Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · api

One read of Claude Developer Platformapi-20260924T173729Z

83 pages moved out of 637 read.

Pages moved 83 significant first
Pages read 637 in this capture
Captured 17:37 UTC
Corpus hash 60090eb3549b corpus-hash

What this read moved

1-25 of 83, page 1 of 4

This capture is too large to show at once. Changes 1-25 of 83 are below, significant first; the rest are on the following screens.

about-claude/models/optimizing-for-cost-and-intelligence Changed · +103 / -2 lines

### Show the model elapsed time

from line 13
1313The levers come in two kinds:
1414 
1515* **Free wins** cut spend without touching quality: prompt caching, token hygiene, a prompt audit against the model you are running, [batch processing](https://platform.claude.com/docs/en/build-with-claude/batch-processing) at 50% off for work that can wait up to 24 hours, and [workspace spend limits](https://platform.claude.com/docs/en/api/rate-limits#setting-lower-limits-for-workspaces) as the backstop.
16* **Tradeoffs** exchange cost for intelligence: model choice, effort, output caps and task budgets, and multi-model architectures.
16* **Tradeoffs** exchange cost for intelligence: model choice, effort, output caps and task budgets, an elapsed-time clock, and multi-model architectures.
1717 
1818Each lever comes with measured results and the rule for when it pays. In Anthropic's measurements, prompt caching was the largest lever by a wide margin: it cut agent-loop cost by a factor of 2.7 to 5.3 on this guide's benchmarks and cut a small triage agent's bill by 83%, or 88% with input trimming added. The multi-model levers are narrower; a second model paid off in two shapes, an advisor and an orchestrator.
1919 
from line 32
3232| Attempts end with `stop_reason: max_tokens` | Raise `max_tokens`; 64,000 covered all but 2 of 14,000 turns measured at the default effort, and 128,000 cost nothing extra per solved task | [Set budgets](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#set-budgets-and-output-caps) |
3333| You can check outputs (tests, a verifier) | Run everything at low effort and re-run failures at `high`; on the coding benchmark measured, the pass rate held at about half the cost | [Re-run failures](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#re-run-failures-at-higher-effort) |
3434| Agent loops with a few very costly runs | Set a task budget (beta; check the support table for which models), a Claude Managed Agents session budget, and a workspace spend limit | [Set budgets](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#set-budgets-and-output-caps) |
35| You want agent runs to finish sooner | Tell the model that time matters, and show it the elapsed time; on DRACO, HLE, and an internal physics set, runs took 33% to 69% less time at a 28% to 54% lower cost per task, with scores up to 1.9 points lower | [Show the model elapsed time](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#show-the-model-elapsed-time) |
3536| A lower-cost model stalls only on hard decisions | Add a frontier advisor. It pays off when priced well above the executor and actually consulted, so first price the advisor's model alone at low effort and measure the consult rate | [Advisor strategy](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#advisor-strategy-escalate-hard-decisions) |
3637| The work exceeds one context window | Delegate partitions to cheaper workers | [Orchestrator strategy](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#orchestrator-strategy-delegate-bulk-work) |
3738 
from line 244
243244 
244245## Trade cost against intelligence
245246 
246These levers set where a single model sits between cost and intelligence: model choice, effort, re-running failures at a higher setting, and the budgets and caps it works within. Start with an effort sweep on your current model ([Tune effort](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#tune-effort)). From lowest to highest cost and capability, the current models are Claude Haiku 4.5, Claude Sonnet 5, Claude Opus 5.5, and Claude Fable 5.1 (the frontier model); [Models overview](https://platform.claude.com/docs/en/models/overview) has the full lineup and prices.
247These levers set where a single model sits between cost and intelligence: model choice, effort, re-running failures at a higher setting, the budgets and caps it works within, and whether it can see how much time has passed. Start with an effort sweep on your current model ([Tune effort](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#tune-effort)). From lowest to highest cost and capability, the current models are Claude Haiku 4.5, Claude Sonnet 5, Claude Opus 5.5, and Claude Fable 5.1 (the frontier model); [Models overview](https://platform.claude.com/docs/en/models/overview) has the full lineup and prices.
247248 
248249### Compare models on cost per task
249250 
from line 363
362363 
363364![Dot plot of per-turn output for Opus 5.5 and Fable 5.1: medians a few hundred tokens, longest 61k and 128k, against the caps](https://platform.claude.com/docs/images/cost-intel-max-tokens-ladder-opus-5-5.png)
364365 
366### Show the model elapsed time
367 
368A model in an agent loop can't see a clock. A [task budget](https://platform.claude.com/docs/en/build-with-claude/task-budgets) shows it how many tokens are left, but by default nothing in the request shows it how long the work has taken. Two small changes give it that signal. Add a two-sentence instruction to the system prompt that says time matters, and from the second request on, send the elapsed time before each of the model's turns.
369 
370Anthropic measured both changes together with Claude Fable 5.1 at `high` effort, on two public benchmarks, DRACO[21](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs) and HLE[22](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs), and on an internal set of 70 research-level physics problems, adapted from the public CritPt benchmark[23](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs). This page calls that set the physics set. Each of the three ran in two shapes: a single agent, and a team in which a lead agent starts helper agents of the same model that work in parallel. A score change counts as inside the margin when its 95% interval stays within a limit that Anthropic set before the runs: 1.5 points on DRACO and 2.5 points on HLE. The following chart plots score against cost per task for each configuration. A second row of bars gives each configuration's time as a ratio to the single agent at `high` effort, without retry waits. A third row gives the score change that both changes make, with its 95% interval:
371 
372![Charts, DRACO, HLE, and the physics set: both changes cut each setup's cost and time, and its score moves by under 2 points](https://platform.claude.com/docs/images/cost-intel-time-awareness.png)
373 
374**With a team of agents.** A team does more work than a single agent, so by default it costs more. On DRACO, the team cost 4.0 times as much as the single agent and took about as long (95% interval 12% less to 13% more). With the instruction and the clock on every agent, the team finished in 33% less time at a 54% lower cost per task. Its score was 1.5 points lower (95% interval 0.9 to 2.1 lower), and the far end of that interval, 2.1 points lower, is past the 1.5-point margin. On HLE, the team finished in 51% less time at a 54% lower cost per task. Its score was 1.7 points lower (95% interval 0.3 to 3.1 lower), and the far end of that interval, 3.1 points lower, is past the 2.5-point margin. On the physics set[23](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs), the team finished in 39% less time. Its cost per task was 28% lower, and that saving depends on how often the prompt cache expired between requests. With no expiry, it would be 23%. Its score was 0.2 points higher (95% interval 1.5 lower to 2.0 higher).
375 
376On DRACO, the lead started a median of 4 helpers per attempt, so the DRACO result shows a team working in parallel. On HLE and the physics set, the lead started a median of 0 helpers, so at least half of those team runs had only the lead agent. Those team results mostly show the lead agent's own behavior, not the effect of parallel helpers.
377 
378**With a single agent.** On the physics set[23](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs), the same changes cut a single agent's time by 34% and its cost per task by 34%. Its score was 0.2 points lower (95% interval 2.5 lower to 2.1 higher). On the physics set, a lower effort level saved cost but not clearly time. At `medium` effort, the single agent cost 37% less per task than at `high`, and its time was 9% less (95% interval 30% less to 16% more). It scored 3.4 points lower (95% interval 0.4 to 6.8 lower), and the interval reaches close to zero. With both changes at `high` effort, the single agent took 27% less time than at `medium` effort (95% interval 5% less to 44% less). Its cost per task was 6% more (95% interval 12% less to 27% more), and its score was 3.2 points higher (95% interval 0.1 lower to 6.5 higher).
379 
380On HLE, the same changes cut a single agent's time by 54% and its cost per task by 48%. Its score was 1.1 points lower (95% interval 2.6 lower to 0.3 higher), and the far end of that interval, 2.6 points lower, is just past the 2.5-point margin. At `medium` effort, the single agent cost 43% less per task than at `high`, took 39% less time, and scored 1.3 points lower (95% interval 2.8 lower to 0.1 higher). With both changes at `high` effort, the single agent took 25% less time than at `medium` effort (95% interval 12% less to 35% less). Its cost per task was 9% less (95% interval 21% less to 6% more), and its score was 0.2 points higher (95% interval 1.3 lower to 1.7 higher).
381 
382On DRACO, the same changes cut a single agent's time by 69% and its cost per task by 49%. Its score was 1.9 points lower (95% interval 1.1 to 2.8 lower), and the far end of that interval, 2.8 points lower, is past the 1.5-point margin. At `medium` effort, the single agent cost 25% less per task than at `high`, took 30% less time, and scored 0.7 points lower (95% interval 0.1 to 1.3 lower). With both changes at `high` effort, the single agent took 53% less time than at `medium` effort (95% interval 42% less to 63% less), and its cost per task was 31% less (95% interval 28% less to 35% less). Its score was 1.2 points lower (95% interval 0.5 to 1.9 lower), and the far end of that interval, 1.9 points lower, is past the 1.5-point margin.
383 
384On all three sets, both changes at `high` effort saved more time than `medium` effort did. On HLE and the physics set, there was no clear difference in cost, and on DRACO the cost was lower. The score was about the same on HLE. On the physics set it was 3.2 points higher, but that interval includes zero, so the difference isn't clear. So for a single agent, the clock saves more time than a lower effort level does. On DRACO, though, the single agent with both changes scored 1.2 points lower than at `medium` effort (95% interval 0.5 to 1.9 lower).
385 
386**When to use it.**
387 
388* Use both changes when an agent's time matters and a small score change is acceptable. On every configuration measured, they cut the time and cost per task, for teams and for single agents.
389* Check score on your own tasks before you adopt them. On DRACO, the score was 1.5 points lower for a team and 1.9 points lower for a single agent. On HLE, it was 1.7 points lower for a team and 1.1 points lower for a single agent. On the physics set, neither score change was clearly different from zero.
390* If you're already thinking about a lower effort level to save time, compare it with the clock. A single agent with both changes at `high` effort took less time than at `medium` effort: 53% less on DRACO, 25% less on HLE, and 27% less on the physics set. Its cost per task was 31% lower on DRACO, with no clear difference on HLE and the physics set.
391 
392**How to add it.** Put this instruction at the start of every agent's system prompt:
393 
394```text wrap
395Time matters here: do not spend time that can be avoided, and the earlier a correct result is obtained, the better. The elapsed time so far is shown before each of your turns.
396```
397 
398The second sentence tells the model that the clock messages exist. The first request carries no clock, and the measured runs used exactly this wording.
399 
400Then, before each request after an agent's first, append a [mid-conversation system message](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages) that gives the elapsed time in whole seconds, such as `Elapsed time: 412 seconds`. Count from the start of the task, not from the start of the agent. In a team, every agent reads the same clock, so the first clock a helper sees already counts the time the team spent before the helper started. In a tool loop, put the message right after the `user` message that carries the tool results, as [Placement after tool results](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages#placement-after-tool-results) shows. If you send the agent a new `user` message instead, put the clock after that message.
401 
402Leave earlier clock messages where they are. Each one becomes part of the conversation history, so the cached prefix still matches on the next request (see [Combining with prompt caching](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages#combining-with-prompt-caching)). Anthropic measured these plain system messages, which stay visible to the model. A [turn-scoped system message](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages#turn-scoped-system-messages) would show the model only the newest clock, and Anthropic didn't measure that form.
403 
404The following example runs one agent's tool loop with both changes. It adds the clock after tool results, and it handles client tools only:
405 
406```python
407import time
408 
409import anthropic
410 
411client = anthropic.Anthropic()
412 
413TIME_MATTERS = (
414 "Time matters here: do not spend time that can be avoided, and the earlier a "
415 "correct result is obtained, the better. The elapsed time so far is shown before "
416 "each of your turns."
417)
418 
419 
420def run_agent(task, system, tools, run_tool, started_at=None):
421 """Run one agent's tool loop. In a team, pass the lead's started_at to every helper."""
422 if started_at is None:
423 # Wall-clock seconds, so helpers in other processes can share the lead's start time.
424 started_at = time.time()
425 messages = [{"role": "user", "content": task}]
426 while True:
427 # Stream because a 128,000-token cap is too large for a non-streaming request.
428 with client.messages.stream(
429 model="claude-fable-5-1",
430 max_tokens=128000,
431 cache_control={"type": "ephemeral"},
