One read of Claude Developer Platformapi-20260930T233759Z
343 pages moved out of 740 read.
What this read moved
151-175 of 343, page 7 of 14This capture is too large to show at once. Changes 151-175 of 343 are below, significant first; the rest are on the following screens.
api/organization/workspaces/service_accounts/list New page · 105 lines, new page
# List Service Account Workspace Members ## Path parameters ## Query parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
---
title: List Service Account Workspace Members
url: https://platform.claude.com/docs/en/api/organization/workspaces/service_accounts/list
---
# List Service Account Workspace Members
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List the service accounts that are members of a workspace.
Each entry includes the service account's `workspace_role`. Use `limit`
and the `next_page` cursor to paginate. Archived workspaces return 400;
use `GET /service_accounts/{id}/workspaces` to audit memberships of an
archived workspace. The implicit default-workspace membership is not
included in this list. Memberships of archived service accounts are
omitted from the results.
## Path parameters
- `workspace_id: string`
ID of the workspace.
## Query parameters
- `limit: optional number`
Number of results per page.
default: 20, minimum: 1, maximum: 100
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
## Returns
- `data: array of ServiceAccountWorkspaceMember`
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: WorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
],
"next_page": "next_page"
}
```
api/organization/workspaces/service_accounts/remove New page · 61 lines, new page
# Delete Service Account Workspace Member ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
---
title: Delete Service Account Workspace Member
url: https://platform.claude.com/docs/en/api/organization/workspaces/service_accounts/remove
---
# Delete Service Account Workspace Member
**DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Remove a service account from a workspace.
Removal is idempotent (returns 200 even if the membership was already
removed). A DELETE against the implicit default-workspace membership
returns 200 but is a no-op and the membership persists; deleting an
explicit default-workspace row reverts to the implicit `workspace_user`
membership. Archived workspaces return 400.
## Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
## Returns
- `type: "service_account_workspace_member_deleted"`
default: service_account_workspace_member_deleted
- `service_account_id: string`
Tagged service account ID (`svac_...`) named in the delete request. Removal is idempotent; see the endpoint description for the implicit-membership no-op.
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`) named in the delete request.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-X DELETE \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"service_account_id": "service_account_id",
"type": "service_account_workspace_member_deleted",
"workspace_id": "workspace_id"
}
```
api/organization/workspaces/service_accounts/retrieve New page · 88 lines, new page
# Get Service Account Workspace Member ## Path parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
---
title: Get Service Account Workspace Member
url: https://platform.claude.com/docs/en/api/organization/workspaces/service_accounts/retrieve
---
# Get Service Account Workspace Member
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Retrieve a service account's membership in a workspace.
Returns the membership record, including the service account's
`workspace_role` in this workspace. Archived workspaces return 400. For
the default workspace, returns the implicit (`implicit: true`)
membership when no explicit membership exists; an explicitly added
membership is returned with its assigned role. An archived service
account returns 404.
## Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
## Returns
- `ServiceAccountWorkspaceMember object`
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: WorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
api/organization/workspaces/service_accounts/update New page · 106 lines, new page
# Update Service Account Workspace Member ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
---
title: Update Service Account Workspace Member
url: https://platform.claude.com/docs/en/api/organization/workspaces/service_accounts/update
---
# Update Service Account Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Change a service account's role in a workspace.
The new `workspace_role` replaces the current one. Only explicit
memberships can be updated; to set a role on the implicit
default-workspace membership, add the service account explicitly with
`POST /workspaces/{workspace_id}/service_accounts`. Archived workspaces
return 400. Archived service accounts cannot be updated and are
rejected.
## Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
## Body parameters
- `workspace_role: NoBillingWorkspaceRole`
New role for the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Returns
- `ServiceAccountWorkspaceMember object`
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: WorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"workspace_role": "workspace_admin"
}'
```
### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
api/organization/workspaces/update New page · 207 lines, new page
# Update Workspace ## Path parameters ## Body parameters ## Returns ## Example ### Response (200)
A whole new page. There's nothing to diff it against, so here is what it says.
---
title: Update Workspace
url: https://platform.claude.com/docs/en/api/organization/workspaces/update
---
# Update Workspace
**POST** `/v1/organizations/workspaces/{workspace_id}`
Update Workspace
## Path parameters
- `workspace_id: string`
## Body parameters
- `data_residency: optional DataResidencyUpdateConfig or null`
Data residency configuration for the workspace.
