Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial
A new release is waiting v2.1.285 npm has it, but its platform binary is not downloadable yet
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260928T220706Z

157 pages moved out of 255 read.

Pages moved 157 significant first
Pages read 255 in this capture
Captured 22:07 UTC
Corpus hash 9aad7bf66b91 corpus-hash

What this read moved

26-50 of 157, page 2 of 7

This capture is too large to show at once. Changes 26-50 of 157 are below, significant first; the rest are on the following screens.

claude-tag/admins/connections/gong Changed · +4 / -4 lines

from line 24
2424 
2525In the bundle, click **Connect** next to **Gong**.
2626 
27| Field | Value |
28| :------------------------- | :------------------------------ |
29| Claude's access key | The access key from Gong |
27| Field | Value |
28| :- | :- |
29| Claude's access key | The access key from Gong |
3030| Claude's access key secret | The access key secret from Gong |
31| Allowed websites | `api.gong.io` (preset) |
31| Allowed websites | `api.gong.io` (preset) |
3232 
3333Gong assigns each company its own API base URL, like `us-46459.api.gong.io`. Copy yours from **Company Settings** → **Ecosystem** → **API** in Gong, then switch to the connection form's **Advanced** tab and enter it under **Allowed websites**.
3434 

claude-tag/admins/connections/google Changed · +9 / -9 lines

from line 16
1616 
1717The connection picker offers two routes:
1818 
19| Route | When to use |
20| :-------------------------- | :---------------------------------------------------------------------------------------------------------------------------------- |
21| **OAuth (Connect button)** | Fastest path. An admin signs in with a Google account that has access to the content Claude needs. |
19| Route | When to use |
20| :- | :- |
21| **OAuth (Connect button)** | Fastest path. An admin signs in with a Google account that has access to the content Claude needs. |
2222| **GCP service-account key** | When you want a dedicated non-human identity in Google with auditable access, or need domain-wide delegation across your Workspace. |
2323 
2424Both routes create a credential and an allowed-websites rule for the Google hosts the connection uses.
from line 35
3535 
3636In the bundle, click **Connect** next to **Custom tool** and choose **GCP access token (with Service Account Key)**.
3737 
38| Field | Value |
39| :----------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
40| GCP service account key (JSON) | The JSON key file from Google Cloud Console |
41| Scopes (optional) | The Google API scopes to request (for example `https://www.googleapis.com/auth/drive.readonly`). If you leave the field empty, the connection requests `https://www.googleapis.com/auth/cloud-platform`. |
42| Subject (optional) | A user email to impersonate via domain-wide delegation. Set this for Workspace data (Drive, Calendar, Gmail, Docs). |
43| Allowed websites | `*.googleapis.com` |
38| Field | Value |
39| :- | :- |
40| GCP service account key (JSON) | The JSON key file from Google Cloud Console |
41| Scopes (optional) | The Google API scopes to request (for example `https://www.googleapis.com/auth/drive.readonly`). If you leave the field empty, the connection requests `https://www.googleapis.com/auth/cloud-platform`. |
42| Subject (optional) | A user email to impersonate via domain-wide delegation. Set this for Workspace data (Drive, Calendar, Gmail, Docs). |
43| Allowed websites | `*.googleapis.com` |
4444 
4545For Google Workspace data (Drive, Calendar, Gmail, Docs), the service account needs domain-wide delegation configured in your Google Admin console. In the service account's domain-wide delegation entry, list every scope you entered in **Scopes**, or `https://www.googleapis.com/auth/cloud-platform` if you left **Scopes** empty. Google's guide is at [developers.google.com/identity/protocols/oauth2/service-account](https://developers.google.com/identity/protocols/oauth2/service-account#delegatingauthority).
4646 

claude-tag/admins/connections/hubspot Changed · +4 / -4 lines

from line 22
2222 
2323In the bundle, click **Connect** next to **HubSpot**.
2424 
25| Field | Value |
26| :------------------------- | :---------------------------------------------------------------------------- |
27| Claude's private app token | The private app token from HubSpot |
28| Allowed websites | `api.hubapi.com` (preset). To add a different host, use the **Advanced** tab. |
25| Field | Value |
26| :- | :- |
27| Claude's private app token | The private app token from HubSpot |
28| Allowed websites | `api.hubapi.com` (preset). To add a different host, use the **Advanced** tab. |
2929 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 

claude-tag/admins/connections/linear Changed · +3 / -3 lines

from line 24
2424 
2525In the bundle, click **Connect** next to **Linear**.
2626 
27| Field | Value |
28| :--------------- | :---------------------- |
27| Field | Value |
28| :- | :- |
2929| Claude's API key | The API key from Linear |
30| Allowed websites | `api.linear.app` |
30| Allowed websites | `api.linear.app` |
3131 
3232The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3333 

claude-tag/admins/connections/notion Changed · +3 / -3 lines

from line 22
2222 
2323In the bundle, click **Connect** next to **Notion**.
2424 
25| Field | Value |
26| :-------------------------- | :------------------------------------------ |
25| Field | Value |
26| :- | :- |
2727| Claude's integration secret | The internal integration secret from Notion |
28| Allowed websites | `api.notion.com` |
28| Allowed websites | `api.notion.com` |
2929 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 

claude-tag/admins/connections/overview Changed · +19 / -19 lines

from line 10
1010 
1111<Warning>Always connect a dedicated account for Claude (for example, `[email protected]`), not your personal login. Anyone in a channel under the bundle's [scope](/docs/claude-tag/admins/attach-to-scope) can use the connection through Claude, so whatever this account can reach is available to every member of those channels. See [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service).</Warning>
1212 
13| Service | Category | Guide |
14| :------------------------------ | :----------------- | :---------------------------------------------------------------------- |
15| Datadog | Monitoring | [Connect Datadog](/docs/claude-tag/admins/connections/datadog) |
16| Sentry | Monitoring | [Connect Sentry](/docs/claude-tag/admins/connections/sentry) |
17| PagerDuty | Monitoring | [Connect PagerDuty](/docs/claude-tag/admins/connections/pagerduty) |
18| Linear | Issue tracking | [Connect Linear](/docs/claude-tag/admins/connections/linear) |
19| Asana | Issue tracking | [Connect Asana](/docs/claude-tag/admins/connections/asana) |
20| Jira and Confluence | Issue tracking | [Connect Jira and Confluence](/docs/claude-tag/admins/connections/atlassian) |
21| Notion | Knowledge and docs | [Connect Notion](/docs/claude-tag/admins/connections/notion) |
22| Google (Drive, Calendar, Gmail) | Knowledge and docs | [Connect Google](/docs/claude-tag/admins/connections/google) |
23| HubSpot | Go-to-market | [Connect HubSpot](/docs/claude-tag/admins/connections/hubspot) |
24| Salesforce | Go-to-market | [Connect Salesforce](/docs/claude-tag/admins/connections/salesforce) |
25| Gong | Go-to-market | [Connect Gong](/docs/claude-tag/admins/connections/gong) |
26| GitLab | Code | [Connect GitLab](/docs/claude-tag/admins/connections/gitlab) |
27| BigQuery (custom) | Data warehouse | [Connect BigQuery](/docs/claude-tag/admins/connections/bigquery) |
28| Snowflake | Data warehouse | [Connect Snowflake](/docs/claude-tag/admins/connections/snowflake) |
29| Amplitude | Product analytics | [Connect Amplitude](/docs/claude-tag/admins/connections/amplitude) |
30| Stripe | Billing | [Connect Stripe](/docs/claude-tag/admins/connections/stripe) |
31| Vercel | Deployments | [Connect Vercel](/docs/claude-tag/admins/connections/vercel) |
13| Service | Category | Guide |
14| :- | :- | :- |
15| Datadog | Monitoring | [Connect Datadog](/docs/claude-tag/admins/connections/datadog) |
16| Sentry | Monitoring | [Connect Sentry](/docs/claude-tag/admins/connections/sentry) |
17| PagerDuty | Monitoring | [Connect PagerDuty](/docs/claude-tag/admins/connections/pagerduty) |
18| Linear | Issue tracking | [Connect Linear](/docs/claude-tag/admins/connections/linear) |
19| Asana | Issue tracking | [Connect Asana](/docs/claude-tag/admins/connections/asana) |
20| Jira and Confluence | Issue tracking | [Connect Jira and Confluence](/docs/claude-tag/admins/connections/atlassian) |
21| Notion | Knowledge and docs | [Connect Notion](/docs/claude-tag/admins/connections/notion) |
22| Google (Drive, Calendar, Gmail) | Knowledge and docs | [Connect Google](/docs/claude-tag/admins/connections/google) |
23| HubSpot | Go-to-market | [Connect HubSpot](/docs/claude-tag/admins/connections/hubspot) |
24| Salesforce | Go-to-market | [Connect Salesforce](/docs/claude-tag/admins/connections/salesforce) |
25| Gong | Go-to-market | [Connect Gong](/docs/claude-tag/admins/connections/gong) |
26| GitLab | Code | [Connect GitLab](/docs/claude-tag/admins/connections/gitlab) |
27| BigQuery (custom) | Data warehouse | [Connect BigQuery](/docs/claude-tag/admins/connections/bigquery) |
28| Snowflake | Data warehouse | [Connect Snowflake](/docs/claude-tag/admins/connections/snowflake) |
29| Amplitude | Product analytics | [Connect Amplitude](/docs/claude-tag/admins/connections/amplitude) |
30| Stripe | Billing | [Connect Stripe](/docs/claude-tag/admins/connections/stripe) |
31| Vercel | Deployments | [Connect Vercel](/docs/claude-tag/admins/connections/vercel) |
3232 
3333GitHub is managed through the Claude GitHub App rather than a connection in this list; see [Configure GitHub access](/docs/claude-tag/admins/configure-github).
3434 

claude-tag/admins/connections/pagerduty Changed · +3 / -3 lines

from line 24
2424 
2525In the bundle, click **Connect** next to **PagerDuty**.
2626 
27| Field | Value |
28| :--------------- | :------------------------- |
27| Field | Value |
28| :- | :- |
2929| Claude's API key | The api key from PagerDuty |
30| Allowed websites | `api.pagerduty.com` |
30| Allowed websites | `api.pagerduty.com` |
3131 
3232PagerDuty accounts on the EU service region use `api.eu.pagerduty.com` instead.
3333 

claude-tag/admins/connections/salesforce Changed · +7 / -7 lines

from line 26
2626 
2727In the bundle, click **Connect** next to **Salesforce**.
2828 
29| Field | Value |
30| :---------------- | :--------------------------------------------------------------------------------------- |
31| Client ID | The app's Consumer Key |
32| Client secret | The app's Consumer Secret |
33| Token URL | Your org's token endpoint, `https://yourcompany.my.salesforce.com/services/oauth2/token` |
34| Scopes (optional) | Leave empty unless your app requires specific scopes |
35| Allowed websites | Your org's host, for example `yourcompany.my.salesforce.com` |
29| Field | Value |
30| :- | :- |
31| Client ID | The app's Consumer Key |
32| Client secret | The app's Consumer Secret |
33| Token URL | Your org's token endpoint, `https://yourcompany.my.salesforce.com/services/oauth2/token` |
34| Scopes (optional) | Leave empty unless your app requires specific scopes |
35| Allowed websites | Your org's host, for example `yourcompany.my.salesforce.com` |
3636 
3737The preset prefills Allowed websites with an example host that cannot resolve. Replace it with your org's host before saving, or every request fails. To change the host later, open the **⋮** menu on this connection in the bundle's Credentials tab and choose **Edit**.
3838 

claude-tag/admins/connections/sentry Changed · +3 / -3 lines

from line 24
2424 
2525In the bundle, click **Connect** next to **Sentry**.
2626 
27| Field | Value |
28| :------------------ | :---------------------- |
27| Field | Value |
28| :- | :- |
2929| Claude's auth token | The api key from Sentry |
30| Allowed websites | `sentry.io` |
30| Allowed websites | `sentry.io` |
3131 
3232Self-hosted Sentry uses your own hostname instead of `sentry.io`.
3333 

claude-tag/admins/connections/snowflake Changed · +4 / -4 lines

from line 22
2222 
2323In the bundle, click **Connect** next to **Snowflake**.
2424 
25| Field | Value |
26| :--------------------------------- | :---------------------------------------------------------------------------- |
27| Claude's programmatic access token | The programmatic access token from Snowflake |
28| Allowed websites | Your account's host, for example `yourorg-youraccount.snowflakecomputing.com` |
25| Field | Value |
26| :- | :- |
27| Claude's programmatic access token | The programmatic access token from Snowflake |
28| Allowed websites | Your account's host, for example `yourorg-youraccount.snowflakecomputing.com` |
2929 
3030The preset prefills Allowed websites with an example host that cannot resolve. Replace it with your account's host before saving, or every request fails. To change the host later, open the **⋮** menu on this connection in the bundle's Credentials tab and choose **Edit**.
3131 

