SPB Git forge

spb/doc-api

Public
2commits 1branches 0releases
15.7 MBsize
maindefault branch
13 days agolast push
Python 88.3% TypeScript 7.6% Shell 4.1%
73.6 KB

# Anthropic — Compliance API, Admin compliance settings, Claude Platform on AWS IAM, regions & data residency

Status: DOCUMENTED · ACCOUNT_RESTRICTED (Compliance API requires an Enterprise org + compliance-scoped key; not available to this account — nothing live-tested)

Everything on this page is derived offline from the downloaded official docs (retrieved 2026-09-18). No request was made to any /v1/compliance/*, /v1/organizations/compliance_settings or AWS endpoint. The DELETE endpoints are destructive and permanent and must never be exercised by this project.

Sources

Last verified: 2026-09-18 (docs only)

Machine-readable twins: generated/fragments/endpoints/anthropic-compliance.json (36 compliance + 2 admin endpoints), generated/fragments/parameters/anthropic-compliance.json (146 params), generated/fragments/errors/anthropic-compliance.json (30 errors), generated/fragments/compatibility/anthropic-iam-actions.json (71 IAM actions), tmp/platform-anthropic/objects-compliance.json (27 objects).


# (a) What the Compliance API is

The Compliance API gives Claude Enterprise (and eligible standalone Claude Console) customers programmatic access to their organization's Activity Feed and — for Claude Enterprise tenants — to the directory (organizations, users, roles, groups), the effective settings of each linked organization, the underlying claude.ai chats, files, projects, and the transcripts of sessions run in Claude apps (Cowork, Claude Code, Claude Science, Claude for Microsoft 365, Claude in Chrome — local sessions; cloud Cowork — remote sessions), plus Claude Code Artifacts. Target users: security, legal, compliance (eDiscovery, DLP, SIEM ingestion, account-deletion responses).

Tenant model: a Claude Enterprise tenant = one parent organization (identity/SSO/SCIM) + linked organizations of two kinds (claude.ai orgs and Claude Console orgs). Parent orgs do not appear in Claude Console. A standalone Console org (no parent) can only use Admin API keys and only the Activity Feed.

# Who can use it / entitlement

Situation How to enable Key
Claude Enterprise org Primary owner enables at claude.ai › Organization settings › API (cascades to all linked orgs) Compliance Access Key created in claude.ai
Standalone Claude Console org (eligible) Org admin toggles Compliance API at Console › Settings › Security (self-service, immediate) — or via Admin API POST /v1/organizations/compliance_settings Admin API key (Activity Feed only)
Console org linked to a parent Nothing to toggle in Console; parent's primary owner enables Compliance Access Key from parent
Claude Platform on AWS Enablement on request via account team; access via IAM action aws-external-anthropic:ListComplianceActivities (Activity Feed only) AWS SigV4 / AWS-issued API key

Turning the Compliance API off stops activity recording and local-session capture (not retroactive, not recoverable), and stops Access Transparency delivery. Recording starts at first enablement — nothing is backfilled.

# Authentication

Item Value
Base URL https://api.anthropic.com, all endpoints under /v1/compliance/*
Auth header x-api-key: <key> (the reference-page examples alternatively show Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY; the guides consistently use x-api-key)
Version header anthropic-version: 2023-06-01 required on every request
Beta header none documented for /v1/compliance/*
Key type 1 Compliance Access Key sk-ant-api01-… — created in claude.ai by primary owner (parent-wide or single-org) or org owner (own org); reaches all endpoints; scopes immutable after creation; no expiry
Key type 2 Admin API key sk-ant-admin01-… — Console › Settings › Admin keys; reaches Activity Feed only, and only carries read:compliance_activities if created while the Compliance API was enabled
Rejected Claude API keys sk-ant-api03-… and Analytics API keys → bare 404 Not found (not 401)

Scopes

Scope Grants
read:compliance_activities Activity Feed (GET /v1/compliance/activities)
read:compliance_user_data chats, messages, files, generated files, artifacts, projects, attachments, project documents, sessions (local + remote), organization users, group members (and, by family, collaborators and Code Artifacts)
delete:compliance_user_data DELETE chats, files, project documents, projects, Code Artifacts
read:compliance_org_data organizations, roles, role permissions, groups, effective organization settings
read:org_audit read-only audit scope accepted by every read endpoint (Needed one of: lists it)
read:compliance_org_settings RETIRED 2026-06-30 — settings endpoint now needs read:compliance_org_data

# Rate limits (documented)

  • 600 requests / minute per parent organization (per org for standalone Console orgs), one budget shared by every key, every linked org and every /v1/compliance/* endpoint.
  • Remote session endpoints carry a second, separate budget on top; its 429 always returns retry-after: 1 and the anthropic-ratelimit-* headers on it describe the shared limit, so back off exponentially.
  • Response headers once authenticated: anthropic-ratelimit-requests-limit, anthropic-ratelimit-requests-remaining, anthropic-ratelimit-requests-reset (RFC 3339); 429 adds retry-after (seconds).
  • Auth failures are rejected before the limiter (no quota); a 403 (scope) consumes one unit.
  • Higher limits: contact Anthropic representative. (No account-specific observations — none available.)

# Pagination model

Endpoint family Sort Scheme Request Response
Activities newest first (order=desc default; asc for incremental sync) cursor limit (1–5000, default 100), after_id / before_id (one at a time) data[], has_more, first_id, last_id
Chats, chat messages oldest first (order_by=created_at|updated_at; messages order=asc|desc) cursor limit (1–1000), after_id / before_id data[]/chat_messages[], has_more, first_id, last_id
Organizations, users, roles, permissions, groups, members, projects, attachments, collaborators, Code Artifacts endpoint-specific (ascending creation / identifier) page token limit, page data[], has_more, next_page
Local & remote sessions and their messages sessions newest first; messages oldest first page token, forward only limit (sessions 1–500, messages 1–1000), page data[], next_page (no has_more — stop when next_page is null)
Files, generated files, artifacts, documents — none (fetch by ID) — object / binary

Cursors and page tokens are opaque; reuse the same cursor on retry (a failed request does not advance position). Local-session messages page tokens expire 24 h after a walk starts; local-session list tokens older than 24 h are re-evaluated against the current retention boundary and may skip sessions. Cursors are scoped to the organization, so they survive key rotation.

# Error catalogue (from Handle Compliance API errors)

Standard Anthropic error body {"error": {"type", "message"}} + request-id header. Match on status + error.type, not on message text (except where noted).

