cmek-aws-kms changedmanage-claude/cmek-aws-kms
Nearest release: v2.1.292, published 11 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+38added
Lines−38removed
From line
55
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits13to this page, all time
The whole hunk
from line 55, old and new numbered
/
from line 55
5555 In the policy, replace `<AWS_ACCOUNT_ID>` with your AWS account ID and `<ORGANIZATION_UUID>` with your organization ID. The `StringEquals` condition on `kms:EncryptionContext:anthropic:org_uuid` binds the key to your Anthropic organization, and validation refuses a key without it. To share one key among several Anthropic organizations, list each organization ID in the condition value.
5656
5757 <Note>
58 **Finding your organization ID:** Copy the **Organization ID** field under **Settings > Organization** in the Claude Console, or under **Organization settings > Organization** in claude.ai, or read the `id` field from the [Organization Info](https://platform.claude.com/docs/en/api/beta/organization/retrieve) endpoint. Use the bare UUID, not the `org_`-prefixed ID.
58 **Finding your organization ID:** Copy the **Organization ID** field under **Settings > Organization** in the Claude Console, or under **Organization settings > Organization** in claude.ai, or read the `id` field from the [Organization Info](https://platform.claude.com/docs/en/api/organization/retrieve) endpoint. Use the bare UUID, not the `org_`-prefixed ID.
5959 </Note>
6060
6161 Save the policy as `key-policy.json`. To create the key in the AWS Console instead, paste the policy there, as described later in this step.
from line 196
196196 </Note>
197197
198198 <Note>
199 **Finding your compartment ID:** Each workspace has a compartment ID that scopes its CMEK data. To find it in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) endpoint.
199 **Finding your compartment ID:** Each workspace has a compartment ID that scopes its CMEK data. To find it in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/organization/workspaces/retrieve) endpoint.
200200 </Note>
201201
202202 You can set up the key in the Claude Console or through the Admin API, with the same result.
from line 242
242242 ```
243243
244244 ```bash CLI
245 ant beta:organization:external-keys create <<'YAML'
245 ant organization:external-keys create <<'YAML'
246246 display_name: "<friendly-name>"
247247 geo: us
248248 provider_config:
from line 254
254254 ```python Python
255255 client = anthropic.Anthropic()
256256
257 external_key = client.beta.organization.external_keys.create(
257 external_key = client.organization.external_keys.create(
258258 display_name="<friendly-name>",
259259 geo="us",
260260 provider_config={"type": "aws", "kms_arn": "<key-arn-from-create-key-step>"},
from line 267
267267 ```typescript TypeScript
268268 const client = new Anthropic();
269269
270 const externalKey = await client.beta.organization.externalKeys.create({
270 const externalKey = await client.organization.externalKeys.create({
271271 display_name: "<friendly-name>",
272272 geo: "us",
273273 provider_config: {
from line 281
281281 ```
282282
283283 ```csharp C#
284 using Anthropic.Models.Beta.Organization.ExternalKeys;
284 using Anthropic.Models.Organization.ExternalKeys;
285285
286286 AnthropicClient client = new();
287287
288 var externalKey = await client.Beta.Organization.ExternalKeys.Create(new()
288 var externalKey = await client.Organization.ExternalKeys.Create(new()
289289 {
290290 DisplayName = "<friendly-name>",
291291 Geo = Geo.Us,
292 ProviderConfig = new BetaAwsExternalKeyConfig
292 ProviderConfig = new AwsExternalKeyConfig
293293 {
294294 KmsArn = "<key-arn-from-create-key-step>"
295295 }
from line 302
302302 ```go Go
303303 client := anthropic.NewClient()
304304
305 externalKey, err := client.Beta.Organization.ExternalKeys.New(context.Background(), anthropic.BetaOrganizationExternalKeyNewParams{
305 externalKey, err := client.Organization.ExternalKeys.New(context.Background(), anthropic.OrganizationExternalKeyNewParams{
306306 DisplayName: anthropic.String("<friendly-name>"),
307 Geo: anthropic.BetaOrganizationExternalKeyNewParamsGeoUs,
308 ProviderConfig: anthropic.BetaOrganizationExternalKeyNewParamsProviderConfigUnion{
309 OfAWS: &anthropic.BetaAWSExternalKeyConfigParam{
307 Geo: anthropic.OrganizationExternalKeyNewParamsGeoUs,
308 ProviderConfig: anthropic.OrganizationExternalKeyNewParamsProviderConfigUnion{
309 OfAWS: &anthropic.AWSExternalKeyConfigParam{
310310 KMSARN: "<key-arn-from-create-key-step>",
311311 },
312312 },
from line 320
320320 ```
321321
