admin-api changedmanage-claude/admin-api
Nearest release: v2.1.247, published under an hour before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+1,609added
Lines−140removed
From line
8
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits7to this page, all time
The whole hunk
from line 8, old and new numbered
/
The two sides of this change are more than 400 edits apart, too far apart to line up, so this is the differ's own diff of it and the words inside a line are not marked.
from line 8
88 **The Admin API is unavailable for individual accounts.** To collaborate with teammates and add members, set up your organization in **Console → Settings → Organization**.
99</Tip>
1010
11The [Admin API](https://platform.claude.com/docs/en/api/admin) allows you to programmatically manage your organization's resources, including organization members, workspaces, and API keys. This provides programmatic control over administrative tasks that would otherwise require manual configuration in the [Claude Console](https://platform.claude.com/).
11The [Admin API](https://platform.claude.com/docs/en/api/admin) lets you manage your organization's members, workspaces, invites, and API keys programmatically instead of by hand in the [Claude Console](https://platform.claude.com/).
1212
1313<Check>
1414 **The Admin API requires special access**
from line 20
2020</Check>
2121
2222<Note>
23 **Claude Enterprise:** Claude Enterprise (claude.ai) organizations use the Admin API too, with a scoped API key created in claude.ai. Of the endpoints on this page, only members and invites are available to them, alongside Claude-Enterprise-only endpoints: groups and custom-role reads, and [spend limits](https://platform.claude.com/docs/en/manage-claude/spend-limits-api). See [User management](https://platform.claude.com/docs/en/manage-claude/user-management) for Claude Enterprise.
23 **Claude Enterprise:** Claude Enterprise (claude.ai) organizations call the Admin API with a scoped API key created in claude.ai. From this page, only the members and invites endpoints apply to them. They also get Enterprise-only endpoints: group and custom-role reads, and [spend limits](https://platform.claude.com/docs/en/manage-claude/spend-limits-api). See [User management](https://platform.claude.com/docs/en/manage-claude/user-management).
2424</Note>
2525
2626<Note>
27 **Claude Platform on AWS:** Most of the Admin API is not available on Claude Platform on AWS. Workspace endpoints (create, get, list, update, and archive on `/v1/organizations/workspaces`) are available. Other endpoints including organization members, workspace members, invites, API keys, usage reports, cost reports, and rate limit reports are not available. See [Claude Platform on AWS](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws) for details.
27 **Claude Platform on AWS:** Only the workspace endpoints (create, get, list, update, and archive on `/v1/organizations/workspaces`) are available on Claude Platform on AWS. Organization members, workspace members, invites, API keys, and the usage, cost, and rate limit reports aren't. See [Claude Platform on AWS](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws).
2828</Note>
2929
3030## Authentication
3131
32Authenticate with either credential. An Admin API key covers most endpoints; the service-account, federation-issuer, and federation-rule endpoints accept only an `org:admin` OAuth token. The following examples call the [organization info endpoint](https://platform.claude.com/docs/en/manage-claude/admin-api#accessing-organization-info) both ways.
32Authenticate with either credential. An Admin API key covers most endpoints. The service-account, federation-issuer, and federation-rule endpoints accept only an `org:admin` OAuth token. The following examples call the [organization info endpoint](https://platform.claude.com/docs/en/manage-claude/admin-api#accessing-organization-info) both ways.
33
34The Python, TypeScript, C#, Go, Java, PHP, and Ruby SDKs expose the Admin API under `client.beta.organization`, and the `ant` CLI under `ant beta:organization`. The examples on this page use the default client, which reads an Admin API key from `ANTHROPIC_API_KEY` or an OAuth bearer token from `ANTHROPIC_AUTH_TOKEN`. SDK list methods in Python, TypeScript, C#, Go, and Java return an iterator that fetches more pages on demand, so `limit` sets the page size, not the total. The PHP, Ruby, and curl examples return one page. In the CLI, `--limit` caps the results on the member, invite, workspace, workspace-member, and API-key lists. For each endpoint's parameters and responses, see the [Admin API reference](https://platform.claude.com/docs/en/api/admin).
3335
3436### OAuth bearer token
3537
36Log in with the [`ant` CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart) under a dedicated profile, requesting the `org:admin` scope (see [Admin access](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication#admin-access)), then export the bearer token. A dedicated profile keeps your routine commands from running with elevated access:
38Log in with the [`ant` CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart) under a dedicated profile with the `org:admin` scope (see [Admin access](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication#admin-access)), then export the bearer token. `--profile admin` stores the `org:admin` credential under its own profile and makes it the CLI's active profile. The exported variable applies to every SDK and CLI call in that shell. Use a shell you reserve for administration, unset the variable when you're done, and switch the CLI back with `ant profile activate default`:
3739
3840```bash CLI
3941ant auth login --profile admin --scope "org:admin"
40export ANTHROPIC_OAUTH_TOKEN=$(ant auth print-credentials --profile admin --access-token)
42export ANTHROPIC_AUTH_TOKEN=$(ant auth print-credentials --profile admin --access-token)
4143```
4244
43Interactive tokens are short-lived; if requests start returning 401, re-run the `export` command, which refreshes the token automatically.
45Interactive tokens are short-lived. If requests start returning 401, re-run the `export` command to refresh the token.
46
47The SDKs and the `ant` CLI read `ANTHROPIC_AUTH_TOKEN` automatically. Leave `ANTHROPIC_API_KEY` unset in the same shell so they send the bearer token. Automated workloads skip the login: they authenticate through workload identity federation, and the SDKs and CLI perform the token exchange from the federation environment variables. See [Bootstrap a workload to manage WIF](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#bootstrap-a-workload-to-manage-wif).
4448
4549Call the Admin API with the exported token:
4650
47```bash cURL
48curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \
49 --header "anthropic-version: 2023-06-01" \
50 --header "authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
51```
51<CodeGroup>
52 ```bash cURL
53 curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \
54 -H "authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \
55 -H "anthropic-version: 2023-06-01"
56 ```
57
58 ```bash CLI
59 ant beta:organization retrieve
60 ```
61
62 ```python Python
63 client = anthropic.Anthropic()
64
65 organization = client.beta.organization.retrieve()
66
67 print(f"id: {organization.id}")
68 print(f"name: {organization.name}")
69 ```
70
71 ```typescript TypeScript
72 const client = new Anthropic();
73
74 const organization = await client.beta.organization.retrieve();
75
76 console.log(`id: ${organization.id}`);
77 console.log(`name: ${organization.name}`);
78 ```
79
80 ```csharp C#
81 AnthropicClient client = new();
82
83 var organization = await client.Beta.Organization.Retrieve();
84
85 Console.WriteLine($"id: {organization.ID}");
86 Console.WriteLine($"name: {organization.Name}");
87 ```
88
89 ```go Go
90 client := anthropic.NewClient()
91
92 organization, err := client.Beta.Organization.Get(context.Background())
93 if err != nil {
94 log.Fatal(err)
95 }
96
97 fmt.Printf("id: %s\n", organization.ID)
98 fmt.Printf("name: %s\n", organization.Name)
99 ```
100
101 ```java Java
102 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
103
104 var organization = client.beta().organization().retrieve();
105
106 IO.println("id: " + organization.id());
107 IO.println("name: " + organization.name());
108 ```
109
110 ```php PHP
111 $client = new Client();
112
113 $organization = $client->beta->organization->retrieve();
114
115 echo "id: {$organization->id}\n";
116 echo "name: {$organization->name}\n";
117 ```
118
119 ```ruby Ruby
120 client = Anthropic::Client.new
121
122 organization = client.beta.organization.retrieve
123
124 puts "id: #{organization.id}"
125 puts "name: #{organization.name}"
126 ```
127</CodeGroup>
52128
53129An `org:admin` token grants access to the whole organization, regardless of the workspace the underlying profile or [federation rule](https://platform.claude.com/docs/en/manage-claude/admin-api#federation-rules) is bound to.
54130
from line 134
58134
59135To create an Admin API key for your organization type, see [Create an Admin API key](https://platform.claude.com/docs/en/manage-claude/admin-api-keys).
