Anthropic — Admin API (organizations, members, workspaces, keys, RBAC, WIF, spend limits, usage & cost, rate limits, tunnels, external keys)
Status: DOCUMENTED · LIVE_VERIFIED for GET /v1/organizations/me with a regular API key (HTTP 200) · ACCOUNT_RESTRICTED for every other endpoint probed (21 read-only GETs → 401 authentication_error "The Admin API requires an Admin API key or an organization-scoped API key."); no Admin key is available in this atlas, and no mutation was attempted.
Sources:
- https://platform.claude.com/docs/en/manage-claude/admin-api · /admin-api-keys · /wif-admin-api · /user-management · /spend-limits-api · /usage-cost-api · /rate-limits-api · /claude-code-analytics-api · /analytics-api · /workspaces
- Reference: https://platform.claude.com/docs/en/api/admin (100 endpoints under
/v1/organizations/**; beta-typed twins under/api/beta/organization/**) - Live probes:
tmp-live/platform-anthropic/admin-probes.json,reports/live-requests.jsonl
Last verified: 2026-09-18
1. Authentication model — three credential kinds (and what the SDK env vars mean)
| Env var / credential | Header | Prefix | Who/where | What it can call |
|---|---|---|---|---|
ANTHROPIC_API_KEY — regular API key (workspace-scoped or org-scoped personal key) |
x-api-key |
sk-ant-api03-… |
Console → Settings → API keys | Messages, Batches, Files, Skills, Managed Agents, Models… Only GET /v1/organizations/me among Admin endpoints (observed 200). A personal key or service-account key that is not scoped to a workspace ("organization-scoped API key") is documented to work on Admin endpoints with the permissions of the linked account — our key is workspace-scoped, hence 401. |
ANTHROPIC_ADMIN_KEY — Admin API key |
x-api-key |
sk-ant-admin01-… |
Console → Settings → Admin keys; only members with the admin role (owners/primary owners) | All Admin endpoints except service accounts, federation issuers/rules (OAuth-only). Also Usage & Cost, Claude Code Analytics, Rate Limits, Compliance Activity Feed (read). Claude Enterprise (claude.ai) orgs instead create a scoped key sk-ant-api01-… with scopes read:members, write:members, read:rbac_groups, write:rbac_groups, read:spend_limits, write:spend_limits, read:analytics, read:compliance_*, delete:compliance_*, read:org_audit… (scopes fixed at creation; exceeding them → 403 listing held vs needed scopes). |
ANTHROPIC_AUTH_TOKEN — OAuth bearer token |
Authorization: Bearer … |
sk-ant-oat01-… |
ant login --profile admin with scope org:admin (admin/owner/primary owner); also the credential Claude Code and the Agent SDK use for user sessions (claude setup-token), and workload identity federation tokens (workspace:developer, workspace:inference, workspace:manage_tunnels, org:admin) |
Everything an Admin key can, plus service accounts / federation issuers / federation rules (which reject Admin keys). Federation-minted tokens are scoped by the rule's oauth_scope. |
Notes: the SDKs read ANTHROPIC_API_KEY or ANTHROPIC_AUTH_TOKEN in the default client and expose the Admin API as client.beta.organization.* (CLI ant beta:organization …) — the pinned SDK surfaces (sources/anthropic/openapi/{python,node}-sdk-api.md) cover organization/users/invites/workspaces(+members, rate_limits, service_accounts)/api_keys/service_accounts/federation/rate_limits/external_keys/compliance_settings but not usage_report, cost_report, analytics, rbac or spend limits (raw HTTP needed; see sdk field per endpoint in the fragment). anthropic-version: 2023-06-01 is mandatory. Individual (non-organization) accounts cannot use the Admin API. Claude Platform on AWS supports only the workspace and external-key endpoints. Admin endpoints are per-organization rate-limited (documented: 100 req/min; invite creation 1,200/h; spend-limits endpoints 60/min; analytics 60/min).