claude-tag/admins/connections/stripe Changed · +4 / -4 lines

from line 22
2222 
2323In the bundle, click **Connect** next to **Stripe**.
2424 
25| Field | Value |
26| :------------------ | :---------------------------------------------------------------------------- |
27| Claude's secret key | The secret key from Stripe |
28| Allowed websites | `api.stripe.com` (preset). To add a different host, use the **Advanced** tab. |
25| Field | Value |
26| :- | :- |
27| Claude's secret key | The secret key from Stripe |
28| Allowed websites | `api.stripe.com` (preset). To add a different host, use the **Advanced** tab. |
2929 
3030The field labeled Claude's secret key accepts a restricted key; the label is the field name, not a key-type constraint.
3131 

claude-tag/admins/connections/vercel Changed · +3 / -3 lines

from line 22
2222 
2323In the bundle, click **Connect** next to **Vercel**.
2424 
25| Field | Value |
26| :-------------------- | :--------------------------- |
25| Field | Value |
26| :- | :- |
2727| Claude's access token | The access token from Vercel |
28| Allowed websites | `api.vercel.com` |
28| Allowed websites | `api.vercel.com` |
2929 
3030The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See [how Agent Proxy works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
3131 

claude-tag/admins/customize Changed · +31 / -31 lines

from line 8
88 
99Claude Tag's behavior is shaped by four layers, each set in a different place:
1010 
11| Layer | What it is | Who sets it | Where |
12| :---------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| **Connections** | Credentials for the systems Claude can reach (GitHub, Drive, Datadog, your APIs) | Owner; a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | [Access bundles](/docs/claude-tag/admins/add-connections), or the channel's Configure page for a channel manager |
14| **Plugins and skills** | Instructions that teach Claude how to use a tool or follow a process. A plugin bundles one or more [skills](https://code.claude.com/docs/en/skills). | Owner; channel members can add plugins to their channel unless an admin restricts editing | [Bundle Plugins tab](/docs/claude-tag/admins/add-connections#attach-plugins), a [skills repository](/docs/claude-tag/admins/skills-repo), or the channel's Configure page |
15| **Custom instructions** | Standing guidance read in every session at a scope (team conventions, output formats). Outranks channel memory. | Owner for any scope; channel members for the channel scope, from the [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel) | [Per-scope instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
16| **Channel memory** | Facts Claude saves while working in a channel | Anyone in the channel | By [telling Claude](/docs/claude-tag/users/memory) |
11| Layer | What it is | Who sets it | Where |
12| :- | :- | :- | :- |
13| **Connections** | Credentials for the systems Claude can reach (GitHub, Drive, Datadog, your APIs) | Owner; a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | [Access bundles](/docs/claude-tag/admins/add-connections), or the channel's Configure page for a channel manager |
14| **Plugins and skills** | Instructions that teach Claude how to use a tool or follow a process. A plugin bundles one or more [skills](https://code.claude.com/docs/en/skills). | Owner; channel members can add plugins to their channel unless an admin restricts editing | [Bundle Plugins tab](/docs/claude-tag/admins/add-connections#attach-plugins), a [skills repository](/docs/claude-tag/admins/skills-repo), or the channel's Configure page |
15| **Custom instructions** | Standing guidance read in every session at a scope (team conventions, output formats). Outranks channel memory. | Owner for any scope; channel members for the channel scope, from the [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel) | [Per-scope instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
16| **Channel memory** | Facts Claude saves while working in a channel | Anyone in the channel | By [telling Claude](/docs/claude-tag/users/memory) |
1717 
1818Connections and plugins decide what Claude *can do*; instructions and memory shape *how it does it*.
1919 
from line 21
2121 
2222Access and organization-wide behavior are set at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), per scope (a scope is a channel, a workspace, or your whole organization), so the same agent can work differently in different channels. Most controls below are Owner-only.
2323 
24| Setting | What it does | More |
25| :-------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------- |
26| Custom instructions | Standing guidance read in every session on a scope, like team conventions. Outranks channel memory. | [Add custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
27| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. **Respond automatically** exists only on channels, not on workspaces or your whole organization. Channel members can change it too, from Slack or the channel's Configure page, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
28| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
29| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
30| Default model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
31| Auto mode allow rules | Actions pre-approved in a scope's sessions that Claude's permission checker would otherwise flag or stop | [Auto mode allow rules](#auto-mode-allow-rules) |
32| Environment | Which cloud environment a scope's sessions run in | [Configure the environment for a scope](#configure-the-environment-for-a-scope) |
33| Enable Claude Tag | Turns Claude on or off in a scope | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
34| Claude Tag version | Which generation answers in a scope (**New** or **Legacy**) | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
24| Setting | What it does | More |
25| :- | :- | :- |
26| Custom instructions | Standing guidance read in every session on a scope, like team conventions. Outranks channel memory. | [Add custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
27| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. **Respond automatically** exists only on channels, not on workspaces or your whole organization. Channel members can change it too, from Slack or the channel's Configure page, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
28| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
29| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
30| Default model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
31| Auto mode allow rules | Actions pre-approved in a scope's sessions that Claude's permission checker would otherwise flag or stop | [Auto mode allow rules](#auto-mode-allow-rules) |
32| Environment | Which cloud environment a scope's sessions run in | [Configure the environment for a scope](#configure-the-environment-for-a-scope) |
33| Enable Claude Tag | Turns Claude on or off in a scope | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
34| Claude Tag version | Which generation answers in a scope (**New** or **Legacy**) | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
3535 
3636### Channel connections are separate from personal connectors
3737 
from line 43
4343 
4444Everything in the table below is open to channel members, with no admin involved.
4545 
46| To change | Say something like | More |
47| :----------------------------- | :--------------------------------------------------------- | :------------------------------------------------------------------------- |
48| How Claude formats output | "remember for this channel: post reports as a table" | [Memory](/docs/claude-tag/users/memory) |
49| How chatty Claude is | "ask before posting anything longer than a screen" | [Memory](/docs/claude-tag/users/memory) |
50| When Claude follows a thread | "stay quiet in this thread unless someone tags you" | [Control when Claude Tag responds](/docs/claude-tag/users/when-claude-responds) |
51| What Claude does on a schedule | "every morning at 9, post a digest of open threads" | [Set up routines](/docs/claude-tag/users/proactivity) |
52| What Claude remembers | "what do you remember about this channel?" then correct it | [Memory](/docs/claude-tag/users/memory) |
46| To change | Say something like | More |
47| :- | :- | :- |
48| How Claude formats output | "remember for this channel: post reports as a table" | [Memory](/docs/claude-tag/users/memory) |
49| How chatty Claude is | "ask before posting anything longer than a screen" | [Memory](/docs/claude-tag/users/memory) |
50| When Claude follows a thread | "stay quiet in this thread unless someone tags you" | [Control when Claude Tag responds](/docs/claude-tag/users/when-claude-responds) |
51| What Claude does on a schedule | "every morning at 9, post a digest of open threads" | [Set up routines](/docs/claude-tag/users/proactivity) |
52| What Claude remembers | "what do you remember about this channel?" then correct it | [Memory](/docs/claude-tag/users/memory) |
5353 
5454Changes in the table above are saved to channel memory; verify one stuck by asking what it remembers.
5555 
from line 88
8888 
8989An environment carries a setup script, environment variables, and a network access level. Not everything a channel needs belongs there, so match each need to its place before you create one:
9090 
91| What the channel needs | Where to put it |
92| :------------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
93| A tool installed before Claude starts, such as a runtime or a database client | The environment's setup script, a Bash script whose installs are on disk before Claude starts work |
94| A value every session should see, such as a deployment target or a feature flag | The environment's environment variables, as `KEY=value` pairs, one per line |
95| Web access without a credential | The environment's network access level; see [broad web access through the environment](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) |
96| An API key, token, or other credential | A [connection](/docs/claude-tag/admins/add-connections), never an environment variable |
97| Setup for one repository, such as installing its dependencies | That repository's `CLAUDE.md`; see [install project dependencies](/docs/claude-tag/admins/configure-github#install-project-dependencies) |
91| What the channel needs | Where to put it |
92| :- | :- |
93| A tool installed before Claude starts, such as a runtime or a database client | The environment's setup script, a Bash script whose installs are on disk before Claude starts work |
94| A value every session should see, such as a deployment target or a feature flag | The environment's environment variables, as `KEY=value` pairs, one per line |
95| Web access without a credential | The environment's network access level; see [broad web access through the environment](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) |
96| An API key, token, or other credential | A [connection](/docs/claude-tag/admins/add-connections), never an environment variable |
97| Setup for one repository, such as installing its dependencies | That repository's `CLAUDE.md`; see [install project dependencies](/docs/claude-tag/admins/configure-github#install-project-dependencies) |
9898 
9999Keep credentials out of environment variables because every session on the environment reads them and Claude can print them. There is no separate secrets store. A connection stores the credential outside the sandbox and attaches it to matching requests at the network layer, so Claude uses the service without holding the raw value. [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) describes how. A connection also travels with the access bundle, so you choose channel by channel which sessions can use it. Repository-specific setup goes in `CLAUDE.md` so the people who maintain the repository keep it current. Claude reads it when it starts work in that repository.
100100 

claude-tag/admins/federated-access/authorization-server Changed · +8 / -8 lines

from line 30
3030 
3131In **Authorization servers**, click **Connect an authorization server**, enter your token endpoint in the **Token endpoint** field, enter your authorization server's issuer identifier in the **Issuer URL** field (or leave it empty if your server requires the token endpoint URL as the audience), and copy the **Issuer**, **JWKS URL**, **Audience**, and **Subject prefix** rows from the **Set your authorization server to accept these values** card. Then click **Cancel**; you register the endpoint after configuring the server.
3232 
33| Value | What to configure |
34| :------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
35| Issuer | `https://identity.anthropic.com/agents`, matched exactly. The OpenID Connect (OIDC) discovery document is at `https://identity.anthropic.com/agents/.well-known/openid-configuration`. |
36| JWKS URL | The JSON Web Key Set (JWKS) named by `jwks_uri` in the discovery document, `https://identity.anthropic.com/agents/jwks.json`. Accept ES256 only. Select the key by `kid`, and refetch the JWKS on an unknown `kid` before rejecting the token. |
37| Audience | Your authorization server's issuer identifier, as you enter it in the **Issuer URL** field when you connect the server, for example `https://auth.example.com`. It must be an HTTPS URL on the same host as the token endpoint. If your server requires the token endpoint URL as the audience instead, leave **Issuer URL** empty and the audience is the token endpoint address as the console stores it (the host lowercased, a bare trailing slash dropped, the rest kept as entered). Either way, copy the **Audience** row into your verifier rather than typing it. The `aud` claim is a JSON array with one element. Accept only this exact value, not any address on your host. |
38| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`. Every token's `sub` claim starts with this prefix and ends with one agent's ID; see the [subject](/docs/claude-tag/admins/federated-access/token-reference#subject) format. Agent IDs aren't shown in the console; your server learns them from the tokens it receives, and they change, for example when a Slack channel is deleted and recreated. |
39| Tenant | Your organization ID, the value between `/org/` and `/agent/` in the **Subject prefix**, carried in every token as the `tenant` claim. |
40| Expiry | Tokens expire 10 minutes after they're issued. Check `exp`, allowing up to 60 seconds of clock skew. |
33| Value | What to configure |
34| :- | :- |
35| Issuer | `https://identity.anthropic.com/agents`, matched exactly. The OpenID Connect (OIDC) discovery document is at `https://identity.anthropic.com/agents/.well-known/openid-configuration`. |
36| JWKS URL | The JSON Web Key Set (JWKS) named by `jwks_uri` in the discovery document, `https://identity.anthropic.com/agents/jwks.json`. Accept ES256 only. Select the key by `kid`, and refetch the JWKS on an unknown `kid` before rejecting the token. |
37| Audience | Your authorization server's issuer identifier, as you enter it in the **Issuer URL** field when you connect the server, for example `https://auth.example.com`. It must be an HTTPS URL on the same host as the token endpoint. If your server requires the token endpoint URL as the audience instead, leave **Issuer URL** empty and the audience is the token endpoint address as the console stores it (the host lowercased, a bare trailing slash dropped, the rest kept as entered). Either way, copy the **Audience** row into your verifier rather than typing it. The `aud` claim is a JSON array with one element. Accept only this exact value, not any address on your host. |
38| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`. Every token's `sub` claim starts with this prefix and ends with one agent's ID; see the [subject](/docs/claude-tag/admins/federated-access/token-reference#subject) format. Agent IDs aren't shown in the console; your server learns them from the tokens it receives, and they change, for example when a Slack channel is deleted and recreated. |
39| Tenant | Your organization ID, the value between `/org/` and `/agent/` in the **Subject prefix**, carried in every token as the `tenant` claim. |
40| Expiry | Tokens expire 10 minutes after they're issued. Check `exp`, allowing up to 60 seconds of clock skew. |
4141 
4242## Configure the authorization server
4343 