432 system=TIME_MATTERS + "\n\n" + system,
433 tools=tools,
434 messages=messages,
435 ) as stream:
436 response = stream.get_final_message()
437 messages.append({"role": "assistant", "content": response.content})
438 if response.stop_reason != "tool_use":
439 return response
440 results = [
441 {
442 "type": "tool_result",
443 "tool_use_id": block.id,
444 "content": run_tool(block.name, block.input),
445 }
446 for block in response.content
447 if block.type == "tool_use"
448 ]
449 messages.append({"role": "user", "content": results})
450 # A system message must follow a user turn, so the clock goes after the tool results.
451 elapsed = int(time.time() - started_at)
452 messages.append(
453 {"role": "system", "content": f"Elapsed time: {elapsed} seconds"}
454 )
455```
456 
457Claude Fable 5.1 supports mid-conversation system messages. The [list of supported models](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages) covers the others. On a model without them, such as Claude Sonnet 5, you can put the same line in a text block after the last `tool_result` block in the `user` turn. Anthropic measured only the system-message form.
458 
459On Claude Managed Agents, you can send a [`system.message` event](https://platform.claude.com/docs/en/managed-agents/events-and-streaming#sending-system-messages) with a tool result or a user message. The message applies to that turn and every later turn. So turns that follow the platform's built-in tools, such as web search, see the last clock you sent, not the current time. A `system.message` also reaches only the session's primary thread. In a [multiagent session](https://platform.claude.com/docs/en/managed-agents/multiagent-orchestration), that is the coordinator's thread, so the worker agents never see a clock that you send this way. To show the current time before every turn, and to every agent in a team, run the agent loop yourself on the Messages API.
460 
365461## Combine models
366462 
367463Multi-model architectures fit workloads whose task complexity varies enough that different steps are best served by different models. When your traffic mixes routine work that a smaller model handles reliably with harder steps that need frontier capability, splitting the work keeps frontier intelligence where it matters while most tokens bill at smaller-model rates. When a workload lacks that mix, because its difficulty is uniform or it is one dependent chain, a single well-tuned model is usually the better choice. Each strategy section gives the rule for telling the two cases apart.
from line 511
415511 
416512This pattern saves wall-clock time when workers can run in parallel: on the corpus benchmark[8](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs), an episode took about 2.3 hours with the coordinator running the platform's documented limit of 25 concurrent workers, compared with 15 to 20 hours solo. It saved money in only two measured situations. On work a single model could handle alone, the same model at lower effort was cheaper every time.
417513 
514When workers run in parallel, a time instruction and an elapsed-time clock can shorten the run. On DRACO[21](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs), a team of same-model agents with the instruction and the clock finished in 33% less time at a 54% lower cost per task, and scored 1.5 points lower. Every agent in that team had the instruction and the clock. Anthropic didn't measure the clock with lower-cost workers. On Claude Managed Agents, the clock reaches only the coordinator, so the workers never see it. Anthropic didn't measure a team in which only the coordinator has the clock. The coordinator's clock is also current only on turns that follow your own tool results or messages. [Show the model elapsed time](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#show-the-model-elapsed-time) has the recipe for an agent loop that you run on the Messages API.
515 
418516**Case 1: insurance against the cost tail on routine work.** A frontier model running alone occasionally spirals on a routine problem it would normally solve. Because you cannot tell in advance which those will be, a few such runs dominate the bill. A coordinator that hands routine work to a lower-cost worker caps that tail, because any spiraling now happens at worker rates.
419517 
420518Anthropic measured this on a deliberately easy slice of BrowseComp[4](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#refs) (10 problems the solo model reliably solves; 50 delegated and 70 solo runs). A Claude Fable 5 coordinator with one Claude Sonnet 5 worker cost about half as much as Claude Fable 5 alone on average and about a third as much at the 90th percentile ($12 compared with $33), and the solo model's single most expensive run, at $84, was also wrong:
from line 837
73983718. **Compaction timing measurement:** The triage agent's long variant from [Trim input and context tokens](https://platform.claude.com/docs/en/about-claude/models/optimizing-for-cost-and-intelligence#trim-input-and-context-tokens), run August 24, 2026, on Claude Sonnet 5 with the 5-minute cache, cost from the usage fields at list prices, five sessions per arm: a no-change arm at the default effort throughout ($0.81 per session), and two arms that start at low effort and make the same two cache-breaking changes, a switch to the default effort and one added tool, either mid-session at requests 12 and 17 ($0.95) or together on the first request after the first compaction ($0.75). A fourth arm of six sessions, run August 25, 2026, made the same two changes on the request that triggered the first compaction ($0.92 per session): that request's summarization pass wrote the 81,000-token context to the cache instead of reading it, so that pass cost $0.21 against $0.04 for the same pass in the boundary arm. Sessions first compacted at request 21 to 25 (16 of the 21 sessions at request 22), once the prompt passed the 80,000-token compaction trigger, and two no-change sessions compacted a second time near the end. The boundary arm's lower total than the no-change arm reflects its low-effort requests before the change and those second compactions rather than caching: the two arms' re-write costs differ by under a cent. The mid-session arm paid $0.23 per session in cache re-writes; the difference between the mid-session and boundary arms was $0.20 with a 95% confidence interval of $0.11 to $0.29. One mid-session session ran cheap ($0.82) after its model mis-called the search tool following compaction and got empty results; it is included, and without it the arm averages $0.98. Accuracy averaged 14.2 of 20 labels in each August 24 arm and 14.7 in the August 25 arm; cache reads were 91% of prompt tokens with no changes, 85% mid-session, 91% at the boundary, and 86% with the changes on the triggering request.
74083819. **Cache duration measurement on Claude Fable 5.1:** The same 20-issue triage job and harness as reference 16, run August 23 and August 26, 2026, on the Claude Fable 5.1 launch snapshot at its launch prices ($10 input, $12.50 5-minute write, $20 1-hour write, $0.25 cache read, $50 output per million tokens), three settings per schedule: the 5-minute cache, the 1-hour cache, and the 5-minute cache kept warm by a `max_tokens: 0` request on the unchanged prefix every 4 minutes, timed from the previous request's start (the August 23 runs sent keep-alive requests with `max_tokens: 1`; in the August 26 cells reported here, every keep-alive request refreshed the cache and billed no output). Schedules: no pauses, 10% of turns, and every turn at 6 minutes on all 20 issues, and 45-minute pauses on the 5-issue subset; three runs per cell (six for the August 26 keep-alive cell with 45-minute pauses), cost computed from each response's `usage` fields at list prices, accuracy against the same gold labels (12 to 17 exact labels of 20). Per-session means on August 26 for the 5-minute, 1-hour, and keep-alive settings: no pauses $2.42, $3.09, $2.29; 10% paused $4.50, $2.96, $2.36; every turn $22.89, $3.01, $2.62; the August 23 cells agree within 6%. The 45-minute figures ($1.68, $0.59, and $0.71 per 5-issue session) are from a clean re-run on August 26 after a cache-billing incident spoiled that day's first cells; the August 23 runs gave $1.67, $0.58, and $0.70. The crossover between the 5-minute and 1-hour settings is 3.1% of turns, the same measure as reference 16.
74183920. **Terminal-Bench 3:** the public terminal-agent benchmark's 74 tasks, run on [Claude Managed Agents](https://platform.claude.com/docs/en/managed-agents/overview) with two custom tools, a shell and a file editor that the evaluation harness runs in each task's own container, in place of the platform's built-in tools, and otherwise at the platform's default settings for external accounts, two runs per model at `high` effort, August 27 to 28, 2026. These runs used Terminal-Bench version 3.0, and their scores are not comparable with the public Terminal-Bench leaderboard or with the Terminal-Bench 4.0 results in the Claude Opus 5.5 system card, which come from runs in Claude Code at `max` effort. Each task's time limits are 2.5 times the benchmark's own, which gives the agent between 75 minutes and 20 hours per task (5 hours for the median task), and each task gets three times the memory it specifies, from 6 GiB to 96 GiB, with extra memory for the 12 tasks that run helper services. The agent had no general internet access: its containers could reach an internal package mirror, a short list of download sites including GitHub and the Python Package Index, and a few sites specific to some tasks, and eight of the tasks had no network access at all. Scores are raw pass rates over the 148 attempts per model; single runs swing by 5 to 11 points. Costs are what a customer would be billed at list prices, re-priced request by request from the runs' usage records with the 5-minute cache lifetime. Claude Opus 4.7 ended 11 of its 148 attempts at its output cap.
84021. **DRACO:** Perplexity, "DRACO: a Cross-Domain Benchmark for Deep Research Accuracy, Completeness, and Objectivity," arXiv:2602.11685, 2026. Its 100 research tasks across 10 domains are graded against expert-written rubrics, and the score is the benchmark's normalized score. Every configuration ran on the Claude API with Claude Fable 5.1, the default adaptive thinking, the production safety classifiers on, and `max_tokens` at 128,000: a single agent at `high` and at `medium` effort, the single agent at `high` with the instruction and the clock, and a team at `high` with and without them. The team is a lead agent that starts helper agents of the same model through a tool, with no cap on their number. On DRACO, the lead started a median of 4 helpers per attempt. Each configuration made three attempts at each task, run September 8 to 10, 2026. An attempt that hit the four-hour limit was run again, and the new attempt counts. The only attempts left out are all 3 attempts at one task for the single agent at `medium` effort, so that configuration covers 99 tasks. That task timed out on every attempt, in the original run and in the re-run. Scoring those 3 attempts as 0, as the benchmark's own scoring would, affects only the two comparisons with `medium` effort. The score change at `medium` effort against `high` moves from 0.7 to 1.7 points lower, and the score change with both changes against `medium` effort moves from 1.2 to 0.2 points lower. The agents used a search tool and a fetch tool that the evaluation harness hosts over a pinned web index. Those tools set part of the time, and yours will run at a different speed, so the page gives time as a ratio between configurations, not in minutes. Time is the wall-clock time per task, from the first request to the last request on any agent, minus the estimated time spent waiting to retry requests after rate-limit or overload errors. Those errors came from the test account's shared limits. All configurations of a set started together. The slower ones finished hours later, so part of their time ran under different load. Each task's cost is its requests priced at public list prices, with prompt caching billed as it would be for a customer who sets a cache breakpoint at the end of each request and uses the 5-minute cache lifetime, for model tokens only. The harness's tools add no charges. Score changes are paired differences over tasks, with 95% bootstrap intervals. A change counts as inside the margin when its interval stays within 1.5 points on DRACO and 2.5 points on HLE. Anthropic set those margins before the runs. Claude Opus 5 grades the answers. Against each set's own grader, Opus 5 scored 1.9 to 2.4 points higher on DRACO, 2.2 to 2.9 points lower on HLE (Opus 5 graded 495 of the 500 questions, and the benchmark's grader graded all 500), and 1.3 to 2.0 points lower on the physics set, whose own grader also uses the expert reference solutions, in every configuration. The two graders agree on the direction of every change.
84122. **HLE:** Phan et al., "Humanity's Last Exam," arXiv:2501.14249, 2025. Expert-written questions with exact answers, graded against the reference answers. Measured on the first 500 questions, with the benchmark's own sources blocked from search, and the same setup as reference 21. Each configuration made three attempts at each question, run September 8 to 10, 2026. Claude Opus 5 compares each answer with the reference answer, with adaptive thinking on, as it is by default. The judge graded 495 of the 500 questions in every configuration, and the scores cover those 495. For the other 5, the grading request was over the judge's 1M-token limit. An attempt that hit the four-hour limit was run again, and the new attempt counts, so every configuration has all 1,500 attempts. Scoring the 5 ungraded questions as 0, as the benchmark's own scoring would, changes no finding.
84223. **Physics set:** An internal set of 70 research-level physics problems, adapted from the public CritPt benchmark: Zhu et al., "Probing the Critical Point (CritPt) of AI Reasoning: a Frontier Physics Research Benchmark," arXiv:2509.26574, 2025. Expert reviewers corrected the problem statements. Claude Opus 5 grades each answer against expert reference solutions that aren't public, so the scores can't be compared with published results. The score is the mean grade over a problem's attempts, averaged over problems. Measured on all 70 problems, four attempts per problem, run September 8 to 9, 2026. Every agent had a Python tool, a shell, and a file editor in a sandbox container with no network access, and no search or fetch tools. Otherwise the setup is that of reference 21. No score margin was set for the physics set before the runs, so the page gives its score changes with their 95% intervals and doesn't describe them as inside a margin.
742843 
743844## Next steps
744845 