HTTP error.type code (atlas) Meaning (message semantics) Retry? Action
400 invalid_request_error compliance_api_not_enabled Compliance API is not enabled for this organization — key valid but API not enabled (or turned off) for the org/parent; every endpoint returns it. False Enable the Compliance API (claude.ai > Organization settings > API for Enterprise; Console > Settings > Security toggle for standalone Console org), then resend.
400 invalid_request_error unknown_query_parameter Unknown query parameter: 'created_at[gte]'. Did you mean 'created_at.gte'? — unrecognized params are rejected, not ignored. False Use dot notation for ranges (created_at.gte), [] suffix for arrays (activity_types[]), and after_id/before_id/page per endpoint.
400 invalid_request_error invalid_parameter_value Message starts with the parameter name then the failed constraint, e.g. limit: Input should be less than or equal to 1000, created_at.gte: Input should be a valid datetime…, activity_types[].0: Input is not one of the permitted values., created_at.gte: Input should have timezone info, created_at.lt must be strictly after created_at.gte.; tool_use_input_max_bytes/tool_result_max_bytes accept positive int or -1. False Correct the named parameter; respect per-endpoint limit maxima; RFC 3339 timestamps with explicit UTC offset.
400 invalid_request_error invalid_pagination_cursor Invalid activity_id format: '…' (activities) / Invalid pagination cursor for 'after_id' (chats) / The page parameter is not a valid cursor for this request. (local sessions, cursor bound to session+order) / The page cursor has expired. Restart the walk without a page parameter… (local session messages, 24 h). False Treat cursors as opaque; copy first_id/last_id/next_page unchanged; on expiry restart without page.
401 authentication_error api_key_invalid API key is invalid. — value does not match a usable Compliance Access Key / Admin API key (truncated/altered). False Compare stored secret; create a new key if the copy is wrong.
401 authentication_error api_key_deactivated API key has been deactivated. — key disabled or deleted. False Re-enable if only disabled; otherwise create a new key and rotate.
401 authentication_error api_key_expired API key has expired. — Admin API key past its expiration (Compliance Access Keys have no expiry). False Create a new key and update the integration.
403 permission_error insufficient_scope_activities Missing required scopes. Got: [...] Needed one of: ['read:compliance_activities', 'read:org_audit'] on GET /v1/compliance/activities. False Create a Compliance Access Key with read:compliance_activities, or use an Admin API key created while the Compliance API was enabled.
403 permission_error insufficient_scope_org_data … Needed one of: ['read:compliance_org_data', 'read:org_audit'] on organizations/roles/groups/settings endpoints; Admin API keys cannot read org metadata. False Create a new Compliance Access Key with read:compliance_org_data.
403 permission_error retired_scope_org_settings Got: ['read:compliance_org_settings'] Needed one of: ['read:compliance_org_data', 'read:org_audit'] — scope retired 2026-06-30; settings endpoint now needs read:compliance_org_data. False Create a new key with read:compliance_org_data, migrate, delete the old key.
403 permission_error insufficient_scope_user_data … Needed one of: ['read:compliance_user_data', 'read:org_audit'] on chats/messages/files/projects/sessions/users/group-members; Admin API keys can never hold this scope. False Use a Compliance Access Key created in claude.ai with read:compliance_user_data.
403 permission_error insufficient_scope_delete … Needed: ['delete:compliance_user_data'] on DELETE chats/files/projects/documents. False Create a separate key carrying delete:compliance_user_data (keep read and delete keys separate).
404 not_found_error request_not_authenticated Bare Not found — no key, or a key type the Compliance API does not accept (e.g. sk-ant-api03- Claude API key); same body as a non-existent path; any endpoint incl. lists. Exception: organization settings endpoint returns 401 instead. False Send an sk-ant-api01- or sk-ant-admin01- key in x-api-key; check the path against the reference.
404 not_found_error chat_not_found Chat conversation not found: '<claude_chat_id>' — hard-deleted, retention-expired, or outside key scope. User-deleted chats are NOT 404 (listed with deleted_at). False Reconcile against claude_chat_created / claude_chat_viewed activities; drop the ID from the queue.
404 not_found_error file_not_found File not found: <uuid> — file missing/deleted (deleting a chat deletes its files); message uses the underlying UUID; applies to metadata, content and delete endpoints, chat files and project files. False Reconcile against claude_file_uploaded / claude_file_deleted / claude_chat_deleted activities.
404 not_found_error generated_file_or_artifact_not_found Generated file not found: '…' (metadata) / Generated file content not found: '…' (content) / Artifact version not found: '…' (both artifact endpoints) — deleted with their chat. False Look up the chat via Get chat messages; if deleted_at set, remove from queue.
404 not_found_error project_not_found No project is found with the provided id. (detail/attachments/collaborators) / No project found with provided id, or it has already been deleted. (DELETE). False Reconcile against claude_project_created / claude_project_deleted activities.
404 not_found_error project_document_not_found No project document found with the provided id. / …, or it has already been deleted. (DELETE) — text project documents (claude_proj_doc_) only. False List current attachments via GET /v1/compliance/apps/projects/{project_id}/attachments.
404 not_found_error local_session_not_found Local session not found. — not readable (other parent org), never existed, ZDR in effect, or fully aged out of retention; no transient form. Malformed non-clls_ ID → 400. False Confirm via the local session list; if absent, transcript is not retrievable.
404 not_found_error local_sessions_not_available Local sessions are not available. — returned on EVERY local-session call incl. the list while the endpoints are unavailable to the parent org; independent of session ID; can be temporary. True Keep queued IDs; retry on the next scheduled run; if persistent contact Anthropic with request-id.
404 not_found_error remote_session_not_found Remote session not found. — cse_ ID missing/deleted, outside scope, or session still pending (no transcript yet). Malformed ID → 400. conditional Check status via the remote session list; retry after it leaves pending; deleted sessions are gone.
404 not_found_error organization_role_or_group_not_found The "<org_uuid>" organization does not exist or the requester is not authorized to access it. / Role not found. / Group not found. False Verify the ID against the corresponding list endpoint.
404 not_found_error organization_settings_not_available organization not found in this organization's hierarchy — org not a linked child, invalid UUID, or settings endpoint not yet enabled for the parent (same body on purpose). False Verify against List organizations; if a known-good ID still 404s, contact your Anthropic representative.
409 invalid_request_error project_has_attached_chats The "<claude_proj_id>" project cannot be deleted as it has chats attached to it. Delete or detach all chats, and try deleting the project again. (type is invalid_request_error — distinguish by 409). False List chats with user_ids[] + project_ids[], delete or detach each, retry the project delete.
429 rate_limit_error compliance_rate_limit_exceeded Compliance API rate limit of 600 requests per minute per parent organization has been exceeded… — shared budget across all keys/linked orgs/endpoints; remote-session endpoints carry a second budget (its 429 has retry-after: 1 always). True Wait retry-after seconds (fallback exponential backoff 1 s → 60 s); do NOT advance the cursor. Headers: anthropic-ratelimit-requests-limit/-remaining/-reset.
500 api_error — Deterministic failure when x-should-retry: false header present; otherwise transient. conditional Honor x-should-retry; if absent retry with exponential backoff (1 s → 60 s).
502/503/504/529 — — Transient upstream/overload errors. True Retry with exponential backoff; check status.anthropic.com. Exception: some local-session 503s are not transient (see overloaded_error).
503 overloaded_error local_sessions_index_unavailable The local-sessions index is temporarily unavailable. Try again shortly. — transient. True Retry with backoff; do not advance page cursor.
503 overloaded_error local_sessions_captured_content_unavailable Captured content is temporarily unavailable. Try again shortly. — usually transient; persistent for CMEK orgs whose key is disabled/revoked/unreachable (never reported as not_captured). conditional Retry with backoff; if it keeps recurring for a CMEK org, check the key in your KMS and stop walking that org's transcripts.
503 overloaded_error local_sessions_retention_overrides_unavailable The local-sessions index cannot currently evaluate retention overrides for this page/session. Try again later. — depends on the org's data/settings, can persist. conditional Do not hold the walk open: narrow created_at window or skip the session and retry on a later run (restart without page).

Retry contract summary: 400/401/403/404/409 → fix and resend; 429 → wait retry-after, never advance the cursor; 500 → honour x-should-retry: false; 502/503/504/529 → exponential backoff (1 s → 60 s), except the local-session 503s above.


# (b) Endpoint tables per resource group

36 Compliance endpoints (36 reference leaf pages) + 2 Admin API compliance-settings endpoints. 5 endpoints are DELETE (⚠️ permanent hard-deletes — never call). All statuses are DOCUMENTED · ACCOUNT_RESTRICTED (docs-only; our account has no Enterprise/compliance entitlement).