claude-tag/admins/federated-access/aws Changed · +4 / -4 lines

from line 20
2020 
2121In **Cloud roles**, click **Connect an AWS role** and copy the **Issuer**, **Audience**, and **Subject prefix** rows from the **Set the role's trust policy to accept these values** card. Then click **Cancel**; you connect the role after creating it in AWS.
2222 
23| Value | What it is |
24| :------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
25| Issuer | `https://identity.anthropic.com/agents`. The URL of the identity provider you create in AWS, including the `/agents` path. |
26| Audience | `sts.amazonaws.com`. The same for every organization, so it can't identify yours. |
23| Value | What it is |
24| :- | :- |
25| Issuer | `https://identity.anthropic.com/agents`. The URL of the identity provider you create in AWS, including the `/agents` path. |
26| Audience | `sts.amazonaws.com`. The same for every organization, so it can't identify yours. |
2727| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`. Every token's subject starts with this prefix and ends with one agent's ID. The trust policy must require at least this prefix. |
2828 
2929## Create the identity provider and role in AWS

claude-tag/admins/federated-access/connect-a-gateway Changed · +9 / -9 lines

from line 26
2626 
2727Claude authenticates with a JSON Web Token (JWT) in the `Authorization: Bearer` header of every request. It reuses one token for a session's requests for about five minutes, or until your gateway answers 401, and then requests a new one, so don't treat a repeated `jti` as a replay. Verify it with a standard JWT or OpenID Connect (OIDC) library configured with these values.
2828 
29| Value | What to configure |
30| :-------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
31| Issuer | `https://identity.anthropic.com/agents`, matched exactly. The OIDC discovery document is at `https://identity.anthropic.com/agents/.well-known/openid-configuration`. |
32| Signing keys | The JSON Web Key Set (JWKS) named by `jwks_uri` in the discovery document, `https://identity.anthropic.com/agents/jwks.json`. Accept ES256 only. On an unknown key ID, refetch the key set before rejecting the token. |
33| Audience | Your gateway address as the console stores it (the console converts the host to lowercase), for example `https://gateway.example.com`. The `aud` claim is a JSON array with one element, so use the library's audience option. |
34| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`, copied from the dialog. Every token's `sub` claim names one agent in one organization. |
35| Tenant | Your organization ID, the value between `/org/` and `/agent/` in the **Subject prefix**, carried in every token as the `tenant` claim. |
36| Control subject | A reserved test identity in your organization, copied from the dialog. Anthropic uses it only for the connection check. |
37| Expiry | Tokens expire 10 minutes after they're issued. Check `exp`, allowing up to 60 seconds of clock skew. |
29| Value | What to configure |
30| :- | :- |
31| Issuer | `https://identity.anthropic.com/agents`, matched exactly. The OIDC discovery document is at `https://identity.anthropic.com/agents/.well-known/openid-configuration`. |
32| Signing keys | The JSON Web Key Set (JWKS) named by `jwks_uri` in the discovery document, `https://identity.anthropic.com/agents/jwks.json`. Accept ES256 only. On an unknown key ID, refetch the key set before rejecting the token. |
33| Audience | Your gateway address as the console stores it (the console converts the host to lowercase), for example `https://gateway.example.com`. The `aud` claim is a JSON array with one element, so use the library's audience option. |
34| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`, copied from the dialog. Every token's `sub` claim names one agent in one organization. |
35| Tenant | Your organization ID, the value between `/org/` and `/agent/` in the **Subject prefix**, carried in every token as the `tenant` claim. |
36| Control subject | A reserved test identity in your organization, copied from the dialog. Anthropic uses it only for the connection check. |
37| Expiry | Tokens expire 10 minutes after they're issued. Check `exp`, allowing up to 60 seconds of clock skew. |
3838 
3939The subject check is yours to implement, and it's required, because every organization's tokens come from the same issuer; see [Authorize on the subject](/docs/claude-tag/admins/federated-access/token-reference#authorize-on-the-subject). Implement the check in one of two forms, strongest first:
4040 

claude-tag/admins/federated-access/gcp Changed · +8 / -8 lines

from line 23
2323 
2424In **Cloud roles**, click **Connect a Google Cloud identity** and copy the **Issuer** and **Subject prefix** rows from the **Set the workload identity provider to accept these values** card (the **JWKS URL** row isn't needed, because Google reads the keys from the issuer). Then click **Cancel**; you connect the identity after setting up Google Cloud.
2525 
26| Value | What it is |
27| :------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
28| Issuer | `https://identity.anthropic.com/agents`. The issuer URL of the provider you create in the pool. |
26| Value | What it is |
27| :- | :- |
28| Issuer | `https://identity.anthropic.com/agents`. The issuer URL of the provider you create in the pool. |
2929| Subject prefix | `wimse://identity.anthropic.com/org/<your organization ID>/agent/`. Every token's subject starts with this prefix and ends with one agent's ID. The organization ID between `/org/` and `/agent/` is also the value of the token's `tenant` claim. |
3030 
3131## Create the pool and provider in Google Cloud
from line 32
3232 
3333Create a workload identity pool and an OpenID Connect (OIDC) provider in it with these settings. Replace `<your organization ID>` with the ID from your **Subject prefix**.
3434 
35| Setting | Value |
36| :------------------ | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
37| Issuer URL | `https://identity.anthropic.com/agents` |
38| Allowed audiences | Leave at Google's default, the provider's own resource name, which Google accepts with or without a leading `https:`. Claude sends the name exactly as you enter it in Claude's admin settings, so if you pin allowed audiences instead, pin that same spelling. |
39| Attribute mapping | `google.subject` = `assertion.sub`. You can also map `attribute.org` = `assertion.tenant`, which lets you grant roles to all of your organization's agents as one principal set in [Grant access](#grant-access). |
35| Setting | Value |
36| :- | :- |
37| Issuer URL | `https://identity.anthropic.com/agents` |
38| Allowed audiences | Leave at Google's default, the provider's own resource name, which Google accepts with or without a leading `https:`. Claude sends the name exactly as you enter it in Claude's admin settings, so if you pin allowed audiences instead, pin that same spelling. |
39| Attribute mapping | `google.subject` = `assertion.sub`. You can also map `attribute.org` = `assertion.tenant`, which lets you grant roles to all of your organization's agents as one principal set in [Grant access](#grant-access). |
4040| Attribute condition | `assertion.sub == "<full subject>"` for one agent. To allow several agents, join one comparison per agent with CEL's or operator. To admit every agent in your organization instead, `assertion.sub.startsWith("wimse://identity.anthropic.com/org/<your organization ID>/agent/")`. |
4141 
4242Google doesn't require an attribute condition, and nothing checks it for you. Without one, agents of every other Claude Tag organization can authenticate to your pool, because every organization's tokens come from the same issuer; see [Authorize on the subject](/docs/claude-tag/admins/federated-access/token-reference#authorize-on-the-subject). The condition on `assertion.sub` is the subject check every connection type needs. The exact form accepts only the agents you list, and the prefix form accepts every agent in your organization, because every subject carries your organization ID between `/org/` and `/agent/`.

claude-tag/admins/federated-access/limits Changed · +40 / -40 lines

from line 14
1414 
1515## Identity token
1616 
17| Limit | Value |
18| :---------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
19| Token lifetime | 10 minutes. Tokens can't be revoked before they expire. When you remove a gateway, Claude stops using it at once; when you remove a cloud role or authorization server, within about a minute (current behavior, may change). A token issued before the removal stays valid until it expires. |
20| Signing algorithm | ES256 only. |
21| Claims | See the [identity token reference](/docs/claude-tag/admins/federated-access/token-reference#claims); verifiers must ignore claims they don't recognize. |
17| Limit | Value |
18| :- | :- |
19| Token lifetime | 10 minutes. Tokens can't be revoked before they expire. When you remove a gateway, Claude stops using it at once; when you remove a cloud role or authorization server, within about a minute (current behavior, may change). A token issued before the removal stays valid until it expires. |
20| Signing algorithm | ES256 only. |
21| Claims | See the [identity token reference](/docs/claude-tag/admins/federated-access/token-reference#claims); verifiers must ignore claims they don't recognize. |
2222 
2323## Gateways
2424 
25| Limit | Value |
26| :------------------------------------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
27| Registered addresses per organization | 5, counting gateways and authorization-server token endpoints together. |
28| Token reuse | Claude reuses one token for a session's requests to the same gateway for about five minutes, half the token's lifetime, or until the gateway answers 401, and then requests a new one (current behavior, may change). A gateway sees the same `jti` on many requests. |
29| Gateway address | An HTTPS host name only, with no path, port, query, or trailing slash. The host name needs a domain, like `gateway.example.com`, uses only letters, numbers, hyphens, and dots, and has at most 253 characters (current behavior, may change). The console rejects an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange, and names the reason. The connection check also refuses a host name that resolves to a private address. |
30| One connection per gateway | A gateway connected in one Access bundle can't be connected again in another. Attach that bundle to each scope that needs the gateway. |
31| [Allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the gateway's connection | Exactly the gateway's host, the only host Claude sends the token to. It can't be widened or given a wildcard. |
32| Connection check | Runs only against an HTTPS host with no path. The console sends two `POST` requests to the address, each with an empty body and a test token, doesn't follow redirects, and can take up to a minute. [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway) lists the expected responses. The console refuses a check that runs many times in quick succession and says how long to wait. |
33| Same address twice in one organization | Entering an address that is already registered runs the connection check again (unless you skip it) without changing the stored result, then moves to the bundle step. The run counts toward the check limit. |
25| Limit | Value |
26| :- | :- |
27| Registered addresses per organization | 5, counting gateways and authorization-server token endpoints together. |
28| Token reuse | Claude reuses one token for a session's requests to the same gateway for about five minutes, half the token's lifetime, or until the gateway answers 401, and then requests a new one (current behavior, may change). A gateway sees the same `jti` on many requests. |
29| Gateway address | An HTTPS host name only, with no path, port, query, or trailing slash. The host name needs a domain, like `gateway.example.com`, uses only letters, numbers, hyphens, and dots, and has at most 253 characters (current behavior, may change). The console rejects an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange, and names the reason. The connection check also refuses a host name that resolves to a private address. |
30| One connection per gateway | A gateway connected in one Access bundle can't be connected again in another. Attach that bundle to each scope that needs the gateway. |
31| [Allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the gateway's connection | Exactly the gateway's host, the only host Claude sends the token to. It can't be widened or given a wildcard. |
32| Connection check | Runs only against an HTTPS host with no path. The console sends two `POST` requests to the address, each with an empty body and a test token, doesn't follow redirects, and can take up to a minute. [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway) lists the expected responses. The console refuses a check that runs many times in quick succession and says how long to wait. |
33| Same address twice in one organization | Entering an address that is already registered runs the connection check again (unless you skip it) without changing the stored result, then moves to the bundle step. The run counts toward the check limit. |
3434 
3535## AWS roles
3636 
37| Limit | Value |
38| :---------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
39| **Role ARN** | A commercial-partition IAM role, `arn:aws:iam::<account>:role/<name>`. AWS GovCloud and AWS China roles aren't supported. |
40| **Allowed AWS hosts** | Hosts ending in `.amazonaws.com` only, for example `s3.us-east-1.amazonaws.com` or `*.amazonaws.com`. |
41| Role session | 1 hour. The exchange doesn't ask for a longer session, so raising the role's maximum session duration has no effect. Claude reuses one session's credentials for the same agent until shortly before they expire, or until AWS answers a request with 403 (current behavior, may change). |
42| Token audience | `sts.amazonaws.com`, the same for every organization. Condition the trust policy on the `sub` claim as well as the audience; see [Authorize on the subject](/docs/claude-tag/admins/federated-access/token-reference#authorize-on-the-subject). |
43| One connection per role | A role can be connected once in your organization. |
37| Limit | Value |
38| :- | :- |
39| **Role ARN** | A commercial-partition IAM role, `arn:aws:iam::<account>:role/<name>`. AWS GovCloud and AWS China roles aren't supported. |
40| **Allowed AWS hosts** | Hosts ending in `.amazonaws.com` only, for example `s3.us-east-1.amazonaws.com` or `*.amazonaws.com`. |
41| Role session | 1 hour. The exchange doesn't ask for a longer session, so raising the role's maximum session duration has no effect. Claude reuses one session's credentials for the same agent until shortly before they expire, or until AWS answers a request with 403 (current behavior, may change). |
42| Token audience | `sts.amazonaws.com`, the same for every organization. Condition the trust policy on the `sub` claim as well as the audience; see [Authorize on the subject](/docs/claude-tag/admins/federated-access/token-reference#authorize-on-the-subject). |
43| One connection per role | A role can be connected once in your organization. |
4444 
4545## Google Cloud identities
4646 
47| Limit | Value |
48| :------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
49| **Workload identity provider** | The full resource name of a provider in a workload identity pool under a numeric project, `//iam.googleapis.com/projects/<number>/locations/global/workloadIdentityPools/<pool>/providers/<provider>`. Workforce identity pools aren't supported. |
50| **Service account to act as** | Optional. A service account, `<name>@<project>.iam.gserviceaccount.com`. Default compute and App Engine service accounts aren't accepted. Leave it empty to call Google Cloud as the federated identity itself. |
51| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
52| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always, with no setting to change it. On Google Cloud APIs, IAM decides what the credential can do. An API that needs an OAuth scope of its own answers 403 whatever IAM allows; see [The cloud API answers 403 after a successful exchange](/docs/claude-tag/admins/federated-access/troubleshooting#the-cloud-api-answers-403-after-a-successful-exchange). |
53| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
54| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
47| Limit | Value |
48| :- | :- |
49| **Workload identity provider** | The full resource name of a provider in a workload identity pool under a numeric project, `//iam.googleapis.com/projects/<number>/locations/global/workloadIdentityPools/<pool>/providers/<provider>`. Workforce identity pools aren't supported. |
50| **Service account to act as** | Optional. A service account, `<name>@<project>.iam.gserviceaccount.com`. Default compute and App Engine service accounts aren't accepted. Leave it empty to call Google Cloud as the federated identity itself. |
51| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
52| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always, with no setting to change it. On Google Cloud APIs, IAM decides what the credential can do. An API that needs an OAuth scope of its own answers 403 whatever IAM allows; see [The cloud API answers 403 after a successful exchange](/docs/claude-tag/admins/federated-access/troubleshooting#the-cloud-api-answers-403-after-a-successful-exchange). |
53| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
54| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
5555 
5656### What the credential-minting block refuses
5757 
from line 71
7171 
7272## Authorization servers
7373 
74| Limit | Value |
75| :-------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
76| **Token endpoint** | A full HTTPS URL of at most 256 characters (current behavior, may change), with an optional path and no port, query, fragment, user name, password, spaces, or special characters. The same host rules as a gateway address apply, and a trailing slash is dropped. |
77| Token audience | Your authorization server's issuer identifier as you entered it (an HTTPS URL on the same host as the token endpoint, with the same address rules), or the token endpoint URL exactly when you left the issuer identifier empty. It can't be changed after the server is connected. |
78| **Resource** | Optional. An absolute URI with no fragment, at most 256 characters with no spaces (current behavior, may change). |
79| **Scope** | Optional. Space-separated scope words with no quotes or backslashes, at most 256 characters in total (current behavior, may change). |
80| **Allowed API hosts** | Must not include the token endpoint's host. |
81| Token exchange | A form-encoded `POST` that doesn't follow redirects and must complete within about 10 seconds (current behavior, may change). |
82| Access token reuse | Reused until about five minutes before it expires (for tokens shorter than 10 minutes, until half their lifetime has passed) when `expires_in` is between 5 minutes and 1 day. When `expires_in` is missing or shorter, the token is used for one request. When it is longer than a day, the token isn't cached either, so every request goes to the token endpoint. (Current behavior, may change.) |
83| Subject check | Your authorization server performs it; the console has no connection check for token endpoints. The server must accept only your own agents' full subjects, or at minimum check that each token's subject starts with your organization's **Subject prefix**. |
84| Endpoint reuse | A registered address can be connected as a gateway or as an authorization server, not both. A token endpoint stays listed in the **Gateways** table after you remove its authorization server, and frees its place among the 5 registered addresses only when you remove it there too. |
74| Limit | Value |
75| :- | :- |
76| **Token endpoint** | A full HTTPS URL of at most 256 characters (current behavior, may change), with an optional path and no port, query, fragment, user name, password, spaces, or special characters. The same host rules as a gateway address apply, and a trailing slash is dropped. |
77| Token audience | Your authorization server's issuer identifier as you entered it (an HTTPS URL on the same host as the token endpoint, with the same address rules), or the token endpoint URL exactly when you left the issuer identifier empty. It can't be changed after the server is connected. |
78| **Resource** | Optional. An absolute URI with no fragment, at most 256 characters with no spaces (current behavior, may change). |
79| **Scope** | Optional. Space-separated scope words with no quotes or backslashes, at most 256 characters in total (current behavior, may change). |
80| **Allowed API hosts** | Must not include the token endpoint's host. |
81| Token exchange | A form-encoded `POST` that doesn't follow redirects and must complete within about 10 seconds (current behavior, may change). |
82| Access token reuse | Reused until about five minutes before it expires (for tokens shorter than 10 minutes, until half their lifetime has passed) when `expires_in` is between 5 minutes and 1 day. When `expires_in` is missing or shorter, the token is used for one request. When it is longer than a day, the token isn't cached either, so every request goes to the token endpoint. (Current behavior, may change.) |
83| Subject check | Your authorization server performs it; the console has no connection check for token endpoints. The server must accept only your own agents' full subjects, or at minimum check that each token's subject starts with your organization's **Subject prefix**. |
84| Endpoint reuse | A registered address can be connected as a gateway or as an authorization server, not both. A token endpoint stays listed in the **Gateways** table after you remove its authorization server, and frees its place among the 5 registered addresses only when you remove it there too. |
8585 
8686## Testing
8787 

