Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · api

One read of Claude Developer Platformapi-20260925T153714Z

310 pages moved out of 637 read.

Pages moved 310 significant first
Pages read 637 in this capture
Captured 15:37 UTC
Corpus hash 850f99a0d461 corpus-hash

What this read moved

151-175 of 310, page 7 of 13

This capture is too large to show at once. Changes 151-175 of 310 are below, significant first; the rest are on the following screens.

home Changed · +4 / -4 lines

from line 164
164164 </HomeJourneyStep>
165165 
166166 <HomeJourneyStep title="Operate">
167 <HomeJourneyLink icon="settings" href="https://platform.claude.com/docs/en/build-with-claude/workspaces">
167 <HomeJourneyLink icon="settings" href="https://platform.claude.com/docs/en/manage-claude/workspaces">
168168 Workspaces and admin
169169 </HomeJourneyLink>
170170 
from line 172
172172 API key management
173173 </HomeJourneyLink>
174174 
175 <HomeJourneyLink icon="chart" href="https://platform.claude.com/docs/en/build-with-claude/usage-cost-api">
175 <HomeJourneyLink icon="chart" href="https://platform.claude.com/docs/en/manage-claude/usage-cost-api">
176176 Usage monitoring
177177 </HomeJourneyLink>
178178 
from line 222
222222 </HomeJourneyStep>
223223 
224224 <HomeJourneyStep title="Operate">
225 <HomeJourneyLink icon="settings" href="https://platform.claude.com/docs/en/build-with-claude/workspaces">
225 <HomeJourneyLink icon="settings" href="https://platform.claude.com/docs/en/manage-claude/workspaces">
226226 Workspaces and admin
227227 </HomeJourneyLink>
228228 
from line 230
230230 API key management
231231 </HomeJourneyLink>
232232 
233 <HomeJourneyLink icon="chart" href="https://platform.claude.com/docs/en/build-with-claude/usage-cost-api">
233 <HomeJourneyLink icon="chart" href="https://platform.claude.com/docs/en/manage-claude/usage-cost-api">
234234 Usage monitoring
235235 </HomeJourneyLink>
236236 </HomeJourneyStep>

manage-claude/admin-api Changed · +7 / -7 lines

from line 8
88 **The Admin API is unavailable for individual accounts.** To collaborate with teammates and add members, set up your organization in **Console → Settings → Organization**.
99</Tip>
1010 
11The [Admin API](https://platform.claude.com/docs/en/api/admin) lets you manage your organization's members, workspaces, invites, and API keys programmatically instead of by hand in the [Claude Console](https://platform.claude.com/).
11The [Admin API](https://platform.claude.com/docs/en/api/beta/organization) lets you manage your organization's members, workspaces, invites, and API keys programmatically instead of by hand in the [Claude Console](https://platform.claude.com/).
1212 
1313<Check>
1414 **The Admin API requires special access**
from line 32
3232 
3333Authenticate with any of the three credentials. An Admin API key covers most endpoints. The service-account, federation-issuer, and federation-rule endpoints accept only an `org:admin` OAuth token. Send a personal key or service account key in the `x-api-key` header, as you would an Admin API key. The following examples call the [organization info endpoint](https://platform.claude.com/docs/en/manage-claude/admin-api#accessing-organization-info) with an OAuth token and with an Admin API key.
3434 
35The Python, TypeScript, C#, Go, Java, PHP, and Ruby SDKs expose the Admin API under `client.beta.organization`, and the `ant` CLI under `ant beta:organization`. The examples on this page use the default client, which reads an Admin API key from `ANTHROPIC_API_KEY` or an OAuth bearer token from `ANTHROPIC_AUTH_TOKEN`. SDK list methods in Python, TypeScript, C#, Go, and Java return an iterator that fetches more pages on demand, so `limit` sets the page size, not the total. The PHP, Ruby, and curl examples return one page. In the CLI, `--limit` caps the results on the member, invite, workspace, workspace-member, and API-key lists. For each endpoint's parameters and responses, see the [Admin API reference](https://platform.claude.com/docs/en/api/admin).
35The Python, TypeScript, C#, Go, Java, PHP, and Ruby SDKs expose the Admin API under `client.beta.organization`, and the `ant` CLI under `ant beta:organization`. The examples on this page use the default client, which reads an Admin API key from `ANTHROPIC_API_KEY` or an OAuth bearer token from `ANTHROPIC_AUTH_TOKEN`. SDK list methods in Python, TypeScript, C#, Go, and Java return an iterator that fetches more pages on demand, so `limit` sets the page size, not the total. The PHP, Ruby, and curl examples return one page. In the CLI, `--limit` caps the results on the member, invite, workspace, workspace-member, and API-key lists. For each endpoint's parameters and responses, see the [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization).
3636 
3737### OAuth bearer token
3838 
from line 243
243243 
244244### Organization members
245245 
246List [organization members](https://platform.claude.com/docs/en/api/admin-api/users/get-user), update their roles, and remove them.
246List [organization members](https://platform.claude.com/docs/en/api/beta/organization/users/retrieve), update their roles, and remove them.
247247 
248248List the members of your organization:
249249 
from line 539
539539 
540540### Organization invites
541541 
542Invite users to your organization and manage pending [invites](https://platform.claude.com/docs/en/api/admin-api/invites/get-invite).
542Invite users to your organization and manage pending [invites](https://platform.claude.com/docs/en/api/beta/organization/invites/retrieve).
543543 
544544Invite a user to your organization:
545545 
from line 856
856856 
857857### Workspace members
858858 
859Manage [user access to specific workspaces](https://platform.claude.com/docs/en/api/admin-api/workspace_members/get-workspace-member):
859Manage [user access to specific workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/members/retrieve):
860860 
861861Add a member to a workspace:
862862 
from line 1350
13501350 
13511351### API keys
13521352 
1353Monitor and manage [API keys](https://platform.claude.com/docs/en/api/admin/api_keys/list). Each key in the response includes its `expires_at` timestamp (`null` for keys without an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration)) and `principal`, the identity it acts as (see [Key types](https://platform.claude.com/docs/en/manage-claude/authentication#key-types)). For a personal key, `principal` is `{"type": "user_actor", "user_id": "user_..."}`; for a service account key, `{"type": "service_account_actor", "service_account_id": "svac_..."}`; and for a workspace key, `null`. Each key also has a `scope` object: `{"type": "workspace", "workspace_id": "wrkspc_..."}` for a key bound to one workspace, or `{"type": "organization"}` for a key that can work across any workspace the account has access to. The top-level `workspace_id` field is deprecated and is `null` both for keys bound to the Default Workspace and for keys without a workspace scope; use `scope` to tell them apart. Filtering the list by `workspace_id` with the Default Workspace's ID returns only keys bound to the Default Workspace; keys without a workspace scope aren't returned under any `workspace_id` filter.
1353Monitor and manage [API keys](https://platform.claude.com/docs/en/api/beta/organization/api_keys/list). Each key in the response includes its `expires_at` timestamp (`null` for keys without an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration)) and `principal`, the identity it acts as (see [Key types](https://platform.claude.com/docs/en/manage-claude/authentication#key-types)). For a personal key, `principal` is `{"type": "user_actor", "user_id": "user_..."}`; for a service account key, `{"type": "service_account_actor", "service_account_id": "svac_..."}`; and for a workspace key, `null`. Each key also has a `scope` object: `{"type": "workspace", "workspace_id": "wrkspc_..."}` for a key bound to one workspace, or `{"type": "organization"}` for a key that can work across any workspace the account has access to. The top-level `workspace_id` field is deprecated and is `null` both for keys bound to the Default Workspace and for keys without a workspace scope; use `scope` to tell them apart. Filtering the list by `workspace_id` with the Default Workspace's ID returns only keys bound to the Default Workspace; keys without a workspace scope aren't returned under any `workspace_id` filter.
13541354 
13551355List the active API keys in a workspace:
13561356 
from line 1723
17231723}
17241724```
17251725 
1726For parameter details and response schemas, see the [Organization Info API reference](https://platform.claude.com/docs/en/api/admin-api/organization/get-me).
1726For parameter details and response schemas, see the [Organization Info API reference](https://platform.claude.com/docs/en/api/beta/organization/retrieve).
17271727 
17281728## Usage and cost reports
17291729 

manage-claude/analytics-api Changed · +5 / -5 lines

from line 18
1818| **Claude Code Analytics API** | Admin API key (`sk-ant-admin01-...`) | [Claude Console > Settings > Admin keys](https://platform.claude.com/settings/admin-keys) | Organization admin | Daily Claude Code metrics per user: sessions, lines of code, commits, pull requests, tool acceptance, and estimated cost by model |
1919| **Claude Enterprise Analytics API** | Analytics API key | [claude.ai > Organization settings > API](https://claude.ai/admin-settings/api-access) | Primary owner | Organization-wide engagement and adoption (user activity, active-user summaries, project, skill, and connector usage), plus cost and usage reports |
2020 
21The key types are not interchangeable: an Admin API key cannot call the Claude Enterprise Analytics API, and an Analytics API key cannot call the Admin API. Both APIs appear under the [Admin API reference](https://platform.claude.com/docs/en/api/admin), but they are separate APIs with separate key types. If your organization uses both the Claude Platform and Claude Enterprise, you can provision both keys and use each API for its own data.
21The key types are not interchangeable: an Admin API key cannot call the Claude Enterprise Analytics API, and an Analytics API key cannot call the Admin API. Both APIs appear under the [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization), but they are separate APIs with separate key types. If your organization uses both the Claude Platform and Claude Enterprise, you can provision both keys and use each API for its own data.
2222 
2323<Note>
2424 Looking for API usage and cost data rather than product analytics? See the [Usage and Cost API](https://platform.claude.com/docs/en/manage-claude/usage-cost-api), which explains the right path for both Claude Console and Claude Enterprise organizations.
from line 48
4848 </Step>
4949</Steps>
5050 
51For the available metrics, request parameters, and response schema, see the [Claude Code Analytics API guide](https://platform.claude.com/docs/en/manage-claude/claude-code-analytics-api) and the [API reference](https://platform.claude.com/docs/en/api/admin/usage_report/retrieve_claude_code).
51For the available metrics, request parameters, and response schema, see the [Claude Code Analytics API guide](https://platform.claude.com/docs/en/manage-claude/claude-code-analytics-api) and the [API reference](https://platform.claude.com/docs/en/api/beta/organization/usage_report/retrieve_claude_code).
5252 
5353## Get access to the Claude Enterprise Analytics API
5454 
from line 64
6464 </Step>
6565 
6666 <Step title="Call the API">
67 Pass the key in the `x-api-key` header and include the [`anthropic-version`](https://platform.claude.com/docs/en/api/versioning) header on every request. Endpoints live under `https://api.anthropic.com/v1/organizations/analytics/`. For request examples, parameters, and response schemas, see the [Claude Enterprise Analytics API reference](https://platform.claude.com/docs/en/api/admin/analytics).
67 Pass the key in the `x-api-key` header and include the [`anthropic-version`](https://platform.claude.com/docs/en/api/versioning) header on every request. Endpoints live under `https://api.anthropic.com/v1/organizations/analytics/`. For request examples, parameters, and response schemas, see the [Claude Enterprise Analytics API reference](https://platform.claude.com/docs/en/api/beta/organization/analytics).
6868 </Step>
6969</Steps>
7070 
from line 75
7575* **Project, skill, and connector usage:** adoption breakdowns for chat projects, skills, and connectors
7676* **Cost and usage reports:** per-user and organization-level token usage and cost over time (usage-based Enterprise plans)
7777 
78For endpoint details, parameters, and response schemas, see the [Claude Enterprise Analytics API reference](https://platform.claude.com/docs/en/api/admin/analytics). The following sections cover data freshness, metric definitions, and operational guidance that apply across those endpoints.
78For endpoint details, parameters, and response schemas, see the [Claude Enterprise Analytics API reference](https://platform.claude.com/docs/en/api/beta/organization/analytics). The following sections cover data freshness, metric definitions, and operational guidance that apply across those endpoints.
7979 
8080## Data availability and freshness
8181 
from line 126
126126 Track API token usage and costs for your organization.
127127 </Card>
128128 
129 <Card title="Claude Enterprise Analytics API reference" href="https://platform.claude.com/docs/en/api/admin/analytics">
129 <Card title="Claude Enterprise Analytics API reference" href="https://platform.claude.com/docs/en/api/beta/organization/analytics">
130130 Endpoint reference for engagement, adoption, and cost data.
131131 </Card>
132132 

manage-claude/authentication Changed · +3 / -3 lines

from line 48
4848 
4949The legacy `x-api-key: YOUR_API_KEY` header is still supported in place of `Authorization`.
5050 
51Store API keys in a secrets manager, rotate them periodically, and disable or delete any key you suspect has leaked. On the [API keys page](https://platform.claude.com/settings/keys), **Disable** is reversible (the Admin API reports the key's `status` as `"inactive"`, and **Re-enable** returns it to `"active"`), while **Delete** is permanent: the key is archived and still appears in [List API Keys](https://platform.claude.com/docs/en/api/admin/api_keys/list) with `status: "archived"`. Expired keys can only be deleted. You can also set an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration) when you create a key to limit how long a leaked credential stays usable.
51Store API keys in a secrets manager, rotate them periodically, and disable or delete any key you suspect has leaked. On the [API keys page](https://platform.claude.com/settings/keys), **Disable** is reversible (the Admin API reports the key's `status` as `"inactive"`, and **Re-enable** returns it to `"active"`), while **Delete** is permanent: the key is archived and still appears in [List API Keys](https://platform.claude.com/docs/en/api/beta/organization/api_keys/list) with `status: "archived"`. Expired keys can only be deleted. You can also set an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration) when you create a key to limit how long a leaked credential stays usable.
5252 
5353<CodeGroup>
5454 ```bash cURL
from line 129
129129 
130130The [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api) accepts a personal key or service account key only if the key isn't scoped to a specific workspace.
131131 
132You can find a workspace's ID in the **ID** column of [Settings → Workspaces](https://platform.claude.com/settings/workspaces) in the Claude Console, or by calling the [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) endpoint. List Workspaces omits the Default Workspace; its ID is in the `anthropic-workspace-id` [response header](https://platform.claude.com/docs/en/manage-claude/workspaces#identify-the-workspace-behind-an-api-response) of any request that runs there.
132You can find a workspace's ID in the **ID** column of [Settings → Workspaces](https://platform.claude.com/settings/workspaces) in the Claude Console, or by calling the [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) endpoint. List Workspaces omits the Default Workspace; its ID is in the `anthropic-workspace-id` [response header](https://platform.claude.com/docs/en/manage-claude/workspaces#identify-the-workspace-behind-an-api-response) of any request that runs there.
133133 
134134<CodeGroup>
135135 ```bash cURL
from line 334
334334 
335335After a key expires, requests made with it return a `401 authentication_error`. Create a new key to restore access; expired keys cannot be reactivated.
336336 
337The Console API keys table shows each key's expiration, and the Admin API reports each key's `expires_at` timestamp on the [List API Keys](https://platform.claude.com/docs/en/api/admin/api_keys/list) and [Retrieve API Key](https://platform.claude.com/docs/en/api/admin/api_keys/retrieve) endpoints, so you can audit and rotate keys before they expire. The field is `null` for keys without an expiration.
337The Console API keys table shows each key's expiration, and the Admin API reports each key's `expires_at` timestamp on the [List API Keys](https://platform.claude.com/docs/en/api/beta/organization/api_keys/list) and [Retrieve API Key](https://platform.claude.com/docs/en/api/beta/organization/api_keys/retrieve) endpoints, so you can audit and rotate keys before they expire. The field is `null` for keys without an expiration.
338338 
339339Expiration limits the lifetime of a leaked credential, but it is not a substitute for secret hygiene. Regardless of expiration, store keys in a secrets manager and disable or delete any key you suspect has leaked.
340340 