agents-and-tools/tool-use/tool-runner Changed · +3 / -3 lines

from line 589
589589 
590590The tool runner is an iterable that yields messages from Claude. On each iteration, the runner checks whether Claude requested a tool use. If so, it runs the tool and sends the result back to Claude automatically, then yields the next message from Claude to continue your loop.
591591 
592You can end the loop at any iteration with a `break` statement. The runner loops until Claude returns a message without a tool use, or until it reaches `max_iterations` if you set it.
592You can end the loop at any iteration with a `break` statement. The runner loops until Claude returns a message without a tool use, or until it reaches `max_iterations` (csharp, java, php: `maxIterations`; go: `MaxIterations`) if you set it.
593593 
594594If you don't need intermediate messages, you can get the final message directly:
595595 
from line 821
821821 
822822You take over by modifying the runner's messages from inside the loop body. The exact method depends on the SDK. See the per-language tabs that follow.
823823 
824When you take over for an iteration, the runner does not append the assistant message or tool results from that turn. You become responsible for keeping the conversation valid: append the assistant message and a tool result yourself (if you want the turn to count), modify state conditionally so the loop can still exit when there are no tool calls, and pass `max_iterations` to bound the loop. All seven SDKs support `max_iterations`.
824When you take over for an iteration, the runner does not append the assistant message or tool results from that turn. You become responsible for keeping the conversation valid: append the assistant message and a tool result yourself (if you want the turn to count), modify state conditionally so the loop can still exit when there are no tool calls, and pass `max_iterations` (csharp, java, php: `maxIterations`; go: `MaxIterations`) to bound the loop. All seven SDKs support `max_iterations` (csharp, java, php: `maxIterations`; go: `MaxIterations`).
825825 
826826<Tabs>
827827 <Tab title="Python">
from line 1106
11061106 
11071107### Automatic context management
11081108 
1109For long-running agentic tasks, the TypeScript and Ruby tool runners support automatic [compaction](https://platform.claude.com/docs/en/build-with-claude/context-editing#client-side-compaction-sdk), which generates summaries when token usage exceeds a threshold so the conversation can continue beyond context window limits. Both SDKs have deprecated this client-side option in favor of [server-side compaction](https://platform.claude.com/docs/en/build-with-claude/compaction-threshold), which works with every SDK's tool runner through the `context_management` request parameter. The Python SDK (v1.0 and later) and the Go, Java, C#, and PHP tool runners don't include client-side compaction. The Python, TypeScript, C#, Go, Java, PHP, and Ruby tool runners have a `compact_before_next_turn()` helper for on-demand compaction, spelled in each language's own casing. See [Compact in a loop](https://platform.claude.com/docs/en/build-with-claude/compaction-on-demand#compact-in-a-loop). Use it or a `context_management` compaction edit on a runner, not both.
1109For long-running agentic tasks, the TypeScript and Ruby tool runners support automatic [compaction](https://platform.claude.com/docs/en/build-with-claude/context-editing#client-side-compaction-sdk), which generates summaries when token usage exceeds a threshold so the conversation can continue beyond context window limits. Both SDKs have deprecated this client-side option in favor of [server-side compaction](https://platform.claude.com/docs/en/build-with-claude/compaction-threshold), which works with every SDK's tool runner through the `context_management` request parameter. The Python SDK (v1.0 and later) and the Go, Java, C#, and PHP tool runners don't include client-side compaction. The Python, TypeScript, C#, Go, Java, PHP, and Ruby tool runners have a `compact_before_next_turn()` (typescript, java, php: `compactBeforeNextTurn()`; csharp, go: `CompactBeforeNextTurn()`) helper for on-demand compaction. See [Compact in a loop](https://platform.claude.com/docs/en/build-with-claude/compaction-on-demand#compact-in-a-loop). Use it or a `context_management` compaction edit on a runner, not both.
11101110 
11111111### Debugging tool execution
11121112 

api/beta Changed · +85 / -46 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

Nothing in the body moved in this read. What changed is above.

api/beta/dreams Changed · +15 / -5 lines

from line 235
235235 
236236 An asynchronous job that reads a memory store and past sessions, then writes a reorganized version of that memory store.
237237 
238 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead. The Dreams API is in research preview, so this resource can still change.
238 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead.
239239 
240 The Dreams API is in research preview: the request and response shapes are volatile and may change without the deprecation period that applies to generally-available endpoints.
241 
240242 See the [Dreams guide](https://platform.claude.com/docs/en/managed-agents/dreams#how-it-works) for what a dream reads and produces.
241243 
242244 - `type: "dream"`
from line 1122
11201122 
11211123 An asynchronous job that reads a memory store and past sessions, then writes a reorganized version of that memory store.
11221124 
1123 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead. The Dreams API is in research preview, so this resource can still change.
1125 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead.
11241126 
1127 The Dreams API is in research preview: the request and response shapes are volatile and may change without the deprecation period that applies to generally-available endpoints.
1128 
11251129 See the [Dreams guide](https://platform.claude.com/docs/en/managed-agents/dreams#how-it-works) for what a dream reads and produces.
11261130 
11271131 - `type: "dream"`
from line 1529
15251529 
15261530 An asynchronous job that reads a memory store and past sessions, then writes a reorganized version of that memory store.
15271531 
1528 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead. The Dreams API is in research preview, so this resource can still change.
1532 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead.
15291533 
1534 The Dreams API is in research preview: the request and response shapes are volatile and may change without the deprecation period that applies to generally-available endpoints.
1535 
15301536 See the [Dreams guide](https://platform.claude.com/docs/en/managed-agents/dreams#how-it-works) for what a dream reads and produces.
15311537 
15321538 - `type: "dream"`
from line 1937
19311937 
19321938 An asynchronous job that reads a memory store and past sessions, then writes a reorganized version of that memory store.
19331939 
1934 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead. The Dreams API is in research preview, so this resource can still change.
1940 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead.
19351941 
1942 The Dreams API is in research preview: the request and response shapes are volatile and may change without the deprecation period that applies to generally-available endpoints.
1943 
19361944 See the [Dreams guide](https://platform.claude.com/docs/en/managed-agents/dreams#how-it-works) for what a dream reads and produces.
19371945 
19381946 - `type: "dream"`
from line 2219
22112219 
22122220 An asynchronous job that reads a memory store and past sessions, then writes a reorganized version of that memory store.
22132221 
2214 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead. The Dreams API is in research preview, so this resource can still change.
2222 By default the dream writes its result to a new memory store and doesn't change the input memory store. With `output_behavior` set to `update_existing`, it writes its result into the input memory store instead.
2223 
2224 The Dreams API is in research preview: the request and response shapes are volatile and may change without the deprecation period that applies to generally-available endpoints.
22152225 
22162226 See the [Dreams guide](https://platform.claude.com/docs/en/managed-agents/dreams#how-it-works) for what a dream reads and produces.
22172227 

api/beta/memory_stores Changed · +30 / -30 lines

from line 2615
26152615 
26162616 - `created_by: optional BetaManagedAgentsActor`
26172617 
2618 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
2618 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
26192619 
26202620 - `BetaManagedAgentsSessionActor object`
26212621 
2622 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
2622 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
26232623 
26242624 - `type: "session_actor"`
26252625 
26262626 - `session_id: string`
26272627 
2628 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
2628 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
26292629 
26302630 minLength: 1
26312631 
26322632 - `BetaManagedAgentsAPIActor object`
26332633 
2634 Attribution for a write made directly via the public API (outside of any session).
2634 A direct caller of the public API, identified by the API key that authenticated the request.
26352635 
26362636 - `type: "api_actor"`
26372637 
26382638 - `api_key_id: string`
26392639 
2640 ID of the API key that performed the write. This identifies the key, not the secret.
2640 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
26412641 
26422642 minLength: 1
26432643 
26442644 - `BetaManagedAgentsUserActor object`
26452645 
2646 Attribution for a write made by a human user through the Anthropic Console.
2646 A human user, for example acting through the Anthropic Console.
26472647 
26482648 - `type: "user_actor"`
26492649 
26502650 - `user_id: string`
26512651 
2652 ID of the user who performed the write (a `user_...` value).
2652 ID of the user (a `user_...` value).
26532653 
26542654 minLength: 1
26552655 
26562656 - `BetaManagedAgentsServiceAccountActor object`
26572657 
2658 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
2658 A workload authenticated as a service account, for example via Workload Identity Federation.
26592659 
26602660 - `type: "service_account_actor"`
26612661 
26622662 - `service_account_id: string`
26632663 
2664 ID of the service account that performed the write (a `svac_...` value).
2664 ID of the service account (a `svac_...` value).
26652665 
26662666 minLength: 1
26672667 
from line 2677
26772677 
26782678 - `redacted_by: optional BetaManagedAgentsActor`
26792679 
2680 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
2680 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
26812681 
26822682- `next_page: optional string or null`
26832683 
from line 2923
29232923 
29242924 - `created_by: optional BetaManagedAgentsActor`
29252925 
2926 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
2926 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
29272927 
29282928 - `BetaManagedAgentsSessionActor object`
29292929 
2930 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
2930 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
29312931 
29322932 - `type: "session_actor"`
29332933 
29342934 - `session_id: string`
29352935 
2936 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
2936 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
29372937 
29382938 minLength: 1
29392939 
29402940 - `BetaManagedAgentsAPIActor object`
29412941 
2942 Attribution for a write made directly via the public API (outside of any session).
2942 A direct caller of the public API, identified by the API key that authenticated the request.
29432943 
29442944 - `type: "api_actor"`
29452945 
29462946 - `api_key_id: string`
29472947 
2948 ID of the API key that performed the write. This identifies the key, not the secret.
2948 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
29492949 
29502950 minLength: 1
29512951 
29522952 - `BetaManagedAgentsUserActor object`
29532953 
2954 Attribution for a write made by a human user through the Anthropic Console.
2954 A human user, for example acting through the Anthropic Console.
29552955 
29562956 - `type: "user_actor"`
29572957 
29582958 - `user_id: string`
29592959 
2960 ID of the user who performed the write (a `user_...` value).
2960 ID of the user (a `user_...` value).
29612961 
29622962 minLength: 1
29632963 
29642964 - `BetaManagedAgentsServiceAccountActor object`
29652965 
2966 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
2966 A workload authenticated as a service account, for example via Workload Identity Federation.
29672967 
29682968 - `type: "service_account_actor"`
29692969 
29702970 - `service_account_id: string`
29712971 
2972 ID of the service account that performed the write (a `svac_...` value).
2972 ID of the service account (a `svac_...` value).
29732973 
29742974 minLength: 1
29752975 
from line 2985
29852985 
29862986 - `redacted_by: optional BetaManagedAgentsActor`
29872987 
2988 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
2988 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
29892989 
29902990#### Example
29912991 
from line 3208
32083208 
32093209 - `created_by: optional BetaManagedAgentsActor`
32103210 
3211 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
3211 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
32123212 
32133213 - `BetaManagedAgentsSessionActor object`
32143214 
3215 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
3215 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
32163216 
32173217 - `type: "session_actor"`
32183218 
32193219 - `session_id: string`
32203220 
3221 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
3221 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
32223222 
32233223 minLength: 1
32243224 
32253225 - `BetaManagedAgentsAPIActor object`
32263226 
3227 Attribution for a write made directly via the public API (outside of any session).
3227 A direct caller of the public API, identified by the API key that authenticated the request.
32283228 
32293229 - `type: "api_actor"`
32303230 
32313231 - `api_key_id: string`
32323232 
3233 ID of the API key that performed the write. This identifies the key, not the secret.
3233 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
32343234 
32353235 minLength: 1
32363236 
32373237 - `BetaManagedAgentsUserActor object`
32383238 
3239 Attribution for a write made by a human user through the Anthropic Console.
3239 A human user, for example acting through the Anthropic Console.
32403240 
32413241 - `type: "user_actor"`
32423242 
32433243 - `user_id: string`
32443244 
3245 ID of the user who performed the write (a `user_...` value).
3245 ID of the user (a `user_...` value).
32463246 
32473247 minLength: 1
32483248 
32493249 - `BetaManagedAgentsServiceAccountActor object`
32503250 
3251 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
3251 A workload authenticated as a service account, for example via Workload Identity Federation.
32523252 
32533253 - `type: "service_account_actor"`
32543254 
32553255 - `service_account_id: string`
32563256 
3257 ID of the service account that performed the write (a `svac_...` value).
3257 ID of the service account (a `svac_...` value).
32583258 
32593259 minLength: 1
32603260 
from line 3270
32703270 
32713271 - `redacted_by: optional BetaManagedAgentsActor`
32723272 
3273 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
3273 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
32743274 
32753275#### Example
32763276 