60136
61```bash cURL
62curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \
63 --header "anthropic-version: 2023-06-01" \
64 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
65```
137<CodeGroup>
138 ```bash cURL
139 curl --fail-with-body -sS "https://api.anthropic.com/v1/organizations/me" \
140 -H "x-api-key: $ANTHROPIC_API_KEY" \
141 -H "anthropic-version: 2023-06-01"
142 ```
143
144 ```bash CLI
145 ant beta:organization retrieve
146 ```
147
148 ```python Python
149 client = anthropic.Anthropic()
150
151 organization = client.beta.organization.retrieve()
152
153 print(f"id: {organization.id}")
154 print(f"name: {organization.name}")
155 ```
156
157 ```typescript TypeScript
158 const client = new Anthropic();
159
160 const organization = await client.beta.organization.retrieve();
161
162 console.log(`id: ${organization.id}`);
163 console.log(`name: ${organization.name}`);
164 ```
165
166 ```csharp C#
167 AnthropicClient client = new();
168
169 var organization = await client.Beta.Organization.Retrieve();
170
171 Console.WriteLine($"id: {organization.ID}");
172 Console.WriteLine($"name: {organization.Name}");
173 ```
174
175 ```go Go
176 client := anthropic.NewClient()
177
178 organization, err := client.Beta.Organization.Get(context.Background())
179 if err != nil {
180 log.Fatal(err)
181 }
182
183 fmt.Printf("id: %s\n", organization.ID)
184 fmt.Printf("name: %s\n", organization.Name)
185 ```
186
187 ```java Java
188 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
189
190 var organization = client.beta().organization().retrieve();
191
192 IO.println("id: " + organization.id());
193 IO.println("name: " + organization.name());
194 ```
195
196 ```php PHP
197 $client = new Client();
198
199 $organization = $client->beta->organization->retrieve();
200
201 echo "id: {$organization->id}\n";
202 echo "name: {$organization->name}\n";
203 ```
204
205 ```ruby Ruby
206 client = Anthropic::Client.new
207
208 organization = client.beta.organization.retrieve
209
210 puts "id: #{organization.id}"
211 puts "name: #{organization.name}"
212 ```
213</CodeGroup>
66214
67215## How the Admin API works
68216
69When you use the Admin API:
70
711. You make requests using either credential from the [Authentication](https://platform.claude.com/docs/en/manage-claude/admin-api#authentication) section
72
732. The API allows you to manage:
74
75 * Organization members and their roles
76 * Organization member invites
77 * Workspaces and their members
78 * API keys
79 * Service accounts, federation issuers, and federation rules (these endpoints require an `org:admin` OAuth token; Admin API keys are not accepted)
80
81This is useful for:
82
83* Automating user onboarding/offboarding
84* Programmatically managing workspace access
85* Monitoring and managing API key usage
217Authenticate with either credential from [Authentication](https://platform.claude.com/docs/en/manage-claude/admin-api#authentication), then manage the following resources:
218
219* Organization members and their roles
220* Organization invites
221* Workspaces and their members
222* API keys
223* Service accounts, federation issuers, and federation rules (`org:admin` OAuth token only)
224
225Common uses include automating onboarding and offboarding, managing workspace access, and auditing API keys.
86226
87227## Organization roles and permissions
88228
89There are five organization-level roles. See more details in the [API Console roles and permissions](https://support.claude.com/en/articles/10186004-api-console-roles-and-permissions) article.
229There are five organization-level roles. For details, see [API Console roles and permissions](https://support.claude.com/en/articles/10186004-api-console-roles-and-permissions).
90230
91231| Role | Permissions |
92232| ------------------ | ------------------------------------------------------------------------------ |
from line 236
96236| billing | Can use playground and manage billing details |
97237| admin | Can do all of the preceding, plus manage users |
98238
99Organization owners and primary owners have all admin permissions and can additionally manage admins. All references to the admin role on this page also apply to owners and primary owners.
239Organization owners and primary owners have all admin permissions and can also manage admins. All references to the admin role on this page also apply to owners and primary owners.
100240
101241## Key concepts
102242
103243### Organization members
104244
105You can list [organization members](https://platform.claude.com/docs/en/api/admin-api/users/get-user), update member roles, and remove members.
245List [organization members](https://platform.claude.com/docs/en/api/admin-api/users/get-user), update their roles, and remove them.
246
247List the members of your organization:
106248
107249<CodeGroup>
108250 ```bash cURL
109 # List organization members
110251 curl "https://api.anthropic.com/v1/organizations/users?limit=10" \
111 --header "anthropic-version: 2023-06-01" \
112 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
113
114 # Update member role
115 curl "https://api.anthropic.com/v1/organizations/users/{user_id}" \
116 --header "anthropic-version: 2023-06-01" \
117 --header "content-type: application/json" \
118 --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \
119 --data '{"role": "developer"}'
120
121 # Remove member
122 curl --request DELETE "https://api.anthropic.com/v1/organizations/users/{user_id}" \
123 --header "anthropic-version: 2023-06-01" \
124 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
252 -H "x-api-key: $ANTHROPIC_API_KEY" \
253 -H "anthropic-version: 2023-06-01"
254 ```
255
256 ```bash CLI
257 ant beta:organization:users list --limit 10
258 ```
259
260 ```python Python
261 client = anthropic.Anthropic()
262
263 users = client.beta.organization.users.list(limit=10)
264
265 # Automatically fetches more pages as needed.
266 for user in users:
267 print(f"{user.id}: {user.email} ({user.role})")
268 ```
269
270 ```typescript TypeScript
271 const client = new Anthropic();
272
273 const users = await client.beta.organization.users.list({ limit: 10 });
274
275 for await (const user of users) {
276 console.log(`${user.id}: ${user.email} (${user.role})`);
277 }
278 ```
279
280 ```csharp C#
281 AnthropicClient client = new();
282
283 var page = await client.Beta.Organization.Users.List(new() { Limit = 10 });
284
285 await foreach (var user in page.Paginate())
286 {
287 Console.WriteLine($"{user.ID}: {user.Email} ({user.Role.Raw()})");
288 }
289 ```
290
291 ```go Go
292 client := anthropic.NewClient()
293
294 users := client.Beta.Organization.Users.ListAutoPaging(context.Background(), anthropic.BetaOrganizationUserListParams{
295 Limit: anthropic.Int(10),
296 })
297
298 for users.Next() {
299 user := users.Current()
300 fmt.Printf("%s: %s (%s)\n", user.ID, user.Email, user.Role)
301 }
302 if err := users.Err(); err != nil {
303 log.Fatal(err)
304 }
305 ```
306
307 ```java Java
308 import com.anthropic.models.beta.organization.users.UserListParams;
309
310 void main() {
311 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
312
313 var params = UserListParams.builder()
314 .limit(10)
315 .build();
316 var users = client.beta().organization().users().list(params);
317
318 for (var user : users.autoPager()) {
319 IO.println(user.id() + ": " + user.email() + " (" + user.role().asString() + ")");
320 }
321 }
322 ```
323
324 ```php PHP
325 $client = new Client();
326
327 $users = $client->beta->organization->users->list(limit: 10);
328
329 foreach ($users->getItems() as $user) {
330 echo "{$user->id}: {$user->email} ({$user->role})\n";
331 }
332 ```
333
334 ```ruby Ruby
335 client = Anthropic::Client.new
336
337 users = client.beta.organization.users.list(limit: 10)
338
339 users.data.each do |user|
340 puts "#{user.id}: #{user.email} (#{user.role})"
341 end
125342 ```
126343</CodeGroup>
127344
128### Organization invites
129
130You can invite users to organizations and manage those [invites](https://platform.claude.com/docs/en/api/admin-api/invites/get-invite).