Observed error body (all restricted endpoints, HTTP 401):
{"type":"error","error":{"type":"authentication_error","message":"The Admin API requires an Admin API key or an organization-scoped API key."},"request_id":null}2. Organization roles
Console org role (role on users/invites) |
Permissions |
|---|---|
user |
playground |
claude_code_user |
playground + Claude Code |
developer |
playground + manage API keys |
billing |
playground + billing |
admin |
all of the above + manage users (owners/primary owners: also manage admins; not assignable via API) |
| Claude Enterprise roles | user, managed (permissions via RBAC groups/custom roles), owner, membership_admin, primary_owner — API can assign only user/managed |
Workspace roles (workspace_role): workspace_admin, workspace_billing, workspace_developer, workspace_restricted_developer, workspace_user.
3. Endpoints (100)
Legend: LV = LIVE_VERIFIED with regular key · AR = ACCOUNT_RESTRICTED (401 with regular key, needs Admin key / OAuth) · D = documented, not called (mutations or sub-resources; we never mutate).
users (4)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/users |
List Users | after_id, before_id, email, limit, roles | — | cursor_ids | — | AR |
DELETE |
/v1/organizations/users/{user_id} |
Remove User | — | — | — | — | D |
GET |
/v1/organizations/users/{user_id} |
Get User | — | — | — | — | D |
POST |
/v1/organizations/users/{user_id} |
Update User | — | json | — | — | D |
invites (4)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/invites |
List Invites | after_id, before_id, email, limit, roles, statuses | — | cursor_ids | — | AR |
POST |
/v1/organizations/invites |
Create Invite | — | json | — | — | D |
DELETE |
/v1/organizations/invites/{invite_id} |
Delete Invite | — | — | — | — | D |
GET |
/v1/organizations/invites/{invite_id} |
Get Invite | — | — | — | — | D |
workspaces (5)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/workspaces |
List Workspaces | after_id, before_id, include_archived, limit | — | cursor_ids | — | AR |
POST |
/v1/organizations/workspaces |
Create Workspace | — | json | — | — | D |
GET |
/v1/organizations/workspaces/{workspace_id} |
Get Workspace | — | — | — | — | D |
POST |
/v1/organizations/workspaces/{workspace_id} |
Update Workspace | — | json | — | — | D |
POST |
/v1/organizations/workspaces/{workspace_id}/archive |
Archive Workspace | — | — | — | — | D |
workspaces › members (5)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/workspaces/{workspace_id}/members |
List Workspace Members | after_id, before_id, limit | — | cursor_ids | — | D |
POST |
/v1/organizations/workspaces/{workspace_id}/members |
Create Workspace Member | — | json | — | — | D |
DELETE |
/v1/organizations/workspaces/{workspace_id}/members/{user_id} |
Delete Workspace Member | — | — | — | — | D |
GET |
/v1/organizations/workspaces/{workspace_id}/members/{user_id} |
Get Workspace Member | — | — | — | — | D |
POST |
/v1/organizations/workspaces/{workspace_id}/members/{user_id} |
Update Workspace Member | — | json | — | — | D |
workspaces › rate_limits (1)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/workspaces/{workspace_id}/rate_limits |
List Workspace Rate Limits | group_type, limit, page | — | opaque_cursor | — | D |
workspaces › service_accounts (5)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/workspaces/{workspace_id}/service_accounts |
List Service Account Workspace Members | limit, page | — | opaque_cursor | — | D |
POST |
/v1/organizations/workspaces/{workspace_id}/service_accounts |
Create Service Account Workspace Member | — | json | — | — | D |
DELETE |
/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id} |
Delete Service Account Workspace Member | — | — | — | — | D |
GET |
/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id} |
