Status: DOCUMENTED · ACCOUNT_RESTRICTED (Compliance API requires an Enterprise org + compliance-scoped key; not available to this account — nothing live-tested)
Everything on this page is derived offline from the downloaded official docs (retrieved 2026-09-18). No request was made to any /v1/compliance/*, /v1/organizations/compliance_settings or AWS endpoint. The DELETE endpoints are destructive and permanent and must never be exercised by this project.
Sources
Last verified: 2026-09-18 (docs only)
Machine-readable twins: generated/fragments/endpoints/anthropic-compliance.json (36 compliance + 2 admin endpoints), generated/fragments/parameters/anthropic-compliance.json (146 params), generated/fragments/errors/anthropic-compliance.json (30 errors), generated/fragments/compatibility/anthropic-iam-actions.json (71 IAM actions), tmp/platform-anthropic/objects-compliance.json (27 objects).
# (a) What the Compliance API is
The Compliance API gives Claude Enterprise (and eligible standalone Claude Console) customers programmatic access to their organization's Activity Feed and — for Claude Enterprise tenants — to the directory (organizations, users, roles, groups), the effective settings of each linked organization, the underlying claude.ai chats, files, projects, and the transcripts of sessions run in Claude apps (Cowork, Claude Code, Claude Science, Claude for Microsoft 365, Claude in Chrome — local sessions; cloud Cowork — remote sessions), plus Claude Code Artifacts. Target users: security, legal, compliance (eDiscovery, DLP, SIEM ingestion, account-deletion responses).
Tenant model: a Claude Enterprise tenant = one parent organization (identity/SSO/SCIM) + linked organizations of two kinds (claude.ai orgs and Claude Console orgs). Parent orgs do not appear in Claude Console. A standalone Console org (no parent) can only use Admin API keys and only the Activity Feed.
# Who can use it / entitlement
| Situation |
How to enable |
Key |
| Claude Enterprise org |
Primary owner enables at claude.ai › Organization settings › API (cascades to all linked orgs) |
Compliance Access Key created in claude.ai |
| Standalone Claude Console org (eligible) |
Org admin toggles Compliance API at Console › Settings › Security (self-service, immediate) — or via Admin API POST /v1/organizations/compliance_settings |
Admin API key (Activity Feed only) |
| Console org linked to a parent |
Nothing to toggle in Console; parent's primary owner enables |
Compliance Access Key from parent |
| Claude Platform on AWS |
Enablement on request via account team; access via IAM action aws-external-anthropic:ListComplianceActivities (Activity Feed only) |
AWS SigV4 / AWS-issued API key |
Turning the Compliance API off stops activity recording and local-session capture (not retroactive, not recoverable), and stops Access Transparency delivery. Recording starts at first enablement — nothing is backfilled.
# Authentication
| Item |
Value |
| Base URL |
https://api.anthropic.com, all endpoints under /v1/compliance/* |
| Auth header |
x-api-key: <key> (the reference-page examples alternatively show Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY; the guides consistently use x-api-key) |
| Version header |
anthropic-version: 2023-06-01 required on every request |
| Beta header |
none documented for /v1/compliance/* |
| Key type 1 |
Compliance Access Key sk-ant-api01-… — created in claude.ai by primary owner (parent-wide or single-org) or org owner (own org); reaches all endpoints; scopes immutable after creation; no expiry |
| Key type 2 |
Admin API key sk-ant-admin01-… — Console › Settings › Admin keys; reaches Activity Feed only, and only carries read:compliance_activities if created while the Compliance API was enabled |
| Rejected |
Claude API keys sk-ant-api03-… and Analytics API keys → bare 404 Not found (not 401) |
Scopes
| Scope |
Grants |
read:compliance_activities |
Activity Feed (GET /v1/compliance/activities) |
read:compliance_user_data |
chats, messages, files, generated files, artifacts, projects, attachments, project documents, sessions (local + remote), organization users, group members (and, by family, collaborators and Code Artifacts) |
delete:compliance_user_data |
DELETE chats, files, project documents, projects, Code Artifacts |
read:compliance_org_data |
organizations, roles, role permissions, groups, effective organization settings |
read:org_audit |
read-only audit scope accepted by every read endpoint (Needed one of: lists it) |
read:compliance_org_settings |
RETIRED 2026-06-30 — settings endpoint now needs read:compliance_org_data |
# Rate limits (documented)
- 600 requests / minute per parent organization (per org for standalone Console orgs), one budget shared by every key, every linked org and every
/v1/compliance/* endpoint.
- Remote session endpoints carry a second, separate budget on top; its 429 always returns
retry-after: 1 and the anthropic-ratelimit-* headers on it describe the shared limit, so back off exponentially.
- Response headers once authenticated:
anthropic-ratelimit-requests-limit, anthropic-ratelimit-requests-remaining, anthropic-ratelimit-requests-reset (RFC 3339); 429 adds retry-after (seconds).
- Auth failures are rejected before the limiter (no quota); a 403 (scope) consumes one unit.
- Higher limits: contact Anthropic representative. (No account-specific observations — none available.)
| Endpoint family |
Sort |
Scheme |
Request |
Response |
| Activities |
newest first (order=desc default; asc for incremental sync) |
cursor |
limit (1–5000, default 100), after_id / before_id (one at a time) |
data[], has_more, first_id, last_id |
| Chats, chat messages |
oldest first (order_by=created_at|updated_at; messages order=asc|desc) |
cursor |
limit (1–1000), after_id / before_id |
data[]/chat_messages[], has_more, first_id, last_id |
| Organizations, users, roles, permissions, groups, members, projects, attachments, collaborators, Code Artifacts |
endpoint-specific (ascending creation / identifier) |
page token |
limit, page |
data[], has_more, next_page |
| Local & remote sessions and their messages |
sessions newest first; messages oldest first |
page token, forward only |
limit (sessions 1–500, messages 1–1000), page |
data[], next_page (no has_more — stop when next_page is null) |
| Files, generated files, artifacts, documents |
— |
none (fetch by ID) |
— |
object / binary |
Cursors and page tokens are opaque; reuse the same cursor on retry (a failed request does not advance position). Local-session messages page tokens expire 24 h after a walk starts; local-session list tokens older than 24 h are re-evaluated against the current retention boundary and may skip sessions. Cursors are scoped to the organization, so they survive key rotation.
# Error catalogue (from Handle Compliance API errors)
Standard Anthropic error body {"error": {"type", "message"}} + request-id header. Match on status + error.type, not on message text (except where noted).