345Update a member's role:
131346
132347<CodeGroup>
133348 ```bash cURL
134 # Create invite
135 curl --request POST "https://api.anthropic.com/v1/organizations/invites" \
136 --header "anthropic-version: 2023-06-01" \
137 --header "content-type: application/json" \
138 --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \
139 --data '{
140 "email": "[email protected]",
349 curl "https://api.anthropic.com/v1/organizations/users/user_01XyDMpzjS89pFZXqSFUBDr6" \
350 -H "x-api-key: $ANTHROPIC_API_KEY" \
351 -H "anthropic-version: 2023-06-01" \
352 -H "content-type: application/json" \
353 -d '{"role": "developer"}'
354 ```
355
356 ```bash CLI
357 ant beta:organization:users update \
358 --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \
359 --role developer
360 ```
361
362 ```python Python
363 client = anthropic.Anthropic()
364
365 user = client.beta.organization.users.update(
366 "user_01XyDMpzjS89pFZXqSFUBDr6", role="developer"
367 )
368
369 print(f"id: {user.id}")
370 print(f"role: {user.role}")
371 ```
372
373 ```typescript TypeScript
374 const client = new Anthropic();
375
376 const user = await client.beta.organization.users.update("user_01XyDMpzjS89pFZXqSFUBDr6", {
377 role: "developer"
378 });
379
380 console.log(`id: ${user.id}`);
381 console.log(`role: ${user.role}`);
382 ```
383
384 ```csharp C#
385 using Anthropic.Models.Beta.Organization.Users;
386 // ...
387
388 AnthropicClient client = new();
389
390 var user = await client.Beta.Organization.Users.Update(
391 "user_01XyDMpzjS89pFZXqSFUBDr6",
392 new() { Role = Role.Developer }
393 );
394
395 Console.WriteLine($"id: {user.ID}");
396 Console.WriteLine($"role: {user.Role.Raw()}");
397 ```
398
399 ```go Go
400 client := anthropic.NewClient()
401
402 user, err := client.Beta.Organization.Users.Update(
403 context.Background(),
404 "user_01XyDMpzjS89pFZXqSFUBDr6",
405 anthropic.BetaOrganizationUserUpdateParams{
406 Role: anthropic.BetaOrganizationUserUpdateParamsRoleDeveloper,
407 },
408 )
409 if err != nil {
410 log.Fatal(err)
411 }
412
413 fmt.Printf("id: %s\n", user.ID)
414 fmt.Printf("role: %s\n", user.Role)
415 ```
416
417 ```java Java
418 import com.anthropic.models.beta.organization.users.UserUpdateParams;
419
420 void main() {
421 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
422
423 var params = UserUpdateParams.builder()
424 .role(UserUpdateParams.Role.DEVELOPER)
425 .build();
426 var user = client.beta().organization().users()
427 .update("user_01XyDMpzjS89pFZXqSFUBDr6", params);
428
429 IO.println("id: " + user.id());
430 IO.println("role: " + user.role().asString());
431 }
432 ```
433
434 ```php PHP
435 use Anthropic\Beta\Organization\Users\UserUpdateParams\Role;
436 // ...
437
438 $client = new Client();
439
440 $user = $client->beta->organization->users->update(
441 userID: 'user_01XyDMpzjS89pFZXqSFUBDr6',
442 role: Role::DEVELOPER,
443 );
444
445 echo "id: {$user->id}\n";
446 echo "role: {$user->role}\n";
447 ```
448
449 ```ruby Ruby
450 client = Anthropic::Client.new
451
452 user_id = "user_01XyDMpzjS89pFZXqSFUBDr6"
453 user = client.beta.organization.users.update(user_id, role: :developer)
454
455 puts "id: #{user.id}"
456 puts "role: #{user.role}"
457 ```
458</CodeGroup>
459
460Remove a member from the organization:
461
462<CodeGroup>
463 ```bash cURL
464 curl -X DELETE "https://api.anthropic.com/v1/organizations/users/user_01XyDMpzjS89pFZXqSFUBDr6" \
465 -H "x-api-key: $ANTHROPIC_API_KEY" \
466 -H "anthropic-version: 2023-06-01"
467 ```
468
469 ```bash CLI
470 ant beta:organization:users remove --user-id user_01XyDMpzjS89pFZXqSFUBDr6
471 ```
472
473 ```python Python
474 client = anthropic.Anthropic()
475
476 removed_user = client.beta.organization.users.remove("user_01XyDMpzjS89pFZXqSFUBDr6")
477
478 print(f"id: {removed_user.id}")
479 ```
480
481 ```typescript TypeScript
482 const client = new Anthropic();
483
484 const removedUser = await client.beta.organization.users.remove(
485 "user_01XyDMpzjS89pFZXqSFUBDr6"
486 );
487
488 console.log(`id: ${removedUser.id}`);
489 ```
490
491 ```csharp C#
492 AnthropicClient client = new();
493
494 var removedUser = await client.Beta.Organization.Users.Remove("user_01XyDMpzjS89pFZXqSFUBDr6");
495
496 Console.WriteLine($"id: {removedUser.ID}");
497 ```
498
499 ```go Go
500 client := anthropic.NewClient()
501
502 removedUser, err := client.Beta.Organization.Users.Remove(context.Background(), "user_01XyDMpzjS89pFZXqSFUBDr6")
503 if err != nil {
504 log.Fatal(err)
505 }
506
507 fmt.Printf("id: %s\n", removedUser.ID)
508 ```
509
510 ```java Java
511 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
512
513 var removedUser = client.beta().organization().users()
514 .remove("user_01XyDMpzjS89pFZXqSFUBDr6");
515
516 IO.println("id: " + removedUser.id());
517 ```
518
519 ```php PHP
520 $client = new Client();
521
522 $removedUser = $client->beta->organization->users->remove(
523 userID: 'user_01XyDMpzjS89pFZXqSFUBDr6',
524 );
525
526 echo "id: {$removedUser->id}\n";
527 ```
528
529 ```ruby Ruby
530 client = Anthropic::Client.new
531
532 user_id = "user_01XyDMpzjS89pFZXqSFUBDr6"
533 removed_user = client.beta.organization.users.remove(user_id)
534
535 puts "id: #{removed_user.id}"
536 ```
537</CodeGroup>
538
539### Organization invites
540
541Invite users to your organization and manage pending [invites](https://platform.claude.com/docs/en/api/admin-api/invites/get-invite).
542
543Invite a user to your organization:
544
545<CodeGroup>
546 ```bash cURL
547 curl "https://api.anthropic.com/v1/organizations/invites" \
548 -H "x-api-key: $ANTHROPIC_API_KEY" \
549 -H "anthropic-version: 2023-06-01" \
550 -H "content-type: application/json" \
551 -d '{
552 "email": "[email protected]",
141553 "role": "developer"
142554 }'
143
144 # List invites
145 curl "https://api.anthropic.com/v1/organizations/invites?limit=10" \
146 --header "anthropic-version: 2023-06-01" \
147 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
148
149 # Delete invite
150 curl --request DELETE "https://api.anthropic.com/v1/organizations/invites/{invite_id}" \
151 --header "anthropic-version: 2023-06-01" \
152 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
555 ```
556
557 ```bash CLI
558 ant beta:organization:invites create --email [email protected] --role developer
559 ```
560
561 ```python Python
562 client = anthropic.Anthropic()
563
564 invite = client.beta.organization.invites.create(
565 email="[email protected]", role="developer"
566 )
567
568 print(f"id: {invite.id}")
569 print(f"email: {invite.email}")
570 print(f"status: {invite.status}")
571 print(f"expires_at: {invite.expires_at}")
572 ```
573
574 ```typescript TypeScript
575 const client = new Anthropic();
576
577 const invite = await client.beta.organization.invites.create({
578 email: "[email protected]",
579 role: "developer"
580 });
581
582 console.log(`id: ${invite.id}`);
583 console.log(`email: ${invite.email}`);
584 console.log(`status: ${invite.status}`);
585 console.log(`expires_at: ${invite.expires_at}`);
586 ```
587
588 ```csharp C#
589 using Anthropic.Models.Beta.Organization.Invites;
590 // ...