# activities — scope: read:compliance_activities, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/activities Query compliance activities activity_types[], actor_ids[], after_id, before_id, created_at, exclude_activity_types[], limit, order, organization_ids[], user_ids[] {data, first_id, has_more, last_id} cursor DOCUMENTED · ACCOUNT_RESTRICTED

# organizations — scope: read:compliance_org_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/organizations List organizations limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# organizations/users — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/organizations/{org_uuid}/users List organization users limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# organizations/roles — scope: read:compliance_org_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/organizations/{org_uuid}/roles List Compliance Roles limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/organizations/{org_uuid}/roles/{role_id} Get Compliance Role — {id, created_at, description, name, updated_at} — DOCUMENTED · ACCOUNT_RESTRICTED

# organizations/roles/permissions — scope: read:compliance_org_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/organizations/{org_uuid}/roles/{role_id}/permissions List Compliance Role Permissions limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# organizations/settings — scope: read:compliance_org_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/organizations/{organization_id}/settings Get effective organization settings — {type, api_keys, organization_id, settings} — DOCUMENTED · ACCOUNT_RESTRICTED

# groups — scope: read:compliance_org_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/groups List Compliance Groups limit, name_prefix, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/groups/{group_id} Get Compliance Group — {id, created_at, description, name, roles, source_type, updated_at} — DOCUMENTED · ACCOUNT_RESTRICTED

# groups/members — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/groups/{group_id}/members List Compliance Group Members limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# apps/chats — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/chats List chats after_id, before_id, created_at, limit, order_by, organization_ids[], project_ids[], updated_at, user_ids[] {data, first_id, has_more, last_id} cursor DOCUMENTED · ACCOUNT_RESTRICTED
DELETE /v1/compliance/apps/chats/{claude_chat_id} Delete chat ⚠️ destructive — {type, id} — DOCUMENTED · ACCOUNT_RESTRICTED

# apps/chats/messages — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/chats/{claude_chat_id}/messages Get chat messages after_id, before_id, created_at, limit, order, tool_result_max_chars, tool_use_input_max_chars, updated_at {id, chat_messages, created_at, deleted_at, first_id, has_more, href, last_id…} cursor DOCUMENTED · ACCOUNT_RESTRICTED

# apps/chats/files — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data

Method Path Title Key query params Returns Pagination Status
DELETE /v1/compliance/apps/chats/files/{claude_file_id} Delete file ⚠️ destructive — {type, id} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/chats/files/{claude_file_id} Get file metadata — {id, claude_chat_ids, created_at, filename, md5, message_ids, mime_type, size_bytes} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/chats/files/{claude_file_id}/content Download file content — binary stream (chunked) — DOCUMENTED · ACCOUNT_RESTRICTED

# apps/chats/generated_files — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/chats/generated-files/{claude_gen_file_id} Get Claude-generated file metadata — {id, claude_chat_id, created_at, filename, md5, mime_type, size_bytes} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/chats/generated-files/{claude_gen_file_id}/content Download a Claude-generated file — binary stream (chunked) — DOCUMENTED · ACCOUNT_RESTRICTED

# apps/artifacts — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/artifacts/{artifact_version_id} Get artifact metadata — {id, artifact_type, claude_chat_id, created_at, md5, size_bytes, title, version_id} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/artifacts/{artifact_version_id}/content Download artifact content — JSON {content, title, artifact_type} — DOCUMENTED · ACCOUNT_RESTRICTED

# apps/projects — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/projects List projects created_at, limit, organization_ids[], page, updated_at, user_ids[] {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED
DELETE /v1/compliance/apps/projects/{project_id} Delete project ⚠️ destructive — {type, id} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/projects/{project_id} Get project details — {id, attachments_count, chats_count, created_at, deleted_at, description, instructions, is_private…} — DOCUMENTED · ACCOUNT_RESTRICTED

# apps/projects/attachments — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/projects/{project_id}/attachments List project attachments limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# apps/projects/collaborators — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/projects/{project_id}/collaborators List project collaborators limit, page {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# apps/projects/documents — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data

Method Path Title Key query params Returns Pagination Status
DELETE /v1/compliance/apps/projects/documents/{document_id} Delete project document ⚠️ destructive — {type, id} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/projects/documents/{document_id} Get project document content — {id, content, created_at, filename, user} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/projects/documents/{document_id}/metadata Get project document metadata — {id, claude_project_id, created_at, filename, md5, mime_type, size_bytes, user} — DOCUMENTED · ACCOUNT_RESTRICTED

# apps/sessions/local — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/sessions/local List local sessions created_at, limit, page, updated_at {data, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/sessions/local/{local_session_id} Retrieve a local session — {type, id, created_at, organization_uuid, product_surface, truncated, updated_at, user…} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/sessions/local/{local_session_id}/messages Retrieve local session messages limit, order, page, tool_result_max_bytes, tool_use_input_max_bytes {data, next_page, session} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# apps/sessions/remote — scope: read:compliance_user_data, read:org_audit

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/sessions/remote List remote sessions created_at, limit, organization_ids[], page, user_ids[] {data, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/sessions/remote/{claude_remote_session_id}/messages Retrieve remote session messages limit, order, page, tool_result_max_bytes, tool_use_input_max_bytes {data, next_page, session} page_token DOCUMENTED · ACCOUNT_RESTRICTED

# code/artifacts — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data

Method Path Title Key query params Returns Pagination Status
GET /v1/compliance/apps/code/artifacts List Code Artifacts limit, organization_ids[], page, updated_at, user_ids[] {data, has_more, next_page} page_token DOCUMENTED · ACCOUNT_RESTRICTED
DELETE /v1/compliance/apps/code/artifacts/{artifact_id} Delete Code Artifact ⚠️ destructive — {type, id} — DOCUMENTED · ACCOUNT_RESTRICTED
GET /v1/compliance/apps/code/artifacts/{artifact_id}/versions/{version_id} Download Code Artifact Version Content — binary stream (chunked) — DOCUMENTED · ACCOUNT_RESTRICTED

# admin/compliance_settings — scope: Admin API key (org admin)

Method Path Title Key query params Returns Pagination Status
GET /v1/organizations/compliance_settings Get Compliance Settings — BetaComplianceSettings object — DOCUMENTED · BETA · ACCOUNT_RESTRICTED
POST /v1/organizations/compliance_settings Update Compliance Settings — BetaComplianceSettings object — DOCUMENTED · BETA · ACCOUNT_RESTRICTED

# Activity Feed query parameters (GET /v1/compliance/activities)

Parameter In Type Required Default Min/Max Description
activity_types[] query enum (506 values) False — — Filter activities by type. See the response data schema for the additional fields each type returns. Cannot be combined with exclude_activity_types[].
actor_ids[] query array of string False — — Filter activities by actor IDs (currently only user_... IDs are supported). Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users.
after_id query string False — — Pagination cursor for retrieving the next page of results. To paginate, pass the last_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret it
before_id query string False — — Pagination cursor for retrieving the previous page of results. To paginate, pass the first_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpr
created_at query object False — —
created_at.gt query string False — — Filter activities created after this time (RFC 3339 format)
created_at.gte query string False — — Filter activities created at or after this time (RFC 3339 format)
created_at.lt query string False — — Filter activities created before this time (RFC 3339 format)
created_at.lte query string False — — Filter activities created at or before this time (RFC 3339 format)
exclude_activity_types[] query enum (506 values) False — — Exclude activities of these types. Cannot be combined with activity_types[].
limit query number False 100 1/5000 Maximum results (default: 100, max: 5000)
order query enum: asc, desc False desc — Sort direction by created_at. desc (default) returns newest-first; asc returns oldest-first for incremental sync. Activities become queryable after a short asynchronous ingestion delay. When using asc with `after
organization_ids[] query array of string False — — Filter activities by organization IDs (accepts org_... or organization UUID). Enumerate IDs via GET /v1/compliance/organizations.
user_ids[] query array of string False — — Alias for actor_ids[], for consistency with other compliance routes. If both are provided, the lists are merged.