| HTTP |
error.type |
code (atlas) |
Meaning (message semantics) |
Retry? |
Action |
| 400 |
invalid_request_error |
compliance_api_not_enabled |
Compliance API is not enabled for this organization — key valid but API not enabled (or turned off) for the org/parent; every endpoint returns it. |
False |
Enable the Compliance API (claude.ai > Organization settings > API for Enterprise; Console > Settings > Security toggle for standalone Console org), then resend. |
| 400 |
invalid_request_error |
unknown_query_parameter |
Unknown query parameter: 'created_at[gte]'. Did you mean 'created_at.gte'? — unrecognized params are rejected, not ignored. |
False |
Use dot notation for ranges (created_at.gte), [] suffix for arrays (activity_types[]), and after_id/before_id/page per endpoint. |
| 400 |
invalid_request_error |
invalid_parameter_value |
Message starts with the parameter name then the failed constraint, e.g. limit: Input should be less than or equal to 1000, created_at.gte: Input should be a valid datetime…, activity_types[].0: Input is not one of the permitted values., created_at.gte: Input should have timezone info, created_at.lt must be strictly after created_at.gte.; tool_use_input_max_bytes/tool_result_max_bytes accept positive int or -1. |
False |
Correct the named parameter; respect per-endpoint limit maxima; RFC 3339 timestamps with explicit UTC offset. |
| 400 |
invalid_request_error |
invalid_pagination_cursor |
Invalid activity_id format: '…' (activities) / Invalid pagination cursor for 'after_id' (chats) / The page parameter is not a valid cursor for this request. (local sessions, cursor bound to session+order) / The page cursor has expired. Restart the walk without a page parameter… (local session messages, 24 h). |
False |
Treat cursors as opaque; copy first_id/last_id/next_page unchanged; on expiry restart without page. |
| 401 |
authentication_error |
api_key_invalid |
API key is invalid. — value does not match a usable Compliance Access Key / Admin API key (truncated/altered). |
False |
Compare stored secret; create a new key if the copy is wrong. |
| 401 |
authentication_error |
api_key_deactivated |
API key has been deactivated. — key disabled or deleted. |
False |
Re-enable if only disabled; otherwise create a new key and rotate. |
| 401 |
authentication_error |
api_key_expired |
API key has expired. — Admin API key past its expiration (Compliance Access Keys have no expiry). |
False |
Create a new key and update the integration. |
| 403 |
permission_error |
insufficient_scope_activities |
Missing required scopes. Got: [...] Needed one of: ['read:compliance_activities', 'read:org_audit'] on GET /v1/compliance/activities. |
False |
Create a Compliance Access Key with read:compliance_activities, or use an Admin API key created while the Compliance API was enabled. |
| 403 |
permission_error |
insufficient_scope_org_data |
… Needed one of: ['read:compliance_org_data', 'read:org_audit'] on organizations/roles/groups/settings endpoints; Admin API keys cannot read org metadata. |
False |
Create a new Compliance Access Key with read:compliance_org_data. |
| 403 |
permission_error |
retired_scope_org_settings |
Got: ['read:compliance_org_settings'] Needed one of: ['read:compliance_org_data', 'read:org_audit'] — scope retired 2026-06-30; settings endpoint now needs read:compliance_org_data. |
False |
Create a new key with read:compliance_org_data, migrate, delete the old key. |
| 403 |
permission_error |
insufficient_scope_user_data |
… Needed one of: ['read:compliance_user_data', 'read:org_audit'] on chats/messages/files/projects/sessions/users/group-members; Admin API keys can never hold this scope. |
False |
Use a Compliance Access Key created in claude.ai with read:compliance_user_data. |
| 403 |
permission_error |
insufficient_scope_delete |
… Needed: ['delete:compliance_user_data'] on DELETE chats/files/projects/documents. |
False |
Create a separate key carrying delete:compliance_user_data (keep read and delete keys separate). |
| 404 |
not_found_error |
request_not_authenticated |
Bare Not found — no key, or a key type the Compliance API does not accept (e.g. sk-ant-api03- Claude API key); same body as a non-existent path; any endpoint incl. lists. Exception: organization settings endpoint returns 401 instead. |
False |
Send an sk-ant-api01- or sk-ant-admin01- key in x-api-key; check the path against the reference. |
| 404 |
not_found_error |
chat_not_found |
Chat conversation not found: '<claude_chat_id>' — hard-deleted, retention-expired, or outside key scope. User-deleted chats are NOT 404 (listed with deleted_at). |
False |
Reconcile against claude_chat_created / claude_chat_viewed activities; drop the ID from the queue. |
| 404 |
not_found_error |
file_not_found |
File not found: <uuid> — file missing/deleted (deleting a chat deletes its files); message uses the underlying UUID; applies to metadata, content and delete endpoints, chat files and project files. |
False |
Reconcile against claude_file_uploaded / claude_file_deleted / claude_chat_deleted activities. |
| 404 |
not_found_error |
generated_file_or_artifact_not_found |
Generated file not found: '…' (metadata) / Generated file content not found: '…' (content) / Artifact version not found: '…' (both artifact endpoints) — deleted with their chat. |
False |
Look up the chat via Get chat messages; if deleted_at set, remove from queue. |
| 404 |
not_found_error |
project_not_found |
No project is found with the provided id. (detail/attachments/collaborators) / No project found with provided id, or it has already been deleted. (DELETE). |
False |
Reconcile against claude_project_created / claude_project_deleted activities. |
| 404 |
not_found_error |
project_document_not_found |
No project document found with the provided id. / …, or it has already been deleted. (DELETE) — text project documents (claude_proj_doc_) only. |
False |
List current attachments via GET /v1/compliance/apps/projects/{project_id}/attachments. |
| 404 |
not_found_error |
local_session_not_found |
Local session not found. — not readable (other parent org), never existed, ZDR in effect, or fully aged out of retention; no transient form. Malformed non-clls_ ID → 400. |
False |
Confirm via the local session list; if absent, transcript is not retrievable. |
| 404 |
not_found_error |
local_sessions_not_available |
Local sessions are not available. — returned on EVERY local-session call incl. the list while the endpoints are unavailable to the parent org; independent of session ID; can be temporary. |
True |
Keep queued IDs; retry on the next scheduled run; if persistent contact Anthropic with request-id. |
| 404 |
not_found_error |
remote_session_not_found |
Remote session not found. — cse_ ID missing/deleted, outside scope, or session still pending (no transcript yet). Malformed ID → 400. |
conditional |
Check status via the remote session list; retry after it leaves pending; deleted sessions are gone. |
| 404 |
not_found_error |
organization_role_or_group_not_found |
The "<org_uuid>" organization does not exist or the requester is not authorized to access it. / Role not found. / Group not found. |
False |
Verify the ID against the corresponding list endpoint. |
| 404 |
not_found_error |
organization_settings_not_available |
organization not found in this organization's hierarchy — org not a linked child, invalid UUID, or settings endpoint not yet enabled for the parent (same body on purpose). |
False |
Verify against List organizations; if a known-good ID still 404s, contact your Anthropic representative. |
| 409 |
invalid_request_error |
project_has_attached_chats |
The "<claude_proj_id>" project cannot be deleted as it has chats attached to it. Delete or detach all chats, and try deleting the project again. (type is invalid_request_error — distinguish by 409). |
False |
List chats with user_ids[] + project_ids[], delete or detach each, retry the project delete. |
| 429 |
rate_limit_error |
compliance_rate_limit_exceeded |
Compliance API rate limit of 600 requests per minute per parent organization has been exceeded… — shared budget across all keys/linked orgs/endpoints; remote-session endpoints carry a second budget (its 429 has retry-after: 1 always). |
True |
Wait retry-after seconds (fallback exponential backoff 1 s → 60 s); do NOT advance the cursor. Headers: anthropic-ratelimit-requests-limit/-remaining/-reset. |
| 500 |
api_error |
— |
Deterministic failure when x-should-retry: false header present; otherwise transient. |
conditional |
Honor x-should-retry; if absent retry with exponential backoff (1 s → 60 s). |
| 502/503/504/529 |
— |
— |
Transient upstream/overload errors. |
True |
Retry with exponential backoff; check status.anthropic.com. Exception: some local-session 503s are not transient (see overloaded_error). |
| 503 |
overloaded_error |
local_sessions_index_unavailable |
The local-sessions index is temporarily unavailable. Try again shortly. — transient. |
True |
Retry with backoff; do not advance page cursor. |
| 503 |
overloaded_error |
local_sessions_captured_content_unavailable |
Captured content is temporarily unavailable. Try again shortly. — usually transient; persistent for CMEK orgs whose key is disabled/revoked/unreachable (never reported as not_captured). |
conditional |
Retry with backoff; if it keeps recurring for a CMEK org, check the key in your KMS and stop walking that org's transcripts. |
| 503 |
overloaded_error |
local_sessions_retention_overrides_unavailable |
The local-sessions index cannot currently evaluate retention overrides for this page/session. Try again later. — depends on the org's data/settings, can persist. |
conditional |
Do not hold the walk open: narrow created_at window or skip the session and retry on a later run (restart without page). |
Retry contract summary: 400/401/403/404/409 → fix and resend; 429 → wait retry-after, never advance the cursor; 500 → honour x-should-retry: false; 502/503/504/529 → exponential backoff (1 s → 60 s), except the local-session 503s above.
# (b) Endpoint tables per resource group
36 Compliance endpoints (36 reference leaf pages) + 2 Admin API compliance-settings endpoints. 5 endpoints are DELETE (⚠️ permanent hard-deletes — never call). All statuses are DOCUMENTED · ACCOUNT_RESTRICTED (docs-only; our account has no Enterprise/compliance entitlement).