manage-claude/cmek-aws-kms Changed · +12 / -18 lines

from line 55
5555 In the policy, replace `<AWS_ACCOUNT_ID>` with your AWS account ID and `<ORGANIZATION_UUID>` with your organization ID. The `StringEquals` condition on `kms:EncryptionContext:anthropic:org_uuid` binds the key to your Anthropic organization, and validation refuses a key without it. To share one key among several Anthropic organizations, list each organization ID in the condition value.
5656 
5757 <Note>
58 **Finding your organization ID:** Copy the **Organization ID** field under **Settings > Organization** in the Claude Console, or under **Organization settings > Organization** in claude.ai, or read the `id` field from the [Organization Info](https://platform.claude.com/docs/en/api/admin-api/organization/get-me) endpoint. Use the bare UUID, not the `org_`-prefixed ID.
58 **Finding your organization ID:** Copy the **Organization ID** field under **Settings > Organization** in the Claude Console, or under **Organization settings > Organization** in claude.ai, or read the `id` field from the [Organization Info](https://platform.claude.com/docs/en/api/beta/organization/retrieve) endpoint. Use the bare UUID, not the `org_`-prefixed ID.
5959 </Note>
6060 
6161 Save the policy as `key-policy.json`. To create the key in the AWS Console instead, paste the policy there, as described later in this step.
from line 196
196196 </Note>
197197 
198198 <Note>
199 **Finding your compartment ID:** Each workspace has a compartment ID that scopes its CMEK data. To find it in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/admin-api/workspaces/get-workspace) endpoint.
199 **Finding your compartment ID:** Each workspace has a compartment ID that scopes its CMEK data. To find it in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) endpoint.
200200 </Note>
201201 
202202 You can set up the key in the Claude Console or through the Admin API, with the same result.
from line 636
636636 
637637### Create the KMS key
638638 
639The key policy has three statements: your account's root admin statement; a statement that lets the Claude Platform on AWS service principal encrypt, decrypt, and generate data keys; and a separate statement for `kms:DescribeKey`. Both service-principal statements carry a recommended `aws:SourceArn` condition: the service calls your key on behalf of a specific workspace and passes that [workspace's ARN](https://platform.claude.com/docs/en/api/claude-platform-on-aws-iam-actions#service-details) as the source ARN, so the pattern shown limits the grant to workspaces in your own AWS account. `DescribeKey` is granted separately because it has no `EncryptionContext` parameter, so an `EncryptionContext` condition on that action would always deny.
639The key policy has three statements: your account's root admin statement; a statement that lets the Claude Platform on AWS service principal encrypt, decrypt, and generate data keys; and a separate statement for `kms:DescribeKey`. The crypto statement carries an optional `EncryptionContext` condition that binds the key to the workspaces you list. `DescribeKey` is granted separately because it has no `EncryptionContext` parameter, so an `EncryptionContext` condition on that action would always deny.
640640 
641If you plan to use the optional `EncryptionContext` condition shown here, create the workspace first (without a key), copy its compartment ID, and substitute it for `<compartment-uuid>`. To find the ID in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read it from the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/admin-api/workspaces/get-workspace) endpoint. If you don't plan to use the condition, delete the `StringEquals` entry from that statement's `Condition` block and keep the `ArnLike` entry.
641If you plan to use the optional `EncryptionContext` condition shown here, create the workspace first (without a key), copy its compartment ID, and substitute it for `<compartment-uuid>`. To find the ID in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read it from the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) endpoint. If you don't plan to use the condition, delete the `Condition` block from that statement.
642642 
643643```bash
644644export YOUR_ACCOUNT=$(aws sts get-caller-identity --query Account --output text)
from line 664
664664 \"Action\": [\"kms:Encrypt\", \"kms:Decrypt\", \"kms:GenerateDataKey\"],
665665 \"Resource\": \"*\",
666666 \"Condition\": {
667 \"ArnLike\": {
668 \"aws:SourceArn\": \"arn:aws:aws-external-anthropic:*:${YOUR_ACCOUNT}:workspace/*\"
669 },
670667 \"StringEquals\": {
671668 \"kms:EncryptionContext:anthropic:compartment_uuid\": [
672669 \"<compartment-uuid>\"
from line 676
679676 \"Effect\": \"Allow\",
680677 \"Principal\": {\"Service\": \"aws-external-anthropic.amazonaws.com\"},
681678 \"Action\": \"kms:DescribeKey\",
682 \"Resource\": \"*\",
683 \"Condition\": {
684 \"ArnLike\": {
685 \"aws:SourceArn\": \"arn:aws:aws-external-anthropic:*:${YOUR_ACCOUNT}:workspace/*\"
686 }
687 }
679 \"Resource\": \"*\"
688680 }
689681 ]
690682 }"
from line 684
692684 
693685Capture `KeyMetadata.Arn` from the output. You need it when you register the key.
694686 
695Both conditions are optional hardening, and they compose. The `aws:SourceArn` condition can be written before any workspace exists; to pin the key to particular workspaces instead of your whole account, list their full workspace ARNs in place of the wildcard pattern, and to start without it, delete the `ArnLike` entry from both service-principal statements (removing a `Condition` block that this leaves empty). The `EncryptionContext` condition is also optional. Every encrypt, decrypt, and data-key call made for a workspace, including the attach-time check, carries that workspace's compartment ID as `anthropic:compartment_uuid`, so the condition lists the compartment ID of each workspace you attach the key to and needs no all-zeros entry. Adding it binds the key to the workspaces you list at the IAM layer as well. Because a compartment ID exists only once its workspace exists, the order is: create the workspace, put its compartment ID in the condition (at key creation, or later with `kms:PutKeyPolicy`), then attach the key. Before attaching the key to each additional workspace, add that workspace's compartment ID the same way. To start without it, delete the `StringEquals` entry from the `AllowClaudePlatformOnAWSCrypto` statement's `Condition` block; if you add it later, include the compartment ID of every workspace the key is already attached to.
687The `EncryptionContext` condition is optional. Every encrypt, decrypt, and data-key call made for a workspace, including the attach-time check, carries that workspace's compartment ID as `anthropic:compartment_uuid`, so the condition lists the compartment ID of each workspace you attach the key to and needs no all-zeros entry. Adding it binds the key to the workspaces you list at the IAM layer as well. Because a compartment ID exists only once its workspace exists, the order is: create the workspace, put its compartment ID in the condition (at key creation, or later with `kms:PutKeyPolicy`), then attach the key. Before attaching the key to each additional workspace, add that workspace's compartment ID the same way. To start without it, delete the `Condition` block from the `AllowClaudePlatformOnAWSCrypto` statement; if you add it later, include the compartment ID of every workspace the key is already attached to.
696688 
689You can further restrict both service-principal statements with an `aws:SourceArn` condition. The service passes the [workspace's ARN](https://platform.claude.com/docs/en/api/claude-platform-on-aws-iam-actions#service-details) (`arn:aws:aws-external-anthropic:<region>:<account-id>:workspace/<workspace-id>`) as the source ARN on every call it makes with your key, so `"ArnLike": {"aws:SourceArn": "arn:aws:aws-external-anthropic:*:<account-id>:workspace/*"}` limits the grant to workspaces in your own AWS account, and a list of full workspace ARNs limits it to those workspaces. This condition is not required; the `EncryptionContext` condition on its own binds the key to the workspaces you list.
690 
697691You can also create the key from the AWS Console: choose a symmetric key with the encrypt and decrypt key usage, a single-region key, and KMS key material origin, in the workspace's region. Leave key usage permissions empty in the Create-key wizard, then open the key's **Key policy** tab and replace the JSON with the policy shown here.
698692 
699693### Register and attach the key
from line 698
704698 </Step>
705699 
706700 <Step title="Attach the key to a workspace">
707 Attach the key to a new workspace before you send any requests to that workspace. For a workspace that already receives requests, the key can take [up to a day to take effect](https://platform.claude.com/docs/en/manage-claude/cmek#how-it-works). In the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. Under **Encryption key**, select the key, click **Save**, and confirm. You can also select a key when you create a workspace in the Claude Console, but only if your key policy does not yet name specific workspaces (no `EncryptionContext` condition, and the account-wide `aws:SourceArn` pattern rather than individual workspace ARNs), because the workspace's ID and compartment ID are assigned at creation. Once attached, a workspace's key can't be changed.
701 Attach the key to a new workspace before you send any requests to that workspace. For a workspace that already receives requests, the key can take [up to a day to take effect](https://platform.claude.com/docs/en/manage-claude/cmek#how-it-works). In the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. Under **Encryption key**, select the key, click **Save**, and confirm. You can also select a key when you create a workspace in the Claude Console, but only if your key policy does not yet name specific workspaces (no `EncryptionContext` condition), because the workspace's compartment ID is assigned at creation. Once attached, a workspace's key can't be changed.
708702 
709703 This is when the key is validated: the attach call checks your principal's access to the key and performs an encrypt/decrypt round against it with the workspace's compartment ID as the encryption context, so a problem with either the key policy or your principal's permissions surfaces as an error on that call. If the attach fails with a KMS access error, check the following:
710704 
711705 * The key policy names the `aws-external-anthropic.amazonaws.com` service principal and grants `kms:Encrypt`, `kms:Decrypt`, and `kms:GenerateDataKey`, plus `kms:DescribeKey` in a separate statement that has no `EncryptionContext` condition.
712 * The `aws:SourceArn` condition matches this workspace's ARN (your account ID, and the workspace if you listed specific ARNs), and any `EncryptionContext` condition includes this workspace's compartment ID.
706 * Any `EncryptionContext` condition includes this workspace's compartment ID, and any `aws:SourceArn` condition you added matches this workspace's ARN.
713707 * The key is enabled, single-region, and in the same AWS account and region as the workspace.
714708 * The principal you are signed in as has `kms:DescribeKey`, `kms:Encrypt`, and `kms:Decrypt` on the key.
715709 * No service control policy or resource control policy in your AWS organization prevents the service principal or your principal from using the key.
716 * If the policy looks right and the attach still fails, find the denied `kms:` event in CloudTrail in the key's account (it shows the calling principal and, for cryptographic calls, the encryption context), then retry with the `aws:SourceArn` condition temporarily removed to tell a source-ARN mismatch apart from an encryption-context mismatch. Once the key is attached, whether on that retry or after you correct the encryption context, restore the `ArnLike` entry on both service-principal statements with `kms:PutKeyPolicy`, using the account-wide `aws:SourceArn` pattern or the ARN of every workspace the key is attached to.
710 * If the policy looks right and the attach still fails, find the denied `kms:` event in CloudTrail in the key's account (it shows the calling principal and, for cryptographic calls, the encryption context), then correct the condition with `kms:PutKeyPolicy` and retry.
717711 </Step>
718712</Steps>
719713 

manage-claude/compliance-activity-feed Changed · +11 / -9 lines

from line 138
138138 
139139Every entry in `data` is an Activity with this top-level shape:
140140 
141| Field | Type | Description |
142| ------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
143| `id` | string | Unique identifier for the activity. |
144| `created_at` | RFC 3339 string | When the activity occurred. |
145| `organization_id` | string or null | Organization where the activity occurred, or `null` for events not tied to an organization (sign-in, sign-out, Compliance API calls). |
146| `organization_uuid` | string or null | Same scoping as `organization_id`, expressed as a UUID. |
147| `actor` | Actor union | Who or what performed the activity. See the following actor table. |
148| `type` | string | The activity type, for example `claude_chat_created`. |
149| *additional fields* | varies | Type-specific fields, for example `claude_chat_id` on chat events or `filename` on file events. See [Query compliance activities](https://platform.claude.com/docs/en/api/compliance/activities/list) in the API reference for the per-type field list. |
141| Field | Type | Description |
142| ------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
143| `id` | string | Unique identifier for the activity. |
144| `created_at` | RFC 3339 string | When the activity occurred. |
145| `organization_id` | string or null | Organization where the activity occurred, or `null` for events not tied to an organization (sign-in, sign-out, Compliance API calls). |
146| `organization_uuid` | string or null | Same scoping as `organization_id`, expressed as a UUID. |
147| `actor` | Actor union | Who or what performed the activity. See the following actor table. |
148| `type` | string | The activity type, for example `claude_chat_created`. |
149| *additional fields* | varies | Type-specific fields, for example `claude_chat_id` on chat events or `claude_file_id` on file events. See [Query compliance activities](https://platform.claude.com/docs/en/api/compliance/activities/list) in the API reference for the per-type field list. |
150150 
151151The `actor` field is a discriminated union. The `type` discriminator tells you which other fields are present:
152152 
from line 163
163163A `user_actor` activity does not always mean the user took the action. Processes that Anthropic runs on a user's behalf can currently appear as `user_actor` for the affected user rather than as `system_actor`, and this attribution may change. For example, memory activities from a migration, such as `platform_memory_store_created`, `platform_memory_created`, and `platform_memory_deleted`, are attributed this way. These migration activities currently show an `ip_address` of `0.0.0.0`.
164164 
165165A `claude_*_viewed` activity means a Claude app loaded content, not that a person viewed it. Types such as `claude_chat_viewed`, `claude_file_viewed`, and `claude_project_viewed` are recorded each time a Claude app loads the chat, file, or project from Anthropic's servers. Repeated loads are not deduplicated. The web, desktop, and mobile apps load content at different moments, sometimes in the background, and can display a cached copy without loading it. Counts of these activities vary by platform as a result, and they do not correspond to messages sent or screens viewed.
166 
167Activities about a file, project document, or artifact do not include its name or title. As of September 24, 2026, the `filename` and `title` fields on these activities are always `null`, an empty string, or omitted, including on activities recorded before that date. To look up a name or title, pass the activity's `claude_file_*`, `claude_proj_doc_*`, or `claude_artifact_version_*` ID to the matching metadata endpoint in [Retrieve files and artifacts](https://platform.claude.com/docs/en/manage-claude/compliance-content-data#retrieve-files-and-artifacts), using a Compliance Access Key with the `read:compliance_user_data` scope. You cannot look up a name or title after the file, document, or artifact is deleted, or when the activity has no such ID.
166168 
167169<Note>
168170 **Build forward-compatible handlers.** Pass through unrecognized `type` and `actor.type` values, and ignore fields your handler does not expect, so your integration keeps working when new activity types ship.

manage-claude/rate-limits-api Changed · +4 / -4 lines

from line 156
156156* **`models` list:** For `model_group` entries, the `models` field lists every model ID and alias that counts against that group's limits. Use this list to look up which group any model string falls under. For other group types, `models` is `null`.
157157* **`limits` list:** Each group carries a list of `{type, value}` pairs. The `type` field identifies the limiter (such as `requests_per_minute`, `input_tokens_per_minute`, or `output_tokens_per_minute`) and `value` is the configured limit. See [Rate limits](https://platform.claude.com/docs/en/api/rate-limits) for how each limiter is measured and enforced.
158158 
159For complete parameter details and response schemas, see the [Organization Rate Limits API reference](https://platform.claude.com/docs/en/api/admin/rate_limits/list).
159For complete parameter details and response schemas, see the [Organization Rate Limits API reference](https://platform.claude.com/docs/en/api/beta/organization/rate_limits/list).
160160 
161161### List all organization rate limits
162162 
from line 471
471471* Within a group that is present, a limiter type that is absent from `limits[]` has no workspace override for that limiter. The workspace inherits the organization value for it.
472472* For each limiter that is present, `org_limit` is the organization-level value for the same limiter, or `null` if the organization has no configured limit for that limiter type.
473473 
474For complete parameter details and response schemas, see the [Workspace Rate Limits API reference](https://platform.claude.com/docs/en/api/admin/workspaces/rate_limits/list).
474For complete parameter details and response schemas, see the [Workspace Rate Limits API reference](https://platform.claude.com/docs/en/api/beta/organization/workspaces/rate_limits/list).
475475 
476476<Tip>
477 To retrieve your organization's workspace IDs, use the [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) endpoint, or find them in the [Claude Console](https://platform.claude.com/settings/workspaces). The default workspace cannot have rate limit overrides, so it has no entry on this endpoint; use the organization endpoint to read its limits.
477 To retrieve your organization's workspace IDs, use the [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) endpoint, or find them in the [Claude Console](https://platform.claude.com/settings/workspaces). The default workspace cannot have rate limit overrides, so it has no entry on this endpoint; use the organization endpoint to read its limits.
478478</Tip>
479479 
480480<CodeGroup>
from line 809
809809 
810810* [Rate limits](https://platform.claude.com/docs/en/api/rate-limits)
811811* [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api)
812* [Admin API reference](https://platform.claude.com/docs/en/api/admin)
812* [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization)
813813* [Workspaces](https://platform.claude.com/docs/en/manage-claude/workspaces)
814814* [Usage and Cost API](https://platform.claude.com/docs/en/manage-claude/usage-cost-api)
815815 