Repeatable filters use bracket syntax (activity_types[]=a&activity_types[]=b); range filters use dot notation (created_at.gte). Unknown parameters are rejected with 400. activity_types[] and exclude_activity_types[] are mutually exclusive.

# Session transcript parameters

GET …/sessions/local/{id}/messages and GET …/sessions/remote/{id}/messages share: limit (1–1000, default 100), order (asc default / desc), page, tool_use_input_max_bytes and tool_result_max_bytes (default 10 000 bytes; -1 = server maximum ≈ 1 MiB; 0 invalid). Chat messages use tool_use_input_max_chars / tool_result_max_chars instead (chars, not bytes).


# (c) Data model

Identifier prefixes: org_ (tagged org id) / bare UUID (organization_uuid), user_, claude_chat_, claude_chat_msg_, claude_file_, claude_gen_file_, claude_artifact_ / claude_artifact_version_, claude_proj_, claude_proj_doc_, clls_ (local session), clsm_ (local session message), cse_ (remote session), csev_ (remote message), cagt_ (agent owner of a remote session), wrkspc_, apikey_, activity_. user_id is the stable join key (survives email changes and account deletion).

# Activity (Activity Feed event)

Common fields: id, created_at (RFC 3339), organization_id (org_… or null for sign-in/sign-out/Compliance-API-call events), organization_uuid, actor (union), type, plus type-specific fields (e.g. claude_chat_id, claude_project_id, filename). Retained 6 years; queryable within ~1 minute; at-least-once delivery → dedupe on id. claude_*_viewed events mean an app loaded the content, not that a human viewed it.

Actor union (actor.type) — 11 variants documented in the reference:

actor.type Fields When
user_actor email_address, user_id, ip_address, user_agent signed-in claude.ai / Console user
api_actor api_key_id, ip_address, user_agent Claude API or Compliance API call with a customer key (both key types)
admin_api_key_actor admin_api_key_id, ip_address, user_agent Admin API management action
unauthenticated_user_actor unauthenticated_email_address (nullable), ip_address, user_agent pre-sign-in (e.g. sso_login_initiated)
anthropic_actor email_address (always null) Anthropic acted (incl. Access Transparency anthropic_access)
system_actor service (nullable) automated Anthropic background processing
service_account_actor service_account_id, ip_address, user_agent service account
scim_directory_sync_actor workos_event_id, directory_id, idp_connection_type (e.g. OktaSCIMV2, AzureSCIMV2) IdP SCIM push
federated_identity_actor issuer, subject, audience[], ip_address?, user_agent? OIDC workload identity
federated_actor provider ∈ {aws (account_id, signed_principal), azure (subscription_id), gcp (project_number), oidc (issuer)}, subject?, ip_address?, user_agent? cloud-federated caller (e.g. Claude Platform on AWS)
attested_device_actor external_client_id, kid_hash, ip_address?, user_agent? App Attest device token

Activity types — the reference enumerates 506 values for activity_types[] (the guide says "hundreds"). Grouped:

Family Count Examples
org_* (organization settings toggles) 98 org_compliance_api_settings_updated, org_claude_code_zero_data_retention_disabled, org_claude_code_desktop_enabled
platform_* (Claude Console: keys, workspaces, members, usage views) 85 platform_usage_report_claude_code_viewed, …
claude_* (claude.ai chats/files/projects/artifacts/skills/plugins) 77 claude_chat_created/viewed/deleted, claude_file_uploaded/exported, claude_project_document_uploaded, claude_artifact_published, claude_skill_created
integrations (tunnel_/mcp_/desktop_/ghe_/github_/slack_) 42
billing / workspaces / service accounts / LTI / marketplace 37
ccr_* (Claude in Slack / channel agents) 36 ccr_agent_created, ccr_session_created, ccr_slack_channel_joined
other 34 compliance_api_accessed, cowork_session_updated, api_key_created, audit_log_export_started, admin_api_key_created, cli_plugin_exec_policy_updated
claude_code_* 34 claude_code_credential_revoked, claude_code_security_scan_created, claude_code_user_settings_updated
group_/rbac_/role_* (RBAC) 23
auth & identity (sso_/scim_/magic_/trusted_device …) 22 sso_login_initiated, account_deleted, abuse_decision_received, age_verified
design_* (Claude Design) 12
inference_* (inference hooks) 6
Total 506 full enum in generated/fragments/parameters/anthropic-compliance.json (activity_types[])

Notable types: compliance_api_accessed (every Compliance API call; actor.api_key_id attributes it to a key), org_compliance_api_settings_updated (toggle on/off), audit_log_export_started/accessed, claude_chat_created/viewed/deleted, claude_file_uploaded/deleted/exported, claude_project_document_uploaded, sso_login_initiated. Access Transparency documents anthropic_access and cmek_preserve event types, but neither string appears in the reference enum — treat as DOCUMENTATION_INCOMPLETE (guide vs reference mismatch).

# Organizations, users, roles, permissions, groups

Object Fields
ComplianceOrganization uuid, name, created_at — list sorted by creation asc; parent-scoped key sees every linked org
ComplianceOrganizationUser id (user_), email, full_name, created_at, organization_role ∈ {admin, billing, claude_code_user, developer, managed, membership_admin, owner, parent_org_admin, parent_org_owner, primary_owner, user}
ComplianceRole id, name, description, created_at, updated_at (custom RBAC roles)
ComplianceRolePermission action, resource_type, resource_id
ComplianceGroup id, name, description, roles[] (role ids), source_type ∈ {direct, scim}, created_at, updated_at; list filter name_prefix
ComplianceGroupMember user_id, email, created_at, updated_at

# Effective organization settings (GET /v1/compliance/organizations/{organization_id}/settings)

Returns {type: "effective_organization_settings", organization_id (bare UUID), settings[], api_keys[]}. Rows reflect the enforced state (after HIPAA/regulatory restrictions, feature availability, org-type defaults, inter-feature dependencies); a setting the org's admins cannot change is omitted (missing ≠ off). api_keys[] lists every Compliance Access Key of the parent (type: compliance_api_key, id, name, scopes[], is_active, created_at, created_by_id, expires_at) — never secrets. Target must be a linked org (not the parent). Unauthenticated requests get 401 here (404 elsewhere).