# activities — scope: read:compliance_activities, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/activities |
Query compliance activities |
activity_types[], actor_ids[], after_id, before_id, created_at, exclude_activity_types[], limit, order, organization_ids[], user_ids[] |
{data, first_id, has_more, last_id} |
cursor |
DOCUMENTED · ACCOUNT_RESTRICTED |
# organizations — scope: read:compliance_org_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/organizations |
List organizations |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# organizations/users — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/organizations/{org_uuid}/users |
List organization users |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# organizations/roles — scope: read:compliance_org_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/organizations/{org_uuid}/roles |
List Compliance Roles |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/organizations/{org_uuid}/roles/{role_id} |
Get Compliance Role |
— |
{id, created_at, description, name, updated_at} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# organizations/roles/permissions — scope: read:compliance_org_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/organizations/{org_uuid}/roles/{role_id}/permissions |
List Compliance Role Permissions |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# organizations/settings — scope: read:compliance_org_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/organizations/{organization_id}/settings |
Get effective organization settings |
— |
{type, api_keys, organization_id, settings} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# groups — scope: read:compliance_org_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/groups |
List Compliance Groups |
limit, name_prefix, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/groups/{group_id} |
Get Compliance Group |
— |
{id, created_at, description, name, roles, source_type, updated_at} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# groups/members — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/groups/{group_id}/members |
List Compliance Group Members |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/chats — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/chats |
List chats |
after_id, before_id, created_at, limit, order_by, organization_ids[], project_ids[], updated_at, user_ids[] |
{data, first_id, has_more, last_id} |
cursor |
DOCUMENTED · ACCOUNT_RESTRICTED |
DELETE |
/v1/compliance/apps/chats/{claude_chat_id} |
Delete chat ⚠️ destructive |
— |
{type, id} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/chats/messages — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/chats/{claude_chat_id}/messages |
Get chat messages |
after_id, before_id, created_at, limit, order, tool_result_max_chars, tool_use_input_max_chars, updated_at |
{id, chat_messages, created_at, deleted_at, first_id, has_more, href, last_id…} |
cursor |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/chats/files — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
DELETE |
/v1/compliance/apps/chats/files/{claude_file_id} |
Delete file ⚠️ destructive |
— |
{type, id} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/chats/files/{claude_file_id} |
Get file metadata |
— |
{id, claude_chat_ids, created_at, filename, md5, message_ids, mime_type, size_bytes} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/chats/files/{claude_file_id}/content |
Download file content |
— |
binary stream (chunked) |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/chats/generated_files — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/chats/generated-files/{claude_gen_file_id} |
Get Claude-generated file metadata |
— |
{id, claude_chat_id, created_at, filename, md5, mime_type, size_bytes} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/chats/generated-files/{claude_gen_file_id}/content |
Download a Claude-generated file |
— |
binary stream (chunked) |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/artifacts — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/artifacts/{artifact_version_id} |
Get artifact metadata |
— |
{id, artifact_type, claude_chat_id, created_at, md5, size_bytes, title, version_id} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/artifacts/{artifact_version_id}/content |
Download artifact content |
— |
JSON {content, title, artifact_type} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/projects — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/projects |
List projects |
created_at, limit, organization_ids[], page, updated_at, user_ids[] |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
DELETE |
/v1/compliance/apps/projects/{project_id} |
Delete project ⚠️ destructive |
— |
{type, id} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/projects/{project_id} |
Get project details |
— |
{id, attachments_count, chats_count, created_at, deleted_at, description, instructions, is_private…} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/projects/attachments — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/projects/{project_id}/attachments |
List project attachments |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/projects/collaborators — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/projects/{project_id}/collaborators |
List project collaborators |
limit, page |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/projects/documents — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
DELETE |
/v1/compliance/apps/projects/documents/{document_id} |
Delete project document ⚠️ destructive |
— |
{type, id} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/projects/documents/{document_id} |
Get project document content |
— |
{id, content, created_at, filename, user} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/projects/documents/{document_id}/metadata |
Get project document metadata |
— |
{id, claude_project_id, created_at, filename, md5, mime_type, size_bytes, user} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/sessions/local — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/sessions/local |
List local sessions |
created_at, limit, page, updated_at |
{data, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/sessions/local/{local_session_id} |
Retrieve a local session |
— |
{type, id, created_at, organization_uuid, product_surface, truncated, updated_at, user…} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/sessions/local/{local_session_id}/messages |
Retrieve local session messages |
limit, order, page, tool_result_max_bytes, tool_use_input_max_bytes |
{data, next_page, session} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# apps/sessions/remote — scope: read:compliance_user_data, read:org_audit
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/sessions/remote |
List remote sessions |
created_at, limit, organization_ids[], page, user_ids[] |
{data, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/sessions/remote/{claude_remote_session_id}/messages |
Retrieve remote session messages |
limit, order, page, tool_result_max_bytes, tool_use_input_max_bytes |
{data, next_page, session} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
# code/artifacts — scope: read:compliance_user_data, read:org_audit · DELETE: delete:compliance_user_data
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/compliance/apps/code/artifacts |
List Code Artifacts |
limit, organization_ids[], page, updated_at, user_ids[] |
{data, has_more, next_page} |
page_token |
DOCUMENTED · ACCOUNT_RESTRICTED |
DELETE |
/v1/compliance/apps/code/artifacts/{artifact_id} |
Delete Code Artifact ⚠️ destructive |
— |
{type, id} |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
GET |
/v1/compliance/apps/code/artifacts/{artifact_id}/versions/{version_id} |
Download Code Artifact Version Content |
— |
binary stream (chunked) |
— |
DOCUMENTED · ACCOUNT_RESTRICTED |
# admin/compliance_settings — scope: Admin API key (org admin)
| Method |
Path |
Title |
Key query params |
Returns |
Pagination |
Status |
GET |
/v1/organizations/compliance_settings |
Get Compliance Settings |
— |
BetaComplianceSettings object |
— |
DOCUMENTED · BETA · ACCOUNT_RESTRICTED |
POST |
/v1/organizations/compliance_settings |
Update Compliance Settings |
— |
BetaComplianceSettings object |
— |
DOCUMENTED · BETA · ACCOUNT_RESTRICTED |
# Activity Feed query parameters (GET /v1/compliance/activities)
| Parameter |
In |
Type |
Required |
Default |
Min/Max |
Description |
activity_types[] |
query |
enum (506 values) |
False |
— |
— |
Filter activities by type. See the response data schema for the additional fields each type returns. Cannot be combined with exclude_activity_types[]. |
actor_ids[] |
query |
array of string |
False |
— |
— |
Filter activities by actor IDs (currently only user_... IDs are supported). Enumerate IDs via GET /v1/compliance/organizations/{org_uuid}/users. |
after_id |
query |
string |
False |
— |
— |
Pagination cursor for retrieving the next page of results. To paginate, pass the last_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpret it |
before_id |
query |
string |
False |
— |
— |
Pagination cursor for retrieving the previous page of results. To paginate, pass the first_id value from the most recent response. Clients should treat this value as an opaque string and not attempt to parse or interpr |
created_at |
query |
object |
False |
— |
— |
|
created_at.gt |
query |
string |
False |
— |
— |
Filter activities created after this time (RFC 3339 format) |
created_at.gte |
query |
string |
False |
— |
— |
Filter activities created at or after this time (RFC 3339 format) |
created_at.lt |
query |
string |
False |
— |
— |
Filter activities created before this time (RFC 3339 format) |
created_at.lte |
query |
string |
False |
— |
— |
Filter activities created at or before this time (RFC 3339 format) |
exclude_activity_types[] |
query |
enum (506 values) |
False |
— |
— |
Exclude activities of these types. Cannot be combined with activity_types[]. |
limit |
query |
number |
False |
100 |
1/5000 |
Maximum results (default: 100, max: 5000) |
order |
query |
enum: asc, desc |
False |
desc |
— |
Sort direction by created_at. desc (default) returns newest-first; asc returns oldest-first for incremental sync. Activities become queryable after a short asynchronous ingestion delay. When using asc with `after |
organization_ids[] |
query |
array of string |
False |
— |
— |
Filter activities by organization IDs (accepts org_... or organization UUID). Enumerate IDs via GET /v1/compliance/organizations. |
user_ids[] |
query |
array of string |
False |
— |
— |
Alias for actor_ids[], for consistency with other compliance routes. If both are provided, the lists are merged. |
Repeatable filters use bracket syntax (activity_types[]=a&activity_types[]=b); range filters use dot notation (created_at.gte). Unknown parameters are rejected with 400. activity_types[] and exclude_activity_types[] are mutually exclusive.