manage-claude/spend-limits-api Changed · +10 / -10 lines

from line 114
114114 
115115`GET /v1/organizations/spend_limits/effective` returns one row per current member, reflecting each member's effective spend limit, its `source` in the scope hierarchy, and their `period_to_date_spend`. Requires the `read:spend_limits` scope.
116116 
117For complete parameter details and response schemas, see [List effective spend limits](https://platform.claude.com/docs/en/api/admin/spend_limits/list_effective) in the API reference.
117For complete parameter details and response schemas, see [List effective spend limits](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/list_effective) in the API reference.
118118 
119119```bash cURL
120120curl "https://api.anthropic.com/v1/organizations/spend_limits/effective?limit=20" \
from line 150
150150 
151151`GET /v1/organizations/spend_limits/{spend_limit_id}` returns one configured spend limit by ID. Use it to inspect the row that a `spend_limit_id` field referenced. Requires the `read:spend_limits` scope.
152152 
153For complete parameter details and response schemas, see [Retrieve a spend limit](https://platform.claude.com/docs/en/api/admin/spend_limits/retrieve) in the API reference.
153For complete parameter details and response schemas, see [Retrieve a spend limit](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/retrieve) in the API reference.
154154 
155155```bash cURL
156156curl "https://api.anthropic.com/v1/organizations/spend_limits/spl_01AbCdEfGhIjKlMnOpQrSt" \
from line 162
162162 
163163`POST /v1/organizations/spend_limits` sets a per-user spend limit override. This is an upsert keyed on `(scope, period)`: setting a limit for a user and period that already has one overwrites it in place. This endpoint accepts only `scope.type: "user"`; seat-tier, group, and organization-level defaults are configured in claude.ai settings. Requires the `write:spend_limits` scope.
164164 
165For complete parameter details and response schemas, see [Create a spend limit](https://platform.claude.com/docs/en/api/admin/spend_limits/create) in the API reference.
165For complete parameter details and response schemas, see [Create a spend limit](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/create) in the API reference.
166166 
167167```bash cURL
168168curl --request POST "https://api.anthropic.com/v1/organizations/spend_limits" \
from line 189
189189 
190190`DELETE /v1/organizations/spend_limits/{spend_limit_id}` removes a per-user override, after which the member falls back to any inherited seat-tier, group, or organization default. Seat-tier, group, and organization-level rows cannot be deleted through this endpoint. Requires the `write:spend_limits` scope.
191191 
192For complete parameter details and response schemas, see [Delete a spend limit](https://platform.claude.com/docs/en/api/admin/spend_limits/delete) in the API reference.
192For complete parameter details and response schemas, see [Delete a spend limit](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/delete) in the API reference.
193193 
194194```bash cURL
195195curl --request DELETE "https://api.anthropic.com/v1/organizations/spend_limits/spl_01RsTuVwXyZaBcDeFgHiJk" \
from line 203
203203 
204204`GET /v1/organizations/spend_limit_increase_requests` lists requests, most recent first. Filter by `status[]` (`pending`, `approved`, `denied`) and `actor_ids[]`. The list excludes requests whose requester is no longer a member of the organization. Requires the `read:spend_limits` scope.
205205 
206For complete parameter details and response schemas, see [List spend limit increase requests](https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/list) in the API reference.
206For complete parameter details and response schemas, see [List spend limit increase requests](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/list) in the API reference.
207207 
208208```bash cURL
209209curl --globoff "https://api.anthropic.com/v1/organizations/spend_limit_increase_requests?status[]=pending&limit=50" \
from line 217
217217 
218218`GET /v1/organizations/spend_limit_increase_requests/{id}` returns one request by ID. Requires the `read:spend_limits` scope.
219219 
220For complete parameter details and response schemas, see [Retrieve a spend limit increase request](https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/retrieve) in the API reference.
220For complete parameter details and response schemas, see [Retrieve a spend limit increase request](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/retrieve) in the API reference.
221221 
222222```bash cURL
223223curl "https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/slir_01AbCdEfGhIjKlMnOpQrSt" \
from line 229
229229 
230230`POST /v1/organizations/spend_limit_increase_requests/{id}/approve` approves a pending request: it writes a per-user spend limit at the admin-supplied `amount` for the requester and transitions the request to `approved`. The request does not carry a requested amount; you supply the new spend limit on approval. Requires the `write:spend_limits` scope.
231231 
232For complete parameter details and response schemas, see [Approve a spend limit increase request](https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/approve) in the API reference.
232For complete parameter details and response schemas, see [Approve a spend limit increase request](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/approve) in the API reference.
233233 
234234```bash cURL
235235curl --request POST "https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/slir_01AbCdEfGhIjKlMnOpQrSt/approve" \
from line 243
243243 
244244`POST /v1/organizations/spend_limit_increase_requests/{id}/deny` denies a pending request. Idempotent on `denied`: denying an already-denied request returns 200 with the existing resource. The endpoint rejects an attempt to deny an already-approved request so automation can distinguish a retry from a conflicting decision. Requires the `write:spend_limits` scope.
245245 
246For complete parameter details and response schemas, see [Deny a spend limit increase request](https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/deny) in the API reference.
246For complete parameter details and response schemas, see [Deny a spend limit increase request](https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/deny) in the API reference.
247247 
248248```bash cURL
249249curl --request POST "https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/slir_01AbCdEfGhIjKlMnOpQrSt/deny" \
from line 390
390390## See also
391391 
392392<CardGroup cols={2}>
393 <Card title="Spend Limits API reference" href="https://platform.claude.com/docs/en/api/admin/spend_limits">
393 <Card title="Spend Limits API reference" href="https://platform.claude.com/docs/en/api/beta/organization/spend_limits">
394394 Generated request and response schemas for every Spend Limits API endpoint.
395395 </Card>
396396 
397 <Card title="Spend Limit Increase Requests API reference" href="https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests">
397 <Card title="Spend Limit Increase Requests API reference" href="https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests">
398398 Generated request and response schemas for the increase-request endpoints.
399399 </Card>
400400 

manage-claude/usage-cost-api Changed · +10 / -10 lines

from line 32
3232 
3333Anthropic provides cost and usage reporting through two APIs, depending on which Claude product your organization manages:
3434 
35| Your organization | API | Key type |
36| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
37| Claude Console (Claude Platform) | The Usage and Cost Admin API described on this page | Admin API key (`sk-ant-admin01-...`) or another [Admin API credential](https://platform.claude.com/docs/en/manage-claude/admin-api#authentication) |
38| Claude Enterprise (claude.ai) | The [Claude Enterprise Analytics API](https://platform.claude.com/docs/en/api/admin/analytics) cost and usage endpoints | Analytics API key |
35| Your organization | API | Key type |
36| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
37| Claude Console (Claude Platform) | The Usage and Cost Admin API described on this page | Admin API key (`sk-ant-admin01-...`) or another [Admin API credential](https://platform.claude.com/docs/en/manage-claude/admin-api#authentication) |
38| Claude Enterprise (claude.ai) | The [Claude Enterprise Analytics API](https://platform.claude.com/docs/en/api/beta/organization/analytics) cost and usage endpoints | Analytics API key |
3939 
4040Claude Enterprise parent organizations do not appear in Claude Console and carry no Admin API keys, so for them the Analytics API key is the only path to this data. See [Analytics APIs](https://platform.claude.com/docs/en/manage-claude/analytics-api) for how to create each key type and which plans the Claude Enterprise cost data applies to.
4141 
from line 103
103103* **Filtering & grouping:** Filter by API key, workspace, model, service tier, context window, [data residency](https://platform.claude.com/docs/en/manage-claude/data-residency), or speed (beta), and group results by these dimensions
104104* **Server tool usage:** Track usage of server-side tools such as web search
105105 
106For complete parameter details and response schemas, see the [Usage API reference](https://platform.claude.com/docs/en/api/admin-api/usage-cost/get-messages-usage-report).
106For complete parameter details and response schemas, see the [Usage API reference](https://platform.claude.com/docs/en/api/beta/organization/usage_report/retrieve_messages).
107107 
108108### Basic examples
109109 
from line 149
149149```
150150 
151151<Tip>
152 To retrieve your organization's API key IDs, use the [List API Keys](https://platform.claude.com/docs/en/api/admin-api/apikeys/list-api-keys) endpoint.
152 To retrieve your organization's API key IDs, use the [List API Keys](https://platform.claude.com/docs/en/api/beta/organization/api_keys/list) endpoint.
153153 
154 To retrieve your organization's workspace IDs, use the [List Workspaces](https://platform.claude.com/docs/en/api/admin-api/workspaces/list-workspaces) endpoint, or find your organization's workspace IDs in the Claude Console.
154 To retrieve your organization's workspace IDs, use the [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) endpoint, or find your organization's workspace IDs in the Claude Console.
155155</Tip>
156156 
157157#### Data residency
from line 239
239239* **Grouping:** Group costs by workspace or description for detailed breakdowns. When grouping by `description`, responses include parsed fields such as `model` and `inference_geo`
240240* **Time buckets:** Daily granularity only (`1d`)
241241 
242For complete parameter details and response schemas, see the [Cost API reference](https://platform.claude.com/docs/en/api/admin-api/usage-cost/get-cost-report).
242For complete parameter details and response schemas, see the [Cost API reference](https://platform.claude.com/docs/en/api/beta/organization/cost_report/retrieve).
243243 
244244<Warning>
245245 Priority Tier costs use a different billing model and are not included in the cost endpoint. Track Priority Tier usage through the usage endpoint instead.
from line 331
331331Use the Usage and Cost APIs to deliver a better experience for your users, manage costs, and preserve your rate limit. Learn more about some of these other features:
332332 
333333* [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api)
334* [Admin API reference](https://platform.claude.com/docs/en/api/admin)
334* [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization)
335335* [Analytics APIs](https://platform.claude.com/docs/en/manage-claude/analytics-api) - Which analytics API and key type your organization needs
336336* [Pricing](https://platform.claude.com/docs/en/about-claude/pricing)
337337* [Prompt caching](https://platform.claude.com/docs/en/build-with-claude/prompt-caching) - Optimize costs with caching

manage-claude/user-management Changed · +20 / -20 lines

from line 4
44description: "Manage the people in your Claude Enterprise organization with the Admin API: list members and change roles, send and withdraw invites, manage groups, and read custom roles."
55---
66 
7This page covers managing the people in your **Claude Enterprise** (claude.ai) organization programmatically, using the [Admin API](https://platform.claude.com/docs/en/api/admin): list members and look them up by email address, change a member's role, remove members, send and withdraw invites, manage your enterprise's groups and their membership, and read your organization's custom roles. For Claude Console (Claude Platform) organizations, see the [Admin API guide for Claude Console](https://platform.claude.com/docs/en/manage-claude/admin-api).
7This page covers managing the people in your **Claude Enterprise** (claude.ai) organization programmatically, using the [Admin API](https://platform.claude.com/docs/en/api/beta/organization): list members and look them up by email address, change a member's role, remove members, send and withdraw invites, manage your enterprise's groups and their membership, and read your organization's custom roles. For Claude Console (Claude Platform) organizations, see the [Admin API guide for Claude Console](https://platform.claude.com/docs/en/manage-claude/admin-api).
88 
99<Note>
1010 Group and custom-role requests don't require the `anthropic-beta: ce-user-management-2026-07-13` [beta header](https://platform.claude.com/docs/en/api/beta-headers). Requests that still send it are accepted and behave identically.
from line 121
121121 
122122`GET /v1/organizations/users` returns the organization's members, most recently added first. Filter by `email` to look up a specific member; the match is case-insensitive and tolerates common variants of the same address (for example, `[email protected]` matches `[email protected]`). Requires the `read:members` scope.
123123 
124For complete parameter details and response schemas, see [List users](https://platform.claude.com/docs/en/api/admin/users/list) in the API reference.
124For complete parameter details and response schemas, see [List users](https://platform.claude.com/docs/en/api/beta/organization/users/list) in the API reference.
125125 
126126```bash cURL
127127curl "https://api.anthropic.com/v1/organizations/[email protected]" \
from line 133
133133 
134134`GET /v1/organizations/users/{user_id}` returns one member by ID. Requires the `read:members` scope.
135135 
136For complete parameter details and response schemas, see [Get user](https://platform.claude.com/docs/en/api/admin/users/retrieve) in the API reference.
136For complete parameter details and response schemas, see [Get user](https://platform.claude.com/docs/en/api/beta/organization/users/retrieve) in the API reference.
137137 
138138```bash cURL
139139curl "https://api.anthropic.com/v1/organizations/users/user_01AbCdEfGhIjKlMnOpQrSt" \
from line 145
145145 
146146`POST /v1/organizations/users/{user_id}` sets the member's role to `user` or `managed`. Members holding an administrative role (`owner`, `membership_admin`, or `primary_owner`) cannot be changed through this endpoint, and administrative roles cannot be assigned; both return 400 and are managed in claude.ai organization settings. If your organization's identity provider manages roles (advanced SSO or advanced SCIM provisioning), role updates return 400. Requires the `write:members` scope.
147147 
148For complete parameter details and response schemas, see [Update user](https://platform.claude.com/docs/en/api/admin/users/update) in the API reference.
148For complete parameter details and response schemas, see [Update user](https://platform.claude.com/docs/en/api/beta/organization/users/update) in the API reference.
149149 
150150```bash cURL
151151curl -X POST "https://api.anthropic.com/v1/organizations/users/user_01AbCdEfGhIjKlMnOpQrSt" \
from line 159
159159 
160160`DELETE /v1/organizations/users/{user_id}` removes the member from the organization, returning any purchased seat they occupied to the organization's pool. Members holding an administrative role cannot be removed through this endpoint, and if your identity provider manages membership (SCIM), removals return 400. Requires the `write:members` scope.
161161 
162For complete parameter details and response schemas, see [Remove user](https://platform.claude.com/docs/en/api/admin/users/delete) in the API reference.
162For complete parameter details and response schemas, see [Remove user](https://platform.claude.com/docs/en/api/beta/organization/users/remove) in the API reference.
163163 
164164```bash cURL
165165curl -X DELETE "https://api.anthropic.com/v1/organizations/users/user_01AbCdEfGhIjKlMnOpQrSt" \
from line 184
184184 
185185The optional `rbac_group_ids` field lists groups (by `rbac_group_`-prefixed ID) to assign to the member when they accept. Passing a non-empty `rbac_group_ids` additionally requires the key to carry the `write:rbac_groups` scope, because group assignment can grant the permissions attached to the group's roles.
186186 
187For complete parameter details and response schemas, see [Create invite](https://platform.claude.com/docs/en/api/admin/invites/create) in the API reference.
187For complete parameter details and response schemas, see [Create invite](https://platform.claude.com/docs/en/api/beta/organization/invites/create) in the API reference.
188188 
189189```bash cURL
190190curl -X POST "https://api.anthropic.com/v1/organizations/invites" \
from line 216
216216 
217217`GET /v1/organizations/invites` returns the organization's invites, most recent first, across the `pending`, `accepted`, and `expired` states; there is no status filter. Requires the `read:members` scope.
218218 
219For complete parameter details and response schemas, see [List invites](https://platform.claude.com/docs/en/api/admin/invites/list) in the API reference.
219For complete parameter details and response schemas, see [List invites](https://platform.claude.com/docs/en/api/beta/organization/invites/list) in the API reference.
220220 
221221```bash cURL
222222curl "https://api.anthropic.com/v1/organizations/invites?limit=20" \
from line 228
228228 
229229`GET /v1/organizations/invites/{invite_id}` returns one invite by ID. Requires the `read:members` scope.
230230 
231For complete parameter details and response schemas, see [Get invite](https://platform.claude.com/docs/en/api/admin/invites/retrieve) in the API reference.
231For complete parameter details and response schemas, see [Get invite](https://platform.claude.com/docs/en/api/beta/organization/invites/retrieve) in the API reference.
232232 
233233```bash cURL
234234curl "https://api.anthropic.com/v1/organizations/invites/invite_01QrStUvWxYzAbCdEfGhIj" \
from line 240
240240 
241241`DELETE /v1/organizations/invites/{invite_id}` withdraws a `pending` invite, deactivating the link in the invitation email. Withdrawing an `accepted` invite returns 400 (remove the member instead); withdrawing an `expired` invite returns 400. Requires the `write:members` scope.
242242 
243For complete parameter details and response schemas, see [Delete invite](https://platform.claude.com/docs/en/api/admin/invites/delete) in the API reference.
243For complete parameter details and response schemas, see [Delete invite](https://platform.claude.com/docs/en/api/beta/organization/invites/delete) in the API reference.
244244 
245245```bash cURL
246246curl -X DELETE "https://api.anthropic.com/v1/organizations/invites/invite_01QrStUvWxYzAbCdEfGhIj" \
from line 256
256256 
257257`GET /v1/organizations/rbac_groups` returns your enterprise's groups, including identity-provider-managed (`scim`) groups. Requires the `read:rbac_groups` scope.
258258 
259For complete parameter details and response schemas, see [List groups](https://platform.claude.com/docs/en/api/admin/rbac_groups/list) in the API reference.
259For complete parameter details and response schemas, see [List groups](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/list) in the API reference.
260260 
261261```bash cURL
262262curl "https://api.anthropic.com/v1/organizations/rbac_groups?limit=20" \
from line 287
287287 
288288`GET /v1/organizations/rbac_groups/{rbac_group_id}` returns one group by ID. Requires the `read:rbac_groups` scope.
289289 
290For complete parameter details and response schemas, see [Get group](https://platform.claude.com/docs/en/api/admin/rbac_groups/retrieve) in the API reference.
290For complete parameter details and response schemas, see [Get group](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/retrieve) in the API reference.
291291 
292292```bash cURL
293293curl "https://api.anthropic.com/v1/organizations/rbac_groups/rbac_group_01UvWxYzAbCdEfGhIjKlMn" \
from line 299
299299 
300300`POST /v1/organizations/rbac_groups` creates a group with the given `name` (1–255 characters) and no roles or members. Requires the `write:rbac_groups` scope.
301301 
302For complete parameter details and response schemas, see [Create group](https://platform.claude.com/docs/en/api/admin/rbac_groups/create) in the API reference.
302For complete parameter details and response schemas, see [Create group](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/create) in the API reference.
303303 
304304```bash cURL
305305curl -X POST "https://api.anthropic.com/v1/organizations/rbac_groups" \
from line 326
326326 
327327`POST /v1/organizations/rbac_groups/{rbac_group_id}` updates the group. `name` is the only field this endpoint can change. Requires the `write:rbac_groups` scope.
328328 
329For complete parameter details and response schemas, see [Update group](https://platform.claude.com/docs/en/api/admin/rbac_groups/update) in the API reference.
329For complete parameter details and response schemas, see [Update group](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/update) in the API reference.
330330 
331331```bash cURL
332332curl -X POST "https://api.anthropic.com/v1/organizations/rbac_groups/rbac_group_01UvWxYzAbCdEfGhIjKlMn" \
from line 340
340340 
341341`DELETE /v1/organizations/rbac_groups/{rbac_group_id}` deletes the group. Its members remain members of their organizations, but they lose the permissions of its attached roles, and a group [spend limit](https://platform.claude.com/docs/en/manage-claude/spend-limits-api), if one existed, stops applying to them. Requires the `write:rbac_groups` scope.
342342 
343For complete parameter details and response schemas, see [Delete group](https://platform.claude.com/docs/en/api/admin/rbac_groups/delete) in the API reference.
343For complete parameter details and response schemas, see [Delete group](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/delete) in the API reference.
344344 
345345```bash cURL
346346curl -X DELETE "https://api.anthropic.com/v1/organizations/rbac_groups/rbac_group_01UvWxYzAbCdEfGhIjKlMn" \
from line 359
359359 
360360`GET /v1/organizations/rbac_groups/{rbac_group_id}/members` returns the group's members (each with their `user_id` and email), oldest first. Only current members of your enterprise's organizations are returned, so a page might contain fewer than `limit` entries while `has_more` is `true`. Requires the `read:rbac_groups` scope.
361361 
362For complete parameter details and response schemas, see [List group members](https://platform.claude.com/docs/en/api/admin/rbac_groups/members/list) in the API reference.
362For complete parameter details and response schemas, see [List group members](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/members/list) in the API reference.
363363 
364364```bash cURL
365365curl "https://api.anthropic.com/v1/organizations/rbac_groups/rbac_group_01UvWxYzAbCdEfGhIjKlMn/members?limit=100" \
from line 388
388388 
389389`POST /v1/organizations/rbac_groups/{rbac_group_id}/members` adds an organization member to the group by `user_id`. The user must already be a member of one of your enterprise's organizations (the request returns 404 otherwise), and adding someone who is already in the group returns 400. For `scim` groups, membership is managed in your identity provider and this request returns 400. To assign groups to a person who has not joined yet, use `rbac_group_ids` on [invite creation](https://platform.claude.com/docs/en/manage-claude/user-management#create-an-invite) instead. Requires the `write:rbac_groups` scope.
390390 
391For complete parameter details and response schemas, see [Add group member](https://platform.claude.com/docs/en/api/admin/rbac_groups/members/create) in the API reference.
391For complete parameter details and response schemas, see [Add group member](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/members/create) in the API reference.
392392 
393393```bash cURL
394394curl -X POST "https://api.anthropic.com/v1/organizations/rbac_groups/rbac_group_01UvWxYzAbCdEfGhIjKlMn/members" \
from line 413
413413 
414414`DELETE /v1/organizations/rbac_groups/{rbac_group_id}/members/{user_id}` removes the member from the group; they remain a member of their organization. The request returns 404 if the user is not a member of the group, and 400 for `scim` groups, whose membership is managed in your identity provider. Requires the `write:rbac_groups` scope.
415415 
416For complete parameter details and response schemas, see [Remove group member](https://platform.claude.com/docs/en/api/admin/rbac_groups/members/delete) in the API reference.
416For complete parameter details and response schemas, see [Remove group member](https://platform.claude.com/docs/en/api/beta/organization/rbac_groups/members/delete) in the API reference.
417417 
418418```bash cURL
419419curl -X DELETE "https://api.anthropic.com/v1/organizations/rbac_groups/rbac_group_01UvWxYzAbCdEfGhIjKlMn/members/user_01AbCdEfGhIjKlMnOpQrSt" \
from line 438
438438 
439439`GET /v1/organizations/rbac_roles` returns your organization's custom roles. Requires the `read:members` scope.
440440 
441For complete parameter details and response schemas, see [List roles](https://platform.claude.com/docs/en/api/admin/rbac_roles/list) in the API reference.
441For complete parameter details and response schemas, see [List roles](https://platform.claude.com/docs/en/api/beta/organization/rbac_roles/list) in the API reference.
442442 
443443```bash cURL
444444curl "https://api.anthropic.com/v1/organizations/rbac_roles?limit=20" \
from line 466
466466 
467467`GET /v1/organizations/rbac_roles/{rbac_role_id}` returns one role by ID. Requires the `read:members` scope.
468468 
469For complete parameter details and response schemas, see [Get role](https://platform.claude.com/docs/en/api/admin/rbac_roles/retrieve) in the API reference.
469For complete parameter details and response schemas, see [Get role](https://platform.claude.com/docs/en/api/beta/organization/rbac_roles/retrieve) in the API reference.
470470 
471471```bash cURL
472472curl "https://api.anthropic.com/v1/organizations/rbac_roles/rbac_role_01CdEfGhIjKlMnOpQrStUv" \
from line 480
480480 
481481Two `action` values need special care: an `organization` permission whose action is `capability_access_all` (every product feature) or `capability_access_all_ga` (every stable product feature, that is, every feature not labeled beta or research preview) is a blanket grant (one that covers neither model access nor the `permission_`-prefixed admin-panel permissions) and is listed as that single row rather than expanded. When you tally what a role grants, treat a blanket row as covering everything its variant describes, not just the features named in other rows.
482482 
483For complete parameter details and response schemas, see [List role permissions](https://platform.claude.com/docs/en/api/admin/rbac_roles/permissions/list) in the API reference.
483For complete parameter details and response schemas, see [List role permissions](https://platform.claude.com/docs/en/api/beta/organization/rbac_roles/permissions/list) in the API reference.
484484 
485485```bash cURL
486486curl "https://api.anthropic.com/v1/organizations/rbac_roles/rbac_role_01CdEfGhIjKlMnOpQrStUv/permissions?limit=20" \