591
592 AnthropicClient client = new();
593
594 var invite = await client.Beta.Organization.Invites.Create(new()
595 {
596 Email = "[email protected]",
597 Role = Role.Developer
598 });
599
600 Console.WriteLine($"id: {invite.ID}");
601 Console.WriteLine($"email: {invite.Email}");
602 Console.WriteLine($"status: {invite.Status.Raw()}");
603 Console.WriteLine($"expires_at: {invite.ExpiresAt:O}");
604 ```
605
606 ```go Go
607 client := anthropic.NewClient()
608
609 invite, err := client.Beta.Organization.Invites.New(context.Background(), anthropic.BetaOrganizationInviteNewParams{
610 Email: "[email protected]",
611 Role: anthropic.BetaOrganizationInviteNewParamsRoleDeveloper,
612 })
613 if err != nil {
614 log.Fatal(err)
615 }
616
617 fmt.Printf("id: %s\n", invite.ID)
618 fmt.Printf("email: %s\n", invite.Email)
619 fmt.Printf("status: %s\n", invite.Status)
620 fmt.Printf("expires_at: %s\n", invite.ExpiresAt.Format(time.RFC3339))
621 ```
622
623 ```java Java
624 import com.anthropic.models.beta.organization.invites.InviteCreateParams;
625
626 void main() {
627 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
628
629 var params = InviteCreateParams.builder()
630 .email("[email protected]")
631 .role(InviteCreateParams.Role.DEVELOPER)
632 .build();
633 var invite = client.beta().organization().invites().create(params);
634
635 IO.println("id: " + invite.id());
636 IO.println("email: " + invite.email());
637 IO.println("status: " + invite.status().asString());
638 IO.println("expires_at: " + invite.expiresAt());
639 }
640 ```
641
642 ```php PHP
643 use Anthropic\Beta\Organization\Invites\InviteCreateParams\Role;
644 // ...
645
646 $client = new Client();
647
648 $invite = $client->beta->organization->invites->create(
649 email: '[email protected]',
650 role: Role::DEVELOPER,
651 );
652
653 echo "id: {$invite->id}\n";
654 echo "email: {$invite->email}\n";
655 echo "status: {$invite->status}\n";
656 echo "expires_at: {$invite->expiresAt->format(DATE_ATOM)}\n";
657 ```
658
659 ```ruby Ruby
660 client = Anthropic::Client.new
661
662 invite = client.beta.organization.invites.create(email: "[email protected]", role: :developer)
663
664 puts "id: #{invite.id}"
665 puts "email: #{invite.email}"
666 puts "status: #{invite.status}"
667 puts "expires_at: #{invite.expires_at.iso8601}"
153668 ```
154669</CodeGroup>
155670
156### Workspaces
157
158For a comprehensive guide to workspaces, including Console and API examples, see [Workspaces](https://platform.claude.com/docs/en/manage-claude/workspaces).
159
160### Workspace members
161
162Manage [user access to specific workspaces](https://platform.claude.com/docs/en/api/admin-api/workspace_members/get-workspace-member):
671List pending invites:
163672
164673<CodeGroup>
165674 ```bash cURL
166 # Add member to workspace
167 curl --request POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members" \
168 --header "anthropic-version: 2023-06-01" \
169 --header "content-type: application/json" \
170 --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \
171 --data '{
172 "user_id": "user_xxx",
675 curl "https://api.anthropic.com/v1/organizations/invites?limit=10" \
676 -H "x-api-key: $ANTHROPIC_API_KEY" \
677 -H "anthropic-version: 2023-06-01"
678 ```
679
680 ```bash CLI
681 ant beta:organization:invites list --limit 10
682 ```
683
684 ```python Python
685 client = anthropic.Anthropic()
686
687 invites = client.beta.organization.invites.list(limit=10)
688
689 # Automatically fetches more pages as needed.
690 for invite in invites:
691 print(f"{invite.id}: {invite.email} ({invite.status})")
692 ```
693
694 ```typescript TypeScript
695 const client = new Anthropic();
696
697 const invites = await client.beta.organization.invites.list({ limit: 10 });
698
699 for await (const invite of invites) {
700 console.log(`${invite.id}: ${invite.email} (${invite.status})`);
701 }
702 ```
703
704 ```csharp C#
705 AnthropicClient client = new();
706
707 var page = await client.Beta.Organization.Invites.List(new() { Limit = 10 });
708
709 await foreach (var invite in page.Paginate())
710 {
711 Console.WriteLine($"{invite.ID}: {invite.Email} ({invite.Status.Raw()})");
712 }
713 ```
714
715 ```go Go
716 client := anthropic.NewClient()
717
718 invites := client.Beta.Organization.Invites.ListAutoPaging(context.Background(), anthropic.BetaOrganizationInviteListParams{
719 Limit: anthropic.Int(10),
720 })
721
722 for invites.Next() {
723 invite := invites.Current()
724 fmt.Printf("%s: %s (%s)\n", invite.ID, invite.Email, invite.Status)
725 }
726 if err := invites.Err(); err != nil {
727 log.Fatal(err)
728 }
729 ```
730
731 ```java Java
732 import com.anthropic.models.beta.organization.invites.InviteListParams;
733
734 void main() {
735 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
736
737 var params = InviteListParams.builder()
738 .limit(10)
739 .build();
740 var invites = client.beta().organization().invites().list(params);
741
742 for (var invite : invites.autoPager()) {
743 IO.println(invite.id() + ": " + invite.email() + " (" + invite.status().asString() + ")");
744 }
745 }
746 ```
747
748 ```php PHP
749 $client = new Client();
750
751 $invites = $client->beta->organization->invites->list(limit: 10);
752
753 foreach ($invites->getItems() as $invite) {
754 echo "{$invite->id}: {$invite->email} ({$invite->status})\n";
755 }
756 ```
757
758 ```ruby Ruby
759 client = Anthropic::Client.new
760
761 invites = client.beta.organization.invites.list(limit: 10)
762
763 invites.data.each do |invite|
764 puts "#{invite.id}: #{invite.email} (#{invite.status})"
765 end
766 ```
767</CodeGroup>
768
769Delete an invite:
770
771<CodeGroup>
772 ```bash cURL
773 curl -X DELETE "https://api.anthropic.com/v1/organizations/invites/invite_015gWxHNr6h6TdRPZTmuCGnn" \
774 -H "x-api-key: $ANTHROPIC_API_KEY" \
775 -H "anthropic-version: 2023-06-01"
776 ```
777
778 ```bash CLI
779 ant beta:organization:invites delete --invite-id invite_015gWxHNr6h6TdRPZTmuCGnn
780 ```
781
782 ```python Python
783 client = anthropic.Anthropic()
784
785 deleted_invite = client.beta.organization.invites.delete(
786 "invite_015gWxHNr6h6TdRPZTmuCGnn"
787 )
788
789 print(f"id: {deleted_invite.id}")
790 ```
791
792 ```typescript TypeScript
793 const client = new Anthropic();
794
795 const deletedInvite = await client.beta.organization.invites.delete(
796 "invite_015gWxHNr6h6TdRPZTmuCGnn"
797 );
798
799 console.log(`id: ${deletedInvite.id}`);
800 ```
801
802 ```csharp C#
803 AnthropicClient client = new();
804
805 var deletedInvite = await client.Beta.Organization.Invites.Delete(
806 "invite_015gWxHNr6h6TdRPZTmuCGnn"
807 );
808
809 Console.WriteLine($"id: {deletedInvite.ID}");
810 ```
811
812 ```go Go
813 client := anthropic.NewClient()
814
815 deletedInvite, err := client.Beta.Organization.Invites.Delete(context.Background(), "invite_015gWxHNr6h6TdRPZTmuCGnn")
816 if err != nil {
817 log.Fatal(err)
818 }
819
820 fmt.Printf("id: %s\n", deletedInvite.ID)
821 ```
822
823 ```java Java
824 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
825
826 var deletedInvite = client.beta().organization().invites()
827 .delete("invite_015gWxHNr6h6TdRPZTmuCGnn");
828
829 IO.println("id: " + deletedInvite.id());
830 ```
831
832 ```php PHP
833 $client = new Client();
834
835 $deletedInvite = $client->beta->organization->invites->delete(
836 inviteID: 'invite_015gWxHNr6h6TdRPZTmuCGnn',
837 );
838
839 echo "id: {$deletedInvite->id}\n";
840 ```
841
842 ```ruby Ruby
843 client = Anthropic::Client.new
844
845 invite_id = "invite_015gWxHNr6h6TdRPZTmuCGnn"
846 deleted_invite = client.beta.organization.invites.delete(invite_id)
847
848 puts "id: #{deleted_invite.id}"
849 ```
850</CodeGroup>
851
852### Workspaces
853
854See [Workspaces](https://platform.claude.com/docs/en/manage-claude/workspaces) for Console and API examples.