# Session transcript parameters
GET …/sessions/local/{id}/messages and GET …/sessions/remote/{id}/messages share: limit (1–1000, default 100), order (asc default / desc), page, tool_use_input_max_bytes and tool_result_max_bytes (default 10 000 bytes; -1 = server maximum ≈ 1 MiB; 0 invalid). Chat messages use tool_use_input_max_chars / tool_result_max_chars instead (chars, not bytes).
# (c) Data model
Identifier prefixes: org_ (tagged org id) / bare UUID (organization_uuid), user_, claude_chat_, claude_chat_msg_, claude_file_, claude_gen_file_, claude_artifact_ / claude_artifact_version_, claude_proj_, claude_proj_doc_, clls_ (local session), clsm_ (local session message), cse_ (remote session), csev_ (remote message), cagt_ (agent owner of a remote session), wrkspc_, apikey_, activity_. user_id is the stable join key (survives email changes and account deletion).
# Activity (Activity Feed event)
Common fields: id, created_at (RFC 3339), organization_id (org_… or null for sign-in/sign-out/Compliance-API-call events), organization_uuid, actor (union), type, plus type-specific fields (e.g. claude_chat_id, claude_project_id, filename). Retained 6 years; queryable within ~1 minute; at-least-once delivery → dedupe on id. claude_*_viewed events mean an app loaded the content, not that a human viewed it.
Actor union (actor.type) — 11 variants documented in the reference:
actor.type |
Fields |
When |
user_actor |
email_address, user_id, ip_address, user_agent |
signed-in claude.ai / Console user |
api_actor |
api_key_id, ip_address, user_agent |
Claude API or Compliance API call with a customer key (both key types) |
admin_api_key_actor |
admin_api_key_id, ip_address, user_agent |
Admin API management action |
unauthenticated_user_actor |
unauthenticated_email_address (nullable), ip_address, user_agent |
pre-sign-in (e.g. sso_login_initiated) |
anthropic_actor |
email_address (always null) |
Anthropic acted (incl. Access Transparency anthropic_access) |
system_actor |
service (nullable) |
automated Anthropic background processing |
service_account_actor |
service_account_id, ip_address, user_agent |
service account |
scim_directory_sync_actor |
workos_event_id, directory_id, idp_connection_type (e.g. OktaSCIMV2, AzureSCIMV2) |
IdP SCIM push |
federated_identity_actor |
issuer, subject, audience[], ip_address?, user_agent? |
OIDC workload identity |
federated_actor |
provider ∈ {aws (account_id, signed_principal), azure (subscription_id), gcp (project_number), oidc (issuer)}, subject?, ip_address?, user_agent? |
cloud-federated caller (e.g. Claude Platform on AWS) |
attested_device_actor |
external_client_id, kid_hash, ip_address?, user_agent? |
App Attest device token |
Activity types — the reference enumerates 506 values for activity_types[] (the guide says "hundreds"). Grouped:
| Family |
Count |
Examples |
| org_* (organization settings toggles) |
98 |
org_compliance_api_settings_updated, org_claude_code_zero_data_retention_disabled, org_claude_code_desktop_enabled |
| platform_* (Claude Console: keys, workspaces, members, usage views) |
85 |
platform_usage_report_claude_code_viewed, … |
| claude_* (claude.ai chats/files/projects/artifacts/skills/plugins) |
77 |
claude_chat_created/viewed/deleted, claude_file_uploaded/exported, claude_project_document_uploaded, claude_artifact_published, claude_skill_created |
| integrations (tunnel_/mcp_/desktop_/ghe_/github_/slack_) |
42 |
|
| billing / workspaces / service accounts / LTI / marketplace |
37 |
|
| ccr_* (Claude in Slack / channel agents) |
36 |
ccr_agent_created, ccr_session_created, ccr_slack_channel_joined |
| other |
34 |
compliance_api_accessed, cowork_session_updated, api_key_created, audit_log_export_started, admin_api_key_created, cli_plugin_exec_policy_updated |
| claude_code_* |
34 |
claude_code_credential_revoked, claude_code_security_scan_created, claude_code_user_settings_updated |
| group_/rbac_/role_* (RBAC) |
23 |
|
| auth & identity (sso_/scim_/magic_/trusted_device …) |
22 |
sso_login_initiated, account_deleted, abuse_decision_received, age_verified |
| design_* (Claude Design) |
12 |
|
| inference_* (inference hooks) |
6 |
|
| Total |
506 |
full enum in generated/fragments/parameters/anthropic-compliance.json (activity_types[]) |
Notable types: compliance_api_accessed (every Compliance API call; actor.api_key_id attributes it to a key), org_compliance_api_settings_updated (toggle on/off), audit_log_export_started/accessed, claude_chat_created/viewed/deleted, claude_file_uploaded/deleted/exported, claude_project_document_uploaded, sso_login_initiated. Access Transparency documents anthropic_access and cmek_preserve event types, but neither string appears in the reference enum — treat as DOCUMENTATION_INCOMPLETE (guide vs reference mismatch).
# Organizations, users, roles, permissions, groups
| Object |
Fields |
ComplianceOrganization |
uuid, name, created_at — list sorted by creation asc; parent-scoped key sees every linked org |
ComplianceOrganizationUser |
id (user_), email, full_name, created_at, organization_role ∈ {admin, billing, claude_code_user, developer, managed, membership_admin, owner, parent_org_admin, parent_org_owner, primary_owner, user} |
ComplianceRole |
id, name, description, created_at, updated_at (custom RBAC roles) |
ComplianceRolePermission |
action, resource_type, resource_id |
ComplianceGroup |
id, name, description, roles[] (role ids), source_type ∈ {direct, scim}, created_at, updated_at; list filter name_prefix |
ComplianceGroupMember |
user_id, email, created_at, updated_at |
# Effective organization settings (GET /v1/compliance/organizations/{organization_id}/settings)
Returns {type: "effective_organization_settings", organization_id (bare UUID), settings[], api_keys[]}. Rows reflect the enforced state (after HIPAA/regulatory restrictions, feature availability, org-type defaults, inter-feature dependencies); a setting the org's admins cannot change is omitted (missing ≠ off). api_keys[] lists every Compliance Access Key of the parent (type: compliance_api_key, id, name, scopes[], is_active, created_at, created_by_id, expires_at) — never secrets. Target must be a linked org (not the parent). Unauthenticated requests get 401 here (404 elsewhere).
