SPB Git forge

spb/doc-api

Public
2commits 1branches 0releases
15.7 MBsize
maindefault branch
13 days agolast push
Python 88.3% TypeScript 7.6% Shell 4.1%
31.0 KB

# Anthropic — Admin API (organizations, members, workspaces, keys, RBAC, WIF, spend limits, usage & cost, rate limits, tunnels, external keys)

Status: DOCUMENTED · LIVE_VERIFIED for GET /v1/organizations/me with a regular API key (HTTP 200) · ACCOUNT_RESTRICTED for every other endpoint probed (21 read-only GETs → 401 authentication_error "The Admin API requires an Admin API key or an organization-scoped API key."); no Admin key is available in this atlas, and no mutation was attempted.
Sources:

Last verified: 2026-09-18


# 1. Authentication model — three credential kinds (and what the SDK env vars mean)

Env var / credential Header Prefix Who/where What it can call
ANTHROPIC_API_KEY — regular API key (workspace-scoped or org-scoped personal key) x-api-key sk-ant-api03-… Console → Settings → API keys Messages, Batches, Files, Skills, Managed Agents, Models… Only GET /v1/organizations/me among Admin endpoints (observed 200). A personal key or service-account key that is not scoped to a workspace ("organization-scoped API key") is documented to work on Admin endpoints with the permissions of the linked account — our key is workspace-scoped, hence 401.
ANTHROPIC_ADMIN_KEY — Admin API key x-api-key sk-ant-admin01-… Console → Settings → Admin keys; only members with the admin role (owners/primary owners) All Admin endpoints except service accounts, federation issuers/rules (OAuth-only). Also Usage & Cost, Claude Code Analytics, Rate Limits, Compliance Activity Feed (read). Claude Enterprise (claude.ai) orgs instead create a scoped key sk-ant-api01-… with scopes read:members, write:members, read:rbac_groups, write:rbac_groups, read:spend_limits, write:spend_limits, read:analytics, read:compliance_*, delete:compliance_*, read:org_audit… (scopes fixed at creation; exceeding them → 403 listing held vs needed scopes).
ANTHROPIC_AUTH_TOKEN — OAuth bearer token Authorization: Bearer … sk-ant-oat01-… ant login --profile admin with scope org:admin (admin/owner/primary owner); also the credential Claude Code and the Agent SDK use for user sessions (claude setup-token), and workload identity federation tokens (workspace:developer, workspace:inference, workspace:manage_tunnels, org:admin) Everything an Admin key can, plus service accounts / federation issuers / federation rules (which reject Admin keys). Federation-minted tokens are scoped by the rule's oauth_scope.

Notes: the SDKs read ANTHROPIC_API_KEY or ANTHROPIC_AUTH_TOKEN in the default client and expose the Admin API as client.beta.organization.* (CLI ant beta:organization …) — the pinned SDK surfaces (sources/anthropic/openapi/{python,node}-sdk-api.md) cover organization/users/invites/workspaces(+members, rate_limits, service_accounts)/api_keys/service_accounts/federation/rate_limits/external_keys/compliance_settings but not usage_report, cost_report, analytics, rbac or spend limits (raw HTTP needed; see sdk field per endpoint in the fragment). anthropic-version: 2023-06-01 is mandatory. Individual (non-organization) accounts cannot use the Admin API. Claude Platform on AWS supports only the workspace and external-key endpoints. Admin endpoints are per-organization rate-limited (documented: 100 req/min; invite creation 1,200/h; spend-limits endpoints 60/min; analytics 60/min).

Observed error body (all restricted endpoints, HTTP 401):

json
{"type":"error","error":{"type":"authentication_error","message":"The Admin API requires an Admin API key or an organization-scoped API key."},"request_id":null}

# 2. Organization roles

Console org role (role on users/invites) Permissions
user playground
claude_code_user playground + Claude Code
developer playground + manage API keys
billing playground + billing
admin all of the above + manage users (owners/primary owners: also manage admins; not assignable via API)
Claude Enterprise roles user, managed (permissions via RBAC groups/custom roles), owner, membership_admin, primary_owner — API can assign only user/managed

Workspace roles (workspace_role): workspace_admin, workspace_billing, workspace_developer, workspace_restricted_developer, workspace_user.

