Identity token reference changedclaude-tag/admins/federated-access/token-reference
Nearest release: v2.1.269, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 11 Sep 2026 23:40 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+28added
Lines−28removed
From line
12
where the diff opens
First seen
10 Sep 2026
this site's first read of the page
Recorded edits4to this page, all time
The whole hunk
from line 12, old and new numbered
/
from line 12
1212
1313## Issuer and signing keys
1414
15| Item | Value |
16| :----------------------------------------- | :------------------------------------------------------------------------------------------------ |
17| Issuer (`iss`) | `https://identity.anthropic.com/agents`. Match it exactly, including the `/agents` path. |
18| OpenID Connect (OIDC) discovery document | `https://identity.anthropic.com/agents/.well-known/openid-configuration` |
15| Item | Value |
16| :- | :- |
17| Issuer (`iss`) | `https://identity.anthropic.com/agents`. Match it exactly, including the `/agents` path. |
18| OpenID Connect (OIDC) discovery document | `https://identity.anthropic.com/agents/.well-known/openid-configuration` |
1919| Signing keys, as a JSON Web Key Set (JWKS) | `https://identity.anthropic.com/agents/jwks.json`, the `jwks_uri` named in the discovery document |
20| Signing algorithm | ES256 only. Reject any other `alg`, including `none`. |
20| Signing algorithm | ES256 only. Reject any other `alg`, including `none`. |
2121
2222Both documents are public and need no authentication to fetch. One issuer serves every Claude Tag organization, so the issuer and signature prove only that Anthropic issued the token. The [subject](#subject), or the `tenant` claim, is what ties a token to your organization.
2323
from line 27
2727
2828## Lifetime
2929
30| Claim | Value |
31| :---- | :---------------------------------------------------------------------------------------- |
32| `iat` | When the token was issued, in seconds since the Unix epoch |
30| Claim | Value |
31| :- | :- |
32| `iat` | When the token was issued, in seconds since the Unix epoch |
3333| `nbf` | 15 seconds before `iat` (current behavior, may change). Libraries check it automatically. |
34| `exp` | 10 minutes (600 seconds) after `iat` |
35| `jti` | A unique ID for this token |
34| `exp` | 10 minutes (600 seconds) after `iat` |
35| `jti` | A unique ID for this token |
3636
3737Allow up to 60 seconds of clock skew when you check `exp`, and treat `exp` as the earliest moment a token may stop working rather than an exact cutoff; cloud providers apply their own grace.
3838
from line 66
6666
6767The `aud` claim is a JSON array with one element. Use your library's audience option rather than comparing the raw claim text; some libraries print a one-element array as a bare string.
6868
69| Where the token goes | `aud` |
70| :---------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
71| A gateway you connected | The HTTPS address you registered, which the console accepts only as a bare host on the standard port and stores in lowercase, for example `https://gateway.example.com` |
72| AWS | `sts.amazonaws.com` |
73| Google Cloud | Your workload identity provider's full resource name, for example `//iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/claude/providers/agents` |
69| Where the token goes | `aud` |
70| :- | :- |
71| A gateway you connected | The HTTPS address you registered, which the console accepts only as a bare host on the standard port and stores in lowercase, for example `https://gateway.example.com` |
72| AWS | `sts.amazonaws.com` |
73| Google Cloud | Your workload identity provider's full resource name, for example `//iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/claude/providers/agents` |
7474| An authorization server | Your server's issuer identifier as you entered it when connecting the server (an HTTPS URL on the token endpoint's host), for example `https://auth.example.com`, or the token endpoint URL exactly as registered, for example `https://auth.example.com/oauth2/token`, if you left the issuer identifier empty |
7575
7676The audience identifies the destination, not your organization; every organization's AWS tokens share `sts.amazonaws.com`. Always check the [subject](#subject) too.
from line 79
7979
8080These are the claims a token carries.
8181
82| Claim | Value |
83| :------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
84| `iss` | `https://identity.anthropic.com/agents` |
85| `sub` | The agent's subject; see [Subject](#subject) |
86| `aud` | One-element array; see [Audience](#audience) |
87| `iat`, `nbf`, `exp` | Issued-at, not-before, and expiry times; see [Lifetime](#lifetime) |
88| `jti` | Unique token ID |
89| `tenant` | Your Claude organization ID, the same value as the subject's `org/` segment. Together with `iss`, this is the pair a relying party pins to trust tokens from one organization. Not your cloud or identity provider's tenant ID. |
90| `agent_id` | The agent ID, the same value as the subject's `agent/` segment |
91| `profile_id` | The ID of the Access bundle the connection belongs to, starting with `capp_`. Informational. |
92| `platform` | `slack` when the request came from Slack. Present whenever `slack_workspace_id` is. |
93| `slack_workspace_id` | The ID of the Slack workspace Claude is acting in. Present when the request came from a Slack workspace your organization owns. |
94| `slack_channel_id` | The ID of the Slack channel Claude is acting in. Present whenever `slack_workspace_id` is and Claude is acting in one channel rather than a whole workspace. |
82| Claim | Value |
83| :- | :- |
84| `iss` | `https://identity.anthropic.com/agents` |
85| `sub` | The agent's subject; see [Subject](#subject) |
86| `aud` | One-element array; see [Audience](#audience) |
87| `iat`, `nbf`, `exp` | Issued-at, not-before, and expiry times; see [Lifetime](#lifetime) |
88| `jti` | Unique token ID |
89| `tenant` | Your Claude organization ID, the same value as the subject's `org/` segment. Together with `iss`, this is the pair a relying party pins to trust tokens from one organization. Not your cloud or identity provider's tenant ID. |
90| `agent_id` | The agent ID, the same value as the subject's `agent/` segment |
91| `profile_id` | The ID of the Access bundle the connection belongs to, starting with `capp_`. Informational. |
92| `platform` | `slack` when the request came from Slack. Present whenever `slack_workspace_id` is. |
93| `slack_workspace_id` | The ID of the Slack workspace Claude is acting in. Present when the request came from a Slack workspace your organization owns. |
94| `slack_channel_id` | The ID of the Slack channel Claude is acting in. Present whenever `slack_workspace_id` is and Claude is acting in one channel rather than a whole workspace. |
9595
9696Tokens may carry additional claims Anthropic uses internally for audit; ignore any claim not listed here and never base an authorization decision on it.
9797
No line in this hunk matches that.