Row type |
value shape |
Setting names |
Boolean |
boolean |
access_transparency_enabled, ai_powered_artifacts_enabled, api_workbench_feedback_collection_enabled, api_zero_data_retention_enabled, artifact_connectors_enabled, ask_your_org_enabled, chat_enabled, claude_ai_chat_sharing_enabled, claude_ai_feedback_collection_enabled, claude_ai_integration_sharing_enabled, claude_ai_skill_plugins_scanning_enabled, claude_code_desktop_bypass_permissions_enabled, claude_code_desktop_enabled, claude_code_fast_mode_enabled, claude_code_metrics_logging_enabled, claude_code_remote_control_enabled, claude_code_review_enabled, claude_code_routines_enabled, claude_code_security_enabled, claude_code_trusted_devices_required, claude_code_web_enabled, claude_code_workflows_enabled, claude_design_enabled, claude_enterprise_claude_code_zero_data_retention_enabled, claude_in_slack_enabled, claude_science_custom_connectors_enabled, claude_science_custom_skills_enabled, claude_science_enabled, claude_science_managed_network_allowlist_enabled, claude_science_memory_enabled, claude_science_modal_enabled, claude_science_scientific_model_endpoints_enabled, claude_science_ssh_hosts_enabled, cmek_enabled, code_execution_enabled, code_execution_network_egress_enabled, connector_tools_default_always_allow, content_redaction_enabled, cowork_trusted_devices_required, desktop_extension_allowlist_enabled, directory_sync_enabled, frontier_data_use_enabled, group_skill_sharing_enabled, hipaa_compliance_enabled, inline_visualizations_enabled, ip_allowlist_enabled, location_metadata_enabled, member_usage_dashboard_visible, memory_enabled, org_wide_skill_sharing_enabled, public_projects_enabled, skill_sharing_enabled, skills_enabled, sso_claude_ai_enforced, sso_console_enforced, sso_enabled, third_party_interactive_content_enabled, user_skill_creation_enabled, web_search_enabled, work_across_apps_enabled |
Integer |
number or null |
account_session_duration_seconds |
String |
string or null |
claude_code_default_worker_environment_id, claude_code_default_worker_pool_id |
StringList |
array of string |
allowed_invite_domains, disabled_admin_request_types, ip_allowlist_ip_ranges |
ProvisioningMode |
"jit_advanced" or "jit_permissive" or "login_only" or 2 more ∈ {jit_advanced, jit_permissive, login_only, scim_advanced, scim_permissive} |
sso_provisioning_mode |
DataRetention |
map[data_type → {type:'fixed', duration:number, timescale:'day'|'month'} | {type:'indefinite'}] — key all is exclusive; keys seen: chat (example) |
data_retention_periods |
# Chats, messages, files, generated files, artifacts
ComplianceChat (list item): id, name, model, organization_uuid, organization_id (deprecated), project_id, user {id, email_address} (null when key is single-org restricted), href, created_at, updated_at, deleted_at (set when the user deleted it in claude.ai — chat stays listed, content gone). List filters: user_ids[] (≤10), organization_ids[], project_ids[] (requires user_ids[]), created_at.*, updated_at.*, order_by. Legacy filter param rejected after 2026-09-22.
ComplianceChatMessages: chat fields + chat_messages[] (id, role ∈ {user, assistant}, created_at, content[] of text {text, thinking_redacted, truncated} / tool_use {id, name, input (JSON string), integration_name, mcp_server_url, truncated} / tool_result {tool_use_id, name, content[], is_error, integration_name, mcp_server_url, truncated}, files[], generated_files[], artifacts[] {id, version_id, title, artifact_type}) + has_more, first_id, last_id.
ComplianceFileMetadata: id, filename, mime_type, size_bytes, md5, claude_chat_ids[], message_ids[], created_at. Content endpoint streams the stored variant (may be extracted text for Word/PowerPoint/some PDFs) with Content-Disposition: attachment; filename*=utf-8''…, Content-Type, Content-MD5 (base64), Transfer-Encoding: chunked.
ComplianceGeneratedFileMetadata: id (claude_gen_file_), claude_chat_id, filename, mime_type, size_bytes, md5, created_at.
ComplianceArtifactVersionMetadata: id, version_id, claude_chat_id, title, artifact_type (e.g. application/vnd.ant.code), md5, size_bytes, created_at. Content endpoint returns JSON {content, title, artifact_type} for one version.
# Projects
ComplianceProject / ComplianceProjectDetails: id, name, description, instructions, is_private, organization_uuid, user, created_at, updated_at, deleted_at, chats_count, attachments_count.
- Attachments (union on
type): project_file {id claude_file_, filename, mime_type, size_bytes, md5, created_at} → download via the chat-files content endpoint; project_doc {id claude_proj_doc_, filename, mime_type text/plain, updated_at} → GET /v1/compliance/apps/projects/documents/{document_id} (content string) or /metadata (md5, size_bytes, claude_project_id, user).
- Collaborators (union on
type): user {user_id}, group {group_id}, organization {organization_uuid}, organization_role {organization_role}; each with role ∈ {owner, admin, editor, viewer} and granted_at.
DELETE project → 409 while chats are attached.
# Sessions — local vs remote
|
Local sessions |
Remote sessions |
| What |
Sessions on users' machines while signed in with Enterprise account: Cowork (Desktop), Claude Code (terminal/Desktop/IDE), Claude Science, Claude for Microsoft 365, Claude in Chrome |
Cowork sessions started on claude.ai web/mobile, run in Anthropic-managed cloud |
| Endpoints |
GET …/sessions/local, …/local/{id}, …/local/{id}/messages |
GET …/sessions/remote, …/remote/{id}/messages |
| ID prefix |
clls_ (messages clsm_) |
cse_ (messages csev_) |
product_surface |
cowork, claude_code, claude_science, claude_in_chrome, office_agents[/excel|/powerpoint|/word|/outlook] |
cowork_remote |
| Object |
type: compliance_local_session, id, organization_uuid, workspace_id?, user {id, email_address?}, product_surface, created_at (first retained call), updated_at (last), truncated — no status, no deleted_at |
id, organization_uuid, user? / agent_id? (cagt_) + started_by_user?, status ∈ {pending, active, paused, archived, failed}, product_surface, claude_project_id?, created_at, updated_at |
| List filters |
created_at.gte/.lt (RFC 3339 with offset; lt strictly after gte), updated_at.gte; no user/org filter |
organization_ids[] (≤500), user_ids[] (1–10, excludes agent-owned), created_at.* |
| Message object |
type: compliance_local_session_message, id, role, created_at, model?, content[] (text / tool_use / tool_result), provenance ∈ {null, content_unavailable {reason e.g. not_captured, retention_elapsed}, client_asserted, synthetic_marker (system-prompt stand-in)} |
id, role, created_at, content[], content_unavailable (bool), sent_by_user_id? |
| Retention |
6 years by default, or the org's finite custom conversation retention period (shortest wins); enforced read-side per inference call |
6 years unless the user deletes the session (then unlisted; messages → 404) |
| Rate budget |
shared 600 rpm only |
shared + second remote budget |
| Excluded |
Claude Code with Console API key / Bedrock / Vertex / Foundry; Claude Code cloud sessions; HIPAA-enabled orgs; ZDR sessions; thinking blocks, images/binary, tool & MCP definitions, system prompt, citations |
thinking blocks and images |
| CMEK |
transcripts encrypted under customer key; unusable key → 503 Captured content is temporarily unavailable (persistent) |
— |
Both families are read-only (no delete). Coverage is stable for Cowork and Claude Code; Science / Microsoft 365 / Chrome coverage is beta.
# Claude Code Artifacts (/v1/compliance/apps/code/artifacts)
ComplianceCodeArtifact: id, organization_uuid, owner_user_id?, user?, read_mode ∈ {owner, users, org, public}, published_version_id?, updated_at?, versions[] {id, name, created_at} (≈20 most recent). List sorted by identifier (not time) with page/next_page (pages may be short/empty while next_page is set); filters organization_ids[] (≤500), user_ids[] (≤200), updated_at.*. Version content is streamed (Content-MD5; early-terminated chunked transfer is the only truncation signal; 503 while upload in flight). DELETE initiates asynchronous permanent removal.
# (d) Integration patterns
- Window polling: tile with
created_at.gte (inclusive) / created_at.lt (exclusive), keep lt ≥ 1 min in the past (documented indexing lag), overlap windows by a few minutes or run reconciliation; dedupe on id. Page inside a window with after_id=last_id while has_more.
- Cursor-driven incremental reads: persist
first_id, pass as before_id to get newer events (walk toward the present until has_more is false, then persist); backfill with after_id=last_id. Alternative: order=asc + after_id. Cursors survive key rotation.
- Chats export: omit
user_ids[], set order_by=updated_at, paginate with after_id — picks up new, modified and user-deleted chats in one loop.
- SIEM correlation: join on
actor.user_id (primary), actor.email_address, actor.ip_address, actor.user_agent, created_at; ingest compliance_api_accessed to audit who queried compliance data.