Get Service Account Workspace Member | — | — | — | — | D |
POST |
/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id} |
Update Service Account Workspace Member | — | json | — | — | D |
api_keys (3)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/api_keys |
List API Keys | after_id, before_id, created_by_user_id, limit, status, workspace_id | — | cursor_ids | — | AR |
GET |
/v1/organizations/api_keys/{api_key_id} |
Retrieve API Key (Admin API) | — | — | — | — | D |
POST |
/v1/organizations/api_keys/{api_key_id} |
Update API Key | — | json | — | — | D |
service_accounts (8)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/service_accounts |
List Service Accounts | include_archived, limit, page | — | opaque_cursor | — | AR |
POST |
/v1/organizations/service_accounts |
Create Service Account | — | json | — | — | D |
GET |
/v1/organizations/service_accounts/{service_account_id} |
Get Service Account | — | — | — | — | D |
POST |
/v1/organizations/service_accounts/{service_account_id} |
Update Service Account | — | json | — | — | D |
POST |
/v1/organizations/service_accounts/{service_account_id}/archive |
Archive Service Account | — | — | — | — | D |
GET |
/v1/organizations/service_accounts/{service_account_id}/workspaces |
List Workspaces For Service Account | limit, page | — | opaque_cursor | — | D |
POST |
/v1/organizations/service_accounts/{service_account_id}/workspaces |
Add Workspace To Service Account | — | json | — | — | D |
DELETE |
/v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id} |
Remove Workspace From Service Account | — | — | — | — | D |
federation (WIF) (13)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/federation_issuers |
List Federation Issuers | include_archived, limit, page | — | opaque_cursor | — | AR |
POST |
/v1/organizations/federation_issuers |
Create Federation Issuer | — | json | — | — | D |
GET |
/v1/organizations/federation_issuers/{federation_issuer_id} |
Get Federation Issuer | — | — | — | — | D |
POST |
/v1/organizations/federation_issuers/{federation_issuer_id} |
Update Federation Issuer | — | json | — | — | D |
POST |
/v1/organizations/federation_issuers/{federation_issuer_id}/archive |
Archive Federation Issuer | — | — | — | — | D |
GET |
/v1/organizations/federation_rules |
List Federation Rules | include_archived, issuer_id, limit, page | — | opaque_cursor | — | AR |
POST |
/v1/organizations/federation_rules |
Create Federation Rule | — | json | — | — | D |
GET |
/v1/organizations/federation_rules/{federation_rule_id} |
Get Federation Rule | — | — | — | — | D |
POST |
/v1/organizations/federation_rules/{federation_rule_id} |
Update Federation Rule | — | json | — | — | D |
POST |
/v1/organizations/federation_rules/{federation_rule_id}/archive |
Archive Federation Rule | — | — | — | — | D |
GET |
/v1/organizations/federation_rules/{federation_rule_id}/workspaces |
List Federation Rule Workspaces | limit, page | — | opaque_cursor | — | D |
POST |
/v1/organizations/federation_rules/{federation_rule_id}/workspaces |
Add Federation Rule Workspace | — | json | — | — | D |
DELETE |
/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id} |
Remove Federation Rule Workspace | — | — | — | — | D |
rbac (11)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/rbac_groups |
List RBAC Groups | limit, page | — | opaque_cursor | — | AR |
POST |
/v1/organizations/rbac_groups |
Create RBAC Group | — | json | — | — | D |
DELETE |
/v1/organizations/rbac_groups/{group_id} |
Delete RBAC Group | — | — | — | — | D |
GET |
/v1/organizations/rbac_groups/{group_id} |
Get RBAC Group | — | — | — | — | D |
POST |
/v1/organizations/rbac_groups/{group_id} |
Update RBAC Group | — | json | — | — | D |
GET |
/v1/organizations/rbac_groups/{group_id}/members |
List RBAC Group Members | limit, page | — | opaque_cursor | — | D |
POST |