api/beta/memory_stores/memory_versions Changed · +57 / -57 lines

from line 257
257257 
258258 - `created_by: optional BetaManagedAgentsActor`
259259 
260 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
260 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
261261 
262262 - `BetaManagedAgentsSessionActor object`
263263 
264 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
264 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
265265 
266266 - `type: "session_actor"`
267267 
268268 - `session_id: string`
269269 
270 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
270 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
271271 
272272 minLength: 1
273273 
274274 - `BetaManagedAgentsAPIActor object`
275275 
276 Attribution for a write made directly via the public API (outside of any session).
276 A direct caller of the public API, identified by the API key that authenticated the request.
277277 
278278 - `type: "api_actor"`
279279 
280280 - `api_key_id: string`
281281 
282 ID of the API key that performed the write. This identifies the key, not the secret.
282 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
283283 
284284 minLength: 1
285285 
286286 - `BetaManagedAgentsUserActor object`
287287 
288 Attribution for a write made by a human user through the Anthropic Console.
288 A human user, for example acting through the Anthropic Console.
289289 
290290 - `type: "user_actor"`
291291 
292292 - `user_id: string`
293293 
294 ID of the user who performed the write (a `user_...` value).
294 ID of the user (a `user_...` value).
295295 
296296 minLength: 1
297297 
298298 - `BetaManagedAgentsServiceAccountActor object`
299299 
300 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
300 A workload authenticated as a service account, for example via Workload Identity Federation.
301301 
302302 - `type: "service_account_actor"`
303303 
304304 - `service_account_id: string`
305305 
306 ID of the service account that performed the write (a `svac_...` value).
306 ID of the service account (a `svac_...` value).
307307 
308308 minLength: 1
309309 
from line 319
319319 
320320 - `redacted_by: optional BetaManagedAgentsActor`
321321 
322 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
322 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
323323 
324324- `next_page: optional string or null`
325325 
from line 565
565565 
566566 - `created_by: optional BetaManagedAgentsActor`
567567 
568 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
568 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
569569 
570570 - `BetaManagedAgentsSessionActor object`
571571 
572 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
572 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
573573 
574574 - `type: "session_actor"`
575575 
576576 - `session_id: string`
577577 
578 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
578 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
579579 
580580 minLength: 1
581581 
582582 - `BetaManagedAgentsAPIActor object`
583583 
584 Attribution for a write made directly via the public API (outside of any session).
584 A direct caller of the public API, identified by the API key that authenticated the request.
585585 
586586 - `type: "api_actor"`
587587 
588588 - `api_key_id: string`
589589 
590 ID of the API key that performed the write. This identifies the key, not the secret.
590 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
591591 
592592 minLength: 1
593593 
594594 - `BetaManagedAgentsUserActor object`
595595 
596 Attribution for a write made by a human user through the Anthropic Console.
596 A human user, for example acting through the Anthropic Console.
597597 
598598 - `type: "user_actor"`
599599 
600600 - `user_id: string`
601601 
602 ID of the user who performed the write (a `user_...` value).
602 ID of the user (a `user_...` value).
603603 
604604 minLength: 1
605605 
606606 - `BetaManagedAgentsServiceAccountActor object`
607607 
608 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
608 A workload authenticated as a service account, for example via Workload Identity Federation.
609609 
610610 - `type: "service_account_actor"`
611611 
612612 - `service_account_id: string`
613613 
614 ID of the service account that performed the write (a `svac_...` value).
614 ID of the service account (a `svac_...` value).
615615 
616616 minLength: 1
617617 
from line 627
627627 
628628 - `redacted_by: optional BetaManagedAgentsActor`
629629 
630 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
630 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
631631 
632632### Example
633633 
from line 850
850850 
851851 - `created_by: optional BetaManagedAgentsActor`
852852 
853 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
853 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
854854 
855855 - `BetaManagedAgentsSessionActor object`
856856 
857 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
857 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
858858 
859859 - `type: "session_actor"`
860860 
861861 - `session_id: string`
862862 
863 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
863 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
864864 
865865 minLength: 1
866866 
867867 - `BetaManagedAgentsAPIActor object`
868868 
869 Attribution for a write made directly via the public API (outside of any session).
869 A direct caller of the public API, identified by the API key that authenticated the request.
870870 
871871 - `type: "api_actor"`
872872 
873873 - `api_key_id: string`
874874 
875 ID of the API key that performed the write. This identifies the key, not the secret.
875 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
876876 
877877 minLength: 1
878878 
879879 - `BetaManagedAgentsUserActor object`
880880 
881 Attribution for a write made by a human user through the Anthropic Console.
881 A human user, for example acting through the Anthropic Console.
882882 
883883 - `type: "user_actor"`
884884 
885885 - `user_id: string`
886886 
887 ID of the user who performed the write (a `user_...` value).
887 ID of the user (a `user_...` value).
888888 
889889 minLength: 1
890890 
891891 - `BetaManagedAgentsServiceAccountActor object`
892892 
893 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
893 A workload authenticated as a service account, for example via Workload Identity Federation.
894894 
895895 - `type: "service_account_actor"`
896896 
897897 - `service_account_id: string`
898898 
899 ID of the service account that performed the write (a `svac_...` value).
899 ID of the service account (a `svac_...` value).
900900 
901901 minLength: 1
902902 
from line 912
912912 
913913 - `redacted_by: optional BetaManagedAgentsActor`
914914 
915 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
915 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
916916 
917917### Example
918918 
from line 956
956956 
957957- `BetaManagedAgentsActor = BetaManagedAgentsSessionActor or BetaManagedAgentsAPIActor or BetaManagedAgentsUserActor or BetaManagedAgentsServiceAccountActor`
958958 
959 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
959 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
960960 
961961 - `BetaManagedAgentsSessionActor object`
962962 
963 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
963 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
964964 
965965 - `type: "session_actor"`
966966 
967967 - `session_id: string`
968968 
969 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
969 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
970970 
971971 minLength: 1
972972 
973973 - `BetaManagedAgentsAPIActor object`
974974 
975 Attribution for a write made directly via the public API (outside of any session).
975 A direct caller of the public API, identified by the API key that authenticated the request.
976976 
977977 - `type: "api_actor"`
978978 
979979 - `api_key_id: string`
980980 
981 ID of the API key that performed the write. This identifies the key, not the secret.
981 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
982982 
983983 minLength: 1
984984 
985985 - `BetaManagedAgentsUserActor object`
986986 
987 Attribution for a write made by a human user through the Anthropic Console.
987 A human user, for example acting through the Anthropic Console.
988988 
989989 - `type: "user_actor"`
990990 
991991 - `user_id: string`
992992 
993 ID of the user who performed the write (a `user_...` value).
993 ID of the user (a `user_...` value).
994994 
995995 minLength: 1
996996 
997997 - `BetaManagedAgentsServiceAccountActor object`
998998 
999 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
999 A workload authenticated as a service account, for example via Workload Identity Federation.
10001000 
10011001 - `type: "service_account_actor"`
10021002 
10031003 - `service_account_id: string`
10041004 
1005 ID of the service account that performed the write (a `svac_...` value).
1005 ID of the service account (a `svac_...` value).
10061006 
10071007 minLength: 1
10081008 
from line 1010
10101010 
10111011- `BetaManagedAgentsAPIActor object`
10121012 
1013 Attribution for a write made directly via the public API (outside of any session).
1013 A direct caller of the public API, identified by the API key that authenticated the request.
10141014 
10151015 - `type: "api_actor"`
10161016 
10171017 - `api_key_id: string`
10181018 
1019 ID of the API key that performed the write. This identifies the key, not the secret.
1019 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
10201020 
10211021 minLength: 1
10221022 
from line 1078
10781078 
10791079 - `created_by: optional BetaManagedAgentsActor`
10801080 
1081 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
1081 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
10821082 
10831083 - `BetaManagedAgentsSessionActor object`
10841084 
1085 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
1085 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
10861086 
10871087 - `type: "session_actor"`
10881088 
10891089 - `session_id: string`
10901090 
1091 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
1091 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
10921092 
10931093 minLength: 1
10941094 
10951095 - `BetaManagedAgentsAPIActor object`
10961096 
1097 Attribution for a write made directly via the public API (outside of any session).
1097 A direct caller of the public API, identified by the API key that authenticated the request.
10981098 
10991099 - `type: "api_actor"`
11001100 
11011101 - `api_key_id: string`
11021102 
1103 ID of the API key that performed the write. This identifies the key, not the secret.
1103 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
11041104 
11051105 minLength: 1
11061106 
11071107 - `BetaManagedAgentsUserActor object`
11081108 
1109 Attribution for a write made by a human user through the Anthropic Console.
1109 A human user, for example acting through the Anthropic Console.
11101110 
11111111 - `type: "user_actor"`
11121112 
11131113 - `user_id: string`
11141114 
1115 ID of the user who performed the write (a `user_...` value).
1115 ID of the user (a `user_...` value).
11161116 
11171117 minLength: 1
11181118 
11191119 - `BetaManagedAgentsServiceAccountActor object`
11201120 
1121 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
1121 A workload authenticated as a service account, for example via Workload Identity Federation.
11221122 
11231123 - `type: "service_account_actor"`
11241124 
11251125 - `service_account_id: string`
11261126 
1127 ID of the service account that performed the write (a `svac_...` value).
1127 ID of the service account (a `svac_...` value).
11281128 
11291129 minLength: 1
11301130 
from line 1140
11401140 
11411141 - `redacted_by: optional BetaManagedAgentsActor`
11421142 
1143 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
1143 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
11441144 
11451145### Beta Managed Agents Memory Version Operation
11461146 
from line 1164
11641164 
11651165- `BetaManagedAgentsServiceAccountActor object`
11661166 
1167 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
1167 A workload authenticated as a service account, for example via Workload Identity Federation.
11681168 
11691169 - `type: "service_account_actor"`
11701170 
11711171 - `service_account_id: string`
11721172 
1173 ID of the service account that performed the write (a `svac_...` value).
1173 ID of the service account (a `svac_...` value).
11741174 
11751175 minLength: 1
11761176 
from line 1178
11781178 
11791179- `BetaManagedAgentsSessionActor object`
11801180 
1181 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
1181 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
11821182 
11831183 - `type: "session_actor"`
11841184 
11851185 - `session_id: string`
11861186 
1187 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
1187 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
11881188 
11891189 minLength: 1
11901190 
from line 1192
11921192 
11931193- `BetaManagedAgentsUserActor object`
11941194 
1195 Attribution for a write made by a human user through the Anthropic Console.
1195 A human user, for example acting through the Anthropic Console.
11961196 
11971197 - `type: "user_actor"`
11981198 
11991199 - `user_id: string`
12001200 
1201 ID of the user who performed the write (a `user_...` value).
1201 ID of the user (a `user_...` value).
12021202 
12031203 minLength: 1
12041204 

api/beta/memory_stores/memory_versions/list Changed · +10 / -10 lines

from line 255
255255 
256256 - `created_by: optional BetaManagedAgentsActor`
257257 
258 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
258 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
259259 
260260 - `BetaManagedAgentsSessionActor object`
261261 
262 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
262 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
263263 
264264 - `type: "session_actor"`
265265 
266266 - `session_id: string`
267267 
268 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
268 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
269269 
270270 minLength: 1
271271 
272272 - `BetaManagedAgentsAPIActor object`
273273 
274 Attribution for a write made directly via the public API (outside of any session).
274 A direct caller of the public API, identified by the API key that authenticated the request.
275275 
276276 - `type: "api_actor"`
277277 
278278 - `api_key_id: string`
279279 
280 ID of the API key that performed the write. This identifies the key, not the secret.
280 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
281281 
282282 minLength: 1
283283 
284284 - `BetaManagedAgentsUserActor object`
285285 
286 Attribution for a write made by a human user through the Anthropic Console.
286 A human user, for example acting through the Anthropic Console.
287287 
288288 - `type: "user_actor"`
289289 
290290 - `user_id: string`
291291 
292 ID of the user who performed the write (a `user_...` value).
292 ID of the user (a `user_...` value).
293293 
294294 minLength: 1
295295 
296296 - `BetaManagedAgentsServiceAccountActor object`
297297 
298 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
298 A workload authenticated as a service account, for example via Workload Identity Federation.
299299 
300300 - `type: "service_account_actor"`
301301 
302302 - `service_account_id: string`
303303 
304 ID of the service account that performed the write (a `svac_...` value).
304 ID of the service account (a `svac_...` value).
305305 
306306 minLength: 1
307307 
from line 317
317317 
318318 - `redacted_by: optional BetaManagedAgentsActor`
319319 
320 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
320 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
321321 
322322- `next_page: optional string or null`
323323 

