Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · api

cmek-aws-kms changedmanage-claude/cmek-aws-kms

Nearest release: v2.1.292, published 11 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Recorded here
Lines+38added
Lines−38removed
From line 55 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits13to this page, all time

The whole hunk

from line 55, old and new numbered
/
lines
from line 55
5555 In the policy, replace `<AWS_ACCOUNT_ID>` with your AWS account ID and `<ORGANIZATION_UUID>` with your organization ID. The `StringEquals` condition on `kms:EncryptionContext:anthropic:org_uuid` binds the key to your Anthropic organization, and validation refuses a key without it. To share one key among several Anthropic organizations, list each organization ID in the condition value.
5656 
5757 <Note>
58 **Finding your organization ID:** Copy the **Organization ID** field under **Settings > Organization** in the Claude Console, or under **Organization settings > Organization** in claude.ai, or read the `id` field from the [Organization Info](https://platform.claude.com/docs/en/api/beta/organization/retrieve) endpoint. Use the bare UUID, not the `org_`-prefixed ID.
58 **Finding your organization ID:** Copy the **Organization ID** field under **Settings > Organization** in the Claude Console, or under **Organization settings > Organization** in claude.ai, or read the `id` field from the [Organization Info](https://platform.claude.com/docs/en/api/organization/retrieve) endpoint. Use the bare UUID, not the `org_`-prefixed ID.
5959 </Note>
6060 
6161 Save the policy as `key-policy.json`. To create the key in the AWS Console instead, paste the policy there, as described later in this step.
from line 196
196196 </Note>
197197 
198198 <Note>
199 **Finding your compartment ID:** Each workspace has a compartment ID that scopes its CMEK data. To find it in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) endpoint.
199 **Finding your compartment ID:** Each workspace has a compartment ID that scopes its CMEK data. To find it in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/organization/workspaces/retrieve) endpoint.
200200 </Note>
201201 
202202 You can set up the key in the Claude Console or through the Admin API, with the same result.
from line 242
242242 ```
243243 
244244 ```bash CLI
245 ant beta:organization:external-keys create <<'YAML'
245 ant organization:external-keys create <<'YAML'
246246 display_name: "<friendly-name>"
247247 geo: us
248248 provider_config:
from line 254
254254 ```python Python
255255 client = anthropic.Anthropic()
256256 
257 external_key = client.beta.organization.external_keys.create(
257 external_key = client.organization.external_keys.create(
258258 display_name="<friendly-name>",
259259 geo="us",
260260 provider_config={"type": "aws", "kms_arn": "<key-arn-from-create-key-step>"},
from line 267
267267 ```typescript TypeScript
268268 const client = new Anthropic();
269269 
270 const externalKey = await client.beta.organization.externalKeys.create({
270 const externalKey = await client.organization.externalKeys.create({
271271 display_name: "<friendly-name>",
272272 geo: "us",
273273 provider_config: {
from line 281
281281 ```
282282 
283283 ```csharp C#
284 using Anthropic.Models.Beta.Organization.ExternalKeys;
284 using Anthropic.Models.Organization.ExternalKeys;
285285 
286286 AnthropicClient client = new();
287287 
288 var externalKey = await client.Beta.Organization.ExternalKeys.Create(new()
288 var externalKey = await client.Organization.ExternalKeys.Create(new()
289289 {
290290 DisplayName = "<friendly-name>",
291291 Geo = Geo.Us,
292 ProviderConfig = new BetaAwsExternalKeyConfig
292 ProviderConfig = new AwsExternalKeyConfig
293293 {
294294 KmsArn = "<key-arn-from-create-key-step>"
295295 }
from line 302
302302 ```go Go
303303 client := anthropic.NewClient()
304304 
305 externalKey, err := client.Beta.Organization.ExternalKeys.New(context.Background(), anthropic.BetaOrganizationExternalKeyNewParams{
305 externalKey, err := client.Organization.ExternalKeys.New(context.Background(), anthropic.OrganizationExternalKeyNewParams{
306306 DisplayName: anthropic.String("<friendly-name>"),
307 Geo: anthropic.BetaOrganizationExternalKeyNewParamsGeoUs,
308 ProviderConfig: anthropic.BetaOrganizationExternalKeyNewParamsProviderConfigUnion{
309 OfAWS: &anthropic.BetaAWSExternalKeyConfigParam{
307 Geo: anthropic.OrganizationExternalKeyNewParamsGeoUs,
308 ProviderConfig: anthropic.OrganizationExternalKeyNewParamsProviderConfigUnion{