/v1/organizations/rbac_groups/{group_id}/members |
Add RBAC Group Member | — | json | — | — | D |
DELETE |
/v1/organizations/rbac_groups/{group_id}/members/{user_id} |
Remove RBAC Group Member | — | — | — | — | D |
GET |
/v1/organizations/rbac_roles |
List RBAC Roles | limit, page | — | opaque_cursor | — | AR |
GET |
/v1/organizations/rbac_roles/{role_id} |
Get RBAC Role | — | — | — | — | D |
GET |
/v1/organizations/rbac_roles/{role_id}/permissions |
List RBAC Role Permissions | limit, page | — | opaque_cursor | — | D |
spend_limits (4)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
POST |
/v1/organizations/spend_limits |
Set Spend Limit | — | json | — | — | D |
GET |
/v1/organizations/spend_limits/effective |
List Effective Spend Limits | limit, page, period, user_ids | — | opaque_cursor | — | AR |
DELETE |
/v1/organizations/spend_limits/{spend_limit_id} |
Delete Spend Limit | — | — | — | — | D |
GET |
/v1/organizations/spend_limits/{spend_limit_id} |
Get Spend Limit | — | — | — | — | D |
spend_limits › increase_requests (4)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/spend_limit_increase_requests |
List Spend Limit Increase Requests | actor_ids, limit, page, status | — | opaque_cursor | — | AR |
GET |
/v1/organizations/spend_limit_increase_requests/{spend_limit_increase_request_id} |
Get Spend Limit Increase Request | — | — | — | — | D |
POST |
/v1/organizations/spend_limit_increase_requests/{spend_limit_increase_request_id}/approve |
Approve Spend Limit Increase Request | — | json | — | — | D |
POST |
/v1/organizations/spend_limit_increase_requests/{spend_limit_increase_request_id}/deny |
Deny Spend Limit Increase Request | — | json | — | — | D |
usage & cost reports (3)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/cost_report |
Get Cost Report | starting_at, bucket_width, ending_at, group_by, limit, page | — | opaque_cursor | — | AR |
GET |
/v1/organizations/usage_report/claude_code |
Get Claude Code Usage Report | starting_at, limit, page | — | opaque_cursor | — | AR |
GET |
/v1/organizations/usage_report/messages |
Get Messages Usage Report | starting_at, account_ids, api_key_ids, bucket_width, context_window, ending_at, group_by, inference_geos, limit, models, page, service_account_ids, service_tiers, speeds, workspace_ids | — | opaque_cursor | — | AR |
analytics (11)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/analytics/apps/chat/projects |
Get Chat Project Usage | date, ending_date, filter, group_by, limit, order, order_by, page, starting_date | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/artifacts |
Get Artifact Activity | date, filter, group_by, limit, page | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/connectors |
Get Connector Usage | date, ending_date, filter, group_by, limit, order, order_by, page, starting_date | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/cost_report |
Get Cost Over Time | starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, group_by, inference_geos, limit, models, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/plugins |
Get Plugin Usage | date, ending_date, filter, group_by, limit, order, order_by, page, starting_date | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/skills |
Get Skill Usage | date, ending_date, filter, group_by, limit, order, order_by, page, starting_date | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/summaries |
Get Activity Summaries | starting_date, ending_date, filter | — | — | — | AR |
GET |
/v1/organizations/analytics/usage_report |
Get Token Usage Over Time | starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, group_by, inference_geos, limit, models, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids | — | opaque_cursor | — | AR |
GET |
/v1/organizations/analytics/user_cost_report |
