Organizations
api/compliance/organizations
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/compliance/organizations Changed · +144 / -545 lines
### Query parameters ### Headers #### Response (200) ## Domain types ## Organizations › Users ### List organization users #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ## Organizations › Roles ### List Compliance Roles #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Get Compliance Role #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ## Organizations › Roles › Permissions ### List Compliance Role Permissions #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ## Organizations › Settings ### Get effective organization settings #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Query Parameters ### Header Parameters #### Response ## Domain Types # Users ## List organization users ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Domain Types ### User List Response # Roles ## List Compliance Roles ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Get Compliance Role ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Role List Response ### Role Retrieve Response # Permissions ## List Compliance Role Permissions ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Domain Types ### Permission List Response # Settings ## Get effective organization settings ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Setting Retrieve Response
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
---- -title: Organizations -url: https://platform.claude.com/docs/en/api/compliance/organizations ---- - # Organizations ## List organizations -**get** `/v1/compliance/organizations` +**GET** `/v1/compliance/organizations` List organizations under the parent organization.
`limit` and `page` to paginate: each response includes `has_more` and a `next_page` token to pass on the next request. -### Query Parameters +### Query parameters - `limit: optional number` Maximum results (default: 1000, max: 1000) + default: 1000, maximum: 1000, minimum: 1 + - `page: optional string` Opaque pagination token from a previous response's `next_page` field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice. -### Header Parameters +### Headers - `"x-api-key": optional string` ### Returns -- `data: array of object { created_at, name, uuid }` +- `data: array of object` List of organizations sorted by creation date, ascending
### Example -```http +```bash curl https://api.anthropic.com/v1/compliance/organizations \ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Organization List Response -- `OrganizationListResponse object { created_at, name, uuid }` +- `OrganizationListResponse object` Information about an organization.
Unique identifier for the organization (UUID format) -# Users - -## List organization users - -**get** `/v1/compliance/organizations/{org_uuid}/users` +## Organizations › Users + +### List organization users + +**GET** `/v1/compliance/organizations/{org_uuid}/users` List current user members of an organization. -### Path Parameters +#### Path parameters - `org_uuid: string` The organization UUID -### Query Parameters +#### Query parameters - `limit: optional number` Maximum results (default: 500, max: 1000) + default: 500, maximum: 1000, minimum: 1 + - `page: optional string` Opaque pagination token from a previous response's `next_page` field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice. -### Header Parameters +#### Headers - `"x-api-key": optional string` -### Returns - -- `data: array of object { id, created_at, email, 2 more }` +#### Returns + +- `data: array of object` List of current organization members sorted by organization join date ascending
User account creation timestamp + format: date-time + - `email: string` User's current email address
Token to retrieve the next page. Use this as the 'page' parameter in your next request -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/compliance/organizations/$ORG_UUID/users \ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Domain Types - -### User List Response - -- `UserListResponse object { id, created_at, email, 2 more }` - - User member information for compliance responses. +## Organizations › Roles + +### List Compliance Roles + +**GET** `/v1/compliance/organizations/{org_uuid}/roles` + +List Compliance Roles + +#### Path parameters + +- `org_uuid: string` + + The organization UUID + +#### Query parameters + +- `limit: optional number` + + Maximum results (default: 500, max: 1000) + + default: 500, maximum: 1000, minimum: 1 + +- `page: optional string` + + Opaque pagination token from a previous response's `next_page` field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice. + +#### Headers + +- `"x-api-key": optional string` + +#### Returns + +- `data: array of object` + + List of roles - `id: string` - User identifier (tagged ID) - - - `created_at: string` - - User account creation timestamp - - - `email: string` - - User's current email address - - - `full_name: string` - - User's current full name - - - `organization_role: "admin" or "billing" or "claude_code_user" or 6 more` - - User's built-in role within the organization. This is distinct from any custom RBAC roles that may also be assigned. - - - `"admin"` - - - `"billing"` - - - `"claude_code_user"` - - - `"developer"` - - - `"managed"` - - - `"membership_admin"` - - - `"owner"` - - - `"primary_owner"` - - - `"user"` - -# Roles - -## List Compliance Roles - -**get** `/v1/compliance/organizations/{org_uuid}/roles` - -List Compliance Roles - -### Path Parameters - -- `org_uuid: string` - - The organization UUID - -### Query Parameters - -- `limit: optional number` - - Maximum results (default: 500, max: 1000) - -- `page: optional string` - - Opaque pagination token from a previous response's `next_page` field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice. - -### Header Parameters - -- `"x-api-key": optional string` - -### Returns - -- `data: array of object { id, created_at, description, 2 more }` - - List of roles - - - `id: string` - Role identifier (tagged ID) - `created_at: string or null`