claude-tag/admins/federated-access/overview Changed · +13 / -13 lines

from line 18
1818 
1919## Choose a connection type
2020 
21| Connection type | Who accepts the token | Choose it when |
22| :------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------- |
23| **Gateway** | A service you run. It verifies the token, maps the agent to permissions, and forwards the request to your internal systems with credentials you hold. | You want one entry point in front of internal APIs. The [sample gateway](https://github.com/anthropics/claude-tag-wif-gateway-sample) is a starting point. |
24| **AWS role** | AWS, through an IAM OIDC identity provider. AWS issues temporary credentials for a role whose trust policy names Anthropic's issuer and your organization. | Claude should call AWS APIs under a role you govern with IAM. |
25| **Google Cloud identity** | Google Cloud, through a workload identity pool. Google issues an access token for the federated identity, acting as a service account if you name one. | Claude should call Google Cloud APIs under an identity you govern with IAM. |
26| **Authorization server** | Your OAuth 2.0 authorization server. It accepts the token as a JWT bearer grant (RFC 7523) and returns an access token for your APIs. | Your APIs are already protected by your own OAuth server and you'd rather issue its tokens than run a gateway. |
21| Connection type | Who accepts the token | Choose it when |
22| :- | :- | :- |
23| **Gateway** | A service you run. It verifies the token, maps the agent to permissions, and forwards the request to your internal systems with credentials you hold. | You want one entry point in front of internal APIs. The [sample gateway](https://github.com/anthropics/claude-tag-wif-gateway-sample) is a starting point. |
24| **AWS role** | AWS, through an IAM OIDC identity provider. AWS issues temporary credentials for a role whose trust policy names Anthropic's issuer and your organization. | Claude should call AWS APIs under a role you govern with IAM. |
25| **Google Cloud identity** | Google Cloud, through a workload identity pool. Google issues an access token for the federated identity, acting as a service account if you name one. | Claude should call Google Cloud APIs under an identity you govern with IAM. |
26| **Authorization server** | Your OAuth 2.0 authorization server. It accepts the token as a JWT bearer grant (RFC 7523) and returns an access token for your APIs. | Your APIs are already protected by your own OAuth server and you'd rather issue its tokens than run a gateway. |
2727 
2828In every case the system on your side decides what the agent may do in your systems. Each connection type has its own setup page: [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway), [Connect an AWS role](/docs/claude-tag/admins/federated-access/aws), [Connect a Google Cloud identity](/docs/claude-tag/admins/federated-access/gcp), and [Connect an authorization server](/docs/claude-tag/admins/federated-access/authorization-server).
2929 
from line 46
4646 
4747To cut off access, remove the connection in the console. These lifetimes then apply:
4848 
49| What | How long it lasts |
50| :--------------------------------------------- | :------------------------------------------------------------------------------------------------------------------- |
51| A removed connection | Claude stops using a removed gateway at once, and a removed cloud role or authorization server within about a minute |
52| An identity token already issued | 10 minutes from when it was issued |
53| AWS credentials already exchanged | 1 hour, the role session length |
54| A Google Cloud credential already exchanged | As long as Google Cloud issued it for |
55| An access token from your authorization server | The `expires_in` your server returned |
49| What | How long it lasts |
50| :- | :- |
51| A removed connection | Claude stops using a removed gateway at once, and a removed cloud role or authorization server within about a minute |
52| An identity token already issued | 10 minutes from when it was issued |
53| AWS credentials already exchanged | 1 hour, the role session length |
54| A Google Cloud credential already exchanged | As long as Google Cloud issued it for |
55| An access token from your authorization server | The `expires_in` your server returned |
5656 
5757Anthropic doesn't review your gateway, trust policy, or authorization server. When you connect a gateway, the console offers a connection check that confirms the gateway rejects a token whose subject isn't your organization. The other connection types have no check in the console, so you verify them yourself with the steps on each setup page.
5858 

claude-tag/admins/federated-access/token-reference Changed · +28 / -28 lines

from line 12
1212 
1313## Issuer and signing keys
1414 
15| Item | Value |
16| :----------------------------------------- | :------------------------------------------------------------------------------------------------ |
17| Issuer (`iss`) | `https://identity.anthropic.com/agents`. Match it exactly, including the `/agents` path. |
18| OpenID Connect (OIDC) discovery document | `https://identity.anthropic.com/agents/.well-known/openid-configuration` |
15| Item | Value |
16| :- | :- |
17| Issuer (`iss`) | `https://identity.anthropic.com/agents`. Match it exactly, including the `/agents` path. |
18| OpenID Connect (OIDC) discovery document | `https://identity.anthropic.com/agents/.well-known/openid-configuration` |
1919| Signing keys, as a JSON Web Key Set (JWKS) | `https://identity.anthropic.com/agents/jwks.json`, the `jwks_uri` named in the discovery document |
20| Signing algorithm | ES256 only. Reject any other `alg`, including `none`. |
20| Signing algorithm | ES256 only. Reject any other `alg`, including `none`. |
2121 
2222Both documents are public and need no authentication to fetch. One issuer serves every Claude Tag organization, so the issuer and signature prove only that Anthropic issued the token. The [subject](#subject), or the `tenant` claim, is what ties a token to your organization.
2323 
from line 27
2727 
2828## Lifetime
2929 
30| Claim | Value |
31| :---- | :---------------------------------------------------------------------------------------- |
32| `iat` | When the token was issued, in seconds since the Unix epoch |
30| Claim | Value |
31| :- | :- |
32| `iat` | When the token was issued, in seconds since the Unix epoch |
3333| `nbf` | 15 seconds before `iat` (current behavior, may change). Libraries check it automatically. |
34| `exp` | 10 minutes (600 seconds) after `iat` |
35| `jti` | A unique ID for this token |
34| `exp` | 10 minutes (600 seconds) after `iat` |
35| `jti` | A unique ID for this token |
3636 
3737Allow up to 60 seconds of clock skew when you check `exp`, and treat `exp` as the earliest moment a token may stop working rather than an exact cutoff; cloud providers apply their own grace.
3838 
from line 66
6666 
6767The `aud` claim is a JSON array with one element. Use your library's audience option rather than comparing the raw claim text; some libraries print a one-element array as a bare string.
6868 
69| Where the token goes | `aud` |
70| :---------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
71| A gateway you connected | The HTTPS address you registered, which the console accepts only as a bare host on the standard port and stores in lowercase, for example `https://gateway.example.com` |
72| AWS | `sts.amazonaws.com` |
73| Google Cloud | Your workload identity provider's full resource name, for example `//iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/claude/providers/agents` |
69| Where the token goes | `aud` |
70| :- | :- |
71| A gateway you connected | The HTTPS address you registered, which the console accepts only as a bare host on the standard port and stores in lowercase, for example `https://gateway.example.com` |
72| AWS | `sts.amazonaws.com` |
73| Google Cloud | Your workload identity provider's full resource name, for example `//iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/claude/providers/agents` |
7474| An authorization server | Your server's issuer identifier as you entered it when connecting the server (an HTTPS URL on the token endpoint's host), for example `https://auth.example.com`, or the token endpoint URL exactly as registered, for example `https://auth.example.com/oauth2/token`, if you left the issuer identifier empty |
7575 
7676The audience identifies the destination, not your organization; every organization's AWS tokens share `sts.amazonaws.com`. Always check the [subject](#subject) too.
from line 79
7979 
8080These are the claims a token carries.
8181 
82| Claim | Value |
83| :------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
84| `iss` | `https://identity.anthropic.com/agents` |
85| `sub` | The agent's subject; see [Subject](#subject) |
86| `aud` | One-element array; see [Audience](#audience) |
87| `iat`, `nbf`, `exp` | Issued-at, not-before, and expiry times; see [Lifetime](#lifetime) |
88| `jti` | Unique token ID |
89| `tenant` | Your Claude organization ID, the same value as the subject's `org/` segment. Together with `iss`, this is the pair a relying party pins to trust tokens from one organization. Not your cloud or identity provider's tenant ID. |
90| `agent_id` | The agent ID, the same value as the subject's `agent/` segment |
91| `profile_id` | The ID of the Access bundle the connection belongs to, starting with `capp_`. Informational. |
92| `platform` | `slack` when the request came from Slack. Present whenever `slack_workspace_id` is. |
93| `slack_workspace_id` | The ID of the Slack workspace Claude is acting in. Present when the request came from a Slack workspace your organization owns. |
94| `slack_channel_id` | The ID of the Slack channel Claude is acting in. Present whenever `slack_workspace_id` is and Claude is acting in one channel rather than a whole workspace. |
82| Claim | Value |
83| :- | :- |
84| `iss` | `https://identity.anthropic.com/agents` |
85| `sub` | The agent's subject; see [Subject](#subject) |
86| `aud` | One-element array; see [Audience](#audience) |
87| `iat`, `nbf`, `exp` | Issued-at, not-before, and expiry times; see [Lifetime](#lifetime) |
88| `jti` | Unique token ID |
89| `tenant` | Your Claude organization ID, the same value as the subject's `org/` segment. Together with `iss`, this is the pair a relying party pins to trust tokens from one organization. Not your cloud or identity provider's tenant ID. |
90| `agent_id` | The agent ID, the same value as the subject's `agent/` segment |
91| `profile_id` | The ID of the Access bundle the connection belongs to, starting with `capp_`. Informational. |
92| `platform` | `slack` when the request came from Slack. Present whenever `slack_workspace_id` is. |
93| `slack_workspace_id` | The ID of the Slack workspace Claude is acting in. Present when the request came from a Slack workspace your organization owns. |
94| `slack_channel_id` | The ID of the Slack channel Claude is acting in. Present whenever `slack_workspace_id` is and Claude is acting in one channel rather than a whole workspace. |
9595 
9696Tokens may carry additional claims Anthropic uses internally for audit; ignore any claim not listed here and never base an authorization decision on it.
9797 

