateLimits.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.ratelimits.RateLimitListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = RateLimitListParams.builder() + .groupType(RateLimitListParams.GroupType.BATCH) + .build(); + var rateLimits = client.beta().organization().rateLimits().list(params); + + for (var group : rateLimits.autoPager()) { + var models = group.models() + .map(modelIds -> " (" + String.join(", ", modelIds) + ")") + .orElse(""); + IO.println(group.groupType().asString() + models); + for (var limit : group.limits()) { + IO.println(" " + limit.type() + ": " + limit.value()); + } + } + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\RateLimits\RateLimitListParams\GroupType; + // ... + + $client = new Client(); + + $rateLimits = $client->beta->organization->rateLimits->list( + groupType: GroupType::BATCH, + ); + + foreach ($rateLimits->data as $group) { + $models = $group->models ? ' (' . implode(', ', $group->models) . ')' : ''; + echo "{$group->groupType}{$models}\n"; + foreach ($group->limits as $limit) { + echo " {$limit->type}: {$limit->value}\n"; + } + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rate_limits = client.beta.organization.rate_limits.list(group_type: :batch) + + rate_limits.data.each do |group| + models = group.models ? " (#{group.models.join(", ")})" : "" + puts "#{group.group_type}#{models}" + group.limits.each do |limit| + puts " #{limit.type}: #{limit.value}" + end + end + ``` +</CodeGroup> Valid values are `model_group`, `batch`, `token_count`, `files`, `skills`, and `web_search`.
manage-claude/wif-admin-api Changed · +1149 / -82 lines
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
### Interactive (your terminal) -Log in with the [`ant` CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart) under a dedicated profile, requesting the `org:admin` scope (see [Admin access](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication#admin-access)), then export the bearer token: +Log in with the [`ant` CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart) under a dedicated profile, requesting the `org:admin` scope (see [Admin access](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication#admin-access)), then export the bearer token. Logging in with `--profile admin` stores the `org:admin` credential under its own profile name and also makes it the CLI's active profile, and the exported variable applies to every SDK and CLI call in that shell; so use a shell you reserve for administration, unset the variable when you are done, and switch the CLI back with `ant profile activate default`: ```bash CLI ant auth login --profile admin --scope "org:admin" -export ANTHROPIC_OAUTH_TOKEN=$(ant auth print-credentials --profile admin --access-token) +export ANTHROPIC_AUTH_TOKEN=$(ant auth print-credentials --profile admin --access-token) ``` Interactive tokens are short-lived; if requests start returning 401, re-run the export command (it refreshes the token automatically). + +The SDKs and the `ant` CLI read `ANTHROPIC_AUTH_TOKEN` automatically; leave `ANTHROPIC_API_KEY` unset in the same shell, because these endpoints reject API keys and some clients prefer the key when both are set. ### Workload (CI and automation)
</Step> <Step title="Exchange the workload's identity token"> - At runtime, the workload exchanges the JWT from its identity provider for a short-lived `org:admin` bearer token using the same [token exchange](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#authenticate-from-your-workload) as any other federated workload. + A workload that uses one of the SDKs or the `ant` CLI does not perform the exchange itself. Point the client at the rule with the federation environment variables and construct it with no arguments, exactly as for inference in [Construct the SDK client](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#construct-the-sdk-client); the client exchanges the identity token on the first request and, before the resulting access token expires, re-reads the identity token and exchanges it again: + + ```bash + export ANTHROPIC_FEDERATION_RULE_ID=fdrl_... # the org:admin rule from step 1 + export ANTHROPIC_ORGANIZATION_ID=00000000-0000-0000-0000-000000000000 + export ANTHROPIC_SERVICE_ACCOUNT_ID=svac_... # the rule's target service account + export ANTHROPIC_IDENTITY_TOKEN_FILE=/path/to/jwt # or ANTHROPIC_IDENTITY_TOKEN + # ANTHROPIC_WORKSPACE_ID is required only if the rule is enabled for all + # workspaces or more than one; the org:admin endpoints ignore the binding. + unset ANTHROPIC_API_KEY ANTHROPIC_AUTH_TOKEN # both take precedence over federation + ``` + + The `ant` CLI reads the same variables, or takes `--federation-rule`, `--organization-id`, `--service-account-id`, and `--identity-token-file` flags. For a workload that runs more than one `ant` command, use a [federation profile](https://platform.claude.com/docs/en/manage-claude/wif-reference#profile-configuration-file) rather than flags or environment variables: with flags or variables the CLI exchanges the identity token again in every process, and identity tokens that carry a `jti` claim (GitHub Actions tokens do) are accepted only once, so a second command would be rejected; a profile is also the only way to give the CLI a `workspace_id` for the exchange when the rule is enabled for all workspaces or more than one, because unlike the SDKs the CLI does not pass `ANTHROPIC_WORKSPACE_ID` or `--workspace-id` into the exchange. Every SDK also accepts the same settings as explicit constructor arguments, shown per language in [Construct the SDK client](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#construct-the-sdk-client). See [Environment variables](https://platform.claude.com/docs/en/manage-claude/wif-reference#environment-variables) and [Credential precedence](https://platform.claude.com/docs/en/manage-claude/wif-reference#credential-precedence) for the full list and ordering. + + A workload that calls the API with curl exchanges the JWT for a short-lived `org:admin` bearer token itself, using the same [token exchange](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#authenticate-from-your-workload) as any other federated workload, and sends it in the `authorization: Bearer` header. </Step> <Step title="Manage issuers and workspace-scoped rules through the API"> - With the minted token in `ANTHROPIC_OAUTH_TOKEN`, the workload creates and manages your federation configuration using the endpoints on this page. + With the client configured (or, for curl, the minted token in `ANTHROPIC_AUTH_TOKEN`), the workload creates and manages your federation configuration using the endpoints on this page. </Step> </Steps>
All endpoints live under `https://api.anthropic.com/v1/organizations/`. Every request to the federation and service-account endpoints needs the API version header and the bearer token: -```bash cURL -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/service_accounts" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" -``` +In the SDKs these endpoints are `client.beta.organization.service_accounts`, `client.beta.organization.federation.issuers`, and `client.beta.organization.federation.rules` (`ant beta:organization:service-accounts`, `federation:issuers`, and `federation:rules` in the CLI). The SDK and CLI examples construct the default client, which sends the bearer token from `ANTHROPIC_AUTH_TOKEN`, or, in an automated workload, performs the federation exchange itself as described in [Bootstrap a workload to manage WIF](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#bootstrap-a-workload-to-manage-wif). SDK list methods fetch further pages on demand, so `limit` sets the page size; the PHP and Ruby examples read one page. + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/service_accounts" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:service-accounts list + ``` + + ```python Python + client = anthropic.Anthropic() + + service_accounts = client.beta.organization.service_accounts.list() + + for service_account in service_accounts: + print(f"{service_account.id}: {service_account.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + for await (const serviceAccount of client.beta.organization.serviceAccounts.list()) { + console.log(`${serviceAccount.id}: ${serviceAccount.name}`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.ServiceAccounts.List(); + + await foreach (var serviceAccount in page.Paginate()) + { + Console.WriteLine($"{serviceAccount.ID}: {serviceAccount.Name}"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + serviceAccounts := client.Beta.Organization.ServiceAccounts.ListAutoPaging(context.Background(), anthropic.BetaOrganizationServiceAccountListParams{}) + + for serviceAccounts.Next() { + serviceAccount := serviceAccounts.Current() + fmt.Printf("%s: %s\n", serviceAccount.ID, serviceAccount.Name) + } + if err := serviceAccounts.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var serviceAccounts = client.beta().organization().serviceAccounts().list(); + + for (var serviceAccount : serviceAccounts.autoPager()) { + IO.println(serviceAccount.id() + ": " + serviceAccount.name()); + } + ``` + + ```php PHP + $client = new Client(); + + $serviceAccounts = $client->beta->organization->serviceAccounts->list(); + + foreach ($serviceAccounts->getItems() as $serviceAccount) { + echo "{$serviceAccount->id}: {$serviceAccount->name}\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + service_accounts = client.beta.organization.service_accounts.list + + service_accounts.data.each do |service_account| + puts "#{service_account.id}: #{service_account.name}" + end + ``` +</CodeGroup> Admin API keys are not accepted on these endpoints; the Admin API page's `x-api-key` examples do not apply here.