- Retention horizons: Activity Feed 6 y (Anthropic) · chat/file/project content = org's claude.ai retention policy or until user deletion · local transcripts 6 y or custom period · remote transcripts 6 y or user deletion · hard-deleted content: gone immediately. Export before retention/deletion if your legal hold is longer; the API cannot return removed content.
- Completeness: at-least-once delivery, no
total_count/checksum; log start cursor, terminal last_id, record count, run time and final request-id; store provenance + content hash for chain of custody.
- Deletion endpoints (
DELETE chat / file / project document / project / Code Artifact): require delete:compliance_user_data, return {id, type: "<resource>_deleted"} (claude_chat_deleted, claude_file_deleted, claude_project_document_deleted, claude_project_deleted, code_artifact_deleted), immediate and irreversible — archive first, use a separate delete-scoped key, never call from this project.
- Sandbox: no test sandbox is documented (FAQ "How do I get a sandbox…" → contact account team).
# (e) Admin API compliance settings (beta)
Singleton per Console organization, Admin API key (org admin). Not available on Claude Platform on AWS (workspace/external-key routes are the only Admin routes there).
| Method |
Path |
Body |
Returns |
SDK |
GET |
/v1/organizations/compliance_settings |
— |
{type: "compliance_settings", state: {type: "enabled"|"disabled"}}; a child org reads the state inherited from its parent |
client.beta.organization.compliance_settings.retrieve() / client.beta.organization.complianceSettings.retrieve() |
POST |
/v1/organizations/compliance_settings |
{"state": {"type": "enabled"}} or string shorthand "enabled"/"disabled" |
same object (canonical form) |
.update(state=…) |
Semantics: enabled turns the Compliance API on and starts capturing events; disabled stops both; setting the current value is a no-op success; a disabled state is overridden by a later provisioning action that enables Access Transparency (which re-enables the Compliance API); automated provisioning never disables. Reference example uses X-Api-Key + anthropic-version; SDK surfaces route it as …/compliance_settings?beta=true; no anthropic-beta header value is documented (uncertain).
What it is. Claude Platform on AWS is the full Anthropic platform (Messages API, Files, Skills, Batches, Managed Agents, beta features) operated by Anthropic but reached through your AWS account: AWS supplies authentication (SigV4 or API key), IAM-based access control, CloudTrail and Marketplace billing. Unlike Bedrock (AWS runs inference; SigV4 service bedrock/bedrock-mantle), here the base URL is https://aws-external-anthropic.{region}.api.aws/v1/…, request/response shapes are the first-party Claude API, and every request carries anthropic-workspace-id: wrkspc_…. Available in all AWS commercial regions; the workspace's AWS region scopes the gateway endpoint, IAM, CloudTrail and billing — not where inference runs (use inference_geo).
Auth flow
| Path |
Mechanism |
IAM requirement |
| SigV4 (primary) |
Sign requests with AWS credentials from the default provider chain (env vars, ~/.aws/credentials, SSO/credential_process, ECS/IMDS roles). curl: --aws-sigv4 "aws:amz:<region>:aws-external-anthropic" (+ x-amz-security-token for temporary creds). SDKs: platform clients (AnthropicAWS / AnthropicAws) sign and add the workspace header. |
route action(s) on the workspace ARN, e.g. CreateInference |
| API key (bearer) |
Key generated in AWS Console › Claude Platform on AWS › API keys; sent as x-api-key (env ANTHROPIC_AWS_API_KEY / apiKey). |
route action(s) + CallWithBearerToken on Resource: "*" |
| Short-term token |
AWS token-generator libraries (JS/Python/Java) mint a ≤12 h token from SigV4 creds, used as x-api-key; not auto-refreshed. |
same as API key (CallWithBearerToken) |
| Console |
AWS Console › Open Claude Console federation; Console role (Admin/Developer) assigned by Anthropic rep, not derived from IAM. |
AssumeConsole on Resource: "*" |
Credential precedence in SDKs: apiKey arg → awsAccessKey+awsSecretAccessKey → awsProfile → ANTHROPIC_AWS_API_KEY → default provider chain. OAuth is not supported. Organization membership = AWS IAM (no Admin API member endpoints).
Service details: IAM prefix aws-external-anthropic; single resource type workspace; ARN arn:aws:aws-external-anthropic:{region}:{account-id}:workspace/{workspace-id} (resource segment = the wrkspc_ id). 71 actions; beta variants of a route need no extra action; every unlisted route is denied. No service-specific IAM condition keys are documented. IAM matching is case-insensitive and *File also matches *UserProfile — enumerate Files actions explicitly.
Managed policies (all on Resource: "*"): AnthropicFullAccess (*), AnthropicReadOnlyAccess (Get*, List*, CallWithBearerToken), AnthropicInferenceAccess (Get*, List*, CreateInference, CreateBatchInference, CancelBatchInference, DeleteBatchInference, CountTokens, CallWithBearerToken), AnthropicLimitedAccess (InferenceAccess + all Managed Agents actions), AnthropicSelfHostedEnvironmentAccess (GetEnvironment, ProcessEnvironmentWork, GetSession, UpdateSession, GetSkill, CallWithBearerToken). Get*/List* wildcards grant content reads (file bytes, skill content, batch results, session history, memories, key metadata) and ListComplianceActivities; AssumeConsole is only in FullAccess. Wildcard gotchas: Archive*, ProcessEnvironmentWork, RotateWebhookSecret, RegisterKey, DisableKey are not matched by Create*/Update*/Delete*; sub-resource create/delete maps to Update<Parent>.
Complete IAM action table (condition keys: none documented for any action)
Action (aws-external-anthropic:) |
Group |
Resource |
Routes authorized |
CloudTrail |
In managed policies |
CreateInference |
Inference |
workspace ARN |
POST /v1/messages |
Data |
Full, Inference, Limited |
CountTokens |
Inference |
workspace ARN |
POST /v1/messages/count_tokens |
Data |
Full, Inference, Limited |
CreateBatchInference |
Batch processing |
workspace ARN |
POST /v1/messages/batches |
Data |
Full, Inference, Limited |
GetBatchInference |
Batch processing |
workspace ARN |
GET /v1/messages/batches/{id}
GET /v1/messages/batches/{id}/results |
Data |
Full, Inference, Limited, ReadOnly |
ListBatchInferences |
Batch processing |
workspace ARN |
GET /v1/messages/batches |
Data |
Full, Inference, Limited, ReadOnly |
CancelBatchInference |
Batch processing |
workspace ARN |
POST /v1/messages/batches/{id}/cancel |
Data |
Full, Inference, Limited |
DeleteBatchInference |
Batch processing |
workspace ARN |
DELETE /v1/messages/batches/{id} |
Data |
Full, Inference, Limited |
GetModel |
Models |
workspace ARN |
GET /v1/models/{id} |
Data |
Full, Inference, Limited, ReadOnly |
ListModels |
Models |
workspace ARN |
GET /v1/models |
Data |
Full, Inference, Limited, ReadOnly |
CreateFile |
Files |
workspace ARN |
POST /v1/files |
Data |
Full |
GetFile |
Files |
workspace ARN |
GET /v1/files/{id}
GET /v1/files/{id}/content |
Data |
Full, Inference, Limited, ReadOnly |
ListFiles |
Files |
workspace ARN |
GET /v1/files |
Data |
Full, Inference, Limited, ReadOnly |
DeleteFile |
Files |
workspace ARN |
DELETE /v1/files/{id} |
Data |
Full |
CreateSkill |
Skills |
workspace ARN |
POST /v1/skills |
Data |
Full |
GetSkill |
Skills |
workspace ARN |
GET /v1/skills/{id}
GET /v1/skills/{id}/versions
GET /v1/skills/{id}/versions/{version}
GET /v1/skills/{id}/versions/{version}/content |
Data |
Full, Inference, Limited, ReadOnly, SelfHostedEnvironment |
ListSkills |
Skills |