api/beta/memory_stores/memory_versions/redact Changed · +10 / -10 lines

from line 189
189189 
190190 - `created_by: optional BetaManagedAgentsActor`
191191 
192 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
192 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
193193 
194194 - `BetaManagedAgentsSessionActor object`
195195 
196 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
196 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
197197 
198198 - `type: "session_actor"`
199199 
200200 - `session_id: string`
201201 
202 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
202 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
203203 
204204 minLength: 1
205205 
206206 - `BetaManagedAgentsAPIActor object`
207207 
208 Attribution for a write made directly via the public API (outside of any session).
208 A direct caller of the public API, identified by the API key that authenticated the request.
209209 
210210 - `type: "api_actor"`
211211 
212212 - `api_key_id: string`
213213 
214 ID of the API key that performed the write. This identifies the key, not the secret.
214 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
215215 
216216 minLength: 1
217217 
218218 - `BetaManagedAgentsUserActor object`
219219 
220 Attribution for a write made by a human user through the Anthropic Console.
220 A human user, for example acting through the Anthropic Console.
221221 
222222 - `type: "user_actor"`
223223 
224224 - `user_id: string`
225225 
226 ID of the user who performed the write (a `user_...` value).
226 ID of the user (a `user_...` value).
227227 
228228 minLength: 1
229229 
230230 - `BetaManagedAgentsServiceAccountActor object`
231231 
232 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
232 A workload authenticated as a service account, for example via Workload Identity Federation.
233233 
234234 - `type: "service_account_actor"`
235235 
236236 - `service_account_id: string`
237237 
238 ID of the service account that performed the write (a `svac_...` value).
238 ID of the service account (a `svac_...` value).
239239 
240240 minLength: 1
241241 
from line 251
251251 
252252 - `redacted_by: optional BetaManagedAgentsActor`
253253 
254 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
254 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
255255 
256256## Example
257257 

api/beta/memory_stores/memory_versions/retrieve Changed · +10 / -10 lines

from line 203
203203 
204204 - `created_by: optional BetaManagedAgentsActor`
205205 
206 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
206 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
207207 
208208 - `BetaManagedAgentsSessionActor object`
209209 
210 Attribution for a write made by an agent during a session, through the mounted filesystem at `/mnt/memory/`.
210 An agent acting during a session, for example through the session's mounted filesystem. It names the session itself, not the user or API key that started the session.
211211 
212212 - `type: "session_actor"`
213213 
214214 - `session_id: string`
215215 
216 ID of the session that performed the write (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
216 ID of the session (a `sesn_...` value). Look up the session via [Retrieve a session](/docs/en/api/beta/sessions/retrieve) for further provenance.
217217 
218218 minLength: 1
219219 
220220 - `BetaManagedAgentsAPIActor object`
221221 
222 Attribution for a write made directly via the public API (outside of any session).
222 A direct caller of the public API, identified by the API key that authenticated the request.
223223 
224224 - `type: "api_actor"`
225225 
226226 - `api_key_id: string`
227227 
228 ID of the API key that performed the write. This identifies the key, not the secret.
228 ID of the API key (an `apikey_...` value). This identifies the key, not the secret.
229229 
230230 minLength: 1
231231 
232232 - `BetaManagedAgentsUserActor object`
233233 
234 Attribution for a write made by a human user through the Anthropic Console.
234 A human user, for example acting through the Anthropic Console.
235235 
236236 - `type: "user_actor"`
237237 
238238 - `user_id: string`
239239 
240 ID of the user who performed the write (a `user_...` value).
240 ID of the user (a `user_...` value).
241241 
242242 minLength: 1
243243 
244244 - `BetaManagedAgentsServiceAccountActor object`
245245 
246 Attribution for a write made by a workload authenticated as a service account, for example via Workload Identity Federation.
246 A workload authenticated as a service account, for example via Workload Identity Federation.
247247 
248248 - `type: "service_account_actor"`
249249 
250250 - `service_account_id: string`
251251 
252 ID of the service account that performed the write (a `svac_...` value).
252 ID of the service account (a `svac_...` value).
253253 
254254 minLength: 1
255255 
from line 265
265265 
266266 - `redacted_by: optional BetaManagedAgentsActor`
267267 
268 Identifies who performed a write or redact operation. Captured at write time on the `memory_version` row. The API key that created a session is not recorded on agent writes; attribution answers who made the write, not who is ultimately responsible. Look up session provenance separately via the [Sessions API](/docs/en/api/beta/sessions/retrieve).
268 Identifies who performed an operation. Recorded when the operation happens and not updated afterwards, so the ID may refer to a user, service account, API key, or session that has since been deleted.
269269 
270270## Example
271271 

api/beta/messages Changed · +64 / -8 lines

### Beta Cache Miss Reason

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

Nothing in the body moved in this read. What changed is above.

api/beta/messages/batches Changed · +4 / -4 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

Nothing in the body moved in this read. What changed is above.

api/beta/organization Changed · +41 / -10 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

from line 9042
90429042 
90439043**GET** `/v1/organizations/workspaces/{workspace_id}/rate_limits`
90449044 
9045List rate-limit overrides configured for a workspace.
9045List a workspace's rate limits.
90469046 
9047Returns only the groups and limiter types that have a workspace-level
9048override. Groups without overrides inherit the organization limits and
9049are not listed; use `GET /v1/organizations/rate_limits` to see those.
9047By default, returns only the groups and limiter types that have a
9048workspace-level override. With `include_inherited=true`, returns every
9049group with organization-level limits the workspace can see, listing for
9050each the values it inherits from the organization as well as its own
9051overrides. Each value's `source` says which it is.
90509052 
90519053When `limit` is omitted, every matching entry is returned in a single
90529054page; when `limit` truncates the result, follow `next_page` to fetch
from line 9078
90769078 
90779079 - `"web_search"`
90789080 
9081- `include_inherited: optional boolean`
9082 
9083 Also list the limiter values the workspace inherits from the organization, including groups with no workspace-level override.
9084 
9085 default: false
9086 
90799087- `limit: optional number`
90809088 
90819089 Maximum number of items to return per page. Ranges from `1` to `1000`.
from line 9100
90929100 
90939101- `data: array of BetaWorkspaceRateLimit`
90949102 
9095 Rate-limit entries for the workspace, one per group that has at least one override.
9103 Rate-limit entries for the workspace: one per group with at least one override, or, with `include_inherited` set to `true`, one per group the workspace can see that has organization-level limits.
90969104 
90979105 - `type: "workspace_rate_limit"`
90989106 
from line 9190
91829190 
91839191 - `limits: array of BetaWorkspaceRateLimitValue`
91849192 
9185 The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
9193 The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With `include_inherited` set to `true`, the limiter types the workspace inherits from the organization are listed too, each marked by `source`.
91869194 
91879195 - `type: string`
91889196 
from line 9200
91929200 
91939201 The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
91949202 
9203 - `source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource`
9204 
9205 Where `value` comes from. `organization` values are listed only when `include_inherited` is `true`, and then `value` equals `org_limit`.
9206 
9207 - `BetaWorkspaceRateLimitWorkspaceSource object`
9208 
9209 - `type: "workspace"`
9210 
9211 Always `workspace`: a workspace-level override is stored.
9212 
9213 default: workspace
9214 
9215 - `BetaWorkspaceRateLimitOrganizationSource object`
9216 
9217 - `type: "organization"`
9218 
9219 Always `organization`: no workspace-level override is stored, so the organization's value applies.
9220 
9221 default: organization
9222 
91959223 - `value: number`
91969224 
9197 The workspace-level override value for this limiter type.
9225 The workspace's value for this limiter type: the workspace-level override when `source.type` is `workspace`, otherwise the organization's value.
91989226 
91999227 - `models: array of string or null`
92009228 
from line 9230
92029230 
92039231 - `rate_limit_id: string`
92049232 
9205 The `id` of the organization's RateLimit entry this override applies to.
9233 The `id` of the organization's RateLimit entry this entry applies to.
92069234 
92079235 - `workspace_id: string`
92089236 
9209 ID of the Workspace this override applies to.
9237 ID of the Workspace this entry applies to.
92109238 
92119239 - `group_type: "batch" or "files" or "model_group" or 3 more`
92129240 
from line 9281
92539281 "limits": [
92549282 {
92559283 "org_limit": 0,
9284 "source": {
9285 "type": "workspace"
9286 },
92569287 "type": "type",
92579288 "value": 0
92589289 }
from line 10530
1049910530Remove a service account from a workspace.
1050010531 
1050110532Removal is idempotent (returns 200 even if the membership was already
10502removed). A DELETE against the implicit default-workspace membership
10503returns 200 but is a no-op and the membership persists; deleting an
10504explicit default-workspace row reverts to the implicit `workspace_user`
10505membership. Archived workspaces return 400.
10506 
10507#### Path parameters
10508 
10509- `workspace_id: string`
10510 
10511 ID of the workspace.
10512 
10513- `service_account_id: string`
10514 
10515 ID of the service account.
10516 
10517#### Headers
10518 
10519- `"anthropic-beta": optional array of AnthropicBeta`
10520 
10521 Optional header to specify the beta version(s) you want to use.
10522 
10523 - `string`
10524 
10525 - `"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more`
10526 
10527 - `"message-batches-2024-09-24"`
10528 
10529 - `"prompt-caching-2024-07-31"`
10530 
10531 - `"computer-use-2024-10-22"`
10532 
10533 - `"computer-use-2025-01-24"`
10534 
10535 - `"pdfs-2024-09-25"`
10536 
10537 - `"token-counting-2024-11-01"`
10538 
10539 - `"token-efficient-tools-2025-02-19"`
10540 
10541 - `"output-128k-2025-02-19"`
10542 
10543 - `"files-api-2025-04-14"`
10544 
10545 - `"mcp-client-2025-04-04"`
10546 
10547 - `"mcp-client-2025-11-20"`
10548 
10549 - `"dev-full-thinking-2025-05-14"`
10550 
10551 - `"interleaved-thinking-2025-05-14"`
10552 
10553 - `"code-execution-2025-05-22"`
10554 
10555 - `"extended-cache-ttl-2025-04-11"`
10556 
10557 - `"context-1m-2025-08-07"`
10558 
10559 - `"context-management-2025-06-27"`
10560 
10561 - `"model-context-window-exceeded-2025-08-26"`
10562 
10563 - `"skills-2025-10-02"`
10564 
10565 - `
10533removed). A DELETE against the

api/beta/organization/workspaces Changed · +41 / -10 lines

from line 1226
12261226 
12271227**GET** `/v1/organizations/workspaces/{workspace_id}/rate_limits`
12281228 
1229List rate-limit overrides configured for a workspace.
1229List a workspace's rate limits.
12301230 
1231Returns only the groups and limiter types that have a workspace-level
1232override. Groups without overrides inherit the organization limits and
1233are not listed; use `GET /v1/organizations/rate_limits` to see those.
1231By default, returns only the groups and limiter types that have a
1232workspace-level override. With `include_inherited=true`, returns every
1233group with organization-level limits the workspace can see, listing for
1234each the values it inherits from the organization as well as its own
1235overrides. Each value's `source` says which it is.
12341236 
12351237When `limit` is omitted, every matching entry is returned in a single
12361238page; when `limit` truncates the result, follow `next_page` to fetch
from line 1262
12601262 
12611263 - `"web_search"`
12621264 
1265- `include_inherited: optional boolean`
1266 
1267 Also list the limiter values the workspace inherits from the organization, including groups with no workspace-level override.
1268 
1269 default: false
1270 
12631271- `limit: optional number`
12641272 
12651273 Maximum number of items to return per page. Ranges from `1` to `1000`.
from line 1284
12761284 
12771285- `data: array of BetaWorkspaceRateLimit`
12781286 
1279 Rate-limit entries for the workspace, one per group that has at least one override.
1287 Rate-limit entries for the workspace: one per group with at least one override, or, with `include_inherited` set to `true`, one per group the workspace can see that has organization-level limits.
12801288 
12811289 - `type: "workspace_rate_limit"`
12821290 
from line 1374
13661374 
13671375 - `limits: array of BetaWorkspaceRateLimitValue`
13681376 
1369 The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
1377 The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With `include_inherited` set to `true`, the limiter types the workspace inherits from the organization are listed too, each marked by `source`.
13701378 
13711379 - `type: string`
13721380 
from line 1384
13761384 
13771385 The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
13781386 
1387 - `source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource`
1388 
1389 Where `value` comes from. `organization` values are listed only when `include_inherited` is `true`, and then `value` equals `org_limit`.
1390 
1391 - `BetaWorkspaceRateLimitWorkspaceSource object`
1392 
1393 - `type: "workspace"`
1394 
1395 Always `workspace`: a workspace-level override is stored.
1396 
1397 default: workspace
1398 
1399 - `BetaWorkspaceRateLimitOrganizationSource object`
1400 
1401 - `type: "organization"`
1402 
1403 Always `organization`: no workspace-level override is stored, so the organization's value applies.
1404 
1405 default: organization
1406 
13791407 - `value: number`
13801408 
1381 The workspace-level override value for this limiter type.
1409 The workspace's value for this limiter type: the workspace-level override when `source.type` is `workspace`, otherwise the organization's value.
13821410 
13831411 - `models: array of string or null`
13841412 
from line 1414
13861414 
13871415 - `rate_limit_id: string`
13881416 
1389 The `id` of the organization's RateLimit entry this override applies to.
1417 The `id` of the organization's RateLimit entry this entry applies to.
13901418 
13911419 - `workspace_id: string`
13921420 
1393 ID of the Workspace this override applies to.
1421 ID of the Workspace this entry applies to.
13941422 
13951423 - `group_type: "batch" or "files" or "model_group" or 3 more`
13961424 
from line 1465
14371465 "limits": [
14381466 {
14391467 "org_limit": 0,
1468 "source": {
1469 "type": "workspace"
1470 },
14401471 "type": "type",
14411472 "value": 0
14421473 }