Get Per-User Cost | starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, exclude_deleted_users, group_by, inference_geos, limit, models, order, order_by, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/user_usage_report |
Get Per-User Token Usage | starting_at, bucket_width, claude_tag_categories, claude_tag_user_ids, context_windows, ending_at, exclude_deleted_users, group_by, inference_geos, limit, models, order, order_by, page, products, rbac_group_ids, slack_channel_ids, speeds, user_ids | — | opaque_cursor | — | D |
GET |
/v1/organizations/analytics/users |
List User Activity | date, ending_date, filter, group_by, limit, order, order_by, page, starting_date | — | opaque_cursor | — | AR |
rate_limits (1)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/rate_limits |
List Organization Rate Limits | group_type, limit, model, page | — | opaque_cursor | — | AR |
tunnels (9)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/tunnels |
List Tunnels | include_archived, limit, page, workspace_id | — | opaque_cursor | mcp-tunnels-2026-05-19 | AR BETA |
GET |
/v1/organizations/tunnels/{tunnel_id} |
Get Tunnel | — | — | — | mcp-tunnels-2026-05-19 | D BETA |
POST |
/v1/organizations/tunnels/{tunnel_id}/archive |
Archive Tunnel | — | — | — | mcp-tunnels-2026-05-19 | D BETA |
GET |
/v1/organizations/tunnels/{tunnel_id}/certificates |
List Tunnel Certificates | include_archived, limit, page | — | opaque_cursor | mcp-tunnels-2026-05-19 | D BETA |
POST |
/v1/organizations/tunnels/{tunnel_id}/certificates |
Create Tunnel Certificate | — | json | — | mcp-tunnels-2026-05-19 | D BETA |
GET |
/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id} |
Get Tunnel Certificate | — | — | — | mcp-tunnels-2026-05-19 | D BETA |
POST |
/v1/organizations/tunnels/{tunnel_id}/certificates/{certificate_id}/archive |
Archive Tunnel Certificate | — | — | — | mcp-tunnels-2026-05-19 | D BETA |
POST |
/v1/organizations/tunnels/{tunnel_id}/reveal_token |
Reveal Tunnel Token | — | — | — | mcp-tunnels-2026-05-19 | D BETA |
POST |
/v1/organizations/tunnels/{tunnel_id}/rotate_token |
Rotate Tunnel Token | — | json | — | mcp-tunnels-2026-05-19 | D BETA |
external_keys (6)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/external_keys |
List External Keys | limit, page | — | opaque_cursor | — | AR |
POST |
/v1/organizations/external_keys |
Create External Key | — | json | — | — | D |
DELETE |
/v1/organizations/external_keys/{external_key_id} |
Delete External Key | — | — | — | — | D |
GET |
/v1/organizations/external_keys/{external_key_id} |
Get External Key | — | — | — | — | D |
POST |
/v1/organizations/external_keys/{external_key_id} |
Update External Key | — | json | — | — | D |
POST |
/v1/organizations/external_keys/{external_key_id}/validate |
Validate External Key | — | — | — | — | D |
compliance_settings (2)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/compliance_settings |
Get Compliance Settings | — | — | — | — | AR |
POST |
/v1/organizations/compliance_settings |
Update Compliance Settings | — | json | — | — | D |
me (1)
| Method | Path | Title | Path/query params | Body | Pagination | Beta header | Status |
|---|---|---|---|---|---|---|---|
GET |
/v1/organizations/me |
Get Current Organization | — | — | — | — | LV |
Pagination styles
- ID cursors (
limit1–1000 default 20,before_id/after_id; responsedata, has_more, first_id, last_id): users, invites, workspaces, workspace members, api_keys. - Opaque cursor (
limit,page= previousnext_page): rbac_groups/roles, service accounts, federation issuers/rules (limit ≤ 100), spend limits, usage/cost reports (limit= number of time buckets), analytics, tunnels, external keys. Cursors are bound to the query filters (changing filters + old cursor → 400). - Bracket lists: repeat
param[]=v(group_by[]=model&group_by[]=workspace_id,user_ids[]=…).