A [service account](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#service-accounts) (`svac_...`) is the non-human identity that a federated token acts as. Set `organization_role` to `developer`. -```bash cURL -# Create a service account -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/service_accounts" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ - -H "content-type: application/json" \ - -d '{ - "name": "inference-worker", - "organization_role": "developer" - }' - -# List service accounts -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/service_accounts?limit=20" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" - -# Archive a service account -curl --fail-with-body -sS -X POST "https://api.anthropic.com/v1/organizations/service_accounts/svac_.../archive" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" -``` +Create a service account: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/service_accounts" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "name": "inference-worker", + "organization_role": "developer" + }' + ``` + + ```bash CLI + ant beta:organization:service-accounts create \ + --name inference-worker \ + --organization-role developer + ``` + + ```python Python + client = anthropic.Anthropic() + + service_account = client.beta.organization.service_accounts.create( + name="inference-worker", organization_role="developer" + ) + + print(f"id: {service_account.id}") + print(f"name: {service_account.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const serviceAccount = await client.beta.organization.serviceAccounts.create({ + name: "inference-worker", + organization_role: "developer" + }); + + console.log(`id: ${serviceAccount.id}`); + console.log(`name: ${serviceAccount.name}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.ServiceAccounts; + + AnthropicClient client = new(); + + var serviceAccount = await client.Beta.Organization.ServiceAccounts.Create(new() + { + Name = "inference-worker", + OrganizationRole = OrganizationRole.Developer + }); + + Console.WriteLine($"id: {serviceAccount.ID}"); + Console.WriteLine($"name: {serviceAccount.Name}"); + ``` + + ```go Go + client := anthropic.NewClient() + + serviceAccount, err := client.Beta.Organization.ServiceAccounts.New(context.Background(), anthropic.BetaOrganizationServiceAccountNewParams{ + Name: "inference-worker", + OrganizationRole: anthropic.BetaOrganizationServiceAccountNewParamsOrganizationRoleDeveloper, + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", serviceAccount.ID) + fmt.Printf("name: %s\n", serviceAccount.Name) + ``` + + ```java Java + import com.anthropic.models.beta.organization.serviceaccounts.ServiceAccountCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ServiceAccountCreateParams.builder() + .name("inference-worker") + .organizationRole(ServiceAccountCreateParams.OrganizationRole.DEVELOPER) + .build(); + var serviceAccount = client.beta().organization().serviceAccounts().create(params); + + IO.println("id: " + serviceAccount.id()); + IO.println("name: " + serviceAccount.name()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\ServiceAccounts\ServiceAccountCreateParams\OrganizationRole; + // ... + + $client = new Client(); + + $serviceAccount = $client->beta->organization->serviceAccounts->create( + name: 'inference-worker', + organizationRole: OrganizationRole::DEVELOPER, + ); + + echo "id: {$serviceAccount->id}\n"; + echo "name: {$serviceAccount->name}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + service_account = client.beta.organization.service_accounts.create( + name: "inference-worker", + organization_role: :developer + ) + + puts "id: #{service_account.id}" + puts "name: #{service_account.name}" + ``` +</CodeGroup> + +List service accounts: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/service_accounts?limit=20" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:service-accounts list --limit 20 + ``` + + ```python Python + client = anthropic.Anthropic() + + service_accounts = client.beta.organization.service_accounts.list(limit=20) + + for service_account in service_accounts: + print(f"{service_account.id}: {service_account.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + for await (const serviceAccount of client.beta.organization.serviceAccounts.list({ + limit: 20 + })) { + console.log(`${serviceAccount.id}: ${serviceAccount.name}`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.ServiceAccounts.List(new() { Limit = 20 }); + + await foreach (var serviceAccount in page.Paginate()) + { + Console.WriteLine($"{serviceAccount.ID}: {serviceAccount.Name}"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + serviceAccounts := client.Beta.Organization.ServiceAccounts.ListAutoPaging(context.Background(), anthropic.BetaOrganizationServiceAccountListParams{ + Limit: anthropic.Int(20), + }) + + for serviceAccounts.Next() { + serviceAccount := serviceAccounts.Current() + fmt.Printf("%s: %s\n", serviceAccount.ID, serviceAccount.Name) + } + if err := serviceAccounts.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.serviceaccounts.ServiceAccountListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = ServiceAccountListParams.builder() + .limit(20) + .build(); + var serviceAccounts = client.beta().organization().serviceAccounts().list(params); + + for (var serviceAccount : serviceAccounts.autoPager()) { + IO.println(serviceAccount.id() + ": " + serviceAccount.name()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $serviceAccounts = $client->beta->organization->serviceAccounts->list(limit: 20); + + foreach ($serviceAccounts->getItems() as $serviceAccount) { + echo "{$serviceAccount->id}: {$serviceAccount->name}\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + service_accounts = client.beta.organization.service_accounts.list(limit: 20) + + service_accounts.data.each do |service_account| + puts "#{service_account.id}: #{service_account.name}" + end + ``` +</CodeGroup> + +Archive a service account: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS -X POST "https://api.anthropic.com/v1/organizations/service_accounts/svac_01ABCDEFabcdef0123456789XY/archive" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:service-accounts archive svac_01ABCDEFabcdef0123456789XY + ``` + + ```python Python + client = anthropic.Anthropic() + + service_account = client.beta.organization.service_accounts.archive( + "svac_01ABCDEFabcdef0123456789XY" + ) + + print(f"id: {service_account.id}") + print(f"archived_at: {service_account.archived_at}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const serviceAccount = await client.beta.organization.serviceAccounts.archive( + "svac_01ABCDEFabcdef0123456789XY" + ); + + console.log(`id: ${serviceAccount.id}`); + console.log(`archived_at: ${serviceAccount.archived_at}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var serviceAccount = await client.Beta.Organization.ServiceAccounts.Archive( + "svac_01ABCDEFabcdef0123456789XY" + ); + + Console.WriteLine($"id: {serviceAccount.ID}"); + Console.WriteLine($"archived_at: {serviceAccount.ArchivedAt:O}"); + ``` + + ```go Go + client := anthropic.NewClient() + + serviceAccount, err := client.Beta.Organization.ServiceAccounts.Archive( + context.Background(), + "svac_01ABCDEFabcdef0123456789XY", + anthropic.BetaOrganizationServiceAccountArchiveParams{}, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", serviceAccount.ID) + fmt.Printf("archived_at: %s\n", serviceAccount.ArchivedAt) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var serviceAccount = client.beta().organization().serviceAccounts() + .archive("svac_01ABCDEFabcdef0123456789XY"); + + IO.println("id: " + serviceAccount.id()); + IO.println("archived_at: " + serviceAccount.archivedAt().orElseThrow()); + ``` + + ```php PHP + $client = new Client(); + + $serviceAccount = $client->beta->organization->serviceAccounts->archive( + serviceAccountID: 'svac_01ABCDEFabcdef0123456789XY', + ); + + echo "id: {$serviceAccount->id}\n"; + echo "archived_at: {$serviceAccount->archivedAt?->format(DATE_ATOM)}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + service_account_id = "svac_01ABCDEFabcdef0123456789XY" + service_account = client.beta.organization.service_accounts.archive(service_account_id) + + puts "id: #{service_account.id}" + puts "archived_at: #{service_account.archived_at}" + ``` +</CodeGroup> The create endpoint returns the new service account:
| `{"type": "explicit_url", "url": "..."}` | Point at a JWKS endpoint directly. | | `{"type": "inline", "keys": [...]}` | Upload the key set for providers that are not reachable from the public internet. | -```bash cURL -# Register an issuer (GitHub Actions, with JWKS discovery) -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_issuers" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ - -H "content-type: application/json" \ - -d '{ - "name": "github-actions", - "issuer_url": "https://token.actions.githubusercontent.com", - "jwks": {"type": "discovery"} - }' - -# List issuers -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_issuers?limit=20" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" - -# Archive an issuer -curl --fail-with-body -sS -X POST "https://api.anthropic.com/v1/organizations/federation_issuers/fdis_.../archive" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" -``` +Register an issuer. This example registers GitHub Actions with JWKS discovery: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_issuers" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "name": "github-actions", + "issuer_url": "https://token.actions.githubusercontent.com", + "jwks": {"type": "discovery"} + }' + ``` + + ```bash CLI + ant beta:organization:federation:issuers create \ + --name github-actions \ + --issuer-url https://token.actions.githubusercontent.com \ + --jwks '{type: discovery}' + ``` + + ```python Python + client = anthropic.Anthropic() + + issuer = client.beta.organization.federation.issuers.create( + name="github-actions", + issuer_url="https://token.actions.githubusercontent.com", + jwks={"type": "discovery"}, + ) + + print(f"id: {issuer.id}") + print(f"name: {issuer.name}") + print(f"issuer_url: {issuer.issuer_url}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const issuer = await client.beta.organization.federation.issuers.create({ + name: "github-actions", + issuer_url: "https://token.actions.githubusercontent.com", + jwks: { type: "discovery" } + }); + + console.log(`id: ${issuer.id}`); + console.log(`name: ${issuer.name}`); + console.log(`issuer_url: ${issuer.issuer_url}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Federation.Issuers; + + AnthropicClient client = new(); + + var issuer = await client.Beta.Organization.Federation.Issuers.Create(new() + { + Name = "github-actions", + IssuerUrl = "https://token.actions.githubusercontent.com", + Jwks = new BetaJwksDiscovery() + }); + + Console.WriteLine($"id: {issuer.ID}"); + Console.WriteLine($"name: {issuer.Name}"); + Console.WriteLine($"issuer_url: {issuer.IssuerUrl}"); + ``` + + ```go Go + client := anthropic.NewClient() + + issuer, err := client.Beta.Organization.Federation.Issuers.New(context.Background(), anthropic.BetaOrganizationFederationIssuerNewParams{ + Name: "github-actions", + IssuerURL: "https://token.actions.githubusercontent.com", + JWKS: anthropic.BetaOrganizationFederationIssuerNewParamsJWKSUnion{ + OfDiscovery: &anthropic.BetaJWKSDiscoveryParam{}, + }, + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", issuer.ID) + fmt.Printf("name: %s\n", issuer.Name) + fmt.Printf("issuer_url: %s\n", issuer.IssuerURL) + ``` + + ```java Java + import com.anthropic.models.beta.organization.federation.issuers.BetaJwksDiscovery; + import com.anthropic.models.beta.organization.federation.issuers.IssuerCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = IssuerCreateParams.builder() + .name("github-actions") + .issuerUrl("https://token.actions.githubusercontent.com") + .jwks(BetaJwksDiscovery.builder().build()) + .build(); + var issuer = client.beta().organization().federation().issuers().create(params); + + IO.println("id: " + issuer.id()); + IO.println("name: " + issuer.name()); + IO.println("issuer_url: " + issuer.issuerUrl()); + } + ``` + + ```php PHP + $client = new Client(); + + $issuer = $client->beta->organization->federation->issuers->create( + name: 'github-actions', + issuerURL: 'https://token.actions.githubusercontent.com', + jwks: ['type' => 'discovery'], + ); + + echo "id: {$issuer->id}\n"; + echo "name: {$issuer->name}\n"; + echo "issuer_url: {$issuer->issuerURL}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + issuer = client.beta.organization.federation.issuers.create( + name: "github-actions", + issuer_url: "https://token.actions.githubusercontent.com", + jwks: {type: :discovery} + ) + + puts "id: #{issuer.id}" + puts "name: #{issuer.name}" + puts "issuer_url: #{issuer.issuer_url}" + ``` +</CodeGroup> + +List issuers: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_issuers?limit=20" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:federation:issuers list --limit 20 + ``` + + ```python Python + client = anthropic.Anthropic() + + issuers = client.beta.organization.federation.issuers.list(limit=20) + + for issuer in issuers: + print(f"{issuer.id}: {issuer.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + for await (const issuer of client.beta.organization.federation.issuers.list({ limit: 20 })) { + console.log(`${issuer.id}: ${issuer.name}`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.Federation.Issuers.List(new() { Limit = 20 }); + + await foreach (var issuer in page.Paginate()) + { + Console.WriteLine($"{issuer.ID}: {issuer.Name}"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + issuers := client.Beta.Organization.Federation.Issuers.ListAutoPaging(context.Background(), anthropic.BetaOrganizationFederationIssuerListParams{ + Limit: anthropic.Int(20), + }) + + for issuers.Next() { + issuer := issuers.Current() + fmt.Printf("%s: %s\n", issuer.ID, issuer.Name) + } + if err := issuers.