# 3. Endpoints (100)

Legend: LV = LIVE_VERIFIED with regular key · AR = ACCOUNT_RESTRICTED (401 with regular key, needs Admin key / OAuth) · D = documented, not called (mutations or sub-resources; we never mutate).

users (4)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/users List Users after_id, before_id, email, limit, roles — cursor_ids — AR
DELETE /v1/organizations/users/{user_id} Remove User — — — — D
GET /v1/organizations/users/{user_id} Get User — — — — D
POST /v1/organizations/users/{user_id} Update User — json — — D

invites (4)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/invites List Invites after_id, before_id, email, limit, roles, statuses — cursor_ids — AR
POST /v1/organizations/invites Create Invite — json — — D
DELETE /v1/organizations/invites/{invite_id} Delete Invite — — — — D
GET /v1/organizations/invites/{invite_id} Get Invite — — — — D

workspaces (5)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/workspaces List Workspaces after_id, before_id, include_archived, limit — cursor_ids — AR
POST /v1/organizations/workspaces Create Workspace — json — — D
GET /v1/organizations/workspaces/{workspace_id} Get Workspace — — — — D
POST /v1/organizations/workspaces/{workspace_id} Update Workspace — json — — D
POST /v1/organizations/workspaces/{workspace_id}/archive Archive Workspace — — — — D

workspaces › members (5)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/workspaces/{workspace_id}/members List Workspace Members after_id, before_id, limit — cursor_ids — D
POST /v1/organizations/workspaces/{workspace_id}/members Create Workspace Member — json — — D
DELETE /v1/organizations/workspaces/{workspace_id}/members/{user_id} Delete Workspace Member — — — — D
GET /v1/organizations/workspaces/{workspace_id}/members/{user_id} Get Workspace Member — — — — D
POST /v1/organizations/workspaces/{workspace_id}/members/{user_id} Update Workspace Member — json — — D

workspaces › rate_limits (1)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/workspaces/{workspace_id}/rate_limits List Workspace Rate Limits group_type, limit, page — opaque_cursor — D

workspaces › service_accounts (5)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/workspaces/{workspace_id}/service_accounts List Service Account Workspace Members limit, page — opaque_cursor — D
POST /v1/organizations/workspaces/{workspace_id}/service_accounts Create Service Account Workspace Member — json — — D
DELETE /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id} Delete Service Account Workspace Member — — — — D
GET /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id} Get Service Account Workspace Member — — — — D
POST /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id} Update Service Account Workspace Member — json — — D

api_keys (3)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/api_keys List API Keys after_id, before_id, created_by_user_id, limit, status, workspace_id — cursor_ids — AR
GET /v1/organizations/api_keys/{api_key_id} Retrieve API Key (Admin API) — — — — D
POST /v1/organizations/api_keys/{api_key_id} Update API Key — json — — D

service_accounts (8)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/service_accounts List Service Accounts include_archived, limit, page — opaque_cursor — AR
POST /v1/organizations/service_accounts Create Service Account — json — — D
GET /v1/organizations/service_accounts/{service_account_id} Get Service Account — — — — D
POST /v1/organizations/service_accounts/{service_account_id} Update Service Account — json — — D
POST /v1/organizations/service_accounts/{service_account_id}/archive Archive Service Account — — — — D
GET /v1/organizations/service_accounts/{service_account_id}/workspaces List Workspaces For Service Account limit, page — opaque_cursor — D
POST /v1/organizations/service_accounts/{service_account_id}/workspaces Add Workspace To Service Account — json — — D
DELETE /v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id} Remove Workspace From Service Account — — — — D