workspace ARN |
GET /v1/skills |
Data |
Full, Inference, Limited, ReadOnly |
UpdateSkill |
Skills |
workspace ARN |
POST /v1/skills/{id}/versions
DELETE /v1/skills/{id}/versions/{version} |
Data |
Full |
DeleteSkill |
Skills |
workspace ARN |
DELETE /v1/skills/{id} |
Data |
Full |
CreateAgent |
Agents |
workspace ARN |
POST /v1/agents |
Data |
Full, Limited |
GetAgent |
Agents |
workspace ARN |
GET /v1/agents/{id}
GET /v1/agents/{id}/versions |
Data |
Full, Inference, Limited, ReadOnly |
ListAgents |
Agents |
workspace ARN |
GET /v1/agents |
Data |
Full, Inference, Limited, ReadOnly |
UpdateAgent |
Agents |
workspace ARN |
POST /v1/agents/{id} |
Data |
Full, Limited |
ArchiveAgent |
Agents |
workspace ARN |
POST /v1/agents/{id}/archive |
Data |
Full, Limited |
CreateSession |
Sessions |
workspace ARN |
POST /v1/sessions |
Data |
Full, Limited |
GetSession |
Sessions |
workspace ARN |
GET /v1/sessions/{id}
GET /v1/sessions/{id}/events
GET /v1/sessions/{id}/events/stream
GET /v1/sessions/{id}/resources
GET /v1/sessions/{id}/resources/{id} |
Data |
Full, Inference, Limited, ReadOnly, SelfHostedEnvironment |
ListSessions |
Sessions |
workspace ARN |
GET /v1/sessions |
Data |
Full, Inference, Limited, ReadOnly |
UpdateSession |
Sessions |
workspace ARN |
POST /v1/sessions/{id}
POST /v1/sessions/{id}/events
POST /v1/sessions/{id}/resources
POST /v1/sessions/{id}/resources/{id}
DELETE /v1/sessions/{id}/resources/{id} |
Data |
Full, Limited, SelfHostedEnvironment |
ArchiveSession |
Sessions |
workspace ARN |
POST /v1/sessions/{id}/archive |
Data |
Full, Limited |
DeleteSession |
Sessions |
workspace ARN |
DELETE /v1/sessions/{id} |
Data |
Full, Limited |
CreateEnvironment |
Environments |
workspace ARN |
POST /v1/environments |
Data |
Full, Limited |
GetEnvironment |
Environments |
workspace ARN |
GET /v1/environments/{id}
GET /v1/environments/{id}/work
GET /v1/environments/{id}/work/{work_id}
GET /v1/environments/{id}/work/stats |
Data |
Full, Inference, Limited, ReadOnly, SelfHostedEnvironment |
ListEnvironments |
Environments |
workspace ARN |
GET /v1/environments |
Data |
Full, Inference, Limited, ReadOnly |
UpdateEnvironment |
Environments |
workspace ARN |
POST /v1/environments/{id} |
Data |
Full, Limited |
ArchiveEnvironment |
Environments |
workspace ARN |
POST /v1/environments/{id}/archive |
Data |
Full, Limited |
DeleteEnvironment |
Environments |
workspace ARN |
DELETE /v1/environments/{id} |
Data |
Full, Limited |
ProcessEnvironmentWork |
Environments |
workspace ARN |
GET /v1/environments/{id}/work/poll
POST /v1/environments/{id}/work/{work_id}
POST /v1/environments/{id}/work/{work_id}/ack
POST /v1/environments/{id}/work/{work_id}/heartbeat
POST /v1/environments/{id}/work/{work_id}/stop |
Data |
Full, Limited, SelfHostedEnvironment |
CreateVault |
Vaults |
workspace ARN |
POST /v1/vaults |
Management |
Full, Limited |
GetVault |
Vaults |
workspace ARN |
GET /v1/vaults/{id}
GET /v1/vaults/{id}/credentials
GET /v1/vaults/{id}/credentials/{id} |
Management |
Full, Inference, Limited, ReadOnly |
ListVaults |
Vaults |
workspace ARN |
GET /v1/vaults |
Management |
Full, Inference, Limited, ReadOnly |
UpdateVault |
Vaults |
workspace ARN |
POST /v1/vaults/{id}
POST /v1/vaults/{id}/credentials
POST /v1/vaults/{id}/credentials/{id}
POST /v1/vaults/{id}/credentials/{id}/archive
DELETE /v1/vaults/{id}/credentials/{id} |
Management |
Full, Limited |
ArchiveVault |
Vaults |
workspace ARN |
POST /v1/vaults/{id}/archive |
Management |
Full, Limited |
DeleteVault |
Vaults |
workspace ARN |
DELETE /v1/vaults/{id} |
Management |
Full, Limited |
CreateMemoryStore |
Memory stores |
workspace ARN |
POST /v1/memory_stores |
Data |
Full, Limited |
GetMemoryStore |
Memory stores |
workspace ARN |
GET /v1/memory_stores/{id}
GET /v1/memory_stores/{id}/memories
GET /v1/memory_stores/{id}/memories/{id}
GET /v1/memory_stores/{id}/memory_versions
GET /v1/memory_stores/{id}/memory_versions/{id} |
Data |
Full, Inference, Limited, ReadOnly |
ListMemoryStores |
Memory stores |
workspace ARN |
GET /v1/memory_stores |
Data |
Full, Inference, Limited, ReadOnly |
UpdateMemoryStore |
Memory stores |
workspace ARN |
POST /v1/memory_stores/{id}
POST /v1/memory_stores/{id}/memories
POST /v1/memory_stores/{id}/memories/{id}
DELETE /v1/memory_stores/{id}/memories/{id}
POST /v1/memory_stores/{id}/memory_versions/{id}/redact |
Data |
Full, Limited |
ArchiveMemoryStore |
Memory stores |
workspace ARN |
POST /v1/memory_stores/{id}/archive |
Data |
Full, Limited |
DeleteMemoryStore |
Memory stores |
workspace ARN |
DELETE /v1/memory_stores/{id} |
Data |
Full, Limited |
CreateWebhook |
Webhooks |
workspace ARN |
POST /v1/webhooks |
Management |
Full, Limited |
GetWebhook |
Webhooks |
workspace ARN |
GET /v1/webhooks/{id} |
Management |
Full, Inference, Limited, ReadOnly |
ListWebhooks |
Webhooks |
workspace ARN |
GET /v1/webhooks |
Management |
Full, Inference, Limited, ReadOnly |
UpdateWebhook |
Webhooks |
workspace ARN |
POST /v1/webhooks/{id} |
Management |
Full, Limited |
DeleteWebhook |
Webhooks |
workspace ARN |
DELETE /v1/webhooks/{id} |
Management |
Full, Limited |
RotateWebhookSecret |
Webhooks |
workspace ARN |
POST /v1/webhooks/{id}/regenerate_signing_secret |
Management |
Full, Limited |
CreateUserProfile |
User profiles |
workspace ARN |
POST /v1/user_profiles |
Data |
Full |
GetUserProfile |
User profiles |
workspace ARN |
GET /v1/user_profiles/{id} |
Data |
Full, Inference, Limited, ReadOnly |
ListUserProfiles |
User profiles |
workspace ARN |
GET /v1/user_profiles |
Data |
Full, Inference, Limited, ReadOnly |
UpdateUserProfile |
User profiles |
workspace ARN |
POST /v1/user_profiles/{id} |
Data |
Full |
CreateWorkspace |
Workspaces |
* (account-scoped) |
POST /v1/organizations/workspaces |
Management |
Full |
GetWorkspace |
Workspaces |
workspace ARN |
GET /v1/organizations/workspaces/{id} |
Management |
Full, Inference, Limited, ReadOnly |
ListWorkspaces |
Workspaces |
* (account-scoped) |
GET /v1/organizations/workspaces |
Management |
Full, Inference, Limited, ReadOnly |
UpdateWorkspace |
Workspaces |
workspace ARN |
POST /v1/organizations/workspaces/{id} |
Management |
Full |
ArchiveWorkspace |
Workspaces |
workspace ARN |
POST /v1/organizations/workspaces/{id}/archive |
Management |
Full |
RegisterKey |
Encryption keys |
* (account-scoped) |
POST /v1/organizations/external_keys |
Management |
Full |
GetKey |
Encryption keys |
* (account-scoped) |
GET /v1/organizations/external_keys/{id} |
Management |
Full, Inference, Limited, ReadOnly |
ListKeys |
Encryption keys |
* (account-scoped) |
GET /v1/organizations/external_keys |
Management |
Full, Inference, Limited, ReadOnly |
UpdateKey |
Encryption keys |
* (account-scoped) |
POST /v1/organizations/external_keys/{id} |
Management |
Full |
DisableKey |
Encryption keys |
* (account-scoped) |
DELETE /v1/organizations/external_keys/{id} |
Management |
Full |
ListComplianceActivities |
Compliance |
* (account-scoped) |
GET /v1/compliance/activities |
Management |
Full, Inference, Limited, ReadOnly |
CallWithBearerToken |
Authentication |
* (route-less) |
(none) |
— |
Full, Inference, Limited, ReadOnly, SelfHostedEnvironment |
AssumeConsole |
Console access |
* (route-less) |
(none) |
— |
Full |
CloudTrail: Management events (default-on) = workspace, external key, compliance, vault, webhook actions; Data events (opt-in, extra cost) = inference, batch, model, file, skill, user profile and other Managed Agents actions. Access Transparency for this platform is delivered via the Compliance API (not CloudTrail).
