Claude apps gateway spend limits changedclaude-apps-gateway-spend-limits
Nearest release: v2.1.284, published 17 hours after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 28 Sep 2026 00:07 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 23:37 UTC.
Upstream edited
Recorded here
Lines+24added
Lines−24removed
From line
28
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits7to this page, all time
The whole hunk
from line 28, old and new numbered
/
from line 28
2828 -d '{"scope": {"type": "rbac_group", "rbac_group_id": "contractors"}, "amount": "10000", "period": "daily"}'
2929```
3030
31| Field | Values | Description |
32| ------------ | ------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
33| `scope.type` | `user`, `rbac_group`, `organization` | `user` targets one developer by their OpenID Connect (OIDC) `sub`, the stable user ID your identity provider assigns; pass it as `scope.user_id`. `rbac_group` targets an [IdP group](/docs/en/claude-apps-gateway-config#managed) by name; pass it as `scope.rbac_group_id`. `organization` is the org-wide default. The gateway accepts all three; Anthropic's public `POST` is user-only today. |
34| `amount` | Whole-number string of USD cents, or `null` | `null` is unlimited. `"0"` is a zero cap, which blocks every request. |
35| `period` | `daily`, `weekly`, `monthly` | A scope can hold one cap per period, and each enforces independently: a developer is blocked if over any of them. |
31| Field | Values | Description |
32| - | - | - |
33| `scope.type` | `user`, `rbac_group`, `organization` | `user` targets one developer by their OpenID Connect (OIDC) `sub`, the stable user ID your identity provider assigns; pass it as `scope.user_id`. `rbac_group` targets an [IdP group](/docs/en/claude-apps-gateway-config#managed) by name; pass it as `scope.rbac_group_id`. `organization` is the org-wide default. The gateway accepts all three; Anthropic's public `POST` is user-only today. |
34| `amount` | Whole-number string of USD cents, or `null` | `null` is unlimited. `"0"` is a zero cap, which blocks every request. |
35| `period` | `daily`, `weekly`, `monthly` | A scope can hold one cap per period, and each enforces independently: a developer is blocked if over any of them. |
3636
3737A group or organization cap is a per-seat default that each member inherits, not a shared pool. Per period, a developer's effective cap resolves in this order: a per-user override, then the most restrictive of their group caps, then the org default, then unlimited. [`admin.group_limit_mode: max`](/docs/en/claude-apps-gateway-config#admin) flips the multi-group tie-break to least-restrictive instead.
3838
from line 91
9191
9292The endpoints below are served under `/v1/organizations/spend_limits`.
9393
94| Method and path | Description |
95| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
96| `GET /v1/organizations/spend_limits` | List configured caps, optionally filtered to one `scope_type` of `organization`, `rbac_group`, or `user`. Query: `?limit=&after_id=&before_id=&scope_type=`. |
97| `POST /v1/organizations/spend_limits` | Create or replace a cap for `{scope, period}`. |
98| `GET /v1/organizations/spend_limits/{id}` | Fetch one cap by its `spl_`-prefixed ID. |
99| `DELETE /v1/organizations/spend_limits/{id}` | Delete one cap. Returns `{type: "spend_limit_deleted", id}`. |
100| `GET /v1/organizations/spend_limits/effective` | Resolved cap and to-date spend per principal per period. |
101| `GET /v1/organizations/spend_limits/audit` | Admin mutation trail, newest-first. Query: `?limit=&after_id=`. |
94| Method and path | Description |
95| - | - |
96| `GET /v1/organizations/spend_limits` | List configured caps, optionally filtered to one `scope_type` of `organization`, `rbac_group`, or `user`. Query: `?limit=&after_id=&before_id=&scope_type=`. |
97| `POST /v1/organizations/spend_limits` | Create or replace a cap for `{scope, period}`. |
98| `GET /v1/organizations/spend_limits/{id}` | Fetch one cap by its `spl_`-prefixed ID. |
99| `DELETE /v1/organizations/spend_limits/{id}` | Delete one cap. Returns `{type: "spend_limit_deleted", id}`. |
100| `GET /v1/organizations/spend_limits/effective` | Resolved cap and to-date spend per principal per period. |
101| `GET /v1/organizations/spend_limits/audit` | Admin mutation trail, newest-first. Query: `?limit=&after_id=`. |
102102
103103Conventions mirror Anthropic's Admin API:
104104
from line 123
123123
124124Group-sourced caps resolve against those last-seen groups with the same `group_limit_mode` tie-break that enforcement uses, so the viewer shows the cap that actually applies.
125125
126| Query parameter | Description |
127| ---------------- | ------------------------------------------------------------------------------------------------------- |
128| `user_ids[]` | Repeatable. Filter to specific principals by OIDC `sub`. |
129| `period[]` | Repeatable. Filter to `daily`, `weekly`, or `monthly` rows. |
130| `sort` | `spend_desc` lists top spenders first. Requires exactly one `period[]`. |
131| `q` | Case-insensitive substring filter over the OIDC `sub`, last-seen email, and last-seen display name. |
126| Query parameter | Description |
127| - | - |
128| `user_ids[]` | Repeatable. Filter to specific principals by OIDC `sub`. |
129| `period[]` | Repeatable. Filter to `daily`, `weekly`, or `monthly` rows. |
130| `sort` | `spend_desc` lists top spenders first. Requires exactly one `period[]`. |
131| `q` | Case-insensitive substring filter over the OIDC `sub`, last-seen email, and last-seen display name. |
132132| `limit` / `page` | Page size, 1–1000 with a default of 20, and the opaque cursor from the previous response's `next_page`. |
133133
134134<Warning>
from line 147
147147
148148The gateway holds four spend-related tables; an hourly sweep enforces the retention windows:
149149
150| Table | Contents | Retention |
151| ------------------ | ----------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
152| `spend` | Per-principal period-to-date counters in cents | [`admin.spend_retention_months`](/docs/en/claude-apps-gateway-config#admin), default 13 |
153| `spend_limits` | The configured caps | Until deleted via the API |
154| `admin_audit` | The mutation trail | [`admin.audit_retention_days`](/docs/en/claude-apps-gateway-config#admin), default 365 |
150| Table | Contents | Retention |
151| - | - | - |
152| `spend` | Per-principal period-to-date counters in cents | [`admin.spend_retention_months`](/docs/en/claude-apps-gateway-config#admin), default 13 |
153| `spend_limits` | The configured caps | Until deleted via the API |
154| `admin_audit` | The mutation trail | [`admin.audit_retention_days`](/docs/en/claude-apps-gateway-config#admin), default 365 |
155155| `principal_emails` | Each principal's last-seen email, display name, and IdP groups. Contains PII. | [`admin.identity_retention_days`](/docs/en/claude-apps-gateway-config#admin) since last activity, default 90 |
156156
157157When a developer leaves, delete any per-user cap via `DELETE /v1/organizations/spend_limits/{id}`; their spend and identity rows age out on the retention windows above. To erase one person immediately, for offboarding or a data subject access request (DSAR), run `DELETE FROM principal_emails WHERE principal = '<sub>'` directly against the gateway database. That removes the only table holding their email, name, and groups. The `spend` and `admin_audit` rows reference the pseudonymous OIDC `sub` only and age out on their own windows.
No line in this hunk matches that.