federation (WIF) (13)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/federation_issuers List Federation Issuers include_archived, limit, page — opaque_cursor — AR
POST /v1/organizations/federation_issuers Create Federation Issuer — json — — D
GET /v1/organizations/federation_issuers/{federation_issuer_id} Get Federation Issuer — — — — D
POST /v1/organizations/federation_issuers/{federation_issuer_id} Update Federation Issuer — json — — D
POST /v1/organizations/federation_issuers/{federation_issuer_id}/archive Archive Federation Issuer — — — — D
GET /v1/organizations/federation_rules List Federation Rules include_archived, issuer_id, limit, page — opaque_cursor — AR
POST /v1/organizations/federation_rules Create Federation Rule — json — — D
GET /v1/organizations/federation_rules/{federation_rule_id} Get Federation Rule — — — — D
POST /v1/organizations/federation_rules/{federation_rule_id} Update Federation Rule — json — — D
POST /v1/organizations/federation_rules/{federation_rule_id}/archive Archive Federation Rule — — — — D
GET /v1/organizations/federation_rules/{federation_rule_id}/workspaces List Federation Rule Workspaces limit, page — opaque_cursor — D
POST /v1/organizations/federation_rules/{federation_rule_id}/workspaces Add Federation Rule Workspace — json — — D
DELETE /v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id} Remove Federation Rule Workspace — — — — D

rbac (11)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/rbac_groups List RBAC Groups limit, page — opaque_cursor — AR
POST /v1/organizations/rbac_groups Create RBAC Group — json — — D
DELETE /v1/organizations/rbac_groups/{group_id} Delete RBAC Group — — — — D
GET /v1/organizations/rbac_groups/{group_id} Get RBAC Group — — — — D
POST /v1/organizations/rbac_groups/{group_id} Update RBAC Group — json — — D
GET /v1/organizations/rbac_groups/{group_id}/members List RBAC Group Members limit, page — opaque_cursor — D
POST /v1/organizations/rbac_groups/{group_id}/members Add RBAC Group Member — json — — D
DELETE /v1/organizations/rbac_groups/{group_id}/members/{user_id} Remove RBAC Group Member — — — — D
GET /v1/organizations/rbac_roles List RBAC Roles limit, page — opaque_cursor — AR
GET /v1/organizations/rbac_roles/{role_id} Get RBAC Role — — — — D
GET /v1/organizations/rbac_roles/{role_id}/permissions List RBAC Role Permissions limit, page — opaque_cursor — D

spend_limits (4)

Method Path Title Path/query params Body Pagination Beta header Status
POST /v1/organizations/spend_limits Set Spend Limit — json — — D
GET /v1/organizations/spend_limits/effective List Effective Spend Limits limit, page, period, user_ids — opaque_cursor — AR
DELETE /v1/organizations/spend_limits/{spend_limit_id} Delete Spend Limit — — — — D
GET /v1/organizations/spend_limits/{spend_limit_id} Get Spend Limit — — — — D

spend_limits › increase_requests (4)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/spend_limit_increase_requests List Spend Limit Increase Requests actor_ids, limit, page, status — opaque_cursor — AR
GET /v1/organizations/spend_limit_increase_requests/{spend_limit_increase_request_id} Get Spend Limit Increase Request — — — — D
POST /v1/organizations/spend_limit_increase_requests/{spend_limit_increase_request_id}/approve Approve Spend Limit Increase Request — json — — D
POST /v1/organizations/spend_limit_increase_requests/{spend_limit_increase_request_id}/deny Deny Spend Limit Increase Request — json — — D

usage & cost reports (3)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/cost_report Get Cost Report starting_at, bucket_width, ending_at, group_by, limit, page — opaque_cursor — AR
GET /v1/organizations/usage_report/claude_code Get Claude Code Usage Report starting_at, limit, page — opaque_cursor — AR
GET /v1/organizations/usage_report/messages Get Messages Usage Report starting_at, account_ids, api_key_ids, bucket_width, context_window, ending_at, group_by, inference_geos, limit, models, page, service_account_ids, service_tiers, speeds, workspace_ids — opaque_cursor — AR