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.federation.issuers.IssuerListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = IssuerListParams.builder() + .limit(20) + .build(); + var issuers = client.beta().organization().federation().issuers().list(params); + + for (var issuer : issuers.autoPager()) { + IO.println(issuer.id() + ": " + issuer.name()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $issuers = $client->beta->organization->federation->issuers->list(limit: 20); + + foreach ($issuers->getItems() as $issuer) { + echo "{$issuer->id}: {$issuer->name}\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + issuers = client.beta.organization.federation.issuers.list(limit: 20) + + issuers.data.each do |issuer| + puts "#{issuer.id}: #{issuer.name}" + end + ``` +</CodeGroup> + +Archive an issuer: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS -X POST "https://api.anthropic.com/v1/organizations/federation_issuers/fdis_01ABCDEFabcdef0123456789XY/archive" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:federation:issuers archive \ + --federation-issuer-id fdis_01ABCDEFabcdef0123456789XY + ``` + + ```python Python + client = anthropic.Anthropic() + + issuer = client.beta.organization.federation.issuers.archive( + "fdis_01ABCDEFabcdef0123456789XY" + ) + + print(f"id: {issuer.id}") + print(f"archived_at: {issuer.archived_at}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const issuer = await client.beta.organization.federation.issuers.archive( + "fdis_01ABCDEFabcdef0123456789XY" + ); + + console.log(`id: ${issuer.id}`); + console.log(`archived_at: ${issuer.archived_at}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var issuer = await client.Beta.Organization.Federation.Issuers.Archive( + "fdis_01ABCDEFabcdef0123456789XY" + ); + + Console.WriteLine($"id: {issuer.ID}"); + Console.WriteLine($"archived_at: {issuer.ArchivedAt:O}"); + ``` + + ```go Go + client := anthropic.NewClient() + + issuer, err := client.Beta.Organization.Federation.Issuers.Archive( + context.Background(), + "fdis_01ABCDEFabcdef0123456789XY", + anthropic.BetaOrganizationFederationIssuerArchiveParams{}, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", issuer.ID) + fmt.Printf("archived_at: %s\n", issuer.ArchivedAt) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var issuer = client.beta().organization().federation().issuers() + .archive("fdis_01ABCDEFabcdef0123456789XY"); + + IO.println("id: " + issuer.id()); + IO.println("archived_at: " + issuer.archivedAt().orElseThrow()); + ``` + + ```php PHP + $client = new Client(); + + $issuer = $client->beta->organization->federation->issuers->archive( + federationIssuerID: 'fdis_01ABCDEFabcdef0123456789XY', + ); + + echo "id: {$issuer->id}\n"; + echo "archived_at: {$issuer->archivedAt?->format(DATE_ATOM)}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + issuer_id = "fdis_01ABCDEFabcdef0123456789XY" + issuer = client.beta.organization.federation.issuers.archive(issuer_id) + + puts "id: #{issuer.id}" + puts "archived_at: #{issuer.archived_at}" + ``` +</CodeGroup> To read or update a single issuer, use `GET` and `POST` on `/v1/organizations/federation_issuers/{issuer_id}`. An OAuth caller cannot update an issuer that backs a rule whose `oauth_scope` is anything other than `workspace:developer` or `workspace:inference`; see [Permissions and constraints](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#permissions-and-constraints).
A [federation rule](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation#federation-rules) (`fdrl_...`) binds an issuer to a service account: JWTs from the issuer that satisfy the rule's match conditions can mint tokens that act as the rule's target. The `workspace_id` in the create request enables the rule in that workspace at creation; add more workspaces later through the `/federation_rules/{rule_id}/workspaces` sub-resource. Either `workspace_id` or `applies_to_all_workspaces: true` is required on create. -```bash cURL -# Create a rule (GitHub Actions deploys from the main branch) -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_rules" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ - -H "content-type: application/json" \ - -d '{ - "name": "gha-deploy", - "issuer_id": "fdis_...", - "match": { - "subject_prefix": "repo:my-org/my-repo:ref:refs/heads/main", - "claims": {"repository_owner": "my-org"} +Create a rule. This example lets GitHub Actions deploys from the main branch act as the service account: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_rules" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "name": "gha-deploy", + "issuer_id": "fdis_01ABCDEFabcdef0123456789XY", + "match": { + "subject_prefix": "repo:my-org/my-repo:ref:refs/heads/main", + "claims": {"repository_owner": "my-org"} + }, + "target": { + "type": "service_account", + "service_account_id": "svac_01ABCDEFabcdef0123456789XY" + }, + "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + "oauth_scope": "workspace:developer", + "token_lifetime_seconds": 600 + }' + ``` + + ```bash CLI + ant beta:organization:federation:rules create <<'YAML' + name: gha-deploy + issuer_id: fdis_01ABCDEFabcdef0123456789XY + match: + subject_prefix: "repo:my-org/my-repo:ref:refs/heads/main" + claims: + repository_owner: my-org + target: + type: service_account + service_account_id: svac_01ABCDEFabcdef0123456789XY + workspace_id: wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + oauth_scope: "workspace:developer" + token_lifetime_seconds: 600 + YAML + ``` + + ```python Python + client = anthropic.Anthropic() + + rule = client.beta.organization.federation.rules.create( + name="gha-deploy", + issuer_id="fdis_01ABCDEFabcdef0123456789XY", + match={ + "subject_prefix": "repo:my-org/my-repo:ref:refs/heads/main", + "claims": {"repository_owner": "my-org"}, + }, + target={ + "type": "service_account", + "service_account_id": "svac_01ABCDEFabcdef0123456789XY", + }, + workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + oauth_scope="workspace:developer", + token_lifetime_seconds=600, + ) + + print(f"id: {rule.id}") + print(f"name: {rule.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rule = await client.beta.organization.federation.rules.create({ + name: "gha-deploy", + issuer_id: "fdis_01ABCDEFabcdef0123456789XY", + match: { + subject_prefix: "repo:my-org/my-repo:ref:refs/heads/main", + claims: { repository_owner: "my-org" } }, - "target": { - "type": "service_account", - "service_account_id": "svac_..." + target: { + type: "service_account", + service_account_id: "svac_01ABCDEFabcdef0123456789XY" }, - "workspace_id": "wrkspc_...", - "oauth_scope": "workspace:developer", - "token_lifetime_seconds": 600 - }' - -# List rules, optionally filtered by issuer -curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_rules?issuer_id=fdis_..." \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" - -# Archive a rule -curl --fail-with-body -sS -X POST "https://api.anthropic.com/v1/organizations/federation_rules/fdrl_.../archive" \ - -H "anthropic-version: 2023-06-01" \ - -H "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" -``` + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + oauth_scope: "workspace:developer", + token_lifetime_seconds: 600 + }); + + console.log(`id: ${rule.id}`); + console.log(`name: ${rule.name}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var rule = await client.Beta.Organization.Federation.Rules.Create(new() + { + Name = "gha-deploy", + IssuerID = "fdis_01ABCDEFabcdef0123456789XY", + Match = new() + { + SubjectPrefix = "repo:my-org/my-repo:ref:refs/heads/main", + Claims = new Dictionary<string, string> { ["repository_owner"] = "my-org" } + }, + Target = new() { ServiceAccountID = "svac_01ABCDEFabcdef0123456789XY" }, + WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + OAuthScope = "workspace:developer", + TokenLifetimeSeconds = 600 + }); + + Console.WriteLine($"id: {rule.ID}"); + Console.WriteLine($"name: {rule.Name}"); + ``` + + ```go Go + client := anthropic.NewClient() + + rule, err := client.Beta.Organization.Federation.Rules.New(context.Background(), anthropic.BetaOrganizationFederationRuleNewParams{ + Name: "gha-deploy", + IssuerID: "fdis_01ABCDEFabcdef0123456789XY", + Match: anthropic.BetaFederationRuleMatchParam{ + SubjectPrefix: anthropic.String("repo:my-org/my-repo:ref:refs/heads/main"), + Claims: map[string]string{"repository_owner": "my-org"}, + }, + Target: anthropic.BetaServiceAccountTargetParam{ + ServiceAccountID: "svac_01ABCDEFabcdef0123456789XY", + }, + WorkspaceID: anthropic.String("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"), + OAuthScope: "workspace:developer", + TokenLifetimeSeconds: anthropic.Int(600), + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", rule.ID) + fmt.Printf("name: %s\n", rule.Name) + ``` + + ```java Java + import com.anthropic.core.JsonValue; + import com.anthropic.models.beta.organization.federation.rules.BetaFederationRuleMatch; + import com.anthropic.models.beta.organization.federation.rules.BetaServiceAccountTarget; + import com.anthropic.models.beta.organization.federation.rules.RuleCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var match = BetaFederationRuleMatch.builder() + .subjectPrefix("repo:my-org/my-repo:ref:refs/heads/main") + .claims(BetaFederationRuleMatch.Claims.builder() + .putAdditionalProperty("repository_owner", JsonValue.from("my-org")) + .build()) + .build(); + var params = RuleCreateParams.builder() + .name("gha-deploy") + .issuerId("fdis_01ABCDEFabcdef0123456789XY") + .match(match) + .target(BetaServiceAccountTarget.of("svac_01ABCDEFabcdef0123456789XY")) + .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + .oauthScope("workspace:developer") + .tokenLifetimeSeconds(600) + .build(); + var rule = client.beta().organization().federation().rules().create(params); + + IO.println("id: " + rule.id()); + IO.println("name: " + rule.name()); + } + ``` + + ```php PHP + $client = new Client(); + + $rule = $client->beta->organization->federation->rules->create( + name: 'gha-deploy', + issuerID: 'fdis_01ABCDEFabcdef0123456789XY', + match: [ + 'subjectPrefix' => 'repo:my-org/my-repo:ref:refs/heads/main', + 'claims' => ['repository_owner' => 'my-org'], + ], + target: [ + 'type' => 'service_account', + 'serviceAccountID' => 'svac_01ABCDEFabcdef0123456789XY', + ], + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + oauthScope: 'workspace:developer', + tokenLifetimeSeconds: 600, + ); + + echo "id: {$rule->id}\n"; + echo "name: {$rule->name}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rule = client.beta.organization.federation.rules.create( + name: "gha-deploy", + issuer_id: "fdis_01ABCDEFabcdef0123456789XY", + match: { + subject_prefix: "repo:my-org/my-repo:ref:refs/heads/main", + claims: {repository_owner: "my-org"} + }, + target: { + type: :service_account, + service_account_id: "svac_01ABCDEFabcdef0123456789XY" + }, + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + oauth_scope: "workspace:developer", + token_lifetime_seconds: 600 + ) + + puts "id: #{rule.id}" + puts "name: #{rule.name}" + ``` +</CodeGroup> + +List rules, optionally filtered by issuer: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/federation_rules?issuer_id=fdis_01ABCDEFabcdef0123456789XY" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:federation:rules list \ + --issuer-id fdis_01ABCDEFabcdef0123456789XY + ``` + + ```python Python + client = anthropic.Anthropic() + + rules = client.beta.organization.federation.rules.list( + issuer_id="fdis_01ABCDEFabcdef0123456789XY" + ) + + for rule in rules: + print(f"{rule.id}: {rule.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + for await (const rule of client.beta.organization.federation.rules.list({ + issuer_id: "fdis_01ABCDEFabcdef0123456789XY" + })) { + console.log(`${rule.id}: ${rule.name}`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var page = await client.Beta.Organization.Federation.Rules.List(new() + { + IssuerID = "fdis_01ABCDEFabcdef0123456789XY" + }); + + await foreach (var rule in page.Paginate()) + { + Console.WriteLine($"{rule.ID}: {rule.Name}"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + rules := client.Beta.Organization.Federation.Rules.ListAutoPaging(context.Background(), anthropic.BetaOrganizationFederationRuleListParams{ + IssuerID: anthropic.String("fdis_01ABCDEFabcdef0123456789XY"), + }) + + for rules.Next() { + rule := rules.Current() + fmt.Printf("%s: %s\n", rule.ID, rule.Name) + } + if err := rules.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.federation.rules.RuleListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = RuleListParams.builder() + .issuerId("fdis_01ABCDEFabcdef0123456789XY") + .build(); + var rules = client.beta().organization().federation().rules().list(params); + + for (var rule : rules.autoPager()) { + IO.println(rule.id() + ": " + rule.name()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $rules = $client->beta->organization->federation->rules->list( + issuerID: 'fdis_01ABCDEFabcdef0123456789XY', + ); + + foreach ($rules->getItems() as $rule) { + echo "{$rule->id}: {$rule->name}\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rules = client.beta.organization.federation.rules.list( + issuer_id: "fdis_01ABCDEFabcdef0123456789XY" + ) + + rules.data.each do |rule| + puts "#{rule.id}: #{rule.name}" + end + ``` +</CodeGroup> + +Archive a rule: + +<CodeGroup> + ```bash cURL + curl --fail-with-body -sS -X POST "https://api.anthropic.com/v1/organizations/federation_rules/fdrl_01ABCDEFabcdef0123456789XY/archive" \ + -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:federation:rules archive \ + --federation-rule-id fdrl_01ABCDEFabcdef0123456789XY + ``` + + ```python Python + client = anthropic.Anthropic() + + rule = client.beta.organization.federation.rules.archive( + "fdrl_01ABCDEFabcdef0123456789XY" + ) + + print(f"id: {rule.id}") + print(f"archived_at: {rule.archived_at}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const rule = await client.beta.organization.federation.rules.archive( + "fdrl_01ABCDEFabcdef0123456789XY" + ); + + console.log(`id: ${rule.id}`); + console.log(`archived_at: ${rule.archived_at}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var rule = await client.Beta.Organization.Federation.Rules.Archive( + "fdrl_01ABCDEFabcdef0123456789XY" + ); + + Console.WriteLine($"id: {rule.ID}"); + Console.WriteLine($"archived_at: {rule.ArchivedAt:O}"); + ``` + + ```go Go + client := anthropic.NewClient() + + rule, err := client.Beta.Organization.Federation.Rules.Archive( + context.Background(), + "fdrl_01ABCDEFabcdef0123456789XY", + anthropic.BetaOrganizationFederationRuleArchiveParams{}, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", rule.ID) + fmt.Printf("archived_at: %s\n", rule.ArchivedAt) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var rule = client.beta().organization().federation().rules() + .archive("fdrl_01ABCDEFabcdef0123456789XY"); + + IO.println("id: " + rule.id()); + IO.println("archived_at: " + rule.archivedAt().orElseThrow()); + ``` + + ```php PHP + $client = new Client(); + + $rule = $client->beta->organization->federation->rules->archive( + federationRuleID: 'fdrl_01ABCDEFabcdef0123456789XY', + ); + + echo "id: {$rule->id}\n"; + echo "archived_at: {$rule->archivedAt?->format(DATE_ATOM)}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + rule_id = "fdrl_01ABCDEFabcdef0123456789XY" + rule = client.beta.organization.federation.rules.archive(rule_id) + + puts "id: #{rule.id}" + puts "archived_at: #{rule.archived_at}" + ``` +</CodeGroup> The list endpoint returns a page of rules and the cursor for the next page:
manage-claude/workspaces Changed · +669 / -43 lines
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