4. Resources & objects (summary — full field lists in generated/fragments/objects/anthropic-platform-objects.json)
| Object | Key fields | Notes |
|---|---|---|
organization |
id, name |
observed: {"id":"6fcc8f83-…","type":"organization","name":"AgentiLab"} |
user |
id, email, name, role, added_at |
POST /users/{id} changes role; DELETE removes (never run) |
invite |
id, email, role, status (pending/accepted/expired/deleted), invited_at, expires_at, accepted_at, rbac_group_ids[] |
expiry server-assigned; pending invite consumes a seat (Enterprise) |
workspace |
id, name, display_color, created_at, archived_at, compartment_id, external_key_id, tags{}, data_residency{workspace_geo:"us", default_inference_geo: global|us, allowed_inference_geos[]} |
default workspace = workspace_id: null in reports; POST /workspaces/{id}/archive |
workspace_member |
user_id, workspace_id, workspace_role |
add/update/remove |
api_key |
id, name, status (active/inactive/archived/expired), partial_key_hint, created_at, expires_at, created_by{type:user|service_account,id}, principal{user_actor|service_account_actor}, scope{organization|workspace(workspace_id)}, workspace_id |
list filters status, workspace_id, created_by_user_id; update = rename/status (no creation, no secret retrieval via API) |
service_account |
id, name, description, organization_role (admin|developer), archived_at, *_by_actor_id |
OAuth org:admin only; workspaces attached via /service_accounts/{id}/workspaces and /workspaces/{id}/service_accounts |
federation_issuer |
id, name, issuer_url, jwks{discovery|explicit_url|inline}, check_jti, max_jwt_lifetime_seconds, poll_status, jwks_polling_disabled_at |
WIF: external OIDC issuer (GitHub Actions, GCP, AWS…) |
federation_rule |
id, name, issuer_id, match{subject_prefix, audience, claims{}, condition}, target{type:service_account, service_account_id}, oauth_scope, token_lifetime_seconds, applies_to_all_workspaces, workspace_ids[], attributes{} |
maps external JWTs → short-lived Anthropic OAuth tokens; OAuth callers may only create rules with workspace:developer/workspace:inference; archive is a soft delete (400 while a live rule references the issuer/service account) |
rbac_group / rbac_role |
group: id, name, roles[], source_type (direct|scim); role: id, name; /rbac_roles/{id}/permissions lists permission strings |
Claude Enterprise only (read:rbac_groups…) |
spend_limit |
id, amount (string, cents; null = unlimited), currency, period (monthly today; daily/weekly reserved), scope{user|seat_tier|rbac_group|organization|organization_service|workspace} |
GET /spend_limits/effective = per-member resolved limit + source + period_to_date_spend; POST /spend_limits sets a per-user override; DELETE removes it |
spend_limit_increase_request |
id, actor, period, status (pending/approved/denied), spend_summary, resolved_at, resolved_by |
created by members in claude.ai; /approve (writes the same row as POST spend_limits) and /deny accept suppress_notification |
rate_limit |
id, group_type (model_group/batch/files/skills/token_count/web_search), models[], limits[{type, value}] (requests_per_minute, input_tokens_per_minute, output_tokens_per_minute…) |
org level /rate_limits, workspace overrides /workspaces/{id}/rate_limits; read-only (?model= lookup 404 if unknown) |
tunnel (admin view) |
id, domain, display_name, workspace_id, archived_at; certificates; reveal_token/rotate_token |
MCP tunnels (beta mcp-tunnels-2026-06-22) — pairs with /v1/tunnels in Managed Agents |
external_key |
id, display_name, geo, provider_config{aws(kms_arn, region, role_arn)|gcp(key_name)|azure(key_name, tenant_id, vault_uri, client_id)}, attachment{attached|unattached} |
customer-managed encryption keys (CMEK); /validate (not on Claude Platform on AWS) |
compliance_settings |
state{type: enabled|disabled} |
toggles the Compliance API for the org |
5. Usage & cost reports (cookbook)
| Endpoint | Required | Granularity / limits | Grouping & filters | Notes |
|---|---|---|---|---|
