Limits for federated agent access changedclaude-tag/admins/federated-access/limits
Nearest release: v2.1.283, published 10 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 26 Sep 2026 05:05 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+40added
Lines−40removed
From line
14
where the diff opens
First seen
10 Sep 2026
this site's first read of the page
Recorded edits4to this page, all time
The whole hunk
from line 14, old and new numbered
/
from line 14
1414
1515## Identity token
1616
17| Limit | Value |
18| :---------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
19| Token lifetime | 10 minutes. Tokens can't be revoked before they expire. When you remove a gateway, Claude stops using it at once; when you remove a cloud role or authorization server, within about a minute (current behavior, may change). A token issued before the removal stays valid until it expires. |
20| Signing algorithm | ES256 only. |
21| Claims | See the [identity token reference](/docs/claude-tag/admins/federated-access/token-reference#claims); verifiers must ignore claims they don't recognize. |
17| Limit | Value |
18| :- | :- |
19| Token lifetime | 10 minutes. Tokens can't be revoked before they expire. When you remove a gateway, Claude stops using it at once; when you remove a cloud role or authorization server, within about a minute (current behavior, may change). A token issued before the removal stays valid until it expires. |
20| Signing algorithm | ES256 only. |
21| Claims | See the [identity token reference](/docs/claude-tag/admins/federated-access/token-reference#claims); verifiers must ignore claims they don't recognize. |
2222
2323## Gateways
2424
25| Limit | Value |
26| :------------------------------------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
27| Registered addresses per organization | 5, counting gateways and authorization-server token endpoints together. |
28| Token reuse | Claude reuses one token for a session's requests to the same gateway for about five minutes, half the token's lifetime, or until the gateway answers 401, and then requests a new one (current behavior, may change). A gateway sees the same `jti` on many requests. |
29| Gateway address | An HTTPS host name only, with no path, port, query, or trailing slash. The host name needs a domain, like `gateway.example.com`, uses only letters, numbers, hyphens, and dots, and has at most 253 characters (current behavior, may change). The console rejects an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange, and names the reason. The connection check also refuses a host name that resolves to a private address. |
30| One connection per gateway | A gateway connected in one Access bundle can't be connected again in another. Attach that bundle to each scope that needs the gateway. |
31| [Allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the gateway's connection | Exactly the gateway's host, the only host Claude sends the token to. It can't be widened or given a wildcard. |
32| Connection check | Runs only against an HTTPS host with no path. The console sends two `POST` requests to the address, each with an empty body and a test token, doesn't follow redirects, and can take up to a minute. [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway) lists the expected responses. The console refuses a check that runs many times in quick succession and says how long to wait. |
33| Same address twice in one organization | Entering an address that is already registered runs the connection check again (unless you skip it) without changing the stored result, then moves to the bundle step. The run counts toward the check limit. |
25| Limit | Value |
26| :- | :- |
27| Registered addresses per organization | 5, counting gateways and authorization-server token endpoints together. |
28| Token reuse | Claude reuses one token for a session's requests to the same gateway for about five minutes, half the token's lifetime, or until the gateway answers 401, and then requests a new one (current behavior, may change). A gateway sees the same `jti` on many requests. |
29| Gateway address | An HTTPS host name only, with no path, port, query, or trailing slash. The host name needs a domain, like `gateway.example.com`, uses only letters, numbers, hyphens, and dots, and has at most 253 characters (current behavior, may change). The console rejects an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange, and names the reason. The connection check also refuses a host name that resolves to a private address. |
30| One connection per gateway | A gateway connected in one Access bundle can't be connected again in another. Attach that bundle to each scope that needs the gateway. |
31| [Allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the gateway's connection | Exactly the gateway's host, the only host Claude sends the token to. It can't be widened or given a wildcard. |
32| Connection check | Runs only against an HTTPS host with no path. The console sends two `POST` requests to the address, each with an empty body and a test token, doesn't follow redirects, and can take up to a minute. [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway) lists the expected responses. The console refuses a check that runs many times in quick succession and says how long to wait. |
33| Same address twice in one organization | Entering an address that is already registered runs the connection check again (unless you skip it) without changing the stored result, then moves to the bundle step. The run counts toward the check limit. |
3434
3535## AWS roles
3636
37| Limit | Value |
38| :---------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
39| **Role ARN** | A commercial-partition IAM role, `arn:aws:iam::<account>:role/<name>`. AWS GovCloud and AWS China roles aren't supported. |
40| **Allowed AWS hosts** | Hosts ending in `.amazonaws.com` only, for example `s3.us-east-1.amazonaws.com` or `*.amazonaws.com`. |
41| Role session | 1 hour. The exchange doesn't ask for a longer session, so raising the role's maximum session duration has no effect. Claude reuses one session's credentials for the same agent until shortly before they expire, or until AWS answers a request with 403 (current behavior, may change). |
42| Token audience | `sts.amazonaws.com`, the same for every organization. Condition the trust policy on the `sub` claim as well as the audience; see [Authorize on the subject](/docs/claude-tag/admins/federated-access/token-reference#authorize-on-the-subject). |
43| One connection per role | A role can be connected once in your organization. |
37| Limit | Value |
38| :- | :- |
39| **Role ARN** | A commercial-partition IAM role, `arn:aws:iam::<account>:role/<name>`. AWS GovCloud and AWS China roles aren't supported. |
40| **Allowed AWS hosts** | Hosts ending in `.amazonaws.com` only, for example `s3.us-east-1.amazonaws.com` or `*.amazonaws.com`. |
41| Role session | 1 hour. The exchange doesn't ask for a longer session, so raising the role's maximum session duration has no effect. Claude reuses one session's credentials for the same agent until shortly before they expire, or until AWS answers a request with 403 (current behavior, may change). |