manage-claude/wif-admin-api Changed · +4 / -4 lines

from line 485
485485 
486486To read or update a single service account, use `GET` and `POST` on `/v1/organizations/service_accounts/{service_account_id}`. A service account must be a member of a workspace before federated tokens can act in it. Every service account has an implicit membership in your organization's default workspace; add explicit memberships for other workspaces with `GET`, `POST`, and `DELETE` on `/v1/organizations/service_accounts/{service_account_id}/workspaces`, where `DELETE` targets `.../workspaces/{workspace_id}`.
487487 
488For complete parameter details and response schemas, see the [Service accounts API reference](https://platform.claude.com/docs/en/api/admin/service_accounts).
488For complete parameter details and response schemas, see the [Service accounts API reference](https://platform.claude.com/docs/en/api/beta/organization/service_accounts).
489489 
490490## Federation issuers
491491 
from line 824
824824 
825825To read or update a single issuer, use `GET` and `POST` on `/v1/organizations/federation_issuers/{issuer_id}`. An OAuth caller cannot update an issuer that backs a rule whose `oauth_scope` is anything other than `workspace:developer` or `workspace:inference`; see [Permissions and constraints](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#permissions-and-constraints).
826826 
827For complete parameter details and response schemas, see the [Federation issuers API reference](https://platform.claude.com/docs/en/api/admin/federation_issuers).
827For complete parameter details and response schemas, see the [Federation issuers API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/issuers).
828828 
829829## Federation rules
830830 
from line 1256
12561256 
12571257To read or update a single rule, use `GET` and `POST` on `/v1/organizations/federation_rules/{rule_id}`. To manage the workspaces a rule can mint tokens in, use `GET` and `POST` on `/v1/organizations/federation_rules/{rule_id}/workspaces`, and `DELETE` on `/v1/organizations/federation_rules/{rule_id}/workspaces/{workspace_id}`.
12581258 
1259For complete parameter details and response schemas, see the [Federation rules API reference](https://platform.claude.com/docs/en/api/admin/federation_rules).
1259For complete parameter details and response schemas, see the [Federation rules API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/rules).
12601260 
12611261## Permissions and constraints
12621262 
from line 1279
12791279* [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation): concepts and the Console setup walkthrough
12801280* [WIF reference](https://platform.claude.com/docs/en/manage-claude/wif-reference): environment variables, validation rules, OAuth scopes, and error codes
12811281* [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api): the rest of the organization management surface
1282* [Admin API reference](https://platform.claude.com/docs/en/api/admin): generated request and response schemas for every Admin API endpoint
1282* [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization): generated request and response schemas for every Admin API endpoint
12831283 

manage-claude/wif-reference Changed · +12 / -12 lines

from line 123
123123 
124124| Scope | Grants access to |
125125| -------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
126| `workspace:developer` | All non-administrative Claude API endpoints in the rule's workspace: [Messages](https://platform.claude.com/docs/en/api/messages) (including streaming and token counting), [Models](https://platform.claude.com/docs/en/api/models-list), [Managed Agents](https://platform.claude.com/docs/en/managed-agents/overview) and their sessions, [Files](https://platform.claude.com/docs/en/build-with-claude/files), and [Skills](https://platform.claude.com/docs/en/build-with-claude/skills-guide). This matches the access a workspace API key in the same workspace has. |
127| `workspace:inference` | The inference endpoints in the rule's workspace: [Messages](https://platform.claude.com/docs/en/api/messages) (including streaming and token counting), [Models](https://platform.claude.com/docs/en/api/models-list), and the [OpenAI-compatible chat endpoint](https://platform.claude.com/docs/en/cli-sdks-libraries/libraries/openai-sdk). Use this for workloads that only need to call Claude and never need to manage Files, Skills, or other resources. |
126| `workspace:developer` | All non-administrative Claude API endpoints in the rule's workspace: [Messages](https://platform.claude.com/docs/en/api/messages) (including streaming and token counting), [Models](https://platform.claude.com/docs/en/api/models/list), [Managed Agents](https://platform.claude.com/docs/en/managed-agents/overview) and their sessions, [Files](https://platform.claude.com/docs/en/build-with-claude/files), and [Skills](https://platform.claude.com/docs/en/build-with-claude/skills-guide). This matches the access a workspace API key in the same workspace has. |
127| `workspace:inference` | The inference endpoints in the rule's workspace: [Messages](https://platform.claude.com/docs/en/api/messages) (including streaming and token counting), [Models](https://platform.claude.com/docs/en/api/models/list), and the [OpenAI-compatible chat endpoint](https://platform.claude.com/docs/en/cli-sdks-libraries/libraries/openai-sdk). Use this for workloads that only need to call Claude and never need to manage Files, Skills, or other resources. |
128128| `workspace:manage_tunnels` | The [MCP tunnels API](https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/reference#tunnels-api): create, list, and get tunnels, register and archive CA certificates, reveal and rotate the tunnel token, and archive tunnels. The Console's create-tunnel modal window locks this scope when you create a rule from it. |
129129| `org:admin` | Full access to the [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api) (organization members, invites, workspaces, API keys, and the rest). An OAuth `org:admin` token can only create or modify rules scoped to `workspace:developer` or `workspace:inference`, and cannot update an issuer that backs a rule with any other scope; see the [constraints](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#permissions-and-constraints). |
130130 
from line 143
143143 
144144Anthropic enforces these constraints when you create or update issuers and rules, and when verifying an incoming JWT at exchange time.
145145 
146For complete parameter details and response schemas, see the [Service accounts API reference](https://platform.claude.com/docs/en/api/admin/service_accounts), [Federation issuers API reference](https://platform.claude.com/docs/en/api/admin/federation_issuers), and [Federation rules API reference](https://platform.claude.com/docs/en/api/admin/federation_rules).
146For complete parameter details and response schemas, see the [Service accounts API reference](https://platform.claude.com/docs/en/api/beta/organization/service_accounts), [Federation issuers API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/issuers), and [Federation rules API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/rules).
147147 
148148### Resource fields
149149 
from line 172
172172 
173173### JWT verification
174174 
175| Constraint | Detail |
176| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
177| Maximum size | The `assertion` JWT must be at most 16 KiB. |
178| Signing algorithm | Only asymmetric algorithms (RSA and ECDSA families: ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512) are accepted. HMAC (`HS256`, `HS384`, `HS512`) and `none` are rejected. |
179| Key ID | The JWT header must carry a `kid` that matches a key in the issuer's JWKS. Tokens without `kid` are rejected. |
180| Required claims | `sub` must be present. `iat` must be present and not in the future. `exp` must be present and in the future. |
181| Single use | An assertion that carries a `jti` claim can be exchanged only once per issuer: repeating an exchange with the same `jti` is rejected as a replay. The issuer's `check_jti` field (enabled by default) controls this check; assertions without a `jti` claim are not subject to it. See the [Federation issuers API reference](https://platform.claude.com/docs/en/api/admin/federation_issuers). |
182| Maximum lifetime | The token's lifetime (`exp` minus `iat`) must not exceed the issuer's configured maximum (1 hour by default, configurable for each issuer in the Claude Console). |
183| Clock skew | A 30-second leeway is applied to `exp`, `nbf`, and `iat`. |
175| Constraint | Detail |
176| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
177| Maximum size | The `assertion` JWT must be at most 16 KiB. |
178| Signing algorithm | Only asymmetric algorithms (RSA and ECDSA families: ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512) are accepted. HMAC (`HS256`, `HS384`, `HS512`) and `none` are rejected. |
179| Key ID | The JWT header must carry a `kid` that matches a key in the issuer's JWKS. Tokens without `kid` are rejected. |
180| Required claims | `sub` must be present. `iat` must be present and not in the future. `exp` must be present and in the future. |
181| Single use | An assertion that carries a `jti` claim can be exchanged only once per issuer: repeating an exchange with the same `jti` is rejected as a replay. The issuer's `check_jti` field (enabled by default) controls this check; assertions without a `jti` claim are not subject to it. See the [Federation issuers API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/issuers). |
182| Maximum lifetime | The token's lifetime (`exp` minus `iat`) must not exceed the issuer's configured maximum (1 hour by default, configurable for each issuer in the Claude Console). |
183| Clock skew | A 30-second leeway is applied to `exp`, `nbf`, and `iat`. |
184184 
185185## Rule matching semantics
186186 

manage-claude/workspaces Changed · +7 / -7 lines

from line 14
1414 
1515* **Workspace identifiers** use the `wrkspc_` prefix (for example, `wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ`)
1616* **Maximum 100 workspaces** per organization by default (archived workspaces don't count); contact your account team if you need more
17* **Default Workspace** has a `wrkspc_` ID like any other workspace (returned in the [`anthropic-workspace-id` response header](https://platform.claude.com/docs/en/manage-claude/workspaces#identify-the-workspace-behind-an-api-response) and accepted by [Get Workspace](https://platform.claude.com/docs/en/api/admin/workspaces/retrieve)), but it doesn't appear in [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) results, and API keys, usage reports, and cost reports show `null` for its `workspace_id`, as do all-workspaces API keys (an API key's `scope` field tells them apart; for a key bound to the Default Workspace it carries the real ID)
17* **Default Workspace** has a `wrkspc_` ID like any other workspace (returned in the [`anthropic-workspace-id` response header](https://platform.claude.com/docs/en/manage-claude/workspaces#identify-the-workspace-behind-an-api-response) and accepted by [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve)), but it doesn't appear in [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) results, and API keys, usage reports, and cost reports show `null` for its `workspace_id`, as do all-workspaces API keys (an API key's `scope` field tells them apart; for a key bound to the Default Workspace it carries the real ID)
1818* **API keys** can be scoped to a single workspace. In this case, they can only access resources within that workspace. Some API keys can be granted permissions across multiple workspaces, and provide a [workspace ID header](https://platform.claude.com/docs/en/manage-claude/authentication#select-a-workspace) to access resources within that workspace
1919 
2020### Claude Code workspace
from line 438
438438 ```
439439</CodeGroup>
440440 
441For complete parameter details and response schemas, see the [Workspaces API reference](https://platform.claude.com/docs/en/api/admin/workspaces/retrieve).
441For complete parameter details and response schemas, see the [Workspaces API reference](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve).
442442 
443443### Managing workspace members
444444 
from line 816
816816 ```
817817</CodeGroup>
818818 
819For complete parameter details, see the [Workspace Members API reference](https://platform.claude.com/docs/en/api/admin/workspaces/members/retrieve).
819For complete parameter details, see the [Workspace Members API reference](https://platform.claude.com/docs/en/api/beta/organization/workspaces/members/retrieve).
820820 
821821## API keys and resource scoping
822822 
from line 836
836836* **[MCP tunnels](https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/overview)** are managed with a `workspace:manage_tunnels` OAuth token obtained through [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation), not an API key. Tunnels are created in a workspace, and the Console **MCP tunnels** list and the Managed Agent server picker show tunnels in the current workspace only; the cap of 10 active tunnels applies organization-wide. Tunnel management requires a role with tunnel management permissions; organization developers can view but not change them.
837837* **Workspaces** themselves and **organization members** are managed at the organization level through the [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api), using an Admin API key, an `org:admin` OAuth token, or a personal or service account key that isn't scoped to a specific workspace.
838838 
839To look up your organization's workspace IDs, call the [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) endpoint or find them in the [Claude Console](https://platform.claude.com/settings/workspaces).
839To look up your organization's workspace IDs, call the [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) endpoint or find them in the [Claude Console](https://platform.claude.com/settings/workspaces).
840840 
841841<Note>
842842 [Prompt caches](https://platform.claude.com/docs/en/build-with-claude/prompt-caching) are also isolated per workspace on the Claude API, [Claude Platform on AWS](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws), and [Microsoft Foundry](https://platform.claude.com/docs/en/build-with-claude/claude-in-microsoft-foundry). On Amazon Bedrock and Google Cloud, prompt caches are isolated per organization.
from line 1008
10081008 
10091009* Confirm which workspace's usage, cost, and [rate limits](https://platform.claude.com/docs/en/api/rate-limits) the request counted toward
10101010* Match it against the `workspace_id` field in [Usage and Cost API](https://platform.claude.com/docs/en/manage-claude/usage-cost-api) reports and on [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api) objects such as API keys (both report `null` for the Default Workspace, as API keys also do for all-workspaces keys; an API key's `scope` field tells the two apart and, for a key bound to one workspace, carries that workspace's real ID)
1011* Check whether it's your Default Workspace's ID by passing it to [Get Workspace](https://platform.claude.com/docs/en/api/admin/workspaces/retrieve) with an [Admin API key](https://platform.claude.com/docs/en/manage-claude/admin-api-keys): the Default Workspace comes back with `"name": "Default"`, even though [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) omits it
1011* Check whether it's your Default Workspace's ID by passing it to [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) with an [Admin API key](https://platform.claude.com/docs/en/manage-claude/admin-api-keys): the Default Workspace comes back with `"name": "Default"`, even though [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) omits it
10121012* Open that workspace in the [Console](https://platform.claude.com/settings/workspaces) to find the request's resources, such as sessions, files, message batches, and skills
10131013 
10141014## Workspace limits
from line 1099
10991099 
11001100<AccordionGroup>
11011101 <Accordion title="What's the Default Workspace?">
1102 Every organization has a "Default Workspace" that cannot be renamed, archived, or deleted. Like every workspace, it has a `wrkspc_` ID: the API returns it in the [`anthropic-workspace-id` response header](https://platform.claude.com/docs/en/manage-claude/workspaces#identify-the-workspace-behind-an-api-response), and you can pass it to [Get Workspace](https://platform.claude.com/docs/en/api/admin/workspaces/retrieve) and [Update Workspace](https://platform.claude.com/docs/en/api/admin/workspaces/update). It has no member list of its own, because access to it follows each member's organization role. It doesn't appear in [List Workspaces](https://platform.claude.com/docs/en/api/admin/workspaces/list) results, and API keys, usage reports, and cost reports that belong to it show `null` for `workspace_id`, as do all-workspaces API keys; an API key's `scope` field tells the two apart and, for a key that belongs to the Default Workspace, carries its real ID.
1102 Every organization has a "Default Workspace" that cannot be renamed, archived, or deleted. Like every workspace, it has a `wrkspc_` ID: the API returns it in the [`anthropic-workspace-id` response header](https://platform.claude.com/docs/en/manage-claude/workspaces#identify-the-workspace-behind-an-api-response), and you can pass it to [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) and [Update Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/update). It has no member list of its own, because access to it follows each member's organization role. It doesn't appear in [List Workspaces](https://platform.claude.com/docs/en/api/beta/organization/workspaces/list) results, and API keys, usage reports, and cost reports that belong to it show `null` for `workspace_id`, as do all-workspaces API keys; an API key's `scope` field tells the two apart and, for a key that belongs to the Default Workspace, carries its real ID.
11031103 </Accordion>
11041104 
11051105 <Accordion title="What's the Claude Code workspace?">
from line 1138
11381138## See also
11391139 
11401140* [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api)
1141* [Admin API reference](https://platform.claude.com/docs/en/api/admin)
1141* [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization)
11421142* [Rate limits](https://platform.claude.com/docs/en/api/rate-limits)
11431143* [Usage and Cost API](https://platform.claude.com/docs/en/manage-claude/usage-cost-api)
11441144 