855
856### Workspace members
857
858Manage [user access to specific workspaces](https://platform.claude.com/docs/en/api/admin-api/workspace_members/get-workspace-member):
859
860Add a member to a workspace:
861
862<CodeGroup>
863 ```bash cURL
864 curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members" \
865 -H "x-api-key: $ANTHROPIC_API_KEY" \
866 -H "anthropic-version: 2023-06-01" \
867 -H "content-type: application/json" \
868 -d '{
869 "user_id": "user_01XyDMpzjS89pFZXqSFUBDr6",
173870 "workspace_role": "workspace_developer"
174871 }'
175
176 # List workspace members
177 curl "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members?limit=10" \
178 --header "anthropic-version: 2023-06-01" \
179 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
180
181 # Update member role
182 curl --request POST "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members/{user_id}" \
183 --header "anthropic-version: 2023-06-01" \
184 --header "content-type: application/json" \
185 --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \
186 --data '{
187 "workspace_role": "workspace_admin"
188 }'
189
190 # Remove member from workspace
191 curl --request DELETE "https://api.anthropic.com/v1/organizations/workspaces/{workspace_id}/members/{user_id}" \
192 --header "anthropic-version: 2023-06-01" \
193 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
872 ```
873
874 ```bash CLI
875 ant beta:organization:workspaces:members add \
876 --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \
877 --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \
878 --workspace-role workspace_developer
879 ```
880
881 ```python Python
882 client = anthropic.Anthropic()
883
884 member = client.beta.organization.workspaces.members.add(
885 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
886 user_id="user_01XyDMpzjS89pFZXqSFUBDr6",
887 workspace_role="workspace_developer",
888 )
889
890 print(f"user_id: {member.user_id}")
891 print(f"workspace_role: {member.workspace_role}")
892 ```
893
894 ```typescript TypeScript
895 const client = new Anthropic();
896
897 const member = await client.beta.organization.workspaces.members.add(
898 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
899 {
900 user_id: "user_01XyDMpzjS89pFZXqSFUBDr6",
901 workspace_role: "workspace_developer"
902 }
903 );
904
905 console.log(`user_id: ${member.user_id}`);
906 console.log(`workspace_role: ${member.workspace_role}`);
907 ```
908
909 ```csharp C#
910 using Anthropic.Models.Beta.Organization.Workspaces;
911
912 AnthropicClient client = new();
913
914 var member = await client.Beta.Organization.Workspaces.Members.Add(
915 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
916 new()
917 {
918 UserID = "user_01XyDMpzjS89pFZXqSFUBDr6",
919 WorkspaceRole = BetaNoBillingWorkspaceRole.WorkspaceDeveloper
920 }
921 );
922
923 Console.WriteLine($"user_id: {member.UserID}");
924 Console.WriteLine($"workspace_role: {member.WorkspaceRole.Raw()}");
925 ```
926
927 ```go Go
928 client := anthropic.NewClient()
929
930 member, err := client.Beta.Organization.Workspaces.Members.Add(
931 context.Background(),
932 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
933 anthropic.BetaOrganizationWorkspaceMemberAddParams{
934 UserID: "user_01XyDMpzjS89pFZXqSFUBDr6",
935 WorkspaceRole: anthropic.BetaNoBillingWorkspaceRoleWorkspaceDeveloper,
936 },
937 )
938 if err != nil {
939 log.Fatal(err)
940 }
941
942 fmt.Printf("user_id: %s\n", member.UserID)
943 fmt.Printf("workspace_role: %s\n", member.WorkspaceRole)
944 ```
945
946 ```java Java
947 import com.anthropic.models.beta.organization.workspaces.BetaNoBillingWorkspaceRole;
948 import com.anthropic.models.beta.organization.workspaces.members.MemberAddParams;
949
950 void main() {
951 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
952
953 var params = MemberAddParams.builder()
954 .userId("user_01XyDMpzjS89pFZXqSFUBDr6")
955 .workspaceRole(BetaNoBillingWorkspaceRole.WORKSPACE_DEVELOPER)
956 .build();
957 var member = client.beta().organization().workspaces().members()
958 .add("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", params);
959
960 IO.println("user_id: " + member.userId());
961 IO.println("workspace_role: " + member.workspaceRole().asString());
962 }
963 ```
964
965 ```php PHP
966 use Anthropic\Beta\Organization\Workspaces\NoBillingWorkspaceRole;
967 // ...
968
969 $client = new Client();
970
971 $member = $client->beta->organization->workspaces->members->add(
972 workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ',
973 userID: 'user_01XyDMpzjS89pFZXqSFUBDr6',
974 workspaceRole: NoBillingWorkspaceRole::WORKSPACE_DEVELOPER,
975 );
976
977 echo "user_id: {$member->userID}\n";
978 echo "workspace_role: {$member->workspaceRole}\n";
979 ```
980
981 ```ruby Ruby
982 client = Anthropic::Client.new
983
984 workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
985 member = client.beta.organization.workspaces.members.add(
986 workspace_id,
987 user_id: "user_01XyDMpzjS89pFZXqSFUBDr6",
988 workspace_role: :workspace_developer
989 )
990
991 puts "user_id: #{member.user_id}"
992 puts "workspace_role: #{member.workspace_role}"
194993 ```
195994</CodeGroup>
196995
197### API keys
198
199Monitor and manage [API keys](https://platform.claude.com/docs/en/api/admin/api_keys/list). Each key in the response includes its `expires_at` timestamp (`null` for keys without an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration)):
996List the members of a workspace:
200997
201998<CodeGroup>
202999 ```bash cURL
203 # List API keys
204 curl "https://api.anthropic.com/v1/organizations/api_keys?limit=10&status=active&workspace_id=wrkspc_xxx" \
205 --header "anthropic-version: 2023-06-01" \
206 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
207
208 # Update API key
209 curl --request POST "https://api.anthropic.com/v1/organizations/api_keys/{api_key_id}" \
210 --header "anthropic-version: 2023-06-01" \
211 --header "content-type: application/json" \
212 --header "x-api-key: $ANTHROPIC_ADMIN_KEY" \
213 --data '{
1000 curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members?limit=10" \
1001 -H "x-api-key: $ANTHROPIC_API_KEY" \
1002 -H "anthropic-version: 2023-06-01"
1003 ```
1004
1005 ```bash CLI
1006 ant beta:organization:workspaces:members list \
1007 --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \
1008 --limit 10
1009 ```
1010
1011 ```python Python
1012 client = anthropic.Anthropic()
1013
1014 members = client.beta.organization.workspaces.members.list(
1015 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", limit=10
1016 )
1017
1018 # Automatically fetches more pages as needed.