Row type value shape Setting names
Boolean boolean access_transparency_enabled, ai_powered_artifacts_enabled, api_workbench_feedback_collection_enabled, api_zero_data_retention_enabled, artifact_connectors_enabled, ask_your_org_enabled, chat_enabled, claude_ai_chat_sharing_enabled, claude_ai_feedback_collection_enabled, claude_ai_integration_sharing_enabled, claude_ai_skill_plugins_scanning_enabled, claude_code_desktop_bypass_permissions_enabled, claude_code_desktop_enabled, claude_code_fast_mode_enabled, claude_code_metrics_logging_enabled, claude_code_remote_control_enabled, claude_code_review_enabled, claude_code_routines_enabled, claude_code_security_enabled, claude_code_trusted_devices_required, claude_code_web_enabled, claude_code_workflows_enabled, claude_design_enabled, claude_enterprise_claude_code_zero_data_retention_enabled, claude_in_slack_enabled, claude_science_custom_connectors_enabled, claude_science_custom_skills_enabled, claude_science_enabled, claude_science_managed_network_allowlist_enabled, claude_science_memory_enabled, claude_science_modal_enabled, claude_science_scientific_model_endpoints_enabled, claude_science_ssh_hosts_enabled, cmek_enabled, code_execution_enabled, code_execution_network_egress_enabled, connector_tools_default_always_allow, content_redaction_enabled, cowork_trusted_devices_required, desktop_extension_allowlist_enabled, directory_sync_enabled, frontier_data_use_enabled, group_skill_sharing_enabled, hipaa_compliance_enabled, inline_visualizations_enabled, ip_allowlist_enabled, location_metadata_enabled, member_usage_dashboard_visible, memory_enabled, org_wide_skill_sharing_enabled, public_projects_enabled, skill_sharing_enabled, skills_enabled, sso_claude_ai_enforced, sso_console_enforced, sso_enabled, third_party_interactive_content_enabled, user_skill_creation_enabled, web_search_enabled, work_across_apps_enabled
Integer number or null account_session_duration_seconds
String string or null claude_code_default_worker_environment_id, claude_code_default_worker_pool_id
StringList array of string allowed_invite_domains, disabled_admin_request_types, ip_allowlist_ip_ranges
ProvisioningMode "jit_advanced" or "jit_permissive" or "login_only" or 2 more ∈ {jit_advanced, jit_permissive, login_only, scim_advanced, scim_permissive} sso_provisioning_mode
DataRetention map[data_type → {type:'fixed', duration:number, timescale:'day'|'month'} | {type:'indefinite'}] — key all is exclusive; keys seen: chat (example) data_retention_periods

# Chats, messages, files, generated files, artifacts

  • ComplianceChat (list item): id, name, model, organization_uuid, organization_id (deprecated), project_id, user {id, email_address} (null when key is single-org restricted), href, created_at, updated_at, deleted_at (set when the user deleted it in claude.ai — chat stays listed, content gone). List filters: user_ids[] (≤10), organization_ids[], project_ids[] (requires user_ids[]), created_at.*, updated_at.*, order_by. Legacy filter param rejected after 2026-09-22.
  • ComplianceChatMessages: chat fields + chat_messages[] (id, role ∈ {user, assistant}, created_at, content[] of text {text, thinking_redacted, truncated} / tool_use {id, name, input (JSON string), integration_name, mcp_server_url, truncated} / tool_result {tool_use_id, name, content[], is_error, integration_name, mcp_server_url, truncated}, files[], generated_files[], artifacts[] {id, version_id, title, artifact_type}) + has_more, first_id, last_id.
  • ComplianceFileMetadata: id, filename, mime_type, size_bytes, md5, claude_chat_ids[], message_ids[], created_at. Content endpoint streams the stored variant (may be extracted text for Word/PowerPoint/some PDFs) with Content-Disposition: attachment; filename*=utf-8''…, Content-Type, Content-MD5 (base64), Transfer-Encoding: chunked.
  • ComplianceGeneratedFileMetadata: id (claude_gen_file_), claude_chat_id, filename, mime_type, size_bytes, md5, created_at.
  • ComplianceArtifactVersionMetadata: id, version_id, claude_chat_id, title, artifact_type (e.g. application/vnd.ant.code), md5, size_bytes, created_at. Content endpoint returns JSON {content, title, artifact_type} for one version.

# Projects

  • ComplianceProject / ComplianceProjectDetails: id, name, description, instructions, is_private, organization_uuid, user, created_at, updated_at, deleted_at, chats_count, attachments_count.
  • Attachments (union on type): project_file {id claude_file_, filename, mime_type, size_bytes, md5, created_at} → download via the chat-files content endpoint; project_doc {id claude_proj_doc_, filename, mime_type text/plain, updated_at} → GET /v1/compliance/apps/projects/documents/{document_id} (content string) or /metadata (md5, size_bytes, claude_project_id, user).
  • Collaborators (union on type): user {user_id}, group {group_id}, organization {organization_uuid}, organization_role {organization_role}; each with role ∈ {owner, admin, editor, viewer} and granted_at.
  • DELETE project → 409 while chats are attached.

# Sessions — local vs remote

Local sessions Remote sessions
What Sessions on users' machines while signed in with Enterprise account: Cowork (Desktop), Claude Code (terminal/Desktop/IDE), Claude Science, Claude for Microsoft 365, Claude in Chrome Cowork sessions started on claude.ai web/mobile, run in Anthropic-managed cloud
Endpoints GET …/sessions/local, …/local/{id}, …/local/{id}/messages GET …/sessions/remote, …/remote/{id}/messages
ID prefix clls_ (messages clsm_) cse_ (messages csev_)
product_surface cowork, claude_code, claude_science, claude_in_chrome, office_agents[/excel|/powerpoint|/word|/outlook] cowork_remote
Object type: compliance_local_session, id, organization_uuid, workspace_id?, user {id, email_address?}, product_surface, created_at (first retained call), updated_at (last), truncated — no status, no deleted_at id, organization_uuid, user? / agent_id? (cagt_) + started_by_user?, status ∈ {pending, active, paused, archived, failed}, product_surface, claude_project_id?, created_at, updated_at
List filters created_at.gte/.lt (RFC 3339 with offset; lt strictly after gte), updated_at.gte; no user/org filter organization_ids[] (≤500), user_ids[] (1–10, excludes agent-owned), created_at.*
Message object type: compliance_local_session_message, id, role, created_at, model?, content[] (text / tool_use / tool_result), provenance ∈ {null, content_unavailable {reason e.g. not_captured, retention_elapsed}, client_asserted, synthetic_marker (system-prompt stand-in)} id, role, created_at, content[], content_unavailable (bool), sent_by_user_id?
Retention 6 years by default, or the org's finite custom conversation retention period (shortest wins); enforced read-side per inference call 6 years unless the user deletes the session (then unlisted; messages → 404)
Rate budget shared 600 rpm only shared + second remote budget
Excluded Claude Code with Console API key / Bedrock / Vertex / Foundry; Claude Code cloud sessions; HIPAA-enabled orgs; ZDR sessions; thinking blocks, images/binary, tool & MCP definitions, system prompt, citations thinking blocks and images
CMEK transcripts encrypted under customer key; unusable key → 503 Captured content is temporarily unavailable (persistent) —

Both families are read-only (no delete). Coverage is stable for Cowork and Claude Code; Science / Microsoft 365 / Chrome coverage is beta.

# Claude Code Artifacts (/v1/compliance/apps/code/artifacts)

ComplianceCodeArtifact: id, organization_uuid, owner_user_id?, user?, read_mode ∈ {owner, users, org, public}, published_version_id?, updated_at?, versions[] {id, name, created_at} (≈20 most recent). List sorted by identifier (not time) with page/next_page (pages may be short/empty while next_page is set); filters organization_ids[] (≤500), user_ids[] (≤200), updated_at.*. Version content is streamed (Content-MD5; early-terminated chunked transfer is the only truncation signal; 503 while upload in flight). DELETE initiates asynchronous permanent removal.