309 OfAWS: &anthropic.AWSExternalKeyConfigParam{
310310 KMSARN: "<key-arn-from-create-key-step>",
311311 },
312312 },
from line 320
320320 ```
321321 
322322 ```java Java
323 import com.anthropic.models.beta.organization.externalkeys.BetaAwsExternalKeyConfig;
324 import com.anthropic.models.beta.organization.externalkeys.ExternalKeyCreateParams;
323 import com.anthropic.models.organization.externalkeys.AwsExternalKeyConfig;
324 import com.anthropic.models.organization.externalkeys.ExternalKeyCreateParams;
325325 
326326 void main() {
327327 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 329
329329 var params = ExternalKeyCreateParams.builder()
330330 .displayName("<friendly-name>")
331331 .geo(ExternalKeyCreateParams.Geo.US)
332 .providerConfig(BetaAwsExternalKeyConfig.builder()
332 .providerConfig(AwsExternalKeyConfig.builder()
333333 .kmsArn("<key-arn-from-create-key-step>")
334334 .build())
335335 .build();
336 var externalKey = client.beta().organization().externalKeys().create(params);
336 var externalKey = client.organization().externalKeys().create(params);
337337 
338338 IO.println("id: " + externalKey.id());
339339 IO.println("display_name: " + externalKey.displayName().orElseThrow());
from line 341
341341 ```
342342 
343343 ```php PHP
344 use Anthropic\Beta\Organization\ExternalKeys\ExternalKeyCreateParams\Geo;
344 use Anthropic\Organization\ExternalKeys\ExternalKeyCreateParams\Geo;
345345 // ...
346346 
347347 $client = new Client();
348348 
349 $externalKey = $client->beta->organization->externalKeys->create(
349 $externalKey = $client->organization->externalKeys->create(
350350 displayName: '<friendly-name>',
351351 geo: Geo::US,
352352 providerConfig: [
from line 362
362362 ```ruby Ruby
363363 client = Anthropic::Client.new
364364 
365 external_key = client.beta.organization.external_keys.create(
365 external_key = client.organization.external_keys.create(
366366 display_name: "<friendly-name>",
367367 geo: :us,
368368 provider_config: {
from line 398
398398 ```
399399 
400400 ```bash CLI
401 ant beta:organization:external-keys validate --external-key-id "ekey_<id>"
401 ant organization:external-keys validate --external-key-id "ekey_<id>"
402402 ```
403403 
404404 ```python Python
405405 client = anthropic.Anthropic()
406406 
407 validation = client.beta.organization.external_keys.validate("ekey_<id>")
407 validation = client.organization.external_keys.validate("ekey_<id>")
408408 
409409 print(f"status: {validation.status}")
410410 print(f"error: {validation.error}")
from line 413
413413 ```typescript TypeScript
414414 const client = new Anthropic();
415415 
416 const validation = await client.beta.organization.externalKeys.validate("ekey_<id>");
416 const validation = await client.organization.externalKeys.validate("ekey_<id>");
417417 
418418 console.log(`status: ${validation.status}`);
419419 console.log(`error: ${validation.error}`);
from line 422
422422 ```csharp C#
423423 AnthropicClient client = new();
424424 
425 var validation = await client.Beta.Organization.ExternalKeys.Validate("ekey_<id>");
425 var validation = await client.Organization.ExternalKeys.Validate("ekey_<id>");
426426 
427427 Console.WriteLine($"status: {validation.Status.Raw()}");
428428 Console.WriteLine($"error: {validation.Error}");
from line 431
431431 ```go Go
432432 client := anthropic.NewClient()
433433 
434 validation, err := client.Beta.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>")
434 validation, err := client.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>")
435435 if err != nil {
436436 log.Fatal(err)
437437 }
from line 443
443443 ```java Java
444444 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
445445 
446 var validation = client.beta().organization().externalKeys().validate("ekey_<id>");
446 var validation = client.organization().externalKeys().validate("ekey_<id>");
447447 
448448 IO.println("status: " + validation.status().asString());
449449 IO.println("error: " + validation.error().orElse(""));
from line 452
452452 ```php PHP
453453 $client = new Client();
454454 
455 $validation = $client->beta->organization->externalKeys->validate(
455 $validation = $client->organization->externalKeys->validate(
456456 externalKeyID: 'ekey_<id>',
457457 );
458458 
from line 464
464464 client = Anthropic::Client.new
465465 
466466 external_key_id = "ekey_<id>"
467 validation = client.beta.organization.external_keys.validate(external_key_id)
467 validation = client.organization.external_keys.validate(external_key_id)