42| Token audience | `sts.amazonaws.com`, the same for every organization. Condition the trust policy on the `sub` claim as well as the audience; see [Authorize on the subject](/docs/claude-tag/admins/federated-access/token-reference#authorize-on-the-subject). |
43| One connection per role | A role can be connected once in your organization. |
4444
4545## Google Cloud identities
4646
47| Limit | Value |
48| :------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
49| **Workload identity provider** | The full resource name of a provider in a workload identity pool under a numeric project, `//iam.googleapis.com/projects/<number>/locations/global/workloadIdentityPools/<pool>/providers/<provider>`. Workforce identity pools aren't supported. |
50| **Service account to act as** | Optional. A service account, `<name>@<project>.iam.gserviceaccount.com`. Default compute and App Engine service accounts aren't accepted. Leave it empty to call Google Cloud as the federated identity itself. |
51| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
52| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always, with no setting to change it. On Google Cloud APIs, IAM decides what the credential can do. An API that needs an OAuth scope of its own answers 403 whatever IAM allows; see [The cloud API answers 403 after a successful exchange](/docs/claude-tag/admins/federated-access/troubleshooting#the-cloud-api-answers-403-after-a-successful-exchange). |
53| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
54| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
47| Limit | Value |
48| :- | :- |
49| **Workload identity provider** | The full resource name of a provider in a workload identity pool under a numeric project, `//iam.googleapis.com/projects/<number>/locations/global/workloadIdentityPools/<pool>/providers/<provider>`. Workforce identity pools aren't supported. |
50| **Service account to act as** | Optional. A service account, `<name>@<project>.iam.gserviceaccount.com`. Default compute and App Engine service accounts aren't accepted. Leave it empty to call Google Cloud as the federated identity itself. |
51| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
52| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always, with no setting to change it. On Google Cloud APIs, IAM decides what the credential can do. An API that needs an OAuth scope of its own answers 403 whatever IAM allows; see [The cloud API answers 403 after a successful exchange](/docs/claude-tag/admins/federated-access/troubleshooting#the-cloud-api-answers-403-after-a-successful-exchange). |
53| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
54| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
5555
5656### What the credential-minting block refuses
5757
from line 71
7171
7272## Authorization servers
7373
74| Limit | Value |
75| :-------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
76| **Token endpoint** | A full HTTPS URL of at most 256 characters (current behavior, may change), with an optional path and no port, query, fragment, user name, password, spaces, or special characters. The same host rules as a gateway address apply, and a trailing slash is dropped. |
77| Token audience | Your authorization server's issuer identifier as you entered it (an HTTPS URL on the same host as the token endpoint, with the same address rules), or the token endpoint URL exactly when you left the issuer identifier empty. It can't be changed after the server is connected. |
78| **Resource** | Optional. An absolute URI with no fragment, at most 256 characters with no spaces (current behavior, may change). |
79| **Scope** | Optional. Space-separated scope words with no quotes or backslashes, at most 256 characters in total (current behavior, may change). |
80| **Allowed API hosts** | Must not include the token endpoint's host. |
81| Token exchange | A form-encoded `POST` that doesn't follow redirects and must complete within about 10 seconds (current behavior, may change). |
82| Access token reuse | Reused until about five minutes before it expires (for tokens shorter than 10 minutes, until half their lifetime has passed) when `expires_in` is between 5 minutes and 1 day. When `expires_in` is missing or shorter, the token is used for one request. When it is longer than a day, the token isn't cached either, so every request goes to the token endpoint. (Current behavior, may change.) |
83| Subject check | Your authorization server performs it; the console has no connection check for token endpoints. The server must accept only your own agents' full subjects, or at minimum check that each token's subject starts with your organization's **Subject prefix**. |
84| Endpoint reuse | A registered address can be connected as a gateway or as an authorization server, not both. A token endpoint stays listed in the **Gateways** table after you remove its authorization server, and frees its place among the 5 registered addresses only when you remove it there too. |
74| Limit | Value |
75| :- | :- |
76| **Token endpoint** | A full HTTPS URL of at most 256 characters (current behavior, may change), with an optional path and no port, query, fragment, user name, password, spaces, or special characters. The same host rules as a gateway address apply, and a trailing slash is dropped. |
77| Token audience | Your authorization server's issuer identifier as you entered it (an HTTPS URL on the same host as the token endpoint, with the same address rules), or the token endpoint URL exactly when you left the issuer identifier empty. It can't be changed after the server is connected. |
78| **Resource** | Optional. An absolute URI with no fragment, at most 256 characters with no spaces (current behavior, may change). |
79| **Scope** | Optional. Space-separated scope words with no quotes or backslashes, at most 256 characters in total (current behavior, may change). |
80| **Allowed API hosts** | Must not include the token endpoint's host. |
81| Token exchange | A form-encoded `POST` that doesn't follow redirects and must complete within about 10 seconds (current behavior, may change). |
82| Access token reuse | Reused until about five minutes before it expires (for tokens shorter than 10 minutes, until half their lifetime has passed) when `expires_in` is between 5 minutes and 1 day. When `expires_in` is missing or shorter, the token is used for one request. When it is longer than a day, the token isn't cached either, so every request goes to the token endpoint. (Current behavior, may change.) |
83| Subject check | Your authorization server performs it; the console has no connection check for token endpoints. The server must accept only your own agents' full subjects, or at minimum check that each token's subject starts with your organization's **Subject prefix**. |
84| Endpoint reuse | A registered address can be connected as a gateway or as an authorization server, not both. A token endpoint stays listed in the **Gateways** table after you remove its authorization server, and frees its place among the 5 registered addresses only when you remove it there too. |
8585
8686## Testing
8787
No line in this hunk matches that.