managed-agents/agent-setup Changed · +8 / -10 lines

from line 54
5454 AGENT_VERSION=$(jq -r '.version' <<< "$agent")
5555 ```
5656 
57 <MultiFileExample language="cli" label="CLI">
57 <CodeGroupItem>
5858 ```bash CLI
5959 ant apply coding-assistant.md
6060 ```
from line 71
7171 You are a helpful coding agent.
7272 ```
7373 </File>
74 </MultiFileExample>
7574 
75 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the agent from `coding-assistant.md`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this agent instead of creating a second one.
76 </CodeGroupItem>
77 
7678 ```python Python
7779 agent = client.beta.agents.create(
7880 name="Coding Assistant",
from line 165
163165 tools: [{type: "agent_toolset_20260401"}]
164166 )
165167 ```
166 
167 <ForLanguage tab="CLI">
168 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the agent from `coding-assistant.md`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this agent instead of creating a second one.
169 </ForLanguage>
170168</CodeGroup>
171169 
172170The response echoes your configuration and adds `id`, `type`, `version`, `created_at`, `updated_at`, and `archived_at` fields, and fills in `model` fields you omit, such as `effort`, with their defaults. The `version` starts at 1 and increments each time an update changes the agent.
from line 232
234232 echo "Inference geo: $(jq -r '.model.inference_geo' <<< "$agent")"
235233 ```
236234 
237 <MultiFileExample language="cli" label="CLI">
235 <CodeGroupItem>
238236 ```bash CLI
239237 ant apply geo-pinned-assistant.md
240238 ```
from line 249
251249 You are a helpful assistant.
252250 ```
253251 </File>
254 </MultiFileExample>
252 </CodeGroupItem>
255253 
256254 ```python Python
257255 agent = client.beta.agents.create(
from line 374
376374 echo "New version: $(jq -r '.version' <<< "$updated_agent")"
377375 ```
378376 
379 <MultiFileExample language="cli" label="CLI">
377 <CodeGroupItem>
380378 ```bash CLI
381379 ant apply coding-assistant.md
382380 ```
from line 391
393391 You are a helpful coding agent. Always write tests.
394392 ```
395393 </File>
396 </MultiFileExample>
394 </CodeGroupItem>
397395 
398396 ```python Python
399397 updated_agent = client.beta.agents.update(

managed-agents/environments Changed · +30 / -11 lines

#### Package manager hosts

from line 34
3434 EOF
3535 ```
3636 
37 <MultiFileExample language="cli" label="CLI">
37 <CodeGroupItem>
3838 ```bash CLI
3939 ant apply environment.yaml
4040 ```
from line 49
4949 type: unrestricted
5050 ```
5151 </File>
52 </MultiFileExample>
5352 
53 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the environment from `environment.yaml`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this environment instead of trying to create it again.
54 </CodeGroupItem>
55 
5456 ```python Python
5557 environment = client.beta.environments.create(
5658 name="python-dev",
from line 137
135137 
136138 puts "Environment ID: #{environment.id}"
137139 ```
138 
139 <ForLanguage tab="CLI">
140 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the environment from `environment.yaml`, prints its ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` updates this environment instead of trying to create it again.
141 </ForLanguage>
142140</CodeGroup>
143141 
144142Use a unique, descriptive `name` so you can tell environments apart.
from line 248
250248 EOF
251249 ```
252250 
253 <MultiFileExample language="cli" label="CLI">
251 <CodeGroupItem>
254252 ```bash CLI
255253 ant apply environment.yaml
256254 ```
from line 270
272270 type: unrestricted
273271 ```
274272 </File>
275 </MultiFileExample>
273 </CodeGroupItem>
276274 
277275 ```python Python
278276 environment = client.beta.environments.create(
from line 427
429427 }'
430428 ```
431429 
432 <MultiFileExample language="cli" label="CLI">
430 <CodeGroupItem>
433431 ```bash CLI
434432 ant apply environment.yaml
435433 ```
from line 446
448446 allow_package_managers: true
449447 ```
450448 </File>
451 </MultiFileExample>
449 </CodeGroupItem>
452450 
453451 ```python Python
454452 environment = client.beta.environments.create(
from line 572
574572 
575573* `allowed_hosts` specifies domains the sandbox can reach. Specify bare hostnames or wildcard patterns (such as `*.example.com`). Do not include a URL scheme, port, or path.
576574* `allow_mcp_servers` allows outbound access to MCP server endpoints configured on the agent, beyond those listed in the `allowed_hosts` array. Defaults to `false`.
577* `allow_package_managers` allows outbound access to public package registries (such as PyPI and npm) beyond those listed in the `allowed_hosts` array. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
575* `allow_package_managers` allows outbound access to a set of public package registries and code hosts beyond those listed in the `allowed_hosts` array. See [Package manager hosts](https://platform.claude.com/docs/en/managed-agents/environments#package-manager-hosts) for the list. Defaults to `false`. Set it to `true` whenever the environment specifies `packages`; otherwise the request is rejected with a 400 error, even if the registry hosts are listed in `allowed_hosts`.
576 
577#### Package manager hosts
578 
579When `allow_package_managers` is `true`, the sandbox can reach the following hosts in addition to those in `allowed_hosts`. Anthropic maintains this list and can change it.
580 
581| Ecosystem | Hosts |
582| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
583| Code hosting | `github.com`, `api.github.com`, `codeload.github.com`, `raw.githubusercontent.com`, `objects.githubusercontent.com`, `release-assets.githubusercontent.com`, `gitlab.com`, `bitbucket.org` |
584| Node.js | `registry.npmjs.org`, `registry.yarnpkg.com`, `nodejs.org` |
585| Python | `pypi.org`, `files.pythonhosted.org` |
586| Rust | `crates.io`, `index.crates.io`, `static.crates.io`, `static.rust-lang.org` |
587| Go | `proxy.golang.org`, `sum.golang.org` |
588| Java | `repo1.maven.org`, `repo.maven.apache.org`, `services.gradle.org`, `plugins.gradle.org`, `plugins-artifacts.gradle.org` |
589| Ruby | `rubygems.org`, `index.rubygems.org` |
590| PHP | `packagist.org`, `repo.packagist.org` |
591| Ubuntu (apt) | `archive.ubuntu.com`, `security.ubuntu.com`, `ppa.launchpad.net` |
592| Containers | `registry-1.docker.io`, `auth.docker.io`, `production.cloudflare.docker.com`, `download.docker.com`, `ghcr.io` |
593 
594<Warning>
595 Network access is granted per host, not per operation. The sandbox can send any request to an allowed host, including uploads such as `git push` and package publishing, with any credential the command supplies. If the agent processes untrusted input (repository files, fetched web content, or third-party tool output), a successful prompt injection could use an allowed host to copy files out of the sandbox. To reduce this risk, set the `bash` tool's [permission policy](https://platform.claude.com/docs/en/managed-agents/permission-policies) to `always_ask` or `auto`. If the environment does not specify `packages`, you can instead leave `allow_package_managers` set to `false` and list only the hosts your agent needs in `allowed_hosts`.
596</Warning>
578597 
579598## Environment lifecycle
580599 

managed-agents/migration Changed · +4 / -4 lines

from line 302
302302 kill "${stream_pid}" 2>/dev/null || true
303303 ```
304304 
305 <MultiFileExample language="cli" label="CLI">
305 <CodeGroupItem>
306306 ```bash CLI
307307 ant apply agent.md
308308 
from line 336
336336 ---
337337 ```
338338 </File>
339 </MultiFileExample>
339 </CodeGroupItem>
340340 
341341 ```python Python
342342 agent = client.beta.agents.create(
from line 1361
13611361 --json "$(jq -n --argjson version "$AGENT_VERSION" '{version: $version, model: "claude-opus-5-5"}')"
13621362 ```
13631363 
1364 <MultiFileExample language="cli" label="CLI">
1364 <CodeGroupItem>
13651365 ```bash CLI
13661366 ant apply agent.md
13671367 ```
from line 1378
13781378 You are a task automation agent. Complete the task you are given end to end.
13791379 ```
13801380 </File>
1381 </MultiFileExample>
1381 </CodeGroupItem>
13821382 
13831383 ```python Python
13841384 client.beta.agents.update(

managed-agents/multiagent-orchestration Changed · +4 / -4 lines

from line 65
6565 )
6666 ```
6767 
68 <MultiFileExample language="cli" label="CLI">
68 <CodeGroupItem>
6969 ```bash CLI
7070 ant apply engineering-lead.md reviewer.md test-writer.md
7171 ```
from line 109
109109 You write unit tests.
110110 ```
111111 </File>
112 </MultiFileExample>
112 </CodeGroupItem>
113113 
114114 ```python Python
115115 coordinator = client.beta.agents.create(
from line 445
445445 )
446446 ```
447447 
448 <MultiFileExample language="cli" label="CLI">
448 <CodeGroupItem>
449449 ```bash CLI
450450 ant apply coordinator.md researcher.md
451451 ```
from line 480
480480 ---
481481 ```
482482 </File>
483 </MultiFileExample>
483 </CodeGroupItem>
484484 
485485 ```python Python
486486 research_agent = client.beta.agents.create(

managed-agents/permission-policies Changed · +8 / -8 lines

from line 53
5353 }')
5454 ```
5555 
56 <MultiFileExample language="cli" label="CLI">
56 <CodeGroupItem>
5757 ```bash CLI
5858 ant apply agent.md
5959 ```
from line 71
7171 ---
7272 ```
7373 </File>
74 </MultiFileExample>
74 </CodeGroupItem>
7575 
7676 ```python Python
7777 agent = client.beta.agents.create(
from line 245
245245 }')
246246 ```
247247 
248 <MultiFileExample language="cli" label="CLI">
248 <CodeGroupItem>
249249 ```bash CLI
250250 ant apply agent.md
251251 ```
from line 269
269269 ---
270270 ```
271271 </File>
272 </MultiFileExample>
272 </CodeGroupItem>
273273 
274274 ```python Python
275275 agent = client.beta.agents.create(
from line 495
495495 ]'
496496 ```
497497 
498 <MultiFileExample language="cli" label="CLI">
498 <CodeGroupItem>
499499 ```bash CLI
500500 ant apply agent.md
501501 ```
from line 517
517517 ---
518518 ```
519519 </File>
520 </MultiFileExample>
520 </CodeGroupItem>
521521 
522522 ```python Python
523523 tools = [
from line 721
721721 }')
722722 ```
723723 
724 <MultiFileExample language="cli" label="CLI">
724 <CodeGroupItem>
725725 ```bash CLI
726726 ant apply agent.md
727727 ```
from line 752
752752 ---
753753 ```
754754 </File>
755 </MultiFileExample>
755 </CodeGroupItem>
756756 
757757 ```python Python
758758 agent = client.beta.agents.create(

managed-agents/quickstart Changed · +349 / -297 lines

The two sides of this change are more than 400 edits apart, too far apart to line up, so this is the differ's own diff of it and the words inside a line are not marked.