claude-tag/admins/federated-access/troubleshooting Changed · +60 / -60 lines

from line 21
2121 
2222Most dialog messages say what to do. The table adds what the message doesn't. The one message that needs more, "The check didn't pass", has its own entry below the table, followed by what removing and reconnecting a gateway does.
2323 
24| Message | What it means | Do this |
25| :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
26| "The check can't run right now. Try again later, or skip the check and record why." | Anthropic couldn't produce the test tokens for the connection check. The problem is on Anthropic's side, not your gateway's. | Wait a few minutes and click **Run check and connect** again. If the message persists, select the **Skip the check** option, enter a **Reason for skipping**, and click **Connect without the check**; remove and reconnect the gateway later to record a passed check. |
27| "Too many checks in a short time." followed by how long to wait | Your organization ran the connection check too many times in quick succession. The limit counts every admin in the organization. Entering an address that is already registered runs the check again and counts too, unless the **Skip the check** option is selected. | Wait the time the message names. To add an existing gateway to a bundle, click **Add to bundle** in its row of the **Gateways** table instead of entering its address again. |
28| "Too many attempts in a short time." in the **Connect an authorization server** dialog | A general request limit, not the connection check; registering a token endpoint never runs the check. | Wait the time the message names and try again. |
29| "Connecting a gateway needs full Claude Tag management permission. Ask an organization owner." or "This needs full Claude Tag management permission. Ask an organization owner." | Your account can't change federated connections. Channel managers, and admins whose Claude Tag permission covers specific channels only, can't connect a gateway, cloud role, or authorization server. | Ask an organization Owner, or an admin with full Claude Tag management permission, to make the connection from their own account. |
30| A dialog message containing "isn't enabled for your organization yet", or **Federated cloud access** is missing from the left navigation | Federated cloud access isn't available to organizations whose compliance configuration excludes it. The navigation item is also hidden from channel managers and from admins whose Claude Tag permission covers specific channels only, because connecting a system needs full Claude Tag management permission. | Ask an organization Owner, or an admin with full Claude Tag management permission, to open the page. If it's missing for them too, your organization's compliance configuration excludes the feature. |
31| "This organization has reached its limit of 5 gateways. Remove one to connect another." or, in the **Connect an authorization server** dialog, "…limit of 5 registered gateways, which includes token endpoints." | An organization can register 5 addresses. A token endpoint is registered the same way as a gateway, so it counts toward the same 5 and appears in the **Gateways** table marked "Used by a connected authorization server. Manage it from the Authorization servers section." An address is either a gateway or a token endpoint in your organization, not both. | In the **Gateways** table, click **Remove** in the row of a gateway you no longer use. To free a token endpoint's row, click **Remove** in the server's row of the **Authorization servers** table first, then remove the endpoint from the **Gateways** table. See [Removing and reconnecting a gateway](#removing-and-reconnecting-a-gateway). |
32| "This gateway is already registered. Close this dialog and pick it from the list to add it to a bundle." | The address is already registered in your organization, and the dialog couldn't load its row to continue. This message is rare: entering a registered address normally runs the connection check again without changing the stored result, then moves on to the bundle step. | Click **Cancel**, then click **Add to bundle** in the gateway's row of the **Gateways** table. |
33| "`<address>` is already in the bundle `<bundle>`. Assign that bundle to a channel to use the gateway there.", "This role is already connected in the bundle `<bundle>`.", or "This token endpoint is already connected in the bundle `<bundle>`." | A gateway, AWS role, or token endpoint can be connected in only one Access bundle, and this one already is. | To use the connection in more channels, [attach that bundle to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) instead. To move it, in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, and choose **Delete**. Then add it to the new bundle: **Add to bundle** in the gateway's row of the **Gateways** table, or the connect dialog again for the other types. |
34| "`<name>` already covers `<host>` in this bundle, so Claude would never use this connection for the hosts they share. Change the hosts or choose another bundle." in the **Connect a Google Cloud identity** dialog | Another Google Cloud connection in the bundle you chose already has that host under **Allowed hosts**, whatever its provider or service account. Claude uses the first connection in a bundle whose hosts match a request, so the new connection would never be used for the shared host. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The dialog won't connect until the overlap is gone. | Remove the shared host from the new connection's **Allowed Google hosts**, or choose another bundle. To give the host to the new connection instead, first narrow the existing one: in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, choose **Edit**, and change **Allowed hosts**. |
35| "Couldn't connect the gateway. Try again.", "Couldn't add the gateway to the bundle.", "Couldn't connect the role. Try again.", "Couldn't connect the identity. Try again.", "Couldn't register the authorization server. Try again.", or "Couldn't connect the authorization server. Try again." | The request failed for a reason the dialog doesn't name, most often a temporary one. | Try once more. If the message persists, contact your Anthropic account team with the details under [Contact Anthropic](#contact-anthropic). |
36| "The issuer URL must be an https URL on the same host as the token endpoint. Leave it empty to use the token endpoint as the audience." in the **Connect an authorization server** dialog | The **Issuer URL** value must be an HTTPS URL on the same host as the token endpoint, or empty. The token is only ever presented to that server, so its audience must name that server. | Enter the issuer identifier your authorization server uses, on the token endpoint's host, or clear the field to use the token endpoint as the audience. |
37| "This token endpoint is already connected. Manage it from the Authorization servers section." in the **Connect an authorization server** dialog | An authorization server with this token endpoint is already connected in one of your organization's Access bundles, and a server can be connected only once. The dialog checks this before it registers anything. | To use the server in more channels, [attach its bundle to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle). To connect it again, remove it first: in the **Authorization servers** table, click **Remove** in the server's row. |
38| "That address is already connected as a gateway. Enter your authorization server's own addresses, or remove the gateway first." in the **Connect an authorization server** dialog | The token endpoint, or the **Issuer URL** value, is the address of a gateway connected in one of your organization's Access bundles. One address can't be both, because a token sent to the gateway could be replayed to the server as a grant. | Enter the token endpoint and issuer identifier your authorization server publishes. To use that address for the server instead, remove the gateway first: in **Access bundles**, open the bundle that holds the gateway, open its **Credentials** tab, open the **⋮** menu on the gateway's row, and choose **Delete**. Then, in the **Gateways** table under **Federated cloud access**, click **Remove** in the gateway's row. |
39| "That address is registered by a connected authorization server. Enter your gateway's address, or remove the server first." in the **Connect a gateway** dialog | The address you entered is a connected authorization server's token endpoint or audience, for example a server whose **Issuer URL** is the bare host `https://auth.example.com`. One address can't be both, because a token sent to the gateway could be replayed to that server as a grant. | Enter the host your gateway answers on. To use that address for a gateway instead, remove the server first: in the **Authorization servers** table, click **Remove** in the server's row. |
40| "That address is already a connected authorization server's audience. Enter this server's own issuer URL." in the **Connect an authorization server** dialog | The **Issuer URL** value (or the token endpoint, when **Issuer URL** is empty) is already another connected authorization server's audience or token endpoint. Two servers can't share an audience, because a token minted for one would be valid at the other. | In the **Issuer URL** field, enter the issuer identifier this server publishes. If the other server holds this identifier by mistake, remove that server first: in the **Authorization servers** table, click **Remove** in its row, then connect it again with its own issuer URL. |
41| "The address is too long. Issuer URLs have at most 256 characters." under the **Issuer URL** field of the **Connect an authorization server** dialog | The **Issuer URL** field accepts at most 256 characters, the same limit as the **Token endpoint** field. | Check that the field holds only the issuer identifier, for example `https://auth.example.com`, and not a longer value pasted by mistake. |
42| "Couldn't check the addresses against your gateways and servers. Close this dialog and try again." in the **Connect an authorization server** dialog, or "Couldn't check the address against your authorization servers. Close this dialog and try again." in the **Connect a gateway** dialog | Before it registers an address, each dialog loads your organization's existing connections to check that the address doesn't clash with a connected gateway or authorization server. That list didn't load, and the dialog doesn't register an address it couldn't check. | Close the dialog and open it again. If the message persists, reload the page, then contact your Anthropic account team with the details under [Contact Anthropic](#contact-anthropic). |
43| An address-field message such as "Enter only the host, like [https://gateway.example.com](https://gateway.example.com), with no path, port or trailing slash.", "Enter a host name, not an IP address.", "That is an Anthropic address. Enter your own gateway's host name.", "That host name only works inside a private network. Enter a host name that is reachable from the internet.", or "That host is reserved for cloud token exchange. Enter your own gateway's host name." | A gateway address is an HTTPS host only, with a domain name of at least two labels. A token endpoint may have a path, but no port, query, fragment, or sign-in details. Neither can be an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange. | Enter the public address the service answers on, for example `https://gateway.example.com` or `https://auth.example.com/oauth2/token`. The console can't register a private address even with the check skipped. |
24| Message | What it means | Do this |
25| :- | :- | :- |
26| "The check can't run right now. Try again later, or skip the check and record why." | Anthropic couldn't produce the test tokens for the connection check. The problem is on Anthropic's side, not your gateway's. | Wait a few minutes and click **Run check and connect** again. If the message persists, select the **Skip the check** option, enter a **Reason for skipping**, and click **Connect without the check**; remove and reconnect the gateway later to record a passed check. |
27| "Too many checks in a short time." followed by how long to wait | Your organization ran the connection check too many times in quick succession. The limit counts every admin in the organization. Entering an address that is already registered runs the check again and counts too, unless the **Skip the check** option is selected. | Wait the time the message names. To add an existing gateway to a bundle, click **Add to bundle** in its row of the **Gateways** table instead of entering its address again. |
28| "Too many attempts in a short time." in the **Connect an authorization server** dialog | A general request limit, not the connection check; registering a token endpoint never runs the check. | Wait the time the message names and try again. |
29| "Connecting a gateway needs full Claude Tag management permission. Ask an organization owner." or "This needs full Claude Tag management permission. Ask an organization owner." | Your account can't change federated connections. Channel managers, and admins whose Claude Tag permission covers specific channels only, can't connect a gateway, cloud role, or authorization server. | Ask an organization Owner, or an admin with full Claude Tag management permission, to make the connection from their own account. |
30| A dialog message containing "isn't enabled for your organization yet", or **Federated cloud access** is missing from the left navigation | Federated cloud access isn't available to organizations whose compliance configuration excludes it. The navigation item is also hidden from channel managers and from admins whose Claude Tag permission covers specific channels only, because connecting a system needs full Claude Tag management permission. | Ask an organization Owner, or an admin with full Claude Tag management permission, to open the page. If it's missing for them too, your organization's compliance configuration excludes the feature. |
31| "This organization has reached its limit of 5 gateways. Remove one to connect another." or, in the **Connect an authorization server** dialog, "…limit of 5 registered gateways, which includes token endpoints." | An organization can register 5 addresses. A token endpoint is registered the same way as a gateway, so it counts toward the same 5 and appears in the **Gateways** table marked "Used by a connected authorization server. Manage it from the Authorization servers section." An address is either a gateway or a token endpoint in your organization, not both. | In the **Gateways** table, click **Remove** in the row of a gateway you no longer use. To free a token endpoint's row, click **Remove** in the server's row of the **Authorization servers** table first, then remove the endpoint from the **Gateways** table. See [Removing and reconnecting a gateway](#removing-and-reconnecting-a-gateway). |
32| "This gateway is already registered. Close this dialog and pick it from the list to add it to a bundle." | The address is already registered in your organization, and the dialog couldn't load its row to continue. This message is rare: entering a registered address normally runs the connection check again without changing the stored result, then moves on to the bundle step. | Click **Cancel**, then click **Add to bundle** in the gateway's row of the **Gateways** table. |
33| "`<address>` is already in the bundle `<bundle>`. Assign that bundle to a channel to use the gateway there.", "This role is already connected in the bundle `<bundle>`.", or "This token endpoint is already connected in the bundle `<bundle>`." | A gateway, AWS role, or token endpoint can be connected in only one Access bundle, and this one already is. | To use the connection in more channels, [attach that bundle to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) instead. To move it, in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, and choose **Delete**. Then add it to the new bundle: **Add to bundle** in the gateway's row of the **Gateways** table, or the connect dialog again for the other types. |
34| "`<name>` already covers `<host>` in this bundle, so Claude would never use this connection for the hosts they share. Change the hosts or choose another bundle." in the **Connect a Google Cloud identity** dialog | Another Google Cloud connection in the bundle you chose already has that host under **Allowed hosts**, whatever its provider or service account. Claude uses the first connection in a bundle whose hosts match a request, so the new connection would never be used for the shared host. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The dialog won't connect until the overlap is gone. | Remove the shared host from the new connection's **Allowed Google hosts**, or choose another bundle. To give the host to the new connection instead, first narrow the existing one: in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, choose **Edit**, and change **Allowed hosts**. |
35| "Couldn't connect the gateway. Try again.", "Couldn't add the gateway to the bundle.", "Couldn't connect the role. Try again.", "Couldn't connect the identity. Try again.", "Couldn't register the authorization server. Try again.", or "Couldn't connect the authorization server. Try again." | The request failed for a reason the dialog doesn't name, most often a temporary one. | Try once more. If the message persists, contact your Anthropic account team with the details under [Contact Anthropic](#contact-anthropic). |
36| "The issuer URL must be an https URL on the same host as the token endpoint. Leave it empty to use the token endpoint as the audience." in the **Connect an authorization server** dialog | The **Issuer URL** value must be an HTTPS URL on the same host as the token endpoint, or empty. The token is only ever presented to that server, so its audience must name that server. | Enter the issuer identifier your authorization server uses, on the token endpoint's host, or clear the field to use the token endpoint as the audience. |
37| "This token endpoint is already connected. Manage it from the Authorization servers section." in the **Connect an authorization server** dialog | An authorization server with this token endpoint is already connected in one of your organization's Access bundles, and a server can be connected only once. The dialog checks this before it registers anything. | To use the server in more channels, [attach its bundle to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle). To connect it again, remove it first: in the **Authorization servers** table, click **Remove** in the server's row. |
38| "That address is already connected as a gateway. Enter your authorization server's own addresses, or remove the gateway first." in the **Connect an authorization server** dialog | The token endpoint, or the **Issuer URL** value, is the address of a gateway connected in one of your organization's Access bundles. One address can't be both, because a token sent to the gateway could be replayed to the server as a grant. | Enter the token endpoint and issuer identifier your authorization server publishes. To use that address for the server instead, remove the gateway first: in **Access bundles**, open the bundle that holds the gateway, open its **Credentials** tab, open the **⋮** menu on the gateway's row, and choose **Delete**. Then, in the **Gateways** table under **Federated cloud access**, click **Remove** in the gateway's row. |
39| "That address is registered by a connected authorization server. Enter your gateway's address, or remove the server first." in the **Connect a gateway** dialog | The address you entered is a connected authorization server's token endpoint or audience, for example a server whose **Issuer URL** is the bare host `https://auth.example.com`. One address can't be both, because a token sent to the gateway could be replayed to that server as a grant. | Enter the host your gateway answers on. To use that address for a gateway instead, remove the server first: in the **Authorization servers** table, click **Remove** in the server's row. |
40| "That address is already a connected authorization server's audience. Enter this server's own issuer URL." in the **Connect an authorization server** dialog | The **Issuer URL** value (or the token endpoint, when **Issuer URL** is empty) is already another connected authorization server's audience or token endpoint. Two servers can't share an audience, because a token minted for one would be valid at the other. | In the **Issuer URL** field, enter the issuer identifier this server publishes. If the other server holds this identifier by mistake, remove that server first: in the **Authorization servers** table, click **Remove** in its row, then connect it again with its own issuer URL. |