# (d) Integration patterns

  • Window polling: tile with created_at.gte (inclusive) / created_at.lt (exclusive), keep lt ≥ 1 min in the past (documented indexing lag), overlap windows by a few minutes or run reconciliation; dedupe on id. Page inside a window with after_id=last_id while has_more.
  • Cursor-driven incremental reads: persist first_id, pass as before_id to get newer events (walk toward the present until has_more is false, then persist); backfill with after_id=last_id. Alternative: order=asc + after_id. Cursors survive key rotation.
  • Chats export: omit user_ids[], set order_by=updated_at, paginate with after_id — picks up new, modified and user-deleted chats in one loop.
  • SIEM correlation: join on actor.user_id (primary), actor.email_address, actor.ip_address, actor.user_agent, created_at; ingest compliance_api_accessed to audit who queried compliance data.
  • Retention horizons: Activity Feed 6 y (Anthropic) · chat/file/project content = org's claude.ai retention policy or until user deletion · local transcripts 6 y or custom period · remote transcripts 6 y or user deletion · hard-deleted content: gone immediately. Export before retention/deletion if your legal hold is longer; the API cannot return removed content.
  • Completeness: at-least-once delivery, no total_count/checksum; log start cursor, terminal last_id, record count, run time and final request-id; store provenance + content hash for chain of custody.
  • Deletion endpoints (DELETE chat / file / project document / project / Code Artifact): require delete:compliance_user_data, return {id, type: "<resource>_deleted"} (claude_chat_deleted, claude_file_deleted, claude_project_document_deleted, claude_project_deleted, code_artifact_deleted), immediate and irreversible — archive first, use a separate delete-scoped key, never call from this project.
  • Sandbox: no test sandbox is documented (FAQ "How do I get a sandbox…" → contact account team).

# (e) Admin API compliance settings (beta)

Singleton per Console organization, Admin API key (org admin). Not available on Claude Platform on AWS (workspace/external-key routes are the only Admin routes there).

Method Path Body Returns SDK
GET /v1/organizations/compliance_settings — {type: "compliance_settings", state: {type: "enabled"|"disabled"}}; a child org reads the state inherited from its parent client.beta.organization.compliance_settings.retrieve() / client.beta.organization.complianceSettings.retrieve()
POST /v1/organizations/compliance_settings {"state": {"type": "enabled"}} or string shorthand "enabled"/"disabled" same object (canonical form) .update(state=…)

Semantics: enabled turns the Compliance API on and starts capturing events; disabled stops both; setting the current value is a no-op success; a disabled state is overridden by a later provisioning action that enables Access Transparency (which re-enables the Compliance API); automated provisioning never disables. Reference example uses X-Api-Key + anthropic-version; SDK surfaces route it as …/compliance_settings?beta=true; no anthropic-beta header value is documented (uncertain).


# (f) Claude Platform on AWS — IAM

What it is. Claude Platform on AWS is the full Anthropic platform (Messages API, Files, Skills, Batches, Managed Agents, beta features) operated by Anthropic but reached through your AWS account: AWS supplies authentication (SigV4 or API key), IAM-based access control, CloudTrail and Marketplace billing. Unlike Bedrock (AWS runs inference; SigV4 service bedrock/bedrock-mantle), here the base URL is https://aws-external-anthropic.{region}.api.aws/v1/…, request/response shapes are the first-party Claude API, and every request carries anthropic-workspace-id: wrkspc_…. Available in all AWS commercial regions; the workspace's AWS region scopes the gateway endpoint, IAM, CloudTrail and billing — not where inference runs (use inference_geo).

Auth flow

Path Mechanism IAM requirement
SigV4 (primary) Sign requests with AWS credentials from the default provider chain (env vars, ~/.aws/credentials, SSO/credential_process, ECS/IMDS roles). curl: --aws-sigv4 "aws:amz:<region>:aws-external-anthropic" (+ x-amz-security-token for temporary creds). SDKs: platform clients (AnthropicAWS / AnthropicAws) sign and add the workspace header. route action(s) on the workspace ARN, e.g. CreateInference
API key (bearer) Key generated in AWS Console › Claude Platform on AWS › API keys; sent as x-api-key (env ANTHROPIC_AWS_API_KEY / apiKey). route action(s) + CallWithBearerToken on Resource: "*"
Short-term token AWS token-generator libraries (JS/Python/Java) mint a ≤12 h token from SigV4 creds, used as x-api-key; not auto-refreshed. same as API key (CallWithBearerToken)
Console AWS Console › Open Claude Console federation; Console role (Admin/Developer) assigned by Anthropic rep, not derived from IAM. AssumeConsole on Resource: "*"

Credential precedence in SDKs: apiKey arg → awsAccessKey+awsSecretAccessKey → awsProfile → ANTHROPIC_AWS_API_KEY → default provider chain. OAuth is not supported. Organization membership = AWS IAM (no Admin API member endpoints).

Service details: IAM prefix aws-external-anthropic; single resource type workspace; ARN arn:aws:aws-external-anthropic:{region}:{account-id}:workspace/{workspace-id} (resource segment = the wrkspc_ id). 71 actions; beta variants of a route need no extra action; every unlisted route is denied. No service-specific IAM condition keys are documented. IAM matching is case-insensitive and *File also matches *UserProfile — enumerate Files actions explicitly.

Managed policies (all on Resource: "*"): AnthropicFullAccess (*), AnthropicReadOnlyAccess (Get*, List*, CallWithBearerToken), AnthropicInferenceAccess (Get*, List*, CreateInference, CreateBatchInference, CancelBatchInference, DeleteBatchInference, CountTokens, CallWithBearerToken), AnthropicLimitedAccess (InferenceAccess + all Managed Agents actions), AnthropicSelfHostedEnvironmentAccess (GetEnvironment, ProcessEnvironmentWork, GetSession, UpdateSession, GetSkill, CallWithBearerToken). Get*/List* wildcards grant content reads (file bytes, skill content, batch results, session history, memories, key metadata) and ListComplianceActivities; AssumeConsole is only in FullAccess. Wildcard gotchas: Archive*, ProcessEnvironmentWork, RotateWebhookSecret, RegisterKey, DisableKey are not matched by Create*/Update*/Delete*; sub-resource create/delete maps to Update<Parent>.

Complete IAM action table (condition keys: none documented for any action)