Admin API endpoints require an Admin API key (starting with `sk-ant-admin...`) that differs from standard API keys. See [Create an Admin API key](https://platform.claude.com/docs/en/manage-claude/admin-api-keys) for how to provision one. </Note> -```bash cURL -# Create a workspace -curl -X POST "https://api.anthropic.com/v1/organizations/workspaces" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -H "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - -d '{"name": "Production"}' - -# List workspaces -curl "https://api.anthropic.com/v1/organizations/workspaces?limit=10&include_archived=false" \ - -H "anthropic-version: 2023-06-01" \ - -H "x-api-key: $ANTHROPIC_ADMIN_KEY" - -# Archive a workspace -curl -X POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/archive" \ - -H "anthropic-version: 2023-06-01" \ - -H "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +The following SDK and CLI examples construct the default client, which reads the Admin API key from the `ANTHROPIC_API_KEY` environment variable; the SDKs expose these endpoints under `client.beta.organization.workspaces`. SDK list methods fetch further pages on demand, so `limit` sets the page size; the PHP, Ruby, and curl examples return one page. + +Create a workspace: + +<CodeGroup> + ```bash cURL + curl -X POST "https://api.anthropic.com/v1/organizations/workspaces" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{"name": "Production"}' + ``` + + ```bash CLI + ant beta:organization:workspaces create --name Production + ``` + + ```python Python + client = anthropic.Anthropic() + + workspace = client.beta.organization.workspaces.create(name="Production") + + print(f"id: {workspace.id}") + print(f"name: {workspace.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const workspace = await client.beta.organization.workspaces.create({ name: "Production" }); + + console.log(`id: ${workspace.id}`); + console.log(`name: ${workspace.name}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var workspace = await client.Beta.Organization.Workspaces.Create(new() + { + Name = "Production" + }); + + Console.WriteLine($"id: {workspace.ID}"); + Console.WriteLine($"name: {workspace.Name}"); + ``` + + ```go Go + client := anthropic.NewClient() + + workspace, err := client.Beta.Organization.Workspaces.New(context.Background(), anthropic.BetaOrganizationWorkspaceNewParams{ + Name: "Production", + }) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", workspace.ID) + fmt.Printf("name: %s\n", workspace.Name) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.WorkspaceCreateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = WorkspaceCreateParams.builder() + .name("Production") + .build(); + var workspace = client.beta().organization().workspaces().create(params); + + IO.println("id: " + workspace.id()); + IO.println("name: " + workspace.name()); + } + ``` + + ```php PHP + $client = new Client(); + + $workspace = $client->beta->organization->workspaces->create( + name: 'Production', + ); + + echo "id: {$workspace->id}\n"; + echo "name: {$workspace->name}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace = client.beta.organization.workspaces.create(name: "Production") + + puts "id: #{workspace.id}" + puts "name: #{workspace.name}" + ``` +</CodeGroup> + +List workspaces: + +<CodeGroup> + ```bash cURL + curl "https://api.anthropic.com/v1/organizations/workspaces?limit=10&include_archived=false" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:workspaces list --limit 10 --include-archived=false + ``` + + ```python Python + client = anthropic.Anthropic() + + workspaces = client.beta.organization.workspaces.list(limit=10, include_archived=False) + + for workspace in workspaces: + print(f"{workspace.id}: {workspace.name}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const workspaces = await client.beta.organization.workspaces.list({ + limit: 10, + include_archived: false + }); + + for await (const workspace of workspaces) { + console.log(`${workspace.id}: ${workspace.name}`); + } + ``` + + ```csharp C# + AnthropicClient client = new(); + + var workspaces = await client.Beta.Organization.Workspaces.List(new() + { + Limit = 10, + IncludeArchived = false + }); + + await foreach (var workspace in workspaces.Paginate()) + { + Console.WriteLine($"{workspace.ID}: {workspace.Name}"); + } + ``` + + ```go Go + client := anthropic.NewClient() + + workspaces := client.Beta.Organization.Workspaces.ListAutoPaging(context.Background(), anthropic.BetaOrganizationWorkspaceListParams{ + Limit: anthropic.Int(10), + IncludeArchived: anthropic.Bool(false), + }) + + for workspaces.Next() { + workspace := workspaces.Current() + fmt.Printf("%s: %s\n", workspace.ID, workspace.Name) + } + if err := workspaces.Err(); err != nil { + log.Fatal(err) + } + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.WorkspaceListParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = WorkspaceListParams.builder() + .limit(10) + .includeArchived(false) + .build(); + var workspaces = client.beta().organization().workspaces().list(params); + + for (var workspace : workspaces.autoPager()) { + IO.println(workspace.id() + ": " + workspace.name()); + } + } + ``` + + ```php PHP + $client = new Client(); + + $workspaces = $client->beta->organization->workspaces->list( + limit: 10, + includeArchived: false, + ); + + foreach ($workspaces->getItems() as $workspace) { + echo "{$workspace->id}: {$workspace->name}\n"; + } + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspaces = client.beta.organization.workspaces.list(limit: 10, include_archived: false) + + workspaces.data.each do |workspace| + puts "#{workspace.id}: #{workspace.name}" + end + ``` +</CodeGroup> + +Archive a workspace: + +<CodeGroup> + ```bash cURL + curl -X POST "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/archive" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:workspaces archive --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + ``` + + ```python Python + client = anthropic.Anthropic() + + workspace = client.beta.organization.workspaces.archive( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + print(f"id: {workspace.id}") + print(f"archived_at: {workspace.archived_at}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const workspace = await client.beta.organization.workspaces.archive( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ); + + console.log(`id: ${workspace.id}`); + console.log(`archived_at: ${workspace.archived_at}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var workspace = await client.Beta.Organization.Workspaces.Archive( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ); + + Console.WriteLine($"id: {workspace.ID}"); + Console.WriteLine($"archived_at: {workspace.ArchivedAt:O}"); + ``` + + ```go Go + client := anthropic.NewClient() + + workspace, err := client.Beta.Organization.Workspaces.Archive(context.Background(), "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + if err != nil { + log.Fatal(err) + } + + fmt.Printf("id: %s\n", workspace.ID) + fmt.Printf("archived_at: %s\n", workspace.ArchivedAt) + ``` + + ```java Java + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var workspace = client.beta().organization().workspaces() + .archive("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"); + + IO.println("id: " + workspace.id()); + IO.println("archived_at: " + workspace.archivedAt().orElseThrow()); + ``` + + ```php PHP + $client = new Client(); + + $workspace = $client->beta->organization->workspaces->archive( + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + ); + + echo "id: {$workspace->id}\n"; + echo "archived_at: {$workspace->archivedAt?