from line 136
136136 Create an agent that defines the model, system prompt, and available tools.
137137 
138138 <CodeGroup defaultLanguage="CLI">
139 ```bash cURL
140 set -euo pipefail
141 
142 agent=$(
143 curl -sS --fail-with-body https://api.anthropic.com/v1/agents \
144 -H "x-api-key: $ANTHROPIC_API_KEY" \
145 -H "anthropic-version: 2023-06-01" \
146 -H "anthropic-beta: managed-agents-2026-04-01" \
147 -H "content-type: application/json" \
148 -d @- <<'EOF'
149 {
150 "name": "Coding Assistant",
151 "model": "claude-opus-5-5",
152 "system": "You are a helpful coding assistant. Write clean, well-documented code.",
153 "tools": [
154 {"type": "agent_toolset_20260401"}
155 ]
156 }
157 EOF
158 )
159 
160 AGENT_ID=$(jq -er '.id' <<<"$agent")
161 AGENT_VERSION=$(jq -er '.version' <<<"$agent")
162 
163 echo "Agent ID: $AGENT_ID, version: $AGENT_VERSION"
164 ```
165 
166 <MultiFileExample language="cli" label="CLI">
139 <CodeGroupItem>
140 ```bash cURL
141 set -euo pipefail
142 
143 agent=$(
144 curl -sS --fail-with-body https://api.anthropic.com/v1/agents \
145 -H "x-api-key: $ANTHROPIC_API_KEY" \
146 -H "anthropic-version: 2023-06-01" \
147 -H "anthropic-beta: managed-agents-2026-04-01" \
148 -H "content-type: application/json" \
149 -d @- <<'EOF'
150 {
151 "name": "Coding Assistant",
152 "model": "claude-opus-5-5",
153 "system": "You are a helpful coding assistant. Write clean, well-documented code.",
154 "tools": [
155 {"type": "agent_toolset_20260401"}
156 ]
157 }
158 EOF
159 )
160 
161 AGENT_ID=$(jq -er '.id' <<<"$agent")
162 AGENT_VERSION=$(jq -er '.version' <<<"$agent")
163 
164 echo "Agent ID: $AGENT_ID, version: $AGENT_VERSION"
165 ```
166 
167 Save the returned `agent.id`. You'll reference it in every session you create.
168 </CodeGroupItem>
169 
170 <CodeGroupItem>
167171 ```bash CLI
168172 ant apply coding-assistant.md
169173 ```
from line 184
180184 You are a helpful coding assistant. Write clean, well-documented code.
181185 ```
182186 </File>
183 </MultiFileExample>
184 
185 <ForLanguage tab="CLI">
187 
186188 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) prints the agent's ID and records it in `claude-lock.json`. You'll reference it in every session you create.
187 </ForLanguage>
188 
189 ```python Python
190 from anthropic import Anthropic
191 
192 client = Anthropic()
193 
194 agent = client.beta.agents.create(
195 name="Coding Assistant",
196 model="claude-opus-5-5",
197 system="You are a helpful coding assistant. Write clean, well-documented code.",
198 tools=[
199 {"type": "agent_toolset_20260401"},
189 </CodeGroupItem>
190 
191 <CodeGroupItem>
192 ```python Python
193 from anthropic import Anthropic
194 
195 client = Anthropic()
196 
197 agent = client.beta.agents.create(
198 name="Coding Assistant",
199 model="claude-opus-5-5",
200 system="You are a helpful coding assistant. Write clean, well-documented code.",
201 tools=[
202 {"type": "agent_toolset_20260401"},
203 ],
204 )
205 
206 print(f"Agent ID: {agent.id}, version: {agent.version}")
207 ```
208 
209 Save the returned `agent.id`. You'll reference it in every session you create.
210 </CodeGroupItem>
211 
212 <CodeGroupItem>
213 ```typescript TypeScript
214 import Anthropic from "@anthropic-ai/sdk";
215 
216 const client = new Anthropic();
217 
218 const agent = await client.beta.agents.create({
219 name: "Coding Assistant",
220 model: "claude-opus-5-5",
221 system: "You are a helpful coding assistant. Write clean, well-documented code.",
222 tools: [
223 { type: "agent_toolset_20260401" },
200224 ],
201 )
202 
203 print(f"Agent ID: {agent.id}, version: {agent.version}")
204 ```
205 
206 ```typescript TypeScript
207 import Anthropic from "@anthropic-ai/sdk";
208 
209 const client = new Anthropic();
210 
211 const agent = await client.beta.agents.create({
212 name: "Coding Assistant",
213 model: "claude-opus-5-5",
214 system: "You are a helpful coding assistant. Write clean, well-documented code.",
215 tools: [
216 { type: "agent_toolset_20260401" },
217 ],
218 });
219 
220 console.log(`Agent ID: ${agent.id}, version: ${agent.version}`);
221 ```
222 
223 ```csharp C#
224 using Anthropic;
225 using Anthropic.Models.Beta.Agents;
226 using Anthropic.Models.Beta.Environments;
227 using Anthropic.Models.Beta.Sessions;
228 using Anthropic.Models.Beta.Sessions.Events;
229 
230 var client = new AnthropicClient();
231 
232 var agent = await client.Beta.Agents.Create(new()
233 {
234 Name = "Coding Assistant",
235 Model = BetaManagedAgentsModel.ClaudeOpus5_5,
236 System = "You are a helpful coding assistant. Write clean, well-documented code.",
237 Tools =
238 [
239 new BetaManagedAgentsAgentToolset20260401Params
240 {
241 Type = "agent_toolset_20260401",
242 },
243 ],
244 });
245 
246 Console.WriteLine($"Agent ID: {agent.ID}, version: {agent.Version}");
247 ```
248 
249 ```go Go
250 package main
251 
252 import (
253 "context"
254 "fmt"
255 
256 "github.com/anthropics/anthropic-sdk-go"
257 )
258 
259 func main() {
260 client := anthropic.NewClient()
261 ctx := context.Background()
262 
263 agent, err := client.Beta.Agents.New(ctx, anthropic.BetaAgentNewParams{
264 Name: "Coding Assistant",
265 Model: anthropic.BetaManagedAgentsModelConfigParams{
266 ID: anthropic.BetaManagedAgentsModelClaudeOpus5_5,
267 },
268 System: anthropic.String("You are a helpful coding assistant. Write clean, well-documented code."),
269 Tools: []anthropic.BetaAgentNewParamsToolUnion{{
270 OfAgentToolset20260401: &anthropic.BetaManagedAgentsAgentToolset20260401Params{
271 Type: anthropic.BetaManagedAgentsAgentToolset20260401ParamsTypeAgentToolset20260401,
272 },
273 }},
274 })
275 if err != nil {
276 panic(err)
277 }
278 
279 fmt.Printf("Agent ID: %s, version: %d\n", agent.ID, agent.Version)
280 ```
281 
282 ```java Java
283 import com.anthropic.client.okhttp.AnthropicOkHttpClient;
284 import com.anthropic.models.beta.agents.AgentCreateParams;
285 import com.anthropic.models.beta.agents.BetaManagedAgentsAgentToolset20260401Params;
286 import com.anthropic.models.beta.agents.BetaManagedAgentsModel;
287 import com.anthropic.models.beta.environments.BetaCloudConfigParams;
288 import com.anthropic.models.beta.environments.BetaUnrestrictedNetwork;
289 import com.anthropic.models.beta.environments.EnvironmentCreateParams;
290 import com.anthropic.models.beta.sessions.SessionCreateParams;
291 import com.anthropic.models.beta.sessions.events.BetaManagedAgentsStreamSessionEvents;
292 import com.anthropic.models.beta.sessions.events.BetaManagedAgentsUserMessageEventParams;
293 import com.anthropic.models.beta.sessions.events.EventSendParams;
294 
295 void main() {
296 var client = AnthropicOkHttpClient.fromEnv();
297 
298 var agent = client.beta().agents().create(AgentCreateParams.builder()
299 .name("Coding Assistant")
300 .model(BetaManagedAgentsModel.CLAUDE_OPUS_5_5)
301 .system("You are a helpful coding assistant. Write clean, well-documented code.")
302 .addTool(BetaManagedAgentsAgentToolset20260401Params.builder()
303 .type(BetaManagedAgentsAgentToolset20260401Params.Type.AGENT_TOOLSET_20260401)
304 .build())
305 .build());
306 
307 IO.println("Agent ID: " + agent.id() + ", version: " + agent.version());
308 ```
309 
310 ```php PHP
311 use Anthropic\Client;
312 
313 $client = new Client();
314 
315 $agent = $client->beta->agents->create(
316 name: 'Coding Assistant',
317 model: 'claude-opus-5-5',
318 system: 'You are a helpful coding assistant. Write clean, well-documented code.',
319 tools: [
320 ['type' => 'agent_toolset_20260401'],
321 ],
322 );
323 
324 echo "Agent ID: {$agent->id}, version: {$agent->version}\n";
325 ```
326 
327 ```ruby Ruby
328 require "anthropic"
329 
330 client = Anthropic::Client.new
331 
332 agent = client.beta.agents.create(
333 name: "Coding Assistant",
334 model: "claude-opus-5-5",
335 system_: "You are a helpful coding assistant. Write clean, well-documented code.",
336 tools: [{type: "agent_toolset_20260401"}]
337 )
338 
339 puts "Agent ID: #{agent.id}, version: #{agent.version}"
340 ```
341 
342 <ForLanguage not="CLI">
225 });
226 
227 console.log(`Agent ID: ${agent.id}, version: ${agent.version}`);
228 ```
229 
343230 Save the returned `agent.id`. You'll reference it in every session you create.
344 </ForLanguage>
231 </CodeGroupItem>
232 
233 <CodeGroupItem>
234 ```csharp C#
235 using Anthropic;
236 using Anthropic.Models.Beta.Agents;
237 using Anthropic.Models.Beta.Environments;
238 using Anthropic.Models.Beta.Sessions;
239 using Anthropic.Models.Beta.Sessions.Events;
240 
241 var client = new AnthropicClient();
242 
243 var agent = await client.Beta.Agents.Create(new()
244 {
245 Name = "Coding Assistant",
246 Model = BetaManagedAgentsModel.ClaudeOpus5_5,
247 System = "You are a helpful coding assistant. Write clean, well-documented code.",
248 Tools =
249 [
250 new BetaManagedAgentsAgentToolset20260401Params
251 {
252 Type = "agent_toolset_20260401",
253 },
254 ],
255 });
256 
257 Console.WriteLine($"Agent ID: {agent.ID}, version: {agent.Version}");
258 ```
259 
260 Save the returned `agent.id`. You'll reference it in every session you create.
261 </CodeGroupItem>
262 
263 <CodeGroupItem>
264 ```go Go
265 package main
266 
267 import (
268 "context"
269 "fmt"
270 
271 "github.com/anthropics/anthropic-sdk-go"
272 )
273 
274 func main() {
275 client := anthropic.NewClient()
276 ctx := context.Background()
277 
278 agent, err := client.Beta.Agents.New(ctx, anthropic.BetaAgentNewParams{
279 Name: "Coding Assistant",
280 Model: anthropic.BetaManagedAgentsModelConfigParams{
281 ID: anthropic.BetaManagedAgentsModelClaudeOpus5_5,
282 },
283 System: anthropic.String("You are a helpful coding assistant. Write clean, well-documented code."),
284 Tools: []anthropic.BetaAgentNewParamsToolUnion{{
285 OfAgentToolset20260401: &anthropic.BetaManagedAgentsAgentToolset20260401Params{
286 Type: anthropic.BetaManagedAgentsAgentToolset20260401ParamsTypeAgentToolset20260401,
287 },
288 }},
289 })
290 if err != nil {
291 panic(err)
292 }
293 
294 fmt.Printf("Agent ID: %s, version: %d\n", agent.ID, agent.Version)
295 ```
296 
297 Save the returned `agent.id`. You'll reference it in every session you create.
298 </CodeGroupItem>
299 
300 <CodeGroupItem>
301 ```java Java
302 import com.anthropic.client.okhttp.AnthropicOkHttpClient;
303 import com.anthropic.models.beta.agents.AgentCreateParams;
304 import com.anthropic.models.beta.agents.BetaManagedAgentsAgentToolset20260401Params;
305 import com.anthropic.models.beta.agents.BetaManagedAgentsModel;
306 import com.anthropic.models.beta.environments.BetaCloudConfigParams;
307 import com.anthropic.models.beta.environments.BetaUnrestrictedNetwork;
308 import com.anthropic.models.beta.environments.EnvironmentCreateParams;
309 import com.anthropic.models.beta.sessions.SessionCreateParams;
310 import com.anthropic.models.beta.sessions.events.BetaManagedAgentsStreamSessionEvents;
311 import com.anthropic.models.beta.sessions.events.BetaManagedAgentsUserMessageEventParams;
312 import com.anthropic.models.beta.sessions.events.EventSendParams;
313 
314 void main() {
315 var client = AnthropicOkHttpClient.fromEnv();
316 
317 var agent = client.beta().agents().create(AgentCreateParams.builder()
318 .name("Coding Assistant")
319 .model(BetaManagedAgentsModel.CLAUDE_OPUS_5_5)
320 .system("You are a helpful coding assistant. Write clean, well-documented code.")
321 .addTool(BetaManagedAgentsAgentToolset20260401Params.builder()
322 .type(BetaManagedAgentsAgentToolset20260401Params.Type.AGENT_TOOLSET_20260401)
323 .build())
324 .build());
325 
326 IO.println("Agent ID: " + agent.id() + ", version: " + agent.version());
327 ```
328 
329 Save the returned `agent.id`. You'll reference it in every session you create.
330 </CodeGroupItem>
331 
332 <CodeGroupItem>
333 ```php PHP
334 use Anthropic\Client;
335 
336 $client = new Client();
337 
338 $agent = $client->beta->agents->create(
339 name: 'Coding Assistant',
340 model: 'claude-opus-5-5',
341 system: 'You are a helpful coding assistant. Write clean, well-documented code.',
342 tools: [
343 ['type' => 'agent_toolset_20260401'],
344 ],
345 );
346 
347 echo "Agent ID: {$agent->id}, version: {$agent->version}\n";
348 ```
349 
350 Save the returned `agent.id`. You'll reference it in every session you create.
351 </CodeGroupItem>
352 
353 <CodeGroupItem>
354 ```ruby Ruby
355 require "anthropic"
356 
357 client = Anthropic::Client.new
358 
359 agent = client.beta.agents.create(
360 name: "Coding Assistant",
361 model: "claude-opus-5-5",
362 system_: "You are a helpful coding assistant. Write clean, well-documented code.",
363 tools: [{type: "agent_toolset_20260401"}]
364 )
365 
366 puts "Agent ID: #{agent.id}, version: #{agent.version}"
367 ```
368 
369 Save the returned `agent.id`. You'll reference it in every session you create.
370 </CodeGroupItem>
345371 </CodeGroup>
346372 
347373 The `agent_toolset_20260401` tool type enables the full set of pre-built agent tools (bash, file operations, web search, and more). See [Tools](https://platform.claude.com/docs/en/managed-agents/tools) for the complete list and per-tool configuration options.
from line 377
351377 An environment defines the sandbox where your agent runs.
352378 
353379 <CodeGroup defaultLanguage="CLI">
354 ```bash cURL
355 environment=$(
356 curl -sS --fail-with-body https://api.anthropic.com/v1/environments \
357 -H "x-api-key: $ANTHROPIC_API_KEY" \
358 -H "anthropic-version: 2023-06-01" \
359 -H "anthropic-beta: managed-agents-2026-04-01" \
360 -H "content-type: application/json" \
361 -d @- <<'EOF'
362 {
363 "name": "quickstart-env",
364 "config": {
365 "type": "cloud",
366 "networking": {"type": "unrestricted"}
380 <CodeGroupItem>
381 ```bash cURL
382 environment=$(
383 curl -sS --fail-with-body https://api.anthropic.com/v1/environments \
384 -H "x-api-key: $ANTHROPIC_API_KEY" \
385 -H "anthropic-version: 2023-06-01" \
386 -H "anthropic-beta: managed-agents-2026-04-01" \
387 -H "content-type: application/json" \
388 -d @- <<'EOF'
389 {
390 "name": "quickstart-env",
391 "config": {
392 "type": "cloud",
393 "networking": {"type": "unrestricted"}
394 }
367395 }
368 }
369 EOF
370 )
371 
372 ENVIRONMENT_ID=$(jq -er '.id' <<<"$environment")
373 
374 echo "Environment ID: $ENVIRONMENT_ID"
375 ```
376 
377 <MultiFileExample language="cli" label="CLI">
396 EOF
397 )
398 
399 ENVIRONMENT_ID=$(jq -er '.id' <<<"$environment")
400 
401 echo "Environment ID: $ENVIRONMENT_ID"
402 ```
403 
404 Save the returned `environment.id` too.
405 </CodeGroupItem>
406 
407 <CodeGroupItem>
378408 ```bash CLI
379409 ant apply environment.yaml
380410 ```
from line 419
389419 type: unrestricted
390420 ```
391421 </File>
392 </MultiFileExample>
393 
394 <ForLanguage tab="CLI">
422 
395423 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) records the environment's ID in `claude-lock.json` too. To create the agent and the environment with one command, pass both files: `ant apply coding-assistant.md environment.yaml`.
396 </ForLanguage>
397 
398 ```python Python
399 environment = client.beta.environments.create(
400 name="quickstart-env",
401 config={
402 "type": "cloud",
403 "networking": {"type": "unrestricted"},
424 </CodeGroupItem>
425 
426 <CodeGroupItem>
427 ```python Python
428 environment = client.beta.environments.create(
429 name="quickstart-env",
430 config={
431 "type": "cloud",
432 "networking": {"type": "unrestricted"},
433 },
434 )
435 
436 print(f"Environment ID: {environment.id}")
437 ```
438 
439 Save the returned `environment.id` too.
440 </CodeGroupItem>
441 
442 <CodeGroupItem>
443 ```typescript TypeScript
444 const environment = await client.beta.environments.create({
445 name: "quickstart-env",
446 config: {
447 type: "cloud",
448 networking: { type: "unrestricted" },
404449 },
405 )
406 
407 print(f"Environment ID: {environment.id}")
408 ```
409 
410 ```typescript TypeScript
411 const environment = await client.beta.environments.create({
412 name: "quickstart-env",
413 config: {
414 type: "cloud",
415 networking: { type: "unrestricted" },
416 },
417 });
418 
419 console.log(`Environment ID: ${environment.id}`);
420 ```
421 
422 ```csharp C#
423 var environment = await client.Beta.Environments.Create(new()
424 {
425 Name = "quickstart-env",
426 Config = new BetaCloudConfigParams { Networking = new BetaUnrestrictedNetwork() },
427 });
428 
429 Console.WriteLine($"Environment ID: {environment.ID}");
430 ```
431 
432 ```go Go
433 environment, err := client.Beta.Environments.New(ctx, anthropic.BetaEnvironmentNewParams{
434 Name: "quickstart-env",
435 Config: anthropic.BetaEnvironmentNewParamsConfigUnion{
436 OfCloud: &anthropic.BetaCloudConfigParams{
437 Networking: anthropic.BetaCloudConfigParamsNetworkingUnion{
438 OfUnrestricted: &anthropic.BetaUnrestrictedNetworkParam{},
439 },
440 },
441 },
442 })
443 if err != nil {
444 panic(err)
445 }
446 
447 fmt.Printf("Environment ID: %s\n", environment.ID)
448 ```
449 
450 ```java Java
451 var environment = client.beta().environments().create(EnvironmentCreateParams.builder()
452 .name("quickstart-env")
453 .config(BetaCloudConfigParams.builder()
454 .networking(BetaUnrestrictedNetwork.builder().build())
455 .build())
456 .build());
457 
458 IO.println("Environment ID: " + environment.id());
459 ```
460 
461 ```php PHP
462 $environment = $client->beta->environments->create(
463 name: 'quickstart-env',
464 config: ['type' => 'cloud', 'networking' => ['type' => 'unrestricted']],
465 );
466 
467 echo "Environment ID: {$environment->id}\n";
468 ```
469 
470 ```ruby Ruby
471 environment = client.beta.environments.create(
472 name: "quickstart-env",
473 config: {type: "cloud", networking: {type: "unrestricted"}}
474 )
475 
476 puts "Environment ID: #{environment.id}"
477 ```
478 
479 <ForLanguage not="CLI">
450 });
451 
452 console.log(`Environment ID: ${environment.id}`);
453 ```
454 
480455 Save the returned `environment.id` too.
481 </ForLanguage>
456 </CodeGroupItem>
457 
458 <CodeGroupItem>
459 ```csharp C#
460 var environment = await client.Beta.Environments.Create(new()
461 {
462 Name = "quickstart-env",
463 Config = new BetaCloudConfigParams { Networking = new BetaUnrestrictedNetwork() },
464 });
465 
466 Console.WriteLine($"Environment ID: {environment.ID}");
467 ```
468 
469 Save the returned `environment.id` too.
470 </CodeGroupItem>
471 
472 <CodeGroupItem>
473 ```go Go
474 environment, err := client.Beta.Environments.New(ctx, anthropic.BetaEnvironmentNewParams{
475 Name: "quickstart-env",
476 Config: anthropic.BetaEnvironmentNewParamsConfigUnion{
477 OfCloud: &anthropic.BetaCloudConfigParams{
478 Networking: anthropic.BetaCloudConfigParamsNetworkingUnion{
479 OfUnrestricted: &anthropic.BetaUnrestrictedNetworkParam{},
480 },
481 },
482 },
483 })
484 if err != nil {
485 panic(err)
486 }
487 
488 fmt.Printf("Environment ID: %s\n", environment.ID)
489 ```
490 
491 Save the returned `environment.id` too.
492 </CodeGroupItem>
493 
494 <CodeGroupItem>
495 ```java Java
496 var environment = client.beta().environments().create(EnvironmentCreateParams.builder()
497 .name("quickstart-env")
498 .config(BetaCloudConfigParams.builder()
499 .networking(BetaUnrestrictedNetwork.builder().build())
500 .build())
501 .build());
502 
503 IO.println("Environment ID: " + environment.id());
504 ```
505 
506 Save the returned `environment.id` too.
507 </CodeGroupItem>
508 
509 <CodeGroupItem>
510 ```php PHP
511 $environment = $client->beta->environments->create(
512 name: 'quickstart-env',
513 config: ['type' => 'cloud', 'networking' => ['type' => 'unrestricted']],
514 );
515 
516 echo "Environment ID: {$environment->id}\n";
517 ```
518 
519 Save the returned `environment.id` too.
520 </CodeGroupItem>
521 
522 <CodeGroupItem>
523 ```ruby Ruby
524 environment = client.beta.environments.create(
525 name: "quickstart-env",
526 config: {type: "cloud", networking: {type: "unrestricted"}}
527 )
528 
529 puts "Environment ID: #{environment.id}"
530 ```
531 
532 Save the returned `environment.id` too.
533 </CodeGroupItem>
482534 </CodeGroup>
483535 
484536 <Tip>
485537 