Action (aws-external-anthropic:) Group Resource Routes authorized CloudTrail In managed policies
CreateInference Inference workspace ARN POST /v1/messages Data Full, Inference, Limited
CountTokens Inference workspace ARN POST /v1/messages/count_tokens Data Full, Inference, Limited
CreateBatchInference Batch processing workspace ARN POST /v1/messages/batches Data Full, Inference, Limited
GetBatchInference Batch processing workspace ARN GET /v1/messages/batches/{id}
GET /v1/messages/batches/{id}/results
Data Full, Inference, Limited, ReadOnly
ListBatchInferences Batch processing workspace ARN GET /v1/messages/batches Data Full, Inference, Limited, ReadOnly
CancelBatchInference Batch processing workspace ARN POST /v1/messages/batches/{id}/cancel Data Full, Inference, Limited
DeleteBatchInference Batch processing workspace ARN DELETE /v1/messages/batches/{id} Data Full, Inference, Limited
GetModel Models workspace ARN GET /v1/models/{id} Data Full, Inference, Limited, ReadOnly
ListModels Models workspace ARN GET /v1/models Data Full, Inference, Limited, ReadOnly
CreateFile Files workspace ARN POST /v1/files Data Full
GetFile Files workspace ARN GET /v1/files/{id}
GET /v1/files/{id}/content
Data Full, Inference, Limited, ReadOnly
ListFiles Files workspace ARN GET /v1/files Data Full, Inference, Limited, ReadOnly
DeleteFile Files workspace ARN DELETE /v1/files/{id} Data Full
CreateSkill Skills workspace ARN POST /v1/skills Data Full
GetSkill Skills workspace ARN GET /v1/skills/{id}
GET /v1/skills/{id}/versions
GET /v1/skills/{id}/versions/{version}
GET /v1/skills/{id}/versions/{version}/content
Data Full, Inference, Limited, ReadOnly, SelfHostedEnvironment
ListSkills Skills workspace ARN GET /v1/skills Data Full, Inference, Limited, ReadOnly
UpdateSkill Skills workspace ARN POST /v1/skills/{id}/versions
DELETE /v1/skills/{id}/versions/{version}
Data Full
DeleteSkill Skills workspace ARN DELETE /v1/skills/{id} Data Full
CreateAgent Agents workspace ARN POST /v1/agents Data Full, Limited
GetAgent Agents workspace ARN GET /v1/agents/{id}
GET /v1/agents/{id}/versions
Data Full, Inference, Limited, ReadOnly
ListAgents Agents workspace ARN GET /v1/agents Data Full, Inference, Limited, ReadOnly
UpdateAgent Agents workspace ARN POST /v1/agents/{id} Data Full, Limited
ArchiveAgent Agents workspace ARN POST /v1/agents/{id}/archive Data Full, Limited
CreateSession Sessions workspace ARN POST /v1/sessions Data Full, Limited
GetSession Sessions workspace ARN GET /v1/sessions/{id}
GET /v1/sessions/{id}/events
GET /v1/sessions/{id}/events/stream
GET /v1/sessions/{id}/resources
GET /v1/sessions/{id}/resources/{id}
Data Full, Inference, Limited, ReadOnly, SelfHostedEnvironment
ListSessions Sessions workspace ARN GET /v1/sessions Data Full, Inference, Limited, ReadOnly
UpdateSession Sessions workspace ARN POST /v1/sessions/{id}
POST /v1/sessions/{id}/events
POST /v1/sessions/{id}/resources
POST /v1/sessions/{id}/resources/{id}
DELETE /v1/sessions/{id}/resources/{id}
Data Full, Limited, SelfHostedEnvironment
ArchiveSession Sessions workspace ARN POST /v1/sessions/{id}/archive Data Full, Limited
DeleteSession Sessions workspace ARN DELETE /v1/sessions/{id} Data Full, Limited
CreateEnvironment Environments workspace ARN POST /v1/environments Data Full, Limited
GetEnvironment Environments workspace ARN GET /v1/environments/{id}
GET /v1/environments/{id}/work
GET /v1/environments/{id}/work/{work_id}
GET /v1/environments/{id}/work/stats
Data Full, Inference, Limited, ReadOnly, SelfHostedEnvironment
ListEnvironments Environments workspace ARN GET /v1/environments Data Full, Inference, Limited, ReadOnly
UpdateEnvironment Environments workspace ARN POST /v1/environments/{id} Data Full, Limited
ArchiveEnvironment Environments workspace ARN POST /v1/environments/{id}/archive Data Full, Limited
DeleteEnvironment Environments workspace ARN DELETE /v1/environments/{id} Data Full, Limited
ProcessEnvironmentWork Environments workspace ARN GET /v1/environments/{id}/work/poll
POST /v1/environments/{id}/work/{work_id}
POST /v1/environments/{id}/work/{work_id}/ack
POST /v1/environments/{id}/work/{work_id}/heartbeat
POST /v1/environments/{id}/work/{work_id}/stop
Data Full, Limited, SelfHostedEnvironment
CreateVault Vaults workspace ARN POST /v1/vaults Management Full, Limited
GetVault Vaults workspace ARN GET /v1/vaults/{id}
GET /v1/vaults/{id}/credentials
GET /v1/vaults/{id}/credentials/{id}
Management Full, Inference, Limited, ReadOnly
ListVaults Vaults workspace ARN GET /v1/vaults Management Full, Inference, Limited, ReadOnly
UpdateVault Vaults workspace ARN POST /v1/vaults/{id}
POST /v1/vaults/{id}/credentials
POST /v1/vaults/{id}/credentials/{id}
POST /v1/vaults/{id}/credentials/{id}/archive
DELETE /v1/vaults/{id}/credentials/{id}
Management Full, Limited
ArchiveVault Vaults workspace ARN POST /v1/vaults/{id}/archive Management Full, Limited
DeleteVault Vaults workspace ARN DELETE /v1/vaults/{id} Management Full, Limited
CreateMemoryStore Memory stores workspace ARN POST /v1/memory_stores Data Full, Limited
GetMemoryStore Memory stores workspace ARN GET /v1/memory_stores/{id}
GET /v1/memory_stores/{id}/memories
GET /v1/memory_stores/{id}/memories/{id}
GET /v1/memory_stores/{id}/memory_versions
GET /v1/memory_stores/{id}/memory_versions/{id}
Data Full, Inference, Limited, ReadOnly
ListMemoryStores Memory stores workspace ARN GET /v1/memory_stores Data Full, Inference, Limited, ReadOnly
UpdateMemoryStore Memory stores workspace ARN POST /v1/memory_stores/{id}
POST /v1/memory_stores/{id}/memories
POST /v1/memory_stores/{id}/memories/{id}
DELETE /v1/memory_stores/{id}/memories/{id}
POST /v1/memory_stores/{id}/memory_versions/{id}/redact
Data Full, Limited
ArchiveMemoryStore Memory stores workspace ARN POST /v1/memory_stores/{id}/archive Data Full, Limited
DeleteMemoryStore Memory stores workspace ARN DELETE /v1/memory_stores/{id} Data Full, Limited
CreateWebhook Webhooks workspace ARN POST /v1/webhooks Management Full, Limited
GetWebhook Webhooks workspace ARN GET /v1/webhooks/{id} Management Full, Inference, Limited, ReadOnly
ListWebhooks Webhooks workspace ARN GET /v1/webhooks Management Full, Inference, Limited, ReadOnly
UpdateWebhook Webhooks workspace ARN POST /v1/webhooks/{id} Management Full, Limited
DeleteWebhook Webhooks workspace ARN DELETE /v1/webhooks/{id} Management Full, Limited
RotateWebhookSecret Webhooks workspace ARN POST /v1/webhooks/{id}/regenerate_signing_secret Management Full, Limited
CreateUserProfile User profiles workspace ARN POST /v1/user_profiles Data Full
GetUserProfile User profiles workspace ARN GET /v1/user_profiles/{id} Data Full, Inference, Limited, ReadOnly
ListUserProfiles User profiles workspace ARN GET /v1/user_profiles Data Full, Inference, Limited, ReadOnly
UpdateUserProfile User profiles workspace ARN POST /v1/user_profiles/{id} Data Full
CreateWorkspace Workspaces * (account-scoped) POST /v1/organizations/workspaces Management Full
GetWorkspace Workspaces workspace ARN GET /v1/organizations/workspaces/{id} Management Full, Inference, Limited, ReadOnly
ListWorkspaces Workspaces * (account-scoped) GET /v1/organizations/workspaces Management Full, Inference, Limited, ReadOnly
UpdateWorkspace Workspaces workspace ARN POST /v1/organizations/workspaces/{id} Management Full
ArchiveWorkspace Workspaces workspace ARN POST /v1/organizations/workspaces/{id}/archive Management Full
RegisterKey Encryption keys * (account-scoped) POST /v1/organizations/external_keys Management Full
GetKey Encryption keys * (account-scoped) GET /v1/organizations/external_keys/{id} Management Full, Inference, Limited, ReadOnly
ListKeys Encryption keys * (account-scoped) GET /v1/organizations/external_keys Management Full, Inference, Limited, ReadOnly
UpdateKey Encryption keys * (account-scoped) POST /v1/organizations/external_keys/{id} Management Full
DisableKey Encryption keys * (account-scoped) DELETE /v1/organizations/external_keys/{id} Management Full
ListComplianceActivities Compliance * (account-scoped) GET /v1/compliance/activities Management Full, Inference, Limited, ReadOnly
CallWithBearerToken Authentication * (route-less) (none) — Full, Inference, Limited, ReadOnly, SelfHostedEnvironment
AssumeConsole Console access * (route-less) (none) — Full

CloudTrail: Management events (default-on) = workspace, external key, compliance, vault, webhook actions; Data events (opt-in, extra cost) = inference, batch, model, file, skill, user profile and other Managed Agents actions. Access Transparency for this platform is delivered via the Compliance API (not CloudTrail).