# (g) Regions, IP addresses, data residency, retention, access transparency
# Supported regions (access from)
The official list enumerates 175 countries/territories (page: Supported regions) — including Canada, USA, UK, EU member states, Japan, South Korea, Australia, India, Brazil, Mexico, Israel, UAE, Saudi Arabia, South Africa, Ukraine (except Crimea, Donetsk, Luhansk). Notably absent: China, Russia, Iran, North Korea, Belarus, Venezuela, Cuba, Syria, Afghanistan, Ethiopia, Hong Kong, Macau. Full list reproduced in sources/anthropic/pages/api/supported-regions.md.
# IP addresses (fixed, "will not change without notice")
| Direction |
Range |
| Inbound IPv4 (api.anthropic.com / Console) |
160.79.104.0/23 |
| Inbound IPv6 |
2607:6bc0::/48 |
| Outbound IPv4 (egress for MCP connector, web search, web fetch — also for Claude Platform on AWS tool calls) |
160.79.104.0/21 |
| Phased out (remove from allowlists) |
34.162.46.92/32, 34.162.102.82/32, 34.162.136.91/32, 34.162.142.92/32, 34.162.183.95/32 |
Claude Platform on AWS inbound endpoint aws-external-anthropic.{region}.api.aws resolves to AWS IP ranges.
# Data residency
Two independent controls (exact names from Data residency):
| Control |
Where |
Values |
Notes |
inference_geo (request body param on POST /v1/messages, also per-request in Batch API, and on Managed Agents agent/session config) |
per request |
"global" (default) · "us" |
Claude 4.6+ only (400 on Opus/Sonnet/Haiku 4.5 and older). Response usage.inference_geo reports where inference ran. "us" = 1.1× price on all token categories (and 1.1× Priority-Tier burndown). Available on Claude API + Claude Platform on AWS; not applicable on Bedrock / Vertex / Foundry (Foundry: US Data Zone Standard deployment) nor via the OpenAI-compat endpoint. |
Workspace data_residency (Console or Admin API workspaces) |
per workspace |
allowed_inference_geos: [...], default_inference_geo: "us"|"global" |
Request geo outside the allowlist → error. Legacy "global routing opt-out" orgs were migrated to allowed_inference_geos: ["us"], default_inference_geo: "us". |
| Workspace geo (data at rest + endpoint processing such as image transcoding/code execution) |
set at workspace creation, immutable |
"us" only |
On Claude Platform on AWS not configurable (effective "us"). |
Limitations: rate limits shared across geos; only us/global inference geos; only us workspace geo.
# Retention (API and data retention)
- Anthropic is the data processor for Claude API, Claude Platform on AWS and Claude in Microsoft Foundry (Bedrock / Vertex: cloud provider). Conversation content is not retained by default, except Covered Models (Claude Fable 5.1, Claude Mythos 5.1, Claude Fable 5, Claude Mythos 5) which require 30-day retention — a ZDR org gets
400 invalid_request_error: "In order to access this model, your organization or workspace must have data retention enabled." unless 30-day retention is enabled for the workspace (Console › Workspaces › Privacy controls).
- ZDR (per org, via sales): covers Messages + Token Counting for eligible features, Claude Code with Commercial-org keys / Enterprise+ZDR, Claude Platform on AWS (on request). Not covered: Console/playground, Managed Agents (stateful), consumer plans, Teams/Enterprise UIs, Claude for Excel, Covered Models, third-party integrations, CORS (unsupported under ZDR), flagged content/legal holds (up to 2 years).
- HIPAA readiness (BAA + HIPAA-enabled org, self-service in Console for eligible orgs): API blocks ineligible features with 400; HIPAA orgs have no local-session capture.
- Feature eligibility (ZDR / HIPAA): Yes/Yes — Messages, token counting, thinking, adaptive thinking, effort, fast mode, 1M context, citations, PDF (inline), prompt caching (in-memory KV/hashes), search results, computer use, bash, text editor, memory tool, web search, fine-grained tool streaming, mid-conversation system messages, data residency. ZDR Yes / HIPAA No — advisor tool, browser use, context editing, compaction, tool search, web fetch, cache diagnostics (qualified). Qualified/Yes — structured outputs (schema cached ≤24 h). No/No — Batch (29-day retention), Files API, Skills, code execution & programmatic tool calling (containers ≤30 days), MCP connector, MCP tunnels, Managed Agents.
- Compliance API data has its own retention model (Activity Feed 6 y; claude.ai content per org policy; session transcripts 6 y/custom).
# Access Transparency
- Not self-serve; enabled per org (all workspaces) by the account team; enabling it also enables the Compliance API.
- Each human view of covered content by Anthropic personnel writes an
anthropic_access activity to the Activity Feed (filter activity_types[]=anthropic_access); automated processing does not, except cmek_preserve preservation records. Extra fields: accessed_at, accessor_department (e.g. Safeguards), reason_code ∈ {safety_review, incident_response, policy_violation_investigation, csae_report}, resource_details {type: "message", id, parent}, workspace_id; actor is always {type: "anthropic_actor", email_address: null}.
- Covered: Claude API (
api.anthropic.com) prompts/responses, Claude Code via API key, Claude Platform on AWS (events via Compliance API, not CloudTrail). Not covered: Batch & Files APIs, claude.ai Enterprise seats, Claude for Work, consumer plans, Console playground, Foundry, Bedrock, Vertex.
- The
anthropic_access / cmek_preserve strings are absent from the 506-value reference enum (see §c) — likely a reference-page lag.
# Adjacent (skimmed, not compliance endpoints)
- Inference hooks (beta, Enterprise,
organization:manage): inline allow/deny of each governed prompt by the org's own AI-security HTTPS server (prompt event only); complements the after-the-fact Compliance API. Toggles surface in effective settings / inference_* activity types.
- App Attest: device-attested one-hour tokens for iOS/macOS apps calling
/v1/messages (Claude API only); appears in the Activity Feed as attested_device_actor.
# Uncertainties / not verifiable offline
- Nothing was called: whether our key type would receive
404 Not found (documented for non-compliance keys) is inferred from docs, not observed.
- Scope for
GET …/projects/{id}/collaborators and the Code Artifacts endpoints is not stated on their reference pages; recorded as read:compliance_user_data by resource family.
anthropic_access / cmek_preserve activity types documented in Access Transparency are missing from the reference activity_types[] enum.
anthropic-beta header value for the Admin compliance_settings endpoints is not documented (SDKs use ?beta=true).
- The reference pages' curl examples use
Authorization: Bearer … while every guide uses x-api-key; both are recorded, x-api-key treated as canonical.
- Second rate-limit budget for remote-session endpoints has no documented numeric value.
- IAM: the page documents no condition keys;
condition_keys is [] everywhere (not "none exist" — just none documented).