analytics (11)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/analytics/apps/chat/projects Get Chat Project Usage date, ending_date, filter, group_by, limit, order, order_by, page, starting_date — opaque_cursor — D
GET /v1/organizations/analytics/artifacts Get Artifact Activity date, filter, group_by, limit, page — opaque_cursor — D
GET /v1/organizations/analytics/connectors Get Connector Usage date, ending_date, filter, group_by, limit, order, order_by, page, starting_date — opaque_cursor — D
GET /v1/organizations/analytics/cost_report Get Cost Over Time starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, group_by, inference_geos, limit, models, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids — opaque_cursor — D
GET /v1/organizations/analytics/plugins Get Plugin Usage date, ending_date, filter, group_by, limit, order, order_by, page, starting_date — opaque_cursor — D
GET /v1/organizations/analytics/skills Get Skill Usage date, ending_date, filter, group_by, limit, order, order_by, page, starting_date — opaque_cursor — D
GET /v1/organizations/analytics/summaries Get Activity Summaries starting_date, ending_date, filter — — — AR
GET /v1/organizations/analytics/usage_report Get Token Usage Over Time starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, group_by, inference_geos, limit, models, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids — opaque_cursor — AR
GET /v1/organizations/analytics/user_cost_report Get Per-User Cost starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, exclude_deleted_users, group_by, inference_geos, limit, models, order, order_by, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids — opaque_cursor — D
GET /v1/organizations/analytics/user_usage_report Get Per-User Token Usage starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, exclude_deleted_users, group_by, inference_geos, limit, models, order, order_by, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids — opaque_cursor — D
GET /v1/organizations/analytics/users List User Activity date, ending_date, filter, group_by, limit, order, order_by, page, starting_date — opaque_cursor — AR

rate_limits (1)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/rate_limits List Organization Rate Limits group_type, limit, model, page — opaque_cursor — AR

tunnels (9)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/tunnels List Tunnels include_archived, limit, page, workspace_id — opaque_cursor mcp-tunnels-2026-05-19 AR BETA
GET /v1/organizations/tunnels/{tunnel_id} Get Tunnel — — — mcp-tunnels-2026-05-19 D BETA
POST /v1/organizations/tunnels/{tunnel_id}/archive Archive Tunnel — — — mcp-tunnels-2026-05-19 D BETA
GET /v1/organizations/tunnels/{tunnel_id}/certificates List Tunnel Certificates include_archived, limit, page — opaque_cursor mcp-tunnels-2026-05-19 D BETA
POST /v1/organizations/tunnels/{tunnel_id}/certificates Create Tunnel Certificate — json — mcp-tunnels-2026-05-19 D BETA
GET /v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id} Get Tunnel Certificate — — — mcp-tunnels-2026-05-19 D BETA
POST /v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive Archive Tunnel Certificate — — — mcp-tunnels-2026-05-19 D BETA
POST /v1/organizations/tunnels/{tunnel_id}/reveal_token Reveal Tunnel Token — — — mcp-tunnels-2026-05-19 D BETA
POST /v1/organizations/tunnels/{tunnel_id}/rotate_token Rotate Tunnel Token — json — mcp-tunnels-2026-05-19 D BETA

external_keys (6)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/external_keys List External Keys limit, page — opaque_cursor — AR
POST /v1/organizations/external_keys Create External Key — json — — D
DELETE /v1/organizations/external_keys/{external_key_id} Delete External Key — — — — D
GET /v1/organizations/external_keys/{external_key_id} Get External Key — — — — D
POST /v1/organizations/external_keys/{external_key_id} Update External Key — json — — D
POST /v1/organizations/external_keys/{external_key_id}/validate Validate External Key — — — — D

compliance_settings (2)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/compliance_settings Get Compliance Settings — — — — AR
POST /v1/organizations/compliance_settings Update Compliance Settings — json — — D

me (1)

Method Path Title Path/query params Body Pagination Beta header Status
GET /v1/organizations/me Get Current Organization — — — — LV

# Pagination styles

  • ID cursors (limit 1–1000 default 20, before_id / after_id; response data, has_more, first_id, last_id): users, invites, workspaces, workspace members, api_keys.
  • Opaque cursor (limit, page = previous next_page): rbac_groups/roles, service accounts, federation issuers/rules (limit ≤ 100), spend limits, usage/cost reports (limit = number of time buckets), analytics, tunnels, external keys. Cursors are bound to the query filters (changing filters + old cursor → 400).
  • Bracket lists: repeat param[]=v (group_by[]=model&group_by[]=workspace_id, user_ids[]=…).

