Limits for federated agent access changedclaude-tag/admins/federated-access/limits
Nearest release: v2.1.286, published an hour before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 30 Sep 2026 19:12 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 30 Sep 2026 19:37 UTC.
Upstream edited
Recorded here
Lines+3added
Lines−4removed
From line
1
where the diff opens
First seen
10 Sep 2026
this site's first read of the page
Recorded edits4to this page, all time
# Limits for federated agent access # Limits for federated cloud access
The whole hunk
from line 1, old and new numbered
/
from line 1
1# Limits for federated cloud access
1# Limits for federated agent access
22
3> Counts, lengths, lifetimes, and unsupported configurations for Claude Tag's federated cloud access: gateways, AWS roles, Google Cloud identities, and authorization servers.
3> Counts, lengths, lifetimes, and unsupported configurations for Claude Tag's federated agent access: gateways, AWS roles, Google Cloud identities, and authorization servers.
44
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66
77<BetaNote />
88
9This page collects the fixed limits of Federated cloud access in one place.
9This page collects the fixed limits of Federated agent access in one place.
1010
1111## Where federated connections work
1212
from line 27
2727| Registered addresses per organization | 5, counting gateways and authorization-server token endpoints together. |
2828| Token reuse | Claude reuses one token for a session's requests to the same gateway for about five minutes, half the token's lifetime, or until the gateway answers 401, and then requests a new one (current behavior, may change). A gateway sees the same `jti` on many requests. |
2929| Gateway address | An HTTPS host name only, with no path, port, query, or trailing slash. The host name needs a domain, like `gateway.example.com`, uses only letters, numbers, hyphens, and dots, and has at most 253 characters (current behavior, may change). The console rejects an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange, and names the reason. The connection check also refuses a host name that resolves to a private address. |
30| One connection per gateway | A gateway connected in one Access bundle can't be connected again in another. Attach that bundle to each scope that needs the gateway. |
3130| [Allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the gateway's connection | Exactly the gateway's host, the only host Claude sends the token to. It can't be widened or given a wildcard. |
3231| Connection check | Runs only against an HTTPS host with no path. The console sends two `POST` requests to the address, each with an empty body and a test token, doesn't follow redirects, and can take up to a minute. [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway) lists the expected responses. The console refuses a check that runs many times in quick succession and says how long to wait. |
3332| Same address twice in one organization | Entering an address that is already registered runs the connection check again (unless you skip it) without changing the stored result, then moves to the bundle step. The run counts toward the check limit. |
No line in this hunk matches that.