41| "The address is too long. Issuer URLs have at most 256 characters." under the **Issuer URL** field of the **Connect an authorization server** dialog | The **Issuer URL** field accepts at most 256 characters, the same limit as the **Token endpoint** field. | Check that the field holds only the issuer identifier, for example `https://auth.example.com`, and not a longer value pasted by mistake. |
42| "Couldn't check the addresses against your gateways and servers. Close this dialog and try again." in the **Connect an authorization server** dialog, or "Couldn't check the address against your authorization servers. Close this dialog and try again." in the **Connect a gateway** dialog | Before it registers an address, each dialog loads your organization's existing connections to check that the address doesn't clash with a connected gateway or authorization server. That list didn't load, and the dialog doesn't register an address it couldn't check. | Close the dialog and open it again. If the message persists, reload the page, then contact your Anthropic account team with the details under [Contact Anthropic](#contact-anthropic). |
43| An address-field message such as "Enter only the host, like [https://gateway.example.com](https://gateway.example.com), with no path, port or trailing slash.", "Enter a host name, not an IP address.", "That is an Anthropic address. Enter your own gateway's host name.", "That host name only works inside a private network. Enter a host name that is reachable from the internet.", or "That host is reserved for cloud token exchange. Enter your own gateway's host name." | A gateway address is an HTTPS host only, with a domain name of at least two labels. A token endpoint may have a path, but no port, query, fragment, or sign-in details. Neither can be an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange. | Enter the public address the service answers on, for example `https://gateway.example.com` or `https://auth.example.com/oauth2/token`. The console can't register a private address even with the check skipped. |
4444 
4545### The check didn't pass
4646 
from line 56
5656 
5757The check sends an empty `POST` to the address itself, with nothing added after the host, twice. Work through the causes in order.
5858 
59| Check | What to do |
60| :-------------------------------------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
61| Claude can reach the address from the internet over HTTPS | Confirm the host resolves publicly, the TLS certificate is valid, and the gateway isn't behind a VPN. |
62| An empty `POST` to the address itself is answered directly | The check doesn't follow redirects, and any status other than the two expected ones fails it, including a 503 from a gateway that couldn't fetch the signing keys. |
63| The token whose subject isn't your organization gets 401 or 403 | If the gateway answered 2xx, the subject check is missing or wrong. |
64| The token for the **Control subject** gets 2xx | A gateway that rejects every token is usually missing the control subject, or has a wrong issuer, audience, or key setting. With the sample gateway, add the **Control subject** as a `principals` entry with `allowed_services: []` in `config.yaml`. |
59| Check | What to do |
60| :- | :- |
61| Claude can reach the address from the internet over HTTPS | Confirm the host resolves publicly, the TLS certificate is valid, and the gateway isn't behind a VPN. |
62| An empty `POST` to the address itself is answered directly | The check doesn't follow redirects, and any status other than the two expected ones fails it, including a 503 from a gateway that couldn't fetch the signing keys. |
63| The token whose subject isn't your organization gets 401 or 403 | If the gateway answered 2xx, the subject check is missing or wrong. |
64| The token for the **Control subject** gets 2xx | A gateway that rejects every token is usually missing the control subject, or has a wrong issuer, audience, or key setting. With the sample gateway, add the **Control subject** as a `principals` entry with `allowed_services: []` in `config.yaml`. |
6565 
6666A 503 from the gateway usually means it can't reach `https://identity.anthropic.com` to fetch the keys. For a gateway that rejects every token, [Your gateway rejects every token](#your-gateway-rejects-every-token) lists each setting to compare. If you deployed [Anthropic's sample gateway](https://github.com/anthropics/claude-tag-wif-gateway-sample), its `config.yaml` must carry your real organization ID in the control-subject entry.
6767 
from line 191
191191 
192192Look up the refusal where it happened and fix the configuration it names.
193193 
194| Connection | Where to look | Entry |
195| :-------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
196| AWS role | CloudTrail, the `AssumeRoleWithWebIdentity` event for the role | [AWS refuses AssumeRoleWithWebIdentity](#aws-refuses-assumerolewithwebidentity) if the event failed. [An AWS request fails after a successful sign-in](#an-aws-request-fails-after-a-successful-sign-in) if the event succeeded, or there is no new event. |
197| Google Cloud identity | Cloud Audit Logs, the Security Token Service API entry for the token exchange and, if you named a service account, the IAM Service Account Credentials API entry | [Google Cloud refuses the token exchange](#google-cloud-refuses-the-token-exchange) |
198| Authorization server | Your server's log for the `POST` to the token endpoint | [Your authorization server rejects the grant](#your-authorization-server-rejects-the-grant) |
194| Connection | Where to look | Entry |
195| :- | :- | :- |
196| AWS role | CloudTrail, the `AssumeRoleWithWebIdentity` event for the role | [AWS refuses AssumeRoleWithWebIdentity](#aws-refuses-assumerolewithwebidentity) if the event failed. [An AWS request fails after a successful sign-in](#an-aws-request-fails-after-a-successful-sign-in) if the event succeeded, or there is no new event. |
197| Google Cloud identity | Cloud Audit Logs, the Security Token Service API entry for the token exchange and, if you named a service account, the IAM Service Account Credentials API entry | [Google Cloud refuses the token exchange](#google-cloud-refuses-the-token-exchange) |
198| Authorization server | Your server's log for the `POST` to the token endpoint | [Your authorization server rejects the grant](#your-authorization-server-rejects-the-grant) |
199199 
200200Allow for log delivery delay before concluding there was no attempt. For an AWS role, no new event can also mean Claude reused credentials from an earlier sign-in. See [An AWS request fails after a successful sign-in](#an-aws-request-fails-after-a-successful-sign-in). Otherwise, if your logs show no attempt at the time of the request, the token wasn't issued. [Contact Anthropic](#contact-anthropic) with the details listed there. A gateway connection doesn't produce this error. Your gateway's own response reaches Claude, so Claude reports the status your gateway returned, usually 401 or 403; see [Your gateway rejects every token](#your-gateway-rejects-every-token).
201201 
from line 215
215215 
216216**How to resolve**
217217 
218| Cause | Do this |
219| :--------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
220| Hostname with no usable region | Use the service's regional endpoint, `service.region.amazonaws.com` (for S3, also `bucket.s3.region.amazonaws.com`), and make sure that host is in the connection's **Allowed hosts**. A host that exists only with the region before the service name, such as an OpenSearch domain endpoint, can't be reached through a federated connection. [Contact Anthropic](#contact-anthropic) with the hostname. |
221| Large request to a service other than S3 | Keep the body under 1 MB, or have Claude send the request with an `x-amz-content-sha256` header set to the hex SHA-256 of the body, for example with `curl`. For large data, upload to S3 and pass a reference instead. |
222| S3 upload with signed chunks | Have Claude remove `payload_signing_enabled = true` from the profile in `~/.aws/config`, or add `request_checksum_calculation = WHEN_REQUIRED` to that profile as the reason text suggests, then retry. Either change makes the client send the upload in a form Agent Proxy signs. If the upload still fails, [contact Anthropic](#contact-anthropic). |
218| Cause | Do this |
219| :- | :- |
220| Hostname with no usable region | Use the service's regional endpoint, `service.region.amazonaws.com` (for S3, also `bucket.s3.region.amazonaws.com`), and make sure that host is in the connection's **Allowed hosts**. A host that exists only with the region before the service name, such as an OpenSearch domain endpoint, can't be reached through a federated connection. [Contact Anthropic](#contact-anthropic) with the hostname. |
221| Large request to a service other than S3 | Keep the body under 1 MB, or have Claude send the request with an `x-amz-content-sha256` header set to the hex SHA-256 of the body, for example with `curl`. For large data, upload to S3 and pass a reference instead. |
222| S3 upload with signed chunks | Have Claude remove `payload_signing_enabled = true` from the profile in `~/.aws/config`, or add `request_checksum_calculation = WHEN_REQUIRED` to that profile as the reason text suggests, then retry. Either change makes the client send the upload in a form Agent Proxy signs. If the upload still fails, [contact Anthropic](#contact-anthropic). |
223223 
224224### The cloud API answers 403 after a successful exchange
225225 
from line 255
255255 
256256**How to resolve**
257257 
258| Check | What to confirm |
259| :----------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
260| Audience | The `aud` claim is a JSON array with one element, your gateway address exactly as the console stored it: `https://` plus the lowercase host, no path or trailing slash. Use your library's audience option rather than comparing the raw claim to a string. |
261| Issuer | Exactly `https://identity.anthropic.com/agents`, including the path. A verifier configured with any other issuer value, such as the bare host, a different path, or a trailing slash, rejects every token, including the connection check's token. |
262| Signing keys | Fetched from the JSON Web Key Set (JWKS) named in `https://identity.anthropic.com/agents/.well-known/openid-configuration`. Accept ES256 only. Select the key by `kid`, and refetch the JWKS on an unknown `kid` before rejecting. |
263| Time | The token expires 10 minutes after issue (`exp`) and is valid from 15 seconds before issue (`nbf`). Check `exp`, allowing up to 60 seconds of clock skew, and make sure your gateway's clock is right. |
264| Subject | The subject check accepts your listed agents' full subjects and the **Control subject**, or at minimum every subject starting with your **Subject prefix**, `wimse://identity.anthropic.com/org/<your organization ID>/agent/`, including the `/agent/`. A list that omits the **Control subject** fails the connection check, and a list that omits an agent rejects that agent's requests. |
258| Check | What to confirm |
259| :- | :- |
260| Audience | The `aud` claim is a JSON array with one element, your gateway address exactly as the console stored it: `https://` plus the lowercase host, no path or trailing slash. Use your library's audience option rather than comparing the raw claim to a string. |
261| Issuer | Exactly `https://identity.anthropic.com/agents`, including the path. A verifier configured with any other issuer value, such as the bare host, a different path, or a trailing slash, rejects every token, including the connection check's token. |
262| Signing keys | Fetched from the JSON Web Key Set (JWKS) named in `https://identity.anthropic.com/agents/.well-known/openid-configuration`. Accept ES256 only. Select the key by `kid`, and refetch the JWKS on an unknown `kid` before rejecting. |
263| Time | The token expires 10 minutes after issue (`exp`) and is valid from 15 seconds before issue (`nbf`). Check `exp`, allowing up to 60 seconds of clock skew, and make sure your gateway's clock is right. |
264| Subject | The subject check accepts your listed agents' full subjects and the **Control subject**, or at minimum every subject starting with your **Subject prefix**, `wimse://identity.anthropic.com/org/<your organization ID>/agent/`, including the `/agent/`. A list that omits the **Control subject** fails the connection check, and a list that omits an agent rejects that agent's requests. |
265265 
266266### Your gateway sees the same token ID on many requests
267267 
from line 303
303303 
304304**How to resolve**
305305 
306| CloudTrail error | What to confirm |
307| :--------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
308| `InvalidIdentityToken` | The IAM OIDC identity provider's URL is exactly `https://identity.anthropic.com/agents`, with the `/agents` path (AWS displays it without `https://`), and its audience list includes `sts.amazonaws.com`. |
309| `AccessDenied` | The trust policy's condition keys start with `identity.anthropic.com/agents:`; the `aud` condition is `StringEquals` on `sts.amazonaws.com`; the `sub` condition matches the token's subject, either `StringEquals` on this agent's full subject or `StringLike` on `wimse://identity.anthropic.com/org/<your organization ID>/agent/*`. `AccessDenied` also appears when the role was deleted or renamed. |
310| Any other code | AWS's STS documentation describes it. If the two rows above check out, the token itself is fine. |
306| CloudTrail error | What to confirm |
307| :- | :- |
308| `InvalidIdentityToken` | The IAM OIDC identity provider's URL is exactly `https://identity.anthropic.com/agents`, with the `/agents` path (AWS displays it without `https://`), and its audience list includes `sts.amazonaws.com`. |
309| `AccessDenied` | The trust policy's condition keys start with `identity.anthropic.com/agents:`; the `aud` condition is `StringEquals` on `sts.amazonaws.com`; the `sub` condition matches the token's subject, either `StringEquals` on this agent's full subject or `StringLike` on `wimse://identity.anthropic.com/org/<your organization ID>/agent/*`. `AccessDenied` also appears when the role was deleted or renamed. |
310| Any other code | AWS's STS documentation describes it. If the two rows above check out, the token itself is fine. |
311311 
312312AWS credentials are reused for up to an hour for the same agent, so several threads' requests can appear under one CloudTrail session, and a trust policy change takes effect only when those credentials expire or AWS answers a request with 403.
313313 
from line 325
325325 
326326Google records the reason in your Cloud Audit Logs. The Security Token Service API entry covers the token exchange, and, if you named a service account, the IAM Service Account Credentials API entry covers the impersonation. Both are Data Access audit logs, which Google keeps off by default, as described under [Verify the connection](/docs/claude-tag/admins/federated-access/gcp#verify-the-connection). If the logs were on and show no entry at the time of the request, the token wasn't issued; see [injection failed](#injection-failed). Otherwise, work through the checks in order.
327327 
328| Check | What to confirm |
329| :-------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
330| Attribute condition | The provider's attribute condition accepts this token. A condition that lists full subjects must include this agent's subject. A condition on your **Subject prefix**, `assertion.sub.startsWith("wimse://identity.anthropic.com/org/<your organization ID>/agent/")`, accepts every agent in your organization, as does `attribute.org == "<your organization ID>"` if you mapped `attribute.org` from `assertion.tenant`. Comparing the subject to the prefix with `==`, as in `assertion.sub == "wimse://identity.anthropic.com/org/<your organization ID>/agent/"`, never matches, because every subject continues past the prefix with an agent's ID. Use `startsWith` on the prefix, or `==` on a full subject. |
331| Issuer, attribute mapping, and audience | The provider's issuer is `https://identity.anthropic.com/agents`, its attribute mapping sets `google.subject` to `assertion.sub` (and `attribute.org` to `assertion.tenant` if your condition or grants use it), and the **Workload identity provider** you entered in the console is the provider's full resource name, which is the token's audience. |
332| Service account grant | If you named a service account, the federated identity holds a role on it that allows `iam.serviceAccounts.getAccessToken`, such as `roles/iam.workloadIdentityUser`. |
328| Check | What to confirm |
329| :- | :- |
330| Attribute condition | The provider's attribute condition accepts this token. A condition that lists full subjects must include this agent's subject. A condition on your **Subject prefix**, `assertion.sub.startsWith("wimse://identity.anthropic.com/org/<your organization ID>/agent/")`, accepts every agent in your organization, as does `attribute.org == "<your organization ID>"` if you mapped `attribute.org` from `assertion.tenant`. Comparing the subject to the prefix with `==`, as in `assertion.sub == "wimse://identity.anthropic.com/org/<your organization ID>/agent/"`, never matches, because every subject continues past the prefix with an agent's ID. Use `startsWith` on the prefix, or `==` on a full subject. |
331| Issuer, attribute mapping, and audience | The provider's issuer is `https://identity.anthropic.com/agents`, its attribute mapping sets `google.subject` to `assertion.sub` (and `attribute.org` to `assertion.tenant` if your condition or grants use it), and the **Workload identity provider** you entered in the console is the provider's full resource name, which is the token's audience. |
332| Service account grant | If you named a service account, the federated identity holds a role on it that allows `iam.serviceAccounts.getAccessToken`, such as `roles/iam.workloadIdentityUser`. |
333333 
334334### Your authorization server rejects the grant
335335 
from line 343
343343 
344344**How to resolve**
345345 
346| Check | What to confirm |
347| :-------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
348| Grant shape | The token endpoint accepts `grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer` with the token in `assertion`, plus `resource` and `scope` if you set them, as a form-encoded `POST` with `Accept: application/json`. No `client_id` or client secret is sent, so the endpoint must accept the grant without client authentication. |
349| Audience | The token's `aud` is your authorization server's issuer identifier exactly as you entered it when connecting the server, or the token endpoint URL exactly as registered if you left the issuer identifier empty, as a one-element array. The **Audience** row of the **Connect an authorization server** dialog shows the value. |
350| Issuer and keys | As for a gateway: issuer `https://identity.anthropic.com/agents`, keys from its discovery document, ES256 only. |
351| Subject | Your server must accept only your own agents' full subjects, or at minimum require the **Subject prefix** shown in the **Connect an authorization server** dialog (or pin `iss` and `tenant`, which is the same check). The console's connection check doesn't run for token endpoints, so nothing tests this check for you. |
352| Response | A JSON body with `access_token`, `expires_in`, and, if `token_type` is present, the value `Bearer`. An `expires_in` under 5 minutes or over 1 day, or a missing one, makes Claude exchange a fresh token on every request, which shows in your log as one grant per request. |
346| Check | What to confirm |
347| :- | :- |
348| Grant shape | The token endpoint accepts `grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer` with the token in `assertion`, plus `resource` and `scope` if you set them, as a form-encoded `POST` with `Accept: application/json`. No `client_id` or client secret is sent, so the endpoint must accept the grant without client authentication. |
349| Audience | The token's `aud` is your authorization server's issuer identifier exactly as you entered it when connecting the server, or the token endpoint URL exactly as registered if you left the issuer identifier empty, as a one-element array. The **Audience** row of the **Connect an authorization server** dialog shows the value. |
350| Issuer and keys | As for a gateway: issuer `https://identity.anthropic.com/agents`, keys from its discovery document, ES256 only. |
351| Subject | Your server must accept only your own agents' full subjects, or at minimum require the **Subject prefix** shown in the **Connect an authorization server** dialog (or pin `iss` and `tenant`, which is the same check). The console's connection check doesn't run for token endpoints, so nothing tests this check for you. |
352| Response | A JSON body with `access_token`, `expires_in`, and, if `token_type` is present, the value `Bearer`. An `expires_in` under 5 minutes or over 1 day, or a missing one, makes Claude exchange a fresh token on every request, which shows in your log as one grant per request. |
353353 
354354Claude doesn't read `error_description`, so put the detail in your server's log rather than in the response.
355355 