managed-agents/reference Changed · +9 / -9 lines

from line 95
9595 
9696These are the `ant beta:worker` CLI flags for the pre-built worker that drives a `self_hosted` environment. See [Self-hosted sandboxes](https://platform.claude.com/docs/en/managed-agents/self-hosted-sandboxes) for setting up the environment, running a worker, and the SDK helper options.
9797 
98| Flag | Description |
99| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
100| `--environment-id` | The environment to poll for work. Also reads from `ANTHROPIC_ENVIRONMENT_ID`. |
101| `--environment-key` | Authenticates the worker with this environment. Also reads from `ANTHROPIC_ENVIRONMENT_KEY`. |
102| `--workdir` | Directory where skills are downloaded and tools read and write files. Defaults to `.` (the current directory); the system default working directory is `/workspace`. |
103| `--on-work` | Script to call for each claimed work item instead of running tools in-process. Receives session details as environment variables. |
104| `--unrestricted-paths` | Allow the file tools to read and write paths outside `--workdir`. The workdir check is a guardrail for the file tools only, not a sandbox; it does not constrain bash. |
105| `--max-idle` | How long to wait after the session goes idle with an `end_turn` [stop reason](https://platform.claude.com/docs/en/api/handling-stop-reasons) before shutting down. Defaults to `60s`. |
106| `--log-format` | Log output format. Use `json` for structured log ingestion. Defaults to `text`. |
98| Flag | Description |
99| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
100| `--environment-id` | The environment to poll for work. Also reads from `ANTHROPIC_ENVIRONMENT_ID`. |
101| `--environment-key` | Authenticates the worker with this environment. Also reads from `ANTHROPIC_ENVIRONMENT_KEY`. |
102| `--workdir` | Directory where skills are downloaded and tools read and write files. Defaults to `.` (the current directory); the system default working directory is `/workspace`. |
103| `--on-work` | Script to call for each claimed work item instead of running tools in-process. Receives session details as environment variables. |
104| `--unrestricted-paths` | Allow the file tools to read and write paths outside `--workdir`. The workdir check is a guardrail for the file tools only, not a sandbox; it does not constrain bash. |
105| `--max-idle` | How long to wait after the session goes idle with an `end_turn` [stop reason](https://platform.claude.com/docs/en/build-with-claude/handling-stop-reasons) before shutting down. Defaults to `60s`. |
106| `--log-format` | Log output format. Use `json` for structured log ingestion. Defaults to `text`. |
107107 
108108The CLI worker does not mount [memory stores](https://platform.claude.com/docs/en/managed-agents/memory): a session that attaches one still runs, but the agent finds nothing at the store's `mount_path` and no changes sync back to the store. To use memory stores in sessions on a self-hosted environment, run the SDK worker instead; see [Use memory stores](https://platform.claude.com/docs/en/managed-agents/self-hosted-sandboxes#use-memory-stores).
109109 

managed-agents/scheduled-deployments Changed · +4 / -6 lines

from line 46
4646 EOF
4747 ```
4848 
49 <MultiFileExample language="cli" label="CLI">
49 <CodeGroupItem>
5050 ```bash CLI
5151 ant apply deployment.md
5252 ```
from line 66
6666 Run the weekly compliance scan.
6767 ```
6868 </File>
69 </MultiFileExample>
7069 
70 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) prints the new deployment's ID and records it in `claude-lock.json`. To see the deployment object, run `ant beta:deployments retrieve`.
71 </CodeGroupItem>
72 
7173 ```python Python
7274 deployment = client.beta.deployments.create(
7375 name="Weekly compliance scan",
from line 225
223225 }
224226 )
225227 ```
226 
227 <ForLanguage tab="CLI">
228 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) prints the new deployment's ID and records it in `claude-lock.json`. To see the deployment object, run `ant beta:deployments retrieve`.
229 </ForLanguage>
230228</CodeGroup>
231229 
232230The response includes a deployment object with a populated `schedule.upcoming_runs_at` with the next upcoming fire times, to confirm your schedule was set correctly.

managed-agents/skills Changed · +6 / -8 lines

from line 33
3333 -F "files[]=@example_skill.zip"
3434 ```
3535 
36 <MultiFileExample language="cli" label="CLI">
36 <CodeGroupItem>
3737 ```bash CLI
3838 ant apply skills/pr-summary
3939 ```
from line 50
5050 List what changed, why, and anything a reviewer should look at closely, in three short sections.
5151 ```
5252 </File>
53 </MultiFileExample>
5453 
54 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) uploads the `skills/pr-summary` directory, prints the new skill's ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` uploads your edits as a new version instead of creating a second skill.
55 </CodeGroupItem>
56 
5557 ```python Python
5658 import anthropic
5759 from anthropic.lib import files_from_dir
from line 196
194196 puts "Created skill: #{skill.id}"
195197 puts "Latest version: #{skill.latest_version_id}"
196198 ```
197 
198 <ForLanguage tab="CLI">
199 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) uploads the `skills/pr-summary` directory, prints the new skill's ID, and records it in `claude-lock.json`. Commit `claude-lock.json` so the next `ant apply` uploads your edits as a new version instead of creating a second skill.
200 </ForLanguage>
201199</CodeGroup>
202200 
203201To list, retrieve, delete, and version custom skills, see [Managing custom skills](https://platform.claude.com/docs/en/build-with-claude/skills-guide#managing-custom-skills). For the full request and response schemas, see the [Create Skill API reference](https://platform.claude.com/docs/en/api/skills/create). Skill bundles upload directly to the Skills API rather than through the [Files API](https://platform.claude.com/docs/en/build-with-claude/files).
from line 236
238236 )
239237 ```
240238 
241 <MultiFileExample language="cli" label="CLI">
239 <CodeGroupItem>
242240 ```bash CLI
243241 ant apply agent.md
244242 ```
from line 257
259257 You are a financial analysis agent.
260258 ```
261259 </File>
262 </MultiFileExample>
260 </CodeGroupItem>
263261 
264262 ```python Python
265263 agent = client.beta.agents.create(

managed-agents/tools Changed · +8 / -10 lines

from line 61
6161 )
6262 ```
6363 
64 <MultiFileExample language="cli" label="CLI">
64 <CodeGroupItem>
6565 ```bash CLI
6666 ant apply agent.md
6767 ```
from line 79
7979 ---
8080 ```
8181 </File>
82 </MultiFileExample>
82 </CodeGroupItem>
8383 
8484 ```python Python
8585 agent = client.beta.agents.create(
from line 308
308308 jq '.tools[0].configs' <<< "$agent"
309309 ```
310310 
311 <MultiFileExample language="cli" label="CLI">
311 <CodeGroupItem>
312312 ```bash CLI
313313 ant apply agent.md
314314 ```
from line 335
335335 ---
336336 ```
337337 </File>
338 </MultiFileExample>
339338 
339 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the agent and prints its ID, not the `configs` array.
340 </CodeGroupItem>
341 
340342 ```python Python
341343 client = Anthropic()
342344 
from line 611
609611 puts JSON.pretty_generate(toolset.configs.map(&:to_h))
610612 end
611613 ```
612 
613 <ForLanguage tab="CLI">
614 [`ant apply`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply) creates the agent and prints its ID, not the `configs` array.
615 </ForLanguage>
616614</CodeGroup>
617615 
618616In the Claude Console, set allowed or blocked domains from the `web_search` and `web_fetch` rows of the **Built-in tools** card on the agent form; set `max_content_tokens` and `user_location` in the **Raw** view of the agent's configuration.
from line 712
714712 )
715713 ```
716714 
717 <MultiFileExample language="cli" label="CLI">
715 <CodeGroupItem>
718716 ```bash CLI
719717 ant apply agent.md
720718 ```
from line 738
740738 ---
741739 ```
742740 </File>
743 </MultiFileExample>
741 </CodeGroupItem>
744742 
745743 ```python Python
746744 agent = client.beta.agents.create(