322322 ```java Java
323 import com.anthropic.models.beta.organization.externalkeys.BetaAwsExternalKeyConfig;
324 import com.anthropic.models.beta.organization.externalkeys.ExternalKeyCreateParams;
323 import com.anthropic.models.organization.externalkeys.AwsExternalKeyConfig;
324 import com.anthropic.models.organization.externalkeys.ExternalKeyCreateParams;
325325
326326 void main() {
327327 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 329
329329 var params = ExternalKeyCreateParams.builder()
330330 .displayName("<friendly-name>")
331331 .geo(ExternalKeyCreateParams.Geo.US)
332 .providerConfig(BetaAwsExternalKeyConfig.builder()
332 .providerConfig(AwsExternalKeyConfig.builder()
333333 .kmsArn("<key-arn-from-create-key-step>")
334334 .build())
335335 .build();
336 var externalKey = client.beta().organization().externalKeys().create(params);
336 var externalKey = client.organization().externalKeys().create(params);
337337
338338 IO.println("id: " + externalKey.id());
339339 IO.println("display_name: " + externalKey.displayName().orElseThrow());
from line 341
341341 ```
342342
343343 ```php PHP
344 use Anthropic\Beta\Organization\ExternalKeys\ExternalKeyCreateParams\Geo;
344 use Anthropic\Organization\ExternalKeys\ExternalKeyCreateParams\Geo;
345345 // ...
346346
347347 $client = new Client();
348348
349 $externalKey = $client->beta->organization->externalKeys->create(
349 $externalKey = $client->organization->externalKeys->create(
350350 displayName: '<friendly-name>',
351351 geo: Geo::US,
352352 providerConfig: [
from line 362
362362 ```ruby Ruby
363363 client = Anthropic::Client.new
364364
365 external_key = client.beta.organization.external_keys.create(
365 external_key = client.organization.external_keys.create(
366366 display_name: "<friendly-name>",
367367 geo: :us,
368368 provider_config: {
from line 398
398398 ```
399399
400400 ```bash CLI
401 ant beta:organization:external-keys validate --external-key-id "ekey_<id>"
401 ant organization:external-keys validate --external-key-id "ekey_<id>"
402402 ```
403403
404404 ```python Python
405405 client = anthropic.Anthropic()
406406
407 validation = client.beta.organization.external_keys.validate("ekey_<id>")
407 validation = client.organization.external_keys.validate("ekey_<id>")
408408
409409 print(f"status: {validation.status}")
410410 print(f"error: {validation.error}")
from line 413
413413 ```typescript TypeScript
414414 const client = new Anthropic();
415415
416 const validation = await client.beta.organization.externalKeys.validate("ekey_<id>");
416 const validation = await client.organization.externalKeys.validate("ekey_<id>");
417417
418418 console.log(`status: ${validation.status}`);
419419 console.log(`error: ${validation.error}`);
from line 422
422422 ```csharp C#
423423 AnthropicClient client = new();
424424
425 var validation = await client.Beta.Organization.ExternalKeys.Validate("ekey_<id>");
425 var validation = await client.Organization.ExternalKeys.Validate("ekey_<id>");
426426
427427 Console.WriteLine($"status: {validation.Status.Raw()}");
428428 Console.WriteLine($"error: {validation.Error}");
from line 431
431431 ```go Go
432432 client := anthropic.NewClient()
433433
434 validation, err := client.Beta.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>")
434 validation, err := client.Organization.ExternalKeys.Validate(context.Background(), "ekey_<id>")
435435 if err != nil {
436436 log.Fatal(err)
437437 }
from line 443
443443 ```java Java
444444 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
445445
446 var validation = client.beta().organization().externalKeys().validate("ekey_<id>");
446 var validation = client.organization().externalKeys().validate("ekey_<id>");
447447
448448 IO.println("status: " + validation.status().asString());
449449 IO.println("error: " + validation.error().orElse(""));
from line 452
452452 ```php PHP
453453 $client = new Client();
454454
455 $validation = $client->beta->organization->externalKeys->validate(
455 $validation = $client->organization->externalKeys->validate(
456456 externalKeyID: 'ekey_<id>',
457457 );
458458
from line 464
464464 client = Anthropic::Client.new
465465
466466 external_key_id = "ekey_<id>"
467 validation = client.beta.organization.external_keys.validate(external_key_id)
467 validation = client.organization.external_keys.validate(external_key_id)
468468
469469 puts "status: #{validation.status}"
470470 puts "error: #{validation.error}"
from line 500
500500 ```
501501
502502 ```bash CLI
503 ant beta:organization:workspaces update \
503 ant organization:workspaces update \