api/beta/organization/workspaces/rate_limits Changed · +106 / -15 lines

### Beta Workspace Rate Limit Organization Source ### Beta Workspace Rate Limit Workspace Source

from line 9
99 
1010**GET** `/v1/organizations/workspaces/{workspace_id}/rate_limits`
1111 
12List rate-limit overrides configured for a workspace.
12List a workspace's rate limits.
1313 
14Returns only the groups and limiter types that have a workspace-level
15override. Groups without overrides inherit the organization limits and
16are not listed; use `GET /v1/organizations/rate_limits` to see those.
14By default, returns only the groups and limiter types that have a
15workspace-level override. With `include_inherited=true`, returns every
16group with organization-level limits the workspace can see, listing for
17each the values it inherits from the organization as well as its own
18overrides. Each value's `source` says which it is.
1719 
1820When `limit` is omitted, every matching entry is returned in a single
1921page; when `limit` truncates the result, follow `next_page` to fetch
from line 45
4345 
4446 - `"web_search"`
4547 
48- `include_inherited: optional boolean`
49 
50 Also list the limiter values the workspace inherits from the organization, including groups with no workspace-level override.
51 
52 default: false
53 
4654- `limit: optional number`
4755 
4856 Maximum number of items to return per page. Ranges from `1` to `1000`.
from line 67
5967 
6068- `data: array of BetaWorkspaceRateLimit`
6169 
62 Rate-limit entries for the workspace, one per group that has at least one override.
70 Rate-limit entries for the workspace: one per group with at least one override, or, with `include_inherited` set to `true`, one per group the workspace can see that has organization-level limits.
6371 
6472 - `type: "workspace_rate_limit"`
6573 
from line 157
149157 
150158 - `limits: array of BetaWorkspaceRateLimitValue`
151159 
152 The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
160 The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With `include_inherited` set to `true`, the limiter types the workspace inherits from the organization are listed too, each marked by `source`.
153161 
154162 - `type: string`
155163 
from line 167
159167 
160168 The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
161169 
170 - `source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource`
171 
172 Where `value` comes from. `organization` values are listed only when `include_inherited` is `true`, and then `value` equals `org_limit`.
173 
174 - `BetaWorkspaceRateLimitWorkspaceSource object`
175 
176 - `type: "workspace"`
177 
178 Always `workspace`: a workspace-level override is stored.
179 
180 default: workspace
181 
182 - `BetaWorkspaceRateLimitOrganizationSource object`
183 
184 - `type: "organization"`
185 
186 Always `organization`: no workspace-level override is stored, so the organization's value applies.
187 
188 default: organization
189 
162190 - `value: number`
163191 
164 The workspace-level override value for this limiter type.
192 The workspace's value for this limiter type: the workspace-level override when `source.type` is `workspace`, otherwise the organization's value.
165193 
166194 - `models: array of string or null`
167195 
from line 197
169197 
170198 - `rate_limit_id: string`
171199 
172 The `id` of the organization's RateLimit entry this override applies to.
200 The `id` of the organization's RateLimit entry this entry applies to.
173201 
174202 - `workspace_id: string`
175203 
176 ID of the Workspace this override applies to.
204 ID of the Workspace this entry applies to.
177205 
178206 - `group_type: "batch" or "files" or "model_group" or 3 more`
179207 
from line 248
220248 "limits": [
221249 {
222250 "org_limit": 0,
251 "source": {
252 "type": "workspace"
253 },
223254 "type": "type",
224255 "value": 0
225256 }
from line 361
330361 
331362 - `limits: array of BetaWorkspaceRateLimitValue`
332363 
333 The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
364 The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With `include_inherited` set to `true`, the limiter types the workspace inherits from the organization are listed too, each marked by `source`.
334365 
335366 - `type: string`
336367 
from line 371
340371 
341372 The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
342373 
374 - `source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource`
375 
376 Where `value` comes from. `organization` values are listed only when `include_inherited` is `true`, and then `value` equals `org_limit`.
377 
378 - `BetaWorkspaceRateLimitWorkspaceSource object`
379 
380 - `type: "workspace"`
381 
382 Always `workspace`: a workspace-level override is stored.
383 
384 default: workspace
385 
386 - `BetaWorkspaceRateLimitOrganizationSource object`
387 
388 - `type: "organization"`
389 
390 Always `organization`: no workspace-level override is stored, so the organization's value applies.
391 
392 default: organization
393 
343394 - `value: number`
344395 
345 The workspace-level override value for this limiter type.
396 The workspace's value for this limiter type: the workspace-level override when `source.type` is `workspace`, otherwise the organization's value.
346397 
347398 - `models: array of string or null`
348399 
from line 401
350401 
351402 - `rate_limit_id: string`
352403 
353 The `id` of the organization's RateLimit entry this override applies to.
404 The `id` of the organization's RateLimit entry this entry applies to.
354405 
355406 - `workspace_id: string`
356407 
357 ID of the Workspace this override applies to.
408 ID of the Workspace this entry applies to.
358409 
359410 - `group_type: "batch" or "files" or "model_group" or 3 more`
360411 
from line 425
374425 
375426 - `"web_search"`
376427 
428### Beta Workspace Rate Limit Organization Source
429 
430- `BetaWorkspaceRateLimitOrganizationSource object`
431 
432 - `type: "organization"`
433 
434 Always `organization`: no workspace-level override is stored, so the organization's value applies.
435 
436 default: organization
437 
377438### Beta Workspace Rate Limit Value
378439 
379440- `BetaWorkspaceRateLimitValue object`
from line 447
386447 
387448 The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
388449 
450 - `source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource`
451 
452 Where `value` comes from. `organization` values are listed only when `include_inherited` is `true`, and then `value` equals `org_limit`.
453 
454 - `BetaWorkspaceRateLimitWorkspaceSource object`
455 
456 - `type: "workspace"`
457 
458 Always `workspace`: a workspace-level override is stored.
459 
460 default: workspace
461 
462 - `BetaWorkspaceRateLimitOrganizationSource object`
463 
464 - `type: "organization"`
465 
466 Always `organization`: no workspace-level override is stored, so the organization's value applies.
467 
468 default: organization
469 
389470 - `value: number`
390471 
391 The workspace-level override value for this limiter type.
472 The workspace's value for this limiter type: the workspace-level override when `source.type` is `workspace`, otherwise the organization's value.
473 
474### Beta Workspace Rate Limit Workspace Source
475 
476- `BetaWorkspaceRateLimitWorkspaceSource object`
477 
478 - `type: "workspace"`
479 
480 Always `workspace`: a workspace-level override is stored.
481 
482 default: workspace
392483 

api/beta/organization/workspaces/rate_limits/list Changed · +41 / -10 lines

from line 7
77 
88**GET** `/v1/organizations/workspaces/{workspace_id}/rate_limits`
99 
10List rate-limit overrides configured for a workspace.
10List a workspace's rate limits.
1111 
12Returns only the groups and limiter types that have a workspace-level
13override. Groups without overrides inherit the organization limits and
14are not listed; use `GET /v1/organizations/rate_limits` to see those.
12By default, returns only the groups and limiter types that have a
13workspace-level override. With `include_inherited=true`, returns every
14group with organization-level limits the workspace can see, listing for
15each the values it inherits from the organization as well as its own
16overrides. Each value's `source` says which it is.
1517 
1618When `limit` is omitted, every matching entry is returned in a single
1719page; when `limit` truncates the result, follow `next_page` to fetch
from line 43
4143 
4244 - `"web_search"`
4345 
46- `include_inherited: optional boolean`
47 
48 Also list the limiter values the workspace inherits from the organization, including groups with no workspace-level override.
49 
50 default: false
51 
4452- `limit: optional number`
4553 
4654 Maximum number of items to return per page. Ranges from `1` to `1000`.
from line 65
5765 
5866- `data: array of BetaWorkspaceRateLimit`
5967 
60 Rate-limit entries for the workspace, one per group that has at least one override.
68 Rate-limit entries for the workspace: one per group with at least one override, or, with `include_inherited` set to `true`, one per group the workspace can see that has organization-level limits.
6169 
6270 - `type: "workspace_rate_limit"`
6371 
from line 155
147155 
148156 - `limits: array of BetaWorkspaceRateLimitValue`
149157 
150 The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value.
158 The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With `include_inherited` set to `true`, the limiter types the workspace inherits from the organization are listed too, each marked by `source`.
151159 
152160 - `type: string`
153161 
from line 165
157165 
158166 The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type.
159167 
168 - `source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource`
169 
170 Where `value` comes from. `organization` values are listed only when `include_inherited` is `true`, and then `value` equals `org_limit`.
171 
172 - `BetaWorkspaceRateLimitWorkspaceSource object`
173 
174 - `type: "workspace"`
175 
176 Always `workspace`: a workspace-level override is stored.
177 
178 default: workspace
179 
180 - `BetaWorkspaceRateLimitOrganizationSource object`
181 
182 - `type: "organization"`
183 
184 Always `organization`: no workspace-level override is stored, so the organization's value applies.
185 
186 default: organization
187 
160188 - `value: number`
161189 
162 The workspace-level override value for this limiter type.
190 The workspace's value for this limiter type: the workspace-level override when `source.type` is `workspace`, otherwise the organization's value.
163191 
164192 - `models: array of string or null`
165193 
from line 195
167195 
168196 - `rate_limit_id: string`
169197 
170 The `id` of the organization's RateLimit entry this override applies to.
198 The `id` of the organization's RateLimit entry this entry applies to.
171199 
172200 - `workspace_id: string`
173201 
174 ID of the Workspace this override applies to.
202 ID of the Workspace this entry applies to.
175203 
176204 - `group_type: "batch" or "files" or "model_group" or 3 more`
177205 
from line 246
218246 "limits": [
219247 {
220248 "org_limit": 0,
249 "source": {
250 "type": "workspace"
251 },
221252 "type": "type",
222253 "value": 0
223254 }

api/completions Changed · +8 / -6 lines

from line 17
1717 
1818### Headers
1919 
20- `"anthropic-workspace-id": optional string`
21 
22 Optional header to select the Workspace for this request. The value is a Workspace ID (for example, `wrkspc_011CZkZaBF1tNoB5wlCeusgy`).
23 
24 Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
25 
2026- `"anthropic-beta": optional array of AnthropicBeta`
2127 
28 **Deprecated**: Deprecated. This parameter has no effect on this method and will be removed in a future release.
29 
2230 Optional header to specify the beta version(s) you want to use.
2331 
2432 - `string`
from line 128
120128 - `"inline-tools-2026-09-15"`
121129 
122130 - `"mcp-client-2026-09-15"`
123 
124- `"anthropic-workspace-id": optional string`
125 
126 Optional header to select the Workspace for this request. The value is a Workspace ID (for example, `wrkspc_011CZkZaBF1tNoB5wlCeusgy`).
127 
128 Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
129131 
130132### Body parameters
131133 

api/completions/create Changed · +8 / -6 lines

from line 15
1515 
1616## Headers
1717 
18- `"anthropic-workspace-id": optional string`
19 
20 Optional header to select the Workspace for this request. The value is a Workspace ID (for example, `wrkspc_011CZkZaBF1tNoB5wlCeusgy`).
21 
22 Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
23 
1824- `"anthropic-beta": optional array of AnthropicBeta`
1925 
26 **Deprecated**: Deprecated. This parameter has no effect on this method and will be removed in a future release.
27 
2028 Optional header to specify the beta version(s) you want to use.
2129 
2230 - `string`
from line 126
118126 - `"inline-tools-2026-09-15"`
119127 
120128 - `"mcp-client-2026-09-15"`
121 
122- `"anthropic-workspace-id": optional string`
123 
124 Optional header to select the Workspace for this request. The value is a Workspace ID (for example, `wrkspc_011CZkZaBF1tNoB5wlCeusgy`).
125 
126 Only needed for credentials that can act on more than one Workspace. A credential that belongs to a specific Workspace may omit it; if sent, it must match that Workspace.
127129 
128130## Body parameters
129131 

api/compliance Changed · +2545 / -1467 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