GET /v1/organizations/usage_report/messages |
starting_at (RFC 3339) |
bucket_width 1m (default 60, max 1,440 buckets) / 1h (24 / 168) / 1d (7 / 31) |
group_by[]: account_id, api_key_id, workspace_id, model, service_tier, context_window, inference_geo, service_account_id, speed (needs beta fast-mode-2026-02-01); filters models[], service_tiers[] (standard, batch, priority, priority_on_demand, flex, flex_discount), context_window[] (0-200k, 200k-1M), inference_geos[] (global, us, not_available), speeds[], api_key_ids[], workspace_ids[], account_ids[], service_account_ids[] |
per bucket results[] with uncached_input_tokens, cache_creation (5m/1h), cache_read_input_tokens, output_tokens, server_tool_use (web search…), plus the group keys. Data within ~5 min; poll ≤ 1/min. Code execution is not in usage — see cost. Priority Tier only here. |
GET /v1/organizations/cost_report |
starting_at |
bucket_width 1d only; limit 1–31 (default 7) |
group_by[]: workspace_id, description (adds parsed model, inference_geo, cost_type token/web_search/code_execution) |
amounts = decimal strings in cents ("41280.000000" = $412.80); Priority Tier excluded; default workspace → workspace_id: null |
GET /v1/organizations/usage_report/claude_code |
starting_at (YYYY-MM-DD) |
one day per call; limit ≤ 1000 |
— | see docs/anthropic/claude-code-analytics.md |
GET /v1/organizations/analytics/* |
Analytics API key (Enterprise) | see analytics doc |
# last 7 days by model and service tier (Admin key)
curl -sS "https://api.anthropic.com/v1/organizations/usage_report/messages?starting_at=$(date -u -v-7d +%FT00:00:00Z)&bucket_width=1d&group_by[]=model&group_by[]=service_tier" \
-H "x-api-key: $ANTHROPIC_ADMIN_KEY" -H "anthropic-version: 2023-06-01"
# daily cost by workspace
curl -sS "https://api.anthropic.com/v1/organizations/cost_report?starting_at=$(date -u -v-7d +%FT00:00:00Z)&group_by[]=workspace_id" \
-H "x-api-key: $ANTHROPIC_ADMIN_KEY" -H "anthropic-version: 2023-06-01"Loop on next_page until null. Stable results: pass ending_at ≤ data_refreshed_at (analytics) / avoid the last few minutes (usage).
6. Live probe log (2026-09-18, regular workspace key, read-only)
| Endpoint | HTTP | Status |
|---|---|---|
GET /v1/organizations/me |
200 {"id":"…","type":"organization","name":"…"} |
LIVE_VERIFIED (the only Admin endpoint open to a regular key) |
GET /users?limit=1, /invites?limit=1, /workspaces?limit=1, /api_keys?limit=1, /service_accounts?limit=1, /rbac_roles, /rbac_groups?limit=1, /federation_issuers?limit=1, /federation_rules?limit=1, /spend_limits/effective?limit=1, /spend_limit_increase_requests?limit=1, /rate_limits?limit=1, /usage_report/messages?starting_at=…&limit=1, /cost_report?starting_at=…&limit=1, /usage_report/claude_code?starting_at=…&limit=1, /analytics/usage_report?…, /analytics/summaries?…, /analytics/users?…, /external_keys?limit=1, /compliance_settings, /tunnels?limit=1 (beta mcp-tunnels-2026-06-22) |
401 authentication_error |
ACCOUNT_RESTRICTED |
Interesting response headers on the 200: anthropic-organization-id: <org uuid>, request-id: req_…. No mutations were performed. Examples: examples/anthropic/admin/ · tests: tests/anthropic/test_admin.py (org-me unmarked; the rest behind run_admin_tests + ANTHROPIC_ADMIN_KEY).
7. Gotchas
- 401 (not 403) is returned when the key kind is wrong; 403 lists missing scopes for Enterprise scoped keys.
- Service accounts and federation endpoints refuse Admin keys entirely → need
ANTHROPIC_AUTH_TOKENwithorg:admin. - API keys cannot be created or have their secret read through the Admin API (Console only); update = name/status.
- Money is always a string of minor units;
amount: nullmeans unlimited on effective spend-limit rows. - Usage and cost endpoints have different freshness/granularity; the usage endpoint excludes code execution cost, the cost endpoint excludes Priority Tier.
anthropic-organization-idappears in response headers of regular API calls too — handy to confirm which org a key belongs to without Admin access.