# (g) Regions, IP addresses, data residency, retention, access transparency

# Supported regions (access from)

The official list enumerates 175 countries/territories (page: Supported regions) — including Canada, USA, UK, EU member states, Japan, South Korea, Australia, India, Brazil, Mexico, Israel, UAE, Saudi Arabia, South Africa, Ukraine (except Crimea, Donetsk, Luhansk). Notably absent: China, Russia, Iran, North Korea, Belarus, Venezuela, Cuba, Syria, Afghanistan, Ethiopia, Hong Kong, Macau. Full list reproduced in sources/anthropic/pages/api/supported-regions.md.

# IP addresses (fixed, "will not change without notice")

Direction Range
Inbound IPv4 (api.anthropic.com / Console) 160.79.104.0/23
Inbound IPv6 2607:6bc0::/48
Outbound IPv4 (egress for MCP connector, web search, web fetch — also for Claude Platform on AWS tool calls) 160.79.104.0/21
Phased out (remove from allowlists) 34.162.46.92/32, 34.162.102.82/32, 34.162.136.91/32, 34.162.142.92/32, 34.162.183.95/32

Claude Platform on AWS inbound endpoint aws-external-anthropic.{region}.api.aws resolves to AWS IP ranges.

# Data residency

Two independent controls (exact names from Data residency):

Control Where Values Notes
inference_geo (request body param on POST /v1/messages, also per-request in Batch API, and on Managed Agents agent/session config) per request "global" (default) · "us" Claude 4.6+ only (400 on Opus/Sonnet/Haiku 4.5 and older). Response usage.inference_geo reports where inference ran. "us" = 1.1× price on all token categories (and 1.1× Priority-Tier burndown). Available on Claude API + Claude Platform on AWS; not applicable on Bedrock / Vertex / Foundry (Foundry: US Data Zone Standard deployment) nor via the OpenAI-compat endpoint.
Workspace data_residency (Console or Admin API workspaces) per workspace allowed_inference_geos: [...], default_inference_geo: "us"|"global" Request geo outside the allowlist → error. Legacy "global routing opt-out" orgs were migrated to allowed_inference_geos: ["us"], default_inference_geo: "us".
Workspace geo (data at rest + endpoint processing such as image transcoding/code execution) set at workspace creation, immutable "us" only On Claude Platform on AWS not configurable (effective "us").

Limitations: rate limits shared across geos; only us/global inference geos; only us workspace geo.

# Retention (API and data retention)

  • Anthropic is the data processor for Claude API, Claude Platform on AWS and Claude in Microsoft Foundry (Bedrock / Vertex: cloud provider). Conversation content is not retained by default, except Covered Models (Claude Fable 5.1, Claude Mythos 5.1, Claude Fable 5, Claude Mythos 5) which require 30-day retention — a ZDR org gets 400 invalid_request_error: "In order to access this model, your organization or workspace must have data retention enabled." unless 30-day retention is enabled for the workspace (Console › Workspaces › Privacy controls).
  • ZDR (per org, via sales): covers Messages + Token Counting for eligible features, Claude Code with Commercial-org keys / Enterprise+ZDR, Claude Platform on AWS (on request). Not covered: Console/playground, Managed Agents (stateful), consumer plans, Teams/Enterprise UIs, Claude for Excel, Covered Models, third-party integrations, CORS (unsupported under ZDR), flagged content/legal holds (up to 2 years).
  • HIPAA readiness (BAA + HIPAA-enabled org, self-service in Console for eligible orgs): API blocks ineligible features with 400; HIPAA orgs have no local-session capture.
  • Feature eligibility (ZDR / HIPAA): Yes/Yes — Messages, token counting, thinking, adaptive thinking, effort, fast mode, 1M context, citations, PDF (inline), prompt caching (in-memory KV/hashes), search results, computer use, bash, text editor, memory tool, web search, fine-grained tool streaming, mid-conversation system messages, data residency. ZDR Yes / HIPAA No — advisor tool, browser use, context editing, compaction, tool search, web fetch, cache diagnostics (qualified). Qualified/Yes — structured outputs (schema cached ≤24 h). No/No — Batch (29-day retention), Files API, Skills, code execution & programmatic tool calling (containers ≤30 days), MCP connector, MCP tunnels, Managed Agents.
  • Compliance API data has its own retention model (Activity Feed 6 y; claude.ai content per org policy; session transcripts 6 y/custom).

# Access Transparency

  • Not self-serve; enabled per org (all workspaces) by the account team; enabling it also enables the Compliance API.
  • Each human view of covered content by Anthropic personnel writes an anthropic_access activity to the Activity Feed (filter activity_types[]=anthropic_access); automated processing does not, except cmek_preserve preservation records. Extra fields: accessed_at, accessor_department (e.g. Safeguards), reason_code ∈ {safety_review, incident_response, policy_violation_investigation, csae_report}, resource_details {type: "message", id, parent}, workspace_id; actor is always {type: "anthropic_actor", email_address: null}.
  • Covered: Claude API (api.anthropic.com) prompts/responses, Claude Code via API key, Claude Platform on AWS (events via Compliance API, not CloudTrail). Not covered: Batch & Files APIs, claude.ai Enterprise seats, Claude for Work, consumer plans, Console playground, Foundry, Bedrock, Vertex.
  • The anthropic_access / cmek_preserve strings are absent from the 506-value reference enum (see §c) — likely a reference-page lag.

# Adjacent (skimmed, not compliance endpoints)

  • Inference hooks (beta, Enterprise, organization:manage): inline allow/deny of each governed prompt by the org's own AI-security HTTPS server (prompt event only); complements the after-the-fact Compliance API. Toggles surface in effective settings / inference_* activity types.
  • App Attest: device-attested one-hour tokens for iOS/macOS apps calling /v1/messages (Claude API only); appears in the Activity Feed as attested_device_actor.

# Uncertainties / not verifiable offline

  1. Nothing was called: whether our key type would receive 404 Not found (documented for non-compliance keys) is inferred from docs, not observed.
  2. Scope for GET …/projects/{id}/collaborators and the Code Artifacts endpoints is not stated on their reference pages; recorded as read:compliance_user_data by resource family.
  3. anthropic_access / cmek_preserve activity types documented in Access Transparency are missing from the reference activity_types[] enum.
  4. anthropic-beta header value for the Admin compliance_settings endpoints is not documented (SDKs use ?beta=true).
  5. The reference pages' curl examples use Authorization: Bearer … while every guide uses x-api-key; both are recorded, x-api-key treated as canonical.
  6. Second rate-limit budget for remote-session endpoints has no documented numeric value.
  7. IAM: the page documents no condition keys; condition_keys is [] everywhere (not "none exist" — just none documented).