One read of Claude Documentationclaude-docs-20260928T200706Z
5 pages moved out of 255 read.
Pages moved
5
significant first
Pages read
255
in this capture
Captured
20:07 UTC
Corpus hash
a159f45766b2
corpus-hash
What this read moved
1-5 of 5claude-tag/admins/customize Changed · +2 / -2 lines
## Name, handle, and avatar of the Claude app ## Settings no one can change
from line 145
145145
146146<Warning>Once you add an allow rule, Claude runs the actions it names in every channel the scope covers without anyone approving them in the moment. Keep each rule narrow: name the tool, the action, and the environment it allows, and put rules that unlock sensitive systems on the narrowest scope that needs them.</Warning>
147147
148## Settings no one can change
148## Name, handle, and avatar of the Claude app
149149
150* The Claude app's name, @-handle, and avatar in Slack are the same in every workspace; there is no rename or rebrand setting.
150The Claude app's name, @-handle, and avatar in Slack are the same in every workspace; there is no rename or rebrand setting.
151151
152152## Related resources
153153
claude-tag/admins/federated-access/troubleshooting Changed · +9 / -9 lines
from line 211
211211
212212* **A hostname with no usable region.** Agent Proxy reads the AWS service and signing region from the hostname, so the region must be the last label before `amazonaws.com`, as in `service.region.amazonaws.com`, `my-bucket.s3.us-east-1.amazonaws.com`, or `api.ecr.us-east-1.amazonaws.com`. The [AWS SigV4 credential](/docs/claude-tag/admins/connections/custom#aws-sigv4) section lists the hostname forms Agent Proxy signs, including the services it signs with no region.
213213* **A large request to a service other than S3 with no content hash.** When a request has no `x-amz-content-sha256` header, Agent Proxy hashes the body before signing and refuses a body over 1 MB (1,048,576 bytes). The AWS CLI and SDKs add that header for S3 but usually not for other services.
214* **An S3 upload sent in chunks.** The AWS CLI (2.23.0 and later) and the AWS SDKs that compute upload checksums by default can send S3 uploads in chunks with a checksum trailer. Agent Proxy can't sign a request in that format. The fix is to have the AWS CLI or SDK send the body in one piece.
214* **An S3 upload with signed chunks.** Agent Proxy signs the uploads the AWS CLI and SDKs send by default, including an upload sent in chunks with a checksum trailer. It can't sign an upload whose chunks the client signs one by one, which the CLI and SDKs do only when payload signing is turned on for the profile. The reason text reads `chunked signing (<mode>) is not supported through the proxy`.
215215
216216**How to resolve**
217217
218| Cause | Do this |
219| :--------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
220| Hostname with no usable region | Use the service's regional endpoint, `service.region.amazonaws.com` (for S3, also `bucket.s3.region.amazonaws.com`), and make sure that host is in the connection's **Allowed hosts**. A host that exists only with the region before the service name, such as an OpenSearch domain endpoint, can't be reached through a federated connection. [Contact Anthropic](#contact-anthropic) with the hostname. |
221| Large request to a service other than S3 | Keep the body under 1 MB, or have Claude send the request with an `x-amz-content-sha256` header set to the hex SHA-256 of the body, for example with `curl`. For large data, upload to S3 and pass a reference instead. |
222| S3 upload sent in chunks | Have Claude set the environment variable `AWS_REQUEST_CHECKSUM_CALCULATION=WHEN_REQUIRED` before running the AWS CLI or a script that uses an AWS SDK, or add `request_checksum_calculation = WHEN_REQUIRED` to the profile in `~/.aws/config`, then retry. To apply it in every thread, add a line to the scope's [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions), for example "Before using the AWS CLI or an AWS SDK, add `request_checksum_calculation = WHEN_REQUIRED` to the default profile in `~/.aws/config`." S3 still computes and stores a checksum for the object. If the upload still fails, [contact Anthropic](#contact-anthropic). |
218| Cause | Do this |
219| :--------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
220| Hostname with no usable region | Use the service's regional endpoint, `service.region.amazonaws.com` (for S3, also `bucket.s3.region.amazonaws.com`), and make sure that host is in the connection's **Allowed hosts**. A host that exists only with the region before the service name, such as an OpenSearch domain endpoint, can't be reached through a federated connection. [Contact Anthropic](#contact-anthropic) with the hostname. |
221| Large request to a service other than S3 | Keep the body under 1 MB, or have Claude send the request with an `x-amz-content-sha256` header set to the hex SHA-256 of the body, for example with `curl`. For large data, upload to S3 and pass a reference instead. |
222| S3 upload with signed chunks | Have Claude remove `payload_signing_enabled = true` from the profile in `~/.aws/config`, or add `request_checksum_calculation = WHEN_REQUIRED` to that profile as the reason text suggests, then retry. Either change makes the client send the upload in a form Agent Proxy signs. If the upload still fails, [contact Anthropic](#contact-anthropic). |
223223
224224### The cloud API answers 403 after a successful exchange
225225
claude-tag/admins/connections/custom Changed · +1 / -1 lines
from line 74
7474
7575Use long-lived credentials from a dedicated IAM user where you can. Temporary STS credentials work but expire on their own schedule, and the connection stops working when they do; you re-enter all three values to rotate.
