Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · api

External Keys changedapi/organization/external_keys

Nearest release: v2.1.286, published 6 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Recorded here
Lines+1,072added
Lines−0removed
From line — no hunk to open at
First seen 30 Sep 2026 this site's first read of the page
Recorded edits1to this page, all time

# External Keys ## Create External Key ### Body parameters ### Returns ### Example #### Response (200) ## List External Keys ### Query parameters ### Returns ### Example #### Response (200) ## Get External Key ### Path parameters ### Returns ### Example #### Response (200) ## Update External Key ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Delete External Key ### Path parameters ### Returns ### Example #### Response (200) ## Validate External Key ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### AWS External Key Config ### Azure External Key Config ### Azure External Key Config Param ### External Key ### External Key Attached Attachment ### External Key Unattached Attachment ### GCP External Key Config ### External Key Delete Response ### External Key Validate Response

The whole hunk

1072 lines, new page
/
lines

A whole new page. There's nothing to diff it against, so here is what it says.

---
title: External Keys
url: https://platform.claude.com/docs/en/api/organization/external_keys
---

# External Keys

## Create External Key

**POST** `/v1/organizations/external_keys`

Create an external key config owned by the caller's organization.

### Body parameters

- `provider_config: AWSExternalKeyConfig or GCPExternalKeyConfig or AzureExternalKeyConfigParam`

  KMS provider identity and auth coordinates.

  - `AWSExternalKeyConfig object`

    - `type: "aws"`

    - `kms_arn: string`

      Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

      maxLength: 2048

    - `region: optional string or null`

      AWS region. Derived from `kms_arn` if omitted.

    - `role_arn: optional string or null`

      **Deprecated**

      IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.

  - `GCPExternalKeyConfig object`

    - `type: "gcp"`

    - `key_name: string`

      Full resource name of the Cloud KMS key.

  - `AzureExternalKeyConfigParam object`

    Azure Key Vault provider configuration.

    - `type: "azure"`

    - `key_name: string`

      Name of the key within the vault.

    - `tenant_id: string`

      Azure AD tenant ID.

    - `vault_uri: string`

      Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.

    - `client_id: optional string or null`

      Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

- `display_name: optional string or null`

  Human-friendly display name.

  minLength: 1, maxLength: 255

- `geo: optional "us"`

  Data residency geo. Only `us` is supported.

### Returns

- `ExternalKey object`

  CMEK external key config belonging to the caller's organization.

  Configs are organization-scoped. Workspaces attach to a config; once any
  workspace references it, the provider fields become effectively immutable
  (existing encrypted data needs the config for decrypt).

  - `type: "external_key"`

    default: external_key

  - `id: string`

    Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.

  - `attachment: ExternalKeyAttachedAttachment or ExternalKeyUnattachedAttachment`

    Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.

    - `ExternalKeyAttachedAttachment object`

      - `type: "attached"`

        default: attached

    - `ExternalKeyUnattachedAttachment object`

      - `type: "unattached"`

        default: unattached

  - `created_at: string`

    format: date-time

  - `display_name: string or null`

    Human-friendly display name. Null if none was set.

  - `geo: string`

    Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.

  - `provider_config: AWSExternalKeyConfig or GCPExternalKeyConfig or AzureExternalKeyConfig`

    KMS provider identity and auth coordinates.

    - `AWSExternalKeyConfig object`

      - `type: "aws"`

      - `kms_arn: string`

        Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

        maxLength: 2048

      - `region: optional string or null`

        AWS region. Derived from `kms_arn` if omitted.

      - `role_arn: optional string or null`

        **Deprecated**

        IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.

    - `GCPExternalKeyConfig object`

      - `type: "gcp"`

      - `key_name: string`

        Full resource name of the Cloud KMS key.

    - `AzureExternalKeyConfig object`

      - `type: "azure"`

      - `key_name: string`

        Name of the key within the vault.

      - `tenant_id: string`

        Azure AD tenant ID.

      - `vault_uri: string`

        Key Vault data-plane URI — `https://{vault-name}.vault.azure.net` or `https://{hsm-name}.managedhsm.azure.net`.

      - `client_id: optional string or null`

        Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

  - `updated_at: string`

    format: date-time

### Example

```bash
curl https://api.anthropic.com/v1/organizations/external_keys \
    -H 'Content-Type: application/json' \
    -H 'anthropic-version: 2023-06-01' \
    -H "X-Api-Key: $ANTHROPIC_API_KEY" \
    -d '{
          "provider_config": {
            "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
            "type": "aws"
          }
        }'
```

#### Response (200)

```json
{
  "id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "attachment": {
    "type": "attached"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "display_name": "prod-us-key",
  "geo": "us",
  "provider_config": {
    "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
    "type": "aws",
    "region": "us-east-1",
    "role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
  },
  "type": "external_key",
  "updated_at": "2024-10-30T23:58:27.427722Z"
}
```

## List External Keys

**GET** `/v1/organizations/external_keys`

List external key configs in the caller's organization.

Results are ordered by creation time (newest first). Use the
`next_page` cursor from the response to fetch subsequent pages.

### Query parameters

- `limit: optional number`

  Number of results per page.

  default: 20, minimum: 1, maximum: 100

- `page: optional string`

  Opaque cursor from a previous response's `next_page`.

### Returns

- `data: array of ExternalKey`

  - `type: "external_key"`

    default: external_key

  - `id: string`

    Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN.

  - `attachment: ExternalKeyAttachedAttachment or ExternalKeyUnattachedAttachment`

    Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted.

    - `ExternalKeyAttachedAttachment object`

      - `type: "attached"`

        default: attached

    - `ExternalKeyUnattachedAttachment object`

      - `type: "unattached"`

        default: unattached

  - `created_at: string`

    format: date-time

  - `display_name: string or null`

    Human-friendly display name. Null if none was set.

  - `geo: string`

    Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.

  - `provider_config: AWSExternalKeyConfig or GCPExternalKeyConfig or AzureExternalKeyConfig`

    KMS provider identity and auth coordinates.

    - `AWSExternalKeyConfig object`

      - `type: "aws"`

      - `kms_arn: string`

        Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

        maxLength: 2048

      - `region: optional string or null`

        AWS region. Derived from `kms_arn` if omitted.

      - `role_arn: optional string or null`

        **Deprecated**

Cut at 300 lines. The page has the rest.

Feedback