# RBAC Groups ## List RBAC Groups ### Query parameters ### Returns ### Example #### Response (200) ## Get RBAC Group ### Path parameters ### Returns ### Example #### Response (200) ## Create RBAC Group ### Body parameters ### Returns ### Example #### Response (200) ## Update RBAC Group ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Delete RBAC Group ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Beta RBAC Group ### Beta RBAC Group Deleted ## RBAC Groups › Members ### List RBAC Group Members #### Path parameters #### Query parameters #### Returns #### Example ##### Response (200) ### Add RBAC Group Member #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Remove RBAC Group Member #### Path parameters #### Returns #### Example ##### Response (200)
The whole hunk
715 lines, new pageA whole new page. There's nothing to diff it against, so here is what it says.
---
title: RBAC Groups
url: https://platform.claude.com/docs/en/api/beta/organization/rbac_groups
---
# RBAC Groups
## List RBAC Groups
**GET** `/v1/organizations/rbac_groups`
List RBAC Groups in the Claude Enterprise tenant.
The RBAC Groups API is available to Claude Enterprise organizations only.
### Query parameters
- `limit: optional number`
Number of items to return per page.
Defaults to `20`. Ranges from `1` to `1000`.
default: 20, maximum: 1000, minimum: 1
- `page: optional string`
Optionally set to the `next_page` token from the previous response.
### Returns
- `data: array of BetaRBACGroup`
- `type: "rbac_group"`
Object type.
For RBAC Groups, this is always `"rbac_group"`.
default: rbac_group
- `id: string`
ID of the RBAC Group.
- `created_at: string`
RFC 3339 timestamp of when the RBAC Group was created.
format: date-time
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
- `roles: array of string or null`
RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. `null` means role data was temporarily unavailable — retry to distinguish from an empty list.
- `source_type: "direct" or "scim"`
How the RBAC Group was created: `"direct"` for groups created directly (for example, in the organization's admin settings), `"scim"` for groups provisioned by the identity provider.
- `"direct"`
- `"scim"`
- `updated_at: string`
RFC 3339 timestamp of when the RBAC Group was last updated.
format: date-time
- `has_more: boolean`
Indicates if there are more results in the requested page direction.
- `next_page: string or null`
Token to provide in as `page` in the subsequent request to retrieve the next page of data.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/rbac_groups \
-H 'anthropic-version: 2023-06-01' \
-H 'anthropic-beta: ce-user-management-2026-07-13' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
"created_at": "2024-10-30T23:58:27.427722Z",
"name": "Engineering",
"roles": [
"rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
],
"source_type": "direct",
"type": "rbac_group",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
],
"has_more": false,
"next_page": "eyJjdXJzb3IiOiAicmJhY19ncm91cF8wMSJ9"
}
```
## Get RBAC Group
**GET** `/v1/organizations/rbac_groups/{group_id}`
Retrieve an RBAC Group by ID.
The RBAC Groups API is available to Claude Enterprise organizations only.
### Path parameters
- `group_id: string`
ID of the RBAC Group.
### Returns
- `BetaRBACGroup object`
- `type: "rbac_group"`
Object type.
For RBAC Groups, this is always `"rbac_group"`.
default: rbac_group
- `id: string`
ID of the RBAC Group.
- `created_at: string`
RFC 3339 timestamp of when the RBAC Group was created.
format: date-time
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
- `roles: array of string or null`
RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. `null` means role data was temporarily unavailable — retry to distinguish from an empty list.
- `source_type: "direct" or "scim"`
How the RBAC Group was created: `"direct"` for groups created directly (for example, in the organization's admin settings), `"scim"` for groups provisioned by the identity provider.
- `"direct"`
- `"scim"`
- `updated_at: string`
RFC 3339 timestamp of when the RBAC Group was last updated.
format: date-time
### Example
```bash
curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \
-H 'anthropic-version: 2023-06-01' \
-H 'anthropic-beta: ce-user-management-2026-07-13' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
"created_at": "2024-10-30T23:58:27.427722Z",
"name": "Engineering",
"roles": [
"rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
],
"source_type": "direct",
"type": "rbac_group",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
## Create RBAC Group
**POST** `/v1/organizations/rbac_groups`
Create an RBAC Group in the Claude Enterprise tenant. Groups created via the API have source type `"direct"`.
The RBAC Groups API is available to Claude Enterprise organizations only.
### Body parameters
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
maxLength: 255, minLength: 1
### Returns
- `BetaRBACGroup object`
- `type: "rbac_group"`
Object type.
For RBAC Groups, this is always `"rbac_group"`.
default: rbac_group
- `id: string`
ID of the RBAC Group.
- `created_at: string`
RFC 3339 timestamp of when the RBAC Group was created.
format: date-time
- `name: string`
Name of the RBAC Group. Not uniqueness-enforced.
- `roles: array of string or null`
RBAC Role IDs attached to this RBAC Group. Role attachment is managed in the admin settings and is read-only on this API. `null` means role data was temporarily unavailable — retry to distinguish from an empty list.
- `source_type: "direct" or "scim"`
How the RBAC Group was created: `"direct"` for groups created directly (for example, in the organization's admin settings), `"scim"` for groups provisioned by the identity provider.
- `"direct"`
- `"scim"`
- `updated_at: string`
RFC 3339 timestamp of when the RBAC Group was last updated.
format: date-time
### Example
```bash
curl https://api.anthropic.com/v1/organizations/rbac_groups \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H 'anthropic-beta: ce-user-management-2026-07-13' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"name": "Engineering"
}'
```
#### Response (200)
```json
{
"id": "rbac_group_012rppKaSVsmTo6NqRDXQXNF",
"created_at": "2024-10-30T23:58:27.427722Z",
"name": "Engineering",
"roles": [
"rbac_role_016J8xVtKpDq3Wy9ZmN2hR4s"
],
"source_type": "direct",
"type": "rbac_group",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
```
## Update RBAC Group
**POST** `/v1/organizations/rbac_groups/{group_id}`
Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning.
The RBAC Groups API is available to Claude Enterprise organizations only.
### Path parameters
- `group_id: string`
ID of the RBAC Group.
### Body parameters
Cut at 300 lines. The page has the rest.