1019 for member in members:
1020 print(f"{member.user_id}: {member.workspace_role}")
1021 ```
1022
1023 ```typescript TypeScript
1024 const client = new Anthropic();
1025
1026 const members = await client.beta.organization.workspaces.members.list(
1027 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1028 { limit: 10 }
1029 );
1030
1031 for await (const member of members) {
1032 console.log(`${member.user_id}: ${member.workspace_role}`);
1033 }
1034 ```
1035
1036 ```csharp C#
1037 AnthropicClient client = new();
1038
1039 var page = await client.Beta.Organization.Workspaces.Members.List(
1040 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1041 new() { Limit = 10 }
1042 );
1043
1044 await foreach (var member in page.Paginate())
1045 {
1046 Console.WriteLine($"{member.UserID}: {member.WorkspaceRole.Raw()}");
1047 }
1048 ```
1049
1050 ```go Go
1051 client := anthropic.NewClient()
1052
1053 members := client.Beta.Organization.Workspaces.Members.ListAutoPaging(
1054 context.Background(),
1055 "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1056 anthropic.BetaOrganizationWorkspaceMemberListParams{
1057 Limit: anthropic.Int(10),
1058 },
1059 )
1060
1061 for members.Next() {
1062 member := members.Current()
1063 fmt.Printf("%s: %s\n", member.UserID, member.WorkspaceRole)
1064 }
1065 if err := members.Err(); err != nil {
1066 log.Fatal(err)
1067 }
1068 ```
1069
1070 ```java Java
1071 import com.anthropic.models.beta.organization.workspaces.members.MemberListParams;
1072
1073 void main() {
1074 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
1075
1076 var params = MemberListParams.builder()
1077 .limit(10)
1078 .build();
1079 var members = client.beta().organization().workspaces().members()
1080 .list("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ", params);
1081
1082 for (var member : members.autoPager()) {
1083 IO.println(member.userId() + ": " + member.workspaceRole().asString());
1084 }
1085 }
1086 ```
1087
1088 ```php PHP
1089 $client = new Client();
1090
1091 $members = $client->beta->organization->workspaces->members->list(
1092 workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ',
1093 limit: 10,
1094 );
1095
1096 foreach ($members->getItems() as $member) {
1097 echo "{$member->userID}: {$member->workspaceRole}\n";
1098 }
1099 ```
1100
1101 ```ruby Ruby
1102 client = Anthropic::Client.new
1103
1104 workspace_id = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1105 members = client.beta.organization.workspaces.members.list(workspace_id, limit: 10)
1106
1107 members.data.each do |member|
1108 puts "#{member.user_id}: #{member.workspace_role}"
1109 end
1110 ```
1111</CodeGroup>
1112
1113Update a workspace member's role:
1114
1115<CodeGroup>
1116 ```bash cURL
1117 curl "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members/user_01XyDMpzjS89pFZXqSFUBDr6" \
1118 -H "x-api-key: $ANTHROPIC_API_KEY" \
1119 -H "anthropic-version: 2023-06-01" \
1120 -H "content-type: application/json" \
1121 -d '{"workspace_role": "workspace_admin"}'
1122 ```
1123
1124 ```bash CLI
1125 ant beta:organization:workspaces:members update \
1126 --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \
1127 --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ \
1128 --workspace-role workspace_admin
1129 ```
1130
1131 ```python Python
1132 client = anthropic.Anthropic()
1133
1134 member = client.beta.organization.workspaces.members.update(
1135 "user_01XyDMpzjS89pFZXqSFUBDr6",
1136 workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1137 workspace_role="workspace_admin",
1138 )
1139
1140 print(f"user_id: {member.user_id}")
1141 print(f"workspace_role: {member.workspace_role}")
1142 ```
1143
1144 ```typescript TypeScript
1145 const client = new Anthropic();
1146
1147 const member = await client.beta.organization.workspaces.members.update(
1148 "user_01XyDMpzjS89pFZXqSFUBDr6",
1149 {
1150 workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1151 workspace_role: "workspace_admin"
1152 }
1153 );
1154
1155 console.log(`user_id: ${member.user_id}`);
1156 console.log(`workspace_role: ${member.workspace_role}`);
1157 ```
1158
1159 ```csharp C#
1160 using Anthropic.Models.Beta.Organization.Workspaces;
1161
1162 AnthropicClient client = new();
1163
1164 var member = await client.Beta.Organization.Workspaces.Members.Update(
1165 "user_01XyDMpzjS89pFZXqSFUBDr6",
1166 new()
1167 {
1168 WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1169 WorkspaceRole = BetaWorkspaceRole.WorkspaceAdmin
1170 }
1171 );
1172
1173 Console.WriteLine($"user_id: {member.UserID}");
1174 Console.WriteLine($"workspace_role: {member.WorkspaceRole.Raw()}");
1175 ```
1176
1177 ```go Go
1178 client := anthropic.NewClient()
1179
1180 member, err := client.Beta.Organization.Workspaces.Members.Update(
1181 context.Background(),
1182 "user_01XyDMpzjS89pFZXqSFUBDr6",
1183 anthropic.BetaOrganizationWorkspaceMemberUpdateParams{
1184 WorkspaceID: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1185 WorkspaceRole: anthropic.BetaWorkspaceRoleWorkspaceAdmin,
1186 },
1187 )
1188 if err != nil {
1189 log.Fatal(err)
1190 }
1191
1192 fmt.Printf("user_id: %s\n", member.UserID)
1193 fmt.Printf("workspace_role: %s\n", member.WorkspaceRole)
1194 ```
1195
1196 ```java Java
1197 import com.anthropic.models.beta.organization.workspaces.BetaWorkspaceRole;
1198 import com.anthropic.models.beta.organization.workspaces.members.MemberUpdateParams;
1199
1200 void main() {
1201 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
1202
1203 var params = MemberUpdateParams.builder()
1204 .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ")
1205 .workspaceRole(BetaWorkspaceRole.WORKSPACE_ADMIN)
1206 .build();
1207 var member = client.beta().organization().workspaces().members()
1208 .update("user_01XyDMpzjS89pFZXqSFUBDr6", params);
1209
1210 IO.println("user_id: " + member.userId());
1211 IO.println("workspace_role: " + member.workspaceRole().asString());
1212 }
1213 ```
1214
1215 ```php PHP
1216 use Anthropic\Beta\Organization\Workspaces\WorkspaceRole;
1217 // ...
1218
1219 $client = new Client();
1220
1221 $member = $client->beta->organization->workspaces->members->update(
1222 userID: 'user_01XyDMpzjS89pFZXqSFUBDr6',
1223 workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ',
1224 workspaceRole: WorkspaceRole::WORKSPACE_ADMIN,
1225 );
1226
1227 echo "user_id: {$member->userID}\n";
1228 echo "workspace_role: {$member->workspaceRole}\n";
1229 ```
1230
1231 ```ruby Ruby
1232 client = Anthropic::Client.new
1233
1234 user_id = "user_01XyDMpzjS89pFZXqSFUBDr6"
1235 member = client.beta.organization.workspaces.members.update(
1236 user_id,
1237 workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1238 workspace_role: :workspace_admin
1239 )
1240
1241 puts "user_id: #{member.user_id}"
1242 puts "workspace_role: #{member.workspace_role}"
1243 ```
1244</CodeGroup>
1245
1246Remove a member from a workspace:
1247
1248<CodeGroup>
1249 ```bash cURL
1250 curl -X DELETE "https://api.anthropic.com/v1/organizations/workspaces/wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ/members/user_01XyDMpzjS89pFZXqSFUBDr6" \
1251 -H "x-api-key: $ANTHROPIC_API_KEY" \
1252 -H "anthropic-version: 2023-06-01"
1253 ```
1254
1255 ```bash CLI
1256 ant beta:organization:workspaces:members remove \
1257 --user-id user_01XyDMpzjS89pFZXqSFUBDr6 \
1258 --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ
1259 ```
1260
1261 ```python Python
1262 client = anthropic.Anthropic()
1263
1264 removed_member = client.beta.organization.workspaces.members.remove(
1265 "user_01XyDMpzjS89pFZXqSFUBDr6", workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1266 )
1267
1268 print(f"user_id: {removed_member.user_id}")
1269 ```
1270
1271 ```typescript TypeScript
1272 const client = new Anthropic();
1273
1274 const removedMember = await client.beta.organization.workspaces.members.remove(
1275 "user_01XyDMpzjS89pFZXqSFUBDr6",
1276 { workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" }
1277 );
1278
1279 console.log(`user_id: ${removedMember.user_id}`);
1280 ```
1281
1282 ```csharp C#
1283 AnthropicClient client = new();
1284
1285 var removedMember = await client.Beta.Organization.Workspaces.Members.Remove(
1286 "user_01XyDMpzjS89pFZXqSFUBDr6",
1287 new() { WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" }
1288 );
1289
1290 Console.WriteLine($"user_id: {removedMember.UserID}");
1291 ```
1292
1293 ```go Go
1294 client := anthropic.NewClient()
1295
1296 removedMember, err := client.Beta.Organization.Workspaces.Members.Remove(
1297 context.Background(),
1298 "user_01XyDMpzjS89pFZXqSFUBDr6",
1299 anthropic.BetaOrganizationWorkspaceMemberRemoveParams{
1300 WorkspaceID: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
1301 },
1302 )
1303 if err != nil {
1304 log.Fatal(err)
1305 }
1306
1307 fmt.Printf("user_id: %s\n", removedMember.UserID)
1308 ```
1309
1310 ```java Java
1311 import com.anthropic.models.beta.organization.workspaces.members.MemberRemoveParams;
1312
1313 void main() {
1314 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
1315
1316 var params = MemberRemoveParams.builder()
1317 .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ")
1318 .build();
1319 var removedMember = client.beta().organization().workspaces().members()
1320 .remove("user_01XyDMpzjS89pFZXqSFUBDr6", params);
1321
1322 IO.println("user_id: " + removedMember.userId());
1323 }
1324 ```
1325
1326 ```php PHP
1327 $client = new Client();
1328
1329 $removedMember = $client->beta->organization->workspaces->members->remove(
1330 userID: 'user_01XyDMpzjS89pFZXqSFUBDr6',
1331 workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ',
1332 );
1333
1334 echo "user_id: {$removedMember->userID}\n";
1335 ```
1336
1337 ```ruby Ruby
1338 client = Anthropic::Client.new
1339
1340 user_id = "user_01XyDMpzjS89pFZXqSFUBDr6"
1341 removed_member = client.beta.organization.workspaces.members.remove(
1342 user_id,
1343 workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1344 )
1345
1346 puts "user_id: #{removed_member.user_id}"
1347 ```
1348</CodeGroup>
1349
1350### API keys
1351
1352Monitor and manage [API keys](https://platform.claude.com/docs/en/api/admin/api_keys/list). Each key in the response includes its `expires_at` timestamp (`null` for keys without an [expiration](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration)):
1353
1354List the active API keys in a workspace:
1355
1356<CodeGroup>
1357 ```bash cURL
1358 curl "https://api.anthropic.com/v1/organizations/api_keys?limit=10&status=active&workspace_id=wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" \
1359 -H "x-api-key: $ANTHROPIC_API_KEY" \
1360 -H "anthropic-version: 2023-06-01"
1361 ```
1362
1363 ```bash CLI
1364 ant beta:organization:api-keys list \
1365 --limit 10 \
1366 --status active \
1367 --workspace-id wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ
1368 ```
1369
1370 ```python Python
1371 client = anthropic.Anthropic()
1372
1373 api_keys = client.beta.organization.api_keys.list(
1374 limit=10, status="active", workspace_id="wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1375 )
1376
1377 # Automatically fetches more pages as needed.