from line 19
1919 
2020#### Query parameters
2121 
22- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 507 more`
22- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more`
2323 
2424 Filter activities by type. See the response `data` schema for the additional fields each type returns. Cannot be combined with `exclude_activity_types[]`.
2525 
from line 251
251251 
252252 An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
253253 
254 - `"claude_artifact_invite_accepted"`
255 
256 Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by `invitee_email` and `invitee_user_id`.
257 
258 - `"claude_artifact_invite_created"`
259 
260 A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
261 
262 - `"claude_artifact_invite_revoked"`
263 
264 A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
265 
266 - `"claude_artifact_invite_role_updated"`
267 
268 A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
269 
254270 - `"claude_artifact_published"`
255271 
256272 A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
from line 1021
10051021 
10061022 - `"mcp_server_managed_auth_token_exchanged"`
10071023 
1008 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests denied by organization policy before a token exchange is attempted are not reported, with the exception of the "connector_scope_not_granted" failures described under error_type.
1024 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
10091025 
10101026 - `"mcp_server_managed_auth_updated"`
10111027 
from line 2134
21182134 
21192135 format: date-time
21202136 
2121- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 507 more`
2137- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more`
21222138 
21232139 Exclude activities of these types. Cannot be combined with `activity_types[]`.
21242140 
from line 2366
23502366 
23512367 An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
23522368 
2369 - `"claude_artifact_invite_accepted"`
2370 
2371 Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by `invitee_email` and `invitee_user_id`.
2372 
2373 - `"claude_artifact_invite_created"`
2374 
2375 A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
2376 
2377 - `"claude_artifact_invite_revoked"`
2378 
2379 A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
2380 
2381 - `"claude_artifact_invite_role_updated"`
2382 
2383 A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
2384 
23532385 - `"claude_artifact_published"`
23542386 
23552387 A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
from line 3136
31043136 
31053137 - `"mcp_server_managed_auth_token_exchanged"`
31063138 
3107 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests denied by organization policy before a token exchange is attempted are not reported, with the exception of the "connector_scope_not_granted" failures described under error_type.
3139 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
31083140 
31093141 - `"mcp_server_managed_auth_updated"`
31103142 
from line 4241
42094241 
42104242#### Returns
42114243 
4212- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 507 more`
4244- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 511 more`
42134245 
42144246 List of activity records. Each element's `type` field identifies which activity it is and which additional fields are present.
42154247 
from line 7617
75857617 
75867618 Unique identifier for the activity e.g. 'activity_abcd1234'
75877619 
7620 - `actor_outside_organization: optional boolean or null`
7621 
7622 True when the person who acted belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted commenter or editor access. Absent on older events; treat absence as false.
7623 
75887624 - `claude_artifact_comment_id: optional string or null`
75897625 
75907626 The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Claude or withdrawn from Claude; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Claude session.
from line 8589
85538589 
85548590 Unique identifier for the activity e.g. 'activity_abcd1234'
85558591 
8592 - `actor_outside_organization: optional boolean or null`
8593 
8594 True when the person who published belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted editor access. Absent on older events; treat absence as false.
8595 
85568596 - `claude_artifact_version_id: optional string or null`
85578597 
85588598 The version identifier recorded as live by this publish.
from line 9769
97299769 gateway or a customer-registered federation issuer — acting without an
97309770 Anthropic-provisioned account or service account.
97319771 
9732 - `type: optional "federated_actor"`
9733 
9734 default: federated_actor
9735 
9736 - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
9737 
9738 - `FederatedActorAwsProvider object`
9739 
9740 Asserting party: the AWS account the organization is bound to.
9741 
9742 - `type: optional "aws"`
9743 
9744 default: aws
9745 
9746 - `account_id: string`
9747 
9748 - `signed_principal: string`
9749 
9750 The AWS-signed ARN of the IAM principal that requested the token.
9751 
9752 - `FederatedActorAzureProvider object`
9753 
9754 Asserting party: the Azure subscription the organization is bound to.
9755 
9756 - `type: optional "azure"`
9757 
9758 default: azure
9759 
9760 - `subscription_id: string`
9761 
9762 - `FederatedActorGcpProvider object`
9763 
9764 Asserting party: the GCP project the organization is bound to.
9765 
9766 - `type: optional "gcp"`
9767 
9768 default: gcp
9769 
9770 - `project_number: string`
9771 
9772 - `FederatedActorOidcProvider object`
9773 
9774 Asserting party: a customer-registered OIDC federation issuer.
9775 
9776 - `type: optional "oidc"`
9777 
9778 default: oidc
9779 
9780 - `issuer: optional string or null`
9781 
9782 The federation issuer's URL. Null when the presented credential failed verification.
9783 
9784 - `ip_address: optional string or null`
9785 
9786 - `subject: optional string or null`
9787 
9788 The provider's verified identifier for the caller; its form depends on the provider.
9789 
9790 - `user_agent: optional string or null`
9791 
9792 - `AttestedDeviceActor object`
9793 
9794 An attested mobile device authenticated via Apple App Attest.
9795 
9796 - `type: optional "attested_device_actor"`
9797 
9798 default: attested_device_actor
9799 
9800 - `external_client_id: string`
9801 
9802 - `kid_hash: string`
9803 
9804 - `ip_address: optional string or null`
9805 
9806 - `user_agent: optional string or null`
9807 
9808 - `id: optional string`
9809 
9810 Unique identifier for the activity e.g. 'activity_abcd1234'
9811 
9812 - `cc_email_count: optional number or null`
9813 
9814 Number of 'cc' email recipients.
9815 
9816 - `created_at: optional string`
9817 
9818 When this activity occurred.
9819 
9820 format: date-time
9821 
9822 - `organization_id: optional string or null`
9823 
9824 Organization ID this activity is associated with
9825 
9826 - `organization_uuid: optional string or null`
9827 
9828 Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
9829 
9830 - `primary_email_set: optional boolean or null`
9831 
9832 Whether a primary billing email is configured.
9833 
9834 - `to_email_count: optional number or null`
9835 
9836 Number of 'to' em
9772

api/compliance/activities Changed · +5018 / -2922 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

from line 17
1717 
1818### Query parameters
1919 
20- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 507 more`
20- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more`
2121 
2222 Filter activities by type. See the response `data` schema for the additional fields each type returns. Cannot be combined with `exclude_activity_types[]`.
2323 
from line 249
249249 
250250 An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
251251 
252 - `"claude_artifact_invite_accepted"`
253 
254 Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by `invitee_email` and `invitee_user_id`.
255 
256 - `"claude_artifact_invite_created"`
257 
258 A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
259 
260 - `"claude_artifact_invite_revoked"`
261 
262 A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
263 
264 - `"claude_artifact_invite_role_updated"`
265 
266 A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
267 
252268 - `"claude_artifact_published"`
253269 
254270 A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
from line 1019
10031019 
10041020 - `"mcp_server_managed_auth_token_exchanged"`
10051021 
1006 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests denied by organization policy before a token exchange is attempted are not reported, with the exception of the "connector_scope_not_granted" failures described under error_type.
1022 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
10071023 
10081024 - `"mcp_server_managed_auth_updated"`
10091025 
from line 2132
21162132 
21172133 format: date-time
21182134 
2119- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 507 more`
2135- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more`
21202136 
21212137 Exclude activities of these types. Cannot be combined with `activity_types[]`.
21222138 
from line 2364
23482364 
23492365 An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
23502366 
2367 - `"claude_artifact_invite_accepted"`
2368 
2369 Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by `invitee_email` and `invitee_user_id`.
2370 
2371 - `"claude_artifact_invite_created"`
2372 
2373 A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
2374 
2375 - `"claude_artifact_invite_revoked"`
2376 
2377 A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
2378 
2379 - `"claude_artifact_invite_role_updated"`
2380 
2381 A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
2382 
23512383 - `"claude_artifact_published"`
23522384 
23532385 A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
from line 3134
31023134 
31033135 - `"mcp_server_managed_auth_token_exchanged"`
31043136 
3105 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests denied by organization policy before a token exchange is attempted are not reported, with the exception of the "connector_scope_not_granted" failures described under error_type.
3137 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
31063138 
31073139 - `"mcp_server_managed_auth_updated"`
31083140 
from line 4239
42074239 
42084240### Returns
42094241 
4210- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 507 more`
4242- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 511 more`
42114243 
42124244 List of activity records. Each element's `type` field identifies which activity it is and which additional fields are present.
42134245 
from line 7615
75837615 
75847616 Unique identifier for the activity e.g. 'activity_abcd1234'
75857617 
7618 - `actor_outside_organization: optional boolean or null`
7619 
7620 True when the person who acted belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted commenter or editor access. Absent on older events; treat absence as false.
7621 
75867622 - `claude_artifact_comment_id: optional string or null`
75877623 
75887624 The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Claude or withdrawn from Claude; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Claude session.
from line 8587
85518587 
85528588 Unique identifier for the activity e.g. 'activity_abcd1234'
85538589 
8590 - `actor_outside_organization: optional boolean or null`
8591 
8592 True when the person who published belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted editor access. Absent on older events; treat absence as false.
8593 
85548594 - `claude_artifact_version_id: optional string or null`
85558595 
85568596 The version identifier recorded as live by this publish.
from line 9767
97279767 gateway or a customer-registered federation issuer — acting without an
97289768 Anthropic-provisioned account or service account.
97299769 
9730 - `type: optional "federated_actor"`
9731 
9732 default: federated_actor
9733 
9734 - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
9735 
9736 - `FederatedActorAwsProvider object`
9737 
9738 Asserting party: the AWS account the organization is bound to.
9739 
9740 - `type: optional "aws"`
9741 
9742 default: aws
9743 
9744 - `account_id: string`
9745 
9746 - `signed_principal: string`
9747 
9748 The AWS-signed ARN of the IAM principal that requested the token.
9749 
9750 - `FederatedActorAzureProvider object`
9751 
9752 Asserting party: the Azure subscription the organization is bound to.
9753 
9754 - `type: optional "azure"`
9755 
9756 default: azure
9757 
9758 - `subscription_id: string`
9759 
9760 - `FederatedActorGcpProvider object`
9761 
9762 Asserting party: the GCP project the organization is bound to.
9763 
9764 - `type: optional "gcp"`
9765 
9766 default: gcp
9767 
9768 - `project_number: string`
9769 
9770 - `FederatedActorOidcProvider object`
9771 
9772 Asserting party: a customer-registered OIDC federation issuer.
9773 
9774 - `type: optional "oidc"`
9775 
9776 default: oidc
9777 
9778 - `issuer: optional string or null`
9779 
9780 The federation issuer's URL. Null when the presented credential failed verification.
9781 
9782 - `ip_address: optional string or null`
9783 
9784 - `subject: optional string or null`
9785 
9786 The provider's verified identifier for the caller; its form depends on the provider.
9787 
9788 - `user_agent: optional string or null`
9789 
9790 - `AttestedDeviceActor object`
9791 
9792 An attested mobile device authenticated via Apple App Attest.
9793 
9794 - `type: optional "attested_device_actor"`
9795 
9796 default: attested_device_actor
9797 
9798 - `external_client_id: string`
9799 
9800 - `kid_hash: string`
9801 
9802 - `ip_address: optional string or null`
9803 
9804 - `user_agent: optional string or null`
9805 
9806 - `id: optional string`
9807 
9808 Unique identifier for the activity e.g. 'activity_abcd1234'
9809 
9810 - `cc_email_count: optional number or null`
9811 
9812 Number of 'cc' email recipients.
9813 
9814 - `created_at: optional string`
9815 
9816 When this activity occurred.
9817 
9818 format: date-time
9819 
9820 - `organization_id: optional string or null`
9821 
9822 Organization ID this activity is associated with
9823 
9824 - `organization_uuid: optional string or null`
9825 
9826 Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
9827 
9828 - `primary_email_set: optional boolean or null`
9829 
9830 Whether a primary billing email is configured.
9831 
9832 - `to_email_count: optional number or null`
9833 
9834 Number of 'to' email recipients.
9835 
9836 - `CcrAgentCreat
9770 - `type: optional "federated_actor

api/compliance/activities/list Changed · +2527 / -1463 lines

This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.