claude-tag/admins/managed-by Changed · +29 / -29 lines

from line 14
1414 
1515The table compares the places standing instructions for Claude can live and who writes each.
1616 
17| You want | Use | Who writes it |
18| :---------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------- |
19| The same rules in every channel of a workspace or your whole organization | [Custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) on the workspace or organization scope | An Owner, in admin settings |
20| A central team to write the rules for a few channels it runs, such as a help desk or an on-call channel, without being admins | **Managed by** | Members of a managing channel, by asking Claude in Slack |
21| The people who work in a channel to set its conventions themselves | The **Channel instructions** field on the channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel) | Channel members, unless an admin has [restricted editing](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) |
17| You want | Use | Who writes it |
18| :- | :- | :- |
19| The same rules in every channel of a workspace or your whole organization | [Custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) on the workspace or organization scope | An Owner, in admin settings |
20| A central team to write the rules for a few channels it runs, such as a help desk or an on-call channel, without being admins | **Managed by** | Members of a managing channel, by asking Claude in Slack |
21| The people who work in a channel to set its conventions themselves | The **Channel instructions** field on the channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel) | Channel members, unless an admin has [restricted editing](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) |
2222 
2323You set up **Managed by** one channel at a time, and someone confirms each change to a channel's text in Slack. That suits a handful of channels. To give many channels the same text, use workspace or organization custom instructions.
2424 
from line 95
9595 
9696Managed instructions are either core instructions, which Claude always reads, or reference files, which Claude opens when the core instructions call for one.
9797 
98| Kind | How many | Size limit | When Claude reads it |
99| :---------------- | :--------------------------------------------------- | :----------- | :------------------------------------------------------------ |
100| Core instructions | One per managed channel | 16 KiB | At the start of every new conversation in the managed channel |
101| Reference files | Up to 20 per managed channel, each with a short name | 100 KiB each | When the core instructions point Claude to one by name |
98| Kind | How many | Size limit | When Claude reads it |
99| :- | :- | :- | :- |
100| Core instructions | One per managed channel | 16 KiB | At the start of every new conversation in the managed channel |
101| Reference files | Up to 20 per managed channel, each with a short name | 100 KiB each | When the core instructions point Claude to one by name |
102102 
103103Put what Claude must always follow in the core instructions. Put long material, such as a runbook or an escalation list, in a reference file, and name that file in the core instructions so Claude knows when to open it.
104104 
from line 121
121121 
122122A managing channel's members can read the managed channel's instructions through Claude, so a private channel's text can be managed only from other private channels.
123123 
124| Managed channel | Managing channels can be | Who can add managing channels |
125| :-------------- | :----------------------- | :------------------------------------------------------------ |
126| Public | Public or private | An Owner or Admin |
127| Private | Private only | An Owner or Admin who is also a member of the private channel |
124| Managed channel | Managing channels can be | Who can add managing channels |
125| :- | :- | :- |
126| Public | Public or private | An Owner or Admin |
127| Private | Private only | An Owner or Admin who is also a member of the private channel |
128128 
129129Anyone in the workspace can join a public managing channel and confirm changes there, so prefer a private managing channel for anything sensitive.
130130 
from line 142
142142 
143143Claude words a refusal differently each time, so match a row on its meaning. The table covers the refusals Claude or the Configure page gives for a pairing or a change.
144144 
145| What you're told | Cause | Fix |
146| :-------------------------------------------------------------------------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------- |
147| This channel isn't set as a manager of the other channel | No pairing exists, or it was removed | Add this channel under **Managed by** on the other channel's Configure page |
148| A channel is shared with another organization | The managed or managing channel is a Slack Connect channel, has a pending invitation, or is shared across Enterprise Grid workspaces | Use channels that belong to one workspace only |
149| You aren't in the managing channel, or in the private managed channel | You tried to add a managing channel you haven't joined, or to add managing channels to a private channel you aren't in | Join the channel in Slack, then try again |
150| Claude isn't in one of the channels | Claude was removed from the managed or managing channel, or never added | Run `/invite @Claude` in that channel |
151| One of those channels is archived | One of the managing channels is archived in Slack | Remove the archived channel, then try again |
152| A private channel can only be managed by private channels | The managed channel is private and the managing channel is public, or was made public later | Pick a private managing channel |
153| The managed channel may have been made private or deleted | The managed channel was made private or deleted, or Claude is no longer in it | Check the channel in Slack. If it was made private, an Owner or Admin who is a member of it adds private managing channels again |
154| Claude isn't set up in the managed channel with its own channel configuration | The managed channel has no channel scope of its own on the **Slack** tab | [Add the channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) in admin settings |
155| The managed channel already has five managing channels | Five is the most a managed channel can have | Remove one before adding another |
156| The file would be too large | The core instructions are over 16 KiB, or a reference file is over 100 KiB | Shorten the text, or move detail into a reference file |
157| The managed channel already has the most reference files | Twenty reference files exist | Ask Claude to delete one first |
158| The change is too large to show | The card can't display every changed line | Ask for a smaller part, confirm it, then ask for the next part |
159| The text was refused by the content check | The text is blank or contains characters, links, or formatting the content check doesn't allow | Remove that part or write it as plain text, then ask again |
160| Managed instructions changes aren't available for organizations with restricted compliance settings | Your organization has restricted compliance settings | See [Restricted compliance settings block Claude Tag](/docs/claude-tag/admins/troubleshooting#restricted-compliance-settings-block-claude-tag) |
145| What you're told | Cause | Fix |
146| :- | :- | :- |
147| This channel isn't set as a manager of the other channel | No pairing exists, or it was removed | Add this channel under **Managed by** on the other channel's Configure page |
148| A channel is shared with another organization | The managed or managing channel is a Slack Connect channel, has a pending invitation, or is shared across Enterprise Grid workspaces | Use channels that belong to one workspace only |
149| You aren't in the managing channel, or in the private managed channel | You tried to add a managing channel you haven't joined, or to add managing channels to a private channel you aren't in | Join the channel in Slack, then try again |
150| Claude isn't in one of the channels | Claude was removed from the managed or managing channel, or never added | Run `/invite @Claude` in that channel |
151| One of those channels is archived | One of the managing channels is archived in Slack | Remove the archived channel, then try again |
152| A private channel can only be managed by private channels | The managed channel is private and the managing channel is public, or was made public later | Pick a private managing channel |
153| The managed channel may have been made private or deleted | The managed channel was made private or deleted, or Claude is no longer in it | Check the channel in Slack. If it was made private, an Owner or Admin who is a member of it adds private managing channels again |
154| Claude isn't set up in the managed channel with its own channel configuration | The managed channel has no channel scope of its own on the **Slack** tab | [Add the channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) in admin settings |
155| The managed channel already has five managing channels | Five is the most a managed channel can have | Remove one before adding another |
156| The file would be too large | The core instructions are over 16 KiB, or a reference file is over 100 KiB | Shorten the text, or move detail into a reference file |
157| The managed channel already has the most reference files | Twenty reference files exist | Ask Claude to delete one first |
158| The change is too large to show | The card can't display every changed line | Ask for a smaller part, confirm it, then ask for the next part |
159| The text was refused by the content check | The text is blank or contains characters, links, or formatting the content check doesn't allow | Remove that part or write it as plain text, then ask again |
160| Managed instructions changes aren't available for organizations with restricted compliance settings | Your organization has restricted compliance settings | See [Restricted compliance settings block Claude Tag](/docs/claude-tag/admins/troubleshooting#restricted-compliance-settings-block-claude-tag) |
161161 
162162## Related resources
163163 