->format(DATE_ATOM)}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + workspace = client.beta.organization.workspaces.archive(workspace_id) + + puts "id: #{workspace.id}" + puts "archived_at: #{workspace.archived_at}" + ``` +</CodeGroup> For complete parameter details and response schemas, see the [Workspaces API reference](https://platform.claude.com/docs/en/api/admin/workspaces/retrieve). ### Managing workspace members -Add, update, or remove members from a workspace: - -```bash cURL -# Add a member to a workspace -curl -X POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -H "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - -d '{ - "user_id": "user_xxx", - "workspace_role": "workspace_developer" - }' - -# Update a member's role -curl -X POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members/{user_id}" \ - -H "anthropic-version: 2023-06-01" \ - -H "content-type: application/json" \ - -H "x-api-key: $ANTHROPIC_ADMIN_KEY" \ - -d '{"workspace_role": "workspace_admin"}' - -# Remove a member from a workspace -curl -X DELETE "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members/{user_id}" \ - -H "anthropic-version: 2023-06-01" \ - -H "x-api-key: $ANTHROPIC_ADMIN_KEY" -``` +Add a member to a workspace: + +<CodeGroup> + ```bash cURL + curl -X POST "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{ + "user_id": "user_01XyDMpzjS89pFZXqSFUBDr6", + "workspace_role": "workspace_developer" + }' + ``` + + ```bash CLI + ant beta:organization:workspaces:members add \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --workspace-role workspace_developer + ``` + + ```python Python + client = anthropic.Anthropic() + + member = client.beta.organization.workspaces.members.add( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + user_id="user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_role="workspace_developer", + ) + + print(f"user_id: {member.user_id}") + print(f"workspace_role: {member.workspace_role}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const member = await client.beta.organization.workspaces.members.add( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + { + user_id: "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_role: "workspace_developer" + } + ); + + console.log(`user_id: ${member.user_id}`); + console.log(`workspace_role: ${member.workspace_role}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Workspaces; + + AnthropicClient client = new(); + + var member = await client.Beta.Organization.Workspaces.Members.Add( + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + new() + { + UserID = "user_01XyDMpzjS89pFZXqSFUBDr6", + WorkspaceRole = BetaNoBillingWorkspaceRole.WorkspaceDeveloper + } + ); + + Console.WriteLine($"user_id: {member.UserID}"); + Console.WriteLine($"workspace_role: {member.WorkspaceRole.Raw()}"); + ``` + + ```go Go + client := anthropic.NewClient() + + member, err := client.Beta.Organization.Workspaces.Members.Add( + context.Background(), + "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + anthropic.BetaOrganizationWorkspaceMemberAddParams{ + UserID: "user_01XyDMpzjS89pFZXqSFUBDr6", + WorkspaceRole: anthropic.BetaNoBillingWorkspaceRoleWorkspaceDeveloper, + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("user_id: %s\n", member.UserID) + fmt.Printf("workspace_role: %s\n", member.WorkspaceRole) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.BetaNoBillingWorkspaceRole; + import com.anthropic.models.beta.organization.workspaces.members.MemberAddParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberAddParams.builder() + .userId("user_01XyDMpzjS89pFZXqSFUBDr6") + .workspaceRole(BetaNoBillingWorkspaceRole.WORKSPACE_DEVELOPER) + .build(); + var member = client.beta().organization().workspaces().members() + .add("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", params); + + IO.println("user_id: " + member.userId()); + IO.println("workspace_role: " + member.workspaceRole().asString()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\Workspaces\NoBillingWorkspaceRole; + // ... + + $client = new Client(); + + $member = $client->beta->organization->workspaces->members->add( + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + workspaceRole: NoBillingWorkspaceRole::WORKSPACE_DEVELOPER, + ); + + echo "user_id: {$member->userID}\n"; + echo "workspace_role: {$member->workspaceRole}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + member = client.beta.organization.workspaces.members.add( + workspace_id, + user_id: "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_role: :workspace_developer + ) + + puts "user_id: #{member.user_id}" + puts "workspace_role: #{member.workspace_role}" + ``` +</CodeGroup> + +Update a member's role: + +<CodeGroup> + ```bash cURL + curl -X POST "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members/user_01XyDMpzjS89pFZXqSFUBDr6" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" \ + -H "content-type: application/json" \ + -d '{"workspace_role": "workspace_admin"}' + ``` + + ```bash CLI + ant beta:organization:workspaces:members update \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \ + --workspace-role workspace_admin + ``` + + ```python Python + client = anthropic.Anthropic() + + member = client.beta.organization.workspaces.members.update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + workspace_role="workspace_admin", + ) + + print(f"user_id: {member.user_id}") + print(f"workspace_role: {member.workspace_role}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const member = await client.beta.organization.workspaces.members.update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + { + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + workspace_role: "workspace_admin" + } + ); + + console.log(`user_id: ${member.user_id}`); + console.log(`workspace_role: ${member.workspace_role}`); + ``` + + ```csharp C# + using Anthropic.Models.Beta.Organization.Workspaces; + + AnthropicClient client = new(); + + var member = await client.Beta.Organization.Workspaces.Members.Update( + "user_01XyDMpzjS89pFZXqSFUBDr6", + new() + { + WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + WorkspaceRole = BetaWorkspaceRole.WorkspaceAdmin + } + ); + + Console.WriteLine($"user_id: {member.UserID}"); + Console.WriteLine($"workspace_role: {member.WorkspaceRole.Raw()}"); + ``` + + ```go Go + client := anthropic.NewClient() + + member, err := client.Beta.Organization.Workspaces.Members.Update( + context.Background(), + "user_01XyDMpzjS89pFZXqSFUBDr6", + anthropic.BetaOrganizationWorkspaceMemberUpdateParams{ + WorkspaceID: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + WorkspaceRole: anthropic.BetaWorkspaceRoleWorkspaceAdmin, + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("user_id: %s\n", member.UserID) + fmt.Printf("workspace_role: %s\n", member.WorkspaceRole) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.BetaWorkspaceRole; + import com.anthropic.models.beta.organization.workspaces.members.MemberUpdateParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberUpdateParams.builder() + .