from line 15
1515 
1616## Query parameters
1717 
18- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 507 more`
18- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more`
1919 
2020 Filter activities by type. See the response `data` schema for the additional fields each type returns. Cannot be combined with `exclude_activity_types[]`.
2121 
from line 247
247247 
248248 An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
249249 
250 - `"claude_artifact_invite_accepted"`
251 
252 Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by `invitee_email` and `invitee_user_id`.
253 
254 - `"claude_artifact_invite_created"`
255 
256 A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
257 
258 - `"claude_artifact_invite_revoked"`
259 
260 A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
261 
262 - `"claude_artifact_invite_role_updated"`
263 
264 A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
265 
250266 - `"claude_artifact_published"`
251267 
252268 A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
from line 1017
10011017 
10021018 - `"mcp_server_managed_auth_token_exchanged"`
10031019 
1004 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests denied by organization policy before a token exchange is attempted are not reported, with the exception of the "connector_scope_not_granted" failures described under error_type.
1020 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
10051021 
10061022 - `"mcp_server_managed_auth_updated"`
10071023 
from line 2130
21142130 
21152131 format: date-time
21162132 
2117- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 507 more`
2133- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 511 more`
21182134 
21192135 Exclude activities of these types. Cannot be combined with `activity_types[]`.
21202136 
from line 2362
23462362 
23472363 An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
23482364 
2365 - `"claude_artifact_invite_accepted"`
2366 
2367 Someone outside the organization signed in with a verified account for the invited address and accepted an invitation to an artifact, and can now open it; recorded in the artifact owner's organization. The person who accepted is identified by `invitee_email` and `invitee_user_id`.
2368 
2369 - `"claude_artifact_invite_created"`
2370 
2371 A member invited (or re-invited) an email address outside the organization to an artifact; recorded in the artifact owner's organization with the inviting member as the actor.
2372 
2373 - `"claude_artifact_invite_revoked"`
2374 
2375 A member withdrew an invitation to an artifact for someone outside the organization, removing any access that invitation had granted; recorded in the artifact owner's organization with that member as the actor.
2376 
2377 - `"claude_artifact_invite_role_updated"`
2378 
2379 A member changed the access level of an email invitation to an artifact for someone outside the organization, whether the invitation was still pending or had been accepted; recorded in the artifact owner's organization with that member as the actor.
2380 
23492381 - `"claude_artifact_published"`
23502382 
23512383 A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded when the artifact is saved, including saves of private artifacts, except that automatic saves made while a person keeps editing may be recorded periodically for that person rather than once per save; changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
from line 3132
31003132 
31013133 - `"mcp_server_managed_auth_token_exchanged"`
31023134 
3103 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests denied by organization policy before a token exchange is attempted are not reported, with the exception of the "connector_scope_not_granted" failures described under error_type.
3135 A user attempted to obtain an access token for an MCP server via enterprise managed authorization. This event reports the outcomes of attempted token exchanges. Repeated failures with the same cause may be reported once until the cause changes, and requests refused before a token exchange is attempted are not reported, except the "connector_scope_not_granted" and "identity_assertion_refused" failures described under error_type.
31043136 
31053137 - `"mcp_server_managed_auth_updated"`
31063138 
from line 4237
42054237 
42064238## Returns
42074239 
4208- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 507 more`
4240- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 511 more`
42094241 
42104242 List of activity records. Each element's `type` field identifies which activity it is and which additional fields are present.
42114243 
from line 7613
75817613 
75827614 Unique identifier for the activity e.g. 'activity_abcd1234'
75837615 
7616 - `actor_outside_organization: optional boolean or null`
7617 
7618 True when the person who acted belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted commenter or editor access. Absent on older events; treat absence as false.
7619 
75847620 - `claude_artifact_comment_id: optional string or null`
75857621 
75867622 The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Claude or withdrawn from Claude; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Claude session.
from line 8585
85498585 
85508586 Unique identifier for the activity e.g. 'activity_abcd1234'
85518587 
8588 - `actor_outside_organization: optional boolean or null`
8589 
8590 True when the person who published belongs to a different organization than the artifact's owner organization, such as someone invited by email who accepted editor access. Absent on older events; treat absence as false.
8591 
85528592 - `claude_artifact_version_id: optional string or null`
85538593 
85548594 The version identifier recorded as live by this publish.
from line 9765
97259765 gateway or a customer-registered federation issuer — acting without an
97269766 Anthropic-provisioned account or service account.
97279767 
9728 - `type: optional "federated_actor"`
9729 
9730 default: federated_actor
9731 
9732 - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
9733 
9734 - `FederatedActorAwsProvider object`
9735 
9736 Asserting party: the AWS account the organization is bound to.
9737 
9738 - `type: optional "aws"`
9739 
9740 default: aws
9741 
9742 - `account_id: string`
9743 
9744 - `signed_principal: string`
9745 
9746 The AWS-signed ARN of the IAM principal that requested the token.
9747 
9748 - `FederatedActorAzureProvider object`
9749 
9750 Asserting party: the Azure subscription the organization is bound to.
9751 
9752 - `type: optional "azure"`
9753 
9754 default: azure
9755 
9756 - `subscription_id: string`
9757 
9758 - `FederatedActorGcpProvider object`
9759 
9760 Asserting party: the GCP project the organization is bound to.
9761 
9762 - `type: optional "gcp"`
9763 
9764 default: gcp
9765 
9766 - `project_number: string`
9767 
9768 - `FederatedActorOidcProvider object`
9769 
9770 Asserting party: a customer-registered OIDC federation issuer.
9771 
9772 - `type: optional "oidc"`
9773 
9774 default: oidc
9775 
9776 - `issuer: optional string or null`
9777 
9778 The federation issuer's URL. Null when the presented credential failed verification.
9779 
9780 - `ip_address: optional string or null`
9781 
9782 - `subject: optional string or null`
9783 
9784 The provider's verified identifier for the caller; its form depends on the provider.
9785 
9786 - `user_agent: optional string or null`
9787 
9788 - `AttestedDeviceActor object`
9789 
9790 An attested mobile device authenticated via Apple App Attest.
9791 
9792 - `type: optional "attested_device_actor"`
9793 
9794 default: attested_device_actor
9795 
9796 - `external_client_id: string`
9797 
9798 - `kid_hash: string`
9799 
9800 - `ip_address: optional string or null`
9801 
9802 - `user_agent: optional string or null`
9803 
9804 - `id: optional string`
9805 
9806 Unique identifier for the activity e.g. 'activity_abcd1234'
9807 
9808 - `cc_email_count: optional number or null`
9809 
9810 Number of 'cc' email recipients.
9811 
9812 - `created_at: optional string`
9813 
9814 When this activity occurred.
9815 
9816 format: date-time
9817 
9818 - `organization_id: optional string or null`
9819 
9820 Organization ID this activity is associated with
9821 
9822 - `organization_uuid: optional string or null`
9823 
9824 Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
9825 
9826 - `primary_email_set: optional boolean or null`
9827 
9828 Whether a primary billing email is configured.
9829 
9830 - `to_email_count: optional number or null`
9831 
9832 Number of 'to' email recipients.
9833 
9834 - `CcrAgentC
9768 - `type: optional "federated_a

api/compliance/apps Changed · +15 / -3 lines

from line 15
1515compliance review. Results are sorted chronologically (time ascending)
1616by the `order_by` key, with ties broken by id.
1717 
18Incremental polling with `order_by=updated_at` returns a chat again
19after it receives a new message, is moved into or out of a project, or
20is deleted in claude.ai. A chat is not guaranteed to be returned again
21after other edits, such as a rename.
22 
1823**Deprecation notice:** Combining `user_ids[]` with any `updated_at.*`
1924filter is deprecated and will be rejected with HTTP 400 after
20252026-09-22. For incremental polling by update time, omit `user_ids[]`
from line 169
164169 
165170 - `updated_at: string`
166171 
167 Last update timestamp
172 Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in claude.ai. Other edits, such as renaming the chat, are not guaranteed to change it.
168173 
169174 format: date-time
170175 
from line 665
660665 
661666- `updated_at: string`
662667 
663 Last update timestamp
668 Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in claude.ai. Other edits, such as renaming the chat, are not guaranteed to change it.
664669 
665670 format: date-time
666671 
from line 2326
23212326honored for 24 hours: a cursor older than that is rejected with an
23222327explicit 400; restart the walk to read under the current boundary.
23232328 
2329On a very large session, some pages are too large to read and return a
2330400; retrying does not help. If the request used `order=desc`, read the
2331session oldest first from its first page instead (omit `order` and
2332`page`, then follow `next_page`). Rarely, an oldest-first page returns
2333this 400 too; contact Anthropic support and quote the `request-id`
2334response header.
2335 
23242336#### Path parameters
23252337 
23262338- `local_session_id: string`
from line 2347
23352347 
23362348- `order: optional "asc" or "desc"`
23372349 
2338 Sort direction. `asc` (oldest-first, default) or `desc`.
2350 Sort direction. `asc` (oldest-first, default) or `desc`. On very large sessions some pages are too large to read and return a 400, far more often with `desc`; read those sessions with `asc`, starting again from the first page.
23392351 
23402352 default: asc
23412353 

api/compliance/apps/chats Changed · +8 / -3 lines

from line 13
1313compliance review. Results are sorted chronologically (time ascending)
1414by the `order_by` key, with ties broken by id.
1515 
16Incremental polling with `order_by=updated_at` returns a chat again
17after it receives a new message, is moved into or out of a project, or
18is deleted in claude.ai. A chat is not guaranteed to be returned again
19after other edits, such as a rename.
20 
1621**Deprecation notice:** Combining `user_ids[]` with any `updated_at.*`
1722filter is deprecated and will be rejected with HTTP 400 after
18232026-09-22. For incremental polling by update time, omit `user_ids[]`
from line 167
162167 
163168 - `updated_at: string`
164169 
165 Last update timestamp
170 Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in claude.ai. Other edits, such as renaming the chat, are not guaranteed to change it.
166171 
167172 format: date-time
168173 
from line 343
338343 
339344 - `updated_at: string`
340345 
341 Last update timestamp
346 Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in claude.ai. Other edits, such as renaming the chat, are not guaranteed to change it.
342347 
343348 format: date-time
344349 
from line 761
756761 
757762- `updated_at: string`
758763 
759 Last update timestamp
764 Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in claude.ai. Other edits, such as renaming the chat, are not guaranteed to change it.
760765 
761766 format: date-time
762767 

api/compliance/apps/chats/list Changed · +6 / -1 lines

from line 11
1111compliance review. Results are sorted chronologically (time ascending)
1212by the `order_by` key, with ties broken by id.
1313 
14Incremental polling with `order_by=updated_at` returns a chat again
15after it receives a new message, is moved into or out of a project, or
16is deleted in claude.ai. A chat is not guaranteed to be returned again
17after other edits, such as a rename.
18 
1419**Deprecation notice:** Combining `user_ids[]` with any `updated_at.*`
1520filter is deprecated and will be rejected with HTTP 400 after
16212026-09-22. For incremental polling by update time, omit `user_ids[]`
from line 165
160165 
161166 - `updated_at: string`
162167 
163 Last update timestamp
168 Last update timestamp. Updated when the chat receives a new message, is moved into or out of a project, or is deleted in claude.ai. Other edits, such as renaming the chat, are not guaranteed to change it.
164169 
165170 format: date-time
166171 

api/compliance/apps/sessions Changed · +8 / -1 lines

from line 257
257257honored for 24 hours: a cursor older than that is rejected with an
258258explicit 400; restart the walk to read under the current boundary.
259259 
260On a very large session, some pages are too large to read and return a
261400; retrying does not help. If the request used `order=desc`, read the
262session oldest first from its first page instead (omit `order` and
263`page`, then follow `next_page`). Rarely, an oldest-first page returns
264this 400 too; contact Anthropic support and quote the `request-id`
265response header.
266 
260267#### Path parameters
261268 
262269- `local_session_id: string`
from line 278
271278 
272279- `order: optional "asc" or "desc"`
273280 
274 Sort direction. `asc` (oldest-first, default) or `desc`.
281 Sort direction. `asc` (oldest-first, default) or `desc`. On very large sessions some pages are too large to read and return a 400, far more often with `desc`; read those sessions with `asc`, starting again from the first page.
275282 
276283 default: asc
277284 

api/compliance/apps/sessions/local Changed · +8 / -1 lines

from line 371
371371honored for 24 hours: a cursor older than that is rejected with an
372372explicit 400; restart the walk to read under the current boundary.
373373 
374On a very large session, some pages are too large to read and return a
375400; retrying does not help. If the request used `order=desc`, read the
376session oldest first from its first page instead (omit `order` and
377`page`, then follow `next_page`). Rarely, an oldest-first page returns
378this 400 too; contact Anthropic support and quote the `request-id`
379response header.
380 
374381#### Path parameters
375382 
376383- `local_session_id: string`
from line 392
385392 
386393- `order: optional "asc" or "desc"`
387394 
388 Sort direction. `asc` (oldest-first, default) or `desc`.
395 Sort direction. `asc` (oldest-first, default) or `desc`. On very large sessions some pages are too large to read and return a 400, far more often with `desc`; read those sessions with `asc`, starting again from the first page.
389396 
390397 default: asc
391398 
Feedback