1378 for api_key in api_keys:
1379 print(f"{api_key.id}: {api_key.name} ({api_key.status})")
1380 ```
1381
1382 ```typescript TypeScript
1383 const client = new Anthropic();
1384
1385 const apiKeys = await client.beta.organization.apiKeys.list({
1386 limit: 10,
1387 status: "active",
1388 workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1389 });
1390
1391 for await (const apiKey of apiKeys) {
1392 console.log(`${apiKey.id}: ${apiKey.name} (${apiKey.status})`);
1393 }
1394 ```
1395
1396 ```csharp C#
1397 using Anthropic.Models.Beta.Organization.ApiKeys;
1398
1399 AnthropicClient client = new();
1400
1401 var page = await client.Beta.Organization.ApiKeys.List(new()
1402 {
1403 Limit = 10,
1404 Status = ApiKeyListParamsStatus.Active,
1405 WorkspaceID = "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1406 });
1407
1408 await foreach (var apiKey in page.Paginate())
1409 {
1410 Console.WriteLine($"{apiKey.ID}: {apiKey.Name} ({apiKey.Status.Raw()})");
1411 }
1412 ```
1413
1414 ```go Go
1415 client := anthropic.NewClient()
1416
1417 apiKeys := client.Beta.Organization.APIKeys.ListAutoPaging(context.Background(), anthropic.BetaOrganizationAPIKeyListParams{
1418 Limit: anthropic.Int(10),
1419 Status: anthropic.BetaOrganizationAPIKeyListParamsStatusActive,
1420 WorkspaceID: anthropic.String("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"),
1421 })
1422
1423 for apiKeys.Next() {
1424 apiKey := apiKeys.Current()
1425 fmt.Printf("%s: %s (%s)\n", apiKey.ID, apiKey.Name, apiKey.Status)
1426 }
1427 if err := apiKeys.Err(); err != nil {
1428 log.Fatal(err)
1429 }
1430 ```
1431
1432 ```java Java
1433 import com.anthropic.models.beta.organization.apikeys.ApiKeyListParams;
1434
1435 void main() {
1436 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
1437
1438 var params = ApiKeyListParams.builder()
1439 .limit(10)
1440 .status(ApiKeyListParams.Status.ACTIVE)
1441 .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ")
1442 .build();
1443 var apiKeys = client.beta().organization().apiKeys().list(params);
1444
1445 for (var apiKey : apiKeys.autoPager()) {
1446 IO.println(apiKey.id() + ": " + apiKey.name() + " (" + apiKey.status().asString() + ")");
1447 }
1448 }
1449 ```
1450
1451 ```php PHP
1452 use Anthropic\Beta\Organization\APIKeys\APIKeyListParams\Status;
1453 // ...
1454
1455 $client = new Client();
1456
1457 $apiKeys = $client->beta->organization->apiKeys->list(
1458 limit: 10,
1459 status: Status::ACTIVE,
1460 workspaceID: 'wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ',
1461 );
1462
1463 foreach ($apiKeys->getItems() as $apiKey) {
1464 echo "{$apiKey->id}: {$apiKey->name} ({$apiKey->status})\n";
1465 }
1466 ```
1467
1468 ```ruby Ruby
1469 client = Anthropic::Client.new
1470
1471 api_keys = client.beta.organization.api_keys.list(
1472 limit: 10,
1473 status: :active,
1474 workspace_id: "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
1475 )
1476
1477 api_keys.data.each do |api_key|
1478 puts "#{api_key.id}: #{api_key.name} (#{api_key.status})"
1479 end
1480 ```
1481</CodeGroup>
1482
1483Rename or deactivate an API key:
1484
1485<CodeGroup>
1486 ```bash cURL
1487 curl "https://api.anthropic.com/v1/organizations/api_keys/apikey_01Rj2N8SVvo6BePZj99NhmiT" \
1488 -H "x-api-key: $ANTHROPIC_API_KEY" \
1489 -H "anthropic-version: 2023-06-01" \
1490 -H "content-type: application/json" \
1491 -d '{
2141492 "status": "inactive",
2151493 "name": "New Key Name"
2161494 }'
2171495 ```
1496
1497 ```bash CLI
1498 ant beta:organization:api-keys update \
1499 --api-key-id apikey_01Rj2N8SVvo6BePZj99NhmiT \
1500 --status inactive \
1501 --name "New Key Name"
1502 ```
1503
1504 ```python Python
1505 client = anthropic.Anthropic()
1506
1507 api_key = client.beta.organization.api_keys.update(
1508 "apikey_01Rj2N8SVvo6BePZj99NhmiT", status="inactive", name="New Key Name"
1509 )
1510
1511 print(f"id: {api_key.id}")
1512 print(f"name: {api_key.name}")
1513 print(f"status: {api_key.status}")
1514 ```
1515
1516 ```typescript TypeScript
1517 const client = new Anthropic();
1518
1519 const apiKey = await client.beta.organization.apiKeys.update(
1520 "apikey_01Rj2N8SVvo6BePZj99NhmiT",
1521 {
1522 status: "inactive",
1523 name: "New Key Name"
1524 }
1525 );
1526
1527 console.log(`id: ${apiKey.id}`);
1528 console.log(`name: ${apiKey.name}`);
1529 console.log(`status: ${apiKey.status}`);
1530 ```
1531
1532 ```csharp C#
1533 using Anthropic.Models.Beta.Organization.ApiKeys;
1534
1535 AnthropicClient client = new();
1536
1537 var apiKey = await client.Beta.Organization.ApiKeys.Update(
1538 "apikey_01Rj2N8SVvo6BePZj99NhmiT",
1539 new()
1540 {
1541 Status = Status.Inactive,
1542 Name = "New Key Name"
1543 }
1544 );
1545
1546 Console.WriteLine($"id: {apiKey.ID}");
1547 Console.WriteLine($"name: {apiKey.Name}");
1548 Console.WriteLine($"status: {apiKey.Status.Raw()}");
1549 ```
1550
1551 ```go Go
1552 client := anthropic.NewClient()
1553
1554 apiKey, err := client.Beta.Organization.APIKeys.Update(
1555 context.Background(),
1556 "apikey_01Rj2N8SVvo6BePZj99NhmiT",
1557 anthropic.BetaOrganizationAPIKeyUpdateParams{
1558 Status: anthropic.BetaOrganizationAPIKeyUpdateParamsStatusInactive,
1559 Name: anthropic.String("New Key Name"),
1560 },
1561 )
1562 if err != nil {
1563 log.Fatal(err)
1564 }
1565
1566 fmt.Printf("id: %s\n", apiKey.ID)
1567 fmt.Printf("name: %s\n", apiKey.Name)
1568 fmt.Printf("status: %s\n", apiKey.Status)
1569 ```
1570
1571 ```java Java
1572 import com.anthropic.models.beta.organization.apikeys.ApiKeyUpdateParams;
1573
1574 void main() {
1575 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
1576
1577 var params = ApiKeyUpdateParams.builder()
1578 .status(ApiKeyUpdateParams.Status.INACTIVE)
1579 .name("New Key Name")
1580 .build();
1581 var apiKey = client.beta().organization().apiKeys()
1582 .update("apikey_01Rj2N8SVvo6BePZj99NhmiT", params);
1583
1584 IO.println("id: " + apiKey.id());
1585 IO.println("name: " + apiKey.name());
1586 IO.println("status: " + apiKey.status().asString());
1587 }
1588 ```
1589
1590 ```php PHP
1591 use Anthropic\Beta\Organization\APIKeys\APIKeyUpdateParams\Status;
1592 // ...