- `allowed_inference_geos: optional array of AllowedInferenceGeo or "unrestricted" or null`
Permitted inference geo values. Use 'unrestricted' to allow all geos, or a list of specific geos.
- `Geos = array of AllowedInferenceGeo`
- `"global"`
- `"us"`
- `"unrestricted"`
- `default_inference_geo: optional "global" or "us" or null`
Default inference geo applied when requests omit the parameter. Must be a member of `allowed_inference_geos` unless `allowed_inference_geos` is `"unrestricted"`.
- `"global"`
- `"us"`
- `display_color: optional string`
Hex color code representing the Workspace in the Anthropic Console.
maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$
- `external_key_id: optional string`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. On
Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a
single-Region key in the same AWS account and Region as the Workspace. On that
platform the key is validated against this Workspace when it is attached, so a
key-policy problem is reported as an error on this request. This field is write-once:
once a key is attached to a Workspace it cannot be detached or replaced. To
rotate key material, rotate the underlying key on your cloud KMS; the
`external_key_id` stays the same.
- `name: optional string`
Name of the Workspace.
minLength: 1, maxLength: 40
- `tags: optional map[string] or null`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
## Returns
- `Workspace object`
- `type: "workspace"`
Object type.
For Workspaces, this is always `"workspace"`.
default: workspace
- `id: string`
ID of the Workspace.
- `archived_at: string or null`
RFC 3339 datetime string indicating when the Workspace was archived, or `null` if the Workspace is not archived.
format: date-time
- `compartment_id: string`
Identifier for this Workspace's encryption compartment. When you configure a
customer-managed encryption key (CMEK) on AWS, reference this value in your
KMS key-policy condition so the key is scoped to this compartment. On GCP and
Azure, Anthropic enforces the compartment binding automatically; you do not
need to reference this value in your key configuration. See the CMEK
integration guide for the required key configuration; unless your organization
is on Claude Platform on AWS, it includes a separate value used during key
validation. On Claude Platform on AWS there is no separate validation value:
the key is validated against this Workspace's own value when it is attached, so
if your key policy uses the compartment condition, add this value to it before
attaching the key.
- `created_at: string`
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
- `data_residency: DataResidency`
Data residency configuration.
- `allowed_inference_geos: array of AllowedInferenceGeo or "unrestricted"`
Permitted inference geo values. 'unrestricted' means all geos are allowed.
- `Geos = array of AllowedInferenceGeo`
- `"global"`
- `"us"`
- `"unrestricted"`
- `default_inference_geo: "global" or "us"`
Default inference geo applied when requests omit the parameter.
- `"global"`
- `"us"`
- `workspace_geo: "us"`
Geographic region for workspace data storage. Immutable after creation.
- `display_color: string`
Hex color code representing the Workspace in the Anthropic Console.
- `external_key_id: string or null`
ID of the customer-managed encryption key (CMEK) configuration to use for this
Workspace. Setting this field requires CMEK to be enabled for your
organization. When set, data stored for this Workspace is encrypted with the
referenced key. Create key configurations with the External Keys API. On
Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a
single-Region key in the same AWS account and Region as the Workspace. On that
platform the key is validated against this Workspace when it is attached, so a
key-policy problem is reported as an error on this request. This field is write-once:
once a key is attached to a Workspace it cannot be detached or replaced. To
rotate key material, rotate the underlying key on your cloud KMS; the
`external_key_id` stays the same.
- `name: string`
Name of the Workspace.
- `tags: map[string]`
User-defined tags as string key-value pairs. Keys may not begin with `anthropic`.
## Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"tags": {
"env": "prod",
"team": "platform"
}
}'
```
### Response (200)
```json
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "global",
"workspace_geo": "us"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
```
build-with-claude/claude-in-microsoft-foundry Changed · +17 / -17 lines
build-with-claude/claude-on-amazon-bedrock-legacy Changed · +10 / -10 lines
build-with-claude/claude-on-vertex-ai Changed · +21 / -21 lines
build-with-claude/claude-platform-on-aws Changed · +15 / -15 lines
build-with-claude/preserved-thinking Changed · +4 / -4 lines
build-with-claude/thinking-troubleshooting Changed · +2 / -2 lines
## A 400 error after sending `thinking: {type: "disabled"}` ## A 400 error says `"thinking.type.disabled"` is not supported