468468 
469469 puts "status: #{validation.status}"
470470 puts "error: #{validation.error}"
from line 500
500500 ```
501501 
502502 ```bash CLI
503 ant beta:organization:workspaces update \
503 ant organization:workspaces update \
504504 --workspace-id "<workspace-id>" \
505505 --external-key-id "ekey_<id>"
506506 ```
from line 508
508508 ```python Python
509509 client = anthropic.Anthropic()
510510 
511 workspace = client.beta.organization.workspaces.update(
511 workspace = client.organization.workspaces.update(
512512 "<workspace-id>", external_key_id="ekey_<id>"
513513 )
514514 
from line 519
519519 ```typescript TypeScript
520520 const client = new Anthropic();
521521 
522 const workspace = await client.beta.organization.workspaces.update("<workspace-id>", {
522 const workspace = await client.organization.workspaces.update("<workspace-id>", {
523523 external_key_id: "ekey_<id>"
524524 });
525525 
from line 530
530530 ```csharp C#
531531 AnthropicClient client = new();
532532 
533 var workspace = await client.Beta.Organization.Workspaces.Update("<workspace-id>", new()
533 var workspace = await client.Organization.Workspaces.Update("<workspace-id>", new()
534534 {
535535 ExternalKeyID = "ekey_<id>"
536536 });
from line 542
542542 ```go Go
543543 client := anthropic.NewClient()
544544 
545 workspace, err := client.Beta.Organization.Workspaces.Update(
545 workspace, err := client.Organization.Workspaces.Update(
546546 context.Background(),
547547 "<workspace-id>",
548 anthropic.BetaOrganizationWorkspaceUpdateParams{
548 anthropic.OrganizationWorkspaceUpdateParams{
549549 ExternalKeyID: anthropic.String("ekey_<id>"),
550550 },
551551 )
from line 558
558558 ```
559559 
560560 ```java Java
561 import com.anthropic.models.beta.organization.workspaces.WorkspaceUpdateParams;
561 import com.anthropic.models.organization.workspaces.WorkspaceUpdateParams;
562562 
563563 void main() {
564564 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 566
566566 var params = WorkspaceUpdateParams.builder()
567567 .externalKeyId("ekey_<id>")
568568 .build();
569 var workspace = client.beta().organization().workspaces().update("<workspace-id>", params);
569 var workspace = client.organization().workspaces().update("<workspace-id>", params);
570570 
571571 IO.println("id: " + workspace.id());
572572 IO.println("external_key_id: " + workspace.externalKeyId().orElseThrow());
from line 576
576576 ```php PHP
577577 $client = new Client();
578578 
579 $workspace = $client->beta->organization->workspaces->update(
579 $workspace = $client->organization->workspaces->update(
580580 workspaceID: '<workspace-id>',
581581 externalKeyID: 'ekey_<id>',
582582 );
from line 589
589589 client = Anthropic::Client.new
590590 
591591 workspace_id = "<workspace-id>"
592 workspace = client.beta.organization.workspaces.update(
592 workspace = client.organization.workspaces.update(
593593 workspace_id,
594594 external_key_id: "ekey_<id>"
595595 )
from line 638
638638 
639639The key policy has three statements: your account's root admin statement; a statement that lets the Claude Platform on AWS service principal encrypt, decrypt, and generate data keys; and a separate statement for `kms:DescribeKey`. The crypto statement carries an optional `EncryptionContext` condition that binds the key to the workspaces you list. `DescribeKey` is granted separately because it has no `EncryptionContext` parameter, so an `EncryptionContext` condition on that action would always deny.
640640 
641If you plan to use the optional `EncryptionContext` condition shown here, create the workspace first (without a key), copy its compartment ID, and substitute it for `<compartment-uuid>`. To find the ID in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read it from the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) endpoint. If you don't plan to use the condition, delete the `Condition` block from that statement.
641If you plan to use the optional `EncryptionContext` condition shown here, create the workspace first (without a key), copy its compartment ID, and substitute it for `<compartment-uuid>`. To find the ID in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read it from the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/organization/workspaces/retrieve) endpoint. If you don't plan to use the condition, delete the `Condition` block from that statement.
642642 
643643```bash
644644export YOUR_ACCOUNT=$(aws sts get-caller-identity --query Account --output text)
Feedback