1593
1594 $client = new Client();
1595
1596 $apiKey = $client->beta->organization->apiKeys->update(
1597 apiKeyID: 'apikey_01Rj2N8SVvo6BePZj99NhmiT',
1598 status: Status::INACTIVE,
1599 name: 'New Key Name',
1600 );
1601
1602 echo "id: {$apiKey->id}\n";
1603 echo "name: {$apiKey->name}\n";
1604 echo "status: {$apiKey->status}\n";
1605 ```
1606
1607 ```ruby Ruby
1608 client = Anthropic::Client.new
1609
1610 api_key_id = "apikey_01Rj2N8SVvo6BePZj99NhmiT"
1611 api_key = client.beta.organization.api_keys.update(
1612 api_key_id,
1613 status: :inactive,
1614 name: "New Key Name"
1615 )
1616
1617 puts "id: #{api_key.id}"
1618 puts "name: #{api_key.name}"
1619 puts "status: #{api_key.status}"
1620 ```
2181621</CodeGroup>
2191622
2201623### Service accounts
2211624
222Create and manage service accounts (`svac_...`), the non-human identities that [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation) tokens act as. Admin API keys are not accepted on the service-account, federation-issuer, or federation-rule endpoints; use an `org:admin` OAuth token. See [Manage WIF with the Admin API](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#service-accounts).
1625Create and manage service accounts (`svac_...`), the non-human identities that [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation) tokens act as. These endpoints, like the federation-issuer and federation-rule endpoints, require an `org:admin` OAuth token. See [Manage WIF with the Admin API](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#service-accounts).
2231626
2241627### Federation issuers
2251628
from line 1634
2311634
2321635## Accessing organization info
2331636
234Get information about your organization programmatically with the `/v1/organizations/me` endpoint.
235
236For example:
237
238```bash cURL
239curl "https://api.anthropic.com/v1/organizations/me" \
240 --header "anthropic-version: 2023-06-01" \
241 --header "x-api-key: $ANTHROPIC_ADMIN_KEY"
242```
1637The `/v1/organizations/me` endpoint returns the organization that your credential belongs to:
1638
1639<CodeGroup>
1640 ```bash cURL
1641 curl "https://api.anthropic.com/v1/organizations/me" \
1642 -H "x-api-key: $ANTHROPIC_API_KEY" \
1643 -H "anthropic-version: 2023-06-01"
1644 ```
1645
1646 ```bash CLI
1647 ant beta:organization retrieve
1648 ```
1649
1650 ```python Python
1651 client = anthropic.Anthropic()
1652
1653 organization = client.beta.organization.retrieve()
1654
1655 print(f"id: {organization.id}")
1656 print(f"name: {organization.name}")
1657 ```
1658
1659 ```typescript TypeScript
1660 const client = new Anthropic();
1661
1662 const organization = await client.beta.organization.retrieve();
1663
1664 console.log(`id: ${organization.id}`);
1665 console.log(`name: ${organization.name}`);
1666 ```
1667
1668 ```csharp C#
1669 AnthropicClient client = new();
1670
1671 var organization = await client.Beta.Organization.Retrieve();
1672
1673 Console.WriteLine($"id: {organization.ID}");
1674 Console.WriteLine($"name: {organization.Name}");
1675 ```
1676
1677 ```go Go
1678 client := anthropic.NewClient()
1679
1680 organization, err := client.Beta.Organization.Get(context.Background())
1681 if err != nil {
1682 log.Fatal(err)
1683 }
1684
1685 fmt.Printf("id: %s\n", organization.ID)
1686 fmt.Printf("name: %s\n", organization.Name)
1687 ```
1688
1689 ```java Java
1690 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
1691
1692 var organization = client.beta().organization().retrieve();
1693
1694 IO.println("id: " + organization.id());
1695 IO.println("name: " + organization.name());
1696 ```
1697
1698 ```php PHP
1699 $client = new Client();
1700
1701 $organization = $client->beta->organization->retrieve();
1702
1703 echo "id: {$organization->id}\n";
1704 echo "name: {$organization->name}\n";
1705 ```
1706
1707 ```ruby Ruby
1708 client = Anthropic::Client.new
1709
1710 organization = client.beta.organization.retrieve
1711
1712 puts "id: #{organization.id}"
1713 puts "name: #{organization.name}"
1714 ```
1715</CodeGroup>
2431716
2441717```json
2451718{
from line 1722
2491722}
2501723```
2511724
252This endpoint is useful for programmatically determining which organization an Admin API key belongs to.
253
254For complete parameter details and response schemas, see the [Organization Info API reference](https://platform.claude.com/docs/en/api/admin-api/organization/get-me).
1725For parameter details and response schemas, see the [Organization Info API reference](https://platform.claude.com/docs/en/api/admin-api/organization/get-me).
2551726
2561727## Usage and cost reports
2571728
from line 1738
2671738
2681739## Compliance API
2691740
270Retrieve audit and activity data for your organization with the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api). Admin API keys can read the Activity Feed only; for full access, see [Set up the Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api-access).
1741Retrieve audit and activity data for your organization with the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api). Admin API keys can read only the Activity Feed. For full access, see [Set up the Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api-access).
2711742
2721743## Best practices
2731744
274To effectively use the Admin API:
275
2761745* Use meaningful names and descriptions for workspaces and API keys
277* Implement proper error handling for failed operations
1746* Handle errors from failed operations
2781747* Regularly audit member roles and permissions
2791748* Clean up unused workspaces and expired invites
2801749* Monitor API key usage, audit each key's [`expires_at`](https://platform.claude.com/docs/en/manage-claude/authentication#key-expiration), and rotate keys periodically
from line 1756
2871756 </Accordion>
2881757
2891758 <Accordion title="Can I create new API keys through the Admin API?">
290 No, new API keys can only be created through the Claude Console for security reasons. The Admin API can only manage existing API keys.
1759 No. You create API keys in the Claude Console. The Admin API can only read, rename, and change the status of existing keys.
2911760 </Accordion>
2921761
2931762 <Accordion title="What happens to API keys when removing a user?">
294 API keys persist in their current state as they are scoped to the organization, not to individual users.
1763 They're unaffected. API keys belong to the organization, not to individual users.
2951764 </Accordion>
2961765
2971766 <Accordion title="Can organization admins be removed through the API?">
298 No, organization members with the admin role cannot be removed through the API for security reasons.
1767 No. The API can't remove members with the admin role.
2991768 </Accordion>
3001769
3011770 <Accordion title="How long do organization invites last?">
302 Organization invites expire after 21 days. There is currently no way to modify this expiration period.
1771 Invites expire after 21 days. The expiration period isn't configurable.
3031772 </Accordion>
3041773</AccordionGroup>
3051774
3061775
No line in this hunk matches that.