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + .workspaceRole(BetaWorkspaceRole.WORKSPACE_ADMIN) + .build(); + var member = client.beta().organization().workspaces().members() + .update("user_01XyDMpzjS89pFZXqSFUBDr6", params); + + IO.println("user_id: " + member.userId()); + IO.println("workspace_role: " + member.workspaceRole().asString()); + } + ``` + + ```php PHP + use Anthropic\Beta\Organization\Workspaces\WorkspaceRole; + // ... + + $client = new Client(); + + $member = $client->beta->organization->workspaces->members->update( + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + workspaceRole: WorkspaceRole::WORKSPACE_ADMIN, + ); + + echo "user_id: {$member->userID}\n"; + echo "workspace_role: {$member->workspaceRole}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + user_id = "user_01XyDMpzjS89pFZXqSFUBDr6" + member = client.beta.organization.workspaces.members.update( + user_id, + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + workspace_role: :workspace_admin + ) + + puts "user_id: #{member.user_id}" + puts "workspace_role: #{member.workspace_role}" + ``` +</CodeGroup> + +Remove a member from a workspace: + +<CodeGroup> + ```bash cURL + curl -X DELETE "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members/user_01XyDMpzjS89pFZXqSFUBDr6" \ + -H "x-api-key: $ANTHROPIC_API_KEY" \ + -H "anthropic-version: 2023-06-01" + ``` + + ```bash CLI + ant beta:organization:workspaces:members remove \ + --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \ + --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + ``` + + ```python Python + client = anthropic.Anthropic() + + removed_member = client.beta.organization.workspaces.members.remove( + "user_01XyDMpzjS89pFZXqSFUBDr6", + workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + ) + + print(f"user_id: {removed_member.user_id}") + ``` + + ```typescript TypeScript + const client = new Anthropic(); + + const removedMember = await client.beta.organization.workspaces.members.remove( + "user_01XyDMpzjS89pFZXqSFUBDr6", + { workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" } + ); + + console.log(`user_id: ${removedMember.user_id}`); + ``` + + ```csharp C# + AnthropicClient client = new(); + + var removedMember = await client.Beta.Organization.Workspaces.Members.Remove( + "user_01XyDMpzjS89pFZXqSFUBDr6", + new() { WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" } + ); + + Console.WriteLine($"user_id: {removedMember.UserID}"); + ``` + + ```go Go + client := anthropic.NewClient() + + removedMember, err := client.Beta.Organization.Workspaces.Members.Remove( + context.Background(), + "user_01XyDMpzjS89pFZXqSFUBDr6", + anthropic.BetaOrganizationWorkspaceMemberRemoveParams{ + WorkspaceID: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", + }, + ) + if err != nil { + log.Fatal(err) + } + + fmt.Printf("user_id: %s\n", removedMember.UserID) + ``` + + ```java Java + import com.anthropic.models.beta.organization.workspaces.members.MemberRemoveParams; + + void main() { + AnthropicClient client = AnthropicOkHttpClient.fromEnv(); + + var params = MemberRemoveParams.builder() + .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ") + .build(); + var removedMember = client.beta().organization().workspaces().members() + .remove("user_01XyDMpzjS89pFZXqSFUBDr6", params); + + IO.println("user_id: " + removedMember.userId()); + } + ``` + + ```php PHP + $client = new Client(); + + $removedMember = $client->beta->organization->workspaces->members->remove( + userID: 'user_01XyDMpzjS89pFZXqSFUBDr6', + workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ', + ); + + echo "user_id: {$removedMember->userID}\n"; + ``` + + ```ruby Ruby + client = Anthropic::Client.new + + user_id = "user_01XyDMpzjS89pFZXqSFUBDr6" + removed_member = client.beta.organization.workspaces.members.remove( + user_id, + workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + ) + + puts "user_id: #{removed_member.user_id}" + ``` +</CodeGroup> For complete parameter details, see the [Workspace Members API reference](https://platform.claude.com/docs/en/api/admin/workspaces/members/retrieve).
release-notes/overview Changed · +7 / -0 lines
### August 26, 2026
For updates to Claude Code, see the [complete CHANGELOG.md](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md) in the `claude-code` repository. </Tip> +### August 26, 2026 + +* The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) session endpoints are out of beta for Cowork and Claude Code sessions. See [Retrieve session transcripts](https://platform.claude.com/docs/en/manage-claude/compliance-sessions). +* The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) local session endpoints now also return transcripts of Claude Science sessions (`product_surface` value `claude_science`) and Claude for Microsoft 365 sessions in Excel, PowerPoint, Word, and Outlook (`product_surface` values beginning with `office_agents`), in beta for Claude Enterprise organizations, with your existing Compliance Access Key and the `read:compliance_user_data` scope. See [Sessions on users' machines](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-local-sessions). + +- The [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api) is now available in the `ant` CLI and the Python, TypeScript, C#, Go, Java, PHP, and Ruby SDKs under `client.beta.organization`. They cover organization info, members, invites, workspaces and workspace members, API keys, rate limits, service accounts, workload identity federation issuers and rules, and customer-managed encryption keys. Usage and cost reports and the Claude Enterprise user-management and analytics endpoints remain curl-only. The CLI and SDKs read an Admin API key from `ANTHROPIC_API_KEY` or an `org:admin` OAuth token from `ANTHROPIC_AUTH_TOKEN`. + ### August 20, 2026 * We've released **v1.0 of the [Python SDK](https://platform.claude.com/docs/en/cli-sdks-libraries/sdks/python)**. The SDK's HTTP layer moves from `httpx` to [httpx2](https://httpx2.pydantic.dev), a maintained, API-compatible fork: build custom `http_client`, `Timeout`, and transport objects from `httpx2` (the `DefaultHttpxClient` helpers are unchanged), and call `httpx2.alias_httpx()` at startup if you rely on tracing or mocking libraries that patch `httpx`. v1.0 requires Python 3.10 or later and removes long-deprecated surface, including the legacy Text Completions API, the `temperature`, `top_p`, and `top_k` parameters on Messages methods, and the tool runner's client-side `compaction_control`. On the async client, `.with_raw_response` results now need `await response.parse()`, and `AnthropicBedrock` now raises an error when no AWS region is configured instead of defaulting to `us-east-1`. See the [v1 migration guide](https://github.com/anthropics/anthropic-sdk-python/blob/main/MIGRATION.md) for every change with before-and-after snippets.
api/skills Changed · +2 / -2 lines
- `version: string` - Identifies the skill version: a version ID, or — where the endpoint accepts it — the literal `latest` for the skill's most recent version. + Identifies the skill version: a version ID, or the literal `latest` for the skill's most recent version. Requests carrying the `skills-2025-10-02` beta header address versions by their Unix epoch timestamp instead (e.g., "1759178010641129").
- `version: string` - Identifies the skill version: a version ID, or — where the endpoint accepts it — the literal `latest` for the skill's most recent version. + Identifies the skill version by its version ID. Requests carrying the `skills-2025-10-02` beta header address versions by their Unix epoch timestamp instead (e.g., "1759178010641129").