# 4. Resources & objects (summary — full field lists in generated/fragments/objects/anthropic-platform-objects.json)

Object Key fields Notes
organization id, name observed: {"id":"6fcc8f83-…","type":"organization","name":"AgentiLab"}
user id, email, name, role, added_at POST /users/{id} changes role; DELETE removes (never run)
invite id, email, role, status (pending/accepted/expired/deleted), invited_at, expires_at, accepted_at, rbac_group_ids[] expiry server-assigned; pending invite consumes a seat (Enterprise)
workspace id, name, display_color, created_at, archived_at, compartment_id, external_key_id, tags{}, data_residency{workspace_geo:"us", default_inference_geo: global|us, allowed_inference_geos[]} default workspace = workspace_id: null in reports; POST /workspaces/{id}/archive
workspace_member user_id, workspace_id, workspace_role add/update/remove
api_key id, name, status (active/inactive/archived/expired), partial_key_hint, created_at, expires_at, created_by{type:user|service_account,id}, principal{user_actor|service_account_actor}, scope{organization|workspace(workspace_id)}, workspace_id list filters status, workspace_id, created_by_user_id; update = rename/status (no creation, no secret retrieval via API)
service_account id, name, description, organization_role (admin|developer), archived_at, *_by_actor_id OAuth org:admin only; workspaces attached via /service_accounts/{id}/workspaces and /workspaces/{id}/service_accounts
federation_issuer id, name, issuer_url, jwks{discovery|explicit_url|inline}, check_jti, max_jwt_lifetime_seconds, poll_status, jwks_polling_disabled_at WIF: external OIDC issuer (GitHub Actions, GCP, AWS…)
federation_rule id, name, issuer_id, match{subject_prefix, audience, claims{}, condition}, target{type:service_account, service_account_id}, oauth_scope, token_lifetime_seconds, applies_to_all_workspaces, workspace_ids[], attributes{} maps external JWTs → short-lived Anthropic OAuth tokens; OAuth callers may only create rules with workspace:developer/workspace:inference; archive is a soft delete (400 while a live rule references the issuer/service account)
rbac_group / rbac_role group: id, name, roles[], source_type (direct|scim); role: id, name; /rbac_roles/{id}/permissions lists permission strings Claude Enterprise only (read:rbac_groups…)
spend_limit id, amount (string, cents; null = unlimited), currency, period (monthly today; daily/weekly reserved), scope{user|seat_tier|rbac_group|organization|organization_service|workspace} GET /spend_limits/effective = per-member resolved limit + source + period_to_date_spend; POST /spend_limits sets a per-user override; DELETE removes it
spend_limit_increase_request id, actor, period, status (pending/approved/denied), spend_summary, resolved_at, resolved_by created by members in claude.ai; /approve (writes the same row as POST spend_limits) and /deny accept suppress_notification
rate_limit id, group_type (model_group/batch/files/skills/token_count/web_search), models[], limits[{type, value}] (requests_per_minute, input_tokens_per_minute, output_tokens_per_minute…) org level /rate_limits, workspace overrides /workspaces/{id}/rate_limits; read-only (?model= lookup 404 if unknown)
tunnel (admin view) id, domain, display_name, workspace_id, archived_at; certificates; reveal_token/rotate_token MCP tunnels (beta mcp-tunnels-2026-06-22) — pairs with /v1/tunnels in Managed Agents
external_key id, display_name, geo, provider_config{aws(kms_arn, region, role_arn)|gcp(key_name)|azure(key_name, tenant_id, vault_uri, client_id)}, attachment{attached|unattached} customer-managed encryption keys (CMEK); /validate (not on Claude Platform on AWS)
compliance_settings state{type: enabled|disabled} toggles the Compliance API for the org