Token to retrieve the next page. Use this as the 'page' parameter in your next request -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/compliance/organizations/$ORG_UUID/roles \ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Get Compliance Role - -**get** `/v1/compliance/organizations/{org_uuid}/roles/{role_id}` +### Get Compliance Role + +**GET** `/v1/compliance/organizations/{org_uuid}/roles/{role_id}` Get Compliance Role -### Path Parameters +#### Path parameters - `org_uuid: string`
The role ID (tagged ID, e.g., rbac_role_abc123) -### Header Parameters +#### Headers - `"x-api-key": optional string` -### Returns +#### Returns - `id: string`
Role last-updated timestamp (ISO 8601) -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/compliance/organizations/$ORG_UUID/roles/$ROLE_ID \ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Domain Types - -### Role List Response - -- `RoleListResponse object { id, created_at, description, 2 more }` - - Role information for compliance responses. - - - `id: string` - - Role identifier (tagged ID) - - - `created_at: string or null` - - Role creation timestamp (ISO 8601) - - - `description: string` - - Role description - - - `name: string` - - Role name - - - `updated_at: string or null` - - Role last-updated timestamp (ISO 8601) - -### Role Retrieve Response - -- `RoleRetrieveResponse object { id, created_at, description, 2 more }` - - Role information for compliance responses. - - - `id: string` - - Role identifier (tagged ID) - - - `created_at: string or null` - - Role creation timestamp (ISO 8601) - - - `description: string` - - Role description - - - `name: string` - - Role name - - - `updated_at: string or null` - - Role last-updated timestamp (ISO 8601) - -# Permissions - -## List Compliance Role Permissions - -**get** `/v1/compliance/organizations/{org_uuid}/roles/{role_id}/permissions` +## Organizations › Roles › Permissions + +### List Compliance Role Permissions + +**GET** `/v1/compliance/organizations/{org_uuid}/roles/{role_id}/permissions` List Compliance Role Permissions -### Path Parameters +#### Path parameters - `org_uuid: string`
The role ID (tagged ID, e.g., rbac_role_abc123) -### Query Parameters +#### Query parameters - `limit: optional number` Maximum results (default: 500, max: 1000) + default: 500, maximum: 1000, minimum: 1 + - `page: optional string` Opaque pagination token from a previous response's `next_page` field. Pass this to retrieve the next page of results. Clients should treat this value as an opaque string and not attempt to parse or interpret its contents, as the format may change without notice. -### Header Parameters +#### Headers - `"x-api-key": optional string` -### Returns - -- `data: array of object { action, resource_id, resource_type }` +#### Returns + +- `data: array of object` List of permissions
Token to retrieve the next page. Use this as the 'page' parameter in your next request -### Example - -```http +#### Example + +```bash curl https://api.anthropic.com/v1/compliance/organizations/$ORG_UUID/roles/$ROLE_ID/permissions \ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY" ``` -#### Response +##### Response (200) ```json {
} ``` -## Domain Types - -### Permission List Response - -- `PermissionListResponse object { action, resource_id, resource_type }` - - Permission granted by a role. - - - `action: string` - - Action permitted on the resource - - - `resource_id: string` - - Identifier of the resource the permission applies to - - - `resource_type: string` - - Type of resource the permission applies to - -# Settings - -## Get effective organization settings - -**get** `/v1/compliance/organizations/{organization_id}/settings` +## Organizations › Settings + +### Get effective organization settings + +**GET** `/v1/compliance/organizations/{organization_id}/settings` Retrieve the effective settings for an organization.
The organization must belong to the API key's organization hierarchy; unknown organizations and organizations outside the hierarchy return 404. -### Path Parameters +#### Path parameters - `organization_id: string` The organization's UUID -### Header Parameters +#### Headers - `"x-api-key": optional string` -### Returns - -- `api_keys: array of object { id, created_at, created_by_id, 5 more }` +#### Returns + +- `api_keys: array of object` Compliance API keys configured for the organization hierarchy, ordered by creation time ascending. Key secret values are never included.
When the key was created. + format: date-time + - `created_by_id: string or null` Identifier of the user who created the key, or null when the key was created by automation or its creator's account no longer exists.
When the key will stop authenticating, or null when the key does not expire. + format: date-time + - `type: optional "compliance_api_key"` - - `"compliance_api_key"` + default: compliance_api_key - `organization_id: string` -- `settings: array of object { name, value, type } or object { name, value, type } or object { name, value, type } or 3 more` - - - `Boolean object { name, value, type }` +- `settings: array of object or object or object or 3 more` + + - `Boolean object` A setting whose enforced value is a single true/false flag.