504504 --workspace-id "<workspace-id>" \
505505 --external-key-id "ekey_<id>"
506506 ```
from line 508
508508 ```python Python
509509 client = anthropic.Anthropic()
510510
511 workspace = client.beta.organization.workspaces.update(
511 workspace = client.organization.workspaces.update(
512512 "<workspace-id>", external_key_id="ekey_<id>"
513513 )
514514
from line 519
519519 ```typescript TypeScript
520520 const client = new Anthropic();
521521
522 const workspace = await client.beta.organization.workspaces.update("<workspace-id>", {
522 const workspace = await client.organization.workspaces.update("<workspace-id>", {
523523 external_key_id: "ekey_<id>"
524524 });
525525
from line 530
530530 ```csharp C#
531531 AnthropicClient client = new();
532532
533 var workspace = await client.Beta.Organization.Workspaces.Update("<workspace-id>", new()
533 var workspace = await client.Organization.Workspaces.Update("<workspace-id>", new()
534534 {
535535 ExternalKeyID = "ekey_<id>"
536536 });
from line 542
542542 ```go Go
543543 client := anthropic.NewClient()
544544
545 workspace, err := client.Beta.Organization.Workspaces.Update(
545 workspace, err := client.Organization.Workspaces.Update(
546546 context.Background(),
547547 "<workspace-id>",
548 anthropic.BetaOrganizationWorkspaceUpdateParams{
548 anthropic.OrganizationWorkspaceUpdateParams{
549549 ExternalKeyID: anthropic.String("ekey_<id>"),
550550 },
551551 )
from line 558
558558 ```
559559
560560 ```java Java
561 import com.anthropic.models.beta.organization.workspaces.WorkspaceUpdateParams;
561 import com.anthropic.models.organization.workspaces.WorkspaceUpdateParams;
562562
563563 void main() {
564564 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 566
566566 var params = WorkspaceUpdateParams.builder()
567567 .externalKeyId("ekey_<id>")
568568 .build();
569 var workspace = client.beta().organization().workspaces().update("<workspace-id>", params);
569 var workspace = client.organization().workspaces().update("<workspace-id>", params);
570570
571571 IO.println("id: " + workspace.id());
572572 IO.println("external_key_id: " + workspace.externalKeyId().orElseThrow());
from line 576
576576 ```php PHP
577577 $client = new Client();
578578
579 $workspace = $client->beta->organization->workspaces->update(
579 $workspace = $client->organization->workspaces->update(
580580 workspaceID: '<workspace-id>',
581581 externalKeyID: 'ekey_<id>',
582582 );
from line 589
589589 client = Anthropic::Client.new
590590
591591 workspace_id = "<workspace-id>"
592 workspace = client.beta.organization.workspaces.update(
592 workspace = client.organization.workspaces.update(
593593 workspace_id,
594594 external_key_id: "ekey_<id>"
595595 )
from line 638
638638
639639The key policy has three statements: your account's root admin statement; a statement that lets the Claude Platform on AWS service principal encrypt, decrypt, and generate data keys; and a separate statement for `kms:DescribeKey`. The crypto statement carries an optional `EncryptionContext` condition that binds the key to the workspaces you list. `DescribeKey` is granted separately because it has no `EncryptionContext` parameter, so an `EncryptionContext` condition on that action would always deny.
640640
641If you plan to use the optional `EncryptionContext` condition shown here, create the workspace first (without a key), copy its compartment ID, and substitute it for `<compartment-uuid>`. To find the ID in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read it from the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/beta/organization/workspaces/retrieve) endpoint. If you don't plan to use the condition, delete the `Condition` block from that statement.
641If you plan to use the optional `EncryptionContext` condition shown here, create the workspace first (without a key), copy its compartment ID, and substitute it for `<compartment-uuid>`. To find the ID in the Claude Console, go to [Manage > Security](https://platform.claude.com/settings/workspaces/default/security-compliance) and select the workspace in the workspace picker at the top of the sidebar. The ID is under **Encryption key**, in the **Compartment ID** field. You can also read it from the `compartment_id` field returned by the [Get Workspace](https://platform.claude.com/docs/en/api/organization/workspaces/retrieve) endpoint. If you don't plan to use the condition, delete the `Condition` block from that statement.
642642
643643```bash
644644export YOUR_ACCOUNT=$(aws sts get-caller-identity --query Account --output text)
No line in this hunk matches that.