# 5. Usage & cost reports (cookbook)

Endpoint Required Granularity / limits Grouping & filters Notes
GET /v1/organizations/usage_report/messages starting_at (RFC 3339) bucket_width 1m (default 60, max 1,440 buckets) / 1h (24 / 168) / 1d (7 / 31) group_by[]: account_id, api_key_id, workspace_id, model, service_tier, context_window, inference_geo, service_account_id, speed (needs beta fast-mode-2026-02-01); filters models[], service_tiers[] (standard, batch, priority, priority_on_demand, flex, flex_discount), context_window[] (0-200k, 200k-1M), inference_geos[] (global, us, not_available), speeds[], api_key_ids[], workspace_ids[], account_ids[], service_account_ids[] per bucket results[] with uncached_input_tokens, cache_creation (5m/1h), cache_read_input_tokens, output_tokens, server_tool_use (web search…), plus the group keys. Data within ~5 min; poll ≤ 1/min. Code execution is not in usage — see cost. Priority Tier only here.
GET /v1/organizations/cost_report starting_at bucket_width 1d only; limit 1–31 (default 7) group_by[]: workspace_id, description (adds parsed model, inference_geo, cost_type token/web_search/code_execution) amounts = decimal strings in cents ("41280.000000" = $412.80); Priority Tier excluded; default workspace → workspace_id: null
GET /v1/organizations/usage_report/claude_code starting_at (YYYY-MM-DD) one day per call; limit ≤ 1000 — see docs/anthropic/claude-code-analytics.md
GET /v1/organizations/analytics/* Analytics API key (Enterprise) see analytics doc
bash
# last 7 days by model and service tier (Admin key)
curl -sS "https://api.anthropic.com/v1/organizations/usage_report/messages?starting_at=$(date -u -v-7d +%FT00:00:00Z)&bucket_width=1d&group_by[]=model&group_by[]=service_tier" \
  -H "x-api-key: $ANTHROPIC_ADMIN_KEY" -H "anthropic-version: 2023-06-01"
# daily cost by workspace
curl -sS "https://api.anthropic.com/v1/organizations/cost_report?starting_at=$(date -u -v-7d +%FT00:00:00Z)&group_by[]=workspace_id" \
  -H "x-api-key: $ANTHROPIC_ADMIN_KEY" -H "anthropic-version: 2023-06-01"

Loop on next_page until null. Stable results: pass ending_at ≤ data_refreshed_at (analytics) / avoid the last few minutes (usage).

# 6. Live probe log (2026-09-18, regular workspace key, read-only)

Endpoint HTTP Status
GET /v1/organizations/me 200 {"id":"…","type":"organization","name":"…"} LIVE_VERIFIED (the only Admin endpoint open to a regular key)
GET /users?limit=1, /invites?limit=1, /workspaces?limit=1, /api_keys?limit=1, /service_accounts?limit=1, /rbac_roles, /rbac_groups?limit=1, /federation_issuers?limit=1, /federation_rules?limit=1, /spend_limits/effective?limit=1, /spend_limit_increase_requests?limit=1, /rate_limits?limit=1, /usage_report/messages?starting_at=…&limit=1, /cost_report?starting_at=…&limit=1, /usage_report/claude_code?starting_at=…&limit=1, /analytics/usage_report?…, /analytics/summaries?…, /analytics/users?…, /external_keys?limit=1, /compliance_settings, /tunnels?limit=1 (beta mcp-tunnels-2026-06-22) 401 authentication_error ACCOUNT_RESTRICTED

Interesting response headers on the 200: anthropic-organization-id: <org uuid>, request-id: req_…. No mutations were performed. Examples: examples/anthropic/admin/ · tests: tests/anthropic/test_admin.py (org-me unmarked; the rest behind run_admin_tests + ANTHROPIC_ADMIN_KEY).

# 7. Gotchas

  • 401 (not 403) is returned when the key kind is wrong; 403 lists missing scopes for Enterprise scoped keys.
  • Service accounts and federation endpoints refuse Admin keys entirely → need ANTHROPIC_AUTH_TOKEN with org:admin.
  • API keys cannot be created or have their secret read through the Admin API (Console only); update = name/status.
  • Money is always a string of minor units; amount: null means unlimited on effective spend-limit rows.
  • Usage and cost endpoints have different freshness/granularity; the usage endpoint excludes code execution cost, the cost endpoint excludes Priority Tier.
  • anthropic-organization-id appears in response headers of regular API calls too — handy to confirm which org a key belongs to without Admin access.