- `type: optional "boolean"` - - `"boolean"` - - - `Integer object { name, value, type }` + default: boolean + + - `Integer object` A setting whose enforced value is a whole number; null means no limit is in force. - `name: "account_session_duration_seconds"` - - `"account_session_duration_seconds"` - - `value: number or null` - `type: optional "integer"` - - `"integer"` - - - `String object { name, value, type }` + default: integer + + - `String object` A setting whose enforced value is a single string; null means no value is configured.
- `type: optional "string"` - - `"string"` - - - `StringList object { name, value, type }` + default: string + + - `StringList object` A setting whose enforced value is a list of strings.
- `type: optional "string_list"` - - `"string_list"` - - - `ProvisioningMode object { value, name, type }` + default: string_list + + - `ProvisioningMode object` How organization members are provisioned, resolved to the enforced mode.
- `name: optional "sso_provisioning_mode"` - - `"sso_provisioning_mode"` + default: sso_provisioning_mode - `type: optional "provisioning_mode"` - - `"provisioning_mode"` - - - `DataRetention object { value, name, type }` + default: provisioning_mode + + - `DataRetention object` The data retention periods in force, keyed by the type of data they apply to.
administrator-configured retention period is in force for that data type; Anthropic's service defaults may still apply. - - `value: map[object { duration, timescale, type } or object { type } ]` - - - `Fixed object { duration, timescale, type }` + - `value: map[object or object]` + + - `Fixed object` A fixed retention window measured from each item's last activity.
- `type: optional "fixed"` - - `"fixed"` - - - `Indefinite object { type }` + default: fixed + + - `Indefinite object` An indefinite retention period: data is kept with no time limit. - `type: optional "indefinite"` - - `"indefinite"` + default: indefinite - `name: optional "data_retention_periods"` - - `"data_retention_periods"` + default: data_retention_periods - `type: optional "data_retention"` - - `"data_retention"` + default: data_retention - `type: optional "effective_organization_settings"` - - `"effective_organization_settings"` - -### Example - -```http + default: effective_organization_settings + +#### Example + +```bash curl https://api.anthropic.com/v1/compliance/organizations/$ORGANIZATION_ID/settings \ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY" ``` -#### Response +##### Response (200) ```json {
"type": "effective_organization_settings" } ``` - -## Domain Types - -### Setting Retrieve Response - -- `SettingRetrieveResponse object { api_keys, organization_id, settings, type }` - - The resolved settings in force for one organization at read time. - - Settings appear at most once each, in a fixed relative order, and values - reflect the enforced state. A setting the organization's administrators - cannot change — for example, one controlled by Anthropic policy or not - available to the organization — is omitted from the list. - - - `api_keys: array of object { id, created_at, created_by_id, 5 more }` - - Compliance API keys configured for the organization hierarchy, ordered by creation time ascending. Key secret values are never included. - - - `id: string` - - Unique identifier for the API key. - - - `created_at: string` - - When the key was created. - - - `created_by_id: string or null` - - Identifier of the user who created the key, or null when the key was created by automation or its creator's account no longer exists. - - - `is_active: boolean` - - Whether the key is currently active. A deactivated key is listed for audit visibility but cannot authenticate requests. - - - `name: string` - - The name given to the API key when it was created. - - - `scopes: array of string` - - The permission scopes granted to the key. - - - `expires_at: optional string or null` - - When the key will stop authenticating, or null when the key does not expire. - - - `type: optional "compliance_api_key"` - - - `"compliance_api_key"` - - - `organization_id: string` - - - `settings: array of object { name, value, type } or object { name, value, type } or object { name, value, type } or 3 more` - - - `Boolean object { name, value, type }` - - A setting whose enforced value is a single true/false flag. - - - `name: "ai_powered_artifacts_enabled" or "api_workbench_feedback_collection_enabled" or "artifact_connectors_enabled" or 44 