claude-tag/admins/migrate-from-earlier Changed · +7 / -7 lines

from line 50
5050 
5151The earlier app linked each user's own claude.ai account, so it answered as that person and used their connectors. Claude Tag has one identity for the team, provisioned by an admin who also sets what it can reach in each channel.
5252 
53| | Legacy (the earlier Claude in Slack) | New (Claude Tag) |
54| :------------- | :------------------------------------------ | :------------------------------------------------------------------- |
55| Identity | Each user links their own claude.ai account | One agent identity with org-level service credentials |
56| Sessions | Spawned per request | One persistent session per thread, shared with the channel |
57| Memory | None | Per-channel memory, plus workspace notes shared from public channels |
58| Standing work | None | Routines and channel watching |
59| Who sets it up | Each user, individually | An Owner, once |
53| | Legacy (the earlier Claude in Slack) | New (Claude Tag) |
54| :- | :- | :- |
55| Identity | Each user links their own claude.ai account | One agent identity with org-level service credentials |
56| Sessions | Spawned per request | One persistent session per thread, shared with the channel |
57| Memory | None | Per-channel memory, plus workspace notes shared from public channels |
58| Standing work | None | Routines and channel watching |
59| Who sets it up | Each user, individually | An Owner, once |
6060 
6161The **Claude Tag version** setting on each scope chooses whether the New or Legacy version answers there, and the scope's **Enable Claude Tag** switch turns both off. Access bundles only apply where the New version answers. See [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) for both controls and where to set them.
6262 

claude-tag/admins/network-requirements Changed · +4 / -4 lines

from line 34
3434 
3535The IP allowlist on your service and the [allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on a connection are opposite sides of the same boundary:
3636 
37| | IP allowlist | Allowed websites |
38| :-------------------- | :----------------------------------- | :-------------------------------------- |
39| **Who configures it** | Your team, on your service | You, on the connection in Claude |
40| **What it decides** | Which networks may reach the service | Which hosts a credential may be sent to |
37| | IP allowlist | Allowed websites |
38| :- | :- | :- |
39| **Who configures it** | Your team, on your service | You, on the connection in Claude |
40| **What it decides** | Which networks may reach the service | Which hosts a credential may be sent to |
4141 
4242## Events and webhooks
4343 

claude-tag/admins/restrict-access Changed · +29 / -29 lines

from line 20
2020 
2121At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), under **Where Claude Tag works**, click **Manage** next to **Member access**. The **Claude Tag in Slack** dialog lists your connected workspaces and shows a toggle that controls who in your Slack workspace can use Claude at all; its label depends on your plan. You must be an Owner of your Claude organization to change it.
2222 
23| Plan | Toggle | Off (default) | On |
24| :--------- | :------------------------------------------- | :------------------------------------------------------------------------------------ | :----------------------------------------------------------------------------------- |
23| Plan | Toggle | Off (default) | On |
24| :- | :- | :- | :- |
2525| Enterprise | **Restrict to roles with Claude Tag access** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only members whose role grants the **Claude Tag in Slack** capability can use Claude |
26| Team | **Restrict to your organization** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only Slack users with a Claude account in your organization can use Claude |
26| Team | **Restrict to your organization** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only Slack users with a Claude account in your organization can use Claude |
2727 
2828The toggle applies to channels and DMs alike.
2929 
from line 146
146146 
147147By default, Claude is disabled in any channel that includes a Slack guest. You can change this default per scope with the **How should Claude work in channels with guests** setting, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope → the collapsed **Advanced** section. The setting has three values:
148148 
149| Value | What Claude does in a channel that includes a guest |
150| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
151| **Restrict** (default) | Doesn't reply. When someone mentions it, Claude posts a short notice that it doesn't respond in channels that include guests, with a link to this setting. |
152| **Channel only** | Replies, but while a guest is present it runs with [channel-only access](#how-channel-only-works). The channel's own instructions still apply. |
153| **Full access** | Replies with the full access the scope gives it. Bundles, connections, and instructions from the workspace and from **Default Slack access** apply, along with repositories, memory, and skills. |
149| Value | What Claude does in a channel that includes a guest |
150| - | - |
151| **Restrict** (default) | Doesn't reply. When someone mentions it, Claude posts a short notice that it doesn't respond in channels that include guests, with a link to this setting. |
152| **Channel only** | Replies, but while a guest is present it runs with [channel-only access](#how-channel-only-works). The channel's own instructions still apply. |
153| **Full access** | Replies with the full access the scope gives it. Bundles, connections, and instructions from the workspace and from **Default Slack access** apply, along with repositories, memory, and skills. |
154154 
155155A channel without its own value shows **Inherit** and takes the value from its workspace, or from **Default Slack access**. Only an organization Owner can choose **Full access** or set a scope back to **Inherit**. The setting applies to every guest channel the scope covers. To open one channel rather than a whole workspace, set it on the channel's own scope.
156156 
from line 189
189189 
190190The setting has two values:
191191 
192| Value | Where workspace search finds messages |
193| --------------------------------- | ---------------------------------------------------------------------------- |
192| Value | Where workspace search finds messages |
193| - | - |
194194| **All public channels** (default) | Public channels in the workspace, including ones Claude hasn't been added to |
195| **Only channels Claude is in** | Public channels Claude has been added to |
195| **Only channels Claude is in** | Public channels Claude has been added to |
196196 
197197Most organizations can leave this on **All public channels**. Under **Only channels Claude is in**, Claude can't find messages in your other public channels, so its answers can miss context your team expects it to have.
198198 
from line 265
265265 
266266A channel manager has to be a member of the channel in Slack. The channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel), which opens on claude.ai from the **Configure** link in any Claude reply, is split into tabs. In a channel you assigned to them, a channel manager sees the **Default model** card on the **General** tab and the repository and access bundle cards on the **Tools and access** tab. Members without the role don't see those cards. Owners and Admins also see an **Admin** tab, whose **Channel settings** card holds some of the channel scope's settings from admin settings.
267267 
268| Setting | What a channel manager can do |
269| :----------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
270| **Default model** | Choose the model new threads in the channel start on, from the models your organization allows. **Inherit** keeps the workspace or organization default |
271| **Repositories** | Add repositories beyond the ones your bundles already grant the channel. They can add only repositories their own GitHub account is an admin of |
268| Setting | What a channel manager can do |
269| :- | :- |
270| **Default model** | Choose the model new threads in the channel start on, from the models your organization allows. **Inherit** keeps the workspace or organization default |
271| **Repositories** | Add repositories beyond the ones your bundles already grant the channel. They can add only repositories their own GitHub account is an admin of |
272272| **Access bundles** | Add, rotate, test, and remove credentials, and turn [plugins](/docs/claude-tag/admins/add-connections#attach-plugins) on or off, in the bundle Claude created for the channel and in any bundle they created for it. If the channel has no bundle yet, they can create one. They can't edit a bundle you created or a bundle that other channels share |
273273 
274274When a channel manager adds a credential, Claude also allows the host that credential uses. Channel managers can't change the bundle's domains or rules in any other way. Credentials that use Claude's own identity (mutual TLS, AWS or GCP service identity, and IAP) stay Owner-only: a channel manager can't add, change, or rotate one, but can delete one from the channel's bundle, including one an Owner added. If that happens, Claude loses access to that service until an Owner adds the credential back.
from line 325
325325 
326326Creating bundles, binding them to scopes, and pairing workspaces need an Owner. A [channel manager](#delegate-channel-setup-to-channel-managers) configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The table lists each action and who can take it.
327327 
328| Action | Owner | Channel manager | Channel member |
329| :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------ | :-------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------- |
330| Pair a workspace | Yes | No | No |
331| Create, rename, delete, or bind an Access bundle | Yes | Only to create a bundle for an assigned channel | No |
332| Edit a bundle's Repositories, Domains, or Instructions tab | Yes | No | No |
333| Edit a bundle's Credentials or Plugins tab | Yes | Yes, in a bundle created for an assigned channel | No |
334| Add a channel manager | Yes | No | No |
335| Set a channel's default model or repositories from the Configure page | Yes | Yes, in assigned channels | No |
336| Set a channel's default model by asking Claude in a thread, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** | Yes | Yes | Yes |
337| Turn a channel's [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) setting on or off | Yes | Yes, in assigned channels | Yes, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** |
338| Write channel memory | Yes, in the channel | Yes, in the channel | Yes |
339| Set channel instructions from the Configure link | Yes | Yes, in assigned channels | Yes, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting blocks it |
340| Create, list, or disable a scheduled job in the channel | Yes, in the channel | Yes, in the channel | Yes |
341| Remove Claude from a channel | Yes | Yes, with `/remove`, unless your Slack admin restricts it | Yes, with `/remove`, unless your Slack admin restricts it |
328| Action | Owner | Channel manager | Channel member |
329| :- | :- | :- | :- |
330| Pair a workspace | Yes | No | No |
331| Create, rename, delete, or bind an Access bundle | Yes | Only to create a bundle for an assigned channel | No |
332| Edit a bundle's Repositories, Domains, or Instructions tab | Yes | No | No |
333| Edit a bundle's Credentials or Plugins tab | Yes | Yes, in a bundle created for an assigned channel | No |
334| Add a channel manager | Yes | No | No |
335| Set a channel's default model or repositories from the Configure page | Yes | Yes, in assigned channels | No |
336| Set a channel's default model by asking Claude in a thread, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** | Yes | Yes | Yes |
337| Turn a channel's [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) setting on or off | Yes | Yes, in assigned channels | Yes, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** |
338| Write channel memory | Yes, in the channel | Yes, in the channel | Yes |
339| Set channel instructions from the Configure link | Yes | Yes, in assigned channels | Yes, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting blocks it |
340| Create, list, or disable a scheduled job in the channel | Yes, in the channel | Yes, in the channel | Yes |
341| Remove Claude from a channel | Yes | Yes, with `/remove`, unless your Slack admin restricts it | Yes, with `/remove`, unless your Slack admin restricts it |
342342 
343343Scheduled jobs run with the channel's credentials, so a member creating one can't reach anything the channel itself can't.
344344 
Feedback