7676
77Claude can call the endpoint with `curl`, an AWS SDK, or the AWS CLI. The sandbox holds no real AWS credentials, so a CLI or SDK signs the request with placeholder values; Agent Proxy strips that signature and re-signs with the stored credential before the request leaves for AWS. Agent Proxy can't sign an S3 upload sent in chunks with a checksum trailer, which the AWS CLI and the AWS SDKs send when they compute upload checksums by default. That upload fails with HTTP 502 and a reason that begins `injection failed ("<connection name>")`. Have Claude add `request_checksum_calculation = WHEN_REQUIRED` to the profile in `~/.aws/config` and retry. The federated-access troubleshooting entry [An AWS request fails after a successful sign-in](/docs/claude-tag/admins/federated-access/troubleshooting#an-aws-request-fails-after-a-successful-sign-in) gives the same fix, the environment-variable form, and how to apply the setting in every thread.
77Claude can call the endpoint with `curl`, an AWS SDK, or the AWS CLI. The sandbox holds no real AWS credentials, so a CLI or SDK signs the request with placeholder values; Agent Proxy strips that signature and re-signs with the stored credential before the request leaves for AWS. If a request comes back with HTTP 502 and a reason that begins `injection failed ("<connection name>")`, Agent Proxy couldn't sign it. The troubleshooting entry [An AWS request fails after a successful sign-in](/docs/claude-tag/admins/federated-access/troubleshooting#an-aws-request-fails-after-a-successful-sign-in) lists each cause the reason text names and its fix; the causes and fixes are the same for a connection that stores an access key.
7878
7979#### When AWS returns `SignatureDoesNotMatch`
8080
claude-tag/overview Changed · +1 / -1 lines
from line 6
66 <div className="tm-hero-copy">
77 <span className="tm-pill">Public Beta</span>
88 <p className="tm-hero-title">Tag <span className="tm-hero-at">@Claude</span> in. Get results back in the thread.</p>
9 <p className="tm-hero-lede">Anyone in a channel can tag Claude into a problem and hand it work: reproduce a bug and open a pull request, turn a decision thread into a doc, assemble the state of a project. It posts a checklist in the thread as it goes, and the whole exchange stays visible to the channel.</p>
9 <p className="tm-hero-lede">Anyone in a Slack channel can tag Claude into a problem and hand it work: reproduce a bug and open a pull request, turn a decision thread into a doc, assemble the state of a project. It posts a checklist in the thread as it goes, and the whole exchange stays visible to the channel.</p>
1010
1111 <div className="tm-hero-ctas">
1212 <a className="tm-btn tm-btn-dark" href="/docs/claude-tag/admins/setup-overview">I'm setting it up →</a>
claude-tag/users/models Changed · +2 / -0 lines
from line 54
5454
5555If you ask for a model that isn't on the list, Claude tells you it isn't available, and the thread stays on the model it was already using.
5656
57For how your organization's model settings apply in Slack, see [Models your organization allows](/docs/claude-tag/admins/customize#models-your-organization-allows).
58
5759## Related resources
5860
5961* [Get started](/docs/claude-tag/users/getting-started): what else the reply footer links to