more` - - - `"ai_powered_artifacts_enabled"` - - - `"api_workbench_feedback_collection_enabled"` - - - `"artifact_connectors_enabled"` - - - `"ask_your_org_enabled"` - - - `"chat_enabled"` - - - `"claude_ai_chat_sharing_enabled"` - - - `"claude_ai_feedback_collection_enabled"` - - - `"claude_ai_integration_sharing_enabled"` - - - `"claude_code_desktop_bypass_permissions_enabled"` - - - `"claude_code_desktop_enabled"` - - - `"claude_code_fast_mode_enabled"` - - - `"claude_code_metrics_logging_enabled"` - - - `"claude_code_remote_control_enabled"` - - - `"claude_code_review_enabled"` - - - `"claude_code_routines_enabled"` - - - `"claude_code_security_enabled"` - - - `"claude_code_trusted_devices_required"` - - - `"claude_code_web_enabled"` - - - `"claude_code_workflows_enabled"` - - - `"claude_design_enabled"` - - - `"claude_in_slack_enabled"` - - - `"code_execution_enabled"` - - - `"code_execution_network_egress_enabled"` - - - `"connector_tools_default_always_allow"` - - - `"content_redaction_enabled"` - - - `"cowork_trusted_devices_required"` - - - `"desktop_extension_allowlist_enabled"` - - - `"directory_sync_enabled"` - - - `"frontier_data_use_enabled"` - - - `"group_skill_sharing_enabled"` - - - `"hipaa_compliance_enabled"` - - - `"inline_visualizations_enabled"` - - - `"ip_allowlist_enabled"` - - - `"location_metadata_enabled"` - - - `"member_usage_dashboard_visible"` - - - `"memory_enabled"` - - - `"org_wide_skill_sharing_enabled"` - - - `"public_projects_enabled"` - - - `"skill_sharing_enabled"` - - - `"skills_enabled"` - - - `"sso_claude_ai_enforced"` - - - `"sso_console_enforced"` - - - `"sso_enabled"` - - - `"third_party_interactive_content_enabled"` - - - `"user_skill_creation_enabled"` - - - `"web_search_enabled"` - - - `"work_across_apps_enabled"` - - - `value: boolean` - - - `type: optional "boolean"` - - - `"boolean"` - - - `Integer object { name, value, type }` - - A setting whose enforced value is a whole number; null means no limit - is in force. - - - `name: "account_session_duration_seconds"` - - - `"account_session_duration_seconds"` - - - `value: number or null` - - - `type: optional "integer"` - - - `"integer"` - - - `String object { name, value, type }` - - A setting whose enforced value is a single string; null means no value - is configured. - - - `name: "claude_code_default_worker_environment_id" or "claude_code_default_worker_pool_id"` - - - `"claude_code_default_worker_environment_id"` - - - `"claude_code_default_worker_pool_id"` - - - `value: string or null` - - - `type: optional "string"` - - - `"string"` - - - `StringList object { name, value, type }` - - A setting whose enforced value is a list of strings. - - - `name: "allowed_invite_domains" or "disabled_admin_request_types" or "ip_allowlist_ip_ranges"` - - - `"allowed_invite_domains"` - - - `"disabled_admin_request_types"` - - - `"ip_allowlist_ip_ranges"` - - - `value: array of string` - - - `type: optional "string_list"` - - - `"string_list"` - - - `ProvisioningMode object { value, name, type }` - - How organization members are provisioned, resolved to the enforced mode. - - A configured mode is reported only while the mechanism that enforces it is - active: just-in-time modes require single sign-on to be enabled, and SCIM - modes require directory sync to be enabled. Otherwise `login_only` is - reported, regardless of any stored configuration. - - - `value: "jit_advanced" or "jit_permissive" or "login_only" or 2 more` - - How organization members are provisioned under SSO. - - - `"jit_advanced"` - - - `"jit_permissive"` - - - `"login_only"` - - - `"scim_advanced"` - - - `"scim_permissive"` - - - `name: optional "sso_provisioning_mode"` - - - `"sso_provisioning_mode"` - - - `type: optional "provisioning_mode"` - - - `"provisioning_mode"` - - - `DataRetention object { value, name, type }` - - The data retention periods in force, keyed by the type of data they - apply to. - - A key of `all` covers every data type and is exclusive: when present it - is the only key. A missing key means no organization-level - administrator-configured retention period is in force for that data type; - Anthropic's service defaults may still apply. - - - `value: map[object { duration, timescale, type } or object { type } ]` - - - `Fixed object { duration, timescale, type }` - - A fixed retention window measured from each item's last activity. - - - `duration: number` - - - `timescale: "day" or "month"` - - - `"day"` - - - `"month"` - - - `type: optional "fixed"` - - - `"fixed"` - - - `Indefinite object { type }` - - An indefinite retention period: data is kept with no time limit. - - - `type: optional "indefinite"` - - - `"indefinite"` - - - `name: optional "data_retention_periods"` - - - `"data_retention_periods"` - - - `type: optional "data_retention"` - - - `"data_retention"` - - - `type: optional "effective_organization_settings"` - - - `"effective_organization_settings"`