release-notes/overview Changed · +21 / -15 lines

### September 24, 2026

from line 12
1212 For updates to Claude Code, see the [complete CHANGELOG.md](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md) in the `claude-code` repository.
1313</Tip>
1414 
15### September 24, 2026
16 
17* We're resuming billing for refusals that arrive before any output when `stop_details.category` is `"bio"`, `"frontier_llm"`, or `"reasoning_extraction"`, the categories where we measure low volumes of false positives. Mid-stream refusals were already billed. Refusals billed under this change are charged like any other request, at the rates of the model that ran it. Refusals before any output in other categories are still not billed, and fallback credit is unchanged. This change applies on all platforms. See [How refusals are billed](https://platform.claude.com/docs/en/build-with-claude/refusals-and-fallback#how-refusals-are-billed).
18* The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) local session endpoints are out of beta for Claude for Microsoft 365 sessions in Excel, PowerPoint, Word, and Outlook (`product_surface` values beginning with `office_agents`). See [Sessions on users' machines](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retrieve-local-sessions).
19* The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) [Activity Feed](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed) no longer returns file names, project document names, or artifact titles. The `filename` and `title` fields on file, project document, and artifact activities are now always empty or omitted, including on activities recorded before this change. To look up a name or title by the ID on the activity, use a Compliance Access Key with the `read:compliance_user_data` scope. See [Understand the Activity object](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed#understand-the-activity-object).
20 
1521### September 23, 2026
1622 
1723* [Cache diagnostics](https://platform.claude.com/docs/en/build-with-claude/cache-diagnostics) is out of beta on the Claude API and no longer requires the `cache-diagnosis-2026-04-07` beta header. Include the `diagnostics` object on a Messages request to opt in; requests that still send the header work as before. Responses from `POST /v1/messages` now always include the `diagnostics` field, which is `null` when the request did not include the `diagnostics` object.
from line 64
5864* `thinking.display` accepts a third value, `"updates"`, in beta (`thinking-display-updates-2026-08-18` header). Reasoning comes back with an empty `thinking` field, as under `"omitted"`, and the short progress updates that Claude Fable 5.1, Claude Mythos 5.1, and Claude Fable 5 write between tool calls come back as text, at most one `thinking` block before a tool call. See [Progress updates between tool calls](https://platform.claude.com/docs/en/build-with-claude/thinking#progress-updates).
5965* Text generated by Claude Fable 5.1 and Claude Mythos 5.1 carries Anthropic's text watermark, and supported image, video, and audio files that Claude produces through the [code execution tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool) carry C2PA Content Credentials when you retrieve them through the [Files API](https://platform.claude.com/docs/en/build-with-claude/files) on the Claude API. Marking requires no changes to your requests or response handling.
6066* Like Claude Fable 5, both models require 30-day data retention and aren't available under zero data retention unless expressly authorized by Anthropic. See [Model-specific data retention requirements](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention#model-specific-data-retention-requirements).
61* The guides for the Claude Enterprise endpoints of the [Admin API](https://platform.claude.com/docs/en/api/admin) ([user management](https://platform.claude.com/docs/en/manage-claude/user-management) and [spend limits](https://platform.claude.com/docs/en/manage-claude/spend-limits-api)), the [Claude Enterprise Analytics API](https://platform.claude.com/docs/en/manage-claude/analytics-api), and the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) now show the `anthropic-version` header; send it on every request to these endpoints, as in the rest of the Claude API. See [API versions](https://platform.claude.com/docs/en/api/versioning).
67* The guides for the Claude Enterprise endpoints of the [Admin API](https://platform.claude.com/docs/en/api/beta/organization) ([user management](https://platform.claude.com/docs/en/manage-claude/user-management) and [spend limits](https://platform.claude.com/docs/en/manage-claude/spend-limits-api)), the [Claude Enterprise Analytics API](https://platform.claude.com/docs/en/manage-claude/analytics-api), and the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) now show the `anthropic-version` header; send it on every request to these endpoints, as in the rest of the Claude API. See [API versions](https://platform.claude.com/docs/en/api/versioning).
6268 
6369### August 27, 2026
6470 
from line 91
8591* Both toolsets are available for Claude Fable 5, Claude Mythos 5, Claude Opus 5, Claude Sonnet 5, and Claude Opus 4.8 on the Claude API.
8692* The [Files API](https://platform.claude.com/docs/en/build-with-claude/files) is out of beta on the Claude API. Requests to the `/v1/files` endpoints, and Messages API requests that reference an uploaded file, no longer require the `files-api-2025-04-14` beta header. Requests sent without the header use the current response format: [file expiration](https://platform.claude.com/docs/en/build-with-claude/files#file-expiration) (set `expires_in_seconds` when you upload a file; file objects report `expires_at`), and `page` and `next_page` [pagination](https://platform.claude.com/docs/en/api/overview#pagination) plus an `ids[]` filter when you [list files](https://platform.claude.com/docs/en/build-with-claude/files#list-files). `/v1/files` requests that still send the beta header keep working and return the previous response format. To move an existing integration off the header, see [Migrate from `files-api-2025-04-14`](https://platform.claude.com/docs/en/build-with-claude/files#migrate-from-files-api-2025-04-14).
8793* [Agent Skills](https://platform.claude.com/docs/en/agents-and-tools/agent-skills/overview) and the Skills API (`/v1/skills`) are out of beta on the Claude API. Requests no longer require the `skills-2025-10-02` beta header, including Messages API requests that load Skills through the `container` parameter. Requests that still send the header continue to work unchanged. See [Using Agent Skills with the API](https://platform.claude.com/docs/en/build-with-claude/skills-guide). To move an existing integration off the header, see [Migrate from `skills-2025-10-02`](https://platform.claude.com/docs/en/build-with-claude/skills-guide#migrate-from-skills-2025-10-02).
88* The [Admin API](https://platform.claude.com/docs/en/api/admin) user-management endpoints for **Claude Enterprise** (claude.ai) organizations (members, invites, groups, and custom roles) are out of beta. The `anthropic-beta: ce-user-management-2026-07-13` header is no longer required on group and custom-role requests; requests that still send it are accepted unchanged. See [User management](https://platform.claude.com/docs/en/manage-claude/user-management).
94* The [Admin API](https://platform.claude.com/docs/en/api/beta/organization) user-management endpoints for **Claude Enterprise** (claude.ai) organizations (members, invites, groups, and custom roles) are out of beta. The `anthropic-beta: ce-user-management-2026-07-13` header is no longer required on group and custom-role requests; requests that still send it are accepted unchanged. See [User management](https://platform.claude.com/docs/en/manage-claude/user-management).
8995* You can now restrict which sites a Claude Managed Agents agent's `web_search` and `web_fetch` tools can reach. Set `allowed_domains` or `blocked_domains` on the tool's entry in the `agent_toolset_20260401` `configs` array; `web_fetch` also accepts `max_content_tokens` and `web_search` accepts `user_location`. Each `configs` entry is identified by its `name` and typed by an optional `type`, and requests that pass only `name`, `enabled`, and `permission_policy` continue to work; in the typed SDKs, `configs` entries become per-tool types. See [Restrict web search and web fetch domains](https://platform.claude.com/docs/en/managed-agents/tools#restrict-web-search-and-web-fetch-domains).
9096* Claude Managed Agents sessions that run in a [self-hosted sandbox](https://platform.claude.com/docs/en/managed-agents/self-hosted-sandboxes) can now attach [memory stores](https://platform.claude.com/docs/en/managed-agents/memory). The Python, TypeScript, and Go SDK workers download each attached store into the sandbox at its `mount_path` and sync the agent's changes back to the store. See [Use memory stores](https://platform.claude.com/docs/en/managed-agents/self-hosted-sandboxes#use-memory-stores).
9197* The session viewer in the Claude Console has been redesigned with a timeline minimap, a transcript grouped by model request, and an Inspector panel for session details and cost, raw events, per-tool statistics, mounted resources, and per-thread activity. See [Console observability](https://platform.claude.com/docs/en/managed-agents/events-and-streaming#console-observability).
from line 157
151157 
152158### July 14, 2026
153159 
154* You can now manage the people in your **Claude Enterprise** (claude.ai) organization with the [Admin API](https://platform.claude.com/docs/en/api/admin), in beta for all Claude Enterprise organizations: list members and look them up by email address, change a member's role, remove members, send and withdraw invites, manage groups and their membership, and read custom roles. Group and custom-role requests require the `anthropic-beta: ce-user-management-2026-07-13` beta header; member and invite requests take no beta header. An Admin API key with the `read:org_audit` scope can also call every user-management `GET` endpoint. See [User management](https://platform.claude.com/docs/en/manage-claude/user-management).
160* You can now manage the people in your **Claude Enterprise** (claude.ai) organization with the [Admin API](https://platform.claude.com/docs/en/api/beta/organization), in beta for all Claude Enterprise organizations: list members and look them up by email address, change a member's role, remove members, send and withdraw invites, manage groups and their membership, and read custom roles. Group and custom-role requests require the `anthropic-beta: ce-user-management-2026-07-13` beta header; member and invite requests take no beta header. An Admin API key with the `read:org_audit` scope can also call every user-management `GET` endpoint. See [User management](https://platform.claude.com/docs/en/manage-claude/user-management).
155161 
156162### July 10, 2026
157163 
from line 166
160166 
161167### July 8, 2026
162168 
163* You can now set an expiration when you create an API key or an Admin API key in the [Claude Console](https://platform.claude.com/settings/keys). Choose a preset, a custom duration, or **Never**. For keys with a lifetime of at least 7 days, Anthropic emails the creator before expiration. Existing keys are unaffected. The Admin API reports each key's expiration in the [`expires_at`](https://platform.claude.com/docs/en/api/admin/api_keys/list) field. See [Authentication](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration).
169* You can now set an expiration when you create an API key or an Admin API key in the [Claude Console](https://platform.claude.com/settings/keys). Choose a preset, a custom duration, or **Never**. For keys with a lifetime of at least 7 days, Anthropic emails the creator before expiration. Existing keys are unaffected. The Admin API reports each key's expiration in the [`expires_at`](https://platform.claude.com/docs/en/api/beta/organization/api_keys/list) field. See [Authentication](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration).
164170 
165171### July 2, 2026
166172 
from line 221
215221 
216222### June 9, 2026
217223 
218* We've launched **Claude Fable 5** (`claude-fable-5`), our most capable widely released model, alongside **Claude Mythos 5** (`claude-mythos-5`) for Project Glasswing participants. Both models support a [1M token context window](https://platform.claude.com/docs/en/build-with-claude/context-windows) by default, 128k max output tokens, and always-on [adaptive thinking](https://platform.claude.com/docs/en/build-with-claude/thinking). See [Introducing Claude Fable 5 and Claude Mythos 5](https://platform.claude.com/docs/en/models/fable-5/introducing-claude-fable-5-and-claude-mythos-5) for capabilities, API changes, and availability.
224* We've launched **Claude Fable 5** (`claude-fable-5`), our most capable model open to all customers, alongside **Claude Mythos 5** (`claude-mythos-5`) for Project Glasswing participants. Both models support a [1M token context window](https://platform.claude.com/docs/en/build-with-claude/context-windows) by default, 128k max output tokens, and always-on [adaptive thinking](https://platform.claude.com/docs/en/build-with-claude/thinking). See [Introducing Claude Fable 5 and Claude Mythos 5](https://platform.claude.com/docs/en/models/fable-5/introducing-claude-fable-5-and-claude-mythos-5) for capabilities, API changes, and availability.
219225* Claude Fable 5 and Claude Mythos 5 use the tokenizer introduced with Claude Opus 4.7. Compared to models before Claude Opus 4.7, the same text produces roughly 30% more tokens. The exact increase depends on the content and workload shape. Use the [token counting API](https://platform.claude.com/docs/en/build-with-claude/token-counting#token-counts-on-claude-fable-5) with `model: "claude-fable-5"` to measure your prompts under the new tokenizer.
220226* Claude Fable 5 runs safety classifiers on requests and during response generation. When a classifier declines a request, the Messages API returns `stop_reason: "refusal"`. You are not billed for a request refused before any output is generated. An opt-in `fallbacks` parameter (in beta on the Claude API and Claude Platform on AWS; not supported on the Message Batches API) re-runs refused requests on another model, billed at the fallback model's rates. See [Handling stop reasons](https://platform.claude.com/docs/en/build-with-claude/handling-stop-reasons).
221227* The [`stop_details.category`](https://platform.claude.com/docs/en/build-with-claude/refusals-and-fallback#refusal-response) field on refusal responses now includes `"reasoning_extraction"` on Claude Fable 5, returned when a request is blocked under Anthropic's Terms of Service restrictions on reverse engineering or duplicating model outputs. The existing `"cyber"` and `"bio"` categories are unchanged. No beta header is required.
from line 249
243249 
244250### May 28, 2026
245251 
246* We've launched **Claude Opus 4.8** (claude-opus-4-8), our most capable widely released model. Claude Opus 4.8 supports a [1M token context window](https://platform.claude.com/docs/en/build-with-claude/context-windows) by default on the Claude API, Amazon Bedrock, Google Cloud, and Microsoft Foundry, 128k max output tokens, and the same set of tools and platform features as Claude Opus 4.7. See the [migration guide](https://platform.claude.com/docs/en/about-claude/models/migration-guide) for baseline settings, features, and migration guidance.
252* We've launched **Claude Opus 4.8** (claude-opus-4-8), our most capable model. Claude Opus 4.8 supports a [1M token context window](https://platform.claude.com/docs/en/build-with-claude/context-windows) by default on the Claude API, Amazon Bedrock, Google Cloud, and Microsoft Foundry, 128k max output tokens, and the same set of tools and platform features as Claude Opus 4.7. See the [migration guide](https://platform.claude.com/docs/en/about-claude/models/migration-guide) for baseline settings, features, and migration guidance.
247253* We've launched [mid-conversation system messages](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages). On Claude Opus 4.8, you can send `role: "system"` messages after a user turn (subject to [placement rules](https://platform.claude.com/docs/en/build-with-claude/mid-conversation-system-messages#limitations)) in the `messages` array, preserving prompt cache hits when instructions change during a long-running session. No beta header is required.
248254* The [`stop_details`](https://platform.claude.com/docs/en/build-with-claude/refusals-and-fallback#refusal-response) field on refusal responses is now publicly documented; it returns a `category` (`cyber`, `bio`, or `null`) and a human-readable `explanation`, so your application can route different classes of refusal to the right next step. No beta header is required.
249255* On Claude Opus 4.8, the [effort parameter](https://platform.claude.com/docs/en/build-with-claude/effort) defaults to `high` across all surfaces, including Claude Code and the Messages API.
from line 328
322328 
323329### April 16, 2026
324330 
325* We've launched [Claude Opus 4.7](https://www.anthropic.com/news/claude-opus-4-7), our most capable widely released model for complex reasoning and agentic coding, at the same $5 / $25 per MTok pricing as Opus 4.6. See [What's new in Claude Opus 4.7](https://platform.claude.com/docs/en/about-claude/models/whats-new-claude-4-7) for capability improvements, new features, and the updated tokenizer. Opus 4.7 includes API breaking changes versus Opus 4.6; see the [migration guide](https://platform.claude.com/docs/en/about-claude/models/migration-guide) before upgrading.
331* We've launched [Claude Opus 4.7](https://www.anthropic.com/news/claude-opus-4-7), our most capable model for complex reasoning and agentic coding, at the same $5 / $25 per MTok pricing as Opus 4.6. See [What's new in Claude Opus 4.7](https://platform.claude.com/docs/en/about-claude/models/whats-new-claude-4-7) for capability improvements, new features, and the updated tokenizer. Opus 4.7 includes API breaking changes versus Opus 4.6; see the [migration guide](https://platform.claude.com/docs/en/about-claude/models/migration-guide) before upgrading.
326332* [Claude in Amazon Bedrock](https://platform.claude.com/docs/en/build-with-claude/claude-in-amazon-bedrock) is now open to all Amazon Bedrock customers. Claude Opus 4.7 and Claude Haiku 4.5 are available self-serve from the Bedrock console through the Messages API endpoint at `/anthropic/v1/messages`, in 27 AWS regions with global and regional endpoints.
327333* We've launched [task budgets](https://platform.claude.com/docs/en/build-with-claude/task-budgets) in beta on Claude Opus 4.7. Give Claude an advisory token budget for a full agentic loop (thinking, tool calls, tool results, and output) and the model sees a running countdown, using it to prioritize work and finish gracefully as the budget is consumed. Include the `task-budgets-2026-03-13` beta header in your requests.
328334* Claude Opus 4.7 supports [high-resolution image input](https://platform.claude.com/docs/en/build-with-claude/vision#high-resolution-image-support-on-claude-opus-4-7), raising the maximum image resolution from 1568 to 2576 pixels on the long edge for improved performance on computer use, screenshot understanding, and document analysis. High-resolution support is automatic and requires no beta header; images may use up to approximately 3x more image tokens than on prior models.
from line 379
373379 
374380### February 17, 2026
375381 
376* We've launched [Claude Sonnet 4.6](https://www.anthropic.com/news/claude-sonnet-4-6), our latest balanced model combining speed and intelligence for everyday tasks. Sonnet 4.6 delivers improved agentic search performance while consuming fewer tokens. Sonnet 4.6 supports [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking) and a [1M token context window](https://platform.claude.com/docs/en/build-with-claude/context-windows) (beta). See [Models & Pricing](https://platform.claude.com/docs/en/about-claude/models) for details.
382* We've launched [Claude Sonnet 4.6](https://www.anthropic.com/news/claude-sonnet-4-6), our latest balanced model combining speed and intelligence for everyday tasks. Sonnet 4.6 delivers improved agentic search performance while consuming fewer tokens. Sonnet 4.6 supports [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking) and a [1M token context window](https://platform.claude.com/docs/en/build-with-claude/context-windows) (beta). See [Models & Pricing](https://platform.claude.com/docs/en/models/overview) for details.
377383* API [code execution](https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool) is now **free when used with web search or web fetch**. Sandboxed code execution improves model capability and token efficiency. See the [pricing details](https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool#usage-and-pricing) for standalone usage.
378384* The [web search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool) and [programmatic tool calling](https://platform.claude.com/docs/en/agents-and-tools/tool-use/programmatic-tool-calling) are available with no beta header required. Web search and web fetch now support [dynamic filtering](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool#dynamic-filtering), which uses code execution to filter results before they reach the context window for better performance and reduced token cost.
379385* The [code execution tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool), [web fetch tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-fetch-tool), [tool search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/tool-search-tool), [tool use examples](https://platform.claude.com/docs/en/agents-and-tools/tool-use/define-tools#providing-tool-use-examples), and [memory tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/memory-tool) no longer require a beta header.
from line 419
413419 
414420### November 24, 2025
415421 
416* We've launched [Claude Opus 4.5](https://www.anthropic.com/news/claude-opus-4-5), our most intelligent model combining maximum capability with practical performance. Ideal for complex specialized tasks, professional software engineering, and advanced agents. Features step-change improvements in vision, coding, and computer use at a more accessible price point than previous Opus models. Learn more in [Models overview](https://platform.claude.com/docs/en/about-claude/models).
422* We've launched [Claude Opus 4.5](https://www.anthropic.com/news/claude-opus-4-5), our most intelligent model combining maximum capability with practical performance. Ideal for complex specialized tasks, professional software engineering, and advanced agents. Features step-change improvements in vision, coding, and computer use at a more accessible price point than previous Opus models. Learn more in [Models overview](https://platform.claude.com/docs/en/models/overview).
417423* We've launched [programmatic tool calling](https://platform.claude.com/docs/en/agents-and-tools/tool-use/programmatic-tool-calling) in public beta, allowing Claude to call tools from within code execution to reduce latency and token usage in multi-tool workflows.
418424* We've launched the [tool search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/tool-search-tool) in public beta, enabling Claude to dynamically discover and load tools on-demand from large tool catalogs.
419425* We've launched the [effort parameter](https://platform.claude.com/docs/en/build-with-claude/effort) in public beta for Claude Opus 4.5, allowing you to control token usage by trading off between response thoroughness and efficiency.
from line 458
452458 
453459### October 15, 2025
454460 
455* We've launched [Claude Haiku 4.5](https://www.anthropic.com/news/claude-haiku-4-5), our fastest and most intelligent Haiku model with near-frontier performance. Ideal for real-time applications, high-volume processing, and cost-sensitive deployments requiring strong reasoning. Learn more in [Models overview](https://platform.claude.com/docs/en/about-claude/models).
461* We've launched [Claude Haiku 4.5](https://www.anthropic.com/news/claude-haiku-4-5), our fastest and most intelligent Haiku model with near-frontier performance. Ideal for real-time applications, high-volume processing, and cost-sensitive deployments requiring strong reasoning. Learn more in [Models overview](https://platform.claude.com/docs/en/models/overview).
456462 
457463### September 29, 2025
458464 
from line 518
512518### August 18, 2025
513519 
514520* We've released the [Usage & Cost API](https://platform.claude.com/docs/en/manage-claude/usage-cost-api), allowing administrators to programmatically monitor their organization's usage and cost data.
515* We've added a new endpoint to the Admin API for retrieving organization information. For details, see the [Organization Info Admin API reference](https://platform.claude.com/docs/en/api/admin-api/organization/get-me).
521* We've added a new endpoint to the Admin API for retrieving organization information. For details, see the [Organization Info Admin API reference](https://platform.claude.com/docs/en/api/beta/organization/retrieve).
516522 
517523### August 13, 2025
518524 
from line 539
533539 
534540### August 5, 2025
535541 
536* We've launched [Claude Opus 4.1](https://www.anthropic.com/news/claude-opus-4-1), an incremental update to Claude Opus 4 with enhanced capabilities and performance improvements.\* Learn more in [Models overview](https://platform.claude.com/docs/en/about-claude/models).
542* We've launched [Claude Opus 4.1](https://www.anthropic.com/news/claude-opus-4-1), an incremental update to Claude Opus 4 with enhanced capabilities and performance improvements.\* Learn more in [Models overview](https://platform.claude.com/docs/en/models/overview).
537543 
538544*\*Opus 4.1 does not allow both `temperature` and `top_p` parameters to be specified. Please use only one.*
539545 
from line 577
571577 
572578### May 22, 2025
573579 
574* We've launched [Claude Opus 4 and Claude Sonnet 4](https://www.anthropic.com/news/claude-4), our latest models with extended thinking capabilities. Learn more in [Models overview](https://platform.claude.com/docs/en/about-claude/models).
580* We've launched [Claude Opus 4 and Claude Sonnet 4](https://www.anthropic.com/news/claude-4), our latest models with extended thinking capabilities. Learn more in [Models overview](https://platform.claude.com/docs/en/models/overview).
575581* The default behavior of [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking) in Claude 4 models returns a summary of Claude's full thinking process, with the full thinking encrypted and returned in the `signature` field of `thinking` block output.
576582* We've launched [interleaved thinking](https://platform.claude.com/docs/en/build-with-claude/thinking#interleaved-thinking) in public beta, a feature that enables Claude to think in between tool calls. To enable interleaved thinking, use the [beta header](https://platform.claude.com/docs/en/api/beta-headers) `interleaved-thinking-2025-05-14`.
577583* We've launched the [Files API](https://platform.claude.com/docs/en/build-with-claude/files) in public beta, enabling you to upload files and reference them in the Messages API and code execution tool.
from line 616
610616 
611617### February 24th, 2025
612618 
613* We've launched [Claude Sonnet 3.7](https://www.anthropic.com/news/claude-3-7-sonnet), our most intelligent model yet. Claude Sonnet 3.7 can produce near-instant responses or show its extended thinking step-by-step. One model, two ways to think. Learn more about all Claude models in [Models overview](https://platform.claude.com/docs/en/about-claude/models).
619* We've launched [Claude Sonnet 3.7](https://www.anthropic.com/news/claude-3-7-sonnet), our most intelligent model yet. Claude Sonnet 3.7 can produce near-instant responses or show its extended thinking step-by-step. One model, two ways to think. Learn more about all Claude models in [Models overview](https://platform.claude.com/docs/en/models/overview).
614620 
615621* We've added vision support to Claude Haiku 3.5, enabling the model to analyze and understand images.
616622 
from line 658
652658 
653659### December 19th, 2024
654660 
655* We've added support for a [delete endpoint](https://platform.claude.com/docs/en/api/deleting-message-batches) in the Message Batches API.
661* We've added support for a [delete endpoint](https://platform.claude.com/docs/en/api/messages/batches/delete) in the Message Batches API.
656662 
657663### December 17th, 2024
658664 

about-claude/glossary Changed · +1 / -1 lines

from line 32
3232 
3333## MCP (Model Context Protocol)
3434 
35Model Context Protocol (MCP) is an open protocol that standardizes how applications provide context to LLMs. Like a USB-C port for AI applications, MCP provides a unified way to connect AI models to different data sources and tools. MCP enables AI systems to maintain consistent context across interactions and access external resources in a standardized manner. See the [MCP documentation](https://platform.claude.com/docs/en/mcp) to learn more.
35Model Context Protocol (MCP) is an open protocol that standardizes how applications provide context to LLMs. Like a USB-C port for AI applications, MCP provides a unified way to connect AI models to different data sources and tools. MCP enables AI systems to maintain consistent context across interactions and access external resources in a standardized manner. See the [MCP documentation](https://modelcontextprotocol.io/) to learn more.
3636 
3737## MCP connector
3838 
Feedback